¶ PreShow Banter™ — Watch Out for the Brownies
Research into that.
Which one? The browser one?
Yeah. Yeah. Just about, like, what I could get from a
A browser?
A browser. Right?
It's a lot, but it's also not a lot. You know what I mean? It's like it's like on I don't know. It's one of On those some level, it's not that sensitive that you're using, you know, the Grammarly add on or whatever. But at scale
I was joking.
At scale
That's where I was
gonna go.
Yeah. As soon as you get, like, the big enough, then then you
can sell it. Right? Like Yeah. You can sell it. You can say, oh, I can tell you exactly who what other, like, you know, one password. By the way, you also use your you also use Bitwarden. Or like Yeah. Did you know 70% of your users also have a VPN app? Or I don't know. Something like that. You know? Like, I don't know. Something there's so many insights you could gain, for sure.
Yeah. I think that was really what I kinda came from that. Right? But
Alright. So there's
It's $4.20. Let's smoke some weed.
Yeah. It's getting so high. We're never gonna come back. Like
Or actually take an edible because who smokes weed these days, and we have all this technology at our
Isn't that edible, like, twice as potent, though?
Oh, no. It just depends.
No. No. No. Depends.
It You can get it. There's no going back. That is the downside of an edible. Once once you commit, you're you're You're you're there
for the ride.
Let's sit set up.
Y'all are
crazy talking
about this on record.
I wish it was six hours. No. It can be up to, like, forty eight hours if you do bad badly enough.
Forty eight hours? What the
Yeah. Yeah.
If if
you if it takes you forty eight hours to come down off of a high like that, you've eaten Well,
they make some more than you Trust should me. The so the thing about this culture is that it's a high tolerance building drug. And so the people who actually are chronic users need these absurd doses
Oh my gosh.
Of edibles. And so if you're friends with someone who's a chronic user, and they offer you an edible, and it's like a fifty milligram edible, yeah, you're gonna be
gone That for a would knock me out Yes. For
You're gonna be gone for a while, and you can't come back. Yeah. It depends it also depends on people's metabolisms and stuff. But yeah.
When it when it comes to chemical uptake, inhalation is always the fastest. Liquid is faster. Solid will take a little bit longer, and
almost the true fastest.
Yeah. Oh. Yeah. Know, wasn't gonna go there, but, hey. It's you, Ham. It's you, Corey.
I gotcha. I'll go there.
I know. We we know that's how that's Corey gets gets stuff done fast. Right?
That's it. That's all I have to do.
The AI summary is gonna be like, this is now for adults only. Exactly.
Speaking of speaking of big companies wanting to moderate this at this point, they're definitely putting us in the MA, mature audience only category.
On yeah. I I I still can't get over it. I mean, I grew up in the day when it was the the the devil's lettuce, whatever, and and walking into a dispensary and being able to legally buy stuff is still a trip.
Yeah. Is a dispensary walking distance from my house, and it's across the street from the police shooting range.
That's not
way to keep people mellow when they're using firearms.
I mean, I live in Portland, which is like the most drug focused city that I it's like the greenest city known to man. Yeah. There's like billboard ads that are so funny. They're just like, know, nineties fonts, and they're just like, good weed. There's like no other context.
There's I I gotta say though, there's like no differentiating. I like, from my perspective, there's no differentiate I I can't don't know if anyone else can tell the difference, but I'm like, okay. There's, like, 17,000 variants of the same. I don't know.
So to those of you who participate, happy four twenty. And for those of you who don't, just watch out for the brownies. Okay?
Stay home. Don't drive. It's the same stay home. Don't go anywhere. Don't try to operate under the influence. Definitely don't use cobalt strike under the influence. It's basically impossible.
Yes. Pretty much.
¶ Tim Cook Announces Apple CEO Exit - 2026-04-20
Wow. That's a first.
Am I the only one who didn't hear the awesome metal music?
No. I If didn't
hear you're an audio listener, pretend like there was a really cool metal intro done by Bo himself. Alright.
I don't know if
they Welcome. Heard It's April 2026. This is Black Hills Information Security's talking about news. I don't remember how to podcast now that I didn't hear the intro, so I am confused on
how They heard the music. They heard the music.
I'm glad. Glad.
Anyway That's what's important if they hear the music.
That's more important
than if we do.
Well, that's all that matters. So today, we've got we're living in a post mythos world here, people. So everyone get your CVEs ready. Get your CVSS scores. Add one to them, as John said last week. And we're gonna talk about the Vercel breach. We're gonna talk about webinar TV scraping Zoom recordings. Mhmm. We're gonna talk about cookies, all kinds of cookies. And if you're here for 04:20, you know what kind
of And cookies we're about to talk
I think, I don't know, just some fun some fun things happening. So I guess let's start with Vercel. It seems like the highest profile thing. Wade, you said you've been working this one, just in it. Is it is it bad?
¶ Story # 1: Vercel April 2026 security incident
How bad is it?
Just throw me out there. Gosh. No. Like, we weren't affected. I don't know if I'm allowed to say that on stream. But Well,
I think you just did.
Okay. More
importantly Yeah.
What what is Vercel? Wade, what is Vercel? Dude. What does it do?
Yeah. That that's what took me a while to figure out too. I think Ralph knows about Vercel better than I than I do. No. But I do know secrets can be stored in Vercel, and secrets now must be rotated that we're in Vercel. There was a flag in Vercel that said if it was sensitive, you were cool. If it wasn't sensitive, you weren't cool. You needed enterprise level Vercel in order to have logging, which is a recent thing.
So Oh,
wait. Vercel is a cloud AI company.
Well, no. Hold hold on. No. Go on.
So everyone's a cloud AI company according to them. Okay.
Yes. Bronwen, you are correct. Everyone is a cloud AI company. 100%.
Well no. No. I went to vercel.com, and right away, it says, build in
the Okay.
Okay. But that's the cloud.
Come on. That's the same thing it says on allbirdsshoes.com. Anyway.
I knew we do it. Only because they they shifted over from shoes to AI, which makes no sense whatsoever.
Wait till Skechers does it too.
What what Vercel is is essentially, it's a hosting service for front end
Platform as a service?
Yeah. Yeah, right. They're hosting service for front end frameworks. Right? So if you have a website, and you wanna you could host it on Vercel. We personally use Vercel for my front end. Right? So they host the front end of the website, and then the back end, which is the API, is hosted totally somewhere else. Right? So when you now, that's not how everyone does it.
If you have a node based application, you could have the front end and the back end and the same application, and Vercel will gladly host that for you, as well as many other services that can do that, including Cloudflare, just to mention a few. But Vercel is one of the most popular for doing it. There's also a couple other ones out there that are pretty popular for these deployments. But where the security side comes in is that you can obviously upload environment variables. Now those environment variables can be used within your front end application.
