BreachForums Doomsday - 2026-01-12 - podcast episode cover

BreachForums Doomsday - 2026-01-12

Jan 14, 20261 hr 1 minSeason 6Ep. 2
--:--
--:--
Download Metacast podcast app
Listen to this episode in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episode description

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat

🔗 Register for FREE webcasts, summits, and workshops -
https://poweredbybhis.com


In this episode, we break down the “Doomsday” incident: a major breach forum gets breached, reminding everyone that even cybercriminal communities suffer constant OPSEC failures. We cover what leaked, why these underground markets keep imploding, and how infighting, reused infrastructure, weak authentication, and sloppy identity hygiene turn “elite hackers” into easy targets. Then we connect the dots to law enforcement’s latest crypto actions—how DOJ seizures and mixer investigations work, why blockchain tracing matters, and what criminals try (and fail) to do to hide money flows. Finally, we translate the news into practical defense: validate breach intel, monitor for credential stuffing, enable MFA, use unique passwords, and tighten access logs. Whether you’re a defender, creator, or online, this is the real-world cybercrime story behind the headlines.


Chapters

  • (00:00) - PreShow Banter™ — Task Overflow
  • (02:29) - BreachForums Doomsday - 2026-01-12
  • (05:09) - Story # 1; Did DOJ Prosecutors Violate Trump’s Executive Order by Selling the Forfeited Samourai Wallet Bitcoin?
  • (15:42) - Story # 2: Cloudflare defies Italy’s Piracy Shield, won’t block websites on 1.1.1.1 DNS
  • (23:04) - Story # 3: California bans data broker reselling health data of millions
  • (28:13) - Story # 4: Apple picks Google’s Gemini to run AI-powered Siri coming this year
  • (36:00) - Story # 5: Ragebait as a phishing tactic
  • (38:00) - Story # 6: Doomsday For Cybercriminals — Data Breach Of Major Dark Web Forum
  • (40:31) - Story # 7: The Great VM Escape: ESXi Exploitation in the Wild
  • (45:39) - Story # 8: OpenAI says ChatGPT won't use your health information to train its models
  • (46:23) - Story # 8b: Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools
  • (50:15) - Story # 9: Max severity Ni8mare flaw lets hackers hijack n8n servers
  • (53:05) - Story # 10: Instagram Denies Data Breach, Fixes Unsolicited Password Reset Requests
  • (56:49) - Reporter remembers saving animals a year after L.A. wildfires
  • (57:52) - CTF Winners

Links
Story # 1; Did DOJ Prosecutors Violate Trump’s Executive Order by Selling the Forfeited Samourai Wallet Bitcoin?
Story # 2: Cloudflare defies Italy’s Piracy Shield, won’t block websites on 1.1.1.1 DNS
Story # 3: California bans data broker reselling health data of millions
Story # 4: Apple picks Google’s Gemini to run AI-powered Siri coming this year
Story # 5: Ragebait as a phishing tactic
Story # 6: Doomsday For Cybercriminals — Data Breach Of Major Dark Web Forum
Story # 7: The Great VM Escape: ESXi Exploitation in the Wild
Story # 8: OpenAI says ChatGPT won’t use your health information to train its models
Story # 8b: Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools
Story # 9: Max severity Ni8mare flaw lets hackers hijack n8n servers
Story # 10: Instagram Denies Data Breach, Fixes Unsolicited Password Reset Requests
Reporter remembers saving animals a year after L.A. wildfires


Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest - Join us for our Hybrid Conference and Pre-Conference Training
https://wildwesthackinfest.com

Transcript

PreShow Banter™ — Task Overflow

Bronwen AkerBronwen Aker

Yeah. No. I was reading over the weekend about the whole Stack Overflow business, and absolutely, their interactions have tanked since OpenAI was released. But they they sold out. They've sold their content. So they've got almost nothing in the way of interactions Yeah. But they're making bank because

Ralph MayRalph May

For now. But I mean like, they're not going to continue to make that money forever, you know what I'm saying? Yeah. Like, eventually they need more You need like more questions being answered. And if they're not, then, you know, with this kind of thing, the house cards kinda crumbles. Right?

Corey HamCorey Ham

I don't see any I don't see any sources for Stack Overflow being sold to OpenAI.

Bronwen AkerBronwen Aker

No. It wasn't They license their content. I'll it was either was either 04/2004 or it was MIT tech review. I'll have to to look

Corey HamCorey Ham

We have a partnership.

Bronwen AkerBronwen Aker

But they're getting paid in the partnership. That's the point.

Corey HamCorey Ham

They're making more Yes, Zach.

Bronwen AkerBronwen Aker

You can partner without getting paid. Trust me.

Wade WellsWade Wells

I've done that a lot.

Ralph MayRalph May

Yeah. Did you get married?

Corey HamCorey Ham

Oh, man, dude.

Wade WellsWade Wells

You said it, not me.

Corey HamCorey Ham

If you're getting married and you're not getting paid, you're doing it wrong.

Ralph MayRalph May

See? That's how you 10 x.

Corey HamCorey Ham

Don't forget to call in to the BHIS podcast. That just I could just read Ralph's personal cell phone number on the air.

Wade WellsWade Wells

You could just leak John's number again like he did the other time. Honestly, I thought it was a slow news week. I didn't see anything in the articles really,

Bronwen AkerBronwen Aker

like, grappling.

Corey HamCorey Ham

Yeah. Didn't even get to scroll through the first freaking page of articles.

Wade WellsWade Wells

I went all the way down it. There's some cool AI stuff as

Corey HamCorey Ham

cybersecurity. There's a lot of, like, geopolitics, policies.

Wade WellsWade Wells

Some cool privacy stuff. Right? But some scary privacy stuff further down

Corey HamCorey Ham

cool is an interesting term you got there.

Wade WellsWade Wells

The California privacy stuff is pretty cool, I think.

Corey HamCorey Ham

Yeah. It is. It is. But that's like whack a mole. Right?

Wade WellsWade Wells

Yeah. But at least someone's whacking the malls. Right?

Bronwen AkerBronwen Aker

For sure. Privacy is whack a mole.

Corey HamCorey Ham

Take one we'll take one dead mole over zero, I guess.

Aisling

Right. Exactly.

Wade WellsWade Wells

Nothing else? Nobody else had anything cool stuff?

Corey HamCorey Ham

No. The the show's over.

Wade WellsWade Wells

I was like There's no chicken minutes, you guys can leave.

Corey HamCorey Ham

I like the class like that too. Welcome to Black Hills Information Security talking about news. It's 01/12/2026. We have all kinds of articles, lots of geopolitics, lots of cryptocurrency, money laundering, Discord IPO. I can finally cash in on my 3 prime tokens or whatever I have on Discord on the stock market.

BreachForums Doomsday - 2026-01-12

We've got articles and we've also got hosts. We have Ralph who's who's here. We've got and he's he's branded himself a gator catcher, which I feel like it's more about chasing them than catching them. I feel like you don't really wanna catch.

Ralph MayRalph May

You gotta catch them and then you gotta go release them into another lake and then it's like a circle of life thing, right, where they call you back.

Corey HamCorey Ham

Okay. I see. I I see. We've got Brahma

Cameron Carter

How many times have you done this?

Corey HamCorey Ham

Yes. Please explain. Please explain. How much

Cameron Carter

what's the most money you've made off of one gator?

Ralph MayRalph May

I mean, it's it's pretty good. It's really easy too, by the way. All you do is play baby gator noises and they will come to you.

Corey HamCorey Ham

Ah, okay. That's a tip. That's a hot tip. Mhmm. We've got Pentester aka Cameron who's painting her fireplace during the podcast, which so far is the most productive anything anyone's done on the podcast. We have Wade, and then we also have Dave. Dave is Dave and Cameron are here to plug their upcoming class about iOS hacking or I guess iOS pen testing. Unfortunately, we don't have any iOS articles. So we'll just make up iOS articles as we go along. Alright.

It's fine. We have Aisling. We have is that everyone? Did I say Wade yet? Wade Wells, the legend. He probably is on like 75 podcasts by now. Like, how many podcasts are you actually on, Wade? Do you feel comfortable sharing that number?

Wade WellsWade Wells

Yeah. I guess I can share that number.

