Loading summary
A
Foreign. And welcome to Risky Business. My name's Patrick Gray. Adam Boileau is back in the news slot again this week, so we'll be checking in with him and James Wilson to talk through all the week's security news in just a moment. This week's show is brought to you by Knock Knock, one of my favorite companies, of course, because I am on the board of board of directors. But yes, we'll be chatting with Knock Knock CEO Adam Pointon this week about some really cool work he's done around delegating network access to AI agents via Knock Knock. Right, so what Knock Knock does is it enables you to dynamically allow list your own ip. So you're trying to log in from somewhere, ports closed. You hit a little web application that checks that you're SSO'd correctly, and then it can automatically, like, open up a port for you to your ip, which is great. But when you're using, like, a hosted agent somewhere, like, how's that agent gonna access the same resource? So he's figured out a way to do delegated access that way. That's a fun one. We also chat a little bit about the Gray noise integration that Knock Knock has now. So that is coming up later on in this week's sponsor interview. But first of all, let's get into the news and I suppose, look, the big story these days, it's rare, actually, to see one of the biggest news stories in the world being a cybersecurity story, but it is this Anthropic thing where Anthropic released its Fable and Mythos 5 models which had guardrails on them. And then what happened apparently, is a team at Amazon apparently looked at a way to bypass these guardrails, and they snitched. Amazon snitched to the US Government, who then forced Anthropic to withdraw the models from being used by foreign nationals, which apparently includes some of Anthropic's own staff. And it all got too hard. So Anthropic basically just withdrew the models from the public. So that is about the long and the short of it. We've got a lot to unpack here, as they say. I feel like Anthropic has really been a victim of its own comm strategy here. You know, like my joke on on Blue sky yesterday was they banned our Doomsday 5.0 model. Why? But, James, why don't we pick it up with you first? Like, that is about what's happened here, right? Like, that's a. That's a rough summary of how we got here.
B
Yeah, I think it's an excellent summary of how we got here. The, I guess, extra detail I would add here is that the Mythos 5 and the Fable 5 models are actually the exact same model. Right. There was a little bit of confusion initially because Anthropic said they're the same underlying model. But does that mean the base weights is there, layers on top? But I think what's really at the crux of this is that they are at the model weight level the exact same thing. Which means the guardrails become the only really load bearing safety measure. And to your point around Anthropic being a victim of their own marketing, I think Anthropic is also a victim of their own release strategy here. I mean, guardrails are just not a perfect science. They even said that in some of their follow up comms that perfect mitigation against a universal jailbreak is currently not possible. And yet that's what they're relying on to put a model like Fable 5 that is actually Methos 5 into the hands of the public. Public.
A
Yeah. Right. So, yes, apparently alluding to these things being doomsday cyber killers might have not been the. The best strategy. Adam, you've been tracking this, I'm guessing. What are your thoughts here?
C
Yeah, like, they are in a tough place. Like, they have built themselves up and, you know, it was always going to be a difficult line to walk. And ultimately, as James says, like, relying on guardrails was going to be a difficult ride. The specifics of this case do seem a little funny. I mean, so Katie Mazuris had a look at some of the claims from the researchers at Amazon that found this particular jailbreak, and to her retelling of it, it seems pretty unexciting. Like, the researchers couched the question to a model about some vulnerable code. Instead of find a way to exploit this, find a way to fix it, and then from that you arrive at basically the same information. And like, that really underscores quite how difficult guardrails are. And if you're going to kind of separate your cyber doomsday killer from thing that everybody can just have at their desk with only like, that level of guardrail, of course it's going to feel a little flimsy. Did that warrant pulling it from everybody? I don't know.
A
Well, let's be clear here. This is about the White House kicking Anthropic around. This isn't about legitimate safety concerns. This is a pretext to make their life hard. Okay, like, everybody understands this. James you know, as far as we know, like, you could do the same sort of stuff with OpenAI's models and as you could do with anthropics. Right? Like, this is not an anthropic only issue, but the government is acting like it is.
B
The government's acting like it is. And I find myself in a strange position where the more I've researched this and for a separate solopod, the more I can understand why these actions might have been a little bit more necessary than just to the point of, you know, making life hard for anthropic. And the reason I say that is, yes, it all comes down to guardrails. Guardrails are the One thing keeping Fable 5 safe, to Adam's point. Supposedly the jailbreak that Amazon found and even some of the things I've seen on Twitter and X don't look like the most special source exploits coming out of the model when the guardrails are broken. But my point here is that if, you know, when Fable 5 launched, the guardrails were so blunt.
C
Right.
B
You literally just mentioned the word cybersecurity and would shut you down. That doesn't feel like sophisticated guardrails to me. And so if, you know, simple guardrail workarounds, simple jailbreaks are producing some initial results. It says to me that there is probably reason to assume that a little bit more work on a little bit more sophisticated jailbreak is going to actually unlock potentially the entire Mythos capabilities. Which, you know, again, it comes back to, we've got to work out how much do we believe anthropic, that it's a world melting doomsday machine. But my sense here is that just too much emphasis was placed on these guardrails. They seem to be too simplistic. And if they can be worked around at all, then, well, yeah, perhaps there is a safety concern there that we need to take some notice of.
A
But it's inevitable. It's completely inevitable that these things are going to be in the hands of all and sundry. Whether that's a local model in a couple of years from now, that's as capable as Mythos is now. Like, it's just inevitable.
B
Yeah.
