International cyber security company
POPULARITY
Categories
Don’t let the AI wave crush you. Subscribe to our Newsletter: https://theultimatepartner.com/ebook-subscribe/ Check Out UPX: https://theultimatepartner.com/experience/ Dive into the seismic shifts happening within the AWS Marketplace and discover how AI, self-service product-led growth (PLG), and advanced co-selling strategies are redefining partner success. Matt Yanchyshyn, VP of Marketplace at AWS breaks down the recent announcements from the summit, illustrating how agility and adaptation are crucial to surviving the new agentic future. From lowering professional services fees to the explosion of business applications like ServiceNow, this conversation reveals the hidden mechanics of modern cloud procurement and how you can position your organization to capture massive enterprise opportunities before your competitors do. https://youtu.be/gaWxU1kgCLk Key Takeaways Adapting to the new agentic future requires agility rather than fighting the influx of AI tools. Lowering the listing fee for professional services from 2.5% to 0.5% drastically improves partner economics. Organizations without a self-service or PLG motion on the marketplace are literally leaving money on the table. Millennial buyers increasingly initiate complex enterprise procurements through self-service and AI-driven research. New AI-powered opportunity scoring empowers partners to prove their value internally and to AWS. Marketplace success hinges on optimizing metadata for AI agents, not just traditional SEO. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags: AWS Marketplace, agentic workflow, med pick scoring, phoenix.ai, Cara Cloud, branded storefronts, product-led growth strategy, intrinsic value boost, SaaS evolution, self-service motion, Databricks credit model, Trend Micro companion app, MCP servers, opportunity score tracking, PPA drawdown, concurrent agreements, AAMI structural debt, CXML procurement Transcript: Matt Y Audio Podcast [00:00:00] Matt Y: The ability to adapt with change and kind of roll with punches. ’cause a lot of people are saying like, agents are gonna destroy everything. And, and the opposite has been true. [00:00:08] Vince Menzione: You can feel it happening. The ecosystem is shifting beneath us, the way hyperscalers are partnering, how AI is remaking the channel and what it means to win in 2026. [00:00:19] Vince Menzione: Welcome to the Ultimate Partner Podcast. I’m Vince Menzi, own your host. And each week I sit down with leaders at the intersection of technology, partnerships and outcomes. The voices shaping how ecosystems actually work. We talk about what’s real, what’s changing, and what it takes to lead in this era where the partner channel isn’t just part of the strategy. [00:00:42] Vince Menzione: It is the strategy because being in the room changes everything. [00:00:46] Matt Y: Let’s start. [00:00:50] Vince Menzione: And now on to the really important stuff. So, Matt, I don’t wanna butcher it ’cause I, a couple people have told me how to pronounce your last name and they said use the word magician and you’ll get close to it. But I’m just gonna introduce you as Matt Wy and I’m gonna ask you to pronounce your name on stage, but I want to have you join us. [00:01:08] Vince Menzione: So excited to have Matt wy. After a super busy day and night last night, come over from Brooklyn and join us today. Matt, so great to have you. Thanks. Thank you so much. Thank you so much. Alright, so pronounce your name for us. [00:01:23] Matt Y: Anyone wanna guess? Ian’s? It’s like magician. [00:01:27] Vince Menzione: It’s not that hard, [00:01:28] Matt Y: it’s not that [00:01:28] bad, [00:01:28] Vince Menzione: but I don’t wanna butcher. [00:01:29] Vince Menzione: I wanted to let you do it. Good. [00:01:30] Matt Y: What calls me Matt White. [00:01:31] Vince Menzione: That’s great. [00:01:32] Matt Y: Yeah. [00:01:32] Vince Menzione: So 13 years. [00:01:34] Matt Y: Four coming up on 14 next month. Yeah. [00:01:36] Vince Menzione: Wow. Congratulations. Yeah. So you’ve been there, you’ve been there since the early days. And we, we had a conversation. I had some Microsoft, former Microsoft colleagues. Uh, Theresa Carlson, for those of you who knew the public sector business. [00:01:48] Vince Menzione: Yeah. Who started, I mean, Andy came out, it was so funny because I was there and she was hosting Andy for a dinner and with all the CIOs of the federal government. [00:01:57] Matt Y: Yeah. [00:01:58] Vince Menzione: And she was still at Microsoft and it was actually kind of an interesting time. And she came over and did a lot of great things for a number of years. [00:02:04] Matt Y: Yeah. She [00:02:05] Vince Menzione: and a lot of great [00:02:05] Matt Y: business. [00:02:06] Vince Menzione: Yeah. She really like, it went from employee number one to 7,000. [00:02:09] Matt Y: Yeah. [00:02:09] Vince Menzione: And you, you were, you’ve been there all that whole time. Pretty much. [00:02:12] Matt Y: Yeah, I guess when I started in New York, just down the road, we were, uh, in a Regis facility. There were like 11 of us in, uh, just sitting around a table and we had to speak quietly sometimes because there was a, um. [00:02:21] Matt Y: Some type of a financial services organization down the hall and they’d listen to try and get stock tips on Amazon. Yeah, [00:02:28] Vince Menzione: I love it. [00:02:29] Matt Y: Never leaked. That’s [00:02:29] Vince Menzione: good. I love it. [00:02:30] Matt Y: Yeah, [00:02:30] Vince Menzione: you probably got some great stories and, um, we won’t have time for today ’cause I wanna leave some room for conversations on marketplace end questions. [00:02:38] Matt Y: Yeah. [00:02:38] Vince Menzione: But I would love to invite you back for a real, like, in-depth podcast and I would love to get the whole genesis story. [00:02:44] Matt Y: Let’s do it. [00:02:45] Vince Menzione: We’ll do it. Okay, so let’s talk about, let’s talk about yesterday for you. Uh, some, some really big announcements as well. I thought maybe you could recap a little bit of what’s been going on in the marketplace business and it’s an, it’s been an exciting time. [00:02:58] Matt Y: Yeah. Yeah. You know what’s, I think what was really nice yesterday is it was sort of the combination of bringing, uh, our partner services like Partner Central and all those other services together closer to marketplace. We’ve been doing that over, over several years. So Marketplace has some of its own. [00:03:12] Matt Y: Big announcements, like, uh, we have a, we formalized our list and sell initiative. For example. We have a new, so it we essentially reducing the cost, uh, to list on marketplace through a partner program. [00:03:22] Vince Menzione: Yep. [00:03:22] Matt Y: And incentives associated with that. We have a new AI powered listing experience, which I think is particularly important ’cause I think many of you are like me and watching your SEO numbers go down and watching your agent traffic go up. [00:03:33] Matt Y: And so having, uh, an AI assistance in marketplace to optimize your listings for not just to, you know, retain what you can of your SEO, but prepare for the newent future and improve your GEO as we’re calling it. So that, [00:03:45] Vince Menzione: so it’s GEO now? [00:03:46] Matt Y: Yeah. You know, there’s a little debate right now in the acronym Moral A A EO versus GO I’m going, I’m on the G team, so, yeah. [00:03:52] Vince Menzione: Alright. GEO [00:03:54] Matt Y: It’s like the, the, yeah, they’re gonna win. They’re like the Knicks, but the, um, [00:03:57] Vince Menzione: yeah, yeah, exactly. [00:03:57] Matt Y: But yeah, so AI assisted, uh, I mean, making. The most of, like, essentially marketplace is an excellent conversion engine. And so using AI to help improve that conversion engine in the form of your PDPs for both humans and agents. [00:04:08] Matt Y: So that was an exciting launch. Um, I got the most applause when I announced that. We lowered, we made the economics better for, uh, consulting offers professional services, nice to marketplace. We lowered the listing fee from 2.5 to, to 0.5% and wow, it goes even lower in certain circumstances. So just improving the economics. [00:04:24] Matt Y: I’m really excited to. Really partner with a lot of you to reinvent services through, through the marketplace like we did with SAS and other areas. Uh, and we’re doing with agents right now. So that was a big one. And then a whole series of announcements around, um, how we’re making it easier and more cost effective and more efficient to partner with AWS. [00:04:41] Matt Y: So using AI to, uh, using med pick scoring to automatically progress opportunities so you don’t have to kind of wait on a human. To, to click and progress, you know, that that can take days. And, uh, if you, if you wanna have an opportunity and have that be cos sold with AWS, that can be through a mix of agents for the long tail and with humans in the, in the sort of top end and more complex. [00:05:00] Matt Y: And allowing AI to help all the partners improve their opportunity quality so that we can better co-sell together. So. Yeah, I said AI a lot intentionally. Um, [00:05:09] Audience Guest: yeah, [00:05:10] Matt Y: AI sort of in the whole cycle for buyers, for sellers, uh, for operational efficiency, cost of sales. So a lot of announcements. I think I hit the big ones, so yeah. [00:05:18] Matt Y: I’m Might have missed something there. There we go. [00:05:21] Vince Menzione: George. [00:05:21] Matt Y: Oh, and storefront. Yeah. Thanks George. See, I look at George to see what I missed. Uh, we, we acquired a great company called phoenix.ai late last year. Okay. And you, you actually were said Caresoft and Yeah. Be down. Uh, [00:05:30] Vince Menzione: yeah. [00:05:30] Matt Y: So if you’re familiar with Cara Cloud, they have a procurement portal. [00:05:33] Matt Y: It’s heavy use by the US government, and they, um. Uh, we, we acquired them, uh, the really great growth company. They have over 70 logos now, and they help you build a branded storefront on marketplace, which obviously is important in the government space. If you’re procuring on a certain contract with a certain reseller, um, you know, there’s a certain set of products you’re allowed to buy. [00:05:51] Matt Y: But what we’re finding is even down on Wall Street, you hear, um, enterprises are, are using storefronts for internal procurement and they wanna have a curated collection of, of partner products and, and your own ecosystems internally. So we’re selling to both customers. And also to channel partners to build custom storefronts, branded storefronts for, and [00:06:07] Vince Menzione: it makes total sense, right? [00:06:08] Vince Menzione: Yeah, because you wanna li you wanna limit the, the viewing and, uh, and get, because I mean, how many different listings do we have? Like over 30,000? [00:06:16] Matt Y: Yeah. Yeah. There’s, I think the official numbers over th we have over 36,000. I was checking from over 6,000 vendors. Um, it’s a lot. And, and that’s gonna explode with the AI powered, uh, listing, uh, experience that we launched. [00:06:26] Matt Y: We’re gonna make it easier. And I guess what I’ve been telling partners is. You know, customers aren’t clicking through categories anymore. They’re using AI to search. And so it doesn’t matter how big our catalog is, what matters is being found. And what matters is converting that buyer. So if you have a. [00:06:39] Matt Y: If you’re running a demand gen campaign for say, like, you know, life sciences in, in Jersey and there’s a specific buyer at j and j, you wanna capture, that person doesn’t wanna be just dropped onto a generic marketplace, 30,000 listings. They wanna be dropped in a very specific place where they’re seeing like life sciences offers from Accenture, for example, coupled with a life sciences power thing with Elastic, you know, like, but a solution. [00:07:00] Matt Y: And that they want to land in a curated place where that highly intention buyer can be converted effectively. So that, that’s what we’re doing with all this. [00:07:06] Vince Menzione: And that’s where the GEO comes in because [00:07:09] Matt Y: Yeah. ’cause that buyer might be an agent That’s right. With, and that agent has is even more fickle, honestly. [00:07:14] Matt Y: And you know, what used to be milliseconds for the human before they kind of click away is, is now perhaps microseconds. Yeah. And so, uh, you know, having the right metadata and, and the right positioning, uh, the right story that an agent or a human can pick up to ultimately. Uh, complete their product research and choose your product is, is critical. [00:07:30] Vince Menzione: Very cool. Very cool. So before I, I, I’ve been asked to ask you this because I, I’ve had this con, people have brought come to me and said, you gotta ask Matt about music. He’s a big music guy. And, uh, so what are your favorite bands? [00:07:49] Matt Y: So, I mean, the, the real answer is, uh. I, I go to about a show about every week. [00:07:54] Matt Y: As, as Mike Trill knows, uh, we heard a show last night. Um, we were, uh, just a few hours ago, really? And, uh, um, favorite band, uh, well, I’ll tell, I’ll tell a story. I, I had a side hustle with MTV for years. Um, I used to run a music website. Um, oh, that’s cool. I didn’t know that. It got, it got kind of popular. It got sponsored by, if, if anyone’s into like early hip hop. [00:08:16] Matt Y: It got sponsored by a group called Jurassic Five. ’cause he, one of them reached out to me and said, nice. Hey, uh, you know, I’ve been, I like your website. And he ended up paying for a web, hosting a Dream host, if you remember, of cost back then. [00:08:26] Vince Menzione: Oh, Jesus. [00:08:26] Matt Y: Because I was broke and couldn’t afford it. And then, uh, and then this band sent me like a, a single and said, Hey, you know, trying to get the word out about our little band, can you help us out? [00:08:35] Matt Y: And I put their, uh, I put their, you know, single up on my, on my website and it blew up. And that band is Vampire Weekend. So they’re kind of big now. Wow. Yeah. Um, and uh, that got picked up by like Vanity Fair and all these other guys. And then I got sponsored by MTV to essentially write. Music reviews for years on the side. [00:08:51] Matt Y: So I was working for the Associated Press, laying cable in sports and war and, and, uh, yeah. So Vampire Weekend was good to me that, that they, they kind of paved a way to go to a lot of free shows over the years and a lot of bands and see a lot of great music. But yeah. [00:09:03] Vince Menzione: That is very cool. And that, and how did that get your day? [00:09:05] Vince Menzione: WS It was just a, it was just the