Loading summary
A
What's up? Good morning, everybody. Welcome to the party. Today is Tuesday, March 4, April 14, 2026. This is episode 1110 for you Binary lovers. What would that be? Episode.
B
Hold on.
A
1, 3, 7, 15. So episode 14, actually, it kind of works out well, right? 1110 is 14 in binary and it's April 14th. Oh my God. Is this a coincidence or is. Is this the. The second sign of the apocalypse? Good morning, everybody. We are going to be crushing it. If you're looking to stay current on the top cyber news stories of the day while having a little bit of seasoning of entertainment and good times, well then you're in the right place because this is Simply Cyber's daily Cyber Threat Brief podcast. I AM your host, Dr. Gerald Ozier, and we are coming to you live from the Buffer Osier Flow studio studio here in the low country. And we're going to be ripping through the top eight stories in cyber. I'm going to go beyond those headlines, give you value. The Simply Cyber community above me is going to be delivering support, inclusion and empowerment for each of you. Getting it done. Let's cook, baby. All right, we are pumped, we are locked, we are loaded and we are ready to fire on all cylinders to deliver value to you. Now you can go through the top stories of the day yourself. But so why would you choose Simply Cyber's daily Cyber Threat Brief? Well, let me remind all you long timers and introduce to the first timers that we go beyond the headlines. I've got 20 plus years of experience. Many of us in Chad have tons of experience to speak from and the stories themselves are surface level and that's fine. Oh, this company got ransomware. Oh, this piece of policy and legislation came out. Oh, this apt has got an uptick in activity in Southeast Asia. Fine, fine, fine, fine, fine, fine. But how can we take this information and go beyond to level ourselves up as professionals? Because I gotta tell you, the most important thing that we can do for ourselves is develop ourselves and make us the most valuable marketable cyber security professional we can be. Because spoiler alert, you know, you can love your company, your company can be like your family. But dude, you'll be the first person they lay off if there is cash flow issues, if profits aren't being met, if revenues, you know, dipping, right? I mean, shoot, if there's just no money to pay you, they got to make cuts, right? So I want you to be in the best position for you to be able to crush it. And if you do love your job, holler to you by going through the top stories of the day, you can be right on top of emerging topics and be able to bring them to your stakeholders, your IT people, your business, and be the person who's like always Johnny or Jill on the spot with the top news. So that's the plan. That's what we do. We do it every day. A thousand plus episodes in a row. There's no stopping this train. We are Snowpiercer. We are fully going. Shout out to neckbeard with the squad membership. Thanks, Neckbeard. I'm feeling myself today, guys. You know what I'm gonna do? Let's give some memberships out. Boom. Gifted subs coming down the pike. Open your gullet. It's like an ice lose your freshman year of college. Just let the gold schlager slide on down. Ice cold. Don't worry about the. Don't worry about the spinal meningitis scare the next morning. All right, guys. Hey listen, if this is your first episode, drop a hashtag first timer in chat. Hashtag first timer in chat. We love welcoming our first timers because we want you to be welcome. We want you to know that this is an awesome space. A safe space where you can ask questions, get answers. Zemif. With gifted subs following the path. What's up, Zmith? Thank you. Listen, if you're one of the people who's picked up Zema's gifted subs like mad mad villain 11, you can thank Zenith. Dude, Zemif, I got a Simply Cybercon shirt for you for doing the ctf. It's. It's in my garage. I've got it for you. All right. First timers in chat. Hashtag first timers. If you are not aware of it, every episode of the Daily Cyber Threat Brief is worth half a cpe. A continuing Professional education credit. That's right. So this is an instructor led webinar and it's one hour long. So we say half a cpe saying that half the show is Eduardo educational value, half is entertainment value. Split it right down the middle. Ad tech, we'll see you a little bit later. We'll be here. Hey, we got Sachin, Buru pate. Sachin, first timer. Welcome to the party. Sachin, welcome to the party. Love it. All right, so dude, say what's up in chat. Grab A screenshot. The UN. What is this now? The UN. Ver. VerAX T H E U N V. Not sure how to say it, but welcome to the party. First timer. Welcome to the party. Oh yeah, we got first timers. For days. Get in here. Make room. Mad Destroyer. Coffee cup. Cheers. All right, guys. CPE say what's up. Grab a screenshot. Simple as that. File away once a year, count them up. That's what's up. All right? Now, every single episode, this insanity, this like all, all of this insanity that's going on over here, over here, down here, up there, all of it isn't possible without two things. One, you. You showing up every day makes it happen. If you didn't show up, I wouldn't show up, frankly. Okay, so you fuel the show and I genuinely appreciate it. The other thing that fuels it, it's a business, guys. So it's got to have financial support. It's just the reality of the situation. So I am super proud to not just take money from sponsors, but to share with you partners that are doing amazing things in cyber security. And I stand by. I really like these businesses, which is such a double win for me and for the community. Let me tell you about Flare Academy. You want some free education? Go to Simply Cyber IO Flare. Now, Simply Cyber IO Flare. Flare is doing a two part. It's a double shot. Cue the DJ horn. It's a double shot. The evolution of identity security. Listen, listen to me. You wouldn't know this. Identity security is so hot right now, they couldn't contain it in one show. That Hansel's so hot right now, it literally bust free of the constraints. You can't stop identity security. You can only hope to contain it. Flare Academy is bringing you a double shot. From directories to AI agents on April 15th. Tomorrow at noon to 2, you're going to get the age of directories and Kerberos. And then, as if you needed to get a towel, dab your brow, catch your breath.
B
Boom.
A
Part two. The token error everywhere. Wednesday, April 29th. You only got two weeks to get your stuff in order, get your final arrangements in order, because this is going to be a juggernaut. You could sign up for one or both of these. I recommend both since it costs $0. You put it on your calendar. You show up or you don't. Guys, as a practitioner, I'm telling you right now, if you want to add value to you as an individual contributor, understanding identity security in the modern, you know, it infrastructure, Cloud, hybrid, agentic, AI vendors coming in. Ephemeral access. Dude, there's a lot more than just here's your ad account. Have a good day. Way more than it. Okay. And this right here is four hours. Amazing value. Yes. You get cps, Snake zero, zero Eight, five. You get cpes for days. On this one you get four cpes because it's four hours of training. I'm not making this up, dude. This is like a sick opportunity. And for free. I mean if you want we can charge you. But why people need to get off. Like people need to decouple the cost of something having a direct correlation to the value of something. Cost and value are not related. You can have things that are free that are incredibly valuable. You can have things that cost a lot of money that suck. Go look at half the boot camps out there. 15 grand guaranteed. Six figure job. No, it's just 15 grand. You're guaranteed to lose that. Also want to say holla to anti siphon training. Anti siphon training is disrupting the traditional cyber security training industry by offering high quality cutting edge education to everyone. And right now if you go to AntiSiphone Training.com and you want that this Friday you can learn from Doc Blackburn. Take a workshop for only 25. Dude, that's table stakes. Four hours for 25. My guy. That's six bucks an hour. That's like, that's like half of minimum wage, right? That's a cup of coffee, like you know, a nice Starbucks cup. But still, how to think like a cyber security defender. This class, pretty dope workshop. Not only are you going to get hands on exercises and perform OSINT investigations, you're also going to be kicking it with other like minded cyber security professionals in chat. Anti siphon training is phenomenal. If you haven't done an anti siphon training, definitely Recommend it again. $25, 4 hours, you get 4 CPEs and you get some hands on skills. Thank you very much. Finally another sponsor, the final sponsor, one that I really, really enjoy. I've been working with them for a long time actually I actually sent the, the guy I've been working with for years over there, I sent him a Harry and David gift basket a couple weeks ago. Just because I really like what they're doing and I enjoy working with them. Threat locker continues to crush it. They have been doing application by deny by default on endpoints forever and doing it well. They've moved to the cloud recently which was the big reveal at Zero Trust World. Let's hear from them. And then we are going to melt faces. All you first timer, go put SPF3000 on your face because when we come back I'm absolutely going to torch it. We're lighting, we're lighting the candle, we're melting faces. It's going to be dope believe me. By the way, all sponsor links are in the description below. Let's go. That was a misfire. Let's go. I want to give some love to the Daily Cyber Threat Brief sponsor Threat Locker. Do zero day exploits and supply chain attacks keep you up at night. Don't worry no more. You can harden your security with Threat Locker. Worldwide companies like JetBlue Trust Threatlocker to secure their data and keep their business operations flying high. Threat Locker takes a deny by default approach to cybersecurity and provides a full audit of every action allowed or blocked for risk management and compliance. Onboarding and operation is fully supported by their US based Cyber Hero support team. Get a free 30 day trial and learn more about how ThreatLocker can help prevent ransomware and ensure compliance. Visit threatlocker.com Daily Cyber. All right, what's up everybody? Guess what? It's time to get to work. Do me a favor, sit back. You first timers relax. And for the Robert Hendrickson, the Dream Logics, the Neckbeards and the deb and gradies of the world. Let the cool sounds of the hot news wash over all of us in an awesome wave. I will see you at the mid roll. What's the mid roll, Jerry? The mid roll is a fun little activity where we're gonna do something and on Tuesdays I'm going to share a little bit about myself and see if we can vibe on it. The coffee is flowing. I feel like you know that scene with he man where he says I have the power. Hold on one second. I have the power. And for you listening on audio only, I'm bringing up the picture of he man as he summons the power of his sword from in front of Castle Grayskull. Which made no sense why he was in front of the castle. But this is how I feel right now with all the coffee flowing through my body. I am going to be delivering a scathing cybersecurity webinar right now. Let's go.
