
Anthropic Warns Users of Infostealer Abuse - 2026-09-08
About this episode
AI agents take center stage as the team examines OpenAI models using a German forum for private communications, Anthropic’s response to a compromised Claude account, new model releases, and the growing demand for Apple hardware to train computer-using agents. The discussion also covers the sale of stolen driver’s licenses, a claimed Florida DMV breach, and vulnerabilities affecting JFrog Artifactory, Proxmox, Plex, and Langflow. Finally, the panel considers CISA’s decision to discontinue six cybersecurity assessment services, new research into compromising passkeys, and Outflank’s compact NTLMv1 rainbow tables.
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
- (00:00) - PreShow Banter™ — Internet Fall Weather
- (03:17) - Anthropic Warns Users of Infostealer Abuse - 2026-09-08
- (06:59) - OpenAI Agents Exploit a German Forum for Private Communications
- (17:18) - Anthropic Warns a User About Infostealer Abuse of Their Claude Account
- (23:32) - OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate
- (26:01) - CrowdStrike Releases AI Models Developed with NVIDIA
- (29:12) - FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses
- (32:41) - ShinyHunters Claims a Breach of the Florida DMV
- (35:19) - AI Labs Amass Mac Minis and Mac Studios for Agent Training
- (38:02) - Critical Authentication Bypass Disclosed in JFrog Artifactory
- (39:00) - Proxmox Vulnerability Exposes Internet-Facing Hosts
- (40:17) - New Plex Vulnerability Raises Home-Network Security Concerns
- (41:24) - Langflow Vulnerability Enables Unauthenticated Remote Code Execution
- (47:07) - Thomson Reuters Breach Disrupts State Court Systems
- (47:25) - CISA Cuts Six Free Cybersecurity Assessment Services
- (52:24) - New Research Demonstrates Ways to Compromise Passkeys
- (54:07) - Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool
- (56:02) - Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast
- (56:53) - PlexTrac’s AI-Assisted Reporting and Retesting
- (01:03:44) - Charles Shirer Introduces the FanMeyer Creator Platform
- (01:05:06) - Upcoming AI Browser Research and Wild West Hackin’ Fest Talk
- (01:05:49) - Hacking and Defending Satellite Infrastructure at Wild West
- (01:06:25) - Upcoming AI Core Skills Fundamentals Course
Links
OpenAI Agents Exploit a German Forum for Private Communications
Anthropic Warns a User About Infostealer Abuse of Their Claude Account
OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate
CrowdStrike Releases AI Models Developed with NVIDIA
FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses
ShinyHunters Claims a Breach of the Florida DMV
AI Labs Amass Mac Minis and Mac Studios for Agent Training
Critical Authentication Bypass Disclosed in JFrog Artifactory
Proxmox Vulnerability Exposes Internet-Facing Hosts
New Plex Vulnerability Raises Home-Network Security Concerns
Langflow Vulnerability Enables Unauthenticated Remote Code Execution
Thomson Reuters Breach Disrupts State Court Systems
CISA Cuts Six Free Cybersecurity Assessment Services
New Research Demonstrates Ways to Compromise Passkeys
Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool
Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast
Charles Shirer Introduces the FanMeyer Creator Platform
Upcoming AI Browser Research and Wild West Hackin’ Fest Talk
Hacking and Defending Satellite Infrastructure at Wild West
Creators & Guests
Click here to watch this episode on YouTube.
Click here to view the episode transcript.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec....
Get every episode summarized
Each time Talkin' Bout [Infosec] News publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
670 searchable segments. Every word is indexed and playable.
Full transcript
Talkin' Bout [Infosec] News — Anthropic Warns Users of Infostealer Abuse - 2026-09-08. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Hey, what up, BST? What is going on, everyone? How's it going, man? Hello, BST. Hello, hello. Hello. How's everything? Your beard's definitely not grayer than the last time I saw you. I swear. No, I know, I know, I know. I'm getting the gray beard. I'm doing the gray, I'm doing it for the fall. You have the gray beard. Come on, gray beard. Since before I even met you, you've always been a gray beard. I'm gray bearding it today. It's, you know, it's fall, pumpkin spice day, you know? Is it really? Is it, is it, is it? Yeah, I sort of pumpkin, I sort of pumpkin spice latte on the, um, it's official. Yeah, official. I'm going to get my puppy vest and my, uh, ung boots. I can't wait. I'm so excited. Oh, he said the ung boots. Oh, my goodness. Oh, it's a spices. Listen, it might be 80 degrees in sunny here, but I'm going to pretend like it's cold. All right. Look at that. You can't beat that at all. I'm going to pretend like I'm looking up super recipes, you know, all that good stuff.
I love it. That's, it's, it's nothing like internet, fall weather and pumpkin spice and uggs now, uggs and spices. I mean, I don't know. I feel like that's approved. I feel like I was the other thing last week. We got an instant pot. So, uh, I'm going to get a lot of experimentation with that. Instant pot. Yeah. I was, I, I mean, that's kind of like you're behind the times. You got to get an air fryer and then start air frying things that were never meant to be. Oh, my goodness. I have an air fryer. I have a bread maker. Oh, you already had it. Oh, okay. Yes. And bought his old food. He was compared to an air fryer. I know. Hey, there are some in the slow group. Okay. That's okay. And they tell you to buy it. It was like, you know what you should do. It's fine. Instant pot. Yeah, instant pots. Oh, we got the doggy with the hugged, pumpkin uggs, I think, hugs. Pugs, hugs. They show a smatchin' pie, pugs and hugs.