technology path that was like, [00:09:09] Matt Y: I mean, it’s a, it’s a, I guess it’s a bit of a long story, but, um, the. There’s many versions of this story. I’ll tell the, tell the one quickly. I was living for free in a Fulbright scholarship house in West Africa. You, we can talk about how that happened another time. [00:09:23] Matt Y: And, uh, a guy had sort of fallen down on the floor ’cause he’d had too much to drink. And I, I sort of lay down beside and be like, Hey man, are you all right? And, um, he, uh. He worked, he, he worked for the Associated Press and next day I had the job, um, being West Africa, head of technology for West Africa. [00:09:37] Matt Y: And because of that, um, and as I learned years later, the AP didn’t have dr they had no disaster recovery. Yeah. And I, I can tell you that now ’cause um, you know, 16 years since I worked there, but they, uh, I put the DR in, um, on AWS and we’re talking like, yeah, 16, 17 years ago. This is early. It was early days. [00:09:56] Matt Y: And I, I swear to God, I paid for. Uh, our AWS bill using, um, taxi receipts, fake taxi receipts that I bought in on Nigerian market, um, because there was no budget and so, you know, it was like 30 bucks. [00:10:08] Vince Menzione: I was gonna say swipe a credit card, but they didn’t [00:10:09] Matt Y: knew that this is the entire press this before. [00:10:11] Vince Menzione: This is before, yeah. [00:10:12] Matt Y: Yeah, like the entire ap. Um, and, uh, so AWS called me like, who are you? Like, why, why are you paying on like this like low limit credit card for like the ap? Like, who are you? And, uh. Next day I had the job. Well, a week later I had the job with aw WS. That so cool. So that’s the story’s [00:10:29] Vince Menzione: cool thing. [00:10:29] Matt Y: Yeah. [00:10:30] Vince Menzione: Very cool. [00:10:31] Vince Menzione: Uh, sports teams. So Knicks fan. [00:10:34] Matt Y: Yeah, I mean, I like the Knicks. Um, they’re h hockey, I’m not allowed to say anything different. No. I appreciate them. Uh, I’m a Raptors fan. I grew up in Toronto mostly. Yeah, yeah. Uh, so, and you know, when they won, uh, that was very exciting as well. So no, Nicks are great. I like the Knicks. [00:10:49] Matt Y: Nothing against the Knicks. Um. They’re fine. Yeah. [00:10:54] Vince Menzione: Hockey, hockey fan. Favorite hockey teams? [00:10:56] Matt Y: Oh yeah. Itron. Maple leaf. Maple leaf. Yeah. They’re gonna, they’re gonna win. Of course. Of course. Yeah. Um, like every year they’re actually, we [00:11:02] Vince Menzione: have some Canadians laughing in the sand. [00:11:03] Matt Y: Well, the leaf are, are, are the Knicks of hockey? [00:11:05] Matt Y: Like Yes, they are. You know, it’s 67 years out, coming up on 68 since they won, so That’s crazy. 53 is nothing. I know. Pain. So. Yeah, definitely the least. Yeah. [00:11:15] Vince Menzione: I love it. I love it. It’s so cool. Yeah. So what was the, uh, what was the, what was the last concert you went to? [00:11:22] Matt Y: Well, literally last night. Oh, it was last, [00:11:23] Vince Menzione: oh, that [00:11:24] Matt Y: was actually concert were my favorite bar in the world. [00:11:26] Matt Y: This place called Sunny’s. Uh, it’s, you know, I, I took Mike and, and Matt from, from Texas and from TGS down there to sort of see my neighborhood and they’re like, where are we? And I’m like, yeah, I live here. Uh, sort of an industrial part of Brooklyn. And, and we went to see, um, I dunno what you would call it, like. [00:11:40] Matt Y: I guess it’d be like roots music. There was a woman with an accordion and a guy with a big cowboy hat. Yeah, it was, it was fun. Yeah. [00:11:47] Vince Menzione: That is so funny. Alright, we’re gonna shift back years. Um, important time right now for partners. What, what should partners be looking out for the most? What would you say to them in terms of what’s the, what’s their real headline for them? [00:11:59] Matt Y: Well, I, I, you know, to borrow from you actually, you know, I liked, uh, the, the principles you had up there and, and with agility, um, you know, there’s a lot of fud flying around right now. You know, people. People were like, oh, it’s the demise of sis with the arrival of ai, you know, everyone’s gonna be using agents. [00:12:13] Matt Y: And then it turns out it’s been a huge boon for most, uh, you know, system integrators and consulting companies that I work with. They all have, you know, the, the good ones especially have vibrant consulting practices now, and everyone is deploying fds, uh, you know, um, the new, the new cool acronym. But it’s, it’s essentially created a huge opportunity for the consulting space. [00:12:31] Matt Y: Uh, and similarly, uh, you know, there there’s this narrative around the sa sa apocalypse, which I really hate, you know, ’cause it was, uh, premature and kind of a trigger reaction from the stock market. And, you know, just look, look what Snowflake did. And, you know, they did what a lot of SaaS companies are doing, but they, they added a nice sort of glaze of positioning and, and, you know, their stock popped and they did pretty well. [00:12:50] Matt Y: And so I think the ability to adapt with change and kind of roll with the punches. ’cause a lot of people are saying like, agents are gonna destroy everything. And, and the opposite has been true. For the more successful consulting companies and software companies who have become agentic. But SaaS hasn’t gone away, you know? [00:13:05] Matt Y: No. Look at our own marketplace. We have this agent marketplace, but people aren’t buying atomic agents at scale. They’re buying ified SaaS solutions with sort of agent sidecars, which has created new opportunities for candidly additional licenses, [00:13:16] Vince Menzione: right? [00:13:16] Matt Y: Um, as customers sort of want to consume more AI services on top of their. [00:13:20] Matt Y: On top of their SaaS solutions. So I think being agile, you know, you see like ServiceNow as part of our billionaires club. Yes. They’re not going anywhere. They’re, yeah. They’re gentrifying. You know, Salesforce has pivoted to this headless model, um, along with Asian Force and using sort of Slack as the operating system. [00:13:34] Matt Y: And, you know, you said like a lot of companies from the seventies aren’t around anymore. They’re gonna be winners and losers. Yeah. Um, but the winners are gonna win even more. And so I, I think what’s so important right now for partners is to not, not bite too hard at the, the latest trend. You know, models are changing and everyone’s like, oh, you know, philanthropics really in the world and they’re wonderful, great to work with, amazing technology. [00:13:55] Matt Y: That’s what people are saying about open AI six months ago. That’s right. And before that, you know, and it, I, I was with Fireworks AI yesterday, a great company and they have some really cool stuff with sort of, um, they believe in more cost effective, uh, open source models essentially, that you can find tune. [00:14:08] Matt Y: Maybe that’s gonna win. I don’t know. Um, is it gonna be sort of domain specific models? Is it gonna be highly capable LLMs? Are LLMs gonna level off as soon as Fable and Mythos are allowed to launch? Maybe. I, I don’t think anyone can predict the future right now. So you have to be agile and you have to kind of seize the opportunities and take a couple punches. [00:14:25] Vince Menzione: Yeah. [00:14:26] Matt Y: You know, and marketplace too, like we’re, you have to be unafraid to experiment right now. Um, you know, that’s hard if your stock’s taking a beating. Um, but this is, it’s a, it is a disruptive time, uh, but it’s creating actually enormous opportunities for growth for partners and, and we really see that, you know, in marketplace specifically within AWS. [00:14:45] Vince Menzione: It, it, it does still feel like the deer in the headlights moment. Right. Would you agree? Like you’re probably taking a lot of meetings and, and calls from ISVs specifically? [00:14:54] Matt Y: Well, [00:14:54] Vince Menzione: that are still trying to figure it out. [00:14:56] Matt Y: Yeah. But it’s everyone. Yeah. I think what’s really interesting, I had a meeting [00:14:58] Vince Menzione: with, it’s not just one. [00:14:59] Matt Y: Yeah. I, well, I had a meeting with one of the leading AI companies, like one of the biggest ones. And they, uh, they demonstrated how they work and they were really proud. They were like, you know, look at our agentic workflow. And I came out at me. I’m like, that’s it. Ours is way better. Like really like, you know, ’cause we we’re, we’re using quick desktop with MCP servers and connectors and all this, and you know, we, we have our own sort of ecosystem of partners, a mix of homegrown software and third party. [00:15:20] Matt Y: And I kinda walked out there and, and looked at, you know, my phone, which has been populated by agents this morning with all the, and I was like, I have a way better agent workflow than this world’s leading supposedly AI company. And I think, um, that really, so during, I, I would, during the headlights, you can call it deer in the headlights, I call it chaos. [00:15:36] Matt Y: And in times of chaos there are people who create. Opportunity again. And so, yeah, there are some people who are stuck and who don’t know what to do, who are over worried about token costs, um, who are not experimenting. But there are a lot of companies, uh, taking this opportunity to kind of pivot their business. [00:15:53] Matt Y: Um, I think, I think we’re in a moment and, uh, yeah, I, I candidly I see more of the latter. I see more experimenting. [00:15:59] Vince Menzione: You mentioned ServiceNow. Any other great examples of that? Organizations that really embraced it? [00:16:04] Matt Y: Uh, yeah. Well, you know, ServiceNow is part of this business applications category, as we call it, in marketplace. [00:16:09] Matt Y: That outside of AI, I think is the fastest growing category in marketplace, which is wild when you think about it. ’cause we’ve historically been an infrastructure partner marketplace with security and data and analytics and, you know, security with channel partners, et cetera. But Salesforce, ServiceNow, Workday, Adobe, you know, I could go on. [00:16:23] Matt Y: They, they are actually. You know, our fastest growing category and yeah, ServiceNow, obviously reinventing itself for ai, Salesforce, but Workday, you know, the workday’s done some, who knows if it’s gonna work, but they, they’re experimenting with essentially like a Databricks, uh, credit style model for like, units of work, uh, which I think is fascinating. [00:16:41] Matt Y: Like everyone’s talking about value-based, outcome-based pricing and meter. And, and you have companies that are ERP companies, you know, like traditional business applications, experimenting with effectively like a metered pay as you go, value based credit model. Again, like who knows if it’s gonna work. [00:16:54] Matt Y: But I think that’s really amazing to see and we need more ISVs experimenting. I, I was talking about trend ai and I know they’re, they’re, they’re one of the sponsors yesterday. You know, many of you know them as Trend Micro back in the day. They’ve successfully reinvented themselves. They built that companion app. [00:17:10] Matt Y: Um, you know, that I think we’re seeing. Just a ton of experimentation in the market across categories. Uh, I could go on and on about partners. Um, yeah, there, I I wouldn’t pick a winner right now. Yeah. [00:17:24] Vince Menzione: You, you, we’ve talked about ai. We’ve talked, talk more about the buying journey and how that’s changing, because again, it feels, it feels like that’s also [00:17:33] Matt Y: Yeah. [00:17:33] Matt Y: So, you know, one of, one of the core, uh, strategic objectives, or we’ll say like the philosophy marketplace is that. Um, financial incentives are important, you know, EDP or PPA drawdown, uh, credits. Like we need to act as an efficient and effective vehicle for allowing buyers to exercise their discounts for, and, and sort of partners to exercise their credits, et cetera. [00:17:55] Matt Y: That, that’s actually important. But what, what a lot of people over rotate on that, and we’re really, one of the things we say a lot inside at Amazon or at AWS marketplace is we want to continue to boost the intrinsic value of marketplace beyond the financial incentives. And well over a quarter of all private offers, private pricing, private, uh, custom terms, et cetera. [00:18:14] Matt Y: Um, begin with a self-service or PLG motion. And partners who don’t have a PLG or self-service motion are literally leaving money on the table. Like if you look at like a Databricks for example, and they did a good job integrating buy with a WS within their SaaS application. They have free trials, they have really strong pego and, and, uh, and PLG motion. [00:18:33] Matt Y: They’re making, I can’t share their numbers obviously, but they’re making a ton of money. On purely self-service motions. And importantly, they’re acquiring new business, new logos that they nurture, you know, really like not just leads but closed opportunities, right? That they lead, they’re growing, uh, at a reasonable conversion rate or or success rate into the next big logos. [00:18:50] Matt Y: And these are over multi-year horizons. They’re patient, you know, they bring in these new logos with PLG, and they’re also bringing banking, a lot of large enterprises. Through self-service. I, I was with data Mask. There’s this great little startup from New Zealand. They’re a New Zealand based company. Um, super nice guy. [00:19:06] Matt Y: And, and, uh, they, they got huge logos. I think they got, what was it? A DP and some huge American logos. Okay. And this like logo in, I think it was Chile, or no, it was Peru. They’ve never been to Peru. They don’t have sales in Peru. Um, and they. Buyers were discovering them self-service and they, they, I think they got something like 13 logos entirely through a self-service motion. [00:19:26] Matt Y: One password will tell you the same thing. I was just with them in Toronto and companies big and small startups and the largest are getting enterprise wins in addition to net new small logos through that PLG. Buyer motion. And that’s because you have a whole generation of CFOs, CTOs, CROs, whatever. The C is [00:19:43] Vince Menzione: millennial [00:19:43] Matt Y: who grew up on their phones. [00:19:45] Vince Menzione: Yeah. [00:19:45] Matt Y: And, and it sounds like, you know, hyperbole, but it’s true. They, they want immediate apps, immediate access. And that actually, you’re like, oh, that never translates to business applications. Turns out it does. It does. And they might not be buying on their phone, but what they