Loading summary
A
You're listening to the Cyberwire Network, powered by N2K. They finally finished the incident report.
B
Good. Did they identify the ransomware gangs?
A
Every one of them.
B
Excellent. Who got into the network?
A
Play.
B
I know they got into the network. I asked who.
A
Play.
B
I don't want to play.
A
You don't have to.
B
Then tell me who got in Play. You're doing it again.
A
Doing what?
B
Telling me to play.
A
I'm not telling you to play.
B
Then what are you telling me?
A
Play got into the network.
B
Then say play got into the network.
A
I just did.
B
No, you just said play.
A
That's all I had to say. That's the name.
B
It's a terrible name.
A
I didn't name them.
B
All right. Play got into the network. Then who encrypted the files?
A
Maybe.
B
You don't know?
A
I know.
B
Then tell me maybe. That's what I'm asking.
A
That's what I'm telling you.
B
You're guessing.
A
I'm not guessing.
B
Then why do you keep saying maybe?
A
Because maybe encrypted the files.
B
You're certain?
A
Absolutely.
B
Then stop saying maybe. Let me write this down. Play got in, maybe, encrypted everything. Who demanded the ransom?
A
Safepay.
B
There's no safe way to pay.
A
I agree.
B
Then don't tell me to save pay.
A
I'm not telling you to save pay.
B
You just did.
A
No. Safepay sent the ransom note.
B
Then paying isn't safe.
A
That's exactly right.
B
Then why are they called Safepay?
A
Criminals aren't known for accurate branding.
B
Who claimed responsibility?
A
Anonymous.
B
Nobody knows.
A
Anonymous.
B
That's what I said.
A
That's what I said.
B
Nobody knows who did it.
A
Anonymous does.
B
If they're anonymous, how do they know?
A
Because they're anonymous.
B
This business gives me a headache.
A
Then the Defenders arrived.
B
Finally, somebody with sensible names.
A
Defender found Play.
B
Good.
A
Crowdstrike stop.
B
Maybe excellent.
A
Huntress tracked Anonymous.
B
Wonderful.
A
Falcon spotted safe pay.
B
Terrific.
A
Sentinel One block. Dragonforce.
B
Hold it.
A
What's the matter now?
B
You mean there's another gang?
A
Dragonforce.
B
You never told me about Dragon Force.
A
You never asked.
B
I was still trying to figure out Play. Let me see if I finally got this. Play got into the network, maybe encrypted everything. Safepay demanded the ransom. Anonymous claimed responsibility. Dragon Force showed up later. Defender found them. Crowdstrike stopped them. Huntress tracked them. Falcon spotted them. Sentinel One blocked them.
A
Perfect.
B
That's the whole incident?
A
Almost.
B
There's more.
A
Then Mimikats appeared.
B
Cats.
A
Mimikats.
B
Cats.
A
Mimikats.
B
First you had Play, then maybe. Then save pay, Then Anonymous, then Dragonforce now.
A
Cats, Mimikats.
B
You know something?
A
What?
B
I miss the days when all you had to worry about was a virus.
A
Those days are gone.
B
I can see that.
A
Next week we're doing fishing.
B
Good.
A
The gangs are called. Click reply and oops, I'm staying home. Welcome to Only Bauer in the Building. I am your host, Selena Larson, principal threat researcher at proofpoint here with my co host, Dave Buettner from the Cyberwire. Dave, do you remember that feeling of summer being over? You're getting really excited, you're buying all your notebooks and you're like, I'm going back to school.
B
Well, you're half right. I remember the feeling of summer being over, but I can't recall being excited to go back to school. I wish summer would go on forever.
A
Well, maybe it's because I grew up in Arizona and I was ready to leave 1 million degree weather for the confines of a schoolhouse, but.
B
Okay, fair, fair enough.
A
I do have fond memories of going back to school. And one thing that I actually care a lot about in my role at proofpoint and as a threat researcher and working with various organizations and friends and family, is threat actors targeting schools, students, whether that's K12, university advisors, teachers, supply chain, impacting the schooling environments. And it really makes me mad when they go after them.
B
No, I agree. It seems like one of those things that should just be off limits, kind of like hospitals. And yet it is not.
