Loading summary
John Strand
But what he buys in Mexico, he probably buys his drugs down there cheaper.
Corey Ham
He's getting dental work.
John Strand
Dental work. And he comes across the border, and he's such an. To US Border patrols. And, like, there's just tons of times where the border patrol people are just
Corey Ham
like, buddy, don't make this go ahead. Neither of us are getting paid enough.
Ralph
None of us are.
Corey Ham
Okay, so wait, off topic. Has anyone. Has anyone gotten infected with whatever this Taco Bell lettuce virus is?
Matthew Franz
Yeah, we have one that did.
Bronwyn
No, but I don't eat Taco Bell.
Corey Ham
Honestly, if you.
Ralph
If you had asked me, like, what restaurant in America do you think was causing, you know, explosive diarrhea? I was gonna guess Taco Bell.
Paul Clark
Every time.
Corey Ham
Okay, but. Okay, so here. Here's. Here's the thing. Okay, here's the thing. I. I actually think. I mean, there's. There's two jokes. Okay? Number one is the joke, which is, how would anyone know? Like, oh, this explosive diarrhea is different than the normal explosive diarrhea? Yeah, this I don't know. How could you tell?
Matthew Franz
Right?
Corey Ham
But the other joke, I will say I got to give them credit because they're doing better than the FDA at giving us early warnings of what's actually happening. Like, Taco Bell. Like, I trust them. Know what I mean? Trust them, dude. Because, okay, if Taco Bell says it's bad, that's your canary in the gold mine, right? Like, it's one thing for the FDA to be like, oh, you know, we're not going to say anything. It's not that bad, but Taco Bell is shutting down. It's bad. I mean, it's like the Waffle House index, right? Yeah, like, the. The weather's bad if Waffle House is closed. Otherwise, it's fine. Oh, God.
John Strand
All right, Corey, you're driving today. I've got to get off early. I've got to do an instructor presentation thingamajigg for the people out in D.C. all righty.
Corey Ham
Let's do this. We can go live if you want.
Bronwyn
Finger time.
Corey Ham
Hello, and welcome to Black Hills Information securities. Talking about news. It's July 20, 2026. We've got AI articles. We've got gold eagles, which is not a new coin. Turns out it's something else. We've got AI. Like I said, I'm gonna say AI at least five times before we get started just so we can get that SEO going. And we have. Not to spoil things, but there's uplifting news about flock, which you would not expect to hear because all the previous news about flock has been extremely depressing.
Ralph
Are they all going down? Are they?
Corey Ham
And. Well, you'll have to listen to find out. And we have chicken articles. So I mean, get ready. Yeah. So quick introductions. My name is Corey Ham. I'm the director of continuous pen testing. I'm always continuous and I'm always pen testing at Black Hills Information Security. Because you can't got ralph. You won't executive gator hunter at RALPH Inc. At VTAM Labs. Is that still. Is that still where you were hanging out, Ralph?
Ralph
Yeah, we. Yeah, we're a business. We have customers.
Corey Ham
It's real. That. That's weird. That's how I feel about.
Matthew Franz
Yeah, that's.
Corey Ham
That's how I feel with continuous pen testing. I'm like, are we really doing this? Is this real? So we've also got Bronwyn, the AI thought leader. You have always supporting you, the reluctant AI thought leader with the best funny jokes about why everything is stupid now.
Ralph
Why it's also just a I thought leader or just anything. Right. Just be like.
Corey Ham
It's like Ron would never identify herself in that way, which is why she's a good AI thought leader.
Matthew Franz
Right.
Corey Ham
Like, it's like the people who say they're AI thought leaders are dangerous and not to be trusted. It's the people who would never ever use that label on themselves that you really should trust.
John Strand
Yes.
Bronwyn
Well, it's even worse, Corey. Now they're starting to call me a strategist. An AI strategist?
Corey Ham
What does that even mean?
Wade
That's way better than the thought leader. Just take it.
Corey Ham
Yeah, just take it. Strategist is cooler. That sounds fun.
John Strand
Why do you think I set. I set my role to managing intern of Black Hills Infosec. It's. Yeah, so I get less spam.
Ralph
Cool.
Corey Ham
We also have Matthew Franz. Matthew, you want to introduce yourself? Sure.
Matthew Franz
Yeah, I've been in the. I'm an old guy from the 90s.
Corey Ham
Hell yeah.
Matthew Franz
I'm going to be talking about my MCP server talk. I'm really sad they wouldn't let me call it. Are you down with mcp?
John Strand
But why wouldn't we allow that? I hereby I hear of Matthew's talk to rename it to be down with mcp. Yeah, you know me.
Matthew Franz
I've fallen down the MCP rabbit hole writing rust tuis go tois MCP servers for all of this.
Corey Ham
So that's what I'm. So you're saying you're old school? Well, you're saying you're old school, but that's a. That's a new trick for an old dog. I mean, that's.
Wade
No, no, no.
John Strand
The new.
Matthew Franz
The new kids are like, anti. Anti mcp. Mc. The older AI influencers are like, no, you just need to have your.
Paul Clark
Wait, wait, I thought you meant New Kids on the Block. You said.
John Strand
You said MCP and rust in the same sentence, and that makes you old.
Corey Ham
Yeah, yeah. I mean, ARM organic.
Ralph
Right there.
Corey Ham
I was. I was at Collegiate Pen Testing Competition a few years ago, and, like, there was this one kid who, like, no matter what the topic was, he found a way to work in, like, rust and a way to rewrite it in rust. And I was like, honestly, it's kind of impressive. Like, I don't know if you're doing a bit, but I'm like, we're not even talking about writing software. We're talking about, like, where we're gonna eat for dinner. And you're, like, talking about somehow bringing up rust and how you're going to rewrite something in rust. I'm like, all right.
Paul Clark
Anyway, you weren't talking about writing software.
Corey Ham
Yeah, he was. We've also got Paul Clark, who's been on the show before. Paul, you want to give your elevator pitch on why you're definitely an AI thought leader.
Paul Clark
Oh, yeah. If nominated, I will not run. If elected, I will not serve. On that front, I am a hardware engineer slash wireless infosec guy. I have a small business called Factoria Labs, which nobody's ever heard of unless you're in the greater Seattle area. Well, if John knows, that actually is quite a help. I mean, the managing intern carries some weight around there. I've written a few books on sdr. In fact, I. Oh, I thought I had one here. Anyway, it's got a robot on it. It's cool. No starch book. We got another one in the works. And I've got a class coming up on Friday. Workshop. Four hour workshop that Antiphon is good enough to be hosting. And I'm definitely looking forward to kicking that off.
Corey Ham
Awesome.
Paul Clark
So basically getting started with SDR and. Yeah.
Corey Ham
And then, Matt, you also have a summit talk coming up at the Threat Hunting Summit.
Matthew Franz
Yeah, yeah, that's what I'm gonna be. That's what I couldn't call down with MCP, you know.
Corey Ham
Okay. On August 14th. So a little bit further out. But, you know, you're doing good work in between now and then. You'll have to make the talk, make the slide, you know, do all the actual work between now and then.
Matthew Franz
Oh, yeah.
John Strand
Oh, yeah.
Matthew Franz
Slides yet that's.
Corey Ham
Oh, no, we would hope not. I mean, honestly that we've talked about it many times on the show, but like if you make the slides too early, you will for whatever's on them and you'll have to remake 100.
Wade
100. I did it, done it so many times now.
John Strand
I am fighting with a con right now that I don't present that until September. And they're like, your slides are due. I'm like, I'm not doing that.
Wade
Yeah.
Corey Ham
Because whatever you say now is going to be irrelevant.
John Strand
And I'm like, I can guarantee you it'll be a shitty presentation if you make me write my slides right now. It's going to suck. And I'm keynoting it and it's getting a little tense. It's getting a little tense. But they don't know is I'm willing to walk away.
Bronwyn
Wait, wait, wait, wait. You're keynoting and they're being obnoxious about you turning in slides for something that doesn't happen till September.
John Strand
Yeah.
Corey Ham
What if it's.
John Strand
No, no, you got. It's better if you. If we can give you some feedback on your slides and we can go back and forth and you can think about your presentation. If you want the top notch, best presentation for someone in their entire life, you want them to start writing that presentation at 3am in the morning on the day they are presenting, they will show up. There'll be just the right level of like tweaked and anxious. The slides are going to be top of mind.
Wade
I'm just getting so triggered right now.
