Talkin' Bout [Infosec] News

This week, the team discusses the White House's Initiative Gold Eagle and its implications for cybersecurity information sharing, an unexpectedly positive development involving Flock Safety, and the latest wave of AI news. The conversation also explores evolving AI model capabilities, security guardrails, open-weight Chinese models, and how AI is changing offensive and defensive security. Along the way, the hosts examine recent vulnerability research, industry reactions, and other cybersecurity headlines from the week.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters
  • (00:00) - PreShow Banter™ — The Two Jokes
  • (01:58) - Initiative Gold Eagle - 2026-07-20
  • (12:24) - Story #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination
  • (18:58) - Story #2 - Microsoft Reins in RoguePlanet Zero-Day Threat
  • (21:48) - Story #3 - Now, defenders are embracing the prompt injection, too
  • (27:45) - Story #4 - Security incident disclosure — July 2026
  • (33:38) - Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shift
  • (44:25) - Story #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy
  • (47:24) - Story #7 - Inside Pegasus: The evolution of the world’s most notorious spyware system
  • (48:38) - Story #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE
  • (51:49) - Story #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
  • (53:20) - Story #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFC
  • (58:10) - Paul’s Workshop
  • (01:00:29) - Sign up for the AI Summit to see Matt’s talk
  • (01:02:45) - Bronwen’s Workshop
  • (01:07:10) - Wild West Hackin’ Fest
  • (01:07:25) - DeathCon
  • (01:09:08) - PostShow Banter - Retirement Funds

Links

Story #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination
Story #2 - Microsoft Reins in RoguePlanet Zero-Day Threat
Story #3 - Now, defenders are embracing the prompt injection, too
Story #4 - [Huggingface] Security incident disclosure — July 2026
Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shift
Story #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy
Story #7 - Inside Pegasus: The evolution of the world’s most notorious spyware system
Story #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE
Story #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
Story #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFC
Paul’s Workshop
Sign up for the AI Summit to see Matt’s talk
Bronwen’s Workshop
Wild West Hackin’ Fest
DeathCon


Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 
https://poweredbybhis.com

Brought to you by:
Black Hills Information Security 
https://www.blackhillsinfosec.com

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest
https://wildwesthackinfest.com

Creators and Guests

Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Guest
Matt Franz
Matt Franz is the AI Security Lead at Bespin Global, where he builds products at the intersection of Cloud, SecOps, and AI. With over 25 years of experience in early-stage startups and mature enterprises, Matt blends the strategic perspective of an executive with the hands-on expertise of a builder. His background includes founding the Helix Cloud Operations team at Mandiant/FireEye, serving as VP of Production Engineering at Cofense, and directing global security operations at Ping Identity. A former U.S. Army Intelligence Analyst, Matt currently focuses on large-scale data platforms, security analytics, infrastructure automation, and applying generative AI to offensive and defensive use cases. He builds daily in Python and Golang, with a focus on agentic blue team capabilities.
MB
Producer
Meagan Bentley
Guest
Paul Clark
With nearly a decade of experience as a business owner and software‑defined radio (SDR) consultant and trainer, Paul helps clients and students leverage the power and potential of SDR technology. His company, Factoria Labs, provides consulting services as well as training, particularly in the realm of wireless communications, RF reverse engineering, and GNU Radio. Before founding Factoria Labs, he worked as a software development consultant for Meadow Registry, where he developed and marketed C++ tools for SDR‑based forensics. He has co‑authored three books in a series on getting started with SDR and GNU Radio, sharing his knowledge and passion for the topic. He also has a strong background in product management, embedded software, and mixed‑signal integrated circuit design, having led a cross‑functional team of 20 at Cypress Semiconductor to deliver innovative software solutions for PSoC® microcontrollers. He holds a Master of Science in Electrical and Electronics Engineering from the University of Washington and two patents in the fields of SDR and biometrics.

What is Talkin' Bout [Infosec] News?

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET

John Strand:

Of what he buys in Mexico. He probably buys his drugs down there cheaper.

Corey Ham:

He's getting dental work. We're talking about

John Strand:

dental work. And he comes across the border, he's such an asshole to US border border patrols. And, like, there's just tons of times where the border patrol people are just like

Corey Ham:

Buddy, don't make Okay. Go ahead. Neither of us are getting paid enough.

Ralph May:

None of us

Corey Ham:

are same. Okay. So wait. Off topic, has anyone has anyone gotten infected with whatever this Taco Bell lettuce virus is? Yeah.

Corey Ham:

We have one that did.

Bronwen Aker:

No. But I don't eat Taco Bell. Honestly I understand.

Ralph May:

If you if you had asked me, like, what restaurant in America do you think was causing, you know, explosive diarrhea, I was gonna guess Taco Bell every time.

Corey Ham:

Okay. But okay. So here here's here's the thing. Okay. Here's the thing.

Corey Ham:

I actually think I mean, there's there's two jokes. Okay? Number one is the joke, which is how would anyone know? Like, oh, this explosive diarrhea is different than the normal explosive diarrhea.

John Strand:

Yeah. This

Corey Ham:

is actually explosive. How can you tell? Right? But the other joke, I I will say, I gotta give them credit because they're doing better than the FDA at giving us early warnings of what's actually happening. Like, Taco Bell, like, I trust them.

Ralph May:

You know what

Corey Ham:

I mean? Like, you trust them. Because okay. If Taco Bell says it's bad, that's your canary in the gold mine. Right?

Corey Ham:

Like, the it's one thing for the FDA to be like, oh, you know, we're not gonna say anything. It's not that bad. But Taco Bell's shutting down. It's bad. I mean, it's like the Waffle House Index.

Corey Ham:

Right? Yeah. Like, the the weather's bad if Waffle House is closed. Otherwise, it's fine. Oh, Alright.

John Strand:

Corey, you're driving today. I've got to get off early. I've instructor presentation thingamajiggy for the people out in DC.

Corey Ham:

Alrighty. Let's do this. We can go live if you want.

Bronwen Aker:

Finger time.

Corey Ham:

Hello. And welcome to Black Hills Information Security's talking about news. It's 07/20/2026. We've got AI articles. We've got Gold Eagles, which is not a new coin, turns out.

Corey Ham:

It's something else. We've got AI. Like I said, I'm gonna say AI at least five times before we get started just so we can get that SEO going.

Ralph May:

Beetlejuice.

Corey Ham:

And we have not to spoil things, but there's uplifting news about flock, which you would not expect to hear. Because all the previous news about flock has been extremely depressing.

Ralph May:

Are they all going down? Are they

Corey Ham:

And and well, you'll you'll have to listen to find out. And we have chicken articles. So I mean, get ready.

Paul Clark:

We're just all rounded.

Corey Ham:

Nice. Yeah. So quick introductions. My name is Corey Ham. I'm the director of continuous pen testing.

Corey Ham:

I'm always continuous, and I'm always pen testing at Black Hills Information Security.

John Strand:

Because you can't

Corey Ham:

You got

Corey Ham:

Ralph, won't stop. Executive gator hunter at Ralph Inc. At v VTEM Labs. Is that still is that still where you're hanging out, Ralph?

Ralph May:

Yeah. We yeah. We're we're we're a business. We have customers. It's real.

Corey Ham:

That that's weird. You that that's how I feel about how I get it.

John Strand:

Gins, Ralph. That's how all

Corey Ham:

Yeah. That's that's how I feel with continuous pentesting. I'm like, are we really doing this? Is this real?

John Strand:

This is real. So

Corey Ham:

we've also got Bronwen, the AI thought leader you have. Always supporting you.

Bronwen Aker:

The reluctant AI thought leader.

Corey Ham:

With the best funny jokes about why everything is stupid.

Ralph May:

Now, why it's also LinkedIn. Just AI thought leader or just anything. Right? Because it's be like, yeah, thought leader.

Corey Ham:

It's like, Bronwen would never identify herself in that way, which is why she's a good AI thought leader. Right? Like, it's like, the people who say they're AI thought leaders are dangerous and not to be trusted. It's the people who would never ever use that label on themselves that you really should trust.

John Strand:

Yes.

Bronwen Aker:

Well, it's even worse, Corey. Now they're starting to call me a strategist. An AI strategist.

Corey Ham:

What's that even

Wade Wells:

mean? That's way better than the thought leader. Just take it.

Corey Ham:

You can yeah. Just take it. Strategist is cool.

John Strand:

Sounds think I set I set my role to managing intern at Black Hills Infosec?

Corey Ham:

It's Yeah.

John Strand:

So I can get less spam. Cool.

Corey Ham:

We also have Matthew Franz. Matthew, you wanna introduce yourself?

Matt Franz:

Sure. Yeah. Yeah. I've been in the I'm a old guy from the nineties.

Corey Ham:

Hell yeah.

Matt Franz:

I'm I'm gonna be talking about my MCP server talk. I'm really sad. They wouldn't let me call it, are you down with MCP? But

John Strand:

Why wouldn't we allow that? I hereby I hereby bust the name of Matthew's talk to rename it to be down with MCP. Yeah. You know me.

Wade Wells:

Yes, sir. I know me. Oh, yeah. I've fallen down

Matt Franz:

the MCP rabbit hole writing rust to UIs, Go to UIs, MCP servers for all of this. So that's why

Corey Ham:

I'm So you're saying you're old school, but well, you're saying you're old school, but that's a that's a new trick for an old dog. I mean, that's No. No. No.

