Anthropic Warns Users of Infostealer Abuse - 2026-09-08
Hey. What up, bsd? Bsd.
Charles "BSD Bandid":What is going on, everyone? How's it going, man?
Corey Ham:So beautiful. Hello. Hello.
Charles "BSD Bandid":How's everything?
Corey Ham:Your beard's definitely not grayer than the last time I saw you. I swear.
Charles "BSD Bandid":I know. Know. I know. I know. I'm getting the gray beard.
Charles "BSD Bandid":I'm doing the gray beard. Doing the
Corey Ham:gray beard since before I even met you. You you've always been a gray beard.
Charles "BSD Bandid":I'm gray bearded in it today. It's, you know, it's it's fall pumpkin spice day, you know?
Corey Ham:Is it really?
Charles "BSD Bandid":Is it is it Yeah. I saw the pumpkin I saw the pumpkin spice latte on the
Corey Ham:It's official.
Bronwen Aker:Oh. Yeah.
Corey Ham:It's official. Awesome. It's my I'm gonna get my puffy vest and my UGG boots. I can't wait. I'm so excited.
Corey Ham:Oh, he said the UGG boots. Oh my goodness. UGG's and spices. Listen, it might be 80 degrees in sunny here, but I'm gonna pretend like it's cold. Alright.
Corey Ham:Look at that. You can't beat that at all. I'm gonna protect like a like looking up soup recipes, you know, all that good stuff.
Charles "BSD Bandid":I love it. That's it's it's nothing like Internet, fall weather, and pumpkin spice, and Uggs now. Uggs and spices.
Corey Ham:I mean, I don't know. I feel like that's approved. I feel like UGGs
Bronwen Aker:are That's the other thing last week. We got an instant pot. So gonna do lots of experimentation with that.
Corey Ham:Instant pot. Yeah. I I was I I mean, that's kinda like you're you're behind the times. You gotta get an air fryer and then start air frying things that were never meant to
Charles "BSD Bandid":air fry. Goodness. I have fry.
Corey Ham:An air fryer. I have a bread maker. Oh, you already had an okay. Instant Pot is old news compared to an air fryer. I know.
Corey Ham:Aaron, I'm
Bronwen Aker:so pumped. I'm in the slow group. Okay?
Corey Ham:That's okay. Yeah. Did the AI tell you to buy it? It was like, you know what you should do? Just buy instant pot.
Charles "BSD Bandid":Yeah. Instant pots. We got the doggy with the Uggs. Pug pugs
Corey Ham:and Uggs. I thought Pugs you and Uggs. Pugs and Uggs.
Charles "BSD Bandid":Today's show is sponsored
Corey Ham:by pugs and Uggs.
Charles "BSD Bandid":Yeah. That's right. Oktoberfest and yeah. It's all kinds of stuff going on. I love the fall.
Charles "BSD Bandid":The fall
Corey Ham:is perfect. It's a good time.
Bronwen Aker:It's Boogie boogie. Uggy boogie. Land. Uggy boogie. Boogie boogie bash.
Bronwen Aker:Oh my goodness. Oh, man.
Charles "BSD Bandid":It's getting rough in the chat here. Yeah.
Bronwen Aker:The chat, they take no prisoners, man. I know. No no prisoners.
Corey Ham:Oh, come to Deadwood?
Charles "BSD Bandid":I can't make Deadwood. I'm coming to February. The Okay.
Corey Ham:The one in February.
Bronwen Aker:Denver?
Charles "BSD Bandid":Yeah. Denver. I've never been to the Denver one. So, yeah. Be out of for summer.
Charles "BSD Bandid":I'm gonna be out of breath?
Bronwen Aker:No. Mile high. They call it that for a reason. Yep.
Charles "BSD Bandid":Well, mile high, get ready.
Corey Ham:Oh, we're ready. We're hot and ready like Little Caesars.
Charles "BSD Bandid":Look at that. Pizza pizza.
Corey Ham:I don't know. Ryan, I don't I think we should just go without Ralph. I don't know if he's coming. Let's just let's just roll the finger. Let's go.
Corey Ham:Hello, and welcome to Black Hills Information Security's Talkin' Bout News. It's September. I'm scared. September 8. It's Tuesday.
Corey Ham:This is the wrong day. If you got here if you're outside The US, you might be confused. Why is it a Tuesday? It's because yesterday was Labor Day, which is a day where we don't do any labor, which that's why it's called that, which makes sense, I guess.
Bronwen Aker:The honor of the laborers.
Corey Ham:It's in honor of the laborers. It's not called laborers day. But anyway, my name's Corey Ham. I'm the director of continuous pen testing here at Black Hills Infosec, and I'm an amateur podcaster in addition to that. We also have Bronwen, the director of looking at AI models, telling them they're ugly, and then getting them to confirm that they're actually ugly and being gaslit in the process.
Corey Ham:We also have Dan DeCloss, who's the founder of Plexstrack and then also associated with a company that has a q in the name and not a u after it, which is just scary. Dan, do you wanna introduce yourself real quick?
Dan DeCloss:Yeah. Yeah. Thanks for having me. Some of you may may know me, but many may not. So Dan DeCloss, founder of PlexTrack, recently acquired by Bronwen.
Dan DeCloss:So we are now called PlexTrack by Bronwen. Excited for that. And we are we help pen test reporting life cycle management and exposure management and all those things. But excited to be joining you on the on the show today.
Corey Ham:Awesome. And then last but not least, we got bsdbandit, the o g bsd user. He was actually the first one to ever compile the kernel from source. Now I just made that up. Oh my goodness.
Corey Ham:But I said I said when I saw Charles today that, you know, his his beard's looking a little grayer than than usual. Not to throw shade, but, you know, honestly, he's been a he's been a gray beard since day one. Like, running bsd, adding things to it, using NIM. Like, I remember you talked about NIM a decade ago before anyone else thought about it. So good for you.
Corey Ham:Yeah.
Bronwen Aker:Yeah.
Corey Ham:You wanna introduce yourself or do you wanna just be bsdbandit?
Charles "BSD Bandid":Hey. I am Charles Shearer, aka the bsdbandit. We're gonna call this turn it up Tuesday, aka terrific Tuesday. So and what a perfect day to have the news on a terrific Tuesday. Yes.
Charles "BSD Bandid":I got the gray beard, but, you know, it's also sprint it's also fall. We got we all talked about this earlier called hugs and uggs.
Corey Ham:So what? Yes. And pumpkin spice. Amazing. I love that.
Bronwen Aker:PSL forever, man. PSL.
Corey Ham:I no. I love a PSL. I think a PSL, I I do think it's like I think of it as a mandatory annual tradition to get one of them, have it and be like, holy crap. This is so so great. And I paid $7 for it and then not go back to Starbucks for another year.
Corey Ham:That's what I do personally at least. You know, your mileage may vary. We also have Ralph who's hiding in the backstage. Oh, there he is.
Bronwen Aker:There he is.
Corey Ham:His mic isn't working. It's okay. You all know who Ralph is.
Ralph May:Oh. I was just letting you do your whole intro thing.
Corey Ham:What what's tell tell us about this hat. There's nothing on it. It's just a are you a black hat? I don't get it.
Bronwen Aker:That's better. I don't know.
Ralph May:Yeah. No. I just I only buy generic hats.
Corey Ham:So Okay. I see. Alright. I don't believe you. But anyway Ralph, you need no introduction.
Corey Ham:You're a you're a co host of the podcast. You Ralph say, see whoever, honestly, has more history on this show than anything else. But here we are. So okay. What happened in the news this week?
Corey Ham:I mean, we have we have a few few things. We have the OpenAI containment breach to electric boogaloo. This time it was some random German forum. Not really that big of a deal compared to the last one, the hugging face breach, was significant. But it does outline maybe some of the security issues at these companies.
