Podcast Summary
Podcast: Talkin' Bout [Infosec] News
Host: Black Hills Information Security Team
Episode: A Live Stream From Inside Lazarus Group (2025-12-08)
Date: December 11, 2025
Main Theme and Purpose
In this lively and insightful episode, the Black Hills Information Security (BHIS) crew and friends cover an eclectic mix of current infosec news and notable oddities from the security world. Discussions span from major software vulnerabilities (notably in React and Next.js), a behind-the-scenes look at North Korea’s Lazarus Group, eyebrow-raising incidents involving smart toilets, the ethics of government surveillance and app mandates, misadventures of federal contractors, and the privacy implications of modern surveillance tools. The hosts’ trademark banter adds humor and accessibility to deep technical topics.
Key Topics, Segments & Insights
1. Password Change Humor & Year-End Reflections
- [02:50] The team jokes about “running out of podcasts in 2025” and how they can’t wait to change their passwords to “podcast2026!”
- Humorous Note: The crew pokes fun at using years in passwords and how hackers are either a year behind or ahead.
2. Next.js & React RCE Vulnerability
3. What Does a Malware Developer Look Like? (Lazarus Group Focus)
4. Government Contractors Deleting Databases
5. Apple vs. Government-Mandated Security Apps
6. Russia Blocking FaceTime, Roblox, and More
- [37:42–43:27]
- Russia’s recent nationwide ban of FaceTime and Roblox, efforts to replace them with the surveillance-ready “Max” app.
- Discussion centered on what apps governments target (usually the hardest to surveil) and the implications for citizens’ communications privacy.
- The group speculates how most Western companies have pulled out of Russia but software bans are only now catching up.
7. Smart Toilets, “Anal Prints”, and Security Theater
8. Mass Surveillance Platforms & Outsourcing
- [58:02–62:29]
- Flock, a mass-surveillance camera network, accidentally exposed training materials revealing their use of overseas gig workers to review U.S. surveillance footage.
- Notable Points:
- Raises data sovereignty concerns; whose data is it and where does it go?
- Discussion leads to privacy as a persistent and unsolved issue in 21st-century security.
- Quote:
“Who owns your data? Who owns data about you, who can utilize, manipulate, analyze data that was captured with or without your knowledge?” – Ja [61:10]
9. CTF Announcements and Closing
- [56:39–57:40]
- Winners of the on-demand security training and course prizes are announced, and hosts close the show with typical lightheartedness.
Notable Quotes & Memorable Moments
- “He just looks like a guy that just got back from the grocery store and is on his 9 to 5… that’s what it is.” – Ralph [10:44]
- “Imagine the call where you get called up by the FBI and they’re like, hey, do you use Calendly?” – Ralph [19:54]
- “We joked about it in 2020… and now here we are in 2025!” – John Strand (on smart toilet tech) [50:15]
- “The most embarrassing part of this, if it was breached, would be finding out that your friend has a smart toilet that looks at their poop.” – John Strand [50:39]
- “We fixed the privacy thing by just deleting it. It’s fine. We just don’t have privacy.” – John Strand [61:47]
Overall Flow & Tone
This episode is fast-paced, humorous, at times irreverent, yet always insightful. The group is quick to laugh at absurdities in both hacker culture and the infosec industry, but can pivot into serious critiques of privacy, government overreach, and failures in basic security practice. The team’s camaraderie and genuine expertise make the episode accessible for newcomers, while deep enough for seasoned security professionals.
Timestamps Quick Links
| Segment | Description | Start Time |
|---|---|---|
| Password/2025 banter | Light start, year-in-password jokes | 02:50 |
| Next.js/React CVE | Technical breakdown, mitigations | 04:13 |
| Lazarus Group/Any.run | Attribution, methodology & memes | 09:04 |
| Contractor database wipe | Repeat offender saga | 20:33 |
| Apple vs. Government Apps | Privacy, app mandate ethics | 26:36 |
| Russia bans FaceTime/Roblox | State control, comms security | 37:42 |
| Smart toilets | Privacy theater & IoT security | 45:01 |
| Surveillance outsourcing | Flock, privacy implications | 58:02 |
| CTF Winners & close | Announcements, wrap up | 56:39 |
If you missed the episode, this summary will bring you up to speed on all substantive content and give you plenty of quotable highlights—minus the ads and banter detours!