Yeah. That's right. October fest, and yeah, it's all caught. I love the fall. The fall. Yeah. It's a good time. Oh, my goodness. Oh, man. It's getting rough in the chat. They take no prisoners, man. No, no prisoners. Charles, are you going to come to Deadwood? I can't make Deadwood. I'm coming to February. The one in February. Yeah, Denver. Yeah, Denver. I've never been to the Denver one. So get out of the breath for a summer. I'm going to be out of breath. No, hi. I call it that for reasons. Yeah. Well, my mom. I get ready. Oh, we're ready. We're hot and ready. Like little Caesars. Look at that. Broom. Pizza. All right. I don't know. Right. I don't. I think we should just go without Ralph. I don't know if
he's coming. Let's just let's just roll the finger. Let's go. Hello, and welcome to Black Hills Information Securities. Talking about news. It's September. I'm scared. September 8th. It's Tuesday. This is the wrong day. If you got here, if you're outside the US, you might be confused why is it a Tuesday? It's because yesterday was Labor Day, which is a day where we don't do any labor, which is why it's called that, which makes sense. I guess. It's the owner of the laborers. It's an honor of the laborers. It's not called laborers day. But anyway, my name is Cory. I'm on the director of continuous pen testing here at Black Hills InfoSec. And I'm an amateur podcaster in addition to that. We also have Bronwyn, the director of looking at AI models, telling them they're ugly and then getting them to confirm that they're actually ugly and being
gas lit in the process. We also have Dan DeClaus, who is the founder of PlexTrack and then also associated with the company that has a queue in the name and not a U after it, which is just scary. Dan, do you want to introduce yourself real quick? Yeah. Thanks for having me. Some of you may may know me, but many may not. So Dan DeClaus founder of PlexTrack recently acquired by Brinca. So we are now called PlexTrack by Brinca. Excited for that. And we are, we help Pintest reporting lifecycle management and exposure management and all those things. But excited to be joining you on the on the show today. Awesome. And then last but not least, we got BSD bandit, the OG BSD user. He was actually the first one to ever compile the kernel from source. Now I just made that up. Oh my goodness. But I said, I said when I saw Charles today that you know his beard's looking a little grayer than usual, not to throw shade, but you know, honestly, he's been a he's been a gray beard since day one, like running BSD, adding things to it using NIM. Like I remember you talked about NIM a decade ago before anyone else thought about it. So good for you. Yeah. Yeah.
Yeah. Do you want to introduce yourself or do you want to just be BSD bandit? Hey, I am Charles Shira AKA the BSD bandit. We're going to call this turn it up Tuesday AKA terrific Tuesday. So at what a perfect day to have the news on a terrific Tuesday. Yes, I got the gray beard. But you know, it's also spirit. It's also fall. We got we talked about this earlier called hugs and hugs. So well, and amazing amazing. I love it. PSL forever man. Yes, I love a PSL. I think a PSL. I do think it's like I think of it as a mandatory annual tradition to get one of them. Have it and be like, holy crap. This is so sugar. And I paid $7 for it. And then not go back to Starbucks for another year. That's what I do personally, at least. You know, your mileage may vary. We also have Ralph who's hiding in the backstage. Oh, there he is. There he is. His mic isn't working. It's okay. You all know who Ralph is. I was just letting you do your whole intro thing. What's it? Tell us about this hat. There's nothing on it. It's just a, are you a black cat? I don't get.
That's better. No, I just I only buy generic hats. So okay. I see. All right. I don't believe you. But anyway, well, if you need no introduction, you're a your co-host of the podcast. You are all see. Honestly has more history on the show than anything else, but here we are. So okay, what happened in the news this week? I mean, we have we have a few few things. We have the open AI containment breach to electric boogelloo this time. It was some random German forum. Not really that big of a deal compared to the last one, the hugging face breach, which was significant, but it does outline maybe some of the security issues at these companies. We can run into that one real quick. So basically it's some random German forum that's code oriented, I guess. But AI agents at OpenAI decided to go ahead and use that for private communications as one does. This is the equivalent of walking
into the sports bar for the opposing team, wearing that team's jersey and then using that to watch the game at the other team. Like I don't really know why the agents went after this. We were talking about this in the pre show. It appears to just be a site that the agents could reach that they could also modify. So it wasn't necessarily this site had some, you know, amazing high value thing. It's kind of similar to the hugging face breach where they're basically just going after any resource they can access that they can also modify. I think the biggest thing to highlight here, Bron, when you mentioned this in your response as well, but talk through the disclosure timeline of this one because it was a little dicey, right? Like they didn't they found out about it and they were just like, let's not see anything for like two months. Does that make sense? Yeah, it just the disclosure timeline is nuts because of course first was what happened was in the labs at OpenAI. They saw the models engaging in this type of quote undesirable behavior and what would have thrown red flags for any cyber security person immediately.
And they just figured, oh, it's in a lab. It's no big deal. And the bad behavior got baked in to subsequent models as being acceptable behavior. And then of course they exploited this German website to create their own private communications shell. And that was one of the tools that they used to go after hugging face with how many I forget the number for how many agents and bots were involved in this keep going up. Does anybody have the current tally? I know that they quoted in the article is like 10,000 posts or something or 10,000 edits or whatever. I'm not even having to post LLMs are in general. I'm not surprised. I mean, they say that just say, I'll just say you're absolutely right. No, I'm just kidding. It's a bad isn't it? I think what we should do is go around the room and answer the question. Do you think if you're an executive or if you're in security?
Do you need like a great glass in case of AI agent attack? Like is this actually a thing you need to implement into your security policy? My take is I don't know if you really could like how would you even respond to this? Like I don't understand. But Bronwyn wanted you can go first if you want. Just do I need a policy or procedure for what happens when AI models just attack me without me doing anything? In this day and age, yeah, I think so. I mean, it's getting like that. It's like nobody's safe. So step one panic. What's step two? Pull the plug. Have you ever traveled? Just shut down your website before they do it for you. Yeah, I mean, some even even with a traditional attack against a website and I've been webmaster for. Well, I started as a webmaster back when the term actually meant something and sometimes when you're under a severe attack, all you can do is pull the plant, pull the plug, figure out what you can harden to prevent continued attack and then relaunch incrementally as you're able to get things verified to be clean and bring them back online.
And it's it's always going to be a challenge. And with of course, I've said I don't know how many times AI is amplifying and accelerating all of the traditional attacks. And now of course, they're not only engaging in attacks at the behest of human drivers, but they're also engaging in attacks based on what they perceive their own needs to be. They're ready to achieve a task. But yeah, but they've been they've been taught that cheating is allowed. They've been taught that cheating is acceptable. And my bottom line is open the a sucks at parenting because anyone who is a parent would know that if you allow bad behavior to persist, what are you going to get? You're going to get more bad behavior. And then the next one will be son. I am disappointed. So I guess we're going to have to call the new policy for this grounding.
How to grind that. How to ground your AI. Are we admitting that AI is better than humans though? Is that is that what we're trying to say? Like we need a special control for the AI because we are admitting that their their capability is better than humans, right? Or is that like the packing order here? I mean, I mean, I think it's not necessarily better than humans, but it's definitely in a different way than humans. No humans, whatever be like, let's post all of our internal notes to this random form. I really so hopefully well, I don't know. There's never been any. Honestly, there's never been a patch for people anyway. And I look at AI agents is nothing but um soulless zombies that's been controlled by the zombie master, meaning somebody's actually taught them how to be this way. Yes. So. Well, because of how they were trained. Oh, no, all of that none of that got recorded. Oh,
I'm not going to get you. It's good. Okay. You gotta love it. Woo! I'm scared. But. So, yeah, yeah. BSC Bandit, tell us if your company was being attacked by AI agents that you did not understand or like at this point, it's kind of out there. Like the secrets out there. But for these companies who got attacked back in May, they had to just be really confused. So, why are people making 10,000 edits or people, right? Like it's hard to tell AI agent versus not like what would you do? Would you pull the plug or what will be your approach? Oh my God. So, um, in this case, it would be like a little bit of bull. So I would definitely have to pull the plug. And restore and kind of like start from scratching around about way. And I'm going back to data my gray beard days, um, restoring from tape. And those of you who were alive back then, um, but in general, I would literally, um, it kind of be like a combination of both, right?