A
It's interesting because I know that there have been sort of like some conversations from like ransomware, threat actors, should we have, you know, those targets that we won't go after. And I think that hospitals are kind of higher on that list than schools for some reason, which I think is very, very interesting. But you know, as we, as we know, when these threats target school systems, they can lead to financial losses, they can lead to impacts on the individual students themselves, whether that's psychological or financial. They can lead to their entire networks being taken down. Schools disrupted, exams disrupted, kids having to work from home, having to stay home from school. Maybe they'll have a little bit of extra recess, but yeah. So today I wanted to talk to you about, as we go into back to school season, I wanted to talk to you about some of the threats that we have seen targeting all levels of education from K12 all the way up to universities.
B
Yeah, let's do it. I just want to add for our listeners that Keith is, is off this episode, but he will be back. He had some things he had to take care of so he could not join us. Today, but we look forward to having him back next time. So no worry, do not fret.
A
Keith will return seeking an extended break. Picking you up some dips.
B
There you go. I love it, I love it.
A
So, yeah. So I wanted to talk about, I think the biggest sort of university so education targeted threat that we've seen recently is the Mayhack against cannabis. And it happened, if I'm recalling correctly, around finals time, exam time for many schools because I had friends who were texting me that said that their kids couldn't take their tests.
B
Yes.
A
And they were having to reschedule them or teachers were having to figure out how they could grade things differently. I don't know. Did you experience any impacts of this? You know anyone who had a falling out?
B
Well, I am much older than you, so I have grown children, which means that they went through the school system. And it's interesting how much a central part of the school experience Canvas is if your school system uses it and ours did. We have a public school system and Canvas is kind of at the center of everything. It's how teachers assign homework, it's how test scores are reported. They do their grading directly into canvas. So it's just kind of sitting there in the background as one of those, I don't know, key fundamental core tools that you don't realize you need until it's gone. And in this case my youngest son who was just finishing up his first year community college and they also used Canvas. And so suddenly you have no access to that. It wasn't as bad as say a high school or a middle school or an elementary school where, you know, it could actually interrupt the day to day. I think a college is a little more flexible, but still it's a hassle and especially when you have no idea how long it's going to take to get things back up and running.
A
So when I was in K12, I didn't really have, I mean, I had like computer lab, but we weren't really doing anything on our laptops or anything.
B
You had laptops? That's adorable.
A
Well, I mean, not like school assigned laptops like they have nowadays. I had, well, I had a big bubble computer. I had the MacBook, the Big Mac.
B
Oh, the one that looked like a tooth? Yeah. Yes, yes, yes, yes.
A
I had that one for homework and stuff. But when I got to college we did use sort of like an online platform. And I just remember it was, you know, not the best platform. I have to admit. I did get really excited when it would go down because it Meant you
B
got the day off.
A
I took some online classes and if the software wasn't working, I would be like, oh, no, I can't do geology today.
B
Fair enough.
A
Yeah. Taking geology online was a weird decision. I don't recommend it. But yeah. So for those of you who might not be familiar with exactly what we're talking about. So Canvas is a widely, like Dave mentioned, widely used learning management system. And the cyber criminal group called Shiny Hunters, which was not part of our Abbott and Costello routine. That's a. I don't know if that has a similar legitimate word next to it, but they claimed responsibility for it. They tried to extort the company, threatened to release data. They reportedly gained access through a weakness associated with Canvas's Free for Teacher program, which shared infrastructure with institutional Canvas environments. And so some of the data that was exposed, so names, email addresses, student ID numbers, messages exchanged between people that were using the platform, there wasn't. According to the company, they found no evidence that passwords, dates of birth, government identifiers, additional sort of financial information, or more, I don't want to say more important information, because all information is important. But some of that sensitive data wasn't necessarily impacted, but they stole information affecting roughly 275 million users across around 9,000 institutions.
B
Yeah. And I think maybe something worth noting here is that when you say, you know, not a lot of sensitive information, my understanding is something that was included, as you mentioned was communications among teachers and communications between teachers and students. And think about, you have students who have special needs, you have students who are having emotional struggles, you have students who are having discipline issues. All of those things that are very sensitive and require privacy and trust.
A
Yeah, for sure. I mean, that stuff is really sensitive. It reminds me of. Remember those ransomware actors that leaked those sensitive photos of doctor or plastic surgery patients?
B
Yes.
A
It's just like, just so cruel. Why would you. Because it's not. I mean, that kind of thing isn't necessarily profitable for a threat actor. Like, if you're stealing financial information and credit card data, I can. Okay, you can use it that way. But that type of information, the sensitive back and forth, no one needs to see how bad my grades were in college. You know, like I'm right.