are doing is researching and we see the numbers, the amount of customers who are doing their research, and then eventually landing on the page from chat, GPT. [00:20:06] Matt Y: From major financial, like Fortune 500 companies is extremely high. Yeah. Uh, you have procurement team, sourcing team, uh, developers who are starting the research increasingly, like in clawed in chat, GPT, and then, you know, building a proposal and then handing it to their enterprise procurement team. Yeah. [00:20:22] Matt Y: Which is still largely unchanged. So buyer behavior is on the front end, on the research side is really changing. So the [00:20:29] Vince Menzione: discovery is happening through PLG. [00:20:32] Matt Y: Yeah. [00:20:32] Vince Menzione: And then the backend work on private offers and things like that sometimes still happens the old way. [00:20:36] Matt Y: Yeah. Well, and so, you know, it’s [00:20:37] Vince Menzione: fax machine, [00:20:38] Matt Y: some people Yeah, sure. [00:20:39] Matt Y: They’re bringing the deal directly to Marketplace last minute. But even if that deal goes direct, sometimes they’re still beginning their research journey and increasingly using Marketplace as a research vehicle, which is why we launched Agent Mode, um, to help you sort of help you and agents do research. [00:20:51] Matt Y: But that I think if, if I have one piece of device for any partner consulting or ISV is. Don’t leave those leads and that money on the table by not having a PLG self-service strategy like you’re fooling yourself. Uh, and it’s, it’s a huge, it’s a huge, huge business for us. The, the majority of all customers by far on marketplace don’t even have a PPA, uh, and a huge percentage of even those with PPA spend beyond the p. [00:21:17] Matt Y: And so if you’re just think if you’re just using marketplaces as like BPA retirement, you are literally losing money. [00:21:22] Vince Menzione: Yeah. [00:21:22] Matt Y: Yeah. [00:21:23] Vince Menzione: We have a session with Vinod. We’re gonna talk a little bit about that right after. Great. So good. Um, so I, yeah, I think, um. We talked about, we talked about agents, we’ve talked about the millennial buyer, the change in buying behavior. [00:21:40] Vince Menzione: What other, what other areas of aspect I, I, I, I do wanna think about like opening it up though for a second. I think that maybe with maybe nine minutes left. Sure. I just want to get a read from the people in the room. People have questions for Matt that we weren’t able to ask them. Yeah, I think, I think we probably have a few of those. [00:21:57] Vince Menzione: I think that would probably be great. [00:21:58] Matt Y: I can sense the hardball coming. [00:22:00] Vince Menzione: You’ve known each other [00:22:00] Matt Y: a long time. [00:22:01] Vince Menzione: Yeah. No, no. Hardball. We have a mic back here. Okay. I’ll just, we’ll, we’ll, we’ll get you a mic as we are recording. So good. Thank you. [00:22:11] Audience Guest: Uh, Boris Geller with a, a Click PLG is near and dear to my heart. [00:22:17] Audience Guest: We’ve been doing a lot of business in marketplace and I’m still struggling to sell my vision internally on, on, uh, on PLG. Uh, I think. Ag Agent AI is gonna be one of the drivers, and we are already on, uh, agent Marketplace, but I would appreciate guidance on, uh, best practices. How do we kind of, uh, operationalize it? [00:22:41] Audience Guest: It’s, it’s on us, not on you. [00:22:43] Matt Y: Well, no, I think it’s on both of us. You know, we, uh. One thing that we’re trying to do is give you more data to, to sell to your internal stakeholders in your executive suite. The value of co-sell with AWS all up, like finally with what we launched at, uh, the summit yesterday, you now get an opportunity score. [00:23:02] Matt Y: You, you get a number. People have been asking for this for years, so, so you can say when we do this and we, when we give AWS this information. The score goes up and we have a higher propensity to be cos sold by humans or agents before you had to kind of, it was like this mystery you had to guess. And similarly with marketplace, um, we, we have new dashboards that you can use to sort of, you used to have to sit down with us and go through spreadsheets to trace sort of lead to trace the funnel to sort of a close opportunity. [00:23:28] Matt Y: And we’re gonna continue to launch more there. But you now have more data that you can show. You can be like, listen, these are our inbound leads, this how’s converting, and now we have PRM, the partner revenue measurement where we can say like, this is what it’s translating into in terms of. AWS service revenue driven by our product. [00:23:41] Matt Y: And so that being able to tie from that inbound lead from your demand gen campaign through to a converted opportunity to what you actually drive from an AWS impact perspective, so you can, and then what your opportunity score is that data you can use to sell. Not only internally, but to us as well. Yeah, to a skeptical sales team or whatever who’s not maybe, you know, hype on partners in the, in the US West. [00:24:03] Matt Y: You can be like, listen, I don’t care what you think about my business. This is what I’m gonna drive for you with your quarter retirement from an AWS perspective, and this is how the shape of your customer accounts are gonna change. And this is why you should pay attention to my opportunities. ’cause my opportunity score is, is crazy high and I’m giving you insights into business that AWS would not otherwise have. [00:24:19] Vince Menzione: That’s your brand story we’re talking about. [00:24:21] Matt Y: Yeah. [00:24:22] Vince Menzione: Building your story up with within [00:24:25] Matt Y: So it’s, it’s about the data, I guess. And, and you should, you know, you should all actually be [00:24:28] Vince Menzione: Yeah. [00:24:29] Matt Y: Asking me for more data, so, you know, and tell me like, what do you need to sell to your internal stakeholders? ’cause if I can draw a clear line. [00:24:35] Matt Y: From your demand chain campaign that lands on a marketplace, which I know is a conversion machine, it has way better than industry levels of, of conversion rates. And then you can show, hey, if we have a PLG strategy and we land those leads on marketplace, we will convert them with high efficiency, low cost of sales and, and, and have sort of a bifurcated where we can close some through self service, some through express private offers and some through private offers, depending on deal size. [00:24:57] Matt Y: Like you tell A CFO that, and they’re my number one customer now and they love it ’cause they see cost of sales going down, cost of operations going down and business going up. Um, so I think we have more data than we used to use that data. And let me know what other data do you need to make that pitch and make that pitch to the CFO go around the head of sales, all those other people. [00:25:15] Matt Y: Honestly, the CFO is where we get the best leverage. [00:25:18] Vince Menzione: Awesome. Great question. [00:25:23] Matt Y: Gonna bring your mic. [00:25:23] Vince Menzione: We’re, we’re gonna get your mic here. There you go. Oh, [00:25:25] Audience Guest: thank you. So my name’s Jody Cheval and I’m a consultant now, but I was at Workday during when they adopted AWS and it, a sales organization needs propensity to buy data. [00:25:34] Audience Guest: To really drive the sales team to realize the opportunity kind of makes them visualize it. We didn’t struggle, but it was challenging to get that data because at that time we’re getting spreadsheets. So does AWS have a vision of making that API based data that our client, my clients, can get at and bring into a tool to start building account hypothesis based on that data? [00:25:57] Audience Guest: ’cause it really is important to an enterprise sales guy to have the sense that OAWS can help me close this deal. [00:26:03] Matt Y: Yeah. I mean. Part of that. So we, we launched, we’ve been launching part of that in stages and we’re not done. There’s, there’s more coming. Um, part of that is embedded really within the new, uh, partner agent workflows. [00:26:13] Matt Y: We are giving sort of more, uh, information back to you, not just about like what funding programs you’re eligible for, but like, you know, and when, when we will co-sell this deal with you, which is effectively a signal like we, we see this as a high value opportunity, that you have a likelihood of winning internally. [00:26:28] Matt Y: We, we have this solution matching engine that we’re using and we announced. That, that that ties you the partner to a customer specific opportunity that you have a high propensity or the partner has a high propensity to assist with and ultimately win. And now we’ve tied that to our express private offers, which we announced this week. [00:26:44] Matt Y: So it’s an indirect answer to what you’re asking, but a rep can essentially say. Send a private priced offer to the customer on behalf of the partner without having to ring up the partner because they have a high propensity to win this deal with the customer. So we’re progressively launching features like that. [00:26:59] Matt Y: In addition to the propensity to buy data that we do now share. It used to be kind of, again, manual magic depending on who you knew we could share. Now we do share that programmatically, and there’s more to come specifically in that space. Uh, I’d say watch that space. In the next few months, there’s gonna be more data coming away, but we do have the APIs, we have the agent. [00:27:16] Matt Y: We have things like express private office solution matching, and we have been sort of in that space progressively launching features over the last six to 12 months. And, and you should expect to see some more there soon, not just from us or from our partners. [00:27:27] Vince Menzione: Nice. Any announcement dates? [00:27:30] Matt Y: I can’t commit to a date or else my engineers will get mad at me. [00:27:33] Vince Menzione: It looks like we Another question number. Is the mic still back there? Okay. There’s a gentleman over here [00:27:40] Audience Guest: first Go leaves. Um, it’s awesome. I’m right next to. I was right next. [00:27:46] Vince Menzione: We’ve got a lot of great plants here, so, [00:27:49] Audience Guest: um, so this may be a little bit myopic or, or a challenge that we run into, but I love a lot of the innovation that’s looking forward and all the future things that we’re doing. [00:28:00] Audience Guest: One of the things that we’re struggling with is a little bit of almost like tech or structural debt. How do you think about bringing flexibility to the core pieces that underpin all of the innovation, which is. We are self-hosted. So one of our listings is an a MI. You can’t amend an a MI, you have to cancel and start over. [00:28:18] Audience Guest: So a lot of the building blocks, when you think about PLG, if somebody wants to add to that in an a MI listing, it’s, it’s sort of broken. So how are you thinking about taking all of the, the rapidly changing buyer behavior and then looking back at the structural foundation that underpins all of those things, like offers and, and amendments and changes and all of that? [00:28:39] Matt Y: Yeah. I, I promise I didn’t seed that question, but that, that’s a great one. Um, so not to get too in the weeds, but fundamentally, marketplace was built up, um, a bit like AWS like a set, a series of services somewhat independently. And each product type was effectively its own service, SaaS, server images, ais. [00:28:59] Matt Y: Um, what we’ve done recently is now we, we have, we got rid of product types basically on the backend. You, you don’t see it, but what that means, for example, like another thing AAMIs don’t support today, future data agreements. Um, or concurrent agreements, uh, they will all be supported by amis before the end of the year. [00:29:14] Matt Y: ’cause what we’re doing, this fundamental thing that you won’t even see called product offer decoupling. Uh, and it’s a fundamental piece of things that we need to unwind. ’cause we built up, we were moving very quickly over the years. We had a distributed engineering model and we built each product type independently. [00:29:28] Matt Y: And so yeah, if you’re a seller and you’re selling containers, agents, SaaS, amies, um, we’re breaking down the silos between those so that each of them will get the same benefits. And, and by the way, we’re taking the same approach to international. Hopefully you’ve noticed now that. It’s not like a feature launches in the US only and then takes five years to launch in either public sector or another country. [00:29:48] Matt Y: We, we’ve taken a global approach to feature launch and increasingly a product type neutral approach to feature launches. Uh, that’ll be largely resolved before the year’s out. We’re working on it right now. So again, it’s, it should be transparent to you, like you shouldn’t actually see any difference in the, in the experience. [00:30:05] Matt Y: Except that all of those features will be available. So, so that is, uh, actively under work. And that’s actually something if you’d like to try, um, you’re, you’re welcome to. So, yeah, [00:30:17] Vince Menzione: we have time for maybe one more question and we we’re actually gonna have you up here with a couple partners. [00:30:24] Matt Y: Sounds [00:30:24] Vince Menzione: good. Kind of fun. [00:30:32] Audience Guest: Hey, Matt, uh, met Natasha from Dondo. Uh, quick. So great announcements. And you know, you talked about the million, multi-billion dollar, uh, club, and, uh, that’s all great. Uh, in terms of the. Propensity data. I think that’s coming at the center of a lot of things, right? You know, for enterprises, oh, there’s an investment and you tap into that investment. [00:30:53] Audience Guest: But also there’s the other side of the procurement where a lot of customers, sometimes we work with, they’re like, they still wanna go direct for whatever reason, right? So I think there’s an education piece there, but also trying to understand like how we can work together to, you know, get some of that side of the things sorted out as well. [00:31:11] Audience Guest: You know? ’cause a lot of times it’s not about. Just, you know, retiring the, uh, the, the spend comets, but also like, Hey, I’m used, I’m already used that for something else. So maybe that’s not an, uh, something that applies here. And in also in tying that the PLG motion, uh, you know, for the customers you said, you talked about, you know, if there is. [00:31:34] Audience Guest: Leads on the TA table, like where the, it’s not the enterprise, but you know, the others. Um, I feel like it’s more to do, changing the business model at