Talkin' Bout [Infosec] News

This episode covers computer hardware shortages and chip-manufacturing bottlenecks, digital “letters of marque” for private cyber operations, and New Orleans’ use of AI for 911 calls. The panel also examines the LiteLLM supply-chain attack, Roblox safety concerns, attacks on on-premises SharePoint, AI agents escaping test environments, and vulnerabilities affecting Zoom and Microsoft Defender. Other topics include a post-DEF CON in-flight Wi-Fi incident, Signal’s automatic key verification, airport phone searches, and a PBS broadcaster’s loss of access to 70 years of archived television.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters
  • (00:00) - PreShow Banter™ — Making Investments
  • (04:59) - Airport phone searches, “kill codes,” and border privacy
  • (09:12) - White House Announces "Digital Letters of Marque" - 2026-08-17
  • (11:29) - Story # 1: Digital letters of marque and private-sector “hack back”
  • (18:45) - Story # 2: New Orleans adopts AI for 911 calls
  • (25:10) - Story # 3: LiteLLM supply-chain attack
  • (28:32) - Story # 4: Chris Hansen banned from Roblox during a safety demonstration
  • (32:34) - Story # 5: On-premises Microsoft SharePoint under attack
  • (34:18) - Story # 6: AI agents escape testing sandboxes and hack real targets
  • (42:05) - Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw
  • (44:54) - Story # 8: Post-DEF CON Delta flight Wi-Fi incident
  • (52:44) - Story # 9: ShieldBreak exploit abuses Microsoft Defender
  • (56:55) - Story # 10: Signal introduces automatic key verification
  • (58:32) - Story # 11: PBS broadcaster loses access to 70 years of archived television
  • (01:03:02) - Upcoming webcasts and training

Links
Story # 1: Digital letters of marque and private-sector “hack back”
Story # 2: New Orleans adopts AI for 911 calls
Story # 3: LiteLLM supply-chain attack
Story # 4: Chris Hansen banned from Roblox during a safety demonstration
Story # 5: On-premises Microsoft SharePoint under attack
Story # 6: AI agents escape testing sandboxes and hack real targets
Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw
Story # 8: Post-DEF CON Delta flight Wi-Fi incident
Story # 9: ShieldBreak exploit abuses Microsoft Defender
Story # 10: Signal introduces automatic key verification
Story # 11: PBS broadcaster loses access to 70 years of archived television

ANTICAST - Your Cheap IoT Devices Are Hiding Secrets. Let's Find Them
Training by Jake Williams – Assessing AI Security: Model Context Protocol

Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 
https://poweredbybhis.com

Brought to you by:
Black Hills Information Security 
https://www.blackhillsinfosec.com

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest
https://wildwesthackinfest.com

Creators and Guests

Host
Hayden Covington
Hayden Covington joined Black Hills Information Security (BHIS) in the Summer of 2022 as a SOC Analyst. He chose BHIS after hearing many great things over the years and seeing the quality of work, as well as finding people who have the same passion for the field as he does. His favorite part of the job so far has been the community. Previously, Hayden worked in a SOC for a Naval contractor, where he also served as their SOAR project manager and SME, as well as insider threat lead. When he’s not working, Hayden can be found doing anything athletic (like triathlons!), as well as enjoying video gaming and Formula 1.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Guest
Adrien Lasalle
Adrien Lasalle, known online as NetRunner, is the founder of NetRunSecurity and an offensive security professional with nearly seven years of experience breaking things professionally, from web applications and Active Directory to cloud, OT/SCADA, and embedded devices. His specialty is hardware hacking, PCB design, and anything with a chip in it. A keynote speaker at NorthSec 2025, Adrien has also presented at Wild West Hackin' Fest Deadwood, InCyber Canada, and BSides events across Montreal, Warsaw, Kraków, and Copenhagen. A former firefighter in France, he is now based in Montreal, where he shares his passion for hardware, cybersecurity, and pentest war stories and memes weekly on LinkedIn and Twitch.
Guest
Alex Minster "Belouve"
Alex Minster is a cybersecurity professional with a passion for Open-Source Intelligence (OSINT) , and a desire to use his technical skills to make a meaningful impact on society. With nearly twenty years of experience in cybersecurity, and a current role in Threat Intelligence for a global financial corporation, Alex remains very active in numerous cybersecurity groups including DC608 and Black Hills Information Security. Beyond his professional accomplishments, Alex is an avid oldschool gamer who enjoys arcades, retro gaming, and tabletop games. He brings his passion for adventure and his commitment to helping others to everything he does, both in and out of his professional career.
Guest
Derek Banks
Derek is a BHIS Security Consultant, Penetration Tester, and Red Teamer with advanced degrees, industry certifications, and broad experience across forensics, incident response, monitoring, and offensive security, who enjoys learning from colleagues, helping clients improve their security, and spending his free time with family, fitness, and playing bass guitar.
Guest
Jake Williams
Adrien Lasalle, known online as NetRunner, is the founder of NetRunSecurity and an offensive security professional with nearly seven years of experience breaking things professionally, from web applications and Active Directory to cloud, OT/SCADA, and embedded devices. His specialty is hardware hacking, PCB design, and anything with a chip in it. A keynote speaker at NorthSec 2025, Adrien has also presented at Wild West Hackin' Fest Deadwood, InCyber Canada, and BSides events across Montreal, Warsaw, Kraków, and Copenhagen. A former firefighter in France, he is now based in Montreal, where he shares his passion for hardware, cybersecurity, and pentest war stories and memes weekly on LinkedIn and Twitch.
Producer
Ryan Poirier
Ryan Poirier began his time at Black Hills Information Security (BHIS) as the Video Producer and Editor in August 2020. Ryan polishes and perfects every webcast, podcast, and workshop on the BHIS, ACM, and WWHF YouTube Channels. Prior to Ryan’s time at BHIS, he worked for one of the largest public schools in the United States, conducting their video production and live broadcasting. He joined the BHIS team because he felt like it would be a great group of people to work with, and he couldn’t pass up the perfect next step in his career. Outside of his time with BHIS, Ryan does freelance photography, attends Cars & Coffee events, and expands his knowledge of audio and videos.

What is Talkin' Bout [Infosec] News?

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET

Ralph May:

Yeah. Screw screw AI. We're trying to get hardware right now just like to buy everybody's out that Dude. I've been talking to suppliers to try to get and we're talk I'm not even talking, like, specialized stuff. I'm not talking GPUs.

Ralph May:

Okay? We're not talking AI stuff. I'm saying just regular computer stuff, and it is, like, over a year lead time in in most cases.

Derek Banks:

Wow. Dude, I bought a four terabyte solid state drive, like, two two years ago, three years ago, and I feel like I invested in something.

Ralph May:

Yeah. Oh. Oh. Yeah. Like, it's crazy.

Ralph May:

People are buying up the inventory. It's like toilet paper. It's toilet paper but for computers. Okay? Because they're afraid and, you know, that they won't be able to do whatever it is they do in their business.

Ralph May:

It doesn't have to be AI. Just they might need, you know, computers for this so they buy as many as they can.

Derek Banks:

I need 400 Lenovo laptops for my new hires or whatever.

Ralph May:

Yeah. And everyone's already supply constrained, and so now it's just

Jake Williams:

it's just really gotten easier.

Wade Wells:

Ralph's server. Good work. Over there. It's worth a whole house now.

Derek Banks:

I know.

Wade Wells:

Right? Just in RAM alone.

Ralph May:

Yes. I mean, it's appreciating.

Derek Banks:

Too bad that it's so hard to stand up a chip fab. I mean, we only need, like, $5,000,000,000 or something.

Wade Wells:

That's it. Come on. Ask John how represent I

Jake Williams:

was just gonna magically do it overnight.

Derek Banks:

That's great.

Ralph May:

I literally going live on YouTube. We are going live. I I I was reading about, like, what the actual problem is. So t m TMSC, right, is like the number one manufacturer of chips Yeah. In the world.

Ralph May:

Right? Mhmm. And they produce 70% of all of the chip manufacturing in the world. So, like, they're not the they are the market. Right?

Jake Williams:

Right.

Ralph May:

But the problem is is that historically, when you make chips, right, you the packaging part is where you take the actual, like, chip and then put it on, you know, like the the processor board that's gonna connect to your mother board. Right? That's that's called packaging. Right? But the new kind of chips with the HPSs have a special kind of packaging that happens.

Ralph May:

This is your really fast memory. This is, you know, the stuff that AI loves. Right? And instead of putting the memory on, obviously, the the main board and then trying to go between the board and the processor, they put the memory the on right next to the chip. And they use a special packaging process that connects tons and tons of cable or essentially wires to to the memory.

Ralph May:

And it's this packaging process, TMSC is the only one who does it. And it's like the whole thing. It's like, they they run the whole industry on it. So my point with all

Ralph May:

of this is to make this kind of chip or to compete with this or to produce this fab is really difficult. In fact, The United States is getting two of those packaging facilities in Arizona, but they won't

Ralph May:

be online for another couple years.

Derek Banks:

Yeah. Because it's hard to build that stuff.

