Podcasts

Beers with Talos

Threats, Beers, and No Silver Bullets

Listen to Talos security experts as they bring their hot takes on current security topics and Talos research to the table. Along the way Hazel, Mitch, Matt and a rotating chair of special guests will talk about anything (and we mean anything) that's on their minds, from the latest YouTube trends to Olympic curling etiquette. New episodes every other Thursday.


Your AI Malware Experiments Are Showing

Adversaries are experimenting with AI-integrated malware, and today's guest, Talos researcher Ryan Fetterman has been looking at their working notes. He joins us to talk about CAIRN, his new open-source research toolkit for tracking that experimentation, and what he’s finding, including a C2 an implant that delegates its decisions to AI models, and malware that tries to persuade AI analysis tools to leave it alone. Putting AI in malware is one thing. Establishing whether any of it actually works takes rather more investigation.

A special segment with Joe (from 7.07 to 25.25) talks about his newly published Human IR Framework (published in a personal capacity on Joe's GitHub), the experiences that led him to build it, and why “burnout” doesn’t adequately describe what certain people who work in cybersecurity can go through.

Meanwhile, Dave definitely prepared his "Reason not to Quit" in advance, an attempt to make Hazel Philadelphian takes an unexpected turn towards Wales, and Bill's "Make Hazel a hacker" question sends Hazel once again into a pit of self despair.

Talos Takes

Talos’ spin on security news

Every week, our host brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic in just five or 10 minutes. We cover everything from breaking news to attacker trends and emerging threats.


ClickFix, EtherHiding, and the rise of malicious code in the blockchain

In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure.

Vanja walks us through how threat actors are repurposing legitimate user behaviors — like solving CAPTCHAs — to gain unauthorized access, and how they utilize blockchain smart contracts as bulletproof storage for malicious code. We also explore the divergence in final payloads, ranging from remote access tools to crypto-stealing malware. Tune in for actionable behavioral patterns that your security teams can monitor to detect these incidents before they progress.

Vanja's blog: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/