Threat Talks - Your Gateway to Cybersecurity Insights

Threat Talks

Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!

  1. 17h ago

    How a 19-Year-Old Hacked the NEWS Without Breaking In

    Your Outlook account recovery will accept an authenticator code on its own. No password, no inbox, no phone number. Anyone holding that TOTP secret owns the account, and the second factor you bought to survive credential theft becomes the only thing in the way. Koen Kandelaars found one sitting in a PDF on a public help page at the NOS, the largest news organization in the Netherlands. He scanned a QR code out of an onboarding manual and had a real employee's second factor on his phone.  Rob Maas, Field CTO at ON2IT, walks the full chain with the attacker himself: eleven vulnerabilities in the first responsible disclosure, a twelfth Koen estimates at 1 to 5 million euros, and the recovery flow nobody tested. Timestamps (00:00) - MFA was on. He got in anyway. (02:04) - Why the biggest news organization became the target (03:24) - Mapping the attack surface before touching anything (04:54) - Eleven findings in the first responsible disclosure (08:50) - The Media Cloud help page and the live TOTP QR code (11:19) - How the password reset removes your second factor (14:29) - The 1 to 5 million euro estimate, and what to fix Key Topics Covered Attack surface discovery against a large public broadcasterResponsible disclosure done well: response time, remediation, and recognitionWhere the next generation of defenders comes from, and how they choose a sideRelated ON2IT Content & Referenced Resources: Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams

    How a 19-Year-Old Hacked the NEWS Without Breaking In
  2. Sep 1

    NIST CSF 2.0: No CISO, No Excuse

    The new NIST Cybersecurity Framework 2.0 is out, and most teams still ask the same question: what do I do tomorrow? Lieuwe Jan Koning sits down with NIST's Amy Mahn and Daniel Elliott to turn the framework into a concrete next step. Governance is now its own function. Profiles tell you where you are and where you need to be. And the Quick Start Guides give a 15-page answer to a problem most people think needs 300 pages. If you run security with limited resources, this episode shows you where to start and why the whole thing is free. Timestamps 00:00:00 The framework changed. What do you do tomorrow? 00:02:00 Why Govern became its own function 00:05:49 Profiles: current state, target state, gap analysis 00:08:08 Community profiles: sharing across a sector 00:10:29 Quick Start Guides and mappings to ISO 27001, SOC 2, HIPAA 00:14:24 No CISO? Where small businesses start 00:17:50 The future of CSF and how to contribute Key Topics Covered Why governance moved out of "Identify" and became its own function in CSF 2.0, and what that signals about cyber risk at board level.How organizational and community profiles turn the framework into a current-state, target-state, and gap analysis you can act on.Why CSF 2.0 stopped being a single PDF and became guides, spreadsheets, mappings, and search tools.How CSF maps to ISO 27001, SOC 2, and HIPAA so you report once instead of many times.Where a small business or an IT manager wearing every hat should actually begin.Related ON2IT Content & Referenced Resources:  NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework NIST CSF Quick Start Guides: https://www.nist.gov/cyberframework/quick-start-guides National Cybersecurity Center of Excellence (NCCoE): https://www.nccoe.nist.gov/ NIST CSF contact: csf@nist.gov Threat Talks website: https://threat-talks.com/

    NIST CSF 2.0: No CISO, No Excuse
  3. Aug 4

    The Hacker Who'll Hit You in 5 Years Is in School

    The hacker who will attack your organization in five years is in primary school right now, and nobody is teaching them anything. Tim Murck, Co-founder & Chief Product Officer at HackShield, joins Lieuwe Jan Koning, Co-founder & CTO at ON2IT, to explain how a game turns kids aged 7 to 12 into junior cyber agents instead of future attackers.  The method is not fear. It is teaching kids to ask one question: how are they going to trick me? 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: https://threat-talks.com/the-hacker-wholl-hit-you-in-5-years-is-in-school/🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #cybersecurity #hackshield #securityawareness #cybereducation #kidsonlinesafety Charpters: 00:00:00 The hacker who will attack you is in school now 00:00:27 From actor to HackShield: meet Tim Murck 00:02:00 The mission: digital scouting for kids 7 to 12 00:03:53 Junior cyber agents and the Dutch police 00:05:26 Inside the HackShield universe 00:10:02 Adversarial thinking and the grooming theme 00:13:35 Why age 7 to 12, and the school system's blind spot 00:14:53 Ban phones, or teach kids to swim? 00:18:42 The numbers: half a million Dutch kids, 850,000 worldwide

    The Hacker Who'll Hit You in 5 Years Is in School
  4. Jul 28

    JADEPUFFER: The AI Malware With No Human in the loop

    What if AI stopped being the assistant to cybercriminals and became the attacker itself? That's no longer hypothetical. JADEPUFFER is the first documented case of ransomware run entirely by an AI agent: it broke into a production database, hit a wall mid-attack, then found another way in within 31 seconds, faster than most human penetration testers can react. Rob Maas, Field CTO at ON2IT, sits down with Yuri Wit, SOC DevOps Engineer at ON2IT, to trace how agentic malware evolved out of AI-assisted attacks into a threat that plans, executes, and pivots entirely on its own. 🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: 🎙️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday. #ThreatTalks #ZeroTrust #firewallsecurity  #NetworkSecurity #CyberSecurity #infosec  Charpters: 00:00:00 Cold open: can AI become the attacker?00:01:42 PromptLock and PromptSteal: proof of concept to real world00:04:24 The agentic malware trend and the local LLM question00:07:24 JADEPUFFER: ransomware run entirely by an AI agent00:09:58 Proof of concept, or a live-fire test?00:11:30 Intent-driven attacks and shrinking detection windows00:16:34 Zero Trust: what to do about it starting now 🔔 Follow and Support our channel! 🔔=== ► YOUTUBE: https://youtube.com/@ThreatTalks► SPOTIFY: https://open.spotify.com/show/1SXUyUEndOeKYREvlAeD7E► APPLE: https://podcasts.apple.com/us/podcast/threat-talks-your-gateway-to-cybersecurity-insights/id1725776520 👕 Receive your Threat Talks T-shirthttps://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX

    JADEPUFFER: The AI Malware With No Human in the loop

About

Threat Talks is your cybersecurity knowledge hub. Unpack the latest threats and explore industry trends with top experts as they break down the complexities of cyber threats. We make complex cybersecurity topics accessible and engaging for everyone, from IT professionals to every day internet users by providing in-depth and first-hand experiences from leading cybersecurity professionals. Join us for monthly deep dives into the dynamic world of cybersecurity, so you can stay informed, and stay secure!

You Might Also Like