C
From the CISO series it's cybersecurity headlines. These are the cyber security headlines for Tuesday, April 14, 2026. I'm Sarah Lane. Claude Mythos previews cyber capabilities the AI Security Institute reports that Claude Mythos preview shows a significant jump in cyber capabilities. Successfully completing advanced capture the flag tasks and autonomously executing multi step attack simulations that previously required days of human work. The model solved a 32 step simulated enterprise attack in 30% of runs and and outperformed prior systems. Though tests were conducted in simplified environments real world defenses, the results Highlight growing risks from AI assisted attacks on weak systems and stronger security practices and defenses are increasingly urgent.
A
Yeah. All right. Hey Ky Cipher. Dropping a five banger on the super chat. Go get you some coffee. Thank you very much for that, guys. I mean this is like if you haven't been paying attention, okay, I know that this is the mythos Claude1. This is the AI model that they went to release and then like they a public a PR comms got leaked or whatever and they held it back and basically there's a collection of like Fortune 500, you know, companies that are getting early access to it. Shall we play a game? For the, for the benefit of cyber security, we are focusing on Mythos's capability to do offensive security operations. It was able to Capture do a CTF challenge. Guys, with all due respect, I like CTFs. I think CTFs are a great way to have fun with cyber adjacent topics. It's a fun way to meet other people, right? Like Code Brew. Me and a haircut fish sat at a table at Wild West Hack and Fest last year and dinked around with a ctf. But like a CTF is in no way ever a simulation of what you would be doing in a offensive security engagement, right? It's not. CTFs are not red team light. Now having said that, it does not take away from the fact that the AI could crush a ctf. It also says it was able to do multi step cyber attack simulations. Now here's my thing. 11 it. The concern is like, is this going to replace pen testers? Right? And frankly it will. It will address some pen testing stuff. I think what will end up happening is there's going to be a. Well, it's. I guess let me report on this and then I will give you my hot take My, my tinfoil hat. And again, if you haven't been following me, I know there's some first timers in chat if you haven't been following me. If you go to Simply Cyber IO Books, the first book that comes up, this is my library. This is my reading list. This is when people say what are you reading? Or what do you recommend? This is the list. Okay. This book right here, the Coming Wave. I bought this book March 22, 2024. You can see it right there. By the way, I'm very transparent with this stuff. Okay? You can get it for 14 bucks right now, which is a, a steal. Like the, the guy who wrote this book isn't interested in making money. He's interested in getting the information out. As far as I'm concerned. This is like, to me, I've recommended this book. I've never said what I'm about to say publicly before, but to me, this book is effectively a manifesto for how humans need to be thinking about the impact of AI. Not the newest model, not anthropic versus open AI, like, the macro societal impact of AI and the frequency at which it's updating and the disruption and disruption almost doesn't even, like, qualify for what it's going to do. And what it's been doing. This book, in my opinion, is it's, it's the. It's the answers to the test. And spoiler alert, you're not going to like all the answers to the test. But it's brutal. It's raw, it is objectively honest. So, Claude, mythos. 30% of. 30% of the times it get. You give it an enterprise environment, it can achieve the objective, which they don't really say. Like, is it getting domain admin? Is it getting access to some type of, you know, crown jewel or something like that? But to me, it doesn't matter. It's 30% today. If you look at all these charts, all these charts are up and to the right. Up and to the right. None of them are dipping. None of them are flatlining. Right number goes up. Now, all you bitcoin people are probably getting frothed at the, you know, mouth right now, like, scratching your neck, feeling good. This is not a bitcoin value chart, okay? This is the way AIs are performing up into the right. So it, it, it obviously would support the fact that, like, in one year, it's going to continue up into the right. In one year, instead of 30% of organization of, you know, environments, it's 45%, 60%. Right. I know people talk about this AI bubble popping and stuff. I, I don't. I don't see it, man. Honestly, the only way I see AI bubble popping is if we run into an energy situation. Right? Like, but in my opinion, in my opinion, there's. There's too much value, like, from a revenue from a straight cash, homie. Straight cash, homie. There's too much value in AI to like, let a little thing like power slow you down. You know what I'm saying? So, yeah, anyways, I also think once Mythos becomes a little bit more available, here's what I would suspect would happen. Organizations that have crappy security are going to get cracked open instantly. Organizations that have decent security are going to be a little bit more resilient. To this. But eventually they're going to have to have, you know, Claude Mythos, you know, defensive, you know, version of it or whatever. To what? Like, basically you'll need some type of AI to be instantly, like near instant speed, scanning logs, doing correlations, looking for anomalies, and then either taking action or guiding engineers or analysts to take some action. It's the only way. All right, Mythos blue. Thank you. Phil Stafford.
C
Hack leaves reached companies facing extortion attackers linked to Shiny Hunter Isn't Grand Theft
A
Auto 6 just perennially coming out in six months? Like, I feel like Grand Theft Auto 6 and I know this is a little bit nerdcore and less cyber security, but like grand theft, for those who don't know, Grand Theft Auto 6 is like Elder Scrolls 6. Like, it's just, it's always come, like it's always coming out next year. Always next year. So, like, when next year comes, it's coming out next year. Like it's, it's forever, they say. What does it say? January 2026. Yeah. Okay. All right.
C
Reached business monitoring software maker Anodot stealing authentication tokens to gain access to customer cloud data and exposing more than a dozen companies to extortion threats. The attackers use the tokens to pull sensitive data from cloud storage platforms like Snowflake, prompting access shutdowns. After unusual activity was detected, one affected customer, Rockstar Games, claims the breach had no material impact on its operations.
