Podcast Episodes
Back to SearchFake NDAs, Real Money: Inside the M&A Social Engineering Playbook
In this episode, we examine the Phantom Deal campaign, in which threat actors used publicly available details about companies’ acquisition histories,…
1 day, 17 hours ago
From Vulnerability Research to Domain Admin in Minutes
AI is changing the economics of cyberattacks. In this episode, we examine how a suspected threat actor used AI agents to accelerate PaperCut vulnerab…
1 week, 1 day ago
One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives
Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past i…
2 weeks, 1 day ago
From Data Dumps to Critical Findings: The New Era of Data Extortion
Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. Wit…
3 weeks, 1 day ago
Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover
What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That…
4 weeks, 1 day ago
Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees
Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety sys…
1 month ago
When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders
Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a pro…
1 month, 1 week ago
The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026
An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from …
1 month, 2 weeks ago
Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click
An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No su…
1 month, 3 weeks ago
The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access
Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% s…
2 months ago