Loading summary
A
Good morning, everybody. Welcome to the party. Today is Wednesday, April 29, 2026. I'm your host for Simply Cyber's daily Cyber threat brief podcast, Dr. Gerald Ozer, coming to you live from the Buffer Osier Flow Studio. I hope you're having a great morning so far. Like many others, I feel we're all vibing together that this morning came too quickly. I know time is a human construct, but sometimes it seems to move a bit faster than what I'm thinking. We got a great show for you. If you are looking to stay current on the top cyber news stories of the day while getting engaged with community and networking, maybe a little bit of entertainment, definitely education, then you're in the right place. Get comfortable, get your coffee, because we got work to do. Let's cook. All right, everybody. Good morning. I am feeling the energy coming. I. I do have to ask a personal favor of you. My. My battery is running. It's not blinking red, but it's, like, in the amber color. And you guys, this show, this energy, you always pick me up, light me up, get me going, and I needed a little bit of an extra shove today. Not so much that my head snaps back and I fall over, but, you know, kind of like, you know, one of these nudges, like, hey, hey, jerk, the line's moving. Let's go. Okay. All right, guys. Hey. Every single episode, we're gonna go through eight cyber stories. I'm gonna break them down, go way beyond the headlines to deliver additional insight and value. You can read the headlines yourself, and it's important to read it at the surface level. But there's always additional opportunities to learn and apply them both to your career professionally and to your organization to reduce risk for them, which is ultimately what we get paid for and how you can demand a higher salary. That's right. So definitely don't sleep on that. Now, of the eight stories I have researched and prepped for zero. Do you know why? Ain't nobody got time for that. That's right. Space tacos. Also on the struggle bus. I feel you, Space. Space tacos. By the way, Space tacos. I owe you that Amazon gift card that's coming. I have it on my schedule to do it. 10:15am today for you, Fleet is posting the third best friends. Yep. Giving me the shop from behind. Fleetus, thanks so much for the super chat. Hope everything's going well for you, Felitus. All right, guys, I don't research or prep for the show. This is raw, authentic, and not AI. I'm not John CENA either. This is like the current deep fake deception detection. Whatever. If you're here for the first time, welcome to the party, pal. I want you to know that we have a special emote, special sound effect and we love welcoming our first timers. Guys, you won't meet a bigger advocate and champion of the importance of building networks and relationships in cyber security to benefit your career and your overall, you know, capability to find out about opportunities, help others, enrich yourself, etc. So as part of that mission, you know, I want to make you feel very, very welcome here if you're here for the first time. Because a lot of times when you stumble into a new community, there can be like inside jokes and everybody knows everybody and you feel like an outsider and you know, who's got no time for that? Ain't nobody got time for that? Me. I ain't got time for that. So we cut through the chafe and get right to it. So if you're here for the first time, drop a hashtag first timer in chat. Hashtag first timer in chat. Yep. Go get you some dry socks for yesterday's snafu. Lol. Thank you, Kai Cipher for the super chat. Definitely appreciate it. And yes, I'll go get some, I'll get some dry, not socks, but Adidas slip ons. Let me go and refresh the chat here. There we go. All right, so I got fresh Adidas slides and some coffee from Fleetus. Perfect. And the first timers chat. You guys know what to do if you see any first timers in chat and you are a squad member, meaning your name is Green or Blue, you can have the special emote tray. And there's one in there that looks like John McLean looking down out of Nakatomi Plaza saying, welcome to the party, pal. So go ahead and drop that if you see some first timers because there was room for one more. TJ 12 months. Happy anniversary, TJ squad membership. Thank you very much. Good morning, Dream Logic guys. Every single episode, as a gift from me to you, every single episode of the Daily Cyber Threat Brief is worth half a cpe. So say what's up in chat. Grab a screenshot, you're part of the show. Dennis Keefe Berg, SS Dream Logic. Jesse Johnson, AKA the Cosmic Cowboy. Toasty Pops in the Kansas City Crew. Anvil talking about Hump day. You're all part of the show. So say what's up in chat. Grab a screenshot of that and then you'll notice Today's episode says April 29th. It also says episode 1021 or 1121. That is all to make it uniquely identifiable and forensically sound. Also, the time stamp on your screenshot's going to have today's date. If you are ever audited, you will have that evidence. That's right, ad tech CPEs for days. Come at me, bro. All right, now this show is not possible without the support of the stream sponsors. They enable me to bring this show to you every single day regardless of whether or not I have showered or not. Let's talk about them for a second. All links for sponsors are in the stream or in the description. Let's talk about this one because this one's coming in hot. Anti siphon training is disrupting the traditional cyber security training industry by offering high quality, cutting edge education to everyone, regardless of financial position. And if you want to learn how to break free from burnout, come hang out with Natalie Salman as she takes you on a ride. Ride. Slippy slide. Fantastic voyage of how to break free from the cyber security burnout trap. That's right. One hour today. Free to register. All it takes is your commitment to be there. Several like minded, simply cyber community members will be there. Natalie's gonna break it down for you, make it actionable. 1 hour noon Eastern time today so you can do the daily cyber threat brief, get some emails done. Go grab a ham sandwich, sit down and consume this. I'm going to drop a link in the chat. Just drop that. Go register. Cost nothing to register. And if you end up not being able to make it, there is no, there's no repercussions. You don't get to register for three or two webcasts a year and that's it. You're going to be spending your your bullets on this one. Nope. Go get it. Thank you very much anti siphon training and Natalie Salman for what you're doing. Also wanted to say holler to flare. Flare Cyber Threat Intelligence Plat. Whoops. Flare. Cyber Threat Intelligence platform is ultra cool. They go on the dark web, deep web and dig into, come on, dig into all of that. You know, cyber criminal underground forums, telegram channels, info stealer logs, all of it basically. And why they're doing this is so they can pull it back, put it in a very easy to consume platform. That's the cyber threat intelligence platform. This is a SaaS based app. You log into it, very lightweight, you can get started immediately. Once you have access to the platform, you can find compromised endpoints, compromised users. You guys aware how threat actors are not hacking in? They're logging in in 2026. That's not. That's not like freaking marketing speak. That's literally what's happening. Lapsis Scattered Spider Shiny hunters. That's their bag. They vish and then log in as members of your environment. So if you'd like to get an head start on compromised user accounts in your environment, that's one use case for flare. I actually have a LinkedIn post on how you can make a compelling argument to leadership to buy security or invest in security. You could use that to do flare. But wait a minute. I don't know if flare is right for me. Don't worry. Go to Simply Cyber IO Flare. Simply Cyber IO Flare now. And you can get a two week, two weeks free trial, no strings attached. You sign up, they verify that you're not a criminal or bad guy. Because if a bad guy got access to this, it'd be game over. Get in there and boom baby, boom. See how powerful this platform is? I've used it. I think it's freaking sick. Flair. Go to Simply Cyber IO Flare. And of course, long standing, long tent, long pole in the tent. You know, the platinum diamond double deluxe Cadillac package sponsor for Simply cybercon. Threat Locker. Threat Locker brings application denied by default security to enterprises and they make it work. It is not a burden to your workforce. This has always been the challenge with application deny by default. Oh my God. This stops me from doing everything. Oh my God. Emmett stinks. Well, guess what? Threat Locker solved it. And then they went from the endpoint to the cloud. See what Threadlocker can do for you today. They have massive clients, massive case study. It's. It's a really solid platform. They're going places. I'll tell you what, when they ip, I guarantee you they're gonna ipo. And when they do, watch what happens. My goodness. All right, let's hear from Threat Locker. And then I'm gonna melt your face. If there are any first timers in here, Brooks Teasley. Brooks Teasley or Brooks Steely. We're not sure. Brooke, let us know how to say it. I want to give some love to the daily cyber threat brief sponsor Threat Locker. Do zero day exploits and supply chain attacks, keep you up at night, worry no more can harden your security with Threat Locker. Worldwide companies like JetBlue Trust Threat Locker to secure their data and keep their business operations flying high. Threat Locker takes a deny by default approach to cyber security and provides a full audit of every action allowed or blocked for risk management and compliance. Onboarding and operation is fully supported by their US based Cyber Hero support team get a free 30 day trial and learn more about about how Threat Locker can help prevent ransomware and Ensure compliance. Visit threatlocker.com Daily Cyber. All right, guys, we got a first timer. Brooks Teasley, who's confirmed the pronunciation in the chat. Brooks, welcome to the party, pal. Welcome to the party, pal. I hope you have a great experience. All right, guys, do me a favor. Brooks and everybody else, it is hump day. So sit back, relax, and let's just let the cool sounds, the hot news wash over all of us in an awesome wave. By the way, guys, my battery is green. It is blinking. We can unplug the usbc. This guy is on fire. I was gonna say I'm lit, but I think that that means something else to the kids. So I'm just. I'm hype or whatever. All right, let's go. To not fall behind with the latest AI. All right, hold on. See what I mean, dude? Like, when I got the music going for the show today, I was still kind of sleepy. Jerry. So let me. I didn't have this properly done. Oh, my God. Is this show live or is he like, actually working in production? Ish. Come on, bro. Is he actually working in production? Issues into the recording? You know AI wouldn't do that. AI. Oh, my God. What do we freaking, bro, Are you kidding me right now? Hold on one second. Remove. Oh, my God. Can we not right now? I'm trying to run a show computer. Ah. What, dude, Spotify. Get your cash cleaned. You're so slow. All right, here we go. Sit back, relax. Computer. Play. Computer. I'll reboot you if you don't play this podcast.
