Przejdź do treści
PodcastyBiznesFuture of Threat Intelligence

Future of Threat Intelligence

Team Cymru
Future of Threat Intelligence
Najnowszy odcinek

119 odcinków

  • Future of Threat Intelligence

    Why the old phishing training is obsolete after deepfake attacks

    02.07.2026 | 42 min.
    Resource constraints, not attacker sophistication, are the biggest cyber threat facing state and local governments, and AI is widening the gap by making low-skill attackers faster and more convincing.
    In our latest episode of the Future of Threat Intelligence podcast, Randy Rose, VP of Security Operations and Intelligence, Center for Internet Security, shared how community defense, essential controls, and human verification hold the line as phishing and deepfake threat intelligence evolve.

    Topics discussed:
    Why resource constraints are the number one cybersecurity challenge for state and local governments

    How AI makes low-skill attackers faster while ransomware and phishing stay the top threats

    Mapping CIS Implementation Group 1 controls to top MITRE ATT&CK techniques to reduce risk

    Why traditional phishing training is obsolete after AI-written phishing and deepfake attacks

    How community defense turns one organization's attack into protection for thousands

    Key Takeaways:
    Prioritize an essential set of controls, starting with CIS Implementation Group 1, to buy down the most risk against top threats like ransomware.

    Map your controls to the top MITRE ATT&CK techniques so you know which defenses deliver the greatest impact.

    Retire phishing training built on spotting typos and odd phrasing, and train people for general skepticism instead.

    Build proactive verification, such as two-person integrity, before trusting an email, phone call, or video feed.

    Inventory access alongside hardware and software, tracking who and what has access to what, including AI and agent tools.

    Maintain and exercise an updated incident response plan, and know exactly who to call in each scenario.

    Use AI for data translation, correlation, and enrichment at scale, and reserve creative thinking and context for people.

    Listen to More Episodes:  YouTube  •  Apple  •  Spotify  •  Website
  • Future of Threat Intelligence

    Coalition's Daniel Woods on the attorney-client privilege tactic shaping every IR investigation

    18.06.2026 | 42 min.
    Daniel Woods, Principal Security Researcher at Coalition, sits at an intersection most security practitioners never access: underwriting data, claims history, and live forensics findings from the same vantage point. In this conversation, he traces how cyber insurance evolved from a 10% loss ratio product in the late 1990s to carriers reportedly hitting 130%+ during the ransomware era, and what that financial pressure forced the market to actually build. He also explains the mechanics behind why lawyers end up directing IR investigations, who that structure protects, and why every practitioner who has ever written a forensic report should understand it before an incident forces the question.

    Topics discussed:

    Early cyber insurance economics and how a near-90% profit margin shaped the market

    How California's 2003 breach notification law created the data breach litigation economy

    How the shift from on-site auditors to yes/no questionnaires left insurers blind to whether backups were actually recoverable

    Why RDP as an initial access vector dropped from roughly 80-90% of ransomware claims to around 20%

    Why insurers put lawyers in front of IR investigations and what that means for what gets documented

    The unresolved legal problem with cyber war exclusions along the nation-state/criminal contractor continuum

    Why security practitioners should be in the room during the insurance buying process, not reacting to the vulnerability report afterward

    Why cyber insurance is a broad digital risk product and not just a ransomware backstop

    Key Takeaways:

    Get your security team into the insurance buying process before the vulnerability report arrives. Once it lands, you are in reactive mode with your carrier already holding findings.

    Insurers like Coalition built their underwriting model around external perimeter scanning, specifically flagging open RDP, VPNs without MFA, and exposed attack surface before they quote. That scan is happening whether your team engages with it or not. Use it.

    The backup question on an insurance application has moved well past yes or no. Insurers now ask about recovery time, maintenance cadence, and whether backups are actually tested. A tape environment that takes two months to restore is not a recovery capability and carriers know it.

    When a lawyer is directing your IR investigation, what goes into the forensic report is a legal decision, not just a technical one. Daniel's own interview research with lawyers found that technical practitioners routinely undermine the privilege structure by writing explicit characterizations of organizational failure, things like "flagrant culture of noncompliance," that lawyers cannot shield and litigants can use. Know what you are writing before an incident forces you to find out why it matters.

    Standalone cyber policies and property policies respond very differently to nation-state incidents. Cyber insurers paid out on Sony under standalone cyber. The war exclusion fights over NotPetya happened in property insurance courts. If your coverage mix includes both, those are not equivalent protections.

    The attribution problem cuts both ways. Nation-state actors contracting ransomware groups, or using financially motivated TTPs alongside espionage operations, make war exclusion clauses nearly impossible to apply cleanly. Know where your policy language actually draws that line.

    Cyber insurance covers more than breach response. Impersonation, deepfake fraud, and privacy violation liability are all coverable under the right policy structure. Most buyers do not realize that until they file a claim.