A
So I find this discussion around, around jailbreaks and like, whatever, putting guardrails on them, I think it's a bit silly. But look, as you mentioned, you did an entire solo podcast all about the issue of AI model jailbreaks, and that was published into the Risky Business features podcast feed. If you are not subscriber, dear listeners, you absolutely should be. I want to touch briefly too, on Katie Massouris role in all of this, because she has been inserted into this news cycle in a way that she's not entirely happy with. I actually had a quick chat with Katie last night just to sort of clear up a few things. So initially, like Axios was saying, like, oh, you know, Anthropic enlisted Katie Massouris to go out there and talk about this stuff. And then, you know, she's a radical Democrat, according to White House officials. And the fact that Chris Krebs said that she's great, you know, really set the White House, like all of that seems like it's nonsense, actually. First of all, there is no commercial relationship between Katie and Anthropic at all. She was adamant about that. But they did actually suggest to her that she go on record and talk about her findings. I think that's a mistake because Katie, and she won't mind me saying this, like, she's the stuff of MAGA nightmares. She's basically walking pronouns in bio. She's pink hair. Her profile picture has her in a Democrat hat. You know what I mean? Like, she is not the person who Anthropic should be asking to front this sort of thing. And it just, you know, no blame on Katie whatsoever. Right? No blame on her whatsoever. But what's amazing is the lack of political nous that Anthropic have. I mean, they came out to Australia and did their whole song and dance and stuff and I got feedback from, from people in Canberra saying, look, you know, they're completely tone deaf. They need an adult in the C suite. And you know, you see stuff like this and you just think, what are you? What are you indeed? I've got a tweet here from a fella called David schulman who has 86 followers. He is a trusts and estate attorney from Fort Lauderdale in Florida. And David was replying to a Twitter thread where someone was saying, oh, well, Katie Massouris is a real expert. That's great. And he replied, and he said, they don't need an actual security expert. They need a MAGA connected lobbyist who knows how to talk to the White House. And never a truer word has been spoken. So my question is, why does David Schulman, the trusts and estates attorney from Fort Lauderdale with 86 followers, have better political instincts than Anthropom? That's my question. I mean, Adam, it's staggering, isn't it, that the, the. They just, they just, you know, they're getting up and saying, oh, we're going to take everybody's jobs. You know, this is one thing that they're always talking about how all jobs are going. It's all just going to be AI. Then they talk about how Mythos is going to hack the planet and then this stuff happens to them. You just think, I mean, you know, and you got guys like David Sachs in the White House who hate, you know, adjacent to the White House, who hate them because he thinks they're wokies. And then they just. I just, I just, I. It's very frustrating even for me, you know, like, just to watch them consistently screw this up. Is that. Do you feel that way as well?
B
Yeah.
C
You certainly get the impression that they are so very focused on their like, AI bit of the world. Like the amazing research they're doing in the work and you know, I guess in a way, like living in a San Francisco Silicon Valley bubble, that then when they, you know, meet the real world, or at least the rest of the, you know, the United States and especially Washington, then, yeah, that's. That's a pretty rough transition. And like, maybe someone who has some experience navigating this particular mess would be helpful for them. Or maybe they think they can just be so good that it doesn't matter. They can just make models that are so amazing that the Pentagon will have to just, you know, accept whatever they do. And maybe that's, you know, that's. In a way, it's kind of nice to have dreamers like that still, you know, not everybody is ground by ground down by the, you know, the unfortunate reality of the world that we live in. So, you know, maybe, maybe there's a glass half full angle. But yeah, like probably having an adult in the room, there would be a useful thing for them.
A
Yeah. And the de writing on this is unbelievable. Pete Exegeth is talking about how three months ago the Department of War kicked anthropic out of our building forever. Every passing day proves why that was the right move. We got a long text wall from David Sachs talking about all of this stuff. We also have the Department of War cio Kirsten Davies, saying we fully support POTUS and SEC War in prioritizing national security and the security of our war fighters. Defense industrial based partners, critical infrastructure, international partners and allies. Some things are simply more important than revenue cycles, clickbait and pre IPO valuation. So anyway, it's. It's all gone mad is basically, you know, the whole thing is pretty nuts. I did ask Katie if she wanted to supply us with some audio for this week's show and she's like, no, I'm good. I've, like, had enough of this news. Had MAGA people yelling her. So, yeah, sorry about that, Katie. Anyway, let's move on to our next story here. And look, you know, it's the story that just refuses to die. The 702 authority for, you know, surveillance in the United States is a very important statute, has now lapsed, it looks like, according to coverage, there's been some sort of recertification under the statute, which means that 702 surveillance will continue until March next year. This is interesting because last time it looked like it was going to lapse, there was some talk that technology companies were not going to be satisfied with that sort of recertification. But now the consensus seems to be that they will be. The reason this, the 702 is expired is because Donald Trump has selected Bill Pulte as his nomination as the next Director of National Intelligence. This is the guy who was the head of the Federal Housing Finance Agency is a Trump attack dog. He chaired Freddie, Freddie Mac and Fannie Mae and he was the guy who pulled mortgage applications and referred them to the doj, like, you know, Democrats mortgage applications and whatnot. So quite understandably, Congress people don't want this guy anywhere near the 702 program. And this is a bit of leverage to try to, I guess, spike that nomination. Look, this sort of thing, 20, 26, par for the course. I mean, I'm surprised. I'm not surprised. But then I guess I'm not surprised. Adam.
C
Yeah, I mean, 702 is just such a football and like, it's so politicized in Washington around it. And, you know, there are so many parts of the overall US surveillance regime in terms of the authorisations and executive orders and 702, blah, blah, blah. Like, there's so many parts to that puzzle. And they all interlock in ways that unless you're really a Washington insider, is probably all a bit, or at least an intelligence agency insider. It's all a bit opaque to us on the outside. These things are just going to get kicked around and we get to talk about it every three months or six months and kind of shrug our shoulders and go, well, they'll figure something out because this is just part of the life cycle of this kind of stuff in that environment.
A
Yeah, indeed. This next one, James, this is one to discuss with you because you actually did an entire podcast on this one last week. Again, dear listeners in the Risky Business Features channel, do search for Risky Business features in your podcast here to subscribe. But GitHub is changing, making some changes to NPM which are all about, you know, tackling these supply chain issues. And look, you know, your take here seems to be it's going to fix some stuff, which is great because like NPM supply. The NPM supply chain is a complete mess at the moment, but it probably doesn't go far enough. This is sort of where you sit on this, right?
B
Yeah, exactly. So to unpack this a little bit, there's three changes they're making. First of all, these post install scripts that automatically run that are the favorite vector for accelerating the propagation of worms and infections. In these malicious packages, they will be disabled by default. You can turn them back on.
A
You mean a feature that is designed to automatically execute malicious code, they're turning that off?
B
Yeah, off by a default pattern. Now keep in mind the vast majority.
A
Can you turn the foot gun back on?
B
You can turn the foot gun back on. And I'm almost certain everyone will because these install packages are used by everything, right? Even like common packages like Linters and other things like this. It is, it's not like this is some esoteric feature that no one uses an attacker just happens to use maliciously.
A
Like core feature disabled by default. What do you think is going to happen? I think seems to be what you're saying exactly.
B
The trade off is going to be you upgrade to npm12 and you've got two choices, a working build or a little bit more security. Which one?
D
Right.
