Loading summary
A
Testing, testing.
B
Hey, everybody, Would you like to see a crooked finger? Would you like to see a crooked finger with some amazing music? Let's bring out the Crooked Finger with the amazing music, and then we'll see what happens from there. Hello, everybody, and welcome to another edition of Black Hills Infosec. Talking about news. I'm your host, kind of John Strand. Since I don't think we got Corey trying to join. But look at him. Look at him and laugh. Look at him laugh and point about the fact that his video is not working.
C
Maybe his cellular is on.
B
Maybe. Yeah, maybe he's trying to do it from his phone in a passenger seat of a diesel pickup.
D
Listen, listen. The images you're about to see may shock you, okay?
A
Oh, my.
B
We've got a haircut.
C
No, no.
D
That's what everyone's been saying, that I got a haircut. No, I just changed my spot.
B
It's in a slightly different spot. It still looks good.
C
All right.
B
I feel like we got ESD coming and going, though. Ah, yeah.
C
Every time Corey gets on camera, there's more.
A
There we go.
B
One day, it's just gonna be like, it.
D
It's just gonna be me in a jungle and like, you can't even see my face. Yeah.
B
Cats growling around. Be like, is that. Is that. Is that an ocelot behind you? Got him to keep the Puma company.
D
So that's the goal. That's the goal.
C
He's really gonna connect with the earth.
B
This is our last show of the year, everybody.
C
I just read that. I was like, holy moly.
E
Oh, I didn't even realize that. I'm glad I came.
B
Yeah, it's kind of. Kind of closing it out, so. But you know what we're not gonna do today? We're not gonna do the year in review and the predictions.
C
Oh, my goodness. What?
D
I was just gonna say we kind of a slow news.
B
Okay. We can totally do some predictions. Let's do some stories first.
D
Yeah, there's not many predictions. There's not many good stories.
B
I think there's some good.
D
At least not on my radar. There's. There's the Roblox one. Oh, that one.
B
Let's talk about that.
D
Really? It's not really newsworthy. It's literally just kids complain when you take away Roblox. Like, it's not.
B
I think that you're right about that one. I mean, they do just complain.
D
But.
B
Between this and then what happened down in Australia with the social media ban for kids, I think it points to a bigger trend that's happening. And I don't know how security is going to fit into it. I just don't. I mean, are we going to be getting called into boardrooms where it's like, okay, we need to validate the age of everybody that's coming to this particular website? That might be where we're going. Is that going to be under our ban banner? Kind of hope it's not, because that type of HRA type thing kind of sucks. But everything kind of rolls down to security anyway. But now that's the only hot take I have on it, is you have. They're going to ban it in Russia. And I think it also kind of ties in what's going on in Australia. And I don't necessarily have an opinion about that right now.
D
Whoa, whoa, whoa. You can take away social media, that's fine. Taking away robots, that's a different story.
E
You gotta, you gotta be careful. This, this may become a world of tank situation with this Roblox server. The next thing you know, like, all the rooms.
A
You never know.
B
You never know.
D
That is a good point. That, like. Okay, so I think the only. So we talked about it last week, basically. They did. I think they banned it officially last week. And now this is just the fallout article being like. I mean, the quotes, the quote in the article is pretty funny because the person literally said they have gotten a message from literally every child in Russia.
B
I think they said every second child. Every second child.
D
Every second child aged 8 to 16. So I mean, yeah, that's what you'd expect.
B
It's like everything else that's going on in Russia. But this, this is the line. This is what makes the world.
D
So how long until we get Roblox?
C
The other thing. Are you.
D
That's pretty good. I, I think the other, only other interesting tidbit in this article is that Roblox casually dropped in the article that they have responded to Russia specific takedowns of LGBT type controversy.
B
Yeah. Which is like, it was immoral, I think. Is what they said some kind of like moral fabric, blah, blah, blah, blah. And it's like, have you seen the Internet? And that's what bothers you? I mean, okay, I see. All right.
D
Nation state specific takedowns. I mean, I'm guessing this is the norm. But like, would they do the same thing for America? Would they do content takedown if Trump is like, I don't want this on my platform.
B
But I think that, I think that we've already seen that. Right. Like, if we're looking at like Google and Apple, whenever they talk to China, they're willing to do things for China, but there's no way they would do for the United States. So I think we've already seen large organizations that have that kind of difference in the way that they handle different countries. And I think, I don't know, it seems like a lot of the companies, whenever they started out, they had like, you know, this idea of a moral fabric. And then it was like, you know, what's awesome?
D
And money is better than morals.
E
Well, well, speaking to that moral fabric, right, like Sony, Nintendo and Microsoft have all backed out of Russia. It's just Roblox.
D
Good point.
E
Right. So they are company.
A
For now, 2.
E
Million active daily users. So I don't think I used the data center that I first got hired at actually used to host Roblox servers. Like that was one of our big contracts. It was cool until you get ddosed every weekend, kids calling us while they're ddosing us, asking it, telling us, yeah, no saying, you better give me a server or we're gonna continue to DDoS you.
D
Charles, Charles, you sound like you're straight out of Ventrilo right now. And I absolutely love it.
A
What is going on here?
D
It's something about your mic. It just, it's hitting a nostalgia thing for me. And I love it, I like it.
A
I guess we're gonna work with it though.
D
But hell yeah, yeah.
C
Yeah.
A
I just think that like I said with like with Nintendo there, it's always gonna be some kind of Mario go round, right? You're gonna see like, okay, right now is Roblox next? It could be Kirby's adventure. Maybe Mario might do something wrong one day. We just never know.
C
Right.
A
And it's interesting to see what the kid, how the kids are gonna respond. Are we creating the next generation of programmers and open source people that are just gonna start, hey, you know what? You could take Roblox, we're going to go Roblox. You take Roblox, we're going to go with something else.
B
See, and I want to continue on that thread. I want to pull that thread because I think kind of what you're getting at is I think that a lot of people that make these choices, two things. One, I think they don't know how the Internet and how technology works. Right?
C
Right.