B
The industry association said it's working with Google and Master.
A
Oh, oh, you're gonna be clever. Oh, you're gonna start in the middle of the podcast. You tricky. Okay, okay. From the CISO series. It's cyber security. All right, here we go. Relax.
B
These are the cyber security headlines for Wednesday, April 29, 2026. I'm Rich Strofolino. FIDO alliance working on securing AI agent payments. The industry association said it's working with Google and MasterCard and a pair of working groups to develop industry standards for validating and protecting payments made by AI agents. Google is contributing its agent payments protocol to cryptographically verify that a user has authorized an agent. MasterCard will provide its verifiable intent framework, which will allow users to authorize the agents. The FIDO alliance still needs to build out use cases for using both in real world deployments, then work with merchants and Payment providers on adoption and support. Germany suspects Russia.
A
All right, okay. All right, so I love it, dude. Leave it to MasterCard. Like, I love. This is so stupid to say out loud, but like, like, if I think about it, I love the credit card industry, okay? Which I know sounds stupid. Like, oh, my God, what does this guy got like, Like a Cheryl Teagues, a Kathy Ireland, and a Visa credit card poster hanging up in his room when he's 16? No. All right, and that's. I think that's a Kool Aid drink thing. I never had Cheryl Teagues, but I did have a Kathy Ireland poster and the Bo Jackson with the, the pads and the baseball bat. Anyways, the credit card industry is always pushing the envelope on security and, you know, best practices and stuff. And right now there have been numerous instances of AI buying stuff. There was like an instance of an open claw spending seven grand on training because a woman wanted open claw to help her get more developed professionally. My guy, like, if you're giving AI your credit card, you're already kind of taking a bit of a risk, okay? I'm a risk averse, dude. I'm not giving AI my credit card and saying, hey, why don't you go ham on this? Okay, Maybe I give AI a $50 gift card or debit card and you know, be like, hey, why don't you figure it out? Rogue cyber had the fair faucet one, okay? So they're, they're thinking AI needs to have some type of verification authentication. Dude, this makes a lot of sense, right? Because if you gave your, you know, if you gave someone your credit card, right? Like an admin assistant or something, or a P card in procurement, right, you'd want some type of validation or thresholds, right? Like, oh, any purchase over $500 gets flagged for approval or any purchase over $2,000, you know, some type of alert goes out whatever whatever. With AI, AI can move at the speed of business. So, I mean, Jesus, AI moves at the speed of machine, not business. Business is too slow for AI so, you know, with a prompt injection with some type of malicious supply chain attack on people's aisle. Yeah, I could see a really quick instance where threat actors are abusing credit cards again. I mean, dude, it was so hot year, you know, 2016, 2015, to steal credit cards and new credit card shenanigans. So, you know, I could definitely see AI agents being weaponized that way. So I appreciate the FIDO alliance for getting in front of this again. Love what they're doing. And I, I don't know about you guys, but like, they, the credit card industry is so good. Like back in the day, back in my day, you know, like mid-2000s, you would get like credit card fraudulent charges and you'd have to find them, then you'd have to call and dispute them. It was a big pain nowadays. Like, dude, I had someone buy a Groupon. Do you remember Groupon? Someone bought a Groupon. Like, I don't know, three years ago I went through a drive through somewhere in the middle of nowhere, North Carolina. And like an hour later, like the, the person who took my credit card at the drive through definitely stole my credit card. And they bought a groupon for like 30 bucks. And it got flagged as fraud. Not a fifty thousand dollar jet ski or something like that, a 30 Groupon. And I make purchases. I live on the credit card, right? So the credit card industry is awesome at detecting these things. And you know, this is just another way to go now. Now I will tell you this. If you are taking credit cards as part of your business, likely you will not have to do anything with this. Chances are that the payment card industry will kind of handle this internally on the processor side. But you may want to be informed on how AI is being, what structure, what standards, what protocols are being brought to payments around AI and AI purchases because it could impact you and you want to be on top of that also, for real, you want to be the guy or the lady bringing this to your business, right? Like, oh, hey guys, I want you to know this, this and this. Like, be, be a value add to your business. Final thing I'll say about this because I do like adding additional value to everybody here. It. Listen, I, I've worked in industry like 22, 23 years or whatever it, it, I heard it my first year in, in, in industry, my first year in corporate America. Oh, you've got to understand how the business works, Jerry. You got to understand the business. And, and, and I always said, okay, yeah, you're right. But internally I was always like, dude, my job is to secure stuff. Your job is to per, you know, process payments. Your job's to sell crap. Your job's to lead this business. I don't need to know how the business works. I see packets come in, I block them. I see you click on something stupid, I come talk to you. Okay? That's my job. It only took me until like 15 years in. I'm serious, like, it took me forever to really understand and appreciate when you understand how the business really works. Like, how does it make money. That's where you can inject yourself and be able to really introduce nuance, risk mitigation and nuanced business enablement. It's, it's a game changer. Plus the executive teams, they know how the business works. And if you're talking to them about like, oh, you know, we gotta, we gotta do this thing because it's risky, or threat actors, they don't give us about that. They care about money. So when you can talk like you understand how the business works, you actually get their attention in their ear. It's super valuable in signal phishing.
B
A spokesperson for the German government said Federal prosecutors began investigating phishing attacks against the secure messaging service since mid February 2026. Roughly 300 signal accounts tied to political operatives were compromised by receiving faked suspicious activity notifications, according to a reporting by Der Spiegel. Clicking on these messages would link their account to an external device. While Germany suspects Russian involvement, it did not officially attribute the attacks. This mirrors a warning from the Dutch government last month.
A
Rc all right, listen, Signal is a secure messaging app, okay? And a lot of, you know, important people with important conversations, very sensitive things, very secretive things, very security related things are using Signal. In fact, here in the United States, I think it was CISA or the NSA or somebody like, you know, whatever, executive branch, whatever came out and said you should be using secure messaging apps. This is when China was all up in the ISPs and people had like, I don't want to call it a knee jerk reaction, but people were like, oh my God, like China's in the ISP is used secure messaging app. Signal, as far as I know, is the only one that's like, I mean it's the most secure one, it's the one that's the most widespread, the most popular. Remember any of these apps are only as powerful as the network, right? You could have the most awesome secure messaging app on the planet. But if you're the only one who has it installed, guess what? Not going to message anyone because there's no, like, no one else has it. So that is not a valuable messaging app. It's the value of the app is in the size of the network using the app. Now this is a, like the, the TLDR here is if you are, educate your VIPs, your executive team, if they're using Signal, that if they get some random message with a link in it from a person they don't know, don't click on it, all right? That's the period, full stop, okay? So educate your end users. Now, let me tell you something else. Let me tell you something that will help enrich you as a cyber security professional, because this doesn't come up very often, and I'm super pumped that this came up in this one. When we are looking at risk. When we're looking at risk, okay? Or, you know, attack vectors, attack surface exposure, whatever you want to call it. There's only three things. Welcome to the party, pal. I'm going to demystify everything for everyone right now. Welcome to the party. There's only three things you can attack. You can attack technology, you can attack people, and you can attack process people. Process technology. That's it. Okay? And you can come at me with what about. What about physical security? Yeah. I mean, what part of it Are you lying to a guard because you're dressed up like an a. T That's attacking the human? Are you doing the thing that John Connor did in Terminator 2 where he puts the ATM card and then does his magic thing on his. On his McGuffin and unlocks a door? That's attacking technology, right? Are you understanding the rotations of the guards and then jumping in when they're on the other side of the building? That's an attack on process. So don't come at me with your nuanced examples. It's going to fall into one of those three. Now, why I bring this up is because this is an attack on process, and usually attack on humans and tech are the common ones, just like confidentiality and integrity, or, excuse me, confidentiality and availability of the popular security objectives. And integrity is like the, you know, the bastard cousin who doesn't get enough airtime. Right? It's like Tito Jackson of the Jackson 5. Like, integrity and process are. Are the ones that aren't getting the love. Yeah, I went there. Tito Jackson, let's be real. We all know Tito got hosed. Okay, so with this one, signal allows you to add an additional device. I have signal on my workstation, I have signal on my laptop. I have signal on myself, cell phone. I have signal on a ham sandwich in the house. Okay? I got signal for days. And when you add it, you have to, like, approve it. So what they're doing is attacking the process by setting up another device that the threat actor controls, sending the confirmation link to the victim, and then the victim falls for it. And now all of a sudden, threat actor has access to that individual's signal account. Okay, now this is a little bit of attack on human because it is social engineering. The victim but the process of how you can add an additional device is the root cause of this attack. So be mindful. I don't know can my ham sandwich run Doom obviously so funny. Kai cipher. So all I would say is I do not know if, if mods or anyone, if anyone can confirm this. I. I don't know if there is a way to verify. There has to be. But how, how many device, what devices are connected to your signal account? Right, because the thing is if a threat actor does this, they would probably, I would imagine, have the same access that you have. So they can see that they're there, they can see what devices are there. They might be able to remove devices. So signal is not a centralized enterprise solution. It is an individual like P2P solution. So a peer to peer solution. So it's very difficult to manage at, at an organizational level. So just be on the lookout for that. Also
B
Tito E flaw, an open source robotics platform a GitHub advisory disclosed details on an untrusted data deserialization flaw in
A
hugging Buston Justin says isn't Signal compromised by the CIA? Justin, I don't know if that is a satirical comment just being funny or if you truly believe that or have some information, put it in chat. If there is some information on that, let me know and we can bring it up really quick. Mods are bringing this to my attention. You can view linked devices on signal. We have both. Oh yeah, you can see right here I'm showing it on stream. I'll drop a link in chat again. If you're watching on replay you might not get these links but you can see here it says no linked devices in the screenshot. The screenshot is showing what your device will look like if you look for you go to open your phone, open signal, navigate to signal settings, look at link devices. That's what it is. You can unlink devices is how you would unscrew this attack. But again, threat actor may or may not be able to do that. Also mods, can you keep an eye out for Buston, Justin and the CIA compromise? I hadn't heard that before.
B
ACEs robotics platform Le Robot which could allow for remote code execution. Researchers at RE Security said the flaw is in the Async interface policy server component that allows an unauthenticated attacker on the same network to send a malicious serialized payload to host machines. This doesn't appear to be completely new, with a researcher disclosing the flaw back in December 2025. The flaw remains unpatched with plans to fix it in version 0.6.0. According to Lay Robots Team, that part of the code base needs to be almost entirely refactored, as its original implementation was more experimental.
A
Oh, there we go. Oh, my God. So here's a. Let me. They Let me. Okay, let me go quickly through this because the, The. They buried the headline. You want to talk about a life lesson? A lesson that I am going to drop on your face. And by the way, anybody who's got gray in their hair or basically looks like, you know, you've worked in cyber for two years, yet you look like Yoda because you've aged, like 40 years, you are going to want to scream preach when I give you the buried lesson learned here. All right, so listen, if you're running Le Robot, if you're running Lay Robot hugging faces Lay Robot, there is a CVE that can. Can screw you over. Where untrusted data deserialization stems from the unsafe pickle format. Not to be confused with Pickle Rick, but anyways, yeah, it's just, It's. They're handling data input or they're handling data transferring around in a insecure way. They didn't do validation or clearing on it. They. It. This is. It says RCE Remote code execution. Okay. Rce Remote code execution right here in the title. Unauthenticated rce. Unauthenticated. RCE is the worst. But. But I do want to point out it's not true. Rce, okay? It's Unauthenticated network reachable attacker. So, my guy, you got to be on the same land. You got to be on the same local area network. Now, if you're running, like, a, A quake, you know, land party in the back of a brewery, then, yeah, someone's gonna be able to pop your le roba. But, like, I don't know, like, this is something you want to get patched, obviously. Ah, you gotta patch it. But, like, I'm not, I'm not losing sleep on the. Whoa. Oh, stop. Hold on. I wasn't prepared for that. I, I, I, I, I gotta run in the house and put it on some deodorant. I, this infographic has. Hold on one second. Wow. Go. All right. Hey, Brooks Teasley. Just in full disclosure, I have an unhealthy obsession with good infographics, and this one checks the boxes. All right, let's see what Lay Robot does. It enables robots to use AI policies running on remote GPU servers. Robot sends observation. Basically, this thing just offloads processing to some type of engine offline. This is not inventing the wheel here. Guys, like, instead of. This is how tech works. My guy, like, the robot is doing stuff here, and then instead of doing the data processing locally, it does it in the server. This is, like, this is how a lot of AI works. Okay? So great stuff. Chances are, if you're running it, you already know about this. Go update it. I don't even know what happens. Maybe your research gets compromised if you are using this and you get picked. But I. I don't think it's a big deal. Okay, so let me. Let me activate everybody's ptsd. Everybody's PTSD is about to get triggered. And if you don't know what I'm talking about, consider yourself lucky to be here today, because I'm about to reveal something to you that you can get in front of before it runs you over like a runaway train. Okay? What they said about this is this thing is not really secure because it was originally developed as an experimental concept, yet 24,000 people started. It's deployed in multiple places, and it's off and running. Let me tell you something, okay? This is so real. So many times in your life, you will encounter this situation. Hey, we're thinking about doing this thing. Or, hey, I was tinkering this weekend, and I got this idea, and it can do this thing, right? So people will, like, half bake a solution. It costs nothing. I do it on Friday afternoon. The businesses are charging 50 grand a year to do the same thing. But I built it in house. It's fine. Look at it. Okay? And then people were like, oh, let's try it out. Let's try it out. Oh, yeah, look at this. This does work. Oh, it's just. It's just something I whipped together. Oh, it's just something I. I spun up on the weekend. Okay? I don't even know why I'm using that voice, because I feel like it's always the person who's, like, super eager to contribute and innocent, and it's not malicious by any design. But here's what's going to happen. If you're a cyber security person, you should do everything you can to smother that thing, okay? Because what's going to happen is you're going to be like, hey, how. Like, what are we doing here? How's authentication work? How's auditing work? How's backups work? Who's touching this thing? Where's it going? What are you doing? And they're going to be like, bro, why are you harshing my mellow? I'm literally just doing this Tinkering thing over here. And what's going to end up happening is it's going to freaking work. Business is going to be like, this is awesome. We paid nothing for this. This guy worked all weekend on it. We're making money. Great cash, homie. Then it's going to become a part of critical infrastructure. Then that is going to be a wicked, insecure, gross attack surface. And it's just my tinkering. He's going to quit and leave. And now you have this ridiculous, janky, cobbled together POS critical application all jammed up in your thing, and there's going to be no support plan, no maintenance, no deprecation, no sun setting. And when you try to go make an argument that we should probably buy an enterprise grade solution to do this thing, manag is going to be like, why? This costs nothing. It does the thing. Why are you trying to be, like, such a jerk? Maybe we take it out of your budget, Jerry. Would you like that? We'd be happy to replace it if you pay for it. And then you're going to turn into Skeletor. And just like, trust me, you do not want to walk down that path. You. If you walk down that path, bring a shovel. Because when you get to the end of it, you're going to want to dig a hole and get in it. All right? Oh, my God. The trauma bonding is real. No, no, no. Not now. Not now. Midnight. That. That. That was too traumatic a story to share. The saxophone is not appropriate right now. Oh, yeah. Oh, Okay. I didn't even know we had this. Of course we have an emote for this. There we go. There. This is. This is. This is what you're gonna look like two years down the road. What the. The only way you're gonna get out from underneath it is quitting and going to work somewhere else and hope to holy God that they haven't done the same thing. Dude, I'm not going to tell you the business, okay? I'm not even going to tell you the business. But I work somewhere where this exact thing happened, okay? And it was running on a machine under the dude's permissions. The guy. The guy died. All right? I mean, you know, condolences to his family, okay? Like, he. He died. No one knew how the damn thing worked, his credential. No one knew his creds. Like, so it just. They just put it in a room, like. Or, like, basically his office and, like, just closed the door. And, like, that just. That just continued to exist. It was there when I quit. When I quit that business. It was still running f. All right.