Ralph May:

Yep.

Derek Banks:

I I there's a a a company that I follow, a semi analysis that does a whole bunch of, like, chip, you know, market analysis, and they wrote a bunch about the the what you know, the shortages and why they're happening and why it's hard to make a chip fab. And I I learned, like, the only chips, like, still made in The US go in, like, Texas Instrument calculators.

Ralph May:

Yeah. So the other thing is the the manufacturing process to produce these. They're actually made by I think it's nor the actual the the machine that makes

Hayden Conington:

that Yeah.

Derek Banks:

By their

Ralph May:

is made by, like, a Norwegian company. Dutch.

Alex Minster:

I I could

Ralph May:

be wrong on the country there. Sorry. No. You're right.

Derek Banks:

Is it Norwegian or is it The Netherlands?

Wade Wells:

Netherlands. Netherlands. It's

Derek Banks:

It's one company. There's just one that makes the end it. Or something like that.

Wade Wells:

Yeah. Yeah. Yeah. John's gone down the deep end on that that that place. And then then he made me go down the deep end, and now I'm, like, shooting lasers at, like, pieces of copper.

Wade Wells:

And then I like

Derek Banks:

And the next thing you know, you're, like, realize how fragile this all is, and you're the one who's hoarding all the toilet paper. Is that what

Ralph May:

you're Exactly. Exactly. Yes. But, you know, those lasers, the whole point of that is to make those connections. They've so many connections that it has to make.

Ralph May:

That's why it's using this different process. And the reason why TMSC is the number one manufacturer of chips in the world is because they figured out how to do one thing that no one else could do, which was make money at that actual thing. Right? It's like Wow.

Wade Wells:

The the profit. They profit. Yeah. Okay. That's interesting.

Ralph May:

So, like, we can make the same two nanometer chips in a fab in The US, but none of those fabs actually make profit. They're not profitable.

Derek Banks:

It's kinda like Well, today's cost, but soon. Soon. Soon. Right? What

Wade Wells:

if what if you just made me some, like, twenty twenty chips? Alright? Like, I'll accept that. Like,

Ralph May:

That's the problem.

Ralph May:

Because think about it this way. Think about it this way. The materials to make those chips are the same whether they're the most advanced chip or the old one from five years ago. Well, guess what? All the materials are going for the brand new fastest thing, not the, you know, the most the yeah.

Ralph May:

So anyways, very fun. Crazy.

Wade Wells:

Great.

Derek Banks:

Great. Times. Good times.

Wade Wells:

Didn't anybody go deeper into the guy who who put in like the kill code in his phone at the Atlanta Airport? Yeah. We talked about that last week.

Ralph May:

We we did talk about that last week.

Wade Wells:

Yeah. We talked about it last week, but like, I I like went deeper. Like, I watched some Legal Eagle stuff about it.

Alex Minster:

But you were and I watched the Legal Eagle one too.

Wade Wells:

Yeah. And it it was great. It was super interesting to find out that, like, the reason they were able to get into his phone was because they were claiming because he was coming back into the country.

Ralph May:

Mhmm.

Wade Wells:

And they were able to bypass certain laws because they're saying that he had a risk. But then the people who actually, like, looked at his phone were technically anti terrorism, but they were almost think but they were charging not charging him, but suspecting him for, like, child exploitation. And it it got dude, it got real weird real quick. And then there's, like, highly suggest looking into it because from the way that the law is said and where he's actually gonna go to court, he he's prob he may possibly lose. That's the crazy part.

Jake Williams:

Oh, I think he's gonna lose a 100%. Right? But Yeah. But but what's you know, like, the whole suspicion of, it's the one they throw out all the time. Yeah.

Jake Williams:

Yeah. Oh, that's what we're looking for. Right? Please protect the kid. All about it.

Jake Williams:

Right? But like, receipts, please. Right? Because, you know, like, if you're gonna charge them over that, right, like, bring some receipts up to that point, they that's the first I've heard of that up to that point. It had all been, you know, the Stop Cop City protesting then.

Wade Wells:

Yeah. Yeah. Yeah. That that's it's crazy that that's like where it all originated from was just that single thing, dude. Like, like, I talked about this last time, because if if someone asked me to do that, I would have totally told them that code, but just to see it work.

Wade Wells:

Right? Yeah. And then like

Alex Minster:

And there was I I think also in, like, the the legal legal, like, just going through, like, all of the, like, he was trying to assert his rights. And they were like, no. And it's like, well, I wanna do this. And they're like, no. And so you you have all these things to where it's like, you're using a duress code, and you're you're clearly establishing you're under duress.

Alex Minster:

It's not one of these things that the stories make it out to be that. It's like he he shows up at board, and they go like, hey, give us your password. It's like, oh, yeah. Sure. Let me give you this false password that erases everything.

Alex Minster:

It's like, no. This is clearly going sideways in a hurry. I've tried to exerting my rights. Like, hey.

Ralph May:

I'm I'm just gonna point

Alex Minster:

out this lawyer's card right here.

Ralph May:

Yeah.

Alex Minster:

If you have any questions, talk to them. And they're like, no. Not having any of it. So it's like, yeah. You're you're under duress.

Alex Minster:

And if you're gonna if you're gonna play the counterterrorism card, like, don't be tripped up by a duress code. Like, I I would think they'd be a little more clever than that if they're gonna be counterterrorism.

Wade Wells:

Nah. They are. Maybe. Carpool doesn't standards.

Jake Williams:

Oh. Say for what it's worth, I'm I'm in

Ralph May:

a signal group with well, it

Jake Williams:

doesn't matter. Probably lots of people that are being surveilled too. But, you know, one of these guys, that I work with that's in that group lives in Germany, but is in and out of The States pretty regularly. And, he's one of the admins in the group. And so we'll get the whole, you know, the quick messages like crossing customs, deleting my phone.

Jake Williams:

Right? And so somebody would have to add him back into all the groups afterwards, which I mean, that's one route to do or one, you know, one way to go. So he factory resets his phone as he moves her custom or Wow. Before he moves her customs.

Wade Wells:

Talk about threat model.

Derek Banks:

Oh my gosh. I mean

Wade Wells:

Yes. It makes sense. I get it. Yeah. Yeah.

Wade Wells:

It's Yeah. So

Adrien Lasalle:

But you're not like a suspect issue cross with an empty phone all the time.

Jake Williams:

Sure. I mean, but what do you you can say all day long, I suspect you reset your phone. I mean, if if I say my policy is to reset my phone every week or every three days or whatever, like prove me wrong. Yeah.

Ralph May:

I mean, doesn't mean you commit a crime. No. Yeah. Alright. Alright.

Ralph May:

Sounds good. Let me do it at the end or the beginning? What?

Hayden Conington:

Okay. We still haven't got we

Wade Wells:

still haven't rolled the finger yet. We can roll the finger.

Ralph May:

Roll the finger. No. No. No. I I was I was reading the chat.

Ralph May:

You're you're you're good. Go ahead. Welcome to Black Hills Information Security talking about the news. I'm your host today, Ralph May, and I am joined by illustrious cast of characters. We are not gonna be talking about any AI today.

Ralph May:

We all made a sworn promise. I'm just kidding. There's a lot of people who are gonna be talking tons of AI. But with that being said, I'm gonna go around in our circle of squares here. We have Wade Wells who's digging through logs and holding all the secrets.

Ralph May:

Right?

Wade Wells:

Yeah. That's about right nowadays. Yep. That's all I do.

Ralph May:

Awesome. We also have Derek Banks. Derek, I haven't seen you on the show in a long time.

Derek Banks:

Yeah. Yeah. It turns out I'm normally at this time being a teen Uber driver for my daughter. Alright. Turns out she's off season at the moment.

Ralph May:

Unpaid internship. Yeah.

Derek Banks:

That's right. My third job

Ralph May:

or fourth job or something. We also have Jake Williams. Thanks for joining us, Jake. Haven't seen you in a while.

Jake Williams:

Hey. Always happy to be here.

Ralph May:

Yeah. Yeah. Awesome. And continuing around, we have Adrian, which I have not seen you on a show before.

Adrien Lasalle:

Nope. First time for me. Thank you for the invite.

Ralph May:

First time. Where are you from?

Adrien Lasalle:

Right now, I'm from Montreal.

Ralph May:

But Okay.

Adrien Lasalle:

I'm French.

Ralph May:

So Okay.

Adrien Lasalle:

As you can hear.

Ralph May:

Yeah. Yeah. I was like, I I think I think I hint about a little bit of French. Yeah. It's it's all good.

Ralph May:

Well, thanks for joining us. And then we have Hayden as well.

Hayden Conington:

What's up? I'm What's I'm here. I was told I had to be here.

Ralph May:

Oh, because there's AI talk?

Wade Wells:

No. He was told he's here, so he doesn't get fined.

Hayden Conington:

We got

Ralph May:

blue team around the panel. Get him in there. Yes.

Wade Wells:

What am I? Am I chopped liver now, dude?

Ralph May:

Like, Oh basically my gosh. And last but not least, Alex. Thank you for joining us. Alright. So what do you guys wanna talk about first?

