Skip to content
Artwork for Talos Takes

Talos Takes

Cisco Talos

Every two weeks, host Amy Ciminnisi brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic. We cover everything from breaking news to attacker trends and emerging threats.

Play
  • 20 episodes
  • fortnightly
  • Avg 23 min
  • English
  • Wednesday · 23 min

    Back-to-school cybersecurity: Protecting education networks from ransomware and threats

    As the new academic year begins, school districts face a surge in cybersecurity threats, from phishing attacks and ransomware to student experimentation with network devices. In this episode, Amy sits down with Cisco Talos expert Pierre Cadieux to discuss practical strategies for IT practitioners. How do you strengthen your defenses while managing the delicate balance between security and classroom usability? Here are the most high-priority steps to keep your district safe this semester. Prioritizing patches episode: https://www.buzzsprout.com/2018149/episodes/19360999

    • Transcript
  • August 12 · 22 min

    Don't scan that! QR code phishing and cloud-native threats

    What happens when a QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Attackers are ditching traditional malware for "cloud-native" tactics — using personalized QR code phishing to bypass corporate defenses and operate entirely within the cloud. Beyond the technical details, Amy and Terryn chat about the pressure of defending environments where patient care is on the line and why a blameless culture is a great defense. Take a listen for some practical, down-to-earth advice on how to audit your own logs and keep your team prepared for when things go sideways. Talos IR Trends Q2 2026: https://blog.talosintelligence.com/ir-trends-q2-2026/

    • Transcript
  • July 29 · 15 min

    Q2 Talos IR Trends: Phishing and authentication abuse spike

    In this episode, Amy and analyst Lexi DiScola unpack the trends Talos IR saw on the frontlines in Q2 2026. From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, we explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage. What configuration changes and visibility gaps could be the difference between a minor incident and a full-scale breach? How can you harden your environment with limited resources? Tune into this episode to stay one step ahead of an evolving threat landscape. Talos IR Quarterly Trends Report: https://blog.talosintelligence.com/ir-trends-q2-2026 Find Talos at Black Hat: https://blog.talosintelligence.com/preview-cisco-talos-at-black-hat-usa-2026/

    • Transcript
  • July 15 · 18 min

    ARToken: How attackers are bypassing MFA and maintaining access

    MFA and password resets aren't always enough. That’s terrifying for security teams today. In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing/BEC-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset. This turns a simple phishing click into a long-term breach. It’s time to rethink your defenses. Join us as Cisco Talos Threat Researcher Michael Kelley breaks down how this new breed of automated attack works and, more importantly, how you can spot it. From hunting for suspicious device authorization grants to securing your cloud infrastructure, don't miss this critical look at the new frontier of business email compromise. Blog: https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/

    • Transcript
  • July 2 · 18 min

    From evasion to detection: A guide to analyzing COM-based threats

    While the Component Object Model (COM) is a fundamental Windows technology that allows software to communicate and function, it's also a powerful tool for threat actors looking to move laterally, maintain persistence, and evade traditional security measures. Joining us is Vanya Svajcer, who shares his expertise on how to cut through the noise and identify malicious signals within COM-based binaries. Whether you are a seasoned researcher or just starting your journey into reverse engineering and malware analysis, here's some practical advice on how to start hunting for COM-based threats and making your next investigation a little more effective. Vanja's blog: https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threats

    • Transcript
  • June 18 · 23 min

    Patching in the dark: Managing unknown threats in complex environments

    If you're tired of being told to "just patch," we understand. The threat landscape is evolving at breakneck speed, with AI-driven tools enabling adversaries to uncover and exploit vulnerabilities before defenders even know they exist. In this episode of Talos Takes, Amy sits down with Threat Intelligence Lead Pierre Cadieux to discuss how to defend against these unknown threats. We move past the simplified advice of "just patch everything" to explore the logistical, technical, and business realities that make patching a complex, high-stakes operation rather than a simple button click. From the necessity of testing your patches to the importance of building strong partnerships between security teams and business leadership, this episode breaks down the things defenders often miss that build true resilience in organizations.

    • Transcript
  • June 3 · 19 min

    When synthetic logs don’t lie: Generating coherent attack stories for better detection

    Are your detection rules failing because your test data lacks the nuance of a real-world network? In this episode of Talos Takes, Amy sits down with David Bianco to discuss why traditional synthetic data often falls short and how his new open-source project, EvidenceForge, is changing the game. Synthetic datasets often look like telemetry but lack the critical causal links and realistic background noise that define actual adversary activity. EvidenceForge solves this by creating data that tells a coherent, causal story. From simulating complex attack chains to modeling realistic, "bursty" human behavior, this tool helps threat hunters and detection engineers to sharpen their skills with reproducible, high-quality telemetry. EvidenceForge blog: https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-fake/ PEAK Threat Hunting Assistant episode: https://www.buzzsprout.com/2018149/episodes/18825324

