Beers with Talos Podcast

40 Episodes
Subscribe

By: Cisco Talos

Listen to Talos security experts as they dive into emerging threats, forcing the bad guys to innovate, hacking refrigerators, and other security issues, all with beer.

✂️ Clip this podcast
Eight People Walk Into a Dark Web Forum. They’re All Azim
Today at 9:00 AM

What does it take to become someone a cybercriminal will trust? 

Talos' Azim Khodjibaev takes us inside the psychology of direct adversary engagement. At one point, he was maintaining eight different personas, some of which were talking to each other. He explains how discipline and patience help keep his cover intact, and what can provoke threat actors into revealing information. 

His work has occasionally made Azim part of the story. Ransomware operators have threatened him, and one even put “Azim sucks” in their code. He shares how his research has contributed to Talos identifying prolific cyberc...


For the Record, No Comment
08/19/2026

Kaitlin Acharya joins the Beers with Talos crew to take us inside the world of threat intelligence: what happens when Talos spots something that could become a major threat, how her team tracks changes in threat actor behavior, and how intelligence moves from an investigation into detection content. She also faces some tougher questions involving tennis, Derry Girls and an evil genie.

We also attempt to extract some information about Kaitlin’s former life at a certain intelligence agency. Results are limited.

Our listener question asks which high school subject produces the best cybersecurity professionals. We...


"I Pay You $200 a Month!" - When Threat Actors Argue With AI
08/05/2026

Cybercriminals are increasingly relying on AI, but in doing so, they're creating an entirely new source of threat intelligence.

This week, Talos researcher Arnaud Zobec joins Hazel, Bill, Joe and Dave to discuss what happens when attackers leave behind AI prompt logs, agent configurations and other unexpected artifacts. From jailbreak attempts to agentic workflows and accidental infrastructure leaks, the team discusses what these artifacts reveal about attacker behavior, and where/how AI is changing offensive operations and campaigns. Here's the link to that blog https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/

Also in this episode: our listener q...


Keeping Up With the Cybercriminals
07/22/2026

In this episode of Beers with Talos, Hazel, Bill, Dave and Joe are joined by Kendall McKay to dive into the soap opera of modern cybercrime. From rival gangs launching smear campaigns against one another to reputation systems, trusted intermediaries and dark web "customer reviews". Turns out, every ransomware operation is one passive-aggressive group chat message away from falling apart.

Kendall chats to us about how AI is changing the economics of cybercrime, why it's helping inexperienced attackers get through the front door (only to leave them wondering what to do next), and how defenders can prioritize...


Space Pirates, Living Off Trusted Services, & Bill Declares Food War
07/08/2026

In this episode of Beers with Talos, Hazel, Bill, Dave and Joe are joined by Talos Security Research Engineer James Nutland to discuss Living Off Trusted Services (LOTS) - a growing technique where attackers use platforms such as GitHub, Google Drive, Microsoft services and Telegram for command and control, malware delivery and data exfiltration.

We explore why this trend is growing, how it differs from Living Off the Land (LOTL)....and Lord of the Rings (LOTR)....why trusted services create new detection challenges, and what defenders should be monitoring.

Also in this episode:

Data...


AI Is Finding Bugs Faster. Now What?
06/24/2026

AI is accelerating vulnerability discovery, so what impact is that having on defenders?

In this episode of Beers with Talos, Hazel, Bill, Joe, and Dave are joined by Nick Biasini to unpack what attackers are doing with AI-assisted vulnerability discovery, why local models rather than frontier models may be a more attractive route for them, and the vendors who are now drowning in a flood of bug reports (many of them junk) as AI sifts through decades of technical debt with nothing but time and patience.

We also kick things off with a listener question...


25 Years of Uninterrupted Persistence
04/30/2026

Hazel, Dave and Joe plot to celebrate Bill's 25 years at Talos with stories and a good old fashioned roast.

The team also covers the latest security headlines, including AI-assisted vulnerability research, and why attackers still can’t resist abusing trusted systems (or Roblox).

They also break down the latest Cisco Talos Incident Response Quarterly Trends report, including:

Phishing’s return as the top initial access vectorAI-generated credential harvesting pages built in minutesCrimson Collective activity and GitHub token exposurePre-ransomware incidents and early disruptionWhy logging (still) matters more than ever

Read the full repo...


