The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Microsoft Threat Intelligence Podcast
Microsoft Threat Intelligence Podcast artwork

Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report

Microsoft Threat Intelligence Podcast · 2026-08-12 · 24 min

0:00--:--

Key moments - from our scoring

Substance score

68 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality11 / 20
Guest Caliber15 / 20
Specificity & Evidence16 / 20
Conversational Craft12 / 20

Email remains the primary attack vector, but social engineering threats are expanding across communication platforms where business happens. Cran Hassold covers how attackers are pivoting to Microsoft Teams (via mailbombing pretexts for remote access tool delivery), SMS text messages (business email impersonation), and device code phishing attacks that compromise credentials outside corporate visibility. The conversation examines how the Microsoft-led disruption of Tycoon 2FA infrastructure - a phishing-as-a-service platform used by customers worldwide to host malicious sites - achieved a 92% reduction in Tycoon-related messages by June compared to earlier 2025 levels. While QR code phishing and CAPTCHA-gated phishing attacks peaked with Tycoon driving 76% and 33% respectively, these have fragmented to other services rather than disappeared entirely. For organizations, Hassold prioritizes the basics: enabling DMARC, DKIM, SPF authentication, and domain impersonation policies, plus disabling device code capabilities to mitigate emerging threats. This episode is essential for security leaders tracking the post-disruption threat landscape and understanding how attacker infrastructure changes ripple across the ecosystem.

Key takeaways

  • →Email remains the primary attack vector but attackers are diversifying across Teams, SMS, and other communication platforms to reach victims on less-hardened personal devices.
  • →QR code phishing increased 55% month-over-month in March, and CAPTCHA-gated phishing more than doubled, with Tycoon 2FA responsible for 76% of CAPTCHA attacks and 33% of QR code attacks before disruption.
  • →The Tycoon 2FA infrastructure disruption achieved a 92% reduction in Tycoon-related messages (from 15.1M monthly average to 1.2M by June) with long-lasting impact because customers lacked easy pivot options.
  • →Organizations should prioritize authentication basics (DMARC, DKIM, SPF) and disable device code capabilities to defend against the most prevalent tactics, rather than relying solely on security awareness training.
  • →Phishing should be defined as social engineering for technical exploitation goals (credential compromise or device compromise), distinct from pure social engineering like business email impersonation with no technical endpoint.

Guests

Cran Hassold

Topics in this episode

Tycoon 2FA phishing-as-service platformQR code phishing attacksCAPTCHA-gated phishingMicrosoft Teams mailbombing attacksDevice code phishing and evil tokensBusiness email impersonation (BEI)DMARC, DKIM, SPF authenticationPhishing-as-a-service ecosystemSMS-based credential harvestingRemote access tools (RAT) delivery

Questions this episode answers

What is Tycoon 2FA and why was it disrupted?

Tycoon 2FA was a phishing-as-service platform that provided email templates and infrastructure for customers to host malicious phishing sites worldwide. It was disrupted by Microsoft and international partners because it was the largest single driver of malicious email traffic, responsible for 76% of CAPTCHA-gated phishing and 33% of QR code phishing attacks.

How much did the Tycoon disruption actually reduce phishing volume?

By June 2025, Tycoon-related messages dropped to 1.2 million, representing a 92% reduction compared to the 15.1 million average monthly messages seen in the second half of 2024. The impact has been sustained over four months without the tool making a significant comeback.

What new social engineering attack vectors are attackers using beyond email?

Attackers are pivoting to Microsoft Teams (via mailbombing pretexts to impersonate IT support and deliver remote access tools), SMS text messages for business email impersonation and credential harvesting, and device code phishing attacks that compromise credentials on personal devices outside corporate visibility.

What should organizations prioritize to defend against current phishing threats?

Enable authentication basics like DMARC, DKIM, and SPF to prevent domain spoofing; activate user and domain impersonation policies; monitor for QR code and CAPTCHA-gated phishing; and disable device code capabilities to mitigate multi-factor authentication bypass attacks.

Did other phishing-as-service tools replace Tycoon after the disruption?