    • Transcript
  • May 7 · 20 min

    The trust paradox: How attackers weaponize legitimate SaaS platforms

    In this episode of Talos Takes, Amy Ciminnisi sits down with researcher Diana Brown to discuss the rise of "platform-as-a-proxy" (PAP) attacks. We explore how threat actors are weaponizing legitimate SaaS platforms like GitHub and Jira to deliver phishing campaigns that bypass traditional security filters. By leveraging the platforms' own infrastructure to send authenticated emails, attackers are exploiting the inherent trust employees place in these essential business tools. We break down the mechanics of these campaigns and provide actionable strategies for security teams to move beyond binary trust and implement contextual awareness to better protect their organizations. Blog: https://blog.talosintelligence.com/weaponizing-saas-notification-pipelines/

    • Transcript
  • April 21 · 28 min

    It's not you, it's your printer: State-sponsored and phishing threats in 2025

    In this episode, we unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. Amy and Martin Lee explore the alarming rise of internal phishing campaigns that bypass traditional perimeter defenses, including the widespread weaponization of Microsoft 365's Direct Send feature. Beyond simple phishing, we analyze the aggressive, blended operations of state-sponsored actors from China and North Korea who are combining high-level zero-day exploits with sophisticated social engineering. From the "Dear Leader" interview test to the reality of fake developer personas, we break down exactly how these adversaries are infiltrating modern organizations. 2025 Year in Review report: https://blog.talosintelligence.com/2025yearinreview/

    • Transcript
  • April 7 · 22 min

    2025's ransomware trends and zombie vulnerabilities

    In this episode, Amy and Pierre Cadieux unpack the ransomware and vulnerability trends that defined 2025. From the persistent ransomware threats targeting the manufacturing sector to the rise of stealthy "living off the land" tactics, we break down what these shifts mean for your defense strategy. Why are attackers are increasingly targeting your management infrastructure? How do you spot the difference between a system admin and a threat actor? Tune in to hear Talos' insights on how to move beyond reacting to threats and start building a more resilient, proactive security posture for the year ahead. View the 2025 Year in Review here: https://blog.talosintelligence.com/2025yearinreview/

    • Transcript
  • March 26 · 31 min

    Cybersecurity’s double-header: 2025 insights from Talos and Splunk

    In this episode of Talos Takes, Amy is joined by William Largent (Cisco Talos) and Lou Stella (Splunk) for a "double-header" discussion. With the recent release of the Cisco Talos 2025 Year in Review and the Splunk Top 50 Cybersecurity Threats report, we’re breaking down the most critical trends that shaped the security landscape last year — all based on Cisco telemetry, Talos' original research, and Talos Incident Response engagements. From the professionalization of ransomware-as-a-service to the persistent challenge of decade-old vulnerabilities, this episode moves beyond the headlines to provide a practical roadmap for defenders. You’ll get tips on how to prioritize your defenses and reduce your attack surface for the year ahead. Talos 2025 Year in Review: https://blog.talosintelligence.com/2025yearinreview/ Splunk Top 50 Cybersecurity Threats: https://www.splunk.com/en_us/campaigns/top-50-security-threats.html

    • Transcript
  • March 12 · 23 min

    Modernizing your threat hunt

    In this episode of Talos Takes, David Bianco from Cisco Foundation AI joins Amy to demystify the world of proactive cyber defense. We explore the evolution of the PEAK Threat Hunting framework and talk through how security teams can modernize their approach to identifying risks before they escalate. David also provides an exclusive look at a new open-source tool designed to help hunters navigate the "prepare" phase of PEAK with ease. Whether you are building a new program from scratch or looking to refine your existing strategy, take a listen for actionable advice to help you take that next step in your security journey. PEAK Threat Hunting Assistant: https://blogs.cisco.com/security/introducing-peak-threat-hunting-assistant GitHub: https://github.com/cisco-foundation-ai/PEAK-Assistant

    • Transcript
  • February 26 · 29 min

    Holding the line: Service provider security

    Service providers are the backbone of modern connectivity — but why are they such attractive targets for cyber actors, and what happens when critical networks go down? In this episode, Martin Lee joins Amy to explore the shifting threat landscape for service providers, asking how defenders can spot silent intrusions, what trade-offs must be considered when patching, and how industry collaboration helps prevent widespread disruptions. Join us as we unpack real-world examples and offer practical insights into protecting the infrastructure that keeps our world connected. Video: Footholds in Infrastructure: Protecting Service Providers

