Episódios

  • ShinyHunters' CRM Heist
    Aug 18 2025

    One phone call was all it took for ShinyHunters to breach some of the world's biggest brands. By exploiting Salesforce to infiltrate Google, Cisco, and many others, this group has shown just how vulnerable organizations can be when well-known SaaS platforms become the attack vector. In this special State of Cybercrime episode, Matt and David break down how ShinyHunters pulled off one of the largest CRM–focused attacks of the year without exploiting a single software vulnerability.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    26 minutos
  • Salt Typhoon Returns
    Jul 25 2025

    After their hidden breach of the National Guard, the cybercrime group was discovered to have targeted a major telecommunications firm named Visat. After their hidden breach of the National Guard, the cybercrime group was found to have attacked a large telecommunications company called Visat. The interesting part—these attacks are not disruptive; Salt Typhoon merely gathers information, hoards credentials and finds vulnerabilities. Because of their stealthy nature, these attacks are only detected after the attackers have already left. To what aim remains to be seen. Matt and David dive into these attacks, and talk about what else is happening in the world of cybercrime.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    19 minutos
  • Copilot's Zero-Click Vulnerability
    Jun 18 2025

    In this episode, Matt and David explore a recently patched Copilot vulnerability that allowed attackers to craft emails that prompted Copilot to send sensitive information to an attacker's server. This prompt injection attack begs the question: What other vulnerabilities will AI bring to data? They also follow up with Scattered Spider & Dragonforce's continued assault on UK Retail and how their tactics are beginning to spread to insurance organizations.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    20 minutos
  • UK Retail Under Siege
    May 21 2025

    Several high-profile UK retailers have suffered serious cyberattacks that have disrupted operations for weeks and, in some cases, exposed sensitive customer data. The social engineering techniques used in the attack align with the notorious Scattered Spider group, but a new ransomware group named Dragonforce has claimed responsibility. Matt and David delve into the details of these attacks, what we know about these cybercriminal groups, and whether they are affiliated. They also cover the Coinbase breach — a calculated, high-stakes extortion scheme where hackers bribed overseas contractors to steal sensitive user data and demand a $20 million ransom. Watch now!

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    22 minutos
  • The Oracle Breach Debate
    Apr 19 2025

    📌 We apologize for the technical issues experienced while filming this episode. Now onto the episode details:

    Oracle recently faced a major security scare after a hacker claimed to have stolen 6 million data records — a breach that has everyone talking. After initially denying the breach, Oracle is now saying their Oracle Cloud Infrastructure has not been compromised, but the exposed data came from old legacy servers. Join Matt and David, along with special guest Joseph Avanzato from Varonis Threat Labs, as they explore the hacker's claims, Oracle's response, and the broader lessons about cloud security and incident management.As always, our hosts will update you on the latest cybersecurity news and share tips on protecting your digital assets.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    24 minutos
  • $1.5B ByBit Crypto Heist
    Mar 14 2025

    The Bybit crypto exchange was hacked for a record-breaking $1.5 billion theft of Ether cryptocurrency – perhaps the largest scale theft of all time. The FBI has linked the attack to TraderTraitor, a sub-cluster of the Lazarus Group, who leveraged a compromised machine of Safe{Wallet} to execute a supply chain attack on the Bybit platform. Matt and David review how this attack unfolded, and share updates on DeepSeek AI and Salt Typhoon. Listen now!

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    27 minutos
  • DeepSeek Disruption
    Feb 4 2025

    DeepSeek, the Chinese AI startup dominating news feeds, has experienced exponential growth while wiping almost $1 trillion off the U.S. stock market. However, the model's rise has now been overshadowed by a surge of malicious attacks.

    On this special episode of State of Cybercrime, Matt and David explore the rise of this innovative AI tool, the subsequent attacks, and the potential vulnerabilities of the AI model. DeepSeek won’t be the last shadow AI app you have to worry about.

    So what steps can you take to ensure you can discover and stop shadow AI apps from inhaling your corporate secrets? Read our latest blog for more insights and immediate actions you can take to protect your organization from shadow AI.

    📌 DeepSeek Discovery: How to Find and Stop Shadow AI: https://www.varonis.com/blog/deepseek

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    21 minutos
  • U.S. Treasury Breach
    Jan 15 2025

    On this episode of State of Cybercrime, Matt and David cover the most recent Chinese state-sponsored APT attack by Silk Typhoon on the U.S. Treasury Department. They discuss how the attackers used a remote support tool to enable unauthorized access to Treasury workstations and unclassified documents. They also dive into some of the most pressing cybersecurity news and recent breaches you should know about.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Exibir mais Exibir menos
    26 minutos