
Free Daily Podcast Summary
by Out of the Woods: The Threat Hunting Podcast
Get key takeaways, quotes, and insights from Out of the Woods: The Threat Hunting Podcast in a 5-minute read. Delivered straight to your inbox.
The most recent episodes — sign up to get AI-powered summaries of each one.
Most threat hunters have more data than they know what to do with. The problem isn't access. It's understanding: what your fields actually mean, what normal really looks like, and where your visibility quietly runs out before a hunt even gets started.This session picks up from our last conversation on environmental context and gets into the work that makes data usable. You don't need to have caught the first episode to follow along.What we'll cover: Building data dictionaries that preserve knowledge and help hunters move faster Mapping telemetry fields to the entities and behaviors that matter during a hunt Baselining normal behavior without creating blind spots Working through noisy data, inconsistent logging, and visibility gaps Communicating coverage and gaps in a way that resonates with leadership Join the Conversation on Discord: https://discord.gg/DR4mcW4zBrWatch the episode here: https://youtu.be/usn3Qt435fg
Top Headlines: Group-IB | HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels: https://www.group-ib.com/blog/hollowgraph-microsoft-365/ The Hacker News | New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html Elastic | New North Korean campaign uses fake coding interviews to steal developer credentials: https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography Island.io | AgentBaiting: How Fake AI Skills Deliver Malware at Scale: https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
Top Headlines: JFrog | Miasma Worm Returns to npm: https://research.jfrog.com/post/miasma-worm-returns-to-npm/ Mind Gard | Cursor 0day: When Full Disclosure Becomes the Only Protection Left: https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left Level Blue | QuimaRAT: A Java RAT with burning ambitions: https://www.levelblue.com/hubfs/Web/Library/Documents_pdf/Threat_Spotlight_An_In_Depth_Analysis_of_QuimaRAT.pdf Blackpoint Cyber | LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software: https://blackpointcyber.com/blog/labubarat-a-rust-based-remote-access-tool-masquerading-as-nvidia-software/ ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
In this episode of Out of the Woods, Scott Poley and Tom Kostura review key findings from the Q2 2026 Threat Hunt Report and discuss what stood out across the quarter. They cover supply chain compromises, growing abuse of Node.js and Bun runtimes, a surge in credential harvesting following the Florida Bleed campaign, and a shrinking window between vulnerability disclosure and exploitation tied to the MS Nightmare vulnerabilities. The episode also touches on recent threat profiles, including the Iranian-linked actor Cavern Manticore and a fast-moving intrusion that went from an SEO-poisoned download to full ransomware encryption in under 48 hours, with a focus on what these patterns mean for threat hunters and defenders.Download the full Q2 2026 Threat Hunt Report: https://www.intel471.com/resources/whitepapers/threat-hunt-report-q2-2026 ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
Top Headlines: welivesecurity | Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances: https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/ Adversa AI | AI coding agents vulnerability: GuardFall shell injeciton: https://adversa.ai/blog/opensource-ai-coding-agents-shell-injection-vulnerability/ JFrog Security Research | Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer: https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/ Blackpoint Cyber | A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain: https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/ ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
Top Headlines: JFrog | From PostCSS Masquerading to Windows RAT: https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/ Elastic | Lost in relocation: analysis of a new loader distributing CASTLESTEALER: https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer SOCRadar | Dismantling-FortiBleed: https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf SANS | Own AI Securely: The SANS Secure AI Blueprint: https://www.sans.org/white-papers/own-ai-securely-sans-secure-ai-blueprint ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
Top Headlines: Trend Micro | Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open: https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html The Hacker News | Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models: https://thehackernews.com/2026/06/researchers-build-self-replicating-ai.html Huntress | Unpatched NTLM Leakage in Windows search: URI Handler, Same Bug, No CVE, No Fix | Huntress: https://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler aikido.dev | Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm: https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm?_gl=1*8wn4a9*_up*MQ..*_gs*MQ..&gclid=Cj0KCQjw_vnQBhCxARIsADcZyxL-SVitznmoZxhQ5DpjJdXLfpMZyybysJ0YaiJmipzBYpqtqpTk2GUaAtsMEALw_wcB&gbraid=0AAAAApQ3BFhNDUDPZ7DnB3pGVCSCcmPoZ ----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
Understanding your environment is one of the most overlooked parts of threat hunting, and one of the most important. This live episode focuses on how to profile your environment, work through both existing and newly onboarded datasets, and build a clear picture of what normal actually looks like across your telemetry.The conversation centers on practical approaches. How to think about your data. How to ask better questions. How to work through common challenges like incomplete visibility, noisy datasets, and inconsistent logging across tools. The session will include real examples, lessons learned, and the methods used to turn raw data into meaningful hunting insight.This episode is built for practitioners who want to move beyond reactive detection and make decisions grounded in a deep understanding of their own systems, data, and gaps.What We’ll Cover: How to profile your environment and baseline normal activity across datasets Approaches for working with new and unfamiliar telemetry sources Techniques for handling noisy data and inconsistent logging Ways to identify and account for visibility gaps Practical examples from real-world threat hunting workflows Watch the episode here: https://youtu.be/Uv46waZVAC0
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from Out of the Woods: The Threat Hunting Podcast in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of Out of the Woods: The Threat Hunting Podcast as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by Out of the Woods: The Threat Hunting Podcast.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
Out of the Woods: The Threat Hunting Podcast publishes biweekly. Our AI generates a summary within hours of each new episode.
Out of the Woods: The Threat Hunting Podcast covers topics including Technology, Business. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.