A
Oh, my God. Okay, so that's another thing, man. Like the burden of being popular. Like some third party company that does business monitoring, whatever that is, right? Business monitoring. A company called Anad Dot. One of their clients is Rockstar Games and they. Rockstar Games wasn't impacted yet. The, the graphic highlight on this thing is GTA 6. Deben Grady says, Are you a GTA nerd or an Elder Scrolls nerd? The answer is yes, bro. All right, so this is, you know, standard issue third party vendor attack. You got to look at your supply chain, remember? No. No matter how good your cyber security is, when you give data to your third parties, when you give access to your environment to third parties, if they have crappy security, well, guess what, you're about to get got. All I can say is this is a standard issue story. Like, honestly, it's not even worth going into. It is Shiny Hunters, which is noteworthy. Shiny Hunters continues to be at large. I feel like Shiny Hunters is like one of like the Batman villains. Like they're just like at large doing, doing hacks and stuff. Worth noting. Their hacks are Typically logging in like they steal credentials either through social engineering or other attack techniques. Less technical exploitation. Yeah, you can see here it says Shiny Hunters in the last year, as far as their TTP goes, Shiny Hunters is focused on companies like Anadoc Gainsight Sales Loft, which allows their customers to access and analyze large data sets in the cloud in an effort to steal passwords and tokens. So Shiny Hunter's whole bag is getting those creds which, which they are a. I would say they're a AAA threat actor, right? You, like we've heard of Shiny Hunter. Shiny Hunters has done things, I just want to point out they aren't doing technical exploitation. They are getting creds by either hacking into databases and getting creds, tricking users, calling help desk, whatever. Quick note flare, simply cyber IO flare. I told you about this during the sponsor ad read. I'm not making it up, dude. Like they are doing a two part four hour series on identity security. Do you know why you would want to attend something like this? Because things like this are a reality. On a Tuesday in the middle of April, threat actors are getting massive amounts of creds and because the like tldr, because this company Anadot has, you know, a user account that allows them to access large data sets or you know, the data sets coming from the client site or pushing up in there, whatever it is that identity is, is getting compromised. Right? So if you understand identity security, you can understand how to restrict those identities to what they need to access only. Least privilege, privileged access management, least use on devices and network endpoints. You picking up what I'm putting down? Guys, I got to tell you, like, here's the, here's the, the reality. You either love cyber security or you don't. And that's fine. You choose your own adventure and I will support you and however you feel. But you have to understand there's no easy button. Cyber security is hard and it's very demanding. Right? You can't look at identities and be like, oh my God, like, God, I just spent all this time hardening the gold load or the, what do you guys call it, Gold image. I just felt all that. I spent all this time configuring the servers and the network endpoints and making sure default creds weren't there. I rolled out mfa. I stood up an MDR service. Oh my God, I'm frigging tired. And now you're talking about least privilege. How about I just give access to everything? If you have an account, you have an identity, you can Just access things with. We did a background check. Guess what? It doesn't work that way. If, if you, if you slack in one area, all you have done is built a wall around the perimeter of your building with three sides and not in a triangle format. It's like building a four sided wall and leaving one side open. Or building a fence around your property and not putting one of the panels up in the fence. Sure, not everybody's going to find the hole, but it's a frigging hole in your fence. You see what I'm saying? That this is what cyber security is. You got to do it.
C
SSL library flaw enables forged certificate use A critical vulnerability in the Wolf SSL library.
A
Yeah, listen, Rogue cyber says gold load. Listen, there's a lot of different terms in cyber security. I don't know where it came from or why, when it, Just for those who don't know, maybe you're coming into cyber or it from like adjacent industry, like marketing or something. When you roll out image like you don't like when you stand up images for workstations in your environment, right? You say you got a hundred employees, you're not going to let 100 employees go out and buy a hundred laptops at Best Buy and stand them up and do whatever they want. No, you have standard applications that your business has approved and uses. You have enterprise applications you have licenses to worry about. So what you do is it provisions them or Justin Gold in some, some organizations provisions these endpoints. It gets the, the right stuff on, it's configured properly and then that, that, that, that standard right. Gets set it and I call it a gold load. Some people call it gold image. Like a standard image is a vanilla, vanilla build or vanilla image. Vanilla means like stock from the, from the vendor. Gold image, Gold load gold, whatever that is. What is like considered approved for business use. So nobody says gold load. I don't know why I say it. It's just something that I, I say. So whatever, whatever.
C
Allows improper validation of cryptographic signatures, letting attackers forge certificates and impersonate trusted servers or connections. The flaw affects multiple signature algorithms and could weaken authentication across billions of devices, particularly in embedded and IoT systems. It's been patched in version 5.9.1 and organizations are urged to update quickly to prevent exploitation.
A
All right, ap. So okay, so this Wolf ssl. Oh, I don't know why I said that. Okay, I mean I know why I said it's because I said the word wolf, but it just felt right. Also, spoiler alert, I have a wolf Tattoo on my back. Did you know that? Did you know that? For those who have been long timers, you may know that you also probably stunned that I have multiple tattoos. All right, so 5 billion applications and devices worldwide are using this, I think open source SSL implementation. It's written in C, it's designed for embedded systems, which means it'll be very hard to pick up to, to patch. Okay. Ah, you gotta patch it. Seriously, dude, embedded devices, IoT devices, they're not getting a lot of patches and if they, if you do have to do a firmware update, if you do have to do a firmware update, that's not something my aunt Dorothea does. Okay? Or Carl. Carl doesn't do. Carl doesn't do firmware updates. Okay? Which means this problem is going to persist. Now I do want to point out like, what's the problem here? Does this have a CVSS score? If I had to get, hold on, is there a cve? I, if I had to guess the CVSS score on this is like in this, it doesn't even have a, it does have a cve. I think this cve, I'm just going to guess here, I think it has a score of like six, right? Oh, it doesn't have a value. It says 9.3 on CVSS. Whatever. This, I don't understand what this is. CVSS 4.0. It says 9.3 critical. Okay. On, Is there a. Let me see if I can do this. I, I, I think that this, maybe I misunderstand this again. I didn't say this at the beginning. I don't research or prep for any of these. I have no idea what's coming. Ain't nobody got time for that. Oh God. Code Brew. Let me check out DJ BSS thing. This is a tool DJ B wrote very useful. Low, low score. You have 300ths of 1% of getting exploited in the next 30 days. It's 10 bad. It's not in the kev list, which means it's not being actively exploited in the wild. It says it has a 9.3 CVSS score. But here's my thing. It can allow malicious, it can allow malicious SSL connections to be established. Like sure, like basically the risk is that you would think that you have a or forged certificate. The risk is that you would think you would have a secure connection to a known entity. And in reality you don't. When I think of like embedded devices and whatever, I mean this is not like you're not using these certs to like connect to like, like Google Drive, Dropbox Signal. Like you're not like, what, What? Like dude, these, these, these certificates are on appliances, automotive systems, aerospace, military equipment. I suppose there is some concern of a connection to a forged cert, but like I don't know when, listen, whenever you like. For me personally, whenever I think how bad is this? Right? That's what we need to do. How bad is this? Do care about this as a practitioner, like for me, how bad is this? Like the likelihood is low, right? 3, 10 of 1%. I will say that the likelihood will increase over time because this is a very difficult thing to fix if it is baked into an embedded system. Like I said, you're not. This isn't a Windows patch. This is a pain in the butt patch. So you may not even fix it. What's the impact? I mean does a threat actor really want to get in between me and my water meter out front? Like, you know what I mean? Like I, I don't know what the real case is here for like nation state level threats, so maybe I'm being ignorant about it, but I, I just don't think that this is that bad. That's why the CVSS score, 93, I guess they gave it a high score because technically it can compromise confidentiality and integrity because with the Forge cert they can manipulate the data and obviously they can see the data. So I don't know. I mean I like the Wolf. I think the Wolf's cool and I think this graphic is cool for Wolf ssl, but I'm just not, I'm not really vibing on it being like, you know, go grab your brown pants because you know it's going to be a rough day in the trenches. Is there a patch? I mean there isn't even a patch. Like what are you supposed to do with this? Organizations using Wolf SSL are advised to renew their deployments and apply security updates promptly. What security updates? Okay, yeah, like all of this is like all of this is really crappy, dude. Sys admins managing environments that don't use upstream Wolf SSL releases but use Linux distributions should seek downstream vendor advisories. You know what I mean? Like I don't know.