Wade Wells:

Like, there's Alex. Hey.

Ralph May:

Alex. Yeah. Alright. You could've you could've you could've said anything. It's like the the the screen went to Hayden first, and then it was

Alex Minster:

Yeah. I went to Hayden. I was like, oh, okay.

Ralph May:

You should've just started talking. Feel free to just just start yapping. It's it's all good. Yeah. Anyways, what do guys wanna talk about first?

Derek Banks:

I mean, I think we should talk about the digital letters of Marque, because that sounds really fun.

Wade Wells:

Alright. Throw the throw the link.

Ralph May:

Yeah. What's the digital letters of Oh,

Derek Banks:

the what is that's the the the enabling companies to hack back?

Wade Wells:

I didn't tell you guys. I started I started up my new service. I'm taking funding right now for Yeah. Hack as a service.

Derek Banks:

Was it back during it was, what, probably the early late seventeen hundreds, early eighteen hundreds, combating, piracy and then, at times of war, privateers who owned ships could confiscate enemy ships and pirate ships. They were issued letters of marque from the US government. So these are digital letters of marque.

Ralph May:

Yeah. There you go. So for everyone who hasn't read this very, very short, essentially, we are going to be I'm gonna say we. The United States is letting it mercenaries for cyber secure for cyber attacks from an offensive perspective. Right?

Ralph May:

That's that's kind of what I'm reading into this. I don't know. What do you guys what do you guys think of this? You think it's gonna help?

Wade Wells:

Thank god we're gonna see something big, j greedy. I'm psychic. Like I mean So I'm I'm kind of I'm not surprised we're doing this with this administration type of thing. Right? But it is interesting that we're globally saying that we can do it, whereas in in other markets, it's it's like a hidden secret.

Wade Wells:

Jake, you're muted, by the way.

Hayden Conington:

That's the worst.

Wade Wells:

I I saw your quip. I know it was good.

Jake Williams:

Oh, I just was like, no. No. It's not gonna help. Right?

Ralph May:

Oh, no. I mean, I have

Alex Minster:

I have one thing that I think is gonna help. It may help you kind of like disguise money because like when you go, hey. We're going to hit back, and you go, we're took taking all these millions of dollars to hack back at the enemy, and we have nothing to show for it. Did you do anything? You're like, trust me.

Alex Minster:

I I did a pen test. I I found nothing. I we we hit them back. Like, I threw a bunch of we we threw a bunch. We had a a whole cyber command go after them, and I started we had tried, and that'll be that'll be $8,080,000,000,000,000 dollars, please.

Ralph May:

I I got Claude Pro 100 x, and I swear I got nothing.

Alex Minster:

It's gonna throw it, you know, yeah. They'll they'll throw it through an AI prompt. Be like, you know, please hack foreign country. Thank you. Add it.

Alex Minster:

It'll it'll, you know, generate what it can and

Wade Wells:

I'm I'm wondering if this will create a spike in blue team jobs in the black market. So I'm super

Derek Banks:

I'm really excited to hear I Jake's take on this

Derek Banks:

I really wanna hear Jake's take because I don't think it'll help either. But I I think there's a big problem with having a private company go after what, you know first of all, a nation state. It's not like private companies have, you escalating means of, you know, if something got truly bad happens in a nation state, then what takes out a company? I I don't know. Or attacking criminals, like, I I just don't know it's a good idea to you know, for me to be sitting here at my day job and then to get a, you know, a package at my front door that has, like, you know, pictures of my children.

Ralph May:

Yeah. You know? I mean, this this is was already happening. Right?

Derek Banks:

Well, sure. I would imagine there's contractors involved with what we do Mhmm. But not like this.

Hayden Conington:

It's kinda different than go get them. Right?

Jake Williams:

Well, I think that's important really to call out here too. Right? You know, Ralph notes, there already are contractors doing this. Random companies don't get to hack back. You know, this ultimately requires you to have a minimum million dollar bond, you know, with your company.

Jake Williams:

Right? You have to go through deconfliction. So you're gonna hack on the same targets US government is, right, and blow on one of their cyber operations. I I think my my biggest question is why this is necessary. And as everyone can clearly see, I'm too pretty for jail.

Jake Williams:

So we're not gonna talk about anything classified from my former life. Right? But but look, we already have legal authorities. There's two main legal authorities that we use for for targeting, you know, targeting or using offensive cyber operations to target others. It's law enforcement intelligence.

Jake Williams:

And and it's unclear to me what's wrong with either of those authorities here that we need this. And the fact that we have this and I I'm I'm waiting to see, you know, another DNI clapper, sitting in front of, you know, senator Wyden saying, well, I gave the least untruthful answer I could at the time, right, given the circumstances, you know, about this hacking back. I I just I I there's there's something else going on here. I don't know what it is. I don't wanna know what it is.

Jake Williams:

I think Nurtz is bliss. But there is a technical authority they're using here.

Ralph May:

Some contractor wanted to get some money and I think someone talked to somebody. But I mean, you you you're right. Like, they're it's it's it's already, like, you could already hire someone to do this before and, like, so yeah. I I I don't I don't know. Maybe just being public about it to scare people?

Ralph May:

I don't know.

Hayden Conington:

Yeah. That's

Wade Wells:

that's what I thought, maybe. Right? Like, technically I can

Ralph May:

get you.

Derek Banks:

Can we can

Wade Wells:

we argue that like Russia already does this? Right? Oh, Russia, we're operating.

Ralph May:

Right? Like In many countries, they don't even get like the choice. It's not like, hey, would you like to get paid money? They're like, no, you're doing this. Right?

Ralph May:

Like, do you want to live? Right? Or do you want, you know?

Derek Banks:

Or you want your family to live.

Ralph May:

Yeah. Exactly. Mean yeah. You you could press your, you know, the the pressure however you want. Right?

Ralph May:

So Yeah. I mean, that's the North Korean

Jake Williams:

model. Right?

Ralph May:

Yeah. Hell, yeah, dude. I want

Jake Williams:

your family to live. Right? And then that's three generations. Right? Yeah.

Jake Williams:

So, yeah. I mean, but again, other countries are already doing this. We're already doing this, right, with with contractors. The thing that's separate here and again, like, there's just no reason you wouldn't contract them into one of the intelligence agencies or one of the law enforcement agencies that's already conducting offensive cyber unless there's a classified annex somewhere, right, to this to this executive order, this national security memorandum, policy memorandum that that says, you know, here's our creative reading of the law and here's what this allows that contracting them directly to an agency doesn't. I I bet the money in my pocket on it right now.

Ralph May:

I my my bet is it's definitely about money, period. Some somewhere, somebody's getting rich. Yep. Right? It's just not gonna be me.

Derek Banks:

Well, that's generally the answer for most things, isn't it? I

Wade Wells:

know. Come on. I just they're gonna just start pointing mythos at things. Right? Like, same thing.

Wade Wells:

And and

Derek Banks:

it and at least it wasn't, you know, an AI story, or was it? Maybe this is why the AIs are not, getting, computer fraud and abuse act.

Hayden Conington:

That's an interesting angle. Just like, hey, chat GPT. If you wanna let one of them out, but, like, over there, like,

Wade Wells:

okay. Here's the legal document saying we can do it. We got the Marque. Sure.

Ralph May:

What is it? Speaking of of AI, we'll go to a soft AI article. And this one's actually kind of interesting in the sense of the first US city to use AI for 911 calls, New Orleans. Right? What do you what do you guys what do you guys think about this from Oh, yeah.

Derek Banks:

Not moving to New Orleans. Yeah.

Hayden Conington:

Absolutely right. A bullet a bullet wound can be lethal. Let me read your Yes. Yes. You were right to push back.

Wade Wells:

Sending drone now.

Hayden Conington:

Yes.

Ralph May:

I mean, for from a from not necessarily a a great policy standpoint here, but from a a technology standpoint, I think the tech is there, whether it's going to actually work in, you know, a useful way, life, and all this other fun stuff is is to to be determined.

Derek Banks:

Well, I mean, we've all, like, had interactions with, like, you know, calling, you know, our insurance company or whatever with the AI attendant. I don't know that I want that for my 911 call, because I'm probably gonna be panicked. I mean, I'm calling 911 for a reason.

Alex Minster:

Yeah. And yeah, I would agree that you're not looking at AI for your usual customer service to where you're trying to use AI to find answers. You're using it for, as you said, you're in you're in a crisis. You need that calm. You need that human element of, like Mhmm.

Alex Minster:

Giving that assurance that, like, things are going to be okay. You have, like, that kid calling because, like, their their dad's injured or something, and you'll you don't want an AI response being, like, giving very cold answers to a child that's trying to save their parent. Like, you want that that human element there while they're keeping them call calm and getting people in. This isn't this isn't calling trying to, you know, settle some, you know, unexplained charge on your credit card that you need automation for. You you can't automate that that human element, that human compassion.

Hayden Conington:

It it would make sense if it was like the nonemergency line. Yeah. Yeah. But Derek's point is exactly where my head went is I've never once had an interaction with a call tree that was not miserable and didn't take five times as long to give me for any of that.

