The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/ShadowTalk: Powered by ReliaQuest
ShadowTalk: Powered by ReliaQuest artwork

China-Linked Cyber Espionage: How OP-512 Exploited Legacy IIS Servers and Evaded Detection

ShadowTalk: Powered by ReliaQuest · 2026-06-10 · 23 min

0:00--:--

Episode notes

Your team built defenses around known China-linked clusters. The file hashes are tracked. The behavioral patterns are documented. What those weren't built to catch is a new cluster that studied those exact defenses and engineered around them. A China-linked attacker compromised an internet-facing IIS server, maintained access for over 75 days, and came back on fresh infrastructure. With four China-linked clusters converging on the same legacy IIS stack in twelve months, defenders building detection programs around yesterday's cluster are already behind the next one. Join hosts Alex and John as they discuss: How OP-512 engineered its tooling to evade defenses Why killing a malicious process is incomplete What advantage cross-source correlation provides Two questions your organization should be asking right now: When your detection sources each generate a separate low-confidence signal from the same host, does anything in your current workflow correlate those signals automatically? Do you have internet-facing IIS servers running end-of-life .NET in your environment, and does your vulnerability-management workflow prioritize correctly?

More from ShadowTalk: Powered by ReliaQuest

All episodes →
  • How Hackers Are Using AI Right Now: Faster Attacks, Smarter Malware, and a New Arms Race73 / 100
  • Klue, Kali365, OAuth: When the Front Door Is a Trusted Integration
  • ShinyHunters' Expanding Toolkit: Oracle PeopleSoft Zero-Day Exploitation and the BreachForums Defense Gaps
  • SonicWall, MFA Bypass, IABs: Why Patched Devices Are Still Handing Attackers Initial Access
  • Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook
Explore the best B2B AI & Data podcasts →
All ShadowTalk: Powered by ReliaQuest episodes →