Listen to Talos security experts as they bring their hot takes on current security topics and Talos research to the table. Along the way Hazel, Mitch, Matt and a rotating chair of special guests will talk about anything (and we mean anything) that's on their minds, from the latest YouTube trends to Olympic curling etiquette. New episodes every other Thursday.
What does it take to become someone a cybercriminal will trust?
Talos' Azim Khodjibaev takes us inside the psychology of direct adversary engagement. At one point, he was maintaining eight different personas, some of which were talking to each other. He explains how discipline and patience help keep his cover intact, and what can provoke threat actors into revealing information.
His work has occasionally made Azim part of the story. Ransomware operators have threatened him, and one even put “Azim sucks” in their code. He shares how his research has contributed to Talos identifying prolific cybercriminals and disrupting ransomware operations (experiences that will feature in the forthcoming book "Owned").
The conversation also examines how cybercrime is changing. More inexperienced, loosely organized collectives can pull dozens of people into an active intrusion through a Telegram channel, and Azim tells the crew about one particular ransomware trend that's keeping him up at night.
Before all that, we tackle a listener question about what defenders should prioritise when patching everything is impossible. Hazel tries some American snacks for the first time, Joe tests Hazel's patience with more hacker training, and Dave argues that without Yaddle, there would be no Star Wars.
Every week, our host brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic in just five or 10 minutes. We cover everything from breaking news to attacker trends and emerging threats.
Ah, the crisp fall air, brand-new books and backpacks, and the quiet irony of cybercriminals turning on each other to steal a few extra bucks.
Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. This browser-based attack tricks targets into injecting malicious code into their own sessions under the guise of exploiting a fictional vulnerability to earn crypto-profits.
While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security. Tune in to hear why it’s only a matter of time before these techniques turn from petty crypto-scams toward our enterprise supply chains, and how to protect your organization.
Blog: https://blog.talosintelligence.com/clickfix-moves-into-the-browser/