Loading summary
A
All right, what's up? Good morning everybody. Happy Friday. Today is Friday, April 24, 2026. This is episode 1118 of your Simply Cyber Daily Cyber Threat brief podcast. I'm Dr. Gerald OA, your host for the next hour, coming to you live from the Buffer Osier Flow Studios here in the Low Country. If you're looking to stay current on the top cyber news stories of the day while engaging with a like minded group of supportive, inclusive professionals that are happy that you're here. Well, you're in the right place, my friend. Get your coffee, get settled in because we got a great show for you. Let's get cooking. All right. I do want to say good morning to all of you. What's up? Reynard Waits, Christopher Lycia, Marlon J. Longtime familiar faces like Marcus Kyler, Code Brew Find the true Mike Andruzzi. If you attended the Cisco Protecting Modern Architectures a Lot Simply Cyber Firesides last night, I do want to extend a a sincere appreciation. I did give a shout out yesterday on the Daily Cyber Threat Brief or Cyber Career Hotline, asking if you had time to come on by. There was a great turnout, great questions, great engagement and from the bottom of my heart, I do appreciate those who attended in and more importantly, I hope you got value from it. Now let me tell you about this show. We're going to go through eight stories. There'll be some extra stuff thrown in there. I've got 20 plus years of experience and I like to educate and talk about cyber security. So my goal here is to go beyond those headlines and give you insights you wouldn't get in a textbook or classroom or anything. Just things that you would learn by being on the job. No reason not to have a shortcut or kind of mentoring at scale for you. So that's what we're going to do. Of the stories I got to tell you, I know zero of them. I've done zero research and prep on these stories. Do you know why? Nobody got time for that. That is correct. I don't have time for that. Plus, it's just disingenuous professionals. We don't go through the news twice. Once for our private pleasure and then once to like look like a big brain 4D chess player. To our friends and colleagues, we're just rough, rugged and raw here. We're authentic. On the stream. I do want to say what's up and good morning to the squad members as well as the MOD team. I see Jenny Housley DJ B in chat as always. Dan Reardon's here. Casually Joseph Justin Gold, Kimberly can fix it. Etc. If you are a squad member, if your name is Green on the stream, you have access to the squad emo tray. Do go in there and drop a little mod love for the mods. Just let them know. If you appreciate the mods, go in and use that mod emote. Let them know. Did we just become best friends? Yep. All right. Hey, Kai Cipher. Buying me a cup of coffee. Grande Americano. You better believe I'll go scoop that up. I actually drank a pot right before coming on stream. I don't even have a cup of coffee at my desk today, but I will take that. Thank you so much, Kai Cipher. Appreciate the support. Tom Lavin. We will talk when the Buffalo Sabers Bruins matchup is completed. Until then, you are my enemy. Guys, every single episode of the Daily Cyber Threat Brief is worth half a cp. The show's an hour long. A CPE is one CP per hour. But we have fun for half an hour as well as work for half an hour. It's called Work Life Balance and we're demonstrating it here on Simply Cyber. So if you'd like to get those CPEs like real K or excuse me, reek, L and 1592. William Bailey, brute7679. What knows what's going on? It's very easy. Say what's up in chat. Say what's up in chat. Grab a screenshot. You'll notice that the day's episode happens to say today's date. Top Cyber News 424. Or April 24. Also, it has the episode number 1118. You may never need the evidence. You may never be audited. But if you are, if you have all the screenshots, you'll be able to provide those. Plus, it's wicked easy to count how many CPEs you have because you just hit Control A on the screenshots and count how many files you have. Divide by two, because each one's half a CPE. Come on, guy named 303 Bruins all day, every day. Let's go. Love the Bruins. It's a good matchup too, man. It's a great. It's a great. NHL playoffs are like, unlike any other sport. It's so good. All right. If you're here for the first time, like Telephone Rock. What's up, dude? Space station. What's shaking, bacon? Let me tell you, if you're here for the first time, do me a favor. Solid. Say hello in chat. But drop a hashtag. First timer in chat. I'll go first Just to show you what it looks like. First timer, first timer in chat. If we see a first timer, everybody in the chat is going to run over and say hello, hello, welcome to the party, pal. It's not to scare you off, it's not to freak you out, it's not to push an introvert's buttons. It's just to let you know that this community, first of all is awesome. And second of all, everyone is welcome. If you have good intentions, you are welcome in this community. If you're maliciously intent, you can find yourself out. We're not into malicious intent people. We're not into people who are mean or soccer or not for the cause, you know what I'm saying? All right, what else we got guys? First. Oh, every day of the week has a special segment and Fridays. Hello James. We're cooking at 35000ft. This guy right here, dad joke extraordinaire, he provides me with some custom dad jokes. I don't review or read them in advance. I know that they're in my phone, but I haven't seen them. And we'll do some rib tickling at the mid roll. Yes, I will say if you are a first timer, let us say hashtag first timer. But if you are a good timer like Devin Grady, maybe drop a hashtag good timer in chat. I'm a good timer. I'm gonna drop a good timer myself in chat. All right guys. Every episode is not possible without the support of the stream sponsors. Do want to say thank you to them, starting with 4. Flare. Flare cyber threat intelligence platform is absolutely killing it. If you know, you know. But if you don't know, that's why I'm talking about them for a hot minute. Flare cyber threat intelligence platform, super powerful platform. They go on the dark web, they go into the cyber criminal telegram channels, they rub elbows with Phil, with, I guess with filth, right? With. With people who are stealing from other people, people who are infecting other organizations, people who are committing crime. They get all that data and then they bring it back and they make it in an easy to access platform. Kind of like, well, I don't want to lose my sponsorship with them, so I won't use that word. But. But basically an insulation to protect you from them. The cybercriminal underbelly. And what can you do with this platform? I don't know. You can see if users in your environment are compromised. You can see if passwords have been dumped, you can see if domains have been stood up that look like Your you could see Cyber Criminal telegram channels and they're planning. The power is unbelievable. And also really quick. I don't normally say this, but if you're an msp, this thing scales on value. Because now you can support all of your clients organizations through one portal, right? It's not like flare constrains you to just looking for stuff related to you. It's super powerful. Go to Simply Cyber IO Flare. Simply Whoops. Simply Cyber IO Flare. Now, because the platform is incredibly powerful, they do need to verify that you are a legitimate good person. Right? Not criminal, not criminally minded. Once they do that, you'll be approved for a two week free trial. Easiest. Easiest two week trial ever. It's such a powerful platform. I've used it. I love it. Just to let you know, it's super good. Go to Simply Cyber IO Flare. Find out more. Let's talk about Anti Siphon training. Anti Siphon training is disrupting the traditional cyber security training industry. High quality, cutting edge education to everyone. If you are looking to get cyber security training in a great, easily affordable way, check out Anti Siphone training dot com. Super easy. Put it in chat and if you have trouble, remember Anti Siphon. Just remember it's basically a synonym for doesn't suck. Anti. A siphon sucks, right? They are Anti Siphon. They do not suck. Okay, so check it out. Next Wednesday at noon they have a free webcast one hour where you can sit with Natalie Salman and learn about how to avoid burnout. Guys, burnout is a real thing as much as imposter syndrome is a thing in our industry. Burnout is a real thing too. Figure out how to navigate that. Break free of it. Natalie's going to show you how. Plus lots of Simply Cyber Community members join those streams so you can engage and chit chat with each other while it's happening. I'm going to drop a link in chat for that one. Thank you Anti Siphon for the continued support as always. Finally, let's hear from Threat Locker. Powerful enterprise security platform. Guys, if you want an easy button for protecting your organization from running malware, powershell scripts, downloading all sorts of nonsense things that you've never seen before, well, Threat Locker can protect you at the endpoint and now in the cloud. Quick word from Dart Locker and then I will be melting everyone's face. I want to give some love to the daily Cyber Threat brief sponsor, Threat Locker. Do zero day exploits and supply chain attacks. Keep you up at night. Worry no more. You can harden your security with Threat Locker worldwide. Companies like JetBlue Blue Trust threat Locker to secure their data and keep their business operations flying high. Threat Locker takes a deny by default approach to cyber security and provides a full audit of every action allowed or blocked for risk management and compliance. Onboarding and operation is fully supported by their US based Cyber Hero support team. Get a free 30 day trial and learn more about how Threat Locker can help prevent ransomware and ensure compliance line. Visit threatlocker.com Daily Cyber. All right, all right, all right, guys, it's that time of the day. I need you all to do me a favor. I didn't see any first timers in chat, so this is going to sound familiar. What's up, Tasha? Tasha Miles in the chat. Good to see her. She was at the live stream last night. Appreciate that. All right, do me a favor, everyone. I need you. It is Friday, guys. We are sliding into the weekend. It's like our senior year. May. Senior year of high school. You're just like, oh, my God, I'm done with this. We got a little bit more of a push, guys. So do me a favor, Sit back, relax, and just let the cool sounds of the hot news wash over all of us in an awesome wave. I will take the helm. You just relax on the starboard side. Let the wind pass through your hair. Look out over the bay and I will navigate us into open water. Let's cook, everyone. This is going to be fun.
