
Hosted by Cisco Talos
Every two weeks, host Amy Ciminnisi brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic. We cover everything from breaking news to attacker trends and emerging threats.
234 episodes · publishes fortnightly · latest 2026-07-02 · ~19 min/episode
Rank
#126
Substance
82.6
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#126 of 6182
Substance
Top 2%
outscores 98% of the index
Talos Takes ranks #126 on The B2B Podcast Index with a substance score of 82.6 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Diana Brown is a Talos email security researcher who authored the original research, giving her direct credibility and hands-on knowledge of the threat. She clearly has deep expertise in email security operations and threat detection, and speaks from operational experience rather than theory. This is authentic practitioner-level caliber, though she is speaking about her own organization's findings rather than external experience.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers concrete technical insights about a real attack pattern (PAP attacks), moving beyond platitudes to explain the mechanics of how attackers abuse legitimate platforms' email infrastructure. However, the episode relies heavily on the blog post and doesn't introduce novel findings beyond what was already published, limiting true insight density.
“The attackers simply sign up for a legitimate account, create a repository or set up a project just like any other user. When they push a commit or send an invitation, the platform's own back-end infrastructure generates the email notification.”
“The attackers are essentially hijacking the reputation of the platform to bypass the technical filters and then using the urgency of the allure to bypass the human discernment.”
The 'Platform as a Proxy' (PAP) attack framing is relatively novel and the episode does articulate the shift from domain-level to behavior-based trust in a meaningful way. However, the core concepts - living off the land techniques, authentication bypass via platform reputation, user trust exploitation - are well-established in security literature. The originality is in the application and packaging rather than fundamental new thinking.
“In our industry, we've started calling this a platform as a proxy or PAP attack.”
“They aren't trying to trick the infrastructures, they are using the infrastructure to trick the human.”
Diana Brown is a Talos email security researcher who authored the original research, giving her direct credibility and hands-on knowledge of the threat. She clearly has deep expertise in email security operations and threat detection, and speaks from operational experience rather than theory. This is authentic practitioner-level caliber, though she is speaking about her own organization's findings rather than external experience.
“The email security research team, which I'm part of, uh, has been doing some incredible work this past year, keeping a really close eye on how these SaaS platforms are being abused.”
“When we started cross-referencing those customer submissions with our uh broader telemetry, we saw a pattern emerging.”
The episode provides good specific details about attack mechanics (commit summary/description fields, Jira service management projects, SPF/DKIM/DMARC headers) and includes one concrete metric (2.89% of emails from GitHub on Feb 17). However, it lacks deeper numbers on campaign scale, victim counts, financial impact, or specific company examples of actual attacks. The technical specificity is strong but the evidence base is relatively narrow.
“On February 17th of this year, about 2.89% of the emails that Talos observed sent from GitHub were likely associated with this campaign.”
“When you push a commit, you have two specific fields: the summary, which is a single-line field...And then the description. This is a multi-line field, is that's where they put the body of the scam.”
The host Amy asks reasonable follow-up questions and provides structure to the conversation, but the interview is largely a guided walkthrough of pre-written material from the blog rather than investigative dialogue. There's minimal pushing back or exploring tensions; Amy mostly asks 'can you explain this section' rather than probing assumptions or challenging claims. The conversation is competent but lacks the depth of truly sharp interviewing.
“Diana, how are you doing?”
“Can you talk a little bit about how your team originally noticed that this was happening?”
First period on the Index - history builds from here.
9 scored on substance · 61 tracked in total.
From evasion to detection: A guide to analyzing COM-based threats
2026-07-02 · 19 min
Patching in the dark: Managing unknown threats in complex environments
2026-06-18 · 23 min
When synthetic logs don’t lie: Generating coherent attack stories for better detection
2026-06-03 · 19 min
The trust paradox: How attackers weaponize legitimate SaaS platforms
2026-05-07 · 21 min
It's not you, it's your printer: State-sponsored and phishing threats in 2025
2026-04-21 · 29 min
2025's ransomware trends and zombie vulnerabilities
2026-04-07 · 22 min
Cybersecurity’s double-header: 2025 insights from Talos and Splunk
2026-03-26 · 32 min
Modernizing your threat hunt
2026-03-12 · 23 min
Holding the line: Service provider security
2026-02-26 · 29 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/talos-takes" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/talos-takes/badge.svg" alt="Ranked #20 on The B2B Podcast Index" width="360" height="136" />
</a>Track Talos Takes's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.