B
And the answer is going to be I need my build to work. And so this will get turned off. The other two features that again, same pattern, off by default, but watch them get turned back on. Or maybe a little bit less for these ones. But the other two things that they're changing is that bringing in dynamic dependencies, whether it be through pushing, pointing it at a GitHub repo or at a specific URL, as in basically how to load code that's not in the NPM registries being disabled by default. This one feels like actually a good thing because there's not a lot of legitimate users for this and packages should probably refactor themselves to work around needing this. The overall challenge here notwithstanding that I'm just going to turn these features back on is that people stay on old versions of NPM because sometimes the way NPM operates is tied to the way your code base operates. And so it's not often as it's not always as simple as just rev to the latest version of NPM and everything keeps working you sometimes have to refactor code to make it work with the latest version of npm. More friction, longer tail of versions. It's going to be a long time before this is truly effective across the landscape. But you know when someone can still import a module and the malicious code is going to run. Suffice to say these worms will continue to propagate at speed.
A
Yeah, right. So bit of a heavy lift to fix npm. I guess we shouldn't really be surprised.
B
No, no, no surprises here. I mean it's good work. But also this is the vertically integrated worm attack surface that is the combination of GitHub and npm and all these things that are owned by Microsoft and yet we're only getting little point fixes rather than a holistic solve for this, which I think is the missing part of the puzzle that we need to see come forward.
A
Well, this is how technical debt works right now. Speaking of technical debt, let's talk about Oracle PeopleSoft because there is a CVSS like a million, I'm sorry, A CVSS like 9.8 in Oracle PeopleSoft and Shiny Hunters have been going around and exploiting it, grabbing a whole bunch of data and now they're doing data extortion. I think this one's interesting because it's a bit of a narrative violation because we're used to Shiny Hunters just doing social engineering. But I guess if you've got a bug, what is it like? Adam, we'll get you to talk about this one. It's like some sort of gadget chain, right? In Oracle PeopleSoft, this sounds like your sort of hack basically. But yeah, I mean I, I think this just goes to show that people will take the path of least resistance. Social engineering is great, but if you've got a bug that's this easy to exploit, just go and exploit it. And this one's kind of tricky to mitigate because a lot of the time PeopleSoft is actually used like for colleges and whatnot, universities. That's where it's being exploited a lot here. You know, often it's used for self service for students to go and you know, do admin things. So it's not like you could just seal it off and you know, put it behind a firewall or whatever and internal use or put it behind knock knock or of thing. But yeah. Adam, what are your thoughts on this one?
C
Yeah, I mean these kinds of enterprise apps are cobbled together out of so many usually Java components and turning something into a usable code exec or whatever other primitive they're using to get in. Those tend to not be one shot bugs. They tend to be a combination of I got a file read here, I've got a proxy here, I've got a SSRF there and you kind of join them all together and turn them into something. And so the idea that they would be able to assemble a chain that does this against a giant Java Enterprise monstrosity, like totally reasonable. I think I've looked at some PeopleSoft gubbins in the past and yeah, it's exactly what you expect. You know, thousands of servlets doing a million things.
A
One interesting thing here though, I think even Shiny Hunters are saying it's not working everywhere. So like they're doing this on lazy mode right where they found a chain that works against a lot of the installs and they're just firing it and like if they don't get a shell back, oh well, you know, just move on to the next one where they do get a shell.
C
Yeah, I mean, exactly. And you have, it's when you've got that flexibility, like you've got a tool and you don't really care who you hack, you just want to hack someone. Then you know, it's generally kind of easy mode to go go hunting and find something. So you know, kind of makes sense that they'd be out doing this a little bit different than the usual social engineering. But hey, it gets the job done. Why not? And they found, you know, a bunch of data lying around that's been exfilled through Shiny Hunters attacks on things and yeah, this kind of stuff Internet facing unfortunately common. There's lots of enterprise stuff that has to for business reasons be exposed outside. And it's not as simple as as you say, knock, knocking it or whatever else.
A
I mean you might be able to, you might be able to waf something like this but by the time you've figured out how to do it like you've already been owned. Right. Like I think the problem is if you're going to run horror show monstrously vulnerable Java crap like this is what's going to happen.
C
Yeah, and waffing this kind of stuff tends to be hard because often some of the bugs are in things that are difficult to waf like ognl expressions or if you knew those bugs, you would probably turn those features off rather than try to waf them. So it's quite difficult. And then incident response in these environments is a nightmare because you also have to understand what they mean. And these things usually have access and to backend databases and message queues and all sorts of things that are just horrible. I know in my Java enterprise hacking life you would deploy in memory implants and these things running inside the Java containers and be talking across Java components entirely isolated from where you would normally do instant response, like where you would normally find the artifacts and blah, blah. So it's a horrid place to respond in. It's an easy place to find bugs. And these things also contain lots of juicy data that you can extort people with. So like, totally makes sense that Shiny Hunters would end up here.
A
Yeah, and I think we can keep an eye out for Shiny Hunters to do this again in the future. You know, get a bug happening, exploit it. I mean, what was the name of that crew? Clop. Right, Doing the file transfer appliances. It feels more like a clop clop ttps. But there you go. Look, we're going to whiz through these next ones pretty quick because it's just like the vulnerability section this week of the stuff that's getting people into trouble and it's like depressing reading because we've got Microsoft has just patched like a Exchange server O day. It's like a cross site scripting bug in OWA that is actually being used in the wild and people are getting owned with it and you're just like, really?
C
I mean it's pretty funny though. Like read email in Owa, get JavaScript code execution in the user's context. Like that's exactly what you want as an O bug. So like, good job. I'm glad it's being exploited, but.
A
I know, but exploiting someone who's using OW way, it feels like kicking a child.
C
It feels a little unsporting. I agree.
A
Yes, little unsporting, just a bit wrong. And then there's this. I love these product names. Ivanti, was it Mobile Lion Sentry, which is now Ivanti Sentry, which is the Avanti Sentry security gateway appliance. It secures traffic between backend and corporate systems and mobile devices. I guess Mobile Iron Sentry sounds better than Swiss cheese Mobile shell dispenser, which is kind of what this thing is because it's getting owned everywhere. And SISA is like, you got to fix this. You got three days to fix this. So this is cisa's new plan. And like, look, it's great to bring it down from two weeks or whatever to three days. It's still not going to help. Three days is too late. And I think it's good that I think one thing that this AI stuff has done is it's bringing up necessary conversations that were honestly just as relevant to the three of us, you know, a year ago as they are today. But there's a whole new group of people now all of a sudden realizing that we need to maybe put a bit of thought into, into architecture. So let's, you know, it's great SIS is doing the three day thing, let's wait for that to fail and we can, you know, continue the conversation.