B
From the CISO series, it's cyber security headlines.
C
These are the cyber security headlines for Friday, April 24, 2026.
A
Steve.
C
I'm Steve Prentiss. Cosmetics giant Rituals discloses data breach. The company, based in the Netherlands, said attackers stole personal information of an undisclosed number of customers from its My Rituals membership database during a breach that was discovered earlier this month. No passwords or payment information was accessed. Company representatives stated, though the company did not say how many members of its loyalty program had been affected. There are 41 million members connected to it worldwide. No details about the nature of the cyber attack or the group responsible have yet been released.
A
All right. Hey, really quickly. Robert Trotter with five gifted subs. Did we just become best friends? Yep. Thank you, Robert Trotter. Excuse me. Jesus. All right. Yeah. Gifted subs. Thank you very much. If you are one of the recipients of the gifted sub, do check out that emo tray. You'll notice a bunch of fun emotes have just unlocked. All right, so cosmetic company gets data breached. The. The thing here is it's like less about the cosmetics company and more about these customer value programs. Basically every business does. This started with grocery stores, I feel like a million years ago. And now it's like, oh my God, this data is super valuable. So it's no different than your, your grocery store thing, your, your, you know, delta frequent flyer miles thing. Like they, you know, basically it's, it's rich data on you and how can we market you? So someone hacked into them, got that member's data. Let's figure out what kind of information was stolen so then we can figure out what the impact is. Again with risk analysis, GRC people, that's what we do. The question is first, like, what happened? So we can understand, you know, how to prevent it. But secondly, like, let's deal with the actual, like, basically, you know, the office scene where the guy. I was never a huge person into the office, I'll admit. But like, you know, the scene where the guy's got the chili and then he dumps it. Right? Like we've, this is an example of like dumped chili. When you have an incident, a true incident, and there's a data leak or whatever that is the chili on the floor. Yes. You can put in place prevention to stop it from happening next time. Like in the chili example, like putting a lid on that clamp shut. Right. For example, like the way crock pots do it. But that, that doesn't change the chili on the floor. Right. So we have to look at it. Did the chili get on just wood? Did the chili get on a carpet? Did it go under a desk? Did it fall down and go into a drawer? We've got to do the impact, the blast radius, the analysis. Okay, so that's, that's kind of an analogy for all you. Thank you, Justin Gold. Here we go. For all you office people. We're going to go ahead and show it on the stream. This is what I'm talking about. This is a cyber incident right here. And now you're like, all right, like, all right, how bad is it? Like, how much chili got everywhere? Let's go ahead and analyze it. So in this instance, they got name, email, phone number, date, date of birth, gender, home address. Now they say payment and payment information and passwords were not accessed. Okay? Like it's 2026, dude. I feel like most data breaches, unless you like stink at architecture passwords and payment information typically isn't accessed and shout out to the payment card industry, by the way, for PCI DSS as a regulation, because a lot of businesses do have their payment card information segmented off on a smaller segment or they Outsource it. So full name, email, phone number, date of birth, gender, home address. So what, what, what is bad about this? Well, number one, remember Rituals, the cosmetic company like this, this is bad PR for them. But this does not affect their ability to sell cosmetic products. Right. Like you may have noticed that this didn't impact operations, this doesn't impact retail chain. Their employees can show up tomorrow and punch in payroll is going to run. This has no, this has no impact on to the business operations of this company. Now if you are a shopper or whatever, a consumer of Rituals, maybe now you're going to be looking at Sephora or Ulta. And yes, I know way more about makeup and women's cosmetics than you would think. I do. Not because I wear it, but because I'm married and I have done extensive research on this topic. So, so I can be pretty informed on what products to get when I do, you know, get product for my wife. All right, Little less often now, but ladies, the tarte palette. Am I right? You know what I'm talking about. And by the way, like Korean based moisturizers, Chef's kiss. Okay, so full name, email, phone number. This can result in social engineering attacks, right? We can expect some increase in activity. You could even see really targeted attacks of, hey, this is Bob from Rituals. You know, you've been involved in this data breach. Let me get it, get after you. Also, you know, identity theft, which we see a little less of nowadays. But unfortunately this information can allow a threat actor to appear to be legitimate. So like again, like really quick imagine if you will, I steal this information, then I do some basic OSINT to find, you know, a chief marketing officer at a company that, you know, like, like a Fortune 50 company or something who happens to shop at Rituals. Well then I can call them or email them and send them a targeted spearfishing email. Or I can call them and say, hey, this is Tony from it. We're seeing some issues on your stuff. I just want to confirm that you know your, your home address. Is this your date of birth? Is this like, like I can give you validation information that I've stolen to make it appear that I am a legit person. Right? Yep. Hey, there is no, by the way, just in full disclosure, there is no shame in the skincare game. I will tell you, I don't wear makeup, right? Like, like eyeshadow or the other things foundation, I suppose. But I do put, I do wear moisturizer. I, or I put moisturizer on my wife gets after me about not Putting on the moisturizer that has spf, because I run outside almost exclusively. But guys, when you, when you haven't take. Listen really quick. This is a PSA for everybody out there. Don't be shy about putting moisturizer on your face. This right here, I have not taken care of this situation my entire life. So, like, we're working from like a negative perspective. If I didn't put moisturizer on, I would absolutely look like a Spalding major league baseball catcher's mitt that's like in the seventh inning. Really, really busted up in here. So if anything, moisturizer is a cheat code. Don't. Don't sweat that. But yeah, the Korean based stuff is where it's at. Okay, so anyways, guys, if you suffer a data breach, Daniel Lowry's in the chat. Everybody be cool. Listen, when I did the show on mtv, I did have to go to makeup and they did have to put makeup on me. So I guess I have worn makeup in the past, but that was a special situation. If you are an organization that captures any customer information, which many do, not only should you protect it to the best you can, but assume a third party breach will result in this data getting out, you should put this as one of your tabletop exercises. For sure. Ransomware should be like your first tabletop exercise, but use this one right here where your customer's information gets taken as the tabletop exercise scenario for your leadership team. Okay, let's go.
C
Apple fixes iOS flaw exploited by the FBI. Apple has released an urgent iOS update to fix a security flaw that was reportedly used by the FBI to recover deleted messages. The issue was not in the apps, like signal itself, but in the iPhone's notification system, which stored message previews even after messages were deleted or even if the app was removed. Investigators were able to access these remnants through the device's internal database. Apple has patched the vulnerability in its latest updates to prevent this kind of data recovery from happening again. The case highlights how system level data can persist beyond user expectations or raising ongoing concerns about privacy encryption and how deleted data is actually handled on modern devices.
