Beers with Talos Podcast Threats, Beers, and No Silver Bullets. Listen to Talos security experts as they bring their hot takes on current security topics and Talos research to the table. Along the way, Mitch, Matt and a rotating chair of special guests will talk about anything (and we mean anything) that’s on their minds, from the latest YouTube trends to Olympic curling etiquette. New episodes every other Thursday.
- Black Hat 2024 previewby beerswithtalos@cisco.com (Cisco Talos) on August 1, 2024 at 8:00 am
It’s been a while huh? Apologies for our absence, but the team are back with a run through of everything we’ve got going on at Black Hat – from our 10 year birthday celebrations, the interesting lightning talks in our booth, and Joe Marshall’s “Backdoors and Breaches” game. Come and visit us at Cisco Booth 1732 and Splunk Booth 1940.Before that, Matt encourages Mitch and Lurene to join him in the joy of Tekkno Train by Electric Callboy (Choo Choo!) and Mitch explains why his son has developed a huge potty mouth, with no sense of irony. Lurene also reveals insights into creating a university curriculum for cyber weapons development.Stick around for an illumunating discussion on how AI could affect a Furby. Just don’t google “Long Furbie”. You just googled it didn’t you? Ah man, we warned you…
- Stories from the Power Gridby beerswithtalos@cisco.com (Cisco Talos) on April 11, 2024 at 8:00 am
Power grid security expert Joe Marshall joins the crew today to talk all things, well, power grid security. But not before he gets an impromptu pop quiz from Matt in the roundtable.Joe then tells some stories from his days working in electric utility, deploying new systems and his experiences with pentesting teams (“Wow, y’all need to stop!”). Plus, the team ask Joe about the risks with both aging infrastructure versus newer, smarter based infrastructure. And what happens when threat actors target critical infrastructure?
- The old people episodeby beerswithtalos@cisco.com (Cisco Talos) on March 21, 2024 at 12:00 pm
Matt, Mitch and Lurene discuss if the internet is better or worse today than it was 20 years ago. This leads them to discuss their various career paths, with Lurene talking about how she got into vulnerability exploitation and how Matt got into threat intelligence. And why neither of those paths would be recommended today. Lurene and Matt then clash about threat research and and the importance of approaching things from a “how do I be a problem” perspective.
- The Reverberations of Volt Typhoonby beerswithtalos@cisco.com (Cisco Talos) on February 22, 2024 at 9:00 am
You will no doubt have seen the advisories published over the last few weeks concerning Volt Typhoon’s malicious activities. In this episode, JJ Cummings joins the crew to discuss the background to this threat actor, their impact on the threat landscape, and the covertly strategic (and specific) nature of their operations. The team also discusses their recommendations for defenders, particularly for critical infrastructure organizations.The CISA statement on Volt Typhoon can be found here https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
- The Reddit Security Diariesby beerswithtalos@cisco.com (Cisco Talos) on February 14, 2024 at 9:00 am
Matt, Mitch and Lurene sit down to discuss ârandom stuff from Redditâ (donât be put off â theyâre all genuinely interesting security questions!). Topics range from password managers and how password security guidance has become outdated, how to âself-learnâ in cybersecurity, and thoughtful approaches towards security incidents. Before that, the team comes up with a prank to pull on their co-workers and bring some joy and chaos to Webex meetings. And Lurene reflects on what advice she would give high schoolers today. As Matt says at the end of the episode, we want to hear from you! Get in touch at beerswithtalos@cisco.comHere’s the video ‘Hi Ren’ that Matt mentions at the outset https://www.youtube.com/watch?v=s_nc1IVoMxc
- Talos Speed Dating (the episode we never set out to make but did anyway)by beerswithtalos@cisco.com (Cisco Talos) on December 20, 2023 at 9:00 am
Mitch, Matt and Lurene were almost about to be in the same physical space at the same time to record an episode, and then Lurene couldn’t make it…so we made this instead! Mitch is joined by Azim Khodjibaev from the Talos Threat Intelligence and Interdiction team to rapid-fire interview a bunch of Talos employees who happened to be around the Maryland office. Hear from teammates from all walks of life and areas of expertise about what they’ve loved working on in 2023 and how they feel their work has changed the broader security landscape.Â
- The TurkeyLurkey Man wants YOU to read the Talos 2023 Year in Review reportby beerswithtalos@cisco.com (Cisco Talos) on December 6, 2023 at 9:00 am
We recorded this episode AFTER Thanksgiving, so you’ll need to forgive us for the amount of Thanksgiving talk that doesn’t actually apply until Thanksgiving 2024. It all evens out in the end because the annual “Ranksgiving” from special guest David Liebenberg results in the creation of TurkeyLurkey Man. Then, TurkeyLurkey Man helps the rest of the gang recap the top malware and attacker trends from 2023. If you’d like to read more, download the full Talos Year in Review report here. We also discussed the recent CNN article and Talos blog post on our work to protect Ukraine’s power grid.Â
- Chicken Soup and Contact Centersby beerswithtalos@cisco.com (Cisco Talos) on November 2, 2023 at 8:00 am
It’s that time of the quarter again when we sit down to look at what we learned over the past three months. Caitlin Huey from the Talos Threat Interdiction Team joins the show for this special look at the latest Talos Incident Response Quarterly Trends report. Caitlin’s team helps compile these reports and digs through mountains of data to find out what defenders can learn from what Talos IR is seeing live in the field. If you want to learn more about this report, you can read it on our blog, or watch the Talos IR On Air video here.