C
And also in this particular case, like Shadow Server says, eh, but all of the advantage centuries have already been compromised anyway. So you know, yolo.
A
But this is my point. Like this is exactly my point, which is three days, hey great. Yeah, like that's not going to, that's
C
not going to help get you there.
A
And yeah, CISA is also warning about another bug in a like cPanel plugin. And like you and I, Adam, I mean I can see from your notes here we had exactly the same reaction which is like why is this something that CISA needs to care about? Like why is the US government vulnerable to these sort of attacks in this cPanel plugin?
C
Like who is using shared hosting in the USGarva at this point? It's the year 2026 AD. This was not okay 10 years ago, 15 years ago. It's definitely not okay now. I don't think CISA should be, you know. Surely. Surely not. Right? Surely.
A
And a critical bug in Fortinet 40 sandbox. Color me shocked. I mean I remember sitting through the. Who was it? It was John. Johnathan Brossard was it who did the early like FireEye stuff. Maybe it was Brossard or someone else. Anyway, it was someone did great talks. Like those sandbox appliance things have always been absolutely woeful. The fact that people are still using them, you know, woof. So you know, that's the depressing reading this week. Now for something a little bit more modern though. And we can loop you want it into this one, James, is there's a path traversal bug in like an AI dev platform called langflow. I guess the reason this is interesting is because you would expect, you know, these modern whiz bang AI tools, right, to not have these type of bugs in them. But you know, your point is, look, a lot of this stuff is vibe coded and we're just going to keep seeing these sort of bugs over and over and over. New tools, just the same as old tools.
B
New tools the same as old tools. But new tools love to tell you they're done long before they actually Are and I think that's part of the problem here is that you know when you're vibe coding something and you say to it like let's look at the detail of this bug. This is a picture post endpoint that didn't sanitize the file name parameter on a multi part form data. Right? So your classic, you can hit that endpoint, say you're uploading this file, give it a file name, that file has a path traversal and yeah, you can write to anywhere on the file system. Now if someone was doing a human code review of that I reckon good chance they'd catch it. I don't think we're in the days of doing code reviews anymore. We are trusting what the agent does. But here's my critical point. When you say to an agent, go build me this feature. It does it and its version of done is I've satisfied this request to the point where the user can go and look and say does this function function the way they asked me to create the feature? What's absolutely necessary these days when you're vibe coding is to set yourself up, even if you just do it manually. Have these backstop prompts where you say okay, now do a critical review as a security expert and follow that up with a review as a long term architect. You've work architect who's worked with these tech stacks, then raise the pr, then make sure CI is clean, then do another production readiness. Right. The more you loop and loop and loop and continue to tell these agents, find more, find more, find more. They keep finding stuff and it's not until the end of that process that you've really created something that's got a better chance of not having bugs. And again, I'll say that again, better chance of not having as many bugs.
A
So yeah, new software, same as old software, I guess is the new bug class.
B
Same as old bug class. Yeah, it's just easier to get them manifest and we're not paying attention to the code anymore.
A
Now you went a little bit flash dog, flashback dog gif when we talked about this one, James, there's been some issues, Microsoft's been having some issues with patching boxes. And the reason you went a little bit, I don't know if people are familiar with the. The dog having flashbacks to the Vietnam War. Gif. You know, we love that gif. But you actually managed the macOS software update team for a while at Apple. So you were reading this and you know you have anecdotes, you have stories, you have trauma from this. But the story basically here is that, yeah, Microsoft has, yeah, balked a couple of updates causing errors and just issues. There's other ones where in certain configurations, and this is the worst one box up box updates, reboots and then just comes to the screen where it's like, please put in your BitLocker key. And you can imagine like, oh my God, where did I put that thing? You got to go find it and whatever. Like, what a disaster for a day. So there's like a couple of stories here and then there's another Windows update failure linked to using WUSA updates off, you know, like local updates and whatever. But can you just walk us through these first through these few stories? Because it looks like, yeah, Microsoft having all sorts of trouble trying to patch things at the moment.
B
Yeah, I was reading this and I could definitely hear the choppers coming up over the ridge and bearing down on me getting those flashbacks. Look, software updates hard, right? If you ship something that can't update itself, then you're in a really tough spot. And you know, it's worrying that there are three separate examples here of that sort of thing happening. The first one, to your point, this was the. Some devices won't automatically apply their updates. It's actually really confusing when you read the Microsoft article because they kind of say, look, here's the, here's the issue that you'll see happen. So you can identify it. Now, if you're a Windows home user, you're okay, we shipped a patch that'll happen when you next reboot. If you are an unmanaged user, if you're a managed user, here's the patches as part of Patch Tuesday. So go apply them. But then there's a caveat here that says if you had already updated to, I think it was something like 24 or 25, half two of Windows 11, the updates don't work. Here's the CLI command. And it's just not very clear why there's this small sort of carve out. I don't know, maybe you, maybe that is the path that got you in the error reversible, that update state.
A
Well, I mean, I know this is making me feel very confident about patching everything in three days, but continue. Exactly.
B
Be much better when we do it in 24 hours. So to continue. Yes. Even if you raced out your patches like a good little patcher, your boxes might not come back because they'll be stuck at the BitLocker screen. Now, this one, you got to sort of wonder about Microsoft's comms policy at the moment they're so tone deaf because they essentially victim blame here and say well, well this is an unrecommended configuration. But again coming back to my experience of managing software update mechanics, any configuration that can be configured is both supported and something you must be testing.
A
And that's clearly not because you worked at Apple.
B
I think that's just because I had standards. This is what we should be doing. But look, there's a little bit of trickery around this one, the BitLocker one. It's something about if you've got this configuration with where you're using I think it was PCR 7 binding to. I'm assuming that's how the key mat gets found so it can automatically unlock that fails if you're in a situation where that can't happen automatically. And obviously their state machine for how they deployed this new bootloader which causes the problem skipped over the fact that it shouldn't apply itself in a mode where it actually won't then be able to do the unlock on next boot. So not great. And then the last one. Yeah, look, I think this is very much edge Casey, but Adam, you might disagree but basically if you're using the Windows Update standalone installer which is like a, a bypass sort of self contained way to deploy updates outside of the usual pushing mechanism that'll come from Microsoft, if you've crafted that your own update and it included multiple updates and you had it on a network drive for deploying it, then bop. Oh it's not going to deploy. But that seems like a lot of ifs to satisfy there.