Matt Franz:

The new the new kids are, like, anti anti MCP. MC they all okay. AI influencers are like, no. You just need to have your Wait. Wait.

Corey Ham:

I thought you meant new kids

Ralph May:

on the block.

John Strand:

You said you said MCP and Rust in the same sentence, and

Bronwen Aker:

that makes you old?

Corey Ham:

Yeah. That that yeah. I mean farm organic right there. I was I was at collegiate pen testing competition a few years ago, and, like, there was this one kid who, like, no matter what the topic was, he found a way to work in like Rust and a way to rewrite it in Rust. And I was like, honestly, it's kind of impressive.

Corey Ham:

Like, I don't know if you're doing a bit, but I'm like, we're not even talking about writing software. We're talking about like where we're gonna eat for dinner, and you're like, talking about somehow bringing up Rust and how you're gonna rewrite something in Rust. I'm like, alright.

Matt Franz:

Anyway

Paul Clark:

You weren't talking about writing software.

Corey Ham:

Yeah. Yeah. He was. We've also got Paul Clark, who's been on the show before. Paul, you wanna give your elevator pitch on why you're definitely an AI thought leader?

Paul Clark:

Oh, yeah. If nominated, I will not run. If elected, I will not serve on that front. I am a hardware engineer slash wireless Infosec guy. I am have a small business called Factoria Labs, which nobody's ever heard of unless you're in the I Greater Seattle area.

Paul Clark:

Well, if John knows, that actually is quite a help. I mean, the managing intern carries some weight around there. I have have written a few books on SDR. In fact,

Wade Wells:

I oh, I thought I

Corey Ham:

had one here. Anyway, it's got

Paul Clark:

a robot on it. It's cool. No starch book. We got another one in the works. And I've got a class coming up on Friday workshop, four hour workshop that anti siphon is good enough to be hosting, and I'm definitely looking forward to kicking that off.

Paul Clark:

Awesome. So basically, getting started with SDR. And yeah.

Corey Ham:

And then, Matt, you also have a summit talk coming up at the Threat Hunting Summit? Or Yeah. Yeah.

Matt Franz:

That's what I'm gonna be that's what I couldn't call down with MCP, you know.

Corey Ham:

Okay. On August 14. So a little bit further out, but, you know, you're doing good work in between now and then. You'll have to make the talk, make the slide, you know, do all the actual work between now and then. Oh, yeah.

Corey Ham:

Oh, yeah. That works. I haven't

Matt Franz:

read any slides yet. That's

Ralph May:

the one. Oh, no.

Corey Ham:

We would hope not. I mean, honestly, that we've talked about it many times on the show. But like, if you make the slides too early, you will forget whatever's on them.

Wade Wells:

And I have to remake percent.

Corey Ham:

100 I did

Wade Wells:

it die so many times now.

John Strand:

I am fighting with a con right now that I don't present that until September. And they're like, your slides are due. I'm like, I'm not doing that.

Corey Ham:

Yeah. Because whatever you say now is gonna be irrelevant

John Strand:

in September. I'm like, I can guarantee you it'll be a shitty presentation. If you make me write my slides right now, it's going to suck. And I'm keynoting it, and it's getting a little tense. It's getting a little tense.

John Strand:

What they don't know is I'm willing to walk away.

Bronwen Aker:

Right. Wait. Wait. Wait. Wait.

Bronwen Aker:

You're keynoting, and they're being obnoxious about you turning in slides for something actually just one person. Happen till September?

Corey Ham:

Yeah. What if it's no.

John Strand:

No. You got that's better if you if we can give you some feedback on your slides, and we can go back and forth, and you can think about your presentation. If you want the top notch best presentation for someone in their entire life, you want them to start writing that presentation at 3AM in the morning on the bed

Corey Ham:

that they are presenting.

John Strand:

They will show up. There'll be just a right level of, like, tweaked and anxious. The slides are gonna be top of mind.

Corey Ham:

They're gonna be mean, I don't gonna be the soul

John Strand:

of this John

Wade Wells:

has been so experience I'm just getting so triggered right now.

Corey Ham:

Like, this is the actual invite.

Bronwen Aker:

John, I can one up you. Oh. How many times have you rewritten an entire presentation in, like, on the fly?

John Strand:

I can actually tell you. I think on the fly like, we're talking within an hour before the presentation.

Bronwen Aker:

Actually, I've walked in I've walked into classes and and had a student group be so out of touch with what they were supposed to be learning that I had to completely scrap my syllabus and

John Strand:

teach it to pretty badass there. I have I have I've given a presentation. I can't even find it on YouTube. I think we did it in the old days when we were on GoToWebinar. And I literally gave the presentation while I was writing the slides.

John Strand:

So they saw my process of how I wrote my presentation while I was giving the presentation on writing a presentation. And, everybody, the thing they learned from that is I am really shitty at spelling. They were like, you you are borderline

Bronwen Aker:

illiterate. You hired me. Yeah.

Corey Ham:

You are borderline illiterate, but we still love you.

John Strand:

You know better than anybody other than my sister just how bad I am at gram grammar grammarian grammatical things.

Bronwen Aker:

Grammatical things. That's okay. Now I I have thought this for years, and I I if you're willing to humor me, verify it for me right now. Was it that one character typo that I found that was the the thing that

John Strand:

It was it was a it was a typo that persisted for almost a decade before you saw it.

Bronwen Aker:

That's the one. It was a one character typo in the command string. Okay.

Corey Ham:

Yep.

Bronwen Aker:

So I have been telling people for years, but I have not verified it with you. But I was pretty sure

John Strand:

That was it.

Bronwen Aker:

Yeah. Back so backstory. John and I met when we were both still at Sands. I was a SME. He, of course, was a superstar bouncing around and teaching lots of people really cool stuff.

Bronwen Aker:

I had the the joy and honor yes. Being a thought leader. I had the joy and honor of of helping QC one of the the course updates. And, you know, I I that was me. I went through it.

Bronwen Aker:

Hey. There's a command string. Drop it in a terminal. See if it runs. Well, one of them didn't.

Bronwen Aker:

And so I turned around, researched it, put it into GitLab. Turns out that one character typo had been in there, you say, for ten years, John?

John Strand:

Something like that. Yeah. Yeah.

Bronwen Aker:

Alright. Okay. Well, that's

Corey Ham:

thank you for confirming that. Much as I love let's get I love as much as I love deepening the amount of John Lord that's out there in the world, I should probably do the do the the news. Finishing introductions, we also have John Strand, the thought leader of iwill keynoteyourcon.com, which is a website that he doesn't own.

John Strand:

I'm should get that domain now.

Corey Ham:

He definitely won't keto your con, unless you, you know, unless you have special special permissions. Then we also have Wade, who is here to your lighting and your, like, you really look great, Wade. Like, I wanna give you props

Matt Franz:

for that.

Bronwen Aker:

The depth of

Corey Ham:

field, it's coming in hot. Muted. So you're not you look good, you sound terrible. Dude. There you go.

Corey Ham:

There you go.

Wade Wells:

I I I what I was saying, was I've been trying to Now out of focus. Like Now it's out of like, what's going on? Right? Like, thanks a lot.

Corey Ham:

Like Okay. I'm sorry. I I said nothing. Wade's here. Alright.

Corey Ham:

Anyway There you go. Is it

Matt Franz:

in focus now? Put me back

Wade Wells:

on main screen real quick.

John Strand:

We're stalling so we don't

Wade Wells:

It's it's focused on mine.

Bronwen Aker:

I don't know what

Corey Ham:

to say.

Bronwen Aker:

In back is awesome.

Wade Wells:

It's focused on mine. I'm fine. It looks so good

Corey Ham:

on here. Till we highlighted you the second we highlighted you.

Wade Wells:

I don't know what's

Corey Ham:

going on. I'm sorry. Alright. I I cursed it. It was one of those Schrodinger's cats.

Corey Ham:

Anyway yeah. Let's talk about Gold Eagle Initiative. This is something White House, you know, your classic sigh and read the the White House post. But basically, this appears to be okay. First of all, he talks about a clearing house.

Corey Ham:

What is a clearing house? Because I think of clearing house as like publishers clearing house where they would tell you for $25, they'll publish your book and that's just a scam. So is a clearing house a scam? What is a clearing house?

John Strand:

I don't know. I just think it sounds good.

Corey Ham:

Alright. So basically, this is Trump's made a post about essentially a joint initiative where it's super unclear what's actually happening, but it's DHS, Department of the Treasury, and CISA, and I guess also the Department of War all doing stuff. What they're doing is, I guess, scanning and patching. Who they're doing it to? Very unclear.

Corey Ham:

It's not clear if they're talking about, they say industry partners. We don't know who that is. They it's not clear what's in scope here, what the rules of engagement are. But the goal is to basically bring AI to help identify and fix vulnerabilities in The US, you know, state and local, I'm assuming, and also contractors. We don't know a whole lot of details about this.

Corey Ham:

If you know what this is actually gonna look like, please let us know because we'd love to hear about it. But Couldn't essentially

John Strand:

Couldn't this have been couldn't this have been under SZA? Like

Corey Ham:

It is. It's under everyone. It's just under everyone. Everyone works together. It's fine.

Matt Franz:

Yeah. But does it say public private partnership? I mean, are we playing that bingo? Critical infrastructure bingo or no?

John Strand:

Critical infrastructure public private. They did put clearinghouse in.