They can be used within your back end application, however, you know, it it pieces in there. Vercel does more than just website hosting, if that I'm like using air quotes here because it's a bit more complex, but they also do a lot of other things. But the idea is is that when you do deploy one of these web applications or one of these web frameworks, that you're probably gonna have some environment variables that you wanna access in real time. And if you didn't mark them as secret, then they could have been exposed in this particular breach according to Vercel.
So sensitive is technically what they say, not secret. But yeah, basically, it does enough, on the write up, says that it originated from the compromise of context.ai, a third party AI tool used by a Vercel employee. So this is like that AI supply chain thing that everyone's paranoid about, rightfully so, is if you use these sketchy third party AIs Does anyone know anything about context.ai? Is this just like some random is this reputable, or is it like if you just go on the Google Chrome extension store and search AI,
it's like the third result, So like so this it's gonna loop it's gonna it's gonna work back to one of our favorite things. But so context.a I got got hit. They then pivoted to that user who then they escalated privileges via Google Workspace, and then were able to do stuff. Right? If you go look at some Steeler logs, and there's some context AI creds that got taken a picture of. Yeah. So there's a couple pictures of that. Yeah. So also could be
Next. Js, I guess. I I mean, who knows? There's been so many supply chain type compromises. So it's a reputable company, but they aren't appropriately doing AI, or they aren't appropriately doing credential management stuff with Infosecalers.
It looks like Hudson Rock actually said that, like, they're which if for those who don't know, Hudson Rock is a commercial Infosecaler provider, similar to Flair. It looks like they actually said publicly that, you know, they they think it was Steeler. Somehow, Roblox Autopharm scripts. So it's like, okay, here's the supply chain. An employee at complexity.ai was apparently doing Roblox hacking on his work machine.
Bro, man. On his home computer. On his home computer with his credentials synced. So that's bad. We have the employee at Vercel was using complexity.
Or context.ai, which I guess is that was he or were they allowed to be doing that? We don't know. But my assumption is most companies that are small, and Vercel's probably small, aren't really controlling what third party AI tools people employees are using, and that it has supply chain risk associated with it. So Yeah. If you're a CISO listening to this, don't let your employees install whatever AI tools they want, no matter how much they beg, scream, and cry.
If and then if you're working this as an IR person, they do allow you to pull down logs for ninety days in the CSV, all the audit logs, and then Good you can work it from old good old grep.
Good old grep. You gotta wait up those logs
if you are. You're gonna put environment variables, save them as sensitive, make sure you're marking any, like, key as sensitive or secure, or whatever they call them. Yeah. Every platform has got different ones.
Don't use environment variables. Don't do it. Yeah. There's tools out there. People have been asking me this question a lot.
They're basically like, okay, so when you use You have to use environment variables sometimes. There's a lot of cases where they make sense. But basically, in security, we deal with the trust boundary. Environment variables are only good on one computer for one trust like, that is like, everyone on the computer can now read those environment variables. So if there's any untrusted programs running on that same computer, they're compromised.
Right? Like, you just have to keep that in mind, and you don't put sensitive things in environment variables wherever you possibly can. There's tools like 1Password, and other secrets managers that can dynamically pull credentials from without storing them in environment variables.
Yes. So I I wanna push back on that, because there's a couple things that when you actually implement that, you still have to have that key somewhere on the host in an environment variable, even with one password or whatever you want. Right? You could dynamically pull them all you want. The the the hope or the benefit is that you can rotate them. That's really more important.
You can rotate them, and you can audit who's accessed them, by the way. Yeah. Well,
somewhat, yes. But either way, the the the idea that if I have all of my secrets in a password manager,
that That they can't be compromised?
That they can't be compromised. That's not not to to I'm pushing back on the idea that environment variables are the only Are inherently bad.
Yeah, no.
They're bad.
They're not inherently But
the better ways to do it, right, where you are actually do implement, because I've had to think about this in process flow, about like using one password to pull environment variables in to keep it the most sensitive as possible. The thing is is that key for one password does have to exist somewhere on that remote host
Yeah.
The process. Yeah. Programmatic access, you have to facilitate somehow.
And that key is gonna get have to get scoped to the specific amount of variables that are required, just the minimum required for that application. Well, if as an attacker, I have access to that key, I totally can retrieve those variables on demand right from one password. Right? So it doesn't necessarily stop that attack path, but what it does allow you to do, hope and benefit, is that you can revoke those faster without having to go into Vercel and change every damn one of those environment variables over and over again. Right?
It allows you to one click essentially rotate all your keys without having to go fight across all of your
Alright. Alright, Ralph. Doesn't Bitwarden or someone else have that too, okay? Just stop saying one password.
Well, actually, actually, so you if you wanna know what is kind of the real standard for this, it's actually HashiCorpVault. That's the one that most people use. Like, no offense to 1Password, but like, in most deployments, people are rolling their own HCB instances, or using Yeah.
Well, actually, so 1Password's offering is pretty good. They have actually have two different ways to access that. You can use CLI, and then they have a full API based setup where you can actually essentially like dole out a special server that would only be accessed through maybe a specific kind of network. So it's not even just through one password, and it has a whole token management system to allow you to kind of do a middle piece in there. So you can broker that access to one password, while not actually even exposing the interface that is required to access that key.
So I wanna know the record. Was And I hope that we cross. I I feel like we've I feel like we've crossed over into where Ralph knows more about 1Password than Wade does at this point.
Oh, without a doubt. Without a doubt. I definitely know OP, right? Like, I have it set up in several places, but, I'm over here defending things, not setting engineering up.
Yeah. Yeah. Totally care. Dude, if you ask me to run the socket BHIS, I don't know how the heck to do that. Someone else can figure that
out. Anyway.
Yeah. I think the from my perspective, the the IR, and Patterson, feel free to jump in here. Rolling secrets. This is gonna be the, like, number one most used IR playbook of 2026. Right? Like like, is there anything, any advice you'd have, Wade or Patterson, on how people can get in the practice of being better at rolling these secrets, and how like, is there any tips you guys have that could help, like, with this IR process?
Wow. That's a loaded question. Yeah. Make a plan before you before you're in the midst of crisis. That would be priority one.
That's such a sprawling, sort of unique snowflakey. I mean, listen to us argue about our process moments ago. My yeah. My most significant recommendation is I totally agree rotation of credentials is, you know, it's playbook I don't know, think last year maybe it was playbook number two, but I think you're right. It's the forthcoming, it'll be playbook number one, and sleuth out where your creds live, have a programmatic way to rotate them quickly and efficiently, and once you accomplish that, of course, you should test it, and then you're you're golden.