Yes, QR code and CAPTCHA-gated phishing attacks fragmented to other services, with Tycoon's share of CAPTCHA attacks declining from 76% to 12% by June and QR code attacks from 33% to 14%, indicating other platforms are filling the gap but none has achieved Tycoon's previous dominance.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode delivers substantial technical insights into evolving threat vectors (QR code phishing, CAPTCHA-gated phishing, device code phishing, Teams/SMS pivots, mailbombing tactics) with concrete data points and specific tactical details. However, the conversation lacks deeper analysis of *why* these shifts occur or strategic implications beyond immediate detection - it stays largely at the tactical/observational level rather than driving toward operator-level strategic decisions.

QR code phishing has increased about 55% month over month in March
attackers will then use that as a pretext to contact the, a user saying hey we've seen some weird behavior with your email

Originality

11 / 20

The framing of phishing as 'social engineering for the purpose of some technical goal' is thoughtful but not novel. The core insights - email remains the primary vector, attackers follow paths of least resistance, and infrastructure disruption differs from actor disruption - are logical observations rather than counterintuitive or first-principles thinking. The discussion largely confirms what practitioners already suspect.

phishing is you know, it's social engineering for the purpose of some technical goal at the end of the day
path, uh, of least resistance is always still the effective, uh, driver of like, what option they're going to go for

Guest Caliber

15 / 20

Crane Hassold is a Principal Threat Intelligence Analyst at Microsoft with clear operational responsibility for tracking and analyzing real attack campaigns. He speaks with authority grounded in actual data collection, disruption operations, and tactical field experience. This is a credible practitioner, though Microsoft's vantage point is inherently limited to traffic visible to them.

I have cran hassold who is a principal threat intelligence analyst slash researcher here over at Microsoft
we've seen 1.2 million messages that were linking to tycoon infrastructure

Specificity & Evidence

16 / 20

The episode is rich with concrete numbers: 55% month-over-month QR code phishing increase, CAPTCHA phishing doubled, 92% decline in Tycoon activity post-disruption, 1.2M messages in June vs. 15.1M average in late 2024, Tycoon's share of CAPTCHA attacks dropping from 76% to 12%, QR code attacks from ~33% to 14%. Specific tactics are named (mailbombing, device code phishing, evil tokens, Teams/SMS pivots). However, many metrics lack precise timestamps or baseline comparisons.

QR code phishing has increased about 55% month over month in March
1.2 million messages that were linking to tycoon infrastructure, which still seems like a lot, but it's actually, that's 92% lower than what we had seen, uh, in, in what, March or February

Conversational Craft

12 / 20

The host asks reasonable follow-up questions (e.g., about shifting attack vectors post-disruption, whether 'phishing' remains the right term) and demonstrates knowledge, but rarely pushes back on claims or probes deeper into assumptions. The conversation is collegial rather than adversarial; there's minimal tension or disagreement. Softball moments include accepting explanations without stress-testing them (e.g., why Tycoon hasn't rebounded harder).

So if I were to like, sum that up, path, uh, of least resistance is always still the effective, uh, driver
is phishing still the right term when the attack is ultimately successful through maybe identity permissions rather than just malware?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B72%
  • Speaker A28%

Most-used words

tycoon33phishing29email21attacks21disruption17seen15impact13threat11customers10seeing9tool9microsoft8social8engineering8code8types8

Episode notes

In this episode of the Microsoft Threat Intelligence Podcast, Microsoft Threat Intelligence Director⁠ Elliot Volkman is joined by Microsoft Principal Threat Intelligence Analyst Crane Hassold to explore how phishing and social engineering attacks are changing beyond email. They discuss the rise of QR code phishing, Microsoft Teams scams, SMS-based attacks, and why attackers continue to follow wherever people communicate. Crane also shares practical security recommendations for organizations and explains how Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform led to a dramatic decline in malicious activity while reshaping the broader phishing landscape. In this episode you’ll learn: How phishing attacks are evolving beyond email The security basics every organization should prioritize How attackers are exploiting Microsoft Teams and SMS Some questions we ask: What are you seeing in today's social engineering and phishing landscape? How impactful was the Tycoon 2FA disruption? Has Tycoon activity shifted elsewhere after the disruption?