A
All right, so number one, if you didn't know, if you haven't been paying attention, Apple. First of all, Apple identifies as a hardware company, not a software company. Okay, if you didn't know that, number two, Apple and the FBI have been having this, like, little. I don't even want to call it like a, a, a spat, but like, Apple and the FBI have been kind of going after it for a few years. And some of the topics are quite serious, right? San Bernardino shooter and the FBI wanting like a magic back door put on all iPhone devices and Apple going all the way to the Supreme Court to not allow that. Hold on one second. I feel like, hold on, like this is you. You choose who's Apple and who's the FBI. But I feel like this, this meme captures it right here. For those who are listening on audio only. It's the woman being held back by her friend pointing at the cat at the table. This is like this is FBI and this is Apple the cat, right? So FBI has this basically zero day that they are able to exploit in order to get on a phone. Now Signal as a messaging app is secure and it, you know, it thwarts law enforcement because it allows criminals to communicate securely. Now, not all people using Signal are criminals. I use Signal. Investigative journalists use Signal. I mean we just saw. Not to get political. So this is just an observation of a fact, not really rendering an opinion. We just saw an instance where the FBI investigated a, I think it was the Wall Street Journal or the washing New York Times or whatever, a journalist, because the journalist was investigating the FBI's use of resources for the FBI director's girlfriend who is not a government employee. Right? So, so there are use cases where Signal is, is fine. And by the way, just like we're entitled to privacy, just because you like are a citizen doesn't mean that all your privacy goes out the window for, you know, for, you know, that's what Big Brother is. That's the premise of 1984. You've gone all the way out where there is no privacy. So Apple goes ahead and fixes this patch. If you are just following best practices from a vulnerability management perspective, go ahead and upgrade to 2642 or higher. This will check this out. Now, as I mentioned, Signal is a secure app, but the way that the app works, it is an app stored on your phone. And apparently if you delete Signal messages, there is residual artifacts saved on the phone in a area that is not compartmentalized by Signal, that would allow a forensics investigator to pull that information or someone who's compromised the phone to get to that memory and pull it. Now, of course, if you're running a regular iPhone and it does do data at rest encryption, as long as you are have it locked. So I don't know exactly. This vulnerability is not trivial. Like you either have to exploit the phone using some type of zero day or you have to physically get the phone, unlock it, and then Be able to do stuff. But I gotta tell you, law enforcement, when they arrest you or they detain you and they take your phone, they've got your phone, guys. And let me just remind everybody this is a fact. This is a fact that will not change ever in your cyber security career. So if you've been in cyber security for 30 years, you know this and you're like, oh, yeah, like, you're definitely, like nodding along, maybe feeling the vibes, right? And if today's your first day in cyber security, let this be a fact that you etch in stone is number one. Well, number two, the CIA triads number one. Let's be real. Oh, my God. I, I, I, I built that up so much that I forgot what my point was. Oh, oh, oh. The point is, if someone can get physical access, it bypasses lots of security controls. So you always have to protect physical access. That's why, you know, a threat actor getting into a data center is bad, or a threat actor getting into the office and being able to plug in physical hardware, letting your Zach Hills of the world dress up like AT&T workmen with a clipboard and, and go into spaces they're not allowed is a no, no. Naughty, naughty, naughty. So anyways, Apple fixed this. Way to go. Apple continue to support all the things, but be mindful, just because you're using Signal Signal secure, but the, the way that your messages could be saved are potentially problematic.
C
Hacker group impersonates IT Help Desk via Microsoft Teams deploy malware.
A
Oh my God. This was in the News yesterday named
C
UNC6692 has been using social engineering tactics via Microsoft Teams to deploy a custom malware suite on compromised hosts. Researchers from Mandiant said, quote, as with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT help desk employees convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The modus operandi of this group was to conduct a large email campaign designed to overwhelm a target's inbox with spam emails, creating a false sense of urgency and then approaching the target over Microsoft Teams by sending a message claiming to be from the IT support team to offer assistance with the email bombing problem. Borrowing heavily from Black Basta, this group has been using this technique to deploy tools from the snow malware ecosystem.
A
Oh, my God. Okay, hold on. So a couple things here. We got a couple things here. Okay, so again, guys, get your Kool Aid emotes ready. You know, they talk about Snow, they talk about Mr. Boo like they talk about Black Basta, right? So if you're listening on audio, I'm no showing a picture of Snow the rapper with that one hit wonder. Informer, right? Like just the informer. And then of course, what do we, what else we got? This story's just got tons of 90s references in it by. By accident. Okay, and here we go. Final, final one for you guys just to kind of complete the, the bingo card here. Black basta. Mr. Bone Bostic. Mr. Black Bostic. Guys, if you don't know these rappers, I'm sorry. That's fine. They're all one hit wonders. Guys, here's the deal. The reason I wanted to go a little extra on the jokes for that particular story is because last time I checked. Yep, hold on. Checks, notes. We covered this story at length yesterday, okay? So I'm not gonna rehash it. The TLDR is. This is a. This is an attack vector that is increasing in frequency right now. Educate your workforce, period, Full stop. It's very simple. If you are serious, if, if it doesn't matter, if you're getting a ton of text messages, ton of emails, your computer just explodes in front of you. If it reaches out to you unsolicited to offer you help, say thank you. But then call it, you can call it simply right, Just educate your end users. If it reaches out to you, tell them, thank you, I'm gonna call you right back and then hang up on them. It's a simple. This is how you detonate. This is how you nerf this entire attack sequence. All right? And they're just using Microsoft Teams right now. Tomorrow. It could be, you know, freaking telegram, or it could be WhatsApp, or could be an email or it could be a phone call. They are, it doesn't matter. The communication vehicle does not matter. The medium is irrelevant. They will reach out to you and pretend to be help desk to help you with a problem that they just caused that you don't know. They're the reason it happened. Period. Full stop. Do not fall for this. Thank you for coming to my TED Talk. Also, defense in depth, my guy. EDR solutions, End user awareness training. You know, like obviously network logs, because if they do compromise you, you're going to see traffic going out to C2ET, right? Hold on one second. Congrats, Alex. What did Alex do? Hold on. See, the thing is, I'm up here running the show, but like I'm part of the Simply Cyber community. I, I want to congratulate Alex, too. What did Alex do? I'm scram. I'm skimming chat right now. I don't see it. I want to be part of the team. All right, I. I'll look for Chad. I'm 20 seconds in the future, by the way. It's glorious out here. In the future. I'm like that Nicholas Cage character from that M.O. where he's like, in the future, kind of.
C
Some Microsoft Teams users blocked from meetings following Edge Update.
A
What?
C
Following up on a story we covered on Monday regarding.
A
All right, I'm glad they called out that they're following up on a story that we talked about on Monday, because I was about to lose my mind.
C
Right click paste problems. Another problem has now emerged from a recent Microsoft Edge browser update, this one featuring a bug that prevents Windows users from joining teams meetings. According to an incident report, this issue affects only users who try to join scheduled meetings or meetings via links. Microsoft has advised affected users to basically turn the team's client off and then back on again.
A
All right, so it's 2026. First of all, Alex got his CISSP. Hell yeah. I gotta tell you, of all the certs I ever got. Congratulations, Alex. Of all the certs I ever got, the CISSP was the one that, like, it didn't. I don't know if it necessarily had the biggest, like, career impact, but, like, for me personally and how I felt about myself and my legitimacy as a professional in the industry, the CISSP was like the, the, the bees knees for me. Listen, of all the certs I have, the CISSP is the only one I renew. Like, I've let my CESA and CSUM and all my other ones, my healthcare ones, my privacy ones, I've let those all expire because I don't need them in my career right now. But the cissp, even though I still don't need it, I. I renew it every year. I pay the 250 bucks, whatever it is, simply because of nostalgia. Like, it, it, it, like, I don't know. So, Alex, I'm super happy for you. I know how it feels to get that cert. Congratulations, my guy. All right, so check it out. Microsoft Teams is a problem if you use Edge. I think I found the root cause. The problem is you're using Edge. Oh, all right, so listen, this is a super minor thing. I, I wouldn't even call this a cyber security story. If you wanted to shoehorn it in, you could spray it down with WD40 and wedge it in there and say it's an availability attack. They said turn it off and on again. So someone get Justin Gold on the phone so he can power cycle your teams. News at 11. Like what? Whatever.
C
Huge thanks to our sponsor, Threat Locker. Threat Locker is extending Zero Trust beyond Endpoint control with their recent release of Zero Trust network access and Zero Trust cloud access. Access is limited to exactly what's needed. Learn more and start your free trial today@threatlocker.com CSO Sean Planky.
A
All right, all right, all right. Hey, holler at you guys. We're halfway through the show if you can believe it. I gotta. I don't know if it's because of me. I don't know if you guys feel the same way, but like, Daily Cyber Threat Brief is an hour. Simply Cyber Firesides is an hour. Guys, whenever I'm up here kicking it with you, man, time flies. It just. It's like the fastest hour in of the day. So, guys, hey, guess what? Thank you to the stream sponsors. Threat Locker Anti Siphon Flare. Love them. Remember, if you want to support the channel, the links are in the description below. Go ahead and click those links. Check out the show sponsors. It does go a long way. They do see the clicks and I, which I see the clicks, which. I mean, they see them. Which then leads to them wanting to continue to work with us. Every single day of the week has a special segment and Fridays is Dad Jokes of the Week. James from cricket at 35,000ft from apparent security brings the jokes to you. I don't read them in advance, so I'm about to give you the jokes. Is Alpha Sierra here? Oh, no, no, no. TJ's just missing her. Okay. All right, here we go. James McQuiggin at 35, 000ft, everybody. James McQuiggin is in the chat. He's at James McQuiggin. So if you have any opinions about these jokes, you can take them up with him. Ready? Here we go. All right, here are the dad jokes. Why is a sword never obsolete? All right, guys, this is a great point. AI is displacing a lot of people's jobs. You may want to look into swords. Do you know why swords will never be obsolete? Very simple. It's cutting edge technology. It is always cutting edge technology. All right, how much storage is needed for all the horror books in the world? Now, I'm a little scared about this one. If you don't know. I don't like horror. I don't like horror as a genre with the exception of World War Z. I love World War Z, but everything Else can go away. The horror ones scare me. I am actually going to go see the back rooms movie with my 14 year old, which I'm already terrified about, but I'm willing to do it because I'm an awesome dad. How much storage is needed for all the horror books in the world? Very simple. All you need is a terrorist bite. A terror bite. Oh, my God. And why was the computer overweight? Listen, CRT monitors used to weigh 40, 50 pounds. We got into LED screens which are lighter. But did you know computers are becoming overweight? It's very easy nowadays with SaaS apps. They're getting. They're just eating too many cookies. Too many cookies. Oh, my. There we go. There we go. Want to say thank you to James McQuiggin. At 35, 000ft, the jokes never cease to amaze and impress. Love what he's doing. Let's do the La Las together. This is a Friday vibe. If you're wondering what Friday vibes feel like, close your eyes, pretend you're Jon Hamm in the club, and just let this wash over you in an awesome way.