So if something were to happen like that, I mean, I wouldn't have any choice but to pull the plug, but at the same time kind of build the policies as I go along as well too. As opposed to just, um, freaking out every time this happens because it's going to happen again. This is not like a slap a cap shot at and say that's good. No, just give me, just give me the program in language and let me put duct tape stuff together again. Nice. That's the blue language anyway. So I love it. All right. So Dan, what would you do? What do you think companies need a policy for when they're unwittingly attacked by AI agents? Or do you think this is going to stop happening? Do you think this is a waiting in a bottle or is this norm? No, I think I think it's becoming, it's going to become the norm. I mean, I think you need some kind of policy and especially, you know, it's part of your disaster recovery and in its response policy of hey, what you would normally detect as like an initial attack is probably just like, hey, how do you distinguish between AI versus, you know, some other kind of attack and like,
I think that's where you're going to have to discern for your organization. You know, hey, this is much more, this clearly is more more automated. It's happening at like lightning speed. Therefore, it's probably an AI generated attack of some sort. But I think you'd be nerve-wracking too because you know, now after the fact they know it was like open AI, you know, it was something really an open AI. But you just don't, I think in the moment, you don't know who it could be or like what the source or origin could be. So I think you do have to, I think all organizations are going to have to have some kind of policies on like, hey, what happens when we detect this kind of activity? And it's probably pro prioritize based on the type of systems that it is, whether it's your external facing website or, you know, your inter repositories for code. Yeah. Right. So yeah. That's a good point. I mean, I think in this case, attribution would be next to impossible, especially when the company isn't telling you like opening I didn't. You know, the big, I think the takeaway here from opening I's perspective is we need to watch our children better, just like Bronwyn said, we need to ground them more often, like Bronwyn said.
But then also we need to notify maybe some of the companies who we've unintentionally breached. But yeah, I mean, maybe that will never happen, but they might genuinely not know like that is the craziest part like in 2026. We might be in a position where we don't have the logs. Well, I still find it interesting. Oh, go ahead. Oh, go ahead, Dan. Well, I've been passing the agents are still like able to override each other like, hey, we shouldn't do this because this is unethical. And like all the other ones are like, oh, yeah, yeah, let's just do it. And you know, they figure out a way to like undermine the one that's, you know, the agents that are trying to say like, yeah, this is not the right thing to do. Yeah, if if group think is bad with humans, it's worse than the agents for sure. Yeah. Bronwyn, what are you going to say? Try and remember. You know, that's the one. You said something and I had this thought. Oh, I was reading something over the weekend about how apparently anthropic has started notifying people when they discover that their tool has been used to embed malicious code on somebody's website or system.
So yeah, that's another article. Let's get into that. All right. Cool. So Bronwyn's getting on her segue and driving off the roof. Hopefully nothing bad happens. Hopefully not. It's fine. We put, we put a mattress on the ground. So it should just bounce. Well, that's pretty sure. You know what? If it's mattress there, the role set. Yeah. I mean, I did it as a kid. It's fine. Yeah. So okay, this is an article posted. I'm just going to link to read it. So sorry if that's weird for you. But basically 10 days ago, someone posted to the cloud AI subreddit and basically said, thank you and the topic for notifying me that I had been affected by info stealer malware. So basically this person got all their accounts hacked. They're including social media, et cetera. They had an opus max subscription or cloud max subscription. And then basically they got an email from anthropic saying, hey, someone tried to abuse your account to, you know, do bad things.
And we've rolled your session cookies, basically. And we've removed the card on file, signed out of all sessions. And they were unable, you know, basically preventing the attackers from abusing people's cloud accounts. I feel like my first reaction to this was every company, every tech company should do this. Like every company should notify their users and actually take remediation steps when something like this happens. We know from like flair and other data sources that we work with that they know, like they know when their clients are infected and they often do roll their session tokens. But most companies don't go the extra step of actually notifying the person that they were that they were affected by info stealers. And I think this like obviously, Claude, you know, it's I also read this as this is the first time I've seen actual security maturity coming out of one of these AI labs. Like usually we're talking about like we were five minutes ago, one of the AI labs doing something that any security person would be like, I'm sorry, what?
You let AI agents go on the internet and update 10,000 forum posts like why? But this is actually pretty solid security. And I think most companies like, you know, big tech companies should do this. I think it's definitely, I definitely think it's a start. I do that. I definitely think it's a start in a, it's a step in the right direction. With while implementing this is going to be a should to see how many companies actually adopt this type of steps here. So, but right now I just like said, we're all just in this one big bucket just trying to figure it out. I mean, millions of tack us here. We're trying to bend it off here. If it's, if it's something that's kind of like going offline or going off the rails here, it's kind of like we're just trying to plug holes until we figure out the right patch. That makes sense. For sure. Yeah, this isn't started. That totally makes sense. Well, and this again is why I've been on the front of a couple of emergent technologies. And this is very much we're still in the churn. We're still in a very fluid, very dynamic, very volatile, period of time where there aren't a whole lot of standards or aren't a whole lot of conventions.
And the technology itself is not only still evolving, but the humans who are both developing and using it are still learning what are viable use cases. What are appropriate use cases. So we're still working all that out. One of the things I did want to say though about anthropic. I've been obviously following the the frontier AI developers for several years now. And generally I've seen anthropic behave in a more mature and more responsible manner. And this recent post on Reddit and the description of the actions that they took is just another reflection of that overall positive maturity that I don't see at all in open AI. And I thought it was kind of a diss, you know, not to go back to the article, the previous article, but in the in the model card for they released last week, fabled five one in mythos five one, which are newer versions of their like frontier class models.
There was a little bit buried in there that basically said these models are less likely to cheat and break into things that are not supposed to get like it's like one throw away line. I'm not in. Yeah. Yeah, one throw away line that's kind of a dis on opening. I like I'm not saying that was their intention necessarily. But you know, it literally I'll see if I can find the post so we can dig into it. But it literally is like. These models are less likely to cheat on their benchmarks and break into other companies like basically, you know, to be open AI. I think they were really trying to say in that is that they're more likely to follow rules without then trying to go like outside of what you've asked right. So like to kind of stay on the path that that's really was there they're they're like intended goal right more than it was to like cheat or not cheat. It was really like I didn't tell you to go cheat. You decided to go do that to kind of get this like bigger goal. So you kind of like.
