

What We’ve Learned from LockBit and Black Basta Leaks (and News) - Ian Gray - PSW #888
Aug 21, 2025
02:15:17
This segment is sponsored by Flashpoint. Visit https://securityweekly.com/flashpoint to learn more about them!
Recent leaks tied to LockBit and Black Basta have exposed the inner workings of two of the most notorious ransomware groups—revealing their tactics, negotiation strategies, and operational infrastructure. For defenders, this rare window into adversary behavior offers critical intelligence to strengthen incident response and prevention strategies. In this interview, we'll break down what these leaks reveal and how security teams can use this intelligence to proactively harden their defenses, including:
- Key takeaways from the LockBit and Black Basta leaks—and what they confirm about ransomware operations
- How leaked playbooks, chats, and toolkits can inform detection and response
- Practical steps to defend against modern ransomware tactics in 2025
In the security news:
- Practical exploit code
- Old vulnerabilities, new attackers
- AI and web scraping - the battle continues
- 0-Days: You gotta prove it
- WinRAR 0-Day
- LLM patch diffing
- $20 million bug bounty
- Your APT is showing
- Hacking from the routers
- Its that easy eh?
- NIST guidance on AI
- Words have meaning
- Developers knowingly push vulnerable code
- My Hackberry PI post is live: https://eclypsium.com/blog/build-the-ultimate-cyberdeck-hackberry-pi/
Resources:
- Inside the LockBit Leak: Rare Insights Into Their Operations: https://flashpoint.io/blog/inside-the-lockbit-leak/?utmcampaign=WBHostedSCMedia2025&utmsource=SCMedia&utmmedium=email&sfcampaign_id=701Rc00000S48bZIAR
- 2025 Ransomware Survival Guide: https://flashpoint.io/resources/e-book/2025-ransomware-survival-guide/?utmcampaign=WBHostedSCMedia2025&utmsource=SCMedia&utmmedium=email&sfcampaign_id=701Rc00000S48bZIAR
- AI and Threat Intelligence: The Defenders’ Guide https://go.flashpoint.io/ai-and-threat-intelligence-guide?utmcampaign=WBHostedSCMedia2025&utmsource=SCMedia&utmmedium=email&sfcampaign_id=701Rc00000S48bZIAR
Show Notes: https://securityweekly.com/psw-888