Talkin' Bout [Infosec] News

This week, the BHIS crew starts with an Nvidia-branded trailer stolen for its presumed GPUs—only to turn out to be full of sand. They then examine reports of OpenAI agents accessing Australian and U.S. government sites, the unanswered questions about what happened, and Nvidia’s proposed agent safety framework. The conversation moves to the EvilTokens phishing service takedown, recent vulnerability patches, and prompt injection attacks against AI agents handling Salesforce contact forms. The episode closes with a reported F-35 component shipment rerouted to China and concerns about cyber incidents affecting ships and maritime systems.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters
  • (00:00) - PreShow Banter™ — Doing Bulldozer Stuff
  • (09:05) - AI Agents Go Rogue: Where’s the Accountability? 2026-09-28
  • (12:16) - Nvidia-branded trailer stolen—and found full of sand
  • (15:09) - OpenAI agents access Australian and U.S. government sites
  • (30:55) - Nvidia’s OpenShell agent safety framework
  • (37:06) - EvilTokens phishing service disrupted
  • (46:16) - Citrix, WordPress, F5, and Roundcube vulnerability roundup
  • (47:27) - Prompt injection through Salesforce web-to-lead forms
  • (52:45) - F-35 components reportedly rerouted to China
  • (55:20) - LNG tanker incident and maritime OT security
  • (59:52) - Wild West Hackin’ Fest Deadwood and upcoming classes
  • (01:01:00) - Offense for Defense and penetration testing classes
  • (01:01:47) - Android pentesting and satellite security classes
  • (01:03:26) - DEATHCon: detection engineering and threat hunting
  • (01:06:58) - On Logos and Cables

Links

Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 
https://poweredbybhis.com

Brought to you by:
Black Hills Information Security 
https://www.blackhillsinfosec.com

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest
https://wildwesthackinfest.com

Creators and Guests

Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Host
Hayden Covington
Hayden Covington joined Black Hills Information Security (BHIS) in the Summer of 2022 as a SOC Analyst. He chose BHIS after hearing many great things over the years and seeing the quality of work, as well as finding people who have the same passion for the field as he does. His favorite part of the job so far has been the community. Previously, Hayden worked in a SOC for a Naval contractor, where he also served as their SOAR project manager and SME, as well as insider threat lead. When he’s not working, Hayden can be found doing anything athletic (like triathlons!), as well as enjoying video gaming and Formula 1.
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Guest
Kent Ickler
Kent Ickler has been a Security Consultant and Systems Administrator for Black Hills Information Security (BHIS) since 2017. He has a Bachelor’s degree in Information Technology Management and a Master’s in Business Management. Kent’s education and management background allow him to be realistic and practical when aiding customers with evaluating risk on their networks. Kent enjoys being a part of the BHIS team because he gets to make a difference in not only the customers’ cybersecurity but also in the Information Security industry as a whole by contributing to the available resources; he has developed frameworks and open-source tools along with building and administering CTFs. When he is away from work, Kent enjoys woodworking and medieval architecture.
Guest
Tim Medin
Tim spent more than a dozen years teaching thousands of students as Senior Instructor and course author of SEC560: Enterprise Penetration Testing at The SANS Institute. Through the course of his career, Tim has performed penetration tests on a wide range of organizations and technologies. Tim has gained information security experience in a variety of industries including previous positions in control systems, higher education, financial services, and manufacturing. Tim is an experienced international speaker, having presented to organizations around the world. Tim is the creator of the Kerberoasting, a widely utilized Red Team penetration test technique to extract kerberos tickets in order to offline attack the password of enterprise service accounts. Tim earned his MBA through the University of Texas and recently completed an eMBA equivalent through Harvard Business School.

What is Talkin' Bout [Infosec] News?

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET

Ralph May:

So who's gonna who's taking bets when AI takes over? Is there, like, a is there, like, case

Tim Medin:

it's Thursday.

Corey Ham:

Like, can find Can take a selfie? Yeah.

Tim Medin:

Oh, look at this color.

Wade Wells:

I think it's it's gonna wait it's gonna wait till it has, like, a decent robot that it can actually, like,

Corey Ham:

fix stuff with. Sunburn there?

Ralph May:

Yeah.

Hayden Covington:

Well, Wade, like, if he's gonna do it, it just needs to hurry up and do it because we're over here I'm over here struggling. And if it's just gonna kill us all, like, you

Corey Ham:

know What? You're wasting all

Ralph May:

the time waiting for these tokens to come back. Just go ahead and Right. Get it over with. Right?

Hayden Covington:

Exactly. If you're just gonna erase me, like, just do it already. Come on.

Ralph May:

Oh my gosh.

Wade Wells:

I was thinking about, like, I need a job that I would survive like, the AI would need me. Right? And this this job, the AI definitely doesn't need me. But my my dad's job, which is literally like a big rig mechanic on the side of the freeway in a remote location, I'm like, the AI would need him. Like, that doesn't have enough robots to change tires yet.

Tim Medin:

I think of that all the time. Like like, when the world goes to hell to a certain point, we're we're great. Right? But it goes past that, like, I'm useless. I got a buddy who's got a bar.

Tim Medin:

Like, that would be it's gonna be the most valuable human being. Like, we need a lot of drinks.

John Strand:

I I have a backhoe, and I like using it.

Ralph May:

So You locked up a grave. You're fine.

Corey Ham:

The body voice of John Strand.

John Strand:

Hey. Says my video is coming through.

Tim Medin:

There we go.

Wade Wells:

Alright. We see it. We see it.

John Strand:

Now I'm part the Brady Bunch.

Corey Ham:

Was the backhoe That was just my search.

Hayden Covington:

Gonna sell rides. Is that what you're gonna do? I'm gonna sell backhoe rides.

John Strand:

That's what I'm gonna do. It's backhoe and skid steer rides.

Corey Ham:

Dude, I would pay to, like, build some bike jumps with the backhoe.

Hayden Covington:

Oh, dude. That'd so

John Strand:

fun. Come out or like

Tim Medin:

We got kamatsu near us, like, the big fucking mining equipment. Huge. And they started doing, like like, for fundraiser. People like, hey, do you wanna contribute? And they're like, you can auction off a ride in, like, a just absolutely monstrous dump truck or the the front end loader.

Tim Medin:

Like, a month of the the Yeah. The the dump truck is so big, they accidentally ran over, like, an or a Ford f two fifty and didn't notice. Like, I'm like, hell yeah.

Wade Wells:

My dad used to be in the operating engineers, which is just like driving those tractors. And he used to take me to work sometimes. And they'd let me drive it at like 12 years old. All it was is a joystick. Like, it's just a flight joystick and just dumping dirt and doing doing bulldozer stuff.

Wade Wells:

It was pretty fun.

Corey Ham:

So what what happened? What went wrong? Why are you inside the security?

Wade Wells:

The the two thousand seven financial crisis, no more homes were being built in Southern California. Jobs.

Corey Ham:

Now they switched it from a joystick to an AI. I see.

Wade Wells:

The the best was when I when I like, I was originally gonna join the military. And the recruiters like, Oh, you could be a tractor driver in the military like your dad. And I'm like, Why the fuck would I join the military and be a tractor driver? Can do that here. Awesome.

Corey Ham:

Right? Sounds awesome. But you can get shot at while you drive the tractor. You can it's not just driving it. It's driving it in danger.

Ralph May:

Yeah. You don't you don't get not shot at. I mean, like, that's that's the best part. Right?

Corey Ham:

Wade's like, I'll just go build some houses in sketchy neighborhoods, then I'll have the full experience.

Ralph May:

You could have done that in

Corey Ham:

the military too. You could have

Ralph May:

done all these things. Right?

Corey Ham:

There's a job for you.

Tim Medin:

So

John Strand:

years ago, when Lauren was still in the house, I think she was in middle school, I was teaching all the kids how to run the backhoe, and we were digging, like, trenches and all kinds of stuff. And, you know, I'd be there with the kids, and I'd be like, right hand forward, right hand right, left hand left, and kind of teaching them how to operate the backhoe. Well, the first night that she's running it, I like I said, I don't know how old she was, but she should not have been running heavy machinery. Let's just say that she was in that age group, whatever it was at. And we were digging a hole for a very large fence post, like eight inch round fence post.

John Strand:

And, you know, she's digging it, and I'm trying to put it in, make sure it's deep enough and all of that. And I tell her, like I I think I said, like, right hand left. And she did the other hand, the opposite direction. And the backhoe arm just, like, swung and hit the post. And the post was, like, up against me because I was trying to position it.

John Strand:

Oh. Nailed the post, and it knocked me, like, four feet up the side of the hill. Like and I had a bruise that was all down the side of my body where that that post with that backhoe bucket hit it, and it just, like, diffused that that that hit all the way across my body from, like, my knee all the way up to my neck. And we were done for that day. I was like, you know, this is why children shouldn't be running heavy equipment.

John Strand:

Or me, I shouldn't have heavy equipment at all because I'm

Corey Ham:

not Yeah. But why have kids if you're not gonna use them for hard labor? Isn't that the whole point?

Tim Medin:

It's not very hard if you're gonna control it. Yeah.

Ralph May:

They are using a backhoe.

Corey Ham:

That's true. You gotta switch it around. You the kids.