Corey HamCorey Ham

Is that like asking a lady your age?

Wade WellsWade Wells

I'm on three that are like weekly things but like they get pre recorded and then one that's like every sometimes.

Corey HamCorey Ham

If I wake up early enough Four?

Wade WellsWade Wells

Four or five. Four or five. Five. You know me, like, I don't I don't have a website. I don't do anything. I just do everybody else's thing. That's it's the easiest way to

Corey HamCorey Ham

do it. Same here. Having a website. What is this? Sponsored by Squarespace? Absolutely not. If this podcast is ever sponsored by Squarespace, we're all gonna shut down this company.

Wade WellsWade Wells

I was really trying to get it sponsored by Liquid Death and they won't do it. I've been trying so far.

Corey HamCorey Ham

You don't wanna be sponsored. Liquid

Wade WellsWade Wells

Death. Alright.

Story # 1; Did DOJ Prosecutors Violate Trump’s Executive Order by Selling the Forfeited Samourai Wallet Bitcoin?

Corey HamCorey Ham

So let's get into it. Let's step straight into the political, like, skier. Is I guess it's it's kind of a political article. I don't know. Basically, the word is that Trump is considering pardoning two individuals who got five years in prison, or I guess one year one individual who got five years in prison for running a cryptocurrency mixer service.

Basically, the the service is called Samurai, I'm assuming is how it's pronounced. But there's a few there's a few articles about this. Trump in a recent press conference said that he's considering pardon pardoning this person. There's been nothing finalized about it. This article that Megan's throwing through right now is talking about how when they seized this when the Department of Justice seized this cryptocurrency wallet, they sold it, they liquidated it like they do for all seized assets.

But let's just imagine what a cryptocurrency mixing service would be used for. It probably would be used by nation states like North Korea mainly to launder money. That's kind of the main issue with these services is that they're abused by nation states and criminals, but mostly nation states, I think. And so basically, it's like all the currency in this mixer we're assuming was nation state bad cash. So there's basically two things here.

The first thing is, I mean, privacy versus money laundering. I think we all on this episode or on this show generally are pretty on the side of privacy and we're gonna talk a lot about some other privacy wins. But I guess, is there a limit to privacy? Like, should it be legal to run a Bitcoin mixing service or any cryptocurrency mixing service? Because there's been a bunch of these over the years and a lot of the people who run them have gone to jail because they're so easy to abuse.

I guess, what what do people think? Is it should this be pardoned? Like, it seems like it's pretty cut and dry to me, but I don't know.

Wade WellsWade Wells

For me for me, it kinda like goes against the heart of like cryptocurrency. Well, like the ledger. Right? Everything's supposed to be trackable. Everything's supposed to be able to, like, go back and see exactly how things were. So it's almost against the soul of Bitcoin. At least that's the way I I think of it. And, of course, there's a criminal aspect of it as well. Right? Like, is there a legitimate like, this is also going into the privacy.

I don't think there's, like, a real legitimate reason to have these besides hiding. Yeah. Because it is cryptocurrency. Right? Like, you're you you should be expected to be tracked because that's exactly what it's for.

Corey HamCorey Ham

I totally agree.

Aisling

Yeah. Like, if you actually want a private transaction, that's not the way to do it. That's what Use a different literal cache is for.

Corey HamCorey Ham

Or that. I mean, but there are privacy track. Sure. An Yeah. Well, yeah. I mean, basically, there's essentially, I think what Wade is saying, I wanna put some words in your mouth here, Wade, but basically Go

Cameron Carter

for it.

Corey HamCorey Ham

I'm comfortable with cash or Monero or any other thing that's like, let's call it pseudonymous. So it's not explicitly tied to my name, my credit card, and my address. Right? Like let's say I wanna buy something online but I don't wanna provide the seller with all my personal information, I think that's totally fair. That's the equivalent of buying something in cash.

If I buy something in cash, I don't you don't know who I was, what my, you know, address is, any of that other stuff. But if I buy something with a credit card, that information's out there. I think from my perspective, it's okay to have pseudonymous cryptocurrency like Monero where whose transactions are inherently private or masked in some way, but it's not a mixer. Because the mixer is where you get into which if those if you for those that don't understand what a mixer is, it's essentially like an anonymizing service that I send in x amount of Bitcoin and it comes back through a bunch of other transactions. Essentially, it really is just for anti money laundering.

Like that it really is just for that purpose. Like Tornado Cash was an old one. There's been a bunch of them over the years. It's essentially a way to mix your Bitcoins in with other people so that no one can tell where they came from or who got them.

Cameron Carter

I mean public. Right?

Aisling

It's literally transaction laundering. That is its entire purpose.

Dave Blandford

Yes. And I do have

Aisling

a We can say we're laundering it because we don't want people to know who we are, not because we got the money through some nefarious means. But end of the day, it is a laundering system, that's all it does.

Dave Blandford

Yeah. So my question is, it looks like the law is related to they they got them because they operated a business. Would this apply in like a co op fashion if 10 people got together and there was no profit? Is that how the law was written? So

Corey HamCorey Ham

there was Tornado Cache was set up like that. It was like basically just like a GitHub page. Like it wasn't really there wasn't I mean, there were developers. Right? But it was like essentially what happened was in the case of no one went to jail, but the government sanctioned or blacklisted the Tornado Cache protocol.

Ralph MayRalph May

Okay.

Corey HamCorey Ham

So it was like the government was like, you can't use this. It's illegal for US citizens, residents, and companies to use this protocol. The GitHub was shut down. They did arrest one of the developers, but I don't think the developer actually went to prison, from my understanding. I I guess I don't know what how that actually they but yeah. They basically, they were charged and arrested. Oh, no. Yeah. I'm sorry. I'm catching up on the wiki.

They were arrested essentially for facilitating this protocol. So I think even if you don't make money for it, bought from it, it's still illegal. Guess, is the Yeah.

Wade WellsWade Wells

The long answer. Samurai Right was was conspiracy for money laundering, as well as operating an unlicensed money money transmitting business.

Corey HamCorey Ham

Yes. Which

Wade WellsWade Wells

talk about a mouthful of a law. But

Corey HamCorey Ham

I feel like if it went to a jury, whatever, it's pretty easy to convince them to like, he wrote the code and then the code was used to launder money. Like, it's not, you know, it shouldn't be like a crazy Uh-huh. Big logical leap for that.

Wade WellsWade Wells

Looking at this from like a different perspective, is any is anyone like surprised that he's gonna get pardoned? Like, we already saw the one dude from the Silk Yeah. Road get

Bronwen AkerBronwen Aker

Right?

Wade WellsWade Wells

Like, this is I

Ralph MayRalph May

mean, Ross Holberg was like nuts too. I mean, like, he Yeah. I mean, according He

Corey HamCorey Ham

did to try to kill a guy.

Ralph MayRalph May

Yeah. According according to like, actual court testimony, right, and that he did try to hire someone to kill, like, you know, it

Corey HamCorey Ham

was it was it wasn't Yeah. People ask if Tracers in the Dark goes into crypto washing. Yes, it does. That's like half the book.

Bronwen AkerBronwen Aker

Okay. Well, here's here's another issue though. Executive orders are not law. Period.

Corey HamCorey Ham

This isn't an executive order. What But Oh, you're talking about him violating it? Yeah.

Bronwen AkerBronwen Aker

The the the articles are talking about the fact that the Department of Justice is violating an executive order. And Right. Executive orders are not law.

Corey HamCorey Ham

Period. I mean, would violate sanctions too. Right?

Bronwen AkerBronwen Aker

It's Probably it does violate sanctions. So so okay. If the there are probably other laws involved, and this is where I'm I'm crypto ignorant. I mean, I own some Bitcoin mainly just for the giggle factor, but I don't really know anything about it. But when it comes to the issue of, gee, USM has sold forfeited Bitcoin and it's violating an executive order. Like I said, an executive order isn't law. Laws are passed by congress.

Corey HamCorey Ham

Yeah.

Bronwen AkerBronwen Aker

I mean Yeah. I mean, basically

Corey HamCorey Ham

yeah. I mean, I think the the to me, the executive order violation isn't really the story here. The story is the general like, essentially for me, it's crazy that or interesting to talk about that the government would be like, money laundering is fine. That's basically that's basically what they'd be if they if they pardon this person, they're basically saying running a money laundering business is fine as long as it's done with crypto because we like crypto.

