The Cybersecurity Defenders Podcast

Intel Chat with Matt Bromiley and Chris Luft.

Show Notes

Intel Chat with Matt Bromiley and Chris Luft.

• OpenAI says Astra is the first of its models to reach the "Critical" cybersecurity capability level under its Preparedness Framework — the tier that means a model can independently find and exploit zero-days across well-defended systems, or run an end-to-end attack from a high-level instruction. Astra scored perfectly on ExploitBench, independently discovered two zero-days, escaped a browser sandbox, and chained flaws in a hardened OS to get root. It also refused 91.5% of cyber jailbreak attempts, versus 59% for GPT-5.6 Sol. Matt's take: every frontier model now seems benchmarked on offensive security, and the model with no governors on it is the one to worry about.
• Post-DEF CON phishing aimed at security researchers. Huntress documented an actor who DM'd one of its researchers on X while impersonating a CoinDesk executive organizing a conference. The lure was a Google Doc carrying a malicious Apps Script sidebar, then ClickFix-style instructions — Atomic macOS Stealer (AMOS) for Mac users, fake Google updates and PowerShell for Windows. The Windows chain ended with NetSupport Manager as a RAT, a Ledger wallet implant, and a proxy that installed its own certificate authority and redirected VirusTotal lookups. Matt's read: they probably just bought a conference attendee list, and the write-up should become awareness training for everyone outside security.
• A Philippine nuclear agency and a naval contractor breached through flaws that were already patched. Hunt.io found an attacker-controlled ownCloud server in Amsterdam holding ~1.2GB of files, after the operators exploited an ownCloud bug from 2023 and a WordPress caching plugin bug patched in 2024 that were both still exposed. The haul included a research reactor core-component database, fuel inventories, radiation safety documents, personnel records, BitLocker keys and credential stores. Hunt.io stopped short of attribution despite Chinese-language code comments. The twist Matt loves: for once it was the adversary who left a repository wide open, giving defenders a look at their tooling — Sliver, Metasploit, an embedded Meterpreter build.
• Silver Fox counterfeit installers that switch off Windows Update. Microsoft tracked an active campaign using high-fidelity fake software-download sites aimed mainly at Chinese-speaking users and China-based operations of multinationals, with a payload whose hash changes on every download. It persists via scheduled tasks disguised as IT jobs, adds Defender exclusions from a SYSTEM task, deletes shadow copies, then stops update services, renames update DLLs and clears the Windows Update cache. And it still stages out of C:\Users\Public and C:\ProgramData — which sets Matt off on why those are still not no-go zones after 13 years, and why nobody has shipped the frontier model that just fixes the basics.

Stories covered:
• https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
• https://www.huntress.com/blog/defcon-phishing-google-doc-malware
• https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency
• https://thehackernews.com/2026/09/fake-software-installers-disable.html

Chapters:
0:00 Matt checks in from Virginia Beach
1:44 OpenAI's Astra crosses the "Critical" cyber threshold
3:43 Every frontier model is now aimed at cybersecurity
6:52 So where is the model with no governors on it?
8:23 Post-DEF CON phishing targeting security researchers
10:42 Did the adversary know who they were targeting?
12:55 Turn the write-up into training for everyone else
15:01 Philippine nuclear agency breached through old, patched flaws
17:48 For once, the adversary left the door open
21:26 Silver Fox: counterfeit installers that disable Windows Update
24:00 Still C:\Users\Public, 13 years later
25:42 Give us a frontier model that fixes the basics

The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

Subscribe wherever you listen:
• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740
• YouTube: https://www.youtube.com/@limacharlieio

Learn more about LimaCharlie: https://limacharlie.io

#cybersecurity #infosec #AIsecurity #threatintel #malware

What is The Cybersecurity Defenders Podcast?

An accessible but technical podcast about cybersecurity and the people who keep the internet safe. The podcast is built as a series of segments: we will be looking back at the last couple of weeks in cybersecurity news, talking to different people in the industry about areas of their expertise, we're going to break apart some of the TTPs being used by adversaries, and we will even cover a little bit of hacker history.