B
Will you come.
A
La. All right, all right. Feels good, doesn't it? Let's get back to work, y'. All.
C
Don Planky withdraws from consideration for CESA Director position. According to sources, Planky has withdrawn from consideration after his nomination stalled for more than a year in the Senate. Thirteen months passed without any clear approval from the Senate. And among the troubles that plagued Planki during this period was the announcement from Senator Ron Wyden of Oregon, who said he would block a vote to confirm planky due to CISA's refusal to publicly release an unclassified report on cyber weaknesses in the US Telecom industry. End quote. CISA is currently being run by Acting Director Nick Anderson, and it is unclear who the current administration will now nominate to lead the agency going forward.
A
All right, all right. U.S. federal government's in disarray. The guy who was going to run CESA as the Director withdraws his nomination. Obviously the heat is too hot. And you know this guy, like, whatever, like, shout out to Ron Wyden. That guy's like a people's champion. He said he would block a vote. I guess he's got the votes and the power to block it very, very. I mean, dude, I can't remember ever seeing a appointed position like Supreme Court appointee or, you know, cabinet member ever being blocked. Like, they, they, they show all of the gross, like, history and bad choice. Like all, like all the skeletons come out of the closet. And then you get like the little video shorts where you got some, you know, senator just absolutely lighting up the candidate, embarrassing the crap out of him, and then the person still gets the job as a Supreme Court justice or, you know, insert whatever cabinet member here. So the fact that this dude withdrew himself is wild. I mean, at this level, man, the. The public scrutiny is serious. Ceases in disarray. Honestly, again, from. From my perspective, apolitically speaking, as best I can, CIB reports under Department of Homeland Security. Okay. If you didn't know that it's a sub agency of Homeland Security, in my opinion, like the current federal executive branch, the administration that's running the country right now. Like, if you look at what DHS is responsible for, it's not like every pie slice of DHS's mission is the same size, like immigration, border ICE. That's like a huge pie slice. SISA has been getting punched in the throat like, you know, like they didn't. Like the acting director previously. Jen, she got, I mean, she left on her own because the, the tea leaves read it fine. But like CESA's getting its funding frozen and then budgets cut and everything. CESA is just like getting absolutely taken out to the woodshed. So the fact that their leadership is all jacked up, it's like, okay. And then on top of it, CESA's. Whoever the director of CESA would be, their boss, is in complete flux too, because Christy Gnome got fired or relieved of duty or whatever. However you want to spin it. For all of the shenanigans she was up to, by the way, like, she's. Last I checked, she was having like criminal charges brought up for her for like, like for that 200 million dollar commercial and the vendors who were involved in that, all that stuff. Anyways, it's a complete hot mess. Imagine if you will, you're trying to like hire for Director of Cyber, but like there's no ciso. Or you're hiding, trying to hide for ciso and there's no cio. If that's the org structure, it's just a hot mess express. So this is like whatever, someone will get the job, I guess, eventually, maybe. Maybe someone who can execute the role. Someone that isn't a kind of a political move and more of like all about delivering on CESA's mission. For. For you and I. For you and I. Okay. As practitioners, CESA is still doing the National Vulnerability Database. I mean, even though they're backlogged wicked high, CESA still got, you know, the known exploited vulnerability catalog Shields up, you know, information Sharing Analysis Center. So like CESA is still delivering value to us as individual practitioners. I think if you're a government, federal, state, local agency in any capacity, right? So say you're doing like water, wastewater, you work in critical infrastructure. I believe you can reach out to CISA to get like vulnerability analysis done on YouTube and incident response. Again, like in the state of South Carolina, if you get hit, you can call sled, the state law enforcement division, and they can come and investigate an incident for you. So there is, there is value that CESA still brings. They're not completely. The cupboards aren't bare at sisa, but this is just, this is an indication of bad leadership, in my opinion.
C
Medical data of 500.
A
One other thing, by the way, like, just. This is another like pro tip for everybody. Again, this, this is a tip that you will only learn after having career for like 10 more. 10 or more years. Okay. And I'm not trying to age people here. I'm not trying to be like, oh, like casually Joseph, you're only a young. You wouldn't understand this. Like, this is just something that you wouldn't learn. If you are interviewing for a company and they are having leadership challenges like this, that's a red flag, dude. You need a solid. You need a solid, like stalwart situation in leadership. If leadership is super in flux and there's people coming and going and people backing out at the last minute of roles, that's an indicator that there are cracks in the foundation. Now if you just need to pay the bills, go for it. But just be mindful, keep it. Keep, keep your resume up to date. DJ B coming off the top rope reminds us that DHS funding has not gone through. That's another like, political weapon that's being used. Dude. We, we. I'm gonna have to start my own. Me and Elliot Mati are gonna have to spin up another channel. I'm gonna have to put on a, you know, a mask or something. We can wear those like Point Break rubber president's masks and just start a political show because, gosh, so much going on.
C
Thousand British citizens for sale on Chinese website According to a spokesperson for the UK government speaking yesterday Thursday, the data was for sale on e commerce website Alibaba. The data belongs to the UK Biobank charity and includes genetic sequences, blood samples, medical scans and lifestyle information. In its legitimate usage, scientists working at universities or in the private sector can obtain access to this database for research purposes after signing security contracts. Science Minister Ian Murray told.
A
There's More to this, the House of
C
Commons that the listings were removed before any sales on the E commerce platform were made. Three research institutions have been identified as the source of the posting and their access to the data has been revoked. Murray Emph.
A
Oh my God. The story sized quote.
C
This was not a leak. This was a legitimate download by a legitimately accredited organization. End quote.
