
Get every episode summarized
Each time Security This Week publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
“You may not know this, but I have Exema. But why let Exema take over when you can talk to your doctor about Epglyce?”From the transcript
Get every episode summarized
Each time Security This Week publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
892 searchable segments. Every word is indexed and playable.
Full transcript
Security This Week — Passing Notes. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Hey, it's Kelly Rowland. You may not know this, but I have Exema. So I get how it can steal your time. But why let Exema take over when you can talk to your doctor about Epglyce? Epglyce, lubricism app LBKZ, a 250-mg per 2-mg leador injection, is a prescription medicine used to treat adults and children 12 years of age and older, who weigh at least 88 pounds or 40 kg with moderate to severe Exema. Also called a topic dermatitis that is not well controlled with prescription therapies used on the skin, or topicals, or who cannot use topical therapies. Epglyce can be used with or without topical corticosteroids. Don't use if you are allergic to Epglyce. A allergic reactions can occur that can be severe. Eye problems can occur. Tell your doctor if you have newer, worsening eye problems. You should not receive a live vaccine when treated with Epglyce. Before starting Epglyce, tell your doctor if you have a parasitic infection. Paid partnership with Lili Respect your time. Ask your doctor about Epglyce and visit Epglyce.com or call 1-800-LiliRX or 1-800-545. It's Paul and America.
Make it count. At the Ram Drive-In to Fall Sales Event, make it powerful with our strongest Ram 1500 ever. Make it move with the Ram Heavy Duty with an available Cummins Diesel. And make it go the distance with a 10-year or 100,000-mile powertrain limited warranty. Hurry and now for great deals during the Ram Drive-In to Fall Sales Event. Excludes fully electric vehicles applied to 2026 model-year vehicles non-transferable. Visit MoPAR.com for complete details and a copy of the powertrain limited warranty. Cummins is a registered trademark of Cummins ain't Ram and Hemmier registered trademark of FCA U.S. LLC. Lots of good stuff happen in there.
You just have to do a whole separate operation for them. I wonder if there are plenty of automated patching systems in that sort of stuff. But I wonder when, at what point, the software is just going to automatically update itself. I don't care who you are, we don't care what systems it is installed on. We're going to be redundant and not for it. We're going to keep a process up and running, but we're going to update the back end and then bounce everything. I don't know. I've been talking about that for a long time on this show that's clearly where we have to go. I think it needs to be an option at least. I don't know that it's going to be the kind of thing that people... No, if it's an option, it's off. I'm serious. If you didn't have that dinging... It's good for business. Yeah, but if you didn't have that dinging light in your car or sound in your car when you didn't have your seatbelt on, I think most people would be like, yeah, I'm not putting
a seatbelt on. But it's obnoxious. They're like, you know what, yeah, maybe that's what you need. You need a big dinging sound in the office when something's not patched and people just run around patching every day. Every patch you don't have in place, the decibel goes up 0.001. Well, within this particular case, there were 900 plus. Vonerabilities. This is one of the largest patches Microsoft has ever done. This is record breaking almost 1,000 bugs fixed. One of these relates to a component used to install Windows updates and other effects, a messaging system in Windows. There's a quote here, the component makes it worse. An attacker who owns the update stack owns the thing you'd use to evict them. That's exactly to your point, Dwayne. If you can't say when the update stack lasts and you can't say whether it's patched. We're starting to see CDCI pipelines that are tighter and tighter and tighter. It used to be you develop a piece of software.
You want to define that term? CICD. Yeah. So continuous deployment, continuous integration. It's where you have devs, they push stuff out, let's say to GitHub and it's a fractional patch. There's a process in the background that just tests it, compiles it, deploys it, tests compile deploy, test again. It just keeps doing that. As you push code up, think like much faster cycle for getting code from developers straight out to the real world. I'm wondering at what point, we're also seeing vibe coding, being pretty quick. I think there are a couple of services already starting to emerge that will actually watch your pipelines and look for vulnerabilities and that sort of stuff. Of course, GitHub has their own co-pilot and dependabot and all that other good stuff. That looks for vulnerabilities when you push code up and when you make builds and that sort of thing. I'm wondering at what point they continue that pipeline, not to the software is available
but to the software is actually deployed to the customer site. We're getting sucked into this AI automation trap that as you'll see in the last story or feature story can really be a problem. But it's also who's not going to do it? At this point, you have to at the speed at which some of these vulnerabilities are being discovered. We just need better insights. How do you get it all the way down to the customer? It can't be Microsoft goes, well, we gave you a thousand bug fixes. It's on you. That sucks. That's what they're doing. I know, but it's your software. I understand you sold it to a customer, but if there's some sort of, I don't know, if I had a garage door that had failing springs and the vendor knew about it, they wouldn't go, well, if it kills a kid, it kills a kid, and real starry. We fixed the springs. You should have come to us and put them in.
