Podcasts about talos outreach

  • 6PODCASTS
  • 34EPISODES
  • 20mAVG DURATION
  • ?INFREQUENT EPISODES
  • Jun 28, 2024LATEST

POPULARITY

20172018201920202021202220232024


Best podcasts about talos outreach

Latest podcast episodes about talos outreach

Talos Takes
Time to catch up on the wide-reaching Snowflake incident

Talos Takes

Play Episode Listen Later Jun 28, 2024 16:57


Over 160 companies have been affected by a data breach at data storage company Snowflake, including Ticketmaster, Nieman Marcus and more. But the issue wasn't a security vulnerability or some sophisticated malware — it was just someone who exposed their login credentials at a different company. Host Jon Munshaw got Pierre Cadieux from Talos IR and Nick Biasini from Talos Outreach to discuss the follow-on breaches that have resulted from this and the lessons we can learn about making our login credentials more secure. 

Talos Takes
Turla has been around for 20-plus years at this point, but they're still mixing things up

Talos Takes

Play Episode Listen Later Apr 5, 2024 9:04


Holger Unterbrink of Talos Outreach joins the show this week to discuss his recent Turla APT research. This Russian state-sponsored actor has been around for years but is regularly adding new tooling to its arsenal. Holger has new details about their latest tool, TinyTurlaNG, and insight into the types of organizations they're targeting.

Talos Takes
What's new about GhostSec's ransomware-as-a-service model

Talos Takes

Play Episode Listen Later Mar 8, 2024 12:06


Chetan Raghuprasad from the Talos Outreach team joins Talos Takes this week to talk to Jon about the GhostSec threat actor that he and a few colleagues wrote about for the Talos blog. GhostSec has teamed up with another ransomware group to carry out double extortion attacks all over the globe, with increasing frequency over the past year. They discuss what's unique about this particular RaaS model, where GhostSec came from, and the benefits of going in on a team-up. 

Talos Takes
How are attackers using malicious drivers in Windows to stay undetected?

Talos Takes

Play Episode Listen Later Feb 2, 2024 11:36


Chris Neal from Talos Outreach joins the show today to talk about his research into the ways adversaries are using malicious drivers on Windows to spread malware. He recently launched a new series on the Talos blog about the basics of drivers and how security researchers can reverse engineer them to learn more about attacker TTPs and develop new detection content. Chris discusses when he first spotted this type of attack, what advantages it presents for the attacker and the other aspects of the research he plans to dive into.

Talos Takes
Why has the Phobos ransomware been working for so long?

Talos Takes

Play Episode Listen Later Nov 17, 2023 13:07


Guilherme Venere from Talos Outreach joins the show this week to talk about his research into the 8Base threat actor and its use of a variant of the Phobos ransomware. He recently published several works on the many variants of Phobos that exist in the wild, and why 8Base has been so successful using it for years now. 

ransomware phobos talos outreach
Talos Takes
A warning about scams in "Roblox" (or any other online game, really)

Talos Takes

Play Episode Listen Later Nov 10, 2023 10:09


Tiago Pereira from Talos Outreach joins the program this week to talk about his research into the different types of scams that appear in the online game "Roblox." Many underage users are at risk of being targeted by malicious users looking to steal their money, in-game items or even install malware on their devices. 

Talos Takes
You're never going to believe this, but Lazarus Group is back again

Talos Takes

Play Episode Listen Later Sep 1, 2023 9:53


North Korea's infamous APT group is back on the scene, this time with two new remote access trojans. By now, you've probably heard of Lazarus Group and all the annoying things they do to steal sensitive information, make money for North Korea's missile program, etc. But we have an update on their current tactics and payloads they're sending around the globe. Asheer Malhotra from Talos Outreach joins Talos Takes this week to discuss the two new RATs he and his team discovered, why Lazarus Group is still creating new tools, and how their use of older, open-source software has made tracking them ever-so-slightly easier. 