B
Like, I think that they don't understand that there's a way to try to hack around a lot of these things. And the Internet is not Facebook and Roblox and Minecraft. People are going to find other creative things But I also don't think that that's necessarily their goal. Right. Their go. It necessarily reducing it to zero. I think their goal is reduction. And I'm not just talking about the Roblox issue. I'm talking about anytime that they try to ban social media in Australia, there's a bunch of people like, well, that's just stupid. They're going to get around it through this way and this way and this way, and they're going to use VPNs. That's fine. I think that they're okay with that. I think it's more of an issue of fragmentation and reduction. And I'm sorry, I'm getting to a point on this and it's taking me longer than I should, but I'm really tired. And I think somewhat it goes back to Arab Spring, honestly, because when you looked at Twitter and what happened during the Arab Spring, the ability to use a single platform, that kind of became the platform that everyone was using for Egypt and, you know, other countries that had kind of takeovers. I think that's terrifying to some countries. Right. If you have that type of platform, that's kind of an uncontrolled. That is a problem. And I think sometimes when you're looking at Russia doing this or China is already doing it with video games and all kinds of other things, they have been for years. I think it's less of an issue of trying to reduce it to zero and it's more of an issue of reduction and fragmentation. So you don't have that social media platform that's as big as Twitter was, where it can create this movement across these different countries that and not be controlled by the governments. So that's. That's kind of like if we're getting into some kind of weird takes. That's one of my weird takes on this one as well. And I already think we spent too much time on this.
D
Yeah. Well, so people in the audience, John, are curious where you are. So can you state if you can play Roblox or cannot play Roblox where you're based?
A
That's the Olsen Challenge.
B
Yeah, I can. I can play Roblox.
D
That's all we need to know.
B
I'm at Denver International Airport. I just looked at the facility for Wild West Hockey Fest at mile High for 2027. I'm really excited about it. Somebody says he looks like he's in a Subway sandwich shop. I'm in the United Red Carpet Club.
C
No way. They have wallpaper there at Subway.
D
Yeah, I was going to say that Wallpaper is way too bougie for Subway. Are you kidding me?
B
It is.
D
Subway bread is only 30% bread.
E
I really hope one of our listeners is at the airport right now and can run.
D
Okay, yes. This is not. We do not condone this or encourage it. Do not do this. That's how you go to jail. But yeah, anyway, let's move on. I guess, unless, I guess now that I think about it, it is very normal for countries to follow or companies to follow the laws of the countries they're based in. That's just how it is. Like you. You just have to. Yeah, you have to pay the troll toll to get sovereign nations to agree to do business with you.
C
I guess. Yeah.
D
All right, what else we got?
B
I. There's a story we could stay on Russia, but I would like to talk about the Google killing off its Dark Web report. I think that takes. Interesting. What are your takes on it?
D
So, as the resident Dark Web fake expert, I think the first of all, I was also surprised to learn that this existed. Like I, you know, Dark web information like flare reports and credential exposures and have I been pwned and all that kind of stuff. I definitely agree with their logic of it being just impossible to really know what you're supposed to do based on it, especially for the end user. Like, to be honest, we don't even. We have trouble getting our customers to understand how this all works and do stuff, let alone just a random person who's subscribed to Google Want. So I definitely don't think the information is that actionable for people. My only thing that I really hope is that Google still does all of the stuff they were doing before, which is like protecting the accounts, even if they're not telling you they are, if that makes sense. So like making sure that if Dark Web credential disclosures happen that they invalidate session tokens and invalidate credentials and accounts so that, you know, things are safe, user accounts are safe, if that makes sense. So it's like I don't care that much that they tell you. I just still want them to keep protecting the accounts based on Dark web data.
C
This is classic Google killing off another service.
D
They love killing.
A
I'm not surprised.
C
Yeah, but it's.
E
It honestly sounds like a service that none of us even knew about though.
C
Yeah, unless you had Google one, which most people don't even want any Google stuff.
F
I don't even know it has Google One. They gave it to me for free and I still don't know what it.
C
Is.
B
Do you think like, like, seriously, if I was in charge of this, it'd be like, okay, how can we make this more user friendly rather than just throwing it away? Right? This also makes me wonder how many people, like if you think about your aunts, your uncles, people that are not computer savvy, when let's say that they somehow stumbled into this report that none of us knew about, right? And they looked at it. I talked to a lot of people that get compromised and they blame Google, they blame Yahoo, they blame, you know, Hotmail or whatever. They're like, oh yeah, well, Google clearly let them hack my account. And it's like, well, what was your password? What was password? 1, 2, 3, 4. I wonder how much of it by showing people just kind of the dark underbelly of computer security and the problems security perspective of their accounts for blaming Google.
D
Right? Yes, that totally happened.
B
I think that that may be part of it as well.
D
Yeah, no, that is definitely a thing. We warn our customers about that. So like, here's a common scenario. We encounter with our customers. They. We've actually had this both directions. One direction is an employee of a customer's stuff gets hacked, right? They get hit by info stealers and then we pick it up because it's their work email. We check their work credentials, they aren't valid. But then we tell the customer, hey, you need to tell this person because they have like Netflix, Amazon, Chase, like all these other logins are exposed. But. But then like the situation there is incredibly awkward to go to an employee and be like, you got hacked. We know about it, but it wasn't our fault. So the other thing that we've had happen is we've had customers tell us, hey, can you validate this? Because some employee signed up for a service like Google One's dark web information and it said that their work credentials were compromised. And so they thought that we got breached because of that. So it's like basically all of this whole situation just leads to confusing outcomes for everyone. And so I'm not. I get it. I get just being like, nah, we're out, we're good.
C
Yeah.
B
Because years ago, I can't remember the name of the company, but Recon Ng had a module. We got an API key for like $5,000 where you could. It was kind of like, have I been pwned? But you could get access to the hashes and the credentials. We demonstrated it at derbycon and we demonstrated against the FBI with permission from the FBI. We worked with them before we disclosed it. In the issue at derbycon. And it was a cool presentation by Tim Tomes, if you want to go look at it. After that, we had a whole bunch of people that would call us up and they would say, yeah, can you look that up for us? And we would. And we would sit down and we'd look it up and then we'd show them you have like 47 credentials that are compromised out on the open web and things like that. And then they would get mad at us. So we thought it would be a great sales technique, right? We could do it. We could show them, hey, here's the things that are out there. This is the stuff that we're seeing and here's some things that we can help you with. And almost immediately it was like they would get angry, right? They'd be like, how did this happen? Where these credentials come from? Where are you getting this information? How come you have this information? What are you doing? That's illegal. It gives you this. And it got really dicey. So killed it after like two calls. And I still to this day have people that are starting up pen testing companies that come to me and they're like, so I got this idea for getting customers. What we're going to do is we're going to find companies that have a lot of data breach. We're going to reach out and set up a meeting, extortion style marketing, show this. And I'm like, don't do that. That's not going to work. And they get all excited and they're like, well, we're going to give it a shot. We're going to give it a shot. And then they usually call me up, they're like, yeah, we did that. It didn't, it didn't, it didn't the way that we thought it was. So there's definitely a shoot the messenger aspect to this.
