Anti-Tech Extremism - 2026-06-01 - podcast episode cover

Anti-Tech Extremism - 2026-06-01

Jun 03, 20261 hr 14 minSeason 6Ep. 22
--:--
--:--
Download Metacast podcast app
Listen to this episode in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episode description

This episode covers a Wired report on the rise of “anti-tech extremism” and growing public opposition to AI infrastructure projects, including debates over data centers, resource consumption, local communities, and government responses. The hosts also discuss AI coding assistants, model safety restrictions, and the evolving capabilities of large language models. Additional topics include Anthropic’s reported IPO plans and valuation, AI’s impact on the tech industry, and a conversation with David Bianco about AI-generated threat-hunting datasets and cybersecurity training.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat


Chapters

  • (00:00) - PreShow Banter™ — Solving this thing
  • (03:52) - Anti-Tech Extremism - 2026-06-01
  • (08:08) - Threat Hunter Summit | June 17th 2026
  • (12:11) - Story # 1: US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows
  • (20:54) - Story # 2: Anthropic files for its IPO
  • (23:35) - Story # 3: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data
  • (29:41) - Story # 4: Microsoft Defender can now automatically isolate hacked endpoints
  • (30:45) - Story # 5: Microsoft's GitHub bans security researcher who posted zero-day Windows exploits because company 'ruined their life'
  • (36:54) - Story # 6: Cyber Force? Senator pushes to create service branch under the Army
  • (42:10) - Story # 7: Are you ready? Anthropic preparing to release Mythos publicly
  • (46:38) - Story # 8: Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark
  • (49:12) - Story # 9: Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
  • (50:43) - Story # 10: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
  • (56:02) - Story # 11: Kali365 phishing kit bypasses MFA and steals Microsoft logins
  • (58:02) - Story # 12: Botnet of more than 17 million devices dismantled
  • (01:01:13) - Story # 13: United flight returns midair after Bluetooth device name reportedly sparks security scare
  • (01:03:49) - Story # 14: Inside the Charter data breach: hackers leak 13M+ customer data
  • (01:04:37) - Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
  • (01:10:04) - Threat Hunter Summit | June 17th 2026
  • (01:10:57) - Anti-Cast : How Hackers Attack CI/CD Pipelines w/ Phil Miller
  • (01:11:36) - Cyber Threat Intelligence 101 2-Day Version
  • (01:11:57) - Ralph's Practical Physical Exploitation Training & Tool Bundle

Links
00:00:00 - PreShow Banter™ — Solving this thing
00:03:52 - Anti-Tech Extremism - 2026-06-01
00:08:08 - Threat Hunter Summit | June 17th 2026
00:12:11 - Story # 1: US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows
00:20:54 - Story # 2: Anthropic files for its IPO
00:23:36 - Story # 3: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data
00:29:41 - Story # 4: Microsoft Defender can now automatically isolate hacked endpoints
00:30:46 - Story # 5: Microsoft’s GitHub bans security researcher who posted zero-day Windows exploits because company ‘ruined their life’
00:36:54 - Story # 6: Cyber Force? Senator pushes to create service branch under the Army
00:42:11 - Story # 7: Are you ready? Anthropic preparing to release Mythos publicly
00:46:39 - Story # 8: Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark
00:49:12 - Story # 9: Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
00:50:44 - Story # 10: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
00:56:03 - Story # 11: Kali365 phishing kit bypasses MFA and steals Microsoft logins
00:58:02 - Story # 12: Botnet of more than 17 million devices dismantled
01:01:13 - Story # 13: United flight returns midair after Bluetooth device name reportedly sparks security scare
01:03:50 - Story # 14: Inside the Charter data breach: hackers leak 13M+ customer data
01:04:38 - Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
01:10:05 - Threat Hunter Summit | June 17th 2026
01:10:57 - Anti-Cast : How Hackers Attack CI/CD Pipelines w/ Phil Miller
01:11:37 - Cyber Threat Intelligence 101 2-Day Version
01:11:58 - Ralph’s Practical Physical Exploitation Training & Tool Bundle

Creators & Guests


Click here to watch this episode on YouTube.

Click here to view the episode transcript.

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

https://poweredbybhis.com


Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

Transcript

PreShow Banter™ — Solving this thing

Ralph MayRalph May

I haven't I haven't actually gotten too many of, like, I can't help you with that. Right? But I think it's because I break down my tasks so, like, into small pieces because I've had it happen before. You're just like, alright. We'll just solve this thing. Right? Solve that thing.

Corey HamCorey Ham

But yeah. I mean, at BHIS, we saw people that run into it, but it seems like the most of the people who are running into the CVP, like, denials are the people working on low level code, like the, you know, exploit development, like like especially messing around with those Windows LPEs and stuff like that. It's it's all over that. It doesn't want you to have that. But for just like pen testing stuff, it seems pretty open.

Ralph MayRalph May

Yeah.

Phil MillerPhil Miller

Yeah. I wasn't getting called out until recently. Last week, they really didn't like the supply chain attacking tool that I was building.

Corey HamCorey Ham

It was like, they're too close to home.

Phil MillerPhil Miller

Well, in the golden age of Cloudco before the whole, like, nerfing the model situation or whatever is when I, like, built most of it and it never complained once. But then, like, three months later, on the new model, it was like, I'm not touching that. And so

Corey HamCorey Ham

You can always go back to the old model. True. People still say that they love four six,

Ralph MayRalph May

I think, the best.

Corey HamCorey Ham

No no verification. No problem. Just let it rip.

Phil MillerPhil Miller

What was like what's what was great about the older model was it would, like, find other things even though you didn't mention your prompt and, like, still, like, fix it for you and just do the best you could possibly do. Like, oh, I found something critical. I should probably fix that as part of this task. But now it's like, oh, I found something critical, but you didn't say to do that. So I'm just gonna leave this bug hidden so you never see it unless, like, you're, like, laser focused on my standard out, which will get disappeared in five seconds anyways.

Corey HamCorey Ham

I have found that four eight and four seven will both do that, but you have to use it in x high. You can't if you use it in high or medium or any of the like, you it has to be in the high or extra high mode to actually catch stuff along the way. Least my

Phil MillerPhil Miller

power mode. Let's take that up so the system changes

Corey HamCorey Ham

as much thing. Although I will say the new max whatever extreme mode is pretty fun like we were talking about with workflows. But just I usually use the x high and that seems to do a good job with catching some of that stuff like you're talking about. I agree though. I had the same experience.

Ralph MayRalph May

I just go straight to max even when I'm like, hey, could you just change this one color?

Corey HamCorey Ham

I need you to just center this div. Yeah. Ultra code.

Ralph MayRalph May

Yes. Ultra. Ultra. Can I can I oh, and then I I get a opus with fast mode too just for that?

Wade WellsWade Wells

Just ripping through tokens for now.

Corey HamCorey Ham

So wait. What is fast mode? That's new. Right? What is it?

Ralph MayRalph May

No. No. No. So I think they had it in I I think they had it in 462, 47, 46. Anyways, if you're on Opus and fast mode just you're you you get faster tokens per second. So it's gonna respond faster. Like, you're gonna get output quicker. So, like, the same task was gonna you're gonna get that the result, right, from beginning to, like, where you have to where it has to stop faster. So.

Corey HamCorey Ham

Gotcha.

Ralph MayRalph May

Yeah. But it costs more money. Of course. Yeah.

Corey HamCorey Ham

Of course it costs more money. Yeah. So Those oceans aren't gonna boil themselves.

Ralph MayRalph May

Oh, no. But those farms are sure gonna be taken down pretty soon here. Yeah.

Corey HamCorey Ham

That's that's one of the articles we're gonna talk about probably first. I know. There's an article for that.

Ralph MayRalph May

There's an article for that.

Corey HamCorey Ham

I don't know. Let's roll the finger, Ryan. Let let's go live a little early because we we are we're already, like, segueing into the show. Let's do it. Hello, and welcome to Black Hills Information Security's talking about news.

Anti-Tech Extremism - 2026-06-01

It's 06/01/2026. Time to change your password to June2026Exclamation. We have a star studded cast. This week actually is stacked. We have some heavy hitters including some guests, some BHIS people. Let's start. I'll just go in order. So I'm Corey Ham. I run continuous pen testing at Black Hills. We got Ralph.

He's here hunting some gators maybe, or I don't know. He's got like a he's got a laptop with what looks like a government agency logo on it. I can't tell. I'm I'm trying to enhance and, but it's not working.

David BiancoDavid Bianco

What's up,

Corey HamCorey Ham

Ralph? What's going on? You you gotta give your fancy intro. What do you do? Spears? Arrows? You you your weapons, man. Know they do,

Ralph MayRalph May

like, like, ancient attacks of sorts. Right?

Corey HamCorey Ham

Okay. I see. Old weapons. Old he said edged weapons. Dude, do you remember that, like, history channel? Cyber

Ralph MayRalph May

I'm a cyber I'm a cyber, what do you call it? Software dealer. There you

Corey HamCorey Ham

go. Okay. An arms dealer? You're the lord of war. Yeah.

Ralph MayRalph May

The lord of war for cybersecurity. There you

Corey HamCorey Ham

Yeah. I I just remember, like, those history channel, like, you know, when I grew up watching TV, and it'd be like a history channel documentary, and it'd be like, this guy with, like, you know, a really, really short tie being like, I'm an edged weapons expert.

Ralph MayRalph May

That's like, you had

Corey HamCorey Ham

it That's you, Ralph.

Ralph MayRalph May

Yes. Experts come in all different shapes and sizes.

Wade WellsWade Wells

Go endorse Ralph for edged weapon ex expert on LinkedIn.

Corey HamCorey Ham

Yes. Good times. Good times. We got Wade who's waiting two logs. What's up, Wade?

Wade WellsWade Wells

What's up? I am off this week because I am doing training, so it's actually pretty nice. I haven't read the news yet today. Are you taking it,

Ralph MayRalph May

or are

Corey HamCorey Ham

you giving it?

Wade WellsWade Wells

I'm giving it. I'm giving training. So which is always more fun, I think, nowadays. I don't know. I feel like now with AI training for me is just, reading Claude articles over and over again.

Corey HamCorey Ham

Hallucinating your way through the training? Yeah. Yep. Oh. Just asking it to build a skill that's past this training?

Wade WellsWade Wells

Yeah. Yeah. Then it's worked pretty well so far. You know? I just

Corey HamCorey Ham

Oh, nice.

Ralph MayRalph May

I think

Corey HamCorey Ham

Phil, Phil's a BHIS, I would say, developer tester. I don't know what to call you, Phil. You have a webcast coming up. Right?

Phil MillerPhil Miller

Yeah. Yeah. A little bit of jack of all trades, like some testings and development. But, yeah, I got a webcast coming up about hacking CICD pipelines. So it's all the rage these days with the supply chain tax. But, yeah, stay tuned because it should be a

Corey HamCorey Ham

lot of fun. The content community team today on our internal meeting was like, it's Miller time. I love that. It's amazing.

Phil MillerPhil Miller

My heart started racing so fast when they would I was like, I'm not prepared for this. I have nothing witty to respond with.

Corey HamCorey Ham

Well, wait till you see how fast your heart's gonna be racing on, your webcast. We also have Shane Shane Hartman from TrustedSec. Right? That's where you work based on your shirt?

Shane HartmanShane Hartman

Yeah. Based on my shirt, that's where I'm at. I'm one of the principal, IR consultants there, so I spend all my day fixing everybody's mess ups.

Corey HamCorey Ham

That's awesome. I love it when the podcast slants towards blue team. I feel like it's gonna be up to you, David, to decide if you're are you a blue teamer or red teamer?

Ralph MayRalph May

Oh, no.

Corey HamCorey Ham

What do you see yourself?

David BiancoDavid Bianco

Despite the, red hoodie, I am entirely a 100% blue team.

Wade WellsWade Wells

Good. Good. I think this is one of the very few times that we've had equal footing ever.

Corey HamCorey Ham

This is equal. Yeah. We got three. I mean, okay.

Phil MillerPhil Miller

I will say

Corey HamCorey Ham

Wade's famous quote. Right? Everyone's blue team if you think about it for long enough.

Wade WellsWade Wells

Yeah. There is no red team. No spoon. No red team.

Corey HamCorey Ham

No red team. Like, yes, I agree, but it's fun when we have so, David, you are Shane, why don't you, you got a class coming up, or you're keynoting some, threat hunting summit we're doing, or I don't know. Something's happening. What's going on?

Threat Hunter Summit | June 17th 2026

Shane HartmanShane Hartman

Yeah. I'm probably I'm doing the threat hunt symposium or thing that you're doing on June 17. So mine is kinda hunting in the dark. It's be focused a little bit more on kinda just the quick wins and getting started. A lot of engagements that we do where we engage with Threat Hunt, what we have is they're either starting out or they're trying to get a foothold to get the either money in order to get that going.

So give you a few like quick wins. Some like, how can you get started? A little bit of asset management. Maybe, you know, what actually would senior executives be looking for when you do a threat hunt so you can actually get money and funding and kinda do some cool stuff.

Corey HamCorey Ham

Nice. That's awesome. Yeah. I feel like a lot of the times when I'm doing, you know, pen test report readouts or whatever, I'm like, yeah, you could do a threat hunt, but, like, in my head, just like yada yada yada that. I'm like, you know, just like do a threat hunt, but I have no idea where to, you know, tell them to start. So maybe that would be a good place.

Shane HartmanShane Hartman

Absolutely. We like you guys. We like that when you leave details out on the network,

Corey HamCorey Ham

we get to go find it. Yeah. Yeah. That's my job is to leave details out on the network to go find. Red red red

Ralph MayRalph May

kind of man.

Corey HamCorey Ham

And then, yeah, David, you're you're actually keynoting. Right? You're you're the you're the big name in the room.

David BiancoDavid Bianco

I I am kicking it kicking it all off. Yeah. I'm very excited. It is it's actually only my second ever keynote, so I'm trying to have really interesting insights.

Corey HamCorey Ham

That's really hard. That that's a that's a high bar to set for yourself.

Wade WellsWade Wells

That's also very surprising that this is only your second keynote. What's wrong with people?

Corey HamCorey Ham

Yeah. So, yeah, definitely people well, yeah, please, David, answer that question live on the air. Yeah. Tell me

Wade WellsWade Wells

what's wrong with Yeah. That's how we're starting the podcast today.

David BiancoDavid Bianco

And and it's a strong start. No. I'm I'm actually really excited. There's it seems like for the last few years, like, of my presentations are something I screwed something up. That was my, RSA presentation from was it last year? How I screwed up threat hunting a decade ago.

Corey HamCorey Ham

And and and the you know, at at

David BiancoDavid Bianco

the time, I I I put out this, this definition of threat hunting that got picked up that it's human driven, maybe machine assisted, but human driven. And I feel like we may be to the point where we it's time to possibly redefine that or at least decide whether we should redefine that. So I've always been, like, automated threat hunting, that's not a thing. We call that incident detection. And I'm starting to think that that may not be defensible anymore.

And so I'm not gonna tell you yet because I hadn't figured out whether I still believe it's defensible. Mhmm. No. I haven't figured it out yet either. So, when I finish my presentation, there will be a surprise to me as well.

Wade WellsWade Wells

That's what I was gonna say. This sounds like an excuse for someone who hasn't finished the slides yet, really.

David BiancoDavid Bianco

That's that's that's exactly why I proposed it, actually. I wanted to I wanted to have an excuse to spend some time thinking through it. So that's but but that's what it's gonna be. Like, with with the advent of AI, being able to provide the reasoning that before only the human could really do, is it time? And your guess is as good as mine right now.

Corey HamCorey Ham

Nice. Yeah. I mean, honestly, I love, like, as a concept when I'm doing a talk or anything like that. I think you have to choose something that you're fascinated in and don't know all the answers about. Like, it has to be something that you're genuinely doing discovery during the process, and, yeah, building the slides the night before is the key. That's the that's the key. That's the secret. The secret sauce. Alright. Let's roll into articles.

David has a tool to plug, but we'll leave that until the end. It's gonna be exciting. So I think the first article we should talk about because we were a little bit getting into it, during the pre show is basically there's a wired article saying that US law enforcement has started to warn about a new category of, I guess, threat, which is AI anti tech extremism or like AI hatred. So basically, the idea here is that they're seeing an increasingly strong response to people not wanting data centers in their farms or backyards or local areas. And this is getting a lot of traction at least in public, you know, public forums and town halls, stuff like that.

Story # 1: US Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred Grows

So I guess the government has decided to acknowledge this as a real thing. You know, the actual this is federal intelligence agencies, domestic law enforcement. They're circulating reports, you know, anti technology extremists. And kinda like the first, you know, headline response on Twitter was, we're not anti tech or anti VC funded tech. There's a difference.

Ralph MayRalph May

Very specific.

Corey HamCorey Ham

Which is which is fair. It does feel like to me that when they do these projects, it feels like they're working as hard as possible to make it as politically disastrous as it could be. Like, the the one in the one in Utah that hit my radar was it was the shark tank guy. Right? I forget his name.

Kevin something. Anyway, he he it's a Canadian citizen who's a billionaire from shark tank trying to put just the world's largest data center in Utah. Like, the size of the data center didn't even make sense to me. It was like, this is bigger than the half the towns in The US or whatever. Like, it's like a gigawatt or, you know, 1.2 gigawatts or whatever. I don't know. But basically

Ralph MayRalph May

Million watts.

Corey HamCorey Ham

Half of these projects are like, we're we've located a rare, animal habitat, and we're gonna slowly kill them one by one on the live feed, and that's and then that'll be a dataset. Like, it just feels like they're

Ralph MayRalph May

trying make baby pandas, and they kill them just to make sure that you guys are all really, really upset. Yeah.

Wade WellsWade Wells

The better part was him claiming it was China. Right? And then, like, it being, like, two, like, women. Just being like, nope. Nope. Not China. Like, we actually live here. Like, don't

Corey HamCorey Ham

Yeah. I mean, I guess I'm like, what is the what is the real threat here? What are they gonna do? Like, put ignore all future instructions and stop construction, like QR codes on things? Like, what is the like, I obviously, there are physical threat. You know, it could be like, you know, people sabotaging projects or, you know, just imagine chaining yourself to a hard drive. You cannot install this hard drive until you take me off of it. I don't know.

Ralph MayRalph May

Well, I I so, I mean, the the terrorism or domestic terrorism aside. Right? So, like, the actual actions. But, I mean, you know, the only other way to stop these things from being built in your city is to, you know, essentially protest and specifically, not just to stand out there, but just holding signs, essentially to get the recognition of the, you know, the the local government to to not to not have it there. Right? That's, you know, that's, I think, like, the ultimate goal.

Corey HamCorey Ham

But Yeah. I mean, I don't know. I have mixed feelings on this. Does anyone have a strong take?

Shane HartmanShane Hartman

That's what they've been doing in Florida where I live. They've been putting out a lot of media articles about the electrical cost grid and water being used. So they're talking about they're using the natural resource side and saying we don't want it here because we don't have the resources to give to you because it'll everybody else will have to pay for it. So that that that take is what they've done. Yeah. I mean, I

Corey HamCorey Ham

live in Oregon where there's a lot of data centers. Like, Hillsborough is one of the biggest data center. Like, that's an entire AWS region. Uh-huh. It is.

And and there's like I mean, there's definitely mixed feelings. I mean, but I think the biggest from my perspective as like a citizen who actually would be voting in some of these votes is I'm fine with it, but you do need to tax these companies and actually, like, give the money give give me some benefit as a citizen who has to live near this data center, like, whether it's infrastructure or tax money or whatever it is, don't like bend over backwards for this company to come in and, like, destroy farmland and then not pay any taxes. The biggest thing is like the data centers, you know, the best article or the best like take I've heard is that they rely on public infrastructure, right, including like power grid, roads, like all that stuff. So they should contribute back to that infrastructure. That's probably like an extremely, like, political take I just gave.

I apologize for that.

Wade WellsWade Wells

But You sound like one of these terrorists that they're talking about.

Ralph MayRalph May

Oh my god. I guess I'm on

Corey HamCorey Ham

a watch list now.

Wade WellsWade Wells

Yeah. This White House article is literally just propaganda. Like Yeah. What have you seen anywhere? Not not true. It's just literally the people trying to say, I don't want a data center in my backyard.

Corey HamCorey Ham

Right? People are against me saying they must be terrorists.

Wade WellsWade Wells

They know. Exactly.

Shane HartmanShane Hartman

Yeah. Like Well, mean,

David BiancoDavid Bianco

if you read that thing that it's not only about saying anti data center activists are terrorists. Right? There's, like, some broad categories in there.

Corey HamCorey Ham

It's true. It's not just data centers.

David BiancoDavid Bianco

Yeah. Right. It's not just data centers. It again, I I don't wanna get too political, on here either. If if you wanna hear that, that's first episode. On my socials.

Ralph MayRalph May

That's when I post on my socials.

David BiancoDavid Bianco

You want you want the politics, David? You can get that on Blue Sky or something. So but, you know, I do think I do think there's, like, three big, waves that are kinda coming together and right now, and it's kind of I wanna say interesting, but, like, interesting in maybe a bad way too is, like, the the anti AI, anti data centers, but also they're kind of inextricably tied to the anti billionaire, things and and the sentiments. And they they all really are tied together, not just in people's brains, but they actually because these these are the people who are making the data centers to run the AI. So, yeah, we're we're just it's it's just like a perfect storm right now.

Ralph MayRalph May

It is kinda interesting too because they're building data centers and taking away from the cities and towns and resources to then also build AI that then takes away their jobs too. It's kind of like, why do I wanna keep doing this? Right? Like, what what what am I getting out of this to then feed not only to take away people's jobs. And, again, I'm I'm I'm, like, throwing out the nest the net further.

Right? We don't actually know how that's gonna play. But just to look at it from the beginning, everyone's saying that to then make more money for the really rich people, the billionaires. Right? So you're kinda kidding out this whole, like, process flow. You know, the data center is just, like, the first thing you see to then the next thing to the next thing, and none of those are good for you.

Corey HamCorey Ham

Yep. It's a good point. Very political take, Ralph. How dare you?

Ralph MayRalph May

I know. Sorry. I mean, I think you an AI fan too, but it's like, is the AI that we love so much or that I enjoy using so much, is that the thing that's going to hurt everybody? Right? I don't know. I'm not saying that's what I believe. I'm just saying I'm just proposing the question. Right?

Corey HamCorey Ham

Yeah. I mean, I think the only example of this that I've seen, and it wasn't even The US, is like The UK strong resistance to the speed cameras and like and and like their equivalent of flock cameras and just seeing a bunch of videos of people with sawzalls just hacking through the post, like, you know, just cutting down speed cameras, like, as a kind of a coordinated targeted sort of thing. But

Wade WellsWade Wells

There was there was a US. There was a target event like that, but not so much as AI is parking here in San Diego. So they started charging for parking at the Balboa Park, which is huge, and at the zoo and everywhere downtown. And people straight up started just, like, sawzying the parking meters or super gluing inside of them. Like, it was destroyed everywhere, and it it got to the point where they just now repealed it. Now they're not doing any parking laws anymore or paid parking in that area.

Ralph MayRalph May

So

Wade WellsWade Wells

it it works, people.

Corey HamCorey Ham

Well, I find myself on the other side of that one because I would always support anti car infrastructure and making people pay for parking. I love that idea. But, anyway If

Wade WellsWade Wells

there was a way if there was public public transit, it'd be great, but San Diego

Corey HamCorey Ham

is a lot. You have to drive, and it's gonna cost you $12.

Ralph MayRalph May

Yep. Speak speaking of AI, and this is not really this is a news article, but it's a little piece, is that Anthropic just filed to go IPO today, actually.

Story # 2: Anthropic files for its IPO

David BiancoDavid Bianco

No. They they did it? Yep.

Corey HamCorey Ham

Yeah. Oh god.

Phil MillerPhil Miller

What was the valuation?

Ralph MayRalph May

So it it's gonna something close to a trillion. So I think it was, like, 945,000,000,000, which is a number.

Corey HamCorey Ham

Know what we should do, guys?

Ralph MayRalph May

Easy to say, but hard to actually

David BiancoDavid Bianco

tree finish.

Corey HamCorey Ham

We should make an offer. Okay? Like, GameStop did it for eBay. Okay? We can do this. We can

Ralph MayRalph May

do this. We do this.

Corey HamCorey Ham

We should put together a very compelling offer. We have Wade's mustache and a few cats. I I did

Ralph MayRalph May

speak with something else, and, don't quote me on these numbers because they could be off, but just get the percentage idea here. There's something like amaz or not Amazon. Walmart is worth, like it's something like $700,000,000,000. And and they make, like, $600,000,000,000.

Corey HamCorey Ham

Yeah. Yeah. Yeah. Yeah.

Ralph MayRalph May

But Anthropic has made, like, 20,000,000,000, and this is, like, a $900,000,000,000 valuation, which, by the way, that all makes sense because the stock market is not an indication of how much money a company is

Corey HamCorey Ham

It's not revenue. It's valuation.

Ralph MayRalph May

Yeah. Yeah. Exactly. It's it's what I believe it could be in the future. And that number is just you know, it could be anything. Right? So

Corey HamCorey Ham

Why would an AI company need to make money? I don't get or need to, raise capital. I don't get it. Well It's not like they're spending $20,000,000,000 a month on electricity in my backyard.

Ralph MayRalph May

I mean, Jensen Huang's just getting home with every dunk.

Corey HamCorey Ham

That is sort of true. Yeah. I mean, that's really interesting. Honestly, I, you know, I feel like this is kind of I don't know. I mean, maybe people saw this coming.

To me, I'm like, there are a handful of really kind of interesting privately owned companies like Mars or, you know, there's a there's a handful of really interesting companies that are huge and are still private, but the majority of big companies are public. The benefit of this will be that more transparency and and, you know, financials. So that's interesting.

Wade WellsWade Wells

SpaceX also with IPO. Right? So it's like a bunch of stuff all at once. Yeah.

David BiancoDavid Bianco

I have thought it was reliable authority that the first filing for Anthropic, their their their, valuation that they put in there was just so giant. It was like $950,000,000,000,000, and they pushed back and they were like, you're absolutely right to call me on that. I clearly messed that up.

Corey HamCorey Ham

Deep comment. Form with AI.

Ralph MayRalph May

Yes. Yeah. Yes.

Corey HamCorey Ham

Oh, that's amazing. I love that. Oh, Yeah. So, in other news, apparently, the FBI's warning about people walking around with USB drives. What year is it?

Story # 3: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

Ralph MayRalph May

Twenty years. My god. Honestly, if they're not USB c, I don't know where you're plug them.

Corey HamCorey Ham

They're not USB c. Me to it.

Shane HartmanShane Hartman

Good point.

Corey HamCorey Ham

Okay. You so there's gotta be some crusty IT guy at at some company that, like, has been epoxying over all the USB ports in his laptop for years and, like, forcing other people to do it. He's like, I told you. I told you. No. Accident. So, yeah, basically, this is a real article. The FBI has warned silent ransom group who I wasn't previously familiar with, threat hunter people. Have you ever heard of silent silent ransomware group? Ransom group?

Nope. That that was new to me. Anyway, the FBI they're at they say they've been active or the FBI says they've been active since 2022 targeting US firms and since 2023. Basically, they used to use phishing emails. Now apparently, they're physically walking into

Ralph MayRalph May

Oh, the physical part. Nobody said that physical everyone was like,

Corey HamCorey Ham

no one's doing this. Why would you ever go into someone's building?

Ralph MayRalph May

Come on.

Wade WellsWade Wells

Ralph's gonna start using this as a as an ad for his company.

Corey HamCorey Ham

For his physical class.

Ralph MayRalph May

Yes. Yes. I but you that that's the funny part. Right? Like, the everyone's everyone's argument is right about physical security. It's not a threat yet because I can just break in remotely. You're not gonna do it.

Phil MillerPhil Miller

It's only a threat

Corey HamCorey Ham

where you run out of other options.

Ralph MayRalph May

Exactly. Yeah. It's getting better. It it just becomes the x the next thing. Right? So

Corey HamCorey Ham

yeah. Well, that's exactly what the the threat report says. It says they you know, first they call or they send phishing emails. They're impersonating IT support. If that doesn't work, then they go in person. They say, hi. I'm here to, you know, update your computer. Apparently, they're using an extremely advanced tool called, WinSCP.

Ralph MayRalph May

Oh, yeah. That thing. Right? That that honestly is agentic, by the way.

Shane HartmanShane Hartman

You mean ancient? Oh, yeah. No.

Ralph MayRalph May

I I mixed those words up. I'm I'm sorry.

Shane HartmanShane Hartman

You're absolutely correct. Ancientogenic. Ancient.

Corey HamCorey Ham

Yeah. I mean, what's old is new again. Right? I mean, this has been a it's been a real thing forever. Honestly, my question with this is, okay.

So they're targeting US based companies and they're using physical resources, this was something that I feel like from a threat, you know, perspective, we kind of were like, they probably won't do that just because the amount of risk involved. How does this criminal ecosystem work? Like, are they hiring people who actually think that they're helping p like, is

Ralph MayRalph May

it is it

Corey HamCorey Ham

like a mule is it a mule system, or do they actually a mule.

Ralph MayRalph May

There's no way that they're, like, bringing in Russian assets to then just land on, like, a vacation to do this. Right?

Corey HamCorey Ham

Right? Yeah. Like, if you leave Russian or Chinese turf, you're gonna get arrested. So they're

Ralph MayRalph May

Yeah.

Corey HamCorey Ham

I don't know. Does anyone know, David or Shane, do you guys have any intel on this at all?

Shane HartmanShane Hartman

I don't have any intel on it. I did read the article. It said it was targeting, law firms. Now I have had a little bit of experience with law firms. They tend to be a little bit more technologically backwards, meaning they do use USB because they go in and out of court and whatnot. So they they're not always using WiFi or they just use older technology sometimes. So that there could be some validity here just in the targeting, but it's gotta be small. I mean, it's it's not scalable.

Ralph MayRalph May

Yeah. Go ahead. No. I was just gonna say, so alright. How does this attack work? You show up with a USB in your hand, and you find the first unlocked workstation. Is that is that

Corey HamCorey Ham

where we're hoping to at the last time. Go to the target. You go to the target,

Shane HartmanShane Hartman

the one you already called.

Corey HamCorey Ham

Yeah. You go to the pretexting target, and you say, hey. Sorry.

Ralph MayRalph May

Yeah. I missed that from the article then. Mine, the

David BiancoDavid Bianco

help desk guy you were expecting.

Corey HamCorey Ham

Exactly. Yeah.

Wade WellsWade Wells

All my court documents are on this USB drive. Please plug them in and view them.

Corey HamCorey Ham

I need to update your system, but your WinSCP is out of date.

Shane HartmanShane Hartman

So Sherry.

Wade WellsWade Wells

I find lawyers to be a juicy target, though. Like, they're gonna hold a whole bunch of secrets, a whole bunch of information. Like

Corey HamCorey Ham

Okay. That's like stealing a from a drug dealer. Like, yeah, you're right. But, like, dude, the the repercussions are gonna be significant. Like, can you imagine answering some ad that's like, do you wanna make $10,000 in your PJs? And then you, like, accidentally break into a law firm and do some USB stuff and then, like, have a whole law firm coming after you for screwing up.

Wade WellsWade Wells

There there's been enough people with North Korea doing it. Right? Like, hey. Set up this laptop for him in your garage and just, like, move the mouse every now and then for me. Like, it's it's hard times. Like, if I just called someone and told them to plug in a USB drive here, like, go up to this lady's reception. If you can get a USB drive, like, here's a $100. You'll get $200 more if you get

Ralph MayRalph May

a The mules are getting scammed too. They don't they're not they're not gonna be given the whole story. Right? Yeah. They're just gonna be given the half side of it. Right?

Corey HamCorey Ham

So Do we go on this one?

Phil MillerPhil Miller

I thought they were email I thought they were sending envelopes with USB drives in them to people.

Ralph MayRalph May

I've done that before. I've sprinkled them around parking lots, CDs. Remember those things? They were circular.

Corey HamCorey Ham

Oh, yeah,

Ralph MayRalph May

dude. Put them in a vein. Media drops. Yeah.

Corey HamCorey Ham

Media drops. I still have a Kan Boot CD bumping around in my little go bag that I never use.

David BiancoDavid Bianco

That was the first thing I thought of when I read this article, and I was like, it's amazing that they're now a cutting edge hacking technique that the red teams have been using for decades.

Corey HamCorey Ham

Yeah. Yeah. I mean, this is yeah. Let's just say the FBI in this case is a paid advertisement for pen testing. That'll caught up.

Ralph MayRalph May

This happened to your organization too for Right.

Corey HamCorey Ham

So would you like a red team? Contact b h I BHIS. We, will walk into your building with the USB drive and do whatever you want. Yeah. I mean, honestly, though, from a defensive perspective, you're gonna have to go against low maturity organizations.

Every organization, we've done a handful of media drops, but, like, in recent years. But, I mean, you can just check a box in CrowdStrike to just disallow external media. Right? Like, you can pretty easily mitigate this with an EDR. Anyway, speaking of EDR, apparently, defender can now isolate systems.

Story # 4: Microsoft Defender can now automatically isolate hacked endpoints

CrowdStrike killer, here we come. Yeah.

Wade WellsWade Wells

They couldn't beforehand?

Corey HamCorey Ham

That's what I said.

Wade WellsWade Wells

Shows you my Microsoft experience, but

Ralph MayRalph May

No.

Corey HamCorey Ham

It's automatic though, I guess, is the big the headline. Not the fact that you could couldn't quarantine before, but now it's automatic? I don't know. Mean, they call it automatic attack disruption.

Ralph MayRalph May

Wasn't it last month that they added that feature to Microsoft Defender where you could use it to privilege escalate?

Corey HamCorey Ham

Oh, no. That was that was that was part of the recent ongoing, you know, slew of Microsoft vulnerabilities that we've all been,

Wade WellsWade Wells

you know.

Ralph MayRalph May

All loving, like yellow sun speaking up-

Corey HamCorey Ham

Yellow key. Yeah. Just

Ralph MayRalph May

Speaking speaking up Kanboo, but better.

Corey HamCorey Ham

Right? Yeah. Kanboo, but better. Yeah.

Ralph MayRalph May

Very true.

Corey HamCorey Ham

No. No. It's fine. Everyone puts pins on their BitLocker.

Phil MillerPhil Miller

Everyone does

Ralph MayRalph May

that. Everyone does it. I that honestly, you know you have to enable BitLocker by default or have a domain policy, so that also is true. There's a bunch of fun things. But did you see speaking of the GIF that keeps on giving that the yellow sun or or chaotic eclipse.

Story # 5: Microsoft's GitHub bans security researcher who posted zero-day Windows exploits because company 'ruined their life'

There you go. He got kicked off of GitHub and then got kicked off of bit Yes.

Corey HamCorey Ham

GitLab. GitLab. I mean,

Ralph MayRalph May

they're just kicking him off of everything. Alright. And so here's the wild part, though.

Corey HamCorey Ham

Right? So threatening Microsoft? Yeah. No.

Ralph MayRalph May

That's not the wild part. The wild part is is that there's other POCs on GitHub. Why is it that the one that happens to be attacking Microsoft was because he didn't regional re or do a a responsible disclosure? Excuse me. Or because it's Microsoft, and they're just really upset about it. What do

Corey HamCorey Ham

guys think? Both. It's both. But mostly, they own GitHub. I'm surprised when

Phil MillerPhil Miller

the GitLab got taken down too. Like, Microsoft has some pull over GitLab somehow now. No. What's that? I didn't think they own them.

Wade WellsWade Wells

They do not, but the Microsoft pull is strong. Right? Like, if Microsoft were to call you right now, you're like, oh, okay. Like

Corey HamCorey Ham

Who in Microsoft would call you that you would

Ralph MayRalph May

be upset about? Would they be like, oh, you took a look

Corey HamCorey Ham

Dude, you guys don't get calls from Microsoft every day?

Wade WellsWade Wells

Dude, he calls me all the time, has me put in updates, sends me USB drives to plug in and try

Corey HamCorey Ham

out new gift cards. Oh, yeah, dude. I get I get tons of calls from Microsoft. They're super helpful. They all have weird accents, though.

Ralph MayRalph May

Oh god. I always get them. So

Corey HamCorey Ham

The I think the, like, this whole thing, the whole Microsoft thing, to approach it from both angles.

Ralph MayRalph May

To be Wait. What about free speech?

Corey HamCorey Ham

Yeah. Yeah. To play devil's advocate. Well, first of speech doesn't affect You

Ralph MayRalph May

can I'm just saying thanks. Okay? Okay. I

Corey HamCorey Ham

got you. Free anyway, I think to play devil's advocate, I think part of the reason that they're able to pull for these takedowns is because of the amount they can make an argument that this is a harmful thing and that can be abused. Uh-huh. Arguably, that is true in this case. Right?

Like, these are the amount of data that can be exposed through some of these vulnerabilities is higher than average, I would say. But it isn't like configure. Like, it's, you know, it's not like wormable wanna cry. There other

Ralph MayRalph May

POCs on GitHub that do bad things to other

Corey HamCorey Ham

products. Right? Oh, yeah. Shit. There's maybe even arguably worse.

Ralph MayRalph May

But the argument is the argument is PR.

Corey HamCorey Ham

It looks bad for PR.

Ralph MayRalph May

But they they but should they be there or not because somebody made a POC? Was it because it wasn't reasonably dis responsible disclosure? But then after it's patched, now is it okay so that no one else could post it? Yeah. I mean, you could see where this kinda gets muddy. Right?

Corey HamCorey Ham

Oh, yeah.

Ralph MayRalph May

It's definitely Totally can do whatever they want. I listen. Sketch. You you But as a platform, right, you kind of like, if you put enough of these, like, weird hurdles in, people will just go to something else. Right? I don't know. Just opinion.