Talos Takes
The various ways attackers can mess with URLs, TLDs and DNS

Talos Takes

Play Episode Listen Later Jun 30, 2023 13:42


We decided to have a web navigation extravaganza this week! Guilherme Venere and Jaeson Schultz from Talos Outreach have both long been researching the ways in which bad actors try to damage users' inherent trust in the internet. Most internet users interact with the web by typing in a URL or domain name into their web browser (i.e., google.com) expecting that will take them to the right place. But attackers have found various ways to mess with that series of handshakes that must take place. Guilherme and Jaeson talk to Jon about their past years of research into typosquatting domains, new TLDs that open up the door to data leaks, DNS manipulation and more. Additional reading:".Zip" top-level domains draw potential for information leaksDNS Hijacking Abuses Trust In Core Internet ServiceSea Turtle keeps on swimming, finds new victims, DNS hijacking techniquesSecurity implications of misconfigurationsDomain dumpster diving

Beers with Talos Podcast
The XDR Files

Beers with Talos Podcast

Play Episode Listen Later May 18, 2023 31:58


Our second of two episodes recorded live at the RSA Conference, Mitch and Lurene are joined by Nick Biasini from Talos Outreach and AJ Shipley, a vice president of product management for Cisco Secure. The four of them recap Nick and AJ's talk they gave at RSA and discuss the centralization of cybersecurity. AJ shares some important insights about the product side of cybersecurity, and how everyone in the space needs to be better focused on stopping the bad guys versus competing against one another. They also cover the announcement of Cisco's newest flagship cybersecurity product: Cisco XDR.

Talos Takes
What makes the new Greatness phishing-as-a-service tool so great?

Talos Takes

Play Episode Listen Later May 12, 2023 8:00


Tiago Pereira from Talos Outreach joins the show this week to talk about his recent discovery of a new phishing-as-a-service tool called "Greatness." Since everything else is "as-a-service" nowadays, it's only fitting that attackers have figured out how to monetize easy phishing tools, too. Tiago discusses what makes Greatness unique, why it's going after business targets specifically, and why it creates such convincing fake Office 365 login pages. 

Talos Takes
The basics of threat hunting

Talos Takes

Play Episode Listen Later Oct 21, 2022 10:15


To celebrate this week's National Cybersecurity Awareness Month theme, we have a special 101 episode of Talos Takes to cover the basics of threat hunting. This is a crucial skill for any cybersecurity professional-in-training and one of the questions we get the most often. Asheer Malhotra from the Talos Outreach team joins the show to talk about where he starts finding new malware families and threat actors, what the barriers usually are that he has to overcome and what check boxes he has to hit before he can talk about something publicly. For more on this topic, watch our "Threat Hunting 101" livestream from earlier this week here. 

Talos Takes
Once more into the Lazarus Pit

Talos Takes

Play Episode Listen Later Sep 23, 2022 8:04


Vitor Ventura from the Talos Outreach team joins the show this week to run down Talos' recent research into the Lazarus Group. This well-known North Korean state-sponsored threat actor is well known for their ransomware and cryptocurrency-related cyber attacks, but we recently found them launching a new information-stealing trojan targeting energy companies. Vitor talks about the new trojan, MagicRAT, and how it fits into their larger plans and motivations. 

Talos Takes
Talos Takes Ep. #103: What we can learn from a recent AvosLocker attack

Talos Takes

Play Episode Listen Later Jul 8, 2022 8:28


Chris Neal from Talos Outreach recently dove into a recent AvosLocker ransomware attack in the wild. This week, he joins the show to recap his major takeaways from this attack that other potential targets can learn from. He and Jon talk about the current ransomware-as-a-service landscape, the use of living-off-the-land binaries and other calling cards from this actor to keep an eye out for.

Talos Takes
Talos Takes Ep. #91: The tax scams cometh

Talos Takes

Play Episode Listen Later Apr 11, 2022 6:09


It's tax season! You know what that means — sadness, frustration and scams. Host Jon Munshaw sat down with Nick Biasini from the Talos Outreach team to talk about common tactics adversaries use around this “holiday” to try and spread malware, steal personal information and take users' money. We talk about free security tools you can deploy to block these types of threats, common spam tactics to keep an eye out for and other services that can help you prepare for a worst-case scenario.

Talos Takes
Talos Takes Ep. #61: Why does SideCopy seem so familiar?

Talos Takes

Play Episode Listen Later Jul 16, 2021 8:28


The last time Jon had Asheer Malhotra from Talos Outreach on the show, they covered the Transparent Tribe APT. Asheer joins the show again this week to talk about another threat actor that is very similar to Transparent Tribe, but is just a tad different. Asheer recently co-authored a research paper on the aptly named SideCopy actor, which borrows many TTPs from their fellow actors, including Transparent Tribe. This episode, we'll talk about SideCopy's methods, why they may be borrowing so much from those around them and where they could go from here.

