Skip to main content
Advanced persistent threat

Advanced persistent threat

Search complete. 36 mentions across 17 episodes found for "Advanced persistent threat".

Sep 22, 2026

speaker_0HOST
7:10
Side Copy, which is also tracked as Tag 140, they're a group with heavy tactical overlaps with Transparent Tribe.
speaker_0HOST
7:18
So they are a Pakistan-based APT active since about 2019, right? Now, historically, they've gone after Indian defense forces or government networks like the Afghan Ministry of Finance.
speaker_0HOST
7:30
But Trellix recently documented a massive shift.
speaker_0HOST
7:34
They are now heavily spear phishing academic institutions in India.
speaker_1HOST
12:19
And at the network layer, you need to hunt for anomalous traffic on non-standard ports like 5863.
speaker_0HOST
12:25
It's just an intense game of cat and mouse.
speaker_0HOST
12:27
We've talked about malware hiding inside application architecture and APTs living visibly in system memory, which really brings us to the irony of our third section.
speaker_0HOST
12:37
Because while you are out there hunting for highly complex, reflectively loaded .NET objects.
John HammondGUEST
6:25
That style of using a delimiter and de-obfuscating stuff within a Google Drive is known to Kim Suki, which is the name of the adversary or threat actor.
John HammondGUEST
6:34
It's a North Korea APT, Advanced Persistent Threat.
John HammondGUEST
6:38
And we thought, whoa, okay, stakes are a little bit
David Dean MauroHOST
6:40
high.
John HammondGUEST
8:37
targeted information espionage from an advanced persistent threat on a place of certain caliber, position, and
David Dean MauroHOST
8:44
power.
John HammondGUEST
8:46
But, the question that everyone wants to ask, right, when we get to tell the story to, I don't know, journalists or headlines, what everyone tends to ask is, how do they get in? How do the hackers break into the environment? So, finding and discovering that this was Kimsuki, that APT, their tradecraft and their style is to use a phishing email, fair to say.
John HammondGUEST
9:06
So,

Unknown podcast

2026-09-16: Cisco discloses a critical zero-day in Secure Email Gateway already exploited in the wild with

Sep 16 · 1 Mention

CarolinaHOST
5:44
Source, Security Week.
CarolinaHOST
5:46
Night Eagle APT, Advanced Persistent Threat, targets Russian companies Kaspersky, GERT-investigated Night Eagle, AppQ95.
CarolinaHOST
5:54
Incidents targeting Russian businesses using compromised VPN credentials for initial access.
CarolinaHOST
6:00
Tackers deployed Ghost Container Backdoor on Microsoft Exchange servers, incorporating neorejorgtunnel, CVE-2020-0688 exploit, and Ghost web shell components.
Dennis FisherHOST
2:14
Th-there's a lot of disconnects, at least in my experience, in the entire AI spectrum here from how much it's being used in vulnerability research in, in the real world as opposed to sort of the testing from an elite cadre of people who are very good at this anyway and are now just using frontier models to do the tippy top of that kind of work that took them forever and a day before, and now they're just like, "Okay, let me use this highly trained model to do that stuff that I could do but would take me longer." But like, uh, I mean, I guess we don't totally know the answer to this, but are there...
Dennis FisherHOST
2:57
You know, I don't know that we've seen a bunch of cybercrime groups doing this or, y-you know, APT teams doing this kind of stuff.
Dennis FisherHOST
3:04
Maybe they are in limited capacities, but I'm not seeing like broad evidence of that.
Jeremiah GrossmanGUEST
3:11
If, uh, if we iso- you know, the, the adversary is us- using some amount of AI in their overall campaigns, but if we isolate ourselves to using AI to find and exploit a vulnerability in the wild for some kind of material harm, we haven't seen one yet.

41 MINS LATER

Jeremiah GrossmanGUEST
44:24
They, they never have.
Dennis FisherHOST
44:26
Yeah, they, they have their own stuff and, you know, they, they sell it and trade it back and forth and that, that kind of stuff.
Dennis FisherHOST
44:32
I, I do assume that they have these discussion amongst themselves like, like we said earlier, and they're-- they, you know, they bend towards efficiency and what's gonna make me the most money or achieve my goal in the most efficient manner, right? Like depending on what they're-- if they're a cybercrime group or an APT group.
Dennis FisherHOST
44:53
Like if you're an APT, I've got these orders from my boss, gotta go, go do this thing in the most efficient way possible.

Unknown podcast

2026-09-13: CISA added five actively exploited flaws to the KEV catalog with patch deadlines through September

