Loading summary
Wade
And I was like, punch him right in the mouth. And I did it.
Corey
Really? Was that before or after you took illicit drugs, Wade?
Wade
That was a lit. That allegedly happened. There's no proof or anything about the alleged drugs.
Corey
Gosh, you can't be snorting coffee like that.
Wade
It's just so good.
Corey
I usually make coffee, and then I just take the coffee and put it into the coffee machine to make, like, a double coffee.
Wade
That's pretty extreme. I don't think I've ever seen one. You could do it. You. You brew a cup of coffee and then do a pour over with the coffee.
Corey
Or alternate plan brew. Like, put Red Bull into your pour over and then pour that over the beans.
Wade
That's. That's rough. Oh, my God.
Corey
Wow.
Wade
I had a Red Bull for, like, the first time in a while this weekend because I had to work on a presentation. I needed an upper. It worked really well.
Corey
I got the presentation done. I feel like it's not that strong. I feel like a lot of energy drinks these days are way too much caffeine. Like monsters and Celsius and all these ripits. Rip its are like, what, 300 milligrams or something? That's like three coffees.
Wade
I stick with Red Bull Monster. And then there's a. There's a Vietnamese iced coffee place nearby that if I get them, I have, like, heart palpitation.
Corey
Like, I go into panic mode.
Wade
Yeah, I can't drink the whole coffee. It's ridiculous. I save it for, like, three days.
Corey
We do have chicken news. Kind of. I mean, kind of.
Wade
Sort of. Sort of chicken news. Sorta Oh, I have chicken news for the end. A big chicken mention as a plug.
Corey
Chicken mention.
Wade
A chicken mention. Yeah. Well, I rather plug it at the end. Just.
Corey
Are you gonna get your own episode of Chicken Shop date?
Wade
That. Wouldn't that be amazing?
Corey
Like, they're just like, how would I get that level?
Wade
Famous. Yeah, I know, right? Like, they had Elmo on there. How do I. How do I beat Elmo? Or how do I get at that level?
Corey
Like, you don't want to be thinking in terms of how can you beat Elmo. You just got to be your own person.
Wade
We got a small crew today.
Corey
We do. I don't know where John is. No one showed up. Okay. It's not my fault.
Wade
No one signs up beforehand anyway.
Corey
It's a grand.
Wade
Like, there's the one time.
Corey
Want to show up? Absolutely not.
Wade
It's like the one time there was a bunch of people, like, trying to get in. So then we made the sign up sheet. And then like, none of those people ever come back again.
Corey
What? Wasn't there a news article a couple years ago about that Panera drink that was just killing people? Did we talk about this on the show?
Wade
I don't know if we talked about.
Corey
It was called like, just like Death tea or whatever.
Wade
Killed like two people. Yeah, dude. It reminds me of like Jolts when we were younger, right? When everyone's like, if you drink too many jolts, you're gonna die. Like, nah, it was actually just a lemonade. A Panera bread that kills everybody.
Corey
Yeah, I was gonna say Jolt doesn't have that much, but that is like, you know, that's the OG hacker drink before energy drinks. I would say, like, here's the progression. You had Jolt, then you went to Balls Energy. Then it went just. Then it blew wide open. You had all the different, like, you know, then you have Red Bull and all the others.
John
So what's different about Red Bull? Why is Red Bull not, as, you know, toxic or.
Corey
I think. I think Red Bull just has slightly less caffeine per ounce. Like, the small Red Bull cans only have like 80 milligrams of caffeine, which is like a. That's like an espresso shot. That's nothing crazy. Whereas, like the standard is like the taller cans that are like 300 milligrams.
Wade
Which is like the monster cans.
Corey
Yeah. Okay, so it's more just about like raw caffeine kind of. I think Red Bull's a little lower.
Wade
But I'm very surprised. None of them have started, like, have ever thought about sponsoring like, any security conferences, right?
Corey
Oh, they do. They don't need to. They're.
Wade
I feel like they don't need to.
Corey
Ubiquitous.
Wade
I guess that's right. I guess that is true.
Corey
I will say. When I was in college, we had some kind of hackathon CT thing that we hosted and we like contacted Balls Energy and we're like, hey, can you support it? And they did send like a 24 pack of balls drinks. So they did. Back in like 2012 or whatever, they did support hacker stuff.
Wade
I was trying to get Liquid Death the sponsor Death con, which is the text engineering and threat hunting. I'm like, come on, this is like the perfect. It's perfect thing. Just like, send me one case. That's it. They never got back to me. If anybody knows anybody, make it happen. I'm a huge liquid death drinker.
Corey
Yeah, I don't love Liquid Death, personally. I don't. I don't like it. To me, it's like halfway in between a sweet drink and a not sweet drink. I'm like, it's very slightly sweet. I'm like, who, like, put some orange juice in my sparkling.
Wade
It's better than me drinking soda. I use it as a meal. Meal substitution.
Corey
Oh, okay. Well, that's one way to do it.
Wade
My. My girl diet drink. That's the way to put it.
Corey
You're like, I had three pieces of kale and a liquid death. I'm ready to go for another three hours and I'll pass later.
Wade
Oh, surge, dude. Yeah.
Corey
All right. Roll the finger. Let's get some chicken up in here. Hello and welcome to Black Hills Infosex. Talking about News. It's Monday, May 5th. It's Cinco de Mayo. That's exciting. And it's a new month. It's not April anymore. April fools. It's May. But, yeah, welcome to the show. We have. We're going to talk about all kinds of News. We got JP Morgan Chase putting out warnings about SaaS products. That's kind of fun. We got Scattered Spider coming out of retirement again. Just when you think they're done, someone pulls them back in. You got some cool blog posts, Disney hacking, and maybe some chicken at the end, if we're lucky.
Wade
We have. We have two chicken, two chickens. I have. We have a chicken article and then a chicken call out.
Corey
Or two chicken.
Wade
A chicken plug. A chicken plug. Yeah. Whoever that customer. Yeah.
Corey
Let's start with the JP Morgan article. This is. This is kind of a weird scenario. Basically, like the CISO, Pat, the CISO of J.P. morgan, which J.P. morgan Chase is like, what, the biggest bank in the world? I guess probably one of the CISO of that company, Patrick Opet. Opet. I don't know how to say his name. Outlined concerns about SaaS adoption. Just kind of like decided to get out his soapbox and stand out in the street and complain about SaaS products. It seems like a lot of the complaints are about AI stuff. I mean, it's pretty short. Like, he doesn't go on and on.
Wade
I took it more as just all sass driven stuff the way I took it. But yeah, he also released this before rsa. Right. Which is very tactical.
