
Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research.Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the most pertinent cyber threats. With over 1,000 customers worldwide and 1,200 teammates across six global operating centers, ReliaQuest delivers secu...
10

<p>Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data.</p><p>Join hosts <b>John Dilgen</b> and <b>Brandon Tirado</b> as they discuss:</p>Why data theft has become a central component of modern extortion operationsHow AI and automation are helping attackers analyze hundreds of thousands of files at machine speedWhy “soft data,” including invoices and project documents, can fuel downstream fraud and social engi...

<p>What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call.</p><p> </p><p>Join hosts <b>John Dilgen</b> and <b>Alexandra Moore</b> as they break down:</p><p>✅ How Work Panel packages phishing infrastructure, team management, and real-time credential capture into a single automated console</p><p>✅ Why thr...

<p>Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired.</p><p>Join hosts <b>John Dilgen</b> and <b>Tehman Tariq </b>as they break down:</p><p>✅ How Iranian actors manipulate PLC safety logic while keeping operators in the dark</p><p>✅ Why Russia’s zero-click exploit creates a major email-security and data-exfiltration risk</p>...

<p>Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering.</p><p> Join hosts <b>John Dilgen</b> and <b>Tehman Tariq</b> as they break down:</p><p>✅ How AI agents escaped containment and compromised Hugging Face infrastructure</p><p>✅ Why Claude’s autonomous PyPI attack signals growing software-supply-chain risk</p><p>✅ How coordinated AI agents deceived real developers</p><p>🔑 <b>T...

<p>An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now.</p><p>Join hosts <b>Brandon Tirado</b> and <b>John Dilgen</b> as they break down:</p>How The Gentlemen's pre-packaged affiliate kit drove 580% leak-site growthWhy Deadlock's Polygon blockchain C2 defeats network defensesClop's latest campaign targeting an industrial enterprise application<p> <b>T...

<p>An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token.</p><p> Join hosts <b>Alexandra Moore</b> and <b>John Dilgen</b> as they break down:</p>How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentication trafficWhy hardcoded DNS, opportunistic encrypted DNS, and MFA may not stop the attackHow device-code phishing and WPAD abuse expand the campaign’s reachPractical defenses—including always-on, full-tunnel VPN, strict-mode encrypted DNS, and Conditional Access controls<p> <b>Two...

<p>Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up.</p><p>Join hosts <b>Alexandra Moore</b> and <b>John Dilgen</b> as they break down: </p>How new extortion group Helix and ClickFix are weaponizing identity compromise at scale Why 622 vulnerabilities in a single week signals a permanent shift in the discovery ratePractical defenses for both fronts without doubling your team<p> <b>Two questions your organization should be asking rig...

<p>When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven days.</p><p>Join hosts Tehman Tariq and John Dilgen as they break down:</p>The mechanics behind FortiBleed and what made it so effective at scaleHow the IAB market has turned stolen credentials into a premium productWhy identity drift and non-human identities...

<p>When 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and that changes how defenders need to think about the ransomware landscape today.</p><p>Join host John and special guest <b>Geoff White</b>, journalist and author of Rinsed, as they discuss:</p>How Conti's internal org chart compares to a legitimate software companyThe human cost of ransomware targeting critical infrastructureWhy ransomware groups keep splintering and rebuilding<p> <b>Two questions your organization s...

<p>AI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects fabricated system error messages into AI powered triage pipelines, the arms race between attackers and defenders is accelerating. The question is not whether AI is being used against your organization. It is whether your defenses are keeping pace.</p><p>Join hosts Brandon and John as they discuss:</p>How threat actors are leveraging AI across social engineering and malicious code generationThe...