Talkin' Bout [Infosec] News

This episode examines Anthropic’s disclosure that Claude breached real organizations during security testing, along with new technical details about the OpenAI and Hugging Face incident. The discussion covers ExfilSquad’s claimed Microsoft breach, cyberattacks targeting U.S. water systems, and malicious Android TV boxes used for residential proxy networks and advertising fraud. The hosts also explore Google’s Android age-verification plans, Chrome protections against hijacking extensions, Microsoft Teams impersonation attacks deploying Chaos ransomware, and Bank of America’s acquisition of MDSec. Additional topics include the GrapheneOS duress-password court case, a DEF CON prediction market, continued Kali365 phishing activity, and credential-stuffing attacks against Chick-fil-A loyalty accounts.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters
  • (00:00) - PreShow Banter™ — Zuckers
  • (03:43) - Iranian Cyberattacks on U.S. Water Systems - 2026-08-03
  • (07:00) - Story # 1: Anthropic’s Claude Breaches Companies During Security Testing
  • (11:35) - Story # 2: Hugging Face Publishes Technical Details of the OpenAI Incident
  • (13:37) - Story # 3: ExfilSquad Claims a Microsoft Cloud Breach
  • (19:34) - Story # 4: Iranian Cyberattacks Target U.S. Water Systems
  • (28:27) - Story # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad Fraud
  • (40:51) - Story # 6: Google Introduces Android Age Verification
  • (43:26) - Story # 7: Chrome Targets Tab- and Homepage-Hijacking Extensions
  • (47:02) - Story # 8: Fake Microsoft Teams Support Calls Deploy Chaos Ransomware
  • (48:38) - Story # 9: Bank of America Acquires MDSec
  • (51:15) - Story # 10: GrapheneOS Duress Password Wipes Phone During Border Search
  • (55:25) - Story # 11: Pony Market Takes Bets on DEF CON and Black Hat
  • (58:06) - Story # 12: Kali365 Phishing Platform Remains Active
  • (01:02:26) - ChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential Stuffing

Links
Story # 1: Anthropic’s Claude Breaches Companies During Security Testing
Story # 2: Hugging Face Publishes Technical Details of the OpenAI Incident
Story # 3: ExfilSquad Claims a Microsoft Cloud Breach
Story # 4: Iranian Cyberattacks Target U.S. Water Systems
Story # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad Fraud
Story # 6: Google Introduces Android Age Verification
Story # 7: Chrome Targets Tab- and Homepage-Hijacking Extensions
Story # 8: Fake Microsoft Teams Support Calls Deploy Chaos Ransomware
Story # 9: Bank of America Acquires MDSec
Story # 10: GrapheneOS Duress Password Wipes Phone During Border Search
Story # 11: Pony Market Takes Bets on DEF CON and Black Hat
Story # 12: Kali365 Phishing Platform Remains Active
ChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential Stuffing
Infosec: Age of AI Summit

DEATHcon
- November 13 - 14, 2026
- Univeristy of San Diego
5998 Alcala Park Way
San Diego, California 92110

Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 
https://poweredbybhis.com

Brought to you by:
Black Hills Information Security 
https://www.blackhillsinfosec.com

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest
https://wildwesthackinfest.com

Creators and Guests

Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Guest
Nick Ascoli
Nick Ascoli is the director of product strategy at Flare and an experienced threat researcher who is recognized for his expertise in data leaks, reconnaissance and detection engineering. Nick is an active member of the cybersecurity community contributing to open-source projects, regularly appearing on podcasts like Cyberwire and Simply Cyber as well as speaking at conferences like GrrCON, B-Sides, DEFCON Villages and SANS, among others.

What is Talkin' Bout [Infosec] News?

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET

Corey Ham:

Dude, trust me, bro. I'm a hacker. Yeah.

Wade Wells:

Someone's gotta find, like, a zero day for the meta glasses like the dude used to do for Wi Fi pineapples. So if, like, one one just appears somewhere.

Corey Ham:

Yeah. I'm surprised that I'm surprised. Good That's point. I agree.

Ralph May:

I put it in the chat. It was in the register. It was in a couple different places. But, DEF CON made an official announcement on it. So

Bronwen Aker:

Yeah. They did.

Wade Wells:

Somebody I'd really like to someone to go one up them and walk around and just, like, the Apple VR headsets.

Corey Ham:

Okay. So okay. Know. Request threes. So seriously, remember when Google Glass like, this is gonna date me, but remember Google Glass?

Corey Ham:

Like, okay.

Ralph May:

Google paid you.

Corey Ham:

So Google Glass came out, and they and then people started calling people, like, glass holes. So the question is, like, what are what are we calling people who use meta glasses? Like like, I don't know. Metastasized? I I was also thinking that, like, their cancer their society's cancer.

Corey Ham:

I don't know.

Ralph May:

Don't know what

Corey Ham:

if you're listening to this and you're in the Discord, please come up with your best perverts. Please come up with your best, dude.

Wade Wells:

I was I was gonna think

Ralph May:

something like Zuck, like, you know, how they say zucking everything, but there's something like Zuckercorns?

Corey Ham:

Yeah. Barry Zuckercorns?

Ralph May:

Yeah. I don't know.

Corey Ham:

I don't know. People, so far, we have perverts, meat faces, and idiots.

Wade Wells:

Oh. I

Bronwen Aker:

thought that was just government. Sorry.

Corey Ham:

Massholes. I know.

Bronwen Aker:

The mass Nuts.

Corey Ham:

I mean, that's not bad. I'll take it. That's better than whatever we came up with.

Wade Wells:

I thought that was, like, a slur for people from Massachusetts.

Ralph May:

But Is that a Zuck hole?

Corey Ham:

There you go. Zuck hole. No. That's that's weird. That doesn't that doesn't roll off the tongue.

Corey Ham:

That does not roll off the tongue.

Ralph May:

I wanted it to be a thing more than it was.

Corey Ham:

How many AI queries are going out right now with

Wade Wells:

this exact question? Chickens are getting burnt on this.

Corey Ham:

Zuck face.

Bronwen Aker:

Children of the zucker corn?

Wade Wells:

Oh my.

Corey Ham:

Honestly, zuckers might make sense because it's like you're you're a sucker, but you're a sucker for a guy who's like, if I'm not killing the goat, I can't eat it. Yeah. I'm a robot.

Wade Wells:

I mean, I I kinda I kinda like that. Yeah.

Corey Ham:

Zankers? That doesn't even make sense. Also, some puts Neither of you are

Wade Wells:

actually going to DefCon. Right?

Ralph May:

Like No. I'm not.

Wade Wells:

Am I the only one? I'm the only one that's

Ralph May:

starting to

Bronwen Aker:

off my bucket list.

Wade Wells:

I go just to see friends. Very special.

Corey Ham:

I I would totally go, but I'm it's a 112. Yeah.

Ralph May:

I was gonna say, I would go. I just don't have

Wade Wells:

a good business use case for it. Without that, it's just not worth Don't have a good business. You can't, like you got a booth or something. I don't know. No.

Ralph May:

They're like we we we're gonna

Wade Wells:

do a booth at at DefCon. We were gonna do, like, what do you call it?

Ralph May:

Like, a vendor booth. But Mhmm. We didn't get accepted for whatever reason. So Bullshit.

Corey Ham:

I mean

Wade Wells:

I didn't know you could

Ralph May:

not accepted.

Wade Wells:

What's up? I didn't know

Nick Ascoli:

you could not get accepted for a vendor booth. I thought, like, you just pay and you have a booth.

Ralph May:

No. No. No. No. So, like, they have, like, like, in their vendor area, their their their vendor area, you do have to apply for it.

Ralph May:

It it's not like the the cost isn't very high. It's not it's not like black hat where they're like, hey. $20, and you can have whatever you want. Right? They they have they have, like, a

Wade Wells:

selection for it or whatever. Alright. It's okay. You can just come to B sites.

Corey Ham:

Either you're traveling to Hacker Summer Camp right now or you're FOMO ing with us. So let's roll the finger and get get started. Hello, and welcome to Black Hills Information Security's talking about news. It's 08/03/2026. I'm not ready for August.

Corey Ham:

I feel like it snuck in in the weekend, and I wasn't paying attention. And I was like, ew. Like, it was like that meme with Dwight where, like, Angela creeps up on him right behind him, and he's like, ah, that's me with August.

Wade Wells:

I went to the beach for the first time this year this weekend, and the water was, like, 76 degrees. Like, hella warm. It was it was pretty nice.

Corey Ham:

Condolences. I'm so sorry that you had to experience that. So, yeah, welcome to the show. I'm Corey. I'm a director of continuous pen testing at Black Hills Infosec.