    Listen to more episodes: 
    Apple 
    Spotify 
    YouTube
    Website
  • Future of Threat Intelligence

    How Akira hits thousands of SMBs with $50K-$150K ransoms undetected | Alex Bovicelli

    04.06.2026 | 26 min.
    In part two of this conversation, Alex Bovicelli, Senior Director of Threat Intelligence at Tokio Marine HCC - Cyber & Professional Lines Group,  gets into what the industry keeps getting wrong about ransomware targeting. The organizations getting hit most often are not the ones making headlines, and the attack methods used against them require far less sophistication than most practitioners assume.
    Drawing from claims data across thousands of insured companies, Alex explains how groups like Akira have deliberately built around high-volume, low-ransom SMB campaigns, why unpatched MSP tooling is one of the most consistently exploited entry points most defenders aren't tracking, and how a low-tier threat actor sitting on an infected employee machine for six months can hand off access to a major ransomware group. He also breaks down how access brokers are assessing victim maturity, insurance policy status, and organizational structure to decide whether ransomware or BEC delivers the better return, which has nothing to do with CVSS scores.
    Topics discussed:
    Why SMBs face structurally different attacks than enterprises, not scaled-down versions

    Akira's volume-over-value model: ransoms in the $50K-$150K range, thousands of targets, below the threshold that attracts law enforcement attention

    Unpatched MSP tooling as a lateral movement vehicle the victim never sees coming

    How a low-tier threat actor's own machine was infected with an info stealer, exposing the 6-7 month timeline between initial access and ransomware deployment

    How access brokers assess victim maturity, insurance coverage, and org structure to choose between ransomware and BEC for maximum ROI

    Why criminal exploitability outweighs published vulnerability severity as a patching signal

    How cyber insurance claims data gives CTI teams visibility into active exploitation before it surfaces publicly

    Key Takeaways:
    Stop treating SMB ransomware exposure as a scaled-down version of enterprise risk. The attack methods, economics, and entry points are structurally different, and your defenses need to reflect that.

    Track SSL VPN brute forcing campaigns specifically. Groups like Akira have optimized these tools to run unattended and return thousands of valid credentials against organizations with no account lockout policies.

    Enforce account lockout policies and MFA on every remote access entry point. These aren't advanced controls. They're what separates organizations that get hit from those that don't at the SMB level.

    Audit your MSP's patch posture as part of your own risk assessment. If your MSP is running unpatched tooling, your organization inherits that exposure whether you know about it or not.

    Integrate info stealer log analysis into your detection pipeline. A low-tier threat actor's infected machine can expose a 6-7 month old foothold and reveal exactly how a major ransomware group obtained initial access.

    Understand that access brokers are evaluating your organization's maturity, insurance status, and whether you're centralized or decentralized before deciding whether to hit you with ransomware or BEC. Your structural profile affects how you get targeted.

    Replace CVSS as your primary patching prioritization signal. What access brokers actually care about is ease of exploitation combined with the number of available targets, and your patching sequence should mirror that logic.

    Use post-claim incident response data to validate and calibrate your pre-claim detection signals. Insurance claims data provides visibility into what is actively being exploited in the wild before it reaches the news cycle.

    Listen to more episodes: 
    Apple 
    Spotify 
    YouTube
    Website
  • Future of Threat Intelligence

    The CVSS problem: why severity scores don't predict what gets exploited

    21.05.2026 | 45 min.
    Patrick Garrity, Security Researcher at VulnCheck, has a data problem with how the industry prioritizes vulnerabilities, and the data is his own. After manually categorizing roughly 800 exploited vulnerabilities by technology type each year, what he keeps finding is that the CVSS severity distribution of exploited CVEs tracks closely with the overall CVE population. Meaning the scoring system most teams use to decide what gets patched first has no meaningful relationship to what threat actors are actually targeting. He hasn't yet sliced it fully by category, but what's already visible is enough to warrant rethinking your triage logic.
    He also walks through VulnCheck's exploitation velocity data: roughly 29% of exploited CVEs already have exploitation evidence on or before the day the CVE is published. His read on that number is direct if you're in that bucket, you're likely already compromised before you've had a chance to prioritize the patch.

    Topics discussed:
    Why the CVSS severity distribution of exploited CVEs mirrors the overall CVE population

    Exploitation velocity data: roughly 29% of exploited CVEs have evidence on or before CVE publish date

    How MFA adoption shifted threat actor focus from credential compromise to direct exploitation

    Tree map methodology for categorizing 800+ exploited vulnerabilities by technology type annually

    Cascading vulnerability research: how one high-profile exploit draws threat actors and researchers to adjacent products

    Source validation framework for assessing reliability across 118+ exploitation evidence reporters

    Vendor security-through-obscurity blocking defenders from building detections

    EU Cyber Resilience Act mandating 24-72 hour exploitation disclosure windows in 2026

    How Coalition uses vendor risk indices to set cyber insurance rates based on technology stack

    Key Takeaways: 
    If your remediation SLAs are gated on CVSS score, you're likely deprioritizing real exposure. Patrick's data shows the severity distribution of what gets exploited tracks the overall CVE population, not a cluster at the critical end.

    For any CVE where exploitation evidence predates the publish date, treat it as a probable breach, not a patching event. Patrick's framing: you're "likely already compromised." IR engagement should precede remediation, not follow it.