- Who is Jacques Wagon?by beerswithtalos@cisco.com (Cisco Talos) on September 28, 2023 at 8:00 am
This episode of Beers with Talos has a very special guest: Our old friend Nigel Houghton. He’s one of the OG BWTers and is back with two-plus years’ worth of hot takes to get off his chest. Nigel starts out by delivering his long-awaited update on his beloved Mighty Red. But he, Mitch, Matt and Lurene do eventually get to cybersecurity talk, including things like:The challenge of keeping mountains of cybersecurity data and sharing it with partners.The importance of context around that data when it is shared.How better context leads to better detection methods.Weird Elon Musk guys.Â
- “I’m going to breach you off.” “Not if I breach you off first!”by beerswithtalos@cisco.com (Cisco Talos) on August 24, 2023 at 8:00 am
We know we’re like two weeks late to the Barbie party, but the whole Beers with Talos crew has seen it now so we had to talk about it. Expect a lot of “Barbie” talk up at the top. After that, though, we dive into how to set up deception systems and establish your environment to make it harder for an intruder to get in. The goal here is to make it so that attackers have to waste time and resources trying to get in but ultimately come away empty-handed. We talk about why this is important for the systems we build and why the security community doesn’t talk enough about this approach.Â
- Rachel Tobac on social engineering, expanding opportunities for women in cybersecurityby beerswithtalos@cisco.com (Cisco Talos) on August 3, 2023 at 8:00 am
In this special episode, Matt is flying solo while he interviews Rachel Tobac, the CEO of SocialProof Security. Rachel’s company helps individuals and companies keep their data safe by offering various training and penetration testing opportunities, all related to social engineering attacks and risks. Ahead of BlackHat and DEFCON, Matt wanted to talk to Rachel because they first met at DEFCON a few years ago, where she was a second-place finisher in the Social Engineering Capture the Flag contest for three years in a row. Matt and Rachel discuss the current types of social engineering tactics that adversaries use and the importance of increasing the volume and types of opportunities that exist for women in cybersecurity and privacy. Rachel is the chair of the board for the non-profit Women in Security and Privacy (WISP) where she works to advance women to lead in the fields. She’s currently working on sending a delegation of women to BlackHat later this month.Â
- Yarrr! There be mercenaries on the high seas!by beerswithtalos@cisco.com (Cisco Talos) on August 1, 2023 at 8:00 am
The Beers with Talos Crew is back to a team of four this week, with special guest Nick Biasini joining the show to talk about Mercenary Groups and the spyware they’re creating. This episode, we talk about the current spyware landscape, and how it encompasses “mercenary” groups like the NSO Group and Intellexa, and state-sponsored actors looking to track high-profile targets. Nick’s team recently published multiple pieces about this topic and they are actively researching spyware. If listeners suspect their system(s) may have been compromised by commercial spyware, please consider notifying Talosâ research team at talos-mercenary-spyware-help@external.cisco.com to assist in furthering the communityâs knowledge of these threats.