E
From the other side of this, right from the blue team side, I have had this where I've had to reach out to contact and be like, hey, I found your account. It's your personal account. But if your personal account's on here, probably means your entire passwords are all locked. Did you save any work passwords on there? You said you did it. We're going to reset your password anyway. Like, usually the moment you say anything, that's the. I guess that's the one thing about being like insider defense. Usually everyone immediately jumps to you the moment you say, hey, you got something. Where as from a red teamer or an attacker, I could definitely see the suspicion being built as you telling them about it. But I wish, I wish I would have known about this because I would subscribe to it to tell you the truth.
B
Yeah, right.
D
Well, yeah, I mean at the end of the day like this information isn't going to blow your mind. It's going to be like. And also the to kind of like I know we've kind of maybe talked about this article a little too long. The other hilarious scenario and I tell customers is all the time no one's. There's no validation of this data. And we've actually seen instances of a threat actor was trying to hack our customer, was saving the logins they were attempting against the customer in their browser that got hit by info stealers and then we reported them as credentials and they said this isn't credentials, this is a hacker trying to get into our site. So like there's no validation of the data.
E
Right.
D
Like there's I can type anything. And also this very smart customer who I hope is listening also self misinformation and intentionally infected there did some honey credentials infected them with an info stealer intentionally. And so now they know they can validate like that you have good info sealer data because they intentionally breached a login that isn't a real user that they like keep track of for info sealer tracking. So like yes, it's one of those things of like the data isn't validated. I can say I can, I can go on breach forums right now and say I have a sick combo list and it's just random bs.
C
Right.
E
So what, what if, what if you had a company that could validate though like a password?
D
Well there's that.
F
Well.
E
That'S all I'll say about that. That's all we'll say about that.
D
Okay, so password.
C
I don't know.
E
Yeah, I cannot.
B
That's there's a legit company was to do password stuff. Would that mean way that they would have their password stored in some kind of access with reversible encryption that people could do those types of checks or how far down this rabbit hole are we going to go?
E
Technically it only gets unencrypted when you put your code in. I'm definitely not going to talk about product.
B
So how about we.
D
Well, so. Well but there is a legitimate point here which is that a lot of other companies do this for you already. I think obviously we're talking about password managers. Password managers do this for you already. They tell you if your passwords are compromised. Also like Mozilla can do this, like tons of other services do this as well. And so it's just kind of like an extra unnecessary step.
F
So it just seems like a not fleshed out product that no one really understood how to use correctly. And then they're just killing it off because no one knows how to use it. And it's a waste of however much it costs them to do, which probably isn't much. But you multiply that by their user base, that becomes bigger.
C
Correct.
D
If it's $0.01 per user, it's still an uncalculably large amount of money.
B
And it quickly gets to the point like, how many times have you been in presentations? They're like, the only way we're going to get security is by user awareness. And at some point, point you realize that's not going to work because the users don't care. Right. Like they, they have other things to do. And I'm not saying that like they're dumb or they're idiots. It's just they have a job and that job is accounting. That job is web dev. The job is surfing the Internet. I don't know what they're doing. I don't know what people do outside computer security. Roblox. Right. And computer security and thinking about this crap deeply is not something they have cycles in their life and that's kind of a terrifying concept because it leads to a lot of these types of breaches and these types of things that we actively take advantage of in the continuous pen testing side of bhis. Do we want to try another story, though?
C
Yeah.
D
Yeah. Let's talk about Coupang, coupang, Coupang, coupang. I don't know how to say it. I'm sorry. If you are.
B
Apologize if you're Korean.
D
Yes.
C
If.
D
If you're Korean and you know what this company is and know how to pronounce it. I'm sorry, Coupon.
F
Yeah.
D
Basically this is a breach. It's apparently the largest online retailer in South Korea, which is make. Makes it huge. It's a pretty sizable breach of, I think, what did they say, 36 million users or something like that, 33 million users. The. I think the. So basically the story goes that they raided this company, which that is honestly, to me the biggest. Like that is the biggest surprise, like I commented in the notion being like, could you imagine a US company getting raided because they got breached? Like, can you even imagine, like in the US we'd be like, yeah, we got breached, so what? We'll see you on the stock exchange.
B
Hold on. Oh, okay, I'm done. Imagining it. That was fantastic. Thank you. Continue.
F
Yeah, I want to know what company he was imagining.
A
Right.
D
Yeah. Hope. Yeah. Well, I mean, so basically, they. I don't know if this is South Korean law or. I don't. I have no idea how things work in South Korea, but basically, they raided this company like it was an FBI thing and took all their information, even though the company was court cooperate cooperating with the investigation. They came in and they got fancy blue boxes and took all their stuff home with them. I guess, basically, they've investigated, and it turns out that it. I guess it sounds like it was an inside job, but also kind of not so much of an intentional inside job. It was like a past employee who still had access and probably shouldn't have. Right.
B
It was a Chinese citizen that disappeared. Yeah, but also, this is over 50% of the total population of South Korea.
D
Right.
F
And the second last paragraph is a little.
B
But haven't the recent villages in South Korea and, like, the entire population. Yeah, let's go to the second to last paragraph. Haven't the recent breaches in South Korea been, like, the entire population? So, I mean, in comparison, isn't this kind of a nothing burner? I don't know the CEO, man.
D
No breaches.
B
I love the fact that South Korea, like, they actually have shame in their executive ranks. Like, the CEO resigned. He's like, I'm not. You know, I can't remember what airline it was. There was a CEO of an airline. His daughter got on the airplane and treated the flight attendant. I want to say poorly. It doesn't do it justice. It was horrific what they had this flight attendant do, and he resigned, too. But you would never see that in the U.S. like, I. I don't. I don't know, like, how bad of an incident would have to be for the CEO to fall. I mean, don't they hire CISOs to take the fall for them? Isn't that what you're supposed to do?
D
Yeah, don't worry, John.
F
He's gonna.
D
He. He's gonna come be the CEO of a US Company or something.
F
Yeah.
B
Very shortly. There was the second to last paragraph someone was talking about. Can we bring that up and go to the second to last paragraph and.
D
Read that real quick?
F
It's. It about how, like, the. It's very interesting to think about. Like, we talked about, you know, oh, what if, like, a US Company had gotten raided because they got breached? It sounds like. Like, it says they're being treated as the victim, but if negligence or other legal violations are found they could be held liable in some capacity. So you got breached and if they find out that you did something wrong, they could totally hang you out to dry.
E
The old no logs, no breach scenario.
