1531793375
Research Saturday

Advertise on podcast: Research Saturday

Rating
★★★★☆
4.4
from
8 reviews
This podcast has
468 episodes
Language
English
Publisher
N2K Networks
Explicit
No
Date created
2020/09/14
Latest episode
2026/10/03
Average duration
24 min.
Release period
7 days

Description

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

Unlock Research Saturday podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Social media

Check Research Saturday social media presence


Podcast episodes

Check latest episodes from Research Saturday podcast


Play to win, pay to lose.
2026/10/03
Today we are joined by Jean-Pierre Mouton, Senior Threat Intelligence Consultant at GuidePoint Security, discussing their work on "How Play Achieves Encryption." Play ransomware, also known as PlayCrypt, continues to target organizations across multiple sectors using a consistent double-extortion playbook that combines data theft with widespread encryption. A recent investigation details how the group gained access through a SonicWall VPN, moved laterally using tools such as Mimikatz and PsExec, exfiltrated sensitive data, and used the victim’s own SentinelOne uninstallation utility to disable endpoint protection. The findings highlight several behavioral indicators defenders can monitor, including tool staging through SYSVOL and SystemBC for command and control, event log clearing, and suspicious WinSCP activity. The research and executive brief can be found here: ⁠⁠⁠⁠How Play Achieves Encryption Learn more about your ad choices. Visit megaphone.fm/adchoices
An apple a day, a phish away.
2026/09/26
Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-a-Service platform designed to steal Apple credentials and disable Activation Lock on stolen devices. The platform uses email, SMS, WhatsApp, and AI-driven voice calls to impersonate Apple Support, with researchers uncovering a broader ecosystem spanning 506 domains, 168 storefront brands, and 30 backend installations. Despite its sophisticated social-engineering capabilities, basic coding flaws exposed extensive operational logs and revealed the shared infrastructure, developer activity, and reseller network behind the criminal operation. The research and executive brief can be found here: ⁠Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain Learn more about your ad choices. Visit megaphone.fm/adchoices
All about that proxy.
2026/09/19
Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign. The research and executive brief can be found here: Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims Learn more about your ad choices. Visit megaphone.fm/adchoices
A beast by any other name.
2026/09/12
Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses. In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities. The research and executive brief can be found here: ⁠⁠⁠⁠GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Learn more about your ad choices. Visit megaphone.fm/adchoices
RMM-ber this ransomware.
2026/09/05
Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: ⁠From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks Learn more about your ad choices. Visit megaphone.fm/adchoices
Who let the AI hack?
2026/08/29
Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool. The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities. The research and executive brief can be found here: LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools Learn more about your ad choices. Visit megaphone.fm/adchoices
A RAT in the spreadsheet.
2026/08/22
Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests. The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access. The research and executive brief can be found here: ⁠Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation Learn more about your ad choices. Visit megaphone.fm/adchoices
The botnet that scouts before it strikes.
2026/08/15
Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation Learn more about your ad choices. Visit megaphone.fm/adchoices
A little help from your search engine.
2026/08/08
Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command. The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised. The research and executive brief can be found here: Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer Learn more about your ad choices. Visit megaphone.fm/adchoices
The driver's seat to ransomware.
2026/08/01
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs Learn more about your ad choices. Visit megaphone.fm/adchoices
Cold lures, hot targets.
2026/07/25
This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespionage group that has continued to target Ukrainian government organizations with increasingly sophisticated spearphishing campaigns. We discuss how the group uses malicious PDF lures, server-side victim validation, and an updated JavaScript-based malware chain to selectively deploy espionage tools, demonstrating its ongoing efforts to evade detection while compromising high-value targets across Eastern Europe. The research and executive brief can be found here: ⁠FrostyNeighbor: Fresh mischief and digital shenanigans Learn more about your ad choices. Visit megaphone.fm/adchoices