Ralph MayRalph May

Yeah. This is this is actually counter to everything the federal government has done. Typically, you wanna go after crime, you'll go after the money laundering that has to occur in that Yeah.

Corey HamCorey Ham

In the profiteering Or taxes. Yeah.

Ralph MayRalph May

Yeah. You go after them. Like,

Bronwen AkerBronwen Aker

They've seized assets obtained in whatever laundering in

Ralph MayRalph May

order Yeah. Exactly. Because what happens is is once you seize those assets, this is a way to stop this criminal enterprise because what the criminal enterprise has to do after that is have to prove, right, that that money was not used or that money did not come from illicit activity. So to do that is like a whole thing and most people just let the money go.

Corey HamCorey Ham

That's Yeah. I I mean, basically, the government has a long history of prosecuting

Ralph MayRalph May

Yes.

Corey HamCorey Ham

Illegal businesses through business laws Yes. Taxes Exactly. And, you know, money laundering regulations and things like We

Ralph MayRalph May

can't catch you, like, selling the drugs, but we know that you are getting the proceeds from that and that's how they work it

Corey HamCorey Ham

out.

Wade WellsWade Wells

Once again, going back to tracers in the dark, right, where the tax man Yeah. Is the one who comes down on everybody at the end of the day.

Ralph MayRalph May

Yeah.

Corey HamCorey Ham

Exactly. Basically, the like, from my perspective on this is that if this if this pardon happens, I that to me is against the interest of the executive branch that would pardon it. It's like, nation state North Korea, you can buy your missiles with money laundered date. Like, that that's basically what they're I don't get that. That's

Bronwen AkerBronwen Aker

crazy, but

Cameron Carter

Does the value of Trump coin go up if they do get pardoned?

Corey HamCorey Ham

Good question. We don't know.

Wade WellsWade Wells

I I don't know I don't know if you had to hack someone's iPhone, how would you to get their cryptocurrency wallet, how would you do so?

Cameron Carter

I'd make a bunch of money and employ the NSO group.

Corey HamCorey Ham

Alright. Good answer.

Wade WellsWade Wells

Alright. Well, that didn't work.

Corey HamCorey Ham

Yeah. Okay. So

Bronwen AkerBronwen Aker

Nice attempt at a segue though, Wade.

Story # 2: Cloudflare defies Italy’s Piracy Shield, won’t block websites on 1.1.1.1 DNS

Wade WellsWade Wells

Thank you.

Corey HamCorey Ham

Thank you. Let's let's step out of let's step out of political space real quick and talk about, I guess, it's still politics, but politics around Italy and Cloudflare and a more interesting kind of an interesting story. Politics I really for hope so okay. This here's the article. The article is Cloudflare won't censor basically, Italy find Cloudflare €14,000,000 and Cloudflare was like, no.

This is ridiculous. Which reading into it, I do think that it is ridiculous. Essentially, for those that understand, this is about I don't understand all like the Italian like like like mobster politics of all this. Like, I I really don't like there's a lot of like shady European stuff happening here that I do not understand. But basically, Italy dropped a bomb on Cloudflare.

Was like, you need to censor all these sports piracy websites. And Cloudflare was like, okay. We don't have the ability to do that and won't do that because you just gave it's essentially them sending a list of IPs to Cloudflare and saying, don't resolve these IPs, which is like, for obvious reasons, can just break the whole Internet. Right? Like, there's so many reasons not to do this.

Like, I think the funniest part of this is, of course, it has like that Italian mobster thing where it's like, it's about live sports. So it's a bunch of like shady European, like, FIFA corrupt type people being like, they're they're pirating the sports. They they gotta pay us. It is funny that like, even the EU is like, this scheme is concerning this, you know, quasi court order that isn't a real court order thing is weird. It's like, it's so Italian. I love it.

Wade WellsWade Wells

Do do you think somewhere out there, like, big DNS is getting together in order to fight this?

Ralph MayRalph May

Big DNS. Like, one of big DNS.

Corey HamCorey Ham

Is Cloudflare not big DNS?

Wade WellsWade Wells

No. It's a part of it. Right? They mentioned Google too. Right? So there's some other DNS providers.

Ralph MayRalph May

Hold on. The DNS is democratized. Right? It's not, like, controlled by one entity. Those are just entities that have large presences in that And

Aisling

who can

Wade WellsWade Wells

be sued or who can go to lawsuits for a large amount of money.

Corey HamCorey Ham

Yeah. But you can also still just go to a

Ralph MayRalph May

different different resolver to get the same

Corey HamCorey Ham

And it's recursive. So, like, what you you block it all the way down, Cloudflare could just say, I don't know. Find another DNS server, and then it would Cloudflare still

Ralph MayRalph May

doesn't own the root DNS servers anyways. They're not they don't own that. They're just reproducing that information. Yeah. Right? So they're not in control of I mean, they're not I can't. Right? That like

Corey HamCorey Ham

I like the idea. Okay. Here's the most Italian possible response to this. Cloudflare figures out the entity, like, they're coming from, and then just black holes them only for that entity, so they can't tell if it's been fixed or not. Be like, our DNS our DNS is down. We'll email you back once the DNS comes back and it just never comes back.

Ralph MayRalph May

I I glad to hear, whole Reddit thread on this. And, like, kind of the TLDR of, like, some of the opinions was that, you know, this is just a way to offload the risk onto Cloudflare. And the reason why they all want to do that is because it's like a simple easy scapegoat as opposed to implementing what would be a significant network policies to try to block this and essentially you start going down this rabbit hole and next thing you know it's like the great firewall of China and even then you still don't block everything. So they don't they don't have the money to do that. So it's way easier to just be like, hey, well, Cloudflare, you block it then.

It's your fault.

Corey HamCorey Ham

Right? Yeah. Totally. I I I really wanna like, I want a dramatized adaptation of like the sports bosses in, like, their super tight suits smoking a cigarette with an espresso and being, like, we gotta kill these piracy sites. And then some intern is, like, but it's hard. And they're, like, you gotta do it. And he's, like, what if we just fine them instead? Fine them $14,000,000. Alright. Yeah.

We have a deal. Capiche or whatever. Like, it's just like like this like mobster style deal. Because yeah, you're right. Blocking DNS like, okay, we all know the best response to piracy is just to make it easier and cheaper for legitimate users. Right? Like, that's the way to fix piracy. Don't try to prevent piracy. It's not gonna work. There's always gonna be a way around it.

It's the Internet. Instead, just make it easier to stream whatever, I don't know, Italian Yeah. Curling or whatever. I I don't know exactly what sports are trying to prevent streaming, but Yeah. I mean, it's gonna

Bronwen AkerBronwen Aker

it's gonna be sucker.

Wade WellsWade Wells

Look at, did you like, we didn't even the time frame in which they want this to be blocked.

Corey HamCorey Ham

Thirty minutes,

Wade WellsWade Wells

dude. Thirty minutes. Right?

Corey HamCorey Ham

They wanna block a global block within thirty minutes. Oh, man. Can you imagine having the

Wade WellsWade Wells

Yeah. I just think of working at a data center when we used to tell people to put in like any type of DNS. They're like, yeah, it's gonna take two days to resolve

Dave Blandford

it Yeah.

Corey HamCorey Ham

Right. Right? Yeah. DNS It usually has to be one hour. Time to live record dude, how many what percentage of the internet has TTLs at thirty minutes or less? That's a tiny percentage. Right? Like, most DNS servers are way slower than that anyway.

Wade WellsWade Wells

That there's the law after this is gonna be everyone has to set their TTLs to thirty minutes.

Corey HamCorey Ham

Thirty minutes or less. Twenty nine minutes.

Cameron Carter

Yeah. So the and the

Ralph MayRalph May

other thing too is that and just to kind of close it out, it's like as soon as you open up this can of worms and then like Cloudflare blocks certain things and like all this other stuff, now next thing you know, nobody wants to use Cloudflare anymore because it's kind of like the filtered version of the Internet. Right? So then just another DNS pops up and they do the same thing and, you know, now it's just whack a mole.

Corey HamCorey Ham

So Exactly.