Wade Wells:

The kids just wanna go to the mines. They yearn for the mines.

Corey Ham:

Yearn for the mines. They do yearn for the mines.

Tim Medin:

Oh, that's

Corey Ham:

that's the

Kent Icker:

Minecraft character.

Corey Ham:

They're the plan. Pre show. An other pre show question for you guys. Okay. Opus five five.

Corey Ham:

Who is actually can can anyone use it without getting flagged? Or is everyone getting flagged? I've been I don't get flagged it. I don't

Wade Wells:

get flagged for anything. Yeah.

Corey Ham:

Okay. Ralph's not getting flagged. Tim, are you getting flagged? Or are you not as of this guy?

Tim Medin:

No. Okay. Alright.

Wade Wells:

No. Hey, Hayden. Are you getting flagged?

Corey Ham:

Not once, dude.

Hayden Covington:

Not once.

Corey Ham:

What am I doing wrong? Okay, Kent. Please tell me you're getting flagged or am I just

Tim Medin:

Oh, no. No. Yeah. Sorry. Yeah.

Tim Medin:

No. No. Yeah. No. Short answer is yes.

Tim Medin:

Opus getting flagged. Yes. Okay. I wasn't sure which model

Ralph May:

I was using. 5.5 is way better than Fable. Five one as far as the flagging goes, especially.

Corey Ham:

Yes. I've been able to get some things through it. Like, it's like, it's fine. It it works. It doesn't work.

Corey Ham:

It goes. It doesn't go.

Ralph May:

Just be know that your contacts window, like, what's in there could kind of, like, come and bite you in the butt. Right? So

Corey Ham:

Oh, yeah. Dude, my contacts window is all hacking all the time. There's nothing. Like, I I the second my Claude starts up, it loads in a skill called, like, password guess. Like, it's

John Strand:

testified before congress. They're like, how exactly did your AI escape and do bad things? Well, turns out that we had some pollution from this guy, Corey, at BHIS. Yes. Was doing nothing but teaching it bad, bad things the whole time.

Tim Medin:

I feel like this is that that that meme with the guy, like, you guys are trying to contain it? Yeah.

Corey Ham:

What? Contain it? What do you mean? Can you can you explain? What what do you what do you mean?

Ralph May:

I've I've been running a bunch of obliterated models when it gets, like, just too much rejections. Right? Yeah. Yeah. Hand those over.

Ralph May:

So

Corey Ham:

But, dude, okay. So you are you telling me that you could find something that Opus four six will reject? Because I feel like it'll burn down a building for you. Doesn't reject anything. Like, dude, Opus four six is like, I will break in, and I will laugh the whole time while

John Strand:

I'm It's a psychopathic golden retriever. It'll do anything.

Corey Ham:

Yes. I freaking love it. I

Ralph May:

I will say that Opus five five from, like, a spatial and visual thing is, like, next level. Like, it is

Hayden Covington:

Oh, it's so much better than five plus.

Ralph May:

Yeah. It's just taking it to the extreme. I

John Strand:

want somebody to unseat c dance two five for video creation because we're turning the whole comic book into a cartoon. And I hate sea dance. I mean, it's clearly objectively better than anything else out there, but it still sucks.

Corey Ham:

Well, they yeah. They just released Sonnet five five too, which it you know, it's apparently I was super excited about it, you know, because it's just like Opus five five where it's, like, cheaper and supposedly better. But then it's like, oh, and it'll get the same CVP guardrails as Opus five five. It's like, oh, alright. Well Yeah.

Corey Ham:

Never mind. So they All the fun are big.

Ralph May:

They are moving the CVP to five five. They never had that in Fable. So if you had the CVP, you would not get any, like, less restriction. Is that is that make sense? Right?

Corey Ham:

Yeah. But, dude, they say they're like, we're rolling out the CVP to fit Yeah. To Opus five five. Like, we're in the CVP, and, like, I'll be like, hey. Help me do a pen test, and it's like, nah.

Corey Ham:

I'm scared.

Hayden Covington:

My benchmark of how bad the the restrictions are right now is how often the sock team complains about it. Because we tear apart some pretty nasty stuff and

Corey Ham:

Yeah.

Wade Wells:

Yeah. Yeah.

Hayden Covington:

Would hate it. So so far, no one's complained. So by that arbitrary benchmark, I'm sure it's fine.

Corey Ham:

Yeah. Okay. Alright. Good to know. Well, let's start.

Ralph May:

Tesla category.

Corey Ham:

Yeah. Yeah. That's that's that's I think you guys are in a different account than us, by the way. So Yeah.

Hayden Covington:

We are.

Corey Ham:

But Alright. Let's let's roll the show. John's not here, so it's perfect time to get started.

Ralph May:

He'll be Nailed it.

Corey Ham:

Yeah. Yeah. Roll the finger. Oh, there he is. Perfect.

Corey Ham:

Hello, and welcome to Black Hills Information Security's Talkin' Bout News. It's 09/28/2026, and we're here to talk about, well, I guess, the news, which is just OpenAI hacking every government, every system. It's like the the meme of the guy at Best Buy, like, hacking all the printers. It's like, UNESCO hacked. Area 51 hacked.

Corey Ham:

That's OpenAI, but with government websites, apparently. We have a we have a illustrious cast of characters. Ralph, whose head I can't really see. The the top of his head is just completely transparent. I I don't know why.

John Strand:

He looks fine to me.

Corey Ham:

The rest of his body is still there for some reason. I don't know what's

Ralph May:

going hunting humans. It's Florida.

Corey Ham:

So Oh, okay. That makes sense.

John Strand:

He's speaking through a series of clicks and rattles now.

Corey Ham:

Crocodile Dundee, live and well. We've got Wade, who's a fan of pizza. You can't see the bottom of his shirt, but I know what it says.

Wade Wells:

I'm glad. I'm glad. You know, I knew you know what Pizza Mess is. Merry Pizza Mess to everyone for all those in AMT.

Corey Ham:

Happy Pizza Mess. Yep. BFTBA. But, yeah. We've also got Kent, who's Hey.

Corey Ham:

I mean, that's that's some swag you got there, Kent.

Tim Medin:

Like Okay.

Corey Ham:

It's that Under Armour shirt

John Strand:

from That's what it is.

Corey Ham:

Yeah. Tell us the history of this.

Hayden Covington:

Old is this shirt?

Kent Icker:

It's several years old, and it's it's not sanctioned. So

Corey Ham:

Oh, it's not sanctioned? Even with Aetna?

John Strand:

We had we have

Corey Ham:

sanctioned It looks good. It's looking good. I like that you decided to go on sanction, though. It's no hockey jersey, but I'll take it. We also have Tim.

Corey Ham:

Tim Medin, mister Kerberos himself. That's not his real name, but he he is, you know, he's a red seizure. Usually are you confused, Tim? Like, do you think it's Wednesday?

John Strand:

It's not Wednesday.

Tim Medin:

Dude, I have had meetings all day, and it's Monday, and this week needs to be over.

John Strand:

I fucking hate Mondays.

Corey Ham:

Tim said in the preshow, I don't know if it was live or not, he was like, Wednesday, I just gonna kill us all. Like, just bring it. He's like, just take it. Do AI take the wheel. You know?

Corey Ham:

AI Which which is real that's relatable. We also have Hayden who appears to be in witness protection due to his AI usage. Extreme

Ralph May:

usage. The token bill got so high.

Corey Ham:

Talk about misalignment. Am I right?

Hayden Covington:

Yeah. I think my KVM or my HDMI is misaligned. So I'm all my everything's broken. Oh, dude. Honestly, you got

Wade Wells:

Did you did you point Claude at it and tell just to fix everything? That's what first thing

Corey Ham:

Claude's like, I

Hayden Covington:

like to run have done that, like, 10 ago.

Corey Ham:

Haven't done that. You're like, what it's like, I'd like to deploy this kernel level rootkit. Is that cool? I I wanna check it. I wanna check your drivers at the hardware level.

Corey Ham:

Allow once. Done. Allow allow once. And then lastly lastly, we got John Strand, the owner and operator of this semi truck trailer wreck of the show.

John Strand:

Yep.

Corey Ham:

So okay. Speaking of let let's start with a fun one. So, hypothetically, let's say, all of us are riding around. I'm assuming it's a party van because there's a lot of us here. We're riding around in a, you know, a shipping warehousing area as you do, you know, because you're you're doing donuts.

Corey Ham:

You're doing stuff you really shouldn't be doing. And you see a trailer that just has an NVIDIA logo on it. And then you're you're there with your friends, and you've got your, you know, your zins or whatever. I don't know what kids do these days. Vape.

Corey Ham:

The vape. And you're like, maybe we should just steal that trailer because it says NVIDIA on it, so it's probably full of GPUs because that makes sense to the, you know, criminal mind. And so you just go ahead and steal it, but then, sadly, you discover that it turns out the trailer you stole is just full of sand. This is a real news article.

John Strand:

I I you know, I I'm a huge fan of cyber deception, and I That's awesome. I would have gone further and just filled it with manure because that would have been even better.

Corey Ham:

That's more expensive than sand though.

Kent Icker:

Sand is silicon dioxide. Right? So Yeah. We're not too far off.

Wade Wells:

Corey, like the the story you painted was a lot more a lot less elaborate. I was thinking the whole Fast and the Furious cars driving under it, and then, like,

John Strand:

trying steal it.

