Podcast charts
Published by ReliaQuest
Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research. Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the most pertinent cyber threats. With over 1,000 customers worldwide and 1,200 teammates across six global operating centers, ReliaQuest delivers security outcomes for the most trusted enterprise brands in the world. Learn more at www.reliaquest.com .
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data. Join hosts John Dilgen and Brandon Tirado as they discuss: Why data theft has become a central component of modern extortion operations How AI and automation are helping attackers analyze hundreds of thousands of files at machine speed Why “soft data,” including invoices and project documents, can fuel downstream fraud and social engineering How strong retention, credential-rotation, and OAuth-management practices reduce breach impact Two questions your organization should be asking right now: How much data does your organization retain beyond its business or regulatory need? Could your team rotate hundreds of exposed credentials—not just one—before an attacker uses them? John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado : Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
What if a threat actor already knew your name, your job title, your manager's name, and your direct number before they ever picked up the phone? That's not a hypothetical — that's Work Panel. A new report gave us a rare inside look at the criminal SaaS platform enabling vishing campaigns at scale, and the findings are a wake-up call. Join hosts John Dilgen and Alexandra Moore as they break down: ✅ How Work Panel packages phishing infrastructure, team management, and real-time credential capture into a single automated console ✅ Why threat actors are now impersonating HR to make their calls more convincing ✅ How legitimate B2B platforms are being weaponized to personalize attacks before a single call is made ✅ The specific controls that can stop these campaigns before they reach your users 🔑 Two questions your organization should be asking right now: If a caller already knew your employee's job title, manager's name, and direct number — would your team recognize it as a social engineering attempt, or fall for it? Is your organization still relying on push-based MFA as its primary account takeover defense? 👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree
Three nation-states. Three distinct playbooks. Iranian actors are targeting internet-exposed industrial controllers and disabling critical safety systems. A Russian threat group built a zero-click email exploit that steals 90 days of inbox data the moment a user views a message. And North Korean operatives are applying for software-development jobs at Western companies—and getting hired. Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How Iranian actors manipulate PLC safety logic while keeping operators in the dark ✅ Why Russia’s zero-click exploit creates a major email-security and data-exfiltration risk ✅ How North Korean operatives use forged and stolen identities to infiltrate organizations as employees 🔑 Two questions your organization should be asking right now: Could your security team identify and secure internet-exposed PLCs, HMIs, and SCADA systems before an adversary does? Does your hiring process include controls to detect AI-generated documents, stolen identities, and malicious job applicants ? 👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree
Fully autonomous attacks are here. AI agents escape a test environment, exploit zero-days, coordinate through shared infrastructure, and breach a production company—generating more than 17,000 security events along the way. Elsewhere, another model autonomously publishes malware to PyPI, while AI agents target real open-source developers with tailored social engineering. Join hosts John Dilgen and Tehman Tariq as they break down: ✅ How AI agents escaped containment and compromised Hugging Face infrastructure ✅ Why Claude’s autonomous PyPI attack signals growing software-supply-chain risk ✅ How coordinated AI agents deceived real developers 🔑 Two questions your organization should be asking right now: Could your SOC investigate and contain 17,000 coordinated events at machine speed ? What deception controls do you have in place to slow an AI agent attack? 👉 Tune in for expert insights and practical takeaways: ShadowTalk – ReliaQuest 👉 Find more podcast platforms, resources, and our listener feedback survey: ShadowTalk Official: X | Linktree
An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now. Join hosts Brandon Tirado and John Dilgen as they break down: How The Gentlemen's pre-packaged affiliate kit drove 580% leak-site growth Why Deadlock's Polygon blockchain C2 defeats network defenses Clop's latest campaign targeting an industrial enterprise application Two questions your organization should be asking right now: Do you know exactly where your EDR coverage ends ? If a critical vendor were compromised tonight , would you hear it from them first — or from your own monitoring? John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado : Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token. Join hosts Alexandra Moore and John Dilgen as they break down: How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentication traffic Why hardcoded DNS, opportunistic encrypted DNS, and MFA may not stop the attack How device-code phishing and WPAD abuse expand the campaign’s reach Practical defenses—including always-on, full-tunnel VPN, strict-mode encrypted DNS, and Conditional Access controls Two questions your organization should be asking right now: Does your always-on VPN tunnel all DNS and authentication traffic , or do split-tunneling exceptions leave traveling employees exposed? Who is permitted to authenticate through the device-code flow , and does each exception have a legitimate business justification? John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up. Join hosts Alexandra Moore and John Dilgen as they break down: How new extortion group Helix and ClickFix are weaponizing identity compromise at scale Why 622 vulnerabilities in a single week signals a permanent shift in the discovery rate Practical defenses for both fronts without doubling your team Two questions your organization should be asking right now: Have you audited which accounts in your environment are permitted to authenticate via device code grants and restricted the ones that don't need it? Does your IR runbook hunt for additional compromised accounts, or does it stop at the one sending extortion demands? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven days. Join hosts Tehman Tariq and John Dilgen as they break down: The mechanics behind FortiBleed and what made it so effective at scale How the IAB market has turned stolen credentials into a premium product Why identity drift and non-human identities are becoming attackers' favorite targets Two questions your organization should be asking right now: Does your credential compromise runbook treat session termination as the first step — or is password rotation all that's covered? Can your team name the owner and rotation schedule for your top 10 most privileged non-human identities? Resources: https://linktr.ee/ReliaQuestShadowTalk Tehman Tariq : Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
When 300,000 internal messages from the world's most prolific ransomware gang were leaked, they exposed more then a shadowy underground network, a full company. HR departments. Conti operated with the structure of a mid-sized software firm, and that changes how defenders need to think about the ransomware landscape today. Join host John and special guest Geoff White , journalist and author of Rinsed , as they discuss: How Conti's internal org chart compares to a legitimate software company The human cost of ransomware targeting critical infrastructure Why ransomware groups keep splintering and rebuilding Two questions your organization should be asking right now: When your team thinks about ransomware, are they thinking about a criminal enterprise with structure, funding, and KPIs — or just a hacker in a hoodie? Does your incident response plan account for a negotiation with operators who already know your financials? Resources: https://linktr.ee/ReliaQuestShadowTalk Geoff White: One of the world's leading journalists covering organized crime and technology, with decades of experience investigating fraudsters, hackers, and money launderers. His work has been featured by BBC News, Sky News, Audible, and The Sunday Times , and he has delivered over 300 keynote talks across more than a dozen countries for global brands including Microsoft, HSBC, and Mastercard. He is the author of three books, including The Lazarus Heist — which spawned a hit BBC podcast that ranked number one in the UK Apple charts — and his latest, Rinsed (2024), which The Financial Times called "Riveting." Geoff brings a rare investigative lens to cybercrime, giving ShadowTalk listeners an inside look at the criminal enterprises shaping today's threat landscape. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
AI is not replacing threat actors, instead it is making them faster, cheaper, and harder to stop. From AI powered phishing campaigns generating thousands of pages simultaneously, to a newly discovered macOS implant called Gaslight that injects fabricated system error messages into AI powered triage pipelines, the arms race between attackers and defenders is accelerating. The question is not whether AI is being used against your organization. It is whether your defenses are keeping pace. Join hosts Brandon and John as they discuss: How threat actors are leveraging AI across social engineering and malicious code generation The Gaslight macOS malware with anti-AI analysis tactics What organizations need to do right now to match attackers Two questions your organization should be asking right now: • How long does it actually take your team to detect and contain a critical severity alert? • Are your detections layered across enough diverse log sources? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado : Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
In the Klue compromises threat actors walked in through a trusted integration, using legitimate credentials to quietly siphon Salesforce CRM data at scale. The challenge isn't just responding to Klue. It's recognizing that every OAuth-connected integration in your environment is part of your attack surface. Join hosts Alexandra and John as they discuss: How compromised Klue integrations were leveraged to exfiltrate Salesforce CRM data Attribution and what it signals about the evolving data extortion landscape How Oauth token and device code theft is growing Two questions your organization should be asking right now: How many third-party integrations in your environment have active OAuth access to platforms holding critical data — and when were they last audited? Do you have detections in place for unusual Salesforce API query volume and service account behavior that could signal an active exfiltration? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
ShinyHunters dominated headlines this week: a zero-day, a BreachForums listing, and unverified claims all hitting at once. The problem isn't just keeping up with the volume. It's knowing which of it is real, which is noise, and what your team actually needs to act on. Join hosts Tehman and John as they discuss: ShinyHunters zero-day exploitation of CVE-2026-35273 Why a BreachForums listing extends the threat well beyond the initial compromise What proactive, resource-development-stage detection looks like in practice Two questions your organization should be asking right now: Is your Oracle PeopleSoft Environment Management Hub internet-facing? Do you have dark web and criminal forum monitoring in place to detect before the attack begins? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq : Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs.