A
All right, so this is new. All right. A lot of times things that come through the news, they're just rehashes. It's like a new. It's a new rapper on an old attack. And not like Jay Z or Eminem or something like that. Like rapper, like gift wrapping. It's like new packaging, fresh coat of paint. But it's all the same. It's a. It's a phishing email or it's malware or whatever. This is interesting. This is a new one for me. So I go on Amazon and like, yes, two days ago I went on Amazon and bought a bunch of locks. Locks like padlocks. And then I brought them to the Citadel and I taught all my students how to pick locks. That was the final class of the year for them. So now they're all trained up on breaking out of handcuffs and picking padlocks. No big deal. I go on Amazon all the time. We bought a bird feeder the other day on Amazon. All right. Getting into bird watching. I'm officially that old where like, I'm like, yeah, bird watch. Like, I'm not even joking. Like I'm into it. Okay, Got some binoculars. Never have I seen data for sale. I've seen data for sale on dark web marketplaces. This is basically on Chinese Amazon. Alibaba, where you can buy half a million Brits medical data. This is. This is dystopian. This is entering a whole new level. And I'm not talking about where the rhythm is the base and the base is the treble. I'm talking about. Yikes. So data has value. Data is the new gold. I've been telling everybody that for years. Hope if you're listening, she made stickers two years ago for simply CyberCon 2024 outlining that data is the new gold. And the fact that Alibaba was selling this is kind of crazy. Now the question becomes, who owns this data, right? So if is this. Here's my thing, here's the question. I would say, right? This, this on its surface seems disgusting. Okay? But please allow me a moment for this. What if. You know, like, think about this for a second. I remember in college when I was a dumbass, When I was an idiot. Oh yeah, no, I know about the Merlin bird ID app. Oh yeah, if you know about the Merlin bird ID app, if you know, you know that is a legit app. I've got mine on. I actually got a, a bald eagle. We have, I went to Kaka Interpretive center down in the low country. Anyways, in college, credit card companies set up outside the student Union up at UMass Amherst and if you signed up for a credit card, they would give you a free shirt. I like a complete jack wagon. 18 year old Jerry didn't know anything about anything. I wanted that free shirt. So you know what I did? Yeah, let me sign up for a credit card. Ended up, I probably paid like 30 grand for that shirt at, you know, at the end of the day, like I probably paid that credit card off when I was like in my 30s. So, but, but the, but the question begs right, if someone sells, if, if you sign up for a service or you give permission or you sell access to your own personal data and that person owns it as an asset, can they sell it? Like again I'm not necessarily like, I think this is deplorable, but just thinking objectively about capitalism, if like, let's say I gave everybody in chat a dollar for your data, right? It's simple, doesn't cost you anything. You just hit copy paste and give it to me and I pay you a dollar. Now that is a transaction and I own, according to the contract, the legal rights to that data and I have the right to resell it, repurpose it. Right? If the contract said that. So if I put it on Amazon and sell it, is that illegal? I don't think it's illegal. I think this is a wild. This is wild. Okay? Now of course it seems dodgy because it's like British citizens being having their data sold in, in Chinese e commerce markets. You don't typically see this. You typically see this in like research in the United States. Hippo would have protected this. I don't even know if GDPR applies in the European Union because of Brexit. Roswell UK if you can let me know. But you know, the story here is this is kind of like a data breach. But to me the bigger story is about the legitimacy of selling this data legally or not. Hold on one second. It looks like our chat got jammed up. Let me, let me do this. There we go. All sorted out. Now it says that the data was de identified, meaning it didn't have name, address or NHS number. But when you have enough Information, gender, month, birth year, associated status. Like, you can actually do a lot of different things. Sometimes you don't. It doesn't matter that it's Sierra Montgomery's data. Sometimes it's just enough to know that it is a female between this age bracket in the Pacific Northwest who makes this amount of money, right? Like, it's like a profile, a Persona. Also, final thing I want to share with everybody. If you are a UK citizen, this. This should have some interest to you. If you are a business that sells data, this is actually maybe interesting to you as a cyber security professional. Like, I guess be mindful of contracts and where and like how your. The permissions around data. That's. That's from a GRC perspective. Let me just share this and then I'll move on from a G. By the way, shout out to the GRC Mafia. I'm wearing a GRC shirt today. When you are signing contracts with other businesses in a B2B deal and you're going to be giving them data, make sure that the contract. This seems like overkill. And people get all up in your shorts like, jesus, Jerry, you're slowing everything down. Why do you suck? And I'm like, well, you'll thank me later. So that's why I suck, Kevin. So check it out. Number one, make sure that you own the data. They don't use. They don't own the data. You're granting them rights to use the data for the explicit purpose of whatever their business is. They do not own that data, period. Number two, they will control who has access to that data. Number three, when you terminate the contract, they are legally obligated to delete that data or remove it. Number four, and this one's a big one. It. Upon request, you should be able to get that data back from them, right? Especially if they, like, enrich the data or something like that. Those things need to go in the contract. And again, people are like, oh, my God. I'm just trying to get to the value of this business. Like, get out of my way, Jerry. It's like, you know what? You're gonna thank me later. Announce a prevention, my guy. Because if you don't put those things in and then you terminate the contract, and a year from now, two years from now, they suffer a data breach. Oh, I. I don't want to say I told you so, but I'm sitting in the back sipping on like a coconut drink with an umbrella, giving you one of these eyes like, I'm the little boy in the school photo who looks like that's what's up. All right.
C
Another NPM supply chain worm leaves its mark. According to researchers at Socket and Step Security, a self propagating canister worm style malware strain hit multiple NPM packages tied to Namastex Labs, which is an agentic AI company. This worm appears to target specialized developer workflows rather than broad consumer NPM usage. It shares significant overlap with the open source infections attributed to team PCP last month following their trivy supply chain attack of March. Trigona.
A
All right, if you've been on the. Hold on. I'm sorry guys. If you've been on the fence about getting serious about third party supplied third party supply chain attacks of open source software platforms. Oh my God. Nope. Like, sorry, private DMS with Justin Gold just like ruined my entire day. Justin just like ruined me. If you've been on the fence about taking open source software supply chain attacks seriously, like allow this to be the tipping point. Allow this to be the reason that you're finally going to take it seriously. The Axios breach. I mean there's numerous ways to do it. They can, they can take over abandoned GitHub repos that are, you know, have authority and trust. They can do lookalike domains. They can just contribute source code to those successful projects and get it there. They could pay the developers off a whole bunch of different things. Okay, so another supply chain attack is in here. What do you need to do? So as a practitioner, this is more in the soc analyst swim lane. But what I would recommend is, what I would recommend is looking to see what packages are compromised and then figuring out if they are in your environment and see if they've been updated both on the open source side and then. And in your environment. All right, so it's a self propagating canister worm. Canister worm style. I've never, I've heard of worm style malware. I've never heard of canister worm. That's a new term for me. All right, so they're, they're targeting. So this is like spear fishing developer workflows. All right. All right. The compromised packages, this is step one is automatics. Genie. Automatics, genies, Fair words, websockets, Open web concepts. Okay. I don't know guys, if we have any CICD developers in the chat or people who work directly with the CICD people. I do want to, I'm talking to Tanya Jenka later today. I'll ask her as well. Is there a way to check at the level of packages to see what packages are being used inside your builds. If you can do that, if you can get some type of like software bill of materials or S bomb on the different packages in your builds, this would be good. Find out if you're using these ones. You could see basically many of these things have been fixed already, right? So this Automagic Genie 1, it's. If you're north of version 426042 1.39, you're all set. PG serve. If you're pass 113, you're all set. So anyways, all of these have been fixed. The problem is you have to apply those pit fixes and Phil Stafford is confirming that you can generate S bombs. So here's what I would say about this. Okay, this, this is, this is what I would say about this. These aren't, this isn't an isolated attack. With isolated attacks, you don't want to spend a ton of energy, time and social capital to invest in dealing with that particular problem. You just want to kind of like treat the problem and move on. But now that this is a consistent recurring attack, what I would recommend is getting with your development teams, right? Get, you know, and, and, and being like, guys, this is like a, this is an ongoing thing. Like today, last week it was Axios. Next, you know, this week it's PG Serve. Next week it's going to be whatever. Okay, so like, this is a recurring high likelihood attack vector. We need to put some processes in place for me to be able to quickly communicate with you that there's problems, to be able to quickly inventory and ascertain if we are affected by these attacks and if we are, how do we discover if compromise has happened? So this really is, in my opinion, a conversation and borderline, like a small project between GRC, SecOps and the development team. And everybody's going to be on the same page. Because what you're trying to not deal with is like an active compromise. You're trying to like, line things up. You don't have to make this like building, you know, a new bridge or something. Just, you know, get, get the conversations going, get things going at a minimum. You know, when something like this does drop, you can just quickly email all the relevant parties. Everybody's been kind of like briefed on, you know, like these attack vectors and what to do, and everybody can kind of take action on their own roles. All right?
C
Ransomware uses custom exfiltration tool to steal data. Researchers at cybersecurity company Symantec state the recently observed trigona ransomware attacks are using a Custom command line tool to steal data from compromised environments faster and more efficiently. These researchers say that the shift to a custom tool may indicate that the attacker is investing time and effort in proprietary malware in a bid to maintain a lower profile during a critical phase of their attacks. End quote. It was thought that Ukrainian cyber activists had disrupted the Trigona operation in October of 2023, but semantics report suggests that the threat actors resumed operations.