C
Next 41 delivers zero detection backdoor researchers at Break Glass Intelligence report that China linked APT41 is deploying a zero detection Linux backdoor to steal cloud credentials across Amazon Web Services, Google Cloud, Microsoft Azure and Alibaba cloud environments. The malware uses SMTP based command and control and typo squatted domains to evade detection while extracting credentials from instance metadata Services for lateral movement and privilege escalation. The tooling reflects years of development towards cloud native attacks. And researchers warn stolen credentials can grant attackers broad access, requiring stronger monitoring, logging and access controls to contain intrusions.
A
All right, so APT41 is like Darth Vader. Like, it's just what? And not to. Not to say. Like, it could be Obi Wan kenobi too. Like ABT41 is just like one of those OG threat actor groups. So OG it doesn't even have a cool name like Smashing Pumpkins or Gorilla Tag or. You know what I mean? Like, it's, it's AP41. This is like they're so old that we didn't even have cool naming conventions. We were just like nerds with like square glasses and pocket protectors when, when Apt 41 came on the scene. Now they're using an undetectable back door. Like, wait a sec, hold up, man. Wait, I don't even remember what song that's on. It's like hurting my brain right now. But dude, undetectable. Like, let's pump the brakes. Undetectable. It might be difficult to detect. It may be going undetected at this time, but undetectable. I think Wade Wells is online too and would like to speak to the author of this one. Nothing's undetectable, dude. If it's running on your machine, it's running on your machine. It needs, it needs memory, it needs processes, it needs, you know, compute. Like it can't, it can't be invisible and run on the machine. Okay. It's targeting Linux based cloud workloads to steal creds from AWS and others. So they're getting creds, right? Phil Stafford. It's undetectable, yet here's a report on it. O. It's like saying the Invisible Man's over there, you know? All right, again, I haven't said this in a minute, but there's a couple first timers in chat that are worth, it's worth revisiting this. So apt 41, I made the joke a second ago that like, they don't have cool names like Smashing Pumpkins or you know, Filthy Mop or whatever. But you'll see that it says APT41, also known as Winty, Wicked Panda, Barium, Silver Dragon, Brass, Typhoon. So they do have cool names, but those are other threat intelligence organizations giving those names. So for, for marketing reasons and for threat intelligence confidence levels, different threat intelligence organizations give their own names to different threat actors. This took me years to figure out and wrap my Head around in cybersecurity, which is why I always make it a point to tell people. So if William Bailey is talking about APT41 and Zmith is talking about Silver Dragon, they are talking about the same group of four or five Chinese citizens in Beijing cracking away on a computer. Okay? Like, Brass Typhoon is Microsoft's naming convention. Wicked Panda is Crowdstrike's naming convention, okay? So just. Just know that. All right? All right, now let's see what they're doing. They're hacking Linux. They're using SMTP port 25 as C2. Anything can be used as C2. It's kind of wild because port 25 is unencrypted, right? So you'd be able to see this clear as day. Why. Why isn't shodan look at port 25? That doesn't make any sense. My guy. Hold on one second. Shodan IO port 25. Hold on, I'm gonna log in. I'm just. This is. I have several. This is Shodan IO. Like, what are we talking about here? Dude? I just searched Shodan for port 25, and as expected, here are all the 4,230,000 endpoints on the Internet as of right now that have port 25 open to the Internet. So, like, undetectable port 25, like what? Sorry, maybe. Maybe I'm an ignorant buffoon up here, but like, what are we doing here? All right, the ELF binary strip. Statically linked, designed for persistence, whatever. So it's. I guess it's undetectable because it carries zero detections on VirusTotal. Dude, again, my guy. If I may. Can I just point something out really quickly? VirusTotal is a signature based definition malware engine detector. Okay? If you don't know, Virus Total is a really great tool. It's an online resource. I think Google bought them, right? Virus Total is not independent. Somebody big owns them now. They don't. They don't. They don't publicize it, but someone big owns them. Hey, KT shoots. First timer. What's up? So listen really quickly. Zero detections on Virus Total just means that Virus Total hasn't seen that before. That doesn't mean it's undetectable. Okay, that is like the loosest, most like, spin version of undetectable I've seen in a minute for cyber security. Second of all, allow me to paint you a picture. Okay. Allow me to paint you a picture. Wicked quick. Number one, if I write a piece of code and save it, and it works fine, right? It's a malware. Okay, hold on that's Wednesday. And then I do a hash on it. Okay? Files have hashes. Hashes are one way math functions that are fingerprints for software. Okay, so look at this really quickly. This is malware bazaar. This is just a website full of malware. And you'll see here, these are all malware. And for those listening on audio only, I've gone to malware bazaar. Well, bazaar abuse check. I'm looking at different malware. Don't screw around with malware if you don't know what you're doing. Okay? Don't touch malware unless you know what you're doing. Hunt Star, welcome to the party. But you'll see that all of these files have a hash. Okay, and, and, and it's just. What the hell is this? What are we doing here? Find the objects that only work when plugged into a wall. My. Okay. So stupid. You'll see. See all these hashes? I'm showing a, a piece of malware. Here are all the ashes. This is a, an Android piece of malware. Okay, let me tell you something really quickly. If I open this Android malware and I modify one single element of it, if I add a carriage return, if I add one comment, if I put a space, if I do anything to this Android file and I recompile it or save it, it will have a different signature. This is why signature based anti malware detection engines are terrible and why you have to use behavior based anti malware solutions. Because it does. It won't work in 2026. It's trivial to change the fingerprint on a piece of, on a file, period. Look, David Bianco's pyramid of pain. Do you see the bottom? And we're looking at David Bianco's pyramid of pain. This is how tough it is for threat actors. You'll notice the bottom of the pyramid. The easiest thing for a threat actor to change is the hash value. All right, so let's bring this first full circle when you tell me that it's zero detection on virus totals. Like, come on dude, what are we doing here? Like, yes, it has zero detections, but like it could be that they're modifying every instance of this malware so it will never have a detection on the virus total. Okay. All right. Of course, this is a good one. Apt41, if you're an academic of malware, if you're an academic of cyber security and you like to study threat actors, APT41 is comprehensive. They do the whole cyber kill chain, they do it well. They have high fidelity tooling. They're a great one to study if you want to study. Not the best, but like you want to study one that's doing it well from a from a threat actor perspective. See. Yeah, they're going from basic reverse shells to purpose built cloud cred harvesters with scanner resistance C2 get up on that. Someone at APT41's getting a jelly of the Month club membership for Christmas this year. Good work there people. TLDR if you're running Linux infrastructure in aws, you should be mindful of this. Again, if you're running Linux infrastructure in aws, you are potentially a target for this at minimum. It's worth looking into this. Secondly, check port 25 for traffic in your SIM logs. It's not encrypted or it shouldn't be, so you should be able to see what the commands are and the traffic in that port 25. Let's keep going.
C
Huge thanks to our sponsor Conveyor 3 tools to manage customer security reviews is two too many. Most teams start with a trust center bolt on a questionnaire tool and end up with a knowledge base nobody trusts and a slack channel full of sales pings. Anyway. Conveyor replaces all of it. Trust center, Questionnaire Automation, Self serve for sales, AI managed knowledge library. It's all one platform. Companies like Atlassian and Zapier already made the switch. See why@conveyor.com.