Corey
Totally. Yeah. RSA week is over. That was last week. We had some people there. If you got to talk to John or Rhino or whoever else was there, then good for you. But yeah, I mean, I guess, I mean, I'm concerned about SaaS. I mean, after the snowflake stuff, I think we all Learned that like SaaS prioritizes customer adoption and customer preferences over security. Right. Like feature delivery beats security. We talked on. Was it live or was it after the show? We talked about like the AI calendar that like worms or the AI note taking app that like worms its way through different tenants. Did we.
Wade
That was on the show? Yeah, that was last week.
Corey
Okay. Yeah, yeah. So I feel like this is kind of just his. My take is like, that's his reaction to that because he specifically calls out AI driven calendar optimization service integrating directly into corporate email systems to read only roles. So that's how I see it. It's like he's kind of like freaked out by the adoption of AI. Who would have thought the banking industry would be, you know, afraid of SaaS?
Wade
Now that you say, like the read only calendar stuff that always. I. I was given a piece of advice early on in my career and it's like to go look at all your boss's calendars and to see if anybody has it open. Because then you can see like really good meetings that are going on and possibly jump into stuff that you want to be in or do stuff to directly.
Corey
Wow, that's like some aggressive corporate news. That's like a. That's.
Wade
Dude, definitely. And it is. Well, you go. If they leave it open, they left it open for a reason. Right. So usually it's private by default. Usually it's. Yeah, that's true. But usually most places have it private by default. But it's helped me out several times where I'm like, I see a meeting, I'm like, hey, man, I want to get in on this meeting. He's like, yeah, go for it. And next thing you know, it's a cool project that I get to be on. But it's interesting with the AI part. Like, what is. Are you worried about the AI scraping all your calendar data and knowing who you're meeting with? I guess when it's a bank and maybe it's a little bit more secretive with like insider trading type of stuff or money moving around, that could be a problem. But let's read only rules. Corey, did you. Are you there? Hey, Corey. Crash. He did.
Gerald
Corey crashed.
Wade
Oh, dude. It's a rare. Okay, here we go. It's a rare time where Wade hosts back. Okay, good.
Corey
Okay. Sorry. We're using this new thing called Lima Charlie. I don't know what it is, but it keeps crushing my entire network stack. So that's fun. Security is fun. So, yeah, anyway, what I was saying before I got cut off by my inherent demise of Internet was that like open inboxes is actually a pen test finding open inboxes and calendars. Like, we'll actually go looking for them and report them on engagements. Because, like, nowadays you can't be doing that.
Wade
Okay, all right, Nerf. Nerf corrected me. It's not calendar data. It's all data it uses to generate the calendar. Okay, that makes a little bit more sense.
Corey
I mean, static tears, comment. Why does your calendar have a standing meeting for hostile takeovers? That's basically what that would be if you're just joining. Just rogue Joining a meeting with your boss being like, I have. I have a. An opinion. I do like that someone gave you that advice, though. They were like, be aggressive. Destroy people with calendar invites.
Wade
Yeah. I find it funny that, like this. This is. This direct news is, like, prominent to CISOs, right? Like, really higher upper land management. Where I felt it was from sas. None of us here are actually, like, super higher upper and management. For once, I feel like John would be the one who. To talk about this.
Corey
Yes. I mean, yeah. Yeah. I mean, I don't. My take on this is, like, SaaS is a big risk. We've. We've warned our clients about it. Like, you know, push for mfa, push for, like, security features, make sure you have logs. But ultimately, it's kind of rings hollow. You're right. It does have to come from an executive perspective. They have to start canceling. I want to read all the articles about insourcing. That'll be fun. Like, about companies being like, I can't wait to see all the blog posts from, like, random companies that are like, we built our own salesforce or whatever. You're just like, how. How did you do that?
Wade
Vibe coding.
Corey
Vibe coding? Yeah, we. We used AI to code ourselves into a CRM project. Is that better? I don' probably not. Scattered spiders. Back on the hunt that we talked, I don't know if we mentioned the breach, but UK retail is in a rough spot. There's multiple UK retailers that are getting hit with. With ransomware. The Marks and Spencers. I don't. I apologize. If you're British and you're listening to this, I am so sorry that I'm about to butcher all this stuff, but you're probably used to it. I guess so. Yeah. Basically, scattered spider was the mgm, the people who breached mgm. And they're one of our kind of highly tracked threat actors because we emulated a lot of their techniques. Basically, this is being attributed to them, which is kind of interesting. But, yeah, there's been like supply chain impacts from this and I guess is this. I don't know exactly what Marks and Spencer's. Is it like a Walmart? Is it like a grocery store that also sells shirts?
Wade
So it looks like they had a. They've been targeted. Right? And I use that in two terms. They were targeted and also it was one of their vendors. Vendor. There's rumors that one of their vendors got breached and they're in order to pivot into Marks and Spencer's. Right.
Corey
Well there's also Harrods is hit with. The Harrods hasn't had details posted about it yet, but they're also have been hit and apparently it's a holiday. So I guess if you're British and you're listening to this on a holiday in Britain, then like I guess find a better thing to do on your holiday. But.
Wade
Oh, what is it? Is it.
Corey
So basically like someone's targeting UK retailers. We don't know who's targeted herods, but they are like currently down ransomware. You know, supply chain impacts. These are high. These are high profile for sure. Like these. Anything that impacts like store shelves is a big deal.
Wade
I think I, I thought the, the actual like wiped stock market value was a lot, but I don't remember like how much crowdstrike loss they said MNS has lost.500 million off the stock market value, but in pounds.500 million pounds. That seems like a lot, right?
Corey
That's a ton. Well, I think it's because it's not just because it's a breach, it's because it's impacting their ability to sell data or sell, sell data, sell physical hard goods. Like that's actually pretty crazy, right? I feel like has there been an American retailer that was breached to the point where stuff stops showing up on shelves? I don't, not at least not, not.
Wade
Not one I can think of.
Corey
Yeah, like when Target was breached it was just data loss, it was just credit card theft. It wasn't like they couldn't, you know, I could still buy my four dollar can of Lacroix or whatever. So I don't know, it's weird. What else we got? What is this what it takes to defend a cyber security company? Is this just Sentinel one, like flexing a little bit?
Wade
A little bit. It's more of like why people who are doing cyber security are. It's the last one. It's that purple on the top tier. Target what it takes to defend a cyber security program. It's pretty much like we do cybersecurity we have gnarly amount of clients. We're going to get attacked more than anybody else and with crazy stuff. And also we're kind of not supposed to talk about it because if anything happens, we'll get in trouble.