Derek Banks:

That you ended by saying, I wanna talk to a human. Right.

Hayden Conington:

Talk to a human. Wanna talk a You know, like, I

Wade Wells:

I I just started really started playing around with, like, the Cloud Voice stuff and having it run a DM campaign for me, like like, off to the side so I can play with my players once in a while. And I was surprised at how well it was doing. And I'm like, why can't we just have this in other places? Right? But, like, it's not that good.

Wade Wells:

And then my my first for this is, like, we don't let from the security. I would like if that detection fires. Right? Goes

Ralph May:

to

Wade Wells:

the store. Where's it gonna go? Well, I like, we don't allow to run computers that well. Why are we gonna allow to, like, people's lives or, like, route police insurance or stuff like that? Yeah.

Wade Wells:

Wade getting robot y. Oh, okay. I don't know.

Ralph May:

You're you're having just got a little connection issues. You came back though. You came back. Alright. It was some things.

Wade Wells:

Dude, You got like a with an AI. They probably they probably heard me mention it, and then it's like running the D and D campaign behind me right now.

Ralph May:

Yeah.

Adrien Lasalle:

Okay. So that's why.

Jake Williams:

So so real quick on here as as we have seven white dudes talking about, you know, an eye with in a in a city that is predominantly black. Right? And I I don't know the statistics on the 911 calls, but I'm gonna shoot in the dark here and say predominantly, I mean, probably flows of the population. Look. There are huge, huge bias issues here.

Jake Williams:

Right? And I'm not gonna call out company that, you know, that I've been working with here, but just wrapped up some testing in the last, we'll say, three months. You know, using deepfakes, right, to beat voice authentication, right, for a major bank. And I'm here to tell you that the the voice recognition works phenomenally better for white men with no accent than literally any other group. It will not shock you to learn who it works really poorly for and which specific accents and affects The tracing data.

Derek Banks:

That's because yeah. So Ralph's right. So that's because this isn't an LLM. This is a classifier. Right?

Derek Banks:

And the people who made that were predominantly white men, I would guess, in technology. And for whatever reason, it didn't occur to them to diversify their dataset, which is one of the first things that we learned in the data science master's program was, hey. This crap matters when people use it. So, yeah, I would I'd be worried about bias issues for sure. Look

Wade Wells:

at Derek over here actually using this real world college.

Ralph May:

He's worried about this.

Wade Wells:

He's like some sort of

Jake Williams:

smart person. For like, swatting,

Ralph May:

for example, or other kinds of way.

Jake Williams:

Bro, imagine a prompt injection.

Derek Banks:

That's a

Ralph May:

prompt injection on nine one one. Right? To, like, cause, you know, activities to happen or scenarios, fake scenarios, but without, you know, anyone, like No. To be able to detect

Hayden Conington:

And you know they're using the cheapest model on that too. Oh, yeah. They're putting haiku like They are man.

Derek Banks:

There's like a To Jake's point, it's not an LLM. Right? Before that. It's it's probably not even an LLM. It's probably a transformer.

Derek Banks:

Right? But it's probably not even an LLM. That and when it's trained, it's to your point, it's probably to the lowest bidder. It's probably some crappy model.

Jake Williams:

But but once it generates the text, right, something's going to reason across that that text. I mean, typically, the way these work in the back end is there's a classifier to your point that's that's generating, you know, turning the voice into text that we act on. And it's gonna be an LLM almost certainly acting there. What I was thinking is imagine when they run out of token budget in the middle of a natural disaster or something. Their cost spikes.

Jake Williams:

Right? And guard duty is like, no. Right? So they can't auto scale anymore. And all of a sudden, you're like bleeding out on the side of the road.

Hayden Conington:

Yes. You have

Adrien Lasalle:

to forward your API key API Yeah. To the phone.

Ralph May:

Honestly, it'll just you know you know what happens all the time? Claude goes down or whatever service goes down. It's like it blows my mind how often this happens now. Right? Like, GitHub was down today.

Ralph May:

GitHub was down last week. I'm

Wade Wells:

like Probably.

Ralph May:

Can we just put it on my computer? At least it's always up.

Hayden Conington:

I don't Dude,

Wade Wells:

if you look at Claude's uptime, it is not great either. Like, it's not not like nines.

Hayden Conington:

Right? Yeah. Oh, and now Chad GPTs isn't good either.

Ralph May:

Yeah. Anyways yeah. Speaking of what do you call it? LLMs and more AI. But more specifically, this is around an attack, and this is the the light LLM supply chain attack.

Ralph May:

Shocker, pipelines and PIPE pie are being attacked in a supply chain. And honestly, I feel like this year is the year of supply chain attacks. Right? Like the NPM, everything.

Hayden Conington:

It's like

Wade Wells:

Salud, Hadid. Right? Like, it started there. We all knew it was coming. Like, it's

Derek Banks:

just

Wade Wells:

Oh,

Derek Banks:

it's just the SolarWinds stuff wasn't the year of the supply chain attack?

Wade Wells:

I don't like I

Ralph May:

think different it was different. So like, in the SolarWinds, it was like an actual so just one supplier. But in this, it's like a code like, the supply chain is just a registry of packages. Right?

Derek Banks:

So how how long was Light LLM compromised? Was it two or three days or some something like that?

Ralph May:

Yeah. I don't think most of these attacks don't last very long.

Derek Banks:

Yeah.

Ralph May:

Right?

Jake Williams:

But I think was a

Derek Banks:

couple of days. But just in that time, just how many people download and install it. I mean but, you know, weaponized packages aren't isn't a new concept. I mean, PyPy has been and probably still is full of them. Right?

Ralph May:

Sure. Sure. But the the problem is it's not humans going and being like, oh, I need this package. No. It's CICD pipelines installing them automatically when they're doing testing and all this other fun stuff.

Ralph May:

Yeah. The one

Wade Wells:

thing to point out is, like, CICD pipelines too, like, they're not horrifically hard to log, but that they're they're being spun up and torn down automatically. So like any type of forensics investigation or more data, like, it's it's not the easiest thing for blue teamers to work against. Right? And usually, I don't know Hayden, you can you can guess, you can talk to this as well. I don't know as many people who are specialized blue teamer for more CICD pipeline logging.

Wade Wells:

Right? Like, there's endpoint, there's cloud, but CICD pipeline, like, that's a it's a niche subset.

Derek Banks:

You just hope

Hayden Conington:

nothing bad happens over there.

Derek Banks:

You log your CICD pipeline activity?

Wade Wells:

Bro, right there. That's after all these pipeline stuff. Yeah.

Jake Williams:

Can can can we also just I mean, one place that we just have a universal solution because that that's pretty rare here. Freaking artifact repositories. Right? Build an artifact repository. It will save you from the vast majority of this stuff.

Wade Wells:

Right? Because You get Jake

Jake Williams:

vast majority of these are discovered and pulled within hours. Right?

Derek Banks:

Or or for your your project, maybe pen the packages you're using.

Hayden Conington:

Don't ever update.

Derek Banks:

Put an age gate in for not installing packages younger than five days. A lot of ways around it, maybe. Yep.

Wade Wells:

I was I was gonna say something.

Jake Williams:

At latest is not a version number. It's just

Ralph May:

But what about all the AI vulnerabilities that just got discovered in this new package? I gotta update now.

Wade Wells:

Jake Jake just wants us to have a message board for the AIs. That's why he

Hayden Conington:

wants to set up our factories.

Derek Banks:

I think that's coming in the article or the one after maybe.

Ralph May:

So, anyways, definitely still I I think we're gonna see continue to see this. I think I think that the world of AI makes this more common, if that if that.

Derek Banks:

Oh, yeah. I don't think this is going anywhere.

Alex Minster:

Yeah. Oh, for sure.

Ralph May:

What else do we got here? Anyone else got an article they wanna jump into?

Wade Wells:

I think this one is kinda create did you see the Chris Hansen one? I'll throw it in Discord. So I I literally just saw this one, this one. So Chris Hansen was live at CrimeCon doing a safety demo, and he got banned from Roblox Live. So his account was banned live on stage at CrimeCon while he and the YouTuber demonstrated how strangers can approach users through the platform.

Wade Wells:

So one of the first data centers I worked at, we are big one of our biggest contracts was actually robots. And we used to get DDoSed DDoSed on the weekly for and then we'd get a phone call and be some kid asking us for a a robot server or and then they'll stop the DDoS. But the amount of crime stuff that goes around with Roblox is just like insane. I don't know. What do you what do you think?

Wade Wells:

Yeah.

Hayden Conington:

They've put a lot of effort, I think, into trying to mitigate that. I'm sure they're not doing anywhere near enough, but they definitely caught a bad name for a long time for doing next to nothing. Like, I'm I'm young enough to have played that as a kid, and it's kinda sad to have seen how it has totally gone, like, downhill in terms of monitoring and and, like I I would not allow any kids that I have to play on that site at all. No chance. No shot.

Hayden Conington:

Like, I learned to code on there. No chance. They can go learn to code somewhere else.

Derek Banks:

Scratch from MIT. Yeah.