Full transcript

24 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello and welcome back to the Microsoft Threat Intelligence podcast. I am obviously not shared and if you want a little bit of context of that, uh, please go back into your podcast or video feed for the previous episode where we unfortunately have a little farewell episode for her. Uh, so with that being said, I am Elliot, the director for Microsoft Threat Intelligence. I have been behind the scenes for a little bit and we are going to just jump right into the threat landscape with fortunately, uh, a guest who is um, has been around social engineering and the cybersecurity research world for quite some time. I have cran hassold who is a principal threat intelligence analyst slash researcher here over at Microsoft. And we are going to be talking about uh, what we are seeing across the, I want to say email threats because it is so much more than that. It's maybe social engineering and phishing. Is that the right way to put that, Crane?

Speaker B: Yeah, I think so. I think, you know what I look at, what our team looks at on a day to day basis is email obviously I think everyone knows is still the primary threat vector, primary attack vector for most attacks. Um, you know, we do look at the overall social engineering threat landscape to understand how people are being exploited to fulfill technical goals.

Speaker A: All right, yeah, that sounds about right. Uh, in fact, maybe I'm going to pull at that and we'll have a little philosophical conversation here in a minute. But I do want to just drop, drop some uh, stat that we had published the to the Threat Intelligence blog most recently, uh, with you and some of your peers. Um, but it looks like in support of that uh, QR code, phishing has increased about 55% month over month in March as of when we last tracked it, uh, captcha gated phishing has more than doubled. And then if you had been following our digital crime unit or DCU action or disruption, uh, several months ago or maybe last month, time, uh, is always a bit of a blur here. Uh, they had a disruption activation and uh, activity against tycoon2fa and after that I believe there is a decline of around 92% of their activity that we have been tracking. Uh, obviously, um, once you disruption disrupt an actor or the mechanisms behind it, uh, they redirect their energy. But that's just some interesting little nuggets that we have uh, published. You can of course read Crane's blog for a little bit more details, but what I want to actually pull on is what I was poking out before, which is based on the numbers and the data that we're seeing here. Crane is, I don't think we're actually seeing social engineering and phishing just being an email concern anymore. Do you feel like maybe the perspective has shifted where we're seeing this move? Beyond that it is phishing. It is phishing. We're seeing QR code attacks. Is uh, social engineering, um, shifting their energy majority wise outside of email or is it still the bread and butter?

Speaker B: So it's still the bread and butter in insofar as you know email for most people at least is still the primary communication mechanism when people do business, business conversations. Um, and because it's still the primary way that people communicate um, in the enterprise it's still the way that the attackers are sort of trying to initiate their conversations, trying to initially attack uh, these um, their, their victims. That being said, we are definitely seeing sort of the scope of attack vectors open up pretty dramatically. Um, not super quickly but it's definitely there. For example Microsoft Teams, um, we've started to see a good amount of traction for attackers pivoting m over to Microsoft Teams to try to uh, impact users that way. A lot of what we see with teams are through things like mailbombing attacks where a user may m all of a sudden get hundreds of emails, uh usually legitimate emails, spammy email, things like signing up for newsletters, stuff that's, that's not inherently malicious. But what happens is the, the attacker will then use that as a pretext to contact the, a user saying hey we've seen some weird behavior with your email, what's going on, blah blah blah blah. A vast majority of the mailbombing attacks that pivot over to teams that we've seen um, end up impersonating like an internal IT Help helps help support type, uh, help help desk type of attacks like a Persona. And they'll say hey we need, you know, we've seen that you need see some weird things. How can we help? If you could do me a favor, could you just download this tool? And the tool in itself is, is usually like a remote access remote management tool which is an, you know, in itself, you know, benign. It's, it's a legitimate tool but the attackers are then using that as a pretext to then once they have access to a victim's computer then down uh, download malware to the machine. Um, so teams is definitely a way that uh, that we've seen some attackers start uh, exploiting victims SMS text messages is definitely another, another avenue that we've seen uh, where a lot of that has to do with the fact that attackers want to either get users off of email or target them directly through email to begin with, because they know that it's not as hard as a hardened, uh, platform, uh, than something like an email on a work device might be. Um, so targeting. And usually when we see those types of attacks, a lot of those are business email impersonation attacks. A majority of those are like, eventually end up with, you know, asking someone to go buy gift cards. But we've also seen a rise in the types of attacks that have links in them. And then on the other side of that link, they're trying to compromise credentials. And so what's interesting about that is that you have victims and you have, you have attacks that are compromising corporate credentials outside of the corporate, you know, corporate visibility. And then the first time an enterprise might actually see those being used is when they're being tried, being attempted to be used by the attacker. And they never actually see the compromise to begin with because this is happening, the compromise is actually happening on a personal device. Um, so we've seen that. But really, as we move forward, wherever people communicate for business purposes is where the attackers are going to continue to move. Um, I think eventually email, uh, especially with, you know, a younger generation, probably will not be the preferred way to communicate with anyone at some point. So, you know, eventually email will sort of go the way of the dinosaurs. But until then it still will be email until all that gets phased out.