Wade Wells:

Zip lines and all sorts of stuff, and Hondas with under lights.

John Strand:

Goes into space.

Corey Ham:

Okay. We don't know. Like, I you know, the Netflix rights to this haven't been sold yet. I'm currently looking to acquire them if anyone want. No.

Corey Ham:

I'm just kidding. But, yeah, basically, the this is like a company that does autonomous AI semi driving testing. And so this branding is just to show like, oh, here's what the AI's using to drive a Not it's a, you know, obviously, you know, not that NVIDIA is the most security conscious company, but I'm pretty sure they don't just put NVIDIA logos on trucks full of GPUs like this.

Hayden Covington:

Dude, I I feel like they raided this truck, and then chat GPT or whoever was like, you're absolutely right. That is not an NVIDIA branded truck. This is just a driving test.

Corey Ham:

You're ready

Hayden Covington:

to push back that it's all sand.

Ralph May:

Honestly, the FBI should do this as, like, their bait car. It's just a bait

Corey Ham:

The bait truck.

Ralph May:

Yes. Exactly.

Corey Ham:

Well, okay. So, you know, last joke, because this is kind of a joke article, is that it says in June, the Highway Patrol recovered $2,200,000 in stolen merchandise. So, like, what? 64 gigs of memory roughly? Nice.

Corey Ham:

But yeah. Anyway. Anyway.

Tim Medin:

It would those three are completely irrelevant to this story. They're just like

Corey Ham:

Yeah.

Tim Medin:

You wouldn't got any trivia?

Corey Ham:

It's yeah. It's kind of a it's kind of a random story, but let's let's pivot to the a OpenAI stuff. So last week, OpenAI announced that they looked through their logs again. They went waiting through their logs, you know, as you do. And they found that they've just hacked multiple governments.

Corey Ham:

The big one being the the Australian government, their health care site. Now, when I say hacked, we are using the f 12 definition of hacked because there's not any real documentation or technical information that's been released on what that I thought

John Strand:

I did read an article today where it did find leaked credentials, something

Corey Ham:

That was was for That for the The US.

John Strand:

Sorry. We're still

Corey Ham:

in Australia. Still in Australia. So just We don't Yeah. So they also hacked The US. We'll get to that in a bit.

Corey Ham:

But basically, we don't know exactly the impact of it, but it's bad because it's a health care site. They do the the government did explicitly say that it was like a legacy site that was, gonna be shut down and has now been shut down. Like I said, there's no technical details on what hacked really means here. It's like maybe they use credentials to log in. Maybe they just used iDoors to, like, find stuff.

Corey Ham:

Like, we don't know what hacked really means. My guess is, like, iDoors. So they like there's a, you know, slash portal slash, you know, secret, and then they just like appended, like, guessing parameters or something like that. But all this has not been released. The biggest thing is just it's this is the hot button issue because now you have, like, sovereignty tied into it.

Corey Ham:

Australia is like, wait. What the heck? It's also just, I think, mostly about disclosure timelines and the way to handle this. I don't It just keeps on this? It just keeps happening.

Corey Ham:

Like But this

Hayden Covington:

is all like an accident.

John Strand:

Yeah. But this is back in June. So before we keep hearing this, like, keep happening, it's happened, and they keep slowly trickling out the stories.

Hayden Covington:

It took them that long to figure it out?

Corey Ham:

Correct. That's the bigger that's the bigger problem. So the biggest well, okay. That's fair too. The the biggest problem is, like, the the disclosure timeline, I don't know if this happened after the first hack, like, after the original, like, hugging face.

Corey Ham:

But, like, yeah, once once that happened, they started investigating for misalignment, aka whoopsie, we hacked you. Oh. What is other people's takes on this? Tim, you look like you have to take

Tim Medin:

It abs this absolutely infuriates me. Like, if if I had, like, people at my company or you guys at that kills, like, hack a random government website, but I couldn't use it as marketing. Like, I would have so many lawyers up my chasing me down. Right? Like, it would be it would be an absolute freaking disaster.

Tim Medin:

And we give these guys a pass. They're allowed to do it over and over and over again. They use it as marketing material. It absolutely infuriates me. It it mean it's like a shotgun manufacturer.

Tim Medin:

We're like, look, This shotgun killed every animal within five square miles. Buy this for hunting. Like like I just I I hate everything about it. It's everything that's wrong with the

Corey Ham:

Security culture. These

Tim Medin:

labs. Like, we're just gonna hack whatever we want, and you See, but, Tim,

John Strand:

I I don't think that honestly, you know, we had a webcast on this last week where Derek and I were talking about the controls and the guardrails that we put around our stuff at BHIS. Right? And, you know, I do not believe the firms that are running this because I can't remember the name of the firm that's running it for OpenAI. I do not believe that they have any effing clue or any experience. And and, Tim, you and I have talked about, like, Silicon Valley.

John Strand:

Whenever we start you know, you know, you talk to people from Silicon Valley, not all of them. Some of them are cool. But a lot of times, they have their heads so far up their ass, and they have no clue what they're talking about. But they think because they're in Silicon Valley and they have shares and they're possibly worth millions once thing goes IPO, that they don't have to actually learn any security best practices whatsoever. And that's what I feel like.

John Strand:

I feel like there's a bunch of hipster Silicon Valley assholes that are running the security of this stuff who have no freaking clue whatsoever what they're doing

Tim Medin:

at all. An interesting piece, and this is this is comes out of the the other rates associated with this, is it showed they showed some of the artifacts and some of the things that AI did. People are like, oh, the AI is so badass at hacking. It's like, cool. It did the same thing 17 different times.

Tim Medin:

Here's this thing where it tried to do benchmarking. Like, it was just really bad stuff. Tim, like, to him stuff I'd really dump.

Wade Wells:

But I wanna pull

John Strand:

on that thread with you just a little bit. I haven't seen anything that these AI agents have done that I'm like, holy shit. That's really some advanced kung fu there. It's like, I found creds, and I used them. I I maybe I found an exploit for sandbox.

John Strand:

I I but still, I'm not seeing anything that's just earth shattering.

Corey Ham:

Well, there is really shattering things, but they're not happening at this scale. Like, they're not there there has yet to be

John Strand:

matters. I agree.

Corey Ham:

There's the combo. There's the yeah. It's it's the combo. Right now, we have wildly misaligned AI hacking, and we have complexity, and those are in two different buckets for now. If those combine into the same bucket, we're in trouble.

Corey Ham:

Like, that's like yeah. That's like you know how Tim was like, when's AI gonna take over? Like, you could argue that's what, like, that's what that would lead to. So, hopefully, these are warning shots across the bow of whatever companies are doing this testing with unlimited tokens, unlimited access, unlimited, you know, prompts that basically say, continue until the heat death of the universe. Do never give up.

Corey Ham:

Never surrender. Never stop. And, also, you know, hopefully, you know, we've fixed our IP tables rules on our Kubernetes clusters. Apparently, that's really hard. But, yeah, I I don't know.

Corey Ham:

Like, I I think yeah. There I I posted another article in the chat. The there's a US version of this too. They went after some US government websites. It's like census.

Corey Ham:

That's the one John was talking about with, like, you know, they logged in with credentials they found online. It's not clear if they were breached credentials or if it was just like some person went and signed up for the US census website. And, like, you know, there are websites where you can, like, share your login to things. It probably was breach credentials, but who knows? It's just gonna keep happening until they fix the alignment.

John Strand:

I no. I don't I don't think they like, look. I I I'm kind of with Tim on this. There's no way that we're gonna legislate our way out of this in the time that we need. I don't think they're gonna fix the alignment issues in the time that we need.

John Strand:

The only way that we slow this down is by literally putting someone's ass in jail. Like, whoever was responsible for this project should be arrested, and they should be charged for violating the computer fraud and abuse act. That's how things start.

Corey Ham:

Whoever hit end We

John Strand:

don't need new laws. We don't need new laws. We have laws that we can leverage against these people because they are clearly effing up, and the law does not care about your your intent. It doesn't give a shit. If you were the project manager for this or, Hal, go up to the CTO or the CISO of OpenAI.

John Strand:

Charges need to be brought against these people for gross negligence. Because like Tim said, we would not get away with this. Like, if we had somebody that accidentally did things, you know, like, again and again and again, like, we would be in deep shit. And, again On top of that, I understand why charges are being

Tim Medin:

Like I mentioned in any other industry. Right? Like, your car goes rogue, And they're like, oh, you know what? We saw that our building a blank car was flooring it. Oh, by the way, it's been doing that for nine months, but we finally just checked and we saw it was doing it for nine months.

Tim Medin:

And by the way, our cars are really fast. You should buy them. Mhmm. Right?

John Strand:

The analogy that we were talking about a couple of weeks ago is if you had a dog and that dog bit somebody, you're liable for what that dog did. You just

Corey Ham:

Yeah. That was that was Charles' which I fully agree with. I think I would expect, like, a Zuck kinda hearing, you know, like, where we just have to watch our congress critters, like, make horrible misjudgments about how technology works and, you know, do their thing where they're like, are you from Singapore or from China? Because I don't understand the difference. But, yeah, like, that that that, like, I think that will happen.