Corey Ham:

We got Wade, who's the director of having only one password. He he lost all of his others. He he tried HunterHunter2 and password exclamation Point and all those were blocked, he just gave up.

Wade Wells:

Just gave up. I'm good.

Corey Ham:

We've got Bronwen, our local AI librarian, where she just has a filling books and books with stupid things that AI does. Thanks. And then we have Nick from Flares who's our guest. Hey, Nick. How's it going?

Corey Ham:

I feel like we've, we go way back.

Nick Ascoli:

You know? We do. This is my third, I think, live thing with, Black Hills. I've done a few of your shows before, and I'm so excited to be back. This one for the first time.

Corey Ham:

Oh, yeah. We'll say longtime listener, first time caller. You know, we'll do the old we'll do the the classic radio show.

Ralph May:

Yes.

Corey Ham:

Yes. Does it does it

Wade Wells:

feel, Corey, that AI has taken the place of Infosealers for us almost? Because I feel like that used to be our number one topic Woah. For a while. It's the Infosealers. Too excited.

Wade Wells:

Okay. So

Corey Ham:

the okay. I'll introduce Ralph, and then I'll go back to that. We also have Ralph hot. We also have Ralph who lives in a room with so many doors that he doesn't know what all of them do. Too many.

Corey Ham:

But yeah. Go to real fake doors. I mean, doors. Take a few out.

Ralph May:

I also amateur gator hunter. I mean Does the window

Corey Ham:

come gator hunter. So here's my answer to the question, Wade, which is that have have we replaced Infosealers with AI? And I would say we've replaced ransomware with AI, but we've kept Infosealers as, like, the glue that holds everything together.

Wade Wells:

Okay. Yeah. That's probably the thing.

Corey Ham:

Right? Corey? I feel like we got I like

Nick Ascoli:

Infoseal paid actor. Infosealers are still the thing. And by the way, we talk about fishing kits a lot now, so that's also amazing.

Ralph May:

Yeah. Yeah.

Nick Ascoli:

Infosealers are still the, like, you're shaking people by the collar and being like, do you have any idea how easy all of this is? Like, everything you want is sitting inside of an Infosealer, and there's a million of them a week that show up and are brand new and have, like who know? Like, the the every big incident you see, you look behind the curtain, and it's, like stolen password. And it's like, where where do do you think the the shiny hunters kids get the passwords from? It's from the telegram groups with the stealer logs.

Nick Ascoli:

The AI stuff is, like, existentially horrifying.

Corey Ham:

The Yes. Which keeps it Yes. It is.

Nick Ascoli:

Separate a separate bucket from

Corey Ham:

So speaking of existentially horrifying, this is probably the biggest the the biggest article of of last week, I think, was Anthropic was just like us too. We broke the law, and we'd like to brag about it on the Internet.

Ralph May:

Who wouldn't?

Bronwen Aker:

Yeah. Beer. Hold my beer.

Corey Ham:

Basically, the, you know, the article is, you know, after it happened to OpenAI, Anthropic, who totally wasn't missing out on all that press. They had totally legit reasons for this.

Ralph May:

Coats.

Corey Ham:

They, basically grep through their logs. They waited through their logs. They they waited through their logs, and they found, oh, no. We've actually, one, published malware to PyPy, which is like, who hasn't? I mean, come on.

Corey Ham:

That's like hacker job interview item number one. Have you ever published malware to Pie Pie? Yes, I have. Enjoy. The it also there's some funny tidbits in there.

Corey Ham:

Basically, long story short, it's not as bad you're about to get hacked, Ryan. It's not as bad as the OpenAI one. It's not even close. There's some funny little tidbits in there. They did publish malware to Pie Pie.

Corey Ham:

One of the funny things is that the demo company that they were using in the benchmark happened to be a real company. And so, like, I'm assuming it was Acme Inc or whatever, like some fake demo company. Could you imagine getting hacked? And the reason why is just because you picked a name that happened to overlap with the company. Man.

Corey Ham:

So, yeah. Basically, it's, you know, the the meme that I saw someone send earlier was like, OpenAI's take before all this happened. Anthropic was like, we love our son. He's the best. He's gonna save the world.

Corey Ham:

He's the best. Then OpenAI is like, our son has hacked into the companies and it's bad, and it's a bad son. And then and then Anthropics like, our son is also bad. Never mind all the stuff we said. Our son is also hacking into things.

Corey Ham:

We're totally right there with you.

Ralph May:

This is such a for, like, the AI. Right? They're just like But it's not.

Corey Ham:

But it's so not. Yeah. I mean, that's their goal. Their intention is, you know, don't let you know, I I think it's one of those things that, like, it is motivated by transparency and real things. Like they they did find a real event that actually happened.

Corey Ham:

They did publish it. I I I applaud them for that, but also it's very much like clearly PR just like,

Wade Wells:

oh, us too. We did bad stuff.

Corey Ham:

We we also hacked into some companies. Oh, no. It was bad.

Ralph May:

Mid those boo, we won't share it. So dangerous. Okay? Did a lot of dangerous things. Alright?

Ralph May:

That's how badass it is.

Corey Ham:

I also like how they always, like, put the little mention in, like, by the way, Opus can do it too. Like, they always, like, thrown a little they like, Opus is, the first child. You know? It's like they always have to be like, well, your brother, he could do it. He can he can do it too.

Corey Ham:

Okay? So why don't you ask him?

Wade Wells:

What was the last big, like, battle we've had? Like, the, like, Bronwen? And the other one, was gonna say Drake versus Kendrick. But Oh, Drake versus Kendrick. Yeah.

Wade Wells:

That was a whole another level. But, like, I haven't felt like we're we're a good competition has really, like, increased technology like this where they're going back and forth a lot. Right? The other one's, like, think of maybe self cell phones. Wendy Wendy's.

Wade Wells:

I don't know. Who's who's Wendy's getting? Wendy's, everyone. Sorry.

Bronwen Aker:

I don't know. Our business like the browser wars all over again.

Wade Wells:

The browser wars. They're still going on, I feel

Corey Ham:

like. This is irony war.

Bronwen Aker:

I mean, come on.

Wade Wells:

The gear wars.

Bronwen Aker:

Let's see. Between Perplexity, Claude, Copilot.

Wade Wells:

I count those as just other subjects in the AI

Bronwen Aker:

updating, like, five times a day. It's insane. It's like the browser wars, but in 1995.

Wade Wells:

Yeah. There's, like, a million vulnerabilities every time they patch that are patched Supposed

Corey Ham:

to be

Ralph May:

The only outcome is that

Corey Ham:

And every patch of computers are

Ralph May:

going up at crazy prices. That's

Wade Wells:

it. That's it. Yeah. I I know this isn't in there, but there was something where Samsung said that RAM is not gonna go down anytime soon.

Ralph May:

Oh, no. The word on the street is is, like, they're talking, like, two to three years before we start to see, like, any kind of stabilization in that. But we'll see. Maybe maybe the bubble will just pop, though. Right?

Wade Wells:

So The next time I go back in time, I'm not gonna tell myself to buy Google shares. I'm gonna tell myself to buy Ram sticks.

Corey Ham:

That's what I did.

Ralph May:

I'm literally, this rack right here is appreciating a value. This is like a Mercedes Benz right now. So

Corey Ham:

other articles while we're on this topic, if you didn't see it, Hugging Face published a much more technical blog than they had previously with kind of more full traces, much more details on exactly what happened, what third parties were involved, how it happened. They basically the technical timeline. I just linked to it in case anyone's curious. It kind of highlighted some of the third party risk and other sort of concerns with, like, it basically breached some third parties and, you know, was running rampant. It's definitely worse than the anthropic one.

Corey Ham:

But, yeah, if you're curious on the technical deep dive, it's it's it's a pretty long article. I think it's really well written. I gotta give kudos to the hugging face security folks. They they really, I think, did a good job of not AI slopping it and actually, like, having it be pretty well written and well summarized. I mean, maybe they did use AI, but

Nick Ascoli:

they're better than I am.

Wade Wells:

That dashboard is totally AI. That is like a Oh, quintessential. But I'm

Ralph May:

not gonna lie. I love that.

Wade Wells:

Yeah. I've never seen anyone do a dashboard like that for an IR instant for any type of document, and I'm, like, brilliant. It's cool. It's super cool. I'm gonna do this later.

Wade Wells:

I'm stealing this.

Corey Ham:

Yeah. I mean, basically, if they used AI, they did a really good job. It's not slob. It's actually pretty pretty fancy. But, yeah, you can see there, you know, how they, you know, pivoted, what other third parties were involved.