Talos Takes
Talos Takes Ep. #60 (XL Edition): Kaseya emergency show

Talos Takes

Play Episode Listen Later Jul 9, 2021 21:41


In this special “XL edition” of Talos Takes, we're bringing you the audio version of our live stream this week discussing the Kaseya supply chain attack. Nick Biasini from Talos Outreach went live with Hazel Burton, a Cisco product marketing manager, to discuss what transpired over the long Fourth of July weekend. Nick discussed the Kaseya exploit leveraged in this campaign, plus the follow-on ransomware attacks. This is the best place to get the tl;dr on what happened, what you need to be doing now, and what Cisco Secure solutions can keep you protected.

Talos Takes
Talos Takes Ep. #55: What's next for Transparent Tribe?

Talos Takes

Play Episode Listen Later May 28, 2021 8:28


Asheer Malhotra from Talos Outreach has followed Transparent Tribe for years now. This APT has been all over the place using all sorts of trojans. So where my they go next? Asheer joins Talos Takes this week to discuss the malware this group deploys and how they use typo-squatted domains to lure victims in.

@BEERISAC: CPS/ICS Security Podcast Playlist
ICS/SCADA Security - The Permanence and People Problems

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Apr 22, 2021 42:31


Podcast: Beers with Talos Podcast (LS 45 · TOP 1% what is this?)Episode: ICS/SCADA Security - The Permanence and People ProblemsPub date: 2021-04-21Recorded March 2020 – ICS and SCADA systems are deeply embedded all around us in critical infrastructure. Today we talk about some of the inherent issues in infrastructure security and take a wide-ranging look at the ICS- and SCADA-specific issues found there. Joe Marshall from the Talos Outreach group joins to share his insights on the space and how donuts are the ultimate career track switching tool. Oh- and Matt’s cat discovers jerky. Full show notes on the Talos blogThe podcast and artwork embedded on this page are from Cisco Talos, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

Beers with Talos Podcast
ICS/SCADA Security - The Permanence and People Problems

Beers with Talos Podcast

Play Episode Listen Later Apr 21, 2021 42:31


Recorded March 2020 – ICS and SCADA systems are deeply embedded all around us in critical infrastructure. Today we talk about some of the inherent issues in infrastructure security and take a wide-ranging look at the ICS- and SCADA-specific issues found there. Joe Marshall from the Talos Outreach group joins to share his insights on the space and how donuts are the ultimate career track switching tool. Oh- and Matt’s cat discovers jerky. Full show notes on the Talos blog

Secure Networks: Endace Packet Forensics Files
Episode 20: Craig Williams, Director of Talos Outreach, Cisco

Secure Networks: Endace Packet Forensics Files

Play Episode Listen Later Apr 20, 2021 18:23


What are the latest threats that Threat Intelligence teams are seeing and what are they recommending as best practices for defending against the latest cybersecurity threats? You won’t want to miss this episode of the Endace Packet Forensic files as Michael sits down with Craig Williams, Director of Talos Outreach at Cisco. Craig talks about how threats have been evolving over the last year - particularly during the Covid-19 pandemic - and gives us some insights into recent high-profile security issues.  He also shares some advice how you can validate your corporate applications and implement zero-trust policies to reduce your exposure to threats.

Talos Takes
Talos Takes Ep. #49: LodaRAT's connection to Android devices

Talos Takes

Play Episode Listen Later Apr 16, 2021 6:05


Chris Neal from Talos Outreach has followed LodaRAT for years now. It’s gone from a fairly small threat to a full-on malware with several features that target all sorts of Android devices. Chris joins the show this week to discuss his history of researching LodaRAT and updates us on its latest TTPs. Find out how this trojan tries to trick users into downloading it on their phones and how it hunts for your banking information.

Research Saturday
Encore: Unpacking the Malvertising Ecosystem. [Research Saturday]

Research Saturday

Play Episode Listen Later Jan 2, 2021 29:57


Researchers at Cisco's Talos Unit recently published research exploring the tactics, technics and procedures of the global malvertising ecosystem. Craig Williams is head of Talos Outreach at Cisco, and he guides us through the life cycle of malicious online ads, along with tips for protecting yourself and your organization. The research can be found here:  https://blog.talosintelligence.com/2019/07/malvertising-deepdive.html

The CyberWire
Encore: Unpacking the Malvertising Ecosystem. [Research Saturday]

The CyberWire

Play Episode Listen Later Jan 2, 2021 29:57


Researchers at Cisco's Talos Unit recently published research exploring the tactics, technics and procedures of the global malvertising ecosystem. Craig Williams is head of Talos Outreach at Cisco, and he guides us through the life cycle of malicious online ads, along with tips for protecting yourself and your organization. The research can be found here:  https://blog.talosintelligence.com/2019/07/malvertising-deepdive.html

Research Saturday
PoetRAT: a complete lack of operational security.

