mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Initial Access Trends
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of the mnemonic security podcast, we’re joined by Will Thomas, Senior Threat Intelligence Advisor at the CTI company Team Cymru, to discuss the latest trends in initial access.
Will shares what he is currently observing, including the growing exploitation of edge devices, the targeting of SaaS environments using infostealers and stolen credentials, and the rise of ClickFix-style social engineering techniques.
He also explains how these trends differ between threat actors depending on their motivations, and what organisations should prioritise to stay ahead. Will outlines practical steps defenders can take and the key questions security teams should be asking to stay ahead of attackers.
The conversation also covers Will’s main concerns around threat actors’ use of LLMs, and how CTI and threat hunting should ideally be carried out to support security operations.
Want more Will Thomas? Here you can find his Ransomware-Tool-Matrix: https://github.com/BushidoUK/Ransomware-Tool-Matrix/tree/main/Tools
And his own podcast Future of Threat Intelligence (FoTI) Podcast:
https://www.team-cymru.com/future-of-threat-intelligence-podcast
From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.
Robby PeraltaVulnerabilities, stolen creds, or social engineering. Pick your favorite threat actor. That's usually how they get in. From there, they blend into the background. Remote management tools, native Windows utilities, just living off the land. And before you know it, the data's on its way to a cloud bucket somewhere. Covert entry, minimal noise, clean exit. Kind of reminds me of James Bond in his suit, while others think of bears, spiders, or pandas. Today's guest explains what they're up to and how they're doing it. The rest is up to you. Will Thomas, welcome to the podcast. Thanks for having me. You work for a company called Team Cymru. Is that like a Welsh name, or why is it so complicated? Well, it's not pronounced as it looks, as spelled at least.
Will ThomasIt's the Welsh word for Wales, Cymru. Okay. Um, but yeah, everyone. There's there's a lot of cybersecurity companies that start with C Y, right? Like Cynet, Cyware, whatever. So Cymru, everyone calls it SyMru. Um which is, you know, fair enough. We're just reading the word, but it's yeah, it's the Welsh word for Wales. The name comes from the founder, uh, Rabbi Rob. I believe he had some sort of ancestors from Wales, so decided to call it, you know, what the Americans are like with our heritage. Team Cymru is like a threat intelligence company, one of the you know, first ever CTI companies back 25 years ago before anything like Recorded Future or Intel 471 came along. And the company has been building up its relationship of in info sharing and data sharing partners over um, you know, we've got about eight, seven to eight hundred different partners now who share that data with us, the net flow data from networking devices. And then we sample that and then we see uh where are the threat actors communicating from, right? So imagine you have a command and control server, take a cobalt strike C2 server, for example. If that C2 server has been trying to target victims around the world via launching an exploit or brute forcing or something like that, then if those victims are using those ISPs to connect to the internet, Teen Camry would see those communications from the command and control server to that victim. So normally as a as a one company, you can only see the attacks to you, but we can take those indicators of compromise, indicators of attack, whatever you want to call them, and we can see what else have they been doing on the internet up to 90 days ago. So it's a really powerful data source and allows you to track threat actor activities and get like a higher level of confidence of the behaviors of what you know network infrastructure is doing.
Robby PeraltaSo the definition of threat intelligence. I have the right man. So I was hoping we could start out discussing a bit of the trends that you were seeing in initial access. Uh, what are you tracking these days?
