RSS Amplifier

Podcast

ShadowTalk: Powered by ReliaQuest

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research. Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the…

reliaquest.comSource feed ↗12 episodes

Live Last read · last published · next check

Latest episodes

Saves to your Listen queue, to pick up on another day or another device.

Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover

What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call. Join hosts John Dilgen and Alexandra Moore as they break down: ✅…

Play

Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees

Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired. Join…

Play

When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders

Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering. Join hosts John Dilgen and…

Play

The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026

An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now. Join hosts Brandon…

Play

Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click

An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token. Join hosts Alexandra Moore and John Dilgen as they break down: How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft…

Play

The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access

Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up. Join hosts Alexandra Moore and John Dilgen as they break down: How new extortion group Helix and ClickFix are weaponizing identity compromise at scale Why 622 vulnerabilities in a…

Play

FortiBleed, 70,000 Compromised Devices, and the Credential Economy Powering Every Breach

When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven…

Play

Inside Conti's Leaked Chats: 300,000 Messages, a Criminal Empire, and the Ransomware Playbook Still Running Today

When 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and that changes how defenders need to think about the ransomware landscape today. Join host John and special guest Geoff White , journalist and author of…

Play

How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race

AI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects fabricated system error messages into AI powered triage pipelines, the arms race between attackers and defenders is accelerating. The question is not…

Play

Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration

In the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected integration in your environment is part of your attack surface. Join hosts Alexandra and John as they discuss: How compromised Klue integrations were…

Play

ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps

ShinyHunters dominated headlines this week: a zero-day, a BreachForums listing, and unverified claims all hitting at once. The problem isn't just keeping up with the volume. It's knowing which of it is real, which is noise, and what your team actually needs to act on. Join hosts Tehman and John as they discuss: ShinyHunters zero-day exploitation of CVE-2026-35273 Why a BreachForums listing extends…

Play

China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection

Your team built defenses around known China-linked clusters. The file hashes are tracked. The behavioral patterns are documented. What those weren't built to catch is a new cluster that studied those exact defenses and engineered around them. A China-linked attacker compromised an internet-facing IIS server, maintained access for over 75 days, and came back on fresh infrastructure. With four…

Play