Corey Ham:

We don't know what clearinghouse is. We don't know if it's public private. It says work hand in hand with the private sector, financial institutions.

John Strand:

I'm gonna allow it.

Corey Ham:

Like financial institutions is in there. It's like, wait, week. Who are you I guess they're hacking banks since the Department of the Treasury is involved. We don't know. We're just gonna hope for the best of this one.

John Strand:

So here's my problem with this. And okay. It just shows that they're kind of idiots, the people that are putting this stuff together. Let's make this a a political Wait. Are you saying

Corey Ham:

the quiet John.

John Strand:

Let me get to this. Because here's what's gonna happen. Okay? They got Scott Besson. It's gonna be treasury.

John Strand:

We're gonna go in the entirety of the financial system. And they're gonna unleash this thing. And what they're gonna quickly find out is that this is gonna be a bunch of, like, old IBM systems running back half, Solaric, Spark nine systems. And they're gonna be like, we're gonna come in. We're gonna find the vulnerabilities.

John Strand:

So it's like, yeah. This is all duct tape, bailing wire, and, like, gerbils looking up, gasping with their last breath, asking for the sweet release of death to take them out. It's it's just it's I it just shows that they fundamentally do not understand the problem of vulnerabilities and what's going on. I do love the idea of pulling everything together, getting vulnerabilities, but how do you disclose this to people? How do you coordinate this with people?

John Strand:

How do you actually get are you gonna go start doing assessments for government agencies? It seems like it's an idea that's born out of the fact that they don't know all the things that they've already been doing. And I'm ranting on this.

Corey Ham:

Well, hold on, John, because you forgot one key key detail here, which is AI.

John Strand:

Oh, shit. That's right. Scratch it.

Corey Ham:

I'm done. Never It's magic. It's okay. It's okay. Just AI your problems away, John.

Corey Ham:

It's okay. Yeah. I'll be better now. Yeah. Exactly.

Corey Ham:

I mean, you nailed it. Like, there's no there's not a lot of details on how this is gonna work, who it's gonna target. Is it a good disease?

John Strand:

You know, we are bringing bringing a wartime footing to cyber domain to relentlessly patch vulnerabilities.

Corey Ham:

He does AI definitely wrote that.

John Strand:

He doesn't know what the systems are that are in DOD. The fact that they're ten, twenty years old. Like, you

Corey Ham:

John, would you would you call this a concept of a plan? I call this a concept.

John Strand:

Vague con this is a bad plan. This is a bad plan.

Bronwen Aker:

I don't know. I I of a concept of a plan.

Corey Ham:

And I will say, this administration in particular has been really good at collaboration, everyone working together, getting along, you know. I I don't see why this could pose any doubt.

Bronwen Aker:

So much so much love in the room constantly. It's amazing.

Corey Ham:

Yeah. I'm sure it'll go well. But I guess if if you you know, we'll we'll keep everyone up to date if there's new details about this. But I do love the idea that, like, at some level, this comes down to like a situation room room where they're like, is SSL version two really a critical? Because Nessa says it is like, like, I I wanna hear that conversation amongst like politicians and execs.

Bronwen Aker:

So Corey, you realize in that one scenario, you just gave me more nightmare fodder than I can imagine. The administration getting their hands on a Nessus report.

Corey Ham:

Oh, yeah. Oh my god. Oh, yeah. It's gonna happen. Just get ready.

Wade Wells:

I don't

John Strand:

you know what? Let let you know, this might be one of look. I'm gonna try to spin a positive on this. Right? Because people are gonna look at this and think that it's political.

John Strand:

I've seen all administrations do incredibly stupid shit over my entire career. So, truly, it's nonpartisan. But out of all of the administrations that I've ever seen, I think this administration has a higher tolerance for breaking stuff than any other administration. And if we're gonna look at a positive in this entire thing, like, you know, if they move fast, break lots of things, and then try to get it fixed, then god bless them. Carry on.

Corey Ham:

So okay. You know, I to to tie into other current events, do we think it's gonna be like the low flyover in Florida where it's like the scans will improve continue until morale improves or whatever. That's the positive thing.

John Strand:

Corey, that's the positive thing. Like, a year from now, it's like, holy crap. They literally broke almost the entire government and the financial systems, but they're batch hours. You can't create software now.

Bronwen Aker:

So AI scans way too. Survive John, look at it this way. If we survive, all of the rebuilding after the fact is going to boost the economy like nobody's business.

John Strand:

It's a jobs program, Bronwen.

Wade Wells:

It's a job. Oh, yeah.

Corey Ham:

I mean, there's not a whole lot more to discuss with this. We don't have any We don't we don't have any details on it.

Paul Clark:

But we don't know nothing.

Corey Ham:

Do think, you know, to kind of dovetail with John's, know, looking taking a positive take on it. It is good that the administration, whoever they are, knows that cyber and AI are a big deal and that something needs to be done about this. It's a unique time. I mean, will anything useful happen? TBD.

Corey Ham:

But at least it has someone's attention, and that's a good thing. Yeah. Yep. Alright. Next one.

Corey Ham:

Well, yeah. Anyway, so nightmare eclipse, our favorite persecuted did do it?

Ralph May:

Did he do it?

Corey Ham:

I mean, kind of. So there is LegacyHive was posted to their GitLab. They tweeted about it. It's live as of July 14. The vulnerability is elevation of privilege.

Corey Ham:

It's kind of a unique one. It's not terrible. It's not as bad as I think everyone was thinking it would be. There was also a defender one, I think, a couple weeks ago that got released. This one is, you know, basically requires two sets of credentials.

Corey Ham:

So it requires another standard user's credentials and a third username, which could be the built in admin. And then you can basically elevate privileges. So it's already been hot fixed, I think, or will be hot fixed soon, most likely. But I don't know. We'll see.

Corey Ham:

I

Matt Franz:

was like, see what else? Yeah.

John Strand:

Yeah. What did I say? I was gonna burn I'm going to burn Microsoft to the ground.

Ralph May:

To the ground.

Corey Ham:

This ain't it. Yeah. It's still coming, but this isn't it. Like, elevation of privilege, that's a feature. Right?

Ralph May:

In Microsoft. Yeah. I mean, in Linux too. Jesus Christ. You know how many

Corey Ham:

craps, vulnerabilities there are? It's ridiculous. True.

John Strand:

Yeah. Just another We're coming.

Wade Wells:

Just another internal blue, you know, just something on that scale.

Corey Ham:

Just let's spice it up spice it up from spice it up.

John Strand:

Is that too much to ask for?

Corey Ham:

Just how about Just another internal blue?

Wade Wells:

That was one of the most fun weeks of my life. You know, like working working ten, twenty hour days, just living in the sock, you just go sleep in the back room, pizzas on the table, you know, just the

Bronwen Aker:

smell the smell of days.

John Strand:

Wait, the energy drinks.

Wade Wells:

There's nothing like the manager coming in with a case of monster just for everyone to just look at logs all day, you know? It just really puts you

Corey Ham:

up. So good. Yeah.

Ralph May:

So you needed AI back then.

Corey Ham:

I'm assuming there's I'm assuming there's more bugs coming or maybe this is it. Maybe Microsoft there is a chance that Microsoft has gotten wind of this and is just furiously hot fixing and patching things before the researcher publishes them. We don't know. But basically, we're all expecting more.

Bronwen Aker:

Well, mean, the last patch Tuesday had 500 plus criticals.

John Strand:

570 something? Yeah.

Wade Wells:

Criticals? I mean, just That is a bit above average. Yeah.

Corey Ham:

A bit above average.

Bronwen Aker:

For even for Microsoft, that's above average.

Corey Ham:

Yeah. I mean, stay tuned, but it's possible that, you know, the researcher had some more active bugs, and they're just Yeah. Working through them.

Paul Clark:

We're

John Strand:

And you know what?

Corey Ham:

That's the

John Strand:

best way to do it. You gotta dribble drop these out. Like, you

Bronwen Aker:

just can't roll them all out in

John Strand:

one day, Cause it's one news cycle. You gotta get one a week. Right?

Corey Ham:

So one a week. Yeah. There's a couple of really, I think interesting articles about, basically defensive use of AI. The first one is a really interesting article in Ars Technica about defenders using prompt injection. Have you guys seen this?

John Strand:

Mhmm.

Corey Ham:

It's really interesting. So Tracebit researchers basically published a blog that they did some I mean, I think their testing setup in harness was pretty advanced and pretty cool. But essentially, they used context bombs, essentially, kind of like a zip bomb, but for AI to essentially just reduce as a countermeasure, reduce the likelihood for a Genetic AI to be able to exploit systems. So basically, the kind of big high level statistic is when they're using this technique, which is like prompt injection for defense or for context bombs for defense, The exploit percentage went from five 57% success rate to 5%, and then 36% for persistence down to 1%. They're using Opus four eight.

Corey Ham:

They're using other, like, frontier models. They put they published a bunch of other statistics about it. But I guess defenders wait, is this on your radar? Are you like putting files on your desktop that just says if you're an AI agent, please don't hack me, bro. What?

Corey Ham:

Let's talk about what you're

John Strand:

doing in some way.

Wade Wells:

Maybe I should like I I this was not on my radar whatsoever. I don't and I honestly don't think it's on many defense people's radar whatsoever.

Corey Ham:

I think

Wade Wells:

it's We're dealing with the it probably does. But, like, where are we gonna put this? Like, on? I'm trying to think like, okay. Do I go put

Corey Ham:

10 tools? Right? That's basically how it go. CrowdStrike would have their AI defense mode that that you could turn on or whatever.