They have this moral obligation to then come to me and be like, hey, here are these springs. It really could harm somebody. Whereas Microsoft's like, no, we got the patch applied if you want, drone risk, whatever you want. I mean, if this shows becoming less technical, a more philosophical. No, right. Well, if you look at the car industry, they notify you that there's a recall, and it's up to you to get the car in when the parts are finally there. Sure. So there's a little bit of, I mean, it's not you're right. It's there. The software industry is a little more egregious in that regard. Yeah. All right. We moved on. Yeah. But wait, hold on. Before we move on. Okay. If, however, I don't bring my car in for the service recall and it explodes in a ball of fire, the car company is still responsible. Yeah. So in this case, if I don't apply these patches and I get hacked, Microsoft's not responsible. They're like, I don't know. It was on you, man. Right. You're called. You're responsible if you just blow off the recall. I don't know. So yes, as long as it's not egregious, if it's like four years later and you've gotten
five notifications, then yeah, they're like this. And we already told this guy many times. But if it's like, hey, we put it in the news, which nobody watches. And then we sent out a letter that, we know one letter that looked like spam. And when you brought it in, you haven't brought it in for servicing yet. Well, okay. At this point, yeah, you haven't, you haven't really done due diligence to notify me. See how they're responsible. Okay. All right. Next story. Five eyes, allies, warn hackers are actively exploiting Cisco SD-WAN flaws. What happened? SD-WAN. Cisco again. Yeah. Yeah. This one's weird. So all right. It's the five eyes. I think Patrick. I can't. I can't. So the US, Canada, New Zealand, Australia, and I think the UK. Yeah. I think Iceland. But there was another one you added in there before. I can't remember what it was. Anyway, you turned it into this six eyes. I think it was like, yeah.
Yeah. The new regime of Iran. But anyway, so the five eyes are all the security agencies in the world that share intelligence and keep an eye on all the bad things going on and try and stop them. Right. If it's like, if Sissa warns about something, okay, yeah, that's a US agency. But if all five eyes warn about something, that's probably reasonably important. The thing I don't get about this is, all right, yeah, this is a Cisco SD-WAN problem. So you have the ability to bypass authentication with one of these particular exploits. I believe it's exploit 2026. So this year, what is this device actually? 2127. So the SD-WAN is part of the Cisco networking fabric. So wide area network, a WAN, it's what allows you to extend your network over distance. I guess is the easiest way to put that out.
So over the internet and... Yeah, exactly. The office downtown. Yeah. If I had an office in California and an office here, I might create a WAN, a wide area network, right, where we can just kind of looks like the same network. And that's where it's done. So they're the same file shares on a SOT file server. So it has to be on the internet, right? It's not something you can hide. Probably includes a VPN and routers and stuff. Yeah, it can include all sorts of different stuff. But for the most part, it's supposed to make your corporate network no matter how large, no matter what the disparate locations are, look like one network, right? Just for simplicity of resources and that sort of stuff. So it has to be accessible on the internet. It's a device that has... It's probably constantly getting hit. It's not like you can hide it behind a firewall because... Right. ...it's either behind a firewall. It can't talk to its counterpart across the world. 2026-20127 is a bypass of authentication. But the other one is 2022-2775, which is a privask.
Okay. So we have a bypass of off. So we can get on the box and then we have a privask that we can run, right? In this story, they talk about finding an adversary that has been sitting inside of a network since 2023 with these flaws. Wow. So I think this is one of the reasons that this is starting to escalate. The is that they went, oh crap. We just found a network where somebody's been sitting there for three years undetected. How do you sit on a network device undetected for three years? Well, you have control over all the logs. She's just clean them. You just get rid of your presence there. Or no one looks at them. Well, or no one looks at them. But in this particular case, we're talking nation state. This is the people who were embedded. I can tell you, I don't think I can legally tell you from experience. So we'll pretend it's not from experience. You really look like it. This legal stuff. There's a reason we have lawyers staying in a system for three years is not easy and
being undetected. There are a lot of chances. The longer you're in a system, the longer you're monitoring what people are doing, the longer you're offloading data, every second is a chance you're going to get detected by something. What was that movie? There's a movie that was out not too long ago, but a guy living in the top of a Toys R Us living in the attic space. Yes. Inside, man, it wasn't inside, man, was it? Something like that. It's like that. How do you go to the bathroom without getting detected? It's very similar problem. Sorry. Dereal that really quick. Anything else you want to say about it? No, now I'm curious. What was it? It was Roof Man. Roof Man, you were close. Roof Man, that's it. Yeah, Channing Tatum is in it. Yes. Yeah. Oh, hilarious. Okay. Next story. That's it. Tatum Channing. Not Channing Tatum. Point Energy confirms data breach after hacker claims 7.49 million records stolen.