some times. Like with the enterprises, you have the revenue stream coming through, say large deals, right? And all of a sudden you tap into this, you know, PayGo. [00:31:51] Audience Guest: Where it flips the whole equation with, you know, the financing and the, and the, and the revenue measurement. So I think there’s two aspects of how do you kind of cons reconcile those things in terms of, you know, the revenue measurements going forward. [00:32:05] Matt Y: Yeah. So, so two things real quick on the procurement. [00:32:07] Matt Y: Um, yeah, like, yeah, I sort of alluded to this earlier, but, uh. Procurement is a bit late to the AI ag agentic transformation. They’re trying, and there’s a lot of great new incumbents in this space. And the big leaders like, you know, Coupa and Ariba and Oracle are, are, are evolving their products, albeit a bit slowly. [00:32:26] Matt Y: Um, but the, I think, uh, it’s still the long pole in the tent. You know this. And so like, there are two reasons why deals tend to go direct, because it kind of hits a wall of. Legal, uh, you know, procurement, governance, like all that kind of after the selection’s been made, et cetera, or, or they’re, you know, we can’t change. [00:32:44] Matt Y: People are gonna optimize for, for finance, you know, they’re, they’re going to, if they’re getting big discounts. I mean, that is life. I always say it’s like sellers at the most agented company are still gonna chase quota no matter how, you know, crazy. Uh, your, your company is, and it’s the same with, um, with the chief, uh, financial officer and chief procurement officer. [00:33:01] Matt Y: They are going to, they’re literally. Paid to find discounts. And so we’re not, we’re not gonna get rid of financial engineering. That’s a, that’s a thing. What we can do is reduce the friction for procurement. So we launched, for example, like mandatory purchase orders. That was a big thing. We, we have buyer notifications, now we’re making other procure to pay enhancements. [00:33:17] Matt Y: I mean, procurement systems still use like CXML. It’s like, that was, that was cool when I worked for the ap. And like I, I have teenagers that are old, like older than, so they, I, I think, um. Procurement needs to evolve and we’re gonna help it evolve. We’re gonna push it forward and, and we need to make it more seamless for procurement teams so that we remove those objections. [00:33:38] Matt Y: Uh, I can’t remove the financial engineering objection, like, you know, that’s just life. Um, but I can make it irresponsible not to use marketplace ’cause it’s so easy to use. And, uh, that, that’s kind of the approach we’re taking on, on the front end. Uh, you, you know, I think you, you, again, I didn’t see this question. [00:33:52] Matt Y: You, you stepped into a trap. Un unwittingly, um, PLG is not just is for enterprise. And, and PLG doesn’t necessarily mean pego or self-service. Uh, doesn’t necessarily like, uh, most of our self-service efforts are actually focused on private offers. And not necessarily for pego. Uh, when, when I say self-service and, and PLG, uh, it, it can mean all kinds of things like it. [00:34:14] Matt Y: We have requested private offer, requested demo call to actions, buttons that you can put on your listing. For example, you don’t necessarily need a free trial or a metered pay as you go listing to take advantage of those inbound self-service leads. So, and those inbound self-service leads are often massive enterprise deals, like I mentioned specifically, uh, the data mask. [00:34:31] Matt Y: Those giant enterprise deals that they launched came from an enterprise like Fortune 1000 Enterprise in the US that organically discovered their solution on the marketplace using our AI search. And that was a massive enterprise. And so I, I think yes, there is the long tail, you wanna capture a new logo acquisition, but you should think of your product like growth in your self-service strategy as a way to, um, acquire all kinds of leads, including large enterprise. [00:34:54] Matt Y: And so when I say leave money on the table, I’m not just talking about things that are gonna mature over two years or tiny little deals. These could be massive deals. Uh, and, and you’ll accelerate those deals by accelerating their discovery and, and research so that I think that, so, and my advice is don’t, you don’t have to go all in if you don’t have, if you don’t have metering, if you don’t have PayGo, that’s cool. [00:35:13] Matt Y: Start with something simple. Start with a public listing, with a request to private offer like that. That is a, a huge step. That doesn’t take much, and, and it kind of blows my mind still that a lot of companies aren’t doing that yet. [00:35:25] Vince Menzione: Great answer. Well, it’s now time we’re gonna bring, we’re gonna bring, it’s time. [00:35:29] Vince Menzione: We, we’ve got some great partners coming up here, Nvidia Elastic, Accenture gonna all join us for a conversation. Great. And I’m glad that you’re gonna stay with us. And let’s, let’s, well, let’s thank Matt, by the way, for that session. [00:35:41] Matt Y: Thanks. [00:35:42] Vince Menzione: And [00:35:42] Matt Y: thanks for listening to the Ultimate [00:35:44] Vince Menzione: Partner Podcast. If today’s conversation resonated, share it with a partner leader in your network. [00:35:51] Vince Menzione: Subscribe where you listen. And head over to the ultimate partner.com. For show notes related content and the resources for this episode. And if you haven’t already, now’s the time to register for the Ultimate Partner Live Event in Reston, Virginia, October 26th through October 28th. Until next time, keep showing up in the rooms that matter because being in the room changes everything.
AI isn't just changing how we build software — it's changing how attackers operate. In this episode of the z/Action Podcast, we sit down with Trend Micro to unpack the accelerating security risks of the AI era and what a modern defense strategy looks like across IBM Z and LinuxONE, hybrid cloud, containers, and modern application platforms.The central challenge: agentic AI attacks demand agentic AI defenses. We explore why reactive, siloed tooling falls short — and how organizations can actually reduce tool sprawl and alert noise while gaining more control.We walk through Deep Security and the Zero=Day Initiative as the foundation, then build upward: security for OpenShift Container Platform, and a path toward full-stack visibility that spans every workload touching Z environments. The goal isn't just detection — it's the ability to correlate threats, predict attack paths, and act with precision before damage is done. This conversation maps out a practical approach to addressing this accelerating threat with speed and automation.Stay ConnectedBe part of the conversation! Join the ISV Ecosystem User Group to explore the latest blogs, events, videos, and more from IBM Z partners and innovators.And don't forget to subscribe to z/Action!Each month, we spotlight some of the world's most innovative companies and how they're driving success with IBM Z.
As B2B technology companies scale, size often comes at the cost of agility. Processes calcify, buying cycles stretch, and marketing teams end up running up and down the stairs faster instead of building the elevator.In this episode of the FINITE Podcast, Jodi Norris sits down with Carol Carpenter, CMO at Cohesity, to unpack what it really takes to market at enterprise scale without slowing down. Fresh from Cohesity's merger with Veritas, Carol shares the realities of integrating two large marketing organisations, building trust across cultures, and holding on to startup-style velocity inside a 5,800‑person business.She explains how her team uses AI to redesign workflows – from translation and brand governance tools, to AI‑powered SDR outreach that doubles lead‑to‑meeting conversion. Along the way, she draws a firm line between what can be automated and what cannot: creativity, taste and strategic judgement.Carol has been in technology marketing for most of her career, starting as a product manager at Apple. She enjoys scaling and transforming companies and has done that in leadership roles at VMware, Google, Apple, Trend Micro and now as CMO of Cohesity. Carol gives back through mentorship programs such as the HBS Women Entrepreneurship program and Monte Jade, an AAPI professional organisation.Inside you'll find…How to merge marketing cultures without losing speed, trust or clarityWhere AI genuinely shortens a six‑month enterprise buying journey – and where humans must stay in the loopA practical framework for lifting teams out of execution and into more strategic, high‑leverage work
This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices
This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems. The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model. The research and executive brief can be found here: Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud Learn more about your ad choices. Visit megaphone.fm/adchoices
PODCAST EPISODE | Redefining CyberSecurity With Sean Martin — On Location at InfoSecurity Europe 2026 On Location With Sean Martin And Marco Ciappelli Adversaries are stealing encrypted data today that they cannot read yet, and storing it until a quantum computer can. Sean Martin sat down with Forescout's Rik Ferguson to talk about “harvest now, decrypt later,” why Q-Day is closer than the comfortable timelines suggest, and what the decisions you make this year have to do with secrets you thought were safe forever.
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Intercept and control AI agent activity with Viberails by LimaCharlie: viberails.ioAPT41, a China-linked threat group is deploying a previously undetected backdoor targeting Linux based cloud workflows.Fancy bear, also known as APT28 or Forest Blizzard, is a Russian cyber espionage group believed to operate on behalf of the country's military intelligence services, the GRU. Trend Micro research here.Anthropic's Model Control Protocol widely used in agentic AI systems to connect AI agents with data sources, contains a design flaw that would enable large-scale supply chain attacks. Report here.There's a critical vulnerability in nginx-UI, a web-based management interface for Nginx servers, which is being actively exploited and could allow attackers to take full control affected systems.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
Trend Micro anunció el cambio de nombre de su unidad de ciberseguridad empresarial a TrendAI, una evolución de identidad que busca alinear su estructura con la gobernanza y protección de los sistemas de inteligencia artificial.
Jay and Dave for Breakfast - Triple M Mackay & The Whitsundays
Should a mobile coverage map show you what MIGHT work, or what WILL work - Telstra, Vodafone at odds while the ACMA makes new rules https://eftm.com/2026/03/the-battle-for-mobile-coverage-ramps-up-as-telstra-and-tpg-go-head-to-head-272896 AI making scammers life a dream, Trend Micro finds AI Tools being used to trick Aussies into falling for sob stories https://eftm.com/2026/03/ai-tools-making-scamming-easier-using-emotional-triggers-to-deceive-272890 Like to work with multiple screens? Take a second screen anywhere with the espresso 15 Lite https://eftm.com/2026/03/espresso-15-lite-review-monitor-portable-display-work-work-from-home-remote-work-273061See omnystudio.com/listener for privacy information.
iPhone and iPad cleared for classified NATO work U.S. Education and Healthcare targeted with Dohdoor backdoor Trend Micro warns of critical Apex One code execution flaws Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-nato-adopts-apple-education-and-healthcare-backdoor-apex-one-flaws/ Thanks to today's episode sponsor, Adaptive Security This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Researchers at Trend Micro have uncovered continued activity from China-aligned threat actors leveraging a cross-platform JavaScript-based command-and-control framework known as "PeckBirdy".Silent Push has identified an extensive phishing campaign targeting over 100 organizations, attributed to the threat actor group ShinyHunters.A malicious Visual Studio Code extension impersonating an AI coding assistant for Moltbot has been discovered distributing malware via the official VS Code Extension Marketplace.Dragos has attributed the December 2025 cyberattack on the Polish power grid to the Russian state-sponsored group known as ELECTRUM, with medium confidence.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
En este episodio de 'El Balance de la Economía', Lorena Ruiz entrevista a José de la Cruz, director técnico de Trend Micro para hablar sobre la ciberseguridad y el robo de datos
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Security researchers at Check Point have uncovered a previously unknown Linux malware framework named VoidLink, which stands out for its complexity and modular design.Researchers at Trend Micro have identified a new phishing campaign that combines legitimate services and open-source tools to distribute AsyncRAT, a commodity-remote access trojan.New research into Predator spyware reveals a deeper level of sophistication and operational intelligence than previously understood.The widespread adoption of AI agents in enterprise environments is creating a new class of identity and access control risks as highlighted in a new report from The Hacker News.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
Join us for a powerful episode of Bold Journeys as we explore the real‑world mountaineering experiences of Louise McEvoy, a high-altitude mountaineer who has summited 6 of the Seven Summits ⛰️ including Mt. Everest. Louise breaks down what it takes to tackle the world's tallest mountains and how the grit she developed on the slopes fuels her success in work, leadership, and life. By day, Louise is a high‑impact channel executive who helped shape Trend Micro's award‑winning partner ecosystem and now leads global channel sales at Keyfactor. By night (and often at 20,000+ feet), she's pushing her limits on some of the harshest terrain on earth. In this conversation, Louise shares: - What climbing Everest and Denali taught her about resilience - How mountaineers manage fear, fatigue, and mental overload - The training required for high‑altitude expeditions - How to handle disappointment, setbacks, and unexpected danger - Why pursuing passion outside of work builds stronger leaders - The story behind She Summits Fourteeners, her initiative empowering women through mountaineering This episode isn't just about climbing mountains — it's about building the mental toughness to face life's biggest challenges and emerging stronger on the other side.