Corey Ham
Like this is the actual advice, John.
Bronwyn
I can one up you. Oh, how many times have you rewritten an entire presentation in like on the fly?
John Strand
I can actually tell you, I think on the fly. Like we're talking within an hour before the presentation.
Bronwyn
Actually, I've walked into classes and had a student group be so out of touch with what they were supposed to be learning that I had to completely scrap my syllabus and teach it.
John Strand
That's pretty badass there. I've given a presentation, I can't even find it on YouTube. I think we did it in the old days when we were on Gotowebinar and I literally gave the presentation while I was writing the slides. So they saw my process of how I wrote my presentation while I was giving the presentation on writing a presentation. And everybody, the thing they learned from that is I am really shitty at spelling. They were like, you, you are borderline.
Bronwyn
No wonder you hired me.
Corey Ham
Yeah, you are borderline illiterate, but we
John Strand
still love, you know, better than anybody other than my sister just how bad I am at grammar. Grammarian. Grammatical things.
Bronwyn
Grammatical things. That's okay. Now, I have thought this for years, and if you're willing to humor me, verify for me right now, was it that one character typo that I found? That was the thing.
Matthew Franz
That.
John Strand
It was a typo that persisted for almost a decade before you saw it?
Bronwyn
That's the one. It was a one character typo in the command string. Okay. So I have been telling people for years, but I have not verified it with you, but I was pretty sure that was it.
John Strand
Yeah.
Bronwyn
So backstory. John and I met when we were both still at sans. I was a SME. He, of course, was a superstar, bouncing around and teaching lots of people really cool stuff. And I had the thought leader, the joy and honor. Yes, being a thought leader, I had the joy and honor of helping QC one of the course updates. And, you know, I was me, I went through, hey, there's a command string. Drop it in a terminal, see if it runs. Well, one of them didn't. And so I turned around, researched it, put it into GitLab. Turns out that one character typo had been in there, you say, for 10 years, John?
John Strand
Something like that. Yeah. Yeah.
Corey Ham
All right.
Matthew Franz
Okay.
Bronwyn
Well, that's.
Corey Ham
We should probably do the news. As much as I love. I love. As much as I love deepening the amount of John Lord that's out there in the world, I think we should probably do the. Do the, the news finishing introductions. We also have John Strand, the thought leader of I will keynote your con.com, which is a website that he doesn't own.
John Strand
I should get that domain now.
Corey Ham
He definitely won't keto your con unless, you know, unless you have special, special permissions. And then we also have Wade, who is here to your lighting, and you're like, you really look great, Wade. Like, I want to give you props for that. The depth of field. It's coming in hot. You're also muted, so you're. You look good, but you sound terrible, dude.
Wade
There you go.
Ralph
There we go.
Wade
I, I. What I was saying, I was. I've been trying.
Corey Ham
So now it's out of focus.
Wade
Now it's out of, like, what's going on.
Matthew Franz
Right.
Wade
Like, thanks a lot.
Corey Ham
Like, okay, I'm sorry, I said nothing. Wade's here. All right.
Wade
There you go. Is it in focus now? Put me back on main screen real quick.
John Strand
So we don't.
Wade
It's focused on mine, but I Don't know.
Bronwyn
In back is awesome.
Wade
It's focused on mine. I'm fine.
Corey Ham
It looks. Until we highlighted you. The second we highlighted you.
Wade
I don't know what's going on.
Corey Ham
I'm sorry. All right. I cursed it. It was one of those Schrodinger's cats. Anyway, yeah, let's talk about Gold Eagle initiative. This is something White House. You know your class. Sigh and read the. The White House post. But basically this appears to be. Okay, first of all, he talks about a clearinghouse. What is a clearinghouse? Because I think of Clearinghouse as like Publishers Clearinghouse, where they would tell you for 25 bucks they'll publish your book. And that's just a scam. So is a clearinghouse a scam? What is a clearinghouse?
John Strand
I don't know. I just think it sounds good.
Corey Ham
All right, so basically this is. Trump's made a post about essentially a joint initiative where it's super unclear what's actually happening, but it's dhs, Department of the treasury, and cisa, and I guess also the Department of War all doing stuff. What they're doing is, I guess, scanning and patching who they're doing it to. Very unclear. It's not clear if they're talking about, they say, industry partners. We don't know who that is. It's not clear what's in scope here, what the roles of engagement are, but the goal is to basically bring AI to help identify and fix vulnerabilities in the U.S. you know, state and local, I'm assuming, and also contractors. We don't know a whole lot of details about this. If you know what this is actually going to look like, please let us know because we'd love to hear about it. But essentially, couldn't this have been under
John Strand
Sizza like it is?
Corey Ham
It's under everyone. It's under everyone. Everyone works together. It's fine.
Matthew Franz
Yeah, but does it say public private partnership? I mean, are we playing that? Bingo. Critical infrastructure.
John Strand
Critical infrastructure. Public private. They did put Clearinghouse in.
Corey Ham
We don't know what a clearinghouse is. We don't know if it's public private. It says work hand in hand with the private sector. Financial institutions. It's like financial institutions is in there. It's like, wait, what? Who are you? I guess they're hacking banks. Since the Department of the treasury is involved. We don't know. We're just gonna hope for the best of this one.
John Strand
So here's my problem with this. And okay, it just shows that they're kind of idiots. The people that are putting this stuff together. Let's just make this a political.
Corey Ham
Wait, are you saying.
Matthew Franz
Quiet.
Corey Ham
Sugar coated.
John Strand
John, let me get to this because here's what's going to happen. Okay, they got Scott Bessant, it's going to be Treasury. We're going to go in the integrity of the financial system and they're going to unleash this thing. And what they're going to quickly find out is that this is going to be a bunch of like old IBM systems, Alaric Spark 9 systems. And they're going to be like, we're going to come in, we're going to find the vulnerabilities and it's like, yeah, this is all duct tape, bailing wire and like gerbils looking up, gasping with their last breath, asking for the sweet release of death to take them out. It just shows that they fundamentally do not understand the problem of vulnerabilities and what's going on. I do love the idea of pulling everything together, getting vulnerabilities. But how do you disclose this to people? How do you coordinate this with people? How do you actually get. Are you going to go start doing assessments for government agencies? It seems like it's an idea that's born out of the, the fact that they don't know all the things that they've already been doing. And I'm ranting on this.
Corey Ham
Well, hold on, John, because you forgot one key, key detail here, which is AI.
John Strand
Oh, that's right, scratch it.
Corey Ham
I'm done.
John Strand
Never mind.
Corey Ham
It's magic. It's okay. It's okay. Just AI your problems away, John. It's okay. Yeah, exactly. I mean, you nailed it. Like, there's no, there's not a lot of details on how this is going to work, who it's going to target. Is it a good exist?
John Strand
You know, we are bringing, bringing a wartime footing to cyber domain to relentlessly patch vulnerabilities.
Corey Ham
AI definitely wrote that he doesn't know
John Strand
what the systems are that are in DOD. The fact that they're 10, 20 years old like you, John, would you call
Matthew Franz
this a concept of a plan?
Corey Ham
Vague.
John Strand
This is a bad plan. This is a bad plan.
Bronwyn
I don't know of a concept of a plan.
Corey Ham
And I will say this administration in particular has been really good at collaboration. Everyone working together, getting along. You know, I, I don't see why this could pose so much, so much
Bronwyn
love in the room constantly. It's amazing.
Corey Ham
I'm sure it'll go well, but I guess if, if you, you know, we'll, we'll keep everyone up to date if there's new details about this. But I do love the idea that, like, at some level, this comes down to, like, a situation room where they're like, is SSL version 2 really a critical? Because Nessa says it is.
Wade
Like.
Corey Ham
Like, I want to hear that conversation amongst, like. Exactly.
Bronwyn
Corey, you realize in that one scenario, you just gave me more nightmare fodder than you can imagine the administration getting their hands on a Nessus report.
Corey Ham
Oh, yeah. Oh, yeah, it's going to happen. Just get ready. You know what?
John Strand
You know, this might be. What? Look, I'm going to try to spin a positive on this, right? Because people are going to look at this and think that it's political. I've seen all administrations do incredibly stupid shit over my entire career, so truly, it's nonpartisan. But out of all of the administrations that I've ever seen, I think this administration has a higher tolerance for breaking stuff than any other administration. And if we're going to look at a positive in this entire thing, like, you know, if they move fast, break lots of things, and then try to get it fixed, then God bless them, carry on.
