Podcasts

Beers with Talos

Threats, Beers, and No Silver Bullets

Listen to Talos security experts as they bring their hot takes on current security topics and Talos research to the table. Along the way Hazel, Mitch, Matt and a rotating chair of special guests will talk about anything (and we mean anything) that's on their minds, from the latest YouTube trends to Olympic curling etiquette. New episodes every other Thursday.


Keeping Up With the Cybercriminals

In this episode of Beers with Talos, Hazel, Bill, Dave and Joe are joined by Kendall McKay to dive into the soap opera of modern cybercrime. From rival gangs launching smear campaigns against one another to reputation systems, trusted intermediaries and dark web "customer reviews". Turns out, every ransomware operation is one passive-aggressive group chat message away from falling apart.

Kendall chats to us about how AI is changing the economics of cybercrime, why it's helping inexperienced attackers get through the front door (only to leave them wondering what to do next), and how defenders can prioritize their defenses.

We also discuss the rise of supply chain attacks, and where the lines between cybercrime and state sponsored activity are beginning to blur.

Elsewhere in the episode, Joe once again attempts to Make Hazel a Hacker, Dave explains how a McDonald's receipt became an unlikely piece of counterintelligence, we preview Black Hat 2026, and Bill wraps everything up with his practical takeaways for defenders.

Talos Takes

Talos’ spin on security news

Every week, our host brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic in just five or 10 minutes. We cover everything from breaking news to attacker trends and emerging threats.


ARToken: How attackers are bypassing MFA and maintaining access

MFA and password resets aren't always enough.

That’s terrifying for security teams today. In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing/BEC-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset. This turns a simple phishing click into a long-term breach.

It’s time to rethink your defenses. Join us as Cisco Talos Threat Researcher Michael Kelley breaks down how this new breed of automated attack works and, more importantly, how you can spot it. From hunting for suspicious device authorization grants to securing your cloud infrastructure, don't miss this critical look at the new frontier of business email compromise. 

Blog: https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/