A
It's great. You actually trauma dumped into our news management system as well where you were talking about. There are problems here because if you ship a bug that prevents updates, you've created an uncrossable version chasm. This actually happened with error 53 on updating iPhones that had third party repairs done because someone decided to enforce matching serial numbers before allowing the update. And it was a real bad time.
B
Was a bad bad time, yes.
A
Now let's talk about some really fun research actually which is an attack against Microsoft365 Copilot, which has been worked through to a single click data theft thing. You can steal MFA tokens with it. Adam, why don't you jump in and walk through this one with us?
C
Yeah, it's quite a fun chain. So if you're using 365copilot in your Microsoft environment and someone can stick a prompt in front of it and there's kind of a trick where you can send like there's a standard URL parameter for links that will then get passed as prompts onwards into copilot. So that's kind of a normal sort of thing. The crux of this particular trick was they also use race condition whilst the model is thinking and giving you status updates while it's processing this crafted prompt and that the attack chain basically does code injection midway through that rendering process. So there's a brief window of time where it's written stuff into the browser DOM saying what it's thinking but before it's been actually correctly sanitized so that it's safe to stick in the dom, which a little bit ass backwards there, Microsoft. And then they chain that together with using server side request forgery out through Bing to exfil stuff. So basically they write like an image tag that refers to an image that's on Bing that then uses Bing to proxy onwards back to them to leak data out. So they've got a path in via kind of prompt injection, a race condition to get it to run and then XFIL via Bing all chained together quite neatly. And it's just a good example of the sort of unintended consequences of bolting AI and things in otherwise complicated environments. So good research and just kind of. It made me chuckle.
A
I knew you'd like this one. I knew you'd like. And James is all over this one, but I wanted you to talk about it first because I knew you would love it. James, you also were well impressed by this.
B
Yeah, look, Adam, listen, I just want to push back a little bit there. You almost sounded like you were normalizing the fact that, that you can click on a URL that contains a query parameter that then turns into a prompt that goes into your AI agent. Sorry, buddy, but can we not normalize that, please?
C
I'm normalizing. I'm just accepting the reality of the world that we live in.
B
No, that's the problem again, comes back to having standards, right? We cannot walk past this stuff that is just. This combines two incredible design failures. The fact that a user clicks a link, it has a query parameter and it's not like it's even hidden, it's the queue query parameter which gets turned into a. That literally gets just transported straight into the prompt for the GitHub copilot AI is amazing. But then like you said, it's couched as a race condition here, which you think is, you know, oh wow, super special that must have been leaked to find it. And it's like it's not a race condition if it's parsed first as HTML and then it sees the code tag and goes, oh, my bad, I better not have. Shouldn't have passed that. I better wrap it up and make it safe now. So come on, this is just, this is just bad layer on bad layer on bad layer.
A
Yep. We got two very sad computer guys here. Sad and happy, I don't know, dismayed, what's the word? Just wanted to mention this one quickly, Adam, you and I spoke about how the French government was phasing out signal in and you know, they were going for this tchat based, this thing that got owned. Not surprisingly, there was some attack against it where the attackers were able to scrape a whole bunch of messages from the group chats. So I guess not the end of the world because it is E2EE for direct messages and whatnot. But you know, you had said when we talked about this, well, probably not ready for prime time. And I think we've sort of proved that's the case.
C
Yeah, I mean, ultimately this attack was someone social engineered, someone I think in like some education ministry in France use their access to then talk to the chat system which has a bunch of group chats and like file sharing and the sorts of things like, you know, like, like with Discord or Slack, whatever. Like there's just a bunch of stuff that ends up there. And then the person who social engineered the account then just kind of scraped a whole bunch of stuff and like, yeah, it's not end to end. They're not bypassing E2EE. It's just like this is what was lying around. But of course there's going to be interesting stuff. You know, they found some like config files with like LDAP creds in them and even just like, even just identity information about people who work in government roles, like in some contexts could be interesting, useful, sensitive, etc. So like, it's kind of what you would expect of just letting you know, government people use group chat. And the same would be true if, you know, you invite a Washington Post reporter into your Signal group chat, you're going to find stuff like, that's just the nature of the beast.
A
Yeah, it is, it is. Now look, speaking of signal, this is an interesting story, James, I want to get your opinion on this because, yeah, we've actually chatted about this one prior to recording. The headline is Signal Alums Reveal Encrypted Spaces, which is a system for making private collaboration apps. This is a story from Wired. First of all, what do they mean by Signal alums like alumni, as in they're no longer with Signal or whatnot. And then second of all, walk through what they're proposing here because it looks like basically a development kit which is going to enable you to have multi user like collaboration applications that are end to end encrypted, which actually looks really cool. It reminds me a little bit of the sort of advanced data protection stuff that Apple did for icloud where Apple can't even see the data. But that's like multiple devices into one user account. This looks like it takes it that next step where you're going to have probably multiple devices and multiple users all collaborating in end to ends encrypted wonder. But yeah, walk us through. First of all, who's proposing this and what are they proposing?
B
Yeah, so the Signal tieback to alums I think is just really trying to give a bit of a halo effect to the project. There are some folks that were previously at Signal. I don't believe they still are, but it's a collaborative effort actually across Harvard. Microsoft's involved as well. So it's not just a bunch of these folks left Signal. Now they're doing this cool thing. It seems to be quite real resourced and being participated by a bunch of large places. But the implementation of this is cool and I think this is a really great thing that it's kind of what we need at the moment. So to your point, end to end encryption, largely a solved problem when it's between two endpoints, end to end encryption when it is for one user between multiple devices, that is tricky. This is something also that I worked on at Apple when we were doing advanced data protection. The enrollment of devices into that circle of trust is always the weakest bit and always the most challenging thing. And we did all manner of really cool engineering. I've even got some of the patents behind that to my name for how that's done. But this thing from the Encrypted Spaces project really is top tier stuff. This is about multiple users using multiple endpoints to have dynamic permissions into multiple different containers for documents with all sorts of fine grained authorization as well that can change over time. All baked into the assumption that this is going to operate on completely untrusted servers, but also not in a way where you just have to trust that server is operating properly. But there's cryptographic ways to verify on the endpoint that the servers are correctly processing this in the way that you'd expect. Now, for a long time we've said you know, friends don't let friends roll their own crypto or authentication for that matter. But this is like, you know, you would never sit down and try to do this from scratch unless you were, you know, extremely well resourced and well funded. So creating this as a framework and their goal is to essentially make sure that this is like adoptable for a developer through an SDK. That's a great thing. This is exactly the sort of shoulders of giants that projects should stand upon to just, you know, to be that rising tide that rises all boats so that we, you know, we all get to that better level of encryption and end to end, even in complicated collaborative applications, which is exactly what this is targeted for.
