Épisodes

  • The React2Shell Crisis
    Dec 15 2025
    React2Shell, the zero-click RCE exploit, is rapidly becoming one of the most significant cybersecurity incidents this year. From emergency patches causing a massive Cloudflare outage to active exploitation by China and North Korea-linked groups, this flaw may be the next Log4Shell moment for enterprises and developers alike. Join Matt and David for an episode of State of Cybercrime that breaks down how attackers are weaponizing this vulnerability and what organizations must do to stay safe. They will also dive into the Shai-hulud 2.0 assault on cloud infrastructure as well as the biggest DDoS attack ever recorded. More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: https://www.linkedin.com/company/varonis X/Twitter: https://twitter.com/varonis Instagram: https://www.instagram.com/varonislife/
    Voir plus Voir moins
    23 min
  • AI-Powered Espionage
    Nov 24 2025

    A Chinese state-sponsored group weaponized Anthropic’s Claude tool to launch the first large-scale AI-driven espionage campaign, targeting more than 30 organizations across tech, finance, manufacturing, and government.

    This wasn’t an AI agent merely assisting hackers – it was autonomously performing reconnaissance, exploit development, and data exfiltration.

    Join Matt and David on the next State of Cybercrime as they break down this game-changing leap for attackers. They will also dive into the latest Citrix and Cisco zero-day exploits and share critical updates on emerging AI regulations.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Voir plus Voir moins
    24 min
  • Black Hat Cartels
    Oct 31 2025

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: linkedin.com/company/varonis

    X/Twitter: x.com/varonis

    Instagram: instagram.com/varonislife

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Voir plus Voir moins
    23 min
  • Supply Chain Attacks
    Sep 20 2025

    This month marked the discovery of one of the largest NPM compromises in history. Though AI-assisted social engineering, a profilic developer dubbed Qix was phished. His account was then maliciously used to publish poisoned packages, many of which were used to manipulate crypto transactions. Thankfully, it was detected before too many users downloaded these packages, but it highlights how vulnerable we can be if these upstream components get compromised. In this special State of Cybercrime episode, Matt and David break down this NPM compromise, and cover everything else new in the world of cybercrime.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Voir plus Voir moins
    24 min
  • ShinyHunters' CRM Heist
    Aug 18 2025

    One phone call was all it took for ShinyHunters to breach some of the world's biggest brands. By exploiting Salesforce to infiltrate Google, Cisco, and many others, this group has shown just how vulnerable organizations can be when well-known SaaS platforms become the attack vector. In this special State of Cybercrime episode, Matt and David break down how ShinyHunters pulled off one of the largest CRM–focused attacks of the year without exploiting a single software vulnerability.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Voir plus Voir moins
    26 min
  • Salt Typhoon Returns
    Jul 25 2025

    After their hidden breach of the National Guard, the cybercrime group was discovered to have targeted a major telecommunications firm named Visat. After their hidden breach of the National Guard, the cybercrime group was found to have attacked a large telecommunications company called Visat. The interesting part—these attacks are not disruptive; Salt Typhoon merely gathers information, hoards credentials and finds vulnerabilities. Because of their stealthy nature, these attacks are only detected after the attackers have already left. To what aim remains to be seen. Matt and David dive into these attacks, and talk about what else is happening in the world of cybercrime.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Voir plus Voir moins
    19 min
  • Copilot's Zero-Click Vulnerability
    Jun 18 2025

    In this episode, Matt and David explore a recently patched Copilot vulnerability that allowed attackers to craft emails that prompted Copilot to send sensitive information to an attacker's server. This prompt injection attack begs the question: What other vulnerabilities will AI bring to data? They also follow up with Scattered Spider & Dragonforce's continued assault on UK Retail and how their tactics are beginning to spread to insurance organizations.

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Voir plus Voir moins
    20 min
  • UK Retail Under Siege
    May 21 2025

    Several high-profile UK retailers have suffered serious cyberattacks that have disrupted operations for weeks and, in some cases, exposed sensitive customer data. The social engineering techniques used in the attack align with the notorious Scattered Spider group, but a new ransomware group named Dragonforce has claimed responsibility. Matt and David delve into the details of these attacks, what we know about these cybercriminal groups, and whether they are affiliated. They also cover the Coinbase breach — a calculated, high-stakes extortion scheme where hackers bribed overseas contractors to steal sensitive user data and demand a $20 million ransom. Watch now!

    Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

    More from Varonis ⬇️

    Visit our website: https://www.varonis.com

    LinkedIn: https://www.linkedin.com/company/varonis

    X/Twitter: https://twitter.com/varonis

    Instagram: https://www.instagram.com/varonislife/

    Voir plus Voir moins
    22 min
adbl_web_global_use_to_activate_DT_webcro_1694_expandible_banner_T1