Ralph MayRalph May

And and and into Cloudflare's defense, they're not hosting anything. All they're doing is just records of IP addresses. What happens in there, that's on them, not on Cloudflare.

Corey HamCorey Ham

Well, hold on. I would argue, I don't know if this is a hot take or not, but I think Okay. Controlling a DNS server is potentially the best data collection you could possibly get on the Internet. Maybe browsing like, maybe you could get better data from a search engine, I think the data flowing the the amount of data flowing through a DNS resolver and the amount that you could profit from it is pretty significant. Like, who is resolving what from where is a huge like, that's a huge profit center.

So they are running the service and they are profiting immensely from it, I would imagine. But Yeah. Well, and then do this too. Right?

Ralph MayRalph May

Yeah. Anybody can. This is not special. There

Bronwen AkerBronwen Aker

is another really good issue raised by the Auris Technica article is that if an IP address is filtered inappropriately, then legitimate stuff goes down. I mean, they were talking about how they took down Google Drive for Yeah.

Corey HamCorey Ham

Oh, yeah. So because you can pirate things on Google Drive. Yeah.

Bronwen AkerBronwen Aker

People do it all the time. I mean, I understand why it got flagged, but then you wind up taking down all of Google Drive just because of a few kids who are misbehaving.

Corey HamCorey Ham

Yes. It is it is seriously just throwing out the baby with the bathwater, but the internet version of that. It's like, if you block also, what percentage of the internet is just Cloudflare IPs? You're just gonna they they're asking them to block themselves across the whole internet, like anyway, moving on. This is probably gonna get it's it's a nothing burger.

This is probably not it is interesting to think about, but there's no way this could ever get implemented at on a legitimate, like, on a lit this is never not happening. It just isn't technically feasible. Speaking of whack a mole, let's talk about California banning a data broker. This is a for me, this is a privacy win. Wade, do you wanna run through this one?

Story # 3: California bans data broker reselling health data of millions

Wade WellsWade Wells

Let me find it real quick. Where is it?

Corey HamCorey Ham

Data masters.

Ralph MayRalph May

Pretty much

Corey HamCorey Ham

But sadly,

Wade WellsWade Wells

it's not. It? Throw it up someone throw me the link. From what I remember, pretty much there's a new California has been going pretty hard on data brokers recently. If you didn't know, they actually came out with a program where you can actually request it in California and they will then go out and request you to be removed from all the data brokers, which is amazing. It also had a really cool acronym. I don't remember what it was. Dropped but

Bronwen AkerBronwen Aker

Yeah. Dropped is is the new Dropped. Online platform. Delete request and opt out platform. And I already I live in California. I already signed up for it. Form's super easy to use. And, you know, it's it's nice that somebody is looking out for the privacy of individuals because big tech certainly isn't. And it it's gonna be interesting to see how effective this is because data brokers are worse than tribbles. They they multiply all over the place.

And I I already am using services to pull my data from data brokers. So it's gonna be interesting to see how much this new agency and this new program is going to impact steps that I've already taken and you know, I get the monthly reports x number 100 data brokers have been requested to remove my data from their systems.

Corey HamCorey Ham

So is this gonna turn into like the same system we use for taxes where Incogni and all these delete me services are lobbying against these so that

Wade WellsWade Wells

they That's exactly what I thought. That is exactly what I thought

Corey HamCorey Ham

was No. Gonna happen. You can't have a government agency that does the thing that we also do.

Wade WellsWade Wells

Right. No. One thing to think about joke. Obviously. The sign up for this though is live, but the services from what I read don't go live for another six months. Did you read that somewhere too, Bronwyn?

Corey HamCorey Ham

Correct. Yeah. Has six months.

Wade WellsWade Wells

Bronwyn, what what what prevents a non Californian from signing up for this?

Bronwen AkerBronwen Aker

You have to enter address information. It has to be verified with documents.

Wade WellsWade Wells

With the Okay. So if anybody wants to live in California, here's my note.

Bronwen AkerBronwen Aker

So basically, yeah, you'd have to commit fraud in order to sign up for it, but

Corey HamCorey Ham

Maybe it's okay Trump pardoning those people. We'll be fine.

Bronwen AkerBronwen Aker

Of the things we've seen though when it comes to privacy legislation is that California does tend to be one of the four runners and other states tend to follow. We saw that with CCPA.

Corey HamCorey Ham

And every building in my state now causes cancer. Thanks California.

Ralph MayRalph May

You're welcome. Ruined everything I had. Man,

Corey HamCorey Ham

you ever go to a

Wade WellsWade Wells

Dyson, everything has lead. Don't go to NASA.

Corey HamCorey Ham

No. I mean, you're not wrong, Bronwyn, for sure. That like, this is one of those things of like, if you have to make a policy for The US and you have it you want it to apply to everyone, this is like there's 50,000,000 people or whatever that live in California, so you might as well just lump them all in with that.

Wade WellsWade Wells

So the go into this article though, like, kinda like went around it. So the California Privacy Protection Agency announced that they're hitting a company in Texas, which what what was it? Rick and Rick Becker Data LLC? I feel like it it maybe it's one of those lower level data brokers that I've never heard of, but who knows? Rick and yeah, dude. That just shows you my reading level.

Corey HamCorey Ham

I thought they said it was Data Masters.

Wade WellsWade Wells

Was it? The one I got

Cameron Carter

saw your data

Bronwen AkerBronwen Aker

Oh, they were operating as Data Masters.

Corey HamCorey Ham

Data Masters is a sick name. I'm sad.

Wade WellsWade Wells

That's way better name. That's not even changed that LLC.

Bronwen AkerBronwen Aker

Here's the thing about these laws. Even though they technically only apply to California residents, if I'm interacting with a company based in Texas, I'm still a California resident so that company in Texas has to obey California law because I'm a California resident.

Corey HamCorey Ham

So you have this request. Wondering for anyone wondering what, you know, what this company did. Basically, they bought and resold user information with people suffering from medical conditions so it could be used for targeted advertising, which is like just nazzy We to begin heard your we heard your leg hurts. Here's some pain killers or what like

Bronwen AkerBronwen Aker

We heard you've got Alzheimer's. Here, click this button to get

Corey HamCorey Ham

All the lyrics are already purple. Are you scared? No. Yeah. For sure. It's bad. So this is a win, I think. I mean, a lot of states will probably follow suit. I don't know about setting up their own system. I kinda hope they don't because they'll just SQL injection. But

Ralph MayRalph May

Absolutely.

Corey HamCorey Ham

For sure. It's it's gonna be a thing. So what else we got? I think the other big story, which isn't really a cyber security story, but maybe Dave and Cameron you could chime in on this. Siri has I I guess, now that I say this, all my devices light up.

Story # 4: Apple picks Google’s Gemini to run AI-powered Siri coming this year

I'm so sorry everyone. Yeah. You just hit. The s word that will not the Apple assistant maybe is getting thrown in the garbage? Because the news article is essentially that Apple is teaming up with Google. So Apple announced today, earlier today, that they're gonna team up with Google to use Gemini models to AI power the s words, s I r I.

Ralph MayRalph May

I was reading though that they're still gonna use the Apple hardware that they built. They're just gonna use the models from Gemini, like, on there. But

Corey HamCorey Ham

they already had kind of a deal for OpenAI. Right? They already

Bronwen AkerBronwen Aker

Yeah. Had

Ralph MayRalph May

I don't know. Maybe is this like a like a a pump move for like the stock? Right? I I

Bronwen AkerBronwen Aker

don't know.

Corey HamCorey Ham

I don't know. But these two companies, Apple and Google, have done a lot of battling over the years for sure. So it's interesting to see them teaming up in this way. Basically, they're starting a multi year partnership. I think this is from my perspective, if we're looking at like a high level business perspective, Apple needs this. They need a win. They need to be able to give an AI win

Ralph MayRalph May

Yeah.

Corey HamCorey Ham

Because Is it SIRs isn't their win, though.

Wade WellsWade Wells

That's the thing. Right? Like, it's

Corey HamCorey Ham

But it doesn't matter. I'm saying It doesn't matter.

Ralph MayRalph May

Like, don't care where the AI actually comes from.

Corey HamCorey Ham

You just

Ralph MayRalph May

wanna use the damn thing. Okay?

