Initiative Gold Eagle - 2026-07-20
S6:E29

Initiative Gold Eagle - 2026-07-20

This week, the team discusses the White House's Initiative Gold Eagle and its implications for cybersecurity information sharing, an unexpectedly positive development involving Flock Safety, and the latest wave of AI news. The conversation also explores evolving AI model capabilities, security guardrails, open-weight Chinese models, and how AI is changing offensive and defensive security. Along the way, the hosts examine recent vulnerability research, industry reactions, and other cybersecurity headlines from the week.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters
  • (00:00) - PreShow Banter™ — The Two Jokes
  • (01:58) - Initiative Gold Eagle - 2026-07-20
  • (12:24) - Story #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination
  • (18:58) - Story #2 - Microsoft Reins in RoguePlanet Zero-Day Threat
  • (21:48) - Story #3 - Now, defenders are embracing the prompt injection, too
  • (27:45) - Story #4 - Security incident disclosure — July 2026
  • (33:38) - Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shift
  • (44:25) - Story #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy
  • (47:24) - Story #7 - Inside Pegasus: The evolution of the world’s most notorious spyware system
  • (48:38) - Story #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE
  • (51:49) - Story #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
  • (53:20) - Story #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFC
  • (58:10) - Paul’s Workshop
  • (01:00:29) - Sign up for the AI Summit to see Matt’s talk
  • (01:02:45) - Bronwen’s Workshop
  • (01:07:10) - Wild West Hackin’ Fest
  • (01:07:25) - DeathCon
  • (01:09:08) - PostShow Banter - Retirement Funds

Links

Story #1 - White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination
Story #2 - Microsoft Reins in RoguePlanet Zero-Day Threat
Story #3 - Now, defenders are embracing the prompt injection, too
Story #4 - [Huggingface] Security incident disclosure — July 2026
Story #5 - Chinese AI has leveled up, and brought renewed focus on the open weight model shift
Story #6 - LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy
Story #7 - Inside Pegasus: The evolution of the world’s most notorious spyware system
Story #8a - WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE
Story #8b - Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
Story #9 - Cyberattack threatens utterly critical infrastructure in Japan: KFC
Paul’s Workshop
Sign up for the AI Summit to see Matt’s talk
Bronwen’s Workshop
Wild West Hackin’ Fest
DeathCon


Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

Brought to you by:
Black Hills Information Security 

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

Active Countermeasures

Wild West Hackin Fest

Episode Video

Creators and Guests

Bronwen Aker
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Corey Ham
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
John Strand
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Ralph May
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Wade Wells
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Matt Franz
Guest
Matt Franz
Matt Franz is the AI Security Lead at Bespin Global, where he builds products at the intersection of Cloud, SecOps, and AI. With over 25 years of experience in early-stage startups and mature enterprises, Matt blends the strategic perspective of an executive with the hands-on expertise of a builder. His background includes founding the Helix Cloud Operations team at Mandiant/FireEye, serving as VP of Production Engineering at Cofense, and directing global security operations at Ping Identity. A former U.S. Army Intelligence Analyst, Matt currently focuses on large-scale data platforms, security analytics, infrastructure automation, and applying generative AI to offensive and defensive use cases. He builds daily in Python and Golang, with a focus on agentic blue team capabilities.
Paul Clark
Guest
Paul Clark
With nearly a decade of experience as a business owner and software‑defined radio (SDR) consultant and trainer, Paul helps clients and students leverage the power and potential of SDR technology. His company, Factoria Labs, provides consulting services as well as training, particularly in the realm of wireless communications, RF reverse engineering, and GNU Radio. Before founding Factoria Labs, he worked as a software development consultant for Meadow Registry, where he developed and marketed C++ tools for SDR‑based forensics. He has co‑authored three books in a series on getting started with SDR and GNU Radio, sharing his knowledge and passion for the topic. He also has a strong background in product management, embedded software, and mixed‑signal integrated circuit design, having led a cross‑functional team of 20 at Cypress Semiconductor to deliver innovative software solutions for PSoC® microcontrollers. He holds a Master of Science in Electrical and Electronics Engineering from the University of Washington and two patents in the fields of SDR and biometrics.