ShadowTalk: Powered by ReliaQuest
May 27, 2026 · 29 min · 11 segments
Your user clicked a link, landed on a real Microsoft login page, typed their password, completed MFA, and walked away thinking nothing happened. Somewhere across the internet, an attacker's device…
An employee in your organization got a phishing email.
And they were right.
You know, nothing suspicious happened on their end.
But somewhere across the internet, an attacker's device just received an authenticated session token for that account.
The password is irrelevant now.
The MFA prompt is already fired and passed, and a password reset tomorrow morning won't fix anything, because the token stays valid regardless.
That's what we're tracking right now, and it's working at scale.
[upbeat music] Welcome to Shadow Talk, a cybersecurity podcast powered by ReliaQuest, the leader in agentic AI security operations.
I'm Brandon Tirado, director of GrayMatter Operations.
And I'm John Dilgen, threat intelligence analyst.
And to start things off, I have a question for our listeners.
So your phishing defenses passed every check against the phishing email.
So the question is: Why is the attacker already inside your environment?
Read the full transcript.
Create an account to read the whole episode, search across every transcript, and follow the shows you care about.