Gravy, Glutes, and the Talos Year in Review
03/23/2026

Hazel, Bill, Joe and Dave break down (sometimes in the literal sense) the 2025 Talos Year in Review which is available  now at blog.talosintelligence.com/2025yearinreview

The team, supported as always by the Turkey Lurkey Man, dives into the biggest cybersecurity trends of the year, including:

·       The rapid weaponization of vulnerabilities

·       Why identity abuse showed up everywhere 

·       Ransomware trends

·       A rise in APT investigations

·       What defenders should prioritize heading into the year ahead

Before that, we discuss the cyber activity tied to the situation in the Mid...


It's the B+ Team: Matt Olney returns
03/10/2026

It's the one, the only, it's Matt Olney! We are delighted to have Matt back to talk with the crew about about the most random things, including TikTok diagnosing us with ADHD, inspiring vtubers, K-Pop Demon Hunters, ransomware in hospitals (the serious bit), attacker use of AI, why 1999-era tricks are still undefeated, and an entirely reasonable number of desserts.

We recorded this episode on 20 February - please see the Talos blog for the latest on the developing situation in the Middle East https://blog.talosintelligence.com/talos-developing-situation-in-the-middle-east/

Links to some things Matt mentioned:

<...


Ranksgiving Returns: The Appetizer Uprising
12/04/2025

Guess who’s back? Hazel, Bill and Joe welcome back fresh-from-parental-leave Dave Liebenberg, who has returned with a new baby, and some truly chaotic Thanksgiving opinions.    

We kick things off with the security headlines. Joe gets spicy about a recent “AI-orchestrated cyber campaign” report.  Dave brings us the poetic news that AI models can apparently be jailbroken with a well-placed limerick. Hazel challenges the others to a guessing game about just how much cyberattacks cost the UK, and Bill discusses what’s top of mind for organizations right now.  

But really, you know what you’re here for: th...


Two Marshalls, One Podcast
10/16/2025

Talos' Vice President Christopher Marshall (the “real Marshall,” much to Joe’s displeasure) joins Hazel, Bill, and Joe for a very real conversation about leading people when the world won’t stop moving. We start with Marshall’s days in the Navy’s nuclear program and the art of translating deeply technical work for non-technical leaders. We then get into how he joined Talos (“you WILL do this for me”), why being right beats being first, and how to keep a team steady and mission focussed when the news cycle is anything but. Marshall also talks about the decisions that shaped his...


How to Ruin an APT's Day, with Sara McBroom
09/11/2025

This week, the B-Team gets an upgrade as we’re joined by Sara McBroom from Talos’ nation-state threat intelligence and interdiction team. Sara shares her journey from a liberal arts major to tracking some of the world’s most advanced adversaries. Along the way, she talks about moving from the U.S federal service to Talos, mentoring, leading with empathy, and why making bad actors miserable is a pretty good day’s work.

Before diving into Sara’s story, we hit the security headlines (ouch) and also discuss a Dutch hacker camp with flaming badges and port-a-potty internet...


So You Wanna Be an Incident Commander? Meet Alex Ryan
07/31/2025

We welcome new Talos teammate and incident commander Alex Ryan to the pod this week. Bill, Joe and Hazel chat with Alex about what it really takes to lead through the chaos of a cybersecurity incident, from coordinating stressed-out teams, fielding exec questions, and making sure people eat.

Much to Bill's dismay, we have something resembling a "format" for this episode, and we start by breaking down the week's security news, including:

The SharePoint zero-day exploit (“ToolShell”) and what defenders should do now. Here's the Talos blog we mention https://blog.talosintelligence.com/toolshell-affecting-sharepoint-servers/An AI assis...


Terms and conceptions may apply
Terms and conceptions may apply episode artwork
06/27/2025

Welcome back to the podcast where the structure is theoretical and the only certainty is uncertainty. In this episode, the crew reassembles after a totally intentional and not-at-all accidental hiatus (blame is assigned, forgiveness is not).

We cover:

AI-assisted IVF (spoiler: it's mostly robots and headlines)The dawning of Mind-games-as-a-service in ransomware operationsConference dogs that may have been the real security MVPsA possible underground war against dairyAnd the billionaires quietly building their own genetically-diversified endgame.

We also mourn Bill's departure as he abruptly quits the podcast after one pun too many.

As always...


Year in Review 2024
Year in Review 2024 episode artwork
03/31/2025

Joe, Hazel, Bill and Dave break down Talos' Year in Review 2024 and discuss how and why cybercriminals have been leaning so heavily on attacks that are routed in stealth in simplicity. The team also provide insights into some of the topics of the report, including the top-targeted vulnerabilities of the year, network-based attacks, adversary toolsets, identity attacks, multi-factor authentication (MFA) abuse, ransomware and AI-based attacks. 