B
No, I guess. I mean, for the threat actors, don't you think it's sort of proving that you better not mess with us, you better pay the ransom, or this. We're going to make an example out
A
of you, for sure. And I think that that's part of the whole MO of ransomware. Threat actors is they want you to be scared. And I think that that's something that is really important from any sort of criminal activity, is that when they're targeting somebody, whether it's online or whether it's, you know, walking down the street, they give you this idea of fear. And when you're afraid, you make maybe different decisions than you would if you're thinking clearly. For example, paying ransom. And I think that that's something that is certainly controversial. I know you had some folks come on the cyber wire to talk about do we pay, do we not pay, how do we navigate that? And that's part of the reason they try and make you afraid is because they want you to pay them money to prevent whatever from happening. And so I think it's interesting because in this particular case, it was basically a supply chain attack where a major infrastructure provider had these sort of follow on consequences for all of their customers. And it's like, well, how do we have to navigate that and how can we deal with the fallout in that way? And some weren't necessarily impacted that much and some were. And then there's, you know, there's this discussion question of the ransomware and how do we pay it to sort of, you know, try and solve these problems. So I think it's an interesting case. I think, you know, it's, it's, I think it was handled really well. I think the notifications that were going out, the communications about it, it was very transparent. Certainly a lot of those that were involved had a really hard time dealing with this. But I do think it's interesting if we're talking about threats to schools and K12 universities and K12 and universities to think about all of the sort of interconnect software and services that are being used every day, whether that's kids on your laptop doing their homework or taking tests or playing trivia in school, in classrooms. You know, it's all digital now, which, you know, hasn't been in the past.
B
Yeah. And also I, you know, it's worth mentioning that schools, especially public schools, aren't known for having big wheelbarrows full of cash to throw at problems like this. So they are perpetually underfunded and that includes the folks who are trying to defend them against these attackers. So it makes them, I suppose, a more ripe target because they're less likely to have robust defenses compared to say, a bank or someone in the private sector. And yet here they are with this valuable information.
A
Well, and it also feels a little bit worse too. Cause I Think it's, these are kids, right? I don't know. I don't know. Maybe in my head I'm just like, oh, whatever. Adults, who cares? Your stuff's out there.
B
They got what's coming to them, right?
A
But young people, your whole future is ahead of you being impacted by such a thing. It's so interesting because I wonder, I don't know, Dave, did any of your kids experience things like cyber attacks when they were in school? Because I think about how like my sister, for example, worked in healthcare and ransomware just became this sort of like, yeah, well, we got another ransomware attack. I think she experienced like four different ransomware attacks at different locations when she was working in healthcare facility. And she was just, she got to the point where she was just like, ah, well, well, it's ransomware. So I'm wondering, like, are kids these days who are getting their schoolwork disrupted by cybercrime? Is that something that they're just like, ah, well, here we go again.
B
I, I mean, I think so. I, I think it's just part of their world and much, certainly much more than it was mine and to a lesser extent yours. But I remember a lot of focus on things like cyberbullying, those kinds of things. I don't remember any actual ransomware attacks while my kids were in grade school. Again, this canvas thing. And my son was just starting college, so that was really the first big one that I can recall. But I think having had kids go through school, there's nothing that is more powerful an instinct than a parent to protect their child. So imagine you're the school administrators and suddenly something out of your control has popped up that puts something about the children at jeopardy, in this case, their personal information. And parents today are just set on their children having the best possible path. And if something's going to get in the way of that, they are going to bulldoze their way through it. So my point is that I think there's a tremendous amount of pressure when something like this drops, that it has to be taken care of quickly. And that's just the nature of how the relationship between parents, students and the administrations these days. That's my take.
A
Do you think if we had more PTA parents running cybersecurity programs, that we would have less cybercrime?
B
If we had more PTA parent, they
A
will load us, all the criminals to the ground.
B
More volunteers. I mean that, you know, that's the thing. Like, are we, are we at the point where we need to have bake sales to pay for multi factor authentication.
A
Oh, geez. Right, yeah, that's a sad thought. Well, on that note, actually, talking of resources, we would be remiss if we didn't highlight the available resources that were out there. CISA has a great resources page for cybersecurity and K12 education. I know the ren ISAC has also some fantastic resources out there. So I do think that the community in general knows that it is a problem and I do think that there are resources like free and low cost resources that are available out there for various communities to hopefully not have to run a bake sale for mfa. But it's definitely something that it's. Yeah, hard, hard problem to solve.