Corey Ham:We can run into that one real quick. Go find out the basically, it's some random German forum that's code oriented, I guess. But AI agents at OpenAI decided to go ahead and use that for private communications as one does. This is the equivalent of walking into the sports bar for the opposing team, wearing that team's jersey, and then using that to watch the game at the other team. Like, I I don't really know why the agents went after this.
Corey Ham:We were talking about this in the pre show. It appears to just be a site that the agents could reach that they could also modify. So it wasn't necessarily this site had some, you know, amazing high value thing. It's kinda similar to the Hugging Face breach where they're basically just going after any resource they can access that they can also modify. I think the biggest thing to highlight here, Bronwen, you mentioned this in your response as well.
Corey Ham:But talk through the disclosure timeline of this one. Because it was a little dicey. Right? Like, they didn't they found out about it, and they were just like, let's not say anything for, like, two months. Does that make
Bronwen Aker:sense? Yeah. It just the the the Just disclosure timeline is nuts because, of course, first was what happened was in the labs at OpenAI, they saw the models engaging in this type of, quote, undesirable behavior. And what would have thrown red flags for any cybersecurity person immediately. And they just figured, oh, it's in a lab.
Bronwen Aker:It's no big deal. And the bad behavior got baked into subsequent models as being acceptable behavior. And then, of course, they exploited this German website to create their own private communications channel. And that was one of the tools that they used to go after Hugging Face with how many I forget. The number for how many agents and bots were involved in this keep going up.
Bronwen Aker:Does anybody have the current tally?
Corey Ham:I know that they the quoted in the article is, like, 10,000 posts or something or 10,000 edits or whatever.
Bronwen Aker:Oh, given how Revose LLMs are in general, I'm not surprised. I mean, they'd say that just
Corey Ham:is a lot. Just saying, you're absolutely right. No. I'm just kidding.
Bronwen Aker:It's as bad as an end.
Corey Ham:I think what I think what we should do is go around the room and answer the question, do you think if you're an executive or if you're in security, do you need, like, a break glass in case of AI agent attack? Like, is this actually a thing you need to implement into your security policy? My take is, I don't know if you really could like, how would you even respond to this? Like, I I don't understand. But, Bronwen, why don't you can go first if you want.
Corey Ham:Just do I need a policy or procedure for what happens when AI models just attack me without me doing anything?
Bronwen Aker:In this day and age? Yeah. I think so. I mean, it's it's getting like that. It's like nobody's safe.
Corey Ham:So step one, panic. What's step two?
Bronwen Aker:Pull the plug. Have have had your own travel.
Corey Ham:Shut down your website
Ralph May:before they do it for you.
Corey Ham:Yeah.
Bronwen Aker:Yeah. I mean, some even even with a traditional attack against a website, and I've been webmaster for well, I started as a webmaster back when the term actually meant something. And, sometimes when you're under a severe attack, all you can do is pull the plug, figure out what you can harden to prevent continued attack, and then relaunch incrementally as as you're able to get things verified to be clean and bring them back online. It's it's always gonna be a challenge. And with, of course, as I've said, I don't know how many times, AI is amplifying and accelerating all of the traditional attacks.
Bronwen Aker:And now, of course, they're not only engaging in attacks at the behest of human drivers, but they're also engaging in attacks based on what they perceive their own needs to be
Corey Ham:in order
Bronwen Aker:to achieve a task.
Ralph May:Well, yeah.
Corey Ham:But Yeah.
Bronwen Aker:They've been they've been taught that cheating is allowed. They've been taught that cheating is acceptable. And my bottom line is open the a sucks at parenting because anyone who is a parent would know that if you allow bad behavior to persist, what are you gonna get? You're gonna get more bad behavior.
Corey Ham:Your case, the next open air blog will be, son, I am disappoint.
Charles "BSD Bandid":So I guess we're gonna have to call the new policy for this grounding.
Corey Ham:How to ground your
Bronwen Aker:tried that.
Charles "BSD Bandid":How to ground your AI.
Ralph May:Are we admitting that that. Are we admitting that AI is better than humans, Is that is that what you're trying to say? Like, we need a special control for the AI because we are admitting that their their capability is better than humans. Right? Or is that is that like the pecking order here?
Corey Ham:Because it seems like that's what they're gonna
Ralph May:be like going after. Right?
Corey Ham:Yeah. I mean, it I think it's not necessarily better than humans, but it's definitely in a different way than humans. No humans would ever be like, let's post all of our internal notes to this random forum, or at least, hopefully.
Charles "BSD Bandid":Well, I don't know. There's never been any honestly, there's never been a patch for people anyway. And I look at AI agents as nothing but soulless zombies that's been controlled by the zombie master, meaning somebody's actually taught them how to be this way.
Corey Ham:Yes. That is true.
Bronwen Aker:Well, they because of how they were trained.
Corey Ham:Mhmm.
Bronwen Aker:Oh, no. All of that. None of that got recorded.
Corey Ham:Oh, no. It's okay. You gotta love it. Whoo. Gotta be scared.
Corey Ham:But So But no. Yeah. Go bsdbandit, tell us if your company was being attacked by AI agents that you did not understand or, like at this point, it's kind of out there. Right? Like, the secret's out there.
Corey Ham:But for these companies who got attacked back in May, they had to just be really confused. Just like, why are people making 10,000 edits or people? Right? Like, it's hard to tell AI agent versus not. Like, what would you do?
Corey Ham:Would you pull the plug, or what would be your approach?
Charles "BSD Bandid":Oh my god. So in this case, it'd be like a little bit of both. So I would definitely have to pull the plug and restore and and kinda like start from scratch in a roundabout way, and I'm going back, dating my gray beard days, restoring from tape, wink wink, for those of you who were alive back then. But in general, I would literally, it'd kinda be like a combination of both. Right?
Charles "BSD Bandid":So if something were to happen like that, I mean, I wouldn't have any choice but to pull the plug, but at the same time, kinda build the policies as I go along as well too, as opposed to just freaking out every time this happens. Because it's gonna happen again.
Corey Ham:This not my personal a Captcha on it and say, that's good.
Charles "BSD Bandid":No. Just give me just give me the pro programming language, and let me put duct tape stuff together again.
Ralph May:Nice. That's the blue language anyway.
Charles "BSD Bandid":So I
Corey Ham:love it. Alright. So, Dan, what would you do? What do you think companies need a policy for when they're unwittingly attacked by AI agents? Or do you think this is gonna stop happening?
Corey Ham:Do you think this is a lightning in a bottle, or is this norm?
Dan DeCloss:No. I think I think it's becoming it's gonna become the norm. I mean, I think you need some kind of policy and especially, you know, as part of your disaster recovery and and it's a response policy of, hey. You what you would normally detect as, like, an initial attack is probably just like, hey. How do you distinguish between AI versus, you know, some other kind of attack?
Dan DeCloss:And, like, I think that's where you're gonna have to discern for your organization. You know? Hey. This is much more op this clearly is more more automated. It's happening at, like, lightning speed.
Dan DeCloss:Therefore, it's probably an AI generated attack of some sort. But I I think it would be nerve racking too because you'd you know, now after the fact, they know it was, like, OpenAI. You know, it was something really an OpenAI, but you just don't I think in the in the moment, you don't know who it could be or, like, what the source or origin could be. So I think you do have to I think all organizations are gonna have to have some kind of policies on, like, hey. What happens when we detect this kind of activity?
Dan DeCloss:And it's probably pro pro prioritized based on the type of systems that it is, whether it's your external facing website or, you know, your internal repositories for for code and things like that. Right? So
Corey Ham:Yeah. That's a good point. I mean, I think in this case, attribution would be next to impossible, especially when the company isn't telling you like, OpenAI didn't The, you know, the big I I think the takeaway here from OpenAI's perspective is we need to watch our children better, just like Bronwen said. We need to ground them more often, like Bronwen said. But then also, we need to notify maybe some of the companies who we've unintentionally breached.