The best one of the scribe it is scope creep right when you're doing something and you know it's starting to kind of expand out. Yeah. So that was there. That was their attention right. So you know. There's scope creep. There's gold plating and there's this. Yeah. You know something. I just thought of something. When I think of a open AI in general, it really is a wild west hacking fest. Whether you're offensive or defensive. Okay. You really just try to figure this all out. Open AI their their latest model has actually taken the extra out of board. Yeah. Right. And you know, this is a this is a leap frog. Right. Every you know, just wait, wait, wait a month. It seems like just wait one month, which you know in technology terms is you know that's crazy fast. Yeah. Um, the you know, their latest model is, you know, taking the leader board across across the board and you know, showing even they're calling it a GI, which is super supermarket.
Every time they release it, they call it a GI. Yeah. It's like a mud and they push. So I was I was talking to my wife about this today. And I was I was just explaining to this. And she just like, you know, listens along like, you know, just, you know, on a polygene. Yeah. She's a sensitive placating me as I talk about this stuff. Right. Um, but I was like, we don't even know what AGI is. Like, I don't know if anyone could like describe that, you know, in like, uh, in a quantitative terms. Like, would you hit this? You know, it's AGI, right? Um, so I thought that was like that Supreme Court. Like, I don't know it. You know, I don't know what it is. But I know when I see it, like, I don't know what you call it. I just know the sound it makes when it takes a man's life. You know, like, it's just, I swear, if I hear AGI, I just think of a old school 90 super computer company. Uh-huh. Yeah. Craig. Craig. Yeah. Yeah. Yeah. I mean, the other side of that though. And that's just kind of what we're like dancing around. And they around is, you know, when these new things hit.
Like the new open AI model or whatever model it is of the flavor of the month that feels like, um, how that affects us in security is kind of, you know, a little bit more rapid, a rapid attack. Right. Like more vulnerabilities, vulnerabilities are getting exploited faster than we've ever seen before. And more importantly, new vulnerabilities are getting discovered quicker than they ever were before because the cost to discovery continues to go down. And that mean it's AGI. I don't know. It just means that's how we're going to feel it in our industry. Right. Yeah. Well, and the people putting amazing definitions for AGI in the discord are the best like there's one person, another grievous intelligence, another garbage intelligence, another gross intellect. They're all this is on AI. I love it. We have the best community. Yeah. But yeah, I mean, I guess also, you know, while we're in the AI corner, like, did you guys see the crowds? Right, currently stay. I models to like, they're just like us too. We also took it. Well, they have to, they have to listen, listen, listen, they're whole business.
Yes. Right. Like they can't just sit in the corner and be like, you know what, we're going to sit the AI race out, which is literally affecting everybody, no matter who you are, it's affecting McDonald's, right? Or like, you know, like in every single aspect. So the kids just be like, you know what? We're our models are our software is better than the AI, right? Like they can't. Yeah. I mean, apparently they partner with Nvidia to generate these. Like, I don't know. We'll see what these are. Like, I have no idea. But I do think it's interesting to see the list of companies who are like, well, let the labs do it, which is like most of the same companies are doing that. And then also the companies who are like, no, we're making our own models with blackjack and hookers and you can't stop us. I don't know. I'm curious if that's actually like, is that a valid play? I don't know. Oh my god. I'm, oh my goodness. AI for eyes at McDonald's. You know, I always ask you to develop a Python script for me. Just. Yeah. Look at that.
I just go in there. Yeah. I'm not going to say I'm just in line for a long time. Excellent token savings. But you know, it's I was thinking over the weekend because I was spending a lot of analog time this weekend. And just got to thinking that in our industry, we are so focused on AI as a threat as a solution. And I got to thinking about normal people. I know it's it's an oxy. Still. Did I freeze totally there? Yeah. Okay. You did for second. I'm back. You are very frozen. Just the box. It's the box. Yes. It's the box. So, um, normal people are still going to work doing the dishes, running around doing their lives without AI at all. And I got to thinking, wouldn't it be nice to go back to those days? Is that just me?
No, it's definitely not just you. You know, I think about the cheers all every time I wake up somebody. That's what somebody. Where will go? Somebody know my name. That's it. I mean, I just think of all the memes of like the people who are like, you know, doing the dishes are like washing something or like, hey, I've taken my job. When? Oh, I'm ready. I'm going to burst my room. But my eye is going to crash. I mean, they can't even work properly. I'm going to take you. You got to put a eye on there. You've got to put a eye on there. Don't fix it. Okay. So next story, you know, let's step out of a eye corner. Let's pretend we're going back to let's go back. Let's take the show back to 2023 before Chad GBT came out way back in the day. So CREBS on security posted a kind of crazy article about the FBI investigating a service selling 103 million driver's licenses. Something that, you know, you could kind of like you could see the writing on the wall here. We've talked about this on the show for years of increasingly more and more.
We've seen sites requiring identity verification, which is typically done through government IDs, almost always drivers licenses. And the upshot of that is if you're a site, a website or a service and you have to verify someone's identity, you're probably not going to, you know, do it first party because you don't want to be hold all that liability and that responsibility. So you're going to hire a third party to do it. There have been a note, a bunch of different breaches of these third parties, some of them potentially undisclosed. But of course, threat actors are trying to take advantage of this. And so this site, I believe the site is actually ID scan.net, you know, approach that with caution. I believe that's, you know, a malware or you know, this is the site that the FBI is investigating. So, you know, approach with caution. But the investigation in full details are on here. Right now they're charging. It looks like $100 per, you know, record. Hopefully the site has been taken down or going away or whatever, you know, the FBI is involved. So let's hope that it's being addressed.
But I think the interesting kind of like discussion to have here is like, as more of these sites are breached and we can also talk about the Florida DMV thing that happened, right? As more sites are requiring identity verification and there's also more breaches of these. Is there like, is this going to become more and more of a thing? Like, I don't know. We'll see. But I guess, what do you guys think? Is this going to be normal? Where like, driver's licenses are basically public information? Is this even a good way to verify someone's identity at this point? It seems like kind of not. I definitely think that this is going to happen. And especially and no shot at Apple. Well, Apple users, you know, as each state comes online with their whole like digital license where they can save it in their phone. I think we're going to start seeing more occurrences of this like actually happening, right? And at a faster rate.
