Talos Takes

Patching in the dark: Managing unknown threats in complex environments

23 min · 18. juni 2026
episode Patching in the dark: Managing unknown threats in complex environments cover

Description

If you're tired of being told to "just patch," we understand. The threat landscape is evolving at breakneck speed, with AI-driven tools enabling adversaries to uncover and exploit vulnerabilities before defenders even know they exist. In this episode of Talos Takes, Amy sits down with Threat Intelligence Lead Pierre Cadieux to discuss how to defend against these unknown threats. We move past the simplified advice of "just patch everything" to explore the logistical, technical, and business realities that make patching a complex, high-stakes operation rather than a simple button click. From the necessity of testing your patches to the importance of building strong partnerships between security teams and business leadership, this episode breaks down the things defenders often miss that build true resilience in organizations.

Comments

0

Be the first to comment

Sign up now and become a member of the Talos Takes community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

233 episodes

episode Patching in the dark: Managing unknown threats in complex environments artwork

Patching in the dark: Managing unknown threats in complex environments

If you're tired of being told to "just patch," we understand. The threat landscape is evolving at breakneck speed, with AI-driven tools enabling adversaries to uncover and exploit vulnerabilities before defenders even know they exist. In this episode of Talos Takes, Amy sits down with Threat Intelligence Lead Pierre Cadieux to discuss how to defend against these unknown threats. We move past the simplified advice of "just patch everything" to explore the logistical, technical, and business realities that make patching a complex, high-stakes operation rather than a simple button click. From the necessity of testing your patches to the importance of building strong partnerships between security teams and business leadership, this episode breaks down the things defenders often miss that build true resilience in organizations.

18. juni 202623 min
episode When synthetic logs don’t lie: Generating coherent attack stories for better detection artwork

When synthetic logs don’t lie: Generating coherent attack stories for better detection

Are your detection rules failing because your test data lacks the nuance of a real-world network?  In this episode of Talos Takes, Amy sits down with David Bianco to discuss why traditional synthetic data often falls short and how his new open-source project, EvidenceForge, is changing the game. Synthetic datasets often look like telemetry but lack the critical causal links and realistic background noise that define actual adversary activity. EvidenceForge solves this by creating data that tells a coherent, causal story. From simulating complex attack chains to modeling realistic, "bursty" human behavior, this tool helps threat hunters and detection engineers to sharpen their skills with reproducible, high-quality telemetry. EvidenceForge blog: https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-fake/ [https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-fake/] PEAK Threat Hunting Assistant episode: https://www.buzzsprout.com/2018149/episodes/18825324  [https://www.buzzsprout.com/2018149/episodes/18825324]

3. juni 202619 min
episode The trust paradox: How attackers weaponize legitimate SaaS platforms artwork

The trust paradox: How attackers weaponize legitimate SaaS platforms

In this episode of Talos Takes, Amy Ciminnisi sits down with researcher Diana Brown to discuss the rise of "platform-as-a-proxy" (PAP) attacks. We explore how threat actors are weaponizing legitimate SaaS platforms like GitHub and Jira to deliver phishing campaigns that bypass traditional security filters. By leveraging the platforms' own infrastructure to send authenticated emails, attackers are exploiting the inherent trust employees place in these essential business tools. We break down the mechanics of these campaigns and provide actionable strategies for security teams to move beyond binary trust and implement contextual awareness to better protect their organizations. Blog: https://blog.talosintelligence.com/weaponizing-saas-notification-pipelines/ [https://blog.talosintelligence.com/weaponizing-saas-notification-pipelines/]

7. maj 202620 min
episode It's not you, it's your printer: State-sponsored and phishing threats in 2025 artwork

It's not you, it's your printer: State-sponsored and phishing threats in 2025

In this episode, we unpack state-sponsored and phishing trends from the 2025 Talos Year in Review. Amy and Martin Lee explore the alarming rise of internal phishing campaigns that bypass traditional perimeter defenses, including the widespread weaponization of Microsoft 365's Direct Send feature. Beyond simple phishing, we analyze the aggressive, blended operations of state-sponsored actors from China and North Korea who are combining high-level zero-day exploits with sophisticated social engineering. From the "Dear Leader" interview test to the reality of fake developer personas, we break down exactly how these adversaries are infiltrating modern organizations.  2025 Year in Review report: https://blog.talosintelligence.com/2025yearinreview/ [https://blog.talosintelligence.com/2025yearinreview/]

21. apr. 202628 min
episode 2025's ransomware trends and zombie vulnerabilities artwork

2025's ransomware trends and zombie vulnerabilities

In this episode, Amy and Pierre Cadieux unpack the ransomware and vulnerability trends that defined 2025. From the persistent ransomware threats targeting the manufacturing sector to the rise of stealthy "living off the land" tactics, we break down what these shifts mean for your defense strategy. Why are attackers are increasingly targeting your management infrastructure? How do you spot the difference between a system admin and a threat actor? Tune in to hear Talos' insights on how to move beyond reacting to threats and start building a more resilient, proactive security posture for the year ahead.  View the 2025 Year in Review here: https://blog.talosintelligence.com/2025yearinreview/ [https://blog.talosintelligence.com/2025yearinreview/]

7. apr. 202622 min