For the full report, head to blog.talosintelligence.com/2024yearinreview


The truth about Tasmanian devils, and getting into cybersecurity
02/27/2025

Bill springs a surprise topic on the team in this episode - how did you get into cybersecurity, and what skills have you brought with you throughout your career? What ensues is a rather lovely, vulnerable conversation that we hope will be helpful for anyone currently thinking about their next career move.

Before that Dave has some surprising facts about Tasmanian devils, what they didn't cover (or deliberately hid?) in Looney Tunes, and why the scientific name for Tasmanian devils is a hotly debated topic. 

Some resources for getting into cybersecurity:

Threat intelligence 101 w...


Social Media Bans, Live Experiments, Cybersecurity Crosswords, and Nine Lives: The B team returns
Social Media Bans, Live Experiments, Cybersecurity Crosswords, and Nine Lives: The B team returns episode artwork
01/16/2025

More hijinks and silliness ensue in the second episode of the BWT B Team podcast. Joe shares his frustration with being involuntarily removed from a social media platform, Hazel conducts a live experiment, Dave talks about his newfound addiction to crossword puzzles and its parallels to cybersecurity, and Bill recommends the game "Nine Lives" and shares his top books of the year. 

Joe also briefly chats about his work customizing a tabletop cybersecurity game for humanitarian organizations. And we do a shoutout to Talos’ research on vulnerable Windows drivers and  proxy chain abuse.

Find the late...


Misadventures, Rabbit Holes, and Turkey Lurkey Goes to the Movies
12/05/2024

With Mitch, Matt and Lurene currently stuck in the void, the Beers with Talos B team duly elect themselves to reopen the sacred BWT airwaves with their own brand of nonsense. 

Hazel, Joe, Bill and Dave each share the security rabbit hole they went down this week - from analyst in-jokes about AI, oligarchs and bad actors refusing to learn good op sec, the songs you'd play to send a message mid-hack, and the long awaited return of Turkey Lurkey Man, TM. Dave's insane creation is back with an exciting new take on Thanksgiving. 

For al...


Black Hat 2024 preview
08/01/2024

It's been a while huh? Apologies for our absence, but the team are back with a run through of everything we've got going on at Black Hat - from our 10 year birthday celebrations, the interesting lightning talks in our booth, and Joe Marshall's "Backdoors and Breaches" game. Come and visit us at Cisco Booth 1732 and Splunk Booth 1940.

Before that, Matt encourages Mitch and Lurene to join him in the joy of Tekkno Train by Electric Callboy (Choo Choo!) and Mitch explains why his son has developed a huge potty mouth, with no sense of irony. Lurene also reveals...


Stories from the Power Grid
04/11/2024

Power grid security expert Joe Marshall joins the crew today to talk all things, well, power grid security. But not before he gets an impromptu pop quiz from Matt in the roundtable.

Joe then tells some stories from his days working in electric utility,  deploying new systems and his experiences with pentesting teams ("Wow, y'all need to stop!"). Plus, the team ask Joe about  the risks with both aging infrastructure versus newer, smarter based infrastructure. And what happens when threat actors target critical infrastructure?



The old people episode
03/21/2024

Matt, Mitch and Lurene discuss if the internet is better or worse today than it was 20 years ago.  This leads them to discuss their various career paths, with Lurene talking about how she got into vulnerability exploitation and how Matt got into threat intelligence. And why neither of those paths would be recommended today. Lurene and Matt then clash about threat research and and the importance of approaching things from a "how do I be a problem" perspective.


The Reverberations of Volt Typhoon
#144
02/22/2024

You will no doubt have seen the advisories published over the last few weeks concerning Volt Typhoon's malicious activities. In this episode, JJ Cummings joins the crew to discuss the background to this threat actor, their impact on the threat landscape, and the covertly strategic (and specific) nature of their operations. The team also discusses their recommendations for defenders, particularly for critical infrastructure organizations.

The CISA statement on Volt Typhoon can be found here https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a


The Reddit Security Diaries
#143
02/14/2024

Matt, Mitch and Lurene sit down to discuss “random stuff from Reddit” (don’t be put off – they’re all genuinely interesting security questions!). Topics range from password managers and how password security guidance has become outdated, how to ‘self-learn’ in cybersecurity, and thoughtful approaches towards security incidents.

 Before that, the team comes up with a prank to pull on their co-workers and bring some joy and chaos to Webex meetings. And Lurene reflects on what advice she would give high schoolers today.

 As Matt says at the end of the episode, we want to hear from you! G...