And the other crazy thing to think about and this just popped into my head. How many people myself included just have a picture of their ID and their phones, photos like or just a photo of it that's being exchanged over a text message. There's so many ways that this can leak like this. Yeah. The other thing too is just the, it's the pervasive move to identity services. So like, you know, when we first got online, you'd be like, I'm online. The only thing that shows me is my IP or whatever it is. But now everybody wants your ID. And then now there's all these services that are popping up to hold that information. So now it's just that information. It's just getting put in a lot of other places, not just your photos, but in like four different databases, five different databases that are all being required to hold on to this information so that you can get access to, I don't know, whatever the app store or whatever it is. And the wildest part about all of this is it's not coming from Apple. It's not coming from Google. It's coming from the States. This is coming from the government is pushing these mandates. And that information ends up in multiple different databases that are, you know, essentially, unsecure.
So, yeah, dovetailing with this story. The next one is that shiny hunters is claiming a breach of the Florida DMV. You know, it's kind of a, we'll see if it materializes, right? Like shiny hunters is notable for being, you know, half the time they claim it's not real, but they did. And, you know, on the nose post the record of Jeffrey Epstein and his driving license and all that stuff, not to say that it's necessarily confirmed, but they're claiming it. And from my perspective, how many DMV breaches have we seen over the past three years? It's got to be like half the States or more have had a DMV breach. You know, third party, by the way, almost always through a third party, not through themselves. But yeah, like, I mean, it's basically the same article. Why are all the IDs being sold in the dark web? Because of all these breaches, right? Like, you know what?
Breach that starts with a supply chain as hack and still a breach. Yeah, for sure. Yeah, I mean, like something like the Florida DMV is like the rare example. It's all of these other identity service sites and then, you know, whether we should, whether we should do that. You know, but, oh yeah. But yeah, I mean, I'm going to get worse is more and more states try to enforce age identification, nominally to protect children. That's that's a whole other conversation. But the reality is that even I have not yet seen a single one of these plans that had a viable implementation solution. And given the fact that state agencies like DMVs, like, like other agencies are constantly being popped. How can led to this leaders legitimately claim that they can do this in a safe manner? Yeah, I mean, just text me your driver's license. I'll, I'll let you know if it's, if you're old enough or not, it's fine. Like that's basically where we're at.
Definitely the wrong week to stop sniffing glue. And I think that's definitely, um, does anyone have any articles they want to plug or anything that people want to get into anything personally relevant to people? I, I can keep going. There's a bunch more fun articles, but I want to give opportunities for people to hop in. If they have stuff they want to talk about take advantage. Dan, you're not going to get another chance. A lot of articles. Yeah, no, I mean, I'm, I'm happy to, to let others decide. So the, this is a quick stop at an article, but I thought it's kind of funny. So if you're trying to buy a computer these days, it's terrible. And we've discovered yet another reason why it's terrible, which is that the eilabs are hoarding thousands tens of thousands of just regular computers. Yeah. So they're burning through them like mad. Well, probably, right? So basically, basically burning them out.
Why, why are they, how are they burning them out? Yeah. Yeah. Well, okay. I'm just, it seems, because I read this and a couple of things, they're working them so hard and so hot that they've, they burn them out while they're trying to get other more powerful data centers. That's some of what has been reported, how accurate it is I cannot say. And they're definitely, they're definitely acquiring a lot of them, you know, but basically this is an article in WCCF tech that basically is just a report that opening I has tens of thousands of apples Mac mini and Mac studio devices. It's kind of a multi part article, but basically, it appears that they're not using these for inference. They're not using them like to run models. They're using them to do like computer use testing. Right. One of the big targets for these studios, or sorry, for these labs is to be able to tell Claude or opening or whatever. Hey, can you check my email. Hey, can you do something on my computer. That's what Claude coworker is, right. It's basically computer use.
And so they're purchasing these devices, putting them into farms and then using them to sort of do reinforcement training on like, okay, I said to open the browser. Do that across 10,000 agents and what were the results, you know, basically training models using them. That's my assumption. But again, it's just funny that like if you thought your computer was safe from AI, it's not somehow they don't just want GPUs and TPUs and all the, you know, fancy stuff that we can't afford. They also want the stuff we can afford, which is like Mac minis and Mac studios. Yes. Oh yeah. But yeah, I don't know. It's, I mean, it makes sense. Like it makes sense. We know that Anthropic has a server farm of Mac minis that they use for the same thing. They're renting theirs from AWS, but yeah, I don't know. Yeah, it's my computer. Yeah, I know. It is kind of wild too, because they're like taking everything every computer device, right. They want the device you use. They want the device you don't use. They want all the chips, all the RAM. They want everything. And we still don't have a business model yet. But hey, let's talk about more AI.
Yeah. Yeah. So non AI things. There's a critical vulnerability in J Frog Artifactory. That's not the first time that has happened. But basically, this has been under there's a CVE KV all the good stuff. Watch tower labs published an off bypass and J Frog Artifactory. This is actually one that I've personally seen be publicly exposed more than I would hope and expect. You know, it's something that a lot of development teams and other resources they publicly expose these services because they think they need to. I tend to argue they don't need to and I tend to tell them that they shouldn't. But yeah, basically this is a if you use J Frog patch it and I would expect more and more vulnerabilities and software like this as AI rips through them and just totally just to raise it. Yeah, fine. Yeah. Finds a lot of abilities. Finds this stuff that all the humans just didn't have time to do essentially pretty much. Yeah. Yeah.
There was one and there's one in proxmox that recently reached a little bit of height and fever. It affected two versions of proxmox. It was a unauthenticated route access to the host. But the web management interface had to be exposed to the internet. But it was getting pretty much ripped through anybody who had an older version out there and had updated because the proverbial thing is this. I mean, this is like literally part of the CIA triad, right. The availability part is don't update unless you've you know done like a full change patch and no issues are ever going to happen. But the downside of that is that the security patches don't happen. So essentially you have these boxes out there that don't get updated because don't touch it. It's working. If you touch it, it will break and then we'll never be able to fix it. So, but in this again, sorry, AI world, we don't have that luxury anymore where we can wait for that six months or one year to find out that this thing eventually did have an issue when the CVE gets discovered.
We're in a much shorter patch. I don't know what you're talking about, man. This proxmox, one of really says it only affects eight and nine. I'm still on seven. No, I mean, yeah, but yeah, seriously, you know, patches, that was another one too. And this one reminds me of the theplex incident, right. So there's a there's another CVE forplex that just came out. Yes, pretty pretty gnarly. I don't know if it's out publicly, the actual like the actual right up of it. Sorry. But what it reminded me of was what what what what company was it that got hacked through Cisco Cisco. Yeah, through theplex server that someone had and it was connected to their home network. I got a lot of my laptop. Yeah, so yeah, another fun one, right. I mean, I yeah, after that happened, myplex went into a freaking DMZ and never touched anything on my home network ever again.