- Oh hello, “Susan”by beerswithtalos@cisco.com (Cisco Talos) on May 25, 2023 at 8:00 am
Mitch was out for this recording, so Hazel Burton, the newest addition to Team Talos, stepped in to host this episode! She, Lurene and Matt got together for Mental Health Awareness Month and share stories and advice with one another. Cybersecurity is a notoriously rough field for burnout and an imbalance between work and life, so they share some tips they use to decompress after a long day and how they ignore their inner critics.Â
- The XDR Filesby beerswithtalos@cisco.com (Cisco Talos) on May 18, 2023 at 8:00 am
Our second of two episodes recorded live at the RSA Conference, Mitch and Lurene are joined by Nick Biasini from Talos Outreach and AJ Shipley, a vice president of product management for Cisco Secure. The four of them recap Nick and AJ’s talk they gave at RSA and discuss the centralization of cybersecurity. AJ shares some important insights about the product side of cybersecurity, and how everyone in the space needs to be better focused on stopping the bad guys versus competing against one another. They also cover the announcement of Cisco’s newest flagship cybersecurity product: Cisco XDR.
- SHIFT_NOPby beerswithtalos@cisco.com (Cisco Talos) on May 11, 2023 at 8:00 am
This is the first of two episodes we have coming out that we recorded live at the RSA Conference. In this edition of Beers with Talos, we welcome Mick Baccio, a security strategist for Splunk, to talk about all things RSA. At this point in the week, we had hit the halfway point of RSA and were pretty tired already, so bear with us â don’t expect any hardcore security takes here. That being said, we do gather ’round to share stories, and reflect on RSA and the security community as a whole. There’s no link for it yet, but buy Mick’s book when it comes out!Â
- The one where they talk a lot about wireless routersby beerswithtalos@cisco.com (Cisco Talos) on April 24, 2023 at 2:00 pm
This episode discusses network resilience, hardware hygiene, and the recently disclosed Jaguar Tooth campaign. J.J. joins the show and the usual cast to discuss the recent attacks against out-of-date and unpatched wireless routers from sophisticated, state-sponsored actors. J.J., Matt and Lurene detail the research around these campaigns and advice for anyone to improve their network hygiene. If you’d like to talk to the BWT crew more about this topic, they’ll be at RSA this week with two live episodes and generally hanging around the Cisco booth. Important links for this episode:Talos blog post on Jaguar ToothCisco’s advice on appropriate network hygieneCisco PSIRT blog post on Jaguar Tooth.Cisco Software Checker
- Should we even care about vulnerability severity scores?by beerswithtalos@cisco.com (Cisco Talos) on March 16, 2023 at 8:00 am
Everyone fears the dreaded 10-out-of-10 CVSS severity score on a vulnerability with “critical” written somewhere on the advisory. But does that number even matter to an attacker or hypothetical defender? Matt, Mitch and Lurene discuss the various ways the security community classifies vulnerabilities and how potential targets can use that information to their advantage. They discuss patching strategies, potential security holes that attackers look for and real-world cases of vulnerabilities that have led to breaches or cyber attacks.Other suggested talking points:Band jam sessionsConference season getting underwayWhether Tom Petty’s music is actually complex
- Beers with Talos Ep. #130: Ransomware is a people problem (but getting rid of email helps)by beerswithtalos@cisco.com (Cisco Talos) on February 17, 2023 at 9:00 am
(Recorded Jan. 27, 2023)No Matt this episode, so we have two guests in the rotating chair(s): Nick Biasini and David Liebenberg. Lurene, Mitch and our two esteemed companions talk about the human problem of ransomware. Lurene says getting rid of email altogether is the best option â but since that doesn’t seem likely anytime soon, what are some other options for enterprises and companies to avoid being hit with the latest phishing scam? Other suggested talking points:Wawa vs. SheetzWhy everyone has a “Dave in Accounting”Lurene being way ahead of the curve on Twitter’s slow demise
- Talos Year in Review 2022 w/ Dave Liebenbergby beerswithtalos@cisco.com (Cisco Talos) on December 14, 2022 at 12:00 pm