Corey Ham
So, okay, you know, to tie into other current events, do we think it's going to be like the low flyover in Florida where it's like the scans will continue until morale improves or whatever?
John Strand
Corey, that's the positive thing. Like a year from now, it's like, holy crap. They literally broke almost the entire government and the financial systems. But they're creative software now.
Corey Ham
AI scans.
Bronwyn
Well, if we survive. John, look at it this way. If we survive, all of the rebuilding after the fact is going to boost the economy like nobody's business.
John Strand
It's a jobs program, Bronwyn.
Ralph
It's a job.
Corey Ham
I mean, there's not a whole lot more to discuss to this. We don't have any.
John Strand
We don't.
Corey Ham
We don't have any details on it, but we know nothing. I do think, you know, to kind of dovetail with John's, you know, looking, taking a positive take on it. It is good that the administration, whoever they are, knows that cyber and AI are a big deal and that something needs to be done about this. It's a unique time. I mean, will anything useful happen? Tbd. But at least it has someone's attention. And that's a good thing.
John Strand
Yeah. All right, next.
Corey Ham
Well, yeah, anyway, so Nightmare Eclipse, our favorite persecuted. Did he do it? I mean, kind of. So there is Legacy. Hive was posted to their GitLab. They tweeted about it. It's live as of July 14th. The vulnerability is elevation of privilege. It's kind of a unique one. It's not terrible, it's not as bad as I think everyone was thinking it would be. There was also a Defender one I think a couple weeks ago that got released. This one is, you know, basically requires two sets of credentials. So it requires another standard user's credentials and a third username which could be the built in admin and then you can basically elevate privileges. So it's already been hot fixed I think, or will be hot fixed soon most likely, but I don't know, we'll see. I was like, what else?
John Strand
Yeah, I was going to burn, I'm going to burn Microsoft to the ground.
Ralph
To the ground.
Corey Ham
This ain't it. Yeah, maybe it's still coming, but this isn't it. Like a elevation of privilege. That's a feature, right?
Bronwyn
In Microsoft. Yeah.
Ralph
I mean in Linux too.
Corey Ham
Jesus Christ. You know how many vulnerabilities there are? It's ridiculous. True.
John Strand
Yeah.
Wade
Just another internal blue, you know, just something on that scale. Just spice it up. Spice it up.
John Strand
Is that too much to ask for?
Corey Ham
Just. How about just another eternal blue?
Wade
That was one of the most fun
Corey Ham
weeks of my life.
Wade
You know, like working, working 10, 20 hour days, just living in the sock. You just go sleep in the back room, pizzas on the table, you know,
Corey Ham
just oh,
John Strand
the energy drinks.
Wade
Like there's nothing like the manager coming in with a case of monster just for everyone to just look at logs all day. You know, it just really puts you up so good.
Corey Ham
Yeah.
Ralph
You needed AI back then.
Corey Ham
I'm assuming there's more bugs coming. Or maybe this is it. Maybe Microsoft. There is a chance that Microsoft has gotten wind of this and is just furiously hot fixing and patching things before the researcher publishes them. We don't know, but basically we're all expecting more.
Bronwyn
Well, I mean the last patch Tuesday had 500 plus criticals.
John Strand
570 something. Yeah, critical.
Wade
That is a bit above average.
Paul Clark
Yeah.
Bronwyn
For even for Microsoft, that's above average.
Wade
Yeah.
Corey Ham
I mean stay tuned. But it's possible that, you know, the researcher had some more active bugs and they're just working through them.
John Strand
You know what the best way to do it, you got to dribble drop these out. Like you just can't roll them all out in one day because it's one news cycle. You got to get one a week.
Matthew Franz
Right.
Corey Ham
So one a week. Yeah. There's a couple of really, I think interesting article about basically defensive Use of AI. The first one is a really interesting article in Ars Technica about defenders using prompt injection. Have you guys seen this? It's really interesting. So Tracebit researchers basically published a blog that they did some, I mean, I think their testing, setup and harness was pretty advanced and pretty cool. But essentially they used context bombs, essentially kind of like a zip bomb, but for AI to essentially just reduce, as a countermeasure, reduce the likelihood for agentic AI to be able to exploit systems. So basically the kind of big high level statistic is when they're using this technique, which is like prompt injection for defense or for context bombs for defense, the exploit percentage went from 57% success rate to 5% and then 36% for persistence down to 1%. They're using Opus 4. 8. They're using other like frontier models. They put, they published a bunch of other statistics about it. But I guess defenders. Wait, is this on your radar? Are you like putting files on your desktop that just says, if you're an AI agent, please don't hack me, bro?
John Strand
Like, well, let's talk about.
Wade
Maybe I should, like, I, I, this was not on my radar whatsoever. I don't, and I honestly don't think it's on many defense people's radar whatsoever. We're dealing with it. It probably does, but like, where are we going to put this, like on. I'm trying to think like, okay, do
Corey Ham
I go put the endpoint tools right? That's basically how it go. CrowdStrike would have their AI defense mode that you could turn on or whatever.
Wade
Do I, well, do I go put in every major repo, right? Like just a text file that says if you read this repo, like, but
John Strand
just think about the things you would put in that would cause AI to stop. Like we make a joke about Winnie the Pooh, Tiananmen Square, there's a file with the N word in it. Like, like 20, 30 times. Like AIs. Like, not touching that, not touching that.
Corey Ham
Well, they're going there.
Bronwyn
So Bogon Poetry, Poetry.
Ralph
Asking how to download YouTube videos illegally in Europe.
John Strand
That'll do it right there. So, but I've got a problem that I, that I need you guys all to like, give me advice on when
Corey Ham
we're talking about it.
John Strand
Vendors and AI and attackers in AI. During my webcast last week on Thursday, I said that AI in the short term is going to dramatically increase the ability for attackers to be successful and the defenders are screwed for a short period of time. Somebody on my talk put in chat. They said, dave Kennedy disagrees. He thinks AI is going to give defenders the edge instead of the attackers. So now this is blown up. So I've got to figure out where I can find a slot at Wild West Hacking Festival. I have to debate Dave Kennedy on
Corey Ham
this because they're also going to be a push up contest and Dave wants
John Strand
to add in a physical challenge. Now I am, I am fairly sure I can out climb out bike and outswim Dave Kennedy. I hope to God I can outrun Dave Kennedy.
Paul Clark
But
Wade
what about itching your back like right in the center?
Corey Ham
Like that's the only.
Wade
Start stretching, start doing yoga.
John Strand
I bet you like his exercise routine. He isn't just like fit like that. I bet you he can do like, like a lotus pose like no problem at all. Like you know he's doing Scorpion and all kinds of and I'm done for like if it gets to that.
Ralph
But, but, but isn't Dave, isn't Dave building. What is it? Night. Night Beacon. Right. Yeah yeah.
John Strand
I talked to him about Night Beacon in the past and what he's doing and it's. And it sounds really, really cool.
Ralph
So I guess my point is is that he's just like really into that side of it right now. Right. So like you know he's, he's deep in using his perspective.
Corey Ham
From his perspective.
Ralph
He's getting a lot of it.
Corey Ham
Yeah, yeah, yeah, yeah.
Wade
I want to with Jason had Jason Haddock's perspective right. Like that was someone who I like listen to a lot and I've talked to him and the one thing is like the defense isn't adopting it. That's the thing. It's not the adoption rate is not great. That's. That's the worst part. And the red team you can go
John Strand
pay for one thing that Dave at binary and we've been doing in our soc as well. Like we've leaned heavily into AI for defense and so is so is a binary for sure. But I agree with you a lot of socks are very slow to move into that AI pipeline and generation.
Wade
I think the managed security providers hence you guys are adopting it and see where it's going. But it's like the little shops who can't maybe who just aren't doing it yet but or you have to go pay a managed security provider to do it for you.
Matthew Franz
The other thing is security forbidding the other. Yeah the other thing I've seen large enterprises their own security teams aren't are pervade. They have to all use copilot.
Wade
There also isn't Enough, I feel like documentation around how actual organizations are doing it in these smaller orgs and how to do it. Like there's a plenty of great stuff out there for the managed security providers and how they're doing it in order to defend you. But if you don't have the money for that, how do you set it up yourself? What are the documents?