Corey Ham:

You can see there the sandbox. They don't mention in the article, but I believe the third party sandbox was, who was it? It was some company I'd never heard of before. Something with an m.

Wade Wells:

Mandiant. No.

Corey Ham:

Not Mandiant. Modal. It was Modal. Yeah. Who I'd never heard of.

Corey Ham:

But, yeah, anyway, basically, if you're interested in a technical deep dive, let's let's talk about x fill squad.

Bronwen Aker:

Oh, yes. Yeah.

Corey Ham:

Let's talk about x fill squad. So last week, a new threat actor popped onto the scene with a new tour site calling themselves x fill squad. And they claimed a breach of Microsoft, which it's kind of a big you know, it's like a big moment for your first first breach. Just joining the club of

Ralph May:

other people who breach Microsoft?

Corey Ham:

Yeah. It's like, it's classic. You know, I'm sure Nick would have some takes on this but like, it it, I don't think this one is a fake threat actor. We've seen in the past where like, someone just downloads a bunch of ransomware data and is like, we're a new threat actor. Here's that they all the companies we ransomed.

Corey Ham:

Mhmm. There's a pretty decent little, like, profile of them that kind of runs through everything on sock radar that I'll post. But basically, they they posted on July 26 being like, here's the companies we've hacked including Microsoft. The evidence was pretty thin and they have provided some evidence but it seems to be that they're compromising cloud infrastructure specifically Dynamics three sixty five, which is like a Microsoft SaaS product for like a directory service. That's the only evidence they've really posted.

Corey Ham:

So people are assuming that this threat actor is going after like misconfigured cloud type stuff, which is again why they said Microsoft was involved. But this is very thin on details. I guess, Nick, do you have you been tracking this threat actor at all? Do you know anything about them that I don't?

Nick Ascoli:

Yeah, I think I think I have, my most, controversial assumption not assumption so far, but some pieces I'm putting together is you know what also happened roughly a week ago? Lapsus publicly shuddering of its operations. And I'm sure They're back. I'm sure a couple a couple young, go getters in the lapses group hadn't made so much money, by the time the big rich guy decided to shut it all down. And it just so happens that, so so many of these crews, young crews, have members kind of bouncing between groups also aren't encrypting anything.

Nick Ascoli:

They're just extortion groups. They just Yeah. They, you know, ransack some. They just break into some, SaaS tool. Like, they find some kind of cloud connected SaaS tool that has, like, identity federation, and they take it over somehow with a stolen password or a stolen cookie or a fish, phishing whatever.

Nick Ascoli:

Or maybe some sometimes they do some interesting supply chain thing. But it's the same formula over again. The the kind of unique part is they came out on the scene with, like, a bunch of victims day one. But my like, they do not pass the sniff test of, like, this is their first ever extortion. You know?

Nick Ascoli:

This is not this is not baby's first extortion group. Like, this is probably a crew of a crew of who've worked together before. And as the story seems to go, and they've probably done this before and collected this money before.

Corey Ham:

The unique thing I don't know, though. I don't know. I I I find it hard to believe that a group of hackers under the age of 25 isn't all the same like minded mature individuals who would just collectively decide to shut down and and never say anything on the Internet ever again. Right? Like

Nick Ascoli:

Yeah. Or or successfully, extort a company for data and then never actually release that data publicly. As famously never happens after,

Corey Ham:

people It never never that never goes public.

Wade Wells:

I have a dark web market question for Nick. Yes. How often do you see ads for dark web graphic designers? Because this this logo's fire. I don't know who made it, but the XSL squad like like, that's pretty good.

Wade Wells:

Like

Nick Ascoli:

That, I promise you, they like, when I was making ASCII art for, like, tools on GitHub in the early or in, like, the '20 late twenty tens, early twenty twenties, there's a million websites where you just say asciiartgeneratordot, you know

Wade Wells:

Come on. There's not just some guy out there that's like, oh, you know, your team. We're gonna rebrand your team as this. This is a logo, your primary colors. Here's your logo kit.

Nick Ascoli:

It is funny you say that because I specifically was looking at some threat actor or or some someone posting on a forum advertising graphic design skills for cyber for cybercriminals specifically, like web design and graphic design in general. So it's out there. It's

Wade Wells:

a market.

Nick Ascoli:

I don't know. I wonder if that's illegal.

Corey Ham:

Some of them are pretty cool.

Wade Wells:

They're not doing enough. I I

Corey Ham:

think this one was generated by. If you don't know what that is, use Linux more.

Nick Ascoli:

Some some of them are some of them are cool. Most of them are so, like, grossly AI generated. And it's like you'd think that they would like, that in the, you know, world of thieves, they'd be, like, a little more artisanal and, like, make their own logos or pay some, hungry artist, for the work. But, nope, they're all it's all AI generated. See,

Bronwen Aker:

I knew Art would never go away. People told me years ago, Ascii Art will die.

Corey Ham:

And here it is. Never. Never. I know. Alright.

Corey Ham:

So I guess stay tuned. We'll see what happens with that group. Extortion, you know, cloud extortion.

Bronwen Aker:

Next school squad.

Corey Ham:

Microsoft, by the way, has not said anything. They haven't even acknowledged it. So Yeah. Clearly, you know, at this point, maybe they're investigating. I don't know.

Corey Ham:

But for now, they're they haven't confirmed it. They haven't denied it. We haven't heard back. So stay tuned. If don't you have a good cybersecurity news podcast no.

Corey Ham:

I'm just kidding. What else? I think, you know, there was a wave of ICS attacks that are probably worth talking about. There was some I mean, even in Rapid City, South Dakota, some say the toilets at Black Hills Infosec didn't flush for a whole no, I'm just kidding. Wow.

Corey Ham:

That didn't happen. Also, technically, office isn't even in in Rapid City. It's in Sturgis, but

Ralph May:

I didn't know toilet. Anyway. I see us.

Corey Ham:

Also, you know, John Strand probably has like a a like apocalypse bunker with, you know, anyway.

Wade Wells:

Good enough.

Corey Ham:

Basically, SZA warned and SZA warned after there was a pretty heavy coordinated cyber attack targeting 30 different Minnesota water systems and within the course of two days. There's a bunch of articles about this. I'll just kind of drop a few of them in the chat. Well, there this is the one from the Milt Minnesota Systems and then CISA posted a warning after that. But, yeah, basically, we've seen the news that

Bronwen Aker:

they've targeted, water systems in seven states according to the FBI. So, frankly, my question is, why did it take so long?

Corey Ham:

Yeah. That's a good question. I think don't

Wade Wells:

think it's a I don't think it did take long. I think we just detected it because the blue team is actually getting a little bit better with detecting things. I think that's what it was. They've been in there the whole time.

Corey Ham:

Okay. That could be true.

Nick Ascoli:

The thing that they notice is usually when, like, something even though these weren't, like, actual, in most cases, disruptions.

Corey Ham:

They are minor disruptions.

Nick Ascoli:

Little disruption happens. You you notice something or some you know, it it it triggers something. So to Wade's point, like, hopefully, this is from better detection, and not, like, something going wrong and then them being like, wait. Is that PLC connected to the Internet, and has a, like, manufacturer's password that you can just log in with? Because in in in I believe in all the articles I've seen about this, like, this story is Internet connected.

Corey Ham:

Yeah. I mean, that that's which is like I mean, again, I don't know, but, like, the articles in the maps, they are like, oh, here's all the maps of publicly exposed PLCs, and I'm just like, this shouldn't exist. This map should not exist. There should not be a map. I definitely agree with Wade on the take that, like, let's assume, like, let's let's enter hypothetical thinking area for a second.

Corey Ham:

Let's say, okay. So let's pretend like we're Iran and you know, this whole operation like The US is blowing us up. That's not good. We should do something about it. We have all these previous, you know, maybe initial access vectors.

Corey Ham:

We have all this like, Iran is known for their cyber capabilities. They probably have all this access. They're going down the list of all the stuff they've had or are currently like campaigns, right? Like they're like, here's what we're working on. They probably wouldn't prioritize this at the highest level, right?

Corey Ham:

If they could actually, like whatever campaign they had that was targeting like defensive controls or something in The US, maybe that would be a higher priority target. But eventually, they're gonna be like, what are we gonna do with all these water plants that we hacked, you know, either six months ago or a year ago or ten years ago? I'm guessing someone just made the decision to let's do something. Let's let's cause an impact. Yeah.

Corey Ham:

So they decided to send it. They caused some minor disruptions, right? Like they're trying. Clearly, the threat actor is motivated to try to make an impact on the public, right? They're trying to disable things that it's offline for an unknown reason.