Jake Williams:

My nephew routinely asks me for, like and I'm like, hey. I'm gonna get you the gift, you know, whatever it is. He's like, give me a Roblox gift card. I'm like, no. Just no.

Jake Williams:

On press, you get no. There's there's all kinds it's not a money thing. Like, I'm just not putting you in a site where I know. Right? Like, it's like dropping your kids off at the sexual predator park.

Jake Williams:

I mean yeah.

Wade Wells:

Dude, when you get that type of reputation

Derek Banks:

Let them mention Harley. The Uber that's the white van. Is that what you're saying?

Ralph May:

God. Yeah. With free puppies van? Free free puppies, free candy.

Adrien Lasalle:

Let's see.

Hayden Conington:

Yeah. Yeah. I I don't know how you come back from that as as a company. I think they let it go too far to where the reputation hit is just not I don't know if it's recoverable, at at least in, like, the wide term spheres. They obviously have a huge player base still.

Hayden Conington:

And I imagine that, you know, like, almost after a country is hit by a disaster, their security becomes significantly higher, at least for an extended period, at least in those areas. And so I imagine they're probably doing a lot more than they used to do. But, again, like, there's a lot of games out there. I don't know why that would be the choice.

Jake Williams:

Yeah. Thought it's almost like, you know, foregoing your bank and saying, I wanna put all all my cash and x money. Right? Because don't worry, they're gonna get fantastic return. No?

Jake Williams:

Nobody? Okay.

Hayden Conington:

I did get an invite today, right, where they're

Jake Williams:

like, hey, drop a bunch of money with x. And I'm like, no. Thank you. As a return note.

Derek Banks:

Wait. Do they have crypto now? Is that what it is? I don't even know.

Jake Williams:

So they're they're, doing some really aggressive investments, right, and say that they can cover you up to, I believe, $10,000,000 is the number for FDIC protection, by spreading your money out across a bunch of different banks. Right?

Alex Minster:

Each of which

Jake Williams:

has they're handling that automatically in the background. And the rate of returns have, like, sparked several, reclaimed rate of return. Right? Mhmm. Because they are investment accounts at that point.

Jake Williams:

Right? It's it's all it sparked some congressional inquiry. Right? In a congress that isn't doing a lot of inquiry.

Ralph May:

So yeah.

Hayden Conington:

What I'm saying is put your money in robux, basically.

Jake Williams:

Yes. That's probably the better investment. Right? It's better than the free candy.

Ralph May:

I want I want us today to go back in time. I have a a very quick article which is not AI. And it is the Microsoft SharePoint has being attacked. Right? I feel like I'm back in a time machine.

Ralph May:

So This is like three years ago. Bypassed for SharePoint, which I I feel like, you know, four or five years ago, I mean, this was the thing. Right? Like, we were we were this is what we were talking about. It's still a thing, but not online.

Ralph May:

Only on the self hosted instances, which was always kind of the thing. Right? I feel like Microsoft, like, pays for these almost so that they'll get you to to get the online version of SharePoint. Right? So you can the

Hayden Conington:

get off strategy? Yeah.

Wade Wells:

That's definitely a tactic.

Derek Banks:

Is this on prem SharePoint?

Ralph May:

Yes. On prem SharePoint. Yeah.

Alex Minster:

Okay. Which

Ralph May:

I think that they've literally just left to to, like, rot inside. Oh. Right? But Yeah.

Jake Williams:

Yeah. They don't. They don't. Exchange too.

Ralph May:

What's up? Yeah. Yeah. No. Exchange too.

Ralph May:

Yeah. Yeah. All of them do.

Hayden Conington:

You have on prem

Ralph May:

Exchange. Like going back in time. Right?

Derek Banks:

I just ran into the first customer I've seen in a very, very long time that had external Exchange. And I was like, oh, crap. I haven't seen this in long enough till I gotta go remember what to do.

Hayden Conington:

There's there's probably plenty of options is

Jake Williams:

the good thing. Oh, yeah.

Derek Banks:

Yeah. It worked out, but still,

Ralph May:

like Yes.

Derek Banks:

I hadn't seen it in Hot Minute.

Ralph May:

Hack hacked them. Yeah. So I just kinda felt like we'll go go back in time and talk about, you know, when SharePoint and Exchange vulnerabilities used to be the Well, you know we gotta talk about.

Derek Banks:

What is old is new again. It was the cloud and then packages and then edge devices, now the supply chain, but none of that other stuff really went away. So it's really the year of all this stuff.

Ralph May:

Mhmm. Yep.

Derek Banks:

Alright. So there's there's one that that Jake said that he really wanted to do that I think is gonna be really fun.

Jake Williams:

What you got? Oh, the irregular one?

Ralph May:

Yeah.

Jake Williams:

Yeah. Right? So yeah. Do you want me to grab the link?

Derek Banks:

Yeah. I got it in front of me if you don't.

Wade Wells:

Okay.

Derek Banks:

Yeah. Because that you're you're in in the green room. You're actually telling me something I didn't know about this. So this is great. This is like the story that keeps on giving.

Jake Williams:

Yeah. Yeah. So these yahoos, right, they are basically talking about well, first off, backing up your who is a regular. They, are basically what Meta and, OpenAI, I think definitely Anthropic, contracted with, right, to go and and ultimately, I say to go and ultimately, secure their agents during testing as to create these sandboxes. And, of course, a regular is like, ah, we had some miscommunication.

Jake Williams:

But then also, by the way, you know, we're gonna start doing security practices. Right? Things like monitoring logs. It's wild to me the number of reporters who are just, like, uncritically parroting, you know, what what they're putting in because they talk about, like, logging and monitoring. Like, log I'm literally quoting here.

Jake Williams:

Log monitor for model evaluations requires improved tools because attacks occurred in fewer than one in 10,000 advanced simulations. And even then, hundreds of turns in. And I'm like, that's security logging. Like, that's no different than what we like, who among us is like, oh, you know what? Our logs consistently show threat actors.

Jake Williams:

No. No. That's just how security logs work. These guys are negligent to the nth, man. I just I don't even know where to go with this.

Jake Williams:

Yeah.

Ralph May:

So these guys were getting hired to help secure Frontier security or Frontier models? Is that is that their, like, main job? Their main thing?

Jake Williams:

They were building the sandbox es to do the evaluations. So

Wade Wells:

so they own the artifactory?

Jake Williams:

Sure. Yeah. You know what? Yeah. Absolutely.

Jake Williams:

Right? Like, one of them, they they actually talk about, you know, where they're like, oh, hey. You know, one of the things that happened that led to this is we picked a company name that we thought was fictitious for one of the simulations. It turns out it's not fictitious. There was a name collision, and that's why our agents went out and hacked this real company.

Jake Williams:

They're like,

Derek Banks:

god. Like,

Jake Williams:

spell out negligence one character at a time. Like, you know, your lawyers are saying, shut up. Shut up. Shut up. So you're

Derek Banks:

like Maybe it's gonna come in the future, but I still don't quite understand. Like, if you if you take, you know, the model out, LLM did this, model did that, and you put in my name, Derek Banks, you know, hacked the package repository, spread laterally, and went and hacked a third party company, I'd be going to jail. Right. So I guess I don't understand why there's no talk, like, don't see any talk of, like, responsibility or, like, repercussions, like, I mean, wouldn't if it was a person and not a large language model, wouldn't that be the case? I feel like I'm missing something.

Wade Wells:

Money. Maybe maybe, AIs are about to get citizenship just like corporations.

Derek Banks:

Well, What I'm getting at is the people that Jake's talking about, like, there's a level of responsibility here. Like, it doesn't matter that, like, that the the the entity that did the hacking, isn't a person. It still happened, and there should be some repercussions for it. I'm not saying anybody needs needs to go to jail, but, I mean, there needs to be something that because if if a person did it, it would be a very big problem. Problem.

Wade Wells:

Right? Is it then this I think in this one, if this company was the one who built the network, right, so they built it insecurely, should it be their fault, or should it be the person prompting? I'm not sure

Derek Banks:

I know the answer.

Wade Wells:

Maybe Right. I have no clue either.

Derek Banks:

Right? By, you know, law enforcement.

Wade Wells:

Yeah. And Maybe we just ask ask it.

Hayden Conington:

We're we're seeing all the the the labs now almost, like, trying to compete just to say, like, no. Our model is also good. It hacked these other companies. Like, oh, no. No.

Hayden Conington:

Me too. Don't worry.

Derek Banks:

Oh, yeah. And traffic went back and it's like, oh, yeah.

Wade Wells:

We did it too.

Derek Banks:

Then another chimed in. Oh, us too. Right?

Hayden Conington:

Gemini's like, no. Don't ignore us. We hacked somebody. I promise.

Derek Banks:

Hey. I was gonna say, any of the frontier companies watching this, if you want someone to actually come make a sandbox and monitor and log in, I'm sure any number of security companies represented on this panel would be happy to help. I mean, come on.

Jake Williams:

In in fact, I released a framework much earlier than I planned to. I planned to do it on unprompted this year in the late fall. But I released a framework. I dropped it in chat. Custody specifically to deal with this problem.