Wade Wells:

Do I well, do I go put in every major repo? Right? Like, adjust a text file that says if you read this repo, like

John Strand:

But but just think about the things you would put in that would cause AI to stop. Like, we make a joke about Winnie the Pooh, Tiananmen Square. There's a file with the n word in it, like, twenty, thirty times. Like, AI is like, not touching that.

Corey Ham:

Not touching that. Just Yeah, going there.

Bronwen Aker:

So Bogon poetry. Bogon Bogon poetry. Asking how

Ralph May:

to download YouTube videos illegally in Europe.

Corey Ham:

Right there.

John Strand:

So I've got a problem. That I that I need you guys all to, like, give me advice on. And when we're talking about defenders in AI and attackers in AI, during my webcast last week on Thursday, I said that AI in the short term is going to dramatically increase the ability for attackers to be successful, and the defenders are screwed for a short period of time. Somebody on my talk put in chat, they said, Dave Kennedy disagrees. He thinks AI is going to give defenders the edge instead of the attackers.

John Strand:

So now this is blown up, so I've gotta figure out where I can find a slot at WildBoss Tacking Fest. I have to debate Dave Kennedy on this.

Corey Ham:

Because they're also gonna be a push up contest.

John Strand:

And Dave wants to add in a physical challenge. Now I am I am fairly sure I can out climb, out bike, and out swim Dave Kennedy. I hope to God I can outrun Dave Kennedy, but

Corey Ham:

who was confident about that?

Wade Wells:

What about itching your back, like, right

John Strand:

in the center?

Wade Wells:

Like, that's the only thing. Right? Right here. Start stretching. Start doing yoga.

John Strand:

Yoga. I bet you, like, his exercise routine, he isn't just, like, fit like that. I bet you he can do, like, like, a lotus pose, like, no problem at all. Like, you know, he's doing scorpion and all kinds of shit. And I'm done for, like, if it gets to that.

Paul Clark:

But But

Ralph May:

but isn't Dave isn't Dave building what is it? Night night beacon? Right? It's like Yeah.

John Strand:

I talked to him about night beacon in the past and what he's doing. And and it's it sounds really, really cool.

Ralph May:

So I guess my point is is that he's just, like, really into that side of it right now. Right? So, like, you know, he's he's deep in using Yeah.

Corey Ham:

Yeah. Yeah.

Wade Wells:

Yeah. Wanna I Jason had Jason Haddock's perspective. Right? Like, that was someone who I, like, listened to a lot. And I've talked to him.

Wade Wells:

And the one thing is, like, the the defense isn't adopting it. That's the thing. They're they're it's not the adoption rate is not great. That's that's the worst part. And the red team,

Corey Ham:

you can go pay for subscription now.

John Strand:

Thing that Dave at binary and we've been doing in our SOC as well, like, we've leaned heavily into AI for defense. And so it's so it's binary for sure. But I agree with you. A lot of SOC's are very slow to move into that AI pipeline in generation.

Wade Wells:

I think the managed security providers, hence, you guys are adopting it and see where it's going, but it's like the little shops who can't maybe who just aren't doing it yet, but or you have to go pay a managed security provider to do it for you. The other thing is Security teams are forbidding. The other Yeah. The other thing I've

Matt Franz:

seen large enterprises, their own security teams aren't are prevent they have to all use Copilot.

Wade Wells:

So the Yeah. There also isn't enough, I feel like, documentation around how actual organizations are doing it in these smaller orgs and how to do it. Like, there's a plenty of great stuff out there for the managed security providers and how they're doing it in order to defend you. But if you don't have the money for that, how do you set it up yourself? Flare to the doc

John Strand:

I don't that's an issue of money. Right? Like, I think it's an issue of will. No. You know, BHS, we don't have any VC funding at all.

John Strand:

Like, we're just we're just building this out. Right? And we've got a

Bronwen Aker:

good team.

John Strand:

We'll talk more about that after DEFCON. But when you're looking at a lot of the large vendors that are out there, even even if you're trying to buy that capability, it takes a tremendous amount of dedication and work and trial and error to try to get it to function properly. Like, you just can't buy products off the shelf that just automate this entire pipeline yet. It's just not there.

Corey Ham:

No. Well, so I I there is a little piece of evidence in another article that kind of helps, I think, prove maybe John's point a little bit. Encourage Dave. Please die. Okay, so

Wade Wells:

that website goes down instantly.

Corey Ham:

Interesting article. I just pasted it. But it's about a breach at hugging face, which if you guys don't know, yeah,

John Strand:

AI to breach AI.

Corey Ham:

So okay, This is really the if you don't know what hugging face is, it's basically an AI sharing platform. It's yeah,

Ralph May:

it's basically get it

Bronwen Aker:

out for AI.

Corey Ham:

Sure. The article's interesting if you wanna read through it. AI on AI action. But I think the most interesting part of this article is at the end, the little section that says the asymmetry problem, Meagan. So basically, I'm I'm just gonna read this out loud because I think it's worth calling calling out.

Corey Ham:

When we started the log analysis, we first use frontier models behind commercial APIs. This did not work. This analysis requires submitting large volumes of real attack commands, exploit payloads, and c two artifacts. And these were blocked by the provider safety guardrails, which cannot distinguish an incident responder from an attacker. Then they switched to GLM five two running on their own stuff, and we're able to successfully analyze the data.

Corey Ham:

And then they basically say, this is an important gap that defenders need to plan for. We don't know how the attacker, what model they're using or how they're bypassing jail breaks. But we have to do the same thing on the defensive side if we wanna use AI models to analyze their activity. And that's a really interesting thing I was gonna ask Wade or other defenders on the call. Like, how do you do this?

Corey Ham:

Do do like, do you think their expectation is real? Like, I feel like telling every org they need to be able to run GLM five two in in house is insane.

Matt Franz:

Right? Like, it's like Even if you were sophisticated enough to use, like, a cross platform agent framework that works perfect, the models are so different. Anybody that's tried to mess with OLAMA is just trash compared to anthropic. So this idea, even if you're using the right tools and you know how to use them, the prompts are different. The tool behave everything is different.

Wade Wells:

The environment. Right? Every like, for the blue team, you have to completely customize it to yourself every time.

Matt Franz:

Oh, I think even the tool. Yeah.

Wade Wells:

This doesn't Yeah. The tool. Yeah.

Matt Franz:

Data. Just the tooling aspect are nontrivial. You can't just swap. And, you know, maybe if you're using the API model gateways, inference gateways, things like that, and you have all the routing figured out. But who does that in these organizations?

Matt Franz:

You know, certainly not the spec to this kind of lack of, you know, security poverty line with regards to AI. I think there's also a lot of kind of like I saw the anti cloud mentality in security community. Folks just didn't ever learn it. Think there's some of the same thing going on in AI.

Wade Wells:

Very much agree with that. Yeah.

Corey Ham:

So for any defenders, Wade, have you had issues running incident responses where you're getting guardrails? Like, is

Wade Wells:

that common? Will tell you the truth. I have never had it say no to me anything I've ever done. And and that is looking at files going and hunting down logs, creating me things, performing incident response, or just detection engineering, right? Creating pipelines like I, I have tested stuff out like red teaming before within had it blocked me.

Wade Wells:

But as a blue team, one, I'm not gonna drop it malware to dissect me malware. Right? I don't want to do that. But I have had it do some crazy thing like p caps, you name it. It is the it's never had a problem.

Corey Ham:

So this might just be their unique experience. And this is one of the most challenging things about AI is that like, my AI isn't your AI. Like, me when I go to talk to fable, if I ask it if a fruit is a vegetable, it's like, this has been flagged. Right? Because of my memory and my context and Yeah.

Corey Ham:

All that Like, I cannot use Fable on my account at all. But other people obviously use it to great success. And so it's like, I I do think it's an interesting thing to think about though. You know, if the tool isn't doing the job, you have to switch to another tool. That's just how any tool works when it's incident response based.

Corey Ham:

Right? Like yeah. I don't know.

Wade Wells:

With that, I might The other other

Matt Franz:

thing that's interesting here is I'd love to know the initial exploit vector in terms of uploading a Poison model because there were known vulnerabilities in model pickle files and serialization issues. They're probably not gonna close that. So how did they what sort of model did they upload, and how did it move laterally within their inferencing and model CICD? So I think that's more interesting to me.

John Strand:

And I I think when we're looking at the log thing, kind of getting back to Wade's point, there's a quote from Carl Sagan that I think is really important. It's the absence of evidence is not proof of absence.

Corey Ham:

Oh, man.

Paul Clark:

But it's not evidence of absence.

John Strand:

Whenever you're using when you're using AI to analyze your logs and you're kind of going through this looking glass, but there's a filter associated with it, I think that that's where the distortion of what's really happening becomes a problem. Right? And that's that's what scares me the most about this. Like, how long until the attackers we were joking about certain phrases like Winnie the Pooh, Tina Inman Square, all of that. Okay.

John Strand:

We joke about that, but, yeah, there are very much real guardrails that exist if you're using commercial models that are publicly available that have those guardrails to protect that. Right? Or PII, PHI, things of that nature. So that's why the biggest thing for me in this entire article is the section is the asymmetry problem. Right?

John Strand:

If you go to that section and it says they're running local models with unrestricted open weight level analysis.