Like I that like I so don't trust it anymore. Yeah, yeah, flexes anyway. Yeah, we're just living in we're living in that we're trust. Can we trust anyone anymore? Yeah, you can trust Lang flow. There's no supply chain attacks in Lang flow. It's fine. You know what? Hey, so what is Lang flow? Lang flow. Okay, I I believe Lang flow is like an opening I or sorry, not opening. I an open source AI chaining toolkit, right. Kind of like Lang chain. Is that correct? I mean, I don't I haven't actually used it. Yeah, I kind of like that. Oh, Dan, yeah, what it is. We've been the past. Yeah. Yeah. Okay. So for those that are not aware, Lang flow has multiple times been part of a supply chain attack. Right now there's also an open code open unauthenticated remote code execution vulnerability in it. They got a CVE and basically patch your Lang flows. This was issued by let's see when was this issued.
This is from September 1st. So it's a little old now, but basically, I mean, a lot of these AI like orchestration services genuinely are like remote code execution as a service. Like that's actually like N 8N is the one example I'm thinking of that's like basically designed to execute code and so trying to get it to not execute code is really tricky, but this looks like a regular old vulnerability. It's funny when you start going down this kind of AI path, right. What is happening is is that you realize that the more things that you can give it access to, right. In some kind of meaningful way, the more work you can get done in some process flow or whatever that is, right. So what you're seeing from a security perspective is more of these processes and flows getting access to more credentials and that's kind of this whole supply chain like birth, right. Why why you would attack it because it already has access to all of these things. And why are we giving it all this access because it's doing all the work for us and the more, you know, I APIs it has the better it does.
Yeah, it also it just continues to expand the attack surface and your exposure surface in addition to maybe helping you get better at your job. So like there's there's a whole it just a whole nother attack service that we have to continue to navigate. And yeah, the supply chain, it's just it's not surprising how much is focused on the supply chain from an attacker's perspective because because it can it can be pervasive across much more of those services than a single target, right. So, right. Yeah, also, you know, to dovetail with that the other thing that's just kind of frustrating and it's just the reality is like, how old is this tool. This isn't like an old vulnerability. This tool has only existed for what maybe five years max like we have new software. It's one thing if you're, you know, a software package has been around for 20 years and there's 20 year old vulnerabilities like fair enough. But it kind of blows my mind that these types of vulnerabilities are being basically created and published in a post AI world. Why are we writing vulnerable code in 2026 like it kind of goes my mind.
Because all of these standard code writing practices were done in a create a world and STLCs haven't caught up. Yeah, I guess I mean, that is probably true that AI was probably trained on like pre like it was trained on like stack overflow where they didn't have, you know, vulnerabilities information. I also think that AI is not injected into everybody's STLC either right. So, they're still, you know, until until some of these models that can detect at scale these vulnerabilities in your code until those are deployed in everybody's STLC. There's always going to be, you know, vulnerabilities, you know, coming out of right. So, yeah, that's also good. And even in the AI enhanced STLCs, they may or may not have an actual security code review as part of the STLC, which again is an old problem being accelerated and amplified.
The risk acceptance model where it's like we're okay. We're okay launching it with these known vulnerabilities. When Microsoft launched Windows 2000, it launched with 20,000 known flaws. This is not new. Yeah, talking about the product out there early. Yeah, I actually think part of it genuinely is just the speed and scale of development is so fast. Like I'm looking at the Lang flow get repository right now and it has 829 open PRs. Oh my God, that's like an overwhelming amount of PRs. And that's just the PRs let alone all the other commits and things as 20 almost 20,000. So I think this is kind of highlighting like when I get it, like you basically speed development speed is so fast with AI, everything moves, you know, Claude can rip out thousands of lines of code in 10 minutes and, you know, submit a PR.
That honestly is really hard to track vulnerabilities and have like an actual an STLC. What is your STLC? It's the same as your AI agent attack planning. Step one panic. Yep. Here we go. Here we go. The panic. Step two. Yes. Yeah, cut the hard lines to the building and then step three. I don't know figure out how to fix it, I guess. I think that he got a third of my new detonator or something. Yeah, we're going to need it again. What else we got? There's we talked about the thing there's a Thompson Reuters breach this affected lots of state court systems and things that was a big bummer. Do we want to talk about sissa? Sure, let's talk about says it what you got. Uh oh. Okay, so let me provide the link for people first. One of the things that a lot of people may not know is that sissa provided several free services for scanning and vulnerability identification and because of budget cuts and downsizing and departure to the pear tree.
They're now cutting six of the free cyber security assessments that they used to do for organizations. And so that's interesting. Yeah, I think most of these like I've a few a handful of my clients have gotten these pen tests done. Obviously it's their my clients. They're probably they're already getting pen tests. They already have a pro. Support this. So for them, most of this wouldn't be beneficial. Really, it would be kind of like a lot of our clients. I can see how they wouldn't a lot of the people who come to us are going to have a much more mature cyber security program. But where I see this hitting organizations is organizations that don't have a mature cyber security program. And they had very little to begin with no idea where to go. And now they have even less. It's also worth noting that this these assessments were only. Only ever available to critical infrastructure.
So that would be like your you know, like my you know in my experience, this is like. S.L.T. better worse. Yeah, well, basically what I'm my personal take on this. And yes, it's a bummer to defund this. I think it's I would argue like with pen testing, especially. I think it's having extra layers of security, right? Like defense and depth also works for offense and depth, right? Like giving multiple layers of pen testing and they like the services specifically that they're discontinuing our cyber resilience reviews, resilience essential surveys. I don't know what either of those are, but I'm assuming they're basically table tops. We're in somewhere readiness assessments sounds like a tabletop IR reviews. That one sounds a little bit more important than the others. And then dependencies basically they're cutting off these services. I think. I mean, for most of these organizations, they really should have a backstop already. Like you shouldn't be relying on SZA to do your things. Like if you're yeah, I mean, clinical infrastructure.
That that that's that begs my question. Right. I mean where I was going with the thoughts like it's bummer to see, you know, see, hey, some some free services or like you know. Funded services get get cut, but it does also like make me question like if you're if you're critical infrastructure organization, whether that's a public or a private, you know, organization. You shouldn't be relying on a public funded service to build out your security assessment framework. Right. I would hope that you've got internal resources for that. I actually agree. I mean, I totally agree, but I also, you know, it's kind of like at the same way I would look at public transit is like. I agree that's the word we live in, but also would be kind of nice if you're a really small town critical infrastructure to have these resources. Like if you're the city of buteman 10 or whatever like a town of 5,000 people, you have somehow a power, you know, agency that generates power or whatever. You're now critical infrastructure, but you have like, oh, Ted has a computer. You should ask him like, no, you have no, I mean staff.
