Talkin' Bout [Infosec] News

This episode explores an AI agent that canceled someone else’s gym reservation, the growing offensive and defensive roles of AI, and a sharp rise in ransomware attacks. The panel also discusses privacy concerns surrounding Meta smart glasses, new passkey-theft and MFA-bypass research, the Snowflake hacker’s guilty plea, backdoors in ZBT-Link routers, compromised cameras aboard UK Navy drones, reports of AI models hacking real targets, and research into the reliability of AI-generated security patches.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters
  • (00:00) - PreShow Banter™ — The Old Jerks
  • (08:30) - OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10
  • (12:00) - Story # 1: OpenClaw cancels another person’s gym reservation
  • (27:43) - Story # 2: Ransomware attacks surge 20% amid the AI distraction
  • (39:08) - Story # 3: Backlash grows against Meta’s AI smart glasses
  • (46:28) - Story # 4: Passkey theft and MFA-bypass research
  • (49:19) - Story # 5: Canadian Snowflake hacker pleads guilty
  • (51:16) - Story # 6: ZBT-Link routers found with a China-linked backdoor
  • (53:06) - Story # 7: UK Navy drone cameras reportedly transmitted data to China
  • (56:19) - Story # 8: Meta reports AI models hacking real targets
  • (01:02:44) - Story # 9: AI-generated security patches succeed only about half the time

Links
Story # 1: OpenClaw cancels another person’s gym reservation
Story # 2: Ransomware attacks surge 20% amid the AI distraction
Story # 3: Backlash grows against Meta’s AI smart glasses
Story # 4: Passkey theft and MFA-bypass research
Story # 5: Canadian Snowflake hacker pleads guilty
Story # 6: ZBT-Link routers found with a China-linked backdoor
Story # 7: UK Navy drone cameras reportedly transmitted data to China
Story # 8: Meta reports AI models hacking real targets
Story # 9: AI-generated security patches succeed only about half the time

Infosec: Age of AI Summit


Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 
https://poweredbybhis.com

Brought to you by:
Black Hills Information Security 
https://www.blackhillsinfosec.com

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest
https://wildwesthackinfest.com

Creators and Guests

Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Guest
Kip Boyle
Kip Boyle is a husband, dad, entrepreneur, and experienced cyber risk manager. He founded Cyber Risk Opportunities LLC in 2015 after 7 years as the CISO of PEMCO Insurance in Seattle. As a captain on active duty in the US Air Force, he served in the Combat Archer and F-22 Stealth Fighter programs, where he was the director of enterprise network security. These days, he serves as virtual chief information security officer for many customers, including a professional sports team and fast-growing FinTech and AdTech companies. Over the years, Kip has built teams by interviewing hundreds of cybersecurity professionals. And now, he’s sharing his insider’s perspective with you!
Producer
Ryan Poirier
Ryan Poirier began his time at Black Hills Information Security (BHIS) as the Video Producer and Editor in August 2020. Ryan polishes and perfects every webcast, podcast, and workshop on the BHIS, ACM, and WWHF YouTube Channels. Prior to Ryan’s time at BHIS, he worked for one of the largest public schools in the United States, conducting their video production and live broadcasting. He joined the BHIS team because he felt like it would be a great group of people to work with, and he couldn’t pass up the perfect next step in his career. Outside of his time with BHIS, Ryan does freelance photography, attends Cars & Coffee events, and expands his knowledge of audio and videos.

What is Talkin' Bout [Infosec] News?

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET

Corey Ham:

Like, let's be honest, probably a lot of the old guard, like, gray beard jerks died of COVID. Or like, that was the first

Wade Wells:

time the best time to go live.

Corey Ham:

Just said, yeah. Either died or just won't come out. They're like

Ralph May:

Oh my god.

Corey Ham:

Also with the AI stuff, they're like, these are the people who like, they are like, not. You reach a point where you choose. Are you old man yells at cloud? Or are you like, gonna like embrace new technology? And I feel like AI for a lot of those old guard is just like a no.

Corey Ham:

That's so It's just like a, I'm not doing it. I'm not going to a conference and hearing and wearing a mask and being all paranoid with my rebreather three m thing. And like, then also like hearing pretty much exclusively talks about AI and why it's gonna either save the world or break the world or whatever. That's my thing.

Wade Wells:

So the other big thing is they had the silent disco headsets this year, where if you were going into the main track or anywhere on the main Floor, you had to get a headset, and that was how you heard the listeners.

John Strand:

You the headsets were on the chairs, but you could also run the hacker tracker app. And you could look did you try? I was not

Wade Wells:

an easy like I was not I tried for like thirty minutes. I'm like, you know what, like, I'm just gonna get

Ralph May:

it in development.

Wade Wells:

You gotta go you gotta go sign up for the DEF CON Wi Fi. You gotta bring over stuff onto your phone. You gotta say those honestly, I really I liked how you could hear everything. And that was pretty like, it was very quiet. It was almost spooky quiet inside the main tracks.

Wade Wells:

But it did feel a little dystopian though. Yeah. That was the one thing like a little disconnected.

John Strand:

But so but I

Wade Wells:

didn't go to

John Strand:

any who I don't go to DefCon for the talks. It's like No way. I thought

Corey Ham:

that was your favorite thing. Line for two hours to see someone drop a CD unit they already put on The GitHub two weeks

Ralph May:

last time I was there, the you didn't have to wait that long to see. It that's like the old that's the old DefCon. You could still like see a lot of these like before, it'd be like a line around the block. And you'd like, who cares? But now you could just literally walk up and I'd be like, oh, look, there's some seats.

Corey Ham:

Now there's no line. They got cliffs. Yeah. There was no line. I kind of want to see that.

Corey Ham:

I don't know if it was recorded. I kind of want check out was like,

John Strand:

when when he Ed Scottis got him for one of the hack one of the conferences we did in DC, and it was one of the best presentations, one of the most chaotic presentations I've ever seen in my entire life. During his presentation, he was walk I don't even know what the hell he was talking about, to be completely honest with you. But he dropped down from the audience. Right? And he's walking around the audience, and he goes by people, and he he they have a coffee cup, he would walk by them, grab their coffee cup, and take a sip of their coffee.

Corey Ham:

He's like, oh, that's Irish coffee.

John Strand:

Do this. He would go, no. And then he would sit it down, and he kept going to a whole bunch of things until finally he got to one person's coffee cup. He sipped it and went, and then continued to drink that dude's coffee. Requesting presentation.

Corey Ham:

You are being coffee. Do not resist.

John Strand:

That is where I want to be in my career. I want to be that crazy old bastard that can give a presentation. John and John.

Wade Wells:

Are you not? I have news already. You're not. Yeah. I was about to say you're not far.

Corey Ham:

Oh, no. No. Okay, John. Okay. He's, you're missing the old part.

Corey Ham:

What you gotta do is you gotta have, like, old John Strand that shows up. Like, he has, like, white wig, and he's like,

Bronwen Aker:

hello, dude.

Corey Ham:

John, how do I do AI for Donald's treating you?

Bronwen Aker:

So you can do the proper old wild man dude.

John Strand:

I I I shaved my head down again, and I shaved my beard. But during this last week, I let it grow out. There's a lot of white hairs. But somebody was mentioning at the booth, we had we need to be selling black hats and white hats and old hats. So

Corey Ham:

That's just mean. Whoever says that is, like, 18 years old.

John Strand:

I know. I know. I know. I get sick and tired of some of these young hackers calling me out as a boomer. I'm like, you don't even know what that fucking means.

John Strand:

And I'm not a boomer. Let me explain to you why.

Corey Ham:

Let me explain to you how I drank out of hoses. But I am. I love lead. I listen. Let me to you.

Corey Ham:

I I this But this isn't gonna talk about

John Strand:

the goons, though, like, in the actual show? Because I wanna talk about that. I think it's important to have that conversation.

Ralph May:

Alright. Yeah. So

Corey Ham:

Shout out to the goons. They're awesome. They did great.

John Strand:

They did great.

Corey Ham:

I will say, I'm probably gonna have to rebrand because Yeah. Yeah. Yeah. If we're being honest, this, you know, this is something you know, I don't know if this is, like, maybe the boomer, you know, generational gap. But goons, that means something different in 2026.

Corey Ham:

And It's not good. It's not you you, like

Wade Wells:

Don't Google it. Don't Google it. But the ad then it just turned on.

Ralph May:

I think

John Strand:

it actually kinda got started because the Simpsons had a joke where someone came up to the Simpsons' house and, like, knocked on the door. And I was like, who's there? Who's there? Goons. Who?

Corey Ham:

Yeah.