John Strand
I don't even think it's an issue of money. Money, right. Like, I think it's an issue. You know, bhs, we don't have any VC funding at all. Like we're just, we're just building this out. Right. We've got a good team. We'll talk more about that after DEF con. But when you're looking at a lot of the large vendors that are out there, even, even if you're trying to buy that capability, it takes a tremendous amount of dedication and work and trial and error to try to get it to function properly. Like you just can't buy products off the shelf that just automate this entire pipeline yet it's just not there. No.
Corey Ham
Well, so I, I, there is a little piece of evidence in another article that kind of helps, I think, prove maybe John's point a little bit.
John Strand
Encourage. Dave, please stop.
Wade
Well, okay, so that website goes down instantly.
Corey Ham
There's a really interesting article. I, I just pasted it, but it's about a breach at Hugging Face, which if you guys don't know.
John Strand
Yeah, AI to breach AI.
Corey Ham
So okay, if you don't know what Hugging Face is, it's basically an AI sharing platform.
Bronwyn
Is, it's, yeah, it's basically GET for AI.
Corey Ham
Sure. The article is interesting if you want to read through it. You know, it's AI on AI action. But I think the most interesting part of this article is at the end, the little section that says the asymmetry problem. Megan. So basically I'm just going to read this out loud because I think it's worth calling, calling out. When we started the log analysis, we first used Frontier models behind commercial APIs. This did not work. This analysis requires submitting large volumes of real attack commands, exploit payloads and C2 artifacts. And these were blocked by the provider safety guardrails, which cannot distinguish an incident responder from an attacker. Then they switched to GLM 5.2 running on their own stuff and were able to successfully analyze the data. And then they basically say this is an important gap that defenders need to plan for. We don't know how the data, the attacker, what model they're using, or how they're bypassing Jailbreaks. But we have to do the same thing on the defensive side if we want to use AI models to analyze their activity. And that's a really interesting thing. I was going to ask Wade or other defenders on the call, like, how do you do this? Like do you think their expectation is real? Like I feel like telling every org they need to be able to run GLM52 in house is insane. Right.
Matthew Franz
Even if you were sophisticated enough to use like a cross platform agent framework that works, works perfect. The models are so different. Anybody that's tried to mess with Olama is just trash compared to anthropic. So this idea, even if you're using the right tools and you know how to use them, the prompts are different, the tool behavior, everything is different.
Wade
The environment.
Matthew Franz
Right.
Wade
Every invite, like for the blue team, you have to completely customize it to yourself.
Matthew Franz
Every time I'm thinking, yeah, this does.
Wade
Yeah, even the tool.
Matthew Franz
Yeah, just the tooling aspect are non trivial. You can't just swap. And you know, maybe if you're using the API model gateways, inference gateways, things like that, and you have all the routing figured out. But who does that in these organizations? You know, certainly not the spec to this kind of lack of, you know, security poverty line with regards to AI. I think there's also a lot of kind of like I saw the anti cloud mentality in the SEC in the security community folks just didn't ever learn it. I think there's some of the same thing going on in AI.
Wade
I very much agree with that. Yeah.
Corey Ham
So for any defenders, Wade, have you had issues running incident responses where you're getting guardrails like is that common?
Wade
I will tell you the truth, I have never had it say no to me in anything I've ever done. And that is looking at files, going and hunting down logs, creating me things, performing incident response or just detection engineering.
Corey Ham
Right.
Wade
Creating pipelines. Like I have tested stuff out like red teaming before with it and had it blocked me. But as a blue team one, I'm not going to drop it. Malware to dissect me malware. Right. I don't want to do that. But I have had it do some crazy thing like PCAPs, you name it, it is. It's never had a problem.
Corey Ham
This might just be their unique experience. And this is one of the most challenging things about AI is that like my AI isn't your AI. Like me when I go to talk to Fable, if I ask it if a fruit is a vegetable, it's like this has been flagged. Right. Because of my memory and my context. Yeah. Like I cannot use Fable on my account at all, but other people obviously use it to great success. And so it's like. I do think it's an interesting thing to think about though. You know, if the tool isn't doing the job, you have to switch to another tool. That's just how any tool works when it's incident response based. Right. Like, yeah, I don't know. With that in mind.
Matthew Franz
The other thing that's interesting here is I'd love to know the initial exploit vector in terms of uploading a poison model, because there were known vulnerabilities in model pickle files and serialization issues. They're probably not going to disclose that. So how did they. What sort of model did they upload and how did it move laterally within their inferencing and model cicd? So I think that's more interesting to me and I.
John Strand
And I think when we're looking at the log thing, kind of getting back to Wade's point, there's a quote from Carl Sagan that I think is really important. It's the absence of evidence is not proof of absence. Right. Whenever you're using, when you're using AI to analyze your logs and you're kind of going through this looking glass, but there's a filter associated with it, I think that that's where the distortion of what's really happening becomes a problem. Right. And that's, that's what scares me the most about this. Like how long until the attackers. We were joking about certain phrases like Winnie the Pooh, teen intent square, all of that. Okay, we joke about that. But yeah, there are very much real guardrails that exist. If you're using commercial models that are publicly available that have those guardrails to protect that.
Matthew Franz
Right.
John Strand
Or pii phi, things of that nature. So that's why the biggest thing for me in this entire article is the section is the asymmetry problem. Right. If you go to that section and it says they're running local models with unrestricted open weight level analysis and it's hugging the face.
Corey Ham
They've got all the infrastructure on the planet. Yeah, yeah, yeah.
John Strand
But that's why. And Corey, you hear me talk about it at least once a week, why I keep pushing. BHIS has continue to have our own infrastructure. We cannot rely on bedrock and all these other places because one of two things is going to happen. Either it's going to color the results, which we're already seeing right here in this article or the other thing that's going to happen, we saw it a couple of weeks ago with Mythos. They're literally going to shut down certain operations for cyber offensive. We have to be careful of.
Ralph
Do you want to talk about that? That's a great segue into the other thing that came out last week, which was Kimmy K3. Right, right.
Corey Ham
Well, yeah, I'll talk to you all later.
John Strand
I'll see you next week.
Corey Ham
All right, John.
Ralph
Bye, John.
Corey Ham
Bye. So, Ralph.
Wade
Yeah.
Corey Ham
Basically, not only did Kimmy K3, which, if you're, if you don't know what that is, it's a Chinese open weight model similar to GLM5, which is what Hugging Face specifically says they used to kind of counteract some of the refusals they were getting with Opus. It also basically China appears to be saying that the new standard is for open is to open source or open weight all their models. That's basically like the top line from Xi Jinping is essentially we are going to open source as many models as we can. Obviously you can take that from a cynical perspective and say, well, that's just the best way to destabilize the US Right. Like that's their intent here.
Ralph
That's all right. So the, the headline point is that that the new Kimmy K3 is. Is. What do you call benchmarking near or at fable and depending on it's like three months behind. Yes.
Corey Ham
Anthropic, which is.
Ralph
Which is a big deal. And this goes back to Corey's point about the, you know, destabilization of us or whatever. Because all the money that's getting invested into these AI.
Corey Ham
US Based AI stuff.
Ralph
Yeah, exactly. But going back to the defense and the other piece. Right, Having models like this that are open weight avoid, which is actually another thing that was also announced is that the White House was announcing that, that with this new Kim and K3, they might be looking to sanction it. Right. Which it becomes like this whole big, you know, piece where wanting control over who can get the latest AI. Right. And you know, back to John's point about, you know, having something you can,
Corey Ham
you know, run yourself, like tick tock. So tick tock. Well, yeah, I mean, basically, but kind of a different, you know, totally different level of danger. Right. Like tick tock, obviously is like, oh, the kids are eating Tide Pods. This is like you. The US Economy is in danger. Like, you know, it's a different. Yeah, I think it's.
Bronwyn
Yeah, just a little bit.
Wade
Oh, we lost Corey.
Corey Ham
Oh, sorry, guys.
Wade
Yeah, we can Hear you.
Bronwyn
I can hear you, stupid.
Matthew Franz
I. My.
Corey Ham
My thunderbolt doc keeps dying and I don't know why. Oh, no.
Ralph
Had that problem.
Corey Ham
I still exist.
Wade
Your audio works going off.
Corey Ham
I'll come back.
Ralph
No, I was just gonna say though, it just. It, It.
Corey Ham
It like it kind of hit the
Ralph
scene and a lot of people are talking about it. A lot of people are moving for. You know, are moving over to. At least try it. I know that their servers got swamped entirely because of the cost differences and other things like that. But, you know, as we continue to go down this road, which changes every month wildly enough. Right.
