Loading summary
A
All right. Good morning everybody. Welcome to the party. Today is Monday. Boo. Monday, April 27, 2026. This is episode 1119, I believe, of your simply Cyber Daily Cyber Threat brief. It is an honor to be your host today. My name is Dr. Gerald Ozer. We're coming to you live from the Buffer Osier Flow studio here in the low country. And if you're looking to stay current on the top cyber security news stories of the day, while being entertained, educated and throwing it down with like minded professionals, well, my friend, you have found yourself in the right place. So whether you're at the desk on the elliptical or putting the kids through car line, we are off and running on this beautiful Monday morning. Let's get into it, shall we? Good morning, everybody. Yes, as some of you may have noticed, I went ahead and took a razor to myself on Saturday. I did, I did nip my Adam's apple here. So not a deep fake. I don't think deep fakes are quite like cutting themselves while shaving quite yet, but yes, I, I was getting a little long in the tooth, if you will, so I, I took it back. This is the fountain of youth. But for real, guys. Yes. Hey, every single day we're gonna go through eight stories. I'll break them down, go beyond the headlines in order to deliver additional value and insights for you. Now, of the eight stories, Mary Ellen Kennel, do you know how many. Do you know how many actually, Mary Ellen Kennel's daughter, do you know how many I researched and prepped? None. Do you know why? Ain't nobody got time for that. That's right. Ain't nobody got time for that. So I don't know what's coming. I don't know what the stories are. I gotta. I'm gonna give you my honest thoughts, my honest reaction. That's part of the pleasure of the show. I don't know what I'm gonna say either. What's up, A.A. witherspoon, good to see you. All right. Every episode, whether I know what's going on or not is worth half a cpe. So say what's up in chat. Just like Steve Young, Jay Gould, Jay Gold J, Crypto Code Brew, Temmie Adtech. And the team solos the Sean sailors and the TJ's of the world say what's up in chat, grab a screenshot, right? That's like basically signing in for your registration, file it away. Once you count up those screenshots, divide by two. I might have to learn a new script though. DJ B Sec's been cracking away on the keyboard and there's some reports coming in that he may have solved the CPE registration thing. So more to follow on that. What's up, Ms. Julian, as always, good to see you. Oh, gosh. So we got your CPEs, so continuing professional education credits for people who are holding cyber security certifications. Also, if you're here for the first time, we've been getting a lot of first timers, which is great. I appreciate you guys finding the show. Whether long timers have been pulling you into the show or maybe you stumbled in, maybe the SEO, maybe the every Sunday videos I've been doing for 2026 are paying off. I, I, I'm not quite sure how you found us, but we are really pumped that you're here. Welcome to the party. Welcome to the party. We want you to feel welcome here at Simply Cyber. So if you can drop a hashtag first timer in chat, hashtag first timer in chat, it's not so we can call you out and point at you. It's so we can identify who's new and who we can properly welcome. We have a special emote, a special sound effect. We have an entire thing built around welcoming new people and letting them understand how much we appreciate them. Checking out the show and hope that you stick around and become part of the Simply Cyber community. So let us know in chat with a hashtag first timer. All right, so we did our intros, we did all the things guys. It was a great weekend here in the low country. Did some fun stuff, did some chores right as as we are want to do. But yeah, ready to lock in and crush it this week. Sam Crow 7. Sam Crow 7 says First Timer Live will allow it. Sam Crow 7 welcome to the party, pal. And that's S A M squad members. So Sam, if you can get in there. Yeah. And if you're the car lines. Mary Ellen Kennel, the IT career questions of the world, we salute you car line. Only a couple more weeks left here in the low country for the kids in the schools. All right. Every single episode of the Daily Cyber Threat is brought to you by the show sponsors. Oh cool. Sam Crow usually listens on Spotify. Sam Crow, I hope me describing the the infographics. Whenever I show video I always try to like describe it for the Spotify folks. Hey, every episode's brought to you by the stream sponsors links in the description below for all of them if you can you want to support the channel, support the show, support me. Check out the links in the description below. Clicking on the links themselves do help. First let's talk about Flare. Flare is absolutely slaying it. Hello, my guy. Simply Cyber IO Flare. Flare, the cyber threat intelligence platform that is just making it unfair for bad guys. Whoa, like I'm gonna lose sleep over that. Flare goes out, scrubs the dark web, Cyber criminal forums, Dark web, cyber criminal, telegram channels. They do all those things, pull it back and make it in a easy To Query Interface, SaaS based product, tons of threat intelligence. Don't, don't, you know, don't sleep on this. Flare can take your security operations program and just ratchet it up to 11 with the amount of threat intelligence they can ride. Very targeted. What can I do with this, Jerry? I don't understand. What am I supposed to do with it? You can search for users in your environment and see if they've been compromised. You could search for endpoints, you could search for the domain of your active directory. You can search for your TLD domain, not your tld, but like your website domain and find out if that's been compromised. You can find creds, you can find chatter. I mean it's pretty bananas what's going on in this platform. I love it right now. If you'd like to check it out for two weeks free, no questions asked, go ahead and drop that in here. Simply Cyber IO Flare. I do want to point out real quick, somebody asked me the other day, how do I make a compelling case to management on signing up for Flare even though it's free, a two week free trial, how do I make a compelling case to get management to support me? I want you to know, over on LinkedIn, I actually put together an entire post with like a Steal this blueprint with like five things to say to management in this order with a video explaining how to do it. That's over on LinkedIn. I'm not sure if it came out yet or not, but it's going to be coming out. So go look at my LinkedIn profile. I literally give you the pl. The like the playbook, the script like to get this. So go check it out. Simply Cyber IO Flare. Spoiler alert. It's about talking about risk, not threat actors in zero days. You know what else is great to talk about? Anti siphon training. Anti siphon training is disrupting the traditional cyber security training industry by offering high quality, cutting edge education to everyone, regardless of financial position. And this Wednesday at noon Eastern. So two days from today, there's still time to register. It's not too late. Listen, if you're burning out trying to get into cyber security. I got news to you. When you get in to the industry that's when the work really begins. And that might seem intimidating but it is very rewarding. If you want to get ahead of the game and learn how to break free from the cyber security burnout trap, come join anti siphon training and not not a Leah. Natalia. I'm not sure does anyone know how she says her name? We'll say Natalia or Natalia. Natalia. I'm gonna go Natalia. Salman she's gonna break it down this Wednesday noon Eastern one hour free webinar plus plus Lots of Simply Cyber Community members lots of Simply Cyber Community members in these webcasts. So it's, it's a good time. Finally want to say what's up Threat Locker I see you Threat Locker just absolutely stomping mud holes in the cyber security industry with their effectiveness and reach. Threat Locker Zero Trust platform application by deny by default. Done correctly, it is hard to do. They've done it and now they've moved it to the cloud as well with that big reveal in March of 2026. Let's hear from Threat Locker and then Sam Crow, you're going to get the full audio visual experience of the Daily Cyber Threat Brief as I absolutely melt your face with the top cyber news stories of the day. I want to give some love to the Daily Cyber Threat Brief sponsor Threat Locker. Do zero day exploits and supply chain attacks. Keep you up at night. Worry no more. You can harden your security with Threat Locker. Worldwide companies like JetBlue Trust Threat Locker to secure their data and keep their business operations flying high. Threat Locker takes a deny by default approach to cyber security and provides a full audit of every action allowed or blocked for risk management and compliance. Onboarding and operation is fully supported by their US based Cyber Hero support team. Get a free 30 day trial and learn more about how Threat Locker can help prevent ransomware and Ensure compliance. Visit threatlocker.com Daily Cyber. All right guys, very simple, very simple. Everybody's got a role to play, right? This is how teamwork works. Everybody does their job. My job is to deliver hot takes on cool news. Your job is to sit back, relax and let the cool sounds wash over you in an awesome wave. Let's all do our part. Let's go. From the CISO series, it's cyber security headlines.
B
These are the cybersecurity headlines for Monday, April 27, 2026. I'm Steve Prentice.
A
Yeah, Steve Prentice.
B
ADT says customer data stolen in Cyber Attack. The home security company ADT stated that Monday's breach resulted in a limited set of customer and prospective customer. This consists of basic PII and no payment data was stolen. An ADT spokesperson said, quote, customer security systems were not affected or compromised in any way, end quote. This past Thursday the Shiny Hunters group claimed to have stolen 10 million records and threatened to leak the data if a ransom was not forthcoming.