John Strand:

They go hired goons, and then they, like, open the door. It's

Corey Ham:

Yeah. It's basically probably gonna have to get rebranded. Like, it's one of those things that, like

John Strand:

work right now.

Corey Ham:

Yeah. If if if the modern terminology overtakes your terminology, you kinda just have to change. Right?

John Strand:

Like Like,

Wade Wells:

wait ten years old.

John Strand:

What was Zeke, bro? Bro. He has a big girl, bro.

Ralph May:

Cool. I think I think alright. So they didn't they didn't rebrand their name. But they I think they have rebranded their attitude and I think that's what you were getting.

Corey Ham:

Yes. That is true. Yes.

Ralph May:

As a whole, right? They may have not changed the name but the overall and I think it's two things. I think it's one, the size, the amount of people Hey,

Corey Ham:

we gotta stop.

John Strand:

No. Ralph, wait until after the finger. To what? To talk about this. Wait till the finger comes out.

Corey Ham:

No. That's not the I think Pre show counts as pre show. We don't need that. There's no article that says goons are nice. Yeah.

Corey Ham:

There's no article. John, you have to write an article that's just goons are nice now question mark and publish it publish it to Black Hills in a sec. And then we can talk about it. List tomorrow.

John Strand:

Will publish an article. Goons are nice now, and I won't put that up.

Corey Ham:

Honestly, though, I I do think it's good to talk about I like, you as the, you know, person who does Wild West Hackin' Fest and was like, we had to start this because people were jerks. It's like, I guess people aren't jerks anymore. Alright.

Kip Boyle:

Mhmm. You're trendsetters.

John Strand:

Yeah.

Ralph May:

You're trendsetters. I I I just think that they they had to kind of come together in the sense of there there was a lot of public pieces about what the conference was and what they were doing. And there were some other stuff unrelated necessarily to goons that they had to, like, make a moral compass on. Right? Whether they're gonna let these people into the conference and other stuff.

Ralph May:

And, you know, I feel like it's really difficult to, you know, make those moral compasses and then have your, essentially, representatives of your organization, you know, going against those, you know, ideologies. Agreed. Agreed. Yeah. That that gets difficult.

Ralph May:

Right?

John Strand:

When you when you have a code of conduct saying don't be an asshole Yeah. And you have a group of people that are just, like, asshole in it up,

Corey Ham:

you're like

Ralph May:

There there should be somebody to talk to about it and I I think that might be a piece of it. Right? I know some personal friends who I found out they were I didn't even know they were goons, and I was like, holy crap. And but, like, it didn't really matter at that point, but I do see, like, the perception versus the reality and because

John Strand:

you don't see a gooner. It's just you look at all people. Exactly. Exactly. Judge.

John Strand:

Yes. Yeah. Non goon status.

Kip Boyle:

Very much.

Corey Ham:

Judge you much.

John Strand:

So you ready? We just lost

Wade Wells:

Corey. We lost Corey.

Bronwen Aker:

Yeah. We lost Corey.

Ralph May:

I think it's his his new doc. It's just not docking with him.

John Strand:

Dockin'? So free.

Corey Ham:

Yeah. He got he got like a new doc.

Wade Wells:

He was saying his doc wasn't working that like his camera is going on. It was overheating or something.

Corey Ham:

Technical difficulties.

Wade Wells:

We'll wait. We'll give him two Mississippis. Two Mississippis.

Bronwen Aker:

Oh, there we go. I just admitted him in. Hopefully, it's the real Corey Ham and not a deep fake. Yay.

Ralph May:

Did your deep fake break?

Corey Ham:

I think I think my Mac might be dying, guys. I'm not gonna lie.

Ralph May:

And this is it. Recommend getting a

John Strand:

getting a new one. So let's just not even do the finger. Let's just keep rolling.

Corey Ham:

No. No. No. No. Let's do

Kip Boyle:

the finger.

Corey Ham:

Come on.

Ralph May:

Okay, guys. Come on.

Corey Ham:

Come Come on. Come Come on. Hello and welcome to Black Hills Information Security's Talkin' Bout News. It's 08/10/2026. And we have a beautiful beautiful day.

Corey Ham:

It's half the country's on fire. The other half has a 90% humidity with 90% chance of thunderstorms every day. That's my Def Con's over. We're all back. It was a beautiful 112 degrees.

Bronwen Aker:

Whole time It's Jay.

Corey Ham:

John Strand caught on fire a couple times while he was mountain biking, but he survived.

John Strand:

It was awesome. I I tried to avoid the fires by biking at 04:30 in the morning with a with bike lights, and it was 90 degrees at that point.

Corey Ham:

So it was flipping hot down there. So it makes sense. We should

Ralph May:

definitely do a conference there.

John Strand:

Okay. No. We're not doing a conference in Vegas. That's not going to happen.

Corey Ham:

So there's plenty

John Strand:

of conferences in Vegas. Vegas is well represented.

Ralph May:

Yeah. They they have space. Think I think John's right. You can pretty much do it anywhere else, and it'd be more exotic.

Corey Ham:

Yeah. People are saying the classic line in the Discord, which is that, oh, it's a dry heat anyway. No.

John Strand:

No. Go mountain biking. Go mountain biking.

Corey Ham:

It's not dry if you don't

Bronwen Aker:

It won't be dry for long. Will die.

Corey Ham:

Alright. So introductions. My name is Corey Ham. I'm the director of continuous pentesting at Black Hills, Infosec. And we got Bronwen, the director of AI agents at Black Hills Infosec.

Corey Ham:

We got Kip Boyle, CISO. Where are you the CISO, or are you just everywhere? You're the CISO?

Kip Boyle:

Well, well, I've got my own company called Cyber Risk Opportunities, and I've got about, I don't know, about 24 customers that I CISO for. Fantastic.

Corey Ham:

You're you're CISO x 24. Most people are just x, you know, 10 x engineers. You're a 24 x engineer.

John Strand:

I was talking to a good friend who just wanted one SISO. You're like the Tom Brady of SISOs. You're you're gonna there's gonna be a lot of hate

Corey Ham:

for you.

Ralph May:

Yeah. He's beat the North Koreans.

Corey Ham:

Good job.

Kip Boyle:

Boyd, I wish I had 24 full no kidding paychecks.

Corey Ham:

Yeah. You gotta try. That's that's the your title would be North Korean operator. Yeah. At that point.

Corey Ham:

At that point. Yeah. We also have John Strand, the director of Being John Strand. I think that's his official job title.

Ralph May:

Class.

Bronwen Aker:

Wade. He was lead intern.

Corey Ham:

I don't yeah. Wade, like, what's your actual job title? Is it just like through law? Like, how

John Strand:

is that linked and looked at the camera like, I actually don't know.

Wade Wells:

I recently got pro I actually recently got promoted. Product

Ralph May:

development lead. You could think.

Wade Wells:

Oh, you knew it. You knew it.

Corey Ham:

Wait. How did you know it, Ralph? What's going on here?

Kip Boyle:

That's a marketing function, isn't it? I got the demo.

Wade Wells:

I manage logs and detections.

Corey Ham:

Laser specialist. I see you.

Wade Wells:

Laser specialist. That's a wake up. So I don't need to switch. There

Ralph May:

is a guy

Corey Ham:

named Wade Wells that is a laser specialist for AWS.

Ralph May:

Wow. Why does AWS have lasers and why?

Corey Ham:

Okay. Turns out it's I don't know, dude. I can't read. I don't know.

Wade Wells:

But

Corey Ham:

Anyway, enough about Wade's personal life and job title. We also have Ralph whose job title appears to be laser gator hunter. Yes.

Ralph May:

Yes. I'm working on it. It's I What's the AI laser gator hunter.

Corey Ham:

Okay. Yeah. Yeah. You can fix anything with a laser. We know this.

Corey Ham:

So yeah. I think the first article we should talk about I don't know if you guys even saw this, but it was I think it's the continuation of the most interesting news articles about AI agents doing things they're not supposed to do.

John Strand:

Just keeps

Wade Wells:

Which one? Which one?

Corey Ham:

So the hug the the OpenClaw one. The Australian OpenClaw.

Wade Wells:

That wasn't the one

Corey Ham:

I had. OpenClaw might. Yeah. So, basically, here's what happened. A man who is very high definition in this picture.

Kip Boyle:

He looks AI. Is that He looks kinda air

Corey Ham:

generated, but we're just we we don't know if Australia is real. We're gonna assume this is real. But yeah. Down under. Basically, a guy was running OpenClaw, as you do, because, you know, you can't be bothered to do anything yourself these days.

Corey Ham:

You have, you know, you have your AI assistant do it for you. And he asked for a spot in one of his gym's coveted morning classes. I'm assuming it was I don't know. Like, I was thinking of

Wade Wells:

It was like,

Corey Ham:

I I was thinking of Pilates, hot yoga.