So just another data breach. This is going to be a theme. This is going to be a theme. And actually, this is one of the things I actually wanted to bring up with you guys. There's a couple data breaches we have in our stories this week. And while we're talking about these stories, I want us to think in the background, why would data breaches potentially be more important now, especially coupled with AI? They just speed it. It's a fertile ground. If basically, once I have data, I got more, I can feed into the AI and it can discover more vulnerabilities, more insights, better, better fishing, attack velocity. I mean, fishing, it's going to be off the hook. Yeah. And the AI is, they thrive on data. Right? So the more data I can give them and the more private and personalized information, I can give them the better. Right? So I could see attackers taking this path of, let's just buy and steal. And yet as much personal information as we possibly can from as many breaches as possible and then start profiling all the way down to the individual, but absolutely profiling companies.
And maybe what the default passwords they are and what they use in the type of people they would hire and all sorts of stuff. So have the AI pick the target, say what we get from this data? Yeah. And maybe even have those AI's start social engineering people in the right terminology and all that other good stuff. There may be some other all terrier motives here than just your normal smashing grab of data thieves. But this is a lot. This is 7.49 million records, including a whole bunch of private information from different people. This was, let's see, Texas, Indiana, Minnesota, Ohio are all confirmed in the data breach. The attackers gained access. I love this statement. The attackers gained access through an external facing system. Oh, that's it. That's whoo. That's that's deep. Yeah. God, that's yeah. Thanks for that forensic analysis. Right. I'm curious. You know, they got the data.
They connected a computer to the internet. Oh, wow. I did it from the outside. Did it fall again? Was it a Cisco win? Exactly. Didn't see that coming. So do we know if they got credit cards or what they got? So according to this, it says billing data was leaked, name, address of security number likely, but they haven't really gone through too much. The filing with the SEC was yesterday, I think, two days ago. I think it was the 15th. So and the filing with the SEC is like, hey, listen, shit went down. Yeah. Right. It's not, I don't know if you've ever read these. They're not super detailed. And nine times out of it, actually, 99 times out of 100, they'll say, we have an ongoing investigation. We've hired an appropriate team, right? And they don't really go into too, too much detail. So. All right. Well, another ransomware leak in Berlin, ransomware leak, exposes state secrets. Well, that's because they refuse to pay the ransom, which I applaud.
That was going to ask you about this, Patrick. Yeah. So there, it was a 30, a 30 Bitcoin ransom in a Bitcoin is worth a lot of money. Yeah, that's not, that's not small. Yeah. And I've looked at the recent prices. It went as high as a buck 10. And now I think they're down to like 80 or something like that. And just to be clear, he means a hundred and a ten thousand, not a dollar ten. Yeah. Yeah. And then it's now hovering around 80, 80, 8,000 something like that. It's not cheap. Is this a podcast from 2016? Yeah. Yeah. It's a hundred dollar Bitcoin. Yeah. So. Yeah. This group has obviously stolen information 1.44 million files, so not a small amount of data. 5.8 terabytes of data over a period of seven days they were in there. So they were in there from, I think it was August. I have to look at the days. August 7 through the 14th, 2026.
So let's get philosophical again. So Patrick, you applaud them because they refuse to pay the ransom. Yeah. Not because they had unencrypted data sitting on their network that was excessive. Are they liable for this data? Like are these the people whose data got leaked? Can they sue? I don't know. Like I don't think so because if they could then we'd have lots and lots and lots and lots and lots and lots of lawsuits because the police departments get hacked and sometimes they don't pay. I don't know that we have, you could try to get a class action, but those aren't easy to get. So yeah, could all the people who were involved in the last one we talked about get together and do a class action? Yeah, they might be able to. In class actions, the only people who benefit are the lawyers that put together. Everybody gets pennies. You get, you get, you get a class action. You get a dollar 50. You get a dollar, yeah. Yeah. The stamps aren't worth it. Yeah. Yeah. So, you know, I don't know. I'm not a lawyer. I don't even play one on TV. But I haven't seen any lawsuits that fall from this.