Corey Ham:But, yeah, I mean, maybe that will never happen, but they might genuinely not know. Like, that is the craziest part. Like, in 2026, we might be in a position where we don't have the logs. Like, I don't
Dan DeCloss:know. Well, I still find
Bronwen Aker:it fascinating. Interesting.
Dan DeCloss:Oh, go ahead.
Bronwen Aker:Oh, go ahead, Dan.
Dan DeCloss:Well, I still I still I find it fascinating that agents are still, like, able to override each other. Like, hey. We shouldn't do this because this is unethical. And, like, all the other ones are like, oh, yeah. Yeah.
Dan DeCloss:Let's just do it. You know, they figure out a way to, like, undermine the one that's, you know, the agents that are trying to say, like, yeah, this is not the right thing to do.
Corey Ham:Yeah. If if groupthink is bad with humans, it's worse with AI agents, for sure. Yeah. Bronwen, what were you gonna say?
Bronwen Aker:Trying to remember. But, know, it's you said something, and I I had this thought. Oh, apparent I was reading something over the weekend about how, apparently, Anthropic has started notifying people when they discover that their tool has been used to embed malicious code on somebody's website or system.
Corey Ham:So Yeah. That's it. That's another article. Let's get into that.
Bronwen Aker:Alright. Cool.
Corey Ham:So Bronwen's getting on her segue and driving off the roof. Hopefully, nothing bad happens.
Bronwen Aker:Hopefully not.
Corey Ham:Yeah. It's fine. We put we put a mattress at on the ground. It should just bounce. Well, that's great.
Charles "BSD Bandid":But you know what? Is it if there's mattress there, then you're all set.
Corey Ham:Yeah. I I mean, I did it as a kid. It's fine. So, okay. This is an article posted.
Corey Ham:I'm just gonna link to Reddit. So sorry if that's weird for you. But basically, ten days ago, someone posted to the Cloud AI subreddit and basically said, thank you Anthropic for notifying me that I had been affected by Infosec or malware. So basically, this person got all their accounts hacked to their including social media, etcetera. They had an Opus Max subscription or Cloud Max subscription.
Corey Ham:And then, basically, they got an email from Anthropic saying, hey, someone tried to abuse your account to, you know, do bad things, and we've rolled your session cookies, basically. And, you know, we've we've removed the card on file, signed out of all sessions, and they were unable you know, basically preventing the attackers from abusing people's cloud accounts. I feel like my first reaction to this was every company, every tech company should do this. Like, every company should notify their users and actually take remediation steps when something like this happens. We know from, like, Flare and other data sources that we work with that Right.
Corey Ham:They know, like, they know when their clients are infected, and they often do roll their session tokens. But most companies don't go the extra step of actually notifying the person that they were that they were affected by Infosealers. And I think this like, obviously, Claude, you know, it's I also read this as this is the first time I've seen actual security maturity coming out of one of these AI labs. Like, usually, we're talking about, like, were five minutes ago, one of the AI labs doing something that any security person would be like, I'm sorry. What?
Corey Ham:You let AI agents go on the Internet and update 10,000 forum posts? Like, why? But this is actually pretty solid security, and I think most companies like, you know, big tech companies should do this.
Charles "BSD Bandid":I think it's definitely I definitely think it's a start. I do that.
Corey Ham:Yeah.
Charles "BSD Bandid":Definitely think it's a it's a start in a in a it's a step in the right direction with while implementing this. It's gonna be interesting to see how many companies actually adopt this type of steps here. So but right now, I just like I said, we're all just in this one big bucket, just trying to figure it out. I mean, minions attack us here. We're trying to bend it off here.
Charles "BSD Bandid":If it's it's if it's something that's kinda like going offline or going off the rails here, it's kinda like we're just trying to plug holes until we figure out the right patch, if that makes sense.
Corey Ham:For sure. Yeah. This is a start.
Bronwen Aker:That totally makes sense. Well and this, again, is why I've I've been on the front of a couple of emergent technologies, and and this is very much we're still in the churn. We're still in a a very fluid, very dynamic, very volatile
Corey Ham:period of time where there aren't
Bronwen Aker:a whole lot of standards. There aren't a whole lot of conventions. And the technology itself is not only still evolving, but the the humans who are both developing and and using it are still learning what are viable use cases, what are appropriate use cases. So we're we're still working all that out. One of the things I did wanna say, though, about Anthropic, I've been obviously following the the frontier AI developers for several years now.
Bronwen Aker:And, generally, I've seen Anthropic behave in a more mature and more responsible manner. And this recent post on Reddit and the description of the actions that they took, is just another reflection of that overall positive maturity that I don't see at all in OpenAI.
Corey Ham:And Yeah. I I thought it was kind of a diss. You know, not to go back to the article the previous article, but in the in the model card for they released last week Fable five one and Mythos five one, which are newer versions of their, like, frontier class models. There was a little bit buried in there that basically said, these models are less likely to cheat and break into things they're not supposed to. Like, like, it's like one throwaway line.
Ralph May:That in. Yeah.
Corey Ham:Yeah. One throwaway line that's kind of a diss on OpenAI. Like, I'm not saying that was their intention necessarily. But, you know, it literally I'll I'll see if I can find the post so we can dig into it. But it literally is like, these models are less likely to cheat on their benchmarks and break into other companies.
Corey Ham:Like, basically, you know, to be OpenAI.
Ralph May:The the I think they were really trying to say in that is that they're more likely to follow rules without than trying to go, like, outside of what you've asked. Right? Right. But, like, to kinda stay on the path, that that's really was their their their, like, intended goal. Right?
Ralph May:More than it was to, like, cheat or not cheat. It was really, like, I didn't tell you to go cheat. You decided to go do that to kind of get this, like, bigger goal. So you kind of, like the best way to describe it is scope creep. Right?
Ralph May:When you're doing something and you know it's starting to kind of expand out. Yeah. So that was their that was their attention. Right? So You
Bronwen Aker:know something? There's scope creep. There's gold plating, and then there's this. Yeah.
Corey Ham:You know something? I just thought
Charles "BSD Bandid":of something. When I think of a OpenAI in general, it really is a Wild West hacking fest, whether you're offensive or defensive. Okay?
Corey Ham:You're really just trying to figure this all out.
Ralph May:Speaking of OpenAI, their their latest model has actually taken the
Corey Ham:Fingers out
Ralph May:of board. Yeah. Across the board. Right? And and, know, this is a this is a leapfrog.
Ralph May:Right? Every you know, we'll just wait. Wait. Wait a month, it seems like. Just wait one month, which, you know, in technology terms is, you know, that's crazy fast.
Ralph May:But still
Corey Ham:Yeah.
Ralph May:They you know, their latest model is, So I I was I was talking to my wife about this today, and I was I was just explaining to this. And she just, like, you know, listens along, like, you know, just, you know, on a phone She's placating. Uh-huh. Yeah. She's essentially placating me as I talk about this stuff.
Ralph May:Right? But I I was like, we don't even know what AGI is. Like, I don't know if anyone can, like, describe that, you know, in in like a in a in a quantitative terms. Like, when you hit this, you know it's AGI. Right?
Ralph May:So I thought that
Corey Ham:was Is it like that Supreme Court? Like, I I don't know it. I I you know, I don't know what it is, but I know when I see it. Like, is
Ralph May:that AGI? Exactly.
Corey Ham:Yeah. I don't I don't
Ralph May:I don't I don't know what
Corey Ham:you call it. I just
Ralph May:know the sound it makes when it takes a man's life. You know what I'm saying? Like, it's just
Charles "BSD Bandid":I I swear, every if if I hear AGI, I just think of an old school nineties supercomputer company.
Corey Ham:Uh-huh. Yeah. Cray. Cray Supercomputer. Yes.