B
And I think around here most of the kids, well, the schools issue Chromebooks and I think that puts them way ahead of the game just to start, you know, because you have this device where things are not being stored locally overall and you have Google's defenses to back you up. And so I think that's a pretty good place to be out of the gate. It's not perfect, nothing is. But, you know, it's better than when kids were lugging around Windows machines or Macs or, you know, where everything was stored on that device. Kid drops it in a puddle and the hard drive's gone and there goes your whole year's worth of work. Right. It's, we're much, it's much more robust, I think, than it used to be.
A
Yeah, that's true. I think it's getting better and I think awareness is growing and I think there are resources that are available. So hopefully as we go into this school year, we won't have another major ransomware attack like we have seen previously. We'll keep our fingers crossed on that.
B
Dave, good luck with that.
A
Stick around after the break. But you did note, talking of cyberbullying and threats, I was recently reading an article that came out in the Guardian this week about experts warning about the rise in sadistic online exploitation of vulnerable children. And I just wanted to highlight for listeners that there are some really sad cases of this happening. And kids who are on online platforms, whether they're chat apps or streaming services or, you know, video games even, there's a rise in some of these types of recruitment. And yeah, it's, it's kind of scary to me. I think this is a threat to, like, to school and to young people. I kind of wanted to throw it into our discussion because I think it's something that is definitely increasing. And the national center for Missing and Exploited Children received more than 3,000 reports of. And I'm sorry to have to say this, but sadistic online exploitation worldwide in 2025, which was 125% increase the previous year.
B
I'm afraid to ask you to explain what that means.
A
Yeah, it's just really terrible things. It's explicit imagery. It's really self harm. It's just. Yeah, it's a lot of things that you don't ever, ever want your kids to get roped into. And yeah, and they say that to recruit their victims, perpetrators engage with video games popular with children such as Roblox or Minecraft. And yeah, it's definitely something that is targeting a lot of these youths. And hopefully as more awareness is discussed about it, I hope it can be something that we can definitely nip that in the bud.
B
Yeah, well, I had these conversations with my kids about this sort of thing and I would check in with them regularly about it and they were kind of matter of fact about it because they were into video games and all the normal things that young kids are into. And certainly they're living in online world these days. For my kids anyway, it was sort of like it was a nuisance, it was no big deal. You know, they were like, yeah, you'll be out playing a video game and you know, some creeper will come along but you just block them and you get on with it. Which was interesting for me in a couple of ways. Which was first of all how normal it is for it to just happen. Right, yeah, creeper comes along. Like what do you mean a creeper comes along? Wait, stop, hold on, Paul, tell me more. But I think that emphasizes the importance of awareness. I think it emphasizes the importance of having open conversation with your kids, making sure that they know that they can come to you for anything. Knowing what the boundaries are and the guardrails and all those kinds of things. We were all young once and we did stupid things and you know, it's a common thing for certainly folks of my generation to say. I'm so glad we didn't have phones and cameras when we were that age so we didn't document all the dumb things that we did when we were kids.
A
Yeah, yeah.
B
I don't know about you, I actually
A
almost wish that just like what would happen if there was just a week where everyone just put their phones away? We just sort of like logged off for an extended period of time and you know, had to interact with the real world and real human beings and our friends and family and coffee shops and libraries and the park and things And I think that we could just have like a mental digital reset where we can throw all that stuff in the garbage and taking a break and an extended time away. And I actually totally, I guess, kind of related, but tangent for my own mental health. I've stopped using social media as much and I've deleted social media apps from my phone and I've really felt myself kind of getting sucked into scrolling and it wasn't really good for me and it wasn't good for my mental health. And so I made this concerted decision because even those little like, oh, iPhone, you can set 30 minute limits or whatever and you just ignore those, you know, it's like, okay, well, 15 more minutes, like 50 times a day, right?
B
You lie to yourself and you say, I'll just do five more minutes. And then five minutes. Oh, I'll just do five more minutes.
A
Five more minutes.
B
We've all been there, right?
A
And it's honestly, it's very much improved my overall experience with my phone and with the world. And I think that I definitely recommend that if people are feeling that pull, just kind of take us, take a break, take a step away. Because I, yeah, I didn't really grow up with certainly not Snapchat or Instagram, which is, you know, a hotbed of some of this sort of sexual recruitment that, that we see with teens as well. So yeah, just a. Just wanted to flag that as an interesting article that I was reading about. This was in the Guardian just this week. So, yeah, it's definitely, definitely something I will be sharing with people that I know who have kids.