A
Alright, so adt, the home security company. So obviously when security is involved that's a problem. It just says customer data. I mean not that, that's not nothing, but if it's just like username and pass, excuse me, email, email first, last, whatever, then it really doesn't matter necessarily if it's security company or not. I mean you could do social engineering attacks, but we're talking physical security so that you know, when you introduce a physical element to a cyber attack, meaning like the threat actor has to be there in person, it reduces the likelihood. Just because it's so much easier to attack people over the Internet than it is to like spend money on a plane ticket and fly in and then introduce the risk that you get like trapped like one of these porch pirates who get glitter bombed. You know what I mean? Ain't nobody got, ain't nobody got time for glitter bombs. Ain't nobody got time for that. All right, so okay, they stole a limited set of data. I always love, always love these like incredibly subjective, nebulous qualifiers. Don't worry, Mary Ellen, they only stole a limited set of customer data. What does that mean? They just got first name or like, you know, they got everything except one thing. So it's limited because it isn't everything. Lawyers unite. You know what I mean? Okay, let's see. Stolen information range from names, phone address, date of birth, last four social tax IDs. But don't worry, it's limited. They can, I mean they could file your taxes, they could probably get your credit un frozen, they could definitely pretend to be you on the phone to somebody else. But nope, no problem. Don't worry, customer security systems are not infected in any way. This is probably the priority, right? Honestly guys, it's adt. You spend money to have your house protected or your business protected. If they send you a letter saying your name has been compromised, you're like, okay, but like what does that got to do with what I pay you for monthly? Nothing. Okay, here's your identity theft protection. And oh by the way, ADT takes your security and privacy quite seriously. Yeah, okay, let's see. It was Shiny Hunters. I think I heard them say oh, oh, here we go. Elliot Matice, Phil Stafford. Guys, calm down. Everything's fine. They're offering complimentary identity protection services where appropriate. My guy. Complimentary. Here's another, like, really loose and fast use of a. A word in our English language. Complimentary. Complimentary. You know what complimentary is? Getting, like, an extra scoop of ice cream at Baskin Robbins. Because. Because it's like a Thursday and everybody's in a good mood. Complimentary is like, I don't know, like, getting extra wet naps at the seafood restaurant because it's all you can eat lobster night, and the bib's just not gonna cut it. Complimentary is not identity theft protection when you lose my data, fella. Okay, complimentary is how I guess they're spinning it to avoid being sued in the class action lawsuit for just negligence on handling of sensitive data. I don't know. Oh, complimentary. Get out of here with that noise. Like they're doing us a favor. Complimentary. Like, it's just annoying. It's like, you know what it'd be like? I'm sorry, I'm sorry, I'm sorry. I just. To me, it's insulting and it bothers me. I know this is the first story, but complimentary? This is like if I took my dog's dog waist, right? I'm not even gonna get really gross, but if I took my dog's waist and, like, threw it over my neighbor's fence and then offered complimentary dog cleanup services. What are you talking about, complimentary? Jeez. Okay, get out of here. All right? Don't. Bro. ADT. $5 billion in revenue last year. Hey, now. Great cash, homie. Okay, they've had multiple breaches and intrusions over the last two years, which means they probably have multiple identity theft protections. And multiple complimentary identity theft protections. Complimentary, bro. All right, so Shiny Hunters. They're the young. The young bucks. The young bloods. It's a Shiny Hunters. Lapsus and friggin. What's the other one there? Scattered Spider. The Rom. Not to be confused with the ROM Com. Let's see. British member of Shiny hunters pled guilty, 22 years in prison, while another serving a 10 year sentence. Wow, these guys clam up, huh? All right, so, I mean, hey, here's my thing. There's a couple things working against us. This story is not about adt. I know it starts with adt, but, like, for me, as a cyber professional, as the guy leading this threat brief, here's what I would say. Number one, you know, you. Any. Any Organization, regardless of how good it is at cyber security, will introduce some. Will always have some residual risk. Right. So you should be thinking about what, assume breach. What. What do we do if we get breach? What do we do if a threat actor, you know, ransoms us? What do we do if a threat actor claims to have our information? Etc. Okay, so like not just tabletop exercises on recovering from a breach technically, but like, how do you respond? What's our position? All these. Are we going to offer complimentary identity theft protection services? And, and by the way, just, just really quick on the surface of that, let's pretend that me, Mara Levy, Yetzi and Kyle. Kyle, the lead analyst, all have a. A company, right? And we make a billion dollars a year. Like, congratulations, guys, we made it. Okay. And we have a tabletop and we're like, hey, if we get breached, are we going to offer identity theft protection? And then Mara Levy's like, yes, that sounds good. I'm like, yes, I agree. And then Kyle's like, I don't know. And we're like, Kyle. He's like, I'm in. All right, so we all agree. Put a pin in that really quickly, okay? You like, you don't just like, abracadabra and identity theft protection services happen. Who are you using? How much does it cost? What's it look like to execute an identity theft protection service? Is there any residual concern? How do you identify who you're going to give the Identity Theft Protection Service? Because believe me, if you have 100 million clients, okay, and 10 million are the ones who get compromised, there is no way in a capitalist society we're going to pay for the other 90 million people to have complimentary identity theft protection services. Oh, no, no, no, no, no. Because that's a line item that's not coming out of my executive bonus. And I'm sure Kyle. Kyle wants an extra boat this year. He's not paying for the extra 90 million of identity theft protection services. So you have to identify who is in scope of needing these services. How much is it going to cost? Can you get bulk discounts? Who's your partner? What. What does it look like? What's the letter say that gets sent out? All of these things are details. And as we, you know, it's a common phrase, devil is always in the details, right? So don't just be like, yes, if we have a data breach with a limited set of data, we will offer identity theft protection services. Is anyone else want to go get lunch now that we've just solved all the Problems of this company? No, like, dude, dig into the details, roll your sleeves up, order food in and lock the door because you're not leaving until we solve this. Okay, that's. That's just one example. All right, so adt you. But you burnt.
B
SMS blasting comes to Toronto. We have reported on SMS blasting before, but not in North America. SMS blasters operate by mimicking legitimate cellular base stations, effectively tricking nearby phones into connecting to them instead of official mobile networks and. And are often fitted into cars, allowing cybercriminals to drive through densely packed cities and capture thousands of active cell numbers in order to blast out spam messages. Now, police in Canada's largest city have arrested three men in the country's first known criminal case of this type. The investigation leading to the arrest began last November after being alerted to a suspicious device operating in downtown Toronto. Over the following months, police tracked the device moving through several locations across the greater Toronto area, and two suspects were arrested in March, end quote. Authorities seized a large amount of electronic equipment, including several mobile SMS blasters and a third person turned themselves in to police last week.