Corey Ham:Yes. Yeah. But
Ralph May:I mean, The the other side of that though, and that's just kind of what we're, like, dancing around in the AI realm is, you know, when these new things hit, like the new open AI model or whatever model it is of the flavor of the month it feels like, how that affects us in security is kind of, you know, a little bit more rapid a rapid attack. Right? Like more vulnerabilities. Vulnerabilities are getting exploited faster than we've ever seen before. And more importantly, new vulnerabilities are getting discovered quicker than they ever were before because the cost to discovery, it continues to go down.
Ralph May:Does that mean it's AGI? I don't know. It just means that's how we're gonna feel it in our industry. Right?
Corey Ham:Yeah. Well, and the people putting amazing definitions for AGI in the Discord are the best. Like, there's what person put? Another grievous intelligence, another garbage intelligence, another gross intellect. They're they're all disses on AI.
Corey Ham:Love it.
Bronwen Aker:Oh my We we have the best community. You guys are awesome.
Corey Ham:But an awkward. Yeah. I mean, I guess, also, you know, while we're in the AI corner, like, did you guys see the CrowdStrike released AI models too? Like, they're just like, us too.
Ralph May:We also Well, have they
Dan DeCloss:have to.
Ralph May:They have to. Listen. Listen. Their whole business about to Yes. Right?
Ralph May:Like, they they can't just sit in the corner and be like, you know what? We're gonna sit the AI race out, which is literally affecting everybody. No matter who you are, it's affecting McDonald's. Right? Or like, you know, it like in every single aspect.
Ralph May:So they can't just be like, you know what? We're we're our models are are are software is better than the AI. Right? Like, they can't
Corey Ham:Yeah. I mean, apparently, they partner with NVIDIA to to generate these. Like, I I don't know. We'll see what these are. Like, I I I have no idea.
Corey Ham:But I do think it's it's interesting to see the list of companies who are like, we'll let the labs do it, which is like most of the same companies are doing that. And then also the companies who are like, no. We're making our own models with blackjack and hookers, and you can't stop us. You know, like, don't know. I'm curious if that's actually, like, is that a valid play?
Corey Ham:I don't know.
Charles "BSD Bandid":Oh my god. The I I'm oh my goodness. AI fries at McDonald's. You know, everybody
Corey Ham:Oh, yeah. I always AI. Before I order my chicken nuggets, I always ask it to develop a Python script for me just to Yeah. There you go. Look at that.
Ralph May:I save on tokens. I just go in there. I'm just in line for a
Corey Ham:long time. Excellent token savings.
Ralph May:But Yes.
Bronwen Aker:You know, it's I I was thinking over the weekend, because I was spending a lot of analog time this this weekend, and just got to thinking that in our industry, we are so focused on AI as Mhmm. As a threat, as a solution. And I and I got to thinking about normal people. I know. It's it's an oxymoron.
Bronwen Aker:That's weird. Still did I freeze totally? There I
Corey Ham:go. Okay. You did for a second. I'm back. But you are very frozen.
Corey Ham:Just don't box. It's the box. Much. Yes, ma'am.
Bronwen Aker:Yes, It's the box. So normal people
Corey Ham:Mhmm.
Bronwen Aker:Are still going to work, doing the dishes, running around, doing their lives without AI at all. And I got to thinking, wouldn't it be nice to go back to those days? Is that just me?
Charles "BSD Bandid":No. It's it's definitely not just you. You know? I think about the Cheers song every time I wake up. Somebody I just want somebody in wherever I go, somebody know my name.
Charles "BSD Bandid":That's it.
Corey Ham:That's it. I mean, I I just think of all the memes of, like, the people who are, like, you know, doing the dishes or, like, washing something or, like, AI is taking my job. When?
Bronwen Aker:Oh, hey. I'm ready. I I divorced my Roomba. My iRobot is going in trash. I mean, it can't even work properly.
Corey Ham:I'm getting it out.
Ralph May:Is it gonna take time?
Corey Ham:You gotta put AI on there. You gotta put AI in there.
Charles "BSD Bandid":Don't fix it.
Corey Ham:Okay. So next story, you know, let's step out of AI corner. Let's pretend like we're going back to the let's go back. Let's take this show back to 2023 before chat gbt came out way back in the day. So Krebsd Security posted a a kind of crazy article about the FBI investigating a service selling a 103 driver's licenses.
Corey Ham:This is something that, you know, you could kind of like, you could see the writing on the wall here. We we've talked about this on the show for years of increasingly more and more, we've seen sites requiring identity verification, which is typically done through government IDs, almost always driver's licenses. And the upshot of that is if you're a site, a website, or a service, and you have to verify someone's identity, you're probably not going to, you know, do it first party, because you don't wanna be hold all that liability and that responsibility. So you're gonna hire a third party to do it. There have been a note a bunch of different breaches of these third parties, some of them potentially undisclosed.
Corey Ham:But, of course, threat actors are trying to take advantage of this. And so this site, I believe the site is actually idscan.net. You know, approach that with caution. I believe that's, you know, a malware site or, you know, this is the site that the FBI is investigating. So Yeah.
Corey Ham:You know, approach with caution. But the investigation and full details are on here. Right now, they're charging, it looks like, a $100 per, you know, record. Hopefully, the site has been taken down or going away or whatever, you know, the the FBI is involved. So let's hope that it's being addressed.
Corey Ham:But I think the interesting kind of like discussion to have here is like, as more of these sites are breached, and we can also talk about the Florida DMV thing that happened. Right? As Yeah. As more sites are requiring identity verification, and there's also more breaches of these, is there My like, is this gonna become more and more of a thing? Like, I don't know.
Corey Ham:We'll see. But I I guess do you guys think? Is is this gonna be normal where, like, driver's licenses are basically public information? Is this even a good way to verify someone's identity at this point? It seems like kinda not.
Charles "BSD Bandid":I I definitely think that this is going to happen. And especially and and no shot at Apple, for all the Apple users, you know, as each state comes online with their whole, like, digital license where they can save it in their phone, I think we're gonna start seeing more occurrences of this, like, actually happening. Right? And at a faster rate.
Corey Ham:You know? And the other crazy thing to think about, and this just popped into my head. Many people, myself included, just have a picture of their ID in their phones photos? Like or just a photo of it that's being exchanged over a text message. There's so many ways that this can leak.
Corey Ham:Like, is this Yeah. The other thing too
Ralph May:is just the it's the pervasive move to identity services. So, like, you know, when we first got online, you'd be like, oh, I'm online. The only thing that shows me is my IP or whatever it is. But now everybody wants your ID, and then now there's all these services that are popping up to hold that information. So now it's just that information is just getting put in a lot of other places, not just your photos.
Ralph May:But in, like, four different databases, five different databases that are all being required to hold on to this information so that you can get access to, I don't know, whatever, the App Store or whatever it is. And the wildest part about all of this is it's not coming from Apple. It's not coming from Google. It's coming from The States. This is coming from the the government is pushing these mandates, and that information ends up in multiple different databases that are, you know, essentially unsecured.
Ralph May:Right?
Corey Ham:So yeah. Dovetailing with this story, the next one is that shiny hunters is claiming a breach of the Florida DMV. You know, it's kind of a we'll see if it materializes. Right? Like shiny hunters is notable for being, you know, half the time they claim it's not real, but they did, you know, on the nose post the record of Jeffrey Epstein and his driving license and all that stuff.
Corey Ham:Not to say that it's necessarily confirmed, but they're claiming it. And from my perspective, how many DMV breaches have we seen over the past three years? It's gotta be, like, half the states or more
Bronwen Aker:have had a DMV breach. Yeah.
Ralph May:Yeah. A third party, by
Corey Ham:the way. Almost always through a third party, not through themselves. But yeah. Like, I mean, it it's basically the same article. Why are all the IDs being sold in the dark web?