Well, you're not golden, but you're much better off.
Ready to react quickly, instead of just being like, what credentials were compromised? Where do they live? What do they do? If we roll them, how much of our production environment breaks?
Exactly. Yeah. That's that's the thing, right?
I was gonna say, lot of credentials are moving to to like a mandatory expiration date as well. Yes. So that you
can Everything should be. Honestly, that's like, that's a good thing you can set now before a breach happens, is just set everything to expire every three to six months, or whatever interval you choose, and then you have to get in the practice of rolling
Yeah. Them stuff You're gonna have to to out how to automate your way out of that.
Yeah. Exactly. Because, yeah, it's like, you know, if if you have users that are getting breached, which you do, and you have password expiration, you have MFA, and you have like you basically have to set yourself up in a place where, guess what? Your developers are putting your API keys into ChatGPT, into Anthropic, into Context AI, Cursor, freaking DeepSeek, whatever it is. And so you have to it's you're better off just assuming those credentials are breached all the time, monitoring them for suspicious activity, and rolling them on a regular basis, versus being like, no.
This is the secret break glass key that lives in the secret place, and no one can ever access it, like
Yeah. Yeah. Do think the playbook, a really good one, is to honestly just design rotation into your implementation, and I think you can really help yourself out, you know, when they do get exposed.
Yeah. Then if you're using the variables, right, it's easier to do that because all your passwords are gonna be in a centralized location, and usually you can you can interact with them programmatically, so.
Yeah. And also setting limited scopes, like basically secrets management is if you do it well, it's gonna be a pathway to the end of twenty twenty six without a whole lot of pwnage. If you do it poorly, you're gonna get popped. Like it's this is not the first, and it won't be the last where environment variables are leaked, and blah blah blah. There's all of other ways that environment variables can leak, by the way, or be exposed.
You know, we're talking about, like, browser harvesting, and program harvesting. Like, just assume any program running on your computer can read your environment variables. And there's a lot of programs running on your computer, and they so, like, just keep that in mind. Anytime you export something, it's
really This is the Steeler Logs playbook. Right? The, you know, NPM, valuable pack, malware packet, whatever, you know, but yeah, sure.
Totally. Alright. What else happened? I guess we can talk about a certain teenager who the guy who compromised PowerSchool. This is a breach we talked about when it happened, but there's this pretty interesting long article in ABC News about his experience, and I don't know.
¶ Story # 2: 'Addicted to hacking': Young hacker behind historic breach speaks out for 1st time, before reporting to prison
It's kind of like I feel like it's been a while since we've had these a high a big deep dive into the character of a hacker, and it's kind of interesting. I mean, we don't have to go through the whole article, but it's worth the read. I think it it basically, for me, really reiterates how much these online hacking communities impact these young kids. Right? Like, they basically take over their world and really suck them in and and make them think and feel that they're, you know, living a very glamorous, rewarding life, when in reality, they're just kind of the fall guy for a big cybercrime situation.
So this person, his name is what is it? Matt Lane?
Matthew.
So he yeah. So he's he he got sentenced to four years in prison, and basically, on his way to prison, I guess he'd already done six months, and this was a sentencing hearing. But essentially, he did an interview with ABC News kind of talking about what the life was like and what he did. And he sounds, at least in the article, he sounds very remorseful, and, you know, he's the kind of funny thing that which we'll talk about at the end is he's like, I hope I get a cybersecurity job. Maybe he will, maybe he won't.
I guess we'll see. Please submit your resume to BHIS, and we'll we'll interview you.
But The Darknet Diaries episode will be out shortly, I'm sure.
Yeah. Wait, really? No.
That's a guess. I'm get if he's willing to talk to ABC News, there's no That's fair. Yeah. Which unheard of. Like, usually, we don't hear like, this almost seems like a play for right? At least for me to to make him look good, which he he does seem honest and truthful, but you don't hear about this too often about them. No.
These are rare. These are super rare.
And then, like, it's just like we've talked about before in, like, in The UK. Right? These kid kids have been picked up over and over again, but they're they they keep it a secret and, like, hush Put identities?
And put
them away. Yeah. Identities completely, which is also pretty cool, I think. But without a doubt, he's gonna get a job. Like Yeah. And of course, where did he start? Roblox.
Roblox?
Roblox.
Yeah. I mean, I I think it's, I don't know. I I think it's really just a matter of people who feel like outsiders tend to look for communities where they fit in, regardless of whether it's cybersecurity, or, you know, terrorism, whatever. Pick a pick a It could be just a lot of people fall into sports, or into, you know, like, things that are more normal ways of fitting in, I guess. But in this case, you know, he got sucked into a community that was kind of pushing him in a bad way.
I mean, this is the same thing that happens for most kids who end up as criminals is they get sucked in with people who are older than them, and kind of take advantage of them in a lot of ways.
I I think one of the big differences in this case too is that most people typically don't get caught. Right? He was just used as a scapegoat. Or not a scapegoat, but essentially, like, a patsy in in this. Right? They just used him to to not get caught. Right? And so I think we're gonna see more
It's being made an example of Yeah.
Yeah. And I think we're gonna see more and more of this, though. Right? Because essentially what happens is is that MGM or whoever gets hacked. Right? MGM was mentioned in this article as well. Right? They want a lever to pull. They're not gonna go to, you know, North Korea to get it. So they're they're gonna take it out on The US assets that were used to leverage that attack. Right? And so I think we'll see
more of it. Right? It the one of the interesting kind of notes from this is like, the impact is definitely higher. So with the PowerSchool thing, we talked about it in the I I think on the show. Like, the there was an initial breach, and they actually did a ransom demand, and they got the ransom payment of $3,000,000.
But then there was another ransom demand sent So to all of the individual basically, like, in this scenario, someone gained access to whatever server they ex filled all the data to, you know, whether it was someone trusted or not, we don't know. But essentially, they got the data, a copy of the ransomware dataset. And so, you know, it's kind of a poster child for why you shouldn't pay the ransom because there's no guarantee that someone else hasn't accessed that data, and can use it to continue to extort, and do bad things. I mean, on some level, obviously, there's credibility lost. But it is kind of an interesting sort of subplot, is the fact that they unfortunately, other people, even if he has remorse and feels bad, other people have the data too and can continue to sort of drive impact from it.
Even if he doesn't wanna do that, other people still can. I mean, it looks like they're looking for someone else. You know, they're looking for other people in connection with these crimes in addition to him.