A
It's all right, I'm sorry. I've got something on my mind and it's like absolutely living rent free there. And I was. I found it very difficult to absorb anything from this story. So. Trigona ransomware Today is the first day I've heard of Trigona ransomware. Just be mindful, everybody, that there's new ransomwares all the time. So if it's a ransomware you haven't heard of, don't get sweaty that you're like behind the curve and you're like, oh my God. So let's see what they do. Custom command line tool. They're X filling data. Looks like this. Try going to. Ransomware is not about encrypting your data. It's just about stealing your stuff. Let's see. Good to see Symantec still there. I haven't heard semantics since like 1997. Actually, I shouldn't say that semantic was involved in the semantic. I'm almost positive semantics. The one who wrote the original research paper on Stuxnet. Their security researchers discovered it. All right, all right. So they're using a hard coded server address that's easy to block. I mean, IP addresses can be changed, domain names can be changed, but if it's hard coded into the malware payload, that's easy to block. Right? Let's see. Okay, so the ransomware launched in 2022. This is crazy. So Trigona ransomware has been around for four years and I just heard, become best friends. Yep. Oh, Chuck Sapp. Thanks, Chuck Sapp for the gift for the super chat. 10 bucks and he's saying. Because you're making me blush. Happy Friday, guys. Chuck Sapp's awesome. If you don't know Chuck Sapp, do say hi to him. He is wonderful, longtime Simply Cyber community member. He's. He's the newsletter. If you go to Simply Cyber, IO Newsletter. If you get that newsletter. Chuck is heavily involved in the operational delivery and build out of that. It's awesome. Let's see, where's the IOCs? My man. Okay, here we go. Symantec is listed in the IOC Is indicator of compromise. It's what you need to know so you can see if this is happening in your environment and block it. Can we get a link to the IOCs? This is annoying. I hate when articles do this. Semantic listed the IOCs. Here's no link to it. Is this it? Can we do this? All right, here we go. Iocs, mostly hashes. All right, hashes are okay, so there's hashes and then there's one IP address hard coded. If you're listening on audio, go threat hunting in your Environment for the IPv4 address 163-17-2105A2. It's communicating on port 1080 for exfil C2. Okay, as always guys, file signatures. Hashes are trivial to change. So these IOCs are kind of weak sauce, but whatever. Here's a link to the full story if you want to read it from Symantec. Also a great example of a security researcher blog post. All right, let's get to the good stuff. Excuse me. My goodness, guys. This has been simply Cybers Daily Cyber threat brief Friday, April 24, 2026 Episode 1118 if you got to get out of here, have a wonderful weekend. We'll miss you, but if you got a few minutes and you want to hang out, we got a 30 minute version of cyber Career Hotline. Phone lines are open and we are looking forward to answering your questions. Every Friday we try to get a panel together. We've got a couple regular panelists in the on the green room right now, so we're just gonna jump in there. I'm Jerry, your chat. Have a wonderful weekend. Until next time, stay secure. Gerald Osher, this is the Cyber Career Hotline. If you're building a career in cyber security, this show is for you. Let's get into it. All right everybody. Welcome to Cyber Career Hotline. I got a hard stop at 9:30, so let's get the panelists in here. If you had a comment about the jokes of the week today, you can take them up directly with this man. Ladies and gentlemen, James McQuicken at 35000ft. Hey James, how you doing? You are on mute. We got Robert Wetstein. Wetstein, Robert. Do I always say your name incorrectly?
D
I mean you got it right the second time. Wet. Stein.
A
So he's bow tie security. All about good times. As always, we've got a lot of experience and knowledge on the panel. If you've got questions, drop them in chat. James, just speak whenever you can and we'll confirm that you have audio. Let Me put up the little thing. What is Cyber Career Hotline? Very simple. It's a 30 minute AMA. We, this panel right here and all the panelists that always join love helping you, we love helping you level up as a practitioner, crush job interviews, not spend your money on things that don't have return on investment. So if you have a question, put it in chat with a Q in the front and we will answer them.
B
Shout out first of all to DreamLogic for the wonderful post the of us yesterday. Greatly appreciate that.
A
Yeah, Dream Logic did have a Wonderful post. Thanks. DreamLogic's always putting out great authentic content on LinkedIn. Now, James, there was a story here that I, I, I called you out on. I was like, oh, I wonder if James has a thought on this. Do you remember? Was that today? Oh my God, no.
B
You had the HDMI one yesterday about, you said it yesterday before I went on and then I had it all prepped and just got run away.
A
All right. Yeah.
B
But if there was one today, I've been back and forth. I, I didn't, I didn't hear one specifically.
A
No, no problem. My days run together. We got a question coming in from Elliot Matice. It's for James. Hold on. As soon as I scan to the bottom of this, it has to do with your shirt. And he wants to know if it's a Netscape shirt.
B
Hang on a second, let me back up.
A
I'll give you full screen here.
B
All right, so it's my new apparent security merch now that I've, now that I'm going full blown contractor consultant, working Visa vc. So. And all the other fun stuff. Yeah, so this is the.
A
There you go. He's doing his branding. He has frozen as well. There we are. Yeah, you froze. There we go, James. But you're good. All right, all right. So Mike Andruzzi says, fun question. Should we call Jerry GRC Godfather or GRC Capo? And how do we have a better, how do we have a better suggestion out there? GRC Mafia is like unabashedly celebrating that we are grc. People in the GRC have been swept in the corner far too long. It is our time to shine and we're doing it strong. So I you, I'll leave it to you guys to decide. Pathick says how to be a better practitioner. Are CTFs better? Is THM or platforms like that better? Trying to understand what's the most realistic approach to be a better Blue Team practitioner. Robert, drop some knowledge. Give us two things that he should be doing to optimize his blue team practitioner skill set.
D
Yeah, CTFs I think are good. They allow you to think outside the box. But if you're looking and chasing specifically a blue teaming type role, really understanding logging, understanding kind of deep network topology is going to be critical because pretty much any investigation or anytime you're building rules, you're going to need to understand those basic core functions. So I would start with some core network topology, network traverse knowledge, and then kind of move into doing CTFs too, just for fun, because it keeps your mind fresh and kind of keeps you elastic.
A
All right, Rogue Cyber is suggesting I could be the GRC consigliere. I. I like that. More of an advisor role. I like that. Real quick, I'll spend a hot second on this and then, James, I got a question coming your way. Reynard Wade says I mentioned Sam Altman a few times this week. Sam Altman's the CEO of Open AI. You can certainly Google this Reynard to get all the details, but there's been some allegations about him and some abuse with his sister at his hand. There has been insights of someone who was like trying to break into his house and a guy out of Texas and then the FBI kind of got involved. So there's a lot of non AI related things with Sam Altman that is getting a lot of press. So I just invite you to first of all, Google it and then second of all, check your sources. Make sure that you're reading legit information and not, you know, disinformation, misinformation. Right. Always check your sources. James, question coming in here from escol07. I love this question. This question's for everybody who can hear my voice right now. Esco07 wants to know, how do you leave a company professionally?
B
Get up on the desk, yell peace out, and then jump down and walk out the door. No, I'm kidding. Obviously I'm kidding. No, if you're going to leave professionally, hey, you know, that's exactly it. You do it professionally. You provide at least two weeks notice. You submit it in writing. Usually your exit letter is, you know, complimenting the time that you spent there. The management, your coworkers. You've been given another opportunity that is going to allow you to grow and, you know, and you exit professionally. It's. It's not. Yeah, ironically. Ironically, it wouldn't be anything, you know, they would have no qualms letting you go. So you've got to have no qualms being, you know, walking out the door as well.
A
Robert, you want to comment on this? This is a pretty serious. This is one thing that most people will probably only do a handful of times in their career.
B
Yep.
D
Yeah. I mean, be open and transparent and just be very cordial. Right. Don't like, try to burn bridges on your way out. I've seen employees do things like that where they like, kind of get their last word in. I'm like, what's the point of that? There's no value. I've seen that come back and burn people years later and it's just not worth it. So just like, like James said, keep it simple and just say, hey, thanks, thanks for the time. I appreciate everyone. I appreciate everything I've learned. Please keep in touch. Here's my personal email, my phone, you know, wishing you all the best.
B
Peace. Yep.
A
I agree with Kyle. Kyle too. Like, so what James and Robert are talking about is kind of like your behavior on the way out. Like, decorum. Another, like, great way to leave a very, you know, sweet taste in someone's mouth on the way out. You know, basically set the person who's replacing you up for success. I'm assuming you're not being fired. I'm assuming that you're moving on to another opportunity. And so, you know, hey, like, here's what I'm working on. Here is some key people that I've been talking to. If you, you know, two weeks, maybe say, hey, like, you know, boss, like, who's going to be immediately doing my work? Because I, I want to meet with them for an hour. And even if the person you meet with doesn't take it seriously, doesn't show up, doesn't do it, it doesn't matter because that's on them. You're doing all the things. And really by the time you're like two days out from like your last, like, let's say you, your last day is Friday. By the time you're reaching Thursday, like, you're pretty much just not doing any work. You're. You're available on demand. Right. And then you peace out. So that's, that's what I would say about that. I agree with Robert. Do not piss in anyone's cornflakes on the way out. It. It, you might feel great about it. It's a bad look also. And then James has one more thing. In my opinion. I do not ever disclose anything in the exit interview. That's a choice. But I don't. The HR is not there for me. So, James, go ahead. What do you got?
B
I was going to say sometimes when you do announce that you're Leaving that, don't be surprised. Depending on your role, especially in security, they will pack your bags and have you walk out the door that afternoon. Yeah, yeah. Once they know you're leaving, they want to lock everything down. They want to make sure you're not leaving with anything. And especially in our role in security even. And if you're going to a competitor, they lock you out immediately. So be thinking ahead. You know that when you give your notice that if there's anything you want that's not illegal to take, that you want to have that all prepped ahead
D
of time and don't tell them where you're going, that is none of their business. Right.
B
We'll find out,
D
but there's no reason to discuss it in advance.
