Find partners
DISCARDED: Tales From the Threat Research Trenches

DISCARDED: Tales From the Threat Research Trenches

Hosted by Proofpoint

Episodes

110

Latest episode

Aug 2026

Language

EN

About the show

DISCARDED: Tales from the Threat Research Trenches is a podcast for security practitioners, intelligence analysts, and threat hunters looking to learn more about the threat behaviors and attack patterns. Each episode you’ll hear real world insights from our researchers about the latest trends in malware, threat actors, TTPs, and more. Welcome to DISCARDED

Listen to episodes

60 recent
August 11, 2026Episode 1081 hr 3 min

Half-Click is so Hot Right Now: How Russian and Chinese Attackers Exploit Mailservers

Send us fan mail! Hello to all our cyber stars! Host Selena Larson is joined by co-host Sarah Sabotka, along with returning guest Greg Lesnewich, Principal Threat Research Engineer, and Staff Threat Researcher Mark Kelly, for a follow-up to last episode's half-click deep dive — this time tracking how the technique is spreading beyond TA458 and TA488 into a brand-new Chinese cluster. Greg picks up where last week left off with TA488 (aka Void Blizzard, aka Laundry Bear): after going quiet in February following exposure, the group resurfaced on July 22 — one day before Proofpoint's joint advisory with the NSA — with a new half-click exploit against Microsoft Outlook Web Access. The payload, a previously unseen browser-resident implant called OWAReaper, is built for persistence: it survives credential rotation, browser restarts, and even a full device reimage, and it phones home via GitHub commit messages and image requests proxied through legitimate CDNs like Slack and WordPress. Mark then brings a new actor into the half-click conversation: UNK_MassTraction, a suspected China-aligned cluster exploiting a cross-site scripting flaw in Roundcube to target physics and engineering departments at North American universities — chosen, it turns out, specifically because they were running vulnerable Roundcube instances. The infection chain drops either a webshell or VShell, a Linux backdoor of murky, possibly commercially-developed origin that keeps popping up across Chinese state-sponsored intrusions. The conversation covers: How OWAReaper's persistence differs from anything Greg's seen before — including "poisoning" a user's other emails to reinfect the browser on every new tab Why Greg's assessment of TA488 shifted from "less capable than TA458" to "neck and neck" after seeing this campaign How Mark and Greg discovered UNK_MassTraction independently, within hours of each other Why UNK_MassTraction's targets were all running vulnerable Roundcube — evidence of deliberate reconnaissance, not spray-and-pray IceCube, the Roundcube stealer with telltale signs of LLM-assisted development Why mail servers are functionally edge devices, and what that means for defenders who can't run EDR on them Whether AI is accelerating adversary tradecraft on both the Russian and Chinese sides The ethics of publishing offensive research on a live, evolving technique The funniest (and most unsettling) lure email of the year: "Hi fellow, I really liked your vibe..." Plus: Gus the dog's podcast debut, security awareness training in a world where opening an email can be enough, and shoutouts to Tom Lancaster (Volexity) and Microsoft's patch team. Resources Mentioned: Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit TA488 Targets Zimbra Mailservers with Half-Click Exploits One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation For more information about Proofpoint , check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

August 4, 2026Episode 10747 min

Half-Click, Full Compromise: Inside Russia's TA458 and TA488 Espionage Playbook

Send us fan mail! Hello to all our cyber roosters! Host Selena Larson is joined by co-host Sarah Sabatka and returning guest Greg Lesnewich, Principal Threat Researcher at Proofpoint, to unpack two new reports on Russian aligned espionage actors abusing “half-click” exploits, which are vulnerabilities that compromise a target the moment they open an email in a vulnerable webmail viewer, no link or attachment required. Greg breaks down the two distinct actors covered in Proofpoint's research: TA458, a mature, well-resourced group active across multiple webmail platforms (Zimbra, MDaemon, Roundcube, SOGo, and Horde) primarily targeting Ukraine, Eastern Europe, and militaries/ministries of foreign affairs; and TA488 (aka Void Blizzard, aka Laundry Bear), a comparatively scrappier contractor operation that leaned on a single Zimbra zero-day dubbed “ZimReaper” to steal credentials, full mailboxes, and up to 90 days of email history from Ukrainian government and U.S. targets. The conversation covers how the half-click technique works under the hood (stored cross-site scripting via mishandled JavaScript event handlers in webmail HTML), how it differs from traditional phishing, the evidence pointing to a possible link between TA458 and GRU Unit 20728, why TA488's contractor status may explain its skittishness (burning down infrastructure after being outed) versus TA458's higher risk tolerance (including repeatedly firing exploits at targets that weren't even running vulnerable software), and what defenders running Zimbra, Roundcube, or similar platforms can actually do about it. Resources Mentioned: https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

