Talos Takes

Talos’ spin on security news

Every week, host Jon Munshaw brings on a new guest from Talos or the broader Cisco Secure world to break down a complicated security topic in just five or 10 minutes. We cover everything from breaking news to attacker trends and emerging threats.

Subscribe
  • Talos Takes

    Talos Takes Ep. #48: The history of ObliqueRAT

    After researching and writing about ObliqueRAT for several months now, Asheer Malhotra joins Talos Takes for the first time to discuss this trojan. We’ve seen this malware evolve over the past year or so to ad new evasion techniques and find ways to avoid email filters and usual antivirus protections. Asheer talks about his history researching this malware and provides some advice on how to avoid email spam and the other maldocs these actors try to spread.

    Download
    Run Time: 00:07:54

    Keywords
    • ObliqueRAT
    • malware
    • trojans
    • spam

  • Talos Takes

    Talos Takes Ep. #45: Finding an alternative to SMS multi-factor authentication

    It was only a matter of time before we had Wendy Nather from Cisco Secure Duo on the show. We finally met Beers with Talos’ level of stardom, as Wendy joins the show to discuss SMS messages as a form of multi-factor authentication. We break down why SMS authentication is still around and used by some of our most important services like banks, and what alternatives are out there. We also discuss the dangers of SIM-jacking attacks and the benefits of using Duo’s app-based authentication.

    Download
    Run Time: 00:08:30

    Keywords
    • MFA
    • SMS
    • 2FA
    • passwords

  • Talos Takes

    Talos Takes Ep. #44: A super-sized edition for a roundtable discussion on SolarWinds

    Welcome to the first-ever XL edition of Talos Takes. This one is a little longer than usual, but we promise you it’s worth it. We recently brought together researchers from all corners of Talos to talk about what we know about SolarWinds so far, and what’s still to be discovered. Our various teams have spent the past several months diving deep into the SolarWinds supply chain attack, and this is a collection of Talos’ knowledge on the current situation. Talking points include whether it’s fair to refer to this campaign as “SolarWinds,” what other initial infection vectors there may be, the breadth of the attack and more boots-on-the-ground intelligence. If you want to watch the video version, head to our YouTube page.

    Download
    Run Time: 00:34:50

    Keywords
    • SolarWinds
    • Incident Response
    • supply chain
    • news
    • Headlines

  • Talos Takes

    Talos Takes Ep. #43: Microsoft Exchange Server emergency show

    We put this week’s Talos Takes episode together last minute to discuss the Microsoft Exchange Server zero-day vulnerabilities Microsoft disclosed earlier this week. Nick Biasini joins the show to discuss mitigation strategies and what these vulnerabilities mean for your environment at-large. Plus, we discuss why this is another case of patching above all else. For more coverage on this topic, check out the Talos blog.

    Download
    Run Time: 00:05:30

    Keywords
    • Microsoft
    • Exchange
    • vulnerabilities
    • CVEs
    • zero-day

  • Talos Takes

    Talos Takes Ep. #42: Seriously folks, save your logs

    When Pierre Cadieux steps into a Cisco Talos Incident Response engagement, the first thing he wants to do is check out the customer’s logs. But if there are no logs to be found, he’ll be pretty limited in the kinds of insights he can provide.

    This has come up several times during the SolarWinds era, when customers are wanting to know if they were targeted in the widespread supply chain attack. So in this episode of Talos Takes, Pierre joins the show to discuss why it’s so important to keep logs for everything — log-ins, events, applications and more.

    Download
    Run Time: 00:07:29

    Keywords
    • SolarWinds
    • Incident Response
    • security logs
    • Cisco Talos Incident Response
    • security

  • Talos Takes

    Talos Takes Ep. #41: Why you should upgrade to Snort 3

    For this week’s episode of Talos Takes, we’re switching back to Snort talk. For anyone who hasn’t been on security Twitter over the past month, you may not know that we released the Snort 3 GA last month — formally known as Snort 3.1.0. To celebrate, Nick Mavis joins the show again to discuss Snort 3’s new features and upgrades over 2.9.X. Nick, who regularly writes Snort rules for Cisco Talos and has been working hands-on with both versions of Snort for years, talks about how the rules improve with Snort 3, why detection and protection are better and everything else he loves about Snort 3. For more, check out the Snort 3 page on Snort.org.

    Download
    Run Time: 00:06:02

    Keywords
    • Snort
    • Snort 3

  • Talos Takes

    Talos Takes Ep. #47: Masslogger

    On this week’s episode of Talos Takes, we go back a month or so to reflect on the Masslogger trojan Talos wrote about earlier this year. This malware may not make national headlines, but that doesn’t mean you should just ignore it. Find out where this trojan is hiding and why it’s after your Outlook and Google Chrome login credentials.

    Download
    Run Time: 00:04:51

    Keywords
    • trojan
    • Masslogger
    • malware
    • Threats

  • Talos Takes

    Talos Takes Ep. #40: Lessons learned from our conversations with a ransomware operator

    For the first time in Talos Takes history, we have a whopping TWO guests on to talk about Talos’ latest research paper. In this episode, Dmytro Korzhevin and Azim Khodjibaev discuss their work interviewing a LockBit ransomware operator. They spent multiple weeks speaking to this actor over social media, and eventually turned their conversations into a paper that lays out what we learned about the ransomware landscape. Dmytro and Azim talked about lessons learned, what surprised them about the threat actor, and how actors choose their targets.

    Download
    Run Time: 00:08:12

    Keywords
    • LockBit
    • ransomware
    • malware

  • Talos Takes

    Talos Takes Ep. #39: An update on SolarWinds as it relates to IoT and OT

    We know we just talked about supply chain attacks and SolarWinds last week, but it’s still all anyone in security is talking about. Joe Marshall joins the show this time to approach the SolarWinds breach from an internet-of-things and operational security perspective. He recently co-wrote a blog for Cisco detailing how outsourcing OT over the past few years has made the SolarWinds compromise worse. Joe, a lifelong researcher and security practitioner in the OT and infrastructure space, discusses what we still don’t know about this attack, what you should do if you think you may be affected, and how we can learn from this going forward. For more on Talos’ coverage and defense against the SolarWinds campaign, check out our blog post here.

    Download
    Run Time: 00:12:29

    Keywords
    • SolarWinds
    • IoT
    • operational technology
    • infrastructure

  • Talos Takes

    Talos Takes Ep. #37: What's with all this talk about supply chain attacks?

    The major SolarWinds campaign has been generating headlines for weeks now. And while its specific targets make this attack unique, this is far from the first-ever supply chain attack. So what is a supply chain attack? And should your organization be prepared for them? In this episode of Talos Takes, Nick Biasini talks about the history of supply chain attacks, and how they can even be traced back to the 1970s.

    Download
    Run Time: 00:07:59

    Keywords
    • SolarWinds
    • malware
    • supply chain
    • APTs
    • FireEye