Speaker A: That makes sense to me. So if I were to like, sum that up, path, uh, of least resistance is always still the effective, uh, driver of like, what option they're going to go for and then, um, impact scalability of where they can reach those. Um, okay, that, that lines up. So, uh, let me maybe tee up a philosophical conversation here because, uh, I feel like you have a lot of interesting takes on how we position things or talk about things. So, uh, the main way that I would ask this, I guess, is is phishing still the right term when the attack is ultimately successful through maybe identity permissions rather than just malware? Um, because if the entry point is not, it is basically an entry point. But yeah, is, is it a phishing attack or are we repositioning how this should be defined?

Speaker B: So that's a good question. I think phishing is one of those, you know, the cybersecurity terms that has been, you know, thank you for people like you, Elliot, marketing, uh, folks have sort of, you're welcome. Sort of made them a such a generic term that they means many different things. But I always think, I think it was Think of phishing as a, you know, essentially it's an outreach from an attacker through a communication platform. For the purposes generally, the end result is to either exploit their technical, a uh, technical device usually going to be a computer, or to compromise credentials. That's the general way that I sort of see phishing. The term phishing and that is a little bit different than what we've seen with like things like business email impersonation attacks where there is no technical exploitation. At the end of the chain. It's pure social engineering. But when I, when I think of phishing it's you know, it's, it's social engineering for the purpose of some technical goal at the end of the day. Um, so I think that's a good general, uh, good general definition and way to think about it.

Speaker A: Okay, that makes sense. Uh, yeah, and I'm glad that you've brought up BEI because uh, that's a whole nother topic debate for another day. Um, so I think maybe before I spin off to uh, the disruption actions that we've uh, sort of briefly covered, I do want to maybe pull back and highlight any guidance that you're seeing as a top priority organization should look at based on our most recent findings. Now uh, we have the obvious caveat here is everyone's threat model is going to be different. But based on the findings that you have identified in the last couple of quarters in phishing and social engineering and email based threats, uh, is anything coming top of mind where organizations should maybe like rethink a couple of uh, you know, items and please don't tell me security awareness training because I know you

Speaker B: put it, I mean the number, number one is making sure you're taking care of the basics. Like we still see phishing attacks today, especially email based attacks. They're still like a vast majority of them are like, they're targeting the basics and they're hoping that enterprises and companies are not just like doing the lowest possible amount of work in order to get it done. And so these are cybercriminals we're talking about. So they're also trying to do the least uh, amount of work possible in order to sort of have some sort of financial gain. So one is like make sure you're keeping the basics, like dmarc, dkim, spf, make sure all those are up to date. I can't tell you how many, you know, just still spoofing attacks that we see on a day to day basis. Um, where there's an organization that doesn't have dmarc Enabled um, and so therefore their domain can be spoofed rather easily. Um, and make sure you have the basic user impersonation, um, domain impersonation, those policies and those types of things turned on. Um, so one, make sure you're at least making it somewhat hard for the attackers to do their jobs. Two is sort of understanding the types of attacks that we're seeing more and more often. You know we've tracked QR code and capture gated phishing attacks over the past year because they have been sort of M2 of the two of the tactics that we've seen being used, you know more frequently. Um, and, and by some of the larger sort of the larger phishing as a service groups out there like Tycoon. Um, that being said, we do see an ebb and flow in the volume of those types of tactics every, every every single month. You know, for example the, since Tycoon, Tycoon was a disproportionate driver of both of those types of attacks and since the disruption which I'm sure we'll talk about, we've seen both of those go down but not to the level of hey it was only Tycoon using these, these types of tactics. You know, it's very clear that there are other services and tools and actors that are using these same services. Um, but Tycoon definitely had an impact on them. I will also say things like device code phishing which we don't really talk about in uh, our latest landscape, uh, report or landscape report but we will um, as we move forward into sort of this current quarter and moving forward, um, device code phishing is one of those things that really has been around for um, a bit now but really came on the scene earlier this year with something like evil tokens where you know it's, it's trying to uh, it's trying to exploit that the devices that people get on their phone um, and sort of get in the middle of that transaction to be able to compromise credentials and sort of bypass multi factor authentication. Um so, so and there are really easy ways to get rid of that. There's easy policies um, that I don't have that I don't know how my head they're called. But there are policies that enterprises can use to simply turn that capability off and that will sort of mitigate that entire potential issue. Um so yeah, I think that those are some of the things that organizations should pay attention to um, as we move into the latter part of the year.