July 21, 2026Episode 10635 min

StealC Exposed: Tracking, Emulating, and Disrupting a Top Info Stealer

Send us fan mail! Hello to all our Cyber Pals! Host Selena Larson is joined by Golo Mühr, Malware Reverse Engineer, X-Force Threat Intelligence and Kyle Cucci (Staff Threat Researcher, Proofpoint) to break down the joint research that helped power a major Operation Endgame disruption. Coordinated by Europol, the operation hit 66 domains and 296 servers tied to StealC and its close cousin Amadey, and led to the seizure of more than 25.6 million unique credentials stolen from over 385,000 compromised sites. In this episode, Golo and Kyle take us inside the investigation: How they built a custom StealC emulator to impersonate infected bots, talk to live C2 servers, and pull down real second-stage payloads The tangled relationship between StealC and Amity, and how shared panels and configs let researchers cluster affiliates together Why StealC sometimes delivers... more StealC (spoiler: probably not a masterplan) A juicy case of "no honor among thieves" — evidence that one affiliate exploited a panel vulnerability to steal from other affiliates The one confirmed instance of StealC delivering LockBit Black ransomware, caught in the wild via emulation Why info stealers have become so attractive to threat actors compared to ransomware — lower risk, easier monetization, less law enforcement heat (until now) What "success" actually looks like in a takedown, and why Kyle's proposed "pyramid of pain" for disruptions puts arrests at the top and infrastructure takedowns at the base Plus: fake software downloads, sketchy YouTube game-crack links, public-private collaboration with law enforcement, and a well-earned shoutout to Proofpoint's Isaac for calling this threat over a decade ago. Tune in for a deep dive into how threat intel teams track, emulate, and ultimately help dismantle one of the internet's most active credential-theft operations. Resources Mentioned: https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame https://www.proofpoint.com/us/blog/threat-insight/threat-actors-deliver-malware-youtube-video-game-cracks For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

July 7, 2026Episode 10538 min

OMITB: Trusting the wrong package.

Send us fan mail! Hello to all our Cyber Pals! This week, we present a special replay of "Only Malware in the Building," the podcast that our host, Selena Larson, also co-hosts! Enjoy! Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ , ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcast ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠DISCARDED⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ . Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by her co-hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠N2K Networks⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Keith Mularski⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ , former FBI cybercrime investigator and now Chief Global Ambassador at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Qintel⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ . Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. This week, our hosts dive into the evolving threat of software supply chain attacks and the growing risks facing the open-source ecosystem. As developers increasingly rely on third-party packages and AI-powered coding tools, attackers are finding new ways to abuse trusted software to reach a wider range of targets. The discussion explores why these attacks are becoming more common, what recent incidents reveal about the state of software security, and what organizations can do to better protect themselves. Sources: ⁠ Shai-Hulud worm returns stronger and more automated than ever before ⁠ ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack ⁠ What We Learned: Axios NPM Supply Chain Compromise Emergency Briefing Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise

June 23, 2026Episode 10452 min

From Phishing to Court Cases: How Microsoft Fights Back Against Hackers

Send us fan mail! Hello to all our Cyber Pals! Host Selena Larson is joined by Sean Farrell, Assistant General Counsel at Microsoft's Digital Crimes Unit (DCU), to pull back the curtain on how major cyber crime takedowns actually happen and how Microsoft uses civil lawsuits, criminal referrals, and global partnerships to disrupt some of the most damaging cyber crime operations in the world. They discuss: What DCU does and Sean's path from FBI to AWS to Microsoft How civil claims like the CFAA and RICO are used to seize infrastructure The Fox Tempest takedown and its ties to Rhysida ransomware The global disruption of the Tycoon 2FA phishing-as-a-service operation How targets get chosen, and civil vs. criminal action Why naming victims changes the public narrative on cyber crime Arrests tied to Octo Tempest/Scattered Spider The risks of AI-generated sloppiness in legal and threat intel work Disrupting cyber crime isn't about ending it for good, it's about raising the cost of doing business until bad actors run out of road. Resources Mentioned: https://www.microsoft.com/en-us/corporate-responsibility/customer-security-trust/digital-crimes-unit https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/ https://www.proofpoint.com/us/blog/threat-insight/disruption-targets-tycoon-2fa-popular-aitm-phaas For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

June 9, 2026Episode 1031 hr 5 min

Diving Into the DBIR: Vulnerabilities, AI, and Supply Chain

Send us fan mail! Hello to all our Cyber Pals! Host Selena Larson is joined by guest host Sarah Sabotka as they chat with returning guest: Alex Pinto, Associate Director of Threat Intelligence at Verizon Business, and the architect behind the Verizon Data Breach Investigations Report. Alex joins hosts Selena Larson and Sarah Sabatka to break down the most important findings from this year's report — and there's a lot to unpack. From vulnerabilities overtaking credential abuse as the leading initial access vector, to the sobering reality that organizations are patching more but getting worse outcomes, this year's DBIR paints a complex picture of a threat landscape under pressure. The team also digs into the rise of pretexting and voice-based social engineering, what the data actually says about GenAI and threat actors (spoiler: mostly reinventing the wheel — for now), and why third-party and supply chain compromises are quietly becoming one of the biggest stories in security. They discuss: The VERIS framework and why standardization in threat intelligence matters Ransomware taxonomy, data extortion, and why classification is still a headache Pretexting vs. phishing — and why they require completely different defenses Vulnerability exploitation as the new number one initial access vector Patching capacity and why outcomes are getting worse despite more effort What the DBIR data actually shows about GenAI usage by threat actors Third-party and supply chain breaches — up 60% year over year Shadow AI and the emerging DLP problem no one's fully ready for A sneak peek at Verizon's upcoming cost-of-a-data-breach report The DBIR drops once a year — make sure you're getting the most out of it with this breakdown straight from the source, all 121 nutritious, fiber-rich pages of it. Resources Mentioned: 2026 DBIR For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

May 27, 2026Episode 10246 min

"Always Intentional": A CISO's Pragmatic Take on the Agentic Era

Send us fan mail! What does it actually look like to bring AI into a threat intelligence program at one of the internet's most iconic companies? Hello to all our Cyber Pals! Host Selena Larson is joined by guest host, Sarah Sabotka as they chat with Sean Zadig, Chief Information Security Officer (and "Chief Paranoid") at Yahoo, for a candid conversation about the evolving intersection of AI and cybersecurity. Sean shares how Yahoo's security team, the Paranoids, is navigating the agentic AI transformation: from running a company-wide "skill-a-thon" to get every team member building Claude-powered tools, to rethinking legacy infrastructure from the ground up. He also opens up about what keeps him up at night; including the looming threat of AI-powered exploit frameworks like Mythos, the growing signal-to-noise problem in threat intel feeds, and the very real risk of analyst burnout as the pace of the industry accelerates. But Sean's outlook is surprisingly optimistic. He argues that defenders have a home-field advantage, that the best code ever written is just 12–18 months away, and that the goal of AI in security shouldn't be doing more with fewer people–it should be building more resilient teams. For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