B
Privacy fines and scam losses spike. It's a tale of two figures. On the one hand, the U. S. Federal Trade Commission released a report finding that Americans lost US$2.1 billion in social media scams in 2025, eight times higher than 2020 losses. Social media accounted for 30% of all scam losses in the year. Meta platforms, unsurprisingly, took the top three spots with Facebook seeing $794 million in scam losses and Instagram and WhatsApp combining for 629 million in losses. On the other side of the coin, gartner reports that US states issued $3.45 billion in privacy related fines in 2025, more than the last five years combined. Some of this comes from more active enforcement of the California Consumer Privacy Act. But Gartner also cited the consortium of privacy regulators formed by 10 states last year, leading to more coordinated enforcement and now a huge.
A
All right, so dude, I mean, what a time to be a criminal, right? Like, hold on, do I have this? We are living in the golden age of online scams. That's my flaming donkey voice. The advanced persistent threat actor that we're trying to manufacture and get into. Miter attack Brooks Teasley and others who haven't heard the flaming donkey voice. All right guys. Dude, people are making bank on scams. It, you know, in 1920, you know, it was boiler rooms and online and stock market fraud, Ponzi schemes, etc, dude, as long as someone in this world has a dollar, there's someone else who's going to try to grift it off of them. And online they make it so easy. Go look at these Cambodian like essentially like slave labor camps and the pig butchering scams. Look at all these like lookalike sites. You know, all the, like my. It's so. People steal money all the time, dude, and we're talking $2 billion. This isn't petty crime. This isn't taking someone's fraking, you know, recycling cans and being like, I stole you 35 cents in recycling. No, this is a multi billion dollar industry and it's going to continue to happen. And by the way, this is attacking your mom, this is attacking your uncles. Like, this is attacking your kids. Like, this isn't. Oh, looks like Amazon got hit for another million dollars. Wham wham, like cry me a river. Yeah, yeah, you know, Fortune 5 company. No, this is like attacking elderly people, lonely people, you know, marginalized people. Like this is gross. So be the person. Oh, airdrop. Welcome to the party, pal. All I'll say is be the person in the room who's trying to help other people out. You know, don't be a wet blanket at Thanksgiving. But sure, let people know, you know what I mean. Share it with them. And by the way, if you're going to educate people on scams and dude, rogue cybers in chat, Brian Bushwood. He ran scam school or he runs scam school. The best way to educate someone on how to protect themselves is by showing them how it works. If you describe it, fine. If you show them how it works, boom. Right? And if you want to be like Brian Bushwood, have them perpetrate the attack as the attacker themselves. They'll definitely learn. By the way, Brian Bushwood's going to be coming on simply cyber firesides in a couple weeks to talk about literally this topic, which is awesome.
B
Thanks to our sponsor, Guard Square. Is your mobile app truly protected? Relying on the OS isn't enough. A global study of 1300 security and developer leaders found that 96% of teams using layer protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern security risks. Learn more@guard square.com all right, ransomware gangs still going at it. Earlier this month we reported on the group 0APT putting the ransomware what the cry bit on its leak site.
A
Dude, something's up with Spotify. This computer needs a reboot. Like I need a, you know, I don't know, what do I need? Like I need a pack of secrets of Strixhaven collector's booster to open up. You know what I'm saying? We all need it. All right, so let's do the mid roll. I'm gonna do a different song so I don't have to clean up the copyright later. All right. Hey, guys. Shout out to all y'. All. I want to say thank you very much for being here. Shout out to the stream sponsors Threat Locker, Anti Siphon and Flare. Always bringing the heat. Roswell, uk. I don't know what's going on, but a lot of people saying that you're doing well. So I'm. I'm glad you're doing well. All right, guys, thank you very much for being here. We're at the mid roll every single day of the week as a special segment and Wednesdays is way back Wednesday where we just look at a piece of tech from, you know, history from a. A bygone era and just kind of vibe on it for a second. It's a little fun thing. You youngs wouldn't know. I think casually Joseph didn't exist at the time. He probably did, but I. I like to point it out. Let's. Oh, yeah. Silver Quill. Hell yeah. All right. Hey, listen. Today's way back Wednesday tech. I never had one. I made fun of people that had it. The Windows Phone. The Windows Phone. Guys, listen, I'm not, I'm not joking, man. Microsoft made a play at the mobile phone market. There was Android, iOS and Windows Phone. My friend Matt Jones, Jesse Johnson, you can, you can make fun of him for this. My friend Matt Jones was a die hard Windows Phone user and he said it was a great, great phone phone, awesome device, amazing camera. The problem is they didn't have an app store that was really well produced. They didn't have the support of the applications. And you know, I. Apple and Android just destroyed it. So this is an example where even if you have a great product, it fails sometimes. So anyways, I feel like it's the movie. It's the movie. Gladiator with Russell Crowe. And Windows Phone entered the arena with Android and iOS and then like immediately iOS took a trident and just jammed it through Windows Phone. But Windows Phone, we salute you. All right, so there you go. There's your Noir Cypunk. Yeah, I made fun of everyone that had one too. To me, it's like if you owned a Windows Phone, it's because you were trying to be like, like ira, like, un, un, un. What is it? What are the people with the curly mustaches, like, unironically ironic or something like that. Like, it's like you were trying to be different. Whatever. We. We'll never know. The world will never know. Okay, stay tuned for the Microsoft Zoom. But yeah, Windows Phone. Jesse, if you just kind of slide it into a conversation about how it sucks, you'll watch Matt Jones's eyes light up. He'll also know that I told you.
B
On its leak site, publishing information that partially docks the group. A new report from Halcyon found that Crybit responded by hacking back 0APT site, defacing it, and leaking 0APT's full operation data set with full access logs and PHP source code and system files. This revealed that the initial victims published by 0APT in January 2026 were completely fabricated. So far, 0APT has been unable to recover its site.