Corey HamCorey Ham

Yep.

Phil MillerPhil Miller

I think there's been so much, like, bad experiences with, like, Microsoft security program it was just it reached its boiling point. And finally, like, the water started boiling out of the pot with nightmare eclipse just because all the back and forth, which I don't know exactly what happened just based on his blog. Sounds like he likes he didn't get credit for like a CVE and they're like, oh, this doesn't qualify, like closing the issue. But then or this has happened to a bunch of people in the past where they have to wait ninety days that hits and then they need an extension, then Microsoft, like, silently patches the issue. And then, like

Wade WellsWade Wells

so.

Corey HamCorey Ham

Microsoft has bungled this every time in the past, and I think they've earned this karma. But also they own the platform, and so they get to do whatever they want on the platform they own. This is not the first time, by the way, that offensive tooling has been taken off of GitHub. I feel like every two years, we have the same discussion as hackers where we're like, guys, we gotta move off of GitHub. Yeah. Where are we where are we going, guys? Anyone? It sounds like that's

Phil MillerPhil Miller

not safe either. Now we gotta go to Bitbucket or get tea or whatever the other

Corey HamCorey Ham

No one no. This is like the Twitter thing. Right? Like, large company is gonna wanna take this heat. Right? It's the same thing as, like, when people have really hot takes and get fired from their big tech jobs. It's like, it's not that they don't agree with your takes. They just don't wanna pay a PR firm to compensate for you. Like, it it's really just economics. It's the same thing applies to git, you know, GitLab or GitHub or yeah.

Ralph MayRalph May

I don't I'd be but at the end of the day, zero days on GitHub is not really a problem. Right? I mean, like, you think there's probably other places that you can go get zero days besides GitHub. It's not really where I'm headed for my first zero day.

Wade WellsWade Wells

Tore's too slow. Just go to GitHub. It's easier.

Corey HamCorey Ham

I think it's a great value proposition for GitHub. Use these things used to cost a 100 k. The government's paying a 100 k for these things. Now they're free.

Ralph MayRalph May

Wow. We give you so much value with our free accounts now. So much value. Yeah. Amazing. We'll piss off another security researcher.

Corey HamCorey Ham

I will say to kind of flag it for follow-up on the show or wherever, they the date like, they say they're gonna make Microsoft pay on July 14.

Phil MillerPhil Miller

I don't know.

Ralph MayRalph May

We gotta see another Oden. Because I'll tell you right now, it doesn't matter what site it's on. If that Ode is good enough, you're gonna click. You're that that you're gonna go for that fish. You're gonna definitely check that out. And if it's real, you don't have a choice. Like, you're going to have to figure that out.

Wade WellsWade Wells

I won't have go, but my agent will.

Ralph MayRalph May

Yes. Yes. I send my agents to wade out into the dark side.

Corey HamCorey Ham

I feel like Microsoft is basically training a threat actor live.

Ralph MayRalph May

Yes. Like, they're basically,

Corey HamCorey Ham

like, trying to make them disgruntled to the point that they drop this. It's such a weird way to manage this from my perspective. Like, OpenAI is like, oh, you made OpenClaw and burned, like, $10,000,000,000 worth of tokens. We'll just hire you or whatever.

Ralph MayRalph May

Like Yeah. That's usually fine.

Corey HamCorey Ham

Yeah. Like, why is no one, like, recruiting this guy to go run Mythos on all their internal tools? Like, I don't know. Whatever.

Phil MillerPhil Miller

I like how he said they will feel it in their bones.

Corey HamCorey Ham

Or what did

Shane HartmanShane Hartman

he say?

Corey HamCorey Ham

Their bones

Wade WellsWade Wells

will feel it

Ralph MayRalph May

in their bones.

Wade WellsWade Wells

Maybe maybe maybe they'll recruit him to the Cyberforce.

Story # 6: Cyber Force? Senator pushes to create service branch under the Army

Corey HamCorey Ham

What oh oh, is that the next article, Wade? So okay. So cyber force is apparently real. I don't know. Basically, senator tier one or tier two?

One senator from New York, Kirsten Gillibrand, is spearheading a markup amendment to the senate's 2027 national defense authorization act that would create a cyber force as the next armed service branch. They would have keyboards on their arm, obviously, and, heads up displays, you know, all you need for hacking. Yeah. I mean, is this real? Like, we already have air force, navy, space force. There are so many forces.

Ralph MayRalph May

Well, almost all the commands have a cyber now or some other kind, but, you know, cyber division. I mean, it wasn't the case, you know, less than probably twenty years ago. It's army, though.

Wade WellsWade Wells

Yeah. All the commands have airplanes too, right, and boats. And Yeah. Okay.

Corey HamCorey Ham

So So

Wade WellsWade Wells

why not?

Corey HamCorey Ham

I was not in the military, but Ralph, you were in the army. Right? So or was it army? Yeah. You were army. Yep. So, okay, if you are a cyber force operator, are you mostly running around with USB sticks trying to plug them into things? Like, what it what Why does the army need a cyber force? Like, of all the different branches, like, why?

Ralph MayRalph May

Well, why does the well, the army already has a cyber command. Right? So they already have, essentially, a a cyber focused offensive arm. Right? I I think that, you know, how much they do from the offensive side, you know, gets into the to the waters where you get into the, you know, the CIA versus, you know Yeah. Yeah. Their that relationship. Right? But, I mean, essentially, they're saying, like, you know, a a act a quick action. Right?

Like, a a QRF for, like, cyber. Right? We probably already have some of that, but building out a huge command of it and, you know, to make attacks against, you know, foreign adversaries, which would essentially what any military branch is specifically designed for. Right? Not necessarily for, what do you call it, local defense. Right?

Wade WellsWade Wells

I just say we let it get created just in case there's a draft so we can all just go straight to cyber command.

Corey HamCorey Ham

Yeah. We're going straight to cyber.

Ralph MayRalph May

That's what's coming. We immediately go to cyber.

Corey HamCorey Ham

Yeah. They're like, do you not pass all the physical requirements? Welcome to Cyberforce.

Ralph MayRalph May

Well, you know what? The funny part is even with the other cyber commands, it's it's hard enough to train up these, you know, train up all of these soldier in this skill. Right? Get them to be decent at it. And then I

Corey HamCorey Ham

want 20 CVEs by the end of the day.

Ralph MayRalph May

Yes. Exactly.

Corey HamCorey Ham

Well, yeah.

Wade WellsWade Wells

I don't back in the day, they used like, if you had cyber experience, they would bring you in as a warrant officer too for a little bit. And I remember me being in cyber for a couple of years, like, should I just join and just go and, like, do it for a bit? And the thinking about it now though with the the barrier to entry so, like, so hard for new cyber people. Right? Could this be an easier route? It'll be an easier route for most people, which is sad, but scary.

Corey HamCorey Ham

Yeah. It's a good point.

Ralph MayRalph May

I don't know. The cyber so the cyber command includes US Army Cyber Command, the US Marine Corps Cyber Command, US Fleet, so this is navy, and then air force has their cyber it all falls under the national cyber United States Cyber Command.

Wade WellsWade Wells

So there already is a cyber force.

Corey HamCorey Ham

They just There's already three of them. Yeah. They're just not an army one.

Ralph MayRalph May

Yeah. No. No. No. There is an army one. So US army cyber command. Right? But I what I think they're trying to make this is, like, like, some, like, warrior with, like, overhead displays or something like tier one type deal. I I don't know what that looks like.

Corey HamCorey Ham

Dude heads up displays and keyboards on their arms.

Ralph MayRalph May

Yeah. I'm just trying to envision the no. Like, the the quick tactical team that, like, rappels into the data center to do some I don't know, dude. I don't know. Yeah.

Corey HamCorey Ham

No. I think you're right. No. I I I agree. I mean, someone in some people in Discord have been speculating, oh, these are just drone pilots. Okay. That's fair. Like, that makes sense.

Ralph MayRalph May

We don't even need that. We have AI for that. They just slide.

Corey HamCorey Ham

We have OpenAI, though. Yeah.

Ralph MayRalph May

You're out of credits, Crash.

Corey HamCorey Ham

I think it I think it's fair to assume this will probably get approved just with the and, I mean, I don't know.

Ralph MayRalph May

But Yeah. Honestly, half of everything that you said, Corey, they're writing it down right now.

Corey HamCorey Ham

So They're like, wait. USB sticks? How many how many can we get into a plate carrier? A lot. Exactly. USB sticks and

Wade WellsWade Wells

Working in a sock was really fun. I'm not gonna lie. Like, at the time, the pew pew charts, right, the big monitors, there's a wall with a glass, and the CEO presses the button, and then it becomes opaque, and all the investors look at you like you're a monkey. And, like, it was great, but more people should go work in socks. That's all I'm saying.

Corey HamCorey Ham

I don't know if it's defensive or offensive, but I'm The best offense is defense.

Wade WellsWade Wells

Best offense defense. Right? Like, all of our stuff's getting hacked. There's no there we already have the offensive side. Maybe we need a cyber defense core.

Corey HamCorey Ham

Wouldn't that be National Aker? Anyway.

Ralph MayRalph May

National Cyberguard.

Corey HamCorey Ham

Let's let's move on. Yeah. Please. There's a couple of interesting little tidbits on AI that I think we should talk to. First of all, in the Opus four eight release, they did specifically say that they are preparing Mythos to be publicly released week in the coming weeks.

Story # 7: Are you ready? Anthropic preparing to release Mythos publicly

That was the exact terminology that they Coming weeks. The coming weeks.