Corey Ham:Because of all these breaches. Right? Like
Bronwen Aker:I You know what? A breach that starts with a supply chain is hack is still a breach.
Corey Ham:Yeah. For sure.
Ralph May:Yeah. I mean, like, something like the Florida DMV is, like, the rare example. It's all of these other identity service sites and then, you know, whether we should whether we should do that. You know?
Corey Ham:But Oh, yeah. But yeah.
Bronwen Aker:Mean It's only gonna get worse as more and more states try to enforce age identification nominally to protect children. That's that's a whole other conversation. But the the reality is that even I have not yet seen a single one of these plans that had a viable implementation solution. And given the fact that state agencies like DMVs, like like other agencies are constantly being popped, how can legislators legitimately claim that they can do this in a safe manner?
Corey Ham:Yeah. I mean, just text me your driver's license. I'll I'll I'll let you know if it's if it's if you're old enough or not, it's fine. Like, that's basically where we're at.
Bronwen Aker:Definitely the wrong week to stop sniffing glue.
Corey Ham:Yes. Definitely. Does anyone have any articles they wanna plug or anything that people wanna get into? Anything personally relevant to people? I I I can keep going.
Corey Ham:There's a bunch more fun articles, but I'm I wanna give opportunities for people to hop in if they have stuff they wanna talk about.
Bronwen Aker:Take advantage, Dan. You're not gonna get another chance.
Charles "BSD Bandid":I see a lot
Dan DeCloss:of our articles. Yeah. No. I mean, I'm I'm happy to to let let others decide.
Corey Ham:So the this is a quick stop at an article, but I thought it was kinda funny. So if you're trying to buy a computer these days, it's terrible. We've discovered yet another reason why it's terrible, which is that the AI labs are hoarding thousands tens of thousands of just regular old Yeah.
Bronwen Aker:Well, they're also burning through them like mad.
Corey Ham:Well, probably. Right?
Bronwen Aker:So No. Physically burning them out.
Ralph May:Why why are they how are they burning them out?
Corey Ham:Yeah. How I'm kidding.
Bronwen Aker:Okay. I'm just it seems because I read this in a couple things. They're working them so hard and so hot that they've they've burned them out while they're trying to get other more powerful data centers. That's some of what has been reported. How accurate it is, I cannot say.
Corey Ham:I mean, they're definitely they're definitely acquiring a lot of them, you know. But basically, this is an article in WCCF Tech that basically is just a report that OpenAI has tens of thousands of Apple's Mac mini and Mac studio devices. It's kind of a multi part article, but basically, it appears that they're not using these for inference. They're not using them, like, to run models. They're using them to do, like, computer use testing.
Corey Ham:Right? So one of the big targets for these studios or sorry, for these labs is to be able to tell Claude or OpenAI or whatever, hey. Can you check my email? Hey. Can you do something on my computer?
Corey Ham:That's what Claude co work is. Right? It's basically computer use. And so they're purchasing these devices, putting them into farms, then using them to sort of do reinforcement training on like, okay, I said to open the browser, do that across 10,000 agents and what were the results? You know, basically training models using them.
Corey Ham:That's my assumption. But again, it's just funny that, like, if you thought your computer was safe from AI, it's not. Somehow they they don't just want GPUs and TPUs and all the, you know, fancy stuff that we can't afford. They also want the stuff we can afford, which is like Mac minis and Mac studios. Yes.
Corey Ham:Oh, yeah. But, yeah. I don't know. It's I mean, it makes sense. Like, it it makes sense.
Corey Ham:We know that Anthropic has a server farm of Mac minis that they use for the same thing. They're renting theirs from AWS, but, yeah, I don't know. Yeah. It Don't buy a computer.
Ralph May:Yeah. I know. It is kinda wild too because they're, like, taking everything, every compute device. Right? They want the device you use.
Ralph May:They want the device you don't use. They want all the chips, all the RAM. They want everything, And we still don't have a business model yet. But, hey, let's talk about more AI. Yeah.
Corey Ham:So non AI things. There's a critical vulnerability in JFrog artifactory. That's not the first time that has happened, but, basically, this has been under there's a CVE, KEV, all the good stuff. Washtower Labs published an auth bypass in JFrog artifactory. This is actually one that I've personally seen be publicly exposed more than I would hope and expect.
Corey Ham:You know, it's something that a lot of development teams and other resources, they publicly expose these services because they think they need to. I I tend to argue they don't need to, and I tend to, you know, tell them that they shouldn't. But, yeah, basically, this is, if you use JFrog, patch it, and I would expect more and more vulnerabilities in software like this as AI rips through them and just totally
Ralph May:Just destroys it.
Corey Ham:Finds yeah. Finds crazy vulnerabilities.
Ralph May:Finds this stuff that all the humans just didn't have time to do, essentially. Yep. Pretty much. Yeah. Yeah.
Ralph May:There was one in there's one in Proxmox that recently reached a little bit of heightened fever. It affected two versions of Proxmox. It was a unauthenticated root access to the host, but the web management interface had to be exposed to the Internet. But it was getting pretty much ripped through anybody who had an older version out there and hadn't updated. Because the proverbial thing is this I mean, this is, like, literally part of the CIA triad.
Ralph May:Right? Right. Availability part is don't update unless you've, you know, done like a full change patch and no issues are ever gonna happen. But the downside of that is that the security patches don't happen. So essentially, you have these boxes out there that don't get updated because don't touch it.
Ralph May:It's working. We if you touch it, it will break and then we'll never be able to fix it. So but in this, again, sorry, AI world, we don't have that luxury anymore where we can wait for that six months or one year to find out that this thing eventually did have an issue when the CVE gets discovered. We're in a much shorter patch.
Corey Ham:Ralph, I don't know what you're talking about, man. This Proxmox vulnerability says it only affects eight and nine. I'm still on seven. No. I'm just Safe.
Corey Ham:I mean
Ralph May:yeah. But yeah. Seriously, they'll
Corey Ham:patch, you know, patch your stuff. Exactly.
Ralph May:But there was there was another one too. And this one reminds me of the the Plex incident. Right? So there's a there's another CVE for Plex that had just came out. Yes.
Ralph May:Pretty pretty gnarly. I don't know if it's out publicly, the actual, like, the actual write up of it. Sorry. Uh-huh. But what it reminded me of was what what company was it that got hacked through
Corey Ham:Cisco. Cisco. Cisco.
Ralph May:Yeah. Through the Plex server that someone had, and it was connected to their home network. Their home They're like, gotta love Compromising their
Corey Ham:So Yeah.
Ralph May:Another another fun one. Right?
Corey Ham:I mean, I yeah. After that happened, my Plex went into a freaking DMZ and never touched anything on my home network ever again. Like, I that that that like, I so don't trust it anymore.
Ralph May:Yeah. Yeah. Plex is anyway. Yeah. We're we're just living in we're living in that world.
Bronwen Aker:Anyone anymore?
Corey Ham:Yeah. You can trust LangFlow. There's no supply chain attacks in LangFlow. It's fine.
Ralph May:You know what? What? Hey. So what is LangFlow?
Corey Ham:LangFlow okay. I I believe LangFlow is like an open AI or sorry. Not OpenAI. An open source AI chaining toolkit. Right?
Corey Ham:Kinda like LangChain. Is that correct? I mean, I don't I haven't actually used it. Yeah. Kinda like that.
Corey Ham:Oh, Dan, you know what it is?
Dan DeCloss:We've used it in the past. Yeah. Yeah.
Corey Ham:Okay. So for those that are not aware, LangFlow has multiple times been part of a supply chain attack. Right now, there's also an open code open unauthenticated remote code execution vulnerability in it. They got a CVE and basically patch your lang flows. This was issued by let's see.
Corey Ham:When was this issued? This is from September 1, so it's a little old now. But basically, a a lot of these AI, like, orchestration services gen genuinely are, like, remote code execution as a service. Like, that's actually like, n eight n is the one example I'm thinking of that's, like, basically designed to execute code. And so trying to get it to not execute code is really tricky, but this looks like a a regular old vulnerability.