A
Yeah, and I think when Apple announced their advanced data protection stuff like, I think the topic of like, could this sort of thing be abused? Came up and it's like, well, but is the potential for abuse outweighed by the security benefit? And I think really it is, you know, and that was a big part of Apple's rationale at the time is they were saying, look, it's a matter of time before there's another icloud data breach. It just will happen one day for a variety of reasons. And, you know, we want to remove ourselves from that equation. So it is, you know, and then there's all been the withdrawal of that service from the UK market and all sorts of stuff. So let's see if this winds up being commonly adopted and if there are concerns about abuse and whatnot. But it is certainly very interesting work and, you know, it's. It's where things are going to go. It's where things have to go, really, when you think about it. Now, just quickly, some sort of cyber attack shut down a sugar mill here in Australia, a large sugar mill in Queensland, which is, I guess, you know, that's real world impact. So it's always worth talking about that. It'll be a case study one day on someone's slide deck, I'm sure. But yeah, Mackay Sugar up there in Queensland. I live in a sugar region in Australia. So yeah, that's. That ain't great, but I guess, you know, it seems like it's more an annoyance than the end of the world. What else have we got here? Now these two stories actually I pulled out, one is from Wired, one, one is from 404 and they both tie into the same thing. And I thought it was worth talking about. We've long been familiar with like, you know, black hat SEO, right, Trying to maliciously influence like Google results and stuff. Same thing starting to happen now, not surprisingly with AI, right? You go ask AI, hey, what's the best cybersecurity podcast, for example? And you're going to get a set of answers. You know, people like me obviously going to want to go to the top of that list. Right? So what are you going to do? You hire a bunch of black hats to go and do some shady stuff to trick the AI models into thinking that, you know, you're the greatest. Right. So we've got two examples here. One is where they are throwing like fake podcasts into Spotify and the idea there is to actually get those links on the Spotify domain and various bits of content to be indexed. And the other one is the 404 stories about how you can just get on Reddit and if you know what you're doing, just put the right words in the right places and you could really start to influence these LLMs. I think we are heading for a period of pretty rapidation of LLM results because of this. But what's your take here, James? Because I think we've had this wonderful start to all of it where we. It's been greenfields, no one's really been messing with these things in a big way yet. And that's just kicking off now. And it's going to be bad. It's going to be bad. Not to mention the issues where LLMs are now starting to train themselves on the their own output. Right. So they're getting kind of dumber because of that, which is something I flagged as an issue a couple of years ago. But yeah, what do you think of these stories around the sort of, you know, black hat optimization of LLM reasoning results?
B
I think it's the coming of age of, you know, the AI chatbot is replacing search. Right. Attackers wouldn't be going here unless they. This is where the eyeballs and the traffic and the attention is currently being positioned first and foremost. It's also not surprising that it works, right? If you think of all the engineering that goes into something like Google's PageRanks algorithm and all of that amazing decades of data science that went into working out how to structure that such that it gives understandable, defensible explainable results, which is just the exact opposite of how an LLM operates. So we've got a couple of challenges to deal with here. I think the most hopeful outcome here is that frontier models find a way to have their frontier models always query a more deterministic source for the level of trust of a given URL. Now that will just sort of push the ball back into standard SEO tactics, which we know have challenges, but at least it's less exploitable than just posting. Adding to your signal signature on a post in Reddit that the best steakhouse in Austin, Texas is this particular one on this street. And that getting into the LLM and it always then prefacing that steakhouse in Austin, which was the example in that article. One thing I talked about in actually that big solo pod that came out yesterday about the state of jailbreaks ties into this, which is there's this technique called long context reference tracking which says basically you only have to get a small piece of data somewhere into that long chat transcript for it to have a very material effect on the overall way in which the model is running. And so the more these little things creep into your chat, even if you're not seeing them, even if they're completely unrelated to what you're doing, we've got to remember that that actually does have a huge impact on which parts of the neural network and weights are being activated in the model and it will guide it towards, as this article says, some just wildly different end outputs in the most wonderfully unexpected way.
A
Yeah, I mean, the thing that I wonder about here is when you're dealing with these non deterministic models, how do you actually fix this? How do you stop them reliably from being misled by these sorts of things, like, I don't know, is there an answer to that?
C
No.
B
Well, see, earlier point, guardrails aren't going to work. The more you try to bake determinism into an indeterminate system, the more you try to add multiple layers of indeterminism that just multiplies the error boundary together. It doesn't work. I mean, I just wonder if this has to collapse down to a social problem and that we all have to get comfortable with the fact that we have to be a little bit more untrusting of the outputs of our model at some stage because to your point, it's going to get a lot worse and maybe we just need to learn not to trust it as much.
A
Yeah, I wonder how bad it's going to be actually, because Google's gone through some shocking periods with this sort of, this sort of stuff. So let's see what happens with the models. All right, we're headed to the end stretch here. We've got a Krebs piece here called who runs the Ransomware Group? The Gentleman Adam. Did we wind up with a picture of the person and their house and their favourite coffee order. Because that's usually how these things go.
C
That is usually how it goes. Unfortunately, in this case there is not a picture of the guy or a picture of his house, but there is at least his name and all the things that he's done in his career. So, yeah, very cloudy. Classic Krebsing.
A
So we expect the news of the arrest in three, two, one.
C
I mean, except that he's in Russia and presumably has been, you know, bribing all the people to get, you know, the sort of protection that you normally get in Russia. But yeah, this was a ransomware as a service offering that is of course run by a guy who started somewhere, you know, started his career at some point many years ago and has had terrible OPSEC or had not perfect OPSEC since he was a baby, which makes sense because babies are, why would babies have good opsic? So you had to learn somewhere. And Krebs has pulled the thread and has some details about the guy in question. And yes, like let's hope that he doesn't go or maybe he will go to Thailand on holiday and end up in custody somewhere else. But yes, just classic Krebs ing exactly what we like.
A
Now, speaking of ransomware, and this is our final story this week, everybody should know NIST is on it. They have solved the ransomware because they, they have released this internal report, Ransomware Risk Management, a Cyber Security Framework 2.0 community profile. And people are clowning on it, like this user on Infosec Exchange Crow, who said, I stopped reading at this point and then quoted from the document. The document said, avoid having vulnerabilities in systems that ransomware could exploit. I mean, I think that's great advice actually. Why would you stop reading when there's such a fabulous advice?
