Listen to Talos security experts as they bring their hot takes on current security topics and Talos research to the table. Along the way Hazel, Mitch, Matt and a rotating chair of special guests will talk about anything (and we mean anything) that's on their minds, from the latest YouTube trends to Olympic curling etiquette. New episodes every other Thursday.
Twenty-four hours before recording this episode, Martin Lee stopped being a Talos employee. Naturally, we made him come on the podcast anyway.
Martin talks about abandoning his early career aspirations of researching human viruses and curing cancer, so he could play on the internet. He also talks about how running very long distances in crazy conditions helps him to stop himself thinking about it.
He has some words of wisdom for aspiring practitioners, and why the rest of us should occasionally close our laptops and venture outside...dangerous business, we reckon.
Plus: Does saying please and thank you improve an AI’s answers? What did Agatha Christie have against Bletchley? And how quickly can a $245 million cryptocurrency theft unravel when someone starts buying Lamborghinis at a rate of one a day?
Martin's blog on 'Securing the unpatchable' can be found here https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/
Every week, our host brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic in just five or 10 minutes. We cover everything from breaking news to attacker trends and emerging threats.
Ah, the crisp fall air, brand-new books and backpacks, and the quiet irony of cybercriminals turning on each other to steal a few extra bucks.
Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. This browser-based attack tricks targets into injecting malicious code into their own sessions under the guise of exploiting a fictional vulnerability to earn crypto-profits.
While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security. Tune in to hear why it’s only a matter of time before these techniques turn from petty crypto-scams toward our enterprise supply chains, and how to protect your organization.
Blog: https://blog.talosintelligence.com/clickfix-moves-into-the-browser/