The NSA reshuffles its cybersecurity leadership. A new report unmasks ICE's latest surveillance system. CISA marks a milestone by retiring ten Emergency Directives. Trend Micro patches a critical vulnerability. Grok dials back the nudes, a bit. Cambodia extradites a cybercrime kingpin to China. Ghost Tap malware intercepts payment card data. Researchers disrupt a highly sophisticated VMware ESXi hypervisor exploit. European law enforcement arrest dozens of suspects linked to the international cybercriminal group Black Axe. Our guest is Sonali Shah, CEO of Cobalt, who says 2026 is the year AI stops being a concept and becomes the central battleground of cybersecurity. After firing the experts, DOGE hangs a help wanted sign. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices, we are joined by Sonali Shah, CEO of Cobalt, talking about 2026 is the year AI stops being a concept and becomes the central battleground of cybersecurity. Tune into the full conversation here. Selected Reading NSA cyber directorate gets new acting leadership (The Record) Inside ICE's Tool to Monitor Phones in Entire Neighborhoods (404 Media) CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity (CISA.gov) Trend Micro warns of critical Apex Central RCE vulnerability (Bleeping Computer) X pulls Grok images after UK ban threat over undress tool (The Register) Alleged cyber scam kingpin arrested, extradited to China (The Record) Chinese Hackers Use NFC-Enabled Android Malware to Steal Payment Information (GB Hackers) The Great VM Escape: ESXi Exploitation in the Wild (Huntress) Europol Leads Global Crackdown on Black Axe Cybercrime Gang, 34 Arrest (Infosecurity Magazine) US DOGE Service is hiring following mass workforce losses across the government (Gov Exec) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Black Friday is upon us again, but what should we be aware of when shopping online to help us avoid scam activity?See omnystudio.com/listener for privacy information.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
New DShield Support Slack Workspace Due to an error on Salesforce s side, we had to create a new Slack Workspace for DShield support. https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376 Attackers Exploiting Recently Patched Cisco SNMP Flaw (CVE-2025-20352) Trend Micro published details explaining how attackers took advantage of a recently patched Cisco SNMP Vulnerability https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte Framework BIOS Backdoor The mm command impleneted in Framework BIOS shells can be used to compromise a device pre-boot. https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/ SANS.edu Research: Mark Stephens, Validating the Effectiveness of MITRE Engage and Active Defense https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/
From phishing to prompt injecting to PHI leaks via consumer AI models, AI tools are reshaping healthcare cyber risks. Learn how frameworks like OWASP can help CISOs and IT teams bolster their defenses to protect organizations' AI, data and cloud assets.
En août 2023, sur le forum clandestin BreachForums, un compte pseudonyme nommé AMLO mettait en ligne un outil baptisé Evil-GPT — présenté comme « un assistant sans filtre » capable de contourner les gardes-fous habituels des grands modèles de langage. La promesse : générer en quelques clics des scripts malveillants, des campagnes de phishing ou des modules de collecte de données, sans besoin de compétences techniques. Le prix d'entrée a fait le reste : une dizaine de dollars pour l'accès complet.Très vite, la communauté underground s'est emparée du produit. Sur Telegram et d'autres canaux, des utilisateurs partagent retours d'expérience, codes générés et méthodes d'exploitation — certains attribuent à ces outils des attaques ciblées ou des fraudes (citations de cas comme Mondial Relay ou Ulyss), témoignant d'une banalisation des pratiques. L'offre s'adresse surtout aux néophytes : interface simple, scripts prêts à l'emploi, export des données vers des serveurs Discord, fonctionnalités clé en main.Mais derrière le battage commercial, la réalité technique est plus prosaïque. Une étude de Trend Micro (2024) a montré qu'Evil-GPT et ses clones ne sont pas des IA indépendantes : ils s'appuient massivement sur l'API d'OpenAI, détournée via des clés volées et des prompts jailbreakés. Les analyses de spécialistes et les témoignages sur les forums indiquent que les productions restent souvent basiques — e-mails de phishing génériques, scripts simples — et pas toujours adaptées à des attaques sophistiquées. Pendant ce temps, un écosystème marchand foisonne : WormGPT, FraudGPT, WolfGPT et autres proposent des offres variées, de quelques dizaines à plusieurs milliers de dollars. Le modèle économique mise sur la diffusion massive et l'exclusivité temporaire plutôt que sur des innovations techniques majeures.Conséquence : la barrière d'entrée de la cybercriminalité s'effondre. Les équipes de cybersécurité signalent une hausse des campagnes automatisées et recommandent de traiter toute attaque comme potentiellement générée par un chatbot. Le chercheur Alex Reibman parle d'un essor des « agentic malware » — outils capables d'orchestrer des étapes d'attaque — mais rappelle aussi que leurs limites tiennent souvent aux services d'API sous-jacents. Au final, l'innovation la plus dangereuse n'est peut-être pas l'outil lui-même, mais sa démocratisation. Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.CISA has added CVE-2025-54948, a critical vulnerability in Trend Micro Apex One, to its Known Exploited Vulnerabilities (KEV) catalog, signaling that the flaw has been actively exploited in the wild.PyPI has introduced new security measures to detect and respond to expired domains tied to user accounts, aiming to shut down a known supply chain attack vector: domain resurrection.A recently discovered post-exploitation tool named RingReaper is gaining attention for its sophisticated evasion strategy: abusing the Linux kernel's io_uring interface to operate undetected by standard endpoint detection and response (EDR) systems.A cyberattack on the Netherlands' Openbaar Ministerie (OM), the Public Prosecution Service, has unexpectedly disrupted speed enforcement across the country.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
Podcast: Nexus: A Claroty Podcast (LS 32 · TOP 5% what is this?)Episode: Salvatore Gariuolo on Safe EV ChargingPub date: 2025-08-17Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationSalvatore Gariuolo, a senior threat researcher at Trend Micro, joins the Nexus Podcast to discuss safe EV charging and in particular, the ISO 15118 standard meant to create a trusted environment for electric vehicle charging. Gariuolo contends that while ISO 15118 offers substantial improvements that reduce pressure on the grid, and also introduces a handful of cybersecurity enhancements, it is not sufficient to fully secure the EV charging ecosystem.Listen and subscribe to the Nexus PodcastThe podcast and artwork embedded on this page are from Claroty, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Salvatore Gariuolo, a senior threat researcher at Trend Micro, joins the Nexus Podcast to discuss safe EV charging and in particular, the ISO 15118 standard meant to create a trusted environment for electric vehicle charging. Gariuolo contends that while ISO 15118 offers substantial improvements that reduce pressure on the grid, and also introduces a handful of cybersecurity enhancements, it is not sufficient to fully secure the EV charging ecosystem.Listen and subscribe to the Nexus Podcast
In this episode of OnBase, host Chris Moody talks with Myla Pilao about how brands can remain relevant and resilient in the age of AI. Myla shares her unconventional path into the ICT and cybersecurity industry, and why translating technical narratives into relatable, actionable stories is key to influencing behavior.The conversation explores AI's role in shifting from transactional to relationship-driven customer experiences, the importance of high-quality data, and strategies for hyper-personalization without crossing privacy boundaries. Myla explains how her team balances automation with creativity, integrates AI responsibly, and aligns global teams around AI-driven processes.Key TakeawaysAI as a Relationship Builder: Moving beyond generic automation to personalized, context-aware customer interactions.Data Quality First: “Garbage in, garbage out” still applies—AI's success depends on the integrity of your input data.Hyper-Personalization in Action: Tailoring responses and recommendations to specific, high-priority customer pain points.Balancing AI with Human Creativity: Establishing multi-layer editorial reviews to preserve authenticity and accuracy.Adoption Through Proof of Concept: Testing AI on low-risk content before applying it to mission-critical materials.Three AI-Era Imperatives: Address bias with transparency, embed privacy and compliance, and iterate relentlessly.Quotes“Garbage in, garbage out still holds true. The quality of your data will make or break your AI outcomes.”“The foundation can be AI-driven, but the final touch has to be human.”Best Moments 01:09 – Myla shares her unconventional journey into ICT and cybersecurity.(03:30) – How AI is changing the nature of customer relationships.(05:29) – Data quality as the biggest challenge in AI adoption.(07:39) – Using hyper-personalization to address specific threats like ransomware.(09:18) – Balancing efficiency gains with authenticity in content creation.(12:07) – Aligning global teams through cautious, proof-of-concept AI rollouts.(15:21) – Myla's three operational imperatives for mid-stage AI adoption.(17:57) – Aligning teams around bold visions and measurable results.(20:39) – The challenge of cutting through “too much information” in B2B marketing.Resource recommendationsPragmatic Institute - For product and market strategies.Duarte - For storytelling and visual communication techniques for complex topics.About the GuestMyla V. Pilao is a seasoned cybersecurity marketing leader with extensive experience at the intersection of technology, marketing, and public relations. As Director of Technology Marketing at Trend Micro, she drives thought leadership initiatives that translate complex security concepts into actionable insights for audiences from C-suite executives to everyday tech users.With a career spanning leadership roles in technical support, customer relationship management, and marketing, Myla has built a strong record of guiding teams through the evolving digital landscape with a focus on trust, privacy, and innovation. Prior to Trend Micro, she held customer engagement and support roles in the gaming technology and telecommunications industries.She holds a Master's Degree from National University and a Bachelor's Degree from the University of Santo Tomas.Connect with Myla.
Federal agencies told to patch a new Exchange flaw, millions of sites are vulnerable to HTTP desync attacks, Trend Micro patches a zero-day, and the Salesforce data breaches continue. Show notes Risky Bulletin: CISA tells federal agencies to mitigate on-prem-to-cloud Exchange attack
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Do Sextortion Scams Still Work in 2025? Jan looked at recent sextortion emails to check if any of the crypto addresses in these emails received deposits. Sadly, some did, so these scams still work. https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178 Akira Ransomware Group s use of Drivers Guidepoint Security observed the Akira ransomware group using specific legitimate drivers for privilege escalation https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/ Adobe Patches Critical Experience Manager Vulnerability Adobe released emergency patches for a vulnerability in Adobe Experience Manager after a PoC exploit was made public. https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/ https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html Trend Micro Apex One Vulnerability Trend Micro released an emergency patch for an actively exploited pre-authentication remote code execution vulnerability in the Apex One management console. https://success.trendmicro.com/en-US/solution/KA-0020652
Two Chinese nationals are arrested for allegedly exporting sensitive Nvidia AI chips. A critical security flaw has been discovered in Microsoft's new NLWeb protocol. Vulnerabilities in Dell laptop firmware could let attackers bypass Windows logins and install malware. Trend Micro warns of an actively exploited remote code execution flaw in its endpoint security platform. Google confirms a data breach involving one of its Salesforce databases. A lack of MFA leaves a Canadian city on the hook for ransomware recovery costs. Nvidia's CSO denies the need for backdoors or kill switches in the company's GPUs. CISA flags multiple critical vulnerabilities in Tigo Energy's Cloud Connect Advanced (CCA) platform. DHS grants funding cuts off the MS-ISAC. Helicopter parenting officially hits the footwear aisle. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Sarah Powazek from UC Berkeley's Center for Long-Term Cybersecurity (CLTC) discussing her proposed nationwide roadmap to scale cyber defense for community organizations. Black Hat Women on the street Live from Black Hat USA 2025, it's a special “Women on the Street” segment with Halcyon's Cynthia Kaiser, SVP Ransomware Research Center, and CISO Stacey Cameron. Hear what's happening on the ground and what's top of mind in cybersecurity this year. Selected Reading Two Arrested in the US for Illegally Exporting Microchips Used in AI Applications to China (TechNadu) Microsoft's plan to fix the web with AI has already hit an embarrassing security flaw (The Verge) ReVault flaws let hackers bypass Windows login on Dell laptops (Bleeping Computer) Trend Micro warns of Apex One zero-day exploited in attacks (Bleeping Computer) Google says hackers stole its customers' data in a breach of its Salesforce database (TechCrunch) Hamilton taxpayers on the hook for full $18.3M cyberattack repair bill after insurance claim denied (CP24) Nvidia rejects US demand for backdoors in AI chips (The Verge) Critical vulnerabilities reported in Tigo Energy Cloud connect advanced solar management platform (Beyond Machines) New state, local cyber grant rules prohibit spending on MS-ISAC (StateScoop) Skechers skewered for adding secret Apple AirTag compartment to kids' sneakers — have we reached peak obsessive parenting? (NY Post) Audience Survey Complete our annual audience survey before August 31. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
A national survey of over 500 people has revealed two-thirds have been targeted by online scams. Trend Micro director consumer education Ashley Millar spoke to Corin Dann.