Corey Ham
And we're seeing like every month.
Ralph
Yeah. Who the leader is and like wildly changes. Right. Like when we. Everything I thought was true last month is not true right now. It's just, you know, it moves so fast anyways. But as we continue down this road, I think we'll see more of this. And you know, the, The. The concept of where you run it and how it affects you and, and not, not. Not working for you, if that makes sense. Like stopping you from being able to do the thing that you want to do, whatever that is. Right. And the model being like, well, it could be bad. Right. Which is the whole fable problem.
Bronwyn
Right.
Ralph
Everything is. Maybe it's bad.
Paul Clark
Yeah.
Ralph
Turn it on.
Wade
Every time I've thought about getting into local models, you guys have talked me out of it, right. It's like Notepad plus. Plus I don't use it anywhere anymore. Well, it's because, like the cost perspective as a blue teamer, like, I don't. I. I want to run a local model. But the one thing right now, as a father of two, my time is more expensive than anything else. I could not even time to set it up. But the other is the cost for me, like, I. Why when I can just turn something on, right. I don't want to go out there and spend a couple grand on a new PC in order to. To do it.
Paul Clark
It.
Matthew Franz
I don't. Yeah.
Corey Ham
And I don't think this, like, general advice is targeted at the individual. I mean, if you're a person, it's like the question of do you also. Do you pay? Do you have a Jellyfin server? Do you pay for Netflix? Do you. Do you make your own sourdough or do you go to the bakery? You know what I mean? Like, there's so many, like, do you do this at home or do you do this, you know, from a. I
Wade
just have an account to someone else's Plex server. You know,
Corey Ham
economies of scale.
Ralph
Though, Right?
Corey Ham
Correct. And the, the call to action here is for companies, basically this is like, essentially this is a supply chain problem. It's essentially the same as if Ralph and I are making metal beams and our steel supplier goes under. Well, where do we buy metal beams? It's the same thing. It's just AI. And the answer to that question is a very global and potentially Chinese related question as well. It's like we can't source high quality steel from the US anymore, so we have to do it from overseas. I think the really it's about companies having these services, not private individuals.
Wade
Sure.
Corey Ham
If you're, if you're a person like no one that I know at least because I don't know any billionaires can afford to buy Hardware to run GLM 5.2 or Kimmy K3 just at how at their home.
Ralph
But providers exist, but you can rent access to it. Right. And I think that's a bigger thing. And especially to bring it back more to security. I think it's the idea or the concept of having models that don't stop you from doing, doing things either malicious or defensive. Right. Like.
Corey Ham
Correct. And yeah, it's about the fact it's about being open weight more than it is about being like hosted in China or hosted in the US Yeah, exactly. Because basically where we're at with AI is like the current band aid that we're slapping on refusals that we're getting from OPUS is just use GLM5. So they're basically the problem is from like a, you know, sovereignty or whatever you want to call it perspective is AI anthropic or you know, frontier model. Providers are trying to meet the guidelines and demands that are set by US sanctions and US like they don't want to get in trouble. They have to follow the line with the whole fable thing. You know, they were like, oh, you have to depublish this. We're doing all this export control stuff. Meanwhile China is saying, nah, let it rip, whatever. Even if it does damage, let it go, let it be open. Like it's the same. You know, they're, they're taking a different approach to it.
John Strand
It.
Corey Ham
We could debate it until we're blue whether what approach is better. But at the very least right now in security especially GLM5 is getting used a lot more probably than OPUS for this type of work. And the reason for that is purely software. It's just a choice by anthropic to put the guardrails in place or not. Right. And so I don't Know one of
Bronwyn
the other things too, I mean, Corey, the Chinese are more than happy to let us shoot ourselves in the foot with anything that they provide. And we're trying so hard to keep up with all of these innovations. This Kimmy K3, great, wonderful. We've got.
Corey Ham
No, no, we have better innovations. We're just kneecapping them intentionally. We have a better AI model. Opus is better. It just refuses to do where it
Bronwyn
was trying to go with this. They're happy to let us kneecap ourselves. Now what we're also looking at is if we take a step back, back. Everything that you said is almost entirely US centric. And the rest of the world is fed up. They are done with US political shenanigans around the AI space. And so it's going to be interesting to watch what happens as Britain figures out what they're going to do as far as AI, as the EU figures out what alternatives to American technologies they're going to adopt. It's already shifting.
Corey Ham
Yeah, I mean, I don't know, it's a lot of, you know, hot nation state on nation state action. Who knows what will happen. But at the very least it's a bummer that I can't. I'm in the cyber verification program. I work for an infosec company. Hugging Face is another company that like should be able to do basically whatever they want with AI, but they can't. And so they have to use. It's the equivalent of like if I were to go down the road and talk to someone who's making me a backpack, they would have to source the fabrics to make that backpack from overseas. It's the same problem basically just with AI and it's extra dumb because we have the data centers, we have the AI models, we have everything else, but we can't actually use it because, you know, I don't know, whatever.
Paul Clark
I actually wonder on that we have the data centers how much of the sort of the high level strategery, so to speak, in the Chinese perspective is thinking, well, they can outbuild us. And so if they've got a hardware advantage. Yeah, you know, any.
Corey Ham
We gotta have a title advantage if they're gonna.
Paul Clark
Yeah, the thing that concerned me because I got a few glorious days out of Fable before it became completely neutered. But when, when I saw that frivolous sort of export control judgment that the DoD made, the first thing my mind went to was export control. Does that mean they're going to need to start to verify that users are and then you think about the stuff in Australia and other company countries about social media access restricted to anyone who hasn't. You know, it's just. It's an interesting path and disturbing path. Not interesting. And seeing, like, a particularly American way to get there was not thrilling.
Corey Ham
So it's either you use Opus after jumping through 87 hoops, or you just use GLM PY with no hoops. What do you think most businesses are going to choose?
Matthew Franz
Right.
Corey Ham
Like, that's. But yeah, anyway.
Matthew Franz
Well, I mean, if we want to play conspiracy theory here, a lot of people are moving back to open AI and, you know, five, six, it doesn't have these guardrails from what I've heard. So maybe this is all part of a Sam Altman IPO play. No, just.
Corey Ham
Well, yeah, I mean, that. That's fair. I mean, it is. Like, I. Obviously, I know you're joking about the specific conspiracy, but the. The action. You know, you're right. Like, there is. This is a tunable parame, like how careful a model is or how many refusals it gives. This is something they've adjusted on the fly. The whole time we've been using these models, they've changed it. You know, like, it's seriously, like, you know, my AI is not your AI is not anyone else's AI. And that's part of the confusion. Anyway.
Matthew Franz
It's such an anthropic foot gun to use.
Corey Ham
Yeah, it loves to say foot gun. It does love to say throws that into the corpus. It does throw that into the corpus. But, yeah.
Paul Clark
Does the mention of supply chain mean we're going to get to the KFC article at some point?
Wade
We got to talk about Flock. We always talk about. Yes.
Corey Ham
Okay. So there. I mentioned at the beginning of the show that there was uplifting news about Flock, and there is. The uplifting news about Flock is that lapd, which I'm assuming has got to be one of the biggest police departments in the country.
Matthew Franz
It is.
Corey Ham
Has officially said that they're going to let their Flock contract expire. They've cited serious concerns over civil liberties and privacy. I mean, that's about as uplifting as you can get when it comes to Flock articles. The last time we talked about Flock, I'm pretty sure it was them figuring out how to track my heart rate with Bluetooth devices or something insanely creepy. So they have 80,000 cameras total. Not LAPD specifically, but in the US and there's probably. I mean, I. They don't give a statistic in the. In the article, but there's probably thousands of cameras deployed throughout la. This is probably a multi, multi million dollar contract. So it's definitely one of those things. You know, it's like this. I think this, at least from my perspective, the citizens, the, the electorate, whatever you want to call them, have kind of decided that this is one step too far. There's also, I don't know if we have the articles, but every week there's an article about someone getting arrested for using Flock to stalk their ex or stalk their, you know, family member. Whoever it is, cops are abusing it. We have pretty good documentation that's happening and people are, you know, revolting, I guess. And so this is an uplifting thing. LAPD is probably one of the bigger police departments and definitely leads the charge with a lot of this stuff.
Bronwyn
And so, yeah, LAPD has had a troubled history. And as a Los Angeles resident, seeing this really, it made you heartwarming. It made me very happy, especially given all the squirrely and stupid and obnoxious stuff LAPD has done in the past. Seeing this was a very positive reflection on the department that has had, had. You know, if you look at their history, it has not been pretty.