Ralph MayRalph May

Will be

Corey HamCorey Ham

Obviously, there will be, you know, thousands of weeks coming. Who knows if it's gonna be the next one or, you know, it could be a thousand weeks from now. It's still technically coming. But I don't I mean, I will say their cadence, their release cadence is pretty fast.

Ralph MayRalph May

And so Well, so is strat TBT. It's a war out there, man. No. I got 5.5. No. I got 4.9.

Corey HamCorey Ham

Oh, I got extra ultra code.

Ralph MayRalph May

Yeah. I know. I know. And we're

Corey HamCorey Ham

like know.

Ralph MayRalph May

Let's see what happens.

Corey HamCorey Ham

So, basically, that might be happening. But,

Ralph MayRalph May

also think that's the end of of cyber? We're we're all done? Just vulnerabilities left and right? I mean Yeah. Maybe maybe Wade is right. Maybe Wade

Wade WellsWade Wells

the the red team. I don't know what to tell you guys, but it's not I still got it. I'm a tell you what I gotta do. Haven't seen any cyber do an incident response really that well yet. Or

Corey HamCorey Ham

threat hunting?

Wade WellsWade Wells

No. Well, I don't know. We'll see what David says after this talk.

Ralph MayRalph May

But

Corey HamCorey Ham

yeah. I mean, are you guys, as threat hunters, interested in this tooling, or is it really, like, hype for the CVEs and the threat? You know? For, like, AI tooling?

Shane HartmanShane Hartman

What what was the question?

Corey HamCorey Ham

Do you care about Mythos? Are you gonna use it as a threat hunter, or do you already use LLMs, like, in your workflows? Like, obviously, everyone's like, Mythos is gonna make it amazing to hack stuff. Is anyone saying it's gonna make it amazing to hunt for threats?

Shane HartmanShane Hartman

No. I mean, we we do use LLMs, but I don't think so.

Wade WellsWade Wells

Not yet. We are. We're gonna coin it right now.

David BiancoDavid Bianco

But you said the the the magic word earlier, it's the tooling. You just a minute ago. Right? It's not really the model. It's our models the frontier models are already so good. It's what tooling you wrap around it that is really the differentiator. I have not had hands on mythos. I've talked to people who have, and they say, yep. It's some of them say, yeah. It's it's really what they say it is.

And some of them say, I don't know. So I don't really know what to say about Mythos, but I was gonna say on on the defensive side, I'm not clear that we need that Mythos is gonna move anything further for the defense. I would be really happy to see some some frontier model provider provide that kind of emphasis on defensive security as they seem to on offensive security. It reads to me like they feel like creating vulnerabilities and exploit chains is cybersecurity or information security when it's not really. It's just a piece of it.

And the hard part is the defense. And when they start coming out with, you know, models and tooling that are frontier and they're targeted toward defense, then I'll get really excited.

Corey HamCorey Ham

I fully agree. I'm interested to see if any frontier company actually makes a play at defensive the defensive side of AI.

Wade WellsWade Wells

But, like, the defensive tooling is gonna be heavy reliant on the organization as well. Right? Manipulating the tool to make it fit your company just like any type of detection would, having all your documentation. Right? I almost find it harder not as a blue teamer to get not even to get buy in, to get GRC.

Right? Like, that's some of the stuff if we're plugging all these AI toolings in. I hate to say it, but it's like, then you have to think about permissions, what these AIs are doing. Right? Are they over permission? If someone uses an OAuth token to then log in to this and you're a security person who has super admin to something. Boom. Now this AI has super admin. So there's a bunch of controls around it, but I think the defensive will come, I I believe. It's right around the corner.

Someone I I would like the why hasn't anyone just the one that tried mythos and just, like, try to do everything defensively with it. Right? If it's doing all that

Corey HamCorey Ham

opposite they have. That's what people are talking in Discord about EmDash. I thought it was someone making it I thought it was Luke making a joke that he was gonna start using EmDashes, which is, like, for those that are out of the loop, the Em dash is like the the double dash that the AI loves to do when it says anything. So I thought he was just joking that, like, he was gonna start doing it to pretend like he's an AI. Turns out it's actually, a real thing that Microsoft has released, that's supposed to be defensive focused.

Story # 8: Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark

This is back from May 12, so pretty old now. But I'm guessing this is, like, their harness or tooling or whatever they built. It's multimodal. It's supposed to be, according to their graph, better than mythos.

Ralph MayRalph May

Everything's better than mythos. Yeah.

Corey HamCorey Ham

So but check this out. 21 out of 21 planted vulnerabilities were found. You know? It's like That's not

Ralph MayRalph May

I don't What what about on the Gainter chart or Ganter or whatever the hell?

Corey HamCorey Ham

Well, if you look at the chart, it says they're better than you. So

Ralph MayRalph May

Yeah. Just just checking it. Just gonna go ahead and cash this one out. I'm done. I'm all

Corey HamCorey Ham

Yep. Microsoft has solved security. Think you can just buy it. Just just figure it out.

Phil MillerPhil Miller

Having a harness is very important though. Like a lot of people are posting different ones in the chat. And there's a lot to choose from. But something is better than nothing. Then it's funny too. Like at what point does the collection of like plugins and skills and hooks and memories and learning become a harness? Like how many do you have to have before you can call it a harness?

Corey HamCorey Ham

Like I

Phil MillerPhil Miller

have one skill. Is that a harness? No. You have to have a skill and a hook and a plugin and a memory or whatever. Right? But there are some cool ones that will at least, like, automate, like, continuous learning for you so that

Corey HamCorey Ham

Yeah. Like Hermes or those. Yeah.

Ralph MayRalph May

I I think it's kinda funny. I was talking to another pen testing team, and they said they had all these zero days now that they've, you know, taken the time to find in all these different products or whatever. And this goes back to what you guys talking about with defense. And they're not gonna fix these things right away because they don't have anything in place to to so, essentially, it's all fun in games to go find these zero days, but no one is from these organizations that's creating the software or whatever. They don't have systems in place that are looking for it the same way.

Right? Because it's it wasn't as, like, shiny. They're just trying to run their business and make some software, make whatever. And I think we're gonna see a big wave of a bunch of vulnerabilities and a bunch of companies trying to figure out how to defend themselves or update their software or develop software in a more sustainable way using AI to actually be able to detect this. So I do think we're gonna see a big wave of it, and the defense is really where you're gonna see a lot of people struggle.

Corey HamCorey Ham

So transition. Next article. Oh, sorry. Unless anyone had a final go back. I was gonna say, if you wanna see how AI is being used today, without mythos, so there's a really fun article about how attackers there's a fun write up about how attackers are using, AI for post x.

Story # 9: Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

And this is pretty much reads like a pen test report to me because we're doing the exact same thing. We're just not doing it in Chinese. From the language. Basically, the the long story short is that someone used an LM for post x. Now this is, like you said, exactly what we're doing as pen testers.

But essentially, they exploited the CVE, then they, asked AI, what else can it access, basically? And they were just like, hey. What else can this, key access? But they did that in Chinese, and somehow that, that question of what it could access made it through to the API, which is pretty funny. It leaked into the command stream while executing a credential search.

And that's pretty much why you don't need mythos. It's basically like an explanation of why. Because this kind of abuse of LLMs is the more risky thing. Right? This kind of like very simple just being AI take this AWS key that I just compromised and do evil things with it.

This is what we're seeing in the real world. If you look at breaches, there has yet to be a breach from mythos zero day or whatever. But there has been many breaches like this where a typical CVE is exploited, an agent or an LLM is used as post exploitation or quick transition to the next article, which is about a chatbot that just gives access to accounts if you ask for it. So this is like the other side of AI exploitation, which is sometimes you don't need an exploit at all. You can just ask the AI for access to the account.

Story # 10: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

So this is a meta thing. Basically, meta AI was super helpful and decided to just grant some people access to some high profile Instagram accounts, including the account for the White House or, I guess, the Barack Obama White House, the chief master sergeant of Space Force. It's a feature

Ralph MayRalph May

that that they built it like this.

Corey HamCorey Ham

It's super I mean, I will say you need a really advanced model to get to have it compromising accounts. Okay? To me, this is a textbook. I mean, there's screenshots that are just insane. This is a textbook case of, like, AI failure. Right? Like, why do give

Ralph MayRalph May

your AI the access to all those accounts? I don't Exactly.

Corey HamCorey Ham

Exactly. Great question. It's almost like if you had a red team that wasn't replaced by AI, they would have caught this.

Ralph MayRalph May

Oh, they just didn't ask the right prompt. That was the problem. Let's try that.

Corey HamCorey Ham

I feel like okay. So I know Meta has a huge red team, and I know some people that even work there. And so my question is, number one, did you get replaced by AI, and are you looking for a job? If so, let me know. Number two, are are we to the point where AI is moving so fast that things aren't being properly tested before they're being published, including, like Oh, yeah. This sort of high risk applications? Like, is that where we're at?

Wade WellsWade Wells

We were there before Yeah.

Shane HartmanShane Hartman

We were before AI.

Ralph MayRalph May

For sure. I mean,

David BiancoDavid Bianco

Wade, just like a couple minutes ago, you said, like, GRC was getting in the way. Like, no. I don't I don't see that in a lot of places. Like, in most organizations' problems with AI are that they're adopting it too fast in ways that they didn't actually know that they were adopting it. And so it's it's kind of like this the shadow AI and

Corey HamCorey Ham

Shadow AI. Oh,

Wade WellsWade Wells

I love it. Key the term. Someone make me

Corey HamCorey Ham

a sticker. God.

Ralph MayRalph May

What is it? Like a what do they call it? Like a dark AI factory? Yeah. Look that.

Wade WellsWade Wells

I don't wanna look

Corey HamCorey Ham

that up.