May 12, 2026Episode 10153 min

A Device Code Explosion: The New Era of AI-Enabled Phishing

Send us fan mail! Hello to all our Cyber Sunbeams! Host Selena Larson is joined by guest host, Sarah Sabotka as they chat with Jake Gionet to unpack one of the fastest-growing threats in today’s cyber landscape: device code phishing. What started as a niche technique used in red team exercises has quickly evolved into a widely adopted method for account takeover—fueled by publicly available phishing kits and accelerated by AI-assisted tooling. The trio breaks down how device code phishing works, why it’s suddenly everywhere, and how attackers are exploiting legitimate authentication flows to bypass traditional defenses. They also explore the rise of “phishing-as-a-service” platforms like Evil Tokens, the surprising lack of sophistication behind many campaigns, and how AI is both enabling attackers and exposing their mistakes. Along the way, they dig into real-world examples, threat actor missteps, and the blurry line between innovation and imitation in cybercrime. If you’ve been hearing the buzz around device code phishing and want a clear, grounded explanation—without the hype—this episode delivers. Plus, practical insights on what defenders should actually focus on as these techniques continue to evolve. Resources Mentioned: https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

April 28, 2026Episode 1001 hr 0 min

Champagne with Our Campaigns: A 100th Episode Happy Hour

Send us fan mail! Hello to all our Cyber Pals, Cyber Centaurs, Cyber Stars, and listeners who have been with us for 100 episodes! It’s our 100th episode—and we’re raising a glass to celebrate. 🥂 Host Selena Larson is joined by long-time guest hosts, Sarah Sabotka and Tim Kromphardt, and honorary host, VP of Proofpoint Threat Research Daniel Blackford, for this commemorative episode of Discarded! We reflect on the journey so far, revisit standout moments, and look ahead to what’s next in cybersecurity. From unforgettable guests and inside jokes to real lessons learned from years of tracking threat actors, this episode is part celebration, part reflection, and part unfiltered cyber chat. We dig into: Favorite podcast guests and the insights that stuck with us The reality vs. hype of AI in cybersecurity (and what’s actually useful) How threat actors are evolving—and where they’re… not The surprising truth about targeting, myths in the industry, and why attackers don’t need to be sophisticated to be effective Behind-the-scenes looks at the tools and research we’re building right now Plus, we answer listener questions, share a few laughs (and a few drinks), and talk about what the next 100 episodes might hold. Whether you’ve been with us since episode one or just discovered the show, this milestone episode is a thank-you to our listeners—and a reminder that cybersecurity is as much about people as it is about technology. Cheers to 100 episodes. 🍾 Resources Mentioned: https://www.nytimes.com/2026/04/04/technology/ai-chatbots-teen-roleplay.html For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

April 14, 2026Episode 9933 min

Magic Packets & Stealth Backdoors: The Art of Detection Engineering

Send us fan mail! Hello to all our Cyber Daffodils! Host Selena Larson, and guest Host, Tim Kromphardt, sit down with Stuart Del Caliz, Senior Threat Detection Engineer at Proofpoint, to unpack the stealthy world of backdoors, malware detection, and the “secret signals” threat actors use to stay hidden. From magic packets and port knocking to sophisticated backdoors like BPFdoor, Stuart shares how attackers design covert communication methods—and how defenders work to uncover them without overwhelming security teams with noise. The conversation blends deep technical insight with real-world analogies (think speakeasy knocks and undercover “internet cops”) to make complex detection strategies easier to understand. You’ll also hear: How detection engineers balance accuracy and performance when writing IDS/IPS signatures Why some advanced malware can remain undetected for years—and whether we’re simply not seeing it How historic leaks like Shadow Brokers still influence modern attack techniques The role of “pattern matching” in identifying evolving malware behaviors How file metadata and revoked certificates can reveal threats hiding in plain sight Why community collaboration and feedback loops are critical to stronger detections Whether you’re a security practitioner or deep in the trenches, this episode offers a closer look at the craft of detection engineering—and the constant challenge of writing high-fidelity detections against increasingly evasive threat techniques. Resources Mentioned: https://community.emergingthreats.net/ https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/ https://www.wired.com/story/nsa-hacking-tools-stolen-hackers/ https://github.com/x0rz/EQGRP For more information about Proofpoint, check out our website . Subscribe & Follow: Stay ahead of emerging threats, and subscribe! Happy hunting!

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts