1326304686
ShadowTalk: Powered by ReliaQuest

Advertise on podcast: ShadowTalk: Powered by ReliaQuest

Rating
★★★★★
4.7
from
44 reviews
This podcast has
493 episodes
Language
English
Publisher
ReliaQuest
Explicit
No
Date created
2017/12/15
Latest episode
2026/09/30
Average duration
30 min.
Release period
8 days

Description

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research. Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the most pertinent cyber threats.    With over 1,000 customers worldwide and 1,200 teammates across six global operating centers, ReliaQuest delivers security outcomes for the most trusted enterprise brands in the world. Learn more at www.reliaquest.com.

Unlock ShadowTalk: Powered by ReliaQuest podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Social media

Check ShadowTalk: Powered by ReliaQuest social media presence


Podcast episodes

Check latest episodes from ShadowTalk: Powered by ReliaQuest podcast


CISO Wisdom: Turning Security Investments Into Measurable Risk Reduction
2026/09/30
Security teams are contending with more tools, alerts, and vulnerabilities than ever—but volume does not necessarily equal security. Jigar Shah joins us to discuss how organizations can automate repetitive work, prioritize vulnerabilities based on business risk, build identity-driven security strategies, and connect cybersecurity investments to measurable outcomes. With two decades of leadership experience across healthcare, financial services, retail, and consulting, Jigar brings a business-focused perspective on helping security leaders communicate risk and resilience to the board and C-suite.  A Question Your Organization Should Be Asking Right Now: How quickly can your organization make risk-based decisions?Resources: https://linktr.ee/ReliaQuestShadowTalk Jigar Shah: Transformational IT, data, and cybersecurity executive with two decades of leadership experience across healthcare, financial services, retail, and consulting. He brings a distinctive blend of technology, business, and legal expertise to overseeing complex enterprise initiatives, including cybersecurity programs, cloud migrations, M&A integrations, and risk management for large regulated organizations. A passionate advocate for automation, identity-driven security, and business-aligned cyber strategy, Jigar excels at translating technical priorities into measurable outcomes for boards and C-suite leaders. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
Fake NDAs, Real Money: Inside the M&A Social Engineering Playbook
2026/09/23
In this episode, we examine the Phantom Deal campaign, in which threat actors used publicly available details about companies’ acquisition histories, subsidiaries, executives, and employees to create convincing fake M&A scenarios. The goal: persuade employees to initiate large financial transfers while keeping conversations off corporate communication channels. We also cover a recent series of zero-day disclosures affecting major endpoint-security and Windows products. These vulnerabilities reinforce a critical operational reality: organizations must be prepared to detect and respond even when endpoint-security visibility is weakened or unavailable. Two questions your organization should be asking right now: If an employee received an urgent, confidential payment request from an apparent executive, could they independently verify the request without using the communication channel chosen by the attacker?If an endpoint-security tool went blind during an attack, what identity, network, cloud, and Windows telemetry could your team use to detect and contain the activity?Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
From Vulnerability Research to Domain Admin in Minutes
2026/09/16
AI is changing the economics of cyberattacks. In this episode, we examine how a suspected threat actor used AI agents to accelerate PaperCut vulnerability research, exploit development, target identification, and post-compromise activity—moving from initial access to domain administrator access in as little as seven minutes. We also explore recent reporting on large-scale AI-model distillation campaigns by China-based companies and what the increasing availability of frontier-level AI capabilities could mean for future nation-state and criminal threat operations. Two questions your organization should be asking right now: If an attacker gained initial access through an internet-facing system tomorrow, could your team detect and contain the activity in less than seven minutes?Are you evaluating vulnerabilities, exposed services, and identity privileges as connected attack paths—or as separate security issues?Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
One Empty Field: The Email Security Bypass Letting Attackers Impersonate Your Executives
2026/09/09
Organizations rely on Microsoft 365's RejectDirectSend control to block internal email spoofing—but a structural gap lets attackers walk right past it. With nothing more than a basic Python script and an empty envelope sender, threat actors are impersonating executives, IT support, and finance teams to launch Business Email Compromise, payment fraud, and follow-on account takeover. Join hosts Alexandra Moore and John Dilgen as they discuss: How an empty email header field bypasses RejectDirectSend and lands phishing in executive inboxesHow help desk impersonation combined with spoofed internal email creates a dangerous new pretextWhich controls—IP-restricted connectors, automated containment, and out-of-band verification—actually close the gap Two questions your organization should be asking right now: If someone attempted a Direct Send from an unauthorized IP into your tenant tomorrow, would it be rejected?When was the last time you tested whether your employees follow out-of-band verification procedures under pressure?Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
From Data Dumps to Critical Findings: The New Era of Data Extortion
2026/09/02
Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data. Join hosts John Dilgen and Brandon Tirado as they discuss: Why data theft has become a central component of modern extortion operationsHow AI and automation are helping attackers analyze hundreds of thousands of files at machine speedWhy “soft data,” including invoices and project documents, can fuel downstream fraud and social engineeringHow strong retention, credential-rotation, and OAuth-management practices reduce breach impactTwo questions your organization should be asking right now: How much data does your organization retain beyond its business or regulatory need?Could your team rotate hundreds of exposed credentials—not just one—before an attacker uses them?John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
Vishing at Scale: Inside the Criminal SaaS Platform Enabling Account Takeover
2026/08/26
What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call.   Join hosts John Dilgen and Alexandra Moore as they break down: ✅ How Work Panel packages phishing infrastructure, team management, and real-time credential capture into a single automated console ✅ Why threat actors are now impersonating HR to make their calls more convincing ✅ How legitimate B2B platforms are being weaponized to personalize attacks before a single call is made ✅ The specific controls that can stop these campaigns before they reach your users   🔑 Two questions your organization should be asking right now: If a caller already knew your employee's job title, manager's name, and direct number — would your team recognize it as a social engineering attempt, or fall for it?Is your organization still relying on push-based MFA as its primary account takeover defense?  👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree
Nation-State Actors: Iran’s PLC Attacks, Russia’s Zero-Click Email Exploit, and North Korea’s Fake Employees
2026/08/19
Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired. Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How Iranian actors manipulate PLC safety logic while keeping operators in the dark ✅ Why Russia’s zero-click exploit creates a major email-security and data-exfiltration risk ✅ How North Korean operatives use forged and stolen identities to infiltrate organizations as employees 🔑 Two questions your organization should be asking right now: Could your security team identify and secure internet-exposed PLCs, HMIs, and SCADA systems before an adversary does?Does your hiring process include controls to detect AI-generated documents, stolen identities, and malicious job applicants?👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree
When AI Escapes the Lab: The Hugging Face Breach, PyPI Malware, and What It Means for Defenders
2026/08/12
Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering.  Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How AI agents escaped containment and compromised Hugging Face infrastructure ✅ Why Claude’s autonomous PyPI attack signals growing software-supply-chain risk ✅ How coordinated AI agents deceived real developers 🔑 Two questions your organization should be asking right now: Could your SOC investigate and contain 17,000 coordinated events at machine speed?What deception controls do you have in place to slow an AI agent attack? 👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree
The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026
2026/08/05
An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now. Join hosts Brandon Tirado and John Dilgen as they break down: How The Gentlemen's pre-packaged affiliate kit drove 580% leak-site growthWhy Deadlock's Polygon blockchain C2 defeats network defensesClop's latest campaign targeting an industrial enterprise application Two questions your organization should be asking right now: Do you know exactly where your EDR coverage ends?If a critical vendor were compromised tonight, would you hear it from them first — or from your own monitoring?John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click
2026/07/29
An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token.  Join hosts Alexandra Moore and John Dilgen as they break down: How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentication trafficWhy hardcoded DNS, opportunistic encrypted DNS, and MFA may not stop the attackHow device-code phishing and WPAD abuse expand the campaign’s reachPractical defenses—including always-on, full-tunnel VPN, strict-mode encrypted DNS, and Conditional Access controls Two questions your organization should be asking right now: Does your always-on VPN tunnel all DNS and authentication traffic, or do split-tunneling exceptions leave traveling employees exposed?Who is permitted to authenticate through the device-code flow, and does each exception have a legitimate business justification?John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access
2026/07/22
Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up. Join hosts Alexandra Moore and John Dilgen as they break down:  How new extortion group Helix and ClickFix are weaponizing identity compromise at scale Why 622 vulnerabilities in a single week signals a permanent shift in the discovery ratePractical defenses for both fronts without doubling your team Two questions your organization should be asking right now: Have you audited which accounts in your environment are permitted to authenticate via device code grants and restricted the ones that don't need it?Does your IR runbook hunt for additional compromised accounts, or does it stop at the one sending extortion demands?Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
FortiBleed, 70,000 Compromised Devices, and the Credential Economy Powering Every Breach
2026/07/15
When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven days. Join hosts Tehman Tariq and John Dilgen as they break down: The mechanics behind FortiBleed and what made it so effective at scaleHow the IAB market has turned stolen credentials into a premium productWhy identity drift and non-human identities are becoming attackers' favorite targets Two questions your organization should be asking right now: Does your credential compromise runbook treat session termination as the first step — or is password rotation all that's covered?Can your team name the owner and rotation schedule for your top 10 most privileged non-human identities?Resources: https://linktr.ee/ReliaQuestShadowTalk Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
Inside Conti's Leaked Chats: 300,000 Messages, a Criminal Empire, and the Ransomware Playbook Still Running Today
2026/07/08
When 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and that changes how defenders need to think about the ransomware landscape today. Join host John and special guest Geoff White, journalist and author of Rinsed, as they discuss: How Conti's internal org chart compares to a legitimate software companyThe human cost of ransomware targeting critical infrastructureWhy ransomware groups keep splintering and rebuilding Two questions your organization should be asking right now: When your team thinks about ransomware, are they thinking about a criminal enterprise with structure, funding, and KPIs — or just a hacker in a hoodie?Does your incident response plan account for a negotiation with operators who already know your financials?Resources: https://linktr.ee/ReliaQuestShadowTalk Geoff White: One of the world's leading journalists covering organized crime and technology, with decades of experience investigating fraudsters, hackers, and money launderers. His work has been featured by BBC News, Sky News, Audible, and The Sunday Times, and he has delivered over 300 keynote talks across more than a dozen countries for global brands including Microsoft, HSBC, and Mastercard. He is the author of three books, including The Lazarus Heist — which spawned a hit BBC podcast that ranked number one in the UK Apple charts — and his latest, Rinsed (2024), which The Financial Times called "Riveting." Geoff brings a rare investigative lens to cybercrime, giving ShadowTalk listeners an inside look at the criminal enterprises shaping today's threat landscape. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race
2026/07/01
AI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects fabricated system error messages into AI powered triage pipelines, the arms race between attackers and defenders is accelerating. The question is not whether AI is being used against your organization. It is whether your defenses are keeping pace. Join hosts Brandon and John as they discuss: How threat actors are leveraging AI across social engineering and malicious code generationThe Gaslight macOS malware with anti-AI analysis tacticsWhat organizations need to do right now to match attackers Two questions your organization should be asking right now: • How long does it actually take your team to detect and contain a critical severity alert? • Are your detections layered across enough diverse log sources? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration
2026/06/24
In the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected integration in your environment is part of your attack surface. Join hosts Alexandra and John as they discuss: How compromised Klue integrations were leveraged to exfiltrate Salesforce CRM dataAttribution and what it signals about the evolving data extortion landscapeHow Oauth token and device code theft is growing Two questions your organization should be asking right now: How many third-party integrations in your environment have active OAuth access to platforms holding critical data — and when were they last audited?Do you have detections in place for unusual Salesforce API query volume and service account behavior that could signal an active exfiltration?Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