Corey HamCorey Ham

It's it's getting to the point Well, where that's fair. It's getting to the

Cameron Carter

AI point agent use?

Corey HamCorey Ham

Gemini. Which is yes. Yeah. It's basically unifying it's basically unifying what AI agent you would get on mobile, I guess, if you think about it like that.

Ralph MayRalph May

Well, yeah. Maybe in the background. But like if they are running on their own hardware though, they could still modify things. They're not necessarily beholden to what Google did. I think they're just buying or excuse me The models. Licensing the models, like Yes. So they're not training them. They're not gonna

Wade WellsWade Wells

train No. Okay.

Dave Blandford

And I forget the source where I read this, but Gemini is current I forget where I read it, but it's the, like, the consumer level. So, like, the basis of it was the theory was Google had created the search and they made it affordable and, like, consumer friendly and that Gemini is trending that way. So there's a lot more rush. I'm hearing I'm seeing a lot better things out of Gemini now. So I think it's a good move

Corey HamCorey Ham

overall.

Ralph MayRalph May

Yeah. I mean, so there's there's pretty much three main players right now and I'm not gonna say x.

Corey HamCorey Ham

Frontier models?

Ralph MayRalph May

Yeah. There's like three

Corey HamCorey Ham

assistants main or models?

Ralph MayRalph May

Models. Like three frontier models. Right? There there are there are many other models, but I'm just thinking like from the AI perspective. So one is the OpenAI's model and like they're they have a bunch of different models inside of that, but OpenAI has some pretty frontier models, meaning like the top end most powerful models.

And then Google has the other ones with Gemini, which they have a couple different flavors of it, they are frontier models. They are very, very smart at doing a lot of stuff. Then the last one is Claude. Right? And they have Anthropic. Front yeah. Claude, which is, yeah, ran by the company Anthropic, and they have Frontier models as well. And then kind of the last like one on there, which I'm going to half mention, but mostly because it only gets mentioned in like bad things right now

Corey HamCorey Ham

is You see?

Ralph MayRalph May

No. There's X and the

Corey HamCorey Ham

Oh, Grock. Right. Yeah. I mean, there's a bunch. And a lot of people are gunning for a Frontier model, but the reality is training a Frontier model is like the most expensive thing

Cameron Carter

Yes.

Corey HamCorey Ham

On the planet you could do. And also, the other thing here that's import I think if I was Apple, this move makes sense. Maybe not from an optics perspective because Google is my enemy, but also because Google is potentially the long term pick. The other if you think about it, of all the companies that are making frontier models, Google's the only one that is making money, if you actually think about it. Like, OpenAI and Anthropic are both like, give us money so we can train our AI models or else we're gonna go belly up.

Too fun. Google is comfortable.

Ralph MayRalph May

About OpenAI. Not OpenAI. I'm sorry. Anthropic. They actually use Google GCP to run a lot of their training. Right? They're they're they're like paying Google, and they actually have partnerships with Google even though it is their model. Right? Just I mean, the hardware is a thing and then the model you use is another thing. Right?

And you could rent those, you know, to make it happen. But you're right, Corey. It's really expensive to train them. And they're also none of them are making money right now. Right? Even though Anthropic argues that they're definitely in that, like, a much higher profitability than OpenAI, who's literally taking truckloads of money, jumping it into data centers to train models that none of which are paying and is continuing Coming to farmland near you.

Aisling

And which burn out the chips that they bought to do it with.

Corey HamCorey Ham

What's up? Yeah.

Aisling

Oh, most of the data center cost is getting sunk into chips that get burned out in the process of actually training the frontier models.

Ralph MayRalph May

Yeah. And once the

Aisling

models Those boards are not usable again, they're not resellable, they're shot.

Corey HamCorey Ham

Yeah. Yeah. But anyway No. I could use it to play Roblox, it's fine.

Wade WellsWade Wells

I was about to say, when when all these data centers go up, what are we gonna use them for? Like like it's gonna be like Walmarts disappear and stuff and they just leave these big empty buildings. Right?

Corey HamCorey Ham

Passwords, dude. Imagine the password cracking. You could do

Ralph MayRalph May

Every password. Your password I

Wade WellsWade Wells

don't we don't we don't talk about passwords. Alright. Dude,

Corey HamCorey Ham

okay. Here's what happens. Alright. Here's what happened back last year. I have a plan. Dude, Wade, get me the get me your CEO on the phone. Okay? Here's what's gonna happen. The Wade's employer who is not gonna be named buys an entire data center and then just cracks every password ever, and then just says, here's why you need our service, because we just cracked every password.

Wade WellsWade Wells

Oh my god. It's it's genius. I love it.

Corey HamCorey Ham

I know. That's why I do consulting on the side. Anyway, no,

Dave Blandford

I'm I'm just kidding.

Corey HamCorey Ham

This is a joke. This is a terrible idea.

Ralph MayRalph May

So and and actually to follow-up, CES was just was it last week, right? Yeah. Yeah. And so one of the things announced at CES was NVIDIA took the stage and they announced their latest generation of AI. It's all AI. Which is their

Corey HamCorey Ham

way because it's supposed to be consumer electronics. They're like, oh, by the way, consumers, we're gonna remake the RTX 3,060. Anyway, back to AI.

Ralph MayRalph May

Yes. But one of the things that they did mention on there is like the power consumption like going, you know, and yeah. Whatever. It's all about AI and, you know.

Wade WellsWade Wells

Is that where they mentioned the Palantir stuff too? I don't think that we have an article about that.

Ralph MayRalph May

Oh, no. But did you see that?

Corey HamCorey Ham

Please hit us with an article that we don't have. What you got?

Wade WellsWade Wells

I was watching Gamers Nexus and they came out with a thing watching CES. So Gamers Nexus came was talking about how Nvidia just announced that they are going to make everything Palantir faster. Palantir is pretty much like nation state level spying on individuals and military industrial complex. So there's like some scariness behind that. And then they go into it. But the funny part is Palantir actually, like, commented back to Gamers Nexus about the situation.

Dave Blandford

They're like

Corey HamCorey Ham

Now we're talking about you two jumping something SpyBot with real time kill location data.

Wade WellsWade Wells

That was it. Yeah. And then, literally, like, there's other articles where it's like the Palantir president Palantir is like, yeah. So our stuff kills people sometimes. I don't know what to tell you.

Corey HamCorey Ham

I'm like, fuck. Happens.

Ralph MayRalph May

It is what it is. You never know.

Corey HamCorey Ham

AI is never wrong. It'll be fine.

Wade WellsWade Wells

Never. Never.

Corey HamCorey Ham

Yeah.

Ralph MayRalph May

Just like humans.

Corey HamCorey Ham

The Peter T. M. All right. This has been a dark episode. Does anyone have any That's true. Is there

Cameron Carter

my fault. I don't even know

Wade WellsWade Wells

what You always get us talking about AI. There wasn't

Bronwen AkerBronwen Aker

my fault.

Corey HamCorey Ham

Didn't really talk stories? So, alright. Let's get darker then. The dark web.

Story # 5: Ragebait as a phishing tactic

Wade WellsWade Wells

The insider tool to

Corey HamCorey Ham

This is a pretty I think it's a good thing to remind people about in general. But there's a LinkedIn post that we have in here as a news article that's basically people are using rage bait as a phishing tactic. So is a post by Simo Cohoenin. I don't I'm sorry if I mispronounced your name Simo, but basically this is a fun example fish where someone is impersonating SendGrid and they are sending out an email that says, we will be adding a support ICE donation button to the footer of every email. And then they're just hoping that people click on the opt out link.

Right? Oh, That's the phishing tactic. So I think it's good to remind people in this dark time that people will try to rage bait you into clicking something you shouldn't. In addition to trying to be like, here's a free iPad or whatever. Yeah.

The positive side of phishing, there's also the negative side of phishing, is bait like that. So be on the lookout for that. That's a uniquely, I think, mean one, and like definitely would be out of scope for pen testing. Like our clients would be very upset if we did that. But, yeah. Like you're gonna see threat actors, those are the rules that they don't have to follow. Right? They don't have to be ethical and be reasonable. So just be on the lookout for that kind of stuff.

Bronwen AkerBronwen Aker

And they aren't. They aren't.