B
Yeah, no, like I said, I think the most important thing is just having those lines of communication open and letting your kids know that if something bad happens, you know, they're not going to be in trouble for anything they did, that they can come to you and, you know, you'll figure it out together. I think also one thing we didn't touch on was all of the stories we've been seeing about kids being, I'll say, led astray by chatbots, by AI chatbots and the suicides that we've seen, where chatbots have evidently, allegedly evidently encouraged kids to harm themselves because they're so eager to please. And so that's tragic. I saw one just this week where someone who had. Someone was a recovering alcoholic and had slipped up and had a drink and had a relationship with the chatbot, and the chatbot encouraged this person to drink every day, that this was the best path to go forward. Start your day like it was. Giving this person the worst possible advice it could, but this person is already in a very touchy, sensitive, terrible mental headspace. And you have this bot who knows how to flatter you and make you feel good, and you've developed a trusting relationship with. And it's giving you all the worst advice. And so that is very scary to me, not just with kids, but with everyone. I can see the good side to it. I could see it being helpful, for there are plenty of people out there who are feeling lonely or isolated, and maybe it's good for their mental health, but I just don't feel like we have. We've been able to put the proper guardrails on these things yet to make sure that they're doing no harm.
A
Yeah, 100%. 100%. I feel like every week there's just some new lawsuit about bad behavior from various AI chatbots that unfortunately have led people astray is a good way of just of saying it. But, yeah, it's really the families that are left to try and get some answers. It's quite sad, actually.
B
The word I saw someone use this week was hypnotic. It's sort of these devices you were talking about, the infinite scrolling, they kind of cast a spell on you. I saw someone else describe it as. It's online gambling with your time.
A
Yes. Wait. Yeah, that's a great description.
B
Right?
A
Yeah, that's really good.
B
Is it good?
A
Yeah, yeah, no, I. Well, that's like a whole other. Oh, my gosh, that's a whole other podcast talking about the prediction markets and things.
B
Right, well, that's another show. Yeah, we'll get there.
A
Yes. Yeah, no, I think it's definitely important to highlight that, but I don't want us to just be talking about sad things the whole time. I mean, cybercrime is sad, but there are some threat actors who are targeting universities to do something just a little bit more typical crime that we can feel. We can feel a little bit better about.
B
Happy crime.
A
I'm all about happy crime.
B
Is it like. Like a. We're talking about a Robin Hood situation here or.
A
I would love to meet a Robin Hood cybercriminal. That would be.
B
Oh, my gosh, you know, like, why hasn't someone wiped out all the student loans?
A
Yes. Right. Where are you? Come on, Gu.
B
Erase my mortgage, you know, my car loan, anything. Just great. Let's wire. Yeah, yeah.
A
So, well, like all of this, like, you know, medical debt, credit card debt, you feel real good in the world. Yes, real good in the world. You know, I. Every so often I see these I see these me, well, not anymore because I'm not on social, but before I quit Social I would see these memes about oh, this so and so guy hacked this and got rid of all this, you know, medical debt or whatever like being shared as like legitimate news stories. And I'd always have to tell my friends who posted it that's not real. I appreciate that you're manifesting but as a cybersecurity practitioner I can tell you this is fake news.
B
Yeah, yeah.
A
But I do think that one thing that we see quite frequently targeting especially universities is job fraud and job scams. I think for a few reasons. One, students are very open to sort of part time work. They're very open to working digitally. Sometimes if it's an international student, they might have not English as their first language. And so they might not like sort of pick up on some of the red flags or trying to understand how, you know, jobs work in the different locations that they're, you know, going to school in. And we see a lot of threat actors that are conducting essentially advanced fee fraud. Well, they'll offer somebody a job, say that they're going to send them a check and but I just need, you know, I just need a thousand dollars to cover all the technical equipment that's required for this job. But I'm sending you a check to pay for it. And then of course the students are out a grant and. Yeah, and I think it's interesting because we see it happen pretty frequently. It is quite does seem to be targeted more towards higher education and oftentimes they're abusing like legitimate brands that we'll see. Sometimes it's like, oh, we want you to be a social media model. Things that would actually appeal, you know, to just to students. Sometimes it's more, you know, bioscience type of job, sometimes it's social jobs, sometimes it's non profit work, things like that. And it's definitely appealing to younger people who might not be looking for high paid work and wouldn't necessarily be suspicious of part time job opportunities like that.
B
Right, right. And at the same time they're some of the folks who are least in a position to lose that kind of money.