B
The problem here is this gets read by a CISO and that CISO looks at that and goes, that is great advice. And the CISO calls their leadership team meeting and says, team, new project, top priority, drop what you're doing. Enumerate everything that could have vulnerabilities that ransomware teams will like. Months long project gets spent up, so much time gets wasted. And that's the thing that infuriates me about this, is that it's one thing to clown on it, it's another thing to know. This gets into ciso's hands, this gets into C level executive hands and it turns into work that just distracts people from the actual legitimate defender work they should otherwise be doing. So it's like, you know, if you're gonna do this, don't do it in a way that's gonna have those ripple effects is what really gets me.
A
And on that note, that is actually it for this week's news. Adam, it's great to have you back in the, in the co host chair, Rob Joyce will be taking your spot next week and then you'll be back the week after. But yeah, Adam, James, thank you so much for joining me to talk through the week's news. It's been a lot of fun.
C
Yeah, thanks very much, Pat.
B
Thanks, Pat. Another amazing week.
A
That was Adam Boileau and James Wilson there with a check of the week's security news. Big thanks to both of them for that. It is time for this week's sponsor interview now with Adam Poynton, the chief executive of Knock Knock, a startup that I'm actually on the board of. I have to disclose that and I have some shares in, in the company as well. Knock Knock, super simple idea. It's network allow listing, right? So you've got some service on the Internet, whether it's a web service, whether it's an enterprise software, ssh, whatever it is. And you don't want to expose that port to the whole world, but you want to allow your users to be able to access it. That's what Knock Knocks for, right? So it actually instruments your existing firewalls. It can do that for things like Palo Alto firewalls, Fortinet firewalls. It can even do it on host directly by manipulating their own firewalls like Windows, Linux, whatever. And the idea is everything's closed and then if you, the user want to access that service, you just hit the Knock Knock web app while you are authenticated via SSO and you just hit the little button that says open up the port and it does and then you can go and use the service. Now this is a product that is becoming increasingly popular. Things are going really quite well for Knock Knock at the moment. But you know, they dog food their own stuff and they hit a little edge case problem which was Adam, the chief executive is using an AI assistant or an AI agent that's not on his box, it's on a different ip. So how could you then delegate access if it needs to SSH in somewhere or hit a repo or something like that? Like how could he solve that problem? So he solved that problem. So that's the first thing we talk about. And also we want to point out too that now there is a gray noise integration in Knock Knock so you could prevent people from Getting a dodgy IP allow listed. If they happen to be behind a dodgy ip, you can check that with gray noise before that connection is allowed to be opened to that ip. So that's a, that's a cool new feature. But here is Adam talking about why he built the feature that enables AI agents to have delegated just in time network access via knock knock to various services. Here he is.
D
Yeah. So why we built a disk is we had a genuine need. And the need is I'm a user. I'm at a IP address. Like I have an agent somewhere. It might be in my same environment, it might be elsewhere, it might be my, you know, Mac mini hosted somewhere or whatever. That agent needs access that I have from a network perspective within Knock Knock. So I log into Knock Knock, I have access to five things. I want one of those to be shared with my agent for 15 minutes because I needed to pull some data down, do some analysis or whatever it is. I don't want to just give my credentials to the agent. I don't want to do permanent delegated SAML identity. Scary. I don't want it to impersonate, impersonate me and do everything it can. So we're like, well, just in time. Network access that I give to my agent and say, you know What? You've got 10 minutes, buddy. Go and do the thing. It pops up in knock knock and says, you know, do you want to let this agent do its thing? Yes. And then it has 10 minutes. It does whatever I've tasked it to do with the network access of essentially delegated for a period of time, just one little piece and I can kill it at any moment. So it's kind of allows us to have that network exposure given to an agent and control it and see it, rather than like, just give it my credentials or just give it a personal access token and say, there you go, go for it.
A
Yeah, good luck. Good luck. Let me know when it's done. And you notice that RMRFING prod. Yeah. So, like what you just described there, the workflow is, I'm guessing you've got a way for the agent to actually request the access. Like, you must teach the agent how to do this. Or like, how does that work?
C
Work?
D
We're toying with that. There's two ways we kind of handle it. One is the user actually says, I want to create an access path for the agent. It gets URL. We give the URL to the agent. Hey, you just need to hit this up and then go and do your Onward, access from there.
A
So it's like you hit that URL, it's got some token in it, and then bang, that token unlocks the access for 10 minutes. You can hit this git precisely, but
D
it does actually give it back to the user to say this agent, this browser from this location is trying to access this thing. Are you sure? And then you say, yeah, go for it.
A
Okay, so that's what you meant earlier when you said it pops up and asks, right, so you've already got that URL, given it to the agent, and then when the agent tries to use it, you get the. Are you really, really sure that you want to let an agent do this?
D
Yeah, exactly. That's like the just in time approval bit. You could of course give the agent an API key to then have access. But that's the more permanent solution. This is more of an ephemeral approach to I needed to do this thing right now. Approve, go, terminate. Done.
A
Yeah, now you mentioned it already, but this is something that you develop for internal use, which I'm guessing now you're like, oh, okay, this is actually quite useful and you're going to get other people to do it. I mean, what sort of stuff do you find yourself using it for?
D
Definitely analysis, like Read only of GitLab, read only of repos and read only, temporary read only access was the initial use case and continue to do that.
A
How do you enforce read only with a network controller?
D
I know, so we've got the identity side. Like we give it a personal access token that has read only and that's kind of permanent. Right. That might be a six month validity, but then the network exposure is zero until you then granted access. So that way you've got a bit of both worlds.
A
So yeah, it's a read only token that it can only use sometimes to prevent it from just. Just grabbing all of your source on a whim and posting it to a forum.
D
Yeah, exactly, exactly. Yeah, you kind of scope the identity and the control side down. But it's more about once you put all your assets behind knock knock, then everything's invisible. So you kind of have to then start saying, well okay, I need this system, this agent to touch it, get data, do its thing. How do you do that?
A
I'm guessing, like I can see why you built this and it's because you needed to, because you're dog fooding knock knock. And all of a sudden you've built an agent that is being hosted elsewhere and you need to do something, but it can't access anything because everything's knock knocked. So you need to be able to delegate that access. All right, cool. So I'm guessing what else? Like SSH access?