John Strand:

I was a hot flow yoga is what he was doing.

Corey Ham:

So anyway. He he he asked his AI agent to get him a booking. And the AI agent said, okay, I got you a booking. By the way, I had to cancel someone else's booking using a web application vulnerability that I discovered. And by the way, here's a big pile of CVEs for you.

Corey Ham:

So like, I I basically I think, you know, the the details are a little bit sparse at this point. Right? Like, this is kind of there's two takes here. One is, this is f 12 hacking. Like to some degree, this is kind of like f 12 hacking, which is like for those under a rock, that's basically looking at the page HTML source code.

Corey Ham:

It says, here's the password. Now you have the password. You're a hacker. You're getting prosecuted. But on the other hand

Ralph May:

fuck this.

Corey Ham:

Is it is it f 12 hacking? Like, this person did not ask the AI to hack anything. It did he didn't say, you know, exploit vulnerabilities or, you know, like, he didn't even say, like, you must book this at all costs. Continue. Like, he didn't give it a prompt that backed it into a corner.

Corey Ham:

Right? I I do I do

Ralph May:

feel like this article is kind of pulling at Strand's. I mean, like, you could accidentally do like, any of us could accidentally do this. Like, you don't need to

Corey Ham:

There was no auth. Yeah. It just looked at the API, looked at the Swagger docs, and did what it like, it's not even really hacking. Right? Like, it's

Kip Boyle:

just an over eager intern.

Corey Ham:

Yeah. I like how

John Strand:

we're pooping on the AI's hacking. It's like AI, this is just scrap hacking. Like, this isn't impressive. Go hack.

Corey Ham:

It's always a hackathon. Went

Bronwen Aker:

and it on its own know, unilaterally decided to access the API to boot another person out of their appointment in order to get one for Hold on.

Corey Ham:

But it was so awesome.

Ralph May:

Favorite human. Hacking. There was no I

John Strand:

love I love how it said. It's like, I found through the API that I could cancel other people's reservations, and it says something like, bad news. I can't

Bronwen Aker:

add the

Corey Ham:

hack again. Back. Bad news. So okay. I the the interesting discussion here, first of all, it does say that they were using anthropic models.

Corey Ham:

So we don't know which one. My guess is it was Opus five because that Opus five loves to hallucinate, and it's not the best. I had to switch off of it personally. But I think they turned up the aggression on Opus five just a little too high and they were like, we're gonna be OpenAI. No.

Corey Ham:

So it it wasn't DeepSeek. It wasn't Quinn, or it wasn't one of these, like, open models that everyone's scared about. It was, you know, it was our model

Bronwen Aker:

of Scott. Hermes.

Corey Ham:

No. It was OpenClaw,

Kip Boyle:

not Hermes.

Bronwen Aker:

Oh, it's sorry. Was OpenClaw. Okay. It's corrected. It was OpenClaw.

Corey Ham:

Different And

Bronwen Aker:

OpenClaw does have a history.

Corey Ham:

Well, I mean, if you tell a model to do something, it's gonna do it. It doesn't have

Ralph May:

to try to do it. Right? And if you're like, it didn't work, it's gonna be like, alright, I'll try it again. I'll try it again. Sometimes it'll be like, we've been working on this for, like, three hours.

Ralph May:

You sure you wanna keep going? What? Let's keep going.

Bronwen Aker:

Person on the planet who keeps my AIs on a short leash?

Wade Wells:

Yeah. I told Claude I wanna be an astronaut. That hasn't happened yet. So, you know.

Corey Ham:

You are not the only person on the planet, but you are probably the only OpenClaw user that keeps their because OpenClaw is explicitly saying, let it rip. I will say that my like, there's the interesting thing is, should he be held criminally? Was there even a crime? Like, is is this hacking? Like, you know, not really.

Corey Ham:

Right?

John Strand:

Honestly, this is no different than the people that are, like, getting in car accidents with Teslas. Like, Shanahan, I think, as a coach in San Francisco, I believe, got into a car accident. He's like, autopilot was on in my car. Like, you're still gonna be held liable. Right?

John Strand:

It's your

Corey Ham:

Well, okay.

John Strand:

Or computer. So, yes, I'm gonna say they're they're gonna be held liable.

Corey Ham:

I agree with that. I don't necessarily think there was a crime committed here. Like, obviously, it's not like illegal to book to kill, like, cancel people's gym bookings. I guess, you like, you could there's probably a scenario where you could just call and be like, hey, this is Stanley. I need to cancel my 8AM Pilates and like cancel someone else's reservation.

Corey Ham:

Right? Like, is that illegal? I don't think it is. It's just like being a dick. Yeah.

Corey Ham:

So I I mean, basically, but the the question, you know, the reason this popped off in a news article is because hypothetically, you know, everyone's asking the questions that f that they're asking about OpenAI's containment breach, Meta's containment breach, Anthropics containment breach. Basically, the question of like, what are the rules of engagement with agentic AI? What are like, what are if I did even if, you know, what is the model trained to do, etcetera? I But yeah.

John Strand:

This but this is one of those things I keep talking about. Because whenever we're talking about an Anthropic or Open AI, we're missing the entire conversation. Right? Everyone's trying to say, well, we need to focus on these two. How are they gonna lock things down?

John Strand:

There was, of course, the black hat talk from the guys at OpenAI, which was very political in what they said and what they did not say. But the point that everyone's missing is this capability of an obliterated open weight model that anyone can run on enough hardware is is basically Prometheus bringing fire to everybody. Everybody has it. Or if you want me to get a little bit more obscure, I could say, like, gully foil bringing pyre and throwing it out at the end of The Star is My Destination. When we're looking at this, like, this is not something that people are going to legislate.

John Strand:

This is not something that people are gonna be able to deal with. And I was having another conversation with somebody else at BHIs because we're getting some refusals in some of the commercial models that we're using. We just pivot to a different one, and that's fine. I think eventually, this is gonna get these open weight models for offensive security are gonna get shut down in bedrock because all it takes because we've already look at what we with, like, with Amazon, with IP gateways and Kinesis and, like, all of the different things that they're running Lambda functions, we were using that for pen testing for a long time, and Amazon basically came out and said, no. You're not doing that shit anymore.

John Strand:

And I think that we're going to see these, like, the commercial models, like OpenAI and locking it down for everybody. And then I think you're eventually gonna see Amazon Bedrock is going to be like, no. You're not gonna run offensive AI. And then what the hell do you do for the rest of it? Because once again, somebody can run it on a really good MacBook Pro.

John Strand:

They can run it on a DGX Spark from NVIDIA. So what the hell are we gonna do to try to restrict this down? I think the fire is out, and it's out in the public. It's running wild. And I don't think there's any way other than trying to shore up our defenses to deal with this.

John Strand:

Wade, you are definitely the person.

Wade Wells:

I want to get

Corey Ham:

a deep

John Strand:

side on this because that's where it gets interesting.

Wade Wells:

I want to talk about the call to action from that OpenAI call. Right? At the very end, they talked about how we need to start figuring out how we can get defense to move as quickly as offense in the AI space, right, which is horrifically hard, I still think. There's so much configurations and so many ways you can augment yourself with AI, but it requires a lot of setup still and a lot of allowance from different organizations. But it it'll be interesting if the shit like there's so many AI socks, right?

Wade Wells:

Like I want to see something else. Like there's a couple cool detection engineering ones. Like, I I still think there's enough room out there for AI and Blue Team to innovate, but there hasn't been really. I don't know. What do you what do you think?

John Strand:

I don't wanna get too deep into the weeds on this, but I had a long, long, long conversation with Dave Kennedy about this. And just so you know, there's gonna be a debate between Dave and myself at Wild West Hackingfest. It's gonna be moderated by Ed Scottis. And Dave's intention is going to be that

Corey Ham:

No bench press. This is just a verbal debate.

Ralph May:

Yeah. No. Yeah. If there's weights on stage, you're done. You're done.

John Strand:

Yeah. No. I I use the joke. I think I've said it on the show. I know I can out climb Dave.

John Strand:

I know I can out bike Dave. I can probably outswim Dave. I just hope to God I can outrun Dave. So it's a joke that I've used way too much. I need to stop.

John Strand:

But Dave's contention, he he's got he's got some data. He's bringing some stuff to the stage. I think he's gonna lose. I do. But his contention is that defensive AI is gonna be more powerful than offensive AI.

John Strand:

And I I don't see that. Right? I don't I don't see that for a while.