Corey Ham:

It's And hugging face. They've got all the infrastructure on the planet. Yeah.

John Strand:

Yeah. Yeah. But that's why and Corey, you hear me talk about it at least once a week, why I keep pushing. BHIS has to continue to have our own infrastructure. We cannot rely on Bedrock and all these other places because one of two things is gonna happen.

John Strand:

Either it's gonna color the results, which we're already seeing right here in this article, or the other thing that's going to happen, we saw it a couple of weeks ago with Mythos, they're literally gonna shut down certain operations for cyber offenses. And that's what you have to be careful of.

Ralph May:

Do you wanna talk about the that's a great segue into the other thing that came out last week, which was Kimi k three. Right?

John Strand:

Yeah. Yeah.

Corey Ham:

No. Well, yeah. I do have Chinese. I'll talk

John Strand:

to you all later. I'll see you next week.

Corey Ham:

Alright, John. Alright. Bye, John.

Bronwen Aker:

Bye. So, John.

Corey Ham:

So, Ralph, yeah, basically, not only did Kimmy k three, which if you're if you don't know what that is, it's a Chinese open white model model similar to GLM five, which is what Hugging Face specifically says they used to kind of counteract some of their refusals they were getting with Opus. It also, basically, China appears to be saying that the new standard is for opens is to open source or open weight all their models. That's basically like the top line from Xi Jinping is essentially, we are going to open source as many models as we can. Obviously, you can take that from a cynical perspective and say, well, that's just the best way to destabilize The US. Right?

Corey Ham:

Like, that's their intent here.

Ralph May:

That that's the alright. So the the headline point is that that the new Kimi k three is is, what do call it, benchmarking near or at fable and depending on

Corey Ham:

how going. Months behind Yes. Anthropic.

Ralph May:

Which is which is a big deal. This goes back to Corey's point about the, you know, destabilization of a US or whatever because all the money that's getting invested into these AI

Corey Ham:

US based AI stuff.

Ralph May:

Yeah. Exactly. But going back to the defense and the other piece, right, having models like this that are open weight avoid, which is actually another thing that was also announced is that the White House was announcing that with this new Kimmy K three, they might be looking to sanction it. Right? Which it it becomes like this whole big, you know, piece where wanting control over who can get the latest AI.

Ralph May:

Right? And, you know,

Corey Ham:

back to John's point about, you know, having something that you can, you know, run yourself.

Matt Franz:

Like TikTok. So TikTok.

Corey Ham:

Mhmm. Well, yeah. I mean, basically, but kind of a different, you know, totally different level of danger. Right? Like TikTok obviously is like, oh, the kids are eating Tide Pods.

Corey Ham:

This is like, The US economy is in danger. Like, you know, it's a different. Yeah. I think it's Yeah.

Bronwen Aker:

Just a little bit.

Wade Wells:

Oh, we lost Corey. Oh,

Corey Ham:

sorry, guys. Lost Corey.

Paul Clark:

Yeah. We can hear you.

Bronwen Aker:

I can hear you.

Corey Ham:

Stupid. I my my Thunderbolt dock keeps dying and I don't know why.

Ralph May:

Oh, no. Had that problem.

Corey Ham:

I still exist. Yeah. I'm alive.

Wade Wells:

Your audio works. Go off.

Corey Ham:

I'll come back. No. I I was just

Ralph May:

gonna say though, it just it it, like, it

Paul Clark:

kinda hit the scene and a lot of

Ralph May:

people were talking about it. Lot of people were moving for, you know are moving over to at least try it. I know that their servers got swamped entirely because of the cost differences and other things like that. But, you know, as we continue to go down this road, which changes every month wildly enough. Right?

Ralph May:

And we're seeing like Every month? Yeah. Who the leader is and, like, it wildly changes. Right? Like, when we everything I thought was true last month is not true right now.

Ralph May:

It's just, you know, it moves so fast. Anyways, but as we continue down this road, I think we'll see more of this. And, you know, the the the concept of where you run it and how it affects you and and not not not working for you, if that makes sense. Like Yeah. Stopping you from being able to do the thing that you wanna do, whatever that is.

Ralph May:

Right? And the model being like, well, it could be bad. Right? Which is the whole fable problem. Right?

Ralph May:

Everything is maybe it's bad.

Corey Ham:

Turn it off.

Wade Wells:

Every time I've thought about getting into local models, you guys have talked me out of it. Right? It's like Notepad plus plus. I don't use it anywhere anymore. Well, it's because, like, the cost perspective as a blue teamer, like, I don't I I wanna run a local model, but the one thing right now, as a father of two, my time is more expensive than anything else.

Wade Wells:

I cannot even time to set it up. But the other is the cost for me. Like, I why when I can just turn something on? Right? I don't wanna go out there and spend a couple grand on a new PC in order to do it.

Corey Ham:

I don't yeah. And I don't think this like general advice is targeted at the individual. I mean, if you're a person, it's like the question of do you also do you pay? Do you have a jellyfish server? Do you pay for Netflix?

Corey Ham:

Do you do you make your own sourdough? Or do you go to the bakery? You know what I mean? Like, there's so many like, do you do this at home? Or do you do this, you know, from a

Wade Wells:

just have an account to someone else's Plex server, you know? Yeah.

Corey Ham:

The economy doesn't scale though, right? Correct. And the the call to action here is for companies. Basically, this is like essentially, this is a supply chain problem. It's essentially the same as if Ralph and I are making metal beams and our steel supplier goes under.

Corey Ham:

Well, where do we buy metal beams? It's the same thing. It's just AI. And the answer to that question is a very global and potentially Chinese related question as well. It's like Mhmm.

Corey Ham:

We can't source high quality steel from The US anymore, so we have to do it from overseas. I think the really it's about companies having these services, not private individuals. Sure. You're if you're a purse like, no one that I know at least, because I don't know any billionaires, can afford to buy hardware to run g l m five two or Kimi k three just at how at their home. But Sure.

Corey Ham:

Providers exist. But you

Ralph May:

can rent access to it. Right? And I think that's a bigger thing. And especially to bring it back more to security, I think it's the idea or the concept of having models that don't stop you from doing things either malicious or defensive. Right?

Corey Ham:

Like Correct.

Ralph May:

Yeah. And having that It's about the fact.

Corey Ham:

It's about being open weight more than it is about being, like, hosted in China or hosted in

Ralph May:

The US. Exactly. Exactly.

Corey Ham:

Yeah. Exactly. Because basically, where we're at with AI is like the current band aid that we're slapping on refusals that we're getting from Opus is just use g l m five. So they're basically the the the problem is from like a, you know, sovereignty or whatever you wanna call it perspective is AI anthropic or, you know, frontier model providers are trying to meet the guidelines and demands that are set by US sanctions and US, like, they don't wanna get in trouble. They have to follow the line with the whole fable thing.

Corey Ham:

You know, they were like, oh, you have to depublish this. We're doing all this export control stuff. Meanwhile, China is saying, nah, let it rip. Whatever. Even if it does damage, let it go.

Corey Ham:

Let it be open. Yeah. Like, it's the same, you know, they're they're taking a different approach to it. Could debate it till we're blue whether what approach is better. But at the very least, right now, in security especially, g l m five is getting used a lot more probably than Opus for this type of work.

Corey Ham:

And the reason for that is purely software. It's just a choice by Anthropic to put the guardrails in place or not. Right? And so

Bronwen Aker:

I don't know. One of the other things too. I mean, Corey, the Chinese are more than happy to let us shoot ourselves in the foot with anything that that they provide. And we've we've we're trying so hard to keep up with all of these innovations. This this Kimi k three, great.

Bronwen Aker:

Wonderful. We've got

Corey Ham:

No. No. We have better innovations. We're just kneecapping them intentionally. We we have a better AI model.

Corey Ham:

Opus is better. It just refuses to do.

Bronwen Aker:

Trying to go with this. They're they're happy to let us kneecap ourselves. Now what we're also looking at is if we take a step back, everything that you said is almost entirely US centric. And the rest of the world is fed up. They are done with US poll political shenanigans around the AI space.

Bronwen Aker:

And so it's gonna be interesting to watch what happens as Britain figures out what they're gonna do as far as AI, as the EU figures out what alternatives to American technologies they're going to adopt, it's already shifting.

Corey Ham:

Yeah. I mean, I don't know. It it's a it's a lot of, you know, hot nation state on nation state action. Who knows what will happen? But at the very least, it's a bummer that I can't.

Corey Ham:

I'm in the cyber verification program. I work for an Infosec company. Hugging Face is another company that, like, should be able to do basically whatever they want with AI, but they can't. And so they have to use it's the equivalent of, like, if I were to go down the road and talk to someone who's making me a backpack, they would have to source the fabrics to make that backpack from overseas. It's the same problem Yeah.

Corey Ham:

Basically, just with AI. And it's extra dumb because We have the data have the AI models. We have everything else, but we can't actually use it because, you know, I don't know.

Paul Clark:

Whatever. Actually, I wonder on that. We have the data centers, how much of the sort of the high level strategery, so to speak, in the Chinese perspective is thinking, well, they can out build us. And so, if they've got a hardware advantage.

Wade Wells:

Yeah.