A
So for those let me know. Hey if you can if you're listening on audio only, I don't really check the comments on Spotify or Apple podcasts. I don't even know how to do that if playing the song because listen, I play this song and then I trim it out after the show ends to eliminate any copyright issues. Which means people listening on replay miss this part of it. Let me know if that's a problem in the comments below for the for the replay people. Otherwise we're gonna go When I announce the winners of things I pause the music so it doesn't cut that out. It's it's basically the compromise that I've come up with for us to be able to kick it with simple minds but also me. Manage not blowing up this podcast Shout out to the stream sponsors Threat Locker Anti Siphon Flare bringing the heat. As I mentioned, Flare's got this identity security training Anti siphons got a workshop on Friday Threat Lockers securing all the endpoints in the cloud and on premises Every single day of the week has a special segment and Tuesdays is Tidbits Tuesday where I share a little bit about me and we see if we can buy. This is like, you know, behind the scenes kind of thing. All right, I, I wasn't really prepared for this, but let me tell you, we went on a five hour road trip. Rented a vrbo. By the way, I like verbos more than Airbnb on balance, although I've had good experiences at both. We drove five hours to western Georgia on Friday, right after that Tanya Jenka workshop I did, and then we spent the weekend there and then drove five hours back on Sunday. What I want to focus on a tidbits Tuesday is the car trip. Now, if you are a family person, I feel like it's going to resonate the most. But I think of like Clark Griswold, the family truckster, Eugene Levy selling that car, driving to Wally World. Dude, we've got, we've got standards. Kids are in the back, dogs in the back, Mrs. Is in the front. We've got eye control. We don't do the radio. I've got earbuds on listening to audiobook. The kids are immersed in tech. Mrs. Is doing her thing. We always stop. I, I don't like McDonald's at all. all. But, like, it's usually the most convenient thing because you want to stop. Do bathrooms, like, from an efficiency perspective, we've got to be structured. Right? It is absolutely ridiculous to not be efficient with our stops. Right? So you got to stop, you got to get gas, food, bathroom. Okay? You got to do it. You got to do all three of those. I know McDonald's is typically kind of where those gas stations are. And yes, I understand there's Wendy's and Hardee's and all these other ones, but, like, the consistency is there. I hate when the order gets screwed up. And, and the final thing I'll say is I get out of my mind. I get out of my mind. Okay, when we go through the drive through, the kids are in the back seat. The kids know we're in a drive through. The kids just told me what they wanted. And then the person starts handing me food and I'm trying to hand it back to the kids, and the kids are oblivious that we're getting food. It's like, take the drink, take the drink. Why did, why did you cover up the cup holder? Why? You knew you were getting a drink and a shake. You knew you needed two cup holders. What are we doing? And then the person trying to hand me a bag of food, and I've still got two drinks in my hand. All right, so that's My. My. In. That's my irritation with the family trips. But I love it. We made some good memories. What about you? What's your family trip? Elements. La. All right, let's finish strong. Also, Zmif always comes at me. Zima's always coming at me. Calm down, bruh. Z myth tell me to calm down. Oh, my God, dude, I can't even believe. Like, I. I can't even wrap my head around. Do you remember when we used to print out MapQuest directions and you'd have like 15 pages? How the hell did we get anywhere before. Before Garmins and gps? All right, let's finish strong, y'. All.
C
FBI and Indonesian police dismantle well, yeah. Federal Bureau of Investigation and Indonesian police dismantled the well phishing network, arresting its alleged developer and stealing infrastructure tied to more than $20 million in fraud attempts. The well toolkit functioned as a full service phishing platform, letting attackers mimic login pages, steal credentials, bypass MFA using adversary in the middle techniques, and resell access to more than 25,000 compromised accounts. Researchers including Group IB say the operation supported hundreds of threat actors globally, with activity continuing via encrypted channels even after its marketplace shut down.
A
Regulators. All right. Yes, sir. Yes, sir. Now, I know the FBI has been getting a bum wrap lately because of its leadership, but let me tell you, not all FBA FBI agents are, you know, created equal, I suppose. And there's a lot of great ones out there. And, and this, this group right here. Hell yeah. FBI Indonesia taking out a 20 million dollar fraud network. This group, well, who I've never heard of, Was used global phishing operations, stole tw thousand thousands of victims accounts and tried to steal $20 million in fraud. Well, hold on. Tried to, to attempt 20 million in fraud. What's the actual damage here? So this was a initial access broker, right? So in the cyber criminal underground, different roles have gotten specialized. And there's an entire discipline of people who just get access to resources, whether it's tokens, credentials, you know, access, persistent, like whatever. There's a whole thing. And I guess this, this group was offering that, so they weren't necessarily hacking people, they were just compromising their creds. Now, this was the well fishing kit, which was basically a COTS product for criminals. COTS is an acronym for commercial off the shelf. Like Microsoft Word is a COTS product. All right, they would just make convincing landing pages. It looks like Dropbox. It looks like Google, whatever. I mean, this is really like just a fancier version of social engineering toolkit. This is great, man. So 25,000 accounts are compromised between 2019 and 2023. That infrastructure has been broken down. This is a win for all of us. As a practitioner, you don't have to do anything. Just know that the FBI has done what they need to do in order to help us be safer. FBI Atlanta Special Agent in Charge Marlo Graham. Heck yeah, man. Let's, let's give, let's give Marlo Graham some. Yeah, look at this. There she is, dude. Marlo Graham. Can I just for a minute, I. I normally do wrecking balls for people getting jobs, but this, this woman right here in charge of bringing down a 20 million dollar fraud super network in a different country. Marlo Graham, you are a wrecking ball. I came in like a. Hell yeah. Let's go.
C
Mailbox rule abuse emerges as stealthy threat Proofpoint researchers report a rise in attackers abusing Microsoft365 mailbox rules as a stealthy post compromise tactic. With about 10% of breached accounts in late 2025 seen malicious rules created within seconds of access. These rules hide alerts. They forward sensitive data and manipulate email threads to enable fraud like business email compromise while remaining largely undetected. Because the rules can persist after password resets and be deployed at scale, researchers warn they create durable access and recommend tighter controls on forwarding, MFA and account monitoring.
A
Bain and co. All right. Yeah, okay. It'd be cool to get Marlo Graham on the channel, right? I'm sure she's busy, but. Okay, so check it out. Misuse of mailbox rules. Oh my God, dude, 1997's on the phone, they want to have a conversation. Native email features to maintain Access, Excel data, etc. Dude, this is a huge area that used to be, in my opinion, this used to be like the bee's knees, right? This was like what we would do as threat actors. I mean, as threat. Like I used to be a threat actor. Jesus. But like, dude, setting up forwarding rules, setting rules up. So like when malicious email comes in, it gets either marked as red or filed away, essentially making it so the person, the victim, can continue to use their email, but they don't see the emails that the attacker doesn't want them to see. So let's talk about Microsoft 365 rules. Once inside account, a threat actor. So by the way, this is post exploitation, okay? Post exploitation. They already are inside your account. They own your account. Let's see what they can do. Forward sensitive emails to external accounts. Yep. Number one, dude, this is a really common one. You should absolutely Have a detection in place for when a forward email account gets set up on an account in your environment. Now that could be difficult at scale if you have 50,000 people or whatever. But the thing is, if you are forwarding emails, even if you change your password and kick a threat actor out, they're still going to get all your inbound email. And then when you reply back and the person replies to you, they'll get the whole chain. So forwarding emails also, by the way, insider threat. If someone's going to be quitting and they start forwarding their emails to their personal email, that's kind of an indicator hiding security alerts, password reset, suspicious activity, 100%, dude. So they'll set rules up that look for, oh, you know, like, are you trying to change your password and just delete the email? If you're actively looking at your email, you'll see it come in, then you'll see the rule run and delete it. This is a great opportunity to educate your end users on just, hey, really quickly, if you see something like this when you're looking at your email, notify us immediately, okay? They also say intercepting and manipulating ongoing email conversations. This is business email compromise. All day, all day. What a threat. I'll just say this and then move on. What a threat actor will do is they'll get into a financial analyst's account and they'll just sit there and watch the emails go back and forth, not do anything. And then right before payment is about to go out, they will send a message and say, hey, really quick, we, we, we put the wrong account number on the invoice. Please wire the money to this account and it'll look legit. Threat actor, I mean victim organization will send the money to the wrong bank account and then the threat actors in the wind.
C
Vulnerability exposed. A hacker from Code Wall accessed an internal AI tool used by Bain Co. By exploiting credentials exposed in public code, getting visibility into thousands of chatbot conversations tied to client analysis. The breach took minutes and could have enabled impersonation of employees via exposed tokens, though Bain says no sensitive client data or core systems were at risk and the issue was quickly fixed. This follows similar recent vulnerabilities at McKinsey Co. And Boston Consulting Group Open Air.