D
Okay, so it's different.
B
So this is different. But I've worked, I've worked incidents where the FBI has gone in the Secret Service in some instances and has seized equipment rather dramatically. And usually in those particular situations when they do that, either A, they think that there's a scenario where there's an employee that's like there's multiple employees working together, or B, they believe that there's a nation state level component of it and they have the warrants to basically get that. Even if it's not adversarial with the company. They literally come in and start seizing servers and workstations. Now that is exceedingly rare. And I don't think that they brought ops down for this company either. I think that they were just taking hard drives of workstations. So that would kind of match up with what I've seen with some US Companies where law enforcement has done this type of heavy handed tactic. But most of the time when they do it, they either a think that there's the exigency of the circumstances, that another employee will wipe the data, or they believe that there's an agent state component and they have to move very quickly without notifying the company. But once again, I mean I can think of two in the last 25 years where that happened.
D
So it's really rare. The other thing I'm not clear on is when they talk about liability, are they talking about like, do they have the concept like we have of civil liability versus criminal liability? I don't even know if that's like in the US I don't think there's any criminal liability for breaches whatsoever.
C
Correct.
B
It sounds like it's your doing it.
D
Yeah, it sounds more like it's about.
F
Negligence, about the data loss or maybe even like the repercussions of that data loss because it talks about how much high volume phishing is there is now related to this company and how many reports the police are getting. So I imagine it's just, can they hold them liable for something just in general?
D
Yeah. But is it criminal liability or, or is it money? Because if it's money, it's kind of a different story.
B
So. But getting into it, they do have an app that is very similar to gdpr. I think it's called just looking it up right now. But you can be held liable if you haven't had. It's basically like gdpr. So if you end up. Which by the way, I had someone in London that's like, you guys talk about gdpr, but you need to learn more about gdpr. So I hear you. We're going to learn more to educate ourselves. But you can absolutely be held accountable under the South Korean GDPR in that particular situation. So yes, they do have. Which is something we miss in the United States.
E
Could you imagine like working and like some dude rushes in the office, pushes you aside, types host name on your computer. Your host name comes up and he goes, yep. And then just takes it and runs away with the computer.
F
You just go home after that.
E
That's what I am.
C
Might as well.
B
So years ago when I went to work. Years ago when I went to work for Accenture and there's video on this, I checked a few months ago from an old flip phone, an old Nokia Razor. Was it Motorola Razor? I was working at Accenture and I wasn't on the security team yet. And this guy just came into my office and he was wearing a suit and he just grabbed my trash can and I grabbed my trash can and I'm like, what are you doing with my trash cans? And he mumbled something. I can't even remember what he mumbled. But then he jerked the trash can with me, holding onto the trash can and drug me down the hallway between the cubicles for a few feet. And somebody was able screaming at this guy. I'm like, what the hell are you doing? But he was literally the equivalent of a penetration Tester back in 2000 that was hired and he was doing the thing where he's going around and kind of actively dumpster diving where he was trying to pull down trash and find credentials. And he drugged me a little bit down the key.
D
That's a pretty good pen tester you got there.
B
It's not quite. It's not quite what you're talking about.
E
I would say that's more violent.
B
Only one person stopped us from actively taking their trash. That was me. I won. That guy's a future sans instructor. Let's get him.
F
That's fine with this. Okay.
A
Is that the physical definition of try harder?
F
It sounds like it worked. Except for John.
B
Never skipped egg.
D
While we were hearing John's amazing security awareness training, I got I. Apparently executives can be held up to two years and fined. So basically you could be imprisoned for data breaches for failing to implement private proper security measures. So this could have actual jail time associated with it, which explains why they're Taking it so seriously and how, like they're.
C
Yeah.
B
Were you able to find anything in this article or other articles about how long the guy had been separated from the company?
D
It was for a year, 2024.
C
He.
D
He parted ways. So it's definitely. It's bad. It's definitely bad for them. Like, it's. There's pretty clear. There's pretty clear evidence that this guy should not have had access to the data that he did. And that's definitely on the company to. To close that out. After an employee loses leaves the firm gotta roll those passwords.
E
That's always been a detection of mine, like looking for employees who have been off boarded who are improperly off boarded. Like, that's usual thing that's floating around. Right.
A
So.
B
Well, I think the tools like pingcastle will go through and say, like, when's the last time an account has been accessed too?
E
Yeah.
C
Oh, they do a lot of stuff. I mean, they are all cool. If they leave that in like a folder and then you're on a pen test and then like it has all the passwords in it. That's great.
B
I like it when they do that. We found this folder with all of these, this thing called the SAM file from the previous pen test.
C
You should. Wow, this is. This is pretty interesting.
E
Yeah.
C
Yeah. You didn't change any of those. That's cool.
B
Now, we have seen over the years where we have seen previous years pen test reports while we're pen testing and there's a little bit of the, like looking over the bathroom stall, like, how did they do it? Like.
C
Well, either that or like, you guys missed all of this stuff. Or you're like, ooh, that's how they did it. Okay, let me try that. Let's see if it works this year. It does.
B
Yeah. There was one of the companies that I was doing expert witness stuff and they had five years of pen test reports and I got to review them. And the disparity of like the skill set, the quality was all over the place.
C
Oh, it's all over the place. There's no unifying body. There's no unifying body for the industry. So, like, you can get a pro. You can get like intern, essentially. And I mean that in like the sense of they've never actually done this, so they don't have the experience to handle this kind of test. So. But there's no way to tell.
D
So that was always me.
B
The intern.
D
You gotta start doing.
C
Yeah, yeah.
D
Me and Ralph doing red teams many years back. Same vibe. But we always Pulled it out. You know, we always, we always figured it out.
F
You always got away with that. Trash can.
D
We always got away with that.
B
But you had hair back then. I had hair back then. Everyone had hair. Everyone had hair. It was luxurious.
E
I, I didn't have hair. No mustache.
B
Modern day Scott Stapp. Look at that gu.
C
Did you guys. I did have one article I wanted to cut on for like a second. Did you guys read the. That iRobot was filing for chapter 11? Oh, no.
D
Will Smith is going to be out of a job.
C
So. All right, here's, here's, here's my interesting take on it, right? So I read the article about it and I kind of saw the writing on the raw because right now there's like a robot vacuum war with China and they're building like an army of robot vacuums.
D
So they're really good.
C
Interesting about this is the company that ended up so that robot iRobot file chapter 11. And they actually immediately during that filing sold the company to Shocker, a Chinese company. They're going to inherit all of the IP of iRobot. But what's more interesting is that iRobot was already using this particular company to build all of their robotic vacuum.