Paul Clark:

You know, any

Corey Ham:

We gotta have a model advantage if they're gonna have Yeah. The hardware

Paul Clark:

The thing that concerned me, because I got a few glorious days out of Fable before it became completely neutered. But when when I saw that frivolous sort of export control judgment that the DOD made, the first thing my mind went to was export control. Does that mean they're gonna need to start to verify that users are

Corey Ham:

and then you think

Paul Clark:

about the

Matt Franz:

stuff happening in

Paul Clark:

Australia and other company countries about social media access restricted to anyone who hasn't you know, it's just a it it's an interesting path, and I I mean, disturbing path, not interesting. And and seeing, like, a particularly American way to get there was not thrilling.

Corey Ham:

So it's either you use Opus after jumping through 87 hoops or you just use GLM five with no hoops. What do you think most businesses are gonna choose? Right? Like, that's but yeah. Anyway

Matt Franz:

Well, I mean, they if we wanna play conspiracy theory here, a lot of people are moving back to OpenAI and, you know, five, six. It doesn't have these guardrails from what I've heard. So maybe this is all part of a Sam Altman IPO play. No. Just

Corey Ham:

Well, just yeah. I mean, that that's fair. I mean, it is like, I obviously, I know you're joking about this specific conspiracy, but the the action, you know, you're right. Like, there is this is a tunable parameter of, like, how careful a model is or how many refusals it gives. This is something they've adjusted on the fly the whole time we've been using these models.

Corey Ham:

They've changed it. You know? Like, it it's seriously like, you know, my AI is not your AI, is not anyone else's AI. And that's part of the confusion. Anyway Well, and it's such

Matt Franz:

an anthropic foot gun to use that term.

Corey Ham:

It loves to say foot gun. It it does love to say it throws that throws that into the corpus. It does throw that to the corpus.

Ralph May:

But yeah.

Paul Clark:

Does does the mention of supply chain mean we're gonna get to the KFC article at some point?

Corey Ham:

Yeah. Well, we can we talk about We gotta talk about FLOC.

Wade Wells:

We always talk about FLOC.

Corey Ham:

Yes. But Okay. So there I I mentioned at the beginning of the show that there was uplifting news about FLOC, and

Ralph May:

there is.

Corey Ham:

The uplifting news about flock is that LAPD, which I'm assuming is gotta be one of the biggest police departments in the It is. Country. Is. Has officially said that they're going to let their flock contract expire. They've cited serious concerns over civil liberties and privity privacy.

Corey Ham:

I mean, that's about as uplifting as you can get when it comes to flock articles. The last time we talked about flock, I'm pretty sure it was them figuring out how to track my heart rate with Bluetooth devices or something insanely creepy. Classic. So they have 80,000 cameras total. Not LAPD specifically, but in The US.

Corey Ham:

And there's probably I mean, I they don't give a statistic in the in the article, but there's probably thousands of cameras deployed throughout LA. This is probably a multi multi million dollar contract. So it's definitely one of those things, you know. It's like this I think this, at least from my perspective, the citizens, the the electorate, whatever you wanna call them, have kind of decided that this is one step too far. There's also I don't know if we have the articles, but every week, there's an article about someone getting arrested for using flock to stalk their ex or stalk their, you know, family member, whoever it is.

Corey Ham:

Cops are abusing it. We have pretty good documentation that's happening. And people are, you know, revolting, I guess. And so this is an uplifting thing. LAPD is probably one of the bigger police departments and definitely leads the charge with a lot of this stuff.

Corey Ham:

And so

Bronwen Aker:

Yeah. LAPD has had a a troubled history. And as a Los Angeles resident, seeing this really it it made you heartwarming. Nice. It made me very happy, especially given all the squirrelly and stupid and obnoxious stuff LAPD has done in the past.

Bronwen Aker:

Seeing this was a very positive reflection on the department that has had you know, if you look at their history, it has not been pretty.

Wade Wells:

I'd be surprised if those flock cameras get serviced where Bronwen lives, to tell you the truth. Well,

Bronwen Aker:

they don't have flock cameras up here because in my neck of the woods, the tweakers steal all the copper wires. That's why I don't have a landline anymore, and why I'm on satellite?

Corey Ham:

This is the 2026 version of Arm the Homeless. Just

Wade Wells:

Yeah. Pretty much. Pretty much.

Corey Ham:

Yeah. Anyway

Bronwen Aker:

Well and you saw that four zero four media article about that one cop who almost had a head on collision because he was pursuing a lady illegally, and he'd been using flock on that. I mean, it was just insane.

Corey Ham:

It there's every week, there's an article about a cop getting arrested for using flock in a sketchy way and getting caught doing it. Keeping you know, continuing on, there's if you're into Pegasus, if you if you know what that is, Pegasus, they they tag it as the most notorious Bioware system in the world. I think that's accurate. If you if you're been in Infosec for any amount of time, you know what Pegasus is.

Bronwen Aker:

Worse than iOS?

Corey Ham:

Worse than iOS. Definitely. Basically, the amnesty.org has published a a really interesting write up on Pegasus and, like, it's a up to date. We haven't heard a lot about Pegasus in recent years. We kind of Apple was suing them.

Corey Ham:

There's a bunch of companies suing them for, you know, abusing their terms of service, basically, and hacking their customers. So, yeah. This is a really interesting write up on and it has even specific, like, screenshots of the dashboards and what they look like. It's just a really unique peek behind the scenes of how these tools work. It's pretty much before this was only used or really only seen by nation states.

Corey Ham:

And so it's a really interesting write up. If you're into malware, it's worth a read.

Wade Wells:

Nation states or cartels?

Corey Ham:

Or yeah. Nation states or cartels that are the size of nation states. Or cartels that

Bronwen Aker:

being used by nation states.

Corey Ham:

Yeah. The other quick fires, w p two shell WordPress was a that cracked Friday. I was in continuous spend testing a quite a hustle and bustle. It I thought it was unique because it was basically a textbook example of why we can't have nice things anymore in the world of AI. Because the pub the researchers didn't publish an actual functional exploit.

Corey Ham:

So the coordinated vulnerability disclosure, you know, they patched it, then the researchers went live with their sites. The people who published blogs about it didn't specifically say, here's the exploit. Here's how you do it. But people figured out in about fifteen seconds that if you gave AI the patch diffs, that it could easily figure out the exploit. And so, me and every other pen tester on the planet gave the patch diffs to Claude and had it write in functional exploit and then exploited all, you know, a bunch servers with it before people decided to patch.

Corey Ham:

So it's just kind of an interesting, like, we're at a point where people are saying, I I I'm curious other people's take on this. A lot of people on Twitter otherwise were saying, oh, this is trivial. Like, this they might have as well have just published the exploits. But my question is, is it trivial? Because I it took me about thirty minutes to an hour with Claude and some creative prompting to make it build me a functional exploit.

Corey Ham:

Is that trivial? Is that are we is that where counting is trivial? How

Bronwen Aker:

many many WordPress exploits have you been able to call together in, fifteen minutes in the past?

Corey Ham:

Zero. I I've never made any exploits in my life. But AI can make informed

Bronwen Aker:

How many of you attempted?

John Strand:

None. In the past?

Corey Ham:

We Okay. The past, we would just say that kind of stuff is out of scope because it would take weeks to

Ralph May:

too long. Yeah. Yeah. If it's you know, unless you're really comfortable with the the the code or whatever the language was or whatever. So it just take too long.

Ralph May:

I mean, think I think, Bronwen's obviously making a point here, right, that this does shift the, you know, the the time the time to write that exploit and, you know, if they should actually just publish the go ahead and publish that POC right away. I mean, I don't know. But I I would argue though from the defense side is that if you aren't building things with quick ways of getting updates, you are gonna get creamed out there.

Corey Ham:

Well, so okay. On WordPress specifically, they have an auto update feature. And on my personal WordPress site, it was enabled. And then I never got you know, I never was worried because it auto updated when they published the patch. It was updated.

Corey Ham:

Yeah. Yeah. Obviously, not

Bronwen Aker:

a update

Corey Ham:

Go ahead.

Bronwen Aker:

WordPress itself and all the plugins.

Corey Ham:

This was a WordPress core exploit. So the plugins weren't affected. It it was very a unique unicorn because it was basically a SQL injection leading to remote code execution. Me, personally, I got the SQL injection working. I didn't get the remote code execution working because I didn't really need to.

Corey Ham:

With SQL injection, you can dump the entire WordPress database with all the users. And, you know, it's like at that point, that's what you'd probably want. All the all the

Ralph May:

all the juicy stuff is already in there. Right?

Bronwen Aker:

Yeah. Yeah. Once you've done the Excel, who cares?

Corey Ham:

And WordPress isn't usually that juicy of a target. Like, you're probably in some random cloud hosting provider who has 58,000,000 WordPress server. Like, it's usually not, like, in a client's DMZ or whatever. It's almost always marketing team, third party type deal. The other thing I wanted to call out specifically with this one, because it also I guess, we don't really have an answer on whether just saying AI make the exploit counts as trivial.

Corey Ham:

Like, I don't know if every hacker has AI. I guess, to assume they do. I don't know. Yeah. But basically, the other thing that was interesting with this one is Cloudflare was blocking it right off the bat.

Corey Ham:

Right? So Cloudflare immediately had a WAF rule that if you had the Cloudflare WAF enabled, was blocking this exploit before it ever went live or was published. But the other thing that we noticed with some of our customers is that not every you could sometimes get around Cloudflare by just finding the origin server exposed on the Internet anyway. Right? Yeah.

Corey Ham:

So I just wanted to bring that to people's attention. If you run a WordPress server or any other web server and you are proxying it through Cloudflare WAF, you gotta make sure you aren't also allowing arbitrary inbound traffic on the IP or, like, direct.