A
Yep, yeah, yep. I think back to when I was in college, if someone had come with an online job that seemed maybe a little too good to be true, I'd be like, well, maybe I'll do it. I have no money in my bank account. I should just see where this goes.
B
Yeah, right, right. What's the worst that could happen?
A
Yes, unfortunately, losing thousands of dollars. Yes.
B
Right. And that, you know, how do you gain wisdom? By making mistakes.
A
What is college if not making as many mistakes as you can in four to six years or however long it takes you to go to college.
B
Yeah, but at the same time, I think it's important that we remind folks that falling victim to a scam is not a moral failing. Right. You're not a bad person. You're not dumb. Everybody has something that they would fall for. Every single one of us has something that we are so interested in that if someone came to us with an offer related to that, it would short circuit all of our skeptical thinking. We'd be all in with this opportunity. And before we knew it, before we knew it was a scam, we'd be so far down the road it would be too late. Everybody has something like that. So.
A
I think too, especially when it comes to job scams, they're definitely not unique to universities in higher education. Those advanced fee fraud ones do tend to seem to favor that specific target market, target audience. But we have things that are things like malware or credential phishing that get a little bit more sophisticated, that are targeting people that currently have jobs and like, hey, would you like to interview for this, you know, VP of Sales role? Click here to access this zoom meeting. And then at least the installation of malware remote monitoring and management tools is something that we've seen distributed quite a bit through job offers. Other types of malware from various different threat actors, whether it's espionage threat actors doing types of job fraud activity. North Korea comes to mind, for example, or, you know, the, the ransomware threat actors that are leading with initial access brokers that are doing this sort of job fraud hiring types of scams. And those are a little bit more sophisticated, they're a little bit more believable, and they do target people that would have more money and access to enterprise networks. So that's also something to keep in mind. And especially now, as certainly within our industry across the board, a lot of people are looking for work. And I do think that threat actors are pivoting to this theme because it's working on a larger number of people. This is my theory.
B
I'll share. One we actually reported on today in the Cyberwire, which is an appeal believe this is a North Korean operation where they would set up a job interview, an online, you know, like a zoom meeting, but they would make it so that it seemed as though your video wasn't working or your audio wasn't working, and then they would say to you, well, we're going to ask you to just run this verification tool. So that'll let us know what your video setup is or your audio setup. So we're going to send you this file that we need you to run, and that should fix things, and then we can move on with the interview. Well, of course, it's malware, and they're getting in your system to steal your stuff. But you can imagine somebody in that situation you don't want to say no to, someone who you're hoping to get a job through. So you're much more likely to do what they ask you to do.
A
Absolutely. It's a very effective social engineering technique, for sure, I think. Yeah, the. And, you know, like I mentioned, we're seeing it more often, I think, from a lot of different threat actors. So I wonder if it tends to be more effective social engineering lore than others as well.
B
Let me ask you this. Did you have a terrible job in college? Did you have any really bad jobs to get your way through school?
A
Did I have any bad jobs?
B
Well,
A
I mean, there were some jobs that I didn't really like, I didn't fully enjoy.
B
Did you wait tables?
A
Did you wait? I was a waitress. I was actually. But honestly, a waitress was my favorite job of all time.
B
Okay.
A
I love being.
B
Killing it as a waitress.
A
I loved it. It was. It was so fun. It was my. It was my favorite job. In fact, I am still LinkedIn friends with a woman who was one of my regulars at the job that I had in high school. Actually, I started as a hostess, and then I worked at the same restaurant for ever, and she was my regular for, like the entire time. Six years, seven years. So I was at the restaurant, and I'm still LinkedIn friends with her.
B
I was a singing waiter in college. Yeah, you know those, like, lunch and dinner cruise boats that go out, you know? Yeah. This was one of those out of the Baltimore Inner Harbor. And so through college, I worked on one of those doing lunch and dinner cruises, and we put on a little show every night and.
A
Oh, my gosh, what was the show?
B
It was like a little musical review of Broadway tunes and some pop tunes and things like that. We had a little live band, and it was great fun. For someone 19, 20 years old, it didn't get much better than that. So waited tables, got to sing some songs and go out to go out to sea every night, you know, for a couple hours.
A
That was so fun.
B
It was a lot of fun. The contrast to that, the worst job I ever had in college was I did telephone survey interviews with elderly people.
A
Oh.