Yeah. The example piece too is to stop that from happening again, right, from other people being like, oh, think about this. But I will also flip the coin one more time, and just say that his age, right, being young and just impressionable and willing to do these things, I mean, people at a young age, including myself, have done stupid things that maybe you regret, or maybe it was just unsafe. Right? And this is one of those examples, you know, at a younger age taking taking advantage of people who are younger, you know, to to
Yeah. 15 year old.
Yeah. Like
Unfortunately. Yeah. When I was 15, you could've convinced me I didn't probably.
And unfortunately, Roblox has been a known resource for radicalizing young people, especially young males. And not just not just for hacking. It's it's used for radicalizing young men for all kinds of unfortunate and sometimes violent purposes. I mean Yeah. They only went into hacking. Yeah. He may get a career out of it someday when he gets out of prison. But
Yeah. They they talk about that in the news, in the ABC article too, that like, Roblox is basically there's a couple uplifting parts of the article. Like, one, there's a couple programs that actually go out and try to, you know, recruit people into a community that's, you know, fostering positive things instead of, you know, that's kinda similar to what our community does. Obviously, we don't go out and recruit people on Roblox, but there's something called the hacking games that's like, you know, basically Roblox based positive version of this community. The other thing that they mentioned is that Roblox specifically says they've hired several young people to help secure their systems after they participated in similar programs.
So like the, if you're out there listening to this or, you know, watching and reading the article, realize that there is a pathway to use your skills for good and to get paid for it. Right? Like, you know, you might get a job at Roblox. You might get a HackerOne bug bounty payout. Like, go the the
good resume bug bounty payouts.
Well, no. They're they're still doing payouts. They're just not taking submissions. So
Ah, okay.
Well, if they ever
But, yeah. When they resume well, you could still submit directly, but yeah, anyway, basically, the concept is there is a good and an evil version of this story. I think four years is fair to me. Like, that's like enough time that he'll definitely have, you know, hopefully, some time to think about what he did, but also not like ten years, which is just like a criminal graduate program where you just go and learn how to be a really good criminal. So I don't know.
We'll see what happens. But he does have $14,000,000 in restitution to pay to victims. So when he goes to get his first cybersecurity job, he'll be like, my salary demands are quite high because my restitution demands are also I quite gotta make $14,000,000 a month. Sorry. So we'll see how that goes.
Salary's kinda high, but, you know.
Salary's kinda high, but it's only one month, and then he goes back to prison.
Do you have to pay interest on that?
I'd probably, dude. I'm Right, assuming the I'm assuming the system is set up to completely block anyone from actually being reformed and just put them into a cycle of re a reinfracting early.
Does
bankruptcy apply here? Can, like does bankruptcy not apply to restitution? I don't know.
I don't know. I don't we need we
need get it under a different
These are adult questions, dude. This isn't that kind of show.
Isn't that kind of
show. Fair enough.
¶ Story # 3: Mythos And The CVSS Problem No One Wants to Talk About (But We Need To)
Alright, so next we can talk about Mythos. I mean, I don't know. For me, I guess we talked about it last week. I've still had a lot of customers asking me questions about it. John did a big LinkedIn post about it, which we'll link to if you guys, if anyone didn't see it.
But basically, it's kind of the sentiments that we echoed last week on the news. I think the answer to Mythos is basically twofold. One, it's definitely hype. It's it's, you know, there there is some hype tied into this. Anthropics trying to maintain their relevancy, and that's just part of this.
But also, piece number two is the some of the claims and things are real, and I've been telling customers, you have to assume something like this is is gonna exist in the next, you know, short future. We don't know when or how, but if they're basically advertising this capability, that means all the other AI companies are short are close behind. And that includes DeepSeek. Right? Like, what was the what was the distance between the, like, GPT four o release and DeepSeek release?
Like, does anyone know that off the top of their head? It was probably, like was it three months, six months? Yeah.
Like, I forget timeline's so small for all of them right now.
It's shorter than you think, basically, is what I've been telling clients. Like, this kind of a vulnerability crusher AI will exist in the next three to six months, and publicly so. So basically, get ready for that.
¶ Story # 4: Introducing Claude Opus 4.7
And So I guess the other follow on article to this is that Anthropic did release Opus 4.7, which
Yes. Has well, okay. So, yeah, the Opus four seven release is actually really interesting, specifically because Opus four seven now has specific gateways and gatekeeper stuff built in for cybersecurity abuse. Basically, Opus four six, you just told you were an authorized if you just told her you were an authorized pen tester, it'd be like, oh, alright. What are we doing?
Are we hacking China? Let's go. Yeah. Opus 4.7 supposedly has better, more gateways built in that will basically force you, hey, you know, this seems like you're doing something unauthorized, and it has its own verification model at the account level. So there's also Anthropic Drama where they're requiring identity verification for their accounts, which we don't I don't know if we have an article source for that.
Someone could probably find it. But they're requiring KYC verification for all their accounts. And in Opus four seven, you'll hit that limiter more often of it being like, hey, it seems like you're trying to do bad stuff. For us at Black Hills, if anyone's curious, you can get authorized. So you can basically tell Anthropic, here, we're a pen test company, we're authorized, and they will allow well, they'll take down those gateways.
But I feel like that's a pretty good way to reduce abuse. Obviously, it's kind of a moot point at this point because you could just use 46. Right? You could just be
like, alright.
And 46 is actually better in some ways, in some regards, but the point
is Yes. If if you go back up to the table, Meagan, it it shows technically, Opus four seven is actually worse for cybersecurity by like point 3%, or whatever. If you look, it says, there's one for, what is it, cybersecurity vulnerability reproduction. Yeah. Four six was 73.8, and four seven is 73.1. So it's point 7% worse.
Yeah. They did it on purpose. They nerfed it a little bit. I watched a bunch of people essentially digest the numbers here. But the one thing, going back to what you said, Corey, is that we are still on the continual march of improvement.
Yes. Numbers are
gonna
It's
gonna happen. And it's like, it's so fast, and that like, you know, when is, you know, I keep thinking about like, when is Opus five point o gonna come out? And like honestly, it could be four months, and that could be like, on the extreme version of it, and ChatGPT could come out with something even faster, and you know, that yeah. So it just keeps going. It's like a steady march.
I do wanna say one last thing though about the essentially, the gatekeeping of cybersecurity. OpenAI was a lot worse. Like, you asked it to do something, it'd be like, no, I can't do that. I can't do that. Like it really gate kept a lot more than Anthropic, and now Anthropic's kind of catching up.
Even though arguably, sometimes it gets super annoying, even if you're not trying to do something malicious, right? Just kinda do something related, eventually it gets to the point where it's just like, I'm gonna not help you with this stuff. And you know what's gonna happen in that case? Models are gonna show up that will help you with that.