A
Yeah. All right, so first of all, Super Zoomie, thanks for the squad membership. All right, number two, Blaster. SMS Blaster. What a cool word. Like, if. I think if I was going to start a rock band, like Blaster would be somewhere in there. Not to be confused with one of the greatest hidden. Oh my God guy. One of the greatest hidden gems of the Nintendo 8bit era. And if you know, you know Master Blaster the most. No, no, not Master Blaster from. Hold on. That, that, that's from Mad Max Beyond Thunderdome. I'm talking Master Blaster, the game that was like, stupid. Like the kid has like mutant frogs. Oh, yes, dude. Oh, Blaster Master. Excuse me. Blaster Master. My guy, really quick. Hidden gem, dumbest plot of any video game ever. But for my, you know, nine year old brain, made perfect sense. I played this game indefinitely. It had top down, left, right, you know, car upgrades. This game's a gem. If you are getting one of these like 18, 000 game ROMs and a handheld thing that I is may or may not be legal. Jack out. Blaster Master. This game is a hidden gem. You guys didn't even know you were gonna get this bonus today. Come on now. All right, so that's, that's, that's what I'm thinking of when I read the word Blaster. Okay, so check this out. This is a. This attack, in my opinion, is along the lines of like sim swapping. It's, it's not that it's not even remotely the same as SIM swapping, but I mean, like the frequency and kind of how often you see it, but. SMS blaster, let me show you. It's better to have a graphic for this one. Look it. There's got to be a graphic of this one. Yeah, look at these things, dude. So basically, this is insane. Okay? If you're looking on stream, Sam Crow, you don't need to look on. You don't need to be described because you can see with your eyes. But I'm going to tell you right now, they. They basically get a van. This is like, this should be in like a Ocean's 35 sequel movie. Hold on, hold on. I was wondering who was last few weeks, like Jesse Johnson or. Oh, my God. Or oh, my God. Um, sorry, guys, I'm. I'm doing. I'm. I'm doing something. I flip. I'm doing something here. My guy. All right, what is Nvidia doing on my screen? Okay, so listen, here's the deal. Here is the deal. Your cell phone, right? Your. Oh, look, there's me and Mrs. Ozier, gorgeous me. And I mean your cell phone, right? You can't really stop someone from sending you a text message. And if you just think about the way that the actual text messages work. I send a text message, it gets routed through the, you know, mobile network, and then it goes off of a cell tower. And your phone, your phone is constantly, like, listening, like, oh, am I getting incoming messages? Incoming messages, Incoming messages, right? This is why your phone's battery goes down, because it's constantly trying to, like, check if there's incoming phone calls. Incoming messages, right? So what these enterprising dudes have figured out is that they essentially build what, what is the equivalent of a cell tower inside the back of a van down by the river. Oh, my God. I just worked that in. And what they are able to do is send out text messages that bypass the entire system. So, like, they call it the last mile. Like, that's like a telecommunications term. But instead of me sending a message through like a, you know, some type of spammy script or whatever, and it goes through and it could get stopped along the way. It's just right there. And it's almost. It's almost like airdropping. It's. It's not the same, but it's like airdropping where they can just drive by with their van. And if you're in their sphere of, you know, omnidirectional Radio waves. They can send messages, which means they can send messages that look officially from the government or from your bank or from authorities, law enforcement, whatever. They can send Amber alerts. They can send, you know, blue alerts, like, whatever they want. And it's obviously wicked illegal because it's fraudulent. Now, the one thing I will point out is, like, Toronto straight up got these guys, right? So. I, I love that Toronto law enforcement got after this. You know, don't sleep on the Canadians. They'll take crime down. Those Mounties are legit, right? I don't even know if the Maple Leafs are in the playoffs. I don't think they are. So the police there got some. Got some time to kill. But listen, one thing I want to point out is even if you do this, and this is a great, like, opportunity for you to think about two things. One, as a practitioner, you should educate your end users. In my opinion that, like, I, I, I don't trust anything that comes from text messages. Nothing that, like, I'm not like, law enforcement, government entities. No one is texting you, like, official information. No one's texting me. And they're like, here's your PIN for your, your taxes are like, he, like, law enforcement's coming for you, or here's a subpoena for you to appear in court or you miss jury duty. Like, no, no, no, no, no, no. You can send me a certified letter and we could, or, you know, whatever. So that's number one. So educate your end users. Not. Hold on. Someone got a job. Jay Gool. You can't just drop wrecking balls and not. Does someone get a job? Okay. Oh, the Leafs are not in the playoffs. Yeah, exactly. Listen, Toronto police, they're on a, they're on the war path because they're just like, oh, my God, the Maple Leafs, we, We stink. All right, dude, the, the Bruins have had the Maple Leafs lunch for years. All right, listen, the final thing I want to point out is don't get wrapped around the axle on the tech on this one. A lot of people do this, especially new people. They're like, oh, my God, so cool. Van driving. And it can blast text messages and bypass everyone. Wow, wow, wow. All right, what is the action on objective? Right? Just because I can. Just because I can send you a bunch of text messages right now. So what, what is the action on objective? If it's to steal your money, how do you do that? It's got to be a link to go somewhere, missed toll thing, or you got to fill out a form or Whatever. So now I have to set up that infrastructure, right? And I have to keep it bulletproof so it doesn't get taken down. Or maybe I'm trying to socially engineer you into getting your passwords or something like that, or MFA attack just on a surface. The SMS blaster crime itself, while legal, it like, it does not result in compromise. It's part of the kill chain. So, like, I just, I. A lot of people get so, like, nerds, right? I'm a nerd, right? I'm nerdy by nature. Nerds will get wrapped around the axle of how cool this is. But as cyber security professionals who see the big picture, the question becomes, so what? What is the impact to me, my organization, my data, the apps, my people, what I'm paid to protect? Okay?
B
Microsoft Windows Insider program gets an overhaul. The revamped program has been announced as part of broader plans to address reliability concerns in Windows 11. The Windows Insider program is a beta testing program that allows members to test early Windows releases and provide feedback. Addressing the complaint that it had not really listened to all the feedback from testers, Microsoft is now making the program simpler and more transparent in the hope that it will help with the development of Windows 11. In its blog post, the company admitted that the current channel structure is confusing.
A
All right, so the Windows and Microsoft Insider program, this thing's been around forever or Windows Insider program. It's basically, you're a beta tester. Like, I don't know why they have to like make it more complicated than it is. You're a beta tester, period, full stop. Not really a cyber story, I would argue. I don't know. I guess I'll put that to the community. Is this a cybersecurity story to you? You know, with all due respect to Steve Prentice, who assembled this, like, if I, I mean, I get it's industry news and, and I suppose CISO series cybersecurity headlines, doesn't 100 align with what we're trying to do? So things like this can happen. But like, as a cyber security professional, as a ciso, right? Like, when I see this, I'm not like, oh my God, everybody stop. Pull the newsletter back. We've got to make an update. Windows is fixing their beta testing program. I wish I had a slide whistle, you know what I mean? I guess it, I mean, Sean Saylors, I would not like. So Sean Saylor said it, it depends how they do the patches in your environment, I guess. Now that's a fine idea. Listen, I would never in a thousand years like a Hundred out of a hundred times. As a, as a, you know, information security leader, I would never adopt my entire organization into a beta testing program. That's absolutely ludicrous. Okay, so maybe you get like a couple people who are the beta testers and maybe you would do this so you could vet early adoption of how it might impact your organization, but for the most part, no, you know what I mean? Like, we have so many priorities in information security that like getting an early start on how Windows might not function in my environment is like, not really a big deal. Like, if anything, I just don't patch right away. You know what I mean? Like whenever the beta testing thing gets cleared and then gets to me, I'll apply then. So yeah, anyways, if you want to become a Windows, listen, as an individual, right, if you wanted to get a, become an insider and do beta testing, maybe that could be cool and then you could say you like indirectly work for Microsoft as a beta tester, I suppose as part of your personal brand and portfolio. But whatever. I will say one other thing that's like worth noting. Bigger picture. Okay, Bigger picture again, by the way, for those who don't know, one of the things that I like to do here, one of the things that I promise you is that I go way beyond the headlines, okay? Headlines are cute. You can read the headlines like you're all very smart, intelligent people. You can read the headline. You can have AI crop out the key points of the story and, and you know, put it in a podcast style brief. You can do that. So why would you listen to me flip out? Number one, it's awesome here at Simply Cyber. But number two, I have an a load of experience, just like many people in the chat, and I want to go beyond it so you don't have to learn the hard way. So let me tell you a little something about, about, about what they're doing here. So Microsoft is revamping their beta testing program and they said that it's gotten really squirrely and hairy over the years and they just need to fix it. I want to tell you guys something. Listen, as an individual who runs a cyber security program and, and many of you likely own either your own program or parts of a program. Everybody's got their own little empire, right? Even if it's a tiny little teeny empire like the island of Venutu or Djibouti, right? Those are real places. It's. You got something, right? So what ends up happening? And, and I can tell you from a simply cyber perspective, you know, you Slowly start building things. Building things, building things, building things. Some things work, some things don't work, and you don't always reverse the things that don't work fully and things kind of get organic. And you started out as a circle and it was nice and clean and. And then you started getting these, like, you know, kind of barnacles on it. And by the end of the day, you can see it's still a circle is, but it's definitely, like, rigid and stuff like that every once in a while. You could even call it like spring cleaning. If you've ever, like, taken everything in your garage and put it in your driveway and then tried to clean up or anything in a storage container or go through your closet and throw away clothes you don't do anymore. Like, every once in a while, it is a good idea, just like Microsoft's doing, to take a moment and review your overall whatever and clean it up, get rid of what's not working, tighten up the bolts that are loose, clean it up, do some of the things that you've been talking about doing, and then start moving forward again. Okay, it's. It definitely don't just keep plowing forward. A lot of people will just plow forward, plow forward, plow forward. It's. It's almost. In some places it's called technical debt. If you've ever heard the term technical debt. That is where you're kind of like, making decisions and bringing things forward that really need to be put to bed or, you know, taken out back by the woodshed and turned into wood glue. Like an example would be like, say you have, like, an access database running on a Windows XP machine somewhere, right? That's probably not great, but it's making money or whatever, so you just kind of allow it. You just like, let that continue to fester. Well, maybe you're getting a whole new ERP system and it does a bunch of things, including, like, whatever that Access database does. So maybe you take some time and you're like, all right, we don't need to fix this because it works. But it would be more optimized if we had everything in one place. Clean lines, you know, supported all that. So don't sleep on taking kind of spring cleaning of whatever your project is.