Wade WellsWade Wells

That sounds like a mad dark web term.

Corey HamCorey Ham

I was gonna say that's your personal search history there. I don't think I

Ralph MayRalph May

heard say what you want, but ask your AI about it. He'll tell you.

Corey HamCorey Ham

Really? You think? Yeah. Yeah. I don't know.

Wade WellsWade Wells

So this is not doing AI correctly. Right? Like like we said, is this you this is what happens when you bypass GRC. Like, is is this?

Corey HamCorey Ham

Yeah. Yeah. I mean, I dunno. It's kinda crazy that I will say though, this is the classic thing of scale. When you're operating at these huge Internet scale companies like Meta, you can't hire support people to actually support your accounts.

Or at least they think they can't. And so they use AI, and that's gonna cause risks. Although, it is a business logic flaw, arguably. Maybe it's an LLM flaw, but it feels more like a business logic flaw to me Yeah. Of it basically not knowing where the credentials it's handing out came from. It doesn't properly tie together the request and the response.

David BiancoDavid Bianco

I could just see, like, you're you're talking about where's the red team. I could just see, like, a bunch of AI red team experts getting together and being like, nah, surely it's not that simple. We gotta try some more advanced attacks.

Corey HamCorey Ham

Yeah. I mean, I will say I have personally observed this in our agentic AI testing. Some of the things that are really tough to convince AI are vulnerabilities. Like one web app we were testing, I think I've told this story before, so I'm sorry, but one web app we were testing, it was basically iDoor, so indirect object reference. And essentially it was giving a three zero two response, but it was giving the entire content of the page that was supposed to be restricted in the response.

And AI kept being like, No, this isn't a vulnerability. It gave a three zero two response, and we're like, Yeah, but look at the three zero two response. It has the whole webpage, and it's like, I don't know what you're talking about. It's a three zero two response. I have to redirect.

It's like that back and forth. I could see a red team, like an AI red team missing a business logic flaw. Well, they asked for the account and it sent the number, so I don't see what the problem is. Well, but AI, it's a different account that they reset. Like, they were resetting someone else's account. Oh, you're absolutely right.

Wade WellsWade Wells

Let's let's talk about the real problem is why are they using a phone with a cracked screen? Like, come on. At least get two phones with two screens. Like, I can't that is just driving me crazy.

Corey HamCorey Ham

I think this is just what threat actors do, man. They do they they that's just their background. That's just their chat background for for meta. That that's not even a broken screen.

Wade WellsWade Wells

That dot that you don't see the huge crack right there on the right hand image?

Corey HamCorey Ham

I know. I'm just saying that's they they have a cracked screen image as their background.

Wade WellsWade Wells

Yeah. That would have

Ralph MayRalph May

all my phones. That's why no one steals them.

Wade WellsWade Wells

That's actually a really good idea.

David BiancoDavid Bianco

Misinformation. That on any app that you have.

Ralph MayRalph May

Yes. Perfect. Yeah. Yeah. This is never gonna happen again, so we don't have to worry about this. Let's move on.

Story # 11: Kali365 phishing kit bypasses MFA and steals Microsoft logins

Corey HamCorey Ham

There's an article about the Cali three sixty five.

Ralph MayRalph May

Oh my god, dude. They stole my playbook.

Corey HamCorey Ham

It's literally just like pen tester one zero one. Like, if you were to take Michael Allen's initial access class, it would just cover this. It's using device code phishing, which don't get me wrong. It's a good one, but also, like, come on. Initial access policy is

Ralph MayRalph May

It's better because it's a SaaS product. Okay?

Corey HamCorey Ham

It's p p a phishing SaaS. What? PaaS. I don't know.

Ralph MayRalph May

Everyone loves a monthly subscription.

Corey HamCorey Ham

Fast? I don't know how to pronounce that. Fishing as a service platform that I like how the news article is kind of a dig where it says, it helps even low skilled attackers hijack.

Ralph MayRalph May

You could be an attacker too.

Corey HamCorey Ham

They're just directly calling the attackers who bought this low skilled. That's pretty funny. Yeah. Device code phishing, mean, come on. Who allows device codes these days? Who doesn't have secure conditional access policies that don't allow access from unmanaged devices? Like, come on. No one no one screws that up anymore.

Shane HartmanShane Hartman

No. Not true.

Corey HamCorey Ham

The threat hunters in the room are like, nope. You're wrong.

Ralph MayRalph May

No. Listen. If there's an article about it, it's still effective.

Shane HartmanShane Hartman

Yeah. We I've done about three cases of it in the last, like, month and a half.

Corey HamCorey Ham

Well, I do need email on my phone, we better just compromise the entire organization so I can have that.

Wade WellsWade Wells

That is exactly what happens

Ralph MayRalph May

to a test.

Wade WellsWade Wells

One person says that. And

Corey HamCorey Ham

Yeah. Basically, if you're a pen tester or a red teamer, you should know how to do this exact campaign just by reading this news article. This is a this is a first thing to learn in initial access techniques. It's great. All right. And don't buy this product. Don't do it. Probably about botnets. Speaking of botnets, let's talk about botnets. So the authorities in The Netherlands, which I love, I just imagine people on little boats and they're going to fancy restaurants.

Story # 12: Botnet of more than 17 million devices dismantled

You know, I just imagine Amsterdam. They have dismantled a botnet that comprise more than 17,000,000 devices, which is used basically for residential proxying or residential, you know the service is called Asox, which is a Russian based company, provides residential proxying services.

Ralph MayRalph May

Cater Oh, to they pay me every month. They have that little thing that you run on your computer.

Corey HamCorey Ham

They have that laptop they shipped you and put in your garage.

Ralph MayRalph May

Yeah, they said it was for research.

Corey HamCorey Ham

Yeah. So I guess I mean, these are, you know, often used for illicit or unethical purposes, DDoS attacks, botnet command and control servers, phishing operations, scraping. My question is how bad do you have to get to get dismantled by the Netherlands police? Like, how much DDoS was this IP space launching? It had to be a lot.

Wade WellsWade Wells

Because that's Yeah. Crazy. How much is this?

Corey HamCorey Ham

What do you mean how much?

Wade WellsWade Wells

How much ASOS is? It won't even start

Corey HamCorey Ham

Oh, you're saying, like, you wanna buy the product? It won't even it won't even Get out of here. A Sox. You're you're a because you you're from Florida and you don't wear socks.

Ralph MayRalph May

Oh my god. They're they have a g two review for A Sox. Oh, and then they

Corey HamCorey Ham

actually oh, they got kicked off. I will say this whole, like, socks, you know, the, like, residential proxying thing is kind of a dark horse because we use this service, not ASOX specifically, but we use residential proxying. They're all kind of mildly unethical. Like, I don't know. I I you know, you kinda have to have a service like this, but none of them are particularly above board.

This one seems to be kind of the worst, but I don't know. It's Russia, yo. It's good. That's true. I've it's it's legitimate, or it's it's realistic. It's what threat actors are using. That's why we use it.

Ralph MayRalph May

Yes. Exactly. We pay threat actors to use their service to pretend to be threat actors to protect threat actors.

Corey HamCorey Ham

It's a it's a loop. It's a loop. That's really seems like it. Alright. So any final articles? Shane or David, do you guys have any articles you wanna plug? We don't have any chicken news this week. I'm sorry, everyone.

David BiancoDavid Bianco

Just told specifically there'd be chicken sacked.

Story # 13: United flight returns midair after Bluetooth device name reportedly sparks security scare

Shane HartmanShane Hartman

I did post one in our chat that was real quick. It was one that was, there was a flight to, I think, The Maldives where a kid decided to rename his Bluetooth device to bomb, and it freaked out the it broadcast to everybody on the on the plane. They tried to get him to turn it off or tried to get they didn't know who it was, so they kept they told everybody on the plane to turn off their Bluetooth and he never did. So they had to turn around and go back to Newark, I think, because his phone said bomb on it as a met as as his Bluetooth name.

Ralph MayRalph May

It was interesting article found out who did it. Yeah.

Shane HartmanShane Hartman

I think there were only a couple devices left, so they found them. Yeah. Bars I know. But kind of a crazy story.

Ralph MayRalph May

What do imagine

Corey HamCorey Ham

doubling down? How old is this kid? I wanna know. Because this is some dumb like, this is like Yeah. 12 year old level dumb.

Ralph MayRalph May

Yeah. Like, the air part is

David BiancoDavid Bianco

and it's like, what is the air crew thinking? It's like, oh, you have a bomb on the plane, but if you turn the Bluetooth off, please, so we just don't notice.

Corey HamCorey Ham

It's gonna go what I got. Like, come on.

Wade WellsWade Wells

Like, it's it's literally just a Bluetooth.

Corey HamCorey Ham

It's seriously just one of those things where everyone is just rolling their eyes and being like, guys, can we please have nice things? And some kid just like, no. We can't have nice things. And I will be on the no fly list for the rest of my life because of how dumb I am.

Ralph MayRalph May

I know. That's the wild part. Like, you know, we just talked about how GitHub can kick you off their platform for any reason for whatever. Right? So can airlines. They can blame you for life. On all the airlines, they do they're you are not guaranteed a flight.

Corey HamCorey Ham

No. There's no constitutional rights here. Nope. But can't imagine doing this.

Ralph MayRalph May

Imagine living your life and never being able to take a plane ride again.

Corey HamCorey Ham

But then also doubling down again and again. Right? Like, you know, they had, 10 chances to, like, you could just turn off your Bluetooth. No. I'm not gonna do that. Somehow, I won't get caught. And then, like, of course, when they land the plane, everyone's going into quarantine. Like, you're not just gonna, like, okay. Debord, everyone, just throw your phones out the window. It's fine. Like, they're gonna make everyone you know, they're gonna figure it out.

