ShadowTalk: Powered by ReliaQuest
Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research.
Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the most pertinent cyber threats.
With over 1,000 customers worldwide and 1,200 teammates across six global operating centers, ReliaQuest delivers security outcomes for the most trusted enterprise brands in the world. Learn more at www.reliaquest.com.
Episodes
493 episodes
CISO Wisdom: Turning Security Investments Into Measurable Risk Reduction
Security teams are contending with more tools, alerts, and vulnerabilities than ever—but volume does not necessarily equal security. Jigar Shah joins us to discuss how organizations can automate repetitive work, prioritize vulnerabilities based...
Fake NDAs, Real Money: Inside the M&A Social Engineering Playbook
In this episode, we examine the Phantom Deal campaign, in which threat actors used publicly available details about companies’ acquisition histories, subsidiaries, executives, and employees to create convincing fake M&A scenarios. The goal:...
From Vulnerability Research to Domain Admin in Minutes
AI is changing the economics of cyberattacks. In this episode, we examine how a suspected threat actor used AI agents to accelerate PaperCut vulnerability research, exploit development, target identification, and post-compromise activity—moving...
One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives
Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are...
From Data Dumps to Critical Findings: The New Era of Data Extortion
Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exp...
Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover
What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the crimi...
Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees
Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data...
When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders
Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another m...
The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026
An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; i...
Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click
An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token.<...
The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access
Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up.Join hosts Ale...
FortiBleed, 70,000 Compromised Devices, and the Credential Economy Powering Every Breach
When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now pa...
Inside Conti's Leaked Chats: 300,000 Messages, a Criminal Empire, and the Ransomware Playbook Still Running Today
When 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and...
How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race
AI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects ...
Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration
In the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected...
ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps
ShinyHunters dominated headlines this week: a zero-day, a BreachForums listing, and unverified claims all hitting at once. The problem isn't just keeping up with the volume. It's knowing which of it is real, which is noise, and what your team a...
China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection
Your team built defenses around known China-linked clusters. The file hashes are tracked. The behavioral patterns are documented. What those weren't built to catch is a new cluster that studied those exact defenses and engineered around them. A...
SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access
Your team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps — an...
Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook
Your user clicked a link, landed on a real Microsoft login page, typed their password, completed MFA, and walked away thinking nothing happened. Somewhere across the internet, an attacker's device just received an authenticated session token. T...
SQLite, Mistral, OpenAI: How AI Attacks Are Reshaping the Attack Surface
What happens when an AI agent uncovers a zero-day in hours instead of weeks, and state-backed groups are already operationalizing the same tools? With self-hosted AI infrastructure sprawling outside asset registers and supply chain worms reachi...
Canvas, Trellix, Mini Shai-Hulud: How Defenders Respond When Supply Chain Attacks Become Weekly
What's driving the surge in weekly supply chain attacks, and why does the real defender problem start after the supplier gets hit? With 275 million records exposed and 8,809 institutions caught in the downstream fallout, organizations ...
Akira, ShinyHunters, and The Gentlemen: Extortion Lessons From Early 2026
What factors have driven the top ransomware and extortion groups' success in early 2026? And how should organizations structure their defenses to protect against them?Join hosts Alexandra and John as they discuss:How Akira is...
What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives
Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 ...
Did ShinyHunters Compromise Vercel? Every CISO's Cloud Security Visibility Problem
89% of organizations that suffered a SaaS breach last year believed they had appropriate visibility. They had the logs — what they lacked was detection on what mattered. The Vercel incident shows exactly how costly that gap can be. ...