Wade Wells:

Agree with you. I don't think it'll be for a while. And it's just because the Godzilla, like the Yeah. 10,000 pound gorilla that internal IT is right? Like the first thing one of the first bots that we wrote was something that scrapes notes to try to threat model our network and to try to find stuff that we should have logs for that we don't.

Wade Wells:

Right? And of course,

Corey Ham:

Got what is it out immediately by IT?

Wade Wells:

It did not. So that was the cool part. Right? So we started building it up all these super specialty AIs that's trying to help us augment to fill the holes. But the thing is, to it, there's always gonna be holes, there's always gonna be gaps.

Wade Wells:

And I think the red team will be able to find those quicker. So it's just how do we build a defense to catch them somewhere else. Right?

Ralph May:

I wanna I I think that AI is not better at offense than it is at defense. Right? I think it you can flip that coin over and over again. But I think, Wade, and I agree with you, what you're kinda hitting at is the organizations that are having to implement this. They're moving slow.

Ralph May:

It's not that they it's not that the AI can't be good at defending. It's the organization is already behind and not ready to implement these things to bring them to catch up. Right? We already have an industry AI problem. We have an organization problem.

Kip Boyle:

We have we already have an industry wide cadence of being outgunned and struggling to keep up as blue teamers. And I don't see that changing because AI showed up. I think

Ralph May:

Yep.

Kip Boyle:

It's I think that pattern's gonna continue. And we're just gonna see that the there there's new tooling, but I don't think it's gonna change the heart of it.

Corey Ham:

It could be it could be

Wade Wells:

like an an evolutionary moment where only the people who are good with AI survive.

John Strand:

Yeah. Well, I think that's where

Ralph May:

we're headed. Yeah. I I

Bronwen Aker:

think that's gonna happen anyway be because that's what happens with any new emergent technology. I mean, we've seen it dozens of times and and it

Corey Ham:

Are you telling me horse whip manufacturers are going out of business?

John Strand:

Oh, no. So sorry.

Corey Ham:

I don't believe you. It's terrible. These stupid automobiles, they can only go 20 miles an hour, Bronwen.

Bronwen Aker:

I do think that the blue teamers haven't fully utilized the potential of AI. And having looked at so many pen test reports where the organization doesn't even know their own infrastructure, That's exactly the kind of thing that should be on a prawn job and have an agent going in, check the parameters, see what's new, see what's not behaving, and then report it to a human so they can follow-up on what needs to be followed up. That's a type of grunt work that human teams don't have time to do, and it's exactly the kind of thing that agents could be spun up to do to take the load off of

John Strand:

team teams. I I think you just nailed it, and I wanna get Kip's take on this. I think you just nailed it. But I think that instead of using AI to do these grueling tasks of doing this kind of, like like, good homework, good hygiene, people are like, I want an AI that's going to stop all attacks against my environment all the way through. I want something that's gonna look at all my logs.

John Strand:

It's gonna unify all the logs. It's gonna see everything. It's gonna give us whole 100% visibility, and it's gonna stop all attacks. Instead of saying, I want an AI that's just gonna do asset inventory in my environment, and I wanted to hook into these data sources and pull it back. Make sure that works.

John Strand:

Now I want an AI that makes sure that we we can scan, we can identify API endpoints, and we're getting logs off of those API endpoints. Like, that's boring AI work. I think that everyone is trying to go to the cool, sexy AI work. And I think that there's a lot of You

Bronwen Aker:

know what?

Wade Wells:

You guys are ruining my

Bronwen Aker:

cock.

Corey Ham:

Sexy is

Bronwen Aker:

great on cool and sexy is great on

Corey Ham:

smart ways.

Bronwen Aker:

But you know what? Good security, good governance, good governing is boring.

Ralph May:

Get over it. There you go. Yeah.

Corey Ham:

I was gonna say, like,

John Strand:

girls, everybody should come to the offensive side because it's always fun.

Corey Ham:

But I

John Strand:

wanna get Kip in on buzz as a blast because we hear each other all the time, and Kip is, like, he's he's he's he's like a siso

Wade Wells:

and 25 times siso.

John Strand:

His guy's son knows so much. Putting his on this.

Corey Ham:

He said 24. Did he get another client while we were talking? We were talking? Yeah. I just figured out right.

John Strand:

On retainer, Corey. It's 25 now. It's a 0.25 of 100. Alright. Kip, take it away, man.

Kip Boyle:

I I can't help but to think that there's a bigger issue here, which is human beings don't like being proactive. They're not interested in being proactive. And, so it doesn't matter how good things, you know, proactive things are that are around and available. It goes back to the old marketing principle that people don't buy vitamins, buy aspirin. And so even though we've got these agents that can get proactive, it's the human being that isn't interested in setting it up.

Kip Boyle:

Yeah. I think that's I think that's a huge theme and behind all this.

Corey Ham:

I'm writing that put

John Strand:

you on a panel. Yep. I'm writing that down for my debate with Dave.

Corey Ham:

Take your hat. We'll plug this while we're here. John Strand let us write down this pathway. The AI Summit Friday, Kip's gonna have a panel with four other individuals, and, you can hear more discussion probably just like this. I'm not gonna guarantee there's gonna be this exact question asked.

Corey Ham:

But if I was a panelist, I would ask this question just to throw a big molotov cocktail in the conversation and then walk away.

John Strand:

I and by the way, we're already at 5,500 registrations for the summit. Like, it's gonna

Corey Ham:

be And only 25,000 of those are AI. Only

Kip Boyle:

already got it was not 6,000 at this point

Wade Wells:

over 9,000. You need to

Bronwen Aker:

talk about your math skills.

John Strand:

Let's not talk about my math skills, bro.

Corey Ham:

No, Corey, not John. No, no, hold on. No, I asked AI. It said that was accurate. I don't see what the problem is.

Corey Ham:

Yeah. Well, are you saying I had to use a sub agent to verify the math? What am I, a genius? Yeah. So,

Bronwen Aker:

okay. Gonna recommend an abacus.

John Strand:

We wanna talk about both in minutes.

Corey Ham:

Yeah. Let let's let's pull this back a little bit, because during discussion, multiple news articles came up into my brain. The first one is, there was a news article in the register that basically was like, the everyone's distracted with AI, and they're getting hit by ransomware. Basically, it's like that that is actually happening. Basically, in July, this is the article, 20% increase in ransomware attacks in July from eight from 668 in June, which, again, these numbers are shocking, up to almost 800 incidents.

Corey Ham:

There have been we've talked about it on the news. Right? There's all kinds of articles, deep strike. There's new ransomware threat actors coming out that weren't around before. So like Shiny.

Corey Ham:

You you know, at the end of the day, guess who's not doing, like, the this is the thing. You can't say, oh, it's defensive AI versus defensive AI. And what it actually is is just all of offense versus all of defense, and you don't necessarily need AI to get ransomware. I mean, there's nothing I mean, maybe they used ransomware for some of the ruse or I'm sorry. Maybe they used AI for some of the ruses, or like, I'm sure AI assisted in some way.

Corey Ham:

But what we're not talking about is fully agenda gransomware. Like, AES two fifty six doesn't need AI to encrypt all your files. Right?

John Strand:

That's true.

Corey Ham:

So like, as far as like, are blue teams obsolete or whatever? Obviously not. And in fact, us focusing on all these stupid CVEs is actually pivoting us away from, you know, social engineering, phishing, account compromises, like the the bread and butter stuff that SOC and blue teamers have had to deal with for years.

Ralph May:

And still what's going on

Kip Boyle:

here is the attackers are using AI to increase the frequency of their attacks. They're still using the basic Yeah. Yeah. Yeah. Exactly.

Kip Boyle:

And that and so I I I a lot of my customers are actually in the broader manufacturing industry, and they barely know what they're doing with when it comes to cybersecurity. And One thing that I'm definitely seeing going on here is there's so much lack of awareness out there. The only people that I talk to are the ones that have either been directly burnt by a ransomware attack, or they had a good friend who got directly burnt and couldn't go golfing with them for a week because they were locked down in their building trying to get their systems back up again. There's so much cluelessness out there about this. I think we have a lot of what we need to resist a lot of ransomware attacks.

Kip Boyle:

We just don't do it.

John Strand:

I so I agree with that, Kev. And I I think that what we're seeing here is the fruits of the labor of absolutely trying to meet the bare minimum. Right? I remember years ago, an organization I used to teach for, they had a class, like, called meeting the minimum, and it was it was a huge seller because everyone wanted to look at a compliance standard and basically be like, okay. I get it.