Correct. There's gonna be obliterated models, and hugging face models, and deep seek, and mistral, and all these other quen, and there's Chinese There's
no way but my point is, and it is that there's no way Anthropic or OpenAI, no matter how great their frontier model is, is going to stop what is coming. Right?
Yes. A 100%.
They are just upfront. That's all.
¶ Story # 4b: Identity verification on Claude
Yeah. No. A 100%. I I link to the verification program if anyone's curious in Discord, and the next article we can kinda dovetail in is the KYC verification, Anthropix requiring this. It's not super clear when they're gonna start requiring this or what the rollout's gonna look like.
They they basically just posted this, and now everyone's salty. But essentially, the bummer here is that they're gonna use Persona, which is a company that has taken on a lot of investment from Palantir and Peter Thiel and those sorts of shady folks. And Persona has also had issues with cybersecurity in the past. I will say, I think the issues they've had are very overblown. Like, people's concern like, you know, they they had some issues with them exposing the source code, I believe, for one of their government identity verification systems, and like the way that the authentication worked and stuff.
To my knowledge, they haven't actually had any exposure of like the identities themselves yet. And it should be noted that this company persona is also they seem to be kind of the standard in Silicon Valley. That's what Discord is using. That seems to be what most companies are using. So it's not really out of band. Also, the way, OpenAI is doing this too.
Yeah.
If our parents are, you know, if our parents are OpenAI and Anthropic, they're both doing it, and so we probably just have to roll with it.
I would say get ready for KYC across the whole Internet. It seems like Yeah. That stuff is coming across different pieces, different different market, and and mainly different laws, right, in different states. It's all kind
of moving that direction, and most of these companies, they're in a business, shocker, to make money. If KYC is what they have to do to stay
in business, that's what they're gonna do. Right?
It's just a huge bummer that we can't have a government backed Yeah. Like, actual state run KYC that uses the like, they already have my passport, dude. I already, like, you know, answered a bunch of questions, and gave my fingerprints away, and some guy touched my butt. No. I'm just kidding. But, yeah. I'm already a US citizen.
Was my fingerprint, man. I don't need that.
Well, listen, okay, I went to an appointment, and I'm like, whatever happened happened.
It way cheaper than normal. That's what I said.
Yes. Was discounted.
Now we know a
it's a benefit of my credit card. Alright? Yeah. Yeah. Basically Yeah. Mean, the point is the government already knows who I am, has my identification documents. Yeah. Yeah. Like, can they not just give me, like, an SSH public key or whatever?
Yeah. That's that right? Like, some private private public key system, or, why why hasn't there any been any blockchain? Like, blockchain technology behind it is pretty cool and can track things. Why aren't we using that in, like, more production?
It's a bummer. Does that
make sense? An AI. That would be perfect.
Dude, let's Are we about to make a company again? Another one? No.
No. No. We've already we've already made one company. We don't need to make another. I'm bad. The I think, like, there are countries, what is it? Estonia, I wanna say off the top of my head, that has a full digital identity system that's nationalized, and has voting based on that system. I don't know. It's one of these small countries that you've never heard of, but they have 10 gig Internet and really good tech. I don't know.
It's easier to do at a smaller scale. I mean
Totally.
They Yeah. And they probably have a lot fewer than, what, 360 or 400,000,000 citizens, whatever we're up to these days.
Yeah. I I mean, you're not wrong, but still, that arguably also means we have immense amounts of resources available to create systems like this.
Yeah. If we if we have the will. Yeah. That's We
got break.
That's the bottom line. You know? But Breaking news. News. Breaking news.
¶ Story # 5: Tim Cook to become Apple Executive Chairman John Ternus to become Apple CEO
We got Tim Apple stepping down at Apple, so now he's just changing his name to what? Tim? Tim. What? Tim Apple stepping stepping down after more than a decade. It's probably because he asked Siri whether he should leave, and she was like, yes, leave.
Yeah. She was she was don't let the door hit you in the ass on the way out.
Honestly, so word on the street
is they're finally gonna come out with a new Siri this year.
I mean, okay.
That's just powered by ChatGPT?
Yeah. Yeah. So the the well, no. No. No. So, okay. Hold on. Hold on. So first of all, for those that have been living under a rock, it does seem that he's we don't know, but Apple hasn't been doing super well in AI to the point that I know of several people in my personal life who have seriously considered switching to Android just because of how bad Siri is. And that's totally valid and fair. Hold on, Sam. And he's been unable to correct that. Would you say wrong?
Not not to not to not to say that what everything you said about Suri is not correct, because all of those things are correct.
Is Alexa just as bad, or is Yeah. It It's worse. It's like worse. It's
worse? Yes. And they came out
with an AI version, and and whatever. Right? I I think it's it's tough for the non AI to like, companies that came out with those original, like, voice assistants to like, have to move into it.
They just pushed Gemini to Google, or to the audio, whatever, auto, Google Auto.
Oh, yeah.
And it could not play any of my songs. I was like, Alexa or Google, play Toy Story storyteller on YouTube as I'm driving, and then it plays, like, some random thing, and I'm like, over and over again, I'm like, you know what? I'm just gonna do this myself, and hopefully don't get in a car crash. But
Yeah. Well, okay. So and by the way, before, you know, obviously, we haven't even read the whole article about Tim Apple stepping down, but they did actually partner with Google. That's who they chose as their AI partner. So in iOS 26, which was last year's release, they have ChatGPT integration.
And as an iPhone user, I always use it, but it also ties not in it doesn't tie into anything. But every time I use it, I'm like, ask ChatGPT basic question, and it can answer it. That's as far integrated as it is. It that it's pretty lame. So they did partner with Google to get a Gemini model to basically, hopefully correct some of the issues they have. Who's John Turnis? That's the person they chose as the replacement. Or Ternis? I don't know how to pronounce that.
You Google him, he says he's an engineer and an executive, which
So he's VP of hardware engineering, and then
he's Which asking sounds pretty cool, to tell you the truth. Like, if someone were to shave
I will say, their hardware might be their strongest department, honestly. Yeah. Like, the you you really if you're comparing the iPhone hardware to other companies, that's what everyone sets the bar at, is like the actual physical characteristics. And if you look at the laptops, it's kinda the same thing. They were super pioneering when it came to the Apple silicon stuff, so I think it's a reasonable
They're so so just to just to put it out, so AI is cool and awesome, but the hardware is how we interface with it, and Apple definitely dominates that market space, especially from the handheld. They're overfitting
Oh, yeah.
In The US, and all this other fun stuff. So they're not going anywhere anytime soon, regardless of how crappy Suri is, or maybe that it it proves to be. But, yeah, they're they're definitely a dominant piece in the glass that we get to see. Right?