A
Oh, man, I love watching criminals just cannibalize each other. You know what I mean? Like, this is a win for our team. Team good guys, right? You know, if you see Cobra And Zartan and his crew fighting internally. More power to you. The friend of my friend or the enemy of my enemy is my friend. Right? As I don't know, Dick Tracy put it, I can't believe the movie Dick Tracy was so successful. You want a, a snapshot of why the 90s were, like, weird? The, the. The. Dick Tracy was like a huge movie. It's. I don't think that movie held up very well. All right, the one with Warren Beatty. Okay. And Madonna. All right, so we got two threat actors going at it Cry bit who hacked back at 0APT, stole their data, defaced their website, and then said, next time don't play with the big boys. Guys, this is 100% on, right? Like, listen, I've been saying this for a while now, and again, I don't. Mods. Can you check Crybit and zero Apt threat actors? Is there any evidence to support that they are young, like ages 20 to 26 years old? Because I bet you they are. If I had to guess, Ransomware groups are attacking each other. Honestly, guys, there's so much. There's so much. Here's my thing. There is so much, like, think from a threat actor perspective. There is so much fish in the sea. There's so many businesses. There's so much attack surface that they don't need to fight each other because it's not like they're all competing to attack the same three businesses. There's no reason for them to attack each other. So they're doing it more out of, like, prestige and out of like, turf. You know what I mean? Like, like, oh, this is like my area and I'm better than you, so like, back off. So, but again, like, it's great to see them doing it because it helps us as defenders. Also, it's possible, you know, Cry Bits infrastructure and personnel got leaked, which means law enforcement can use that regulators to get that, to get that information out there and get after him. So again, this doesn't really. I mean, what I would say is whether it's Cry Bit Everest, you know, Black boss, that eight base Medusa Lock bit, like, whatever, it doesn't matter. Like threat actor. Ransomware. Threat actor is ransomware threat actor. Law enforcement's doing their part to round them up as best they can and do takedowns of infrastructure. We have to do the best we can to protect from ransomware attacks and detect them when they happen. And I know ransomware threat actors will tell you when they've done it. So that's your detection. But if you can get in front of it before the serious impact happens, I. E. You find out about a compromised account, you find out about ransomware deploying on a device, you see data exfil going on and you intervene. You can like. It's basically the equivalent of like bleeding out and like putting a tourniquet on it. Like the sooner you can do it, the better outcomes you're going to have from an overall blast radius. Okay, so, but anyways, this is great. We've seen this, by the way. We have seen this before of these criminals kind of turning on each other. Famously Conti ransomware gang, which was a prolific, you know, varsity, you know, premier league level ransomware threat actor, was half Russian, half Ukrainian. When Russia invaded Ukraine, they imploded and they, you know, the Ukrainian side of that criminal enterprise disclosed everything about Conti. It's a. It was. It just. It devol. It dissolved that entire group. Although again, they all had the skills. So you know, them spinning back up. Isn't that very hard? If you're interested in learning about that particular case study, Brian Krebs did an amazing, essentially aggregation and then reporting on those a couple different. He did the parts. A couple different parts. You can see if you're listening on audio only because this show is available on Spotify and Apple podcast. If you didn't know if you prefer to get this audio only while you're on the elliptical, Marcus, or you're mowing the lawn or you're driving somewhere, whatever, it's Krebs on security. And then look up Conti Ransomware group diaries. This is from March of 2022. You can see this aligns with Russia invading Ukraine back in 22 2. If you can imagine it was four years ago. Holy crap. That that war's been going on. But this, this breaks it down. I'm talking hundreds, 100 employees, different departments. They had an HR. This was not a ragtag group of thugs in the basement. This was like a criminal enterprise.
B
Korea targets crypto firms. Researchers at Arctic Wolf found that the Lazarus Group affiliated Blue Noroff team conducted a large scale spear phishing campaign against over 100 cryptocurrency organizations. First observed back in January, these attacks used typo squatted zoom meeting links sent through manipulated calendly invites going into the meetings would capture their live video camera feed and their deploy a clipboard injection attack that attempted to exfiltrate crypto wallet details. This appears to have been a long con with attackers taking up to five months to deploy after initial contact. Once the attack took Place researchers found they retained access to systems for an average of 66 days. Vimeo blames.
A
All right, so the screenshot. The screenshot here looks like, you know, a telegram message channel. All right, so I'm just looking at this really quickly. Arctic Wolf is an mdr, managed detection and response service provider. They do have tons of telemetry and insights to pull from. Okay, Now, Lazarus Group is a long known crypto focus ransomware threat actor. They're known for the Bangladesh bank heist where they tried to steal a billion dollars, literally, from the country of Bangladesh. They succeeded in getting $81 million. They've also attacked multiple crypto exchanges. One, I can't even remember, it was like, last year. One of them, they stole like, $600 million from. Well, they, they definitely robbed the Axi infinity Ronin Bridge two, three years ago for like, $600 million. They, they, they, they attacked some platform last year where the platform actually introduced a, like a, a bounty if you can get their money back. It was kind of cool. I forget that. But North Korea, this is what they do. This is how they fund their regime. And this one's interesting. And, and I want to pull your attention to this. This is why we do this every single day, guys. I want to pull your attention to this. Most social engineering, you know, malware, like, you know, kind of involved com. Complex attacks happen fast. Okay, so here's a click fix attack. You fall for it, I get your creds, I log in, or I trick you into installing malware. I get in C2, and then I, you know, start dumping stuff and moving quickly. Right? Unless you're doing espionage where it's low and slow, rotisserie style, and you want to be in there and be quiet. If it's financially motivated, it's kind of like smash and grab. Okay, this one is a change in the ttps, which is interesting. Ttps are hard to change, and North Korea is doing it. This is an attack that takes months to perpetrate. And honestly, guys, if I was going to steal $500 million, I'd do it over a course of a year. Why not? You know what I mean? I'm going to be retiring after this hack. Again, I don't commit crime. I'm just saying. And please, I don't condone or promote committing crime. So what do they do? It's. It's a combination, guys. They do spear phishing and typo squatting, fake meeting invites. They use AI lures, they're using click fix attacks. So initially, there's an Initial click during a fake meeting to a full system compromise in five minutes, which is bananas. So they have a attack on a victim. Let's see. The victim's internal telemetry revealed a multi stage execution chain initiated through a typo squatted zoom meeting link. So they have a fake zoom meeting link that they send to you, and then they have a manipulated calendly calendar event. So hey, jump on my calendly, you fill out the calendly, you get the meeting invite with a little zoom link. The zoom link is malicious. When they click the link, they're given a fake zoom meeting interface. That means the threat actors are developed code to present this. That interface exfils their live camera feed and uses as allure in future attacks while simultaneously deploying a click fix style attack which has them run PowerShell on their own machine. Then they get credentials of the victim, and then they go looking for crypto wallets and crypto extensions on the device. What's particularly gross is once they get initial victim, then they use that actual credentials to then perpetrate the attack further on pretending to be the victim. So imagine if you will, let's pick DJ or Justin Gold. Right? So, well, hold on. Justin Gold's got the bitcoin, I don't. So I fall for this. They get my stuff, they figure out that I don't have any crypto except some worthless NFTs. And then they say, okay, well, he knows Justin Gold. So we'll reach out to Justin Gold as Jerry, because we have Jerry's credentials. We can look like Jerry now legitimately, and then send the same attack to Justin Gold. Justin Gold falls for it because he's like, oh, it's Jerry. Of course, this probably has to do with the Simply Cybercon sponsorship package. And then boom, they own Justin Gold. And then they're driving 85 on the highway, top down, screaming, money ain't a thing. All right, so what do you do for yourself here? Number one, educate. Educate your end users around. You know, like getting invites through messaging, apps for Zoom and Calendly. Right. Number one, these will look like legitimate incoming meeting requests and stuff. So it's not like it's gonna look like, you know, scary with a dark hoodie or, you know, hi, this is a North Korean. I'd like, I'm pretending to be Jerry. Can we have a meeting? Like it's going to look legit so very real that it could fall for that. There is a click fix attack as part of this attack. So definitely either prevent your end users from being able to run PowerShell through the terminal or capture when PowerShell is being run or well and educate them that they should never open a command shell or hit start, run and then paste in PowerShell. All right. This is going to be a defense in depth approach. Also they're tagging crypto firms so like me and you are probably fine. But if you work in fintech you are absolutely a target and you should be educating your workforce about this and
B
a dot Breach for Incident Vimeo confirmed reports that some of its user and customer data leaked, saying this came as a result of a breach at the security analytics company Anodot. The leaked data included technical information on accounts and video titles and metadata, as well as emails. No video content or payment information was impacted. In response, Vimeo disabled all Anodot credentials and removed the Anodot integration with Vimeo systems. Shiny Hunters added Vimeo to its leak site earlier this week and claimed that its breach of Anodot enabled the theft of Rockstar Games data earlier this month.