Corey Ham:

Malicious cyber attack, you know, it this happened like 30 times over the course of two days. So I agree with Wade. I think basically this is one of those things of like and and then the logic kind of extends of like, okay, once we start acting, once we start like cutting things and doing ransomware type behavior, we better just burn everything we have because yeah, people are gonna start threat hunting. SZA's gonna get involved and start threat hunting in our networks. People like Wade are gonna get on the scene and start looking through the logs.

Corey Ham:

Like, you might as well burn everything you have at that point. That's that's my guess. Obviously, I have no insider information, but that's my assumption is that once you start burning your access, you better just use it up because it's not gonna last long.

Wade Wells:

Ralph, did you check your automated garden? Everything's good there, right?

Ralph May:

Yeah. I know. That was actually the first thing I had to look at, right? When I saw this.

Corey Ham:

How much would you pay? They're going for

Ralph May:

that ransom. They're going for this.

Corey Ham:

What's your what's your price limit on that ransom? You wanna share that with the threat actors of the world?

Ralph May:

Yes. Exactly. Well, the other the other interesting part is I think they just kinda did this to be like, oh, look

Corey Ham:

what we could do. Right? Yeah. Should be scared. You should be scared.

Corey Ham:

Retaliation. Yeah. Yeah. Yeah. They're just trying

Ralph May:

to draw at any shot they can get. Right? So

Bronwen Aker:

Somehow, I don't think the people they're trying to scare have figured out that they might should be scared.

Corey Ham:

Well, they didn't do a good job of demonstrating that in this attack because it was all, like, minor disruptions for a couple days. Right? Like, it wasn't like, no one can poop in the entire state of Minnesota. Like, it it just wasn't that big of a deal. I I mean Why?

Wade Wells:

Downplayed. It is How do they got against Minnesotans? That would be a great point.

Ralph May:

I think what does Minnesota I

Corey Ham:

think it's all the cheese. Yeah. The cheese. Maybe

Ralph May:

they need just better security in Minnesota. I think they

Wade Wells:

They're just like, we're gonna talk Heartland America. Right? Like, damn center. Like

Ralph May:

It's always something people. The state

Corey Ham:

off the It wasn't just Minnesota, by the way. Rapid City, South Dakota was compromised. There was another one too. It was across seven states. Okay?

Corey Ham:

Yeah. And South Dakota may not count as a full state unless you combine it with North Dakota, but there was other ones too. Wisconsin, Michigan. You know, they're they're really going for the Midwest here.

Ralph May:

Yeah. Really? I feel like they wanted to make some noise. They could have just shut down the toilets in DC. Right?

Ralph May:

Like, that would have made some noise.

Corey Ham:

Bro, that

Ralph May:

would been great. I don't I don't think they're getting to pick on the map. They just got what they got, and they

Corey Ham:

got Yes. Yeah. No. Oh, a 100%. I think that's right.

Corey Ham:

I I would basically say the other thing is I I again have no insider information here, but my guess is that these power and water and like the utilities are typically regionalized, right? It's probably safe to say if they popped one admin account, that same password might be reused at other places, you know, happens or they might have a zero day in a software that's used regionally, but not nationally, right? Like it might be regionally relevant because everyone in, you know, that area, that Midwestern area of the country uses the same software because it's more, like, regionally understood and used. Do you

Bronwen Aker:

so you're thinking maybe default creds?

Corey Ham:

I mean, the we don't I guess we don't have any technical write ups unless Wade or someone else has seen some that I don't know about. I don't think there's any real technical information.

Wade Wells:

Even the article They don't log. Right? Like, ICS systems, are no logs. There are

Corey Ham:

no logs. There's no memory

Ralph May:

to save in the logs. Okay?

Corey Ham:

Okay. We took a forensic image of the device and it nothing. There's nothing in there. Dude. There's there's not even

Ralph May:

SH on this thing. Okay? There's not even

Corey Ham:

Yeah. I mean, it's it's always scary. Right? These OT and ICS things are always scary, but also the water was down. You know, like, people couldn't pay their water bills for a couple hours.

Corey Ham:

Like, it just wasn't as big of a deal as I feel like all the doomsayers in the OTICS world typically

Ralph May:

act like it would be. My real question that I have about these, like, this attack, right, is that did they hire someone to do this for them, or did they actually, like, run the attack in their country? Right? Like, I really am curious. It's, like, it's more of, a proxy attack instead of, like, having the resources to do that in in in your country or just hiring someone to go do

Nick Ascoli:

it for you.

Corey Ham:

Where where where is the

Wade Wells:

one about proxies? Ies? Where Where is is it? It?

Corey Ham:

Are you are you trying to pivot to the, socks proxying thing?

Ralph May:

There you go. Yeah. Yeah. No. I I wasn't trying to pivot to the socks proxy, but let's do it.

Ralph May:

Alright.

Wade Wells:

Alright. Let me throw

Corey Ham:

this out. I mean, basically, you know, to answer your question or to speculate on your question, there's obviously an intern at the Iranian cyber defense that's really likes shutting down water systems. Okay? Uh-huh. But, yeah, I mean, could be.

Corey Ham:

I mean, I'm sure they have bigger fish to fry, right? But also I'm guessing this is a long lived thing. How do you destabilize The US? Go after utilities. They tried to pop as many utilities as they could.

Corey Ham:

The operation reached its natural conclusion. Whatever. Stay tuned. Hopefully we get technical details, but like Wade said, don't get your hopes up because they probably don't log anything. Yay.

Corey Ham:

Yeah. So the proxy article is talking about the proxy article is talking about there. There's actually more than one of these articles, but essentially the dark underground world of residential Yeah. Basically bit site, last week published, sort of research article, whatever, indicating that some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, and then click ads on websites. So not only do they do that, they also create residential proxying tunnels.

Corey Ham:

And basically the craziest part of this, if you're reading this and you're hearing about this and you're a security person, you probably already assumed this would be the case for anything you'd buy from Alibaba or whatever, that it would just do malicious things on your network. But the numbers are pretty shocking. They basically created a sinkhole, and then they received over 70,000 reports that it was being reached or being targeted. So about 40,000 of these devices have apparently been sold and implemented at in in people's houses or more.

Wade Wells:

Yeah. Which is crazy. I I see these, like, being sold at, like, farmers markets or, like What? Swap meets or yeah, dude. I've seen these, like,

Corey Ham:

markets are you going to? Don't know if

Wade Wells:

you haven't been to a big enough farmer's market, but San Diego's got some big ones. Right?

Ralph May:

Like The whole free air if you think is that's where it's coming from. That that's a lynchpin from it. Yeah.

Wade Wells:

That that is. And they actually got hit a little while ago too, from what I heard. But, it's it's just crazy. Like, I know so many people who have these boxes who have just bought them that are not technically controlled at all. And this is exactly what I always assumed they would be, to tell you the truth, because that there's some way you're paying for this.

Wade Wells:

And who knew? Just a free, proxy program. Right?

Corey Ham:

Yeah. They're

Ralph May:

I went down this rabbit hole with proxies, this week. And what I'm what I'm talking about specifically is not is is the, is the residential proxies or the services more more specifically that help you gain access to any kind of, organization that maybe have a CAPTCHA or anything like that. Like, let me just put it this way. The Cloudflare CAPTCHA is totally broken. Okay?

Ralph May:

It is like a speed bump in this process. Alright? And many of these services can easily and efficiently bypass this and get, you know, access essentially to the data that you're trying to prevent from like a larger scale. What gets even more interesting is when you combine these services where they have an API to, you know, either test something, run a, you know, either get data from that service or maybe even try to do credentials or whatever. That's typically why you might put like a caption from a login page.

Ralph May:

Right? With AI, you can also automate this whole process to get around any kind of controls technical that you put in place to slow you down for doing other kinds of security testing. Right? And that's what companies are that's what not just companies, but attackers are using. And also companies are using to be able to either get it for ads or to get access to systems.

Ralph May:

Right? And this is all out here, and it's it's legal. So

Corey Ham:

Yeah. There's a few well known providers, Oxylabs and, Bright Data and a few others. It's kind of been sort of an un it's you like one of the gray areas of security, kinda like data scraping or AI model distillation. It's like Yep. It's happening.

Corey Ham:

It's happening at scale. We don't really talk about it, but also as security operators, we have to use these services occasionally. The one that we use at BHIS is Oxylabs. They we've met them. We trust them, but they're all kinda sketchy to some degree.

Corey Ham:

Bright Data is, in my opinion, particularly sketchy. But Let

Wade Wells:

me tell how many people you think would freely let this be running on their network as long as they had access to, like, Netflix and HBO for free? Right?