Will ThomasYeah, trends in initial access is is basically what we tend to focus on from a sort of a networking perspective. So we can see uh threat actors launching exploits against certain devices. So, as well as having that net flow data, we can scan the internet and profile things. So, say if we have a profile of all of the corporate VPNs out there, and we can see who's attacking those, then we can actually see spikes and trends of activity against those devices. So we've seen uh Fortinet, 40 gate devices get exploited with an authenticated RCE kind of bug, you know, worse type of scenario, really. Uh or I've I recently think I saw them them there was an issue in Fortinet's SSO ability where anyone could log in as anyone, which is just kind of bonkers to believe, right? Um, so we've we've definitely seen a trend away from sort of the malware loader type of campaigns where malicious email comes in with a map with an attachment which has a malicious macro that downloads a payload. You don't really see that as much these days. We threat actors, a lot of the top ransomware gangs have started to go for that ex edge device exploitation, those corporate VPNs. SonicWall seems to be get coming up a lot. Akira, the Akira ransomware gang is going after those, Cisco devices as well, uh, AnyConnect and ASA uh devices, Akira has gone after. And generally coming, even nation-state groups, you know, Chinese cyber espionage groups have been uh leveraging zero-day exploits in things like Avanti and some parallel auto global protect uh devices over the years in the last couple of years. So it is that seems to be where the adversaries go. And the main reason I suspect is that uh is because a lot of companies now have EDR and antivirus and stuff in place to protect and stop against those threats automatically. So if you're a threat actor, it's better to go for the device that doesn't have any EDR on it. So if you just go for that device and then kind of linger on there and kind of do uh you know adversary in the middle type work and or types of attacks, then you're able to stay there much longer without being detected and removed. Or if you're a ransomware gang, if you can get onto that first initial foothold, you kind of scan internally, maybe you'll go undetected. And then if you can get to something like a hypervisor, like a VMware ESXi hypervisor, sort of just SSH remoting around to it, you can encrypt everything in that company's organization. So it's a massive issue for defenders these days because it requires re-architecting your sort of security programs in many ways.
Robby PeraltaSo, from what you're seeing, the most activity is going towards edge devices and vulnerabilities or zero days attacking those. What would you say is in second place?
Will ThomasSecond place, I'd probably say uh the targeting of SaaS devices with infosteeler malware or credentials stolen by infosteeler malware. There's kind of a vast community of cyber criminals out there who are distributing infostealers as as far and wide as they can and as many random ways as they can. I've literally seen someone share, I think it was VX Underground reposted a TikTok video where it's like how to get Windows for free. And they just show a command. They're like, here, type this command and run it. And actually, it just downloads an infosteler malware if you do that on your system. So the criminals are getting very creative with how to how to steal your passwords and stuff. But then all that gets hoovered up, it gets made put made available by the cybercrime underground, the crime e-crime markets and stuff. And you could just go in there and query the domain of a company. And if someone had their creds stolen, they'll be there. And if those credits aren't expired, you can just log in. So it's it's a real nasty situation. But I've definitely seen threat actors look for specific platforms in those sets of stolen credentials because it just grabs everything from your browser or everything from just some you know app or somewhere stored on your device. And if you have a you know some SaaS platform you're logged into, whether it's a Salesforce or some Atlassian product or something, then the threat that could just log in, grab everything off there, and exalt you for it.
Robby PeraltaAnd that's where this infamous hackers don't hack in, they log in comes from, is exactly that use case.
Will ThomasYeah, that's right.
Robby PeraltaYeah. If you have a third and fourth place, I know I'm uh maybe being annoying now, but it what would you say those are?
Will ThomasI would say I've seen quite a lot of threat actors doing the kind of the clickfix stuff where you go on a website and a fake capture pops up, and again, they're telling you, like, oh, you have to uh press Windows and R and run a command that's already copied, or it's like Windows R and then control V, and you know, boom, you're infected by the malware, whatever the type of malware that is. That seems to be really, really prolific. And I've seen some modifications of that by threat actors as well recently, where they've done uh they'll make your browser look like it's kind of breaking and stuff. They're using JavaScript to get really creative. All it does is just they just want you to run that command on your system. But the problem is they can see that type of stuff anywhere, they can share the links around, they can post it in you know, YouTube comments I've seen, Reddit comments, Facebook comments, anywhere that people generally like even in uh GitHub pull requests and GitHub issues and stuff, I've seen threat actors using that as well. So it's becoming a lot harder to defend against these types of attacks because it's it's again it's abusing human nature to click on something and follow instructions.
Robby PeraltaInteresting. Uh was there any last ones you want to mention that might just be not very many, but it you still see them.
Will ThomasMaybe not like terribly sophisticated, but I we do still see threat actors, you know, even advanced threat actors just sort of doing SSH brute forcing and RDP brute forcing to get into specific devices. So it's a it's more of a generic type of attack, but it has a specific goal in mind where they're seeking important devices at strategic targets. So think about like what Salt Typhoon is doing and what Berserk Bear and things are doing, where they're going after they're picking their target pretty carefully, trying to basically credential stuff and brute force their way in just to get to the more critical target inside. So for Salt Typhoon, they're going after the sort of Cisco switch or something, uh, or Juniper Switch, uh, to then grab the credentials off that and go upstream even further. So it's more about like pivoting from one target to the next target to the next target. We've seen this historically with like APT-10 and Cloud Hopper going after their MSPs, and the similar to similarly to the Berserk Bear, they actually kind of went after specific 40-gate devices, and then once they're in that, then they can go after the ICS device, the RTU device on the other side of that network to then brick it and cause a power cut or of cause try and cause a power outage in Poland. So again, it's not sophisticated, it but it's relying on defenders and uh administrators not updating their stuff, not not securing their stuff properly with frankly basic, basic security measures.