Podcast reviews

Read ShadowTalk: Powered by ReliaQuest podcast reviews


4.7 out of 5
44 reviews
★★★★★
Maocol99 2026/07/24
Awesome insights
This show always delivers relevant and practical topics to cybersecurity practitioners. They always summarize very practical recommendations
★★★★★
Cyber Practitioner 2025/02/15
For Practitioners By Practitioners
I enjoy how the hosts don’t just repot the news. Listening to a thoughtful discussion of top threats and analysis of what it means to my business is t...
★★★★★
7323Rodlun 2023/07/21
Top notch
I’ve been in electronic warfare and now cybersecurity 50 years. This Reliaquest organization is top notch. They are young and energetic and hire the b...
★★☆☆☆
[REDACTED] USER 2022/08/18
Audio is dreadful
Sounds like the host is talking out of a bucket. Probably good content. Unfortunately terrible audio doesn’t allow for me to listen…
★★★★★
anymonos 2018/07/02
Cybersecurity news
I love being able to get my weekly cybersecurity news in addition to a more detailed analysis from Digital Shadows’ analysts, engineers, etc. As someo...
★★★★★
Jdbjdnd 2018/01/16
Easy to listen to
I really enjoy the background and analysis in this podcast. It’s quite punny which makes it easy to listen to.
★★★★★
mikejones! 2018/01/12
Informative!
Great podcast to stay informed on emerging cyber threats
★★★★★
R__H 2018/01/12
Very informative
This is a very entertaining and informative podcast on the current cyber threat landscape I don’t have time to learn about the stuff on my own with my...
★★★★★
Jplaisance11 2018/01/12
CISO
Fantastic content!
★★★★★
Harkfedvifsefvkibsdy 2018/01/12
Shadow Talk
Great podcast on meltdown, spectre, and opnetneutrality !
check all reviews on apple podcasts

Podcast sponsorship advertising

Start advertising on ShadowTalk: Powered by ReliaQuest relevant audience podcasts


What do you want to promote?