Research Saturday

Play Episode Listen Later Nov 7, 2020 22:15


Cisco Talos discovered PoetRAT earlier this year. Since then, they observed multiple new campaigns indicating a change in the actor's capabilities and showing their maturity toward better operational security. They assess with medium confidence this actor continues to use spear-phishing attacks to lure a user to download a malicious document from temporary hosting providers. They currently believe the malware comes from malicious URLs included in the email, resulting in the user clicking and downloading a malicious document. These Word documents continue to contain malicious macros, which in turn download additional payloads once the attacker sets their sites on a particular victim. As the geopolitical tensions grow in Azerbaijan with neighboring countries, this is no doubt a stage of espionage with national security implications being deployed by a malicious actor with a specific interest in various Azerbajiani government departments. Joining us in this week's Research Saturday to discuss the research from Cisco's Talos Outreach is Craig Williams. The research can be found here:  PoetRAT: Malware targeting public and private sector in Azerbaijan evolves

The CyberWire
PoetRAT: a complete lack of operational security. [Research Saturday]

The CyberWire

Play Episode Listen Later Nov 7, 2020 22:15


Cisco Talos discovered PoetRAT earlier this year. Since then, they observed multiple new campaigns indicating a change in the actor's capabilities and showing their maturity toward better operational security. They assess with medium confidence this actor continues to use spear-phishing attacks to lure a user to download a malicious document from temporary hosting providers. They currently believe the malware comes from malicious URLs included in the email, resulting in the user clicking and downloading a malicious document. These Word documents continue to contain malicious macros, which in turn download additional payloads once the attacker sets their sites on a particular victim. As the geopolitical tensions grow in Azerbaijan with neighboring countries, this is no doubt a stage of espionage with national security implications being deployed by a malicious actor with a specific interest in various Azerbajiani government departments. Joining us in this week's Research Saturday to discuss the research from Cisco's Talos Outreach is Craig Williams. The research can be found here:  PoetRAT: Malware targeting public and private sector in Azerbaijan evolves

Research Saturday
Using global events as lures.

Research Saturday

Play Episode Listen Later Aug 22, 2020 22:52


The goal of malicious activity is to compromise the system to install some unauthorized software. Increasingly that goal is tied to one thing: the user. Over the past several years, we as an industry improved exploit mitigation and the value of working exploits has increased accordingly. Together, these changes have had an impact on the threat landscape. We still see large amounts of active exploitation, but enterprises are getting better at defending against them. This has left adversaries with a couple of options, develop or buy a working exploit that will defeat today's protections, which can be costly, or pivot to enticing a user to help you. In today's threat landscape, adversaries are always trying to develop and implement the most effective lures to try and draw users into their infection path. They've tried a multitude of different tactics in this space, but one always stands out — current events. Joining us on this week's Research Saturday from Craig Williams from Cisco's Talos Outreach team to walk us through how current events are used as lures. The research and blog post can be found here:  Adversarial use of current events as lures The CyberWire's Research Saturday is presented by Juniper Networks. Thanks to our sponsor Enveil, closing the last gap in data security.

The CyberWire
Using global events as lures.

The CyberWire

Play Episode Listen Later Aug 22, 2020 22:22


The goal of malicious activity is to compromise the system to install some unauthorized software. Increasingly that goal is tied to one thing: the user. Over the past several years, we as an industry improved exploit mitigation and the value of working exploits has increased accordingly. Together, these changes have had an impact on the threat landscape. We still see large amounts of active exploitation, but enterprises are getting better at defending against them. This has left adversaries with a couple of options, develop or buy a working exploit that will defeat today's protections, which can be costly, or pivot to enticing a user to help you. In today's threat landscape, adversaries are always trying to develop and implement the most effective lures to try and draw users into their infection path. They've tried a multitude of different tactics in this space, but one always stands out — current events. Joining us on this week's Research Saturday from Craig Williams from Cisco's Talos Outreach team to walk us through how current events are used as lures. The research and blog post can be found here:  Adversarial use of current events as lures The CyberWire's Research Saturday is presented by Juniper Networks. Thanks to our sponsor Enveil, closing the last gap in data security.