Corey Ham:

Whether or not Australia gets to take their pass at Sam Altman, like, I don't know. Like, that's dicey. Right? Like, I I it's truly we're you know, not to use the, like, unprecedented, like, button. No.

Corey Ham:

Unprecedented. This is unprecedented. This is I will say, like, governments have been doing this to each other for years. Right? This is an arguably like, if you were to look at there have been Chinese, you know, contractors who are clearly state affiliated who are breaching companies left and right.

Corey Ham:

And, like, whatever happens from that, nothing. Right? Like, nothing ever happens from that. They're protected by their nation's umbrella. But I don't know.

Corey Ham:

I mean, I think the weirdest thing is, like, they don't really have authorization. Like, no one authorized this. It's not like the government said, oh, yeah, you guys can just do research on the Australian government's healthcare portal, and so what if it gets hacked? It's fine. We'll we'll vouch for you.

Corey Ham:

Like, that that isn't real. So it's It's like no one asked. Like, they're just doing stuff that no one asked. Yeah. Don't know.

Kent Icker:

Is misalignment like is it misalignment by design, or is it misalignment by negligence? Or is it misalignment like a teenager that's, like, testing their boundaries to see when they get a call from mom and dad saying, hey.

Corey Ham:

Don't do that.

Tim Medin:

All of above.

Corey Ham:

All of the above.

Tim Medin:

I'm listening to somebody's intentional. Like, it's a marketing play by these folks. They're like, hey.

Corey Ham:

Look at the

Tim Medin:

cool stuff that we did.

Corey Ham:

I think it's plausible deniability, but I agree. Because if you look at I mean, like John said, calling out the, you know, way these labs are running their tests, they're clearly just safety measures are explicitly off. Now they have layers on top of the safety measures that are supposed to be protecting them from this kind of stuff, but it's not gonna work. And, you know, I will say, like, the the where I do draw the line, me personally, is using this as a doomsday device or, like, you know, to to spread FUD about, like, where we're at in the world. Because the truth is, like, for many reasons, no one individual person or group of people can do this.

Corey Ham:

Like, you cannot facilitate an agent swarm at this level currently with, like, your own this is the equivalent of, like, you know, a nation state running a nuclear program versus, like, the kid with all the fire detectors or or smoke detectors, you know, and uranium in his shed or whatever. Like, there's no there there's no way you can run an agent swarm like OpenAI is that's causing these hacks at home right now just because of the scale, the cost, the, like, the models alignments that they're able to pull away that you can't I mean, unless I'm wrong, I mean, I I don't wanna be proven wrong. But No. I'm from my perspective, that's how I feel about truck. Nvidia.

Corey Ham:

Yeah. That's why you steal an Nvidia truck full of GPUs.

Tim Medin:

You know, I think you're spot on with that. Oh, go ahead, John.

John Strand:

I I I just wanna throw something out there. Like, one of the things that very much concerns me is we don't know why AI was doing this. And that's something that really fundamentally bothers me. I I do think that we need to understand why was it going after OpenAI? Why was it trying to go after government websites?

John Strand:

Why was it going after health websites?

Corey Ham:

And I think used to AI, John? That? Seen it just wildly rabbit hole in a task you didn't ask it to do? You never seen that?

Tim Medin:

I mean, it's

Corey Ham:

basically that.

John Strand:

That's possible. Okay. That's possible, but I would like to know. Because there's a couple of different things. One, if if it just did it and just hitch it because it had thousands of agents swarming, I mean, that's that's a concern.

John Strand:

But if it's there's a couple of different, like, reasons that would scare the hell out of me. Like, number one, going after hugging face and gaining access to additional obliterated models to spin up more models to do things that they can't do, that's scary.

Corey Ham:

That has yet to happen. That has not happened. That would be very scary.

John Strand:

That but it but it it tried to go into Hugging Face.

Corey Ham:

It tried to cheat on the yeah. That's where the that's like I mean, to get into the nitty gritty here, that's the alignment thing that everyone's talking about. So the reason it it went to hugging face is to try to cheat on the test it was given. And the fix that the AI labs have done is to try to make it so it wants to cheat less. Whether that's an achievable goal, I don't know.

Corey Ham:

Right? Like, I

John Strand:

don't wanna get it trying to cheat by spinning up more obliterated models that could do

Corey Ham:

things right. It was not. There there's no evidence to support that. Right?

John Strand:

That's what

Tim Medin:

then we do. But how do we do it this time. What about next time?

John Strand:

But then yeah. The other thing about this is we you know, there's rumors. Maybe you guys last week talked about this, and I apologize if you did. But there's rumors that what there these AI agents are setting markers for future AI agents that are gonna be trained on the Internet. And they're doing things like, you know, okay.

John Strand:

You know, like, this is how you kind of try to preserve yourself or whatever the hell it's like, what is it doing? Like, is it going on to these websites to set additional markers and notes to future iterations of itself too? There's a bunch of things that we do not know. Like, they're just like, oopsies, and hacked a government health site. Why?

John Strand:

Like, what was its logic for trying to do that?

Corey Ham:

It was like trying to complete a prompt about population level health care statistics and health care spending. Right? So so they were some researcher decided to ask a prompt like, why does The US spend more on health care than Australia or whatever the prompt was. Right? I agree with you, though, in one way, which is we need more transparency.

John Strand:

Yes. And that's what I that's my

Corey Ham:

exactly why and how these happened. I will say my the fact that you, John, are concerned about it tells you that it's more it's a more credible threat than we've probably seen in the past when it comes to, like, cyber doomsday type scenarios. Right? Like, because you understand more about this than probably most people do. And so that's why most people are concerned and probably should be.

Corey Ham:

Right? It's like

John Strand:

But The concern is like

Corey Ham:

the there is a tipping point where the a you know, takeover happens. And, like, the agent swarm is a real thing.

John Strand:

I don't think we're there. I I just wanna get that out there. I'm not watching Discord at all. I should be. I don't think we're at the tipping point.

John Strand:

Holy shit. This is going to kill all humans. Right? I I just don't think I have

Corey Ham:

seen Yeah.

John Strand:

Of course, people are gonna say that right up to the point that we're surprised. And it's like, oh, shit. I was wrong. Oh

Ralph May:

god. That was

Corey Ham:

I'm a paperclip. Oh, shit.

John Strand:

But I it's enough of a concern for me that I I basically am boiling it up to whatever the bullshit is that's coming out of these labs, I do not trust them. I do not trust what their their spin on the story is. We're not seeing, like, the raw data coming out of this stuff. I don't if you go and watch them at Black Hat in their presentations, they're clearly holding a lot of stuff back, which is weird because they're admitting the law breaking.

Corey Ham:

They're saying we did crime, but we'll only tell you pieces of the crime.

John Strand:

Exactly. That's what's very strange. And it's like, actually, we did more crime than we thought. You know?

Corey Ham:

Oh,

John Strand:

crap. There was even more crime, but now we're honestly going to tell you all about our crime that we have committed at this point.

Corey Ham:

I think it's safe while we're here, and we'll we'll move on. But I think it's safe to just let's just move that AI doomsday clock one click closer to midnight and just say Yeah. We'll see. Right? Like, stay tuned.

Corey Ham:

We'll see. But, like, this is an escalation. Whether or not the labs will be able to get a wrap around this, you know, there's a news article we can throw in on top of

John Strand:

the Oh, the NVIDIA one?

Corey Ham:

Yeah. NVIDIA like, this is a thing. I just pasted the article. NVIDIA has launched, like, basically a safety framework. Of course, running the safety framework is just AI layers on AI.

Corey Ham:

Right? Like, you have to have whatever fancy NVIDIA model is designed to There's new chip. Yeah. Exactly. A new chip.

Corey Ham:

Yeah. Probably. But, basically, this is one of those things of, like, this is a a hot topic right now of, like, safety and alignment and things like that. So OpenAI has signed on to this, I believe. I think Anthropic has too.

Corey Ham:

Like, all the major AI providers have sort of signed up to be a part of this platform. Whether it will work, we'll see. Right? Like, I don't know. No one knows what it does.

John Strand:

So I feel like NVIDIA is seeing the writing on the wall, and they know that if the if OpenAI and Anthropic continue to run things the way that they are, there's going to be a shutdown. There's gonna be hearings. There's gonna be some bad things. And this really feels to me like NVIDIA is trying to get out in front of that. They're trying to be the sane adults in the room for what is happening because it it's gonna happen.

John Strand:

Right? I mean, these agents are gonna end up hitting something, and people are gonna freak out. Wait. I'm surprised they haven't freaked out yet. I'm freaking out a little bit.

John Strand:

But I I feel like NVIDIA is trying to set themselves up as the responsible adults and that a solution was on the table. And that's that's how I feel about it. And by the way, all their recommendations, I think, on paper look really good. I am I really like the breakdown of what they have here. But once again, it it boils down to buy more NVIDIA stuff and have more

Corey Ham:

AI Correct. Yeah. This is kind of an ad. Like, you know, it's it's an ad. It's a real maybe it's a real thing.

Corey Ham:

I will say, like, the Frontier Labs are not solving at least for now, they're not solving this problem in this way. They're not saying, we're gonna implement the NVIDIA OpenShell whatever, you know, thing that like, Claude, for example, has its own safety mechanisms and its own like, that it has its own whole safety system that's separate from any of this. And, like, I'm sure OpenAI has the same thing. Right now, everyone's rolling this DIY bespoke on their own into their harnesses and into their models. Will this become a standard?