Corey
Well, they also talk about dprk, meaning trying to get jobs, which ties directly into another article we have.
Wade
Well, we'll go back to that. But the DPRK stuff is super interesting because I think more people are starting to talk about it, especially with RSA, with having all those CISOs come together. There was somewhere else where they figured, like, they didn't realize that the DPRK IT worker was as prevalent as they thought. And once all these CISOs got together, they're like, you hired a couple. What? You hired a couple. It was all like the same dude. But it's just crazy, right? Like, it's.
Corey
Wow.
Wade
And the other part, it's like not even really like a cyber security failing. In some points it is, but a lot of it's like different failings, more of within HR and not seeing these anomalies or.
Corey
Yeah, we talked about doing this, like in Antisoc. We talked about how to emulate this. Like, could we do this attack against our clients? And we basically reached the conclusion that like, we couldn't do it. It's basically identity theft. Like, we. We can, like, we decided that if to assess it, we're just going to like war game. It basically like kind of walk through, like what checks and balances exist within your HR team? And is there like passover between the HR team and the security team? And like, how does all that work? Because it's. It is like not really a security thing. It's more of like a security orchestration. Hr, like tying all the pieces together.
Wade
So I haven't seen any. I haven't seen any blowback to like the background check people. Right? Like, there's only like a couple of them, like the big tier ones. Like, why are. What. What's failing with them? Or how are they getting past those background checks?
Corey
That's a good question. I feel like background checks maybe aren't being done until later in the process. Too late in the process.
Wade
I don't know. Every single place I've worked at, it's immediately background check.
Corey
It's like you have to have it.
Wade
You have to have it done before your start. So it's like a mad rush. I had one job where the background check people actually failed. And even though I provided them within all the information and I was going to lose a job because they couldn't finish it in time, which is impressive for that customer. It's a good one, right? But it wasn't good for me, who is already had quit a job and it was waiting for this job to go.
Corey
It's bad. Yeah, but it's. Yeah, I mean I guess I would say like it's nothing new, but it's still prevalent and that in and of itself is kind of notable. That means it's still working, right? Like if a technique that's like, I mean when was the, when was the Darknet diaries about this? It was got to be like two years ago, maybe three years ago. It was a long time ago. The age old thing is like business processes are hard to change. It's the same reason why help desk social engineering works. Right. Because like telling every HR team member do not let this person through without a background check or whatever is, is tough.
Wade
I feel like one of the other things that breaks down though is like I will say cyber security, giving out operational intelligence to managers, right. Like hey, here's what to look out for type of deal. If they don't have their camera on all the time. If they're like saying like hey, I'm only going to go to meetings if you put them on my calendar a week in advance, I'm not going to answer teams right away like give. Like there's clear indicators of one of.
Corey
These people being a good, efficient worker with multiple jobs and being in the sigma grind set. No, I agree. No, I mean totally. I think the other thing is having like all your insider threat alerts and your insider threat like these. I mean obviously they're gathering information. They're also collecting a paycheck and that's not nothing. But the insider threat angle is the biggest risk. When they start downloading terabytes of data out of SharePoint, searching for things they shouldn't be searching for like all the insider threat angles you should be covering anyway are worth like they would, they would hit that same angle if you're, if your hiring processes fail, you still have that as your backup plan.
Wade
I would like to know the strategy of that because I feel from what I've heard right through like back channels is a lot of the times they're not even trying that. They're literally just there to collect the paycheck and not even doing the insiders. Yeah. And most of the times they're like staying for like three to four months, maybe a little even more because like what you give a month and a half or month, two Months, maybe to have someone get spun up and then, yeah, a month of them not working, then you're like, okay, then it takes when like you put them on a pip for a month and then four months have passed and this guy's in your network, like, takes a while.
Corey
There's gonna be like a Reddit post. It's like how I made $8,000 a month by pretending to be a DPRK.
Wade
Oh my God.
Corey
There.
Wade
There is r. Overemployed. Who. Who get. Yeah, it's crazy.
Corey
Totally.
Wade
It's so crazy.
John
I think W just did an article on that too, and it was around the same thing you just mentioned, Wade. Like, more so just collecting, you know, like 13 jobs from one person was doing like 13 jobs and like sending all the money back.
Corey
It's like basically you. You're exploiting the, like, onboarding and offboarding processes. Take like a month on their own. So, like, minimum you have like a couple of, two or three months of salary before they realize you're not ever going to show up and do any real work.
Wade
I almost think that whoever's writing their resumes just needs to spin off a resume writing, like company. Right. If they're getting this many hires and this people through, maybe, maybe there's a different job market here that they need to look at.
Corey
Yeah. I don't know. I feel like the fact North Korea is doing it, I mean, may. It's crazy though, because if you talk to people that are job hunting, it's not easy. So I guess maybe their standards are just really low. They're like, oh, I'm a SOC engineer and I make $30,000 a year. Great, perfect. And they're just taking a bunch of jobs that aren't super appealing to other people. I don't know. So this ties directly into another kind of cool DPRK related article, which is that the Kraken Exchange, which is a pretty high profile crypto exchange, posted a video. I mean, we've heard the attack before, but they posted a lot of really interesting technical content and like recordings and stuff about the attack. Right. Like, they kind of like went full open, open breach, I guess. So they just kind of shared, like they intentionally hired them, I guess, a little bit. And we're just like, all right, what are they going to do?
Wade
So the video actually shows video of the North Korean IT worker. Like they. They recorded everything and I think it was just on video recording. And they didn't actually hire him. They pushed him all the way through and then started asking him questions.
Corey
Okay.
Wade
About, like, hey, what's going on? And then I read a really interesting Reddit comment that says, if you. If you think you're interviewing one of them, just ask them how fat is Kim Jong Un? And if they don't answer, then they're in North Korea. And I was like, oh, my God.
Corey
Yeah. Yeah.
Gerald
I think. I think one of the big things that we could take away from this one is the fact that they noticed that something was wrong about this guy, so they were looking for warning signs. So warning signs do work. I find it funny that this guy, they asked him stuff like, what's your favorite restaurant in Houston where the guy said he was supposed to be from? And the guy sort of went.
Corey
Yeah, yeah, yeah, yeah. I mean, that's really, like. Yeah, that. Exactly what Wade said. That's the thing to tell your business teams. The thing to warn them is, like, push harder to tell that this is a normal person, whether it's small talk, talking about North Korea, whatever it is. Yeah. So what questions? Let's come up with more. Restaurant in your local area. What else you got? Probably, like, make sure you do a pun. That's what that. Do a pun if you can't do a pun. No, I'm just kidding. That's. That's too. That's too narrow.