Sep 13 · 4 Mentions

CarolinaHOST
0:00
Cyber Threat Brief for September 13, 2026 CISA, the Cybersecurity and Infrastructure Security Agency, added five actively exploited flaws to the KEV, Known Exploited Vulnerabilities Catalog, catalog with patch deadlines through September 25, including artifactory bugs chained for admin takeover and a Screen Connect flaw enabling unauthorized file execution.
CarolinaHOST
0:22
Chinese APT, Advanced Persistent Threat, groups deployed a new exploit kit called Blue Moon that chains three zero days in Chrome and Windows, spreading across multiple espionage operations within days.
CarolinaHOST
0:33
Google leaked identifying information for sex crime victims globally through its content removal request system.
CarolinaHOST
0:39
Here's the full breakdown of today's top security stories.
CarolinaHOST
0:42
1.
CarolinaHOST
0:43
CISA, the Cybersecurity and Infrastructure Security Agency, Kev Known Exploited Vulnerabilities Catalog, Additions 5 Actively Exploited Vulnerabilities, Artifactory, Screen Connect, Router OS, High Priority 2, BlueMoon Exploit Kit Chrome Slash Windows Zero Day Chain Used by Chinese APT, Advanced Persistent Threat, Groups High Priority 3.
CarolinaHOST
1:03
XFCE desktop customization not security relevant should be excluded 4.
CarolinaHOST
1:08
NVIDIA slash GROK DOJ investigation not threat intelligence should be excluded 5.
Claire AirdHOST
8:07
The campaign took place in late March, a week after Google and other security vendors publicly exposed the existence of the DarkSword kit.
Claire AirdHOST
8:17
At least four different APT groups are using a new exploit kit to hack into Windows computers.
Claire AirdHOST
8:23
The BlueMoon kit uses Chrome and Windows zero-days to deploy malware on a user's computer if they click a malicious link inside a Chromium-based browser.
Claire AirdHOST
8:33
The kit was spotted in late August.

Unknown podcast

2026-09-11: Cisco firewalls are under attack by state-sponsored groups and Qilin ransomware

Sep 11 · 3 Mentions

CarolinaHOST
0:53
CVSS, a common vulnerability scoring system, 10.0 authentication bypass, to deploy JSB web shells and harvest credentials.
CarolinaHOST
1:02
UAT 11823 exploited both flaws to deliver Cyclops blink malware, attributed to Russian APT, advanced persistent threat, Sandworm.
CarolinaHOST
1:11
UAT 11988 exploited, CVSS 5.3 static credential for kill-in ransomware deployment using legitimate FMC tooling for reconnaissance, credential theft, and endpoint targeting.
CarolinaHOST
1:24
Added to CISA, the Cybersecurity and Infrastructure Security Agency, KEV, Known Exploited Vulnerabilities Catalog with September 12 deadline was added in July with an August 1 deadline now passed.

15 MINS LATER

CarolinaHOST
16:24
Never enter seed phrases into websites, sources, the register Trezor.
CarolinaHOST
16:30
Next section, patch priority.
CarolinaHOST
16:32
Cisco Secure FMC, CVE-2026-20079, CVSS 10.0, and CVE-2026-20316, CVSS 5.3, exploited by APT and ransomware.
CarolinaHOST
16:46
Apply hotfixes immediately.
Roger StoneHOST
17:39
It was October 22nd.
Roger StoneHOST
17:41
The Cybersecurity and Infrastructure Security Agency, that's CISA and the FBI, published a joint cybersecurity advisor warning that the Iranian Advanced Persistent Threat, APT, were likely intent on influence and interfering.
Roger StoneHOST
17:57
with the U.S. elections to show discord among voters and undermine public confidence in the U.S. electoral process.
Roger StoneHOST
18:06
So in other words, it was Iranian collusion, not Russian collusion.
Roger StoneHOST
18:11
Those same advanced persistent threat actors were creating fictitious media sites and spoofing legitimate media sites to spread anti-American propaganda and disinformation as well as voter suppression why are you hearing about it now for the first time here in the stone zone it's typical of the kind of information that no one else brings you but us we'll be right back
speaker_1NARRATOR
18:46
This is the Stone Zone.
speaker_1NARRATOR
18:48
Now, give him his own.

Unknown podcast

2026-09-10: Multiple Chinese espionage groups are rapidly exploiting a Chrome/Windows zero-day chain

Sep 10 · 4 Mentions

CarolinaHOST
2:03
Proofpoint CyberScoop CISA.
CarolinaHOST
2:06
Cisco Secure Firewall Management Center Under Active Attack CVE-2026-20079 CVE-2026-20316 Cisco Talos Confirmed Active Exploitation of Critical Authentication Bypass CVE-2026-20079 CVSS The Common Vulnerability Scoring System 10.0 Low Privilege Login Vulnerabilities in Cisco Secure FMC Software Three Distinct Threat Actor Clusters Identified UAT 12197 deployed web shells and credential exfiltration tools, UAT 11823, linked to Russian APT, advanced persistent threat, sandworm, deployed Cyclops blink malware, and UAT 11988, assessed as Killen ransomware affiliate.
CarolinaHOST
2:50
Conducted extensive reconnaissance and built endpoint encryption target lists, added to CIS a KEV with August 1 remediation deadline, already passed.
CarolinaHOST
2:59
Hotfixes released.

9 MINS LATER

CarolinaHOST
11:36
CIS-KEV deadlines September 18 and 22, and two additional CVEs.
CarolinaHOST
11:41
See show notes for the full list.
CarolinaHOST
11:43
Cisco Secure FMC, critical authentication bypass, CVE-2026-20079, CVSS 10.0, exploited by APT and ransomware.
CarolinaHOST
11:53
Apply hotfixes immediately.
Artificial IntelligenceNARRATOR
11:03
Cyber Safety Review Board, Review of the December 2021 Log4j Event, July 11th, 2022.
Artificial IntelligenceNARRATOR
11:10
CISA, Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations.
Artificial IntelligenceNARRATOR
11:18
SolarWinds SUNBURST Advisory.
Artificial IntelligenceNARRATOR
11:21
SolarWinds, An Investigative Update of the Cyberattack.

7 more episodes mention Advanced persistent threat.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.