Hoppa till innehållet
PoddsändningarNäringslivMicrosoft Threat Intelligence Podcast

Microsoft Threat Intelligence Podcast

Microsoft
Microsoft Threat Intelligence Podcast
Senaste avsnittet

78 avsnitt

  • Microsoft Threat Intelligence Podcast

    Why Threat Actors Love Your RMM

    2026-09-09 | 28 min.
    In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Brandt, Principal Threat Intelligence Incident Commander at Huntress.

    They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain access, shares stories from his years of interacting directly with threat actors and offers practical guidance for detecting suspicious RMM activity before it leads to ransomware or data theft.

    In this episode you’ll learn:

    How AI is making phishing lures and fake websites more convincing

    Why trusted remote-access software can evade traditional endpoint detection

    How security teams can identify and block unauthorized RMM activity

    Some questions we ask:

    What information are attackers looking for once they gain access?

    Why are attackers choosing legitimate tools instead of traditional malware?

    How does compromised access eventually lead to ransomware or data theft?



    Resources:

    Huntress report on RMM abuse

    View Andrew Brandt on LinkedIn

    View Elliot Volkman on LinkedIn



    Related Microsoft Podcasts:

    Afternoon Cyber Tea with Ann Johnson

    The BlueHat Podcast

    Uncovering Hidden Risks



    Discover and follow other Microsoft podcasts at microsoft.com/podcasts



    Get the latest threat intelligence insights and guidance at Microsoft Security Insider



    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.
  • Microsoft Threat Intelligence Podcast

    JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

    2026-08-26 | 31 min.
    In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding their growing AI infrastructure.



    In this episode you’ll learn:

    How Jade Puffer used an LLM to conduct a ransomware attack

    Why agentic AI can make cyberattacks faster and more adaptable

    How organizations can better protect their growing AI infrastructure

    Some questions we ask:

    How did you determine an LLM was conducting the attack?

    What basic security practices are most important against these attacks?

    Does AI allow less-sophisticated threat actors to carry out more advanced attacks?



    Resources:

    Read the research on JADEPUFFER

    View Crystal Morin on LinkedIn

    View Michael Clark on LinkedIn

    View Elliot Volkman on LinkedIn



    Related Microsoft Podcasts:

    Afternoon Cyber Tea with Ann Johnson

    The BlueHat Podcast

    Uncovering Hidden Risks

    Discover and follow other Microsoft podcasts at microsoft.com/podcasts



    Get the latest threat intelligence insights and guidance at Microsoft Security Insider



    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.
  • Microsoft Threat Intelligence Podcast

    Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report

    2026-08-12 | 24 min.
    In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director⁠ Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate.

    Crane also shares practical security recommendations for organizations and explains how Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform led to a dramatic decline in malicious activity while reshaping the broader phishing landscape.

    In this episode you’ll learn:

    How phishing attacks are evolving beyond email

    The security basics every organization should prioritize

    How attackers are exploiting Microsoft Teams and SMS

    Some questions we ask:

    What are you seeing in today's social engineering and phishing landscape?

    How impactful was the Tycoon 2FA disruption?

    Has Tycoon activity shifted elsewhere after the disruption?

    Resources:

    View Elliot Volkman on LinkedIn

    View Crane Hassold on LinkedIn

    Related Microsoft Podcasts:

    Afternoon Cyber Tea with Ann Johnson

    The BlueHat Podcast

    Uncovering Hidden Risks

    Discover and follow other Microsoft podcasts at microsoft.com/podcasts

    Get the latest threat intelligence insights and guidance at Microsoft Security Insider

    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.
  • Microsoft Threat Intelligence Podcast

    A Farewell from Sherrod: New Season Coming Soon

    2026-07-29 | 8 min.
    As we close out season three of the podcast, Sherrod offers her farewell message as she takes on a new threat intelligence leadership role outside of Microsoft. Our executive producer also joins to briefly share our plans for season four, with new faces and voices joining future episodes.
  • Microsoft Threat Intelligence Podcast

    Behind the Book: Threat-Driven Software Development

    2026-07-15 | 59 min.
    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by co-authors Michael Howard, Lee Holmes, and Shawn Hernan for a discussion on their new book, Threat-Driven Software Development: Defending Online Services from Modern Threat Actors.

    Together, they explore how security teams and software developers can build more resilient systems by understanding how real-world threat actors operate. From threat modeling and operational security to the evolving role of AI in both cyber defense and cybercrime, the conversation examines lessons learned from major security incidents and why secure design must be a priority from the earliest stages of software development.

    In this episode you’ll learn:

    Why security should be driven by real-world threat actor behavior

    How developers can reduce risk through better design and operational practices

    The role of threat modeling in modern software development

    Some questions we ask:

    How did the idea for Threat-Driven Software Development come about?

    Why is operational security just as important as application security?

    What do you hope readers take away from this book?

    Resources:

    View Lee Holmes on LinkedIn

    View Michael Howard on LinkedIn

    View Shawn Hernan on LinkedIn

    View Sherrod DeGrippo on LinkedIn



    Related Microsoft Podcasts:

    The BlueHat Podcast

    Uncovering Hidden Risks

    Discover and follow other Microsoft podcasts at microsoft.com/podcasts



    Get the latest threat intelligence insights and guidance at Microsoft Security Insider



    The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.
Fler podcasts i Näringsliv
Om Microsoft Threat Intelligence Podcast
Join us to hear stories from the Microsoft Threat Intelligence community as they navigate the ever-evolving threat landscape - uncovering APTs, cybercrime gangs, malware, vulnerabilities, and other weird and cool tools and tactics in the world of cyber threats. Featuring tales of innovation, teamwork, and cyber espionage, tune in to hear in-depth analyses of Microsoft's influence on the threat landscape and behind the scenes stories from the tireless researchers and analysts that take part. This enthralling and insightful podcast is delivered in a casual, conversational style that transports you to the frontlines of cyber defense.
Podcast-webbplats

Lyssna på Microsoft Threat Intelligence Podcast, Dagen med Di och många andra poddar från världens alla hörn med radio.se-appen

Hämta den kostnadsfria radio.se-appen

  • Bokmärk stationer och podcasts
  • Strömma via Wi-Fi eller Bluetooth
  • Stödjer Carplay & Android Auto
  • Många andra appfunktioner
Microsoft Threat Intelligence Podcast: Poddsändningar i Familj
  • Podcast Microsoft Partnerpodden
    Microsoft Partnerpodden
    Näringsliv, Teknologi, Utbildning
  • Podcast Behind The Tech with Kevin Scott
    Behind The Tech with Kevin Scott
    Teknologi, Utbildning
Sociala nätverk
v8.17.0 | © 2007-2026 radio.de GmbH
Generated: 9/18/2026 - 1:23:07 AM