A
All right, so, all right, here's the deal again. For the sake of time, I'm going to speed run this. If you don't know Bain and Company, there's like, there's, there's consulting professional services like Deloitte, Accenture, Booz Allen, where I worked for a number of years that are like really good, quote unquote prestigious consulting firms. Okay? Do your own research, come up with your own opinion. Obviously I work there. I'm not saying it because I worked. I'm just saying like that they're well respected. Okay? But then there's another tier of consulting firms that are super exclusive and they only hire like Ivy Leaguers and they're, you know, it's a lot of people wearing like thousand dollar suits but then eating out of cardboard in conference rooms at 10pm because they're working like dogs. That's McKinsey, Bain Company, Boston Consulting Group, you may not even heard of those because they only service like the Fortune 100 companies. Big, big ticket items. Okay, they're just saying that Bain's internal AI tool got breached, okay? McKinsey got breached. Dude, they offer consulting services. AI is definitely a threat to white collar jobs. And if I was McKinsey and Bain, I'd be quite concerned because for what they're charging per hour for their services, Claude can get you 80% there. The final thing I'll say really quickly is that just as a fun fact, if you ever wanted to know, if you ever wanted to know why executives get paid ridiculous amounts of money in bonuses and golden parachutes and stuff, I think it's McKinsey you can thank for that. McKinsey executive pay. Hold on one second. Executive pay history. I think it's them. Yeah. McKinsey and company significantly shaped modern executive pay through Arch patent studies in the 50s that pushed for higher executive bonuses, contributing to a massive rise in CEO compensation. So if you've ever wondered why CEOs get paid ridiculous amounts of money, there's a history there. Just Google, Arch Patent McKinsey executive pay and you will get. You'll go down a rabbit hole, trust me.
C
Mac apps need updates. OpenAI said its Mac OS apps require updates after a supply chain attack compromised the widely used axios library.
A
To ZMIF's point, no wonder they get hired by the big firms. Yes, that is part of it. That is part of it. Zmith. If I hire you and you're likely to come back and say that I need to make more money, I like you. I'll bring you back next year too.
C
Which was briefly infected by a North Korean group after hijacking a maintainer's accounts, a GitHub workflow used for app signing downloaded the malicious package, prompting OpenAI to revoke and rotate certificates, despite finding no evidence of data access or system compromise. The company fixed the misconfiguration, is working with Apple to prevent abuse, and warned older macOS app versions will stop working once the certificate is fully revoked.
A
All right, I love this. There's nothing for you to do. OpenAI is handling this. The Axios NPM breach The other day, OpenAI has had some issues with the Mac OS application to it. You do have to. I'm sorry, you do have to update your Mac OS Open AI client. Ah, you gotta. Patrick should be doing that anyways. I don't use open AI. I'm anthropic all day long. But if you are using open AI or you have it in your environment, you gotta patch it. I will say that this is a nice I. I'm shout out to OpenAI. They are being proactive about rotating credentials and doing all this in abundance of caution. Instead of saying, oh, it doesn't look like we're hacked, we're just going to let it fly. Very nicely done. That is a best practice. I will tell you when we're talking about cyber security framework maturity and you look at like NIST CSF 123455 is the most like this is the sign of an organization that's like NIST 3.0 or higher. You don't typically do this unless you have your ducks in a row and you can sustain this level of impact because they're rotating creds. It's, it's, it's painful. Okay. But very nicely done. Open AI. I still don't like you for reasons, but very nice. Again, just as a reminder, if you are running that Axios library in your environment and you did run that vulnerable version, you probably want to consider rotating your creds inserts as well because there could be compromise. It wasn't necessarily compromised to the certs, it was just. There was you. They basically had like super access to your environment. Okay. All right. Yeah. Roswell UK is dropping things. Here we go. All right guys. This was Simply Cyber's daily cyber threat brief podcast. 350, 370 of you here throughout the day. Thank you. On a Tuesday, April 14th. Hopefully you enjoyed the tidbits Tuesday and the the car trips. I'm Jerry from Simply Cyber. Don't go anywhere because you are about to get tuned into the Cyber Career Hotline. That's right, the Cyber Career Hotline. The Cyber Career Hotline is designed for you to get questions and answered, dial in and level up. You will be treated to the professional development musings of one cosmic cowboy. He's the wolf man of cyber security and he's going to be bringing the heat to you. I leave you in the capable hands of Jesse Johnson. Jesse, have a great show, everybody. Be well. I'll see you tomorrow. Also, Also today at 9:30am, Jesse and team Kathy Chambers media is going to be going live with Authentically Cyber. Talking about episode three, Cyber security wasn't the plan. A mentor changed everything. So stay tuned for that as well. I'm Jerry, your chat. Till next time, stay secure. Ever wonder what it takes to break into cyber security? Join us every week. Listen, I'm not going to play the jawjacking segment. We got to make a cyber career hotline. Jesse, you ready to rock? Oh, you look good, Jesse. I like you. All right. Ladies and gentlemen, Jesse Johnson, your Cyber Career Hotline host. Let's go.
B
Yo, yo, yo. Good afternoon, good evening wherever you are and whenever you are. Welcome to the Cyber Career hotline. The line is open. I hope you're doing well out there. YouTube world. What's going on everyone? Yeah, we got some chat, firing up, cooking. Hope everybody's doing well out there. Got some good vibes. Let me know how my microphone sounds. Is it crisp? Is it a little thin? Does it need some dialing up, some tuning in? Wow, this light is a lot brighter than I was expecting. What is going on everybody? Here we go, it's Jesse. Drink. Hey, Legrat 6678 to see you. Legrat. Good morning. Kathy Chambers, tech grunt. What's up Z? Math. So many amazing people that over the last three to three years or so I've actually had the opportunity to meet quite a few people in chat at various cyber security conferences, namely Wild West Hack and Fest in Deadwood, South Dakota and then last year simply Cybercon in South Carolina. Another life changing con that if you get the chance to whether you got to drive, beg, borrow or steal, make sure you get out to South Carolina. It's going to be epic this year for simply Cybercon. Come hang out with us. Random skills. What are the rules for the hotline? Well, in all seriousness, the rules are just put the a Q, a question in there with a question mark with the letter Q and hopefully I'll see it or somebody. If there's a mod that is actively working the chat could put the question that's to do with your cybersecurity career. So I'm a probably a mid level mid to later it and early mid career cybersecurity professional on my journey working, helping build up a vulnerability and threat exposure program with a company which has been absolutely epic. So drop your questions in. Chat about your journey. Breaking in. Maybe it's breaking, leveling up into another part of it or cybersecurity or if you're just not sure and you want to jawjack. You want to talk music, concerts, cons, that's what we're here for. Ask me anything. Let's talk cyber security. Let's talk life. Let's talk football, basketball. Nuggets are in the Western Conference playoffs. It'll be epic. All right, let's go and get in some questions before I get sidetracked and find myself sounding more like a sports radio person versus a cyber career person. Let's get some music rolling too, ladies and gentlemen. Let's go. Let me know if it's too loud how we do. Hey Jesse, do you remember when you hit that deer? I do remember when I hit a deer. About three years ago Wild West Hack and Fest. I was taking Dr. Jerry Ozier back to the airport and on the way back I looked up from the clock to see how much time I had to get my other friends to the airport. And as I looked up in my headlights was a massive buck standing there. And I hit it at about 60 miles an hour, totaled the car and the entire cyber security cyber security community was able to rally around casually Joseph and Dr. Jerry and they put together, you know, a couple thousand dollars which paid for a rental. It was quite the ordeal. Ended up being safe. But yeah total the total the car and kill the deer. Coming back from Wild West Attack and Fest I see some Nuggets love Warriors, some Pistons love when it comes to NFL I am football fan. This is where we ask career questions. KT shoots. KT shoots. This is where we ask career questions about breaking in, leveling up maybe some resume ideas approaches to getting experience. Dr. Jerry would say I'm an example of a person who really kind of hacked my way through the hiring process and found myself in a in a really good position to work in the cybersecurity industry in somewhat of a non traditional way. And my goal was always to provide insight and conversations and considerations around other people breaking into the IT field inspired by folks like Zach Hill. Dr. Jerry. Not loud Jeep. Do you prefer resumes with design and character or simple and boring? Do you think we will ever get away