Robby PeraltaHygiene's always gonna be important. I was gonna ask you what the like if you're seeing any trends in initial access across the different types of threat actors, but it you kind of what you just said made me realize that like APTs, they're just gonna do whatever they can to get in their target. They'll mix and match. They don't have a they don't need to follow any instructions, but the financially motivated actors, are those the ones that you're seeing going after like the edge devices in a particular way? Or how how do you look at those, you know, the trends across the different types of threat actors?
Will ThomasYeah, I would say the look I mentioned earlier with the ransomware gangs going after the the edge devices, the the Sonic Walls, the Fortigates, the Cisco devices, there is a clear pattern of attack of the multiple ransomware gangs going after these. Some some really good research was put out by cyber insurance companies who said if these devices are out of all the claims that we get per year, here's what devices those who claim on their insurance are typically using. And some you know, the usual suspects came up Cisco, Citrix, and Fortinet. If a company was using that, it was like five times more likely to claim on their insurance, which I'm sure is no coincidence. What about XFIL? Yeah, yeah. So for data exfiltration, we typically see threat actors trying to blend in with the traffic because if they're in a network that is actually monitored by defenders, then they have to try and avoid standing out like a sort of thumb. So what some do is they'll tend to use like a web service, you know, something like uh a mega or a Dropbox or a cloud instance, even where you know, if you just see data going to AWS, maybe it doesn't, you know, you see data going there all the time, doesn't look that bad. That's what I typically can see some of them doing. The other thing is to me as a threat hunter, if I see a large amount of data going to Mega, that's an instant telltale sign because there's so many threat actors that use it. I'm surprised that threat actors still use it because to me it's way too obvious. It's easy to detect and block that. But then I've also seen other threat actors trying to use sort of rotating IPs to avoid basically having their IPs blocked. So if you if you just try to block their IP, then they can just lock in and access from another one and continue downloading that data. So if if they're using residential proxies, then it just looks like a normal IP in the country that their company's located. Again, it becomes much harder to detect. It doesn't look like it's coming from a bulletproof host or something. Um, Tor nodes, we generally have seen threat actors like shiny hunters or or whatever they go by these days using Tor nodes. And unless you have that context about what that IP address is, it's just gonna look like a normal, a normal IP. It's only when you enrich it with behavioral tags and things that threat intelligence providers like Team Cymru can offer, or you can you know use PDNS to look up what's running, what's hosting on that IP, um, that we see all this traffic to, or we can see you know in the subdomain is like Tor exit node 001. It's kind of basic stuff to like but the having the infrastructure put in place to firstly have all your logs in in somewhere, and then also enrich that logs with something, it does require investment and expertise to to implement that, but it will prevent so many more attacks, and the attacks don't really haven't really changed too much because they just keep getting away with it.
Robby PeraltaI want to come back to the role of uh a tip and the tips and tricks you have. Uh, but first, you had an off awesome presentation at B-Sides about North Korea, and I also read the blog you had about the Singaporean telcos getting popped. But the difference between those two, and for example, decentralized groups, such as scattered spider, which is not a you know a group in itself, but a collective. What's the difference between tracking, you know, a specific group and tracking a group that's not really a group, that's just a bunch of people? I know you told me last time that you go after the people, but then that makes it, I would assume, so hard to gather that. And, you know, how do you make sense of all that?