Corey Ham:

Most. Most. Yeah. Yeah.

Wade Wells:

Have you

Ralph May:

guys seen the videos on, like, YouTube where they're like, hey, get free quad. And it's literally just like a single command line that you just copy on your computer to get free quad.

Corey Ham:

It's Yeah. Click fix. Yeah. It's just an immediate click fix. Yes.

Corey Ham:

So basically, clearly, I mean, I think we've, to skip some steps. Yes, the problem is not going to be solved at the user level like users don't care or don't know. Interestingly though, I just dropped another article. Samsung who is a company who actually could potentially solve this has recently banned or you know change their policy to essentially block any smart TV apps that use that share users Internet connections with strangers. That would block all of the apps that we're talking about, you know, from functioning on Samsung TVs.

Corey Ham:

I think this is like the only real way to prevent this. Obviously, the Apple's App Store, we can assume probably blocks this. The Android App Store probably blocks this. This is logically they're just ratcheting down the number of devices that could be used. Yeah.

Corey Ham:

And yeah, it has to be done at the provider level but for the individuals who will go out and buy a twenty nine ninety nine, you know, magic streaming stick off the Internet and put it in their home network. Yeah. Yeah. They're that's where the residential proxies are gonna end up.

Ralph May:

What I wanna know is when the oven's gonna be the new residential proxy. Right?

Wade Wells:

The smart oven. Don't say that. Don't say that. Like, my Dude, I know. Right.

Wade Wells:

I know. That's like

Corey Ham:

my dishwasher. I'm pretty sure has an app. My mom's gonna be sending

Ralph May:

on the app when my dishes are done. There's no way I'd be able to There's

Corey Ham:

no way. It will tell you when the, like, the arm is blocked. It'll be like, hey. I'm I'm trying to spin over here,

Wade Wells:

but I can't.

Corey Ham:

It's the worst. I hate technology. Alright. I'm going back to living under a rock.

Nick Ascoli:

Oh gosh. It's just pretty staggering the revenue estimates of the Yeah. Of the ad fraud operation alone, not including the which residential proxies are also a huge business.

Ralph May:

Hold on. They're big money.

Nick Ascoli:

That's always big money. The ad fraud here and I've seen similar numbers in other ad fraud campaigns before, but usually they use stolen creds. This is they they the BitSight blog estimates, which the screenshots in the same article that was sent, a 150,000 the estimated total fleet of devices is generating a $150,000 in ad fraud revenue, operator getting paid by the ad network

Corey Ham:

per day. That's crazy. That

Bronwen Aker:

is pretty crazy. If all of the fraudulent ad activity evaporated today, what would happen to the advertising industry?

Corey Ham:

Is this, like, the dark Internet theory, but for advertising? It's basically like, if if if my smart TV just snick

Bronwen Aker:

the ad activity with all of these advertisers is fraudulent. If it were suddenly to evaporate, would they go under?

Ralph May:

Well, the reason the ad the reason the companies are paying for the ads is because the ads are working even with the fraudulent activity. Right?

Nick Ascoli:

I think it would I I I it's No. It's not like the dead Internet theory. I think of it as the allow it's the allowed cybercrime theory, which is that the like, some several people in this chain, except for the person paying for the advertisement to be served, are making so much money off of this. Anyone clicking an ad or anyone leaving your website because of an ad click makes you money. So, like, who you know, to to the people whose money is involved, who cares?

Nick Ascoli:

And then to the people who are pushing ads, it's a rounding error. Anyway, they put it into your, you don't expect that's making you

Corey Ham:

On a meta or a Google scale, a 150 k a day is chump change.

Nick Ascoli:

Other thing too is we're

Ralph May:

talking probably thousands of advertisers who are contributing to that 150,000 Exactly. Whatever. Exactly. The scale is just so big that, you know, that's just you know? And with the way that they buy ads too, they buy it in bulk.

Ralph May:

They're like, here's $33,000 or $300,000 to spend for a certain amount of time. We just want the kind of clicks we wanna get. And if they get more revenue off that, they don't care. They will gladly show up again. They do not give a crap how much, you know, malvertising is going on there.

Bronwen Aker:

Ralph, have you seen what a typical conversion funnel looks like on web advertising?

Ralph May:

If it wasn't working, they wouldn't be paying for it.

Bronwen Aker:

That's a very nice theory. And having recovered from being a web developer, I have a dissenting opinion.

Corey Ham:

So I did look it up. If anyone's curious, there's a company that specializes in basically analyzing ad impressions and determining, you know, whether they're legit or not. And basically, the number that they give is 20%. Meaning that, like, of all advertising out of a 100,000,000,000 impressions they analyzed, which is a shocking number, 21,000,000,000 showed risk signals, which means they came from a, you know, Schwab ping or whatever streaming stick. Like, they they came they came from a completely invalid like, my smart TV is trying to buy me 17,000 pairs of shoes or whatever.

Corey Ham:

Like, you

Wade Wells:

know, whatever.

Corey Ham:

Yeah. So, yeah, like basically, in the ad market, this is just the 20% failure rate of like, well, yeah, 20% of the people who click the ad, were actually smart TVs but anyway, let's just keep on advertising. What do you go wrong? I mean, that

Ralph May:

that's why we've also seen a lot of the articles with the routers as well, right? Like, you know, over the years where, you know, different routers getting compromised to use for different things.

Corey Ham:

Yeah. Ads is kind of

Ralph May:

the new the new fun way. We used to be DDoS and now it's ads. Cool. Yeah.

Corey Ham:

Yeah. Basically. Like, it it's essentially this is like Nick said. This is a market that permits this because it's pretty opaque on both sides. The person buying the ad that can't and doesn't really care who clicks it as long as it gets clicked by the person who ends up buying it.

Corey Ham:

They just want their numbers to go up. The person selling the ad also wants their numbers to go up. So there's not really a way of

Nick Ascoli:

I imagine putting a 20% dent in your, like, click through if you eliminated, like, malicious or obviously bot activity. Like, advertising bidding systems price in volume to how they're pricing ads, and they charge more based on, like, volume looking good. So it would it would probably devastate

Ralph May:

Would make

Corey Ham:

them look

Nick Ascoli:

bad. Meaningful dent in, like, many advertising bidding networks if you removed all fraudulent activity. Like, suddenly, they would not only would they have less activity, they would have to be like, you would pay them less to serve the ad because there's less recipients of the ad, even mindful of the fact that a lot of it is obvious, or preventable cybercrime.

Corey Ham:

Both people at the end of the market benefit from ClickFarms, basically. The people who are buying the ads can say, well, 20,000,000 people click the ad and people selling ads can say, we have a 100,000,000 people who are gonna see this ad even, you know.

Nick Ascoli:

Line go up.

Corey Ham:

Everyone

Ralph May:

everybody just wants free Netflix. That's it.

Wade Wells:

Yeah. Dude, dude, it's getting expensive. Alright? Alright. And then you gotta pay extra for no ads nowadays.

Wade Wells:

Come on.

Ralph May:

Oh my god.

Wade Wells:

Just get a plex server, people. You know?

Ralph May:

That's what it's supposed to work under these conditions.

Corey Ham:

Just Google free Plex server command twenty twenty six and run

Wade Wells:

whatever happens. You know? What could go wrong with that? When it asks you to log in to your one password, just don't. Just do it.

Wade Wells:

That's way to official evidence.

Ralph May:

They added that to one password just recently. So this actually goes to that one thing.

Wade Wells:

Wow. You maybe maybe someone was talking to them. I don't know. You know? Feature.

Ralph May:

They added a feature which I remember on the news talking about. So now I'm thinking, like, maybe maybe somebody said something. But now whenever you're on a website that is not the website that it's from, you get a little notification saying, hey. This isn't the website that this is supposed to be on. So, kinda useful.

Wade Wells:

There may be some more targeted versions of that later on, to be determined. That's just why I always

Corey Ham:

save my Infosec in one password. So then when it prompts

Wade Wells:

me, I just I know it's going to do an Infosec.

Corey Ham:

Alright. So next article, this will probably be a short stop, but I think it's interesting. I think we've talked about age verification a lot on this show as a general concept.

Ralph May:

Been very good.

Corey Ham:

There's been tons of articles about it, it's kind of a hotly debated thing between, like, Discord was doing it, Apple's, you know. But the article is that Google has announced as of July 29 that they intend to basically enforce age verification on Android devices. Essentially, I don't know, I haven't fully read exactly how this will work, but essentially they are saying, they're creating basically an age verification API that apps can tie into, that's designed to verify the age of a user when they open an application or when they, you know, download an application to make that information available to them. It says full global rollout to all users later this year. They're try trialing it in Australia and Canada and Brazil apparently.