//The Wire//2300Z July 22, 2025////ROUTINE////BLUF: VIOLENCE CONTINUES IN SYRIA. MICROSOFT SOFTWARE VULNERABILITY RESULTS IN CYBERATTACKS ON SHAREPOINT USERS. AIRMAN KILLED DUE TO MALFUNCTIONING SERVICE PISTOL, INVESTIGATION UNDERWAY TO DETERMINE CAUSATION.// -----BEGIN TEARLINE------International Events-Middle East: The civil war in Syria continues as before, with various tribes continuing to consolidate gains in their respective areas. The Jolani government remains largely centered in Damascus, and most of the violence continues in Suwayda.Analyst Comment: Most western nations are still pretending that a ceasefire exists and is in effect, when in practice there is no such cessation of hostilities as tribal violence and random executions of civilians are becoming more common on all sides. An American citizen aligned with the Druze was executed a few days ago, drawing concerns of what the international response will be to the escalating violence throughout the region. So far, there hasn't been much interest from the international community to get involved in Syria again, with the exception of Israel and Turkey (who are the biggest external nationstates involved in the conflict so far). However, this is Syria and things happen quickly here.-HomeFront-USA: Microsoft has faced scrutiny for their response to a recent software vulnerability that was recently announced. Over the weekend Microsoft revealed the discovery of a critical vulnerability within the Sharepoint ecosystem, which was discovered after thousands of government and enterprise-level customers experienced significant cyberattacks (mostly from well-known Chinese hacking groups).Analyst Comment: This morning, it became known that this vulnerability was actually already known, and was identified by Trend Micro (a cybersecurity firm) which found the exploit back on July 8th during a hacking competition. Microsoft allegedly issued software fixes to patch the vulnerability, however a few days ago malign actors were observed utilizing the exploit anyway, confirming that Microsoft's efforts to patch this Sharepoint bug were ineffective.Washington D.C. - The Department of the Air Force has launched an investigation into the M18 service pistol following the death of a service member due to safety concerns. The US Air Force will cease all issuance of the M18 platform while the investigation is ongoing, following several other government agencies which have already halted the use of this weapon system due to safety concerns.-----END TEARLINE-----Analyst Comments: For those who are not aware of the implications of the M18 scandal, this scandal has been building for some time and opinions are sharply divided. Sig Sauer has been the center of much controversy surrounding the P320 (the civilian designation of the M18 service pistol) after multiple reports emerged from owners regarding the pistol not being drop-safe. Most modern handguns incorporate some sort of "drop safety" into their design, which prevents the pistol from firing if the gun is dropped. After admitting there was a problem regarding the drop safety on early P320's, Sig issued a recall and allegedly fixed the issue. However, after some time, an entirely separate series of issues began to be reported, namely that in some cases, the pistol would discharge on it's own at random while holstered. When these reports came out, Sig Sauer did everything in their power to silence these concerns, and several Public Relations efforts were undertaken to shame and gaslight P320 owners into thinking that the problems were entirely the result of the end user and not a design flaw. However, despite the months of denial, problems remained.Several law enforcement agencies halted the use of the M18 a few months ago after very-well-documented cases confirmed that sometimes the M18 will fire a chambered round while hol
William Dalton, VP and Managing Director for North America and Europe from VicOne, the automotive cybersecurity subsidiary of Trend Micro, talks with host John Heinlein, Ph.D., Chief Marketing Officer of Sonatus about the state of automotive cybersecurity. He addresses the unique challenges and opportunities posed by software-defined vehicles (SDVs), how to enhance vehicle security with proactive security measures, and intrusion detection and prevention (IPDS) systems. He discusses their work to support their white-hat hacking challenge "Pwn2Own Automotive", which encourages ethical hackers to identify zero-day vulnerabilities in the automotive sector. This episode was filmed live at AutoTech Detroit in Novi, Michigan, in June 2025
Cloudflare says yesterday's widespread outage was not caused by a cyberattack. Predator mobile spyware remains highly active. Microsoft is investigating ongoing Microsoft 365 authentication services issues. An account takeover campaign targets Entra ID users by abusing a popular pen testing tool. Palo Alto Networks documents a JavaScript obfuscation method dubbed “JSFireTruck.” Trend Micro and Mitel patch multiple high-severity vulnerabilities. CISA issues multiple advisories. My Hacking Humans cohost Joe Carrigan joins us to discuss linkless recruiting scams. Uncle Sam wants an AI chatbot. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, we are joined by Joe Carrigan, one of Dave's Hacking Humans co-hosts, to talk about linkless recruiting scams. You can learn more in this article from The Record: FIN6 cybercriminals pose as job seekers on LinkedIn to hack recruiters. Tune in to Hacking Humans each Thursday on your favorite podcast app to hear the latest on the social engineering scams that are making the headlines from Joe, Dave and their co-host Maria Varmazis. Selected Reading Cloudflare: Outage not caused by security incident, data is safe (Bleeping Computer) Predator Mobile Spyware Remains Consistent with New Design Changes to Evade Detection (Cyber Security News) Microsoft confirms auth issues affecting Microsoft 365 users (Bleeping Computer) TeamFiltration Abused in Entra ID Account Takeover Campaign (SecurityWeek) 270K websites injected with ‘JSF-ck' obfuscated code (SC Media) Palo Alto Networks Patches Series of Vulnerabilities (Infosecurity Magazine) SimpleHelp Vulnerability Exploited Against Utility Billing Software Users (SecurityWeek) Trend Micro fixes critical vulnerabilities in multiple products (Bleeping Computer) Critical Vulnerability Exposes Many Mitel MiCollab Instances to Remote Hacking (SecurityWeek) CISA Releases Ten Industrial Control Systems Advisories (CISA) Trump team leaks AI plans in public GitHub repository (The Register) Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
當金曲歌后徐佳瑩發現在 Uber Eats 上(應該)都點得到,居然狂點一波!雖然點不到白馬和失落沙洲,但香水、辣椒或其他吃的用的都點得到~快上 Uber Eats 想要的都點點看 ⮕ https://fstry.pse.is/7nlf48 —— 以上為 KKBOX 與 Firstory Podcast 廣告 —— 邀請您成為《財訊》頻道的會員,並獲得專屬福利! https://open.firstory.me/user/wealth1974/platforms #蒸餾 #AI #趨勢 #陳怡樺 #防毒軟體 隨著AI技術高速發展,資安議題躍升產業核心焦點。作為資安龍頭,趨勢科技(Trend Micro)自成立近 40 年來,不僅營收屢創佳績,更已成為亞洲市值最高的資安企業。近年因應 AI 浪潮,其數位轉型效益顯著,2024 年營業利益更達 46% 的強勁增長。本次《財訊》獨家專訪趨勢科技執行長,深入探討近期併購傳聞,並解析 AI 時代下資安所面臨的挑戰與應對策略。 段落重點: ● AI熱潮與資安挑戰浮現 。 ● 趨勢科技併購話題探究。 ● AI時代資安基礎建設的變革。 ●「以AI保護AI」的資安新策略與挑戰。 留言告訴我你對這一集的想法: https://open.firstory.me/user/ckijrbz8nehm50847mulgl7v6/comments ★ 完整文章連結:https://www.wealth.com.tw/articles/c161ba13-6297-41b0-813f-5e521495cb01 ★ 訂閱財訊這裡請→https://www.wealthstore.com.tw/ ★ 打電話也可以訂財訊→(02)2551-5228 轉 10。 ★ 商業合作請洽 service1@wealthgrp.com.tw,或撥專線 (02)2551-2561 轉 255。 製作|財訊雙週刊 主持|陳雅潔 來賓|林宏達 企劃|吳匡庭 攝影|吳雨軒 剪輯|蔡克承 後製|蔡克承 錄製日期|2025.5.26 Powered by Firstory Hosting
Forecast = Mostly cloudy with a chance of rogue SSH access—keep your patches up to avoid a phishy forecast! Welcome to Storm⚡️Watch, where we unpack the latest in cybersecurity threats, research, and the tools that keep the digital world safe. In this episode, we invite GreyNoise Security Architect and researcher Matthew Remacle (a.k.a., Remy) to kick things off with a deep dive into a fascinating and highly sophisticated botnet campaign targeting ASUS routers—a story that starts with a little help from machine learning and ends with some hard lessons for defenders everywhere. GreyNoise researchers spotted this campaign using SIFT, their AI-powered network traffic analyzer, which sifted through more than 23 billion network entries and managed to flag just 30 suspicious payloads targeting ASUS routers. What made this botnet stand out was its surgical precision and stealth—far from the usual noisy, attention-grabbing attacks. The attackers knew exactly what they were doing, focusing on disabling TrendMicro security features embedded in the routers, essentially breaking in by first turning off the alarm. The attack chain reads like a masterclass in persistence: brute force and clever authentication bypasses got them in the door, a null byte injection tricked the router's authentication system, and a command injection vulnerability allowed them to manipulate logging features in a way that opened up even more attack paths. The real kicker? The final backdoor was installed using legitimate ASUS features, meaning it could survive firmware updates and stay hidden from traditional detection methods. This campaign affected thousands of routers globally, with over 4,800 compromised devices detected and counting. Even after ASUS released a patch—adding character validation rather than fixing the underlying flaw—researchers found that the fundamental vulnerability remained, and attackers could potentially work around the patch. This story highlights the ongoing challenges in IoT security: complexity breeds vulnerability, persistence is a nightmare to detect and remove when attackers use legitimate features, and patches often address symptoms rather than root causes. It's a reminder that traditional signature-based detection is no longer enough—behavioral analysis and AI-driven anomaly detection are now essential for spotting these advanced threats. We also touch on the bigger picture: the evolving cat-and-mouse game between attackers and defenders, the importance of defense in depth, and why understanding normal network behavior is more critical than ever. Plus, we look at the human element—attackers who are patient, technically sophisticated, and deeply aware of how to evade detection. For organizations, the takeaways are clear: defense in depth, behavioral monitoring, asset management, and patch management are all non-negotiable. And for everyone else, it's a reminder that the devices we trust to protect us are themselves complex and potentially vulnerable computers. Later in the episode, we take a closer look at vulnerability scoring systems—CVSS, EPSS, and SSVC—and why reading between the scores is so important for risk management. We also highlight the value of fresh, actionable data from sources like Censys and VulnCheck, and round things out with a nod to the ongoing conversation happening on the GreyNoise blog. Thanks for tuning in to Storm⚡️Watch. Stay vigilant, keep learning, and remember: in cybersecurity, the difference between safe and compromised can be as subtle as a single null byte. Storm Watch Homepage >> Learn more about GreyNoise >>
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Researchers at Trend Micro have uncovered a new campaign by the Fog ransomware group, notable for its use of DOGE-themed ransom notes aimed at mocking victims rather than just extorting them.In the wake of May 2024's Operation Endgame, which dismantled some of the most prominent malware droppers such as IcedID, Pikabot, SystemBC, Smokeloader, and Bumblebee, law enforcement agencies across Europe and North America have moved into a new phase targeting end users of these platforms.Zscaler researchers have recently observed Mustang Panda—also known by aliases like Bronze President, Stately Taurus, and TA416—upgrading its toolset as part of an ongoing espionage campaign, with a recent operation targeting an organization in Myanmar. Atomic macOS Stealer (AMOS), identified as one of the most impactful macOS-targeting infostealers of 2024, leverages deceptive application installers and phishing tactics to gain access to victim machines.
