Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Allie Luhrs and Mario Samolis from Microsoft Security to explore the growing threat of open source software supply chain attacks. They discuss how malicious NPM packages, compromised developer ecosystems, AI-generated attacks, and software dependency risks are reshaping modern incident response, while sharing insights from their recent presentation at BlueHat IL 2025. In this episode you’ll learn: How attackers are targeting open source software ecosystems at scale Why AI is accelerating both…

Microsoft Threat Intelligence Podcast

by Microsoft · English · Tech & Science

Join us to hear stories from the Microsoft Threat Intelligence community as they navigate the ever-evolving threat landscape - uncovering APTs, cybercrime gangs, malware, vulnerabilities, and other weird and cool tools and tactics in the world of cyber threats. Featuring tales of innovation,…

More from Microsoft Threat Intelligence Podcast

  1. S3 · E73 · 15 Jul 2026 · 1 hr

    Behind the Book: Threat-Driven Software Development

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by co-authors Michael Howard, Lee Holmes, and Shawn Hernan for a discussion on their new book, Threat-Driven Software Development: Defending Online Services from Modern Threat Actors. Together, they explore how security teams and software developers can build more resilient systems by understanding how real-world threat actors operate. From threat modeling and operational security to the evolving role of AI in both cyber defense and cybercrime, the conversation examines lessons learned from major…

  2. S3 · E72 · 1 Jul 2026 · 1 hr 3 min

    Casey Ellis on How AI Is Reshaping Vulnerability Research and Patching

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo sits down with Casey Ellis, founder of Bugcrowd and co-founder of disclose.io, to explore how AI is reshaping vulnerability research, bug bounty programs, and the future of cyber defense. They discuss the growing volume of vulnerabilities, the challenges of responsible disclosure, the rise of AI-assisted hacking, and what happens when increasingly powerful tools are placed in the hands of both defenders and attackers. The conversation also dives into the human side of cybersecurity, from community and…

  3. S3 · E71 · 17 Jun 2026 · 40 min

    Hot Cybercrime Summer:  Smishing, Supply Chains, and Sleuthcon

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo sits down with Aurora Johnson of SpyCloud and Amitai Cohen of Wiz ahead of SleuthCon to explore two rapidly changing corners of the cybercrime landscape. Aurora breaks down the highly organized Chinese-language smishing ecosystem, revealing how phishing operations, fraud networks, and cash-out schemes work together like a mature business. Amitai examines the growing threat to software supply chains, explaining how groups like Team PCP are exploiting CI/CD pipelines, open-source dependencies, and…

  4. S3 · E69 · 20 May 2026 · 42 min

    Eviltokens: A Conversation with Huntress on an AI‑Enabled Device Code Phishing Campaign

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo joins researchers from Huntress to break down the rise of EvilTokens, an AI-powered phishing-as-a-service platform designed to bypass MFA and automate credential theft at scale. Together, they explore how attackers are leveraging legitimate authentication flows, trusted infrastructure, and AI-generated phishing lures to blend malicious activity into normal enterprise traffic. The conversation also examines how modern phishing operations have evolved into highly professionalized cybercrime ecosystems and…

  5. S3 · E68 · 6 May 2026 · 52 min

    Russia’s Forest Blizzard Is Abusing Home + Small Office Routers for Cred Theft

    This week on the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo speaks with Danny Adamitis, Distinguished Engineer at Lumen Technologies’ Black Lotus Labs who break down how the Russian state-linked threat actor Forest Blizzard is exploiting home and small office routers to hijack DNS traffic, enabling large-scale surveillance and targeted credential theft. The conversation highlights how this low-cost approach scales globally, why unmanaged routers have become a critical weak point, and how tactics, from brute force to token theft to DNS hijacking continue to evolve. In…

  6. S3 · E67 · 22 Apr 2026 · 40 min

    The Cybercrime Shift: From Opportunistic Attacks to Marketplace-Driven Ecosystem

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo speaks with Maurice Mason and Jackie Burns-Koven to explore how cybercrime has shifted into a highly organized, marketplace-driven ecosystem. They break down the growing convergence between criminal networks and nation-state actors, highlighting how shared tools, infrastructure, and cryptocurrency have blurred traditional boundaries. The conversation dives into the rise of as-a-service cybercrime models, where access, malware, and infrastructure can be easily bought and sold, lowering barriers to entry and…

  7. S4 · E79 · 7 Oct 2026 · 36 minNew

    Inside this year’s Microsoft Digital Defense Report

    In this episode, host Elliot Volkman is joined by Chloe Messdaghi and Karen Frost for a behind-the-scenes look at Microsoft’s annual Digital Defense Report (MDDR). They explore how AI is reshaping the cybersecurity landscape by increasing the speed, scale, and automation of attacks while also giving defenders new tools to detect and respond to threats. The conversation covers AI agents, phishing and identity-based attacks, vulnerability management, security resilience, and the growing need for organizations to connect signals across their environments. Chloe and Karen also share practical…

  8. S4 · E78 · 30 Sep 2026 · 51 min

    From Identity Compromise to AI Defense: Inside Modern Incident Response

    This week we are taking you back to Black Hat USA 2026 and exploring two sides of the security landscape. First, Microsoft incident response experts Adrian Hill and Terry Mee break down identity-based attacks, from compromised credentials and MFA bypasses to containment, logging, access controls, and the growing risks surrounding AI agents. Then, members of Microsoft’s Defender Purple Team discuss how they recreate full attack chains, including emerging AI-driven techniques, to identify detection gaps, strengthen defenses, and use AI to accelerate security research while keeping human…

  9. S4 · E77 · 9 Sep 2026 · 28 min

    Why Threat Actors Love Your RMM

    In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Brandt, Principal Threat Intelligence Incident Commander at Huntress. They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain…

  10. S4 · E76 · 26 Aug 2026 · 31 min

    JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

    In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding…

Every episode of Microsoft Threat Intelligence Podcast →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play