With this episode, we set out to discuss the first annual Cisco Talos Year in Review report – a look back at the major threats, trends, and topics from 2022 and what we should take forward into 2023.  Our guest Dave Liebenberg runs the team behind this report and joins us to discuss *why* his team undertook this effort, and some of the finer points of the report findings. The Year in Review is broken down into four major parts, and Talos will be releasing “topic focus reports” to zoom in on each through February. …BUT… in reality, we spent the first 20 minutes of the show ranking Thanksgiving foods by awesomeness – henceforth, Ranksgiving – and it was too much fun to cut. If you don’t want to be angered or surprised where turkey lands on the list, skip to the 20 minute mark. The #1 spot is definitely a hot take that could upset some listeners, just like it upset to the previous long-standing title holder. Check out the Year in Review page (https://blog.talosintelligence.com/year-in-review) for the full Year in Review report, topic summary reports, livestreams, podcasts, and other content starting December 14th. Â
- I find your vulnerabilities offensive (and exploitable).by beerswithtalos@cisco.com (Cisco Talos) on November 29, 2022 at 7:00 pm
We are (finally) talking about the recent OpenSSL vulnerability as we had to redo this EP. In our infinite podcasting wisdom, we took a stab at it roughly 2 hours before the embargo expired and coverage was released – which is obviously is a very silly idea in hindsight. After we cover the current issue at hand, Lurene leads us through the surface levels of how vulns can be exploited in the heap or stack, and the different perspective and processes in practice by offensive security experts. If you want to walk away with a new view of vulns and exploits, stay for the whole hour.Here is a great write up from DataDog on OpenSSL vulnerability CVE-2022-3602.
- Im a skiddie, and you can too!by beerswithtalos@cisco.com (Cisco Talos) on October 26, 2022 at 6:00 pm
Mitch was trying to preserve his voice, so Matt is driving the bus during this episode â hang on! In this edition, we’re talking about script kiddies (unfortunately, not “kitties.”) These are basically adversaries with an extreme base level of computer knowledge who use basic scripts to carry out cyber attacks. How can we avoid these attacks, even if they’ll look like benign activity in your environment?Â
- The intricacies of cyber conflict in Ukraineby beerswithtalos@cisco.com (Cisco Talos) on September 22, 2022 at 7:00 pm
At the onset of Russia’s invasion of Ukraine, many experts and government officials expected there to be two fronts of the war â one on the ground in Ukraine and one in cyberspace. But all things considered, we haven’t seen as much offensive cyber warfare come from either side of this conflict this year. J.J. Cummings from Talos Threat Intelligence and Interdiction joins the show again to share his experience from working hands-on with networks in Ukraine. He, Lurene, Mitch and Matt discuss why there haven’t been as many offensive attacks as we were expecting, or if they’re just happening in the background and no one’s talking about it.Other suggested talking points include:What is the “Texas” of other continents?Drama inside the Conti ransomware gang.Why Matt definitely doesn’t spend too much time on Twitter.How sad should we be about the Queen of England dying?Some helpful links:HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine from SentinelOneAcidRain | A Modem Wiper Rains Down on Europe from SentinelOneTranslated: Talos’ insights from the recently leaked Conti ransomware playbookVictoria & Albert Museum in Discussions to Return Artifacts to GhanaUkraine Independence Day: Talos update
- A(nother) new host approaches!by beerswithtalos@cisco.com (Cisco Talos) on August 31, 2022 at 5:00 pm
We’re excited to add to the growing Beers with Talos family with the addition of Lurene Grenier to the squad. Lurene joins her first episode and hits the ground running talking about her current role within Talos. She, Mitch and Matt talk about the major differences between exploit development and vulnerability discovery, and how Lurene started her career in exploit development. While exploit development might sound like the stereotypical thing a “basement hacker” does, it’s actually very important to the security arena and something a hobbyist can easily turn into a career. Other talking points:Unsolicited marketing advice for Pennsylvania government agencies.Dunking on the Tampa Bay Rays.Why Lurene is always right.$8 million worth of exploit development for Apple products.
- Beers with Talos Ep. #111: Saying farewell to Craig and his killer robotsby beerswithtalos@cisco.com (Cisco Talos) on August 12, 2022 at 5:00 pm
[Re-uploaded to fix an audio gap.] Yes, weâve been sitting on this one for a while. But itâs worth it, we promise! We wanted to wait until we had more news to share, so itâs finally time to announce that Craig has left us. We will absolutely miss Craig, but look forward to the next act of Beers with Talos now that 2/5ths of the original crew is gone. We take the time to reminisce with Craig about his time at Talos and talk about this new trend of âbandwidth-sharingâ applications. Stay tuned to BWT Ep. #112 where weâll debut with a new host!