John Strand:

There's 400 pages. Like, just tell me what's the minimum I need to do in order to be compliant. And I think that that worked kind of because a lot of the attacks that were out there had to be somewhat intentional with some examples sorry, some kind of, like, exceptions around automated malware and some worms. But what's going on now, I think, Kip, and I think that just kind of reflecting back what you're saying is, you know, the the quote used to be, I don't have to be the fastest guy in the woods. I just have to be the guy that's faster than the slowest guy.

John Strand:

Am I right? Right. And with AI, as I've said multiple times, the bear now has a jetpack and an a k 47 kills indiscriminately. Yeah. Yeah.

John Strand:

So these all meeting the minimum and just gonna fly in under the radar because you're a small county in, like, whatever state.

Corey Ham:

No one would guess domain.

Kip Boyle:

Yeah. Yeah. Well, see, the the economics of attacking people are so in the favor of the attackers. That it costs nothing to attack anybody no matter how big or how small, they happen to be. And, again, this is something else that senior decision makers at, a lot of places don't understand because they still think about, well, they'd never come after me because I'm too small.

Kip Boyle:

And that's because they think, well, I'm not going to try to sell to small orgs. I'm going to try to sell to big ones because that's where I'm going to get the most bang for my sales dollars you know, that I spend. So their head is not in the game at all. They just don't get it.

John Strand:

Well, sorry. I'm putting down a shirt idea of a network's network no matter how small for exploitation. Yeah.

Bronwen Aker:

Yeah. And by the way,

Kip Boyle:

speed is the new firewall. That's what I'm telling my customers. Mhmm. Speed is the new

Corey Ham:

Gotta start to get speed.

Kip Boyle:

Yeah. Right?

Wade Wells:

That's a good one.

Kip Boyle:

You gotta get fast because they're getting fast coming after us. And, John, to your point, it's like, who, you know, who who cares, you know, if you're not the fastest runner, as long as you're faster than that other guy, you're gonna get out of the woods okay. And I think that absolutely applies here. You gotta be fast at patching. You gotta be fast at detecting when something bad's coming at you.

Ralph May:

The patching one is also kind of interesting. Like, before, historically, you'd like, don't patch right away because what if there's a bug? Oh my god. Of course. Right?

Ralph May:

Of course. Now it's like, if I don't patch right away, I'm just gonna get attacked right away. Like, I'll be the first one to get phoned down because I didn't auto patch.

Kip Boyle:

Right? I I know CSOs who have said, you know, the risk of not patching is now greater than the risk of tipping over a box or two or taking a service offline. So it's flipped.

Corey Ham:

Yeah. I think

Bronwen Aker:

You know, I I have an unpopular opinion. No. Are never ever ever yeah.

Wade Wells:

I know, Sean.

Corey Ham:

Do you?

Bronwen Aker:

We are never ever ever going to get people to do security well until we make it easy. So long as we force our users to make multiple decisions about, gee, is this the right link to click? Is this the right button to click? And all of this stuff until we make it easy for people at multiple levels. But most importantly, at the user level, we are never gonna do security well.

Bronwen Aker:

And the acceleration of red team and malicious attacks courtesy of AI has really shown a spotlight on this this weakness.

Corey Ham:

Well, that was Yeah. I mean, I I asked OpenClaw to fix my network. And it just turned everything off. It was great. That's the quickest way to

Kip Boyle:

do it. Losing their life savings is is unbelievable. People are losing so much from these catfish scams, these romance scams. And But I don't feel that

Bronwen Aker:

still following.

John Strand:

Because a lot

Ralph May:

of them are

John Strand:

losing money on Kelshi and other online betting forms.

Kip Boyle:

So I guess I guess

Ralph May:

my I'm gonna make a bet on that, John. How many people are losing money?

Kip Boyle:

I I guess my my point is is that until until a person experiences it for themselves, they don't get it.

John Strand:

Well, it's the it's the German quote, those who will not learn must feel.

Corey Ham:

Yeah. Well, I

Kip Boyle:

think that's just human beings.

Corey Ham:

To to draw this a couple conclusions, I think. First of all, if you are a practitioner in cybersecurity and you right now, we're in a unique time in cybersecurity, which is that our leadership, regardless of, you know, that CISO or whoever person doesn't know about ransomware until they're not golfing because they're dealing with ransomware. They do know about AI, and you can use that to your advantage because they're gonna come to you asking, what are we doing for AI? And that's your time to say, oh, we're gonna fix all the ten years worth of BS that I've been telling you about that you wouldn't let me fix, and we're gonna do it because AI. Right?

Corey Ham:

Like, AI is the pin end of the wedge. Use it to your advantage. You can get AI to drive any narrative that you want. You you know, you could say, oh, we got we really have to fix our unsupported operating systems because AI. We really have to start patching things because AI.

Corey Ham:

We really have to fix our firewall rules because AI. Like, this is your opportunity.

Wade Wells:

AI is the new sis a kev.

Ralph May:

Yeah. It's exploitable by AI.

Corey Ham:

That's right. You can you can say, oh, you go ask AI if this is a concern because AI thinks everything's a critical. So if you just tell your your, you know, leadership, well, you ask AI, do you think this is a security vulnerability? Here's my report. And it'll be like, this is a critical, oh my God, what's going on?

Corey Ham:

So yeah, basically never let a good disaster go to waste. AI is a little bit of a disaster, but the other Oh, go ahead, Kip.

Kip Boyle:

I'm just going to go, yes, never let a good crisis go to waste because that's when everybody's open to doing something they've never done before so that this thing that they're going through is never gonna happen again. See, that's that's another example of pain moves people to do things they never would have done when they're not feeling pain.

Corey Ham:

Wait a minute. Are right. Wait a minute. So the other thing I would say is

John Strand:

HIS management axiom, Kip. 25, you all. 25. Pain moves people.

Corey Ham:

So the other thing I would say is that, you know, it's not I'm gonna you know, this is a little bit of like a legalese technicality. But I think AI will make defense better through offensive actions. Like, because what I'm seeing at a lot of my companies is that people who don't otherwise do pen testing are like, I asked the AI to find vulnerabilities in our apps, and it found a ton of vulnerabilities. And now I have all this ownership over all these discoveries of vulnerabilities that are things we've never pen tested, never seen, never been looked at. Everyone's a pen tester.

Corey Ham:

Welcome to the party. Sorry. Report writing sucks. It's okay. You'll get used to it.

Corey Ham:

But, yeah, basically, yeah, basically, part of how offense makes your defense better is by letting everyone find vulnerabilities in everything all the time, and just living in that. That pain that we're talking about, live in it. Let it sit in. Let it sink in and just feel the pain.

Kip Boyle:

So Yep. And I'm

John Strand:

scared about that because, you know, this gets into the question of just exactly how much tech debt has the entire IT industry collected.

Corey Ham:

A lot. Oh my god.

Ralph May:

A lot.

Corey Ham:

Oh, jeez.

Ralph May:

But they had checked that before AI. AI just

Corey Ham:

I was gonna say. Right. AI just brings it all out into the open. Yeah. And also helps you fix it.

Corey Ham:

Right?

Bronwen Aker:

All all they did was pour gasoline and light the match.

Corey Ham:

Yeah. Some of the most boring

Bronwen Aker:

things already there.

Corey Ham:

Yeah. Some of the most boring things are are still gonna be boring and have to be fixed, but they can be fixed faster with AI. Yeah. And the other thing is that AI itself isn't really it's pretty neutral. It it doesn't

Wade Wells:

Nope. We lost Corey now. The AI got him. Yeah.

John Strand:

AI got him. This doc I think his Mac actually died.

Corey Ham:

OpenClaw. And

Bronwen Aker:

I I hear his point though.

Wade Wells:

Know there's gonna

Kip Boyle:

some Bad Mac.

Bronwen Aker:

Yeah. Well, we'll have to shuffle on without him for a moment.

Wade Wells:

He's there. His audio

Corey Ham:

I'll works be for a back. I gotta unplug my Mac to get video back, but I'm I'm alive. Keep going. I think you all should talk about the next article, which is definitely about I think if it were me, I would go and talk about the backlash against meta glasses because we talked about that last week.

Bronwen Aker:

Oh. Or flux. Yeah. The perfect glasses.

Ralph May:

Like, what happened what happened now? I mean, I know the DEFCON thing, but what else happened? Like, what was the backlash about the perf glasses? Was there, like, more?

Kip Boyle:

Well, there's a there's a there's a company out there that's selling glasses that are what do they call it? Anti is that it? No. No. No.

Kip Boyle:

No. No. There's a company out there that's selling glasses that are that are they they're like ordinary glasses, but they're selling them as, like, non AI or the anti pervert glasses. I gotta find that. It's it's brilliant.

John Strand:

I I do think it was interesting. They had signs all over DEF CON saying that you're not allowed to use these glasses anywhere. Yeah. I think this is coming.

Corey Ham:

Doctor, let go.

John Strand:

I I think it's right now you can easily identify these glasses. They're clunky. They're large. They're awkward. But I I think, you know, I think augmented reality is gonna happen.

John Strand:

Yeah. You know?

Ralph May:

I think it's gonna turn into, like, the cell phone. Right?

Wade Wells:

Damon. Yeah. Yeah. Yep. Well, that's what Barry

Kip Boyle:

V says, but I'm not so sure.

Bronwen Aker:

I know I know that some companies have been experimenting with contact lenses that can provide enhanced vision stuff, and I I fully see that kind of implementation for these AI enhanced things being just a matter of time. And it's it's a classic problem. We've got this new technology. How long before it becomes undetectable using normal observational means that a typical human would have.

Corey Ham:

That's what

Kip Boyle:

it's gonna have to get to if it's gonna get actually spread. And then that

Ralph May:

was like, when cell phones first came out,

Corey Ham:

you could record. People would like,

Ralph May:

oh my god. Look. They're recording or whatever. I mean, like, it was probably it was a lot lot less intense because you could see that somebody was holding something. Right?

John Strand:

It was very odd.

Ralph May:

Yeah. But still though, I mean, the glasses are the same way. And the other thing too, and this is another article that came out recently is OpenAI is developing a assistant. Right? And one of the things that they're trying to develop in their assistant, which has no screen, by the way, is a camera so it can see around it to give it context on what's going on to help you with the events.

Ralph May:

Alright? Or or to help you with that. Now, whether you want that or not, that's totally independent. I'm just saying that little cameras that can observe what you're doing and then that augmented reality, not just information, but also, like, being able to, like, assist you in that moment by being able to see like, most of the people when you're using an assistant, you need help with something, you just take a picture of it and send it to it. What if you didn't need to take that step and that's where this is kinda gonna go?

Ralph May:

So

Kip Boyle:

Hey, Corey. Show can you show the Duck Duck Go anti perfect glasses link that I just dropped into the chat?

Corey Ham:

Ryan can. I'm I'm Right. That kind of Yeah.

Kip Boyle:

Don't know. Not allowed to touch

Ralph May:

the thing. What's the thing?

Corey Ham:

I don't click links. I don't even know how. Yeah. Here. Pull it up.

Bronwen Aker:

I can share it to Discord.

Ralph May:

Oh, yeah. We got it glasses. Just regular glasses. Got it.

Corey Ham:

Yeah. Then published August 1 or August 4, not April 1. I love it. Zero

Bronwen Aker:

AI cameras or electronics at all. What a novel concept.

Kip Boyle:

An unlimited battery life. Unlimited I don't know.

Corey Ham:

You still have a modern day version

Ralph May:

of a manual transmission right here.

Corey Ham:

I I think the like, to close-up the meta thing, I think the most interesting thing, and this is the same thing as the flock stuff, which I don't think we'll get that deep into. But basically, society has decided, yo, dog, that was the line. This this is the line. This is where we're gonna put up with, And this is be over the line. And that applies like, the meta glasses is definitely getting some backlash.

Corey Ham:

And we've seen like even content creators that use the meta glasses are getting like d you know, like people are like, oh, I don't support you. Like, they're losing subscribers because they're

Ralph May:

stroking on the Metaglasses.

John Strand:

But, Corey, it takes one Pokemon GO. Like, it takes one killer app to completely change everything. Right. What

Corey Ham:

is it gonna be called? Goon at goon while you're a goon? I don't know. Yeah, goon while you can, I guess maybe? Was heading out

Kip Boyle:

at an insurance conference recently because that's where I get some customers sometimes and there was a woman walking around and she had the meta glasses on and I walked up to her and I said, are those things turned on? And she's like, what are you talking about? I said, well, you've got the medical glasses on. I can see that you do. And she goes, oh, most people have no idea that I'm wearing.

John Strand:

They're big and bulky, and they look very obvious.

Ralph May:

I have I have a pair of them. They do light up when you're recording. They're not

Kip Boyle:

Unless you poked its high up.

Ralph May:

Yeah. There's a way

Corey Ham:

to Yeah.

Ralph May:

They they they they're not that bulky but the thing is as that technology does improve, it will get to the point where you can't tell and it it will start to discriminate people who are just wearing glasses. Okay? So, like, eventually, you

Corey Ham:

know, it's gonna be

Kip Boyle:

Well, I guess my point is is that a lot of normies don't understand what's going on yet.

Corey Ham:

Yes. Well, yeah. That's that's totally true. I think that it's the same thing with, like, any new technology. But the the biggest thing is, like, we need to come up with a DOS for like, I don't like, I thought I was thinking about this the other day.

Corey Ham:

I was like, okay. So I'm sitting on the subway next to someone wearing meta glasses. I don't wanna be recorded. What do I do? Right.

Corey Ham:

Like, what if I just can I just say this? I and I know there's already a joke that I'm getting to about what you can do. But my idea was I'll just start listing like PHI. I'll be like, hello. Yes.

Corey Ham:

Oh, you're my doctor? My social security number is 657, you know, whatever. But the other thing, the joke, this is like in the internet now, is people have just been playing Disney copyrighted songs. Oh my god. That's like that's basically the the hack, the denial of service.

Corey Ham:

It's just play Disney copyrighted songs.

Kip Boyle:

It's a small world.

Corey Ham:

Let it go. Let it go. We So yeah.

Ralph May:

Anyway We built we built detections in the in the Tala software for detecting metaglasses, like your ear pods, all of those things. Like

Corey Ham:

Yeah.

Ralph May:

Yeah. You see where they are and around. So they actually are my my point with this is that they are very fingerprintable. Right? Especially with the the low amount of them out there.

Ralph May:

So

Corey Ham:

For sure. But it's just like everyone's saying where, like, at a certain point, it doesn't matter.

Kip Boyle:

At a certain point, I

Ralph May:

can detect LTE signals. Okay. Cool. Everyone's got one.

Corey Ham:

Right? You're not gonna believe this. Everyone has AirPods. Yeah.

John Strand:

Yeah. Is there an LTE signal in the room with you right now?

Corey Ham:

Yes. Yes.

Ralph May:

That device Five g.

Corey Ham:

Five g.

Ralph May:

Well, we actually we have a d f a d f software to actually run down devices that are transmitting on LTE and at different, you know, at different time intervals and all this other fun stuff. But when you're in a room with a bunch of people, yeah, there's a bunch of cell phones everywhere. Right?

Corey Ham:

So no one no one should take this. Do not I wanna be clear in the public. Do not make an entire channel where you fox hunt down people wearing meta glasses and then put a little sticker on their back that says, I'm a pervert. Do not do that. Never do that.

Corey Ham:

That.

Ralph May:

Never do that.

Corey Ham:

Alright. So anyway, pivoting. I do wanna talk about friend of the show and interesting research. Dirk Dirk Jan Malima has published an interesting blog about basically passkey theft. So, you know, in security, we we presented passkeys as this silver bullet.

Corey Ham:

And, of course, anytime there's a silver bullet, there's

Ralph May:

a There's Microsoft to mess it up.

Bronwen Aker:

Here's a

Corey Ham:

silver bullet. Challenge accepted. Okay. That is very true. This is Microsoft's implementation of a silver bullet.

Corey Ham:

That is true.

Kip Boyle:

Still made a is

Corey Ham:

super interesting article basically. Essentially, at if you don't know what Road TX is, if you're not into cloud exploitation, look it up. It's amazing. If you're

Bronwen Aker:

a hacker,

Corey Ham:

it does it's a Swiss army knife of Azure ponage and and Entre Azure Azure Active Directory ponage. It does a ton of different things. But basically, he's added in capabilities to potentially borrow some Windows Hello keys for authentication, and it's worth reading. This is not the only passkey article from this week. There's actually a grouping.

Corey Ham:

We're

Bronwen Aker:

seeing

Corey Ham:

you know, someone even wrote like a meta article in the Hacker News basically about and by meta article, I don't mean like Zuck's yacht with a bunch of sunscreen.

Kip Boyle:

Oh. I'm being

Ralph May:

like He can't help anybody who's nearby. I can tell you that much.

Corey Ham:

Were two other there were SpectreOps published a vulnerability in passkey theft and MFA bypass. And also unit forty two published attacks against the Chrome password manager that can steal pass keys, basically. So there's a lot of research going out into pass keys. They are they are still better than passwords and they

Ralph May:

It's are still better than inbound.

Corey Ham:

Still better than TOTP MFA, but it's not a silver bullet. Right? Like, it depends on the implementation. A key is a key. A credential's a credential.