Talos Speed Dating (the episode we never set out to make but did anyway)
#142
12/20/2023

Mitch, Matt and Lurene were almost about to be in the same physical space at the same time to record an episode, and then Lurene couldn't make it...so we made this instead! Mitch is joined by Azim Khodjibaev from the Talos Threat Intelligence and Interdiction team to rapid-fire interview a bunch of Talos employees who happened to be around the Maryland office. Hear from teammates from all walks of life and areas of expertise about what they've loved working on in 2023 and how they feel their work has changed the broader security landscape. 


The TurkeyLurkey Man wants YOU to read the Talos 2023 Year in Review report
#141
12/06/2023

We recorded this episode AFTER Thanksgiving, so you'll need to forgive us for the amount of Thanksgiving talk that doesn't actually apply until Thanksgiving 2024. It all evens out in the end because the annual "Ranksgiving" from special guest David Liebenberg results in the creation of TurkeyLurkey Man. Then, TurkeyLurkey Man helps the rest of the gang recap the top malware and attacker trends from 2023. If you'd like to read more, download the full Talos Year in Review report here. We also discussed the recent CNN article and Talos blog post on our work to protect Ukraine's power grid. 


Chicken Soup and Contact Centers
#140
11/02/2023

It's that time of the quarter again when we sit down to look at what we learned over the past three months. Caitlin Huey from the Talos Threat Interdiction Team joins the show for this special look at the latest Talos Incident Response Quarterly Trends report. Caitlin's team helps compile these reports and digs through mountains of data to find out what defenders can learn from what Talos IR is seeing live in the field. If you want to learn more about this report, you can read it on our blog, or watch the Talos IR On Air video...


Who is Jacques Wagon?
#139
09/28/2023

This episode of Beers with Talos has a very special guest: Our old friend Nigel Houghton. He's one of the OG BWTers and is back with two-plus years' worth of hot takes to get off his chest. Nigel starts out by delivering his long-awaited update on his beloved Mighty Red. But he, Mitch, Matt and Lurene do eventually get to cybersecurity talk, including things like:

The challenge of keeping mountains of cybersecurity data and sharing it with partners.The importance of context around that data when it is shared.How better context leads to better detection methods.Weird...


"I'm going to breach you off." "Not if I breach you off first!"
#139
08/24/2023

We know we're like two weeks late to the Barbie party, but the whole Beers with Talos crew has seen it now so we had to talk about it. Expect a lot of "Barbie" talk up at the top. After that, though, we dive into how to set up deception systems and establish your environment to make it harder for an intruder to get in. The goal here is to make it so that attackers have to waste time and resources trying to get in but ultimately come away empty-handed. We talk about why this is important for the...


Rachel Tobac on social engineering, expanding opportunities for women in cybersecurity
#138
08/03/2023

In this special episode, Matt is flying solo while he interviews Rachel Tobac, the CEO of SocialProof Security. Rachel's company helps individuals and companies keep their data safe by offering various training and penetration testing opportunities, all related to social engineering attacks and risks. Ahead of BlackHat and DEFCON, Matt wanted to talk to Rachel because they first met at DEFCON a few years ago, where she was a second-place finisher in the Social Engineering Capture the Flag contest for three years in a row. 

Matt and Rachel discuss the current types of social engineering tactics that a...


Yarrr! There be mercenaries on the high seas!
#137
08/01/2023

The Beers with Talos Crew is back to a team of four this week, with special guest Nick Biasini joining the show to talk about Mercenary Groups and the spyware they're creating. This episode, we talk about the current spyware landscape, and how it encompasses "mercenary" groups like the NSO Group and Intellexa, and state-sponsored actors looking to track high-profile targets. Nick's team recently published multiple pieces about this topic and they are actively researching spyware. If listeners suspect their system(s) may have been compromised by commercial spyware, please consider notifying Talos’ research team at talos-mercenary-spyware-help@external.cisco.co...


Oh hello, "Susan"
#136
05/25/2023

Mitch was out for this recording, so Hazel Burton, the newest addition to Team Talos, stepped in to host this episode! She, Lurene and Matt got together for Mental Health Awareness Month and share stories and advice with one another. Cybersecurity is a notoriously rough field for burnout and an imbalance between work and life, so they share some tips they use to decompress after a long day and how they ignore their inner critics. 


The XDR Files
#135
05/18/2023

Our second of two episodes recorded live at the RSA Conference, Mitch and Lurene are joined by Nick Biasini from Talos Outreach and AJ Shipley, a vice president of product management for Cisco Secure. The four of them recap Nick and AJ's talk they gave at RSA and discuss the centralization of cybersecurity. AJ shares some important insights about the product side of cybersecurity, and how everyone in the space needs to be better focused on stopping the bad guys versus competing against one another.