A
So like, wow.
C
It wasn't like they sold it off to a competitor. Like, they were already like part of the supply chain thing, right?
D
It was like, hey, you owe us for parts. And they were like, nah, just take the whole company.
F
Yeah, consolidation at that point, you can have it.
C
And what I think is interesting is how it's not just robotic vacuums, it's all kinds of robotic devices, whether it be lawnmowers and vacuums and other things that are being developed in China now. And from a security standpoint, right, like, where does that put us on this thing where they're essentially taking this whole market of all the stuff that lives in our house, right? The consumer market. And you know, where does that put from, like a bigger picture? I don't know, just something.
B
What we need to do is we need to do like some contact where we take one of these robot vacuums that's like industrial and use it for like get remote access to it and then bridge the wireless network. Because a lot of these devices, they're on the wireless network because they have to for activation and things like that. That's one of the things that I would look for is like, what is the back door for updates and firmware and things like that? And is there a way to bridge onto the wireless network that it's Part of. Because literally you're just bringing these things into your house. And I think we had another story about a kvm because it's not out of the realm of possibility of China doing this.
D
Vacuums up to a kvm, though.
E
Those vacuums are mapping your house too. That's the other thing.
C
Yeah.
D
You know what else is mapping my house? House though. Zillow.
C
Yeah, I was gonna say, I was.
D
Gonna point out, you can just look at every photo. Dude, you can just look at detailed photos of my house from the listing and there's nothing.
C
Do you need the exact details? I mean, honestly, they should be hiring those little robots out to do surveys.
E
I do feel like those robot vacuums, whenever my definitely comes, it comes straight for me every time.
B
It knows it doesn't like you.
E
No acdc.
B
Wait, wait, there's a funny acdc. Who made who? When it starts coming towards you because you might be dealing with a maximum overdrive situation.
A
Nah.
D
If you're in the discord and you're controlling Wade's robot, let us know, please.
B
Take pictures.
C
The Nano KVM1 was about, in essence, the device was getting created and the software configuration was just like horrible, right? And so I think this goes across the board for any kind of either consumer device doesn't have to be just from China. There's like wildly different products and product pricing. And depending on those, they might just not be able to afford really any security. But they're like, hey, it looks, it works, right? Like, we're just trying to sell stuff. Sell stuff.
B
But I also think. I also think with this as you. If you look at like the components Ralph that they build these things out of, right? Like a lot of this crap is just Frankenstein. They get the circuit board from here, they do this, they do that. And a lot of times there will be components within those circuit boards that they don't even use. Right? Like whatever they did with this little. What is it? Nano KVM that they got from China had a little microphone in it. And I'm willing to bet that they just, whoever that KVM company was, they just got access to a whole bunch of really small boards and they had lots of features that were built into them. And that's something that can be turned on after the fact is the way I kind of see it.
C
Well, something that's interesting about the Chinese market is that all of these vendors, right, they're all right next to each other. So like, hey, I can just go over here and get this board. These already. I'll make this and we kind of put it all together and they didn't have to like call around the world and get them all shipped in. They're like literally in the same building almost. Right. And so, I mean, this is economies of scale for them to develop this stuff. So.
E
Yeah, I thought the nano KVM more interesting part, it was beaconing back via dms, right?
C
Oh, that's.
E
It was hitting. It was hitting things, which is classic.
D
But things are straight up. Implant.
E
There's a reason my baby monitor isn't on the network anymore, man. Like, as soon as I. As soon as I hooked up the ubiquity, I realized that my baby monitor was hit in China. And I was like, this is.
C
It's funny because you mentioned that because we're actually working on building ESP32. What do you call it? Implants. Right. Drop devices. So this is ESP32 with a POE. So you can just drop one of these little bad boys as opposed to like the traditional ARM based system, or not arm, but like Raspberry PIs. Right. Super low power. Same idea, though, Right. Like this. That's exactly what that chip's running in those KVM's. They're like. It's a RISC chip, which is in essence like the equivalent of an ESP32. But they're so much more powerful now that you could do all kinds of tasks. It's pretty wild.
D
Put a mic in it. The Chinese people gave you an idea. Put a mic in it.
C
Yeah. No, you could totally put. You can put all kinds of fun stuff on here. It's just you.
E
Could I bring my own VM on there?
A
No.
F
Good Segue smooth.
B
Only if it's qmu. Corey, tell us more.
D
I have no idea what article this is.
B
You hit him.
E
Red Canary one.
B
Beyond the Bomb. When adversaries bring their own virtual machine for persistence. Which I think is funny because we've been using virtualization.
C
Yeah.
D
We've been doing this for years. EDRs are the thorn in our side.
G
Yeah.
B
So I don't know if anybody else had read this, but they base the one thing that I thought was interesting and Wade, I wanted to get your take on this was the spam bomb. I'm trying to figure out how we go from spam bomb because they show like the timeline. They're like, spam bomb. A spam bombing. And then it's like initial access. I'm like, how did I get from point A to point B? I missed how we did this.
E
There's a social engine they called Is that how they.
C
Yeah.
B
So they spam bombed them. And then they called and said, hey, this is your service desk. Are you having any problems with your email? And the guy was like, reading the doc.
C
I've got all.
B
I was reading the timeline wrong. Okay.
D
This is an ancient technique. This is.
C
This is.
D
This is for two or three years.
B
Words other than the pictures, John. Thanks, Andy.
E
So I found this article. I found this article somewhat interesting as like a defender because, like, I think the hot thing is more of like, bring your own vulnerable drivers. Right? That's the. That's the thing. Or bring your own, like, executable in and then that. I. I actually haven't seen VMs as much, so I'm actually. I'm not surprised you guys are using it. But I will tell you this. From an intel standpoint, Red Canary usually writes some of the best intel reports, and this report is very good. So I was a little disappointed when I got to the end and all the IOCs were. Were just IPS and hashes. There's no. There's no MITRE stuff. I was like, were they rushing to get this out because of something? Or would. Did they just not want to do the hard, like, the five extra steps?
C
So how big was this vm, though, that it had download?
F
That's what I was.
E
Not big. Not big.
B
It was really small. But I think it did get bigger.
E
They brought it over. They brought it over via rmm and then they ran a couple commands, threw it up, and then I believe they did sliver C2 in order for C2. And then.
B
Because, of course.
E
Of course. Right. And then Red Canary was able to see the actual server via Shodan, came back at it, which. Which was amazing. Always good to do that. And then they found a couple other things for actual, like, socks boxes.