    • Transcript
  • February 12 · 13 min

    IR Trends Q4 2025: Ransomware chills and phishing heats up

    What separates organizations that successfully fend off ransomware from those that don’t? What were the top threats facing organizations? Can we (pretty please) get a sneak peek into the 2025 Year in Review? Amy is joined by Dave Liebenberg, Strategic Analysis Team Lead, to break down key findings from Q4 2025's Cisco Talos Incident Response Quarterly Trends Report. From the top threats facing organizations — like the persistent exploitation of public-facing applications and the rise of new vulnerabilities such as Oracle EBS and React2Shell — to the unexpected drop in ransomware cases, this episode is packed with useful info. Episode resources: Q4 2025 Quarterly Trends Report: https://blog.talosintelligence.com/ir-trends-q4-2025/ Qilin blog: https://blog.talosintelligence.com/uncovering-qilin-attack-methods-exposed-through-multiple-cases/ Cybersecurity on a Budget blog: https://blog.talosintelligence.com/cybersecurity-on-a-budget-strategies-for-an-economic-downturn/

  • January 28 · 27 min

    Cracking the code: What encryption can (and can’t) do for you

    Step into the fascinating world of cryptography. Host Amy Ciminnisi sits down with Yuri Kramarz from Cisco Talos Incident Response and Tim Wadhwa-Brown from Cisco Customer Experience to learn what encryption really accomplishes, where it leaves gaps, and when defenders need to take proactive measures. Whether you’re picturing classic codebreakers or the latest quantum-proof ciphers, this episode unpacks the essentials: what encryption and hashing actually mean, why key management is a make-or-break factor, and how even the best algorithms can fall short if the basics aren’t handled right. G7's "Coordinating the Transition to Post-Quantum Cryptography in the Financial Sector" roadmap: https://home.treasury.gov/news/press-releases/sb0355

  • January 15 · 27 min

    Cybersecurity certifications and you

    Get ready for a brand-new era of Talos Takes! In the first episode of the year, Amy Ciminnisi, Talos’ Content Manager and new podcast host, steps up to the mic with Joe Marshall to explore certifications, one of cybersecurity’s overwhelming (and sometimes most controversial) topics. We dive into the world of vendor-specific and vendor-agnostic certs, the value they can bring to your career, and the barriers people often face to getting certified. Whether you’re a newcomer facing the sea of choices and feeling some analysis paralysis or a seasoned pro plotting your next move, this episode may just motivate you to tackle your next certification with confidence. Cybersecurity certification roadmap: https://pauljerimy.com/security-certification-roadmap/

    • Transcript
  • Dec 18, 2025 · 45 min

    2015 vs 2025: What the Last Decade of Threats Taught Us

    In this special, end-of-year episode (and Hazel’s final show as host) Talos Takes goes on a time-travel adventure: What would a defender from 2015 think of the cybersecurity realities of 2025? Joined by Talos teammates Pierre Cadieux, Alex Ryan, and Joe Marshall, we compare the threats, tools, and challenges of 2015 with those of 2025. The team recalls where they were in their careers a decade ago, then dives deep into how ransomware has evolved, how APTs and state sponsored attacks have shifted, and why identity has become the new battleground for attackers and defenders alike. They discuss the impact of AI on both sides of the security equation, share what they miss from “the good old days,” of 2015, and offer practical advice for defenders facing the challenges of 2026 and beyond.

  • Nov 25, 2025 · 24 min

    When You’re Told “No Budget”: The Blueprint for Staying Secure

    What happens when your to-do list keeps growing but your budget doesn’t? Hazel is joined by three Cisco Talos Incident Response experts to talk about the reality many organizations face: rising threats, aging infrastructure, and fewer people to defend it all. From configuring what you already have, to open-source strategies, to the impact of cybersecurity layoffs, this episode is packed with practical guidance for securing your organization during an economic downturn. Resources mentioned: https://blog.talosintelligence.com/cybersecurity-on-a-budget-strategies-for-an-economic-downturn/ https://blogs.cisco.com/news/doubling-down-on-resilient-infrastructure https://talosintelligence.com/incident_response

  • Nov 13, 2025 · 11 min

    How Attackers Use Your Own Tools Against You (IR trends Q3 2025)

    In this episode of Talos Takes Hazel sits down with Talos' Bill Largent and Craig Jackson to discuss the latest Cisco Talos Incident Response Quarterly Trends Report (Q3 2025). From a wave of Toolshell events, to a rise in post-exploitation phishing, and the misuse of legitimate tools like Velociraptor, this quarter’s cases all point to a theme: attackers are getting very good at living off what’s already in your environment. Read the full report at https://blog.talosintelligence.com/ir-trends-q3-2025/

  • Oct 24, 2025 · 15 min

    Passwordless Security: Debunking the Biggest Myths

    On this episode of Talos Takes, Hazel welcomes Cisco Duo experts Steven Leung and Tess Mishoe to bust the most common myths around passwordless security and multi-factor authentication (MFA). Discover why not all MFA is created equal, why passwordless doesn't mean less security, and the most seamless way to adopt passwordless solutions. Plus, learn the truth about how passwordless may affect compliance and audits, and whether passwordless really is more vulnerable to phishing.

Showing 1–20 of 20 episodes