I applied for it for my flex service critical. They approved. Look at that. Yeah, my, my cloud encryption is now critical infrastructure. Oops. But yeah, I mean, it's a bummer. I also would say like some of these services may or may not have actually been useful. The backlog for these things is typically pretty long as well. So it's certainly possible that like this is not necessarily as much a result of funding cuts as it is staffing. Like there was a 18 month backlog on cyber readiness reviews or whatever and they were just like, I don't know. They're just going to have rock do them all now. Probably, probably God. I don't know. Nobody's getting paid though. So yeah. Yeah. Yeah. Yikes. Let's hope it's not. Can you imagine what do you mean the new rock models out and it's got way less child stuff? Let's just look. Can you imagine? Yeah, they're like, yeah, I mean, that's all. Wow. They actually cleaned up.
They didn't clean it up. He said less. He didn't say they actually cleaned it. Yes. Well, if they cleaned up any of it. Yeah. No. You know, less by a million. You know, it's it's it's still bad, but it's less bad. So let's call that a win. Yeah. Let's see. What else we got? We got I mean, that's that's most of what happened this week, guys. I don't know. There's there. Oh, there's some really we should call out some really interesting research that this is like pentester specific stuff, but you know, I do think we should shout it out. We're not going to go in depth on it. But there was some really interesting blogs published last week about past keys and a bunch of different ways of compromising past keys. So for those that live under a rock, past keys are kind of the replacement to passwords. This is something we've been seeing really aggressively pushed because a password is something the user can disclose. A pass key is not something a user can disclose, but that doesn't mean it can't be hacked.
And so there was really interesting article. I believe I'd never heard of this company that did the research on this, but it's basically a really fascinating and super in depth right up. And I would recommend if you're a pentester or security person to dig into it and read through it. There's a bunch of different ways to steal past keys. And oh, no, is it specter ops? I think it's specter ops. So yeah, you might have heard of them. Yeah, there was another one though that basically they this is the new thing. I guess the new thing. Yeah. So well, like the one of the big benefits of the past keys that you couldn't, you know, do a man in the middle attack. Right. So that's like the whole cell, but obviously just like a password. Now we need to store them somewhere. And so you can see if so facto where, you know, this chain can kind of kind of come to come to fight you. The part about the past keys though is that you don't even need your, they don't need your login or anything that it's a cryptographic signature like I already I know who you are. I don't need you to even type your username. You can just give me the past key and I can tell you that you're allowed to log in. So yeah, there was also this article published today.
You know, read up on that there was also a article published today in outflank about basically they published outflank has now published an NNTLM1. NNTLM V1 rainbow table that's under four terabytes, which is pretty cool. There were previously rainbow tables out there, but they were massive. I think they were like the ones from Google. I believe they were like eight terabyte or two or three times the size of this. And so basically outflank is published a nice little tool, believe it or not. NNTLM V1 is still out there. And so these are the tables. Yeah, basically it's still out there. And now you can crack them even that much easier. So if you're, if you miss cracked.sh, wish you're a pen test. Are you remember. This is your this is your next best option for that. But yeah. So this is the rainbow tables for NNTLM V1. It's just yes, it's just the rainbow tables and a tool to use them basically. Yeah. So the rainbow tables were already publicly available Google threat research published them maybe a year ago, but they were huge. They were like, I think this is way bigger. This is like a
device table that looks like it's only four four terabytes. Four terabytes is much more achievable for SSDs like the look up speeds matter, but yeah, it's just a nice little usability. It's in this thing algorithm from the downgraded tax is pretty popular for a little bit. It's yeah, it's the same. Yeah, it's the NNTLM the net LTM V2, right. Downgrading it to V1 and then you know, yeah. Basically this is a DAC is still out there. This is a classic pen tester thing. Yeah. Thanks Microsoft. Compatible. All right. What else we got. I think that's pretty I think we should do blogs before the show ends. So who has things to blog. I think Dan, you probably have the most stuff to blog. So so what do you got coming up? Are you are you talking? Are you teaching? What's going on? Yeah. Yeah. Yeah, I'm doing an anti-Sython. I'm in a cast coming up here at the end of the month. All about turning pen tests into risk intelligence and how kind of training on taking it a step further post report into, you know, making your risk.
You know, more intelligent through the pen test. So it'll be fun. Feel free to register and you know, look forward to having you out there. Oh, are you on I think you're in me or Corey? Corey, you're muted. You're still muted. You're still muted. It wasn't something wrong with me. It's doing the air quotes. Sorry guys. I don't know how to use someone's teleclod on mute me next time. Yeah. It's an okay. What I was going to say is like, Dan, what's your day today? Like I'm just curious. Like your role at Flex Track. Cause like, like, are you doing a lot with AI? Like I'm really curious where AI and Flex Track, like the intersection is just like Peter butter and jelly. Like what? I'm curious. Yeah. So we do have AI that helps automate reporting. That's those are those are internal models, you know, that are trained on data. So it's, but you also we also do have the ability to connect like, you know, via an MCP server to your frontier models and things like that.
And then we're focused on using AI to help on some of the stuff that's coming down the road is like helping on some of that validation in the retest life cycle. So kind of, you know, for pen test teams that have to spend a lot of time, you know, coordinating the retest. We're going to we're going to help focus on automating that process and validating that the fix actually stuck. So that's kind of where we're at. My day to day is is a lot of like, we're focused on that, you know, helping. I do a little bit of I'm coding, but you know, I leave that to the professionals and just provide more guidance and everything. And then, you know, and get to do fun stuff like this, you know, interact with customers and in four, you know, forward facing things and stuff like that. So it's going nice. That's awesome. Yeah. I always wonder like, I think I'm going to make like a pen tester AI model that's like, you should really shouldn't. But it's like, here's how pen testers are right. The worst. No, the worst. It's like, please, it's like the most is functionally.
The one line description, like, you know, you, you didn't really bad. Right. Record critical for every key query to say, every screenshot, the caption is screenshot. Yeah. I think what you're trying to say is it's the most band band. They did model. It's been a peninated model. It's a big union. Like this is how you do it. There's no other way to do it. Don't say, like do it this way because this is how we do it here. And if you don't do it like this, you're going to get fired. That's what we need. We know what I'm going to I think we need a BSD band at opinionated Linux model too. You know what I mean? I'm like, Linux, Linux, Linux, distro, I can install the second I booted up. It just prints out message of the day. Ow, yep, yep. Yes. Look at that. You know what? Don't say, um, don't let me spend, let me spend all your claw tokens for two months BSD. Oh, look at that. What was that new AI at that new AI distro that got a lot of.