Research Saturday
Unpacking the Malvertising Ecosystem.

Research Saturday

Play Episode Listen Later Aug 10, 2019 29:42


Researchers at Cisco's Talos Unit recently published research exploring the tactics, technics and procedures of the global malvertising ecosystem. Craig Williams is head of Talos Outreach at Cisco, and he guides us through the life cycle of malicious online ads, along with tips for protecting yourself and your organization. The research can be found here:  https://blog.talosintelligence.com/2019/07/malvertising-deepdive.html

The CyberWire
Unpacking the Malvertising Ecosystem — Research Saturday

The CyberWire

Play Episode Listen Later Aug 10, 2019 26:09


Researchers at Cisco's Talos Unit recently published research exploring the tactics, technics and procedures of the global malvertising ecosystem. Craig Williams is head of Talos Outreach at Cisco, and he guides us through the life cycle of malicious online ads, along with tips for protecting yourself and your organization. The research can be found here:  https://blog.talosintelligence.com/2019/07/malvertising-deepdive.html The CyberWire's Research Saturday is presented by Juniper Networks. Thanks to our sponsor Enveil, closing the last gap in data security.

Research Saturday
Sea Turtle state-sponsored DNS hijacking.

Research Saturday

Play Episode Listen Later May 4, 2019 27:11


Researchers at Cisco Talos have been tracking what they believe is a state-sponsored attack on DNS systems, targeting the Middle East and North Africa. This attack has the potential to erode trust and stability of the DNS system, so critical to the global economy. Craig Williams is director of Talos Outreach at Cisco, and he joins us to share their findings.  The original research can be found here: https://blog.talosintelligence.com/2019/04/seaturtle.html

The CyberWire
Sea Turtle state-sponsored DNS hijacking — Research Saturday

The CyberWire

Play Episode Listen Later May 4, 2019 23:33


Researchers at Cisco Talos have been tracking what they believe is a state-sponsored attack on DNS systems, targeting the Middle East and North Africa. This attack has the potential to erode trust and stability of the DNS system, so critical to the global economy. Craig Williams is director of Talos Outreach at Cisco, and he joins us to share their findings.  The original research can be found here: https://blog.talosintelligence.com/2019/04/seaturtle.html The CyberWire's Research Saturday is presented by Juniper Networks. Thanks to our sponsor Enveil, closing the last gap in data security.

Beers with Talos Podcast
VB 2018 Rundown and Prevalent Problems with PDF

Beers with Talos Podcast

Play Episode Listen Later Oct 19, 2018 42:46


Recorded 10/5/18 - Quick chat to get to know this week’s special guests from the Talos Outreach team - Paul Rascagneres, Vanja Svajcer, and Warren Mercer. We discuss everyone’s work being presented at Virus Bulletin, and Paul and Warren being nominated the Péter Szőr Award. We also cover a lot of vuln discovery work recently released around various PDF software Full show notes available [on the Talos Blog](https://blog.talosintelligence.com/2018/10/beers-with-talos-ep-39-vb-2018-rundown.html)

security vulnerability sz talos prevalent talos outreach vanja svajcer
Beers with Talos Podcast
This is a PSA: Stop Clicking. There is No Prince.

Beers with Talos Podcast

Play Episode Listen Later May 16, 2018 56:19


Recorded 5/11/18 - First and foremost, we recorded this EP one day before our “birthday”. We want to thank everyone, especially you (the listeners), who have let us do this for the last year racking up over half a million downloads! In this EP, we welcome special guest Nick Biasini from Talos Outreach - we set out to talk about several topics, but spend most of our time with Nick around the idea of building a stronger culture of cybersecurity and what it would take to raise the baseline. We are missing Matt this week, and hope he had an amazing time following the DMB tour up to Burlington or whatever he was doing.

security burlington talos dmb psa stop gandcrab talos outreach
The CyberWire
2018 RSAC Outlook - Special Edition

The CyberWire

Play Episode Listen Later May 8, 2018 17:51


Just before the RSA conference this year, we spoke with a pair of industry experts for their take on the year so far, and what they expect to see in the coming months. In this CyberWire Special Edition, we hear from Craig Williams, Director of Talos Outreach at Cisco, and later in the show from Jon Rooney, Vice President of Product marketing at Splunk.