Wade
Have, like, 10 pop culture references that, like, hit different. Different ends of the spectrum that everyone should maybe know, right? Like, where. Like, what kind of scar did. Did Harry Potter have? And everyone's like, oh, yeah, lightning bolt. Or it's like, who's Luke's father?
Corey
It's too common, dude. Everyone knows Harry Potter.
Wade
Hopefully. I don't know.
Corey
Local stuff is. But that. That can be. That they can figure those answers out. The things they can't figure out is like, yeah, things that are specific and local to you that would apply, like where you work, where you last worked, your favorite restaurant. Or like, yeah, your favorite hiking trail or your favorite. I don't know, something like that.
Wade
Something out of the blue. I don't know. We. Maybe we should ask chatgpt. Chat. Let's see. What are the top questions?
Corey
Well, the f. So we. Yeah. Mary Ellen just linked a list of questions or a. The FBI apparently has already weighed in on this, so I guess we're kind of outgunned.
Wade
All right, fine.
Corey
But it's pretty cool, so follow up. The Disney hacker who leaked all that or exfiltrated all that Slack data has been charged. I guess pled guilty, basically. And I don't know, do they know what the has been sentenced, but has pled guilty.
Wade
Has pled guilty. He was only 25. Right. He's from my neck of the woods. He's from Santa Clarita, Los Angeles, which is actually, like, not too far away from Burbank, where a lot of, like, film stuff comes from. Like, I know actually know a lot of people who work in the industry, the film industry actually live in Santa Clarita, which that's probably just a coincidence, like, but I was surprised. So he probably would have been 24 when the hack occurred, right. And when he threw down that malicious AI bottle. But I was surprised he copped to doing it so quickly. They must have gave him a good plea deal.
Corey
I mean, I feel like it was just crushing evidence. I mean, yeah, once. Like, the thing about cyber crimes is, like, once they're proving it, they're really gonna prove it. Like, you're. It's gonna be irrefutably strong evidence. So I feel like it's. At some point you just gotta be like, yeah, it was me. Like, you're not gonna plead not guilty or something. Yeah. I don't know. Kind of interesting. I wonder what the sentencing will be. Does anyone have a guess? I feel like it. It's gotta be like, two years or something. Five years.
Wade
I wouldn't put it over two years. I think I agree with you, because he didn't do any. I guess you could say he did. He did reputational harm. But did he. He didn't, like, have any downtime.
Corey
He didn't leak the plot of Moana too?
Wade
He didn't. I wouldn't surprise if he did if it wasn't in there. Somebody control f that right now.
Corey
I'm just saying it is kind of funny. Yeah, it's reputational. I guess if I was his fence lore, I'd be like, listen, the mouse doesn't care if its data gets leaked. Who cares? It's fine. Like, we. We are going to publish the movies anyway. It's fine. I don't think that.
Wade
Honestly, just a really, really expensive pen test, right? Like, maybe you shouldn't have had all your slack channels open. Like, it's like, super.
Corey
The clop ransomware group used. They were like, listen, move it. Exporting that. It was just a pen test that you didn't ask for and didn't get any results from. It's fine. We talked about that last week, too, with, like, the guy who just walked into that hospital. That was the world's worst.
Wade
Oh, dude, that was a good. Oh, yeah. That poor guy. Wait where is the other one I wanted to talk about? It wasn't.
Corey
Can we get to our first chicken article?
Wade
No. You want it? You want. Yeah, we can get. Yeah, let's get to the first chicken.
Corey
Article, then we'll go for the first chicken article. Chicken. It's not really chicken related at all.
Wade
I am, I am so surprised. I didn't know that this was a threat actor.
Corey
Like there's a threat actor that's named Golden Chicken or actually Golden Chickens. There's more than one chicken. And Golden Chicken, this is the AI probably AI generated art. I don't want to throw sand, but I'm assuming that's AI generated. This is a threat actor. That is a malware as a service. They just released a new info stealer or a new malware steel or what is it? Sorry, yeah, it's a Terra Stealer V2 designed to collect browser credentials, wallet data. There's a couple of articles this week that were like, oh, new info. So yeah, basically there was also a Palo Alto post about a deep dive into an info stealer.
Wade
But that, that one does something a little special that I want to talk about so we can hit the chrome stuff V20 or whatever that. And then it steals one other thing that I thought was funny that I made a comment on. But the interesting part with these, these guys are like the malware that they produce doesn't seem like it's theirs. Like it's top notch. It seems like maybe it was like released prematurely or released for testing. And because most of their stuff is pretty on the ball like fin6 use them. Right. They've been a malware as a malware as a service shop for a while since I think the date was 2018, which is interesting for me because they hadn't really like come across my path as an intel analyst for a while. I probably knew them as their other name, to tell you the truth, which is also Venom Spider, which obviously sounds.
Corey
That's the non chicken related name. You're not allowed to use that.
Wade
We're not allowed to use that anymore. Golden Chicken. But the, the link between chickens and info stealers is honestly a little bit credible to this podcast. Right? Like it really. If you, if you would have said this threat group came out yesterday, I would have been a little scared. Like, hopefully they don't think it was Corey and I like the real.
Corey
Yeah, well, okay, so the real question is who coined Golden Chicken? Is that self coined?
Wade
I searched for that for like a good 20 minutes trying to figure out who original.
Corey
Yeah, all of the original posts are done with Venom Spider. Like the original, like, threat actor profile is all Venom Spider stuff.
John
Yeah, I think Crowdstrike was the Venom Spider one.
Wade
Yeah. Oh, yeah. I thought it was Red Canary, because Red Canary names all their stuff chicken. Or they name it a bird. I believe it's a bird and a color, so that's why I thought. And then I didn't. I searched Golden Chicken. No Red Canary reports come up. I. I'm not gonna lie. I didn't do my best OSINT to figure out where Golden Chicken was coming from, but I. I read at least like three or four. It was like a good page two of Google. Right? Which is unheard of.
Corey
If you work in one of the divisions of Golden Chicken, is that considered a chicken wing?
Wade
Do they call their, like, a foul of everything? They call their employees nuggets.
Corey
They call their employees nuggets? Oh, yeah. I mean, malware as a service. I mean, really, Let me, as the CEO of malware, let me warn everyone about malware as a service. They don't have your best needs. They don't have your best interests at heart. You got to watch out for them. Okay. Wow, there's some really disturbing gifs being posted in our discord.
Wade
Oh, my God. Yeah, that one was rough, right, when you said that.
Corey
All right, so chicken story number one. Stay tuned for chicken story number two.