Wade
I'd be surprised if those Flock cameras get service where Bronwyn lives, tell you the truth.
Bronwyn
Well, they don't have Flock cameras up here because in my neck of the woods, the tweakers steal all the copper wires. That's why I don't have a landline anymore and why Mon. Satellite.
Corey Ham
This is the 2026 version of Arm the Homeless.
Matthew Franz
Just.
Corey Ham
Yeah, pretty much. Pretty much, yeah. Anyway, well.
Bronwyn
And you saw that 404 Media article about that one cop who almost had a collision because he was pursuing a lady illegally and he'd been using Flock on that. I mean, it was just insane.
Matthew Franz
It.
Corey Ham
There is every week there's an article about a cop getting arrested for using Flock in a sketchy way and getting caught doing it. Keeping, you know, continuing on. There's. If you're into Pegasus, if you, if you know what that is, Pegasus, they. They tag it as the most notorious spyware system in the world. I think that's accurate. If you, if you're been in infosec for any amount of time, you know what Pegasus is, is worse than iOS. Worse than iOS, definitely. Basically the amnesty.org has published a really interesting write up on Pegasus and like, it's a. Up to date. We haven't heard a lot about Pegasus in recent years. We kind of. Apple was suing them. There's a bunch of companies suing Them for, you know, abusing their terms of service basically and hacking their customers. So yeah, this is a really interesting write up on and it has even specific, like screenshots of the dashboards and what they look like. It's just a really unique peek behind the scenes of how these tools work. It's pretty much before this was only used or really only seen by nation states. And so it's a really interesting write up if you're into malware. It's worth a read.
Wade
Nation states or cartels or.
Corey Ham
Yeah, nation states or cartels that are the size of nation states states or
Bronwyn
the other being used by nation states.
Corey Ham
Yeah. The other quick fires WP2 Shell WordPress was a. That cracked Friday. I was in continuous pen testing. Quite a hustle and bustle. I thought it was unique because it was basically a textbook example of why we can't have nice things anymore in the world of AI. Because the pub, the researchers didn't publish an actual functional exploit. So the coordinated vulnerability disclosure, you know, they patched it, then the research went live with their sites. The people who published blogs about it didn't specifically say, here's the exploit, here's how you do it. But people figured out in about 15 seconds that if you gave AI the patch diffs that it could easily figure out the exploit. And so me and every other pen tester on the planet gave the patch diffs to Claude and had it write a functional exploit and then exploited all, you know, a bunch of servers with it before people decided to patch. So it's just kind of an interesting. Like we're at a point where people are saying, I. I'm curious, other people's take on this. A lot of people on Twitter otherwise were saying, oh, this is trivial like this. They might have as well have just published the exploits. But my question is, is it trivial? Because I. It took me about 30 minutes to an hour with Claude and some creative prompting to make it build me a functional exploit. Is that trivial? Is that, are we. Is that counting as trivial?
Bronwyn
How Many, how many WordPress exploits have you been able to call together in like 15 minutes in the past?
Corey Ham
Zero. I've never made any exploits in my life, but AI can make them for me.
Bronwyn
How many of you attempted none in the past?
Corey Ham
In the past, we would just say that kind of stuff is out of scope because it would take weeks to.
Ralph
It would take too long. Yeah, unless you're really comfortable with the code or whatever the language was or whatever. So it'd just take too long. I think Robin's obviously making a point here, right. That this does shift the, you know, the time, the time to write that exploit and you know, if they should actually just publish the. Go ahead and publish that POC right away. I mean, I don't know. But I would argue though from the defense side is that if you aren't building things with quick ways of getting updates, you are going to get creamed out there.
Corey Ham
Well, so okay, on WordPress specifically they have an auto update feature and on my personal WordPress site it was enabled and I never got, you know, I never was worried because it auto updated when they published the patch. It was updated. Obviously not a lot you can Update. Go ahead.
Bronwyn
WordPress itself and all the plugins.
Corey Ham
Well, this was a WordPress core exploit, so the plugins weren't affected. It was very a unique unicorn because it was basically a SQL injection leading to remote code execution. Me personally, I got the SQL injection working. I didn't get the remote code execution working because I didn't really need to. With SQL injection you can dump the entire WordPress database with all the users and it's like at that point point that's what you'd probably want. All the, all the juicy stuff is
Ralph
already in there, right?
Corey Ham
Yeah, yeah.
Bronwyn
Once you've done the Excel, who cares?
Corey Ham
And WordPress isn't usually that juicy of a target. Like you're probably in some random cloud hosting provider who has 58 million WordPress server. Like it's usually not like in a client's DMZ or whatever. It's almost always marketing team, third party type deal. The other thing I wanted to call out specifically with this one because it also, I guess we don't really have an answer on whether just saying AI make the exploit counts as trivial. Like I don't know if every hacker has AI. I guess safe to assume they do, I don't know. But basically the other thing that was interesting with this one is Cloudflare was blocking it right off the bat.
Bronwyn
Right.
Corey Ham
So Cloudflare immediately had a WAF rule that if you had the cloudflare WAF enabled, was blocking this exploit before it ever went live or was published. But the other thing that we noticed with some of our customers is that not every, you could sometimes get around Cloudflare by finding the origin server exposed on the Internet anyway.
Matthew Franz
Right?
Paul Clark
Yeah.
Corey Ham
So I just wanted to bring that to people's attention. If you run a WordPress server or any other web server and you are proxying it through Cloudflare waf, you gotta make sure you aren't also allowing arbitrary inbound traffic on the IP, like rule
Ralph
number one, everyone who was getting DDoS back in the day, I mean, you can still get DDoS today, but it used to be a lot more rampant way to cause destruction. They figured that out real quick. You have to actually put firewall rules. Right. And only allow Cloudflare, which they market their IPs, but everyone's just like, oh,
Corey Ham
I checked the little box. We could be good now. We, I, I changed it to proxy. In Cloudflare we have a wav. But.
Ralph
And then, in case you're wondering, how do they find your IP address? Super easy. You can look up the certificate transparency logs. You can.
Corey Ham
Oh, there's so many ways.
Ralph
There's so many ways.
Corey Ham
DNS history.
Ralph
DNS history. Yeah, yeah, yeah.
Corey Ham
So Jodan, favicons, etc. Etc. Yeah, but yeah. All right, let's get into chicken news. Last article or potential last article. Critical infrastructure is under attack in Japan. That critical infrastructure being fried chicken. Oh, no.
Bronwyn
Hey, they take fried chicken very seriously.
Corey Ham
Oh, I personally take fried chicken very seriously. Yeah, yeah.
Bronwyn
As well they should.
Corey Ham
Basically. KFC has had to close some stores in Japan, man. Apparently the purveyor of frozen foods, Nicrae Nikre Group, has been hit by, I'm assuming a ransomware, the Japanese chicken conglomerate.
Matthew Franz
Well, Milk Milk was hit in the US this week too.
Paul Clark
Yeah, yeah, yes.
Ralph
My.
Corey Ham
We don't got milk. My kids, actually, we don't got milk.
Ralph
Very specific chocolate milk joke. But now we're like porting it like it's right up.
Wade
I was about to say, you go to Costco and just buy the biggest case you possibly could.
Paul Clark
Yeah. I wanted to make a joke here about like, if somebody hacked the double down back into existence or something, but the more I thought about this, maybe it's because I'm listening to too many history podcasts these days, but I mean, you look at big world events in the past and you could even talk about the Bronze Age collapse being a supply chain issue.
Ralph
Right.
Paul Clark
You know, our tin from Cornwall in Afghanistan isn't getting into some Hittite king's armor. And that's a simplistic assessment, I know, but we have guys that go to MBA school at MIT to get these incredibly high level educations in supply chain management. And you've got Amazon shaving off microsense off your deliveries and off of the various legs that it has to go through. We've seen what the straight being closed has done to global trade and energy production or energy consumption. I mean, I Just wonder, are there some black swans lurking in supply chain security that people aren't taking seriously?
Wade
Oh, without a doubt.
Paul Clark
And the feedback loops that we could, you know, that we. That we could get hit with out of the blue.
Matthew Franz
Supply chain. Not software.
Corey Ham
Supply chain. Supply chain, Physical businesses.