Totally. Yeah. And that's not gonna change. I think
Yep.
There was an interesting video the other week about like, how Windows laptops are kind of in a weird spot right now, where like, you have Windows, which is Microsoft, then you have like Copilot, is also Microsoft, and then you have like a bunch of laptop manufacturers that have to figure out how to work with Copilot and Microsoft, or else they're not really included in the whole party these days, because like, Windows now requires you to have all these Copilot ties. You have to have a Copilot keyboard. You have to have a Copilot button on your keyboard. So basically You have a Windows computer? Yeah.
Just to be a Windows computer. So like, basically, for a Windows laptop to be really good, all these companies have to work together and do well. For an Apple laptop to be good, it just has to be one product from one company. So I don't know. We'll see.
¶ Story # 6: Microsoft faces fresh Windows Recall security concerns
While we're speaking about Windows, we can talk about new concerns with cybersecurity around Windows Recall, which for those that don't know
Is the coolest feature they ever added. Can't Yeah.
Well, so Recall so Recall was a really cool feature that was designed, like, with the release. Was it Windows 11? Yeah. Or Windows Yeah.
It was like in it was supposed to be in one of the updates for Windows 11 because This
is years ago. Yeah. Years ago. This is September 2024. Wow, that feels like ten years ago in It the world of
does.
That was it does. So long ago. But basically, it was a feature that would essentially record your screen and let you go back to a All previous time. Yeah. All the time. So as you could imagine, they rolled it
in an
incredibly insecure fashion at first, and everyone was like, please no. Can you not do that? And there was a, you know, people were publishing tools that would extract all the data from it. It was a fun little time. And now, I guess, they're trying to re release it, I I assume, and not all the security vulnerabilities have been fixed. That's my assumption.
What about the whole thing being just one big vulnerability? Like That's not like everything that I'm sending it off to I don't
know who. Like, who would use this? Who's the primary user of this? That one person who's screen like
and let chatty p t look at it too.
Bro, maybe that's it. Maybe it's from the AI perspective that the AI destroyed your laptop so much that you gotta re recall back to a time beforehand.
Like the new version of Windows restore? It's just one prompt. It's an AI prompt that restores all the files. It's just a markdown file that says, this file lives here. This file lives here.
I I don't even know anyone who uses backups personally, like, in their personal setups. Like
Who use backups?
I will not I don't know any
data. I don't backups.
I don't know any, like, non techy people will say that. Like, normal well, normies.
Right? That's fair. See I
anyone people. I can't see anyone using this. And then from a corporate perspective, like, understand it. I'm wondering if this could be used forensically. But Yeah. Why you wouldn't need it. Right? It could, but, like, would you even need it if you if you have access to it?
Would you forensicator, would think not.
I don't think you would need it, though. You would just, like, run your normal, like encase or anything to pull everything off of it. You wouldn't have to use recall. So I'm thinking
I mean, it is it could give you a ton of insight into like, it's basically a screen recording of everything the user was doing. Right? So it could give you way more insights than any of those forensic Oh, yeah.
Flat out. That use
They say recalled stores, messages, things on your screen, emails, documents, browser history. If you're using the computer and you got recall on it, it's recording everything.
With the right DLP software, though. Like, I have all that too. That's the thing.
It just that's fair. But, like, I I think the biggest thing is just this no one asked for this. No one actually needs this.
No one wanted this.
Like, okay. Right now, everyone's fighting the battle of all their employees want AI, and they have to figure out how to get AI into their company without screwing up security. No one of their employees are like, can I get Microsoft Recall? One My wants
my favorite use of this is when someone calls in and says their mouse was moving by itself, and I'm like, alright, let's go check it out in Recall, and be like, no, it's not moving. You're moving. We can see it like like that.
Your use for it is just proving people are dumb? Oh. There's way better tools for that, man.
Yeah. But if it's a recording, we could prove
it to them. Don't move my icons. That's exactly how I like it.
Move my icon. That's an oldie. An oldie but a goodie. Yeah. Speaking of creepy recording of things that shouldn't be recorded, four zero four Media published an article about this company called Webinar TV, which their MO, and this is just as a business model, insanely creepy.
¶ Story # 7: WebinarTV Secretly Scraped Zoom Meetings of Anonymous Recovery Programs
Their MO is to enter publicly accessible Zooms using a bot, and then record them and transcribe them. For whatever reason, they're doing this at scale. I don't think anyone really knows why. The the article doesn't really cover why. I I can't really imagine why. But here it is.
Mhmm.
Basically, of course, because public Zooms are public, some of the information in there probably shouldn't be public. And, you know, they give some examples in the article like Graves' Disease and Thyroid Foundation patients, support groups for, like, of the funny ones is like nudist support group. It's like, oh, I have to wear clothes, guys. It sucks. Like, it's recording this data.
It's not super clear why it is, but it's claims that they've hosted over 200,000 webinars. I don't really know what their business model is, but it feels like from a privacy perspective, do they have any lawyers that have ever even thought about this for more than ten seconds? Like, I cannot imagine the amount of PHI and PII. I mean, I think the biggest thing is, if you're going to some of these webinars, just assume it is, you know, being recorded Yeah. By someone, change your name to something anonymous, maybe hide your face, or don't show yourself on camera.
I don't know. Or just it sucks because it's like the companies that are putting on these webinars aren't really trying to do this. They're not trying to make it, you know, a cybersecurity problem, but they are. Yeah. And so yeah.
Then basically, they're also, interestingly enough, the the webinar will actually like register. They they can register, or they they have people that are registering for these sorts of things, and like actually submitting like forms and things to get into some of these webinars. So it's like, I don't know, it's basically super creepy. I don't know what this company is, but I
think that maybe they're pulling all the data to feed AI.
Well, okay. That's not I never thought. One of the things covered in the article too is that some of these public meetings or or publicly listed meetings are things like recovery groups or face faith based conversations. They kind of have to be public in order to serve the population they're trying to reach, which is like, if it's if it's a 12 step group, that's always been an open meeting format. It's always been anybody can show up.
Why would it be any different in a digital form than it is in a physical form? So with webinar TV going and scraping all of this stuff, yeah, this is a huge deal. And, you know, who thought this was a good idea? The only thing the only I can figure in terms of how they're making money is by advertising.
Advertising or, like you said, selling the data to AI. Right? It's like that it it it's at the end of the day, this is data mining. Like, that's basically what this company does. Yeah.
On some level, like, you could argue, oh, it's YouTube, but it's like, it's not YouTube because none of these people the goal of this meeting wasn't to create content. Like, that's not, you know, that that's not how it works. People were just going to the meeting to be at a meeting, not to create content for someone else. So I don't know how this is legal. I don't know where they're based.