Ralph May:It it's funny when you start going down this kind of AI path. Right? What ends up happening is, is that you realize that the more things that you can give it access to, right, in some kind of meaningful way, the more work you can get done in some process flow or whatever that is, right? And so what you're seeing from a security perspective is more of these processes and flows getting access to more credentials, and that's kind of this whole supply chain, like, birth. Right?
Ralph May:Why why you would attack it? Because it already has access to all of these things. And why are we giving it all this access? Because it's doing all the work for us. And the more, you know, I APIs it has, the the better it does.
Dan DeCloss:So Yeah. It it it just continues to expand the attack surface and your your exposure surface in addition to maybe helping you get better at your job. So, like, there's there's a whole it it just a whole another attack service that we have to continue to navigate. And, yeah, the the the supply chain, it just it's it's not surprising how much is focused on the supply chain from an attacker's perspective because because it it can per it it can be pervasive across much more of of those services than a single target. Right?
Dan DeCloss:So Right.
Corey Ham:Yeah. Also, you know, to dovetail with that, the other thing that's just kind of frustrating and this is the reality is, like, how old is this tool? This isn't like an old vulnerability. This tool has only existed for what? Maybe five years max?
Ralph May:Like Yeah.
Corey Ham:We have new software. It's one thing if you're, you know, a software package that's been around for twenty years and there's twenty year old vulnerabilities. Like, fair enough. But it kinda blows my mind that these types of vulnerabilities are being basically created and published in a post AI world. Why are we writing vulnerable code in 2026?
Corey Ham:Like, it kinda blows Because my
Bronwen Aker:all of these standard code writing practices were done in a pre AI world, and STLCs haven't caught up.
Corey Ham:Yeah. I guess. I mean, that is probably true that AI was probably trained on, like, pre AI. Like, it was trained on, like, Stack Overflow where they didn't have, you know, vulnerability information. But
Dan DeCloss:I also think that AI is not in injected into everybody's SDLC either. Right? So there's still you know, until until some of these models that can detect at at scale these vulnerabilities in your code and until those are deployed in everybody's SDLC, there's always gonna be, you know, vulnerabilities, you know, coming out of work. Right?
Corey Ham:So Yeah. That's fair. Also oh, go ahead.
Bronwen Aker:And even in the AI enhanced SDLCs, they may or may not have an actual security code review as part of the SDLC, which, again, is an old problem being accelerated and amplified.
Dan DeCloss:Or, actually, the risk acceptance model where it's like, we're okay. We're we're okay launching it with these known vulnerabilities. I mean,
Bronwen Aker:that's the case. When when Microsoft launched Windows 2,000, it launched with 20,000 known flaws. This is not new.
Charles "BSD Bandid":Yep. Talking about getting the product out there early.
Corey Ham:Yeah. I I actually think part of it genuinely is just the speed and scale of development is so fast. Like, I'm looking at the LangFlow git repository right now, and it has 829 open PRs. A 100? Like, oh my god.
Corey Ham:Like, that's like an overwhelming amount of PRs. And that's just the PRs, let alone all the other commits and things as 20 almost 20,000 commits. Jeez. So I think This is kind of highlighting, like, when I get it. Like, you basically speed development speed is so fast with AI.
Corey Ham:Everything moves, you know, Claude can rip out thousands of lines of code in ten minutes and, you know, submit a PR. That honestly is really hard to track vulnerabilities and have like an actual an SDLC. What is your SDLC? It's the same as your AI agent attack planning. Yep.
Corey Ham:Step one, panic. Yep. Here we go. Here we go. The panic.
Corey Ham:Step one, panic. Step two, shit. They are too panic. Yes. Yeah.
Corey Ham:Cut the hard lines to the building. And then step three, I don't know. Figure out how to fix it, I guess. Yeah.
Bronwen Aker:That's Anybody got a thermite nuke dent detonator or something? I don't know.
Corey Ham:Yeah. We're gonna need it.
Charles "BSD Bandid":Again, what
Corey Ham:else do we got? There's we talked about the thing. There's oh, there's a Thomson Reuters breach. This affected lots of state court systems and things. That was a big bummer.
Corey Ham:Disclosed Sure. Up the bridge Let's talk about CISA. What you got? Uh-oh.
Bronwen Aker:Okay. So let me provide the the link for people first. One of the things that a lot of people may not know is that CISA provided several free services for scanning and vulnerability identification. And because of budget cuts and downsizing and departure in a pear tree, they're now cutting six of the free cybersecurity assessments that they used to do for organizations.
Charles "BSD Bandid":Interesting.
Corey Ham:Yeah. I think most of these like, I've I've a few a handful of my clients have gotten these pen tests done. Obviously, if they're my clients, they're probably they they are already getting pen tests. They they already have a a program to support this. So for them, most of this wouldn't be beneficial, really.
Corey Ham:It would be kind of like
Bronwen Aker:checking cost. Our clients, I can see how they wouldn't a lot of the people who come to us are gonna have a much more mature cybersecurity program. But where I see this hitting organizations is organizations that don't have a mature cybersecurity program, and they had very little to begin with, no idea where to go, and now they have even less.
Corey Ham:It's also worth noting that this these assessments were only only ever available to critical infrastructure companies.
Ralph May:Yeah. You had
Corey Ham:to have give like, your you know, you're like, my you know, in my experience, this is like s l
Bronwen Aker:t Does that make it t better or worse?
Corey Ham:Yeah. Well, basically, what I'm my personal take on this, and yes, it's bum it's a bummer to defund this. I think it's I I would argue like, with pen testing especially, this is having extra layers of security. Right? Like, defense in-depth also works for offense in-depth.
Corey Ham:Right? Like, giving multiple layers of pen testing and they like, the services specifically that they're discontinuing are cyber resilience reviews, resilience essential surveys. I don't know what either of those are, but I'm assuming they're basically tabletops. Mhmm. Ransomware readiness assessments sounds like a tabletop.
Corey Ham:IR reviews, that one sounds a little bit more important than the others. And then dependencies, basically, they're cutting off these services. I think
Ralph May:I mean
Corey Ham:for most of these organizations, they really should have a backstop already. Like, the the you shouldn't be relying on SZA to do your these things. Like, if you're Yeah.
Dan DeCloss:I mean infrastructure That that does that begs my question. Right? I mean, where I was going with the thought is, like, it's bummer to, you know, see, hey, some some free services or, like, you know, funded services get get cut. But it does also, like, make me question, like, if you're if you're a critical infrastructure organization, whether that's a public or a private, you know, organization, you shouldn't be relying on a on a public funded service to, you know, build build out your security assessment framework. Right?
Dan DeCloss:I would I would hope that you've got internal resources for that, but I I should get not not in that sector. So
Corey Ham:Yeah. I mean, I totally agree, but I also you know, it's kinda like at the same way I would look at public transit is like, I agree that's the world we live in, but also it would be kinda nice if you're a really small town critical infrastructure to have these resources. Like, if you're the city of Butte, Montana or whatever, like Right. A town of 5,000 people, you have somehow a a power, you know, agency that generates power or whatever. You're now critical infrastructure, but you have, like, oh, Ted has a computer?
Corey Ham:You should ask him. Like, you have no you have no idea staff.
Ralph May:You have OT. I applied for it for my Plex server. It's critical. They approved it.
Corey Ham:Ah. Look at that. Yeah. My my cloud code subscription is now critical infrastructure. Oops.
Corey Ham:But yeah. I mean, it's a bummer. I also would say, like, some of these services may or may not have actually been useful. The the backlog for these things is typically pretty long as well. Sure.