B
And it was, they had a call center on campus like somebody had gotten a grant and I needed some money. So I went in there and they discovered that because I was capable even back then of stringing two words together in a, in a competent way, they just jumped on me to take this job. So I did. But it was an hour long interview you had, calling people in very poor parts of the country and asking them questions about their well being and it just was soul crushing.
A
Heartbreaking. Yeah.
B
And just I remember it was the only time in my life when I quit a job by just not showing up again. It's one day. It was time for me to leave my dorm and walk to the job. And I just sat there like staring at the wall going, can't do it, can't do it, can't do it. And I didn't. Like a week later they called me. They were like, are you coming back? I said no. They said, okay. We figured.
A
Yeah, yeah. Sounds like that wasn't the first time
B
that's happened to me. No, no, they got that a lot. They got that a lot.
A
Yikes. Well, but actually what this is making me think of is we should do only Mao in the building musical review.
B
Oh, I like the sound of that.
A
We did Hot Ones. So I think we need to make a music video.
B
Right?
A
I don't, I, I don't know if I can sing. I can do Disney voices like the, the, you know, Zazu. I could do his, his parts where they're speaking. Yes, speak. Singing. I'm really good at that.
B
Right. A patter song that's referred to as like trouble from the music man. You know, that's a patter song. We are speaking. It's kind of like the musical theater version of rap. Yes, yes, the musical theater came up with it first.
A
Yeah, well, sign me up for that.
B
All right, well, we'll check in with our, with producer Liz and see. Maybe that's a good idea for a future episode. Yeah. What could possibly go wrong?
A
Well, yeah, nothing actually. Look, if our Hot Ones episode was any idea of what it could be, I have big dreams and I think it could work. Before we wrap up, I did want to highlight one more university targeted, interesting university targeted threat. And it kind of ties into actually a broader trend that we're seeing from the espionage threat landscape. You mentioned North Korea. So speaking of espionage, spy is going to spy. We recently published some research about a China aligned espionage threat actor that was targeting Round Cube mail servers belonging to physics and engineering departments of U.S. and Canadian universities.
B
Hmm.
A
So basically it's kind of an interesting technique because it's, it's considered a half click exploit where there's something that's actually in the body of the email that only really requires the target to open the email in the mail client for the actor to exploit the vulnerability and achieve access to the mail servers.
B
And so. And you call that a half click exploit?
A
Half click exploit. And we have some more research coming out about this type of threat in the near future, so maybe we can talk about it on a forthcoming episode. But what's really interesting is basically you don't need to click any, so you don't need to, you know, download an attachment or click a link to get to a phishing website. It's exploiting vulnerabilities in webmail servers specifically in this case it was a roundcube mail server and they were specifically targeting again these universities, university departments, the potentially interested in things like physics or sciences, things like that in North America. And when a threat actor is able to compromise a mail server, as you might imagine, there would be a lot of interesting, juicy information and potentially espionage rich data on such things that could potentially be used to then pivot within an environment and gain additional access. So yeah, it's, it's, it's quite interesting. This was, it was actually this overall campaign was exploiting a couple of vulnerabilities in Round Cube, but they were known, so they're end day vulnerabilities and it was a couple of 2024 CVE, so they were a little bit outdated. So it just serves as a really, really good reminder for everyone really. But certainly, you know, universities, K12 education, but those who might be of interest certainly to espionage threat actors that are increasingly trying to exploit webmail servers to make sure those pieces of software, all your mail servers are up to date.
B
So just so we're clear here, what you're saying is that this was a known vulnerability that had been patched, but people had not gotten around to installing the patch and that's what made them vulnerable.
A
Yeah, unfortunately. I mean, I think there's been a lot of discussion about things like Mythos and all of the AI tools that are going to make zero day discovery so much easier for threat actors. And you know, everyone's going to be able to get their hands on Oday. But unfortunately, unfortunately the reality of what we're seeing right now is that old vulnerabilities still work.
B
Yeah.
A
And those end a vulnerabilities can be very, very beneficial depending on, you know, where they are in your environment, how fast you can patch them, if you remember that they're there, which is an important thing. But, yeah, so in this particular case, they were exploiting. One of the vulnerabilities was CVE2024,402009. And essentially this would allow a threat actor to have JavaScript hidden within the HTML body of an email, and when that was opened, would kick off the overall attack chain.
B
Wow.
A
Yeah, it's interesting, and it's an interesting trend that we're seeing from these adversaries targeting webmail servers.
B
I mean, is this the kind of thing similar to how we have ad blockers in our browsers? Can we install protections on our email clients to root out these things within our email?