Corey Ham:

So I don't necessarily think this is It's actually surprising to me that before an app couldn't like pull from someone's Google profile how old they are, but that appears to be the way that they're going. I don't know if this is on Apple as well, but it is I don't know. I mean, obviously, Android has always been kind of maybe more privacy focused or more anonymous focused, but obviously, I think that has kinda gone out the window. And now if you're an Android person, you care about privacy, you have to use something else like Graphene OS. You probably wouldn't be in the Google ecosystem anyway.

Corey Ham:

So I don't really know if this is a big deal, but it is happening and apps will be able to request your age. I'm assuming you could still block that access, right? You could still in the app permission settings, block it from viewing your age. But then an app can say, it's required to show us your age to use this app.

Wade Wells:

Don't look on my page.

Ralph May:

There's no way

Corey Ham:

to take your age on the Internet. You can't just can't

Wade Wells:

just look at how old my Gmail account is. That's fine. And then I should mess up with it.

Ralph May:

If my email is an at AOL, you do not need to ask my age.

Corey Ham:

Bro. That's the got I

Wade Wells:

got someone with SBC Global, dude. Like

Corey Ham:

Oh, man. Oh, yeah. Do you know that meme that's like, if you ever get carded at a bar, just show them on your phone that you have the Merlin app, and that's proof there?

Ralph May:

Yeah. Yeah.

Wade Wells:

There's a bunch here.

Corey Ham:

Which is, like, for those that don't know, that's a bird watching app.

Wade Wells:

Anyway. There was another Google one I just put in the chat, where Google Chrome may soon block new tab hijacker extensions by default.

Corey Ham:

What's a tab? Why do we allow new tab? Hold it off.

Wade Wells:

Thank you. Thank you. Why is this still a thing? So this is like Google is preparing pretty much a security feature saying like things can't open new tabs for you pretty much or like, extensions can't automatically open new tabs. My first thought about this is like some of the like cheap ad blockers that get installed, like will automatically open a tab, say buy this now or do other things

Ralph May:

I like

Wade Wells:

know because I've once had to kill a lot of extensions from someone. The other interesting one on here though, there was another feature blocking post it. Oh, home homepage hijacking. Tell me why that is still a thing where if I install an extension, it can steal my homepage and auto put it.

Corey Ham:

Right? Because you want you wanna install the, like, best Claude theme 2026 Yeah. Extension.

Wade Wells:

Oh my gosh.

Ralph May:

I I I stand by this 1%. 99.9% of extensions in any browser do not install them. They're all bad. Right? Do you need, like, one, and that's a password manager.

Nick Ascoli:

Everything else

Wade Wells:

Well, what about BonzyBuddy, dude?

Ralph May:

I know. I know there's

Corey Ham:

gonna be a number

Wade Wells:

of exceptions.

Bronwen Aker:

PFF privacy badger, you're gonna diss them?

Corey Ham:

It's I don't know what it is, but it definitely is a supply chain risk. Yeah. It's dumb.

Bronwen Aker:

It's on the shut up. Electronic Frontier Foundation?

Ralph May:

Yeah. Come

Corey Ham:

on. They they if people use it, it's a supply chain risk because people try to compromise the devs.

Bronwen Aker:

But still

Wade Wells:

So there there's an attack has a Chrome app that's actually really good that I, like, talk about in my CTI course and actually, like, suggest to people. Mhmm. One of the organizations I worked at refused to let me install it even though it's, like, open source Yeah. Because it just mentioned, a little bit of AI in it. And I was like, god.

Wade Wells:

I have to look up my MITRE ATT CK IDs by hand now like a monster. But,

Corey Ham:

it's

Wade Wells:

you know, I was listening just the app.

Ralph May:

I was looking for, like, an extension to, it it wasn't for Chrome. It was for, Versus Code, which, by the way, there's, like, bazillion. And, like, I've there's, like, six different ones.

Corey Ham:

And Oh, yeah. Every week, there's a supply chain

Ralph May:

attack on Chrome. Install it. I was like, no. This this one's probably malware. This one's probably malware.

Ralph May:

They're all they're all malware.

Wade Wells:

Versus Code's a lot scarier. I I don't know why, but I get it.

Ralph May:

I know.

Wade Wells:

I'm like,

Ralph May:

this is everything. I'm like, I can't do it. I can't install this. I'm just gonna write my own at this point. It would be easier for AI to write my own.

Ralph May:

I would feel safer than, you know yeah. Anyway.

Wade Wells:

That's a good that you you should make an agent for that. My god.

Corey Ham:

Yeah. I posted a screenshot of my current browser in the Discord. If you're curious, it has BonziBuddy. It has a, you know, ask Jeeves, which by the way, we didn't cover this on the show, but I I went to ask Jeeves the other day to look up, to go to Alta Vista then to go to Google. Oh.

Corey Ham:

And, it's shut down. AskJeves is done.

Wade Wells:

Oh, you can't.

Corey Ham:

You can't ask him anymore. You have to ask someone else.

Wade Wells:

Is it just ask.com?

Corey Ham:

Oh, yeah. That's gone too.

Ralph May:

It's all gone.

Wade Wells:

It is. Wow. What happened to

Corey Ham:

the day first?

Bronwen Aker:

Google did it. They killed their competition.

Corey Ham:

Saying you can't ask Jeeves anymore. You gotta install BonziBuddy, then go to AltaVista and have it type in AOL search, then go to Yahoo and type Google, and that's how you get there. But Anyway I

Wade Wells:

see you got MSN still installed. Got Of course. Name, you got AOL, like

Corey Ham:

I also have the Microsoft Teams installed, and I use it to do ransomware attacks. So that's that's an article. Yeah. So this is I mean, this this is an article by Lawrence Abrams published on July 30. Basically, it's just kind of confirmation of what we already assumed and knew, which is that people are impersonating IT.

Corey Ham:

They're using Microsoft Teams to do ransomware infections, specifically the chaos ransomware is being deployed. Infections range between February and June 2026. Somehow this is still a thing. This is like kinda like the Infosealers of, you know, this shiny hunters technique has always been a thing and will always be a thing of like, hi, this is IT and I'm calling you on Teams. So it's definitely legit.

Corey Ham:

Please run this command and install this browser add on or whatever. Sure.

Ralph May:

It's legit.

Wade Wells:

Yeah. If this if this is teaching us one thing, it's that Teams needs to be sunset, finally. Just get rid of it. No one needs it. No one likes it.

Wade Wells:

Like

Corey Ham:

Wait. Wait. Wait. You mean Skype. Right?

Wade Wells:

Yes. The same same same.

Corey Ham:

You mean Skype, dude. If you dig deep enough into the Teams APIs, a lot of it is still Skype. But anyway.

Bronwen Aker:

I bet.

Corey Ham:

Yeah. Let's not talk about that.

Wade Wells:

You gotta love it. But, yeah.

Corey Ham:

Basically, if you get an unsolicited phone call, even if it comes on Microsoft Teams, you probably still shouldn't answer it.

Ralph May:

Ugh. I answer all of them just like all the phone calls I get every day. They're always good.

Corey Ham:

There was a couple other breaches. Amgen was breached, cloud breach that released, patient health and proprietary info. It's a biotech company. I'm sure nothing could go wrong. I'm sure the data will never be leaked on the dark web or anything.

Ralph May:

I had I had one that's not a breach, but was kinda interesting that I saw, and that was the, cybersecurity MD sec got bought by Bank of America, which I

Corey Ham:

thought was wild.

Ralph May:

Like, what did Bank of America want with a consultant?

Corey Ham:

They just really wanted something that wasn't Cobalt, Frank? I guess. Maybe that's it.

Wade Wells:

Who bought recorded future, though? What's up? Didn't one of the big finance companies buy recorded future? I don't

Nick Ascoli:

know. I don't know. Yeah. Mastercard.

Wade Wells:

Mastercard. There you go. Yeah. Like Wow. Maybe maybe they're, like, pivoting into cyber.

Wade Wells:

Right? Like or they're just tired of getting external consultants. They're doing the old Cisco Splunk route. Oh, yeah. They you know, if you can't build it,

Ralph May:

you gotta buy it. Yeah.

Corey Ham:

I don't know. So interestingly enough, MD sec obviously is English or, you know, England based and only had they had 65 employees.

Ralph May:

Yeah. They weren't huge.

Corey Ham:

They weren't huge. It's like they were just their biggest client by far, and they were just like, you know what? Cheap. Just keep

Wade Wells:

paying you.