Will ThomasSo for North Korea, it's actually much easier for us to be able to do that because they are confined to specific parts of the internet that they emanate out of. So they use specific ASNs, they use specific cider ranges that we can see team company can see the net flow traffic from those just because of the nature of our global visibility and partners from around the world. We can see that traffic communicating with astral VPN nodes, and then we have that list of astral VPN nodes that then we can you know share with our customers and our and our uh you know intelligence sharing partners, and we can help do something about it. That's actually much easier than focusing on house captured spider operators work, which is essentially they use as many ephemeral services as possible. They use VPN, like consumer grade VPNs, where one IP address can have thousands of users on it at the same time. They use residential proxy IPs where it's just you know someone's home device that's you know forwarding traffic. They'll use web services, commonly used web services, so things like Dropbox and um Wii transfer and things, again, they're gonna be used by your users on a daily basis. So if you see traffic to that, you know, you're not really gonna be able to suspect things. You can't block all of that if you're running a large company with you know thousands of users. It does make things really hard. So that's why a lot of the time when tracking scatter spider or trying to prevent against scatter spider style attacks, it's important to be able to enrich your logs with tags and labeling and being able to say if someone is logging in from a consumer grade VPN, which they never normally do, or that brand of VPN is not allowed, it's not in policy, then you can block it. But if you don't know what that IP address is, then you're never going to be able to fight against that type of threat, essentially, because they'll just blend in. A lot of sort of internal behavioral level stuff as well. You know, that they like to use a whole range of tools. So I've built something called the ransomware tool matrix where I try and categorize every type of tool that a threat actor, a ransomware operator or affiliate or something or gang uses. Um so defenders can go in there and kind of start looking at like which of these tools are blocked, would these tools work in our environment? I mean, if a threat actor logged in and started using this, would we detect it? So helping them to measure the effectiveness of their controls is uh is kind of a uh a fundamental aspect of of how I think CTI and threat hunting should work inside of a business, really, is that you know, we can say, well, we know what the adversary is doing. If they tried that against us, would it be successful? Let's go and let's go and research, let's go and find out.
Robby PeraltaThere was a point in time, at least I don't know, five, six years ago, where they would say there was uh an argument in the industry whether you should block the usage of these sort of tools like sliver or cobalt strike was the other one, that if you should just block them altogether or you should if you should get an alert because then you kind of know that somebody's after you. Modern today, you should just block that shit, right?
Will ThomasLike yeah, I would always vote to block it because yeah, maybe back in the day, maybe 10, 15 years ago, there wasn't this massive, massive ransomware problem. Um, it was more espionage and things and data theft and stuff. I speak to sort of veteran instant responders and they'd say, Yeah, yeah, we'd leave the Chinese APT in the network and see what they did, see what they tried to steal. And I was like, That's exactly what I'm referring to, by the way. Yeah, you can't do that now because within half an hour you could have ransomware deployed on a thousand systems. Like it's just not worth the risk, right? But there is a there is a question of you know, maybe we should be thinking more about like can we create uh like sort of imitation environments, deception environments, and invite the threat actors to go into there, but you can do that in other ways that it doesn't make any mean any risk to your corporate network, right? But still, that's a that is a good way to kind of research these threats. But nowadays, yeah, I would just say block that stuff as cat as quickly as you can, build detection rules around it, and really focus in on these most used tools because there's a lot of tools that just keep getting reused by a lot of different threat actors. Take any desk, for example. You know, I'm not picking on the company for any reason, but for some reason, loads and loads of threat actors love using that tool. So if that tool is present in your environment, you have to question why. Like why is who's using it? What's the value of it? Can we change to something that's more you know, higher end, or or can we just remove it? Can we just use inbuilt Windows systems thing and things, right? So from my perspective, I would just block that stuff and and only allow it on a case-by-case basis.
Robby PeraltaSo knowing what you know uh and observing you know the most mature and effective clients around the world, which which tips do you have? Yeah, I know you just say gave some know your environment and block things that are not in use. So do you have any other ones that maybe aren't so obvious?