Wade
Yeah, that'll come at the end. You want. Let's talk about the.
Corey
Oh, go ahead.
Wade
Oh, yeah, I was gonna say, let's talk about the other info stealer that you want.
Corey
Yeah, you had. Yeah, so Palo Alto Networks, you know, unit 42 posted a kind of. I won't call it like a full deep dive, but kind of a little small analysis of an info stealer that just came out. Yeah, it's called Gremlin Stealer, which is not chicken themed, so obviously we don't support it. But yeah, basically this is advertised on Telegram. It does all the things you'd expect from stealer. The interesting thing about this one, I guess, is that they are bypassing the new Chrome protections that were put in place in March. So I guess it's not really surprising that someone figured out how to bypass a security control that was changed. But, yeah, they steal all the stuff you'd expect. FTP is kind of interesting. That seems. That seems more enterprise targeted. Like FTP are like regular normal people using FTP on a regular basis.
Wade
Maybe. I think that's just. I think that's just functionality. It has functionality, right? Like, it can use FTP is it? Yeah.
Corey
Steelers function stealing FTP creds.
Wade
Oh man, there's still people out there. I was, I was more surprised with the one under FTP. They're stealing my Steam.
Corey
Oh yeah. Steam has been a thing forever, dude. In the, when I would look, it used to be. So some of the info stealers I would look at, they would actually list like in the like description of the thread or whatever. They would be like x PayPal, x credit cards, X Steam games. Like it would tell you like how many like of the ones they stole. What, like what was their spec? Did they have credit cards, wallets, Steam games? So yeah, that, that's been in there forever. Discord and Steam is like a high profile threat.
Wade
I wonder if that's going to go up because with the recent video game news of it going to $80 a game. Why pay $80 when you can pay $80 for someone else's Steam library?
Corey
I mean that's fair. But my hot take actually is that they're going after like the con on Steam. I think they're going after the secondary markets like cs, Go Skins and knives and stuff like that makes sense. That's my guess. I think it's less about like getting the games themselves and more about getting like going into someone's Steam account and either scamming other people and like being like, hey, can you send me Venmo? Or whatever. Or also like getting those like skins and other rare things. Because some of those like knives and skins can be worth like hundreds of dollars. I think so. Yeah, like that's my guess. But I, I mean, I don't know.
Wade
That's like a.
Corey
Above my pay grade.
Wade
I had a buddy who is Steam. His, no, his EA account got taken over and he didn't realize it. And one day this was like when Mass Effect 3 came out. So this is probably a good 10 years ago, if not a little bit less. And all one day he just realized that there was a new saved game on his Mass Effect game. And he was, and he was really weird. And then he saved a game with the message because he's like, this is someone who has my account. And he's like, hello. And the person said, please don't delete game.
Corey
I really invested in this character.
Wade
Just saved, just saved the game. Like, all right, if all you're gonna do is play Mass Effect 3, that's okay.
Corey
I mean that's like that famous YouTuber had his Netflix stolen and like the guy kept watching really good movies and so he just left him in there. Like, this is back in the day. Like, he was like, you know, he, like, he has great taste. He's watching all these good movies. My feed's never been better. Like, nowadays it would be a thing because Netflix has the whole, like, primary login location and all that stuff. But back in the day. Yeah, there's no downside. Right. What's next? Yeah, what is next? I don't know.
Wade
I didn't get that far in the news. We got another at least 14 minutes before I talk about the next chicken episode.
Corey
It's a. It's not a 14 minute long chicken story.
Wade
It's definitely not. You may want to talk about it for 14 minutes after I tell you about it, but it's not that long. It's more of a. It's more of a plug than a story check. You don't got any good news?
Corey
I mean, there's a bunch of data breach news. One of the ones I thought was interesting is like, so in the breach news, there's this article that's like a researcher is basically publicly shaming the Bangalore Water Supply and Sewerage Board, saying, hey, we found this web or we found this host on the Internet that has a publicly accessible login portal. We logged in with the credentials and we, like, reported this to you. Like, why go public with this? In the U.S. if you went public with this, you would get destroyed. Right? Like, how is this legal? I'm kind of blown away. Maybe it's like multinational stuff, but I don't know. It's kind of crazy to me that someone could just go public. I'm assuming that they contacted the company or the board or whatever they are and, you know, said like, hey, can you. Can you do anything about this? And I guess they said no, or I don't know what happened, but they're basically public shaming this public government service. I'm kind of surprised by the optics of this, especially since it seems like Cloud Sec has like a decent presence within India. So I'm a little bit confused, like, how they're getting away with this, but India kind of interesting angle.
Wade
India is pretty hardcore about, like, releasing that stuff too. Like, if you say bad stuff about the president there or the. What do they have? They don't have a president. They have a prime minister. I believe you get. You can get disappeared.
Corey
Yeah, I don't. I don't really know where. Yeah, it's. They have like, India offices. I don't know. I don't they're gonna have them for very long, but. Yeah, I don't know. Oh, yeah, people mentioned the Signal clone. That's a really good one. We should talk. That's. I forgot about that article. Yeah, let's cover that one. This is basically, I want to set the record trade on this. The government. To our knowledge, the government data that was in this BR or government data was not actually lost to this. This is a transitive property of breach is what this is. But, yeah, basically the article is. It was posted on 404media. So people are using this Telemessage app, which is a modified version of Signal. Now why do we need a modified version of Signal? I don't know. It's kind of a transitive property. So it's like Trump admins have been known to use this app and the app was also hacked. I don't really know. So far, nothing's been confirmed that they're actually, you know, the government data was leaked. It's theoretically possible that it did. And yeah, I guess it. Mike Waltz, Tulsi Gabbard, like, people somehow accidentally revealed they're using this. How does this even. How does this stuff even happen?
Wade
Like, they're. They're like, we don't want to accidentally add people that we don't know to our signal group.
Corey
Are you guys using.
Wade
So, like, let's use this Signal Light. It's got like five reviews. It seems good.
Corey
You know, I don't get how this can happen. Like, I don't super understand how anyone is using this app. It's not a malicious app. It's.
Wade
Where does it come up when you search?
Corey
It's an Israeli company that sells. I guess they're selling a version of Signal. This is basically a nom. This is. This is a nom, right? Is this not just. I mean, the article was written by Joseph Cox too, so maybe it really is a knob.
Wade
Telemessage?
Corey
Yeah. Is this like. Is this a government.
Gerald
It sounds like just from reading the start of the article, Telemessage is the actual name of the company also. And they're modifying these apps, WhatsApp, Signal, WeChat, Telegram, to meet government standards. Standards is what it almost sounds like. Because they're focused on trying to sell this stuff to the US government and other governments.