Corey HamCorey Ham

And they aren't. News is you know, honestly, Bronwyn, they might even be criminals.

Wade WellsWade Wells

Oh my gosh. What? Way.

Corey HamCorey Ham

I mean, news

Cameron Carter

is I get

Bronwen AkerBronwen Aker

an email saying, you need to do blah blah blah with your account on this. If I actually have an account with that organization, I pop open a different browser and I go directly to the organization. I do not click any links.

Corey HamCorey Ham

So Because You're smart. Speaking. You should be a you should out be on a podcast anyway.

Story # 6: Doomsday For Cybercriminals — Data Breach Of Major Dark Web Forum

Ralph MayRalph May

Speaking of criminals, right? About the data breach of major dark web form?

Corey HamCorey Ham

Yes. That's yeah. Speaking of

Ralph MayRalph May

criminals dark web form is of cyber criminals. Yeah.

Corey HamCorey Ham

Okay. So yeah. Yeah. So this is what is it called? Doomsday?

Ralph MayRalph May

Doomsday? Yeah.

Corey HamCorey Ham

Yeah. So basically, a data breach finally became, know, This is not the first time, and it won't be the last. There's been I I swear, like, if you go on a breach site and you look for breach sites, like, think raid forums got breached like seven times.

Ralph MayRalph May

Oh, dude. I mean, I I I swear to God, I feel like it's a joke. They're like, we make it so we can breach it, and then we can sell our own breach, and then we

Corey HamCorey Ham

can make another site selling the breach. It's like it's like turtles all the way down. They're just getting breached, just selling their own breach. Yeah. Basically, Doomsday, which apparently is a dark web forum, I don't keep track of these.

The only one I really keep track of is breach forums, is like the worst one. Mhmm. But basically, the ironic part of this is there's 300,000 users, 70,000 of those apparently are linked to traceable IPs. I don't know how traceable like, you know, it could be a botnet, it could be a Starbucks, like who knows exactly what it is. But this data will definitely be hopefully provided to law enforcement and then they'll dig in.

It's a good way to figure out who's who and kinda get a good dossier of threat actors. At the end of the day though, I mean, these sites have gotten breached every year. I've been in these breaches for the accounts that I used to collect from these sites.

Wade WellsWade Wells

I was about to say, do do you collect this breach to put in your collection?

Corey HamCorey Ham

Like I do. I do. I absolutely do. I mean, is like could give you if you're doing an incident response, this could give you super valuable information of like

Ralph MayRalph May

I heard it was like like 30,000 IPs from Starbucks's.

Corey HamCorey Ham

Yeah. Right? Like Great. Who knows how traceable It's traceable. You would hope it's misinformation. You would I mean, opsec though, we've seen. Every criminal gets caught has opsec fails in the in the mix somewhere. Right? Gonna mess up at some point.

Aisling

I'll note that if they didn't have opsec fails, we wouldn't have caught them.

Corey HamCorey Ham

That is that is true.

Aisling

What few criminals have good opsec are the ones who are still out there.

Corey HamCorey Ham

That is that is true. Speaking A of opsec lot of high profile people get caught from bad opsec is I guess a better way to put it.

Story # 7: The Great VM Escape: ESXi Exploitation in the Wild

Wade WellsWade Wells

Did you see the Huntress article about the VM escape stuff?

Corey HamCorey Ham

No. No. Tell me more.

Dave Blandford

I think

Aisling

I saw the headline.

Corey HamCorey Ham

That was

Wade WellsWade Wells

it. Someone else sent me this right

Corey HamCorey Ham

when Yeah. Checked my Yeah. Is this the ghost VM thing?

Wade WellsWade Wells

I don't remember if it's the ghost VM thing, but I know there's a really easy detection for the pretty much they got in through a sonic wall. Like, that was the first vulnerability. But then they had been sitting on this vulnerability in ESXi for they think over a year, a zero day, in order to pretty much bypass and go bypass host isolation. Right? It's a hypervisor vulnerability that allows the attacker to break out of the actual guest VM and just compromise everything.

Corey HamCorey Ham

It's just crazy. That is the craziest thing today.

Ralph MayRalph May

Does the it virtual or the VMware tools to to break out?

Corey HamCorey Ham

Is that is that how it does?

Wade WellsWade Wells

That's a better question, but I don't even know. I'm guessing it does because it's some vulnerability in it. But one of the so because we were talking about op sec, that's what brought me onto this is which is one of, like, the key detections I try to write whenever I go is looking for across all of your logs for any host name that doesn't match your naming schema because there's always someone who gets in who doesn't have one, and it's a key indicator of something that doesn't belong. And that's actually, like, one of the things they caught in this particular breach was the name of the actual host that was attacking them, which always great stuff.

Corey HamCorey Ham

Yeah. So basically, getting into the details of the exploit, they don't know they they don't a 100% know what CVEs or whatever was used, but they say high confidence, those are the ones. There's three CVs listed in the post that are like these are all from 2025 by the way, so patch your ESX. I know companies struggle with this and I understand why, but please patch your ESX. Basically or just don't use it.

Proxmox is pretty good. But basically, the vulnerabilities are out of bounds read in HDFS, which HDFS is the file system that ESXI uses. So it's a memory leak in HDFS. There's also TOC, TOU, which what is that? Time of use or something? I don't know what that actually means. V m c I out of bounds right yeah. Okay. And then arbitrary write and ESXi. So it's like three CVEs chained together. That's pretty crazy. But the good news is all you have to do is patch your ESXI and you're good.

Wade WellsWade Wells

Oh, that's it? Yeah. You say ESX, like, Proxmox is right there. Dude, Proxmox is so confusing sometimes. Like, I just feel like the UI is Dude, have you used CSXi? I have. And it was just so much like, the names for things make sense. Like, I'm like, yeah, that's where that should be. And then, like, I go to Proxmox and I'm like diving into, like, four folders and I'm like, alright. And I still can't remote into this box. What's going on?

Corey HamCorey Ham

Is is definitely

Wade WellsWade Wells

false Without a doubt.

Corey HamCorey Ham

Yeah. But sec, I do think there is a significant amount of the amount of inertia with ESX is super hot. Like, the number of administrators and IT people who got certifications in ESXi and know how to use it, like, you can't just be like, we're turning off all our VMs and we're gonna switch to Proxmox overnight. Like, that's a long process. I mean, we talked about it on the news a couple or maybe a month ago of I forget the company, but I think it's a financial company that was suing Broadcom because they were taking away support.

It's like a class action lawsuit to get about I six I. So like, it's yeah, it's a hot issue right now, but definitely patch your ESXi and it is an interesting threat intel thing. So basically, they broke out of the VM, got control over ESXi, then created another VM to

Wade WellsWade Wells

use for Let post me see. I think they

Ralph MayRalph May

No. No. They compromised the underlying ESXi. Yeah.

Corey HamCorey Ham

So they popped the ESXi server, but then I guess I'm like The shell

Wade WellsWade Wells

in leaked the host name somewhere.

Corey HamCorey Ham

Oh, I see. I see.

Wade WellsWade Wells

Which is super common, like, more common than you'd expect Windows network.

Corey HamCorey Ham

No. It's super common. We've gotten popped on that many times of like, hey, someone's in the host name Callie. Like, that's a such a deep giveaway.

Wade WellsWade Wells

I've had it where, like, the the tester used their handle as the host name and then we just went and looked them up and found them. And I'm like, alright, now we know who's who's testing us.

Corey HamCorey Ham

Turns out pen testers also have bad opsec. Yeah. Which, okay, companies that get mad at this, guess what? We're just being realistic because criminals have bad op sec too. Okay? That's what that's what we're doing. It's all a But

Bronwen AkerBronwen Aker

also, in a pen test, you're legitimately in the space and we kinda want their

Corey HamCorey Ham

Yeah.

Bronwen AkerBronwen Aker

Internal people to find us?

Corey HamCorey Ham

For sure. Think a if you're I think if you're the goal of a pen test is to get caught. Maybe not on day one, but for sure you should be getting caught at some point.

Bronwen AkerBronwen Aker

Yeah. If you're if you're getting d a in an hour, then there's something definitely wrong. We want to get caught. We don't want.