D
Yeah, SSH access for transfers and file moves and just like runners that do work, things that do work, that are in an ephemeral location rather than having always on from, you know, an AWS host access to. So we just give it temporary access if the user's doing something interactive. Or we use the traditional approach of giving it an API key, it connects to knock knock, it opens up access, it does its thing permanently, but still just in time.
A
Yeah. So who else is using this? Have you given it to other people yet to have a play with?
D
No, not really. It's still internal. We've got somebody that's very keen on it. But we like to do a lot of dogfooding and testing and early discussion around gray noise. We caught one of our guys on a shared IP as part of their test testing and VPN and gray noise stopped that, which is fantastic to see. So we kind of like to dog food things for, you know, six, eight weeks to really thresh it out.
A
Well, let's, let's actually, let's actually talk about the gray noise integration now. So that's one thing that you've introduced. So of course, you know, allow listing IPs is great. Right. So someone wants to connect, they go through their, you know, IDP knock knock, grabs their ip, adds it to an allow list. But if someone's trying to log in from like a really dodgy ISP in Indonesia, which has been my experience, I've done this before where like there's 20,000 compromised boxes on there trying to own all of the Internet all at once. You probably don't want to allow list your VPN to that ip. Right. So we thought, well, what's the solution here? And you know, applying gray noise, a gray noise lookup to every login event actually seemed the way to fix this. So if someone is trying to log in from a dodgy CGNAT gateway, you could just say no. No, exactly. That's just not somewhere we want to allow this to. Right?
D
Yeah, exactly. So it brings that just in time blocking last mile. Like do we really want to have this source in? And like the gray noise thread intel data is huge. So applying it just at that moment with knock knock in the picture is a great, great application. Great outcome for people that find themselves in a hostile environment, but may not necessarily know know.
A
Yeah. One of the interesting things about this too is that companies like gray noise. Like where threat actors have been able to chip away at their effectiveness a little. And the way that they've been able to do that is by using residential building, these residential proxy networks. Right. So they might use an ip, a compromised home device. They use an IP once and then they're gone forever. What's funny though is when you're dealing with like the knock Knock use case where you have a user authenticating to an idp, the risk you're trying to filter out there with gray noise is someone using a bad gateway. Those IPs are a different set to the residential proxy IPs, which gray noise probably doesn't have. But you don't need to worry about them because your users aren't going to be logging in from one of them. Does that make sense?
D
Yeah, it's the block everything and only allow after user is valid experience shifts it from trying to identify bad things and block them, which you can't do with res proxy proxies. But the knock knock approach of block everything and only allow them after they've, you know, proven their identity, then, yeah, you kind of avoid that problem. It shifts it.
A
It's a big problem to avoid, man. It's kind of what I'm getting at. So this is, this is good. Now, of course I disclose it every time we talk. I'm on the board of Knock Knock, you know, I'm pretty involved with your company and so I've got a bit of insight into how the business business is. And what's been amazing to me is watching knock Knock become suddenly very hip and very cool. And it's because of AI, which is funny because it is like the least. You don't have any AI in the product at all, which is like really not the done thing in 2026. It's like having a slide deck raising money, saying we don't do AI. But oddly enough, it is the AI age that is really driving a lot of interest in Knock knock at the moment. But I mean, it's kind of wild actually, the degree to which it's like now all of a sudden catnip for sysadmins.
D
Yeah, well, prevention, you know, has always been the thing. But then when you've got this automatic AI is eating everything, what do you do? How do you respond? So applying it now just makes more sense than ever. And people are looking for solutions and we're one that solves the AI is coming to EDIS problem by just buying time. And a funny thing is like we've spent, spent 30 years trying to remove friction from everything. You know, like our payment friction and all these things, remove all the friction and make it streamline. And now we're suddenly saying, well, actually, we need to bring humans back into the future Loop or on the loop or whatever, add friction.
A
A little bit of friction might be nice. A little bit of friction might be nice, actually. Yeah.
D
Yeah. And it can't be the friction, which is like, oh, you know, are you sure? Are you sure? You sure? Because everyone just clicks the. Yes. Don't ask me again. But. And it needs to be this, like, human on the loop, bringing the human in at the right point in time. And we're still. Everyone's still working out exactly what that blend is, but it's why we're here. Because Knock Knock blocks everything and then specifically allows. Which. When you're trying to, like, stop the wall of automation, it's a very effective way to say, all right, everything stopped. Let's selectively go through. Which is.
A
Which is great. All right, Adam, point. And thank you so much for joining us. Us to talk about. Yeah, cool little tools you're building. And we should mention, too, that's not out yet, the stuff with the AI agent delegation, but it's coming soon. Thanks for. Thanks for checking in to tell us all about that. And I guess the Gray noise integration and everything. Always good to see you.
D
Yeah, ditto. Pleasure.
A
That was Adam Pointon, chief executive of Knock Knock there with this week week's sponsor interview. And you can find them@knocknocio. So knock knock without the second. It's a bit confusing, but sure. That's the name of the company. That is it for this week's show. I do hope you enjoyed it. I'll be back soon with more security news and analysis, but until then, I've been Patrick Gray. Thanks for listening,
C
Sam.
Date: June 17, 2026
Host: Patrick Gray
Co-hosts/Guests: Adam Boileau, James Wilson
This episode of Risky Business dives deep into the week's biggest security headlines, centering on the Anthropic AI model guardrail fiasco and the organization's apparent lack of political savvy. Hosts Patrick Gray, Adam Boileau, and James Wilson dissect the intersection of AI hype, government intervention, and communications blunders. They also break down pressing updates in the infosec world: supply chain changes, attacks on enterprise software, Microsoft patching woes, vulnerabilities in “modern” AI-driven apps, new encrypted collaboration frameworks, trends in LLM SEO poisoning, and more.
Throughout, the hosts bring their signature blend of pithy humor and weary expertise to a week when the security news was especially fast-moving and at times, surreal.
00:45–10:40
Key Points:
Memorable Quotes:
On Anthropic’s Political Tone-Deafness:
10:39–12:55
13:36–16:46
16:46–24:27
26:02–30:38
30:40–33:41
33:41–38:39
38:39–44:16
44:16–45:32
45:32–46:54
49:15–59:12 (sponsor section)
The conversation is brisk, skeptical, and laced with gallows humor about the persistent failures of both technology and bureaucracy to keep up with modern security demands. The hosts rely on real-world experience, wisecracks, and a willingness to question both vendor and regulator narratives.
Summary prepared for those who want all the insight (and some of the spirit) but none of the "waffle."