
Free Daily Podcast Summary
by N2K Networks
Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.
The most recent episodes — sign up to get AI-powered summaries of each one.
Today we are joined by Dr. Renée Burton, VP of Threat Intelligence at Infoblox, discussing their work on Lurking Lizard, "Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real." The research uncovers Lurking Lizard, a threat actor that has operated since at least 2022 by using fake software installers, VPNs, and lookalike domains to secretly turn victims’ devices into residential proxy nodes. Researchers identified more than 230 related domains and connected seemingly separate campaigns—including fake 7-Zip, downloader tools, and WireVPN—through shared infrastructure, tracking URLs, deployment patterns, and APIs. The investigation suggests the actor runs an end-to-end proxy operation, recruiting compromised devices and then monetizing their bandwidth through proxy services and fake review sites, with WireVPN appearing to be the latest evolution of the campaign. The research and executive brief can be found here: Fake Installers, Fake Reviews, Fake Services - Real Proxies, Real Victims
Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques to evade defenses. In a recent attack, the threat actors used AnyDesk for remote access, a broad credential-harvesting toolkit, and the PoisonX malicious kernel driver to disable endpoint security before deploying the ransomware. The activity highlights Hyadina’s continued development of its ransomware operations and an escalation in its defense-evasion capabilities. The research and executive brief can be found here: GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks
Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool. The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities. The research and executive brief can be found here: LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools
Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers have identified an evolved version of the SHEETCREEP espionage campaign, using a diplomatic-themed ISO phishing lure to deliver a C# remote access trojan targeting Indian diplomatic interests. The malware abuses the Google Sheets API as a stealthy command-and-control channel, with researchers identifying 91 active victim tabs, including a high-confidence target in Pakistan. The campaign, assessed with moderate confidence as linked to Pakistan-aligned APT36, has added XOR-obfuscated configurations and other anti-analysis techniques to evade detection and maintain persistent access. The research and executive brief can be found here: Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation
Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation
Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command. The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a .NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised. The research and executive brief can be found here: Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs
Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from Research Saturday in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of Research Saturday as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by N2K Networks.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
Research Saturday publishes weekly. Our AI generates a summary within hours of each new episode.
Research Saturday covers topics including News, Technology. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.