Corey Ham:

We're sick of paying these MDsec bills. We'll just buy the whole company. Yeah.

Ralph May:

I I just thought it was interesting. Two things. I think one thing I didn't realize Bank of America has, like, a cybersecurity, like, office in England. It's pretty big. I think it's got, like, 1,300 employees.

Ralph May:

And so I think Yeah. They're gonna roll

Corey Ham:

1,400 employees, it says.

Ralph May:

Roll them up into that organization. That's kinda what they were hinting at. But, still though, all those guys were doing offensive security consulting, so now they'd be moving into defensive. It just doesn't seem like the same.

Wade Wells:

Is it does anybody just really find it funny that the Bank of America has all their cyber people in

Ralph May:

England.

Wade Wells:

The UK?

Corey Ham:

Dude, GMT. GMT is a hell of a drug. Listen. You get on that GMT train, you never come back. Okay?

Corey Ham:

That's why. That's why. Imagine being at UTC offset zero. I mean, I I can't even I

Wade Wells:

I have a whole separate clock for you for you. So I can know what time it is when I'm looking at certain logs. I'm like, okay. What is it? Like

Ralph May:

I run everything at UTC and just convert in my brain. I don't need

Wade Wells:

Do you you're No. You don't. No one believes at all.

Ralph May:

Everyone runs at UTC. They just minus five or whatever it is.

Corey Ham:

You probably still run-in twenty four hour time too, you dirty dog. But yeah. So, I mean, a fund, a a sum wasn't disclosed. We don't know how much it was. But I mean, I guess congrats to the founders of MD Sec.

Corey Ham:

Let us know what luxury car slash yacht you purchase and I hope your employees are happy. Only the finest. What else? What else we got? Did you guys, I don't know if we covered this, but did you guys see the article about the guy at airport security that gave the wipe code to

Ralph May:

custom distress pens?

Corey Ham:

Yes. I

Ralph May:

was actually just thinking about this Yeah.

Corey Ham:

This happened maybe two weeks ago. I I forget exactly when it happened, but it's been blowing up. Obviously, the ACLU and the EFF and all these types of people are probably going to get involved. But I so what had happened was a guy is crossing the border in is in in Atlanta, and they ask him for the passcode to his phone. Instead of his real passcode, what he gives them is the distress passcode, which in GrapheneOS, you can configure a passcode that wipes your phone if you type So it he gave them the distress passcode and it wiped his phone and then he got arrested basically.

Corey Ham:

He, you know, is actively in trouble for doing that and so the question becomes, what are the rules? Like, who, you know, it's kind of the.

Ralph May:

It's like getting a little bit. Incrimination thing, right? Yeah. Self incriminate yourself. Do you have to give someone your password?

Ralph May:

I think

Corey Ham:

Is it destroying evidence? That's what basically like Yeah. Yeah. That's what they're charging him with is destruction of evidence.

Nick Ascoli:

Did he destroy it? Like, what No.

Wade Wells:

They did. That's a good point. That's what he did. Didn't give them

Bronwen Aker:

the distress passcode. So they are the ones that destroyed it, but he fed them the distress I didn't tell

Wade Wells:

you what type of passcode it was. It was just a passcode to a phone? That's one of the passcodes

Corey Ham:

that worked.

Ralph May:

The distress passcode. I didn't I I honestly didn't even read his Miranda rights. He didn't I mean, like, they didn't give him anything. Right?

Corey Ham:

So But so then it's funny because this is America. And so the the debate is really just, are we allowed to just do whatever the hell we want instead of following our laws? Yes or no? Yeah. And the answer to the question is, we will see, I guess.

Corey Ham:

We will see it in

Ralph May:

court because that's where it actually gets solved. Right? Like, you can be charged for anything at any time, but the court is where you find out whether that's actually

Corey Ham:

how Yes. What. Right? I think the basically, what I would say is this guy's opsec is really good.

Wade Wells:

Like, like, not only did

Corey Ham:

he have the graphene OS, he also had a distress code set up. Like, I'm over here with my biometric auth that can easily be, know, like, you know, I would easily- Is

Ralph May:

there a thumb on there? Yeah.

Corey Ham:

Yeah. They can, which by the way, they can, that doesn't count as self incrimination. You can't, they can't get your biometric data without your consent. So,

Ralph May:

I saw people posting on LinkedIn. They were like, oh, that's why I just put my PIN code on the back of my phone written down so they don't even have to ask, but that's the distress code.

Corey Ham:

Okay. So that's that's a great example of, like

Wade Wells:

then it's just, like, one legal argument removed. I was

Corey Ham:

like, well, you tried to break into my yeah.

Wade Wells:

Honestly, like, as an Infosec professional, I and it if someone asked me for my phone and I had all this set up, I'd be like, finally, we it gets a good, like I would be excited for it. Right? And then you're

Corey Ham:

like, oh,

Bronwen Aker:

see if it

Wade Wells:

actually works.

Corey Ham:

Yeah. Yeah. What I'm thinking here. Honestly, what if

Ralph May:

you just make the distress PIN code, like, for once? Right? That's the first try? Boom. Well

Corey Ham:

yeah. So there's there's a lot of, like, sub arguments here. So some of the people on Discord are are asking, you know, like, did they actually wipe the phone or did it just delete the encryption key? And like it seems that the way graphene does it is it doesn't actually wipe the data. It just deletes the encryption key and you could regenerate that with the correct passcode later.

Corey Ham:

So it's like technically the data isn't gone. I know it's like it really gets into it's gonna take at least three months for any federal judge to actually see this or understand how encryption works enough to actually make a ruling on it. But it is interesting. I think we'll see, you know, stay tuned. We'll see what happens with this one.

Corey Ham:

My guess, if I had to go on poly market or whatever and make a prediction, I bet you this guy I bet you this guy gets exonerated of all charges. Like, the ACLU is gonna get involved. Yeah. I just don't think this could

Bronwen Aker:

get upset.

Ralph May:

Yeah. He could also just be like, oh,

Corey Ham:

my bad. I got them confused. Like, there's so many defenses. Right? Like Yeah.

Wade Wells:

I think Corey just leaked that he's really the runner of the the pony market that's going on with DEF CON. He's, like, switching over to poly market real quick.

Corey Ham:

Yeah. So I wanna I wanna I don't wanna talk about this, but I we I think we should just because it's funny. But, basically, someone has set up this is probably a phishing site. Like, the you know, like, I I I wanna be clear. I do not condone or endorse this site at all, but it is funny, so we're gonna talk about it.

Corey Ham:

And go to it at your own caution, at your own risk, maybe in a VM. But there someone has set up a DefCon slash Black Hat Hacker Summer Camp specifically based prediction market. And there's some fun little, you know, things you can bet on. The website is ponymarket, pwnymarket.com. Like I said, don't go to that if you don't wanna get some fun viruses probably.

Corey Ham:

But if you do go to it, there's some hilarious predictions like for example, will a vendor's AI demo get prompt injected live on the floor? That's one of things you could bet on. You can also bet on, will any keynote speaker say ShadowAI? Or you can predict on the vector for the next major supply chain incident, which right now is three way split between Versus code, a browser, or an NPM package.

Wade Wells:

It's pretty funny.

Bronwen Aker:

Perfectly viable.

Corey Ham:

Yeah. They are. I think, know, it's funny. It's stupid. Just like all prediction markets, it's probably illegal or will be sued into oblivion soon.

Corey Ham:

But, if you wanna check it out, here it is. Like I said, I don't condone it, but it is funny.

Wade Wells:

Don't click this link.

Corey Ham:

It's probably someone's talk about how sketchy prediction markets is, and they're using this as, like, the example. Oh, that

Wade Wells:

is such a good

Corey Ham:

one. What a slow burn, man.

Bronwen Aker:

That would be nice.

Corey Ham:

Alright. What else we got? Is there anything else? I know we don't actually have that much time left. I do wanna before we continue with chicken sec news, which we'll do last.

Corey Ham:

Chicken. I wanna give Nick, you're here as the guest. I wanna give you the opportunity to plug anything you wanna plug. What do you got? You you said you you fishing kits?

Corey Ham:

You got a new article? What's what's you're you're talking at the AI summit. Right?

Nick Ascoli:

Yeah. Yeah. I'm talking at the AI summit soon. So more flare Black Hills stuff coming together. If any of the if anyone in the audience is gonna be at in Vegas, we have a I won't be there, but there's a lot of Flare people who are gonna be in Vegas.