A
Yep. Also, if you think you're, I mean, if you're working at a small mid sized business, chances are it's not going to be a thing. But if you have access to sensitive information, say you're working at like an AI tech startup or whatever, don't think you're clever by ex. Filling data and, and then waiting two weeks to give your notice. Because most businesses that know what they're doing will go back 90 days. And if you're, you know, like, if you're stealing data, they're gonna find out. Right. If they know what they're doing. All right, Cyber Seder. What? Oh my God. What the hell? I'm sorry, Like, Restream thinks they're so clever by like updating this platform and now right in the middle of your production. Seriously, it's like this interface is trash. Okay, so Cyber Seder, I, I do want to say, like I was immediately triggered, but in, in, in, in the, in the sense of like what an opportunity to educate. I'm going to take it this way. He wants to know, does GRC boil down to being organizational knowledge librarians? What's the true essence of grc? How could it evolve over time? I'll answer this very quickly and then I know both of these gentlemen next to me are, well, they have GRC roles. Right? So I mean we're, we're, we're more than one dimensional, one trick ponies. But let me tell you, from an organizational knowledge librarians POV partially, we know where documents and policy are. But, but for me, the number one thing that people pay me for from a GRC perspective is understanding how to spend money to reduce risk. Okay. Because think about this Cyber Seder. There are, let's say just to make the numbers work, a thousand risks that your organization is vulnerable to, right? Attack vectors all over the place. Attack surface users, you know, whatever. Like, you know, air conditioner blowing up your. Your, your server rack. Like not even a criminal. Right. Of the thousand risks, right? You could remove all of them, but it's going to cost $50 million. You're not getting $50 million. Okay, you're gonna get 500 grand. So now that you got 500 grand, where do you spend it? Where are you going to reduce risk? Where do you get the biggest return on investment? Where are risks that are really never going to be realized? Where are the ones that are red hot? That is what GRC does, and that's where the real value is. James, you got some thoughts on this one?
B
Yeah, what you said.
A
All right, Robert,
D
I would agree. You kind of nailed it, man.
B
I mean, GRC Godfather, I'm kissing the ring.
D
No, I mean grc. I. I think it's a bad rep of being kind of the ones that come in to kind of cause problems for anything better. But I don't see it that way. It's a. It's a validation of your controls and a validation of risk within the environment to say, where should we put our focus? I think it's invaluable to business.
A
Elliot, Matthias has a question. Robert, I'd like you to take this one since you're a bit of a tinkerer hacker. He's interviewing for a head of IT security role at a very stealth company. Okay. By the way, stealth is like so hot, right? Like so hot right now that Hansel. So hot right now. Stealth AI is so hot. But anyways, he can't find much intel on them, which makes a ton of sense. How would you approach asking good questions?
D
Yeah, it comes down to looking up the company. Like they'll. There'll be some sort of funding rounds that they went through. Get, get an idea of what those funding rounds look like, especially if they're a smaller or a new startup. That'll give you some indicators of who was part of those funding rounds. There's a lot of public information where people put out press releases, stuff like that. Use that intel to kind of further dig into the company a little bit more. Look at when they're established. Then you can kind of build an idea based on how much capital they raised in their series one, series two, on what you can do in that head of security role. And then specifically talk to them about what success looks like to them, as when they ask that kind of like, hey, any questions for us? Be like, yeah, what does Success look like for this role? Maybe. Why is this role being opened? Is it a backfill, is it a new role? And then really coming with a plan, ideally like a high level, like 30, 60, 90. Don't bring it out until they ask like, hey, if you got this role, what would you do? Be like, oh, that's great. I kind of built a deck for this. Let me show you my 30, 60, 90 plan. That will show that you're forward thinking and that kind of is the big difference. I'm happy to do a mock interview with you too if you want to hit me up on LinkedIn. Like I'll make some time and we can go through a mock interview.
A
Yeah, Elliot's totally worth it. Long time squad member and spoke at simply CyberCon 2025. James, you got anything
B
for that? No, I just, I defer to Robert's awesomeness. You know, if you can't find much about it, maybe just have a general set of questions that you normally ask
D
everybody to help you dig in too. Send me some info, I'll help you dig in and we'll pull some data.
A
Yeah, I mean I just like for my couple nickels of thought on this one, Elliot, like what's the long term play? Like is it to exit? Is it to 10x? Is it to what? Like what's the play? Because like you're basically talking about joining that journey if you can like, you know, I don't know how you would ask this question but like what is the founders like? Vibes. Right. Like you like you're going to be spending a lot of time, what's there for the interview?
D
Without question, it'll be a vibe check with the founder. No, no question there.
A
Yeah. And then also one other thing. Since it's head of security, what are the primary like so a lot of companies like this, they are just looking to get sock to because that's what they can use to sell their company and they're not really interested in all of the things to reduce cyber risk. We're moving fast and breaking things. Get out of my way, nerd. So just, just kind of if you can kind of like feel out like what's the priority of cybersecurity for this organization? Okay. Also how big is the organization? Right. More headcount, you know. Okay, continuing to look through chat here. Oh wait, hold on, let me move this, Elliot. Anyways, best wishes to you on the interview too. Dude.
B
I wish you the best check in cyberspace. Yes, hit me up on LinkedIn. All right, I started it One of the, his, his comment in there.
A
Oh, okay, no problem.
B
Doing a beast. Doing a Simply Cyber meetup at B Sides. Basically we're in T shirts.
A
Which B sides?
B
B sides Tampa coming up next month.
A
All right, you want to plug that then?
B
Well, so actually two events here in Central Florida. We got Hack SpaceCon second week and May 8th and 9th, and then the following week, May 16th. Besides Tampa, I'll be at both of those. Looking forward to both of those. If you're gonna be there, especially Simply Cyber folks, you're gonna be there. Let's, let's have a fun meetup. Let me know, hit me up and we'll get, we'll get FedEx, because I know FedEx is going and I know he's got a Simply Cyber flag. I don't know how he stole it from you, Jerry, but he's, he's got a flag.
A
It was, it was a transaction. There was a, there was an approved handoff. Sign the paperwork.
B
That's all good. He knows I'm giving them a hard time.
A
Some people dropping good questions in here for Elliot. Solid question. GRC Guardrail, what does that role mean to you? Consist of. That's another thing, right. Like they might have an idea of what IT security, head of IT Security does. That's different than what you do. Right. It could just be like, oh, you create user accounts. Right. I'm being playful, but it is what it is. All right, so we're caught up on chat right now. I. This is going to be a 9:30 end for, for these things. Just because there's a lot going on today. Open. Open forum. Robert. Any. Any, Any. So Robert does do a ton of mentoring in the community. Has there been any kind of like increasing themes that you've been seeing, Robert, from your mentors that, you know, obviously it's the question that a lot of people have that aren't at, that aren't asking them.
D
Yeah, I mean the biggest trend is I, I think the misconception of where cyber security is and kind of the, the amount of jobs that are open. So a lot of the conversations I have are around kind of setting expectations and explaining that it's going to be about a year or two slog to find an opportunity, you know, for your remote job, for an entry level role or even a senior level role are very hard to find. It's like winning the lottery. I think there's just so many people who are trying to kind of sell services that there's a lot of misconception around what the Actual environment is. So I try to break through that and to plug our talk that we're going to be having, which is exactly to kind of break through those myths with an actual hiring manager to talk about what it looks like kind of through that process. Jerry and I are going to be talking on fireside in I think a few days, some six days, something like that.
A
Is next week. Firesides?
D
Yeah, I think it is.
A
Oh, yeah. Okay, hold on. Let's plug that really quickly. Giddy up on this. Look at this, man. All right, hold on. I'm sharing my screen and we're going to do this. Look at this. So if you're curious, next Thursday at 4:30pm Eastern Time. Computer. There we go. Look at it. Robert's going to. Come on. We're going to be talking about the real truth. So we are going to pare back all the gloss, all the glitz, all the bubble gum wrapper and we're going to get into the real dirt on cyber hiring. And Robert does. He's an executive for a company and responsible for cyber. So he is interviewing and hiring lots of people. There are best practices, there are immediate. You're not going to get the job practices, meaning like these are things you should avoid doing. We're going to cover all of them. Take note. You're one. I'm going to bring a fresh notepad and a pencil to that one.
B
Click on Notify me right now so you know when it's airing. You do not want to miss it. You do not want to miss it.
D
Yeah.
A
Oh, it's going to be wicked. Good one. Sierra says do you have visibility into emerging approaches like intent verification or behavioral constraints that go beyond identity and segmentation for securing autonomous agents? Wow. There's a lot in this space kind of like, like research being done on it. I mean, Robert, do you have any. Have you seen anything around this development in this IAM space for nhis?