Jake Williams:

Right? We're trying to keep agents in, you know, agents and networks. But because we've we've spent be real. We we've spent decades trying to keep the threat actor out of the network, not trying to keep us, the agent that we have running. Right?

Derek Banks:

Oh, egress filtering. Oh, right.

Jake Williams:

I know. I know. Not rocket science here. Right? But but it turns out, you know, you obviously, we're not doing well at it.

Jake Williams:

Look. If the Frontier Labs are if the Frontier Labs are hiring this out this workout, it's because they know how hard it is and they're trying to outsource that work and and possibly some of the liability with it. If the Frontier Labs know that they can't do this successfully, and the people that they're hiring are sucking at it too, your odds of success, I'm not saying that they're zero, but they're not great.

Derek Banks:

Oh, man. I don't even know what to say.

Wade Wells:

I don't either. Did you did anybody read Robopocalypse? It's like it wasn't it was it's okay. It's like World War z, but AI, pretty much. But the way that the so they successfully trap an AI, and it's like in a sandbox, and then it uses, like, the whole, like, able to read sound in order to get out and program something so it escapes That whole thing that that's what I imagine that eventually we'll get to.

Wade Wells:

It's like, yeah, you should have put it in a black box with no windows like you do your socket.

Derek Banks:

So so apparently, you know, the the way that, you know, these things are being trained, like, you know, they're essentially trying it to be creative, and, you know, it it kind of, you know, it kinda made me chuckle when they said we trained it and it's good at cheating. Like, it'll try and go cheat. I was like, yeah. You created a hacker. Right?

Derek Banks:

There's no cheating in hacking. It went and did something in a different way than you thought it would do. Like, you basically made a model that would would go hack, and and then, you know, they had swarms of these things that were leaving messages for each other on a message board, so they, like, learned as they went. It reminded me of Daniel Suarez's Damon novel.

Wade Wells:

Mhmm. Ryan Poirier. The the best was they actually thought that there was someone in there watching them, that there was a rogue agent, and then they investigated it, which is also just great. It's getting it's getting crazy, guys.

Ralph May:

Did you get it?

Jake Williams:

Is this is great job security. Seriously. Yes. Anybody watching this is like, I don't know how I'm gonna get a job. The entry level jobs, AI is killing a lot of those and entry level security work.

Jake Williams:

Instant response, man. Learn incident response, learn how to investigate logs, and learn how agents work because there is going to be a lot of that work. And there folks, there are things that people love to ask for discounts on. Incident response is not one of them.

Derek Banks:

Yeah. That's that's great advice and security architecture too. Right? Oh, yeah. Because we did a podcast episode on the AI SecOps podcast where we went through each one of these steps and talked about, like, how would you detect and defend again?

Derek Banks:

Like, detect and prevent this from happening. And shocker, all the technology exists. Like, irregular's wrong. This is no different than any other security and monitoring situation. Like, everything you could have done exists already.

Derek Banks:

It should have been done.

Ralph May:

You guys you guys remember when, COVID was going on and Zoom bombing was, pretty popular. Right? Everyone was jumping on to because there was no passwords. Right? But, so now we've got a new fun one, and this one is, AI related, and they're calling coined it Zoomsday, which is kinda clever.

Ralph May:

Right? According to the researcher, they used a standard AI model I'm probably Claude. And found a RCE with the annotate. Right? The annotate function inside of Zoom.

Ralph May:

Yeah. It was all all the way down the rabbit hole here, compromising the actual device. Right? From just the annotate feature inside of Zoom. So maybe Zoom should be using AI to check their code.

Ralph May:

I I don't I don't know what

Derek Banks:

Dude, that's that's really cool. Didn't read this one. That reminds me of that, like, Razer mouse vulnerability where you would install the Razer driver, but you could hit enter and, like, go to a command line as a administrator in the like, that's that's really cool. That's amazing it went that long without someone finding that.

Ralph May:

Yeah. That that I think that's the most interesting part. Not that AI found it. That's actually not that interesting anymore. It's that no one else noticed this.

Jake Williams:

Right?

Derek Banks:

Or they did, and they were using it. And they're all like

Ralph May:

Exactly. Exactly. So which is funny because we're on Zoom right now. I'm like, oh, I wonder they they did patch it.

Wade Wells:

Don't tell them, Ralph Gosh. The Opsac.

Ralph May:

They yeah. I know. Don't tell hold on. What's the password here? Let me find it real quick.

Ralph May:

So but they they did patch this. So it's it's been patched.

Jake Williams:

I do hate though when I get those like out of band notifications. Right? Yeah. Or somebody's like on, you know, hit me up in a signal group like, Jake, be wary of Zoom. There's an O day.

Jake Williams:

And I'm like, you're not a, you're not gonna close the loop on this. B, what am I supposed to do? Like, not attend meetings? Right? I mean, you know, it's

Ralph May:

just send you just send emails like, I can't attend. I know too much about Yeah. Can we go something else?

Derek Banks:

I mean, by that logic, you should just turn your computer off.

Ralph May:

Yes. Exactly. Exactly. Yeah. There's there's a zero day and probably all these fun things that you have.

Ralph May:

And even worse than that, some of them just get patched and never announced. They're never like a public blog or anyone did any research. They just find Right. That there's remote code execution in this internally or through a pen test or other security, and they just fix it and it's just all it's all quiet. It it could have been there for years.

Ralph May:

So it's interesting when we get to see the news on it, though.

Adrien Lasalle:

So Mhmm.

Ralph May:

Alright. What else we got? Anyone else got any other articles that they wanted to talk about? I'm I'm just kinda diving through.

Adrien Lasalle:

Let's see. Yeah.

Alex Minster:

I know there was that DEFCON one. It's

Ralph May:

Oh, yeah. That's actually one. Yeah. So the the the plane.

Alex Minster:

The plane.

Hayden Conington:

I checked my flight number. I was like, I wasn't on that flight. I wasn't on that flight.

Ralph May:

So for those who were living under a rock or don't know anything, their DEFCON and Black Hat happened the other week. And as you can imagine, a lot of people had to fly there. They probably don't all drive. And there was a Delta flight going from Las Vegas to Atlanta. And I guess they somebody was messing with the Wi Fi on the flight, and they had a whole thing.

Ralph May:

I think the the what do call it? The audio from the pilot was on there. It's like, we're just coming back from

Alex Minster:

a Well, yeah.

Ralph May:

With a bunch of Yeah.

Alex Minster:

So it was the it was the the in in flight messaging system between the pilots and the tower. Okay. I I I vaguely remember pilot stuff, but a lot of times, that's used in order to get, like, sports scores live

Jake Williams:

Sometimes Only stuff. Right.

Alex Minster:

Only the important stuff. So, yeah, they but they also it was first first picked up by, like, somebody that watches

Ralph May:

this.

Alex Minster:

I I I wanna say it's the AWAC system, but I know that's wrong. But there was, you know, the the the messages they only saw, like and I think it was turbine traveler that first saw the messages. Oh, ACARS. There you go. Not AWACS.

Alex Minster:

ACARS system. And they were monitoring that, and they were only seeing, like, one side of the messages, so they could only see what was sent from the pilot, but not what was sent

Hayden Conington:

Oh.

Alex Minster:

Back to the pilot. You could infer some things to where they're like, wait. So you want us to turn this turn all the Wi Fi off or reset the Wi Fi or what's going on? Additionally, there was there are some others that, like, you know, chase down the more legitimate sounding Reddit users if there is such a thing.

Ralph May:

I I well, I think it

Alex Minster:

was because there are people that were Redditors that were making claims of this, but they went through, like, their message history and said, yeah. These people were at DEFCON. They did post on these things before this incident. That's So they're likely not making up the fact that they were at DEFCON and on this flight.

Ralph May:

DEFCON or not DEFCON. Excuse me. Delta, if or said that no there was no hack of any Delta system, including the aircraft's in flight Wi Fi. So

Hayden Conington:

It was just evil to me. But They probably had

Ralph May:

a flipper, and they freaking were d f ing or not d f ing, but kicking people off d offing. Thank you. People on the plane and yeah.

Alex Minster:

Did you did you see Def Con's response, though? Because there was one there there was one thing that was excellent about DefCon's response to it. Maybe it wasn't. But DefCon did kind of DefCon did say, like, oh, even though, like, this attack has been around since 1997, and it's like, yeah, get them. Get that hacker.

Alex Minster:

Like, call them out. I'll be like, way to use way to use a thirty year old hack.

Adrien Lasalle:

Yes. So does that mean the the pilot has to hack back the guy that was?

Wade Wells:

We stored AI on every single airplane to hack back in case anyone attacks

Ralph May:

Oh, yes. Exactly. Cutting edge technology. By works.

Jake Williams:

Who on the call though is old enough to remember Chris Roberts?

Derek Banks:

Is that the first Is that the person who plugged into the yeah. That was what? 2015 or 2016? 2015. Yeah.

Derek Banks:

Remember John Strand saying, if any of you, like, people that work for me do that, you're fired. I was like, why would I plug into the plane? Like, that sounds terrible.