A
Med tried all right, this story's been like rehash several times, so I'm not gonna, you know, like Vimeo is now one of the victims. But like this is the Shiny Hunter breach. They got a bunch they added to their leak site. If you're a user of Vimeo, your data's been leaked. I don't think it probably not the passwords. Yeah, I don't see the word password here at all. So like your Vimeo account is probably secure. You likely have an uptick in activity in social engineering, potentially phishing emails around Vimeo, but for the most part all they got was technical data, video titles, metadata, things that like, honestly you could probably just scrape anyways. They got customer email addresses in some instances. Again, you should treat your email inbox like a hostile environment. Okay,
B
Medtronic Confirms Attack the medtech giant confirmed unauthorized access to its systems after the threat group Shiny Hunters, you may have heard of them, just a minute ago listed it on its leak site. Medtronic did not confirm any actual data loss, saying its customer networks remain separate from its IT systems. Shiny Hunters removed Medtronic from its Leak site on April 21, indicating it may have paid a ransom. It claims it obtained over 9 million records with personal information and and terabytes of corporate data.
A
Dude, Shiny Hunters, I mean all you got to do is like go find the person buying the Lamborghini with a duffel bag full of cash in like Eastern Europe and you probably found yourself the Shiny Hunters. These guys, in my opinion, these threat actors have absolutely put them on the radar of like international law enforcement. They are, they are like the Bonnie and Clyde of ransomware threat actors right now. Like they're like every attack it's like a 50, 50 shot that it's Shiny Hunters doing this work. They are, they are just going ham on all these things. Medtronic is a huge healthcare medical device company. I will tell you, like Medtron, at least in my experience back when I worked back in healthcare, like I'm pretty sure like Medtronic does a bunch of different medical device stuff, but it's like nothing you can really secure. Like you just put it on the medical device VLAN segment and you know, hope is, is what you gotta go. They do say that one thing that Shiny Hunters has done here is took them off the leak site, which they said suggests Medtronic did pay the ransom. Good on Shiny Hunters. Even though they're criminal and they're, you know, obviously deplorable, they do have integrity in the sense that if you pay the ransom, they pull you down. Right? This is good for their business, right? It reinforces that, listen, we'll stand by it. If we get paid, we will take it down. Now Medtronic, their data is still compromised. So Medtronic still has to notify impacted individuals. Medtronic still has to, you know, do lessons learned and tighten up their ship and all that stuff. It's not like Medtronic just to gets to cut a check and all their problems go away. They just cutting a check has fewer problems for them to deal with as always. Holy Jesus. Medtronic has 95,000 employees. My guy. Now they do say they don't see any impact to their products, safety connections to their customers, etc. Probably was their IT corporate IT environment. Yeah, the networks that support our corporate IT systems were the ones compromised, so. Plus dude, Shiny Hunters doesn't want to get into route into medical devices and dink around with that. Shiny Hunters is into getting large swaths of data and then getting paid straight cash, homie. Straight cash, homie.
B
AI AGENT leads production database again. The founder of the car rental SaaS platform PocketOS Yair Crane posted on X that an AI coding agent from Cursor deleted its production database and all volume level backups in a single API call to Railway, the company's infrastructure provider. The action took about nine seconds. The Cursor agent was attempting to resolve a conflict by deleting a storage volume on Railway using an API token that it found in a completely unrelated project. This saw multiple failures of oversight. The Agent specifically didn't follow established safety protocols. And the Railway API didn't properly document that it could delete all data with no confirmation. Railway also stored its backups on the same volume as the primary data source. PocketOS was able to restore from a full three month old backup.
A
All right, couple things here. Number one, they had a three month old backup that they were able to restore from. Remember this? Okay, yeah, of course. Shall we play a game? Couple things. Number one, three month old backup means three months of work, three months of data, three months of transactions, three months of performance, three punts of investment gone. Like, you know, like, I mean, this is basically better than nothing, but they are definitely suffering now. 2. Claude deleted everything in nine seconds. Listen, I'm all about AI, but guess what? When you unleash the Kraken, all right, you can't guarantee that the Kraken's not going to take a tentacle and slap you as well. AI guys, people are going so YOLO with AI that like this happens. I, I don't, I don't, I don't blame them, okay? I don't blame them. I don't blame them. But, but when you put this much power into the AI agent and you have no idea, like you're just letting it loose in the, in the man, you know, in the chocolate factory, you don't know what's going to happen. Imagine if Willy Wonka just didn't enter the factory and he just told the Oompa Loompas to go ham. He's like, just make a bunch of great tasting chocolate. I'm going to be up in the clock tower over there doing whatever Willy Wonka does, right? You can't guarantee what they're going to do, right? So my whole point is this is why you need a human in the loop. Also to set parameters. They did say it bypassed security guardrails. How about you say you're not allowed, straight up, you're not allowed to delete backup databases, period. Full stop. If you are about to back delete a backup database, you need to stop and ask someone if this is okay. I will tell you this. One of the problems, Phil Stafford does blame them. One of the problems with all of this is it's very difficult to think of every single scenario that could come up where you would want to put a human in the loop with these AI agents. We are in the very early, you know, exploratory phases of AI and AI agents and all that stuff, so. But this one to me is like so obvious, like deleting your backups. Maybe we don't do that. Maybe that is something that AI agents don't have permission for. Exactly. How about not having the API have access to delete a hundred percent? Okay. But no. When you give. When you hit right click and give them God mode permissions so they can do their thing and you can just go sit on a beach and pretend you're working. This is what happens. If I'm not mistaken. Let me, let me see. There's actually a. A scientific term for this. Here we go. There is a scientific principle behind this. You should take it forward. It's the old fafo. You might learn about this in your multivariable calculus. This is a computer science term. Very professional. If you are listening on audio only, I'm showing that classic linear graph with find out on the Y axis or the X axis. The Y AIs and around on the X axis. The more you f around, the more you find out. And you'll notice in that top, top right quadrant is where you give AI agents all the permission and you step back and go hang out somewhere else, you're gonna get punched in the grill eventually. So, yeah, thank you for this. I think Richard Feinman actually developed the original f around find out principal. Let's go. All right, we are at time, Guys. I gotta tell you, I felt like I was dragging my butt in here like a dog that had a dingleberry. But now I am straight booming. I'm feeling great. You guys did it. Thank you so very much for bringing the energy. This was simply Cyber's daily cyber threat brief podcast episode 11, I think 21. Don't go anywhere because we got you covered. The show does not end here. If you got cyber security questions, I've got answers. Welcome. We're going to be kicking off the Cyber Career Hotline. Phone lines are open. I'm gonna be your MC Wolfman Jerry. Jerry Guy coming to you from Miami. So listen, guys, thanks for being here. If you got a bug out, I got you. Have a great Wednesday. Until next time, stay secure. If you can hang out, we're gonna do some jawjacking or we're gonna do some cyber Career hotline. Excuse me. I'm still getting used to the change. Hotline is open. Phone lines are open. Let's go. I'm Dr. Gerald Osher. This is the Cyber Career Hotline. If you're building a career in cyber security, this. This show is for you. Let's get into it. Hey, what's up, friends? I'm Jerry Guy coming hot on the heels of the Daily Cyber Threat Brief hosted by that nerd, Dr. Gerald Oer. Can you play less saxophone for infographics, my guy? What do we do here on Cyber Career Hotline? You put questions in, I give answers. Wade said, first of all, what's up, Wade? Good to see you in the chat. Resurfacing after a little downtime. When you say check your email, are you serious? Are you talking to me? And then if you are, which email? I'm. I'm. Now I'm looking at my email. Wade Wells, if. If you are not having a good time because I'm checking email right now, you can direct your vitriol to Wade Wells waiting through logs and chat as I continue to check my email. I checked my personal email. Now I'm checking my work email. I don't see anything from Wade, so. Okay. All right, back to it, y'. All. Le Robot. That's right, my guy. I've really been enjoying