- Beers with Talos, Ep. #115: Everybody’s measured by quarters â even threat actorsby beerswithtalos@cisco.com (Cisco Talos) on August 12, 2022 at 5:00 pm
We wanted to start off the new year by reflecting on 2021 with Talos Incident Response. The one thing many cyber attacks had in common? People.There are issues that arise any time humans are involved, whether itâs being tempted by a phish or someone making simple human errors. So, Matt, Mitch and Liz discuss how logs are crucial during the worst-case scenario and look at how to remove human error as much as possible from the equation.Outside of initial infection vectors, there are plenty of other lessons learned from 2021 that we can take into incident response this year.
- Beers with Talos Ep. #112: A new host approaches!by beerswithtalos@cisco.com (Cisco Talos) on August 12, 2022 at 5:00 pm
This is our first episode sans-Craig, but we didnât wait long to find his replacement! Tune in as we add a new host to the crew. Then, we talk about drama on the ransomware landscape among as-a-service groups. Please note, we recorded this episode before everything dropped on Log4J. We are recording an emergency episode as we speak on this and will be releasing it later this week.
- Beers with Talos Ep. #113: Emergency Log4j live showby beerswithtalos@cisco.com (Cisco Talos) on August 12, 2022 at 5:00 pm
Log4j was a big enough deal that we finally decided to host a live show. Mitch, Matt, Liz and special guest JJ Cummings from our Threat Intel team got together to update everyone on where things stand with this critical vulnerabilities. Itâs not all doom and gloom though, Matt at least brought some memes!
- Beers with Talos Ep. #117: Talos’ Big Game commercial about a month too lateby beerswithtalos@cisco.com (Cisco Talos) on August 12, 2022 at 5:00 pm
Weâre dropping two episodes today. This is undoubtedly the less serious of the two, as it was recorded prior to the invasion of Ukraine. Check out Ep. #118 for more on that situation. In this episode, though, we got to talk about Talosâ involvement at the Super Bowl. Mitch welcomes on Brett Ellis, who was at SoFi Stadium in Los Angeles to help defend âThe Big Game,â of Talos Incident Response to discuss his experience. He, JJ and Liz talk about what goes into securing these major global events and talk about what itâs like to have to come in and handle someone elseâs networking equipment and then parachute out. If you want to learn more about Talos and Cisco Secure at the Super Bowl, you can read Ciscoâs announcement.
- Beers with Talos Ep. #119: If it walks like a BlackCat, meows like a BlackCat…by beerswithtalos@cisco.com (Cisco Talos) on August 12, 2022 at 5:00 pm
Weâre all still pretty exhausted from our work in Ukraine. But that hasnât slowed down any of the threat actors, unfortunately. So we enlisted special guest Nick Biasini to dive into the BlackCat ransomware group to discuss how it potentially is or isnât connected to BlackMatter/DarkSide. These ransomware-as-a-service groups surprisingly run like regular companies, and even have the same problems with employee retention! Plus, Matt and Liz provide updates on their work in helping to defend Ukrainian networks and organizations.Other talking points:- How to pronounce the company âNikeâ- Surprisingly safe-for-work videos on Omegle- Avoiding burnout when everything is on fire
- Beers with Talos Ep. #118: Reacting to the current situation in Ukraineby beerswithtalos@cisco.com (Cisco Talos) on August 12, 2022 at 5:00 pm
This was admittedly a tough one to record. In the middle of us trying to respond to the situation in Ukraine, we felt it was important to let our listeners in a bit. Matt, JJ and Liz discuss the work they and their teams are doing in Ukraine to protect critical systems there and keep users online. We also talk about the human side of things, and why itâs important for folks in cybersecurity to think about self care during this time.If you want to stay up to date on Talosâ work in Ukraine and our ongoing research about cybersecurity concerns in the region, continually check cs.co/TalosUA. Here are some additional links to Talos research and Cisco announcements:Livestream with Cisco ThousandEyes, Cisco Secure and Cisco TalosSpam campaigns leveraging Ukraine themes to spread malware, steal cryptocurrencyCiscoâs statement on standing with Ukraine