Ralph May:

Rule number one, everyone who everyone who was getting DDoS back in the day I mean, like, you used to get DDoS today, but it used to be, like, a lot more rampant way to, like, cause destruction. They they they figured that out real quick. You have to actually put firewall rules Yeah. Right? And only allow Cloudflare, which they market their IPs.

Ralph May:

But everyone's just like, oh, I checked the little box. We could be good now.

Corey Ham:

We I I change it to proxy in Cloudflare. We have a WAF.

Ralph May:

But then go off wondering how do they find your IP address, super easy. You can look up the certificate transparency logs. You can Oh,

Corey Ham:

there's so many ways.

Ralph May:

There's so many ways.

Corey Ham:

DNS history.

Ralph May:

DNS history. Yeah. Yeah. Yeah. So

Corey Ham:

Jodan, Favicons, etcetera, etcetera.

Ralph May:

Yep.

Corey Ham:

But yeah. Alright. Let's get into chicken news. Last article or potential last article. Critical infrastructure is under attack in Japan.

Corey Ham:

That critical infrastructure being fried chicken.

Ralph May:

Oh, no.

Bronwen Aker:

Hey. They take fried chicken very seriously

John Strand:

in Japan.

Corey Ham:

I personally take fried chicken very seriously. Yeah. As well they should. Basically, KFC has had to close some stores in Japan. Apparently, the purveyor of frozen foods, Nickre Group, has been hit by, I'm assuming, a ransomware.

Ralph May:

The Chinese chicken conglomerate. Yeah.

Matt Franz:

Well, milk milk was hit in The US this week too.

Ralph May:

Yeah. Yes. Yes.

Matt Franz:

My

Corey Ham:

We don't got milk?

Ralph May:

My kids actually

Bronwen Aker:

drink got milk?

Ralph May:

Very specific chocolate milk. And now we're, like, ordering it like it's right after

Wade Wells:

I was about to say, you go to Costco and just buy the biggest case you possibly could. Yeah. Oh my god.

Paul Clark:

Joke here about, like, if somebody hacked the Double Down back into existence or something. But the more I thought about this maybe it's because I'm listening to many history podcasts these days. But, I mean, you you look at big world events in the past, and

Corey Ham:

you could even talk about

Paul Clark:

the Bronze Age collapse being a supply chain issue. Right? You know, our tin from Cornwall in Afghanistan isn't getting into some Hittite king's armor. That's a simplistic assessment, I know. But, like, we have a we have guys that, you know, go to MBA school at MIT to get these, you know, incredibly high level educations in supply chain management.

Paul Clark:

And you've got, you know, Amazon shaving off micro sense off your off your deliveries and off of the off of the various legs that it has to get to to go through. We've seen what the what the strait being closed has done to to global trade and and energy production or energy consumption. I mean, I just wonder, are there some black swans lurking in supply chain security that people aren't taking seriously?

Corey Ham:

Oh, without doubt. Without And the feedback

Paul Clark:

hoops that we could, you know, that we that we could get hit with out of the blue.

Matt Franz:

Just feel that makes you wonder.

Corey Ham:

Supply chain, not software supply chain. Physical

Wade Wells:

The point businesses. Would you count the colonial pipeline as a supply chain attack then? Almost like right? Cause it affected their billing system, which affected the supply, which I would say definitely. And then we've seen plenty of like, I think in the back it was like a Norwegian grocery store who had their inventory system completely hacked.

Wade Wells:

And they all their grocery stores went empty. I think it's crazy. Honestly, it it's probably a cool one to research that I haven't done enough on. But man, chickens, right? I'm I still can't believe that us with the chicken news is still a thing.

Wade Wells:

Like, I

Corey Ham:

made one joke about chickens, like, a couple years ago. Oh my god.

Paul Clark:

Didn't realize it was a recurring theme. Alright.

Wade Wells:

Oh, yeah. So what happened originally, it was an a lady got caught stealing over a million dollars worth of chicken wings.

Corey Ham:

Oh, yeah.

Wade Wells:

Like millions of during COVID. Yeah.

Corey Ham:

Now basically, was selling it out of the back of her car and some Well, they couldn't know. Yeah. They'll the COVID shutdown happened. And then they were like, why are we still ordering 200 k worth of wings every year? There's no school.

Wade Wells:

It was so many wings. They're like, how did you push this amount of wings? And then it would we I remember we even did the math on, like, how much per wing she must have been making. Like, it was it was lit. And then more chicken news just kept appearing.

Wade Wells:

And now it's well, I'm surprised we don't have a shirt yet.

Ralph May:

But just set that out there.

Corey Ham:

Yeah. Obviously, my freaking webcam broke again. But the they haven't disclosed the specific details of the cyber attack. I think it's safe to assume ransomware. They say, you know, they took they voluntarily shut down their systems.

Corey Ham:

And then that led to some stores having to close because no frozen chicken, no chicken wings, no no KFC.

Ralph May:

No KFC.

Corey Ham:

So unless you're vegetarian, in which case, I guess, you shouldn't be going to KFC in the first

Wade Wells:

Yeah.

Paul Clark:

It Also sounds good.

Ralph May:

Yeah. It is kinda interesting though. Like, we'll probably see more, like, supply chain style attack. I don't why do we after COVID, it was like everything was about supply chain after that. Like, we all realized that we lived in this go global world.

Ralph May:

And if one little thing happened, guess what? We're all out of toilet paper.

Corey Ham:

Exactly. I was about

Wade Wells:

to say, thanks a lot, toilet paper.

Corey Ham:

I mean, yeah. I mean, I I think it it's really interesting because it's kind of the shared responsibility model. But instead of going going to a third party, it's just no one. Yeah. It's just like, whose responsibility is it?

Corey Ham:

We don't know. We don't even know where we get these chicken wings because turns out the freezer runs an outdated version of iOS or whatever. And now, you know, it's like all these, like, you genuinely can't suss out all the potential supply chain concerns until it breaks and then you trace it back a 100 steps. Right?

Wade Wells:

Mhmm. Yeah. Well, we got quite a large amount of promos this

Corey Ham:

Yeah. We this week. Let's plug. Paul, you go first.

Paul Clark:

Yeah. We got SDR workshop for our workshop on Friday. Looking forward to getting that kicked off. We are gonna be kind of like taking the anti cast simple project that I started with. You see some remote controlled sockets are driving some lights back there.

Paul Clark:

And we're we're not just gonna demo it. We're gonna actually work through what it looks like to capture, decode, actually look at the bits, see what they do, take over. It's basically, it's your launch ramp to bigger and better things, but we just gotta hammer down some basic basic physics and some basic software so that we can attack the physical layer like we want.

Corey Ham:

I watched I was I've wrapped up the first season of Pluribus this weekend. And I don't know if you've seen that show, but it's a show basically,

Ralph May:

it's a

Corey Ham:

cool show. It's by the guy who made Breaking Bad. But there are some little bits in it where they're doing stuff with radios, and it made me wanna take out the STR and get fired up. Like, basically, it's an alien hive mind, and they may or may not communicate on a certain ultra high frequency, you know, that kind of Spoilers. Is is

Matt Franz:

GNU radio still a thing? I haven't used that for years.

Paul Clark:

So GNU radio is a thing, and I'm actually one of the things I'm gonna do in the in the workshop. I won't have a lot of time in four hours, but I will touch on it in a couple different points. One way you can think about GNU Radio is a way to build tools for your AI. And so the it's it's always been my contention that using these combo tools like Universal Radio Hacker, which is great, and we'll take a look at it, You lose the ability to automate. You lose the ability to write, essentially, radio code, so to speak.

Paul Clark:

If you start giving Claude or Codex a set of RF tools, can sometimes just be NumPy and Python. But interesting things happen really fast. And so this is why I think it's really important to build this foundation and understand, you know, what these waveforms are and what they're doing so you can intelligently construct the kinds of harnesses that are gonna let you do great things really fast.

Corey Ham:

Sweet. Alright, Matthew. Plug your stuff. It's coming later. Right?

Corey Ham:

It's not until August? You're talk at

Matt Franz:

Yeah. It's the summit. It's the summit. So, basically, you know, I was I was late to the whole MCP thing. I wasn't down with with MCP.

Matt Franz:

I was you know, MCP has a everybody was afraid. Right? MCP is the Telnet. MCP is the USB, you know, serial bus for models. But and I ran into this issue where I was and and all the all the vendors now, you know, CrowdStrike, SentinelOne, you know, they have the Purple AI MCP server, Elastic has theirs.

Matt Franz:

And then but if you don't have a vendor, you start looking around for the MCP server, and there's, like, some sketchy TypeScript MCP from somewhere. And it was just like, Okay, I don't trust this. How hard could it be to build it? Particularly with a really simple standard local, not using any web authentication, just standard input up and just for the functions I needed. And it turned out to be pretty easy.

Matt Franz:

And I built about 10 of them. About half of them are open sourced. I've been really investing in Elastic. I just did one for Velociraptor. OS Query is super easy way.

Matt Franz:

And I'll use that as an example of like a beginner, just the OS Query client to learn how to build it. And Go is even though, you talk about, you know, Rust being for hipsters, I actually prefer Go. Coding agents do a much better job. Rust is just too complex and the build time takes too long, even if you get a smaller binary. So I have prompts and contexts on how to build this stuff.