I hope they go away. But on their website, there's 221,000 webinars and searching. I did search for Black Hills. I didn't see any Infosec. Like, they haven't been in ours. They're not they're not in with us right now that I know of.
No. Not in
I'm looking around. Yeah, if you if you do a free webinar, definitely kick these kick these bots out. Free is not free. Free is not free. So we're kinda we're kinda quick firing, but the cookie article is pretty interesting.
¶ Story # 8: Google, Microsoft, Meta All Tracking You Even When You Opt Out, According to an Independent Audit
So this is an article, again, we're four zero four Media. Basically, a company called
I wasn't laughing at you, Corey. Sorry.
I was laughing at you. X-ray you can laugh at me. It's okay. Web X-ray published a report where they basically claimed that all the big tech companies are not enforcing cookie tracking properly. Essentially, the like, from a technical perspective, Google's you ask Google not to track you, and it's like, here's a cookie. I'm tracking you anyway, basically.
Have a cookie. You're gonna love it.
You don't want me to track you? Here you go. Have a cookie. And so essentially, all these companies have disputed. They're like, oh, no.
It's not. It's fine. It's totally tracking. I think the, you know, yeah, the GIFs and the results in the chat are basically exactly how we all felt before the show, which is basically like, are you telling me these big companies are potentially willing to take on fines just to track people because it's more valuable to just take the fines and, you know, get the data versus not ever getting the data? So, basically, we'll see how this plays out.
There are some pretty aggressive privacy laws in states like California that will lead to them incur incurring fines for this sort of behavior. But
Unfortunately, the fines are just a slap on the wrist for them. I mean, you know, what Google earns more than a $100,000 in interest in an hour. So even if it's multiple millions of dollars of fine, there's no incentive for them to stop their behavior. Yes. And they money.
They probably will. I mean, I'm not a lawyer, but I'm assuming they'll be able to hire fancy enough lawyers to get out of this one. And I'm assuming they already hired the lawyers before they did this to make sure they could get away with it before they actually did it, so they don't have to pay retroactive fines. Basically, this is specific to California, but essentially, there's different regulations for businesses versus service providers. Ad vendors like Google and Meta and other people, they contract as service providers, not as businesses, and so they're exempt from a lot of these privacy things, I guess.
But basically, again, kind of depressing and a lot of data mining I and got I got a good article. Well,
I was gonna say the good news is, France is ditching Windows for Linux.
Another one bites the dust, That alright. It's like it's like at least the fourth or fifth European country that's ditching windows, so that's funny. Alright. What you got, Wade?
¶ Story # 9: Little Caesars Wants ChatGPT to Order Your Pizza for You
What you have, Wade?
Alright. Alright.
You guys ready for prompt injection pizza ordering?
Oh. Yes. Ready, dude.
I remember this one. Go ahead.
Little Caesar Little Caesar's starting on the sixteenth. You can now order a pizza straight out of ChatGPT.
Nice. Oh,
no. I'm not saying this is a bad idea or a good idea, but, like, this is an idea for sure. So you can just you can have it order you whatever you want. We recognize this the the the the comment from the executive is great. Today's consumers are turning to Gen AI as part of how they search for everything, including where they get their next meal.
Okay. So I can see it now. OpenAI is gonna buy Grubhub.
We are the joke is, does this does it come with glue? Does the pizza come with glue? Who
is it? Wendy's? Wendy's little chatbot? I guess it uses Anthropic, and people were were injecting in it to get it to do other tasks, write code for it, all kinds of other fun stuff.
Using Sir, this is a Wendy's, but that being said, I will code you a full year from Punch to Labs.
Exactly. But, totally, let me let me take on that task that you've given me here.
You know, you wait for your
food, let's help build that website.
I I wanna I just wanna prompt and just see if I can get free coupon codes, or other things Like, like fake a scenario that was really bad, and see if they give you a coupon code.
Be like, you won't believe this. It was late again. It didn't make it.
Was late again. I need another, like, free order of this, you know? Yes.
I feel like you're gonna have to wave through a lot of agreements before you actually buy anything. Like No. Let's see.
Let's see right now. I'm gonna buy a $5 Hot and Ready. Are they still $5? I don't know.
In Not in this economy either.
Those were the days. I mean, you couldn't drive there for less than $5 in gas, man.
That's probably true.
So, Chet, you wait till order hot
California. We're gonna order some drunken pizza, and he'll It's get back starting. To It's looking. Little Caesar's $5 Hot and and Ready. Yeah. They're not $5 anymore.
Oh,
So couple other quick fire articles before we close. There's a lot of articles today. NIST published a blog or like a news update that they're basically going to start enriching, I don't really know what that means, but enriching certain CVEs, and I'm assuming the reading between the lines part of this is not enriching most CVEs. So essentially, they're basically saying, we get so many submissions for our CVE database that we can't handle updates and tracking on all of them. And so basically what they're saying here, and this is my interpretation, I could be wrong, is that they are essentially choosing a select subset of CVEs to kind of track and update and and actually keep track of, and other CVEs will not be as enriched as they previously would have been.
¶ Story # 10: NIST Updates NVD Operations to Address Record CVE Growth
So the gateways they're using for this are CISA's KEV catalog, CVEs for software used within the federal government, which is, you know, probably a lot more than you would think, but not as many as, you know, random Joomla CVEs or whatever. And then also CISA or sorry, CVEs for critical software as defined by an executive order. So basically, it's kind of a bummer in a way that, like, they're basically they're kind of waving the flag that hacker one did, which is like, there's too many CVEs. We can't handle them all. So basically, I guess the the other reading between the lines here is if you're a if you're a security researcher, I mean, you want a CVE to put on your resume or for whatever other purpose, you should probably focus on the software that is in this list that's, like, that's used within the government, that is in the CISA KV catalog, and is, you know, software, important critical software.
Well, okay. They go ahead. No. It's all you.
Oh, I I was gonna say, I mean, according to this article, they're saying that the CVE submissions increased by 263% between 2020 and 2025. That's gotta be directly related to AI implementation. Definitely.
Yeah.
And, you know, that's even even before AI, the the CBE system was struggling because we don't really have the kind of support for analyzing and patching problems. And we we mentioned last week about how, you know, HackerOne had the bug bounty program, but do we have a remediation bounty program? And we don't. So but the the combination of this, yeah, this sorry. This sucks. I don't have a positive spin on this.
It's kind of a bummer of a week.
