# Caught in the funnel. Page: https://stenobird.com/podcast/research-saturday-1377435/caught-in-the-funnel Text version: https://stenobird.com/podcast/research-saturday-1377435/caught-in-the-funnel.md Podcast: [Research Saturday](https://stenobird.com/podcast/research-saturday-1377435) Published: 2026-01-24T06:00:00+00:00 Episode link: https://thecyberwire.com/podcasts/research-saturday/409/notes Audio file: https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW9034131225.mp3?updated=1769790336 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/caught-in-the-funnel Duration seconds: 1413 ## Resource Today we have Andrew Northern, Principal Security Researcher at Censys, discussing "From Evasion to Evidence: Exploiting the Funneling Behavior of Injects". This research explains how modern web malware campaigns use multi-stage JavaScript injections, redirects, and fake CAPTCHAs to selectively deliver payloads and evade detection. It shows that these attack chains rely on stable redirect and traffic-distribution chokepoints that can be monitored at scale. Using the SmartApe campaign as a case study, the report demonstrates how defenders can turn those chokepoints into high-confidence detection and tracking opportunities. The research can be found here: From Evasion to Evidence: Exploiting the Funneling Behavior of Injects Learn more about your ad choices. Visit megaphone.fm/adchoices ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/caught-in-the-funnel/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/research-saturday-1377435/caught-in-the-funnel.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.