B
Extortion GROUP LINKED TO SURGE OF VISHING ATTACK this new and financially motivated hacking group, known as Blackfile, has been linked to a wave of data theft and extortion attacks against retail and hospitality organizations since February of this year. According to Palo Alto Networks Unit 42. Working with the retail and hospitality information sharing and analysis center. The gang's members impersonate corporate IT help desk staff to steal employee credentials. Unit 42 says this gang is likely linked to the com, which is a network of cybercriminals known for targeting and recruiting young people for extortion, violence and other crimes. In this wave, the attackers use voice based phishing that's vishing from spoofed VoIP numbers or fraudulent caller ID names as a social engineering technique.
A
Yeah, okay, so this is just a bigger kind of state of the union on oh by the way, after Zima said something, I actually have prepared a like quarterly biannual simply cyber community town hall meeting deck. I, I have to schedule it, but that's just ask me at cyber career hotline. This is a larger state of the overall information security threat landscape. Be aware of this black file extortion group. Fine. I'd never heard of them before. It doesn't matter. The attack sequence you have to be thinking about is vishing or voice phishing. This is where they call you. Now remember like with SMS Blaster, like the story that they just mentioned here in Canada, they could send you a text message. Hey, it's Jerry from it. We're seeing some issues. Can you call the help desk? Here's a phone number. Sometimes they'll just call you and make it look like the help desk phone number. Sometimes they'll call you and make it look like it's coming from like the local police or coming from the courthouse. And hey, this is officer Oer. You missed jury duty. There's a warrant out for your arrest. We, we, you know, because of this major influx, we've decided we're going to take, you know, $500 best buy gift cards as payment, whatever. Here's the bigger picture. Here's the bigger picture. Okay guys, right now there is a trend in the, in, in the cyber threat actor landscape. That's really a problem and it's going to continue to be a problem I would say based on my life, like it'll be a problem for like another four, five, six years or excuse me, for the youngs in there who almost got triggered. It could be a problem for another 4, 5, 6, 7 years. Here's the deal. Young people are doing this, but that's not the problem. If you remember when you were young and I see this with my 14 year old now, you know, as you like begin to, I guess leave the nest, right as you become a, an adult and you start functioning independently and you have, you know, Freedom, for lack of a better term. And you have self accountability versus having someone yell at you like I don't know where your sweatshirt is for school, where did you put it? Right? Those individuals are, you know, 15, 16, 17, 18, right? Like they're, they're becoming young adults and they look to their peers and social equals to determine what norms are. And then just like Lord of the Flies or any social experiment you've ever seen, where when you put a bunch of people together and allow them to operate inside of their own ecosystem, there will become a hierarchy of power. And I know this is getting deep in the weeds on psychology and human behavior, but just trust me on this one, okay? And the people at the top, you're seeing this with like YouTube influencers that like do Roblox and stuff like that. People like kids are like, oh my God, I love that guy Ryan's toys, like all that. So when this, the hierarchy begins to format. The people who are new, the people who are young, the people who are looking for social fulfill, not social fulfillment, but social, not satisfaction, what's the word I want, like social acceptance. Okay? They are at the bottom and they're looking up at what needs to be done. And the people at the top are setting social norms on what, what is cool, what is elite, what is lame, what is loser, right? So there, there, there becomes a standard of what's good and what's bad. And what's good is how much money can you steal, how cool did you do it, how rude were you? Etc. And these norms are coming down. So you've got this like incoming recruiting group of youngs who are looking at these people and who have money, which young people typically don't, which have power, which young people typically want and, and they have access to them. So anyways, yes, the calm is bad, shiny hunters, lapses, scattered spider are bad. But there's a much larger macro issue of there's going to be a lot more of them I guess is what I'm trying to point out. And they're using vishing by just calling people and being, you know, braggadocious and threatening and forceful in order to achieve whatever it is they're trying to do, which is typically get credentials or do something like that. So yes, tech run. Thank you. Social, social validation is what I was looking for. But social inclusion, social approval, etc are all those things. So yes, in, in the moment, at the micro level. Yes. Black file, don't click on it. Cordial spider, look out for the ttps, all these things. But I'm telling you guys what you should be. Oh my God guy. What you should be thinking about is this larger macro problem. And a part of this information that I'm sharing with you came from a flare academy webinar I attended a month or two ago called Life Day in the Life of a Ransomware Threat Actor or Ransomware Operator. And it went into all of this really complicated social hierarchy. It's wild. So anyways, educate your end users and, and finally, finally for all practitioners here, get with your help desk and talk through your workflows on vishing and, and please, final, final. This will save you in the long run. Get management involved so that they are in agreement, in alignment and signing off on those processes. Because if you get a phone call from the CEO and the CEO says reset my account or you're effing fired and the help desk person says, okay, because why wouldn't they? They're afraid of losing their job. But if the CEO and management has said we, we all agree, we will never call the help desk. And if we do, like it's on us because we're in the wrong, then you empower your help desk to be able to make those good safety choices and tell the threat actors to move along, sir. Move along.
B
Huge thanks to our sponsor, Guard Square. Mobile app security isn't just a tech issue. It's a revenue issue. A recent global study found that 72% of organizations experienced a mobile app security incident last year. And even worse, 65% saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. You can learn more at guardsquare.com that is G U A R D S Q U a r e guardsquare.com.
A
All right, all right. Hey, listen, I know it's. We're kind of behind schedule on the stream. I'll double time on the back half. But you know what? Sometimes the show just kind of has its own vibes, right? It is a thing. Guys, I want to say thank you all so very much for being here. I hope you're enjoying the show. Like I said, I have no idea what's going to happen. I don't know what we're going to cover. I don't know what's going to trigger me. But I will tell you this. I am authentic and I'm honest and this is how I feel about these things. And thank you for giving me an outlet to be able to share my passion with you while hopefully helping you professionally. That's really the goal. Shout out to the stream sponsors Threat Locker, Anti Siphon and Flare. As always links in the description below. The show is not possible without their support. Every day of the week has a special segment and Mondays is Simply Cyber's Community member of the Week. Now one member of our community every Monday gets recognized. I've been doing it for years. I send them a hundred dollar Amazon gift card for they for them to do whatever they want with it. You want to buy a, you know one of those like radio things that you can like wind up kind of post apocalyptic radios. You do that. You want to buy some disco balls? Get on it. What's the last thing I bought from Amazon? You want to buy a final fantasy? Your shitola Scions and secrets Commander Deck you do you boo. This is sponsored by Threat Locker. Threat Locker doesn't deny by default approach to AppSec. They're the ones who provide the hundred dollar Amazon gift card. I'm just lucky enough to be able to hand it to the person. Jesse Johnson is doing great work, but I wanted to spend a minute and recognize one member who shows on the regular. She's been a long time Simply Cyber Community member. Ladies and gentlemen, Space Tacos. Adrian Harris. She's probably in lurker mode, but if we can lull her out from lurker mode. Space Talkers has been a member of the Simply Cyber community four years. She's in the chat every single morning. Whether she's driving or she's in a meeting. She's always sending supportive information, supportive talk and you know, she's just a great, great community member. So a Adrian Space Tacos. Thank you all so very much and congratulations. All right, now let's get our La la on Sh. You know the words, Adrian. Let's let the La la la. Remember, don't go anywhere. We've got hotline at the end. Roll Marcus. Go. La. All right, all right. Let's keep going for the sake of time, bro.
B
Zion Siphon Water Infrastructure Threat holds no water. Following up on a story we covered last week. The malware called Zion Siphon, first identified by AI cybersecurity firm Darktrace and described as targeting operational technology and industrial control system environments in Israel's water infrastructure might not be anything more than hype. A malware analyst at Dragos called the malware nothing more than hype, stating that, quote, whoever wrote the malware appears to have little knowledge of how operational technology works. It appears the developers, quote, used AI to generate significant portions of the code, leading to hallucinations, guesses and Errors and was so riddled with logic errors and invalid assumptions that Dragos says it would have been inoperable. The company adds, there are publicly less than 10 malware samples capable of threatening industrial control systems, and Zion Siphon is not one of them.