The remediation bounty is you gotta have a job, and you don't The get
bounty honestly, though, I feel like cybersecurity was, like, such a wave to be riding for the last, like, ten years. And then I feel like in the last couple years, it kinda slowed down, where we were like, nah. AI's gonna replace everyone. And I feel like my hope is that this year, that really swings back in the other direction, and everyone's like, never mind. AI's just creating problems, and we need to find people to solve those problems, like, now, or actually more like yesterday.
Yeah. So it's it's like, okay. Great. It's a nice idea that all of these AIs can can possibly replace cybersecurity experts, but the reality is that the increased influx of exploits and and the increased accessibility of being able to attack systems has wiped out any net gain that would have been received. Patterson, you could speak to this better than I can because you're seeing how it's hitting our SOC services already.
Whatever it is that these companies think that they're gonna save by firing all of their cybersecurity people, I'm gonna I'm just gonna say it out loud. I think they're idiots because there's no way possible that AI as it exists today can can ever address all of the things that face any organization that has a profile that could possibly be attacked by malicious actors. And if you're cutting your people and you're thinking that an AI can do it, well, AIs are great at tasks, but you need people, human butts in seats, who are doing jobs to organize and coordinate those tasks because there's too much.
Know, Bronwen. I think Yeah.
We're gonna develop it tomorrow.
I think you're way off, Bronwen. I have an AI that'll solve all the problems by just deleting the whole company. Yeah. It's easy. You could solve all cybersecurity problems.
That that is one solution. Yeah. You know? Unplugging and living under a rock is another solution.
I I mean, I totally agree with you. I think the the key thing that's still, at least as of today, is still true is that AI's gonna do something. Some things are gonna be smart, and some things are gonna be incredibly dumb. And you need someone skilled to to make the decision about which is which.
They're like drunk interns. They have really good hits and really bad misses, but you've gotta supervise them, and that's what you need the humans for. I also think and and I was thinking about this because I I wound up talking to a lot of of friends over the weekend about AI and prompt engineering and where things are going. And I think that in the long run, we're going to be seeing the ability to work with AI, prompt engineering, machine learning, data science, all of those things. These are going to be not just nice to have skills.
They're going to be required skills in Yeah.
Don't need to set up security, but in their minds. It's like the same thing as putting Microsoft Office on your resume. It's like it's not really getting you anywhere, but, like, you do need to know it. Like, that that really
is table
It's table stakes. A 100%. That's a good point. Alright. So let's do our plugs real quick before we close. Patterson has an upcoming wait. What do you got to plug
the if you scroll to the bottom of the news, there are all the plugs
there. Read.
Alright. So here's the poems. That's not the
kind of thing you want to admit in public, Corey.
¶ Workshop: Rapid Endpoint Investigations for Linux and Mac
Come on. Is teaching a pay what you can workshop next week, rapid endpoint investigations for Linux and Mac. Important in the world of supply chains and developers and all these people getting compromised using AI tools they weren't supposed to be using. Patterson, do you have any other things you wanna plug about it? That's pretty exciting.
That was an excellent summary. Yeah. Super excited about it. Webcast this week on the subject for our pay what you can workshop next week. Just practical practical tactical skills for Linux and Mac investigations. So love to see you there.
Nice. That's exciting. Yeah. I mean, we we've increasingly seen more and more clients asking us to do RedTeams on Mac and not so much on Linux. I'm assuming Linux is more like server based stuff, not endpoints, but or I guess it does say NICS endpoints. So for those Linux people out there, you can really probably harden your system a lot by following the onboarding.
Some French should be doing some clients on Linux too real soon.
Oh, good point. If you wanna Hey. If you're doing government work in Europe, you're gonna need to know Linux endpoints in the next, like, very shortly.
Oh, yeah.
¶ Cyber Threat Intelligence 101 2 Day Version
And then, Wade, you also have a workshop coming up not until May, but you're profiling Know Your Enemy.
Meagan, have
a talk.
What are you talking about?
Yeah. I have a talk and a workshop. I don't I don't remember when the talk was. It's on the calendar, but the talk is like how to read the news, which I find
Oh, I I definitely
should go to that.
You should well, you you should if you wanna guest star in it, because I know you you can I can't read secretly
come in
and we can just argue and yell at things? Then, yeah, I have No. That's for Ralph and I. Do have the the $25 workshop on threat actor profiling. That is a full four four hours, which will be super fun. And then I am teaching at the threat hunting summit. My CTI one zero one class, but now it's two days instead of one Yes.
So twice the value?
Twice twice the fun, twice the value, I am sure. It'll be cool.
That's awesome.
Yeah.
It is crazy you can get some of this stuff for $25, or like, you know, even cheaper. That's insane. That's such a good deal. Also doing a webcast. Think it's next week, next Wednesday maybe.
¶ ANTI-CAST: How to Break Free from the Cybersecurity Burnout Trap w/ Natalia Samman
I'm not sure when it is, but I'm going on as a guest to Natalia's webcast, and we're gonna be talking about some burnout stuff. I did a burnout webcast when I first started at Black Hills back in 2021. If you go back and look at it, I didn't have a beard. I had short hair. Kinda terrible. Obviously, have to kinda re up the ante and get back in the modern world of burnout.
And there's a CTF where you have to find Corey's face in that photo.
Am I actually in there? No. I'm not in there, am I? Maybe I am.
I mean, that's that's the CTF, man.
That's the CTF. I'm the robot. Oh, no. Yeah. So see you all next Wednesday.
Not the walrus.
Hopefully not. Although, you never know. I'm just hoping it's not just like some kind of weird therapy thing where then I'm just like crying at the end of it. I'm like, I'm I'm so burned out. This is terrible.
We'll see. Look at the interview.
I might have to role play someone else. I'll role play Wade. I'll be like, I'm a new dad. I got terabytes of logs coming in. I can't wade through them all.
Dude, that that's me to a t. That's it. That's all you need to know. I mean, I
can't wade through
a I told you. You're not gonna sleep for the first two years.
Oh, no. I'm already sleeping. I'm fine. Babies already sleeping, like, six hour shifts. It's pretty nice.
I'll use that in my I'll use that in my That is my webcast.
I'll use that in my
I'll be like, nah. Sleep honestly, sleep is very important.
I I upgraded as a dad and got a garage fridge recently, and it's full of Red Bulls, so I'm I'm good to go.
You don't need that slow down. Sleep is just a garage. I have so
much sugar. I just honestly, I I got that
I'm Celsius too. The Celsius just make me feel weird. Like, I don't know. Don't know. Like
Yeah. Yeah. It's too much. I think Celsius is too much. That's for a person, like, I don't know. That's the thousand milligram edible of energy drinks. Yeah. Could Anyway. So I think that's all we got. Thanks all for coming. We'll see you next week. Have a good week.
Later, guys.
Bye bye. Bye bye.
