Season 1, Episode 57 · Microsoft Threat Intelligence Podcast
Ahoy! A Tale of Payroll Pirates Who Target Universities
19 Nov 2025 · 32 min
Season 1, Episode 57 · Microsoft Threat Intelligence Podcast
19 Nov 2025 · 32 min
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by security researchers Tori Murphy and Anna Seitz to unpack two financially motivated cyber threats. First, they explore the Payroll Pirates campaign (Storm 2657), which targets university payroll systems through phishing and MFA theft to reroute direct deposits. Then, they examine Vanilla Tempest, a ransomware group abusing fraudulent Microsoft Teams installers and SEO poisoning to deliver the Oyster Backdoor and Recita ransomware. Together, they discuss how attackers exploit trust in identity,…
by Microsoft · English · Tech & Science
Join us to hear stories from the Microsoft Threat Intelligence community as they navigate the ever-evolving threat landscape - uncovering APTs, cybercrime gangs, malware, vulnerabilities, and other weird and cool tools and tactics in the world of cyber threats. Featuring tales of innovation,…
S3 · E60 · 14 Jan 2026 · 36 min
To kick off Season 3 of Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Microsoft security researchers Anna Seitz and Jonathan Checchi. Our guests examine two developments shaping today’s threat landscape: the cloud-native evolution of ransomware group Storm-0501 and the SesameOp backdoor’s abuse of trusted AI platforms for stealthy command-and-control. The discussion highlights how identity, hybrid-cloud pivot points, and federated authentication enable high-impact attacks without traditional malware, and why policy-compliant platform abuse is becoming harder to…
S1 · E59 · 17 Dec 2025 · 48 min
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by security researchers Geoff McDonald and JBO to discuss Whisper Leak, new research showing that encrypted AI traffic can still unintentionally reveal what a user is asking about through patterns in packet size and timing. They explain how LLM token streaming enables this kind of side-channel attack, why even well-encrypted conversations can be classified for sensitive topics, and what this means for privacy, national-level surveillance risks, and secure product design. The conversation also…
S1 · E58 · 3 Dec 2025 · 39 min
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Matt Duncan, Vice President of Security Operations and Intelligence at the North American Electric Reliability Corporation’s E-ISAC, to explore the cyber threats targeting the North American power grid. Matt breaks down why the grid remains resilient despite increasing pressure from nation-states, cybercriminals, and hacktivists, how AI is lowering the barrier of entry for attackers, and why OT systems and interconnected devices present unique risks. He also highlights real success stories,…
S1 · E56 · 5 Nov 2025 · 42 min
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Zack Korman, CTO of cybersecurity startup Pistachio. They explore the reality of AI in security, cutting through hype to discuss where AI is both brilliant and flawed, how vendors AI-wash outdated tech, and why Zack believes AI won’t replace jobs but instead scale human creativity. They also dive into phishing simulations, human psychology behind social engineering, AI-powered attacks, jailbreak chaining between AI systems, and the future risks and opportunities AI introduces in cybersecurity.…
S1 · E55 · 22 Oct 2025 · 47 min
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Chloé Messdaghi and Crane Hassold to unpack the key findings of the 2025 Microsoft Digital Defense Report; a comprehensive look at how the cyber threat landscape is accelerating through AI, automation, and industrialized criminal networks. They explore how nation-state operations and cybercrime have fused into a continuous cycle of attack and adaptation, with actors sharing tooling, infrastructure, and even business models. The conversation also examines AI’s growing impact, from deepfakes and…
S1 · E54 · 8 Oct 2025 · 31 min
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Tori Murphy, Anna Seitz, and Chuong Dong to break down two threats: the modular backdoor PipeMagic and Medusa ransomware. They discuss how PipeMagic disguises itself as a ChatGPT desktop app to deliver malware, its sophisticated modular design, and what defenders can do to detect it. The team also explores Medusa’s evolution into a ransomware-as-a-service model, its use of double extortion tactics, and the broader threat landscape shaped by ransomware groups, social engineering, and the abuse…
S4 · E79 · 7 Oct 2026 · 36 min
In this episode, host Elliot Volkman is joined by Chloe Messdaghi and Karen Frost for a behind-the-scenes look at Microsoft’s annual Digital Defense Report (MDDR). They explore how AI is reshaping the cybersecurity landscape by increasing the speed, scale, and automation of attacks while also giving defenders new tools to detect and respond to threats. The conversation covers AI agents, phishing and identity-based attacks, vulnerability management, security resilience, and the growing need for organizations to connect signals across their environments. Chloe and Karen also share practical…
S4 · E78 · 30 Sep 2026 · 51 min
This week we are taking you back to Black Hat USA 2026 and exploring two sides of the security landscape. First, Microsoft incident response experts Adrian Hill and Terry Mee break down identity-based attacks, from compromised credentials and MFA bypasses to containment, logging, access controls, and the growing risks surrounding AI agents. Then, members of Microsoft’s Defender Purple Team discuss how they recreate full attack chains, including emerging AI-driven techniques, to identify detection gaps, strengthen defenses, and use AI to accelerate security research while keeping human…
S4 · E77 · 9 Sep 2026 · 28 min
In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Brandt, Principal Threat Intelligence Incident Commander at Huntress. They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain…
S4 · E76 · 26 Aug 2026 · 31 min
In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding…