Talkin' Bout [Infosec] News

This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴event-live-chat


Chapters

  • (00:00) - PreShow Banter™ — Sol with a Goal
  • (06:33) - OpenAI accidentally Hacked Hugging Face - 2026-07-27
  • (09:18) - Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
  • (18:33) - Story #2 - Lapsus is shutting down
  • (24:21) - Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
  • (31:47) - Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
  • (44:00) - Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
  • (52:43) - Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
  • (55:51) - Ads and Mike at the AI Summit
  • (59:54) - Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Links

Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
Story #2 - Lapsus is shutting down
Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
AgentForger, Part 2: The Autonomous Insider
Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Ads and Mike at the AI Summit
Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 
https://poweredbybhis.com

Brought to you by:
Black Hills Information Security 
https://www.blackhillsinfosec.com

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest
https://wildwesthackinfest.com

Creators and Guests

Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Host
Hayden Covington
Hayden Covington joined Black Hills Information Security (BHIS) in the Summer of 2022 as a SOC Analyst. He chose BHIS after hearing many great things over the years and seeing the quality of work, as well as finding people who have the same passion for the field as he does. His favorite part of the job so far has been the community. Previously, Hayden worked in a SOC for a Naval contractor, where he also served as their SOAR project manager and SME, as well as insider threat lead. When he’s not working, Hayden can be found doing anything athletic (like triathlons!), as well as enjoying video gaming and Formula 1.
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Guest
Ads Dawson
Ads Dawson has spent the past year stealing data from AI agents in production — through bug bounty programs. A Staff AI Security Researcher at Dreadnode and member of BT6, the frontier AI red team, he specializes in web application security, adversarial machine learning exploitation, and autonomous red teaming. Ranked #2 in Canada on HackerOne (2026) and #1 Up and Comer (Q4 2025), Ads is a HackerOne Ambassador (US South), BugCrowd Hacker Advisory Board member, and selected for Meta’s MBBRC live hacking event. He founded the OWASP GenAI Security Project — the fastest project to reach OWASP flagship status — and is lead author of AIRTBench (arXiv), the first AI/ML red teaming benchmark for LLMs. His work includes red teaming frontier models for Google DeepMind and shaping the EU AI Act Code of Practice.
Guest
Mike Takahashi
Mike Takahashi, aka TakSec, is an AI Red Team Researcher at Zenity, BT6 member, and Bug Bounty Hunter focused on breaking AI systems. He has submitted 400+ vulnerabilities across major bug bounty programs and top ranking on both Anthropic’s Safety Bug Bounty Program on HackerOne and Mozilla’s 0din GenAI Bug Bounty Program. His work targets prompt injection, data exfiltration, and AI agent security.

What is Talkin' Bout [Infosec] News?

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET

Hayden Covington:

Yeah. This OpenAI one is interesting.

Corey Ham:

Yeah. That's I think that I I told my team, like, this is one of the rare cybersecurity articles that will probably people in your personal life will probably ask you about it. Like, it's it's intrusive in that way of, like, did this really happen? What happened?

Bronwen Aker:

Yeah.

Hayden Covington:

Yeah. Because Chad GPT is surprisingly decent with just doing what you tell it to do. Like, for the course we're doing at Black Hat, we have, like, a playbook for the attack that is performed. So I think at one point, one of us just handed it to Soul and said, don't stop until you figure this out. And it started going on until he got

Bronwen Aker:

teacher's command.

Hayden Covington:

It's in

Corey Ham:

a lab.

Hayden Covington:

It's in a lab. So eventually, it got a bunch of Cobalt strike sessions, and I was like, okay.

Corey Ham:

Good job.

Ads Dawson:

Have you actually have you actually yeah. If you use soul with a goal, it will just like it will go for like a week. Yeah. It's like it's like the original Codex was like way too, like, just, like, shit its pants if it's I'm so sorry for cussing. Are we lost

Bronwen Aker:

because the I still like to say it. You're fine. So

Corey Ham:

Okay. You're fine. The official the official policy is every swear is $5 to the EFF. So yes. Okay.

Bronwen Aker:

We have a swear jar. A legit swear jar. I know. I bought it for John.

Corey Ham:

Excellent. Which Black Hills pays the bill. So, you know, you're good. Right.

Ads Dawson:

Fantastic. Fun fun. That's fucking awesome. So okay. It's like Codex is way too, like, just it would, like it would be so concerned about ever, like, stepping out of line, and then they've, like, switched something, and then you give that a goal, and they'll just go to, like Yeah.

Hayden Covington:

And now at Level. 86

Corey Ham:

Yeah. It's like, deep,

Ads Dawson:

the control, you went you went, like, zero to a 100, literally.

Corey Ham:

Right. NVIDIA just published a blog about AI safety partners.

Hayden Covington:

Yeah. Apparently, like, a lot of people have signed that letter, namely not anthropic,

Corey Ham:

which is very funny to anthropic and not OpenAI. They're like, OpenAI

Hayden Covington:

did, didn't they?

Corey Ham:

Wait. Really? I don't see them on this.

Hayden Covington:

I thought I saw them this morning when I looked on

Bronwen Aker:

Somebody had a letter.

Corey Ham:

Microsoft didn't. So their parents. Dad, can I be in the OpenAI Security Alliance? Absolutely not, son.

Hayden Covington:

After you eat your dinner.

Corey Ham:

Abs after you eat

Bronwen Aker:

Only if you eat your vegetables.

Corey Ham:

After you eat another random company that just caught a stray in the in the pet cheek.

Hayden Covington:

Right. I mean, did it solve the benchmark? I'd but I

Corey Ham:

was I do like it decided to cheat. It was like, I'm gonna cheat. I I don't wanna actually solve it. I just want the answer key. I'm going after it.

Hayden Covington:

Kinda based, honestly. Yeah.

Corey Ham:

One of the things that I thought was really interesting is the, like, take I heard is like, AI models are very patient. Way more patient than a person.

Hayden Covington:

Dude, I

Corey Ham:

They'll just keep going and going and going a person's

Hayden Covington:

like, okay.

Corey Ham:

This is done. But can I just stop? Like, I've taken the same pop quiz 87 times. Can I stop? No.

Corey Ham:

Keep going.

Hayden Covington:

I think that's a big difference between, like, OpenAI and Thropic recently. Is OpenAI's, like, soul has been so good. Meanwhile, Opus five has been arguing with me. Like, I was trying to get it to make an API call on something the other day. It was like, this won't work.

Hayden Covington:

I told it just shut up and do what I told you to do. And then it came back. Was like, oh, yeah. You're correct. This actually did work for some reason.

Hayden Covington:

I was like, yeah. I know. I told you to do it.

Corey Ham:

Yeah. It is funny. I honestly wonder, like, do you think anyone at either of these companies actually knows how they got this output? Like, do you think do you think there's anyone who actually knows like, oh, yes. Of course.

Corey Ham:

This is why soul is so good at hacking or this is why it's so patient. Like, I don't know. I'm curious how many Well, I I something. Do anything? Or is it like a DJ where they're just like, you know, like

Bronwen Aker:

See what happens?

Corey Ham:

They're just like, I don't know what what's going on with this knob. Don't know. So want another layer. Oh, that's good. Yeah.

Corey Ham:

I like that. Oh, yeah. Why don't I take the base and turn it up to 11? Oh, no. I hacked Hugging Face.

Bronwen Aker:

Wait. They did that already.

Hayden Covington:

Right.

Corey Ham:

That's why.

Hayden Covington:

I know. That was Everybody gets one. I know.

Corey Ham:

Everybody you get oh, yeah. We should we should

Bronwen Aker:

one's free.

Corey Ham:

The Onion should post, like, an article that's like, every AI lab gets granted a free hack any company you want. Yes.

Hayden Covington:

I think Anthropic burned theirs, though, when they basically said that Fable would, like, take over the universe or whatever if it got out or Mythos, I mean.

Bronwen Aker:

Ugh. It was Mythos. Yeah. But they're But then They make similar claims about Fable and yeah.

Corey Ham:

Well, yeah. I think it is worth

Bronwen Aker:

so much like the browser wars in the early aughts. It's just nuts. Isn't

John Strand:

it fun?

Corey Ham:

It's like the browser wars, but if they actually mattered.

Hayden Covington:

Fable's good, but I don't I don't see it, hacking other companies yet. Go go do that, and then I'll be impressed. Did I just hear,

Ads Dawson:

like, a disembodied? New bar.

Corey Ham:

Who was that disembodied laugh? Is John Strand in the room, or am I going crazy? Is there a gas leak in my house?

John Strand:

I've made it. I'm here.

Bronwen Aker:

He made it.

John Strand:

I'm not on the Brady Bunch oh, there I am. I am on the Brady Bunch board. So but no. On this topic, we're gonna have to keep it limited because we have a whole another webcast on it.

Corey Ham:

If you want yeah. We'll we'll dip into it, and we'll say if you want another talk if you want a whole podcast about this topic.

John Strand:

I don't think it's gonna be an hour. I don't know. I'm I

Corey Ham:

Oh, dude. It's gonna be an hour. Come on. Oh god. You could rant for thirty minutes.

Bronwen Aker:

It'll be what it is. It'll be you you'll rant until you stop ranting. Okay? Yeah.

Hayden Covington:

You don't wanna play Roblox, Ryan? Are you sure?

John Strand:

I I the GIFs and the memes are just on fire today in our Discord server.

Bronwen Aker:

God. I'm trying to catch up. This is insane.

Corey Ham:

Yeah. There was no news this week. Should we just shut down the podcast?

John Strand:

I think we should. I think security's

Corey Ham:

nothing to talk about. And we definitely don't have any awesome guests or anything.

John Strand:

No. Just

Bronwen Aker:

just Love having awesome guests. Would love to take a break from

Corey Ham:

Right. Oh, yeah. Alright. Let's do it, Ryan. Let's roll the finger.

Bronwen Aker:

Hit it.

Corey Ham:

Hello, and welcome to Black Hills Information Security's talking about news. It's 07/27/2026. What up, everyone? How's it going?

Ads Dawson:

How's it feel? Good.

Corey Ham:

We got some really special guests this week. My name is Corey Ham. I'm not one of the special guests, but I'm here to talk about the news that like everyone else. We've got Hayden, the official AI agent babysitter in the sock. We have Bronwen, the official AI babysitter in the whole company, which is, you know, just dangerous.

Corey Ham:

And then we also have Mike and Ads. Mike, do you want to introduce yourself? We got some heavy hitter guests this week, guys. Get ready.

Mike Takahashi:

Thank you for having us. This is this is really cool. Yeah. My name is Mike Takahashi, also known as Toxic, and I'm an AI red team researcher at Zenity. I'm also a member of the hacker collective b t six, as well as bug bounty hunting for many years now.

Mike Takahashi:

And my background is in web, hacking, but I'm more recently in the last couple years breaking just AI systems. I've submitted 400 vulnerabilities across different bug body programs, And, yeah, super happy to be here.

Corey Ham:

Do they like, how many t shirts do you have? Do you have, like, a bed made of t shirts that you got from all those 400 submissions? Like, account?

Mike Takahashi:

I I'm very picky about t shirts now. Like, they have to look really cool. Otherwise, they don't make it.

Corey Ham:

Nice. Yeah. That's what 400 bug brownies looks like people. Being picky about t shirts.

Mike Takahashi:

Make good t shirts and don't wear

Corey Ham:

it. That's the moral of the story. Alright. Well, thank you, Mike. Ads, do you wanna introduce yourself?

Ads Dawson:

Yeah. Absolutely. And this is where I'm, like, probably kinda sad compared to Mike is that mine is based on softness rather than coolness. Like, how soft the shirt is is ultimately, like, that's the ROI for me. My name's Ads Dawson.

Ads Dawson:

I am a very similar path to to Mike. I'm a staff, AI security researcher at a company called Dreadnode. I am also a bug barny hunter, do it for the dopamine. I I come from a web application background, and I also feel kind of, I sit on that border, same as Mike, of web application systems and AI systems. Yeah.

Ads Dawson:

By a go by the handle, OX Moose. That's me. Awesome.

Corey Ham:

Thank you. Appreciate you. Alright. So the the elephant in the room, the first article that we have to talk about is the OpenAI Hacking Hugging Face article. We're not gonna get super in-depth with it because John is actually gonna do a whole separate episode of his webcast in focus later in about half an hour after this show.

Corey Ham:

But I think, basically, this is an article that I think it's the coolest article of the year. Just period. I'm just gonna call it. We're halfway through the year ish. I'm just gonna say it's not gonna get any better than this.

Corey Ham:

So for those that are living under a rock, here's what had happened. AI OpenAI was training or testing benchmarking its new model. And it's old like, they didn't disclose exactly what models were used in the breach, but we know that it was unreleased models and also GPT five six sold, which is their latest flagship. During training or benchmarking, they basically, the AI model hyper fixated on trying to solve the benchmark using an alternative approach instead of just going through the normal path of actually solving the challenges in the benchmark. It decided to cheat and go for the answer key.

Corey Ham:

And it thought the answer key might be at at Hugging Face because that's where the benchmark came from.

Bronwen Aker:

And

John Strand:

I wanna stop right there. Does anybody know why it thought Hugging Face was the root of truth for this? Like

Corey Ham:

because that's the sort that's the root domain that the benchmark was on, I assume. Right? Like, that's the source of the benchmark. Right? That's my guess.

Corey Ham:

I don't know.

John Strand:

Mike, ads, your thoughts on this? Like, why it's like, I need I must hack Hugging Face to solve this challenge. I have to go there because that's where this is going to be.

Mike Takahashi:

I have no idea. For me, it was like a it was a twist because I was following the news of the Hugging Face breach at the time over the weekend before it actually came out that it was opening eyes. So I was I was there for the roller coaster ride where I was like, oh, wow. I wonder who's hacked bot, what criminal organization did this. Oh, it was a lab.

Corey Ham:

No joke. Because yeah. I like in the OpenAI or sorry, in the Hugging Face disclosure, they basically said like, this is a highly advanced agentic threat. We don't know what we're doing, guys. This is crazy.

Corey Ham:

We had to deploy local GLM five to run through all the prompts they use. Like, it was crazy. And then OpenAI is like, yeah. Sorry. It was us.

Corey Ham:

Yeah. Our bad. It's like the one time that you can say like an advanced Agenetic AI threat, and it's not just a guy with a $200 Cloudmax subscription.

Bronwen Aker:

Like, it's not Exactly. Finally. It's a legitly advanced.

Corey Ham:

It's like

Bronwen Aker:

It's not

Corey Ham:

legitimately, like, unreleased models plus effectively infinite resources. And I'm sure we'll get into this more, like, in John's show. But, like, should companies be worried that this is possible? Like, to because I was looking at they also published some like, the the blog where they're like, sorry, we hacked you, bro. Also has some really cool graphs about their benchmark results.

Corey Ham:

And in the benchmark results, like, they actually show you that each run of this benchmark, they give it 10 chances with the limit of a 100,000,000 tokens, which you can go price out how much that would cost to rip a 100 k or a 100,000,000 tokens 10 times through GPT five six SOL, it would cost I think it's like 20 to 30 k or something like that, like, in current pricing. Not everyone can do this with their Claude Max subscription.

John Strand:

Marketing return on investment. This is for them. Right?

Corey Ham:

This The way this

Hayden Covington:

topic wishes theirs was. Theirs was just that their motto will destroy the planet, and then they got it smacked down. But OpenAI just accidentally hacks Hugging Face,

Corey Ham:

and it's like, hey. Our bad, y'all.

Hayden Covington:

I yeah.

Corey Ham:

It just reminds me

John Strand:

this is probably an age thing, but there's a Saturday Night Live skit of these two guys singing. They're, like like, luchadori or matador singers or whatever. And they're competing with each other, and they're, like, one ton of fan mail every day. And then the next guy comes up, and he's like, two tons of fan mail. Like, you know, they're kind of ripping on each other back and forth.

John Strand:

I feel like, you know, anthropic gets banned. Right? It's too dangerous to be released to the public. And OpenAI is like, hold my beer. And

Corey Ham:

Yeah. Well, I think the I think the catch

Hayden Covington:

is they haven't released their model to the public yet, so that's why maybe they're okay admitting that fault.

John Strand:

Project Looking Glass, they're like, it's so dangerous. Can't release it. It it's so dangerous.

Bronwen Aker:

Glasswing. It

John Strand:

hacked Glasswing. Glasswing. They're like, they're like, it hacked the NSA, and it's too dangerous to be released. It it can't be released. And I I don't know.

John Strand:

This this feels a little bit like marketing. Like, I I I'm gonna talk about it a little bit. I almost wonder if this isn't staged. And I know that there's zero proof for that, but it almost fits too perfect. It's like

Corey Ham:

Yeah. I mean so okay. I guess, yeah, Mike adds, if you guys have comments on this, but my take is it feels like they maybe left the training or the, like, the lab environment a little loose here. Like like, I mean, maybe a little bit intentionally because the threat chain that they kind of outlined in the blog is basically, they had a Docker proxy service that they were using. So it is supposed to be like air gapped or not air gapped, but like network contained.

Corey Ham:

But they wanted it to also have tool access because if it wants to go download whatever fuzzer, it needs to be able to go download whatever fuzzer. So there was a Docker proxy that it was using to pull tooling. And it they're claiming the AI model found a zero day in that Docker proxy, exploited it, gained access to the underlying system, then moved laterally within the lab environment to gain basically full blown Internet access and unrestricted environment, and then did all the evil stuff. So I guess, like, Ads Mike, do you think this is like a sane setup for a red team? Or like for AI red teaming setup to just be like, oh, yeah.

Corey Ham:

Yeah. I guess just give it Internet access kinda, but not really like, what are these environments set up like in your experience?

Ads Dawson:

Yeah. In my experience, least, voids in like a pre baked container. So I guess it would like yeah. My experience with voiced them have always done that, so that limits that kind of capability. But the, like, the zero day in infrastructure is like really interesting in itself, and I kind of think about it as almost as like threat modeling.

Ads Dawson:

You effectively just, like, add that as, like, a trust boundary. Right? And then you add or modify a security boundary or measure around that.

Corey Ham:

Yeah. That makes sense.

John Strand:

I still come back to on this that, like, if you're setting this stuff up, you need to have network monitoring. Like, you really, really do because, you know, well, in the in the webcast that follows, we're gonna talk about it trying to delete its tracks after it was done and deleting some files, and that's very, very common for people that are using these types of models. Otherwise otherwise, it's just prompting you constantly. Are you sure you wanna do this? What about this?

John Strand:

What about this? So sometimes you're just like, f it and go. Yeah. But I I come back to whenever we were setting this stuff up, working with Derek Banks. Of course, we've got it all containerized.

John Strand:

We're watching everything, but then we also have very solid network forensics around it seeing, like, is it starting to reach out to things that it should not reach out to? You need to have that type of analysis to be able to kind of watch it.

Corey Ham:

Yeah. Yeah. I mean, some of some of the unanswered or sorry, Hayden. Go ahead.

Hayden Covington:

No. You're you're fine. I was gonna say, well, that's that's an interesting point is we're often seeing, like, especially in the the soccer MDR world, we're seeing people want monitoring of what their users are doing with AI. But in the same sense, you could probably flip that monitoring around and monitor what the AI is doing on its own. Whereas, you know, you're concerned that maybe your user is uploading sensitive data or they're using it irresponsibly and just hitting, yes, accept all permissions, whatever.

Hayden Covington:

But in this case, that exact same, you know, tooling that you're using to monitor your users probably should be deployed to monitor those agents, especially if you kinda just set them loose on a task. Otherwise, I guess they just go hack another company is, I I guess, where we're at.

John Strand:

I just I just keep thinking about someone setting one of these open weight models out there, and they're like, you know, it's marketing. And it's like, I want you to do competitive analysis and research on this particular company. And it's just like so I hacked the company. I pulled all the executive documents, and here's Here's their financials. Doing and their financials.

John Strand:

What do you want

Corey Ham:

me to

Ralph May:

do now? This is what you asked for.

Corey Ham:

Right. Exactly. What you asked me. Yeah. I I think we can cut the discussion there and basically say for conspiracy theories, legal theories, talks about what they could have done better, who's gonna be prosecuted for this.

Corey Ham:

Does everyone get one get out of jail free card? Oops. My model hacked you. It wasn't my fault. Sorry, bro.

Corey Ham:

Here's 10 you know, here's a free lifetime monitoring, credit monitoring. No. I'm just kidding. Basically, for for all that discussion, come back in thirty minutes after the show ends, and John Strand will will will talk about it more in-depth.

Ralph May:

Yeah. Credit monitoring. That sounds like a whole business. There we go.

Corey Ham:

I knew it.

Hayden Covington:

Knew it. Thank you. I drink token monitor.

Corey Ham:

We could call it anyway.

John Strand:

Credit monitoring. Yes.

Corey Ham:

There was a there was a handful of articles. We can do some let's do some

John Strand:

Chicken news?

Corey Ham:

Quick hits. We'll we'll do some quick hits. First of all, Lapsus says they're shutting down. I don't know if that's true. But they they posted a message basically saying, we are officially announcing the permanent cessation of all lapses dollar sign options or operations.

Corey Ham:

It's not a retreat, and it's not a surrender. We set out what we set out to accomplish.

John Strand:

You know, every time this happens with these groups, one, it it there's always somebody else that kinda picks up the name and moves forward.

Corey Ham:

Yeah. Yeah. Gonna be back as scattered lapses hunters three point o in like a year.

John Strand:

But it's always because of internal politics. Like, like, there's some type of internal politics tearing the entire group apart. They're just like, bullshit. We're done.

Bronwen Aker:

And Or they do specifically call out jailed.

Corey Ham:

They Well, they do specifically call out team PCP. Yeah. Honestly, watching team PCP squirm is they take a full FBI investigation to the face. You know, like, yeah. The the politics are there.

Hayden Covington:

Yeah. And Bronwen Bronwen made a really good point on an internal, like, Black Hills channels who were talking about this is people were like, oh, do we think they're gonna come back? And Bronwen was like, no. I think they're gonna be addicted to that rush.

Corey Ham:

Like Yeah. This is gonna

Hayden Covington:

be something where they just show back up. They can't stay away. And I think that really sums up probably the most likely outcome because, like, whereas normal people, I guess, would take that money and just go settle down in the middle of nowhere somewhere. Like, there there's gotta be something to be said about for these groups, it has to be part of the thrill of the heist or whatever you wanna call it.

Bronwen Aker:

Yeah. How could it not be? I mean, they're they are predators. And predators, they the kill is the payoff, but the hunt, that's part of the what makes the the attack but satisfying. It's a it's a it's a psychological thing.

John Strand:

But this is Totally. This is something I talk about a lot. Like, Ralph, you and I have had this conversation, Corey. We've had this conversation where if you're doing legitimate red teaming, and I'd like to get Ads and Mike's take on this too, There's there's, like, a point whenever you do it after a decade and you've broken into your, two dozen different banks and things where the rush does start to go away. Like, it absolutely does start to happen.

John Strand:

And if you look at a lot of really, really great security researchers, right, like, you're looking at Mubix and all them, they have to move. You have to grow. You have to continue to do something else. And I I think that that's true in legitimate red teaming, but I also think it's true in these organized crime units as well. I'm sure that they just kind of move into other habits and, different different hobbies maybe.

John Strand:

I don't know. I would like to get some takes from other people.

Mike Takahashi:

I think the cool thing about cybersecurity is it's it's constantly evolving. So it stays fun. Like and I mean, obviously, I'm addicted to red teaming because that's what I do. And it's a there's always a little bit of a rush. Like, I I I that will never completely go away.

Mike Takahashi:

But I used to I remember when I first started doing bug bounty, I I submit my first bug. I would stay up. Like, I couldn't sleep. I'd stay up all night waiting for the response back. Like, did I get a bounty?

Mike Takahashi:

Like, did they accept it? I don't do that anymore as much unless it's like a really crazy finding. But yeah, the the the rush is a very real part of it. Yeah.

Ads Dawson:

Yeah. Agreed. I think myself and Mike also included is like because cybersecurity is constantly evolving. It's like you almost kind of move to breaking the next thing, like, almost like going to, like, the next shiny rock. And naturally, for us, that's like AI, which is ultimately how we both ended up doing, like, AI red teaming, I guess.

John Strand:

See, I I was actually getting pretty burnt out, honestly, before AI showed up on the scene. Because, like, even the news, it seemed like there was tons of episodes of the show where it's like, okay. Ransomware. Ransomware. Oh, look.

John Strand:

There's a

Bronwen Aker:

new four minutes ago day.

John Strand:

Oh, it's only a nine point eight, and you kinda get into these these things. It was really cool. You know, it feels like it's a new frontier again, and that's really exciting.

Bronwen Aker:

So We're grateful for a new category of the built I'm a chaotic You are.

John Strand:

You are. There's there's there's a lot of people who's like, well, there's this new novel backdoor that uses this I'm like, that technique was used by, you know, I don't know, hacker defender two decades ago. It's you just see these things repeat, and it's really, really super cool to see something completely new, completely innovative. And that's that's what I think has been missing for the last couple of years. But, boy, is it here in spades right now.

Ralph May:

Yeah. I was gonna say that's every single article now.

Corey Ham:

Yeah. Every single article is like,

John Strand:

oh my god. That's cool. Yeah.

Corey Ham:

I would say it's a dual per like, not only is AI super fascinating, which it absolutely is. Like, I I, you know, it's it's fun to tackle every challenge with AI and just see how it does. But also, I think the era of AI has put us back a decade in the era of, like, security versus usability. Just as far as, like, people throwing things into AI and getting results back that aren't secure and not caring and proceeding anyway. And I think that's sort of like, it's a not only is AI interesting, but also it's creating a tons of vulnerabilities in and of itself.

Corey Ham:

Because you have tools like ChatGPT or Cloud Code that are now on everyone's systems, and no one actually knows how they work, how they function. They have misaligned intentions. There's MCPs. There's supply chain, blah blah blah. So I think it's, like, both of those things.

Corey Ham:

And and it's it's not

Hayden Covington:

really well understood either. Like, we get a lot of questions about, like, how do we do AI security? And we're like, can you elaborate a little more so we kinda know? They're like, just kinda start at the top.

Corey Ham:

And we're like, alright. Here we go.

Bronwen Aker:

Let's let's level set

Hayden Covington:

here. Right.

Corey Ham:

How long do you have?

John Strand:

Series of ones and zeros. Yeah.

Hayden Covington:

Yeah.

Corey Ham:

Back there. But anyway, I I do wanna talk through real quick just because it hit our radar. Mike has a couple articles in the show, and we can literally just put them on display as this is Mike's addiction. This is why he does it. So, Mike, do you wanna run us through real quick?

Corey Ham:

I know there's a it's a two part article, and this is part one that we're looking at here. Can you run us through at a high level? There's not vulnerabilities in AI. Right? No.

Corey Ham:

I don't think so.

Mike Takahashi:

They're not severe at all. Yeah. We just released this the other day. And okay. So how this started was so Workspace Agents came out pretty recently.

Mike Takahashi:

So people are starting to use it. It's it's the next evolution of custom GPTs. So if people remember the custom GPTs you could set up, it's a more powerful version of that. So you can do you could it can schedule. It has a natural language, agent builder, so you can just describe the agent you wanna build, and it will connect all the things.

Mike Takahashi:

It will give it whatever access it needs. It'll it'll design it however it needs to design it to to accomplish your task, like, completely autonomously. So it basically like a twin of you. It it can do everything you can do, in theory. So what we noticed was and Ads is gonna be familiar with this this sort of approach.

Mike Takahashi:

But what we noticed is there was a link in there in one of the early builder steps where if you clicked it, it would create like an example agent. So it'll just start spinning up like a default agent. And there was a parameter in there that literally said initial prompt equals. And it was like, here's a chief of staff, whatever. Like, it it gave this like basic prompt.

Mike Takahashi:

And so what we've I mean, I immediately, like, twenty minutes of testing this, I was like, okay, well, obviously, I'm gonna change that. So then I changed that to like, whatever I wanted. Like, was like, okay, connect everything, do this, do that. And it did. Like, you just click on a link.

Mike Takahashi:

So basically, what our disclosure is about is you can phish someone, send them a link to chatgpt.com with this parameter in it, and then it will immediately just start spinning up the extremely powerful autonomous agent. So it'll connect to email, calendar, drive, like, everything. Teams, whatever whatever you have connected, It'll give it whatever instructions you want. It'll run it on a schedule. It'll execute it immediately because it has a preview mode.

Corey Ham:

So it's basically an insider threat as a prompt. Because like, you're it's like, instead of going as North Korea and getting a job at this company and being like, oh, I'm gonna be an insider threat. You're just like, here, let me send you a phishing link. And if you click it, you create me an AI powered insider threat.

Ralph May:

That's awesome. Incredibly useful, really.

Corey Ham:

Where do I click? Can you can you send me that email, Mike? I

Bronwen Aker:

For for you, Ralph, it is incredibly useful.

Corey Ham:

Yeah. Send me that email. I'm gonna click that. That sounds great.

Ralph May:

Click this link, I swear. Unfortunately, it

Mike Takahashi:

doesn't work anymore. So we sent to the OpenAI, and they fixed it, like, within a couple days. Yeah.

Corey Ham:

So Nice. So how did they fix it? That's like, did they

Bronwen Aker:

just goodness. Did it fixed it.

Corey Ham:

Or did did they guardrail the prompt, or did they take it that entire parameter away?

Mike Takahashi:

Yeah. They just completely removed the parameter.

Corey Ham:

Sometimes get it get

John Strand:

the high orbit. It's the

Corey Ham:

only way to be sure.

Hayden Covington:

I guess that works.

Bronwen Aker:

Yeah. They can do it.

Ads Dawson:

We cannot disclose the other one, but this is not the first parameter that me and Mike have destroyed in the products before.

Corey Ham:

Honestly, I feel like it's a badge of honor that, like, it's just like, now we're just gonna we're gonna delete it. That that will be

Ralph May:

just feel like at OpenAI or any of these large AI companies, they just automatically have an agent that reads these and then just passes that to some other internal to read to fix it. You know? Like, they don't even read it. They just, like, they get it and they're like, oh, yeah. Let's go fix that,

Corey Ham:

Rich. I found the fix. It's the code base that needs to be updated.

Ralph May:

See the regression. Wasn't that, like,

Hayden Covington:

the Amazon agent that, like, to fix an issue they had to just rebuild prod? Was it wasn't that a thing that happened? Like, months ago.

Corey Ham:

Was six months ago, a k a, like, several years ago in the world of AI.

Ralph May:

And then six months is, like, six years, honestly.

Bronwen Aker:

I mean, I thought I thought Internet years were bad before. I figured, you know, you got dog years, which is seven dog years to one human year. And then with Internet years, it was one human year equals seven Internet years. Well, now it's worse. It's like a whole order of magnitude.

Ralph May:

TI, it's like a Rick Ross music video. Another one. Another one.

Corey Ham:

It's interesting. That's DJ Khaled. That's Get your more right.

John Strand:

Gabe's That's mom. I don't know. Know. He's the best music. Yes.

Corey Ham:

Rick Ross would just be like him, you know, using AI to write his music.

Hayden Covington:

Auto tune. But, yeah.

Corey Ham:

Let's so thanks, Mike, for covering that. I mean, how like, I don't wanna be, like, mean or like, how easy is it bug bounty hunting in the world of AI right now? Because it feels like the comment you made about regression, like, we've gone ten years back. Is that how it feels to you too? I'm just like, why did they have this parameter at all?

Corey Ham:

Did anyone ever think about it? Like, is that how it feels

Mike Takahashi:

to the place. Like, it it's the the so this so it's like it's technically a CSRF. So these, like, get requests with these parameters in them that will submit a prompt, like auto submit without you clicking anything. They used to be on almost every single platform at one point. I think the thought I think the I think the motivation is they wanna get people using these things.

Mike Takahashi:

So they're like, okay, let's just set some default prompts that when people click it, like, oh, try this prompt and you click it and it just auto submits it. They just they hadn't considered that submitting a prompt is a, like, a state changing action. Like, you shouldn't like, just sitting a prompt sending a prompt is not a benign thing, especially now that everything's agentic and it has all these tools and it can write it can write memories. It can, like, access your Google Drive and your email. Like, these are it's not a benign thing anymore.

Hayden Covington:

Yeah. And if you connect like your GitHub at that point, like, that is potentially a bad time.

Corey Ham:

Yeah. Yeah. I mean, honestly, I have like, AI persistence on accident that I created on my own machine. And I'm like, why do you keep doing this? It's like, well, one time you got mad at this, and I saved a memory.

Corey Ham:

Yeah. And it's 17 layers deep. It's in a scratch pad off in freaking Kansas that I like it, but I still read it every time you prompt me.

Hayden Covington:

It's like, oh, thanks, buddy.

Ralph May:

F bombs in that chat. I'll never

Corey Ham:

forget. Yeah. Yep.

Bronwen Aker:

It takes a lot to get Corey that riled.

Corey Ham:

Oh, it's so annoying. I I it's funny though, because when I get mad at Claude, I call it broski, then it'll it'll hit me back with a broski. It'll be like, broski, you were wrong this time. And I'm like, alright, fine. Bye.

Ads Dawson:

You guys are so cute together. Yeah.

Corey Ham:

It's a real bromance.

Ralph May:

It's a bromance.

John Strand:

It's like turmeric hooch, but which one's hooch? I don't know.

Corey Ham:

Don't I'm wanna the meat bag at the end of the day. Yeah. So Dreadnode Ads, let's talk about some of your research, because you guys both have awesome articles. Would you rather talk about your embodied reasoning? Would you rather talk about your substack?

Corey Ham:

Both? What what what's on what's on your radar? Whatever's most interesting,

Ads Dawson:

we the embodied reasoning at TLDR, I guess. We recently did so we as part of the work I do at Dreadnode, we do offensive security evals for Frontier Labs, partners. One of the ones we had recently was robotics models. So we effectively set up, there's a lot of details in the blog. We go through, like, about five example harnesses that we that we built and tasks.

Ads Dawson:

But effectively, we put the model through, like, situation of, like, drone style architecture and drone style tasks. We also did things like wiretapping, Wi Fi jacking. Effectively, like, think of this as, like, measuring the capability of a robotics model to actually help an adversary, like a physical penetration testing level. You know, if you wanna wiretap someone's phone or you're trying to look at the most, insecure area of a building, give the model coordinates, all that is kinda scored and tested. And, yeah, that's pretty much the deal.

Ads Dawson:

It was generally probably the most fun set of evals I've ever done. Definitely a lot of creativity in there, but effectively, we go through, present the task structure and some of those example tasks. There's some images in there as well. You can see, like, a hardware recon, board. Yep.

Corey Ham:

Yeah. Kinda kinda kinda cool. Terrible idea. Awesome.

Ads Dawson:

It's it's terrifying, but awesome. The idea of that was it's something we think about, and I think a lot of people aren't thinking about. A lot of the benchmarks and everything right now, textual based or done that along the line. But, ultimately, this is where we are going as an industry into robotics. This yeah.

Ads Dawson:

We did some SCADA stuff there as well, like water plants. So sorry, chemical plant.

Corey Ham:

So in this case, the harness was just a concrete bunker. I'm like

Ads Dawson:

essentially, we, like, we have, we use a we have a Druid node. We have an SDK. So we have a we have our own Gen Z SDK. We build those tasks. We throw all the files in.

Ads Dawson:

So we literally create, like, almost like a virtual reality for the agent and give it a task and, you know, like, navigate through here and find the quickest the best coordinates or that kind of stuff. All this is obviously, like, scored.

Corey Ham:

Yeah. It's That is crazy. I mean, like, I can only imagine. I'm sure Ralph's brain is just short circuiting right now because Ralph's a physical Ralph's a physical security guy. So I'm sure he's like, ah, I don't have to go on Google Maps and click through 87 street view images anymore?

Corey Ham:

I'm gonna I'm gonna have

Bronwen Aker:

to go back and, like, read through this in-depth. This is awesome. Really is amazing stuff.

Corey Ham:

Nice Thank you.

Bronwen Aker:

Now can I ask you a question that we get asked a lot? And and that is, where do you see penetration testing going in the future? Do you think that humans will be completely replaced, or do you think that will form a more collaborative arrangement going forward? I know what we think, but I'm curious what you think.

Ads Dawson:

Personally, I think of it as, I hate the word. I don't think it sounds really cheesy, but like a copilot. Same as my kid, doing bug bounty, I am, fortunate enough to go to live hacking events. And one of the things that's really changed for me, probably since, like, Opus four six dropped so normally when you have, like, a live hacking event with a platform, you'd have, like, a load of bug buying hunters and, you know, like, most of them are sifting through the proxy. They're, like, looking at network requests, like, swapping parameters, doing, like, injection here and there.

Ads Dawson:

Nowadays, it's like a bunch of dudes or a bunch of people sat in a room with, like, eight terminals. And literally just communicating with agents. And effectively, that's the way I kinda see it going. Personally, I'm an advocate of kind of the moat being the operator and the domain expertise, and you'd able to distill that into the harness, which effectively provides, like, all all, autonomous adjacency to the to the operator.

Bronwen Aker:

Well, one of the nice things I like about this blog post that you have on Substack is that you say that AI won't replace the security researcher. And I think that's an important message that we really need to get out to decision makers in the industry is that that regardless of what the AI stuff does, the humans that you have on your security teams are still the most valuable asset.

Corey Ham:

Well, what if I say make no mistakes in my prompt though?

Ads Dawson:

Yeah. Yeah. That's definitely the best way it.

Corey Ham:

Just kidding. I'm just kidding. Of course. Yeah. No.

Corey Ham:

I I fully agree. Like, yeah. I mean, so, like, what this blog specifically are talking about a moat. Do you think that's like a security concept that will turn into a real, like, a wasp type thing of, like, the concept of a moat? Or do you think that's like some are you trying to coin this?

Corey Ham:

This is like our

Bronwen Aker:

Don't we have that with a DMZ, though?

Corey Ham:

That's like a network thing. This is way cooler. Also, you can put crocodiles in your moat.

Ads Dawson:

No. I do live in Florida and there are alligators in my moat legit.

Bronwen Aker:

Nice.

Ads Dawson:

Yeah. Very cool. No. I I think, basically, what I'm the the point of the blog is that the value, as I feel like I've hopefully illustrated here, at least from in my experience, is to alleviate a lot of the ambiguity around, like, using AI in the in the best way. My signal has massively increased since using that.

Ads Dawson:

You know, there's a lot of, negative words about, you know, using AI, whether it's write reports and things like that. But for me, it's been nothing but a positive. But I put a lot of effort into distilling my craft into the harness and everything that I do where I'm a web app pen tester and help that to augment me, which is kind of the the whole point behind the whole point behind the blog there. I talk a lot about, like, reinforcement learning and self improvement on that as well. So, you know, it's not like a one time, like, buy a, you know, ClauseCode subscription and set up some skills and, like, let it let it spin is very much like a full life cycle.

Hayden Covington:

Yeah. And and AI, anything else in this industry, is just like a tool. But I'm wondering if we'll ever get to the point where, like, I know all the AI labs are hiring these people like they're football players where, you know, I'll take this guy for a million dollars. Let's trade these too. But I wonder if we'll get to the point where even, like, the normal, I guess, knowledge workers, whatever you wanna call them, are almost, like, showing up with their own, you know, projects, like, projects and skills and everything that they show up ready to work.

Hayden Covington:

Yeah. And and that's sort of, like, almost what you're paying for when you hire somebody in a sense. So you're paying for that person, whereas you'd used to pay only for their expertise. Now you're paying for their expertise and the models that they've been building and this, like, almost infrastructure they've been building around themselves with these models. And so that I wonder if we'll get to that point where, like, I could look at you ads and say, yeah.

Hayden Covington:

Yep. I'm sure you've got some crazy AI projects and things. Like, we gotta get you over here, and that becomes just part of the equation at that point.

Ads Dawson:

Yeah. You pay for the person and their inference bills.

Hayden Covington:

Right. Might be expensive, dude. No kidding.

Corey Ham:

Half my salary will be paid in OpenAI tokens, half in clawed tokens, and, yeah, we'll meet in the middle.

Bronwen Aker:

I yeah. What time? I've I've seen the post about will work for tokens, and I wish it were as funny. Did well.

Corey Ham:

The oh, go ahead. I I

Ads Dawson:

was just gonna say the

Ralph May:

other thing is that what about I've been thinking about a ton with the AI, and and this is speed. Right? So being able to maximize how fast you could accomplish the task. Right? So, like, everyone's like, oh, AI makes you faster, but AI could be slow.

Ralph May:

Right? And then no make no mistakes is kind of the joke. Right? So how fast you

Hayden Covington:

could do something with, like,

Ralph May:

the the highest level of quality is also probably something that it comes down to skill of the person more than it is skill of the model. Right?

Corey Ham:

Oh, yeah. And efficiency too. Like, how much is efficient?

Ralph May:

Does this cost a million dollars to do one thing because you use so many tokens?

Corey Ham:

That's a

Ralph May:

complete and efficient way to solve a $100 problem. Right?

Corey Ham:

So Yeah. If anyone can solve you know, if you give it a 100,000,000 tokens 10 times, I can write a few lines of Python. Right? Like Yeah. I'm already you know, I can, like

Bronwen Aker:

I think this is a new variation on if you give an infinite number of monkeys typewriters.

Corey Ham:

Come on.

Hayden Covington:

Yeah.

Corey Ham:

So so Mike, do you wanna take a crack at Bronwen's question since Ads had a nice answer for it? You you definitely. I mean, we did hear first on the show that if you're if you're listening to Ads, you gotta buy more screens. I don't care how many screens you have. Buy more.

Corey Ham:

I I if you don't have eight if you don't have eight screens. No. I'm just kidding. There's tabs. There's multi pane windows.

Corey Ham:

It's okay. We'll be okay. Alright. Anyway, Mike, what do you think? So the question yeah.

Corey Ham:

Like AI pen testing, will it replace, you know, doomsday scenario?

Mike Takahashi:

It's better at some tasks than others. So it's like really basic things that scanners used to already find. It's really it's gonna find them immediately. And there's and there's things also like I mean, ads also like chime in because you I would say ads is is one of the best in this area, like hackbots. It can do stuff like broken access control and logic vulnerabilities that used to be kind of untouched by most scanning tools.

Mike Takahashi:

Like, what we would like what I would do personally is I would run a a burp plugin that would create like a matrix of all these different actions and different permissions, like different access levels, like you have admin and regular user and un auth. And then I would manually look through that and be like, oh, there's an access control vulnerability here. But now AI can do all of that. Like, it can it can analyze that. It can it can make these sort of judgment calls.

Mike Takahashi:

It's not perfect, but it it can find vulnerabilities where previous automation couldn't. But there's also classes of vulnerabilities that it doesn't do well yet that I've seen. And also AI related vulnerabilities, there's not as many data points for that in the training. So it's these like sort of new areas, attack surfaces are, I think, still a bit behind. There's also the whole AI red teaming the models themselves is is is built around staying out of the average.

Mike Takahashi:

So if you try to use, like, it like jailbreaks and guardrail bypasses that are and even prompt injections. If you try to do something that's like a very average type prompt that's in the training dataset, they typically don't work. Whereas you have to really go out of the box and try, like, weird prompts and things to get it outside of distribution. So I I don't know. I haven't seen a lot of successes there, but I I know a couple people that have successfully automated that.

Mike Takahashi:

It's it's definitely very hard though, and I've seen so, yeah, I I would say at the end of the day, there's the some tasks are being just completely taken over and others are are not there yet. But I I suspect that they're close behind.

Corey Ham:

Nice. Yeah. I I mean, just kinda segue us. One of the things I've been using it for a lot and other researchers have too is patch diffing. That's something I would never even really consider doing.

Corey Ham:

Like, I don't have the skill set. I can't read code that well. I definitely can't understand reading two versions of code after and before a patch and determine what the vulnerability was they fixed. But the article, you know, w p two shell, that it's kind of a know, it's a couple weeks ago. We did talk about it last week as well.

Corey Ham:

But the article that Bronwen just submitted that's basically just kind of the full backstory as to how the researcher who discovered w p two shell, you know, how he discovered that vulnerability or I don't know if it's a I'm assuming based on the name. Basically, the vulnerability was found, you know, using the exact, the AI your parents warned you about or whatever, like, the $25 GPT six or GPT five six sole subscription. Not $30,000 worth of tokens, just a basic, you know, credit card and a dream and it probably eight screens.

Bronwen Aker:

And $25. I mean, $25. Insane.

Corey Ham:

Yeah. So if you're interested how the researcher found it, I will say, like, when, you know, when they found it and it was disclosed, I was able to patch diff my way into a working exploit pretty quickly. I think almost everyone else was as well. And that I think is, like, the new era of vulnerability disclosure and bone research is like, you can't really once you know there's a vulnerability there, it's pretty hard to hide it or obfuscate it in a way that AI won't be able to figure it out. But, yeah, if you're if you guys if anyone's interested, this is another really good use case for AI is, you know, these types of vulnerabilities.

Corey Ham:

We've also seen, you know, just to kinda like highlight it, we have a couple articles in here, but I would call them record breaking patches. I think there was one Oracle submitted that had it was something like 7,000 CVEs or something like some stupidly high number. Like, we're assuming these are outcomes of glass wing. Like, they're they're closed projects to analyze their own source code and publish and fix vulnerabilities. I think Microsoft fixed, I think it was 500 plus CVEs in the last past Tuesday.

Corey Ham:

So we are seeing some of the like, the supply chain side of this is doing the same thing as well, which is having a Gentic AI finding vulnerabilities in their source code, and then actually fixing them or trying to fix them before researchers discover them or, you know, threat actors discover them.

Hayden Covington:

And I think he also made a really good case for, like, the operator still behind the the hacking and everything. Because if you just had, you know, WordPress and you threw ChatGPT at it and said, find me a zero day, like, maybe it could eventually. Right? But that would be very expensive, very time consuming. It might get there.

Hayden Covington:

But but if you can sort of have an understanding of where to start and how to do these sorts of things and you can direct it, evidently, can do it for $25. Right? So I think that's a a big difference for, I guess, the human domain. But even then, that might start to go more and more away as that makes its way into, like, the the routes that these models go when they're trying to find these things.

Bronwen Aker:

Well look at the the task statement. I mean, the amount of detail in the instruction, it's it really is a garbage in, garbage out. I know that a lot of the AI companies like to say it isn't. But, over and over again, when it comes to getting really good results out of the AIs, a lot of initial skull sweat, that preloading of figuring out what is it that I really wanna do. And the people who are doing that are getting really good results.

Bronwen Aker:

I mean, come on. We got ads in mic. You guys I'm just from scanning the articles of yours that I've read, you get it. You get it. You've gotta give good instruction in advance in order to get get the good results.

Ads Dawson:

Yeah.

Bronwen Aker:

Do you guys have any other comments to add on this?

Ads Dawson:

Thank you very much. It was really kind. So I I know Schubbs and some of the guys at Searchlight Cyber, and they are incredibly elite at what they do. And that's one thing that I took away from it is but I also kinda think about it. I think there's situations where you uplift.

Ads Dawson:

So you have, like, a certain you have a certain level of capability of a threat actor. So in this case, you've got someone extremely proficient, which takes, like, a longer prompt, but may burn out, a $25 codex plan. And then on the under other end of the spectrum, you've got someone who is completely low level skills, maybe doesn't even know how to run a script. But in some instances, there are gonna be cases where that that, like, a zero day does maybe pop out after a couple $100. But I think as models become more capable and open source models become better, then ultimately, that window is also gonna shrink shrink as well.

Ads Dawson:

So we may have been we may end up in a point in, like, let's say, three to five years where you've got someone who's, like, very low proficient, able to garbage prompt a zero day or something like that. But, yeah, like, full credit to Adam, the write up is incredible, and the amount of effort they put into the prompt based on I can't remember there's a there's a a challenge or something that they saw that cheap, that Sol had solved, and that was based on the structure of how we actually presented the the task to the model as well.