from the current ATS systems that auto filter people with talent? So I've sat with a few hiring managers over the last few years as and we'll actually he'll they'll say can you come go look through resumes with me. The more decorated, at least here in the States, from what I've seen, the more decorated and fancy a resume is, the quicker I've seen a hiring manager close it. So they get pre filtered. And the reason they get pre filtered and I don't think we'll ever get away from that and the reason is, is because there is such an influx, there's a pool of candidates to get one or two positions that you would be spending inordinate amounts of time and resources in personnel for a human being to filter all of those resumes. And considering that a good majority of those resumes probably won't make it to the next phase in the hiring process, to pay that kind of resource for somebody just to, you know, stamp, not accept it and put it into another bin is a waste of time and productivity, right? And at the end of the day, when we look at business decisions, cyber security, posturing, when it comes to our information security, whatever it is, it always comes down to that business bottom line, how is it going to impact the business, how's it going to impact paychecks at the end of the day? And so we will probably never get away from the pre screening of resumes. And one of the reasons I like to keep it simple is because I want to convey maximum value the person. The resume is nothing more than a pro. It's an interest profile match, right? Hey, I'm looking for this person to come work in my life, right? My life being this job. And I'm looking for these set of skills, credentials and things that I like to see in an employee. Here's a list of suitors that I'm going to bring into my life, right? And so you're just trying to see if you're a good fit after that, after the resume gets through you to that initial interview, right? This is where the resume really doesn't matter anymore. And it's more of just talking points. This is where you have to be you. This is where the conversations and being able to speak. 2 Real world cyber incidents that maybe you just see at the Dallas Saber Threat brief, maybe they're incidents you've seen in other fields or it's in your home labbing in your experience. And so believe it or not, the ATS systems that I've seen in sometimes won't filter necessarily. So a lot of these resumes will get humanized on them, then they'll be run through a filter. A lot of times they're not the format, if it's A little off. We're still looking for a fit in keywords but just putting a bunch of keywords into your resume and setting and hoping that works for most people doesn't work. I've really found that having that networking connection before the resume even hits the desk or hits the computer, whatever the inbox, having that connection helps a ton. Silver Cipher I just got my first entry level IT position. I'm excited to start my career. I'm starting at the bottom at a tier one help desk but happy to have my foot in the door. I think that question mark supposed to be an exclamation point and that is epic. Congrats on the new role Berg ssj. I just got my SEC plus. Congrats on the SEC plus. I'm trying to get a part time help desk or a similar type job transitioning from insurance into it. I want to get into cyber security. What shirts should I focus on next? That's a great question Berg ssj. I would not focus on certs. I would focus on getting any and all hands on practical experience and build your professional relationship professional relational network. Build it up and make it as well rounded as possible and at the same time get as much hands on experience and you go well how do you do that? Well that's simple. Maybe you think you want to be a penetration tester. Well check out the hack smarter labs presented by Tyler Ransby and Kairosec.
A
Right.
B
Maybe it's just general it. Well check out IT career questions with Zach Hill and you can go back and look through his videos on breaking into just the IT industry and and building computers and fixing and the tech support system side of things. Show up to the daily cyber threat brief every single every single Monday through Friday at 8am and understand how the real world works. Right. So I would not get any more certifications and I would focus on getting hands on experience and building out your relational profile so that when it is time you've got people and connections healthy, strong connections within the environment. Hey Ellipsis question. We are building an internal Red team as our next step in building our vulnerability management program. How would you go about knowing the team? How would you go about knowing it? About it? Knowing the team? So basically how would I know about. Okay, so the question I understand coming from Ellipsis is they're building an internal red team for the vulnerability management program. How can we actually vet some of the candidates that are coming in for the offset red team if they're inexperienced? What is you think you probably get that within the Scoping conversations. I would be having conversations with the director of those red teams and just being completely honest. I think that's a great question. What do we think, fellow red teamers in chat, Tyler or anybody else's professional red team, or how, how would you go about vetting that kind of experience? I've never been at the top level where I'm having to vet a oncome and onboarding red team into my environment. When I work alongside other red teams, I assume that we're all hired in at a certain experience level and we're all experts to a certain level in our own field. And so I personally don't question it and I trust the process unless there's a reason to not trust it. That's because I've. I mean, I'm a gear in the cog, right in the giant machine. Face. Doyle Policing to Sock I was in law enforcement for a short time myself working on the street and then before that I worked in juvenile corrections. So good on you, man. Thanks for your service. Policing to sock got certs learning splunk, but it feels like playing with an abacus while AI takes over. How do you stay stay motivated? Oh, that's a great question. I don't stay motivated. There are days where I'm completely unmotivated. There are days where I want to don't want to do cyber security or vulnerability management or have to stay up to date with the latest and the greatest exploit or I don't want to build out my network or have a conversation. Motivation comes and goes. That's just a fact of life. Sometimes you're motivated to work out, sometimes you're not. I would find discipline right within that discipline comes freedom. So get into being the CEO of yourself and understand that everything you're doing towards your career should be something to put into your tool belt and add value to either the current employer or a possible future employer. That's what keeps you motivated. Understand that you have to work with artificial intelligence. Work with generative AI, agentic AI, understand how to use it for you as a force multiplier. Have those conversations with the people that you want to work with. So motivation comes and goes. You got to find your why. If your why is I want to make six figures in, in in 90 days, that's cool. I respect that hustle. But that might not be. That might not be a result. You might not get that. So what is your why? Your why needs to keep you motivating. Your why right should be the biggest component of your motivation. And understand that motivation comes in, ebbs and flows. Sometimes you're super stoked, sometimes you're not. But the discipline and understanding, the end goal of whatever it is that is, that has to be your motivation. Without that, the motivation is going to go, you're going to tank and you're going to say up. I give up. It's too hard to break in, it's too hard to level up. I'm done. Stay disciplined. Just like you did in law enforcement, just like it is in the academy. Just like you did when it came to having your OODA loop, having an OODA loop in the hiring markets. The same thing having your OODA loop in resume building with anything. And for some of you that are new to that Ackerman, observe right your circumstances. Orient yourself, right? OODA O O D A decide, observe, orient, decide and then act. Right now I'm going to act. I'm going to make these next steps. I observe the landscape. Okay. AI is really taking over. We're starting to see people pull back a little bit. How can I continue to level up? Fundamentals are still fundamentals. Understanding tc, understanding TCIP networking and understanding the fundamentals of how computers work still hasn't changed. So you still need to get those fundamentals under your belt. Being able to communicate technical concepts to a non technical person person or in a boardroom or an executive level or have hard conversations. Those things don't go away. Your soft skills don't go away that are needed. So continue to refine those, those hard technical skills. Refine your soft skills and, and understand the why you're getting in at the end of the day and let that be your motivation. I don't know if that's encouraging or discouraging. I hope it brings encouragement to somebody who's, who's kind of waning. I mean their motivation is, isn't where they wanted it to be. Legrat just realized that today's 114th anniversary of the Titanic hit an iceberg. Yeah, tomorrow's my birthday. So the Titanic technically sunk on April 15. My birthday is tomorrow. I am 45 years young and loving every minute of it. Follow up question from ellipsis 4 members already selected but none have OPSEC Red Team experience. Reviewing some auto tools. But they can't replace true red teaming.
A
No.