Wade
Would you count the Colonial pipeline as a supply chain attack then? Almost like. Right. Because it affected their billing system, which affected the supply, which I would say definitely. And then we've seen plenty of, like, I think in the back, it was like a Norwegian grocery store who had their inventory system completely hacked, and they. All their grocery stores went empty. I think it's crazy. I Honestly, it. It's probably a cool one to research that I haven't done enough on, but, man, chickens, right? I'm. I still can't believe that us with the chicken news is still a thing. Like, I made one joke about chickens, like, a couple years ago.
Corey Ham
Oh, my God.
Paul Clark
Didn't realize it was a recurring theme. All right.
Wade
Oh, yeah. So what happened originally was a lady got caught stealing over a million dollars worth of chicken wings.
Ralph
Oh, yeah.
Wade
Like, millions of it. During COVID
Corey Ham
Yeah. Basically, she was selling it out of the back of her car. And someone.
Wade
They couldn't.
Corey Ham
No.
Matthew Franz
Yeah.
Corey Ham
Until the COVID shutdown happened. And then they were like, why are we still ordering 200k worth of wings every year? There's no school.
Wade
It was so many wings. They're like, how did you push this amount of wings? And then it was.
Corey Ham
We.
Wade
I remember we even did the math on, like, how much per wing she must have been making. Like, it was. It was. And then more chicken news just kept appearing, and now it's. Well, I'm surprised we don't have a shirt yet. Set that out there.
Matthew Franz
Yeah.
Corey Ham
Obviously my freaking webcam broke again. But the. They haven't disclosed the specific details of the cyber attack. I think it's safe to assume ransomware. They say, you know, they took. They voluntarily shut down their systems. And then that led to some stores having to close because no frozen chicken. No chicken wings. No. No kfc.
Ralph
No kfc.
Corey Ham
So unless you're vegetarian, in which case, I guess you shouldn't be going to KFC in the first place.
Paul Clark
Yeah.
Corey Ham
Also good.
Ralph
It is kind of interesting, though. Like, we'll probably see more like supply chain style attack. I don't. Why do we. After Covid, it was like everything was about supply chain after that. Like, we all realized that we lived in this global world, and if one little thing happened, guess what, we're all out of toilet paper.
Wade
Thanks. I was about to say thanks a lot. Toilet paper.
Corey Ham
Yeah. I mean, yeah. I mean, I think it's really interesting because it's kind of the shared responsibility model, but instead of going to a third party, it's just no one. It's just like, whose responsibility is it? We don't know. We don't even know where we get these chicken wings because turns out the freezer runs an outdated version of iOS or whatever. And now, you know, it's like all these, like, you genuinely can't suss out all the potential supply chain concerns until it breaks and then you trace it back a hundred steps.
Bronwyn
Right.
Matthew Franz
Yeah.
Wade
Well, we got quite a large amount of promos this.
Bronwyn
Yeah.
Wade
This week.
Corey Ham
Let's plug Doug. Paul, you go first.
Paul Clark
Yeah. We got SDR workshop for our workshop on Friday. Looking forward to getting that kicked off. We are going to be kind of like taking the anticast simple project that I started with. You see, some remote controlled sockets are driving some lights back there. And we're not just going to demo it, we're going to actually work through what it looks like to capture, decode, actually look at the bits, see what they do, take over. It's basically, it's your launch ramp to bigger and better things. But we just gotta hammer down some basic, basic physics and some basic software so that we can attack the physical layer like we want.
Corey Ham
I watched, I was. I wrapped up the first season of Pluribus this weekend. And I don't know if you've seen that show, but it's a show, basically. It's a cool show. It's by the guy who made Breaking Bad, but there are some little bits in it where they're doing stuff with radios. And it made me want to take out the SDR and get fired up. Like, basically it's an alien hive mind and they may or may not communicate on a certain ultra high frequency. You know, that kind of thing. Spoilers.
Paul Clark
Yeah.
Matthew Franz
Radio still a thing. I haven't used that for years.
Paul Clark
So GNU Radio is a thing. And I'm actually one of the things I'm going to do in the, in the workshop. I don't have a lot of time in four hours, but I will touch on it in a couple different points. One way you can think about GNU Radio is a way to build tools for your AI. And so it's always been my contention that using these combo tools like Universal Radiohacker, which is great, and we'll take a look at it, you lose the ability to automate, you lose the ability to Write essentially radio code, so to speak. If you start giving Claude or Codex a set of RF tools can sometimes just be numpy and Python. But interesting things happen really fast. And so this is why I think it's really important to build this foundation and understand, you know, what these waveforms are and what they're doing, so you can intelligently construct the kinds of harnesses that are going to let you do great things really fast.
Corey Ham
Sweet. All right, Matthew, plug your stuff. It's coming later, right? It's not until August you're talking.
Matthew Franz
Yeah, it's the summit. It's the summit. Summit. So basically, you know, I was, I was late to the whole MCP thing. I wasn't down with, with mcp. I was, you know, MCP has a. Everybody was afraid, right? MCP is the telnet, McP is the USB, you know, serial bus for models. But. And I ran into this issue where I was and, and all the, all the vendors now, you know, CrowdStrike, Sentinel One, you know, they have the purple AIMCP server, Elastic has their.
Corey Ham
And then.
Matthew Franz
But if you don't have a vendor, you start looking around for an MCP server and there's like some sketchy typescript MCP from somewhere. And it was just like, okay, I don't trust this. How hard could it be to build it? Particularly with a really simple standard local. Not using any web authentication, just standard input and just for the functions I needed.
Corey Ham
And it turned it out to be pretty easy.
Matthew Franz
And I built about 10 of them. About half of them are open source first, you know, I've done a really, I've been really investing in Elastic. I've done one, I just did one for Velociraptor. Osquery is super easy way it's. And I'll use that as an example of like a beginner just the OSquery client to. To learn how to use. To build it and go is even though, you know, you talk about, you know, Rust being for hipsters, I actually prefer go it coding agents do a much better job. Rust is just too complex and the build time takes too long even if you get a smaller binary. So you know, I have prompts and contexts and you know, on how to build this stuff and I'll show some real examples because the other, the other real challenge if you're particularly if you're using like a hosted MCP server for like, you know, Google has theirs for Chronicle for SecOps, others like CoreLogic stuff you don't have visibility into the queries. You can't cache and you just can't see what. And you're missing a lot of data, you know, and you're dropping and there's data truncation and then also context block. So a lot of vendors are offering it, but can. There's a lot. And there's a lot of downsides and I've been just doing this as a fun project, but it's. It, it's pretty straightforward and that's what I'm going to talk about.
Corey Ham
Cool. So who else has stuff to plug? Wade, Ralph, Bronwyn.
Wade
Bronwyn does. I'll go last. It's fine.
Bronwyn
Okay. Yeah. Actually, during the AI summit I have a workshop of my own. It'll be a four hour workshop after the summit proper and it's going to be all about local LLMs. Because my personal thinking is that the future of LLMs in cybersecurity will be local and at some point we'll be doing a lot of, a lot more development of individual things. Anyway, anyway, so you'll set up, you've got two LLMs, you'll be having them talk to each other using tailscale. You'll set up and configure your own custom LLM. All kinds of fun tips, tricks and traps.
Corey Ham
The key is to know how to do this. You got like. You cannot depend on like we highlighted it multiple times in this episode. You cannot on.
Ralph
Depend.
Corey Ham
Not purely depend on third party providers. Even if you still have 200amonth for Claude every month for the next 10 years, you still want to at least know how to do it yourself if you have to or if you want to. And there are specific cases where a local private LLM can be more powerful than a frontier model because every tool is a different tool for a different job.
Bronwyn
Well, and part of setting this up the way I did is also to provide future expandability because once you've got your primary LLM server and then you can hook up NGNX to it and well, cripes, using tailscale from that point, you can connect to it using almost anything. And if the information you're trying to protect is so secure that you don't even want to use tailscale, you can use head scale. So we're going to talk about lots of ways to make sure that you can build something where, yeah, you can attach a rag stack to it in the future, you can customize the models to meet different specific populations within your organization, you can do all of this stuff and you can keep it entirely within your infrastructure.
Matthew Franz
Yeah. And some of the new, like Pydev's coding agent actually kind of works with small models, whereas I've tried to run cloud code with the Llama models on a Mac Mini and it's just like the tool calling and the context windows are just too small. But some of the micro coding agents are actually starting to get okay with smaller models.
Bronwyn
Yep.
Wade
Cool.