Speaker A: Cool. Ah so I appreciate it brought up the disruption to Tycoon 2fa, because that's where I want to go next, which is, um, it's always kind of an interesting debate of how much impact does it actually offer. And obviously the numbers here make it pretty clear that there is a sizable disruption to that activity, especially through those tactics. Um, but this does beg the question. It's sort of like Hydra where you cut off one head. You had to emerge. But is that activity, uh, do you see that activity by chance fragmenting? Is it moving anywhere else? Is it shifting elsewhere? Because it is difficult to disrupt a longevity system versus like ah, an immediacy. Yeah.

Speaker B: So what's interesting about Tycoon is, and this is when it gets into things, the phishing as a service, that entire landscape, um, what's important to remember about Tycoon is that they are a tool that customers are using to facilitate their attacks. Uh, so Tycoon for those who don't know, is a service that allows customers, anyone across the world to do two things. One, they can use a template that is offered, like an email template that's offered by Tycoon, uh, to sort of make realistic. And then also it provides Tycoon also as a service, provides infrastructure that allows customers to use, to host the phishing sites. At the end of the day, what if Tycoon doesn't do is they don't offer the capability to mail, to send the actual emails themselves. Customers need to use a separate tool, separate mailer in order to make that possible. And it's important as we go into the overall impacts of what the Tycoon disruption actually, actually did and how it's persisted over time. So when we look at what happened, so the Tycoon disruptions started, it was Microsoft, it was really dozens of organizations, both in the private sector as well as the public sector. Law enforcement really all around the world sort of helped out with this, which was a great demonstration of how all of these organizations can come um, together for a positive, uh, to make a positive impact. Um, but what after the, so the mitigation, the disruption was focused on disrupting the Tycoon's infrastructure, um, where the final, you know, these final fishing sites were being, were being hosted. And what was interesting is right after the disruption we were monitoring the numbers and what was actually going to happen. And you know, a few weeks went by and we didn't really see that much of a decrease. It went down a little bit, but not, it wasn't like someone flipped a switch and then all of a sudden Tycoon's, you Know, volume went down by a ton. It wasn't like that. It started going down a little bit, but not, not too much. There was actually a pretty massive campaign a week, I think it was a week after our disruption activities happened, um, which actually caused a spike in what we saw from what we observed through tycoon. But what's important to keep in mind is that when we're identifying these campaigns and these messages, they're the emails that are getting sent out. It's important because I guarantee that there were a ton of tycoon customers that had no idea that any of this disruption activity had actually happened. And so they're just sending out their campaigns like, you know, like they would in any other, any other day. But what happened was the email campaigns would go out, we would see them, we would, you know, put a little tick on, on our board, say, hey, here's a new tycoon campaign or a campaign that's leading to tycoon infrastructure. But when you look at the phishing page, the, you know, anyone who receives those, if they do receive them, they're not going to be able to get to the final page. So that's where the early impact came into play. We didn't see, you know, uh, there wasn't an observable volume impact right away, but we could easily, we could easily see that there was an impact in the actual number of victims that were being hit with tycoon that were actually being compromised by tycoon. That was, that was the early impact. And now over the past couple of months we've seen the overall volume of just messages that lead to tycoon, uh, related domains has gone down, just has gone off a cliff. Uh, so let's see. So we saw, you know, just in June we saw 1.2 million messages that were linking to tycoon infrastructure, which still seems like a lot, but it's actually, that's 92% lower than what we had seen, uh, in, in what, March or February. Um, just to give, you know, give a sort of a comparison there at the end of the average, at the, in the Last half of 2025, the average number of messages that we saw in any given month that confirm we're tycoon, we're about, was about 15.1 million. Um, so, you know, it's 1.2 million million sounds like a lot, but it's significantly less than uh, what it used to be. And it's also not driving as much of the notable sort of, uh, notable tactics that we've seen. So um, just, you know, I mentioned, we mentioned the capture gated phishing attacks and the QR code phishing attacks. I just give you some numbers there. So back in December, uh, of last year, Tycoon was responsible for about 76% so 3/4 of all capture gated phishing attacks. Whereas in, uh, in June that number had gone down to 12%. Uh, and then also QR code phishing back in November of last year it had peaked in about a third of all QR code phishing attacks were related to Tycoon. That's now down to about 14%. Um, and so, and that's obviously also had an impact on the overall volume of those tactics being used. But again those tactics aren't decreasing by the same amount of just taking Tycoon out of the equation. It's very clear that there are some services and other tools that are sort of filling in those gaps. Um, but what's great, this is like why we do what we do when it comes to disruption. It's always great to one put a lot of work into setting up a disruption adoption campaign. You know, Tycoon before this was easily the biggest driver of most malicious email traffic that we've, that we had seen, um, for a good year or so. Um, and you know, since over the past what, three, four months now, you know, seeing that that volume and their overall impact, that of this tool that was so disproportionately impactful has gone down significantly. Um, obviously you mentioned someone coming to take their place and have no doubt that uh, there will be some other tool that customers are just going to go to because again the ones that are sending the email campaigns, it's not Tycoon, it's the customers of Tycoon and customers of other phishing as a service tools. Um, and so those customers are, are going to go somewhere else at the end of the day. Um, but we're still trying to figure out which of the many, many, many surfaces out there, many platforms out there. Uh, are these phishing actors going to go to.