A
All right, so, you know, some ham fisted over eager hacktivists trying to develop AI excuse me, trying to develop a weapon to attack Israeli based water plants. And because they're vibe coding it, it doesn't work. So the story. Okay, so first of all, Dragos is kind of like the mandiant of incident response. Dragos is the industri control system operational technology incident response firm. If you are, if you work in OTICS and you have large budget and you get punched in the mouth by a threat actor, Dragos is kind of like the 911 call, right? There's a bunch of people who do it, but Dragos is kind of the, the darling of the industry. Number two, OT and ICS is a niche, niche area of cyber security. And it's not the same as I t. So vibe coding a weapon and I like. And, and then pointing it at ot. You know what I mean? You might as well, you might as well try to stick like 50. Well, you might as well try to stick like a cannonball inside of a revolver, right? Oh, I don't get it. Why doesn't it work? It's ammunition. It's the same thing. My guy. You can't stick. It's. It. It's its own thing, dude. You can't just be like, right, malware. And I'll be back in 15 minutes. Now, I will say, as AI continues to progress, maybe there'll be a, you know, a level where someone who has no clue what they're doing can vibe code a weapon. But right now it seems pretty safe, if anything. What I would get out of this story is two things. One, I think AI's hype cycle is out of control. It's so much money being spent on AI. Great cash, homie. Okay? So much money. AI is the new hype. Okay? So first of all, there you go. Number two, what I see from this, this shouldn't surprise anyone, okay? This is an Israeli water supply. If you haven't been. Again, I'm not going to get super into the weeds on this one. I don't want to get labeled discriminatory, you know, incorrectly. But if you've been following geopolitics and what's going on globally, there are countries that are super not happy with Israel, like they're in global conflict. With, right? So that would be an adversary and adversaries like to in, you know, have influence over their adversaries, right? Win the war, if you will, win the battle. And there's a bunch of different ways you can do that. There's kinetic weapons, there's cyber weapons, etc and some they're just throwing crap at the wall right now. So, so what I would say is, for me, all this does is reinforce the idea that the threat landscape and my threat modeling for protecting my organization, the likelihood is going up and I need to expand my, expand my concept of what an attack could look like. Right? So listen, we're not, you know, we're not. What is it? Is it Madame Cleo? Mistress Cleo? Who's that? What was that 900 number? Scam artist who was like, call now and like get your secrets. Is it Madame Cleo? Miss Cleo? Miss Cleo. All right, I'm not Miss Cleo up here. All I'm where. Like I would know all the attack sequences, but just when we're doing cyber security and we're thinking about where to spend money and what risk to think about, it depends on our business size, our industry that we work in, our revenue, right? Our, our. How big a footprint do we have? What tech stacks are we using? Who have we pissed off? Like in the world, these things all matter. And when your country, when your country, you know, that could be a problem. And, and don't sleep. Like if you're doing business with Israel or you're doing business with Iran or you're doing business in Ukraine, like, you also get your risk profile increased and you should account for it in your threat modeling. If you're not, you're just taking on risk unnecessarily. By the way, this is why GRC people have value and why we get paid a lot of money because we are able to understand how fluid that risk is and be able to quickly recalculate it and be able to move, you know, move in real time.
B
Researchers find pre Stuxnet malware targeting engineering software researchers at Sentinel 1 have published a report on a new Lua based malware that had been created years before the famous Stuxnet worm that had aimed to sabotage Iran's nuclear program by destroying uranium enrichment centrifuges. This previously undocumented cyber sabotage framework dates back to 2005 and primarily targeted high precision calculation software to tamper with results. It has been codenamed Fast 16. It also precedes the earliest known samples of Flame, also known as Flamer and Skywiper, making it the first strain of Windows malware to embed a LUA engine.
A
All right, interesting. Okay, so first of all, I was gonna. I fact checked this thing because it's 2026. Stuxnet was around like I think 2012, 2011. And I thought LUA was a relatively new programming language, but apparently LUA came out in 1993. Plenty of time to have it there. So I don't even know how Sentinel One found this. A Lua based Stuxnet, like malware that is 21 years old has been discovered. Phil Stafford said this is a fun story to read. I'm going to drop a link in chat to this one. This is just. There's a lot of peculiarity to this one. Wild story. Okay? Cyber stories gone wild. Too hot for tv. That's a very deep cut for the olds in the chat. You guys know what I'm talking about? All right, so Stu net, it says first known digital weapon. Yeah, I would guess it was, but. Okay. All right, so here's how they found it. This to me is like the story, like how did they find it? Said they made the discovery after identified an artifact named ServiceManagement EXE that at first blush appeared to be a generic console mode service wrapper sample as a file creation timestamp of August 30, 2005, to which it was uploaded more than a decade later on 2016. This is interesting. So. Hold on, Wait a minute, wait a minute. There's a lot going on here. Published vast troves of data stolen from Equation. Okay, so shadow brokers, if you don't remember, Shadow brokers broke, broke in and stole basically the United States cyber security weapon arsenal and released it. This is when Eternal Blue came out. So if you're, if you're interested, this was a wild, wild time. Okay? WannaCry blew up right afterwards using Eternal Blue. It was like an SMB exploit. So they're saying that looking at this, this is like a History channel documentary here. Fast 16 was included. So which, which this would lead us to believe that this LUA based malware was in fact NSA developed, right? Or Israeli NSA developed. This is pretty cool. I mean, this, again, this is like a history lesson. This is not something that you're going to use today. Yeah, this is really cool. Go, go check the story out. The one thing I would say is there's nothing for you to do here. This is like a fun. If you're into cyber security, you'll enjoy this story. If you're just looking to Break in or you're trying to, like, protect your business today, this story does nothing for you. This is. This is nerdy and cool, but it's old. Dude, this worked in 2006. Like, chances are, you know, the system's been patched.
B
You would hope Carnival Cruise Lines suffers breach and extortion. Troy Hunt's have I Been Pwned? Has potentially identified 7 1/2 million unique email addresses belonging to a subsidiary of the world's largest, largest cruise company. The addresses appear to relate to the Mariner Society loyalty program run by Holland America Line, which is a subsidiary of Carnival Corporation. The exposed data includes names, dates of birth genders, and membership status details. The type of personal data that attackers can easily repurpose for fraud or phishing. Carnival has acknowledged a security incident. And meanwhile, the Shiny Hunters extortion crew published what it claims as, quote, terabytes of internal corporate data, end quote, after negotiations with the cruise line failed.
A
All right, so Shiny Hunters, I'm telling you, these guys, they were in the first story. They're in this story. These guys are going ham again. There's no. They're young. Their brains aren't fully developed, which is not an insult. It's just human, physical. Like, your brain doesn't fully develop till you're 25. So it's not disrespect. And, dude, they're getting after it. Shiny Hunters is a bit of a. Like, you know, the. The gang in Teenage Mutant Ninja Turtles. I make this reference all the time in Teenage Mutant Ninja Turtles when there was the gang of the, you know, misfit kids who, like. Like, we're in the warehouse drinking Code Red Mountain Dew and skateboarding, eating pizza, committing crimes and all that. Petty theft. It's the same thing, right? These guys are going after anyone and everyone. Doesn't matter if you're Carnival Cruise Lines, if you're adt, if you're a freaking Ticketmaster. Snowflake Simply Cyber Publishing Company out of Greenville, South Carolina. It doesn't matter. It's all about straight cash, homie. Straight cash, homie. Also, really quickly, I know that we're at 9 o' clock and we're. We're behind time. I do want to offer a poll and then I'm going to do a polling and then I'm going to answer it. During hotline. I saw a story on LinkedIn. A guy got fired from work. He was a remote worker. He could work from home. And he bought, like a permanent pass on Carnival Cruise Line somehow. And he just was on a Carnival cruise line for like 18 months or he kept getting on and off the ship or whatever it was. He bought like a, a Gold Pass and his employer found out finally and they fired him. It. What do you think about that? Is it, is it okay to work from anywhere if you are remote work and, and just assume, assume the following, right, that this guy was doing his job great, okay? He punched in at 9, punched out at 5. Available email responses. All the things like, it's just an interesting question because most people think I work from home. This guy's like, my home is floating.
B
Microsoft now lets admins uninstall Copilot on enterprise devices Nice. IT administrators can now uninstall the AI powered Copilot digital assistant from enterprise devices using a new policy setting which became available after the April 2026 Patch Tuesday. It's called Remove Microsoft Copilot app and is available as a policy, CSP and group policy. After deploying this month's Windows Security updates on endpoints managed via Microsoft Intune or System Center Configuration Manager, this policy will only apply to Windows 1125H2 devices where the Microsoft 365 Copilot and Microsoft Copilot are both installed. The user did not install the Microsoft Copilot app and the Microsoft Copilot app was not launched in the last 28 days. Got that?