They also cover the announcement of Cisco's newest flagship cybersecurity product: Cisco...


SHIFT_NOP
#134
05/11/2023

This is the first of two episodes we have coming out that we recorded live at the RSA Conference. In this edition of Beers with Talos, we welcome Mick Baccio, a security strategist for Splunk, to talk about all things RSA. At this point in the week, we had hit the halfway point of RSA and were pretty tired already, so bear with us — don't expect any hardcore security takes here. That being said, we do gather 'round to share stories, and reflect on RSA and the security community as a whole. There's no link for it yet, but bu...


The one where they talk a lot about wireless routers
#133
04/24/2023

This episode discusses network resilience, hardware hygiene, and the recently disclosed Jaguar Tooth campaign. J.J. joins the show and the usual cast to discuss the recent attacks against out-of-date and unpatched wireless routers from sophisticated, state-sponsored actors. J.J., Matt and Lurene detail the research around these campaigns and advice for anyone to improve their network hygiene. If you'd like to talk to the BWT crew more about this topic, they'll be at RSA this week with two live episodes and generally hanging around the Cisco booth.

Important links for this episode:

Talos...


Should we even care about vulnerability severity scores?
#131
03/16/2023

Everyone fears the dreaded 10-out-of-10 CVSS severity score on a vulnerability with "critical" written somewhere on the advisory. But does that number even matter to an attacker or hypothetical defender? Matt, Mitch and Lurene discuss the various ways the security community classifies vulnerabilities and how potential targets can use that information to their advantage. They discuss patching strategies, potential security holes that attackers look for and real-world cases of vulnerabilities that have led to breaches or cyber attacks.

Other suggested talking points:

Band jam sessionsConference season getting underwayWhether Tom Petty's music is actually complex


Beers with Talos Ep. #130: Ransomware is a people problem (but getting rid of email helps)
#130
02/17/2023

(Recorded Jan. 27, 2023)

No Matt this episode, so we have two guests in the rotating chair(s): Nick Biasini and David Liebenberg. Lurene, Mitch and our two esteemed companions talk about the human problem of ransomware. Lurene says getting rid of email altogether is the best option — but since that doesn't seem likely anytime soon, what are some other options for enterprises and companies to avoid being hit with the latest phishing scam? 

Other suggested talking points:

Wawa vs. SheetzWhy everyone has a "Dave in Accounting"Lurene being way ahead of the curve on...


Talos Year in Review 2022 w/ Dave Liebenberg
#129
12/14/2022

With this episode, we set out to discuss the first annual Cisco Talos Year in Review report - a look back at the major threats, trends, and topics from 2022 and what we should take forward into 2023.   Our guest Dave Liebenberg runs the team behind this report and joins us to discuss *why* his team undertook this effort, and some of the finer points of the report findings.  The Year in Review is broken down into four major parts, and Talos will be releasing "topic focus reports" to zoom in on each through February. 

...BUT...  in reality, we spen...


I find your vulnerabilities offensive (and exploitable).
#128
11/29/2022

We are (finally) talking about the recent OpenSSL vulnerability as we had to redo this EP.  In our infinite podcasting wisdom, we took a stab at it roughly 2 hours before the embargo expired and coverage was released - which is obviously is a very silly idea in hindsight.
After we cover the current issue at hand, Lurene leads us through the surface levels of how vulns can be exploited in the heap or stack, and the different perspective and processes in practice by offensive security experts.  If you want to walk away with a new view of vulns an...


Im a skiddie, and you can too!
#127
10/26/2022

Mitch was trying to preserve his voice, so Matt is driving the bus during this episode — hang on! In this edition, we're talking about script kiddies (unfortunately, not "kitties.") These are basically adversaries with an extreme base level of computer knowledge who use basic scripts to carry out cyber attacks. How can we avoid these attacks, even if they'll look like benign activity in your environment? 


The intricacies of cyber conflict in Ukraine
#126
09/22/2022

At the onset of Russia's invasion of Ukraine, many experts and government officials expected there to be two fronts of the war — one on the ground in Ukraine and one in cyberspace. But all things considered, we haven't seen as much offensive cyber warfare come from either side of this conflict this year. J.J. Cummings from Talos Threat Intelligence and Interdiction joins the show again to share his experience from working hands-on with networks in Ukraine. He, Lurene, Mitch and Matt discuss why there haven't been as many offensive attacks as we were expecting, or if they're just ha...