D
There's. There's so much that's hype right now. It's very hard to actually kind of see things that are actually a lot of it is basic security practices and kind of ensuring that you have the walls up, so to speak, to. To that to safeguard those things. Then also just your basic RBAC controls for your AI agents. Anytime you're going to give like an agent access across multiple areas, like you want to ensure that you have those safeguards in place. And then it's really. There's a lot of companies that are coming out saying that they're fixing this. There's a Lot of companies coming out saying like, we've solved iam. I don't see that yet. But there's a lot of people trying to say that they know what they're doing.
A
Yeah, the AI hype is out of control. James, did you have a thought on this one or should we push just
B
real quick, you know, with the get regarding agentic AI and governance, actually, I mean, there's not a lot of tools out there. There's so much being developed, so much research. It's the wild, wild west. You've got got organizations moving really fast with AI and we don't have ways to secure it fully and effectively. There's frameworks and there's, you know, NIST and ISO and all the different ones that are out there. But those are the guidelines until we know the organizations are pushing those through. It's, it's right now, it's the Wild west and we're learning as we're going. We're building the airplane as we're flying.
D
Yeah, that is true.
B
But I'm doing a talk on agentic AI next month at Secret Con.
A
Do you have a link to it? You have a link?
B
Not yet. No Secret Cons in Minneapolis, but if you Google Secret Con, you'll see it.
A
All right, Steve Young, he's our Minnesota. Oh, don't you know? Oh yeah, Steve Young. Let us know how you feel about the North Stars going to Dallas and then the Minnesota Wild. I talked to a mini A Minnesota last night and I was like, dude, you pumped for the why the Wild is the NHL team out of Minnesota? He's like, no, I hate the Wild. He's like, they should have called themselves the North Stars. You can have red socks and white socks. Why can't you have the North Stars? I'd be all in. Like, they ruined my childhood. All right, Trap create says tips on interviewing for an I am manager position. They said seems to broker on the PM side of things for an M and A. Okay, so let's just do one tip each. We'll go down the line. Me first, then Robert, then James. So the one tip I would give you is make sure that you're asking about the full scope of what that team's going to do. So you're managing people, not necessarily the tech stack. But is your team responsible for like application provisioning? Right. So like within the app, application provisioning ad is going to be probably an obvious and if you want to like, look like the bee's knees, talk about is your. Is your position responsible for agentic Identities as well. Robert, what's a tip for Trap creates the.
D
The biggest thing that I've seen, I've got a few friends in the IIM space is the people they keep interviewing with don't really understand iam, so really kind of get a clarity for what their thoughts are on, on the responsibilities of that role and what success looks like to them because you know what they're looking for. A lot of people right now are like, hey, you're going to be the manager, but you're also going to be like hands on and doing all the coding. You're gonna. And you're like, well, do you want a manager or do you want an individual contributor? And the answer to that is we want both, but we want to only pay for one.
A
Yeah, yeah, there's no, there's no humans. It's. You're. You're managing the, the stack. Yeah, go ahead, James.
B
Yeah, I'd be looking also at, you know, are they managing. What kind of identities is it human and service and AI type stuff you have. Because if you start having AI, employees and organizations are starting these, you know, get an understanding of what that's going to expect along with everything that Jerry and Robert said.
D
Yeah, I looked at that as a people management position running an IAM program. So I love that we all have different perspectives.
B
That's what makes this awesome.
A
Final question here for the day. Rich464 says he's continuing his IT cyber journey, taking on an account management role. I'm going to do a wrecking ball for that. Nice job, Rick. All right, the wrecking ball. If you're new here, the wrecking ball is a celebration when someone gets a job, usually in cyber, but we'll celebrate everybody getting work. I love it. So he's got account management and you know, a side course of doing risk audits. A little, you know, you know, baked beans, mashed potatoes and risk audits on the side of the plate there. In the current market. Any tips for comms with C suite non tech leadership? I, I mean, I don't know how the current market influences this. I would just say what's the tips for speaking to C suite and non tech leadership? Robert, you're an executive. How do you like people to approach you?
D
I keep it simple. Tell me what you want to start doing, stop doing or pay for like, you know, figure, figure out which one you need me to do and make it one slide, maybe two tops. Don't hit a bunch of stuff. Keep the bullets super high level and just clear and Concise. I'm going to have a lot of questions. Be ready to answer those questions and answer them short, to the point and move on. Like, a lot of us executives don't have a ton of time. And the goal of a conversation with us, if you have 15 to 30 minutes, is just get to the point, tell us what you need us to start doing, stop doing, or what you need us to pay for. Like, do you need budget or do you need us to start doing something? And just keep it simple. There's no reason to get super technical about anything. How is this going to apply to me? How does this help the business,
A
James?
B
Yeah, exactly. Keep it short, keep it simple, keep it in their language. You know, what's the impact to them for their organization, not for you. And always go in, you have an ask, you know, whatever that ask is. I need X done. I need whatever it may be. But you're talking in their language and the asks and everything Robert said.
A
Yeah, and I just want to point one other thing out too, because, like, I feel like there is a real human element that, like, we never talk about. And it's real. Like, and, and maybe this is just me, but I feel like this is general. If, if I'm working on something and someone comes in and they're heming and han meaning they're like, like, they're like, they're like trying to set it up, trying to put like a great look on it before they ask. Like, I'm actually getting irritated, right? And now you're putting me in a mental state where I'm. I'm not, I'm like, I'm like, not really super into, like, not helping you, but, like, you're irritating. Right? Just get to the point. Like, we're trying to do work here, so just. That's just kind of a public service announcement around what, what Robert said. Get to the point. Like, you're obviously having this meeting because you want to have some decision or some type of me be involved in helping you achieve whatever it is you're doing. So, like, let's get to work. That. That's just something I'll say because I know a lot of people get nervous and anxious and they're. They basically are trying to like, buy time before they ask the thing that's giving them the anxiety. Don't do that. All right, guys, I want to say shout out to all you all. Thank you, Robert. Thank you, James McQuiggin. Daniel Lowry's IRL is probably at 10:00am today, so in 30 minutes, go grab yourself a cup of coffee, maybe an apple fritter or, or a bear claw or something. Do your thing and then come on back and hang out with Daniel Lowry. Guys, have a great weekend. Thank you for taking the time. Everybody in the community, great questions, great community. Keep pushing forward, everyone. Have a wonderful time. And we'll see you Tomorrow, Monday at 8:00am Eastern.
Host: Dr. Gerald Auger, Ph.D.
Podcast: Simply Cyber Media Group
Episode Theme: A live, rapid-fire, expert analysis of the eight most critical cyber news stories from April 24, 2026, focusing on practical takeaways and real-world application for cybersecurity professionals, analysts, and leaders.
Dr. Gerald Auger (“Jerry”) delivers cybersecurity headlines with his characteristic mix of deep expertise, mentorship, and good humor. This episode covers major incidents—breaches, legislative news, technical vulnerabilities—and provides actionable insights for cybersecurity operations (blue team), GRC professionals, and career seekers. The episode wraps up with a live Cyber Career Hotline panel, focusing on real-world career advice.
[13:04–20:40]
“[W]hen you have an incident, a true incident, and there's a data leak…that is the chili on the floor. …How much chili got everywhere?”
– Jerry [13:45]
[20:40–26:35]
“If someone can get physical access, it bypasses lots of security controls... You always have to protect physical access.”
– Jerry [22:42]
[26:35–30:49]
“Educate your workforce, period, Full stop…. The communication vehicle does not matter. The medium is irrelevant.”
– Jerry [28:08]
[30:49–33:21]
“I think I found the root cause. The problem is you're using Edge. Oh.”
– Jerry [31:36]
(Light mood, not a critical threat. Move along.)
[37:51–43:12]
“If leadership is super in flux and there’s people coming and going…that’s an indicator that there are cracks in the foundation.”
– Jerry [43:12]
[44:36–52:41]
“This is a new one.…I’ve seen data for sale on dark web marketplaces.…This is basically on Chinese Amazon.”
– Jerry [45:42]
[52:41–58:30]
[58:30–59:18]
[64:02–End]
A rapid-fire, actionable career advice session featuring Jerry, James McQuiggin, Robert Wetstein.
How to Leave a Company Professionally
“Don’t try to get your last word in…it’s just not worth it.” — Robert [69:47]
Essence of GRC Roles
Interviewing for Stealth/Unfamiliar Companies
Communicating Upwards to Executives
Identity & Access Management (IAM) Manager Interviews
Reality of the Job Market
Want to catch it live? Join at 8 AM Eastern every weekday morning: https://simplycyber.io/streams
Show archives, resources, and socials: https://simplycyber.io