A
That's rough. So if you're an admin, you can remove this, but if, if the end users used it deliberately or by accident because they hit the friggin Copilot key on their keyboard or because they logged into Microsoft Office and Copilot comes up first, right? You won't be able to do it, dude. I'm telling you, Microsoft, they had to have been. Someone had to have like grabbed their arm like Scott Farkas behind their back and wrenched it like say uncle. Say uncle. Because like why would Microsoft put in a capability for you to, to remove their, their play on AI? You know what I mean? Like this from a capitalist perspective, this would be like allowing you to like easily remove Internet Exploder from their, you know, operating system. Right? So you know, anyways, the tldr, like chances are you're not the one doing this, but you could share this with your IT team. Hey guys, listen, you know we can remove Copilot. It's about Attack Surface, right? I mean prompt injection is a real thing. I will say this Copilot comes baked in with your Microsoft 365 subscription. I, I, I, I facilitated panels. Some of you may or may not know this. This is where I was hanging out with Devin Grady the other day. But like, I went to a healthcare conference last Thursday or two Thursdays ago, I can't even remember. I went to a healthcare conference recently and I was a moderator for a couple, for a panel and an emcee for part of the show and everything like that. And I, so I stayed for the talk and I listened to the speakers. And these are executives in healthcare organizations in the state of South Carolina. And guys, copilot is quite deployed. It's quite available across at least that dimension, SC healthcare companies. So people are using it. So don't, don't sleep on this. But if you're not using it, I, you know, in my opinion, you should get rid of it.
B
All right, if you have some thoughts on the news from today or about.
A
I have some thoughts about the news. It's called let's go to the hotline. That's going to do it for today's news. Guys, I hope you got value from it. If you were here for the first time. Come on back tomorrow. Sam Crow. I hope you enjoyed the audio visual experience. Shout out to Space Tacos for being our Simply Cyber Community Member of the Week. Honorable mention for Shimeria Gonzalez, who's at In Chat right now. If you do at chi, she'll pop up. She was involved with the Simply Cyber newsletter. If you did not know. I don't really talk about it very often, but if you go to Simply Cyber IO newsletter, you'll see that we actually have a newsletter that comes out every single Monday. We've been doing it for like four or five years. And it's literally got three pieces of actionable intel, one for your end users, one for your IT counterparts, one for your executives. And in a lot of instances, you can literally just copy and paste it. It's yet another piece of value that I forget to tell people about that we offer to you as Simply Cyber Community members. I will tell you that there is like, like there's usually like a sponsor graphic at the top, the newsletter for those who do not know or are remotely interested. The newsletter costs me about 200 bucks a month because of the platform we use and just the sheer volume of people who sign up for it. So I don't want to just absorb those costs. I absorb the cost for years. So there's like a sponsored thing. All right, guys, let's get out of here. I'm Jerry from Simply Cyber. If you gotta go, go. But let me tell you one thing that's pretty dope. If you can stay. We're about to do Cyber Career hotline Phone line here. Get this smooth Lo Fi. Listen. Cyber career hotline. Your questions, my answers. Phone lines are open now. Drop your questions in chat. Let's get into it. I'm Dr. Gerald Osher. This is the Cyber Career Hotline. If you're building a career in cyber security, this show is for you. Let's get into it. All right, everybody, it's all about good times. We try not to take ourselves too seriously here, but it is really fun. If you have a question in chat, put it in there with a Q and I will answer it to the best of my ability. I'm scrolling to the bottom. I saw Marcus Kyler with the Yeet crew, by the way, drop a question. I'm gonna end the poll really quickly. The poll was, is it okay to work from anywhere if you are a remote worker? Chad is pretty divided on this one. 68 Yes, 32 no. So not a slam dunk one way or the other. Some things people were citing around cross country borders. Data regulation, secure connections, etc. So interesting. All right, first question coming out the gate is from my friend Marcus Kyler. Marcus and I have been friends for about three years now. Per the first story, we constantly make fun of businesses who offer free ID protection. Say your security is important to us. What would be a substantive and meaningful response? I mean, honestly, Marcus, it. What would be a meaningful response? I mean, you're going to have to offer it anyways. I mean, if you wanted to be more accountable, you could include what you'd be doing in order to, to prevent it from the future from happening in the future. There are some companies that do get in front of it. So I, I don't. Here's the thing. I've seen companies not offer the identity protection and I've still felt okay about it because I don't really know how super valuable that is. And maybe not your security is important to us. But like, you know, how about like we have a robust approach to cybersecurity, but we're not capable, like any business, to eliminate all risk. We're going to evaluate, you know, from this particular incident to ensure that. One second. I have a UPS connected to my, like my NAS and my workstation are all plugged into a ups, which is like a battery backup slash, you know, bat a business continuity thing. So if we lose power, I can gracefully shut down and it's click. It's like clicking right now. It hasn't made noise in like a year. There's also no visual indicators. It's just like a mechanical click. So anyways, that. That's what I would do, Marcus, in this situation. It is tough, though, when you're a publicly traded company. You know, it happen. Marcus says he sees companies get slammed for not offering it. That's interesting. Noah says, I'm breaking into the industry. I just got my SEC plus, no cyber experience with past jobs. How do I best showcase my skills? Yeah. Okay, so here's what I would say on this one, Noah. Number one, get a website, right? You can do free ones. Like there's get hub pages or get pages. Look at dj, DJ bio website as an example. Put that. Put the home lab, put the cert, kind of have a landing page, do some social. Do. Do consistent social media posts on the work you're doing. You want to kind of have a. Whatever job you're going for, make sure that whatever experience you're developing or skills you're developing are aligned towards that job. And then finally, You should be networking. I mean, you're here right now, Noah. But lots of jobs. Lots of jobs, guys. And Noah, lots of jobs, especially in cybersecurity, are never published, right? Or if they are published because they have to be, they may already be hardwired, meaning hardwired for somebody. Meaning, like, I already know I'm giving this job to Joseph, but because HR says I have to post it for two weeks, I'll post it for two weeks, get a bunch of interview. Get a bunch of resumes. Maybe I have to interview people. I'll interview three people and then give the job to Joseph. You know what I mean? Like, so by networking, you can establish those relationships and find out about opportunities. And it's not about getting a job you don't deserve, okay? It's just having a relationship. Marcus Kyler is saying you got to offer the identity theft protection, but you got to go further in the response. I agree. Even the letters you get, you know, when you get identity theft protection, the letters you get are kind of weak sauce as well. Space Saco says if you'd like to see the company just say they had a problem, they're working to fix it, and they're sorry for the drama when it comes to security breach just once. There you go. All right. Sierra Montgomery's got to go. Have a nice week. Jesse Johnson returning to Slay Secure Slay cert. I believe he's doing that with Tech Ricky now. He can come on tomorrow on Tuesday. And share more about that fun fact. I played Magic the Gathering on spell table with casually Joseph Yesterday, he absolutely pantsed me with a merfolk deck. What else? If you got questions in chat, this is Cyber Career hotline. It's a 30 minute show from 9am to 9:30am Eastern time, Monday through Friday where we do everything in our power to answer your questions. Chris M. Says with looking at bad all day, what tool suggested to get out of the funk, questioning if I can mentally handle it and cyber security is right for me? Yeah, I mean, I mean, I don't know, it's like in our industry, it's not like we're looking at like things that give you nightmares. I mean the, you know, the seriousness is real. But I, I don't know, I guess it's just you get, in my opinion, Chris, you just get desensitized to it because you see it all the time. Not to mention like, you know, I feel like there's a lot of hype around attacks and all these things and like when you see enough of them, like, you can kind of like take a measured approach to them. I think, I think anyone can handle cyber security if they like it. Here's the thing, Chris, and I'll say this to everybody. I've said this before, so you may have already heard this, so you know, bear with me. But like if you want to work in cybersecurity, you, whoever you are, I'm talking to you. If you want to work in cyber security, you can absolutely work in cybersecurity. And the entire mission of simply cyber is to provide support and empower you to achieve those goals. Now having said that, cyber security isn't for everyone. And I'm not trying to say it's not for you. I'm not trying to say we've got enough people, you can move along. What I'm saying is in, in my opinion, this is a hot, I mean, squad members, if we can get a tinfoil hat, please, this is a tinfoil hat comment. In my opinion, cyber security is a lifestyle and I know that that's asking a lot. But just like the people that I see that don't get toasted