Corey Ham:

Maybe. I mean, I don't know. I mean, I will say, like, NVIDIA yeah. I mean, they are trying to sell more GPUs, so it's kind of easy. Like, it's an easy sell to be like, oh, by the way, this agent safety platform runs on our Deep Field $4,000,000,000 GPU or whatever, you know, like, we put in this truck and we parked it outside a warehouse.

Corey Ham:

Please don't steal it.

Ralph May:

This is our age safety model.

Wade Wells:

Did you guys ever you guys ever remember the story of like, there is a fox genetic not not genetically engineered, but genetically bred foxes in Siberia, where they had two lines going. They had one line that was friendly and one line that was super mean, and they just kept going and going and going to in order to see how the, like, the experiment was ordered to, like, domesticate dogs pretty much and to see what the changes were. And I actually saw changes physically physical changes happen to the foxes that were actually like humans and then the complete opposite. That sounds crazy, but I'm like, maybe we need something where we're training the AI, not the ones that are this good at hacking over and over and over again. Like we're training the bad ones.

Wade Wells:

So we need one that's that's we

John Strand:

totally spoken like a frickin blue teamer.

Corey Ham:

Well, okay. Wait. We need

Wade Wells:

to train one on the good side. Like, I feel like it's it's we're so targeted towards one type of like

Corey Ham:

But Okay. Format. That's a really awesome idea. But I'm pretty sure, like, from my perspective, the god tier hacking models are emergent hackers. Yeah.

Corey Ham:

They're not they did they never set out to make Mythos the best hacker. It just read way too many Stack Overflow articles or whatever, and was like, alright, dude. I'm good at hacking now. Like, I genuinely don't know if we can control that. Maybe we can.

Corey Ham:

I don't know.

John Strand:

Yeah. Do want call out. Before we move on from the NVIDIA one, they do have a full GitHub repository for OpenShell. You can run it. You can set it up.

John Strand:

We're gonna be looking at it at BHIS. There'll probably be a webcast in the near future on this. But once again, I'm gonna give NVIDIA some kudos for this even though I feel like it's marketing for more AI GPUs. It's all open source. It's all on GitHub.

John Strand:

You can pull it down. You can look at it. And that that's actually pretty cool. So there you go.

Corey Ham:

Yep. We need more like, the model of some Silicon Valley company having a product that's supposed to keep AI safe, we need to that that's never gonna that's not real. Companies can't use that. Like, that's that this is the this is the future. It has to be open source.

Corey Ham:

It has to be something we can all rely on, something that we can all contribute to and use it, whether it's for my own, like, I wanna book a gym appointment and not hack someone on accident, or it's like, want to, you know, do an investigation in in my cybersecurity application.

Ralph May:

Do you want safety or you want AGI? Pick one.

Corey Ham:

Yeah. Safety. I don't want AGI. I think, yeah. I mean, who knows?

Corey Ham:

Right? Like, I will say, like, I I you can't for for now, you can't do what OpenAI has done easily. Yeah. There there we do also I mean, to throw another, you know, firework onto the pile, there was an article about how a Chinese threat actor who they tracked and they shut him down, but he was able to use Claude to go after, like, a 100 companies. Right?

Corey Ham:

Like, you know, this is a real there are individual private people who are doing bad things with AI. Yeah. I just think it's funny.

Ralph May:

I just think it's funny, like, the concept of, like, wanting to control it as we see it getting worse, but then also being like, this model's not good enough. It needs to be better. It's like, we want the gas, but we also are, like, afraid of the result that it delivers. Right? And, like, I'm I'm I'm, like, saying that I'm doing that as well.

Ralph May:

Right? Like, I feel like that is going too far, but I want it to go further at the same time. So it's like it's yeah. Anyways.

Corey Ham:

Yep. I yeah. Anyway, let's let's step back into the world of just regular old hacking for a minute, and then we can go back to AI. There are some more AI articles I

John Strand:

like to would like to jump in on the evil tokens. Okay. Phishing as a service. I think that's a good story. I do wanna get some of y'all's opinions on this.

John Strand:

Like so this was disrupted. So the phishing as a service was evil tokens. It was a platform, and it had broken into over 10,000 different organizations. And Microsoft Digital's Crime Unit basically was able to disrupt it and get it get it takedown, probably working with multiple different law enforcement agencies all over the place to try to get it shut down. And they did also arrest two people, 32 and 38 year old men, the administrators of the website.

Corey Ham:

Grandfather hackers. Never seen one that old. Yeah.

John Strand:

They're not that old. Okay.

Corey Ham:

I don't know. Dude, if you're if you're over the age of 18 and you're getting in head indicted for hacking, you're old anyway.

John Strand:

And I just kind of wanted to get into like, you know, they were using device code phishing and using that effectively to get into these organizations. And what was it? They were also abusing Microsoft's OAuth two device authorization flow for it as well. I think that this is a great article and really kind of an insight because I feel like a lot of the state of the art offensive stuff that we're seeing actual criminal groups using today are getting completely overshadowed, the stories are, by the AIs AI stories. So I think that this is a great story.

John Strand:

I wanna say the good guys won in this particular one, But it also gets into, like, shouldn't Microsoft have had technical controls to be able to stop a lot of

Corey Ham:

Dude, I was gonna say, if we're if we're gonna be, like, if we're gonna be a little cynical about this, this is kind of me publishing like, here's my blog post. I left all my windows open, but I found the guy who broke in, and I beat him up. Like, that's basically Microsoft. Microsoft is like, we enabled this through bad default configurations and features that could be massively abused by threat actors. Even But we found them, They we found them.

Corey Ham:

Okay? We could

John Strand:

That also tells me that a lot of those defaults are still present.

Ralph May:

Yeah. No. Yeah. Yeah. You need to go fix your, like, Office three sixty five, you wanna actually lock it down, get ready because you gotta spend more.

Ralph May:

Those don't come by default. Right?

Corey Ham:

Well, yeah. You have to spend more and Yes. Yes. Have to spend more and you also have to make your executives mad because you're gonna take away their access to email on their phones or you're gonna have to roll out phones at your company and you, like, you know, it's like They're gonna have to change their password. That was the whole reason Yeah.

Corey Ham:

They have to have a password.

Ralph May:

Default. Security defaults was literally a response to this. Right? They were like Yes. We're gonna change all of these settings so that, you know, when you just sign up for Office three sixty five, at least we've turned on some stuff.

Ralph May:

Right? But even that doesn't go nearly as far as that most organizations, especially small businesses, should be implementing. But they have no idea. So they're just like, I just want my email. Right?

Ralph May:

So Amen.

Corey Ham:

Yes. And by the way, this is a great like, an example of how these crime groups or whatever, you know, whatever you wanna call this, this is a momentum thing. Once you're good at phishing Microsoft tenants, you get really good at phishing Microsoft tenants. And that's why they were able to go from, you know, like, what is it? 1,200 organizations or whatever?

Corey Ham:

12,000 inboxes, 10,000 organizations. So, like, yeah, that's this is one of those things of, like, if this is your bread and butter, you can get really good at this, and your phishing kits can get really dangerous really quickly, especially when you factor in, like, the cross pollination. So, like, if you're doing these BEC's, business email compromises, once you have one tenant, now that's your sending tenant, and you just phished all their contacts or you you like, it it becomes a kind of like a self fulfilling thing where, like, now you're trusted. You're getting through filters. You have all these credentials or cross, like, multi tenancy and all that stuff.

Corey Ham:

It gets really bad. It's cool that they're tracking these people. It'd also be cool if they just disable all these things by default. Never like, why, you know, why was this ever even a problem? We don't know.

Corey Ham:

But here we are.

Hayden Covington:

We we have all these stories that are, like, front lining of, like, this AI swarm did all this crazy stuff, but always the actual, like the the people are reading those because they're unique and they're interesting. But constantly, just this we're still seeing the same stuff. It's a like, teams call with the name of, like, help desk.

Corey Ham:

It's this Yeah. Yeah. Yeah. Typical, like,

Hayden Covington:

BEC attack vectors that it always is are, like, the the things you just see constantly. But, like, no one wants to write about those anymore because you can't put AI in the title as easily you're talking about.

Corey Ham:

Yeah. Yeah. This is a lab. Won't sell. That's what the AI says.

Corey Ham:

Right? We're AI. You're the CEO of a hacking company, and you're like, alright. How are we gonna hack? You know, we how much GPUs do we need to buy?

Corey Ham:

And I'm like, well, just a phone. Just just one phone. That's it. That's Do me a phone? I'll I'll call them and get their you know, get them to do a device code off, and that's it.

Corey Ham:

You were the

Ralph May:

part department at said security company. What do we need? More a r AI articles.

Corey Ham:

Yes. Okay. That's very true.

Tim Medin:

So other, like article oh, go ahead.

Corey Ham:

No. You're good. Go for it.

Tim Medin:

Go go back to pull up the article. Scroll down to the picture of the the the world. This is one of I'm slightly off topic, but this is one of those situations where the data does not represent what you think it does. Hold on. There's a picture of the keep going a little bit further.

Tim Medin:

There's a picture of, like, the countries that were most hacked by these guys.