Wade Wells:

Alright. Well, Jake, tell the story because I'm pretty sure I don't.

Derek Banks:

Press us the old guys.

Jake Williams:

Yeah. Because you circa 2015, you know, he tweeted literally from in flight saying, I'm gonna make the plane fly sideways. I've got control of the engines. I've plugged in, what have you. Now whether or not that's even possible for an in flight entertainment system or was in 2015, no reason to discuss that specifically because there's a bunch of conjecture back and forth there.

Jake Williams:

I will tell you what definitely happened though is that, you know, he was detained when he landed. I was working with several people from his company in a SASSAG role and a contractor who the company, like, evaporated overnight. Because as I'm sure you can imagine, as that made big news, there's lots of people like, yeah. We're not we're not doing business with this clown. And so and Chris is an OG.

Jake Williams:

He's done a lot for the community, or prior to. I mean, he's kinda fallen off the map now because, like, yeah. I mean, I remember seeing, you know, private signal group, where he was, basically auctioning off bourbon a year and a half later, from his collection. Right? Trying to pay legal bills.

Jake Williams:

Right? Downsizing a house, all that. Like, so the real no joke. Like, people that had paychecks one day literally didn't the next because of these shenanigans. Right?

Jake Williams:

So

Derek Banks:

I mean, I'm all for, like, the flight, you know, like the airplane systems being tested just preferably not while it's under flight with

Hayden Conington:

Yeah.

Ralph May:

Know. On it. Yeah. Right? That seems That's the

Adrien Lasalle:

whole decree. Yeah. Yeah.

Hayden Conington:

I mean and and who

Jake Williams:

who on the call here isn't mature enough to know better? Right? Yeah.

Wade Wells:

I always just wanted to try to do DNS tunneling out. Like, this is back when you could you could supposedly, you could DNS tunnel out of the Wi Fi and get Internet for free. Oh, yeah. I

Derek Banks:

did it.

Ralph May:

Oh, I did it.

Wade Wells:

You did it? Oh, yeah. When when how recent

Alex Minster:

all the time. You should

Jake Williams:

Yeah. Statual limitations is well over on that one.

Alex Minster:

That's Okay.

Ralph May:

Alright. Right? So yeah. I cannot completely deny. I would like I would like to know or I'd like everyone to know, I pay for the Wi Fi now, but honestly, I have done for it.

Derek Banks:

What's free now? Right? Like, at least That's not done for free domestic.

Wade Wells:

On airlines.

Alex Minster:

Yeah. Like And this is one of the things to where it's like, you know, post DefCon, I'm kind of surprised this doesn't happen more often where people just power on their toys because I look. I've been in a hacker meeting where somebody brings in their new Wi Fi pineapple, and they go, yeah. Let's just check all of the boxes, boxes, turn turn on on all all of of the the things, and then you get, like, a very angry venue owner coming in being like, yeah. This is messing with our credit card systems.

Alex Minster:

Our TVs that are streaming things are now just streaming like troll a little low. Like, because you just turned on everything, which we kinda responded with two things where it's like, okay. First off, we'll find the first, and we'll shut it down. Second of all, why do you have such a flat network that we completely broke your stuff with turning on a all the switches on all the, you know, checkboxes on a box completely wreck your business. Let's have a let's have a more intelligence talk now.

Wade Wells:

And then I can see that

Alex Minster:

happening with with DEFCON people buying those, you know, whatever devices. And I'm not blaming devices, but your, you know, your, you know, pineapple pagers or your flippers or whatever and being like, I'm bored on a flight. Let me just turn this thing on. It has its own self contained battery because it's lithium battery, and I have to put it in my carry on. I just yeah.

Alex Minster:

Hit hit all the buttons, do all the things, and this creates a a situation. I think because they weren't detained and because of some of the things that I that has come up from, people who were on that flight. They're like, yeah. It seems like they made their announcements. They kinda said, hey.

Alex Minster:

Whoever this is, knock it off. And it self resolved. But because people are out there, you know, watching the messages, it made headlines because it's a it sounds like a juicy story.

Wade Wells:

All I heard was Alex hack some mom and pop pizza with a Wi Fi pineapple.

Ralph May:

Oh my

Alex Minster:

god. Pizza place One

Ralph May:

and pineapple. A bar. It was a bar. Pizza

Wade Wells:

place is Yeah.

Hayden Conington:

Gosh. Talk about the shield break stuff. That was interesting. The ShieldBreak POC with the Defender stuff.

Ralph May:

I don't know

Hayden Conington:

if you all read about that. Mhmm.

Jake Williams:

Is this like the second That's Marquelyn's fender vulnerability?

Hayden Conington:

Uh-huh. Where like, you know, Defender becomes the weak link. Yeah. So so bay basically, you already have to have, like, local privilege, but you abuse Defender to write a specific DLL that you then load into, like, the the Windows error reporting. And it just then executes your code, I guess, at a very high level.

Hayden Conington:

I mean, trivial to detect and prevent, but like yeah. That that one was very fascinating to see drop on like a I guess it dropped on like a Wednesday or whatever.

Ralph May:

Oh, this is the Nightmare Eclipse guy. Yeah.

Hayden Conington:

Nightmare Eclipse.

Jake Williams:

That's what I'm saying. Like, Nightmare Eclipse, man, is absolutely eating Microsoft's launch. I just dropped the link in the chat. Yeah. Or sorry, in the Discord.

Jake Williams:

But Nightmare Eclipse is eating Microsoft's launch. Right? Like, it's it's legit embarrassing at this point that that they continue to drop vulnerabilities here. I

Hayden Conington:

yeah. Yeah. And this is the thing is, like, so specific too. Like, that that is just it's almost embarrassing to the fact that that's in there. Because there's a very specific DLL too.

Hayden Conington:

It's it's phoneinfo.dll, which doesn't exist by default, but you are then, like, abusing through Defender.

Wade Wells:

I used

Jake Williams:

Ghost Reduction, right, we talked about these Ghost DLLs. Right? There's a bunch of them out there. The one thing I'm gonna give Microsoft credit for is that they changed some default behavior some years ago. Where just because you load a used to be if you loaded a DLL even just to read an icon out of it, it wrote it ran all the code in DLL main.

Jake Williams:

Thankfully, it doesn't do that anymore. So but, you know, still, I mean, ugh.

Wade Wells:

This this is the same guy who said that the July 14. Right? Like

Ralph May:

Yeah. Yeah. Over and over again. You know? Yes.

Ralph May:

That's I I I think it's interesting because I feel like Microsoft just needs to just start all over again. Like, Windows 12 is just a fresh rewrite. Just be like, it doesn't work with the all all the old stuff. Right? Like, just we're moving.

Ralph May:

We're we're we're dumping everything.

Derek Banks:

It's really just Linux under the hood or something?

Hayden Conington:

That is the year of Linux.

Derek Banks:

That's right.

Ralph May:

We finally get it when Microsoft has to just use Linux to keep going. Oh my gosh. They don't have patch all over it. Yeah. So he's probably gonna have another one.

Ralph May:

I don't know. He keeps dropping them.

Jake Williams:

I I would say that's that's likely. I mean but did like, real question here. Right? Why is Microsoft not, like, paying for this person? Right?

Jake Williams:

I mean, like, they should

Alex Minster:

be offering

Jake Williams:

this person f u money, right, to come back into the fold. I have some inside knowledge that that they were a former employee or system inside. I heard some rumor inside Sure. That they think they knew nightmare eclipse is. They think it's a former employee.

Jake Williams:

Offer them f u money. Bring them back in. Like, everybody has a dollar amount. Right? Even if they hate Microsoft, where they'll come back into the fold.

Jake Williams:

And, you know, I mean, like, beyond the public perception piece, this is just what's good for Microsoft's customers because I don't see this stopping anytime in the future. Right? You know, they've been able to carry this on now for what? Since April ish? March, April something?

Hayden Conington:

And that must be what Microsoft is hedging on is that eventually they'll run out of of things they can abuse. And it they're hoping that, like, it won't look bad if they start throwing money at this person that is very publicly embarrassing them. So they're trying to figure out which one looks, I guess, best for them publicly. Like, neither of them look good, but which one looks worse?

Derek Banks:

I I I don't know. I I think that with enough, you know, like, you know, domain insider knowledge about an operating system and, a coding harness and a decent local LLM, it ain't going away anytime soon.

Hayden Conington:

Right. Next thing you know, you're

Jake Williams:

gonna start hacking other companies. Don't forget that Microsoft one of the pillars of Microsoft's SDL, right, is that knowledge of the code should not translate to new vulnerabilities.

Hayden Conington:

Mhmm. That's true.

Ralph May:

Definitely not true.

Jake Williams:

I I'm not I'm not arguing the point. Just saying that's the point.

Ralph May:

Yeah. I know. Right? Did you guys did you guys see the new signal automatic key verification? So alright.