by cyber, the people who like thrive, they typically, it's typically like more than a job. It's like they're into it, they're into cyber security. Like how attacks work is interesting. New techniques is interesting. Ways to defend is interesting. And because of that interest, you never really get broken. I mean you can burn out by overworking, but like, it's just, you never get satisfied where you're like, ugh, Gross. I don't want to go to work because I, you know, I'm not interested. Like, to me like that, that's like cyber security is constantly, constantly changing. Constantly. And if you, if you like that it's a new day every day, then you, sir, you, you, you, you thrive. And if you're like, oh, my God, like, I barely can keep up it, you'll have a tough time. So again, Chris, I'm not saying you can handle it or not handle it. I'm just trying to lay out, like, at a macro level what my experience is. And this is a real topic that I would love the simply cyber community member you to drop your thoughts in chat about, because it's a serious topic, man. Some people spend years trying to break in and then they, they're like, oh, I don't like this job. You know what I mean? All right, All right. So continuing to look through chat. Jesse, There's Jesse. Jesse's saying, let's go. Trap Create says, how does one narrow down a niche in it when it, when it's all interesting? Oh, yeah, no, no, for sure, dude. Cyber security is interesting. I love it. What I would say is, don't a lot of people, like, casually Joseph, not to, like, dox him right here, but casually Joseph is kind of going through this struggle right now. Sorry, Joseph, I'm just gonna air this. But I think it's something that you would tell other people. Guys, don't get sweaty and worried about the process. Most people, Most people, when they work in industry one to three years, like, they're. You start getting your first job, and then, yeah, up to three years, you are, like, doing all the things right. Maybe you're professionally doing soc analyst work, but you're also dabbling with, like, GRC or CFP or capture the flags or Red Team or reversing or ida. You're playing with different things. You're getting experience, you're learning about new things all the time. Then between like the years of like, three to six, four to six, that's when you start leaning into a specific niche. Now, this niche can come just by virtue of your job, virtue of your opportunities, virtue of where you're passionate and you're able to, like, double down on it. And then once you do that, trap creates, that's where you're going to get that niche. And then, you know, 6 to 10, you start becoming a subject matter expert in that niche. All right, so as far as narrowing down goes, the question is, how does one narrow down? What I would say is look at the intersection, the Venn diagram, if you will, of like what you have opportunity to do typically professionally or through an outlet that allows you to develop professionally, meaning professional talks, collaborations with other work researchers, you know your thesis for a master's degree or whatever. Take that and then overlay it with like what you're passionate about and lean into that. That's how I would narrow it down. Listen, I got a master's in computer science in like 2004 or six or something, I can't remember but. And I did my thesis on wireless security and I like drove around with like wardrobe. I was like war driving with like a antenna out my car and I was collecting all this information. I was doing analysis on the overall, you know, with a large enough data set, what is the macro level view of, of residential wireless networks etc. And I, I loved it. I loved it. Do you know how much I do with wireless networks now? Zero. I own a WI fi pineapple and it's still in the box. You know what I mean? So don't, don't, don't overthink it. Don't get overwhelmed. Like go to the buffet. Try all the things. If you like something, go back and eat a little bit more. But don't be beholden to it. All of it, no matter what you're doing, trap creates, all of it is going to be able to support whatever you end up doing long term. All right. Continuing to look through chat. Cyber Shinigami. Anyone know of any network engineering jobs or connects I can share with former colleague who was unexpectedly laid off? That sucks. I guess just PSA here. If anyone knows anything for sure, drop it in here. Let's see. Continuing to look through chat. This is cyber Career hotline. Phone lines are open, Proverbial phone lines. Just ask questions and I'll answer. E.K. berger says, I think this is a question. It doesn't start with a Q, but it kind of had a question vibe. It is the current events, especially you work at. Okay, never mind. It wasn't a question. All right, I'm, I'm going back to only looking for things that start with a Q. Bearded ruckus. Bearded ruckus. Bring them ruckus. All right. With all the expectations required in the field in these times, do you think that this is to weed out some people to correct the market with all the expectations required in the field in these times? No, I don't think it's that. I think it's just. I, I mean, I don't think it's the weed out people to correct the market. I don't think the market needs a correction. I think there's more people than there is opportunities. Despite the fact that reports will say that there's more opportunities, I don't think it's the weed out. I just think some. Some organizations don't understand the value of cyber security. Right. They know they need I t. They don't necessarily understand cyber. It's becoming more and more apparent that you do need it. But I. I don't think it's to weed out anyone. Continue to look through chat. All right, so this isn't a question, but because I did like disclose casually Joseph's private journey. Thank you, Joseph, for sharing. Plus, I didn't think you would care me sharing that, so I did it. Talking about. Talking about niching down. He says what he's been doing is trying to identify upcoming needs and see whether it intersects with his interests. And that makes it easier. And of course you can always switch your niche later on for sure. Like most things that you do aren't going to be invalid or not add value to you as a professional. So that's the silver lining. All right. Oh, we are caught up on chat. Nice. If you have questions, put it in queue. This is Cyber Career Hotline. Phone lines are open. I love this, by the way, just so people know if you're a long timer. I rebranded the name to ow. I rebranded the name to Cyber Career hotline. Just so the title of the show is very obvious what we're doing here. Jawjacking did not indicate that we were helping people with their Cyber Career Hotline would suggest Q A. It also plays into like that 90s vibe. So that's why we changed it. Question coming in from Kyle. Kyle, how do you know you're ready to take the S.I.S. b for S.E.C. plus, wait until I got a 90. Yeah, I mean, that sounds like a pretty good barometer. If you can get a 90 on a practice test, go sit for it. Dude, the CIS P is like 600 bucks or something like that. Or it used to be back in my day. So, like, I don't want to just piss away 600 bucks. So I. I want to guarantee that I'm going to nail it. You know what I mean? All right. Hey, really quick, just to share another fun thing. Simply, Cybercon is coming November 8th and 9th. You can register now. Many of you are already registering. FYI, we only are going to allow like a hundred And I think 17 people at the event because, you know, obviously it's a smaller venue. If you want to learn about it, come on down. Simply cybercon.org if you'd like to speak. CFP is going to open in mid May. I want everyone to know that we only have 11 speaking slots for this year. 11. So we're going to definitely get more than 11 people submitting to speak. So we're going to do a blind review. So there will be no. No nepotism, no favoritism, no. No influence, no thumb on the scale. It will be blind review by a panel. Also, Justin Gold has done some work. Hopefully that spot. Justin, can I get an update on the sponsorship package, please? The sponsorship package is almost available. Almost ready. So if you. If your organization is looking to sponsor Simply Cybercon for sure, let us know. We also are. Somebody already reached out to me. There will be a slot for some workshops. I think we have slots for four workshops. So if you organization wanted to do a sponsored workshop, we would certainly welcome you into that. Dude. Stones fan Rob Cooper bringing the heat. This guy lived at the Sphere for fish three day concert. Like an absolute boss. Rob, how was the. How was fish, dude? Fish with a ph. Concerts, if you're interested in concerts. Charleston, South Carolina does have a couple good venues. We have this like tennis stadium, stadium on Daniel island that gets things like, you know, Darius Rucker or Chris Stapleton. We have North Charleston Performing Arts center that gets some concerts. Meh. And then we actually have downtown the Music Farm where I saw AWOL Nation live back in like 2011. AWOL Nation sick concert. A little bit of a one hit wonder, but I gotta tell you, they were a solid, solid live concert. All right, Funky Monk, you're welcome for the news. Phil Stafford says CIS P is $750 just to age myself. When I took the CISSP, it was a paper exam. Oh my God, you're old. Yes, that's right. I had to get a number two pencil and fill out a scantron test. Oh yeah, Firefly Distillery. I forgot about that Firefly Distillery. They had OAR in Dispatch, I think recently. Berlinda says, what's your coffee brand? I'm kind of a basic B Berlinda, but I just drink Starbucks French roast. You know why? I'll tell you why. I do Starbucks French Roast. Actually, not even. I used to do like I do Kirkland signature French Roast. Costco. For me, in my money, I could buy 10 pounds of it for like 60 bucks, 70 bucks. I have coffee for months. It tastes the same every day. It's good. It's good enough. So that's. That's what I drink Kirkland Signature Costco's French Roast. I, you know, occasionally when I go out to like a coffee shop to meet someone or cafe, I'll get a cappuccino or I'll get a coffee and I enjoy it. But for the most part, you know what I like? I like consistency and