Will ThomasYeah, having that knowledge of what device do we use for this? What device do we use for that? Do we have the logs for this anywhere? If an incident was to happen today, would we be able to know if we were compromised by it? You know, asking those sorts of questions on a daily basis whenever some intelligence comes out that says, oh, a new uh Juniper device is being exploited in the wild by a Chinese APT group for the last six months. Can you say, okay, A, do we use those devices? B, where do we use them? C, do we have any of the logs for those? And D, can I actually threat hunt and see if we if they tried to target us or if any of them were exploited? We're even leaving out like, are any of them vulnerable? Are they patched? Are they secured? Do they have controls, controls in place? Right. There's so much work that you can do by being more proactive, and you're stopping so much more like if you can spend, for example, $100,000 being proactive, you could potentially save a million dollars reacting to a massive incident, right? So you may as well try and get ahead, have teams and resources who are helping you get ahead of those things, patching stuff. That's open, locking down ports that shouldn't be exposed to the internet, removing dodgy accounts. Maybe something has been exploited and it's got a cryptocurrency miner running on it. Shutting stuff like that down prevents anyone else from getting in. When you're dealing with massive environments, those are the types of things that you come across. So vulnerability management is not dead yet. No, definitely not. It keeps many teams up at night. The worst type of scenario is when a critical bug gets dropped on a Friday with a POC on GitHub or something like that. And then just all the ransomware gangs and all the APTs go crazy on it Friday night. And it's just you know, really pull one out for the defenders uh when I whenever that happens.
Robby PeraltaSo two questions in one to wrap it up here. So the um the role of a threat intelligence platform are also a tip. What is that? Or like what should clients know about that? Because I don't think that many clients have that unless they're really big. I would assume that most clients outsource this to an MDR provider and they just expect that to be in place. So maybe if you have any thoughts around that as well. And then I have to ask it, uh, you know, what are you seeing around the threat actor use of you know LLMs or agentic, if you do have any insight into that? What do you think is interesting? And I'll let you figure out the order do you want to answer those questions in?
Will ThomasUh yeah, I'll tackle the the threat intelligence platform one first. So, threat intelligence platforms, they kind of have a bad reputation, I think, in the industry because no one is able to really give them the time and resources that they deserve to operationalize them properly. You know, many companies will just go out and buy high-end enterprise as a SaaS tip for you know hundreds of thousands of dollars, but then never actually properly hook it up to their EDR or to their firewall or their proxy or something like that and enrich those logs. And nowadays I'm seeing a trend of companies from our own customers at Dean Camry. I'm seeing customers, they'll have a seam and they have a then they have a saw to do automation and they kind of want to just let's just enrich everything in our seam and saw and build playbooks and generate alerts and threat hunt inside of it, which is great. You know, it's a great way to to use threat intelligence, just plug it directly into the tools that you're in most of the time. But if you don't have a threat intelligence platform, then you're not really able to store some of that stuff in there and have it and keep it as a like a knowledge base. So every time an alert is fired, you want to extract those indicators of compromise, put them in a threat intelligence platform, and then keep them. Because if you do that for enough time, you know, if you do that for a month or or six months, you know, certain patterns will emerge. You'll see, okay, 90% of the phishing emails come from this sender. Why don't we just block them? Why don't we put enhanced inverting around them? All the SSH brute forcing that we've seen in the last month come from these three ASNs. Well, again, we can make sure that nothing can log in from those. We can make sure nothing can connect to us from those. You're able to know, understand your environment, and understand the landscape and the threats focused on your organization. I think one of the problems that some teams fall into, I mean, my old team as well, when we were probably getting started, was that we fell into the trap of like, well, let's, you know, let's focus on what China's doing today, or let's focus on what Russia's doing today, and let's go and threat hunt for the latest sandworm TTPs. It's like, well, that's that can be good, but has that threat actor ever targeted you before? And what's the likelihood of that threat actor targeting you? Does the technologies and exploits and things that they use even affect your organization? Like if they're targeting Avanti VPNs, but you don't even have Avanti VPNs, is there really much of a point in threat hunting for that when there's so many other things that do affect you, you could be threat hunting for? So it's having that that knowledge of your organization, of your tech stacks, of your security stacks, and you know, the priorities of these things, which many teams I think are still, you know, I still find that they're struggling to deal with these themselves personally. So having having a tip is a it's a good idea, it's a great thing to do, but you have to dedicate the right time and resources. And if you're not using it pop properly, then it becomes a huge kind of black hole of time and money. So you some teams I've just seen, they say, Well, we'll just enrich our semen saw and do as best we can, but you know, you're not being proactive then. You're being you've you've gone back to being reactive. So the other thing, so the other question you asked was about LLMs and threat actor use of LLMs. I guess my my main worry and concern is the fact that threat actors are using it to speed up their attacks and develop things quicker. I've seen reports and blogs and talks and things about oh, I used this LLM to find a zero day for me. And I verified it and it works. And and it's in the in like open source software. So the software and the code is all public. Anyone can analyze it and find the bugs. The idea is that as an open source community, the developers are all you know finding the bugs and squashing the bugs themselves. But realistically, there's too much open source software for every bug to ever be found and squashed. But now with LLMs, you can just go and rapidly find this stuff. So I think advanced thread actors and maybe even sort of organized hypercriminal groups will start to be using LLMs to find those vulnerabilities in zero days in that open source software, which is broadly used across you know across the world and things. So if you have a bug in one of those, you can access a lot of different types of systems. And the potential is pretty scary. And then the other potential is that they can kind of automate attack styles as well. Um, so how hard is it? How hard would it be to really automate a kind of a ransomware attack from start to beginning where you gain access, you enumerate, you deploy an RMM tool, you brute for you, you know, you brute force an account, you log in, you run the ransomware on the domain controller. Like it's not the most sophisticated type of attack in the world. So I don't see why a bunch of scripts can't be put together for an LLM and run against companies. So that would be those would be my two main concerns.