Nvidia built a chip to comply with American export rules. This week, those rules changed. Markets reacted dramatically, but chances are that the $2.5 trillion chipmaker can stand the hit. (00:21) Anthony Schiavone and Mary Long discuss Nvidia's $5.5 billion charge and earnings from Prologis. Then, (12:31), Ricky Mulvey talks with Kevin Simzer, COO of Trend Micro, about AI's impact on the cybersecurity space. Companies mentioned: NVDA, PLD, AOT Host: Mary Long Guests: Anthony Schiavone, Ricky Mulvey, Kevin Simzer Engineer: Dan Boyd Learn more about your ad choices. Visit megaphone.fm/adchoices
A cyberattack targeting Oracle Health compromises patient data. The DOJ nabs over $8 million tied to romance scams. Trend Micro examines a China-linked APT group conducting cyber-espionage. A new Android banking trojan called Crocodilus has emerged. North Korea's Lazarus Group targets job seekers in the crypto industry. CISA IDs a new malware variant targeting Ivanti Connect Secure appliances. Maria Varmazis, host of N2K's T-Minus Space Daily show chats with Jake Braun, former White House Principal Deputy National Cyber Director and chairman of DEF CON Franklin. They discuss designating space as critical infrastructure. Nulling out your pizza payment. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Maria Varmazis, host of N2K's T-Minus Space Daily show sits down with Jake Braun, former White House Principal Deputy National Cyber Director and chairman of DEF CON Franklin, and they discuss designating space as critical infrastructure and sharing an overview of its attack surface. Selected Reading Oracle Health breach compromises patient data at US hospitals (Bleeping Computer) Oracle Warns Health Customers of Patient Data Breach (Bloomberg) Critical Condition: Legacy Medical Devices Remain Easy Targets for Ransomware (SecurityWeek) U.S. seized $8.2 million in crypto linked to 'Romance Baiting' scams (Bleeping Computer) DOJ Seizes USD 8.2M Tied to Pig Butchering Scheme (TRM Labs) Earth Alux Hackers Employ VARGIET Malware to Attack Organizations (Cyber Security News) 'Crocodilus' Android Banking Trojan Allows Device Takeover, Data Theft (SecurityWeek) ClickFake Interview – Lazarus Hackers Exploit Windows and macOS Users Fake Job Campaign (Cyber Security News) CISA Analyzes Malware Used in Ivanti Zero-Day Attacks (SecurityWeek) How A Null Character Was Used to Bypass Payments (System Weakness on Medium) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
XWiki Search Vulnerablity Exploit Attempts (CVE-2024-3721) Our honeypot detected an increase in exploit attempts for an XWiki command injection vulnerablity. The vulnerability was patched last April, but appears to be exploited more these last couple days. The vulnerability affects the search feature and allows the attacker to inject Groovy code templates. https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800 Correction: FBI Image Converter Warning The FBI's Denver office warned of online file converters, not downloadable conversion tools https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam VMWare Vulnerability Broadcom released a fix for a VMWare Tools vulnerability. The vulnerability allows users of a Windows virtual machine to escalate privileges within the machine. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518 Draytek Reboots Over the weekend, users started reporting Draytek routers rebooting and getting stuck in a reboot loop. Draytek now published advise as to how to fix the problem. https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/ Microsoft Managemnt Console Exploit CVE-2025-26633 TrendMicro released details showing how the MMC vulnerability Microsoft patched as part of its patch tuesday this month was exploited. https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Python Bot Delivered Through DLL Side-Loading A "normal", but vulnerable to DLL side-loading PDF reader may be used to launch additional exploit code https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778 Tomcat RCE Correction To exploit the Tomcat RCE I mentioned yesterday, two non-default configuration options must be selected by the victim. https://x.com/dkx02668274/status/1901893656316969308 SAML Roulette: The Hacker Always Wins This Portswigger blog explains in detail how to exploit the ruby-saml vulnerablity against GitLab. https://portswigger.net/research/saml-roulette-the-hacker-always-wins Windows Shortcut Zero Day Exploit Attackers are currently taking advantage of an unpatched vulnerability in how Windows displays Shortcut (.lnk file) details. Trendmicro explains how the attack works and provides PoC code. Microsoft is not planning to fix this issue https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html
The CISA and FBI warn that Ghost ransomware has breached organizations in over 70 countries. President Trump announces his pick to lead the DOJ's National Security Division. A new ransomware strain targets European healthcare organizations. Researchers uncover four critical vulnerabilities in Ivanti Endpoint Manager. Microsoft has patched a critical improper access control vulnerability in Power Pages. The NSA updates its Ghidra reverse engineering tool. A former U.S. Army soldier admits to leaking private call records. Our guest is Stephen Hilt, senior threat researcher at Trend Micro, sharing the current state of the English cyber underground market. The pentesters' breach was simulated — their arrest was not. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest is Stephen Hilt, senior threat researcher at Trend Micro, sharing the current state of the English cyber underground market. Learn more in the report. Selected Reading CISA and FBI: Ghost ransomware breached orgs in 70 countries (Bleeping Computer) Trump to nominate White House insider from first term to lead DOJ's National Security Division (The Record) New NailaoLocker ransomware used against EU healthcare orgs (Bleeping Computer) PoC Exploit Published for Critical Ivanti EPM Vulnerabilities (SecurityWeek) Microsoft Patches Exploited Power Pages Vulnerability (SecurityWeek) NSA Added New Features to Supercharge Ghidra 11.3 (Cyber Security News) Army soldier linked to Snowflake extortion to plead guilty (The Register) Katie Arrington Returns to Pentagon as DoD CISO (GovInfo Security) Penetration Testers Arrested by Police During Authorized Physical Penetration Testing (Cyber Security News) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Slide, a new backup and disaster recovery appliance designed for managed service providers, was introduced by former Datto founders Austin McCord and Michael Fass at the right-of-boom cybersecurity conference in Las Vegas. The appliance, which is slightly larger than an Apple Mac Studio, boasts a storage capacity of up to 16 terabytes and operates at speeds capable of saturating a 10-gigabit network connection. McCord emphasized the appliance's speed and efficiency, claiming it is significantly faster than existing market solutions. The founders aim to foster a culture of connection and support, allowing users to easily cancel their service with a single click, which they view as a reflection of a customer-centric philosophy.Apple has unveiled its first in-house cellular modem, the C1, which will debut in the iPhone 16E, marking a significant step away from reliance on Qualcomm chips. The C1 modem is touted as the most power-efficient modem ever included in an iPhone, promising reliable 5G connectivity. While the iPhone 16 and 16 Pro will continue to use Qualcomm technology for the time being, Apple is strategically testing the C1 modem in a budget model to assess its performance without risking issues for premium users. This move aligns with Apple's broader goal of controlling its hardware stack and optimizing performance across its devices.In the realm of artificial intelligence, xAI has launched Grok 3, a new model that boasts enhanced capabilities and has been trained on a significantly larger dataset. Grok 3 has achieved impressive scores on various benchmarks, including math performance, and features a deep search capability that enhances its reasoning. However, early testing has revealed some limitations, such as citation accuracy and humor comprehension. The company plans to open-source Grok 2 to address previous criticisms regarding biases, while also introducing a new subscription plan for Grok 3.Lastly, the podcast discusses potential acquisition talks surrounding Trend Micro, a Japanese cybersecurity firm, which is reportedly valued at approximately $8.54 billion. The discussions involve several private equity firms, and if the acquisition goes through, it could lead to significant changes in Trend Micro's product roadmap and support structure. Additionally, Sophos has announced a partnership with Pax8 to streamline security management for service providers, indicating a trend towards consolidating vendor relationships in the cybersecurity space. This partnership aims to simplify access to a wide range of security solutions, although it remains to be seen whether Sophos can effectively compete with existing offerings in the marketplace. Four things to know today 00:00 Cancel Anytime with One Click? Slide's Backup Solution Calls Out the Industry's Biggest Flaws04:21 Apple Unveils C1 Modem in iPhone 16e, Taking First Steps Away from Qualcomm06:19 xAI's Grok 3 Hits the Scene with More Power, More Data, and… More Questions08:37 Big Money Meets Big Security: Trend Micro Buyout Talks Heat Up While Sophos Joins the Pax8 Party Supported by: https://www.huntress.com/mspradio/https://cometbackup.com/?utm_source=mspradio&utm_medium=podcast&utm_campaign=sponsorship Event: : https://www.nerdiocon.com/ All our Sponsors: https://businessof.tech/sponsors/ Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/ Support the show on Patreon: https://patreon.com/mspradio/ Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com Follow us on:LinkedIn: https://www.linkedin.com/company/28908079/YouTube: https://youtube.com/mspradio/Facebook: https://www.facebook.com/mspradionews/Instagram: https://www.instagram.com/mspradio/TikTok: https://www.tiktok.com/@businessoftechBluesky: https://bsky.app/profile/businessof.tech
Europol dismantles the Manson cybercrime market. Operation Destabilise stops two major Russian-speaking money laundering networks. New details emerge on China's attacks on U.S. telecoms. Black Lotus Labs uncovers a covert campaign by the Russian-based threat actor “Secret Blizzard”. Cisco issues patches for a high impact bootloader vulnerability. Trend Micro researchers uncovered Earth Minotaur targeting Tibetan and Uyghur communities. Payroll Pirates target HR payroll systems to redirect employee funds .Pegasus spyware may be more prevalent than previously believed. Our guest today is Jon France, CISO at ISC2, with insights from the ISC2 2024 Workforce Study. How businesses can lose customers one tip at a time. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest today is Jon France, CISO at ISC2, sharing the ISC2 2024 Workforce Study. You can read the press release about the report here and dig into the details of the report itself here. Selected Reading 50 Servers Linked to Cybercrime Marketplace and Phishing Sites Seized by Law Enforcement (SecurityWeek) UK's NCA Disrupts Multibillion-Dollar Russian Money Launderers (Infosecurity Magazine) The White House reveals at least 8 U.S. telecom firms impacted by China's Salt Typhoon cyberattack (Fast Company) Senators implore Department of Defense to expand the use of Matrix (Element) Snowblind: The Invisible Hand of Secret Blizzard (Lumen) Frequent freeloader part I: Secret Blizzard compromising Storm-0156 infrastructure for espionage (Microsoft Security) Russian Hackers Exploit Rival Attackers' Infrastructure for Espionage (Infosecurity Magazine) Bootloader Vulnerability Impacts Over 100 Cisco Switches (SecurityWeek) MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur's Multi-Platform Attacks (Trend Micro) Hunting Payroll Pirates: Silent Push Tracks HR Redirect Phishing Scam (Silent Push) iVerify Mobile Threat Investigation Uncovers New Pegasus Samples (iVerify) How a Russian man's harrowing tale shows the physical dangers of spyware (CyberScoop) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
A WIRED investigation uncovers the ease of tracking U.S. military personnel. Apple releases emergency security updates to address actively exploited vulnerabilities. Latino teenagers and LGBTQ individuals are receiving disturbing text messages spreading false threats. Crowdstrike says Liminal Panda is responsible for telecom intrusions. Oracle patches a high-severity zero-day vulnerability. Trend Micro has disclosed a critical vulnerability in its Deep Security 20 Agent software. A rural hospital in Oklahoma suffers a ransomware attack. A leading fintech firm is investigating a security breach in its file transfer platform. Researchers deploy Mantis against malicious LLMs. Ben Yelin from the University of Maryland Center for Health and Homeland Security discusses AI's bias in the resume screening process. Tracking down a lost Lambo. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, we have Ben Yelin, Program Director, Public Policy & External Affairs at the University of Maryland Center for Health and Homeland Security and our Caveat podcast co-host, discussing AI's racial and gender bias in the resume screening process. You can read about it here. Selected Reading Anyone Can Buy Data Tracking US Soldiers and Spies to Nuclear Vaults and Brothels in Germany (WIRED) GAO recommends new agency to streamline how US government protects citizens' data (The Record) Apple Issues Emergency Security Update for Actively Exploited Flaws (Infosecurity Magazine) Texts threatening deportation and 're-education' for gays stoke both fear and defiance (NBC News) Chinese APT Group Targets Telecom Firms Linked to BRI (Infosecurity Magazine) Oracle Patches Exploited Agile PLM Zero-Day (SecurityWeek) Trend Micro Deep Security Vulnerability Let Attackers Execute Remote Code (Cyber Security News) Oklahoma Hospital Says Ransomware Hack Hits 133,000 People (GovInfo Security) Fintech Giant Finastra Investigating Data Breach (Krebs on Security) AI About-Face: 'Mantis' Turns LLM Attackers Into Prey (Dark Reading) Hackers Steal MLB Star Kris Bryant's $200K Lamborghini By Rerouting Delivery (Carscoops) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
SecTor, Canada's largest cybersecurity conference, today announced the release of its full schedule of Summits for SecTor 2024. The live, in-person event will take place from October 22 to October 24 at the Metro Toronto Convention Centre in downtown Toronto. Summits will take place on Tuesday, October 22 and include:SecTor Executive Summit – This Summit will offer CISOs and other cybersecurity executives an opportunity to hear from industry experts helping to shape the next generation of information security strategy. Sponsors include: Armis, Sysdig, Cyera, and Trend Micro. To apply, please visit blackhat.com/sector/2024/executive-summit.html.Inaugural AI Summit at SecTor – This Summit will take place as part of The AI Summit Series, a global conference and expo series focusing on practical applications of AI technologies. This Summit will underscore the importance of artificial intelligence (AI) as an organization's newest and greatest weapon within the ever-evolving cybersecurity landscape. Passes can be purchased here: blackhat.com/sector/2024/ai-summit.html.Cloud Security Summit at SecTor – This Summit is Canada's leading cloud security event featuring keynote speakers, panel discussions, and networking opportunities, and provides an invaluable opportunity for every security professional to engage with leaders and discuss the future of cloud security. Sponsors include: CrowdStrike, Cyera, Kyndryl, Okta, OpenText, StrongDM, Sysdig, and Lookout. Passes can be purchased here: blackhat.com/sector/2024/cloud-summit.html.Note: This story contains promotional content. Learn more.ResourcesLearn more and catch more stories from SecTor Cybersecurity Conference Toronto 2024: https://www.itspmagazine.com/sector-cybersecurity-conference-2024-cybersecurity-event-coverage-in-toronto-canadaLearn more about 2 Minutes on ITSPmagazine Short Brand Story Podcasts: https://www.itspmagazine.com/purchase-programs
On this episode of The Cybersecurity Defenders Podcast we talk about some of the common pitfalls faced by founders with Andrew Plato, Founder & CEO of Zenaciti.Andrew is an experienced CEO, founder, author, and cybersecurity expert. In 1995, Andrew founded Anitian, one of the earliest cybersecurity companies on record, where he pioneered innovations in intrusion detection, endpoint security, and cloud security. He led the development of a revolutionary automated platform for secure cloud environments, and under his leadership, Anitian formed strategic partnerships with major tech companies like AWS, Microsoft, and Trend Micro before he exited the company in 2022. Andrew also leads Zenaciti, providing business and security intelligence, and recently founded Screenopolis, focusing on media analysis. He is also the author of The Founder's User Manual: Practical Strategies for the Startup Leader.