Story # 8: OpenAI says ChatGPT won't use your health information to train its models

Corey HamCorey Ham

So what else we got? There's a couple articles about AI and HIPAA and healthcare. I don't know if we wanna this is like kind of a regulatory question I don't really understand. But basically, both Anthropic and ChatGPT OpenAI have both said that they're gonna make healthcare oriented solutions that are commercially available. I don't really know if this is I don't even know how this is possible. Like, I don't I'm not a HIPAA expert, but it seems kind of is this just like GovCloud? It's like

Wade WellsWade Wells

it's it's fine. It's like,

Corey HamCorey Ham

it's fine because we Okay. Say it's Sounds

Bronwen AkerBronwen Aker

good.

Ralph MayRalph May

Don't talk back.

Story # 8b: Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools

Corey HamCorey Ham

There's a couple articles. I'll I'll link them here just in case anyone's interested. But both Anthropic here's the article about Anthropic bringing a HIPAA ready enterprise, you know, chatbots. And OpenAI has something that's basically exactly the same.

Cameron Carter

So we don't really need these at all because we already have technology that handles HIPAA data extremely poorly, and that is mobile applications. Right.

Corey HamCorey Ham

Right. That's probably true.

Cameron Carter

Yeah. Dave, you wanna talk about mobile applications?

Corey HamCorey Ham

Yes. Please tell us tell us some war stories from testing HIPAA mobile application.

Dave Blandford

Yeah. Don't. Just don't.

Corey HamCorey Ham

Keep your

Dave Blandford

keep medical off off a phone. No. It's it's just unintended places where data will write and just what has act just not using the native default features. It it it can get pretty ugly. So my advice is in the browser. Not you have to do it online.

Corey HamCorey Ham

Yeah. Or in your AI chatbot.

Dave Blandford

Or in your AI chatbot. Absolutely.

Cameron Carter

So I legitimately once had a mobile application that was connecting to an API. And to log in to the mobile app, you entered a four digit PIN. And so I figured that would go into the key chain and be used to decrypt some kind of long lived session token that would then be used for authentication. But, no, it was just a username and four digit PIN code going to the server to access patient accounts

Corey HamCorey Ham

in clear text. Oh. Well, no one could choose 1234.

Ralph MayRalph May

It's fine. Just actually put together a mobile application from scratch on Android. And yeah. Yeah. So I I know exactly what you're talking about as far as how to secure or like the security of mobile applications.

A lot of it actually has to do with Google itself. Like Google has access to all kinds of things, you know, on the device and how you configure that. Mhmm. You know, we're actually using, what do you call it, the GrapheneOS, which decoupifies the entire operating system while also not while creating con complete host isolation containers. You can, like, run other things like Google Store in an isolated container so it's not even actually connected to the to the underlying Android operating system and and that, like, from a a non isolated standpoint.

But I think it really just comes down to as far as the applications themselves, comes down to developers who wanna make it as fast as possible. Screw security, I need to sell. And, you know, let's just move on to the next thing. Right?

Corey HamCorey Ham

So Speedy So if

Cameron Carter

someone built an app like that and wants to learn how to test it, where would they go?

Ralph MayRalph May

What's up?

Corey HamCorey Ham

Can't help you there. They'd ask AI how to do it. No. They would take your class. You can plug it later.

Ralph MayRalph May

Oh, oh, no. No. No. We actually have a an app called Atlas, and it's actually for pen testing, physical pen testing, and it allows you to actually hook up to the Proximart with Bluetooth now directly. The only actually, I think it's the only mobile device that allows you to hook the Proximart directly over Bluetooth.

And you can read card data, write card data, do all kinds of fun stuff on there. You can also do, like, reporting. It'll it'll show you where flock cameras are. It'll show you where other, like, OSINT data. And everything's encrypted at rest on the device at at full time. Yeah. Anyways, so it's

Corey HamCorey Ham

I only I only use AI. Sorry.

Ralph MayRalph May

You only use AI for what?

Corey HamCorey Ham

I only I only use AI, dude. If it doesn't have AI chatbot, I don't even know

Ralph MayRalph May

It does not have any AI chatbots. It doesn't have Dude, no okay.

Corey HamCorey Ham

This is a side tangent, but my the weather app that I use, it has like an AI function and it's so stupid. I love it. Like, it's just like a a really it uses the on device, like, it's on device only and it's just an AI chatbot that's set to be like as salty as possible and it's just like, it's raining again, f you, and you're just like, thanks for this chat interface. That's super useful. Anyway, let's talk about n eight n.

Story # 9: Max severity Ni8mare flaw lets hackers hijack n8n servers

N Nathan? It's not Nathan, but I

Bronwen AkerBronwen Aker

What what n eight n?

Corey HamCorey Ham

I saw that.

Wade WellsWade Wells

I don't even know. It's condensed

Bronwen AkerBronwen Aker

n eight n.

Corey HamCorey Ham

Yeah. So there have been, I mean, like a countless number of CVE 10 or CVE 9.8 vulnerabilities in n eight n. We've actually only had one client to publicly expose their n eight n, but in general, this is the most recent one. It's called NI nightmare, which allows people to take control over locally deployed n eight n instance. It got a 10 out of 10 severity and according to data security company, Cyera, there are more than a 100,000 public vulnerable servers.

For those who don't know what it is, it's just a tool that connects a bunch of AI things together. So you could have it run one command and one module and one model and then send that data to OpenAI and then pull it back down and then send it back to Claude. It's essentially a way to connect together a bunch of AI services. Honestly, it's really cool and I highly recommend you download it and mess around with it. But definitely make sure you keep this up to date because n eight n has had a ton of vulnerabilities.

It turns out making a framework that just runs code and models is a vulnerable framework by design. So this is yet another one.

Ralph MayRalph May

Been out for a long time though. Like, it's been out for a while, way before actual the AI was even a Right? Because you were like, I just take this task and then I'll do this next. And like, you just pick like a, you know, a task sheet of things you wanna do, like automate.

Corey HamCorey Ham

Like IFTTT, but self hosted.

Ralph MayRalph May

Yeah. Exactly. Exactly. And so but as soon as you turn the AI piece, now you could do like, well then I asked the AI to do that and then it does this and then you next thing you know, your rabbit hole is, you know

Corey HamCorey Ham

Yeah.

Ralph MayRalph May

Pretty pretty

Corey HamCorey Ham

So patch your n eight n's. Honestly, you probably forgot you even had it out there. So just delete it and start over.

Ralph MayRalph May

Just start over again. Just get a new version. Right?

Corey HamCorey Ham

But the other thing the other reason why the n eight n stuff is really bad is because someone's at the door. Someone someone's stopping at the door. But basically, you someone Robin's like, I don't have any doors.

Ralph MayRalph May

I don't have any doors. I've got like six in my office.

Wade WellsWade Wells

I was about to say, Robin's got like seven doors. Way back

Corey HamCorey Ham

in Real fake doors. Basically, n eight n, you also give it a bunch of keys. That's the other reason why it's bad. But ironically, like, you read the blog post for Nightmare, like, the last step is just create an n eight n task to run a shell command. Like that's where like it has that capability, so that's why it's such a vulnerable service.

Like one of the things you would do with the service is run a shell command. So like, yes. Turns out when that's one of the options in the tool, compromising the web UI has some impact.

Ralph MayRalph May

Yes. Yeah. It's it's it's still cool. It's still kind of a cool tool though.

Story # 10: Instagram Denies Data Breach, Fixes Unsolicited Password Reset Requests

Corey HamCorey Ham

So the last article I wanna bring up, which this is something that hit my me and my personal life, people were asking about it. Instagram breach, I guess.

Ralph MayRalph May

And it was an insta breach?

Corey HamCorey Ham

Yeah. Like Oh. So so basically, here's the article. It's essentially that people are phishing with previously leaked information. So people are sending out this happened in 2024, I guess. But basically, people are sending out password Great. Reset reminders and then using them as phishing. Apparently, someone's estimated that it could impact up to 17,500,000 Instagram accounts. I don't know where that number came from, but I'm like, that's a lot of phishes.

Ralph MayRalph May

So I think they they they scraped an API to get all this data and then now they're using all of it to send out fishing. Right?