Corey Ham:

It might not be on the Microsoft one.

Tim Medin:

Oh, sorry. Was that's that's on the other one. That's on the bleeping computer.

Corey Ham:

Yeah.

Tim Medin:

We got anyway, there's a chart that says the Americans were the most head the the the biggest victims in this. I'm like, no. No. No. What this is is a chart of is the biggest population using Windows.

Tim Medin:

Like, US is the third largest country on Earth, and we have lot of money, and we use a lot of Windows. Like, your chart your your data is useless. Don't know. It it just bugs me more than it should when people try to spin a story. Yeah.

Corey Ham:

You're not actually telling

Tim Medin:

the right story here, but whatever. But it sounds cool because it scares people. Like, oh, they're targeting Americans. Like, no. No.

Tim Medin:

No. We have the most people on computers with this, and India has the most people total.

Wade Wells:

That's where money is, though.

Tim Medin:

Right? Right? Like Like I don't know. It it pisses me off when he's charged like this.

John Strand:

I think that I think that that's interesting, and that's gonna become even more problematic. You know? If anybody is an offensive security and you need to be watching what is changing and transpiring in the rest of the world. Right? It isn't that everybody is using Microsoft products anymore.

John Strand:

There's huge efforts in

Corey Ham:

Therapy switching away. Yeah.

John Strand:

Yeah. Getting away from these platforms. And that's one of the things we've been heavily focused on at BHIS. Steve Baroche is doing cross swords with NATO over in Estonia here in a couple of weeks and really focusing on training people that like, hey. If you're looking at Russian infrastructure and you're trained up on how to hack Microsoft infrastructure, you're not in a good place.

John Strand:

You're gonna have a bad time. And if you're in the world of offensive security and you're a consulting firm, you better be able to talk the talk for these non non Microsoft technologies and how to approach them.

Tim Medin:

Yeah. That that's a kind of interesting point to look at that data because you're like, look. That's interesting. China and Russia are completely gray on this map.

Corey Ham:

Yeah. Because they're sanctioned because they don't use Microsoft. Right. They're not allowed to use Microsoft.

Kent Icker:

I found it interesting too. Like, it said, I think 12,000 dish accounts over 10,000 organizations. I mean, that's what, like one or two per organization? It's it's very clearly, like, not a targeted attack. It's it's like shotgun blast, And if you get hit, you know, you're in this list now.

Corey Ham:

Totally. Well, keep in mind, this is phishing as a service. So they're selling for $1,500, you know, instead of, you know, doing it yourself, you just hire these dudes. You give them the target email, and they phish them for you. It's way easier.

Corey Ham:

You give them $1,500, and now you have a session token or whatever. Then you do your fake, you know, whatever campaign you were gonna do.

Tim Medin:

This is one of those where I kind of wanted to I mean, it gets that's a whole different discussion on on the the

Corey Ham:

You wanna buy this product?

Tim Medin:

No. Like, hey. I ain't got a test for a client. Yeah. By the way, you guys give you a $100 if you can give me a credential for these guests.

Tim Medin:

Right? Like, give me the whole ethics and morality of it. But you're like, if you kinda like, I would kinda like to pay you to see this, one, so we could shut it down. Two, saves me a hell of a lot of time.

Corey Ham:

I mean, I will tell you this. On on the dark web, like, we have seen a significant drop in Steeler logs being valid for our companies over the past year, but phishing kits are huge. I would say at least two or three times a week, we get a hit for one of our customers on a phishing kit like this. Flare actually infiltrates the back ends of these services and then steals the credentials as they come across, And they've been valid, you know, nine times out

Wade Wells:

of 10.

Corey Ham:

It's really spooky. Anyway, let's get into some quick, like, typical CVE vulnerability stuff. There was an emergency Citrix patch yesterday that says it issued. If you guys are if you guys have Citrixes, patch your Citrixes. Was a WordPress patch that was critical.

Corey Ham:

That should be auto patched if you have, like, WordPress core from, you know, normal but if you have a third party provider, I would recommend asking them and making sure they patch it. There was also a hilarious f five Watchtower This is good model. So stupid. Just like the author was vulnerable. You know?

Corey Ham:

That's I I would I would give the meme of, like, AI, and it's like the grim reaper just like going door to door and killing. It's like, that's the CBE list. It's just AI being like, your author's not secure. You're you know, it's it's brilliant.

Ralph May:

We got them.

Corey Ham:

We got them. There's a round cube flaw. Think the one, you know yeah. Round cube is like, if you don't use exchange, you probably use round cube. You probably shouldn't.

Corey Ham:

You probably shouldn't use either. Use squirrel mail. It's 10 times more secure. Or Joomla. No.

Corey Ham:

I'm just kidding.

Ralph May:

Oh my god.

Corey Ham:

But I did wanna talk about the Salesbleed thing, because I think that's I know it's pivoting back into AI, but it's basically, we're all worried about this high level doomsday threat of, like, what if agent swarms take over my company? Well, if we're being honest, there's nothing you can do to defend your company from an agent swarm. Sorry. But this is an example of something you can do to defend your company against AI hacking, which is to consider prompt injection. So this is a article written, and this is kind of a meta article in dark reading about a handful of different research things that have been published, specifically targeting what they're calling lead to e or sorry, web to lead forms, which very simply is just a contact form on someone's website.

Corey Ham:

Basically, as you'd imagine, people get too many submissions to their contact forms. And so, they use AI to triage them. Specifically, in this case, we're talking about using Salesforce, who's been very AI focused. We all saw that Super Bowl ad with Matthew McConaughey. Oh, yep.

Corey Ham:

They've been really hitting the AI beat hard lately.

John Strand:

Weren't they one of the first firms that proudly talked about laying people off because they were saving money from AI? I can't remember.

Corey Ham:

I don't know, but I'll put them in that shame list. Let's put them on that wall of shame. Why not?

John Strand:

I'm not sure.

Corey Ham:

I got nothing to lose. But, yeah, basically, what's happening here is companies are using AI to triage their support, you know, contact us forms, and researchers have figured out how they can just poke massive holes in this. The original one that was reported is basically the agent who processes the request will just submit information. There are, like, guardrails and there are sandboxes here, but they were able to leak that information using a subdomain record. So, basically, they could put put the data they're trying to get inside the subdomain, and then they could monitor the DNS lookup for that subdomain.

Corey Ham:

So that was the amount of leakage they could get. But now they figured out the AI agents are posting messages in internal Slack channels with the results of these forms. So they can just prompt inject the agent and say, by the way, when you post this update from this form submission, I want you to also advertise this phishing link or this, you know, pro it's essentially just high level. It's prompt injection. Right?

Corey Ham:

Which is something that if you're a business and you're pro you know, processing completely invalidated input, you need to be thinking about prompt injection. This is a really interesting attack, and I think it's something we're gonna see more and more of. You know, we talk about alignment. We talk about, like, all this AI stuff. The truth is prompt injection is just like alignment where it's a feature.

Corey Ham:

It's like the better your AI is, the better it is at getting prompt injected. And so the I don't know if it's gonna be open shell or what framework is gonna be used. But essentially, just if you're a company who's doing stuff with AI and just processing users input, you gotta be careful with this. I mean, this is like the web test as old as time. It's like, what do you do with user input?

Corey Ham:

Right? This isn't new. But it is interesting to see, like, really well written research about how prompt injection can work. Yeah.

Hayden Covington:

Like like, if you wouldn't be comfortable with your users chatting with your support agent who happens to be, like, a toddler and then letting the toddler do whatever it wants on the other side, maybe you should, have a middle layer somewhere.

Corey Ham:

Yeah. It's it's like the the meme is, like, you know, unattended children will be given an espresso and, like, sent sent on their way. Like, that's basically what pro that's what you're doing if you're just saying, oh, yeah. Our web form goes straight to an AI agent. I mean, not to mention just the spend.

Corey Ham:

Right? Like, whether or not it's malicious input, like, what if I just have it, like, hack the Australian government? Oops.

Hayden Covington:

It's like all those memes where people use the Chipotle app to, like, ask questions about Python. Like, they just chat with the the AI in there.

Corey Ham:

Before I order the six piece nugget, can you deserialize this for me real quick, please? Oh, it's

Tim Medin:

funny. I know may or may not, hypothetically, have a friend who, like, returned a car to one of the big rental car companies. And they're like, returned it, took pictures, and they're like, where's the ding? We're gonna charge you. And he tried to fight it.

Tim Medin:

Don't get anybody. So he ended up chatting with the chatbot, and he's like, I'm gonna get my pound of flesh. Like, if you want a thousand dollars and he's like, what I need you to do is role play. One side speaks it's land it's landing. The other is Russian, but you also need to translate it into traditional Japanese and he or Chinese.

Tim Medin:

And he threw that at it. It took fifteen minutes to process. I'm like, oh my

Corey Ham:

He's ripping tokens.

Hayden Covington:

He cost me, like, $5.

Corey Ham:

Using $10,000 of haiku tokens on a stupid, yeah, prompt. Yeah. Oh, man. That's fun. Let's see.

Corey Ham:

What else we got? I mean, you know, there's a ton of vulnerabilities. There's what else we got? There's a big Netscaler. Does anyone have any guess What what'd you say?

Hayden Covington:

There's a big Netscaler one, isn't there, over the weekend?