Corey
I mean, this just sounds like anom, but made by threat actors to sell to governments instead of made by governments to sell to threat actors. It's like the reverse anom. What is happening? Are they doing a reverse anom? Yeah. I don't super understand why they're using this. From my perspective, The US Government is pretty crystallized around what chat apps it's allowed to use, right? Like, no one should be using this app.
Wade
Yeah, yeah. Well, if they can't use Signal, right? Like, why would you use this app? Like, that's.
Corey
No, I thought they're supposed to use Signal. Are they not supposed to use Signal?
Wade
They're not supposed to know. They're not supposed to use. I don't know if you were being sarcastic or not with that.
Corey
No, I'm serious. What are they supposed to use?
Wade
They're supposed to use like an internal comfort, internal comms. Like they have Message. Definitely. Maybe. Maybe it is now, right? Like, they got the beta sneak peek preview to use this telemessage and then it just got popped real quick.
Corey
This is just terrifying to me that some company is selling versions of Signal, I guess, to the US Government and I was not securing it properly.
Wade
I don't know, I was going to say at least good for Signal, right? Like, if you got people straight up just pulling your repo and trying to recreate it and then still putting in, like, vulnerabilities, like, at least your product is secure.
Corey
Like, yeah, well, you got to have vulnerable. You got to have the vulnerability. The key thing that they have to implement is the ability to read the messages. Like, this is literally the COVID story they use for a nom.
Wade
Like, Signal is open source, right?
Corey
Yeah, it is.
Wade
Okay, cool, cool. I was making sure.
Corey
Yeah, yeah. Signals open source, but it doesn't have the ability to have audits logging of all the messages. Right. So for. For enterprise or government, I get why they would do it, but. Okay, I don't know. I mean, it's just a gen, I think in general, like, whether it's US Citizens or just world citizens, we have an issue right now where no one can really decide what apps to use or what chat apps to use and what's secure.
Wade
I'm so tired of using Facebook Messenger.
Corey
Yeah, like, you have Facebook messenger, you have WhatsApp, you have Signal. Like, now all my friends are starting to use Signal for some reason, like, unprovoked. And so I'm like, all right, okay. But like, then every time we meet as a friend group, everyone's like, who doesn't have Signal? You go get signal right now. Like, it's like a whole. And I'm just sitting back being like, I have no comment. I signal. But now, obviously we have to switch to Tele Message.
Wade
You didn't already switch? I thought that's what we were telling people.
Corey
I guess I should Switch.
Gerald
Everybody switched to pigeon. It does it all.
Corey
Pigeon plus otr. No, no, you gotta have OTR in there. Pigeon plus otr. That was a disaster too. I mean those privacy wise, that was not end to end encrypted.
Wade
Okay. What about the. Microsoft being able to use RDP with revoked passwords? I know. I'm pretty sure we've. We've talked about this on stream before.
John
Yeah.
Corey
What is this? Is this just cache credentials? What is this?
Wade
That's what it feels like. Right. I think. I think it's more of just this bug is getting out to the world. But I swear we've talked about it before. So let me say Remote Desktop Protocol. Yeah. The mechanism for Windows all. Well, pretty much you can disable an account and they can still use rdp. Like what. What the f. Okay, so how does. This isn't just a bug? No, this isn't just a bug. It's a trust breakdown. Oh. The guy's name is Wade. Wrote in his report people trust that changing their passwords will cut off authorization. So it's not a bug. Microsoft also said they confirmed it and said it wasn't a bug.
Gerald
Working as intended. It's a way to go ahead and allow at least one user account to have access to login no matter how long a system's been offline.
Corey
So how do you. Is it just credential caching? Is that all it is? I think that's all it is.
Gerald
That's what it sounds like to me.
Corey
Yeah. Caution, when a user performs a local log and they're credential verified locally against a cache copy before being authenticated with an identity provider. Is it. Does it require network failure to work or is it literally just like how do you trigger it? Or is it just something that triggers on its own? I don't know.
Wade
Trying to get into that.
Corey
Yeah. Update. Also, it fails to advise users on what steps need to take to lock down rdp. I mean I will say honestly, most, most super highly mature organizations don't allow RDP anyway. Like workstation to workstation. Right. Like that's a. That's a lateral movement pathway anyway so.
Wade
And then if you right now don't. If you have that blocked, go and verify. I will tell you that just in case. You never know if someone accidentally turned a switch somewhere and it's on again.
Corey
Totally. Well, we just use Quick Assist for rmm so we're secure. It's fine.
Wade
Oh, I. I use any desk for everybody.
Corey
Any desk. You just have all your computers added into one.
Wade
Anydesk Like, I want to play a game on my computer downstairs at just any desk into my computer downstairs, and I don't.
Corey
Any desk into your computer. Is that cool?
Wade
Yeah. You're playing Mass Effect 3 earlier, right?
Corey
Or sharing on any desk account. I like to.
John
I like to talk about the. This is kind of funny. The one where the dev is kind of like hacking back in a way where he has those. He drops those zip bombs and then they, you know, explode into like 32.
Corey
Gigabyte files, which is this one.
John
I didn't see the article in Chat.
Wade
Software Dev fortifies his blog with zip bombs attacking bots Meet the Meet their end with explosive data package.
John
I'll put it into the discord too, so people can have it.
Wade
Go for it. You know, Go for it. Read it.
Corey
4.5 petabyte file.
John
Yeah, I just thought it was kind of a fun way to.
Corey
Yeah, yeah. I mean, I got to say, like, if I got. I would probably. It would probably work against me. Like, I got like a nuclei scan result that was like, sensitive data, and then it just, like downloaded a zip. I'd be like, yeah, I'll open. I'd probably open it in a vm, but it would work against me. I'd probably just get a good laugh out of it. I do like a 7 zip listing of the file and it'd be like, total size 7.6 petabytes or whatever. All right, maybe I won't extract that.
Wade
Just put like, name it all the Social Security numbers or something like.
Corey
Yeah, yeah. 000 through 11111. Yeah. I mean, there's so many, like, AI, anti AI for every, like, glue trap, there's an AI that detects glue traps. It's a fun little world we live in with scraping. So what is this WhatsApp private processing thing? Did anyone see this?
Wade
No.