Robby PeraltaYeah. And I mean that last example that is happening today. I mean, almost in like a proof of concept level, but at least what what the reports have shown are they're using too off-the-shelf tools that we've seen before and we know about. I guess it gets really scary once they start using tools that we haven't we don't have signatures for, which you don't know about. So you haven't added them to your lists. Because if that happens, then yeah. But you haven't seen this happening yet.
Will ThomasOr well, well, we have we have seen um blogs about researchers finding vulnerabilities, and then we've seen those exploits that vulnerabilities get exploits developed for them, and then those get rapidly used in the wild. So React2 Shell is a great example of that, where a researcher used, I believe they used OpenAI or potentially Claude to find the vulnerability in React. And then the exploit got made, published to GitHub, and then we just saw way a massive wave of exploitation using that bug. And then I believe AWS, the threat intelligence team at AWS put a blog out saying, like, we've seen Chinese APT groups using this. So it's already going on, really, whether it's the threat actors finding it and using it themselves. I'm sure there's a some of that going on, but we've already seen cases of you know really smart researchers finding it, but then cybercriminals taking advantage of it. You kind of uh made a point that reminded me of the fact that with those signatures, right, you can kind of create infrastructure in an entirely unique way every time. That makes writing those fingerprints and signatures much harder. And if you can recompile and edit your code and rewrite your code in a different language every time, again, that makes writing those detection rules and behavioral rules much harder. And you know, that things are gonna get things are gonna slip through, things are gonna get missed because of that. And I'm sure that's what like the EDR vendors and the firewall vendors are are focusing on right now. But yeah, it's it's it is a worry.
Robby PeraltaDoes that sort of like decrease the value that you'd get from uh from your team, for example, since a lot of what you're doing is sort of reputation and analysis-based?
Will ThomasYeah, I would say the the value that we bring is different in a way that we provide as much context as we can about an IP address for people to be and domains, for people to be able to come up with their own signatures and make their own decisions about this stuff. So, as well as providing tags that are based on our signatures and fingerprints, we do also provide sort of reputational and risk scores about things that can also help you uh pick up and track this stuff. So if an IP address has like a self-signed certificate, or it's spoofing a certificate, or it was created on an ASN, and statistically that ASN has a lot of malicious traffic associated with it. You know, there are ways and patterns that you know threat actors won't be able to always evade, but you know, there are ways that they can uh develop stuff to to get around it.
Robby PeraltaThat's like that pyramid of pain, right? Those are the things that they don't switch very often, I guess. Uh last question for you. Your if we do want to follow you know the the access, the initial access trends, you have a podcast of your own. How often is that? And what did you discuss in that podcast?
Will ThomasThat's right. Yeah. So, Team Cymru, we have a weekly podcast now called the Dragon News Bites. So we go over the the weekly news and then we add our own thoughts and opinions, you know, kind of like I've been doing here. So feel free to tune in, listen to the latest threats, um, and and you know, get a get a taste of you know what we think about it.
Robby PeraltaWell, Ms. Thomas, thank you for all you do, all the great work, and and Team Cymru as well. And I'm looking, I'm hoping I see you before the B-sides and Burmouth. But uh until then, thank you for your time. Take care.
Will ThomasYou're welcome. Thank you. Bye-bye.
Robby PeraltaWell, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast mnemonic.no. Thank you for listening. We'll see you next time.