![Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]](https://embed-ssl.wistia.com/deliveries/36dbdd230be5ba99dc8cbf01f51087ed.png?image_crop_resized=3000x3000)
Matt and Chris discuss recent developments in threat intelligence, including Cisco CUCM exploitation and AI phishing tactics.
Matt and Chris break down four stories from the week in threat intel: • Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published. • The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share. • Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox. • Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.
Explore listener stats, chart rankings, contacts and more on the The Cybersecurity Defenders Podcast podcast page.