B
Wasn't this a Windows 7 box? Because they were in the book.
D
This is just a really bad pen test.
E
It is a Windows 7.
D
They use Windows 7.
E
Come on, dude.
C
What? The target host was Windows 7?
B
No, that's what I was trying to figure out too. You can afford. So you can afford Red Canary, but you're still running Windows 7. There's like. There's. There's. There's a dichotomy happening in this report that kind of like. Like is interesting.
C
They download the whole Windows 7 VM.
D
Correct. And then make a Linux VM.
C
Like, why Windows? I don't understand.
D
It's so bad. It gets worse. They downloaded a Windows 7 VM and then they just C2'd it and then just use it to launch beacons in their network. Dude, just. Guys just use ssh. If all you want is a network proxy, you don't need to freaking download a qa.
B
Yeah, I think it was a joke. I think that they set up like a. Like an iron hacker challenge in China. They're like, okay, here's what you got to do. Here's what you got to do.
C
Okay.
B
Okay. First you got to use QMU. All right. Then you got to use Windows 7. Then credit this thing.
E
Yeah.
D
Was this that try hack me advent of cyber but in China or something.
C
It would kill me too. If you looked in the Windows 7 VM they had to actually like bypass Windows Defender to get their payload to run in their own.
B
Oh yeah, someone made a really good.
F
Comment in the discord said just go with what Claude knows. Imagine they're just trying to use AI and it's like, well, first install Windows and like, okay.
D
Hey, I see an ISO.
A
Let me grab it. There we go.
B
This is the strangest hack the box ever. I don't know.
A
Yeah.
D
I will say though, I don't think this is China. If anyone, this would be Russia. They're like, it's. It's the only Windows 7 licenses we had an ISO keys.
C
TXT.
D
This isn't China, dude. China would be using red flag OS or something.
A
When it. When in doubt, blame China.
C
Yeah, I do. I do want to know where this Windows 7 image that was so small is.
B
Yeah.
D
Why didn't they put that in the IOCs? Why didn't they put that on IOCs?
F
Just a link to download it.
B
Did you find it in your environment? Just. Just delete it just. And make it go away.
C
Oh my God.
D
Executives hate this one trick to keep Windows 7 running without violating compliance requirements.
C
Yeah.
B
Oh, trying to find the next story. There's a lot had another like way to drop malware on supply chain.
D
This isn't the first one and probably.
B
Won'T be the last one of many. It seems very similar to the old school GUAP generic update process exploit that existed a number of years ago. But there's been a couple against Notepad for their similar to this as well.
C
You guys use Notepad?
B
Notepad.
D
We have VS code older languages such.
B
As FORTRAN and COBOL that has.
D
That's the reason to use it.
B
That's the reason right there. I thought it was weird that that was in the article about this attack. I just threw that in there. I just feel like the author of this article. A PC world is like a Hardcore Notepad plus plus. And he fights with people. He's gotta sneak that in. He's like, well, if you're using Fortran, it's like, no, I'm not.
E
I'm still. I'm still a hardcore Notepad plus plus user.
C
Oh, dude.
E
Why regex? Like, I can easily use regex. I can add characters when I'm doing mass amounts of queries. Say someone throws me an IOC list, I can add an OR in front of everything. I can parse it.
D
Say the line.
A
Hey, wait, I was once guilty of viing everything but VS code has slapped my hand to.
D
Yeah, you can use vs. You can use VIM bindings in VS code. That's what I do.
A
I do.
B
Yep.
A
HJKL always.
E
It's just nice. I don't. VSCode takes forever to launch sometimes no pattern. You know, it doesn't support 90 of the time.
F
Versus code sucks. Just use like cursor or something. That's so much better. Right, right, right.
B
I just use said knock from the command line as my editor. So there are some extensions available for trans syntax highlighting and.
C
Yes, perfect. Yeah.
D
Hey, those are malware. Those are malware.
E
All right, we got, we got 15 minutes. Let's do predictions.
B
Do we want to. Do we want.
D
Oh, are we actually going to.
E
I will give, I'll give my hot take prediction.
D
Okay, you want to go first?
E
Go, I'll go first. More Salesforce application breaches.
C
Yep, agree.
E
I think that's going to be a key one. Make sure you profile. If you have Salesforce go in there, grab the log, start profiling all those apps and just make sure they are talking from the right IP over and over again. It's pretty easy thing.
A
Yep.
D
That's on our radar. We're already simulating that attack against our customers and it's been eye opening to say the least.
E
Yeah.
D
All right.
B
I think my prediction is. I think 6, 7 will stop being funny.
F
We're gonna be into 2026. So it has.
C
It's gonna be the year of the six.
D
I think that's a prediction for 2027.
B
This monkey's gone to heaven. But my, my real prediction, and I hope, I hope I'm right on this one and I very well could be wrong. But, but I think that this whole kind of down slowing of computer security hiring, I predict come summer of 2026 it's going to bounce back and we're going to see a lot more hiring. I think especially around the time of Black Hat Def Con. I think you're going to start seeing a lot of people having conversations of the AI protection and all the amazing things that we were supposed to get with AI are not securing our environments. And I think a lot of organizations are going to realize they're behind the eight ball and having people to be able to help protect their networks. And I hope to God I'm right. Because the alternative is two things. Either a, we just continue to go into oblivion into 2027, and people keep thinking that AI is going to solve all things computer security, or even worse than that, AI does, which I don't think is going to happen, but we'll see. So that's my prediction. I think we're going to see a hiring snapback around August of next year and that's just me throwing something to the wall and see if it sticks.
D
My prediction is there's some kind of AI caused cyber event that like, I don't know, I don't want to call it like Skynet type. I'm not saying, I'm not at all saying that it is like an intrusion by AI or something like that.
C
I'm talking about like, maybe it's two.
B
AI agents fighting over DNS records, I don't know.
D
But at some point there's going to be a mass Internet outage in 2026 related to something that AI did and also related to cybersecurity. So stay tuned on this podcast because I bet you that's going to happen.
F
Is that a threat? Corey? That was really specific.
D
Yes, this is super specific. If you do not subscribe to this podcast, the Internet will not make it through 2026. It will go down at least once.
H
Along those same lines, that reaches into my prediction for next year, which is that we're going to see a massive breach due to AI walls falling down from prompt injection due to asking nicely.
B
Now the question is, what do we qualify as massive? Like, are we talking front page, New York Times?
H
Yes, we're talking like front page. We're talking something along the lines of at least a solar wind scale.
E
Ooh, that's amazing.
B
Okay, okay, I dig that one.