the my guy stuff. Question. Here we go. We got a couple questions coming in now. Have you ever heard of GRC Playground? Oh, actually. So Kyle, this is a. Dude, Kyle is like co hosting the show right now. So check this out. Look at this. I got you, Kyle. This is a GRC playground. Ashley Pierce put this up. This is like a GRC engineering hands on lab thing. I checked this out. I thought this was so cool that I literally went to the LinkedIn. This is how networking works, everybody. I went on LinkedIn and I literally. You could see it right here. Come on, Ashley, my guy. Come on. Look, I literally went on and said, hi, Ashley, I'm trying to connect with you. I want 20 minutes of your time to meet. Here's a quick video. I made her a loom video and I explained that I want to make a video for Simply Cyber. Going through all the labs, explaining the value, showing everyone exactly how to use this playground step by step. And she hasn't replied yet, but I'm hoping she does. Dude, look at this. I can't. Like, I can't. I maxed out my connections on LinkedIn. I can't connect with anyone, which sucks. So anyways, yes, Kyle. The long answer is yes. I. I think it's cool. I did run into a. A small issue with Scope on the binaries, but it is great. So Soulshine says, where are you with your GRC Engineering classes or studying? So, great question. Soul Shine. For those who don't know, I was going to spend the back half of April working on learning AI and taking classes from Anthropic I'm still in the middle of that and I was going to take the anecdotes GRC Engineering 101. Now I have completed the GRC Engineering 101 from anecdotes soul Shine. And let me explain it to you. I was mistaken. So the GRC Engineering 101 from anecdotes is a 19 page PDF. So I read the whole 19 pages. I have a LinkedIn post coming out about it on what it is. What's the value? In fact, when I completed the GRC Engineering 101 is when I then went and found this GRC playground which allows me to actually do practical application of GRC engineering. So the TLDR again, I have a link coming out for this, but I found the GRC Engineering 101 an excellent primer to help people who have no idea what GRC Engineering is ground themselves in what it is and then be able to go further. So those are the answers to your questions. Soul Shine. All right, continuing to look through the chats, what are your thoughts on cgrc? KT shoots. I don't know what that is. What the heck? Does anybody know what CGRC is? I don't know what that is. Risky 1955. What the flip man says. Explain the importance of networking LinkedIn and getting a mentor and being a mentee to someone aspiring to join the field. I'll do you better than that if you want to invest the time. Risky. Look at this. I got a video for it. Where is it? Where is it? Where is it? Where is it? Right here. This is called Practical Cyber Skill Stream Personal branding for your cyber career. This is a one hour. This is a one hour webinar where me and Mike Miller, literally for an hour. Risky. Explain the importance of networking. We walk through how to build a powerful LinkedIn profile and then we talk about networking. We don't talk about mentor or mentee specifically. So I'll spend a second talking about that. But I'm going to drop a link in chat if you're watching on replay. The title of it is Personal Branding for your Cyber career in 2026 on Simply Cyber's YouTube channel. So again, I'm not trying to push it off, but what I am doing is saying I can answer this question, but I already spent an hour making a video that has hands on walkthrough. Tt like the practical exercises, all that. Now let me answer this in 30 seconds or less. You could be the best at anything in cyber security. You could be the best Pen tester, the best soc analyst, the best detection engineer, the best runter, the best GRC person. And your boss tells you you're the best, but nobody else knows that you're great. So when you go apply for a job, you're in the same friggin pool as everybody else. Networking builds that relationships and expands the knowledge of people knowing that you're great at what you do. Super valuable when you want to move in the industry, allowing you to be more marketable. LinkedIn is guys, people are going to go to your LinkedIn profile if you apply for a job and you make it to a level where they're going to talk to you, they're going to go look to your LinkedIn profile, get it cleaned up, make it a landing page for marketing you. Now, as far as getting a mentor or a mentee, all I would say is talk to people, engage, mentor and mentee. Doesn't need to be like a Padawan and a Jedi Master where you're linked together for years. I called Brian Bushwood the other day to talk to him about a project. He's effectively mentoring me on a show project I'm working on because he's done it before. I'm not like, all right, Brian, we're basically married now. No, you can have like transactional mentoring capabilities. You can men, I can mentor backwards. Right. So you know, Brian was asking me questions about CISOs and you know, executive level things. So that's what's up. All right. Justin Gold wants to know if my refrigerator's running. It is, Justin. Both the one in the garage full of beers and the one in the house full of ham sandwiches. Okay, so Wade well's literally putting my email on stream. Thank you, Wade. I will go ahead and check that. Thank you, bro. That's like Charles Fin frock level. All right, I'm, I'm searching on Wade in, in my email. This is what it looks like. Wait, the last email I have from you, dude, is February 9th, so I'm not sure if you're sending me malware. What are you doing? So let me know. Meaning it got flagged. Okay, Wade, you can use Discord and dm me too. That, that'll work. And if, if for clarity or whatever, let me know. All right, Continuing to look through chat. This is Cyber Career Hotline. The basic premise is, is if you have a question, put it in chat and I will do everything I can to answer it. Okay, that's what's up. I'm here to help. I'm here to help you all right, looking through ch. Oh, my God. Looking through chat here. I want to say hi to Rhonda Rummerfield. I want to say what's up to Flip node. Marcus Kyler says certified in GRC cert. Okay. I mean, it's ise too. It's probably okay. Crinkle says missed a few episodes. So you may have talked about this. What are your thoughts on the whole Delve controversy? Oh, my God, dude, I heard about this at rsa. If you guys didn't hear about this, okay, this is insane. Okay, all right, All right, listen. Delve. Delve is a company here. Listen, I don't want to get, you know, sued for libel or whatever. So this is all. I'm gonna just show you what I heard. Delve security fraud. Listen, this is so hot. I heard this in at rsa like, it happened right at rsa. Okay, so Delve replies to this as misleading statements or whatever. But listen, essentially, the. The. The. Whatever you want to call it, the. The deal is. Okay, the deal is. This is so bad. A company called Delve claims to. Here's the thing. A lot of startup companies that want to get acquired seek Sock 2 compliance. Sock 2 is kind of like a rubber stamp that you're some level of secure. And a lot of VCs and acquiring companies want to see SOC2 compliance. Delve said, we can help you get SOC2 compliant. We're definitely guaranteed. And what ended up happening, allegedly, is that Delve was building all these SOC2 profiles and portfolios for businesses. So, like, let's say my business gave Delve 20 grand to get us SOC2 compliant. And Risky 1955 gave, you know, Dell 50 grand to get him SOC2 compliant, et cetera, et cetera. What ended up happening is they allegedly were just copying and pasting fake data or data from a different client into everyone's profile. So as a tech startup company, I don't know what SOC2 compliance is. I just know I go look at this folder, and it's full of documentation says, I'm Sock two compliant, thumbs up. But it was all fabricated. It was all fake. It was all bull crap. I mean, it was. It was fraud is what is alleged that Delve was committing. So Delve is just casting, cashing checks, and these businesses think that they're good to go. In reality, it's It. You know, it's nothing. It's all vaporware. So that's what's up with Delve. I haven't followed up on any of it, but what. Wow, wow, wow. Wow, wow, wow. All right, if anybody has any thoughts, you're welcome to put them in the chat. Rogue cyber. You're not Brian. I'm sorry. For all this time, I really thought you were. I'm sorry. Rogue cyber. I swear to God, I thought you were Brian this whole time. I am so sorry, dude. I'm sorry. That, that is a. That is a stunner to me. Rogue Cyber. I'm getting confused with Modern Rogue. Thank you for clarifying that. I've been calling you Brian Bushwood for like weeks. All right, here we go. Any tips for making sure non tech family members don't feel isolated or out of place at networking mixers or conferences? So like esco07, you're saying like you bring your spouse or you bring your cousin to a networking event? I mean, I feel like anything else, like, you know, bring them into the conversation. Did you know that geese aren't good listeners? You can tell because they always say, huh, huh, huh. That's a good one. Oh my God. Guys, Mrs. Oer told me the best dad joke ever. I'm saving it for Friday. Remind me. Kai Cipher, what are your thoughts on the newest Miter from Framework Embed? We're using it for conducting attack surface analysis. It seems helpful. I feel it's lacking something compared to Attack. Listen, Miter came out with Defend and that was not as good as Miter Attack. I don't know about Embed. Let's take a look. Embed is