ShadowTalk: Powered by ReliaQuest

ReliaQuest

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research. Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the most pertinent cyber threats.    With over 1,000 customers worldwide and 1,200 teammates across six global operating centers, ReliaQuest delivers security outcomes for the most trusted enterprise brands in the world. Learn more at www.reliaquest.com.

  1. 1 day ago

    From Data Dumps to Critical Findings: The New Era of Data Extortion

    Threat actors do not see old email archives, forgotten shared drives, and outdated CRM exports as clutter. They see them as searchable inventory. With AI-assisted analysis, attackers can rapidly identify sensitive communications, regulatory exposure, customer relationships, and credentials buried in stolen data. Join hosts John Dilgen and Brandon Tirado as they discuss: Why data theft has become a central component of modern extortion operationsHow AI and automation are helping attackers analyze hundreds of thousands of files at machine speedWhy “soft data,” including invoices and project documents, can fuel downstream fraud and social engineeringHow strong retention, credential-rotation, and OAuth-management practices reduce breach impactTwo questions your organization should be asking right now: How much data does your organization retain beyond its business or regulatory need?Could your team rotate hundreds of exposed credentials—not just one—before an attacker uses them?John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.

  2. 5 Aug

    The Gentlemen, Deadlock, and Clop: The Groups Driving Ransomware & Extortion in 2026

    An affiliate receives a ready-made intrusion kit — pre-compromised targets, an EDR killer, and a full deployment workflow included. No building from scratch. No long ramp-up. Just deploy, observe, and iterate. That's the future of ransomware; it's how the new number-one group operated in Q2 2026. And it's just one of three stories reshaping the extortion landscape right now. Join hosts Brandon Tirado and John Dilgen as they break down: How The Gentlemen's pre-packaged affiliate kit drove 580% leak-site growthWhy Deadlock's Polygon blockchain C2 defeats network defensesClop's latest campaign targeting an industrial enterprise application Two questions your organization should be asking right now: Do you know exactly where your EDR coverage ends?If a critical vendor were compromised tonight, would you hear it from them first — or from your own monitoring?John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Brandon Tirado: Director of GreyMatter Operations for ReliaQuest. A skilled cyber defense professional with a unique combination of management and hands-on experience. With a deep understanding of adversary motives and the tactics, techniques, and procedures (TTPs) they use to achieve their goals, Brandon enjoys operationalizing his knowledge to make it more difficult for adversaries to operate within the environments of ReliaQuest customers. His managerial and hands-on experience enriches ShadowTalk with practical and strategic viewpoints.

  3. 29 Jul

    Compromised Hotel Gateways, Fake Microsoft Domains, and the APT28-Adjacent Campaign That Bypasses MFA Without a Phishing Click

    An employee connects to hotel Wi-Fi, receives a familiar Microsoft 365 sign-in prompt, and authenticates. No phishing email. No malicious link. No suspicious attachment. Yet an attacker walks away with a valid, MFA-satisfied session token.  Join hosts Alexandra Moore and John Dilgen as they break down: How compromised hotel and conference-center Wi-Fi gateways silently redirect Microsoft authentication trafficWhy hardcoded DNS, opportunistic encrypted DNS, and MFA may not stop the attackHow device-code phishing and WPAD abuse expand the campaign’s reachPractical defenses—including always-on, full-tunnel VPN, strict-mode encrypted DNS, and Conditional Access controls Two questions your organization should be asking right now: Does your always-on VPN tunnel all DNS and authentication traffic, or do split-tunneling exceptions leave traveling employees exposed?Who is permitted to authenticate through the device-code flow, and does each exception have a legitimate business justification?John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

  4. 22 Jul

    The Largest Patch Tuesday Ever: 622 CVEs, a 1,380% Phishing Surge, and the Two-Front War on Initial Access

    Defenders aren't losing ground on one front, they're losing it on two at once. The largest Patch Tuesday in history just dropped alongside a 1,380% surge in phishing, and threat actors aren't waiting for you to catch up. Join hosts Alexandra Moore and John Dilgen as they break down:  How new extortion group Helix and ClickFix are weaponizing identity compromise at scale Why 622 vulnerabilities in a single week signals a permanent shift in the discovery ratePractical defenses for both fronts without doubling your team Two questions your organization should be asking right now: Have you audited which accounts in your environment are permitted to authenticate via device code grants and restricted the ones that don't need it?Does your IR runbook hunt for additional compromised accounts, or does it stop at the one sending extortion demands?Resources: https://linktr.ee/ReliaQuestShadowTalk John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest. Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

  5. 15 Jul

    FortiBleed, 70,000 Compromised Devices, and the Credential Economy Powering Every Breach

    When a 20-person team using AI, automated tools, and a list of default credentials compromised 70,000 devices across 194 countries they exposed how mature the criminal market behind credential theft has become. Initial access brokers are now packaging pre-validated enterprise access for an average of $113,000, and the window from information stealer infection to ransomware deployment is just seven days. Join hosts Tehman Tariq and John Dilgen as they break down: The mechanics behind FortiBleed and what made it so effective at scaleHow the IAB market has turned stolen credentials into a premium productWhy identity drift and non-human identities are becoming attackers' favorite targets Two questions your organization should be asking right now: Does your credential compromise runbook treat session termination as the first step — or is password rotation all that's covered?Can your team name the owner and rotation schedule for your top 10 most privileged non-human identities?Resources: https://linktr.ee/ReliaQuestShadowTalk Tehman Tariq: Sr. Manager of Cyber Operations at ReliaQuest. He has spent a majority of my career leading our Incident Response, Security Architecture, and Detection teams. As well has working hand in hand with CISOs to introduce automation allowing for the maturity of their security programs. John Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.

Ratings & Reviews

4.9
out of 5
18 Ratings

About

Want to hear what industry experts really think about the cyber threats they face? ShadowTalk is a weekly cybersecurity podcast, made by practitioners for practitioners, featuring analytical insights on the latest cybersecurity news and threat research. Threat Intelligence Analyst John Dilgen brings extensive expertise in cyber threat intelligence and incident response, specializing in researching threats impacting ReliaQuest customers. John and his guests provide practical perspectives on the week’s top cybersecurity news and share knowledge and best practices to help businesses mitigate the most pertinent cyber threats.    With over 1,000 customers worldwide and 1,200 teammates across six global operating centers, ReliaQuest delivers security outcomes for the most trusted enterprise brands in the world. Learn more at www.reliaquest.com.

You Might Also Like