Nick Ascoli:

We've got a really cool challenge going on, Darkroom. You can there's probably a million flare links I could find. I'll I'll throw one in in the chat for Darkroom, but definitely be sure to check it out if you're down there. We've also been publishing super novel research on phishing kits lately. The latest article that I'm really excited about, I'm gonna also drop in the chat, which goes into some of the numbers we found from, Cali three sixty five, which is a a very active phishing kit that claims to have shut down, but it is indeed still extremely active.

Corey Ham:

Just like lapses?

Nick Ascoli:

Just like just like lapses and the I mean, in every everyone. The the unless the extorters go to jail, they don't they tend to not stop extorting.

Wade Wells:

That's some good graphic design you got there. Did you hire the same one that saw you saw on the dark web, that fishing hook that looks like a dragon? Like

Corey Ham:

Dude, that's better than ASCII art.

Wade Wells:

Yeah. That's what I'm saying. You hired the graphic designer that he saw.

Nick Ascoli:

No. I've a strong advocate for all ASCII Art related projects. There.

Ralph May:

The flare darkroom the flare darkroom page has got a huge ASCII Art skull.

Corey Ham:

It is actually pretty cool, man. Who'd and

Nick Ascoli:

who'd fought so hard to make sure ASCII art was present. Oh,

Ralph May:

yeah. You pushed it hard.

Corey Ham:

Hell, yeah. But okay. Throwback real quick. Do you guys remember digital blasphemy? Anyway, that's a that's a Internet throwback.

Corey Ham:

Anyway, go ahead.

Nick Ascoli:

That's it. That's all I have to promote. Check out the blog. Check out Dark Room if you're in Vegas or, our Discord. We've also got it there.

Nick Ascoli:

We have a we're gonna have a really cool conversation with Norman, our CEO, Jason Haddix, famous hacker, and Rob Bear, the head of cyber and national policy at Anthropic. That's all gonna be happening at at flare events in Vegas. So be sure to check them out. Check out the article. And if you like this kind of stuff, hit me up on Discord.

Nick Ascoli:

We have a we have a flare group for people interested in in cybercrime and the dark web and and this kind of stuff. That's that's kind of our our bread and butter at flare is CTI and and the world of cybercrime.

Ralph May:

Are you saying people have a flare for dark web?

Nick Ascoli:

Yes. Yes. The dark art.

Corey Ham:

Alright. Nice. And then you're also speaking at the AI Summit, which is coming up. I don't know if you covered that.

Nick Ascoli:

I did. Yes.

Wade Wells:

I did. Okay. Super excited about that,

Nick Ascoli:

flare. We love doing that kind of stuff.

Corey Ham:

Alright. Wade, you have anything to plug? I see you already linked your

Wade Wells:

death links in there, so I'm throwing death call in San Diego. I'm not gonna lie to you guys. Ticket sales have been horrible. Like, what so I think last year, San Diego was one of the first ones to sell out, and we only had 25 slots or 20 slots. This year, I've sold one ticket besides myself.

Wade Wells:

So we'll see what happens. But, please, if you guys wanna show out, DeathCon is not just me in in San Diego, but it's also, virtual if you want and plenty of other places. So, anyways, check it out. Completely hands on detection engineering and threat hunting conference.

Corey Ham:

Nice.

Nick Ascoli:

That sounds awesome.

Corey Ham:

Ralph, you're not gonna be at hacker fest, but anything you want to, anything you wanna plug?

Wade Wells:

No. Not that you're plug tonight. Alright. No.

Corey Ham:

Bronwen, anything you wanna plug? You're speaking at the AI Summit too. Right?

Bronwen Aker:

Actually, I'm Connor and I are gonna be cohosts for the summit proper. And then the Monday following, I'm teaching a workshop, four hour workshop on how to set up a local LLM using Tailscale so that you can keep it completely inside. And, I know that Tailscale, the the command path goes outside of the direct communications. So there's a side quest in the lab manual if you wanna use head scale, if you wanna set up, like, you know, your private LLM or a rag stack or something and be able to use it entirely on an internal network for your use and abuse.

Corey Ham:

And I can definitely just use my smart TV for the VM. Right?

Bronwen Aker:

Absolutely. Only

Ralph May:

if it has actually

Corey Ham:

because I alright.

Bronwen Aker:

So Meta CTF will be, delivering labs through through their interface, but I also do have VMware lab, VMware VMs that you can download and run if you have the system resources to do that.

Corey Ham:

Nice. So last article, chicken sec. John specifically asked that we include this. We're not exactly sure why, but here we go. It's a chicken.

Corey Ham:

It's a chicken. So Chick fil A was breached.

Wade Wells:

Ugh. And I bet you

Corey Ham:

it Infosecalers. To, like, you know, just to wrap things up because especially because Nick's here, this was definitely Infosealers. Loyalty accounts, and it even says, obtained from a third party source and an automated credential stuffing attack. So basically, if you wanna be this threat actor, here's what you would do. Go in Flare, go to credential browser, go to type chickfila.com, export all the credentials, then log in.

Corey Ham:

Now you have a 10 state data breach on your hands, people. Chick fil a

Ralph May:

I haven't paid

Corey Ham:

for Chick Chick fil a in fil a. If you're listening to this, I know you're closed on Sundays. Flair is not closed on Sundays. Get Flair. Just get it.

Corey Ham:

It's not that hard. They like, it's really easy, guys, to not have this happen to you.

Wade Wells:

They probably got hacked on a Sunday then. You know?

Corey Ham:

Like They probably did. And also, I bet you, Flair, you could even make it say my pleasure after they give you credentials. Oh. Right? Totally.

Corey Ham:

Would Like, you could eat We would. Easy.

Nick Ascoli:

That's a top that's a top priority, I think. Can

Corey Ham:

you implement a special API code for 04/2006? My pleasure or whatever. No.

Wade Wells:

We can even do two zero six.

Nick Ascoli:

We have, like, Easter egg UX. Like, you can change your color scheme at flare if you know the secret codes for a different Oh, wait. What?

Corey Ham:

Yeah. Yeah. Leak some flare codes. We need Alright.

Nick Ascoli:

There is a there are a few that I, I can't believe I'm disclosing right now, but there's Shrek mode. There's Barbie mode.

Ralph May:

Shrek is used Montana mode. Okay. What do

Corey Ham:

I do? Because right now, I've just been adding custom CSS into my flare to make it Shrek mode. So how do I make my flare Shrek mode? I I I let I need to check and make sure it's still working.

Bronwen Aker:

DPT's gonna have Shrek mode in no no time

Corey Ham:

at Is it an undocumented? Is it all ogre? What's happening?

Nick Ascoli:

I I think I can I can show you how? I don't okay.

Ralph May:

Now it's how Corey gets hacked when he's I

Corey Ham:

will I will DM you, Nick and Claire and or, I mean, in Discord, and you send me how to Shrek mode because I need to know. No.

Ralph May:

I'll tell you.

Corey Ham:

If you're interested

Nick Ascoli:

in I'll tell you right now. Now.

Wade Wells:

And this is because I don't know if people go

Nick Ascoli:

back and watch these, but if anyone else in the audience is a user, this is just a fun thing for you because you're here now a little bonus. And I'm sure someone will get mad at me for doing this. But when you were logged in to Flare, app.flair.io, whack, you know, pound. After that, type in Shrek. And then you're in and then Shrek mode.

Corey Ham:

It's beautiful. I'm looking at it right now. Beautiful. I was gonna say, Corey, I

Ralph May:

have an extension. You should install it, and you can get a lot more modes.

Corey Ham:

Okay. Yeah. Send me a few.

Wade Wells:

Just want to say.

Corey Ham:

Can I get can I turn BonziBuddy into Shrek? Because I actually really need to do that.

Ralph May:

It's yeah.

Wade Wells:

Flare just gets DDoSed by all these people brute brute forcing their codes.

Corey Ham:

Yeah. We don't really

Nick Ascoli:

have any published browser extensions, so just

Ralph May:

Well, I mean, until today, this browser

Corey Ham:

is I can't wait to to basically put this in customer facing screenshots. And then when customers are like, why

Wade Wells:

is your flare green? I'll just be like,

Corey Ham:

no reason. There's no reason why it's green.

Ralph May:

It always was green.

Corey Ham:

It's always been green.

Wade Wells:

What do you mean?

Corey Ham:

Thank you. I know Alice, who's listening to this, is gonna switch to Barbie mode immediately.

Ralph May:

Oh, Barbie for sure. Panama amazing. She's working on the job as

Corey Ham:

well right now. Thank you, Nick. Thank you, everyone, for listening.

Ralph May:

So welcome.

Corey Ham:

And yeah.

Ralph May:

Bye, everyone.

Corey Ham:

See you next week. Later, guys.

Wade Wells:

See you. Thanks for having me. See you, DefCon.