a cultivated knowledge base of cyber threats to embedded devices providing a common attack framework. Okay, I'll drop a link in chat Miter Embed again. I know it's spelled wrong, but whatever. You know, I gotta tell you, I'm not 100% sure on this. What I will tell you is I'll tell you this on May 4th. May 7th. On May 7th, Matt Brown. Matt Brown, who's an incredible YouTube content creator, he's incredibly smart around IoT OT hardware hacking. He's going to come in and talk about hardware hacking. Kai Cipher, if you can come on down to that stream. I feel like Miter Embed would be something that would be straight up in Matt Brown's wheelhouse. Let's ask him about it. Because I'm not really doing embedded systems, cyber security or research. Right. So feel like I'm not the best person to ask, but Matt would be. So let's do that. Is privacy compliance a GRC role? How to get spot up on quickly? So privacy is its own thing. There is a lot of overlap between privacy and Cyber security, specifically in the confidentiality field. But privacy goes beyond just what cyber security cares about, right? So privacy cares about that. Like, I'm allowed to make edits to my records that you hold. As part of that privacy care is that I'm allowed to request you to delete it. Right. Like cyber doesn't care about that. So if you want to get spun up on privacy compliance quickly, what I would recommend is. Oh, my God. My very first cyber security video on Simply Cyber. So this is like going back in the archives, like 2019. I actually went and got a cybersecurity. I mean, excuse me. I went and got a privacy certification because I was interviewing for a chief privacy officer role. I was so burnt out at my job that I wanted to get another job. I was like, I can't do this job anymore. I hate. I hate this job. And I went and interviewed for a chief privacy officer job. Spoiler alert. I did not get the job. But the reason I didn't get the job is because I literally told them, which is ter. Which is terrible. I told them I. I'll probably be in this job for like two years max, because this job, I'm going to solve this job and then I'm going to be bored af. And they're like, really? That's how you feel? And I'm like, yeah. And they're like, well, thanks for coming in. And I'm like, I can do this job. I can build a privacy program from the ground up. Like, you guys will have a bomb privacy program. But it. It. Once it's on autopilot, what am I going to do? I can't be. I need to be intellectually stimulated. I can't just be like pushing peas around on a plate. And they're like, all right, you made your point. Get out. And I was like, all right, so check it out. I did get this AHIMA cyber security certification called chips. If you want to get. If you want to get. If you want to get spun up, this CHIPS cert's a pretty good one. Okay. There are healthcare specific ones, but I will tell you, this chps one's pretty good. Look at this one. This is 41 year old Jerry, early YouTuber. This guy. I think I had like 30 subs at this point. Oh, man. Peak. This is in the guest bedroom. All right. Continuing to look through chat for people's questions. If you have a question, drop it in chat. This is the Cyber Career Hotline. I am here to help you. Whoever's hosting the hotline is here to Help you whether it's me, Cosmic Cowboy, Jesse Johnson, DJ B sec, Tyler Ramsby, Daniel Lowry, Bow Tie Security Fleet is posting. Anyone who hosts the Cyber Career Hotline is here to help. Run Fish says, does Open Claw have a chance? I don't think so. I used it. I uninstalled it. I put Karn to bed. I like Claude co work. Dude, Restream is pissing me off and I'm sorry if there's children here listening. I'm getting very frustrated with Restream right now. Rogue cyber OT versus it. Separate programs or integrated programs? Programs. That's a spicy question. I think they need to be integrated programs because they have the same common mission. I do think that you would have an OTICS person in your department who's responsible for that, allowed to kind of operate independently, but they need to be under one. They need to be under one umbrella because they do have the same mission. I know. Phil Stafford. Phil Stafford said I was silly for telling the truth in an interview. Yeah, I know. They actually told me that I would have gotten the job, but they just, they don't want to find a new person in two years. Which is funny because the two women that interviewed me, one of them quit like shortly afterwards. How is water damaged from the pressure? Oh no, the pressure washing incident's fine if you were here yesterday or you weren't here yesterday. We had the house pressure washed and the guy. Great guy that. Great work. He pressure washed this door, which is not sealed well. So he basically pressure washed the inside of the house. It was fine. Edward, I'm thinking about starting a blog to document my transition from engineer to grc. Do you think that would help? Yeah, Broseph, a thousand percent do it. And every time you release a blog post, spam it all over LinkedIn. Like, what's the value of the post? Why should people read it? Get the conversation going. Phone lines are open. That's right. Jesse Johnson. All right, I am caught up on chat. It's 9:27, So this is great. So I'm here to help, guys. I'm loving life. You guys brought the heat. Super pumped for that. Thank you very much. Brian Brushwood, as I call him. Brian Bushwood. Jesus. Not a very good friend. Brian Brushwood. I'm sorry, Brian Jesus. I hope he doesn't watch this stream. Yeah, this guy right here, Brian Brushwood. Okay, Brian Brushwood, Modern Rogue Scam school. He did a show called Game on back in the day. Really cool guy, really fun guy. I, I like him quite a bit. Very charismatic. Gonna get them on the show Simply Cybers Firesides in a couple weeks. Oh, speaking of firesides, may I? Speaking of firesides. Come get some of this tomorrow. You. Hey, listen, you want to have cyber career hotline on steroids? Real truth from a cyber hiring manager, Robert Wetstein. Wetstein. I say his name wrong? I'm sorry, I'm terrible with names. Today, Robert, aka Bowtie Security. He is an executive at a Fortune 500 company. He hires and interviews cyber candidates all the time. Do you want to hear what the the person is thinking on the other side of the table? Do you want to know why they're asking certain questions? Do you want to know absolute red flags that you should not be doing? Do you want to optimize your interviewing? Come get all the secrets from a real one. Bow Tie Security, Robert Wetstein. Robert Wetstein. Tomorrow I'm going to drop a link in chat. As always, you can go to Simply Cyber IO schedule and get a calendar invite for it. Thank you very much, Kimberly. Kimberly can fix it, ladies and gentlemen. Always bringing, bringing the heat. Just like an absolute awesome. All right, we're at 9:30, guys. I think we had a solid show. Simply Cyber Daily cyber threat brief, hot cyber career hotline. Everybody go forth and crush it. It's Wednesday, April 29th. Hump day. We are living our best life, guys. Have a wonderful day. And until next time, stay secure. See.
Date: April 29, 2026
Host: Dr. Gerald Auger, Simply Cyber Media Group
In episode 1121, Dr. Gerald Auger brings high energy and community spirit to the top headlines facing the cybersecurity world. Covering eight pivotal cybersecurity stories, Jerry dives beyond the headlines to provide actionable insights with humor, practical career advice, and technical richness. The episode continues its mission to educate, entertain, and build an inclusive cyber community, making each story relevant for professionals at every stage.
[12:55-19:33]
[19:33-25:26]
[26:50-35:51]
"So many times in your life, you will encounter this situation… people half-bake a solution, it gets adopted, turns into critical infrastructure, then you’re stuck with a janky, cobbled together POS application nobody knows how to support." (28:01)
[35:51-39:20]
"This is attacking your mom, your uncles, your kids… this isn’t, oh, looks like Amazon got hit for another million dollars. No, this is a multi-billion dollar industry." (37:10)
[43:25-49:10]
[49:10-56:03]
[56:03-57:36]
[57:36-60:45]
[60:45-61:34]
On Process Attacks
"Don’t come at me with your nuanced examples. It’s going to fall into one of those three: people, process, technology." (21:14)
On Networking as Career Currency
"Networking builds those relationships and expands the knowledge of people knowing you’re great at what you do—super valuable when you want to move in the industry." (74:00+ during Cyber Career Hotline)
On Infighting Among Ransomware Gangs
"I love watching criminals just cannibalize each other... this is a win for our team." (43:53)
On the Risks of Unsanctioned Tech Projects
"You do not want to walk down that path. If you walk down that path, bring a shovel. Because when you get to the end of it, you’re going to want to dig a hole and get in it." (30:50)
[~65:00+ (Post-News Hotline Section)]
| Segment | Start | |-------------------------------|----------| | Main Stories Begin | 12:55 | | AI Payment Security | 12:55 | | Signal Phishing (Germany) | 19:33 | | Le Robot RCE Flaw | 26:50 | | Privacy Fines & Scams | 35:51 | | Ransomware Gangs Infighting | 43:25 | | North Korea Crypto Attacks | 49:10 | | Vimeo/Anodot Breach | 56:03 | | Medtronic/Shiny Hunters | 57:36 | | AI Deletes SaaS Database | 60:45 | | Career Hotline/Q&A Section | ~65:00 |
Catch the next episode live, see the resource links at Simply Cyber (simplycyber.io), and join the daily chat for community, job leads, and up-to-the-minute threat insights!
“Have a wonderful day. And until next time, stay secure.” — Dr. Gerald Auger