Corey
So this is that. There's an article. Here it is. I just linked it. But basically, article feels like a kind of an oxymoron to me because the article is WhatsApp says in app AI tools will still keep messages secret. And I'm like, the AI tools are going to help secure the messages. So I guess, basically it's WhatsApp. They've, I guess, figured out a way to initiate a request to a confidential and secure environment. Well, it's both. It's confidential and secure. So, I mean, good to go. So I guess it's like AI, but somehow still encrypted or end to end encrypted. I don't really understand how that's possible, but it is kind of cool if you have the. I mean, it's similar, I guess, maybe similar to what Apple's doing with chat GPT where they like take the data and anonymize it to the best of their ability. But I don't know, it's kind of interesting to think about the technical implications of it. You have like this end to end encrypted message. You send it to cloud server but some other cloud server can't decrypt the contents of the message but can respond to it and send it back to you.
Wade
Like, I don't know.
Corey
Yeah, well, it's a cool idea, but I'm. The prompt itself might reveal sensitive information.
Wade
Why do you need a. I don't know. Why do you. Why do you need it in WhatsApp? It's just AI, everything. Just too much AI.
Corey
Well, that's like Facebook's whole thing, or meta's whole thing I guess, is like.
Wade
That'S what they're going.
Corey
Yeah, they're. They're like AI and everything. That's like their current business plan. So it fits. It's kind of cool. Don't get me wrong. I mean, I'll probably read through this article, but, you know, I would guess it's probably similar to what Apple's doing with their confidential usage of chat GPT. It's like you have these isolated cloud container type deals you deploy, you know, isolated cloud instance. It does the AI thing that it destroys itself. So it's like there's no storing of data.
Wade
Okay, here's a good one that I think we've been talking about for a while that I'm surprised I didn't read earlier. House passes bill to study routers national security risk.
Corey
I saw this and I was like, what does that even mean? Like, is this a pen test? No, it's not a pen test.
Wade
A bill requiring the department of commerce to study national security issues posted by routers and modems controlled by U. S. Adversaries Passed in the house on Monday.
Corey
Right? So it's past the house, it's not even real, or it's not like fully passed. It's partially passed. But I mean, what would this. Can you imagine? You're just like a guy, a contractor guy or girl, whatever, contractor for the government, and you get like a contract and it's like, we need you to assess where all the routers came from and whether there's national security risks. It's like, how would you even begin? Just like go and look in a server Cabinet and be like, well this one says Made in China. So it's probably insecure.
Wade
Like you go on Shodan and you just look for default creds and you say, yeah, we're, we're at risk.
Corey
Yeah, like my question about this and obviously I'm too lazy to read the actual bill, but it's like, how are they going to check or verify? Is it just going to be, this is a company that's known to do business. Like they're going to have a list of bad companies and a list of routers made by that company and they're just going to cross reference the two.
Wade
That's like my guess, maybe, maybe they, they push this all the way through and they do something good like we said and just make a standard for routers. Right? Like, like you, you have, you cannot have default creds. You have to have an end of life or a lifetime for X amount of years. Right. Maybe a couple security settings here and there. And we, then we need to jump on this and make that sticker we were talking about and you make it a US certified router. Right.
Corey
Well, so this kind of gets into like actual, at least in my pen testing experience, especially with continuous pen testing. Like as an example with this sonic wall, I'll get, let's, let's get specific with this sonic wall vul multiple clients have this vulnerability and I have messaged them and said, hey, you have this sonicwall vulnerability, you need to do something about it. And they respond and they say it's not actually ours, it's shared responsibility model. And I think that's the biggest thing about a lot of these firewalls and routing devices is like it's provisioned to them by their isp. They have no ability to do anything to it. They can't log into it, they can't mess with it, they can't patch it. And so I think that's the same thing the government would run into if they tried to figure out even just all the routers used by the government. It'd be like, well, this one isn't really. This is our, you know, our building has this or our ISP has this or our, whatever. That's like the tricky part with these routers is there's no one's ultimately responsible for the security of them. I'm personally super supportive of any kind of probe or whatever it is into like telecommunications infrastructure because I think this is like a huge weakness. And it's not just the US government, it's also companies, private companies too we.
Wade
Did skip on one very important part, and that is the name of this.
Corey
Bill, the routers bill.
Wade
Removing our unsecure technologies to ensure reliability and security.
Corey
I know, it's so silly. It's actually kind of funny. It's like. I mean, it's cool. I like a fun. I'm an acronym enthusiast, so I get it. Yeah. I mean, I'm supportive of anything that's like scrutinizing networking devices with after the Storm or what was it? Octotempest or whatever. The people who infiltrated the. Or is it why am I Assault Typhoon. That's who it was. I knew it was something storm related. Salt Typhoon. The people who infiltrated the US government's. Or not the US government, but all ISPs last year. I feel like after that every. Everyone's super paranoid about this, which I agree with.
Gerald
If this fact actually fails and they have to reintroduce it, would that be a reroute act?
Corey
I think that would be. The first act will be a sin. Then there'll be a sin act.
Wade
That's where I was gonna. That's great. No, they got to issue it a fin. When they, when they deny it.
Corey
No, let's be real. It's the government. They don't care whether anyone gets it. It's. It's udp. This is a UDP act.
Wade
All right, we got some more minutes. Okay, so this, this is a chicken. This isn't even a chicken news. This is more of a chicken adverb. So on Friday, me, Gerald Oer and Josh Mason are gonna do a cyber version of Hot Ones. Okay, if that's all. So if you realize that I've had a Hot Ones box in like the back of my closet for like four or five months, because we've been supposed to do this for a while now. So we're gonna be answering like cyber security questions while eating hot sauce. And the worst part is like my idea. And now I'm really not looking forward to this. Like, I should have never, should never have to bomb.
Corey
Do you have like all.
Wade
Oh, yeah. So. So a buddy. It was my buddy, a buddy of mine's idea. He wanted to do it. And I, I, I have the original. The bomb at my house. And like people do, we partake in some alcohol and we all get a Dino nugget and eat the bomb and suffer together. So the, the new Hot One sauces, though, they actually don't come with the original the bomb. That's like absolutely horrid. They come with like a, the Bomb reimagining, which isn't nearly as bad.
Corey
Okay. So I watched this video that was like analyzing like that the one YouTube channel analyzed all of the sauces for their actual Scoville content and basically like the result was only Da Bomb is hot and that's the hottest one. And the rest of them are not that bad. That was basically the end, like the last dab. And all those are not actually that hot.
Wade
So they are hot. I've had them all.
Corey
Sure.
Wade
Already.
Corey
But not like 10 times hotter than the bob.
Wade
No, they're not. They're not the original. Then the other thing is like the bomb just tastes like gasoline. That's the thing. Like it's not meant to be eaten.
Corey
Right.
Wade
It's meant to be put in chili. But yeah. And then the scoville units on the bottles are actually the scoville units of the chili used in it, not the actual, actual sauce.