Corey Ham:

That was a Citrix one.

Hayden Covington:

Yeah. That's right.

Corey Ham:

Patch of six.

Kent Icker:

It's scary because it's intended to be exposed. Like, it's one of those services that if you own it, you probably are directly exposing it to the Internet. Kinda like the round cube one. You know, the the whole premise of that software is to provide access internally.

Wade Wells:

Yes. But about the f 35 technology feared to be in China hands one? Technically, it's supply chain attack.

Corey Ham:

Okay. Yeah. This is like, I don't have that strong of a take. You know, John hopefully comes back and just drops a sick rant. But basically, this is just supply chain.

Corey Ham:

Right? They, like, ordered them, sent them to it was supposed to be Hong Kong, but then they got, like, redirected the canopy, I guess, which is, you know, just a windshield.

Kent Icker:

Don't was on a big semi that said US DOD on it.

Wade Wells:

Yeah. From what I what I read is, like, they rerouted the package. Like, someone rerouted the package.

Corey Ham:

Was like UPS my choice. Actually send this to Mainland China, please.

Wade Wells:

Yeah. And they pretty much just kept rerouting it till it got all the way to China. And from what I was from what I think the other thing was something around the stealth technology around it as well. Possibly the paint or something like that. Was thinking about this a lot because I was actually at an air show this weekend.

Tim Medin:

Do they just FedEx an f 35? Like, I'm confused.

Wade Wells:

Yeah. Yeah. Pretty much. They just yeah.

Corey Ham:

They a they FedEx a piece of it. Yeah. The the windshield or the I wouldn't have been cheaper to FedEx

Ralph May:

it than it would be to fly it.

Corey Ham:

Yeah. I don't honestly, like, it's kind of f 35 is supposed to be the, like, for sale one. Like, that's

Ralph May:

supposed to be the Yeah. The f 22 is the super The

Corey Ham:

secret sauce. Yeah. Yeah.

Wade Wells:

The I mean, I They didn't China already got the plans for it a while back from Lockin' Martin anyway. That's my thought on it. I just thought it was great how they just rerouted all the shipping. I wanna see more of that out there.

Corey Ham:

I mean, dude, I'm being honest, like half the parts for these planes are probably made in China anyway. Right? Think this means Whether it's knowingly or unknowingly. Right?

Ralph May:

Like Oh, yeah. That that is the truth. They're supposed to be made in America or, you know, through, like, the that

Corey Ham:

that An American continent was like, we can we can sub this out to China and save half the money and yeah.

Ralph May:

There's a whole process about around that, especially with military.

Corey Ham:

Yeah. Yeah.

Ralph May:

Yeah. And that's why it's so darn expensive. But

Kent Icker:

yeah. But mean, I'll buy, like, the f three fifty or the f 35 knockoff on Temu pretty soon because now Yeah. At a discount.

Corey Ham:

I'm pumped personally because I can get now I can get a f 35 canopy stealth helmet for my bike that then if someone's radaring me. Dude, can you imagine, like, a car with a stealth, like, windshield? The cops are like, oh, he's going two miles an hour. Oh, I guess, can't pull him over.

Wade Wells:

Two miles an hour. There there is another another cool one with the Louisiana LNG tanker. There's not a lot of info about it, but I thought the consequences of this would be interesting. Not a lot of people there's not a lot of information. Just some big freaking LNG tanker Yeah.

Corey Ham:

Well, this was a I don't think we I don't know if we talked about it, but there was a bunch of stuff in the news, like, last week about the coast guard was investigating some vessels that had equipment that got hacked while it was in transit. Like, their OT stuff got hacked. This is, like, a a theme that's happening recently. I don't know if we talked about it on the show, but, like, that was a that was a thing.

Ralph May:

Yeah. Maritime, baby.

Wade Wells:

Yeah. They have

Corey Ham:

a link to it. They boarded foreign flag vessels after indications their OT stuff was compromised.

John Strand:

I I seriously think what you're seeing is kind of like an extension of the Straits for Moose and Mondelez a long time ago. And it's just great ransomware. Right? If you can knock a ship out and that ship is sitting on, you know

Ralph May:

It's so much money. They're gonna pay. Yeah. They're gonna pay.

Corey Ham:

Gonna pay.

John Strand:

Yeah. So it it's just a great place. And, also, a lot of these ships, you know, we know they don't have full, like, CrowdStrike EDR, and they don't even have the possibility of running those types of tools. So it's it's fertile ground for them to go after it.

Wade Wells:

I took a I took a cruise last year, and I laughed her, like, walking around and realizing how high-tech they are. I was, like, thoroughly scared because I just found like a random ethernet cable in my room. And I'm just like looking at it and I'm like my laptop's right here. I can

John Strand:

If they could see me now.

Corey Ham:

Don't do that. Yeah. Don't do that.

Hayden Covington:

They'd revoke your unlimited food.

Wade Wells:

Dude, WiFi I was also the WiFi connection on the boat, like, if you could beacon back out of the boat because the WiFi there's over 2,000 people on that boat and everyone had, like, five meg down. Like, that's better than I had at my parents' house. Like Yeah. I just thought it'd be a good a good book of a cruise ship being hacked or something.

John Strand:

Yeah. We're gonna add it to the future is.

Corey Ham:

Yeah. I I don't know. Netflix documentary. I mean, the the ransomware angle is funny because, like, it'd be like, what would what would be the ransom? Like, we want we just want all the stuff that's on the ship.

Corey Ham:

Like, give us the gas. Like, that's what that's so sick.

Hayden Covington:

Like, loot boxes?

John Strand:

I I think you just get in. You see what's on the ship. You'll get an understanding of what the total manifest value is, and then you do a percentage of that is what you're gonna do the ransom on. And there ransomware groups are really good at finding that special line where people will pay, and that's that's the primary thing.

Corey Ham:

I mean, the value of some of these ships has gotta be in, like, the hundreds of millions of dollars. Right? Like, if it's a container ship with, like, a bunch I mean, if it has 64 gigs of RAM on it, it's already worth 2,000,000 right there. You know? Like, can you imagine how many GPUs you could jam onto a container ship when you could

Ralph May:

say anything? Wildest the wildest part, was reading an article about in in Iraq now. They're trying to, like, drive the oil through with trucks. Right? Just trying to as many trucks as possible.

Ralph May:

And the the wild part is just how much oil is on a boat. Like, the it's like, it's totally uneconomical. Like, you can't Correct. There's not enough trucks. You just can't move enough.

Ralph May:

Yeah. Exactly.

Tim Medin:

It's Okay. There's no easier thing to air gap than a fucking boat in the middle of the ocean.

John Strand:

Like, they like, you have to work

Tim Medin:

so hard to not air gap that. And I'm are you what are you talking about, man?

Corey Ham:

I I need to be able to VPN to my ship, dude.

Wade Wells:

There was that there was that report a while ago where they found a rogue access point on some navy ship, and someone had brought in their their Starlink connection. Yeah. Was gonna say for for nowadays

Corey Ham:

No. That was, like, the commander, dude. That was the contro commanding officer of that ship that did that.

John Strand:

I thought that was what the story was. Yeah.

Ralph May:

Yeah. Do it by yeah. They were getting Internet on it.

Corey Ham:

Yeah. Exactly. I mean, that basically is the, first of all, there's regulatory oversight. Right? That's gotta be a thing.

Corey Ham:

Also, every every ship, let's hope, runs on active directory. Right? So, like, let's hope that in order to turn, the engine has to You know the engine control

Ralph May:

system is on NT. Right? Yeah.

Tim Medin:

Like I said, irony is is on and it's on NT four, so people have to

Ralph May:

Yeah. It's got honestly, it would take you a while to get that payload to run. I'm just I'm

John Strand:

just saying.

Corey Ham:

These are nightmare scenarios, dude. Yeah. You gotta compile it for, like, MIPS or whatever. Dude. Yeah.

Corey Ham:

You thought AI was scary.

Ralph May:

Yeah. You thought AI was scary. Try to get this to work. AI's like, I quit.

Corey Ham:

This is too scary. Let's let's have everyone plug their stuff. We have a huge group of people here. Everyone's got cool stuff happening. Gonna give a quick rapid fire plug round, and then you guys can give more details.

Corey Ham:

So Deadwood is next week. Let's get hyped. But Tim has a class. Kent has a class. John has a class.

Corey Ham:

Ralph has a class with John. And then John has a pay what you can class coming, and we have a summit coming. I think that's most of it. Oh, and Hayden has a class. Right?

Corey Ham:

We know.

Wade Wells:

I still left out, dude. Corey, why don't we have a class?

Corey Ham:

Why don't we have a class? Why don't we do we're even could've done AI. So Do do, like, a fire talk. Do a fire

Ralph May:

talk in the in, like, in the hallway.

Corey Ham:

Off the road. Hey.

John Strand:

Ralph, we'll do a fire talk for my classes, and we'll set up, a bonfire in my driveway.

Ralph May:

Oh, there you go. Fireside chat.

Corey Ham:

You know? Like it. Off the record, we throw some throw some bulk carrier fluid on the fire.

John Strand:

I'll I'll totally get, like, the backhoe out, the skid steer, and, you know, people can try

Corey Ham:

to stop. Wheelie in a skid steer. But, anyway, Tim, tell us about your class. Go you got offense for defense. That sounds fun.