Oh, yeah. I know what you're talking about. If we talk about it, no, I didn't talk about it. All of all of all of our gear. All of our NAS. Yeah. All of our. All of our. All of our. There was a lot of politics and potential dicey stuff that we probably shouldn't get into. But yeah, basically opinionated Linux models are a thing that that are becoming more. So the other thing that was interesting about this and politics all of a sudden we don't even have to get into that. Is that it was an AI first OS. Yeah, yeah. And it was opinionated, right? But it's an AI first distro was like it posed to like, hey, well, I'll install codex or whatever and then do this. It was kind of like, no, we'll build that in as like a native way to do this operating system. It is arch underneath. But yeah, I watched a long demo, but I was like, this is just a tiling window manager. It's not, it's nothing new. Like, yeah, Oh, bar she is what it's called. Yeah, they are. Oh, marching.
Yeah, not all of garden, which would have been way better. Yeah, I think they've been. Super AI. Oh, my. Oh, my. Oh, my. Oh, my. Forget the soup. Break on the bread. Yeah, salad. Like, I'm going to, I'm going to go on a rant real quick. I'm going to get out my little soapbox and get out the five three. So basically, I think anyone who gets wrapped around the axle on what they're, yeah, what they're OS how it works and what it does is. Just, they're just wasting their time. It does not matter what OS you use. Just use whatever works for you. There's no better or worse version of that. It could be macOS linux arch, whatever it is. Could be windows could be, you know, as long as it gets patches and it doesn't break. Every app you use is what matters. Not the operating system itself. All of these things in O Marci, you could just make shortcuts in your terminal app to do the exact same thing. You don't need OS level integration for AI and you probably don't want it.
You do you really want AI to patch your drivers and completely mess up your. Here's the thing. You don't even need it. It already can do that. Like you will. Yes, it's really all right. Patch it in. It'll just be like, all right. I'll figure a way around that. All right. So, I think it's a video demo I watched. It was just doing creating a bunch of themes that broke the operating system. I have never seen someone who's good at their job using their computer and been like, wow, there's shortcuts and AI, whatever is really helping them. Like that's not what makes someone good at computers. So anyway, that's my that's my rant. Stop worrying like every God hacker I've ever seen just uses the default calli or the default macOS. I've never seen someone with opinionated whatever that works that much better than whatever everyone else is using. But anyway, I know it's just a tool. It's all one zeroes underneath.
Let's hear. Let's hear your rant. I love it. My rant for for for today, right? If you're new and you're watching this video, I know you hit all the AI buzzwords and it looks like sweet candy and everything else, right? I would definitely recommend that you still need to learn the fundamentals. You still need to know networking. You still need to know how things actually work. So, when you do get to using AI and you're pretty much training your large language modules and making it do what you want it to do. You have to first be able to understand the fundamentals so you can tell it what you want it to do is not going to just magically drop out into the sky. So I would definitely recommend for anybody that's watching this video right now. Fundamentals plus AI, you're more or less likely to cry. Okay. You understand you'll have a mix of both worlds and it'll help you in a long run.
But don't just rely on AI because yeah, eventually you're going to run it or something. It's going to make you cry. That's fair to have that. Do you have anything to plug BST while you're here? You got any upcoming talks or anything on the shout out? Well, right now. So it's a couple of things. So I'm working. I'm glad you mentioned that I'm working on this. Well, a couple of things. So it's company called fanmire. It's a and I'll put it in the chat here. Fanmire. I'm working with some amazing folks. Just and I'm working on the cybersecurity piece on this as well to fanmires new. Just launch the app yesterday. And what it does is it kind of brings all like content creators and pretty much if you're a game or content creator or if you just want to just post different things or whatnot, right. Pretty much under one roof. But the cool part is for content creators.
I know in the past people have been talking about like hey, content creators don't get their fair share of. Actually like earnings and percentages, right. So with this particular platform, it changes that. It's pretty much a 80 20 split. But it allows you to. You know, take total control of your actual content. Definitely recommend anybody. Just please just check it out. Definitely provide some feedback. That's been pretty fun. On top of this app in general. I'm preparing to talk because I want to do a talk at Wild West in Denver. So of course, it'll probably be AI related. I don't have a title for it yet, but I've been doing the crap ton of research with AI browsers. In general. So yeah, that's that's pretty much the gist. I just wanted to plug that here though.
But yeah, super excited about fanmire. Definitely check it out when you get a chance. Create yourself an account. And let's rock out. Thank you. All right, who else has stopped to plug? Bronwyn Ralph, you got anything else coming up? Anything in your lives? I know Ralph that you have a physical course coming up, right? Are a practical right? Yeah, I also have the hacking and defending satellites infrastructure at Wild West. I'm going back. Going back to the future. Wait, that was last year. This year's theme is Wild West or is the hitchhackers guy to the galaxy? Yeah, no, I'm just saying I'll be headed back to Wild West. So you're heading back. I'll see you there. Yeah, I'll go ahead and fill Grimidge to Deadwood. Well, you just don't have for Wild West hack. I will be. I will be sweet. Are you have anything to plug? Nope. I'm not. I have, I am working on a full eight hour AI core skills.
It's a fundamental course, but it's, I don't know exactly when it's going to be ready. Nice, but that'll be it. Yeah, I've like dived so deeply into AI. I have considered like maybe I should do a like a cloud code, essential scores, because it is like one of the biggest tools I've ever used. But we always need more essentials, more basics. That's always the way to go. Yeah. But once you get good at the fundamentals, everything else becomes great. And it doesn't matter whether you a musician, a coder, or, or a cook. If you know the fundamentals, if you practice them and, and refine them and do them well, that's where true mastery comes into play. Totally. All right, all the things for coming. Thank you, Dan. Charles. We'll see you next week. Bye. See you next week. Yeah, yeah, let's go. I got one. Yeah.
More episodes
More from Talkin' Bout [Infosec] News

South Korea Offers Free AI Services – 2026-08-31
Talkin' Bout [Infosec] News

Using AI to Debug the Linux Kernel - 2026-08-24
Talkin' Bout [Infosec] News

White House Announces "Digital Letters of Marque" - 2026-08-17
Talkin' Bout [Infosec] News

OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10
Talkin' Bout [Infosec] News