Corey Ham:

They can be stolen. They can be replayed in

Wade Wells:

certain circumstances. Software to store your pass keys in. That's

Kip Boyle:

Yeah. But I don't need passwords anymore. So why would I have password manager?

Wade Wells:

Like digital wall. It's a pass key manager now. Pass key manager.

Ralph May:

Now, it's on the box.

Corey Ham:

Or or No. I think you should let I think you should let Windows do it and let them screw it. Yeah. It's much more

Wade Wells:

secure that way.

Ralph May:

Oh my gosh. Have you Jesus. I did that last week. Just trying to secure your own intro your whole intro environment. If you've ever, like, gone down this road, like, Microsoft makes this the most complex thing ever.

Ralph May:

I'm not surprised. There's like 15 more things like passkey for, you know, issues. Right? Especially with Windows Hello. Oh my gosh.

Corey Ham:

Yeah. And they did supposedly fix this. Now, we can probably go and look at the same code base and find 17 other vulnerabilities of the same exact type. But this had it's got a CVE and it was fixed. So yay.

Ralph May:

Won't happen again.

John Strand:

What else do we got?

Corey Ham:

It'll never happen again. There's I guess this is kind of a small thing, but the snowflake hacker, Canadian guy, waifu, that was his code name online, Pled guilty to the snowflake breaches and is facing up to thirty years in jail. Yeah. So that's that happened last week during Defcon week.

Bronwen Aker:

Ouch.

Corey Ham:

Yeah. Pled guilty, I'm assuming to avoid I don't know what to avoid. More jail time?

Ralph May:

Yeah. Less sentence maybe? Yeah. It probably took a lesser sentence by plea Yeah.

Corey Ham:

As opposed to going to court and then getting found guilty. Also, like, in most these digital crimes, if we're being honest, the amount of evidence it it's likely that the amount of evidence this person is facing is just an immense like, there's no hearsay. It's like, we have seven terabytes of logs. Like That's that's what he said.

John Strand:

We have you in a chat board detailing everything you did step by step to, you know, all

Corey Ham:

of

John Strand:

your friends, and it's unencrypted. Like

Ralph May:

The logs don't stop us, but

Kip Boyle:

surely catch you. This guy was hacking like he was in a in a jurisdiction that had no extradition.

Corey Ham:

Yeah. I

Kip Boyle:

mean, it was completely stupid for him to do this in Canada.

Corey Ham:

Are you telling me young males don't have fully developed frontal lobes? I don't know if I

John Strand:

believe I think that's

Corey Ham:

what they're saying. This would be the first I've ever seen a young kid doing something dumb. It's not like I see them riding around my neighborhood on electric bikes every day doing leeches.

Ralph May:

My gosh. I can't wait until the article comes out where hacker caught and open AI subpoenaed for chat logs. Unbelievable. What found?

Corey Ham:

Yeah. Yeah.

Ralph May:

Guaranteed that's gonna happen. I'm just predicting this news story.

Corey Ham:

Yep. Yep. It's already happening. Yeah. For sure.

Corey Ham:

But So that happened. I mean, that's like a minor article. Basically, I mean, what else? There's I'm trying to think I mean, the the passkey stuff is big. There was that router thing we could talk about.

Corey Ham:

Basically, So if you you own a router made by a company called ZBT link, which again, this is we're talking about normies. Right? Like, the only people who ever bought this are people who have no concept what cyber security is. Then there's no no one in this room would ever even consider buying something like this, I don't think. But you never know.

Corey Ham:

But yeah. Here's the article basically that turns out there's a backdoor. Who would've who could've predicted this? Who would've

Kip Boyle:

They sold a lot of these things.

Corey Ham:

I think I can back to China? Who knew what? A backdoor to China. So this is like okay. We saw what was it?

Corey Ham:

Three months ago or something? The FCC banned any new router sale that was that didn't have their magic stamp of approval, which of course this wouldn't have a magic stamp of approval. 100,000 devices worldwide. We don't know what in The US what the count is. But this is the exact kind of thing that the current administration and general politics is trying to avoid, is basically a product that creates a botnet, then a backdoor, and is just a way how do you hack a US citizen?

Corey Ham:

You sell them a box that just is a, you know, part of a botnet. Zero. Sorry. This will be if you if you've deployed one of these, there's a CVE. You should definitely patch it instead of taking it out back and killing it with the hit slash

Ralph May:

If you deployed one of these, you cheap son of a bitch. You could've got a better one.

Corey Ham:

Could've got okay. Like, come on. You could've got literally and even just use the free like, there's a free router from your ISP. Like, what are you doing?

Kip Boyle:

They probably got this one from their ISP. Let's be serious. Probably.

Corey Ham:

Their ISP is like Shenzhen technology or something.

Kip Boyle:

So Hey, man. It's the it's the lowest per unit cost, and I gotta buy a ton of these. What is it?

Ralph May:

I I also saw another article. There was I think it was the royal or the I just posted it. Yeah. The United Kingdom Navy, they actually have they had cameras on their water drones, and they were compromised. Those cameras were manufactured in China, and they were sending information back to China.

John Strand:

What? What?

Bronwen Aker:

Yes. They were sending a ping and location information.

Ralph May:

Yeah. So Fine.

Corey Ham:

It's called the Kraken anyway.

Wade Wells:

How does it get that far where you just didn't notice it pinging? Right? Like Kraken. How many networks is it on?

Ralph May:

For the most part, I don't think actual Chinese devices are probably all, like, all the home stuff. For the most part, all of them. But when you're putting it on military things, okay, they're probably gonna turn that one on. Right? Like, that's the one time.

Ralph May:

It's just so dumb.

Corey Ham:

It's so It's so transparently stupid.

Kip Boyle:

You mentioned this in the, like, in the pre pre show banter, and it made me remember that, Taiwan is building an entire, industry of, of drones where they, as a national, you know, survival policy, are not allowing any Mainland China components to be in Yeah. Anywhere of

Corey Ham:

Oh, Same here. Same here. Yeah. We're doing the same thing in The US.

Ralph May:

Yeah. And a lot of

Corey Ham:

Oh, I was gonna say. Go ahead.

Ralph May:

I was gonna say a lot of the modern drones now that they're designing are designed specifically for GPS denied availability.

Corey Ham:

Yeah. Yeah. Fiber optic only.

John Strand:

No.

Ralph May:

Yeah. Not just fiber optic. Vision based GPS. Right? So that they're looking to identify their location based off the vision controls, not just off of a fiber optic cable.

Ralph May:

You know, like, they're they're fully in of, like, at electronic jamming on those devices.

Corey Ham:

So I also I mean, I'm speculating here about these cameras. But basically, the scenario is that it was provided the product was provided by a defense supplier in The UK, which is the, you know, same defense people. But basically, my guess is that this is totally unintentional. I don't think this is nation state trying to get into a defense con like, I genuinely think they just bought crappy cameras off of Alibaba or whatever and used them in their products and then realized later, ah, crap. The bill of materials has this in it.

Corey Ham:

Like, that's my guess. I'm speculating about that, but I don't even think it's fair to pin this on China. They're just selling cheap stuff, and it has backdoors in it. Shoddy procurement. Dumb enough to actually use it.

Kip Boyle:

Shoddy procurement.

Bronwen Aker:

That's what happens when you always go with the lowest bidder.

Corey Ham:

That's why you got a no

Ralph May:

in the military way. You've literally Well, you got a no bidder. Don't

Corey Ham:

bother. We got we we gotta have rid of that. I got a guy. He can paint the whole reflecting pool over the weekend for a 100 k. It's fine.

Ralph May:

I know.

Wade Wells:

He's gonna kill it.

Corey Ham:

Yeah. Yeah. I don't know. Any other article? I mean, there's a there's a handful of there's no chicken news.

Corey Ham:

I'm just gonna spoil it. Sorry, everybody.

Ralph May:

I'm sorry.

Corey Ham:

It was everything

Kip Boyle:

that was

Corey Ham:

I think, like, I the thing that's really sticking in my brain right now, like, didn't talk about it because I'm just assuming everyone's in the loop. But Meta also announced last week that their AI models hacked someone. Like,

Kip Boyle:

basically They literally would die. We'd announce that. Me too.

Corey Ham:

Me too. Too. My son is also It's so bad.

John Strand:

I think Yeah. Whenever yeah. I I think when it happened with OpenAI and then Anthropics, like, we hacked three companies. It's now a marketing tactic, which is sad.

Corey Ham:

Well, okay. So two other two other quick articles and just hot takes I have on this. So first of all, I think we just have to accept as an industry that there's two different audiences. There's the security folks like us. And then there's the AI machine learning engineers who actually build and test these models.