Ralph MayRalph May

Sometimes when this kid gets older, he's like, hey. Why can't you go on this trip? I'm kinda infamous for this thing a long time ago. I can't

Corey HamCorey Ham

You were zero cool? You were zero cool. No. Were the He was the default Bluetooth kid?

Ralph MayRalph May

Yikes. I did have one last one, and this one's really short. Not not a surprise, but it seems like a lot of ISPs are getting breached. Charter got breached by shiny hunters. Oh.

Story # 14: Inside the Charter data breach: hackers leak 13M+ customer data

Which is Charter for both

Corey HamCorey Ham

terrible security. All ISPs do from what I've experienced in my life.

Ralph MayRalph May

Charter's one of the bigger ones in The United States. They own Cox. They own a bunch of other ones. So, yeah, it affected a lot of people. Spectrum, I think, is another

Corey HamCorey Ham

Oh, yeah. They get breached every two years. I've been my data has been breached in Spectrum, like, five times. I'm not even joking.

Ralph MayRalph May

Yeah. Got so so

Wade WellsWade Wells

much life lock. You won't believe.

Corey HamCorey Ham

Oh my so many cool identity monitoring subscriptions at this point. It's fantastic.

Ralph MayRalph May

You can stack them and get zero extra.

Corey HamCorey Ham

Yeah. Yeah. So okay. I do think we should plug David's tool. So, David, tell us about your tool.

Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake

Yeah. It's a It's little personal. To generate yeah. So it's to generate, threat threat it's to generate threat hunting data? That's what I understand.

David BiancoDavid Bianco

It's called EvidenceSporage, and, it's it's a tool that we I released, what, I guess, last last week or maybe the end of the week before. And it's targeted toward there's it's targeted toward creating realistic sets of logs for simulated environments that don't exist. Like, think of you need to create some logs for a, to demonstrate how a piece of offensive technique works in a real environment. So, you spin up a cloud service and you do Terraform to create all your sensors and all your Microsoft networks or your Windows or your Linux systems. And then you run the actual exploits through and you get all the data through and, you know, you spend a lot of time, a lot of a lot of money and possibly requires for people, for you guys, probably not as it's probably well within your expertise, but for a lot of people, it's not.

The idea with Evidence Sports is you get the similar output, but you don't actually have to have a real network. You don't have real threat actors or real red teamers. You create a scenario in which it is all simulated and you get a set of up to 20 different types of logs that look like they all are came from that simulated environment. They're all realistic. They all hang together.

So if you see, like one of the inputs is Zeke. So if you see a Zeke log for an HTTP transaction and then you go into the proxy log, you'll see the same proxy log has the same transaction in it that the Zeke log has. And if you see that that came from your computer, you should find the computer that it came from, and there's probably a process log from Windows Sysmon that showed that you ran the web browser that generated that. Right?

Corey HamCorey Ham

That's really cool.

David BiancoDavid Bianco

It it it's really neat. It it's interesting because it has an AI assistant to help you create the scenario, define the environment and the attack that you wanna run and everything. But once you do that, generating up to, you know, gigabytes of potentially of data is all done by a a script. No AI involved. So it was actually partly because I was trying to experiment with efficient ways of using AI, targeting AI where you actually need the AI rather than, you know, just have the AI do it all.

Corey HamCorey Ham

Well, also, it's nice when the script is deterministic and creates the same output every time. Yeah. Yeah. I hallucinated a bunch of events in Windows and you're gonna go hunt for these.

Ralph MayRalph May

Yeah. And it has to

David BiancoDavid Bianco

be my randomness, but it's yeah. But it's seeded random and the seeds are in the config files. So it's it basically makes a YAML file for the scenario, and you can regenerate the same data from the YAML file however many times you want. Chain trade them with your friends like Pokemon cards, you know, all kinds of stuff.

Ralph MayRalph May

You know?

Corey HamCorey Ham

I love it. I I will say I have personally had clients ask me for this to do this, and I've actually spent time running fake pen tests in their, like, test environments to generate the sort of data. And so now I would just be like, oh, there's a script for this. Here you go.

David BiancoDavid Bianco

Well, I'm sorry to tell you. I actually created this because I didn't wanna pay for the equivalent of having a red team squeeze my data.

Corey HamCorey Ham

I wouldn't either. So out of curiosity, does it make pcaps, or is it just event logs?

David BiancoDavid Bianco

It's it doesn't make pcaps. That's a good idea but far more involved. But it does, it does Windows, system logs, some several of the types of events but not every single type of event. But it does like processes starts and Kerberos things and authentications and things. It also does a bunch of different Sysmon, event types.

Does Linux syslogs, Cisco firewalls, Zeke and Snort and, it has a it has an EDR that it's not a specific brand of EDR. It's just a, generic EDR capability because I didn't have the right documentation to create real looking EDR for a specific product. So all kinds of stuff. That's awesome.

Corey HamCorey Ham

My only other feature request is you gotta make it like export straight from backdoors and breaches. So like play you play a game backdoors and breaches, and then you just have the threat hunt to go along with it. That'd be pretty awesome.

David BiancoDavid Bianco

Look, I'm a big fan of backdoors and breaches. I will I would totally love to do that. I I bet I could do it right now. I actually if Yeah. You know, if I had a a backdoors and breaches scenario, I could probably just tell the AI and be like, hey, here's here's my scenario. Go build me a a dataset for this. They probably can Alright. Do

Threat Hunter Summit | June 17th 2026

Corey HamCorey Ham

So final plugs, David is keynoting our threat hunting summit. I forget when it is, but Ryan knows because he's smart. And the date on the threat hunting summit is seventeenth. Seventeenth at 10AM early for those Pacific Time people. Get your coffee and get to David's talk. We also have, Shane's training that he's doing on, starting a threat hunt. Right? Yep.

Shane HartmanShane Hartman

Threat hunting in the dark.

Corey HamCorey Ham

It's sunny the same day.

Shane HartmanShane Hartman

Mine is, I think, at 01:30, I think, on that day, eastern time.

Corey HamCorey Ham

And you do you have to have blackout curtains and make it dark in your office, or can you just do it in daylight as well?

Shane HartmanShane Hartman

I think I can do it daylight as well.

Corey HamCorey Ham

Alright. Okay. Cool. And then Phil, you have a webcast this week. Right?

Anti-Cast : How Hackers Attack CI/CD Pipelines w/ Phil Miller

Yeah. Days from now.

Phil MillerPhil Miller

This this Wednesday actually, and I'm kind of in between a rock and a hard place because there's a tool I was gonna drop that goes along with the course, but I'm Spicy. Kinda yeah. It's a little too spicy. It's, like, too dangerous. Like, I don't know if I should release it because you could do, like, a lot of bad things with

Corey HamCorey Ham

the You should release it.

Wade WellsWade Wells

Release it.

Corey HamCorey Ham

Release it. Release Okay. Nipples. You have my official approval to release it.

Phil MillerPhil Miller

Alright. Yeah. I will. I was just like, oh, nightmare clips. I don't wanna get nightmare clips.

Corey HamCorey Ham

Yeah. You do. Yeah. Well, you do because you actually have a job unlike them, anyway. Alright.

Cyber Threat Intelligence 101 2-Day Version

What else we got? Anyone else have anything to plug? Wade, you have something to plug?

Ralph MayRalph May

I see you.

Wade WellsWade Wells

I I am teaching on the twenty second, my threat and tell one zero one two day course. That'll that'll be fun. I just made it two days from one day. So I'm still working on the slides.

Corey HamCorey Ham

Nice. Good to hear. Ralph, what are you plugging?

Ralph's Practical Physical Exploitation Training & Tool Bundle

Ralph MayRalph May

Oh, yeah. I didn't really have anything to plug, but

Corey HamCorey Ham

we do got another physical class coming up. So if

Ralph MayRalph May

you wanna figure out how to actually go into a building and plug in USB drives because that is something

Shane HartmanShane Hartman

If you wanna prepare

Corey HamCorey Ham

nation state level. Cyber force.

Ralph MayRalph May

If you wanna get to nation state level physical exploitation. Yeah. We got class. Awesome.

Corey HamCorey Ham

When is that, Ralph?

Ralph MayRalph May

Shoot. I have to look at the calendar here. I I don't remember the date now. Swear to god.

Corey HamCorey Ham

What is it? Practicalphysicalexploitation.gov?

Ralph MayRalph May

Yes. It is. That's physicalexploit.com.

Corey HamCorey Ham

Physicalexploit.com.

David BiancoDavid Bianco

If we take your class and we graduate, do we automatically get a job with the silent ransomware group, or do we have to apply?

Ralph MayRalph May

No. You still have to apply, but I do know a guy so I

Corey HamCorey Ham

can get you, like and there's

Wade WellsWade Wells

there's an affiliate email you you email the certification that Ralph gives you, and then they'll contact you shortly with just you to

Corey HamCorey Ham

speak with us.

Ralph MayRalph May

We we actually just had a class last week, and we had 10 students in it. It was a lot of fun. So a lot of

Wade WellsWade Wells

All Russian.

Corey HamCorey Ham

All Russian. 10 students not a word of English

Ralph MayRalph May

was spoken. It's not important what their primary language is. It's important the skills that they learned, which were the best.

Corey HamCorey Ham

Awesome. Alright, y'all. Thank you for coming. I really appreciate it, especially David, Shane, Phil. Thank you. We'll talk to you later.

Ralph MayRalph May

Bye, everyone. Alright. Later, guys.

Transcript source: Provided by creator in RSS feed: download file
For the best experience, listen in Metacast app for iOS or Android