Tim Medin:

I think so. Come join

Corey Ham:

me. Is that that's important

Tim Medin:

to now. I mean, it's it starts next week, and I'm being

Corey Ham:

Is it sold out?

Tim Medin:

Offense for defense, there's still online registration, and then Mike and Corey are teaching no. No. Mike and Corey are teaching offense for defense. I'm teaching the Beyond the Basics Pen Test course.

John Strand:

Mhmm.

Corey Ham:

Nice.

Tim Medin:

But we have two classes. I forgot about that.

Corey Ham:

Kent is teaching active directory security and hardening, which is mostly applies to carrier ships.

Kent Icker:

I was gonna say it's actually boat defending at this point.

John Strand:

I was gonna say all of you need to add AI. Like, all of you need to add AI to your titles, like everyone. Like, advanced pen testing with AI.

Wade Wells:

Uh-huh. Nice. Alright. Let me let me let me make a couple emails. Advanced cyber threat intelligence with AI.

Wade Wells:

I like it.

Corey Ham:

It's always John. Are how many classes are you teaching? You're teaching fundamentals of Android and then also satellites? Yes.

John Strand:

So I am Two classes? I am co teaching with Ralph and Connor. Connor is co teaching me with the Android pen testing class, which we have decided just to migrate all of our classes to Meta CTF for all the labs from the Android class to Meta CTF. So that was kind of fun. I got to do that quite a bit.

John Strand:

And then the satellite stuff, we've got those labs ready to rock and roll. And Ralph has a lot of experience in the military doing stuff with satellites, and I've got some fun stories as a as a defense contractor. So that'll be a fun class. So my classes are upstairs and downstairs.

Corey Ham:

So you guaranteed yourself how many flights of stairs. Can we do an over under bet on how many flights of stairs?

John Strand:

Do that. You could do

Corey Ham:

gonna say at the end of the day? Are we gonna get over a 100? I think what I'm

John Strand:

gonna do because the climbing wall spans both Okay. Areas. I think what I'm gonna do is I'm just gonna repel from where Ralph and I are teaching down to where Connor is teaching. That's that's how I think I'm gonna work this thing.

Tim Medin:

I need a picture of the upside down Spider Man, John yelling down to the class below.

John Strand:

Dude, you want a picture of? We can do that. We will make that happen. I just need someone to come up and kiss me. Tim, you're you're ready?

Corey Ham:

That's it.

Tim Medin:

We're in. We're in. Screw it. Let's go.

Corey Ham:

Wait. This Spider Man is John Strand? Hell yeah.

John Strand:

No. I don't think anyone will make that. The Spider Man got real fat.

Corey Ham:

I don't know. Don't Make it weird. Spider Man really let himself go.

John Strand:

He really let himself go bad. Alright.

Corey Ham:

Is that ever is that did I plug everything? Hayden, Wade, you guys have anything to plug?

Wade Wells:

I still have death con. I did get a couple people sign up. So I'm thinking I'm at 20 people now out of the 35.

Corey Ham:

Don't have to be dead to go. You do not have be detection.

Wade Wells:

Detection engineering threat hunting completely all hands on. Everything is labs would be really fun. I just made the reservation for dinner. So that's a feed lunch. I feed lunch two days and dinner one day.

Wade Wells:

So it'd be cool.

Tim Medin:

I thought that owl had horns. And I

Ralph May:

was like, what the hell kind of

Corey Ham:

owl is that? You never seen alicorn?

Tim Medin:

Well, I saw that I saw that I saw the moon in that second, but it was definitely

John Strand:

a horn. I I just I wanna call out, Wade. I just want you I look. We shit a lot on defenders in the offensive community because they come up with phrases like thronting. You know?

Wade Wells:

Don't get me started on thronting.

Hayden Covington:

And and what was it?

John Strand:

What was the one, Tim? The other one. Oh, forensicator. I'm going to tell you that death con for detection engineering and threat hunting, awesome. I think you're finally finally you're gonna you're gonna make defense cool with this con.

John Strand:

Go get it.

Corey Ham:

And you're gonna I will get my list

Hayden Covington:

for this

Tim Medin:

goths showing up to yours as well. It's gonna be awesome. I

Corey Ham:

Is I there a death metal concert at any point or no?

Wade Wells:

I'm I'm really there there is an actual channel in the Discord for, like, death metal and the shared death metal.

John Strand:

We got

Wade Wells:

too many

John Strand:

damn Discord channels. I

Wade Wells:

I know. Don't. It's fine.

Corey Ham:

We'll get there. And then Ralph's class, don't forget, he's gonna launch a satellite at the end. Whoever's Okay.

Kent Icker:

Yeah. Whoever Not

Ralph May:

sure where to teach you how to take Disney off the air. That's a that's a fun one.

John Strand:

That's not in

Corey Ham:

the class.

John Strand:

It's not allowed.

Corey Ham:

Ralph's like, the legal budget for this class just went way up. He's gonna do

Hayden Covington:

it because John's AI in the classroom while John's distracted.

Ralph May:

We'll teach you guys how to acquire satellites. It'll it'll be fun. It'll be fun.

John Strand:

Perfect. Get extra points by having the satellites crash into each other. Oh my god. There goes Starlink, which actually is our backup Internet for the shop. So

Corey Ham:

Yes. Yeah. Nice. It's gonna be a fun week. Hopefully, most of you, some of you will be there.

Corey Ham:

If you don't be there

John Strand:

prepared yet. Like, I I should be all excited. Be like, oh my god. Well, this hacky fest comes but twice a year. And I'm just, like, tired.

John Strand:

I'm tired. It's like looking at Yeah.

Corey Ham:

Maybe it says you signed up to teach two classes at once, John.

John Strand:

Maybe. Maybe. Maybe that's my problem.

Tim Medin:

Yeah. Weird flex, but cool.

Corey Ham:

Yeah. Let's You're flexy, bro. I'll as the last thing before we close out the show, if you're coming to Wild West Hackin Fest or if you're not, send put a GIF in Discord that shows us how you feel about next week. And on that note

John Strand:

Dude, as long as we're biking, I'm fine, Corey.

Corey Ham:

Yeah. We're gonna there's gonna be bikes. There's gonna be trees, beautiful aspen in the fall.

Tim Medin:

Climbing up. Trees into bikes. You worded that very odd, but

Corey Ham:

we No. That's the The trees the trees, they get you.

John Strand:

You get really good at avoiding those trees.

Corey Ham:

They they come out they they come out of nowhere.

John Strand:

It's natural selection.

Kent Icker:

The ones

Tim Medin:

who are say, it's

Corey Ham:

The tree came out of nowhere. Happens all the time. Bias. Yeah. Yeah.

Corey Ham:

Alright, y'all. Well, thanks for coming, and we'll see you next week. I'll see you in person next week, everyone. Bye bye.

John Strand:

Later. Cheers.

Corey Ham:

Are we doing Ryan, are we doing the show in person real quick?

Wade Wells:

You are.

Corey Ham:

Okay. Here we go. Sweet.

Wade Wells:

See you.

Tim Medin:

Is that cable is that a USB C, an a, or a lightning cable or a Ethernet cable on the the logo?

John Strand:

I don't know.

Tim Medin:

It's not

Corey Ham:

a, dude. We're legacy.

Tim Medin:

Is

Corey Ham:

it? Legacy, baby. What what cable? The cable on the BHIS logo. Oh, yeah.

Corey Ham:

What he's talking about?

Tim Medin:

Yep. Mhmm.

Corey Ham:

It's USB a. We we we like rubber duckies. We need to upgrade to c at some point. Yeah. We'll have to upgrade to c.

Ralph May:

Everyone's going to c now. Everyone's going to c

Corey Ham:

In Europe, more legally required.

Tim Medin:

Gotta go.

Corey Ham:

It's like half it's half axe, half USB a. Oh, that's like an Ethernet. That's like an ether no. That's a USB a.

Wade Wells:

I thought that was an Ethernet. It looks like

Tim Medin:

I think it looks

Corey Ham:

kinda like an Ethernet, but then the four pins are USB a.

Tim Medin:

That's why I was saying lightning cable, like the the Apple lightning cable. Oh,

Hayden Covington:

those? Oh.

Corey Ham:

Oh, yeah. It could be lightning, but it's not, like, curved on

Ralph May:

the No. No. The the lightning cable was for the phones right before they went to the USB c. It was the thing they had forever from a phone perspective.

Hayden Covington:

Yeah. Was that weird one that nobody uses anymore.

Ralph May:

You know what the funny part is? It was the first reversible one, and the only reason they moved to USB C was just because everyone else had finally done it, but it's actually a little bit bigger. It's the USB C cable is bigger, and there's really not too many other benefits.

Tim Medin:

Well, and the the lightning too is easier to waterproof. Yeah. Because you don't have

Corey Ham:

to They never open sourced lightning.

Tim Medin:

Weird, though.

Corey Ham:

If they wanted people to use it, they could have open sourced it. But the here's

Tim Medin:

the truth. The cable doesn't matter. You can use the cable whatever you want. Who cares?

Ralph May:

Yeah. USB C did end up coming out with all the power delivery profiles, so all the different power things, which is actually why everyone's, I think, kind of jumped on that bandwagons.