C
I think that vibe coding and AI is going to cause a class of vulnerabilities that everyone is affected by, right? Yeah.
B
I could go with Shekis. I could go with Shekis.
C
So in essence that what would happen is, is that because everyone has decided to use AI to do all of this and the AI has the same functional issue, it creates a class that everyone you know essentially has, right?
D
Yeah, Some weird training thing that got coded into a Thousand programs.
C
And then everyone's like, oh, my God. Instead of EM dashes, though, it's going to be something like, way worse than that.
A
That.
C
Right. Like, it'll be something that everyone is affected by because they're, you know, coding in this way, even if they're not doing. Because they don't have time to look all of it because they fired half the team so that they could do more, you know, so, new attack 10.
E
I can see it being added.
C
Yeah, yeah, yeah, yeah, yeah. Don't do this. Don't use em.
A
I think, I think just to. Just to piggyback, I think think the same is going to happen in the API and web space when it comes to, like, Vibe coding and everything else. I think AI is going to set us back a lot further far as, like, even with these new AI browsers where there's some instances where within the server response you're getting, like, a username and password. And who knows, that application could have been coded by a bunch of vive coders that don't really think about security whatsoever. They just think about pushing the product out. So I do think that AI is going to cause a huge gaping hole in the world of application security. Just my prediction. Nice.
B
Nice.
D
I agree, Hayden. Anyone else have any?
C
Yeah, anyone else?
G
I mean, I was kind of. I kind of have two. Really? I was thinking about what BSD Bandit just said. Like, I think Vibe hacking is going to become, like, huge. And I also think. I'm not going to say which one, but I think that one of the major CTF platforms that's out there is going to go under.
C
Ooh.
A
Ooh. That's a good. That's a good prediction.
B
All because we're not a major CTF platform.
C
Because of, like, the Vibe hacking. It's like, too much, like, it's too trivial to, like, for the. For the AI agents to do it. Is that what you're saying?
G
No, they won't.
D
I don't think they'll be related.
C
I felt like they were.
B
I think that that one's interesting. I think that that one's interesting because there's a lot of VC funding going into this space and VC funding wants their power to flush.
C
Yeah. Here's an open question for everyone. When do you guys think, or do you think the AI bubble will pop? Like, do you think it's okay?
B
Yeah, I think it's going to be tied with all the things that we're talking about here, because I think it's possible everything we discussed comes to pass right Massive AI vulnerabilities causing organizations to pause and reflect venture capital, realizing that the amount of money that they've been sinking into AI, they're not going to see those returns for a decade.
C
Decade. Yeah.
B
And AI vibe coding, I mean, we're already seeing with organizations where we're pen testing them and we find vulnerabilities and they're like, we don't know how to fix this because this was created by AI. We're already seeing the beginning of a lot of these different things, and I don't see a good way out.
H
Yeah. And add onto that, right now you're starting to see Nvidia, their stock prices, and the stock prices of some of these other companies start breaking down. I mean, you've got Disney now investing in OpenAI to try and help keep them afloat. You're already seeing the start of the bubble popping is everybody's rushing to try and shore up the tech industry.
F
Yeah, yeah.
D
There's only way. No, it's not going to go away.
A
It's just going to be minimized.
F
It's going to be an overcorrection, which kind of ties into like what my, I guess, only prediction could be, which is a little bit selfish, I think. But I'm thinking that the trend of automating tier 1 SoC is going to continue and it's going to go well to the point where they start branching into the higher tiers of like, SOC analysis. And it's really going to start.
E
Cut them off. Someone cut them off right now.
F
It's going to start biting people. The models are going to get better and then they're going to think, well, we can just do all of it. And then they're going to start messing up bad.
B
You remember, whenever I started talking to our own internal soc, there was a bunch of people that started freaking out, like when we started getting stuff set up. And I remember having conversations with multiple SOC analysts and I was like, I don't look at AI as something that I can reduce costs. I look at AI as something that we can kick more ass with. Right, exactly. And that's what we've been focusing on is not like, how can we reduce our head count. Right. We just want to be able to do more and be more effective in what we are doing. And I'm already seeing that, like some of the, some of the crap that you guys are coming up with and what you're detecting is like top notch, but it's hard getting there. Right. And I think that a lot of organizations instead of the growing pains that we're going through. I think that, you know, one of the things about a society is it can be this black hole where you don't know that you've gotten too far ahead in your skis by laying off people and cutting costs and dropping and dropping and dropping and dropping until you're tumbling down the side of the mountain. And at that point, it's too late. And I think that you're 100% right about that. But I think if you're a Soc, you don't need to look at AI as saving money. Look at AI. We finally have a tool that can help us get caught up, and we're not using it that way.
F
I have two comments on that is I've written a talk and a half about this in the last couple of days. But the two things that I came away with are someone said this to me, is that a force multiplier only works if you have a force to multiply. So if your analysts are not skilled enough, they cannot properly utilize AI for proper investigations. So I think that really just is the crux of the issue, is you're not gonna be able to know whether or not it's wrong. You're not going to know how to prompt it correctly in the right directions for your investigations unless you are experienced enough to utilize it. And, yeah, I think that they're just going to keep pushing it further and further as the models get better without giving it time to mature. And I think it's really going to.
B
Screw some people over.
F
Yeah.
E
Both of our blue team con. Both of our blue team summit talks on AI.
F
Now, mine's actually on taking threat intel and turning it into detections. Okay, good, good.
B
I've done that already. My wish list is detection Forge. Like, this is. This is what I hope to see in 2026 from our SOC. Detection Forge is the tool that we use to create our detects, and it does validation. I want it to kick out Atomic Red Team Atomics.
F
Oh, yeah.
B
Like, when we do detection for it, it just kicks that out to the side.
F
So what we have now, John, that you'll be interested to see at some point is we can create issues for detection stories and tag copilot and it'll write a first draft and then the copilot code reviewer will review the first. And it's worked pretty well so far. One of them was really crap, but most of them have been pretty good and at least enough to where it saves you 30 minutes, 45 minutes of templating and, oh, Which Miter tag should.
C
I add to this?
F
I got to make sure the reference links are indented. Like, saves you time, but also, you still need somebody there to make sure it's right.
B
You do.
D
I think that's the important part.
E
I was going to say in a, In a combo with Hayden and John about hiring more than having the AI sock. I, I. This is what I'm hoping to see, but I think I'm, I'm being too positive, is what I've seen with these AI summaries is I could probably teach someone that does not have a lot of security experience to be a somewhat decent SOC analyst very, very quickly. And I don't think enough people are utilizing that in order to spin up or at least hire new people to get into a soc because they just don't want to pay people. But it's so easy to spin someone up right now that just has basic security knowledge and have the AI hold their hand through a lot of this stuff that I just. I hope so.