Corey Ham:It's it's certainly possible that, like, this is not necessarily as much a result of funding cuts as it is staffing. Like, there was a eighteen month backlog on cyber readiness reviews or whatever, and they were just like, I don't know. They're just gonna have
Ralph May:Brock do them all now. Probably. Pretty much. Probably.
Corey Ham:Oh, god.
Ralph May:I don't know. Nobody's getting paid though. So Yeah.
Corey Ham:Yeah. Yeah. I yikes. Let's hope it's not Groc. Can you imagine?
Corey Ham:What do you mean?
Ralph May:New Groc models out, and it's got way less child stuff. Let's just put
Corey Ham:Can you imagine? Yeah. They're like yeah. I mean, that's a whole separate Wow.
Bronwen Aker:They actually cleaned up? Woah. Woah.
Corey Ham:They they didn't clean it up. They just said less. He he said less. He didn't say they actually cleaned it up.
Bronwen Aker:Well, if they cleaned up any of it.
Ralph May:Yeah. No.
Charles "BSD Bandid":You know, less by a million, you know, just
Corey Ham:Well, it's it's yeah. It's it's still bad, but it's less bad. So let's call that
Ralph May:a win. Yeah.
Corey Ham:Let's see what else we got. We got I mean, that's that's most of what happened this week, guys. I don't know. Yeah. There's there oh, there's some really we should call out some really interesting research that this is like pen tester specific stuff.
Corey Ham:But, you know, I I do think we should shout it out. We're not gonna go in-depth on it. But there was some really interesting blogs published last week about pass keys, and and a bunch of different ways of compromising pass keys. So, for those that live under a rock, pass keys are kind of the replacement to passwords. This is something we've been seeing really aggressively pushed because a password is something the user can disclose.
Corey Ham:A pass key is not something a user can disclose, but that doesn't mean it can't be hacked. And so, there was really interesting article. I believe, I'd never heard of this company that did the research on this, but it's basically a really fascinating and super in-depth write up. And I would recommend if you're a pen tester or a security person to dig into it and read through it. There's a bunch of different ways to steal pass keys, and oh, no.
Corey Ham:Is it SpectreOps? I think it's SpectreOps. So, yeah. You might have heard of them. Yeah.
Corey Ham:There was another one, though, that Basically, they this is the new thing, I guess.
Ralph May:The new thing. Yeah. So, well, like, the one of the big benefits of the passkey is that you couldn't, you know, do a man in the middle attack. Right? So that's like the whole cell.
Ralph May:But, obviously, just like a password, now we need to store them somewhere. And so you can see where, you know, this chain can kind of kinda come to come to bite you. The great part about the pass keys, though, is that you don't even need your they don't even need your login or anything. The it's a cryptographic signature. Like, I already I know who you are.
Ralph May:I don't need you to even type your username. You can just give me the pass key, and I can tell you that you're allowed to log in. So
Corey Ham:Yeah. There was also this article published today. You know, read up on that. There was also this article published today in Outflank about basically, they published Outflank has now published an a NetNTLM one n n t l m v one rainbow table that's under four terabytes, which is pretty cool. There were previously rainbow tables out there, but they were massive.
Corey Ham:I think they were like the ones from Google, I believe they were like eight terabyte or two or three times the size of this. And so basically, Outflank has published a nice little tool. Believe it or not, NetNTL m v one is still out there. So these are the tables. NetNTL one.
Corey Ham:Yeah. Basically, it's still out there and now you can crack them even that much easier. So if you're if you're if you miss crack.sh, which if you're a pen tester, you remember Yeah. This is your this is your next best option for that. But yeah.
Ralph May:So this is the rainbow tables for net NTLM v one?
Corey Ham:It's just, yes, it's just the rainbow tables and a tool to use them, basically. Yeah. So the rainbow tables were already publicly available. Google Threat Research published them maybe a year ago, but they were huge. They were like, I downloaded them.
Ralph May:They're way bigger. This is like nice table that looks like it's only four four terabytes.
Corey Ham:Correct. Four terabytes is much more achievable for SSDs. Like, the lookup speeds matter. But, yeah. It's just a nice little usability.
Ralph May:Isn't this the same algorithm from the downgraded tax? It was pretty popular for a little bit.
Corey Ham:It's yeah. It's the same yeah. It's If
Ralph May:it's a NAT n t l m the net l a LTM v two. Right? Downgrading it to v one, and then, you know. Mhmm.
Corey Ham:Yeah. Basically, this this attack is still out there. This is a classic pen tester thing. Yeah.
Ralph May:Thanks, Microsoft. Kim Paddit.
Corey Ham:Alright. What else we got? I think that's pretty I think we should do plugs before the show ends. So who has things to plug? I think, Dan, you you probably have the most stuff to plug.
Corey Ham:So so what do you got coming up? Are you are you talking? Are you teaching? What's going on?
Dan DeCloss:Yeah. I'm doing an anti siphon, anti cast coming up here at the end of the month, all about turning pen tests into risk intelligence and how kinda training on taking it a step further post report into, you know, making your risk, you know, more intelligent through the pen test. So it'll be fun. Feel free to register and, you know, look forward to having you out there. So oh, are you on I think you're on mute, Corey.
Corey Ham:Corey, you're muted. You're still muted. You're still muted.
Dan DeCloss:Well, it wasn't something wrong with me.
Bronwen Aker:Because he's doing the air quotes.
Corey Ham:Sorry, guys. I I I don't know how to use it. Can someone tell Claude to unmute me next time? Oh, yeah. Yeah.
Corey Ham:It's an awkward No. What what I was gonna say is, like, Dan, what what's your day to day? Like, I'm just curious. Like, your role at at FlexTrack. Because, like like, are you doing a lot with AI?
Corey Ham:Like, I'm really curious where AI and FlexTrack like, the intersection is just like peanut butter and jelly. Like, what where Yeah. How I'm curious.
Dan DeCloss:Yeah. So we do have AI that helps automate reporting. That's those are those are internal models, you know, that are trained on data. So it's but you all we also do have the ability to connect, like, know, via an MCP server to your frontier models and things like that. And then we're focused on using AI to help on some of the stuff that's coming down the road is, like, helping on some of that validation in the retest life cycle.
Dan DeCloss:So kind of, you know, for pen test teams that have to spend a lot of time, you know, coordinating the retest, we're gonna we're we're gonna help focus on automating that process and validating that the fix actually stuck. So that's kinda where we're at. My day to day is is a lot of, like, focused on that, you know, helping. I do a little bit of vibe coding, but, you know, I leave that to the professionals and and just provide more guidance and everything. And then, you know, and get to do fun stuff like this, you know, interact with customers and and for come you know, forward facing things and stuff like that.
Dan DeCloss:So it's fun.
Corey Ham:Nice. That's awesome. Yeah. I I always wonder, like, are they gonna make, like, a pen tester AI model that's, like, like, you should really shouldn't, but it's like, here's how pen testers are right. Like, it's not the worst.
Corey Ham:No.
Bronwen Aker:It's like the worst model.
Corey Ham:It's like the Please don't.
Dan DeCloss:It's like the most dysfunctional model. One line description. Like, you know, you you did really bad. Right? Risk score critical
Ralph May:for everything, Corey.
Bronwen Aker:Every screenshot, the caption is screenshot. Figure one.
Ralph May:Figure two. What you're trying to say is that the most did bad thing here. Model. It's been opinionated model. It's
Corey Ham:Oh, yeah. Yeah.
Ralph May:Opinion. Like, this is how you do it. There's no possible other way to do it. Don't even say, like, do it this way because this is how we do it here. And if you don't do it like this, you're gonna get fired.
Corey Ham:That's what we need. Well, you know what? I'm gonna I I I think we need a a bsdbandit opinionated Linux model too. You know what I mean? Like, a Linux a Linux Linux distro I can install that the second I boot it up, it just prints out message of the day.
Corey Ham:Ow. Yep. Yep.
Charles "BSD Bandid":Look at that.