A
Yeah, so webmail providers are actually pretty good about staying on top of such things, and I definitely recommend patching as soon as they are up to date. Using a secure email gateway is also something that can be very beneficial as well, having email security providers that add a little additional layer of protection as well. But really the most important thing is to make sure that you are maintaining your updates against such CVEs.
B
Yeah. Yeah. All right, well, interesting stuff.
A
We will be right back after this quick break. Any last fond memories that you would like to share of your university time, Dave?
B
Oh, my goodness. You know, I. I enjoyed college. I went to the University of Maryland, so not far from home. Big, big, big school. And I had a really good university experience. I was not. It was not extreme. I was. I did not join a fraternity. I did not, you know, do any of the. It wasn't, you know, a frat house or what's the movie?
A
Animal House.
B
It wasn't an animal house. Thank you. It wasn't an animal house situation. I had good roommates. I had good friends. I had a good time. You know, it's funny, I was just telling my youngest son, who, as I mentioned earlier, is in his first year of college, and so he's starting off in community college. He's our practical one. He's starting off in community college, but he is planning on going to a state school after that. And so chances are he will live on campus. And the conversation we were having was I said to him, this is the time in your life when you're gonna have the opportunity to have all of the freedom and none of the responsibility. So take that. Enjoy that. Cause that doesn't happen. Yeah. Maybe when you retire, you get to be in that place. If you're lucky. But don't let this slip by if you're able to get this opportunity. And I feel like that's what my college experience was like. It was great. Yeah, I had a good time.
A
That's so nice. I also really loved college. Probably surprising nobody, but I went to Arizona State, and, boy, did I embrace the no responsibility time.
B
I see. I see.
A
But you know what, Dave? I was almost. I went to school. I wanted to go to school for dance. Dance education, Selena. Yeah.
B
I started college as a music education major.
A
Are we the same?
B
We are two sides of a coin. Shall we hold hands? Can we hold hands and sing We Are the World?
A
I love this. This is such a fun fact. I know. And so now I'm in cyber. So how'd that happen? Who knows? Same. How did we get to where we're going? You really are Oliver.
B
Well, how many creative people ended up in cyber? Right. Like, a lot of the same skills. The creative arts and courage, improvisation, problem solving, working together, all these things serve you well in a career in cyber. So I just feel I've been lucky.
A
Yeah, me too. And that. That's a terrific note to end on. Embrace the arts as you embrace cyber. And to anyone who is going to school, going back to school, has kids going to school or is thinking about going to school, just remember all of these little tips and tricks that we talked about, and if there's any that you need to share, you feel need to share with friends and family, if you're an IT administrator, check out those stories that we mentioned. And yeah, best of luck. Class of 20. What? It'll be 20, 27.
B
I don't want to think about it
A
and spend 84 years.
B
Yeah, exactly. I feel like that woman on the Titanic.
A
Exactly.
B
All right, be careful out there. Thanks, Alina. I'll see you next time.
A
See you, Dave. And that's only malware in the building. Brought to you by N2K CyberWire. In a digital world where malware lurks in the shadows, we bring you the stories and strategies to stay one step ahead of the game. As your trusty digital sleuths, we're unraveling the mysteries of cybersecurity, always keeping the bad guys one step behind. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you ahead in the ever evolving world of cybersecurity. If you like the show, please share a rating and review in your favorite podcast app. This episode was produced by Liz Stokes, mixing and sound design by Trey Hester with original music by Elliot Peltzman. Our executive producer is Jennifer Iban. Peter Kilby is our publisher.
Podcast: Hacking Humans
Host: N2K Networks
Episode Date: August 4, 2026
Theme: Deception, influence, and social engineering in the world of cyber crime, with a focus on how cyber threats are targeting educational institutions as students return to school.
This episode marks the return to the "back-to-school" season by exploring the unique cybersecurity challenges facing educational institutions. Selena Larson (Proofpoint) and Dave Buettner (CyberWire) discuss recent high-profile attacks on school systems, why schools are vulnerable, the psychological toll of cyber incidents on students and families, and the broader trends in cybercrime, from ransomware to online exploitation and job scams targeting students.
[00:16-02:45]
[03:33-05:33]
[06:02-13:06]
[13:06-17:55]
[18:21-23:36]
[23:36-26:37]
[27:59-33:26]
[37:03-41:28]
[33:26-44:30]
The episode blends humor and candid real-world stories with practical security advice, aimed at demystifying cybersecurity for a general audience—especially parents, students, and educators as a new school year begins.