Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Microsoft researchers Kelsey Clapp and Anna Seitz to examine two major cybercrime campaigns. The team unpacks Storm 2561’s use of SEO poisoning to distribute Trojanized software like SilentRoute and Bumblebee, stealing VPN credentials and paving the way for ransomware brokers. They also dive into Storm 1811’s ReadBed malware, a loader deployed through bold social engineering tactics, such as fake IT help desk calls via Teams, that enable lateral movement and ransomware deployment. The…

Microsoft Threat Intelligence Podcast

by Microsoft · English · Tech & Science

Join us to hear stories from the Microsoft Threat Intelligence community as they navigate the ever-evolving threat landscape - uncovering APTs, cybercrime gangs, malware, vulnerabilities, and other weird and cool tools and tactics in the world of cyber threats. Featuring tales of innovation,…

More from Microsoft Threat Intelligence Podcast

  1. S1 · E55 · 22 Oct 2025 · 47 min

    The New Frontlines of Cybersecurity: Lessons from the 2025 Digital Defense Report

    In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Chloé Messdaghi and Crane Hassold to unpack the key findings of the 2025 Microsoft Digital Defense Report; a comprehensive look at how the cyber threat landscape is accelerating through AI, automation, and industrialized criminal networks. They explore how nation-state operations and cybercrime have fused into a continuous cycle of attack and adaptation, with actors sharing tooling, infrastructure, and even business models. The conversation also examines AI’s growing impact, from deepfakes and…

  2. S1 · E54 · 8 Oct 2025 · 31 min

    Threat Landscape Update: Ransomware-as-a-Service and Advanced Modular Malware

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Tori Murphy, Anna Seitz, and Chuong Dong to break down two threats: the modular backdoor PipeMagic and Medusa ransomware. They discuss how PipeMagic disguises itself as a ChatGPT desktop app to deliver malware, its sophisticated modular design, and what defenders can do to detect it. The team also explores Medusa’s evolution into a ransomware-as-a-service model, its use of double extortion tactics, and the broader threat landscape shaped by ransomware groups, social engineering, and the abuse…

  3. S1 · E53 · 24 Sep 2025 · 26 min

    Stopping Domain Impersonation with AI

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Kelly Bissell, Corporate Vice President at Microsoft, to explore how domain impersonation and typosquatting are changing in the age of AI. They discuss how attackers are increasingly using AI and bots to scale online deception, why this tactic is so effective, and how Microsoft is countering cutting-edge defenses like Siamese neural networks to detect fraudulent domains in real time. Kelly shares insights on the massive scale of these threats, the shift toward defender advantage, and the…

  4. S1 · E51 · 27 Aug 2025 · 44 min

    Live from Black Hat: Ransomware, Responsible Disclosure, and the Rise of AI

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is live from Black Hat 2025 with a special lineup of Microsoft security leaders and researchers. First, Sherrod sits down with Tom Gallagher, VP of Engineering and head of the Microsoft Security Response Center (MSRC). Tom shares how his team works with researchers worldwide, why responsible disclosure matters, and how programs like Zero Day Quest (ZDQ) are shaping the future of vulnerability research in cloud and AI security. He also announced the next iteration of ZTQ with $5 million up for grabs. Next,…

  5. S1 · E50 · 7 Aug 2025 · 1 hr 18 min

    How Microsoft Stays Ahead of the World’s Most Dangerous Hackers

    In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo is joined by Aarti Borkar, Simeon Kakpovi, and Andrew Rapp for a behind-the-scenes look at how Microsoft Threat Intelligence and Microsoft Incident Response teams collaborate as part of a closed-loop system, the emotional toll of breaches, and how organizations of any size can build resilience through preparation and psychological safety. By listening to this segment, you’ll get a preview of what this group brought to the main stage of Black Hat this year. Later, Sherrod chats with Snow, co-founder of the…

  6. S4 · E79 · 7 Oct 2026 · 36 min

    Inside this year’s Microsoft Digital Defense Report

    In this episode, host Elliot Volkman is joined by Chloe Messdaghi and Karen Frost for a behind-the-scenes look at Microsoft’s annual Digital Defense Report (MDDR). They explore how AI is reshaping the cybersecurity landscape by increasing the speed, scale, and automation of attacks while also giving defenders new tools to detect and respond to threats. The conversation covers AI agents, phishing and identity-based attacks, vulnerability management, security resilience, and the growing need for organizations to connect signals across their environments. Chloe and Karen also share practical…

  7. S4 · E78 · 30 Sep 2026 · 51 min

    From Identity Compromise to AI Defense: Inside Modern Incident Response

    This week we are taking you back to Black Hat USA 2026 and exploring two sides of the security landscape. First, Microsoft incident response experts Adrian Hill and Terry Mee break down identity-based attacks, from compromised credentials and MFA bypasses to containment, logging, access controls, and the growing risks surrounding AI agents. Then, members of Microsoft’s Defender Purple Team discuss how they recreate full attack chains, including emerging AI-driven techniques, to identify detection gaps, strengthen defenses, and use AI to accelerate security research while keeping human…

  8. S4 · E77 · 9 Sep 2026 · 28 min

    Why Threat Actors Love Your RMM

    In this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Brandt, Principal Threat Intelligence Incident Commander at Huntress. They explore how cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) tools, why trusted remote-access software has become an attractive alternative to traditional malware, and how AI is improving phishing and social engineering. Spike also breaks down a real-world attack that deployed multiple RMM tools to maintain…

  9. S4 · E76 · 26 Aug 2026 · 31 min

    JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

    In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding…

  10. S4 · E75 · 12 Aug 2026 · 24 min

    Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report

    In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director⁠ Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate. Crane also shares practical security recommendations for organizations and explains how Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform led to a…

Every episode of Microsoft Threat Intelligence Podcast →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play