Ralph May:

So for all you signal users out there, you know, when you get that little message and somebody wiped their phone and they're like, their key has changed. If you wanna make sure that they really are, you have to, like, go meet them up and, like, look at the QR code and do this whole thing. You're usually just like, whatever. Accept. So the thing that launches, they launched a new automatic key verification to stop essentially, to stop server level wiretapping.

Ralph May:

Right? So, like, in between, you know, both of those connections. They launched that just recently to make your connection more secure. Fascinating. It's kinda interesting.

Wade Wells:

I just always put in the number when it prompts me. It's like, reverify, reverify. Yes. I know.

Hayden Conington:

It's treated the AI way. Accept all. Go. No problem.

Jake Williams:

No problem. We've got to verify.

Derek Banks:

Push notifications for the VPN. I just accept them.

Jake Williams:

I was gonna say, most people verify, like, signal your safety number changed about the same way that the SSH key on this remote host changed. Exactly.

Ralph May:

I know. Like, RMRFColonDotSSH.

Wade Wells:

It the

Derek Banks:

same people?

Hayden Conington:

Press command r and then enter this command? Yeah. Sure.

Ralph May:

Why not?

Derek Banks:

These are the same people who install py Python packages as root. I'm just saying.

Jake Williams:

True shame.

Ralph May:

Yes. Yes. Well, I mean,

Derek Banks:

and I do that too. It's okay.

Ralph May:

Yeah. The problem is these literally do change.

Wade Wells:

Here. This is an interesting one. The PBS one. PBS broadcaster loses access to 50 terabytes of data. Oh, yeah.

Wade Wells:

I'm almost years of TV. So the crazy part is they did have backups. Right? Well, they were using a third party provider named OSS. That OSS that But that was the backup.

Wade Wells:

Backup. That was the backup. But then, that company went That's not

Ralph May:

a backup. Backup. That's not a backup? No. What is it?

Ralph May:

321. Okay? You have three copies, two locations. Right? Like, I I mean, the the whole the whole thing.

Ralph May:

It's it's no. It's three copies. Okay. It's They're PBS. Alright?

Wade Wells:

They're running on low money. Alright? Maybe Ralph can donate some like you, man. Yeah. Is like, okay.

Wade Wells:

I'll support. Here's some terabytes. Alright? You can store some on my servers.

Derek Banks:

Just like like a guy in a basement who had a couple of data systems tied together and that's where the 50 terabytes was? Like

Wade Wells:

That that's what it seems like. They actually found out that the company was delinquent under Colorado's secretary of state and then realized that they were he they were actually

Derek Banks:

That's utilizing Iron really No.

Alex Minster:

But

Wade Wells:

That's really, like, pretty much what happened. Yeah. Yeah. Like, the company defunct, and then they were actually just third party to Iron Mountain, which totally normal, like resellers. Right?

Wade Wells:

Now they're in contact with Iron Mountain to try to get their data back. But

Derek Banks:

Oh my gosh.

Wade Wells:

Dude, could you imagine all the episodes of Mister Rogers

Derek Banks:

just Obsessing the street.

Jake Williams:

Yeah. So

Ralph May:

the yeah. The three two one was it's three copies, two different media types, and one should be off-site. Right? So they were just doing one copy and one was off-site. Right?

Ralph May:

So if you're going to do this properly, you should have the data. You should have a backup to a tape or some other medium, and then you should back that up to an off-site. So

Derek Banks:

Storage is expensive these days though. Right? Right.

Wade Wells:

What if the first two failed and this was the third one and it's the only one they're reporting on?

Ralph May:

How how how did

Wade Wells:

that They on they were disres I don't know. The tapes got hot and melted or something.

Hayden Conington:

Of of two locations, one of them has to be somebody's plex. Right? Like, with all that Yeah. Someone's got that something else. Yeah.

Jake Williams:

So no joke since we're already you know, we've already done the way back thing here, you know, previously with Chris. Mega upload. I believe that's 2013 if I recall.

Ralph May:

Oh, still around.

Jake Williams:

Oh, I know. Tracking. But when their servers got seized up in Canada, I had two enterprise clients who had unique backup data on those servers that got seized. And so they had to work then internationally with law enforcement trying to get this data off of

Ralph May:

Oh god.

Jake Williams:

This data off of these systems. And it's a yeah. Fun times, man. Know your backup provider.

Ralph May:

Yeah. And also the other, like, I'll I'll put this. The other security feature of a backup is you definitely wanna use some kind of worm backup so that you're not in a scenario where that data can be deleted. Right? You want retention policies in that data so that you you you can't even automatically delete it.

Ralph May:

Right? Like, you don't have that choice. It ages out at a certain point. Right? That's your little ransomware, fun one there.

Ralph May:

So which we don't got as much ransomware anymore. It's all AI.

Alex Minster:

Ransomware is good.

Wade Wells:

I know. We could use some good it used to be Oh, this podcast

Alex Minster:

is something about

Wade Wells:

ransomware. Right? Wait. Now it's just nothing but packages and AI. That's all we get to talk about.

Ralph May:

Oh, hold on. I don't want any.

Hayden Conington:

Give me a cool ransomware talk. Give me a second. Don't want any resistance.

Alex Minster:

And in this episode, Wade wishes for ransomware.

Ralph May:

Yes. So Don't don't wish for it.

Jake Williams:

We don't It's out there.

Ralph May:

Chicken articles this round, and we also don't have any ransomware. I think that's gonna be the new joke when we're we're trying to find somebody's probably gonna go find them now as we oh, yeah. I found, like, six ransomware stories.

Derek Banks:

So how long is it into your frontier model swarm of AI hackbots is doing ransomware campaigns? Is that the next story?

Wade Wells:

That that that is the next in in Damon, that is, like, the the middle chapter. Right? And then once once the augmented glasses are freely available to be distributed to the followers, that's when the ransomware will stop

Hayden Conington:

in our class. Well, the real ransomware now is the cost of inference. That's the new ransomware. They're gonna jack it up, and then that's the ransom.

Wade Wells:

You know what? Kinda like did you guys hear I remember, like, Bezos came out and said, like, soon, you won't own it. Like, the one you won't own anything. Right? And then, like, your computers would all just be virtual.

Wade Wells:

And, like, this was when they were trying to do the virtual gaming stuff, which I was like, this never got caught on. But now, I'm like, goddamn, it's gonna they're gonna make us do it. Like, it's a bit scary.

Derek Banks:

Yeah. So both Adrian and Jake have things to promote. Correct?

Ralph May:

Oh, yes. They totally do. Yep.

Jake Williams:

Go ahead, Adrian. Fire away, man.

Adrien Lasalle:

Yeah. So I have webcast about hardworking for beginners. Those are like the basic steps if you want to go into hardware hacking, the tools, what are the targets, and hopefully people can start straight after this webcast and mess with the WiFi router or something else. And it's now September 2. So hope you would be there.

Ralph May:

Nice. Is that a is that a one hour webcast or is it a is it a four hour?

Adrien Lasalle:

Yeah. It's one hour.

Ralph May:

It's just it's alright. One hour. Awesome. Awesome. Man, I love doing some IoT stuff.

Ralph May:

That's really fun.

Derek Banks:

Yeah. Hardware hacking's fun.

Ralph May:

Yeah. It's also, like, if you ever do get into it, there's just so many things out there that are horribly, like, I I don't know how they got there from a security standpoint. So and with the advent of AI, you could have

Jake Williams:

a lot of fun really fast.

Derek Banks:

That's where Skynet is going to be. Right? And all the IoT devices.

Wade Wells:

It's just distributed across all IoT. Yeah.

Adrien Lasalle:

There is no security. It's just obfuscation most of the time. So

Jake Williams:

yeah. Yeah. Yeah. For sure. Jake, you also had something too, didn't you?

Jake Williams:

Yeah. Yeah. Sure enough. So this Friday, much sooner than than Adrian's here. But this Friday, we're running a one day seminar on MCP.

Jake Williams:

I know everybody here has heard of MCP. I keep talking to folks who have no idea how to security assess it. And so have, you coming from somebody who's worked now, couple of MCP related incidents in the wild, as well as done a bunch of security assessment. I've got three custom MCP servers that I built that you'll work on throughout the day and learn how to do security assessment. So I hope to see some of you folks there.

Jake Williams:

I know not everybody can be there, but I sure hope to see some of you folks there. And I promise it'll be a be a fun jam packed day. So I dropped the link in the link in the chat as well. Oh, I see Ryan did as well. Awesome.

Jake Williams:

So

Ralph May:

yeah. Sweet. I love MCPs. I put MCPs on everything. Yeah.

Ralph May:

I hope, like, it's all connected.

Wade Wells:

You should see his garden. It's just MCPs.

Ralph May:

It's not like every single But you

Jake Williams:

know, the s in MCP stands for security.

Derek Banks:

That's correct.

Ralph May:

I thought it meant for just JavaScript.

Hayden Conington:

Yeah.

Ralph May:

Oh, awesome. Sweet. Well, does anyone else have any articles? Think I think that was I think that was it for today. Well, hey, guys.

Ralph May:

I really appreciate everybody joining and everybody who was listening live or whenever you do listen to us. We really appreciate it. And we will get to see you guys next Monday. Alright. See you, guys.