B
Here's the problem, Wade. Here's the. Here's the problem with that. We have seen people, whether it's interns, whether it's pen testers, whether it's junior soc analysts, and also talking to a number of customers where AI is doing one of two things to people like either A, it makes them lazy, and I'm seeing that a lot. To where people aren't actually trying to understand the core fundamentals of what things are coming to them, or they use it as a tool to try to do amazing things. And it seems like that's a very small subset of the universe right now, and that's a big concern that I have, is if somebody's using vibe coding, that's great. Use that as a tool, try to strive. But then you're also getting this huge percentage. And I hate to say it, but talking to my customers, I think it's like 65, 70% of the people are using AI as just this lazy crutch to where basically they're saying, yeah, AI told me that that wasn't malicious. And it's like, well, did you verify it? Well, AI told me it wasn't wrong. Yeah, AI. AI generated that code for the website. It should be fine. It worked. It passed my checks. Right. And that's my biggest concern in this industry is I hate to tell you, but I think it's about 70% of the industry, especially the younger generation, has came up and they've been using AI to generate papers. They were using all these different services and they get to the point where they have to do a job and they continue to trust implicitly this service that they have.
C
That's really what AI slop is, right? No effort. Something. But that something that they made would have taken a lot of effort, effort for someone to actually do. But it was just AI. But no one appreciates it. Because the thing that we all appreciate in this world is the recognition of the limited time we have on this earth.
F
And I have another good, good PowerPoint quote for you is one of the ones that I threw in is that AI can make a good analyst great, but it can't make a bad analyst good. Because there has to be some amount of foundational understanding to be able to prompt and correctly recognize issues.
D
Well, I think we're going to be.
B
Changing our hiring process in testers and in SoC analysts. Like, what was it? Just trying to hire a cicd pipeline engineer or developer is one of the most. Two of the most painful things I've ever done in this company over the past year. And I think that we've got to try to come up with a way where we're using our platform in our lms, where somebody wants to work here. We've got to create challenges that cannot be easily solved by AI and then try to use that, try to filter these people out. Because we're getting onto interviews with people and I don't know if you guys. I think we talked about it on the show a couple of weeks ago. We had one interviewee that we are 99% certain was taking all of the questions we were asking and answering it with AI to the point where the interviewers asked him to turn around from his computer and answer a question and he refused to do so. So, yeah, it's getting weird out there, folks.
C
All right.
D
Everyone else is becoming soapbox. I want to take my AI soapbox. I think go for it. The things, the things that we said when all this AI stuff started are still true. Like my. My claim was AI is not going to replace people's jobs. People who don't use AI will be replaced. Not AI replaces a person. Like, and I also would like to mirror what Hayden said, which is I have yet to see someone who isn't very good at their job fix it with AI. That's not. It's not going to happen it. But I've seen people who are really good at their jobs get even better with AI. Like, that is. I think what's happening is the people who are good are getting even better and more efficient. And faster. The people who suck are still gonna suck. And I think, John, like no matter how you came up in the world, like the same thing you said about, oh, I was brought up on AI is the same thing as it was in the 1950s. It's like you just listen to what your professors told you and didn't actually learn anything. Like you, you're just a parrot for information that you learned in college.
B
Or you used Google to answer these questions exactly.
D
Like I think really AI maybe turbocharges it and it makes it harder for people to figure out that, you know, you're kind of full of crap. But I think at the end of the day, like you know, like everyone else has mirrored here, if you don't know how to validate the results coming out of the AI, it you are, your output's not going to be good no matter what it is.
E
I think, I think I just realized something. We're starting to become closer to a star track order environment. You know, where your, your like reputation is your currency. So therefore, because we can't trust people, you have to trust their reputation and the people around them. So more and more, right? So yeah, yeah, you get a reputation. Oh my God. That's another black mirror.
D
Amazing.
B
It's brutally awesome.
D
It's like a skeleton with the Santa hat. I don't know, I can't tell what it is.
B
Punk rock misfits vibes. I want to call out the CTF winners. Ninja Cat. Congratulations Ninja Cat. You get one year on demand access to anti Siphon security training platform which our full catalog is available still for Black Friday. Just go to anti Siphons website and you should see a banner at the top. And then QNS came in second. QNS and they get one anti Siphon training class of their choice. So hats off to both of them and their hard work. By the way, if you're wondering what this is, join our Discord server and you'll see that there's a CTF Discord chat and you can get in there and get more information about what this is. But the point is our webcast, we're trying to add in more hands on little micro CTF challenges with every single webcast that we do instead of making them passive. So with that, let's take it out. Thank you so much everybody. Go forth and do awesome things and we'll see you in the new year.
D
See you in 26. Seven.
F
Later.
C
Yeah.
B
We'Re still here.
C
25. That.
Hosts: John Strand & the BHIS Team
Release Date: December 18, 2025
Main Theme:
The last episode of 2025 assembles the Black Hills Information Security (BHIS) crew for some spicy infosec news and hot-take predictions for 2026, interspersed with their signature banter. They dive into everything from Russia banning Roblox to Google’s Dark Web report shutdown, South Korea’s Coupang breach, smart device and IoT security woes, and then spend the last portion dropping bold predictions for cyber threats and trends in 2026.
Purpose:
Wrap the year with discussion on top infosec stories and deliver hot take predictions for cybersecurity in 2026. No year-in-review nostalgia, just current events, industry insight, and foresight.
| Segment | Start | End | |-------------------------------------------------|-----------|-----------| | Open/Banter/Roblox & Gov’t Censorship | 00:44 | 09:00 | | Google Kills Dark Web Reports | 10:22 | 19:17 | | Coupang Breach (SK), Executive Fallout | 20:05 | 30:09 | | IoT Takeover, iRobot Sale, Smart Device Risks | 31:12 | 36:48 | | BYOVM: Red Canary / Virtual Machine Attacks | 37:00 | 41:10 | | Notepad++ & Editor Brawls, Supply Chain Attacks | 42:07 | 44:20 | | Hot Take Predictions for 2026 | 44:20 | 60:00 |
The team skips the nostalgia to work through current headlines and eccentric (but informed) takes about the next year in infosec. While the tone is playful, the warning is serious: be ready for an AI-induced vulnerability mess, keep an eye on app supply chain issues, and don’t write off the human factor in defense and detection, regardless of what shiny automation is promised for 2026.