not having to make choices in the morning. I like to not think about my coffee. All right. Okay. So Stones fan said fish was awesome. I've been to a movie at the Sphere. It was an awful movie but I would love to see a music concert there, I'll tell you that. By the way, if you're wondering, the movie was called Postcards from Home or Postcards from Earth or something like that. It was basically like a 90 minute visual, visual experience that was amazing. But the entire premise of the movie is to make you feel like a, a parasite as a human being. So I, you know, I felt like, I felt terrible about myself when I left. Video was cool. But the thing is I grew up in Boston, dude. We had the Museum of Science Omni Theater like back in the 90s. We did domes before the Sphere was even like considered. Berg, SSJ says anyone have a portfolio or website or projects I can check out? I got one for you Berg. Come check out this. This is like hands down the number one end all, be all option. DJ B sec my guy dj b sec.com this guy right here at Berg. Check this out. Ben Cheryl aka DJ B Sec. This is his website. It is hosted on GitHub Get Pages. He's done the domain name redirect so he owns dj bsec.com. you can't see it on chat but look at this. He's got his background, he's got his security intel, he's got his YouTube, Tik Tok, LinkedIn, GitHub. Dude, nice clean look. Love it, love it, love it, love it. This guy, he's jamming, man. He's like Bob Marley, he's jamming. And Burke, he wants you to be jamming with him too. Lol. Oh also can I just share a quick fun one? Bilbo, the real Bilbo actually turned me on to like a really great band. Hold on. Yeah, check this out guys. This is your playlist for today. Revolution. If you're into like the modern new wave reggae, like stick figure Revolution is another one of these real Bilbo turned me on to these guys. If you want to just kind of like vibe out and like get some work done today but have like modern reggae on it Says rock music band. But it's, you know, if you live in a state that is like, legalized medic. Like recreational use of plants, revolution might be what you do on Saturday. It's definitely cool. I like it. All right, what else we got? I got 1 minute, 45 seconds left, guys. Christopher, Lycia knows about revolution. DJ B Sec is in the chat. Marcus Kyler's keeping my. My guy reference count. Thank you, Marcus. James McQuiggin saw the Eagles at the Sphere. Super sick. All right, guys, here we go. It is not yacht rock is. I don't know. I can't even afford a dinghy. Kyle. Kyle. So I don't know what yacht rock is. All right, guys, I'm Jerry from Simply Cyber. Hey, let me really quick give you guys some quick. If you're still here. If you're still here, I consider you like hardcore Simply Cyber community members. I just want to provide a couple updates because I did some work over. I did some work over the weekend. And this isn't to like. This is more just to make you guys aware. Let's not to scare you or whatever. We are. It's. It's April 27th. We're about to enter the summer. I have a lot, lot going on in the next couple months. Like, so much that I had to sit down with like, a paper 2026 calendar and use a highlighter and like, highlight, you know, hard commitments. I penciled in soft commitments, made some like, dude, it's gonna be bananas. It's gonna be very demanding on myself, very demanding on my family. And we will, you know, obviously everything's going to continue with Simply Cyber. Don't get sweaty on that. But I just want to make everybody aware. So will be traveling quite a bit as a family. So we're going to be going back to Georgia for a week. I may be moving to Georgia. Just so everyone knows. Like, I guess just to share inside secrets with you. I'm going to Las Vegas at the end of May for Cisco Live. I'm going obviously to Black Hat defcon. We're taking a. We take a family vacate or we take a family trip with another family at the end of June every year. So if you've been a regular, you know that I'm gonna have to get coverage for daily Cyber threat brief that week. So you'll have a guest host for a week. Details to follow on that. We're going to be driving up and down the co. The. The. The East Coast. Like, 4th of July is going to be 4th of July is on a Saturday, but I think that Friday is the third, and that's. That might be not a day. So, anyways, there's just a lot coming up. It's always busy in the summer, and I want to be very, very clear to everybody, let you all know. All right? Because, you know, yes, I run the show, and it's my thing and whatever, but. But it's a community, guys. It takes a village. And when. When there's really disruptive things, I want to be really clear and communicative with you guys. All right? Happy anniversary to Phil Stafford. So Cyber Risk, which X asks a good question. Would you move Simply Cybercon? You know, I don't think so. I don't know. Cyber Risk, which we would have to decide, like, where we're looking to move in Georgia. Like, doesn't even show up on a map. So, like. Like, bringing you guys there probably wouldn't be good. I really, like, I'm. I'm, like, excited to move, but I really love the Charleston area and Folly Beach. So if. If this conference works this year, coming at Folly beach, if it's, like, a great venue and everybody loves it, which I think it's, like, a perfect spot for what I'm trying to achieve, then, I mean, I don't mind coming back. Like, I. I would come back. It'd be a great reason to come back to the low country, so I don't think it would change. But, you know, we would be an hour outside of Atlanta, so, you know, maybe. Maybe it does. I don't know. Let's. I. We don't even know if we're moving yet, so. So, Rich. Okay, now we're in bonus time. Rich says, what would happen in the studio? So get this. This is part of the deal. Like, where we're looking. We would own a lot of land. Okay? And I already thought about this. I was talking to Mrs. Ozier about it. Like, I think what I'm gonna end up doing is building, like, one of those, like, metal space buildings. Like, it'll be like a proper studio with, like, it'll. It'll be bigger than the Buffer Ozier Flow Studio. It'll be. It'll be. It'll be bigger. It'll be better. So stay tuned for that. Code Brew is hilarious. An hour outside Atlanta could be three miles. All right, guys, thanks so very much. I've been Jerry from Simply Cyber. I still am Jerry from Simply Cyber. This has been Cyber career hotline. I hope you got your questions answered. High fives for everybody. Thanks for hanging out. I appreciate you. Foreign. We'll see you tomorrow at 8am Eastern Time. If you. Oh, by the way, I've been doing this. I still haven't got enough information on this. I've been doing this every Sunday in in 2026. Still not sure if it's working or not. But we did release a produced video on on Simply Cyber. We do it Sundays at 4pm this video is from a FBI spy recruiter. This dude is, like, super unbelievable, legit. And he basically goes through how how he recruits people and how he socially engineers the crap out of people and how you can avoid it. So the episode is called Trust no one. Go watch it if you if you missed it. It's a good one. All right. For real, though, I'm out. I'm Jerry, your chat. Until next time.
Host: Dr. Gerald Auger ("Jerry"), Simply Cyber Media Group
Main Theme:
A rapid-fire, commentary-driven breakdown of the day’s eight top cybersecurity news stories, woven with pragmatic industry insights, actionable takeaways, and a strong emphasis on real-world practice over hype. This episode intersperses serious career advice and engaging community banter.
Jerry dives into eight handpicked cybersecurity news updates relevant to security analysts, leaders, and business professionals. He evaluates breaches, attack trends, product updates, and career insights—always with real talk and a bit of humor. This episode features everything from high-profile breaches (ADT, Carnival Cruises) to emerging attack techniques (SMS blasting in Toronto) and community Q&A. The recurring motif: Protecting against modern threats requires adaptive thinking, clear communication, and the support of a vibrant professional community.
[10:48]
"Complimentary is like getting an extra scoop of ice cream at Baskin Robbins...not identity theft protection when you lose my data, fella." (15:07)
[19:18]
"Just because I can send you a bunch of text messages...so what, what is the action on objective?" (27:07)
[28:13]
"It is a good idea...to take a moment and review your overall whatever and clean it up, get rid of what's not working, tighten up the bolts that are loose..." (32:09)
[35:09]
"Get management involved so that they are in agreement, in alignment and signing off on those processes...so you empower your help desk to be able to make those good safety choices and tell the threat actors to move along, sir. Move along." (41:32)
[46:48]
[52:50]
[57:00]
"These guys are like the gang in Teenage Mutant Ninja Turtles...drinking Code Red Mountain Dew, skateboarding, eating pizza, committing crimes..." (57:56)
[59:58]
On "Complimentary" Identity Protection:
"Complimentary? Get out of here with that noise. Like they're doing us a favor." (16:12)
SMS Blaster Explanatory Tangent:
"This should be in like an Ocean's 35 sequel movie...they essentially build what, what is the equivalent of a cell tower inside the back of a van down by the river." (22:03)
On Beta Software and Technical Debt:
"You slowly start building things...and then you start getting these, like, barnacles on it." (29:50)
AI-Generated Malware Skepticism:
"You might as well try to stick like a cannonball inside of a revolver...It's its own thing, dude. You can't just be like, right, malware. And I'll be back in 15 minutes." (48:15)
Reality of Social Engineering:
"If the CEO calls and says reset my account or you're effing fired...But if management has said we, we all agree, we will never call the help desk...you empower your help desk to be able to make those good safety choices." (41:10)
[63:05–End]
[43:21] – Mondays are for “Community Member of the Week.”
This engaging, insightful episode combines practical threat insights with career-building wisdom. Jerry’s direct style, analogies, and community devotion make it a “can’t miss” for cyber professionals and new entrants alike.