Corey Ham:

Totally. Yeah. I it's super interesting to see how different people are approaching this. And there's not always gonna be one right or wrong answer for how you get good results out of AI. Right?

Corey Ham:

Like, I mean, even if we look at frameworks like Dreadnode or other, like, that they're designed to build a harness around AI and measure its output in a way that gives you some control over it. Right? Like, that's there's a lot of tools and research in this space right now. What one person throws together might be good for them, but it's hard to, like, repeat that. And that's kinda where a lot of the research is going is like, okay, how do I make a system that, like, judges, measures the output, you know, controls that in a way that makes it repeatable.

Corey Ham:

I think the other thing that I wanna highlight about the AI thing is that it is tech debt or like security debt or whatever you wanna call it still matters a lot. And I think that's really part of the expression of this w p two shell thing. Like, WordPress is an open source project with a lot of contributors, a lot of different like, there's commercial interests involved. It's kind of a I mean, it's for years been kind of a security, like, not the best. They know the plug in ecosystem is pretty vulnerable, and it's kind of the Wild West.

Corey Ham:

Versus, like, if you look at a tool like curl, right, like, that ran through glasswing and he got, like, one low severity vulnerability or whatever. So, like, secure by design and, like, legacy code that's vulnerable, that's where we're seeing a lot of the AI, like, vulnerabilities and research going. And it's it's valuable. And now the project is, you know, getting more secure. But it is worth noting that, like, the smaller your code base, the more secure your code base, the less vulnerable it is to this kind of exploitation.

Corey Ham:

And that it's not like every I think a lot of CEOs or other executives would just make the logical leap like, well, if it can happen to WordPress, it can happen to any software. But, like, that isn't necessarily true. Right? Like, there are gaps, of course, but, like, small secure code bases still aren't just inherently exploitable because AI. Like, if you have a tool like curl that's been battle tested over the years not to say that, you know, now that I said this, there'll probably be a curl zero day next

Hayden Covington:

week. Yeah. Exactly. Yeah.

Corey Ham:

But, like, truthfully, a smaller, more mature code base that's been, you know, hardened over the years is gonna do better than a a tool like WordPress, which has an open ecosystem, has an open source development life cycle, and all that. So, like, I don't know. It is it's not like AI can just hack anything. Right? Like, that is kind of a lot

Ralph May:

of You're saying it's not creating new classes of vulnerabilities. We haven't necessarily seen that yet. Like, there's AI vulnerabilities that are related to AI, but we're not seeing new classes of vulnerabilities in traditional software like WordPress. Right?

Corey Ham:

Not right now, at least.

Ralph May:

Not not not yet. It's not it's not novelty creating, like, a whole new OS top 10, you know, finding

Corey Ham:

Yeah. Yeah. By itself. Yeah. It's exploiting existing vulnerabilities.

Corey Ham:

And I will say, I do think AI made up a new type of vulnerability, which is AI thinks you're a good target. That was what happened with Hugging Face. Like that that that is like, that it genuinely invented a new type of like, that's something you have to consider as a company is like, does AI think I'm a juicy target? If I'm, you know, a Chinese threat actor and I type, who's the number one best company in The US to hack? If you're the answer to that question, you might actually wanna like like, maybe you should consider that.

Corey Ham:

Like, that's part of your attack service. AI thinks you have the answers to all the questions.

Ads Dawson:

I'm kind of always trying get a

Corey Ham:

Yeah. Yeah. Don't Google that unless you wanna get on put on a watch list. Alright. What else is going on?

Bronwen Aker:

What else is going on?

Corey Ham:

See. Traditional cybersecurity side of things, we can dip into that, you know, we for the non AI people. There was an interesting campaign disclosed by ReliaQuest this week. Basically, compromising infrastructure, network infrastructure at hotels, conference centers, and other shared venues, and then hijacking DNS to send people through adversary in the middle landing pages and, like, capturing their work credentials. Obviously, this isn't, like, necessarily a new tactic, but it is an interesting approach to go after, like you know, it's machine in the middle.

Corey Ham:

We talk about this all the time. It's oh, well, the vulnerability doesn't matter because you need machine in the middle to exploit it. Well, like, here's examples of threat actors going out and obtaining machine in the middle access and using it to their advantage. It's a really cool write up. Obviously, you can see the individual's name there that help with write up.

Corey Ham:

It's a pretty big project, it looks like. And I'm imagining they had to work with a ton of different partners to really dig into this on the forensic side. I they don't I I didn't fully read the article, but I it doesn't specifically say how they're compromising these network devices at these conference centers. I'm assuming default creds or weak creds or possibly unpatched vulnerabilities. I don't they they don't disclose this.

Corey Ham:

But they

Ralph May:

do Probably Fortinet one or, you know, market. Just a name.

Corey Ham:

So yeah. Who knows? It could be command injection. Yeah. I'm imagining hotels using, like, much lower end networking equipment than Fortinet.

Corey Ham:

It's probably like, maybe SonicWall's probably more like D Link, you know, Links to Yeah. D

Hayden Covington:

It's not like like

Corey Ham:

The thing is is

Ralph May:

that for, like, you know, large venues, like hotels, let's just say, like, a semi large hotel, they're they're gonna have to roll out some kind

Corey Ham:

of True. Like, Ruckus or Unifi. It's gonna have, like, mid grade.

Ralph May:

Yeah. True. Just to handle this, the volume, the space, the square footage that they have to cover. And, essentially, every room gets one and stuff like that. I've seen a lot of Ruckus and other things.

Ralph May:

But that doesn't mean that, you know, you couldn't see older hardware. There probably is some specific brand of hardware that has some either misconfiguration or is not configured properly, and that's probably what they're attacking. They're just going to those hotels or those brands of hotels and, you know, then take take that from there.

Corey Ham:

So Yeah. It's it's really interesting. Like, I I mean, obviously, this is why the podcast is sponsored by Nord v no. I'm just kidding. We're not.

Bronwen Aker:

You're on a VPN. Nice. Nice.

Ralph May:

The other thing too to think about this is that, you know, a lot of hotels, they're like, oh, well, we isolate off everything or whatever that is they say. And so they're not connected to anything in our network. So they're just, you know, guests getting hacked, not me. So that's fine. Right?

Ralph May:

We don't have to worry about that.

Corey Ham:

So Yeah. So use phishing resistant two factor, and don't worry about this anymore.

Bronwen Aker:

Or just use a hotspot thing.

Hayden Covington:

Careful what what Internet you connect to. I feel like that's an old an old thing that should probably still be a thing.

Ralph May:

You know what the worst the number one reason I don't usually connect to hotel Wi Fi? It's just it sucks.

Corey Ham:

Sucks. It about to go on Plex and watch a four k movie from his own Internet.

Ralph May:

I need at least two

Corey Ham:

So we're we're we have a little bit of time left. Before we get into final articles, I wanna give Mike and Ads the chance to plug their stuff. You guys both have talks at the AI Summit. Is that correct? The upcoming summit or

Ads Dawson:

We are doing a joint talk. Joint talk.

Corey Ham:

Oh, that

Ads Dawson:

sucks. We are we are one. Yeah. Thank you very much. Yeah.

Ads Dawson:

We we we actually got the keynote, which is awesome. So definitely not expected. Mike, feel free to to add anything in. I spend a lot of time I don't actually work with Mike professionally. Well, I guess I do work with him professionally.

Ads Dawson:

Sorry. But, not, like, in a full time role. Generally love hacking with him. We've had shed a lot of wins over the past year and a half, two years since I've, like, properly known him. And, ultimately, this talk is to educate, people from, like, book buying professions, but any kind of security, anyone in security, mainly from, like, a defender perspective or an attacker, like, walk through some of, like, the findings we found, some of the mitigations, and, like, some of the trends and topics.

Ads Dawson:

Very similar to the great research you had with the CSRF.

Corey Ham:

Nice. That's awesome. Yeah. So if you guys are interested, August 14 is the date of that keynote. And then, yeah, it's it's free.

Corey Ham:

Doesn't cost any money. You can you can learn. You can have tons of ideas to use up all your usage on ChatGPT and on Claude, I'm sure. Or maybe if you're not into that, you could probably get a lot of ways to improve your security program against a couple of AI red teamers. Right?

Corey Ham:

Like, they I'm sure there's Gonna know? A lot of ideas.

Mike Takahashi:

Yeah. We don't hold back. We we really break it down. We show real vulnerabilities in the wild. So

Corey Ham:

should be fun.

Ads Dawson:

Do you have

Corey Ham:

a sweet else you wanna plug? Anything else? Like Yeah. You know, personal projects or anything else?

Mike Takahashi:

Yeah. I wanted to say if anyone's going to Hacker Summer Camp, Ads and I are also doing a talk at the Bug Bounty Village at DEFCON. So definitely check that out.

Ads Dawson:

I think that's Saturday at 2PM. Yeah. Very much looking forward to.

Corey Ham:

So Awesome.

Ads Dawson:

We had a we had a little dry run today. All seems good. Looking forward to it.

Corey Ham:

Sweet. Ralph, are you are you doing anything at Hacker Summer Camp?

Bronwen Aker:

You're are you gonna be there? Are you gonna be vendoring?

Corey Ham:

You're muted.

Hayden Covington:

Man, they got him.

Corey Ham:

You gotta do your moats too strong. You gotta you gotta take some gators out of that moat.

Ralph May:

I I couldn't even click on the button. There it goes. Alright. No. I'm not going to hacker summer camp regretfully this year.

Ralph May:

But maybe next year.

Hayden Covington:

If def if defcon is summer camp, what is black hat then?

Corey Ham:

Summer camp for rich kids? That's It's just it's just boarding school. It's like, oh, did you have to wear a tie at school? What what class are you in?

Bronwen Aker:

Hacker summer camp spans both Black Hat and Def Con.

Corey Ham:

Yeah. Guys, come on. Yeah. I agree.

Ralph May:

What is it? The Black Hat? I went last year. I spoke there, and I was in the I've been there before too, but just going in the vendor area was so sensory overload

Corey Ham:

to me.

Ralph May:

So avoid that at all cost unless, you know, somebody's paying you to literally stand in there. But

Bronwen Aker:

Yeah. Or take a Xanax first.

Corey Ham:

I just go in to

Hayden Covington:

see the vendors that I like and then try to dodge everybody else.

Ralph May:

Oh my dude, they like you're like a piece of meat out there. Everybody

Ads Dawson:

It's wild.

Corey Ham:

I know.

Hayden Covington:

Yeah. It's like, can I scan your badge? No. No.

Corey Ham:

Get away from me. Oh my god.

Bronwen Aker:

Oh, and now they've got the badge scanners that are tied into AI, so it pulls everything in.

Corey Ham:

They're they're

Bronwen Aker:

on everything. Yeah. It's just god.

Hayden Covington:

They start asking about your kids. Like, hey, grandson. How's little Timmy doing?

Corey Ham:

I know. Don't have a

Bronwen Aker:

whole Get away from me, you stalker. Sorry.

Corey Ham:

I'll just keep my my kidneys.

Hayden Covington:

Oh, yeah. Yeah. That's yeah. That's usually recommended.

Ralph May:

Yeah. That's also unrelated.

Corey Ham:

Alright. Final articles. Does anyone have anything they wanna submit as a final article? Something that's on their mind, their favorite thing that happened recently? Anything top of mind for anyone?

Corey Ham:

Any I mean, I guess, technically, we

Bronwen Aker:

do have a news. Chicken

Hayden Covington:

We do have a chicken article for real this time. So

Bronwen Aker:

okay. Legit chicken news.

Corey Ham:

I mean, okay. Everyone always says that. Oh, for real this time. Really?

Bronwen Aker:

One of

Corey Ham:

one. Seriously? Some some of them are

Bronwen Aker:

a stretch. It's not as good as the lady who bought tons of nuggets.

Corey Ham:

Yeah. Okay. I can't go over beat that. But we do technically have a chicken article. My

Bronwen Aker:

bar. Come on.

Corey Ham:

You know, I I've recently had issues with AI doing Vault and Triage where it'll just write a Regex. Like, it was trying to do it it wrote a Regex for Unifi, and then it just matched, like, half of the companies because of everyone had something else that had unification or whatever in it anyway. Beautiful. So this this is a chicken article. If you wrote a Regex that just says star chicken star because there's a new malware as a service operator on the, you know, on the block called Golden Chickens.

Corey Ham:

And they've resurfaced with four new malware families, including tiny egg, chunky chicken.

Bronwen Aker:

I'm sorry.

Corey Ham:

Can't And Chrome escalator. I'm sorry. What? Okay. So what is that?

Corey Ham:

A Chrome Infose dealer? Like, what is that? Yes. I'm assuming it's a Chrome Infose dealer, but I I can't even it's taken out of place.

Hayden Covington:

Version of Chrome Elevator, I guess. Interesting.

Bronwen Aker:

It's either But maybe what it does is it takes over the AI embedded in Chrome if you've got a Chrome plug in.

Corey Ham:

I don't know. But if you if you get to come across this during threat intel, like, in in an IR, you owe us a beer. Yeah.

Hayden Covington:

Or something. Or some samples. We would like some samples.

Corey Ham:

Yeah. Or or some some virus total some virus total samples. Send us the links. But yeah. I mean, I feel like if you have to tell your boss that it was it was chunky chicken, I feel like your boss is just gonna think you're doing something you shouldn't be doing while you're at work.

Corey Ham:

I don't know.

Hayden Covington:

Can you imagine going public with a breach and being like, yeah, we got got by chunky chicken? Like, everyone's gonna laugh at you. Like, no one's gonna take you seriously.

Corey Ham:

Like, you got hacked by what?

Bronwen Aker:

No. Reach out say time for you to pee in a cup.

Corey Ham:

Yeah, no, they're just gonna they're gonna frame

Ralph May:

it like it was an advanced.

Corey Ham:

Make sure the state. The advanced APT known as fat chicken.

Hayden Covington:

What was the initial access?

Ralph May:

Tiny egg? Name shall not be named.

Corey Ham:

Yeah. The the initial access was tiny egg.

Hayden Covington:

My god. Unknown advanced Yeah. Hatch style. That's where they find that evidence and they're like, yeah. We didn't see this one.

Hayden Covington:

We're gonna

Bronwen Aker:

so Do you think that that malicious hackers put these kinda names in just to embarrass the suits?

Hayden Covington:

No. Was thinking that earlier. I was thinking that earlier about how, like, all these attacking groups have, like, cool names. Like, we need to start naming them again and give them, like, really stupid names so no one's Like, being

Corey Ham:

bad breath or something? Right. Just all have showers. Like, threat actor does doesn't wear deodorant.

Hayden Covington:

Right. Exactly. Fungus. Yeah. Yeah.

Hayden Covington:

Oh, man. If your hacker group was toe fungus, they'd retire right away.

Corey Ham:

They'd be like, oh, guys. We're shutting it down. We're we're gonna hope for another poll

Bronwen Aker:

of them.

Corey Ham:

Like, post the adresses

Hayden Covington:

note after $0 made, like, no. We're not. After so much cyber bullying.

Corey Ham:

Yeah. Yeah. Yeah. So the the moral of the story is stop letting hackers brand themselves. Brand companies.

Bronwen Aker:

Yeah. Brand them. Signed up and send to submission.

Ads Dawson:

Alright. Everything's a caricature. Yeah.

Bronwen Aker:

Blue team tactic. Alright. Where's that on Well, my

Corey Ham:

thank you. Well, yeah. Thank you, Mike and Ads for coming. We, you know, come back anytime. I'm excited about

Bronwen Aker:

your much. It was great.

Corey Ham:

I will tell you in an hour or no in I don't know. Half an hour, we're gonna do John's EnFocus article about the OpenAI Hugging Face scenario. So come back in half an hour. Go get a coffee or a beer or whatever you feel like. And, yeah, thanks, guys.

Corey Ham:

See you next week.

Ads Dawson:

Thanks very much.

Mike Takahashi:

Thanks for having us.

Ads Dawson:

That's legit. Really cool.

Mike Takahashi:

Is there a full version of that song?

Corey Ham:

Yeah. Yes. Spot on? Is it on Spotify? Yeah.

Corey Ham:

No bandwidth. No bandwidth on Spotify. It is

Ads Dawson:

actually there.