
Hosted by Microsoft
Listed under Technology, Business
Join us to hear stories from the Microsoft Threat Intelligence community as they navigate the ever-evolving threat landscape - uncovering APTs, cybercrime gangs, malware, vulnerabilities, and other weird and cool tools and tactics in the world of cyber threats.
76 episodes · publishes fortnightly · latest 2026-08-12 · ~40 min/episode
Rank
#131
Substance
78.5
/ 100
Breakdown
Scored 2026-08
Updated monthly
Across the index
#131 of 1549
Substance
Top 8%
outscores 92% of the index
Microsoft Threat Intelligence Podcast ranks #131 on The B2B Podcast Index with a substance score of 78.5 out of 100, scored across 2 recent episodes. It scores highest on guest caliber and specificity & evidence. Crane Hassold is a Principal Threat Intelligence Analyst at Microsoft with clear operational responsibility for tracking and analyzing real attack campaigns. He speaks with authority grounded in actual data collection, disruption operations, and tactical field experience. This is a credible practitioner, though Microsoft's vantage point is inherently limited to traffic visible to them.
Averaged across 2 recently scored episodes, with cited evidence.
The episode delivers substantial technical insights into evolving threat vectors (QR code phishing, CAPTCHA-gated phishing, device code phishing, Teams/SMS pivots, mailbombing tactics) with concrete data points and specific tactical details. However, the conversation lacks deeper analysis of *why* these shifts occur or strategic implications beyond immediate detection - it stays largely at the tactical/observational level rather than driving toward operator-level strategic decisions.
“QR code phishing has increased about 55% month over month in March”
“attackers will then use that as a pretext to contact the, a user saying hey we've seen some weird behavior with your email”
The framing of phishing as 'social engineering for the purpose of some technical goal' is thoughtful but not novel. The core insights - email remains the primary vector, attackers follow paths of least resistance, and infrastructure disruption differs from actor disruption - are logical observations rather than counterintuitive or first-principles thinking. The discussion largely confirms what practitioners already suspect.
“phishing is you know, it's social engineering for the purpose of some technical goal at the end of the day”
“path, uh, of least resistance is always still the effective, uh, driver of like, what option they're going to go for”
Crane Hassold is a Principal Threat Intelligence Analyst at Microsoft with clear operational responsibility for tracking and analyzing real attack campaigns. He speaks with authority grounded in actual data collection, disruption operations, and tactical field experience. This is a credible practitioner, though Microsoft's vantage point is inherently limited to traffic visible to them.
“I have cran hassold who is a principal threat intelligence analyst slash researcher here over at Microsoft”
“we've seen 1.2 million messages that were linking to tycoon infrastructure”
The episode is rich with concrete numbers: 55% month-over-month QR code phishing increase, CAPTCHA phishing doubled, 92% decline in Tycoon activity post-disruption, 1.2M messages in June vs. 15.1M average in late 2024, Tycoon's share of CAPTCHA attacks dropping from 76% to 12%, QR code attacks from ~33% to 14%. Specific tactics are named (mailbombing, device code phishing, evil tokens, Teams/SMS pivots). However, many metrics lack precise timestamps or baseline comparisons.
“QR code phishing has increased about 55% month over month in March”
“1.2 million messages that were linking to tycoon infrastructure, which still seems like a lot, but it's actually, that's 92% lower than what we had seen, uh, in, in what, March or February”
The host asks reasonable follow-up questions (e.g., about shifting attack vectors post-disruption, whether 'phishing' remains the right term) and demonstrates knowledge, but rarely pushes back on claims or probes deeper into assumptions. The conversation is collegial rather than adversarial; there's minimal tension or disagreement. Softball moments include accepting explanations without stress-testing them (e.g., why Tycoon hasn't rebounded harder).
“So if I were to like, sum that up, path, uh, of least resistance is always still the effective, uh, driver”
“is phishing still the right term when the attack is ultimately successful through maybe identity permissions rather than just malware?”
2 periods tracked.
2 scored on substance · 63 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/microsoft-threat-intelligence-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/microsoft-threat-intelligence-podcast/badge.svg" alt="Ranked #14 on The B2B Podcast Index" width="360" height="136" />
</a>Track Microsoft Threat Intelligence Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.