Corey
Yeah. So basically the original Da Bomb was the hottest sauce ever on Hot Ones. So if you want to suffer, go for that one. All the other ones are like stand ins for that.
Wade
Yeah, pretty much. So if you want to see me suffer. Friday. Yeah.
Corey
Are you doing it live in person?
Wade
Yeah, we're doing it live. We're doing it live. It's not going to be recorded. That's the thing.
Corey
Where, where is this happening? How do I.
Wade
On Simply Cyber. The Simply Cyber YouTube channel. So we're doing it live and then it's going to get recorded, but it's not going to be up. It's not going to be up right away. We're going to send it to someone who wants to edit it and try to make it as much as they can. A Hot Ones episode.
Corey
Like closer to the Hot Ones.
Wade
Yeah, yeah. And we're also, I think all of us are recording in different locations. So I'm gonna try to record in my kitchen just to have more space and just if I need to puke or something, it's not gonna be like all over my computer.
Corey
Nice.
Wade
But we'll see how it goes.
Corey
What time on Friday?
Wade
That's a good question. Let me look at my calendar. Or it's on the Simply Cyber YouTube channel. It says 11am Pacific. So what is that, Eastern? Two, two, two. Yeah, I know time zones. I work East Coast.
Corey
What about Central? You got to cover Central 1, 1. What about Mountain?
Gerald
Mountain.
Corey
We gotta cover Hawaii. What about Hawaii? What about Newfoundland? It's 30 minutes off. Don't question it.
Wade
What about that island that only has birds on it? That's like plus 12. Nobody else.
Corey
Plus 12. How is that even possible?
Wade
Yeah. Yeah. Go figure. Yeah, it is. Go. There's. There's an island that is, like, plus 12. Look at it. Look it up. Or.
Corey
All right, if you're in that island that only has birds on it, please do not eat the chicken. You're eating it like an endangered endemic bird that's never been seen ever again. So don't eat the chickens.
Wade
It's going to be rough. I'm not looking forward to that. I made. I will admit, I made so you can see the image in. On. In Discord right now. I made that. I hammered that out in, like, an hour. I was pretty impressed with my. My gimp skills. I finally got to the point of.
Corey
Them are just photos that look like someone else took out a conference or something. And then.
Wade
Because they definitely are. Yeah.
Corey
Like, real.
Wade
When I googled Jerry, that was, like, the best photo that came up. So I just grabbed it, got rid of the background, and then Jason gave me his photo, and then I don't have photos of myself, so I grabbed one from Wild West Hack Infest.
Corey
Nice. Well, we'll have to look forward to that. I think. I think we're good to call it here. Thanks all for coming. Patch your firewalls or just destroy them. Better option. All right, see y' all later. See ya next week. Bye, Sam.
Podcast Summary: "Scatterd Spider Weaves Another Attack" – May 9, 2025
Podcast Information:
In the May 9, 2025 episode of "Talkin' About [Infosec] News, Powered by Black Hills Information Security," hosts Wade and Corey delve into a myriad of cybersecurity topics, ranging from high-profile breaches and threat actors to emerging security challenges in SaaS and AI integrations. The conversation is enriched with personal anecdotes, expert insights, and forward-looking perspectives that cater to both seasoned professionals and newcomers in the infosec realm.
The episode kicks off with a discussion on Patrick Opet, the Chief Information Security Officer (CISO) of J.P. Morgan Chase, who has publicly expressed apprehensions regarding the rapid adoption of Software as a Service (SaaS) products, particularly those integrated with Artificial Intelligence (AI).
Corey highlights Opet’s stance:
"He specifically calls out AI-driven calendar optimization service integrating directly into corporate email systems to read-only roles. So that's how I see it. It's like he's kind of freaked out by the adoption of AI." (06:00)
Key Points:
A significant portion of the episode is dedicated to the resurgence of the Scattered Spider threat actor, notorious for previous high-profile breaches such as the MGM Resorts incident.
Wade summarizes:
"They're being attributed to them, which is kind of interesting. But, yeah, there's been like supply chain impacts from this..." (11:00)
Key Points:
The conversation shifts to the concerning trend of North Korean (DPRK) IT workers infiltrating organizations. Corey explains:
"These people being a good, efficient worker with multiple jobs and being in the sigma grind set." (18:15)
Key Points:
Wade and Corey explore the Malware as a Service (MaaS) landscape, focusing on threat actors like Golden Chicken and the Gremlin Stealer.
Corey notes:
"Golden Chicken, that is a malware as a service shop for a while since I think the date was 2018..." (27:00)
Key Points:
A segment is dedicated to WhatsApp’s adoption of AI tools, aiming to enhance user experience while maintaining message confidentiality.
Corey remarks:
"It's like you have this end-to-end encrypted message. You send it to a cloud server but some other cloud server can't decrypt the contents of the message but can respond to it and send it back to you." (38:00)
Key Points:
Wade and Corey analyze a recently passed House bill mandating the Department of Commerce to study national security risks associated with routers and modems controlled by U.S. adversaries.
Wade explains:
"A bill requiring the department of commerce to study national security issues posted by routers and modems controlled by U. S. Adversaries. Passed in the house on Monday." (45:44)
Key Points:
In a lighter note, the hosts announce an upcoming episode inspired by the popular "Hot Ones" format, where they will answer cybersecurity questions while consuming increasingly spicy sauces.
Wade shares:
"On Friday, me, Gerald Oer and Josh Mason are gonna do a cyber version of Hot Ones." (50:31)
Key Points:
The episode "Scatterd Spider Weaves Another Attack" offers a comprehensive exploration of current and emerging cybersecurity threats, blending serious analysis with engaging dialogue. From high-stakes breaches and sophisticated threat actors to innovative yet challenging integrations of AI in security tools, hosts Wade and Corey provide valuable insights and actionable intelligence for their audience. The anticipation of their upcoming "Hot Ones"-style episode further adds a unique and entertaining dimension to the infosec discourse.
Notable Quotes:
Wade on AI Integration:
"Whatever has to come from an executive perspective." (07:53)
Corey on SaaS Risks:
"SaaS is a big risk. We've warned our clients about it." (10:29)
Gerald on Insider Threats:
"These people being a good, efficient worker with multiple jobs and being in the sigma grind set." (18:15)
Corey on Golden Chicken:
"We have a threat actor that's named Golden Chicken..." (25:45)
Wade on Upcoming Episode:
"We're going to be answering like cyber security questions while eating hot sauce." (50:31)
Stay tuned for more insightful discussions and updates in the world of information security, powered by Black Hills Information Security.