NASA Gets Phished by Chinese - 2026-04-27
This episode dives into the economics and competitive dynamics of the AI industry, including discussions on profitability, pricing strategies, monopolization, and the rise of open and distilled models—particularly concerns around Chinese AI competition. The hosts also cover a reported long-running phishing campaign linked to Chinese actors targeting NASA-affiliated researchers and engineers, highlighting how social engineering was used to extract sensitive aerospace information.
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
Links
Story # 1: ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
Story # 2: A Mexican surveillance giant you’ve never heard of is now watching the U.S. border
Story # 3: Scam messages offering ships safe transit through Hormuz, security firm warns
Story # 4: Apple fixes bug that let the FBI recover deleted Signal messages
Story # 5: Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Story # 6: cDc communications | CULT OF THE DEAD COW | The Hacktivismo Declaration: Rebooted 2026-04-21
Story # 7: NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
Story # 8: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Story # 9: Discord group says it accessed Claude Mythos by guessing location
Story # 10: Introducing GPT‑5.5
Story # 11: CERT-In Advisory CIAD-2026-0020
Story # 12: pro j e c t d e a l
Click here to watch this episode on YouTube.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
- (00:00) - PreShow Banter™ — Making More Money than OpenAI
- (04:58) - NASA Gets Phished by Chinese - 2026-04-27
- (07:22) - Story # 1: ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
- (13:07) - Story # 2: A Mexican surveillance giant you’ve never heard of is now watching the U.S. border
- (19:59) - Story # 3: Scam messages offering ships safe transit through Hormuz, security firm warns
- (24:24) - Story # 4: Apple fixes bug that let the FBI recover deleted Signal messages
- (27:49) - Story # 5: Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
- (30:28) - Story # 6: cDc communications | CULT OF THE DEAD COW | The Hacktivismo Declaration: Rebooted 2026-04-21
- (34:07) - Story # 7: NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
- (36:29) - Story # 8: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
- (41:34) - Story # 9: Discord group says it accessed Claude Mythos by guessing location
- (44:19) - Story # 10: Introducing GPT‑5.5
- (46:46) - Story # 11: CERT-In Advisory CIAD-2026-0020
- (50:47) - Story # 12: pro j e c t d e a l
Links
Story # 1: ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
Story # 2: A Mexican surveillance giant you’ve never heard of is now watching the U.S. border
Story # 3: Scam messages offering ships safe transit through Hormuz, security firm warns
Story # 4: Apple fixes bug that let the FBI recover deleted Signal messages
Story # 5: Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Story # 6: cDc communications | CULT OF THE DEAD COW | The Hacktivismo Declaration: Rebooted 2026-04-21
Story # 7: NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
Story # 8: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Story # 9: Discord group says it accessed Claude Mythos by guessing location
Story # 10: Introducing GPT‑5.5
Story # 11: CERT-In Advisory CIAD-2026-0020
Story # 12: pro j e c t d e a l
Click here to watch this episode on YouTube.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Brought to you by:
Black Hills Information Security
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest
Episode Video
Creators and Guests
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Host
Hayden Covington
Hayden Covington joined Black Hills Information Security (BHIS) in the Summer of 2022 as a SOC Analyst. He chose BHIS after hearing many great things over the years and seeing the quality of work, as well as finding people who have the same passion for the field as he does. His favorite part of the job so far has been the community. Previously, Hayden worked in a SOC for a Naval contractor, where he also served as their SOAR project manager and SME, as well as insider threat lead. When he’s not working, Hayden can be found doing anything athletic (like triathlons!), as well as enjoying video gaming and Formula 1.
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Guest
Aisling nic Lynne "siriciryel"
Aisling nic Lynne is a cybersecurity practitioner with strong interest in privacy and forensics, all the way back to setting up GPG inside her AOL IMs in college. Her broad technical background includes being a sysop for a top-20 supercomputer, high-energy particle physics experiments, and aero engine engineering. She is a second-generation ttrpg player, handyma'am, and would collect more Star Wars LEGO sets if only she had a place to put them. Some people want to see the world burn; she wants to see people's eyes alight with understanding.
Producer
Ryan Poirier
Ryan Poirier began his time at Black Hills Information Security (BHIS) as the Video Producer and Editor in August 2020. Ryan polishes and perfects every webcast, podcast, and workshop on the BHIS, ACM, and WWHF YouTube Channels. Prior to Ryan’s time at BHIS, he worked for one of the largest public schools in the United States, conducting their video production and live broadcasting. He joined the BHIS team because he felt like it would be a great group of people to work with, and he couldn’t pass up the perfect next step in his career. Outside of his time with BHIS, Ryan does freelance photography, attends Cars & Coffee events, and expands his knowledge of audio and videos.