    When a major exploitation event lands on a product, immediately pull your full inventory for adjacent products in the same technology category. Both threat actors and researchers start looking at related products the moment a category gets attention.

    Audit your network edge devices for end-of-support and end-of-life status. Many of these products carry 20-30 years of tech debt and were never built with product security as a baseline consideration.

    When evaluating or renewing network security products, ask the vendor directly: what does your vulnerability disclosure process look like, and is patching automated? If remediation requires a manual change control window every time, that's a structural liability that compounds under pressure.

    Push back on vendors who restrict patch details or technical indicators to paying customers. Threat actors who already reversed the product don't need that information. Defenders who are trying to build detections do.

    Look at how insurance carriers like Coalition score your technology stack by vendor risk. If products you're running carry a high-risk rating in those indices, that's worth taking into a vendor conversation or a board briefing it's independent, data-backed validation that your exposure is real.

    Listen to more episodes: 
    Apple 
    Spotify 
    YouTube
    Website
  • Future of Threat Intelligence

    Unit 42's Andrew Rathbun on the Sysmon Configuration Mistake Enterprises Are Making

    07.05.2026 | 42 min.
    Andrew Rathbun, Senior Consultant at Palo Alto Networks Unit 42, has spent years tearing apart Windows endpoints across ransomware, APT, insider threat, and DPRK IT worker cases. His read on the state of enterprise Windows logging is blunt: most organizations have spent significant money on detection tooling while leaving the native forensic record so truncated that proving an intrusion timeline is nearly impossible. He introduces the "conveyor belt of volatility" as a forensic lens, every second, events fall off the back end of your log, and the default sizes Microsoft ships are a relic of 2002 disk economics. Accepting those defaults in a contemporary environment isn't a configuration oversight; it's a gift to the attacker.
    The conversation goes deep on the four artifacts Andrew calls his sysadmin Christmas list of Sysmon, the Security Event Log, Volume Shadow Copies, and the $J USN Journal, and why each is typically either absent, stale, or undersized when he arrives on a case. He also covers what DPRK IT worker cases look like from the endpoint, why EDR alert queues are generating true positives that go ignored for days, and how he actually uses AI on cases, including a specific example of generating a PowerShell script to convert Linux audit log epoch timestamps to human-readable time, a script he's been running in production for years.

    Topics discussed:
    The "conveyor belt of volatility" framework for understanding Windows event log retention

    Why accepting default log sizes actively shortens the forensic timeline available during incident response

    Why Sysmon's inclusion in Windows 11 is long overdue, how stale installations with outdated event IDs are a common unforced error in enterprise environments

    How volume shadow copies can extend forensic visibility across months of attacker activity

    The $J USN Journal as a file system ledger for every file creation, deletion, rename, and size change on a Windows partition

    Why EDR is a mandatory but insufficient control, including how alert fatigue causes true positives to be miscategorized as false positives

    What DPRK fake IT worker cases look like from the endpoint, including the forensic value of USB artifact timestamps

    How AI functions as a genuine force multiplier in DFIR while remaining unreliable as a source of authoritative forensic ground truth

    Why GitHub fluency, not tool mastery, is the foundational skill for anyone entering digital forensics

    Key Takeaways: 
    Size the Windows Security event log to at least 1 GB. The default 32 MB cycles 4624/4625 events fast enough that authentication history from the week before your incident is already gone.

    Deploy Sysmon and keep it current. Treat version currency as a security control.

    Size the $J USN Journal appropriately on all Windows partitions. It's a file system ledger of every create, delete, rename, and resize.

    Enable volume shadow copies and treat retention depth as a forensic asset. 

    Alert on event IDs 1102 and System 104. These signal security log and general event log clearing.

    Audit EDR queues for true positives closed as false positives.  

    Baseline USB artifact timestamps and KVM device registry entries on remote worker endpoints. 

    Use AI to parse unfamiliar log syntax and generate one-off scripts — not as forensic ground truth. 

    Don't assume EDR coverage eliminates the need for native Windows logging. They capture different visibility layers.

    Build GitHub fluency as a foundational DFIR skill.
Więcej Biznes podcastów
O Future of Threat Intelligence
Welcome to the Future of Threat Intelligence podcast, where we explore the transformative shift from reactive detection to proactive threat management. Join us as we engage with top cybersecurity leaders and practitioners, uncovering strategies that empower organizations to anticipate and neutralize threats before they strike. Each episode is packed with actionable insights, helping you stay ahead of the curve and prepare for the trends and technologies shaping the future.
Strona internetowa podcastu

Słuchaj Future of Threat Intelligence, The Diary Of A CEO with Steven Bartlett i wielu innych podcastów z całego świata dzięki aplikacji radio.pl

Uzyskaj bezpłatną aplikację radio.pl

  • Stacje i podcasty do zakładek
  • Strumieniuj przez Wi-Fi lub Bluetooth
  • Obsługuje Carplay & Android Auto
  • Jeszcze więcej funkcjonalności
Future of Threat Intelligence: Podcasty w grupie