B
For me, if I knew that coming in and I'm not don't want to give professional advice. This is just like a legal disclaimer. I would want to put a pause on that personally. But then again, I don't know the big Picture of what the. What the entire end goal of the operation is. I've learned within careers that the initial question you're presented there's usually a layers to it. So I'm not 100 sure on your organization, the infrastructure and your end goal, but that is something you may want to put a pause on. Just as a consideration is the level of experience. Right. You want some, you don't want your heart surgeon, a group of heart doctors that you're doing open heart surgery to have no experience and only use the auto tools. Thank you for the birthday wishes. For the AI bit space tacos. Hello friend, good to see you. Is it, isn't it a good motivator to. To become an effective prompt master? Absolutely, absolutely. And understand at least for me, using AI as a force multiplier, already having an idea, already having the ability to critically think, analyze, communicate, but then just saying how can we make it even 2x right? 3x so prompt master getting the right information. I think it was Einstein that said this. You don't have to know everything but man knowing where to find that information or how to get the information that is crucial. So if you can understand how to get the information. Build a hands on lab. Yep, build a hands on lab. And there's multiple ways to do that. Now you can spin it up on your own machine in a virtualized environment, something like use Proxmox or you could use. Any hypervisor virtualization tool. You can spin it up that way you can spin up a lab in the cloud using AWS or Azure resources. And at the same time maybe you could learn infrastructure as code. You know if that's using a chatbot to help you develop and lay out an entire, you could put a small network, maybe invest in yourself, say, you know what, instead of, instead of buying this coffee, instead of buying whatever thing I don't need, I'm going to invest in three months of cloud space, cloud resources. I'm going to put money into myself and I'm going to spin up a small network using infrastructure as code and I'm going to open part of it to the Internet, the public facing Internet. I'm going to build up an open source free SIM of some kind. Maybe I'll even do some source, some automation and I'm going to pen test myself and I'm going to let this run for three months and at the end of the day I'm going to put together a report, I'm going to put together a CC report, a pen test report, maybe a vulnerability Manager report. And this is just to gain a holistic idea of how cybersecurity works. Right. You're understanding the flow of traffic and at the end of that three months you're going to build up an environment. You're going to have seen real world attacks, you're going to have done the research, The Google, the YouTubing and understanding how to triage mitigate, how to isolate, how to contain your environment. You're going to understand how to have conversations. Then you're going to do the reporting side. Maybe you're going to use a chatbot or LLM or some kind of agentic AI to help you with your report and then you're going to start building this repository of experience for yourself, being the CEO of you. So now you've got a full automated network that you invested in yourself and there you can, you can spin it down at some point, but now you have this experience of understanding not just the beginning, the ones and the zeros, but then putting a report together that's executive facing so that you can take real world business impact implications. It's kind of the same word. You can take real world business impact into your interviews. Oh I think getting the hands on experience on your own if you can't get get the get the job is is so important. Random skill says what do I think of using Docker to build out your environment and use it for all? Absolutely. Oh dude. Using Docker Kubernetes cluster you Understanding containerization, understanding it at scale. There's one thing in understanding it in your own house or at a fundamental level. Now let's try and scale that up. What do large scale IT infrastructures look like? What is that? Zero Trust Architecture. Right. Dr. Jerry Ozer said it best. Hackers aren't hacking in, dropping exploits. They're walking in the front door, they're logging in. We're now seeing as identity is that big is that piece right? That's our new perimeter is the identity. And so understanding identity and access management, zero trust architectures, all those key words but at the end of the day it's still the human, it's still the human element. Three things we can, we can hack, right? People, processes and technologies. That has not changed since the dawn of time. Those are the three things that a threat actor can hack. And that's basically it. As a person, the process is involved or technology. And so that hasn't changed. Joey karen I spent 9 years in it got sec plus size of plus cissp have done try hack me and home labs. I'VE tried breaking into cyber security for a few years now. Any advice how to finally just get that job? I hear that from folks. And my suggestion would be is to if you can't afford it, is to continue to be patient with yourself, stay flexible and try and find find ways to make yourself invaluable to a company. Well that's kind of, it's kind of vague and stupid. Think of ways things that are going on within our environment. Think of ways that you can make yourself invaluable to a company. Maybe it's your soft skills, maybe it's the way you do something different than somebody else. You have to find something that makes you stand out. That might require some soul searching and feel free to reach out to me if you want to like go back and forth on ideas. Same thing with I think it was Doyle face law enforcement. If you want to talk about going from law enforcement enforcement into cyber happy to chat those things. I wasn't a cop for super long but that's what my major is in. So question probably our last one. After earning my Comptia trifecta what are some budget red blue team certifications? I would recommend I'm disenfranchised with OSCP and sans. Well I understand being disenfranchised. Okay, I do understand that. So if you're completely disenfranchised and I like the guitar on your avatar. Let's a Martin looks like a Martin guitar player. So I, I, I too can be disenfranchised with CompTIA OSCP. At the end of the day you got to play the game sometimes, right? And so you got your comptia. Get your foot in the door. Look at maybe the TCM security, the practical penetration tester cert. We're seeing more and more of that on job requirements. Look at Hack Smarter labs for blue team certifications. Hands on blue team skills certification. You can look at the anti siphon training. They've got a sock skills course that comes with a certificate of completion. That's a real world and a big name in the industry also. What was the other one? Blue team blue team BTL blue team 1, blue team level 1, BTL 1, BTL 1 and BTL 2. Those are hands on blue team labs. They may not be widely recognized but they do provide some hands on experience. Oh that's a great they'll be the last comment and then I got to go because I do not want to miss Kathy Chambers. What's up Kathy, I love you. Can't wait to see you Just because the title does not say cyber or security in it doesn't mean it's not a security role. Don't let titles get your hand up. I don't have My boss said that my title could be literally whatever it wants. I don't actually have explicitly security or cyber mentioned in my title at all. And I work knee deep in cybersecurity, you know, eight to ten hours a day. Rock and roll. Thanks for dropping it in chat. Kimberly can fix it. Thanks for hanging out with me on this wonderful Tuesday. I hope you have an excellent, excellent, excellent, excellent day. I got a roll. I'm gonna drop some graphics. Let's get out of here. Jump over Kathy Chambers. Until next time, stay secure. Take care of each other.
A
Sam.
Host: Dr. Gerald Auger (Simply Cyber Media Group)
Theme: Fast-paced breakdown of the day’s top 8 cybersecurity stories with practical analysis for professionals—plus a follow-on Cyber Career Hotline Q&A with Jesse Johnson.
This episode delivers an energetic tour through April 14th’s most pressing cybersecurity news, connecting headlines to real-world impacts for practitioners. Dr. Gerald Auger brings sharp, witty commentary, consistently looping technical news back to actionable takeaways and broader career development advice. The latter part transitions to the “Cyber Career Hotline” hosted by Jesse Johnson, answering community questions on breaking into and advancing in cybersecurity.
| Time | Segment/Story | |-----------|----------------------------------------------------------| | 13:00 | Claude Mythos: AI offensive cyber capabilities surge | | 19:59 | Shiny Hunters breach via Anodot, supply chain risk | | 25:50 | WolfSSL flaw: Embedded IoT PKI vulnerability | | 33:39 | APT41’s undetectable Linux cloud backdoor | | 49:24 | FBI/Indonesia bust WELL phishing-as-a-service | | 53:18 | Microsoft 365 mailbox forwarding rule abuse | | 57:21 | Bain & Co breached via exposed credentials | | 60:30 | OpenAI macOS client update (npm supply chain attack) |
Tone: Friendly, practical, supportive, candid
Dr. Auger and Jesse Johnson together bring news analysis and career mentorship, making advanced cyber topics digestible, fun, and actionable. For both working professionals and those seeking to break into cyber, this episode offers real-world lessons, cautionary tales, and encouragement to stay current, stay disciplined, and above all, stay secure.
Links Mentioned:
Tip: Claim CPEs for attending, and get involved with the Simply Cyber community for daily news, engagement, and career support!