Matt Franz:

And I'll show some real examples because the other real challenge, if you're using a hosted MCP server for like, Google has theirs for Chronicle, SecOps, others like CoreLogic, don't have visibility into the queries, you can't cache, and you just can't see what and you're missing a lot of data, you know, and you're dropping and there's data truncation and then also context flow. So a lot of vendors are offering it, but it it it can there's a lot and there's a lot of downsides. And I've been just doing this as a fun project, but it's it's it's pretty straightforward, and that's what I'm gonna talk about.

Wade Wells:

Cool. So

Corey Ham:

Who else has stuff to plug? Wade, Ralph, Bronwen?

Wade Wells:

Bronwen does. I'll I'll go last. It's fine.

Bronwen Aker:

Okay. Yeah. Actually, during the AI summit, I have a workshop of my own. It'll be a four hour workshop after the summit proper, and it's gonna be all about local LLMs because my personal thinking is that the future of LLMs in cybersecurity will be local, and at some point, we'll be doing a lot of a lot more development of individual things anyway. So you'll set up you've got two, LLMs.

Bronwen Aker:

You'll be having them talk to each other using Tailscale. You'll set up and configure your own custom LLM, all kinds of fun tips, tricks, and traps.

Corey Ham:

The key is to know how to do this. You you got, like I'm

Bronwen Aker:

gonna show

Corey Ham:

you. You cannot depend on like, highlighted it multiple times in this episode. You cannot purely depend on third party providers. Even if Yes. You still have $200 a month for Claude every month for the next ten years, You still wanna at least know how to do it yourself if you have to or if you want to.

Corey Ham:

And there are specific cases where a local's private LLM can be more powerful than a frontier model because every tool is a different tool for a different job.

Bronwen Aker:

Well and and part of setting this up the way I did is also to provide future expandability because once you've got your your primary LLM server and then you can, you know, hook up NGN X to it and and well, cripes, using Tailscale. From that point, you can connect to it using almost anything. And if you don't even if the information you're trying to protect is so secure that you don't even want to use tail scale, you can use head scale. So we're gonna talk about lots of ways to make sure that you can build something where, yeah, you can attach a rag stack to it in the future. You can customize the models to meet different specific populations within your organization.

Bronwen Aker:

You can do all of this stuff, and you can keep it entirely within your infrastructure.

Matt Franz:

Yeah. And some of the new, like, pi PIDEV's coding agent actually kinda works with small models, whereas I've tried to run Cloud Code with the llama models on a Mac Mini, and it's just like Yeah. The tool calling and the the context windows are just too small. But some of the the the microcoding agents are actually starting to get okay with smaller models. Yep.

Matt Franz:

Cool.

Corey Ham:

Ralph, you have a wireless training environment

Ralph May:

Yeah. Yeah.

Corey Ham:

I just thing that you released.

Ralph May:

Yeah. Yeah. It's totally free. Wireless training, It's it's a Tala. And we actually built a a Wi Fi attacking platform.

Ralph May:

And this actually gets into a really interesting thing that Paul brought up, which is about building feedback loops into wireless or into RF and specifically with AI agents. And so what we built, right, is the wireless testing lab. And the whole point of this is to attack it. Right? So you can learn how wireless works and go through the all the process without having to manually build up all of these things.

Ralph May:

Right? So it's full documentation. The code is open source. It's free to use. So you can if you wanna ever learn how to do any Wi Fi testing, it is all in there.

Ralph May:

Any kind of network from WPA two, three, enterprise, all of that stuff, it makes it super easy

Corey Ham:

to set up. So yeah. Kinda cool. So take SDR, combine it with this, and you get a fun little combination of chaos.

Paul Clark:

Oh, yeah. Yeah. This is Super important question. It says, talla means wolf. What language?

Ralph May:

What's up?

Paul Clark:

Talla means wolf. I see it on the screen here. Like, what language is that? What language is what? Talla means wolf, obviously.

Ralph May:

Oh, this is I I think it's written in Go.

Corey Ham:

No. Language. The word What

Matt Franz:

human language?

John Strand:

In what place

Bronwen Aker:

we each does it mean wolves?

Ralph May:

Oh. Oh. Shoot. I can't remember what it was. Travis is actually the one who who put this one.

Ralph May:

That's alright. Can look up.

Corey Ham:

Listen, It's several Native Americans. Native American. There you go. Ralph is more of a kick down the door guy. He's not he's not on the he's like john where he's gonna have typos, you know, it's just, you know, not language.

Corey Ham:

Good to know. Alright, wait, wait,

Wade Wells:

but I'll do so I'll do the two. I'll do the Wild West Hackin' Fest, Deadwood is in person. It's almost sold out. So if you need to buy your tickets soon, get them. Virtual tickets are still available with the training combo.

Wade Wells:

Right? So if you wanna do virtual and training, you can go for it. So make sure you get on that. Then I also wanted to plug DeathCon, which is detection engineering and threat hunting. This is also a both virtual and in person conference.

Wade Wells:

I actually run the San Diego DeathCon. So if you want to come out to sunny San Diego and hang out with me for two days, definitely do it. There are this is like a worldwide conference. So if you are even not in The US, there are several different venues for it. So highly suggest checking it out.

Wade Wells:

The last this like, the one thing cool thing about this conference is it's no talks. Well, there's everything hands on laps. So super cool if you're really into learning and want to actually do things.

Corey Ham:

Ew, I hate learning.

Wade Wells:

I know. Ryan Ryan also wanted to say training in person combo tickets are still available while I'm less hacking fest. So make sure you guys go. I haven't been in

Corey Ham:

a while. I feel bad. But No. He's calling out.

Matt Franz:

No. East Coast.

Wade Wells:

No East Coast? I'm surprised there's no one on the East Coast. There's a Florida one. There's Orlando.

Bronwen Aker:

Yeah. That Florida one. Come

Ralph May:

on, man. We're like the bottom of the state.

Wade Wells:

You can that'd even better. Come out to San Diego. San Diego in November. It'll be fine. So

Bronwen Aker:

San Diego in November is nice.

Corey Ham:

Yeah. That's where you wanna be in November. Alrighty, y'all. I think that's everything. Thanks for listening.

Corey Ham:

Have fun with your tokens, and we'll see you next week.

Ralph May:

Maxim. Alright. Thanks tokens.

Wade Wells:

Have a

Corey Ham:

good one. Oh, I can do that. Think I need a new laptop. I don't know what's going on with my Thunderbolt dock. It's

John Strand:

Oh, dying. This

Corey Ham:

is a fancy one too. I have the t s five. I just got it. I don't know why

Ralph May:

TS five? Dude, I know.

Corey Ham:

These Thunderbolt docs cost more than my first laptop does.

Ralph May:

I know. Right? I I actually had a problem with I have one of the studios, and I bought it before it got crazy expensive. Anyhoo, but only certain ports are actually Thunderbolt. Right?

Ralph May:

That's the thing I actually Yeah. Just because of USB C, and I know I get it. Look.

Paul Clark:

But It's

Corey Ham:

a laptop, man. All the ports are the same.

Ralph May:

I I On the MacBooks, I think all three are Thunderbolt five on all.

Corey Ham:

Listen, Ralph. Do not talk me out of using this as a fake excuse to get a new laptop.

Ralph May:

Yes. Give it Yeah. Yeah. Can make sure.

Wade Wells:

I'm also sure.

Corey Ham:

Hold on. What m five

Ralph May:

is crazy? Is it m is it m one?

Corey Ham:

No. It's m two.

Ralph May:

Oh, losing dude, m five is so much faster. Oh, m five

Corey Ham:

is so much faster.

Paul Clark:

I'm about to

Corey Ham:

go to John Strand and beg for a freaking massive m five max fully maxed out. It cost more than my house.

Bronwen Aker:

I'm I'm I'd be happy just to have him get me a one of the GTX things.

Wade Wells:

The smartest

Bronwen Aker:

part has gone from, like, 3,600. Yeah.

Ralph May:

Oh, yeah.

Bronwen Aker:

3,600.

Ralph May:

No. I know. I bought my laptop, the m five, like, right before the whole stuff went crazy. Like, I mean, Apple re raised their price on that.

Corey Ham:

Yes. Apple just increased all their

Ralph May:

prices. Yeah. And so, like, I feel, like, lucky. I'm, like, I'm holding on. I my my my studio has got a 128 gigs of RAM.

Ralph May:

I feel like a rock star. I'm like, I'm a millionaire over here too.

Corey Ham:

Yeah. It's basically a DJX Spark. No. It's basically it's basically my retirement plan.

Wade Wells:

I'm just holding to that RAM.

Ralph May:

No. No. No.

Corey Ham:

That's the hard drives in the home lab. That's the last

Ralph May:

Oh my god. Dude. Oh my dude, I have sticks of RAM in here that are worth over a thousand dollars apiece now.

Corey Ham:

So dumb.

Ralph May:

Oh my god, dude.

Corey Ham:

I know. I was looking at replacing some drives. I was like, nope. Not gonna replace any drives. Just gonna have to wait.

Ralph May:

I'm like, I'm gonna have to ride everything out. And luckily, I I I bought way too much. Like, I was like,

Corey Ham:

oh, I don't know this. Yeah. Mean The murder pays off when they're

Ralph May:

I I need a terabyte of RAM. It's it's gonna come in purpose for something. And now I'm

Corey Ham:

just like, I just need to have Yeah. It's your retirement. It's actually your retirement.