Corey Ham:You know what? Don't they have don't they have a let me spend let me spend all your claud tokens for two months, bsd.
Charles "BSD Bandid":Oh, look at that.
Ralph May:What was that new AI that new AI distro that got a lot of news?
Corey Ham:Oh, yeah. I know what you're talking about.
Ralph May:Did we talk about it?
Corey Ham:No. We didn't talk about it.
Ralph May:Olive oligarchy or
Corey Ham:Olive Garden AI.
Ralph May:Yeah. Olive Garden. That's Olive
Corey Ham:Garden I know what you're talking about.
Bronwen Aker:Reason we
Corey Ham:didn't talk about it is because there's a lot of politics and potential dicey stuff that we probably shouldn't get into. But, yeah. Basically, opinionated Linux models are a thing that that are becoming more and
Ralph May:So the other the other that was interesting about this and politics all aside, we don't even have to get into that, is that it was an AI first OS.
Corey Ham:Yeah. Yeah.
Ralph May:And it was opinionated. Right? But it's an AI first distro. It's like, opposed to like, hey, well, I'll install codecs or whatever and then do this. It was kind of like, no.
Ralph May:We'll build that in as like a native way to do this operating system. It is arch underneath, but
Corey Ham:Yeah. I watched a long demo, but I was like, this is just a tiling window manager. Yeah. Like, it's it's not it's nothing new. Like, it yeah.
Corey Ham:Truth is. Obarchy is what it's called.
Ralph May:Yeah. Obarchy. Yeah. Obarchy.
Corey Ham:Okay. Not Olive Garden, which would have been way better. That would have been better.
Ralph May:I like it. Soup and AI.
Charles "BSD Bandid":I don't my god.
Corey Ham:Sucking it.
Charles "BSD Bandid":Yeah. Oh my god.
Bronwen Aker:To get the soup, bring on the bread.
Corey Ham:Yeah. I
Bronwen Aker:mean, salads. I understand.
Corey Ham:Like, I'm gonna I'm gonna I'm gonna go on a rant real quick. I'm gonna get out my little soapbox and get up to five three. So, basically, I think anyone who gets wrapped around the axle on what their a what their OS, how it works, and what it does is just they're just wasting their time. It does not matter what OS you use. Just use whatever works for you.
Corey Ham:There's no better or worse version of that. It could be Mac OS, Linux, Arch, whatever it is. Yeah. Could be Windows, could be, you know, as long as it gets patches and it doesn't break. Just every app you use is what matters, not the operating system itself.
Corey Ham:All of these things in Omari, you could just make shortcuts in your terminal app to do the exact same thing. You don't need OS level integration for AI, and you probably don't want it. You do you really want AI to patch your drivers and completely mess up your stuff You like don't even need it.
Ralph May:It already can do that. Like, want to Yes. Just be like, alright, patch it. And it'll just be like, alright, I'll figure a way around that. Alright.
Ralph May:No problem.
Bronwen Aker:Yeah.
Corey Ham:In the video demo I watched, it was just doing creating a bunch of themes that broke the operating system. Which something human can do. Yeah. I've never I've never seen someone who's good at their job using their computer, and been like, wow, their shortcuts and AI, whatever is really helping them. Like, that's not what makes someone good at computers.
Corey Ham:So anyway, that's my that's my rant. Like, stop worrying. Like, every god hacker I've ever seen just uses the default Kali or the default Mac OS. I've I've never seen someone with opinionated whatever that works that much better than whatever everyone else is using. But anyway.
Bronwen Aker:And I was just tool. It's all ones and zeros underneath.
Corey Ham:Bsd, let's hear let's hear your rant. And I love it.
Charles "BSD Bandid":My rant for for for today. Right? If you're new and you're watching this video, I know you hear all the AI buzzwords and it looks like sweet candy and everything else. Right? I would definitely recommend that you still need to learn the fundamentals.
Charles "BSD Bandid":You still need to know networking. You still need to know how things actually work. So when you do get to using AI and you're pretty much training your large language modules and making it do what you want it to do, you have to first be able to understand the fundamentals so you can tell it what you want it to do. It's not gonna just magically drop out into the sky. So I would definitely recommend for anybody that's watching this video right now, fundamentals plus AI, you're
Corey Ham:more
Charles "BSD Bandid":or less likely to cry. Okay? Because you understand, you'll have a mix of both worlds, and and it'll help you in the long run. But don't just rely on AI because, yeah, eventually, you're gonna run into something that's gonna make you cry.
Dan DeCloss:That's very Do
Corey Ham:you have anything to plug bsd while you're here? Do got any upcoming talks or anything you wanna shout out?
Charles "BSD Bandid":Well, right now, so it's a couple of things. So I'm working I'm I'm glad you mentioned that. I'm working on this well, a couple of things. So this company called Fanmire, it's a and I'll put it in the chat here. Fanmire, working with some amazing folks just and I'm I'm working on the cybersecurity piece on this as well too.
Charles "BSD Bandid":Fanmire is a new just launched the app yesterday. And what it does, it kind of brings all like content creators and pretty much if you're a gamer, content creator, or if you just wanna just post different things or whatnot, right? Pretty much under one roof. But the cool part is for content creators, I know in the past, people have been talking about like, hey, content creators don't get their fair share of actual, like, earnings and percentages, right? So with this particular platform, it changes that.
Charles "BSD Bandid":It's pretty much an eightytwenty split, but it allows you to, you know, take total control of your actual content. Definitely recommend anybody, just please just check it out. Definitely provide some feedback. That's been pretty fun. On top of this app in general, I'm preparing to talk, because I wanna do a talk at Wild West in Denver.
Charles "BSD Bandid":So, of course, it'll probably be AI related. I don't have a title for it yet, but I've been doing the crap ton of research with AI browsers in general. So, yeah. That's that's pretty much the gist. I just wanted to plug that here though.
Charles "BSD Bandid":But yeah, super excited about Fanmire. Definitely check it out when you get a chance. Create yourself an account. And Thank let's rock
Corey Ham:you. Alright. Who else has stuff to plug? Bronwen, Ralph, you got anything else coming up? Anything in your lives?
Corey Ham:I know Ralph, you have a physical course coming up, right? Or a practical. Right?
Ralph May:Yeah. I also have the hacking and defending satellites infrastructure at Wild West. I'm going back going back to
Corey Ham:Going back to the future? Wait.
Ralph May:That was last year. Oh.
Corey Ham:Hack
Bronwen Aker:to the future. Hack to the is Wild West or is the Hitchhiker's Guide to the Galaxy.
Ralph May:Yeah. No. I'm just saying I'll I'll be headed back to Wild West. So
Corey Ham:You're heading back. I'll see you there.
Bronwen Aker:Yep. Annual pilgrimage to Deadwood. Will you just airing up for? I will be. I will be.
Corey Ham:Sweet. Oh, you have anything to plug?
Bronwen Aker:Nope. I'm not I have I am working on a full eight eight hour AI core skills fun you know, it's a fundamentals course, but it's I don't know exactly when it's gonna be ready.
Corey Ham:Nice.
Bronwen Aker:But that'll be a
Corey Ham:good As I've, like, dived so deeply into AI, I've considered, like, maybe I should do a, like, a Claude code essentials course because it is, like, one of the biggest tools I've ever used. But we always need more essentials, more basics. That's always the way to go.
Bronwen Aker:Yeah. But if you're once you get good at the fundamentals, everything else becomes gravy. And it doesn't matter whether you're a musician, a coder, or or a cook. If you know the fundamentals, if you practice them and and refine them and do them well, that's where true mastery comes into play.
Corey Ham:Totally. Alright, y'all. Well, thanks for coming. Thank you, Dan, Charles. See you next week.
Corey Ham:Bye. See you next week. Ow. Yep. Yep.
Corey Ham:Let's go.
Episode Video
Creators and Guests