Corey Ham:

I'm increasingly convinced that the security people have never been in the room for any of these conversations or any of these discussions or approvals. Like genuinely, you're telling me the most advanced labs in the world don't know how freaking IP tables works or how to use it? Like that's basically where we're at. They like the most advanced technology in the world doesn't know how to use the most basic security controls. And I think the reason is, the same thing that happened with developers in the nineteen nineties and '19 like whatever.

Corey Ham:

Programmers weren't never taught security. So programmers wrote vulnerable code. I think we're in the same boat with AI ML engineers. They went through this course at Stanford that covered, you know, whatever fancy graphs and you know, numbers and weights and matrices and all that stuff. And at no point during that machine learning PhD did they have to take a class on threat modeling, containment, security, anything like that.

Bronwen Aker:

And so I'm sorry. Corey. What? I hate to tell you this. Nothing's changed.

Bronwen Aker:

Programmers are still not taught security ever.

Corey Ham:

No. They definitely are. I mean, when I I went to college for programming, and I had to take multiple security classes. Like, that is the the standard

John Strand:

school, but I think that this is just once again the Dunning Kruger effect. Right? Where you have people that are you know, they're really smart in one area. Right? Like, maybe they're developers, maybe they're in AI, and they just assume that they're gonna be good at computer security.

John Strand:

Right? They just assume that that's going to be the case. And the other the the bigger thing that bothers me about this kind of riffing off of what you were saying, Corey, is these are the people, these are the organizations that, like, two years ago were like, we gotta be careful. We gotta be careful. AI is gonna be dangerous.

John Strand:

It's gonna be really, really dangerous. Like, literally, the CEOs of these AI companies were telling us about the dangers of AI. Elon Musk is like, you know, there's about a one in three chance that AI is gonna wipe us all out. And then they end up setting up these labs with hardly any really good controls. Clearly, no effing monitoring whatsoever for what the AI is actually doing.

John Strand:

And honestly, you know, whenever you look at I can't remember if it was OpenAI or I think it was Anthropic that they saw what happened with OpenAI. They're like, we should go check our logs. If they're, you know, waiting through logs. We should go check our logs and see if something like that happened. Oh, crap.

John Strand:

It happened three times. Once again, it bothers me that we put more controls on our AI that we're using at BHIS than these companies that have literally billions of dollars at their disposal do. But I think it comes back to they don't think of computer security because they think they're the smartest guys in the room. And because they're really smart in this area, they automatically think it translates into every other area.

Corey Ham:

I think it's genuinely just lack of literacy. I don't even think it's necessarily that they think they're good. I think they just didn't even consider it. Okay. So I I would say

Bronwen Aker:

it's too out of the

John Strand:

same point, I I would say.

Corey Ham:

I I

Bronwen Aker:

take a hazard to having worked in academia and and worked with people in that headspace, I think there's also a lot of innocence going along. Like, one of the things when I when I was doing a deeper read into the the whole hugging face attack, and I finally was able to to find out that the researchers gave the specific directive to the models to be the best hackers they could be. The kind of person who's gonna do that is someone who has never had to suffer the consequences, and that's a a degree of innocence and ignorance.

Corey Ham:

Definitely some of

Kip Boyle:

that going on. You know what else is going on?

Bronwen Aker:

And that's that, I think, is is part of it. And that's why we need to have more jaded, crusty, pessimistic people like those of us in this room in those rooms with

John Strand:

Yes. Those young

Bronwen Aker:

You know, we're jaded. We know how things are gonna go sideways despite the best of of intentions.

Corey Ham:

Yeah. But

Kip Boyle:

look. And There's another thing that's going on is that these senior decision makers are on a happy path. Okay? They they wanna go public. They want the next biggest customer.

Kip Boyle:

They want the next quarter's profit, you know, to be bigger than the previous quarter. They don't think about what could go wrong. All they spend their time thinking about is what's going to go right.

Corey Ham:

They're like, I would one step further.

Bronwen Aker:

I ever worked with who only ever tested for success.

Corey Ham:

I mean, I would go one step further and say that my opinion about the current leadership at the AI labs is that they're just completely out of touch with any form of reality in any way shape or form.

Kip Boyle:

Well, there's that too.

Corey Ham:

You you see the, you know, Sam Altman getting toasted in the comments for being like, here's a great AI tip. If you if your kid expresses interest in a topic, just have AI generate a podcast, then you can listen to the podcast with your kid. It's like, dude, or you could just freaking talk to your kid.

Ralph May:

No. Don't say that.

Corey Ham:

Yeah. But this quote that

John Strand:

quote was even worse than that. I think this quote was something like, if your kid's playing soccer games or sports games, have it generate a podcast based on their sports game. That that counts. I don't know how like,

Corey Ham:

think I I wanna be clear. I think it was done genuinely with altruistic intent. I think probably 80 of the people who are working at these labs have altruistic intentions. Honestly, I think I'm to a point where like, that to me is more concerning. Like, I think Bronwen said that, like, we need we need more like crusty people.

Corey Ham:

Like, having an altruistic intent like thinking your AI is gonna save the world, it's not. Like it's you you gotta be careful with that. You know, it's like fanaticism. I

Wade Wells:

have the pivot. I have the pivot. So self promotion

Corey Ham:

Pivot out the door. Right?

Wade Wells:

Yeah. So one password came out with a recent research data about the patch the planet movement with Trail of Bits and Google, right? So this this is a 50 page report about it, that if you scroll down a little bit more, Ryan, there's a good pie chart a little bit more. Keep going. There you go.

Wade Wells:

Here. Scroll up a little bit. You can see each scenarios. Oh, no, no. So there's five scenarios, right?

Wade Wells:

One, the scenario is the AI patched a vulnerability and it was a complete fix, a complete fix, and it alerts and application behavior, alters. It doesn't fix the vulnerability. It completely fixes the old vulnerability, but it adds a new one. And then the third one is it doesn't fix the vulnerability. And it adds a new vulnerability.

Wade Wells:

Oh, talking about that again? Yeah. So from this data, it seems like it's got about a fiftyfifty chance to actually fix things. And it's a really good paper. I haven't read the whole paper.

Wade Wells:

I've read a good portion of it, though. So highly suggest it. I just thought it was crazy after

Ralph May:

looking into it. Which model is this? It must not be a good model. That's why.

Corey Ham:

Oh, yeah. That's definitely it's always the model. Definitely. It's always the model. It was

Wade Wells:

the prompt. Their prompt was only only sorta fix the problem. Yes. The the

Ralph May:

what do you call it? The scaffolding, what however you

Corey Ham:

call They didn't say make no mistakes and change no security vulnerabilities.

Ralph May:

I wanna see that clock marked down right now. I guarantee I could find the issue.

Corey Ham:

Yeah. I'll I'll have to take more I mean, I have to look into this. I mean, I think, basically, from my perspective, if the more the less adults there are in the room with AI, the more it's just gonna go crazy. Yeah. But yeah.

Bronwen Aker:

Looks like any youngster.

Corey Ham:

Let's close out, I think, with some plugs. Obviously, the AI summit is this week. I think pretty much everyone in this room other than maybe me and Ralph are presenting or talking or doing something at it. Wade, are you you're presenting. Right?

Wade Wells:

I'm not doing anything. I Alright. I had I had a lot going on and I was like, yeah.

Corey Ham:

Some What of you are just up? But anyway, Bronwen, Kip, and John, I'm assuming, John, are you doing something for this too?

Kip Boyle:

I am. I think I

Ralph May:

should've done the talk. I'm a loser. Yep. I'm there

John Strand:

for opening. I'm there for a panel discussion and a contender for closing. So, yeah, I'm gonna be there pretty much all day. It's a really stacked group. There's some fantastic people there.

John Strand:

It's incredible.

Bronwen Aker:

I mean, I'll be co hosting with Connor. We've got just tons and tons of people. It's being held on a Friday, and then Monday and Tuesday, the next weekend, we have workshops going on. If you haven't signed up, please check those out as well. It's gonna be just a great time.

Corey Ham:

Yep. It's super exciting. And you will learn something. You might it might be scary what you learn, but you will learn something.

Kip Boyle:

Speaking of workshops, I'll plug mine. I'm gonna teach one in September, how to hunt ShadowAI and what to do about what you find.

Corey Ham:

ShadowAI? That doesn't exist.

Ralph May:

No. No. I'm going to my phone now.

Corey Ham:

Alright. Anyone else have any final closing anything to plug or any closing remarks?

John Strand:

That's all we got.

Corey Ham:

Alrighty. Thanks everyone for coming. We'll see you Friday. I hope. If not, we'll see you next week.

Kip Boyle:

Later, everybody's great.

Corey Ham:

Bye y'all.