When trusted sites turn.
2026/07/18
Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation. The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign. The research and executive brief can be found here: Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites Learn more about your ad choices. Visit megaphone.fm/adchoices
Conti-versal opinions.
2026/07/11
Today we are joined by Geoff White, host of Cyber Hack and BBC journalist, taking a deep dive into the Conti ransomware gang. Geoff explores an in-depth investigation into the notorious Conti ransomware gang, drawing from thousands of leaked internal messages to reveal how the group operated behind the scenes. The research uncovers surprising internal debates over targeting healthcare organizations, the fallout from accidentally exposing sensitive Saudi royal family data, and frantic efforts to free an arrested gang member. It also offers a rare look at Conti leader Vitaliy Kovalev through newly uncovered video footage, providing an unprecedented glimpse into one of cybercrime's most influential figures. Learn more about your ad choices. Visit megaphone.fm/adchoices
Is your enterprise AI strategy delivering ROI yet? [AI Security Brief]
2026/07/04
While we take a break this 4th of July weekend, please enjoy this encore of AI Security Brief. Your enterprise AI strategy isn’t as far along as you think. The reality for most organizations today is that AI is disrupting existing processes more than it’s delivering outcomes… so far. And according to Dr. Grace Trinidad, Research Director at IDC, that’s how it should be. In this episode, host Johnny Hand sits down with Dr. Grace to discuss how AI adoption follows the same pattern as almost every major digital transformation, and why this disruption phase we’re in is messy, yet critically important.  What we cover: How history demonstrates that automation across industries created disruption well before delivering value Why your AI adoption strategy is much more than simple tool deployment What business and technology leaders need to consider as they integrate AI into operational workflows How token consumption and AI FinOps are the emerging security and cost risk How AI ontologies will be the next real business differentiator Why stick around:  If you’ve been wondering if your organization’s AI adoption strategy is ahead of the curve, Dr. Grace will give you a much clearer picture of where you really stand. Episode resources: Dr. Grace Trinidad on LinkedIn Securing the AI Enterprise: 5 Key Steps for Business Leaders Closing the Governance Gap in Agentic AI ⁠Johnny Hand on LinkedIn TrendAI on LinkedIn About AI Security Brief AI Security Brief is where security and technology leaders come to get ahead. Join us for real conversations on the AI trends, threats, and decisions that can't wait. About TrendAI™ TrendAI™ empowers organizations to lead the future of AI with proactive security designed to inspire innovation and eliminate risk. TrendAI™. AI Fearlessly. Learn more about your ad choices. Visit megaphone.fm/adchoices
More bark than byte.
2026/06/27
This week we are joined by Daniel Schwalbe, Chief Information Security Officer & Head of Investigations at DomainTools, discussing their work on "ZionSiphon OT Malware First Attempts? Psyops? Both?" Researchers at DomainTools take a closer look at ZionSiphon, a purported operational technology malware sample targeting the water sector, and find that despite its alarming appearance, it lacks many of the capabilities needed to function as a credible cyber-physical weapon. They break down the malware's architecture, its operational shortcomings, and why it may be more of a prototype or proof of concept than a deployable threat. With heightened concern surrounding attacks on critical infrastructure amid the ongoing U.S.-Iran conflict, the research offers timely insight into separating genuine OT threats from overhyped malware. The research and executive brief can be found here: Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? Learn more about your ad choices. Visit megaphone.fm/adchoices

Podcast reviews

Read Research Saturday podcast reviews


4.4 out of 5
8 reviews
★☆☆☆☆
[REDACTED] USER 2023/06/24
Podcast doesn’t play while on VPN.
Podcast doesn’t play while on VPN.
★★★★★
Jedi Wannabi 2021/09/01
A fascinating look into the guts of the machine
I love learning about how even the people who deeply know and understand the intricacies of existing data networks are constantly breaking new ground.
★★★★★
GottaRun21 2020/10/28
The go-to for cyber research discussion
Need or want to know more about the leading research in security? You’ve found just the thing. It’s the perfect show to catch up on the latest researc...
★★★★★
Frogstar5 2020/10/28
One of my favorites from the CyberWire
I never miss an episode of Research Saturday. These one-on-one interviews with researchers from all over the world, and from a diverse range of compan...
check all reviews on apple podcasts

Podcast sponsorship advertising

Start advertising on Research Saturday relevant audience podcasts


What do you want to promote?