Speaker A: Thank you for walking through that with such great depth and also including the numbers piece of the equation because uh, I feel like it might have been a conversation with you or otherwise. But if you maybe go for disruption against specific actor, uh, the weight on that is a little bit different than actually taking out the infrastructure and the systems that organizations rely on. Especially if you know, they're, you know, their customers are essentially still using it to a dead end. So that's always a fun little benefit. I'm sure that makes just taking um, their lures out off the table pretty quick.

Speaker B: Yeah, but one of the great things about this is that, you know, and I've seen disruption in operations happen in the past where, you know, you may see a very short blip in volume decrease because the actors behind the scenes are just pivoting to something else that they've either already had staged in the chance that there is some sort of disruption or they're able to easily sort of pack up what they've done and move somewhere else that has. Because of the way that the whole operation went down and sort of the, you know, what we were targeting and how we're targeting it, that really wasn't an option for Tycoon which so being able to see, not only was there an impact, a short term impact, but it's been pretty consistent and uh, long lasting over the past four months, um, that they haven't, that the tool hasn't come back in force that we sometimes see with other types of uh, mitigation operations.

Speaker A: Excellent. All right, well Crane, thank you again for coming on here and sharing a little bit of your expertise and your understanding of the threat landscape. Uh, for anyone who's interested in a little bit more in depth breakdown, feel free to go to the Microsoft Threat Intelligence blog, where as of mid July somewhere. Mid July, that is when we publish the most recent one. I believe there's at least one or two other ones, um, based on Crane and team's finding and research. All right, thank you all. Uh, we will see you ah, at Black Hat if you're going to be there. Uh, and that is it for this episode of the Microsoft Threat Intelligence podcast podcast.

More from Microsoft Threat Intelligence Podcast

All episodes →
  • Casey Ellis on How AI Is Reshaping Vulnerability Research and Patching69 / 100
  • A Farewell from Sherrod: New Season Coming Soon
  • Behind the Book: Threat-Driven Software Development
  • Hot Cybercrime Summer:  Smishing, Supply Chains, and Sleuthcon
  • Supply Chain Attacks: Open Source or Open Door?
Explore the best B2B Engineering & DevTools podcasts →
All Microsoft Threat Intelligence Podcast episodes →