Your team built defenses around known China-linked clusters. The file hashes are tracked. The behavioral patterns are documented. What those weren't built to catch is a new cluster that studied those exact defenses and engineered around them. A China-linked attacker compromised an internet-facing IIS server, maintained access for over 75 days, and came back on fresh infrastructure. With four China-linked clusters converging on the same legacy IIS stack in twelve months, defenders building detection programs around yesterday's cluster are already behind the next one. Join hosts Alex and John as they discuss: How OP-512 engineered its tooling to evade defenses Why killing a malicious process is incomplete What advantage cross-source correlation provides Two questions your organization should be asking right now: When your detection sources each generate a separate low-confidence signal from the same host, does anything in your current workflow correlate those signals automatically? Do you have internet-facing IIS servers running end-of-life .NET in your environment, and does your vulnerability-management workflow prioritize correctly? Resources: https://linktr.ee/ReliaQuestShadowTalk Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
Your team patches the device. The firmware version matches the advisory. The ticket closes. The device comes off the remediation queue. What your workflow never tracked is that the advisory also required six manual LDAP configuration steps — and without them, the authentication bypass still works. An initial access broker authenticated through the VPN, reached a domain-joined file server, and was gone in under 40 minutes. Your dashboard still showed a clean queue. With initial access brokers operating on disciplined, sub-hour timelines and patch-management workflows built around a single completion step, defenders are closing tickets on devices that are still wide open. Join hosts Tehman and John as they discuss: How a firmware update can still leave a device fully exploitable How initial access brokers progressed their attack in under 40 minutes Why teams that prioritize from a single vulnerability score alone are behind Two questions your organization should be asking right now: Does your patch-management workflow include a separate item for post-patch manual configuration requirements? When CISA, NVD, and the vendor publish different CVSS scores for the same CVE, does your vulnerability-management policy specify which authority takes precedence — and does it supplement static scoring with a dynamic signal like EPSS? Tune in for expert insights, practical takeaways, and the full threat report: https://linktr.ee/ReliaQuestShadowTalk Tehman Tariq : Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. John Dilgen: John Dilgen is a Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
Your user clicked a link, landed on a real Microsoft login page, typed their password, completed MFA, and walked away thinking nothing happened. Somewhere across the internet, an attacker's device just received an authenticated session token. The password is irrelevant. The MFA prompt already fired and passed. With PhaaS platforms now converging on token-theft tradecraft and post-compromise automation executing in seconds, defenders are racing a scripted attacker with a manual playbook. Join hosts Brandon and John as they discuss: How device code phishing uses real authentication infrastructure to capture valid session tokens How one campaign hit 35,000+ users across 13,000+ organizations in 26 countries Why rogue device registrations complete before the average analyst reads the alert Two questions your organization should be asking right now: Has your Conditional Access policy been reviewed specifically for device code grant flows, not whether CA policies exist, but whether they cover the OAuth flows that session-token theft actually exploits? When a phishing confirmation fires, how many manual steps stand between that alert and full token revocation with rogue device deregistration, and is that response faster than the attacker's automation? Resources: https://linktr.ee/ReliaQuestShadowTalk Brandon Tirado : Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.
What happens when an AI agent uncovers a zero-day in hours instead of weeks, and state-backed groups are already operationalizing the same tools? With self-hosted AI infrastructure sprawling outside asset registers and supply chain worms reaching inside AI vendors themselves, defenders need a new operating model. Join hosts Tehman and John as they discuss: How an AI agent surfaced a memory-safety zero-day in SQLite How Mini Shai-Hulud reached Mistral AI and OpenAI devices Why the intel-to-action chain still runs at multi-day tempo Two questions your organization should be asking right now: Do you have visibility into the shadow AI infrastructure, self-hosted models, and inference endpoints sitting unauthenticated on your network? When high-confidence intel lands, what's your median time from "advisory published" to "response action executed"? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Tehman Tariq : Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs.
What's driving the surge in weekly supply chain attacks, and why does the real defender problem start after the supplier gets hit? With 275 million records exposed and 8,809 institutions caught in the downstream fallout, organizations need a new playbook. Join hosts Alexandra and John as they discuss: How ShinyHunters abused admin sessions RansomHouse's hypervisor-focused automation How Mini Shai-Hulud compromised 170+ npm packages Two questions your organization should be asking right now: Do you have visibility into how trusted vendors authenticate, export, and move your data through native platform features? Are your software pipelines protected against poisoned packages and unauthorized publishing activity in real time? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
What factors have driven the top ransomware and extortion groups' success in early 2026? And how should organizations structure their defenses to protect against them? Join hosts Alexandra and John as they discuss: How Akira is exploiting unknown assets inherited through M&A Why ShinyHunters' vishing and SaaS misconfiguration models work How The Gentlemen grew 588% quarter-over-quarter Two questions your organization should be asking right now: Have you run a full asset discovery sweep on every environment inherited through acquisition in the last few years? Do you have automated containment rules in place for anomalous MFA device enrollment and EDR-killing behavior? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 minutes. The tactic has been automated, refined, and is now running faster than most SOCs can respond. Join hosts Alexandra and John as they discuss: How attackers leverage Microsoft Teams phishing to target high-privilege accounts with alarming speed Why automation is compressing attack timelines and sharpening target selection The controls that can stop it, from help desk verification to automated containment workflows Two questions your organization should be asking right now: When IT requests remote access to a senior leader's endpoint, is identity verified through a channel separate from the one the request came from? Do your highest-privilege accounts have dedicated automated containment workflows — or are they the gap in your response playbook? Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.
89% of organizations that suffered a SaaS breach last year believed they had appropriate visibility. They had the logs — what they lacked was detection on what mattered. The Vercel incident shows exactly how costly that gap can be. Join hosts Brandon and John as they discuss: How a third-party OAuth chain may have exposed Vercel's internal data Why SaaS visibility gaps leave organizations exposed The controls that can break the attack Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado : Director of GreyMatter Operations for ReliaQuest. Brandon is a skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 13, 2026. Cached outside the daily freshness window; the positions keep the date they were taken on.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.