The US is set to propose a ban on Chinese software and hardware in connected cars. Dell investigates a breach of employee data. Unit 42 uncovers a North Korean PondRAT and a red team tool called Splinter. Marko Polo malware targets cryptocurrency influencers, gamers, and developers. An Iranian state-sponsored threat group targets Middle Eastern governments and telecommunications.The alleged Snowflake hacker remains active and at large. German officials quantify fallout from the CrowdStrike incident. Apple's latest macOS update has led to widespread issues with cybersecurity software and network connectivity. Our guest is Vincenzo Ciancaglini, Senior Threat Researcher from Trend Micro, talking about the uptick in cybercrime driven by the generative AI explosion. Supercharging your graphing calculator. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest is Vincenzo Ciancaglini, Senior Threat Researcher from Trend Micro, talking about the uptick in cybercrime driven by the generative AI explosion. Read their blog "Surging Hype: An Update on the Rising Abuse of GenAI" here. Selected Reading Exclusive: US to propose ban on Chinese software, hardware in connected vehicles (Reuters) Dell investigates data breach claims after hacker leaks employee info (Bleeping Computer) North Korea-linked APT Gleaming Pisces deliver new PondRAT backdoor via malicious Python packages (Security Affairs) Global infostealer malware operation targets crypto users, gamers (Bleeping Computer) Iranian-Linked Group Facilitates APT Attacks on Middle East Networks (Security Boulevard) Hacker behind Snowflake customer data breaches remains active (CyberScoop) Discovering Splinter: A First Look at a New Post-Exploitation Red Team Tool (Palo Alto Networks) Organizations are changing cybersecurity providers in wake of Crowdstrike outage (Help Net Security) Cybersecurity Products Conking Out After macOS Sequoia Update (SecurityWeek) Secret calculator hack brings ChatGPT to the TI-84, enabling easy cheating (Ars Technica) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
In this conversation, the hosts discuss patchless patching, vulnerabilities in the Windows TCP/IP stack, and the trustworthiness of Microsoft. They highlight the challenges of marketing in the cybersecurity industry and the importance of building trust with customers. The conversation also touches on the need for vendors to prioritize security and code quality over rushing products to market. Overall, the hosts express concerns about the frequency of security vulnerabilities and the potential impact on customer trust. Other topics of discussion include the Innovators and Investors Summit at Black Hat, the potential sale of Trend Micro, layoffs in the industry, and the controversy surrounding room searches at DEF CON. They also touch on the concept of time on the moon and its implications for future lunar missions. Devo, the security analytics company, recently launched data orchestration, a data analytics cloud, and security operations center (SOC) workflow enhancements. Enterprise security teams are struggling with growing data volumes—and they're also up against headcount and budget constraints. These solutions offer security teams data control, cost optimizations, and efficient automation for better security outcomes. Segment Resources: https://www.devo.com/defend-everything/ This segment is sponsored by Devo. Visit https://securityweekly.com/devobh to learn more about how Devo's new solutions can streamline your security operations. As security monitoring has gotten more mature over the years, remediating security vulnerabilities is still stuck in the dark ages requiring mountains of CVE reports and thousands of manual tasks to be done by network engineers at the wee hours of the nights and weekends. Cyber resilience requires a more continuous approach to remediation, one that does not depend on manual work but also one that can be trusted not to cause outages. This segment is sponsored by BackBox. Visit https://securityweekly.com/backboxbh to learn more about them! Many cybersecurity experts are calling recent attacks on healthcare more sophisticated than ever. One attack disrupted prescription drug orders for over a third of the U.S. and has cost $1.5 billion in incident response and recovery services. Separately, an operator of over 140 hospitals and senior care facilities in the U.S. was also victimized. These attacks are becoming all too common. Disruptions can lead to life-and-death situations with massive impacts on patient care. All industries, especially healthcare, have to better prepare for ransomware attacks. Are you ready to turn the tables on threat actors? Marty Momdjian, Semperis EVP and General Manager provides advice on how hospitals can regain the upper hand. This segment is sponsored by Semperis. Visit https://securityweekly.com/semperisbh to learn more about them! The annual report details the latest ransomware attack trends and targets, ransomware families, and effective defense strategies. Findings in the report uncovered an 18% overall increase in ransomware attacks year-over-year, as well as a record-breaking ransom payment of US$75 million – nearly double the highest publicly known ransomware payout – to the Dark Angels ransomware group. Segment Resources: For a deeper dive into best practices for protecting your organization and the full findings, download the Zscaler ThreatLabz 2024 Ransomware Report Link below - https://zscaler.com/campaign/threatlabz-ransomware-report This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-372
How safe are we in the age of AI PCs? As AI technology becomes increasingly integrated into our everyday devices, the promise of faster, more personalized computing comes with a critical question: Are we truly prepared for the security and privacy challenges that follow? In this episode, I sit down with Eric Shulze, VP of Product Management at Trend Micro, to explore the rapidly evolving landscape of AI PCs. With chip makers in a race to innovate, these new devices promise unparalleled speed and privacy by running generative AI locally on specialized neural processing units (NPUs). But as AI's role expands, so do the concerns over data security and privacy. Eric shares his insights on the potential risks associated with on-device AI, including the threat of compromised data and the spread of misinformation. We delve into the steps consumers can take to protect themselves, from choosing reputable vendors to implementing additional security layers. Eric also reveals how Trend Micro is stepping up to the challenge, with plans to roll out cutting-edge tools to safeguard AI PC users. But it's not all about the risks. We also explore the excitement surrounding AI innovation—how it's transforming personalization and accessibility in tech, and why ethical considerations must be at the forefront of this revolution. Plus, Eric offers a unique glimpse into his own career journey, from studying zoology and working as a dolphin trainer to becoming a leader in the tech industry. As AI PCs move from concept to mainstream reality, what do you need to know to stay safe and informed? Tune in to find out, and join the conversation on how we can balance innovation with privacy in the digital age. What are your thoughts on the future of AI PCs? Let us know!
Apple warns targeted users of mercenary spyware attacks. CISA expands its Malware Next-Gen service to the private sector. US Cyber Command chronicles their “hunt forward” operations. Taxi fleets leak customer data. Trend Micro tracks DeuterBear malware. The BatBadBut vulnerability enables command injection on Windows. Cybercriminals manipulate GitHub's search functionality. Scully Spider may be utilizing AI generated Powershells scripts. A study from ISC2 shed's light on salary disparities. On our Threat Vector segment, host David Moulton, Director of Thought Leadership at Unit 42, welcomes Donnie Hasseltine, VP of Security at Second Front Systems and a former Recon Marine, as they delve into the indispensable role of a military mindset in cybersecurity. Guest Dr. Sasha Vanterpool, Cyber Workforce Consultant with N2K, introducing the new podcast series Cyber Talent Insights. And AI music sings the license. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guests On our Threat Vector segment, host David Moulton, Director of Thought Leadership at Unit 42, welcomes Donnie Hasseltine, VP of Security at Second Front Systems and a former Recon Marine, as they delve into the indispensable role of a military mindset in cybersecurity. You can listen to the full conversation here. Guest Dr. Sasha Vanterpool, Cyber Workforce Consultant with N2K, introducing the new podcast series Cyber Talent Insights that is launching on Friday, April 12, 2024. You can read more about Cyber Talent Insights here. Selected Reading iPhone users in 92 countries received a spyware attack warning from Apple (Engadget) CISA to expand automated malware analysis system beyond government agencies (The Record) US Cyber Force Assisted Foreign Governments 22 Times in 2023 (SecurityWeek) Taxi software vendor exposes personal details of nearly 300K (The Register) Cyberespionage Group Earth Hundun's Continuous Refinement of Waterbear and Deuterbear (Trend Micro) BatBadBut: You can't securely execute commands on Windows (Flatt) New Technique to Trick Developers Detected in an Open Source Supply Chain Attack (Checkmarx) Malicious PowerShell script pushing malware looks AI-written (Bleeping Computer) Women make less than men in US cyber jobs — but the gap is narrowing (CyberScoop) Permission is hereby granted (Suno) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.
The Cyber Safety Review Board hands Microsoft a scathing report. Jackson County, Missouri declares a state of emergency following a ransomware attack. The concerning growth of Chinese brands in U.S. critical infrastructure. Malware campaigns make use of YouTube. OWASP issues a data breach warning. Trend Micro tracks LockBit's faltering rebound. India's government cloud service leaks personal data. ChatGPT jailbreaks spread on popular hacker forums. On our Learning Layer segment, host Sam Meisenberg and Joe Carrigan continue their discussion of Joe's CISSP study journey and focus on the when and how of studying for Domain 1. And you can no longer just walk out of an Amazon grocery store. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Learning Layer segment, host Sam Meisenberg and Joe Carrigan continue their discussion of Joe's CISSP study journey and focus on the when and how of studying for Domain 1. Resources for this session: Effect of sunlight exposure on cognitive function among depressed and non-depressed participants: a REGARDS cross-sectional study Selected Reading Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack (AP News) Missouri county declares state of emergency amid suspected ransomware attack (Ars Technica) Forescout research finds surge in Chinese-manufactured devices on US networks, including critical infrastructure (Industrial Cyber) YouTube channels found using pirated video games as bait for malware campaign (The Record) OWASP issues data breach alert after misconfigured server leaked member resumes (ITPro) Trend Micro: LockBit ransomware gang's comeback is failing (TechTarget) Indian government's cloud spilled citizens' personal data online for years (TechCrunch) ChatGPT jailbreak prompts proliferate on hacker forums (SC Media) Amazon Ditches 'Just Walk Out' Checkouts at Its Grocery Stores (Gizmodo) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.
A SIM-swapper faces prison and fines. Here come the class action suits against UnitedHealth Group. Aviation and Aerospace find themselves in the cyber crosshairs. A major mortgage lender suffers a major data breach. A look at election misinformation. The UK shares guidance on migrating SCADA systems to the cloud. Collaborative efforts to contain Smoke Loader. Trend Micro uncovers Earth Krahang. Troy Hunt weighs in on the alleged AT&T data breach. Ben Yelin unpacks the case between OpenAI and the New York Times. And fool me once, shame on you… Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Ben Yelin, Program Director at University of Maryland's Center for Health and Homeland Security and cohost of our Caveat podcast, discusses the article on how “OpenAI says New York Times ‘hacked' ChatGPT to build copyright lawsuit.” Selected Reading District of New Jersey | Former Telecommunications Company Manager Admits Role in SIM Swapping Scheme (United States Department of Justice) Cash-Strapped Women's Clinic Sues UnitedHealth Over Attack (Gov Info Security) Nations Direct Mortgage Data Breach Impacts 83,000 Individuals (SecurityWeek) Preparing Society for AI-Driven Disinformation in the 2024 Election Cycle (SecurityWeek) NCSC Publishes Security Guidance for Cloud-Hosted SCADA (Infosecurity Magazine) Unit 42 Collaborative Research With Ukraine's Cyber Agency To Uncover the Smoke Loader Backdoor (Palo Alto Networks Unit 42) Prolific Chinese Threat Campaign Targets 100+ Victims (Infosecurity Magazine) Troy Hunt: Inside the Massive Alleged AT&T Data Breach (Troy Hunt) Kids' Cartoons Get a Free Pass From YouTube's Deepfake Disclosure Rules (WIRED) Ransomware Groups: Trust Us. Uh, Don't. (BankInfoSecurity) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The Consumer Electronics Show kicks off with big news from Nvidia and many more. (00:21) Jason Moser and Deidre Woollard discuss: - Announcements from CES. - What could make Apple's Vision Pro successful. - The relevance of Twilio's CEO switch. (17:42) Ricky Mulvey interviews Kevin Simzer, Chief Operating Officer of Trend Micro, about cybersecurity in the cloud and the new threats facing electric cars. Companies discussed: AAPL TWLO, NVDA, AMD, OTC: TMICY Claim your Epic Bundle discount here: www.fool.com/epic198 Host: Deidre Woollard Guests: Jason Moser, Ricky Mulvey, Kevin Simzer Producers: Mary Long, Ricky Mulvey Engineers: Dan Boyd, Desiree Jones Learn more about your ad choices. Visit megaphone.fm/adchoices