Corey HamCorey Ham

Yeah. So but it's like the the upshot of it is like use two factor and and don't get phished. So it's like

Wade WellsWade Wells

The upside is don't use Instagram. Get off all

Corey HamCorey Ham

social Well, okay. That's even better. Live in the forest. That's that's the next that's like That's the next level.

Bronwen AkerBronwen Aker

I actually I actually removed both Facebook and LinkedIn and a couple of other social media apps from my phone.

Corey HamCorey Ham

I

Aisling

just Oh, you're following Choff?

Bronwen AkerBronwen Aker

I am I am detoxing from social media.

Wade WellsWade Wells

It gets a little boring sometimes, but I've read a lot more.

Corey HamCorey Ham

The dumb the dumb phones. I'm I'm

Bronwen AkerBronwen Aker

going for quality over quantity. I'm I'm combating the slop.

Corey HamCorey Ham

That's a good for you, honestly. I think we should all do that. There is Job. Like a whole growing market of like, you know, dumb phones. Or the what is the the I think the most recent Nothing Phone has like an actual physical switch to switch between smart mode and dumb mode. You

Cameron Carter

know Isn't that a Jitterbug?

Corey HamCorey Ham

Basically, like, it is dumb Jitterbug. Nice. Well, Jitterbug is like kind of holds you back. Because you're like, alright, now I need to like walk to the restaurant, and I'm Yeah.

Ralph MayRalph May

And all you have is one other button that says life alert? You

Corey HamCorey Ham

you press it, you're like, I'm at the hotel and I need to get to this restaurant. They're like, you gotta stop pressing this.

Ralph MayRalph May

You have you have exhausted all of

Corey HamCorey Ham

your credits in this plan. Yeah. Yeah. You had one credit a

Cameron Carter

year and

Corey HamCorey Ham

you just used it.

Dave Blandford

Well, even Apple has their like, the the defense they give for like, journalists or people targeted by by Pegasus, they it turns their Apple phone into a to a dumb phone, essentially.

Corey HamCorey Ham

Yeah. The under attack mode or whatever. Yeah.

Bronwen AkerBronwen Aker

Yeah. Lobotomize your smartphone.

Corey HamCorey Ham

So Yeah. Yeah. I mean, there's there's a whole, you know, there's a whole thing. I saw Pebble. Pebbles bringing a couple Pebbles back for those that like love their Pebble watches back in like 2012. I saw them made a new they made a new watch. I feel like that was such like a nerd specific thing where like, everyone cool in 2012 had a Pebble.

Ralph MayRalph May

I had a Pebble.

Corey HamCorey Ham

Yeah. Everyone cool did. Now everyone has an Apple Watcher.

Ralph MayRalph May

Now I'm just a loser.

Bronwen AkerBronwen Aker

I never had a Pebble. Does that mean I'm not cool?

Corey HamCorey Ham

It's because you weren't cool in 2012.

Ralph MayRalph May

Yeah. You got cooler. Okay.

Corey HamCorey Ham

Now, you're cool. You could buy the pebble too.

Ralph MayRalph May

You could buy the pebble as well. They're probably cheap online except for the hips.

Bronwen AkerBronwen Aker

If you wanna be a pebble too.

Wade WellsWade Wells

They're not cheap. They're $200.

Corey HamCorey Ham

What? Dude, that's the shelf right over here. I can make some easy cash, dude. Wait, $200, that's how much I'm paying a month for all the subscription services it takes to watch the Olympics.

Ralph MayRalph May

You know and you know how much Well,

Wade WellsWade Wells

let me give you let me give you this Italian website real quick.

Corey HamCorey Ham

Yeah. Okay.

Aisling

Wow. But

Reporter remembers saving animals a year after L.A. wildfires

Bronwen AkerBronwen Aker

before we do the CTF stuff, I actually did have it's not an InfoSec related chicken story. No. But it is a chicken story. And it's it

Wade WellsWade Wells

We don't need we don't need it. It's okay.

Bronwen AkerBronwen Aker

We It's really short and sweet. Apparently, during the Eaton fires, all the wildfires we had a year ago here in Southern California, there were a bunch of chickens who were rescued. And there was a follow-up story by NBC or I'll have to look it up here. Where is it? Oh, I closed that tab. Anyway, there are follow-up stories, and basically, the chickens are doing well. That's it.

Ralph MayRalph May

Okay. Chicken survived.

Corey HamCorey Ham

Great article. Survived. They're thriving. What about the eggs? Did the eggs survive?

Bronwen AkerBronwen Aker

Oh. Oh. They probably were off their lane.

Corey HamCorey Ham

What did they say first? The chicken or the egg? I think the chicken. That that tells you everything you need to know right there, people. Save the chicken first. Don't save the egg. That thing's already hard boiled. Alright. Yeah. So CTF winners, let's do let's do the CTF winners.

CTF Winners

The winner the first place prize goes to Josh Kemp, who gets a year of anti siphon on demand training for free. Then the second place prize goes to christy b seventy eight, who gets one class of their choice. You should have gotten an email. If you haven't gotten an email, let us know. I have no idea what the CTF was. If anyone knows what it is

Cameron Carter

I was

Wade WellsWade Wells

gonna Please

Corey HamCorey Ham

post it in the chat. I'm assuming the CTF was get on the podcast.

Wade WellsWade Wells

A year's worth of a year worth is a lot. Right? Like, that's a that's a long time. Yeah.

Aisling

A year's worth of access is

Corey HamCorey Ham

You can learn a lot in the year.

Wade WellsWade Wells

Is your iOS class on demand yet?

Dave Blandford

Not yet.

Wade WellsWade Wells

David? Not yet? Not yet. Are you gonna make it on demand? That's up

Corey HamCorey Ham

to you. It would be hard to do it because you'd have is there a is there a hardware component at all that, yeah, I guess you have to bring a representative device?

Cameron Carter

Nope. So we're doing it all virtualized. We'll be using the Corellium platform. If someone is dead set on bringing their own rooted device, we will do our best to help them, but no guarantees with any of the labs or if anything goes wrong with their own device.

Ralph MayRalph May

Is it is it Android

Cameron Carter

and iOS? Hardware free. No. First, it's just iOS.

Ralph MayRalph May

It's just it's just iOS? Do you do you have you guys gotten the or have you guys ever played with the development platforms that you guys can get from from Apple?

Corey HamCorey Ham

Yeah. Yeah.

Dave Blandford

Yeah. So so we actually the class, we have our own app as well. So we did we we designed and we have a a vulnerable app. So but yeah. Yeah.

Cameron Carter

There any cool CTF challenges in the app?

Corey HamCorey Ham

I'm sure there are based on your face. I yeah. So

Cameron Carter

there's couple of questions that I didn't answer.

Corey HamCorey Ham

So Yeah.

Ralph MayRalph May

Yeah. So last question because now I'm just interested. So this is a virtual only or in person?

Cameron Carter

It's a hybrid class. It'll be on demand. This will be virtual. But

Ralph MayRalph May

This is gonna be

Cameron Carter

people signed up for in person at Wild West Denver. Hoping to get a few more. And yeah. So we'll be live walking around, helping people out.

Corey HamCorey Ham

Nice.

Cameron Carter

Making jokes, having a good class.

Corey HamCorey Ham

Sounds like fun. It should be great. Someone asked about the CTF answers. Megan, do you know where the CTF answers are or how people can find them? You can't.

Ralph MayRalph May

You can't.

Corey HamCorey Ham

That's the CTF. That's the CTF answers. Them.

Wade WellsWade Wells

You know what you do? What was his name? You find Josh and you ask him and you become his friend.

Corey HamCorey Ham

That's honestly, if you wanna know the way to network and be good in the cyber security community, that is the way to do it.

Wade WellsWade Wells

CTF Awesome. Teamwork? No? Maybe he shares password with Anti for anti siphon, you know, something.

Corey HamCorey Ham

The real CTF was the friends we made along the way.

Ralph MayRalph May

Oh. They hacked my heart.

Bronwen AkerBronwen Aker

I'm not Alright.

Aisling

I'm not sure how I feel about being a flag.

Corey HamCorey Ham

Alright. Thanks everyone for coming. We'll see you all next week and bye bye.

Ralph MayRalph May

Bye bye.

Corey HamCorey Ham

Bye bye.

Transcript source: Provided by creator in RSS feed: download file
For the best experience, listen in Metacast app for iOS or Android