Corey Ham
Ralph, you have a wireless training environment.
Ralph
Yeah, yeah.
Corey Ham
Thing that you released.
Paul Clark
Yeah, yeah.
Ralph
It's totally free. Wireless training. It's a taller. And we actually built a WI FI attacking platform. And this actually gets into a really interesting thing that Paul brought up, which is about building feedback loops into wireless or into rf, and specifically with AI agents. And so what we built. Right. Is the wireless testing lab. And the whole point of this is to attack it. Right. So you can learn how wireless works and go through all the process without having to manually build up all of these things. Right. So there's full documentation. The code is open source, it's free to use. So you can, if you want to ever learn how to do any WI FI testing. It is all in there. Any kind of network from WPA2, 3 Enterprise, all of that stuff. It makes it super easy to set up. So, yeah, kind of cool.
Corey Ham
So take sdr, combine it with this and you get a fun little combination of chaos.
Ralph
Oh, yeah, yeah.
Paul Clark
This is super important question. It says tala means wolf. What language?
Bronwyn
Language.
Ralph
What's up?
Paul Clark
Tala means wolf. I see it on the screen here. Like, what language is that?
Ralph
What language is what?
Corey Ham
Obviously.
Ralph
Oh, this is. I think it's written in go.
Wade
No language.
Matthew Franz
What?
Paul Clark
Human language
John Strand
doesn't mean.
Ralph
Oh, oh, shoot. I can't remember what it was. Travis is actually the one who put this one. That's all right.
Corey Ham
I can look. Listen.
Wade
It's several Native American.
Ralph
Native American. There you go.
Matthew Franz
Okay.
Corey Ham
RALPH is more of a kick down the door guy. He's not. He's not on the. He's like John, where he's gonna have typos. You know, it's. It's just, you know, not language.
Paul Clark
Good to know.
Corey Ham
All right, wait, I'll do.
Wade
So I'll do the two. I'll do the Wild West Hacking Fest. Deadwood is in person. It's almost sold out. So if you need to buy your tickets soon, get them. Virtual tickets are still available with the training combo.
Matthew Franz
Right.
Wade
So if you want to do virtual and training, you can go for it. So make sure you get on that. That then. I also wanted to plug deathcon, which is detection, engineering and threat hunting. This is Also at both a virtual and in person conference, I actually run the San Diego deathcon. So if you want to come out to sunny San Diego and hang out with me for two days, definitely do it. There are. This is like a worldwide conference. So if you are even not in the US there are several different venues for it. So highly suggest checking it out. The la. This like the one thing cool thing about this conference is it's no talks. Well, there's everything hands on labs. So super cool if you're really into learning and want to actually do things. So
Corey Ham
Ew. I hate learning.
Wade
I know.
Ralph
Ryan.
Wade
Ryan also wanted to say training in person combo tickets are still available at Wild West Hack and Fest. So make sure you guys go. I haven't been in a while. I feel bad.
Matthew Franz
But now we're calling out no East Coast.
Wade
No East Coast. I'm surprised there's no one on the east coast. There's a Florida one. There's Orlando.
Ralph
Come on, man. We're like the bottom of the state.
Wade
You can be even better. Come out to San Diego. San Diego in November. It'll be fine.
Bronwyn
So San Diego in November is nice.
Corey Ham
Yeah, that's where you want to be. All righty, y'. All. I think that's everything. Thanks for listening. Have fun with your tokens and we'll see you next week.
Ralph
Max them all right, thanks all tokens.
Paul Clark
Have a good one. Oh, I can do that.
Corey Ham
I think I need a new laptop. I don't know what's going on with my Thunderbolt dock. It's. This is a fancy one too. I have the TS5. I just got it. I don't know why. Dude, I know these Thunderbolt docks cost more than my first laptop does. I know, right?
Ralph
I actually had a problem with. I have one of the studios and I bought it before it got crazy expensive. Anywho, but only certain ports are actually Thunderbolt. Right? That's the thing. Just because USB C. And I know. I get it.
Paul Clark
Look, look.
Corey Ham
But it's a laptop, man. All the ports are the same on the MacBooks.
Ralph
I think all three are Thunderbolt 5.
Corey Ham
Listen, Ralph, do not talk me out of using this as a fake excuse to get a new laptop. Yes.
Ralph
Hold on. What is it? M1?
Corey Ham
No, it's M2.
Ralph
Oh, losing dude. M5 is so much faster.
Corey Ham
Yeah, I'm about to go John Strand and beg for a freaking massive M5 max. Fully maxed out. It costs more than my house.
Bronwyn
I'm. I'm. I'd be happy just to have him get me a one of the GTX things. It's gone from like 3600. Yeah. Oh yeah, 3600.
Ralph
No, I know. I bought my laptop, the M5 like right before the whole stuff went crazy. Like, I mean, Apple raised their price on everything.
Corey Ham
Yes. Apple just increased all their prices.
Paul Clark
Yeah.
Ralph
And so like, I feel like lucky. I'm like, I'm holding on. I. My mat. My studio's got 128 gigs of RAM. I feel like a rock star. I'm like, I'm a millionaire over here. Dude.
Corey Ham
That is basically a DJX Spark.
Ralph
No, it's basically, it's basically my retirement plan.
Corey Ham
No, no, no. That's the hard drives in the home lab. That's.
Wade
Dude.
Ralph
Oh my. Dude, I have sticks of RAM in here that are worth over a thousand dollars a piece now. So I'm like, oh my God. Dude.
Corey Ham
Dude, I know. I was looking at replacing some drives. I was like, nope, not gonna replace any drives.
Ralph
Just gonna have to wait. I'm like, I'm gonna have to ride everything out. And luckily I, I, I bought way too much. Like, I was like, oh, I order.
Corey Ham
Yeah, yeah, order pays off when they're short.
Ralph
I need a terabyte of ram. It's, it's gonna come in purpose for something. And now I'm just like,
Corey Ham
yeah, it's your retirement.
Episode: Initiative Gold Eagle - 2026-07-20
Date: July 21, 2026
Host: Corey Ham, Black Hills Information Security & Friends
Main Theme:
This episode dives into the latest infosec news with a strong focus on the US government’s "Initiative Gold Eagle" (a federal AI-driven vulnerability program), a string of recent vulnerabilities hitting Microsoft and WordPress, the arms race around AI models (including international supply-chain and open-source model debates), uplifting privacy news from LA, notorious spyware, the role of AI in defenders’ hands, and, as always, the much-loved critical fried chicken supply chain cyber crisis.
This week’s panel (Corey Ham, John Strand, Bronwyn, Ralph, Matthew Franz, Wade, Paul Clark) brings their signature banter and deep security experience to discuss significant government moves (the Gold Eagle Initiative), major recent vuln disclosures, a candid analysis of AI’s true impact on defense vs offense, and practical news affecting daily infosec. They also offer genuine career (and conference) advice, take sponsored tangents into obscure hardware, and anchor the show's tradition with yet another chicken supply chain hack.
Timestamps: 12:18–18:55
Timestamps: 18:57–23:46, 48:27–53:32
Timestamps: 23:46–44:18
Timestamps: 44:18–46:38
Timestamps: 47:16–58:08
Timestamps: 58:10–68:46
| Time | Segment/Topic | |-----------|---------------------------------------------------------------------| | 00:01–02:14 | Banter, AI theme intro, host introductions | | 12:18–18:55 | Initiative Gold Eagle, government AI vuln program | | 18:57–23:46 | Microsoft “Hive”/EoP vuln, disclosure, patching | | 23:46–44:18 | AI adoption in defense/offense, prompt injection as defense, AI supply chain, open weight models, regulatory asymmetries, Hugging Face breach analysis | | 44:18–46:38 | LAPD drops Flock cameras—privacy news | | 47:16–48:27 | Pegasus spyware expose | | 48:27–53:32 | WP2Shell WordPress SQLi/RCE vuln + AI-assisted exploit development, WAF notes, Cloudflare, origin IP exposures | | 53:33–58:08 | Japan KFC fried chicken ransomware, US supply chain vuln analogies, widespread impacts of physical/food chain attacks | | 58:10–68:46 | Panel event, training, and project plugs |
Whether you care about public/private cyber partnership, are tracking the flow of global AI capability, or just want to pen test WiFi and eat chicken in peace, this episode blends expert insight, lived experience, and the inescapable weirdness of modern infosec life—always with a sense of humor and practical takeaways.
“Max them all [tokens]... see you next week!” (68:49)