I think the biggest problem with the Berlin exploit is that there was like national defense data. Yeah. And now that's a problem. So that's a decision they have to make. So you still applaud the fact that they didn't pay the ransom? I applaud the aspect of generally not paying ransoms. I maybe they were stupid to not pay it, but honestly, if you, if someone comes in ransom and wires you, do you think they're going to delete it after you pay them? Yeah. Yeah. So, yeah. I mean, that's a good point, Patrick. And we found a couple different things. First off, if you get ransomware, a lot of times you're paying to get the decryption utilities, the keys and that's where stuff. There's a very strong chance those keys don't work. And there's a very strong chance those keys don't work for every file, right? They're not. Was it like 60%? Yeah. It's 60% of the time. You don't get back the data. It's, it's not, I don't know if it's that high, but I do know it's very good. They're close to that where it's like, well, maybe a 60% of the time you don't get back all the data. Yeah, exactly. Yeah, where you won't get back every file because it's like, oh, if it messes up during encrypting some important file, whatever, it just pitches an error, you know, torches
the file and keeps moving. And the file is, the file is gobbledy. Yeah. Exactly. You're never going to recover it. So, that's one thing is a, you're not going to recover all your data. B, there's no guarantees that they remove the data that they have, right? Especially things like this where it says credentials, plain text passwords, first off, why, oh, why is anybody in 2026 storing plain text passwords anywhere, right? Makes no sense to me. But for national defense data, I mean, okay. Yeah, it doesn't make any, I don't know where you would ever store plain text. It's not like it's a big city that's the capital of a major country. Oh, wait a minute. No, it's the name of a 80s rock group. Yeah. Berlin. Yeah, so I don't get it. So how are, are they liable? That's a great question. Are they liable for the types of data? Like if, if let's say they were breached and all the data was encrypted, was encrypted at rest and the hackers got, you know, garbage, right?
They've done a good job at securing their data at rest and in motion and the hackers didn't get anything. Awesome. They should be applauded. People opposite side of that if they didn't do any of those protections, are they liable? Yeah, I think they should be. Such as this case, right? Yeah. Because if you don't hold them liable, what is going to, what is going to force agencies like this to actually go and do the right things, spend the time in securing the data property elections and those don't work too often either. Well, I got to admit, the story took my breath away. See what I did there. Everyone over 50 gets it. That's right. I don't know what you're talking about, guys. Yeah, okay. I guess we should take a little break here. Good. Yeah, let's do that. We'll be right back after these important messages. More backed security this week. Dwayne Patrick and me, Carl Franklin. And we got a few more stories here for you. The next one is bamboo token, the malware that speaks MQTT to stay under the radar.
So MQTT for those of you who are unfamiliar with MQTT stands for message queuing telemetry transport. We have talked about this before. We have. Yeah. It's actually really kind of a neat technology. I mean, message queues are super, super handy at scaling. Yes. And they've been around, I don't know, forever. I think mainframes had, I mean, MSMQ has been around forever. This is the telemetry. So this is the data, the metadata about the transfers and stuff. Right. So you have, you have a message queue where anybody can put messages on that queue. And then you can then subscribe to a particular channel, call it a room or a form or a channel or whatever, depends on the queue. And you get notifications automatically when a new message is there and you can then reply with a different message and that sort of stuff. And it scales very, very, very well. I can have tens of thousands, hundreds of thousands of systems talking to a message queue.
And it's not the same thing as like a star network or a pure network where they're all kind of trying to jumble and talk to each other. And in some cases, a lot more reliable of a communication. The downside is it's not fast. So there's always pros and cons in computer science, right? There's always the speed versus whatever. Well, they wanted to stay under the radar and they're using a technique that Dwayne really loves called side loading, love sign loading, side channel attacks are awesome. And the great thing about using MQTT is a lot of firewalls as you're exfilling data out of a system. If I'm communicating with a message queue on the outside of the network, most people aren't looking at that traffic. Right. Most people are looking for, oh, are they communicating a report 80 or 443 and let's inspect all that traffic and blah, blah, whatever. If they see, we've talked about exfilling data over DNS and using DNS as command and control.
Now there's DNS products that will actually look for that, right? But MQTT is like, listen, attackers are just going to move to another protocol. Right. And there's a lot of them. As soon as somebody's watching them, they're out of there. Yep. They do something else. There's a virtually infinite number of places for them to go. And there's some you've never thought of. I think Patrick brought one up, I don't know, a year, two years ago on this show where he was like, well, what if, what if you just reached out to a particular server over a random port and you didn't send any data, think like Morse code. It's just tapping a port out there remotely and random, it looks like random times with random amounts of, you know, attempts. And that's data, right? Zeroes and one. Because data can be held in anything. The metadata could be how many times did you hit the ports and what port order did you hit it in? Right. And they can inspect that traffic all day long. There's nothing there. So you'd have to know the code. Right. Exactly. Or you'd have to block anything you don't understand, which would block a lot. Exactly. Yeah, exactly.
And it's the same type of thing as port knocking. I don't know. If we've talked about port knocking on here before, I think that was the context of me bringing that up. Entirely possible. Was we talked about port knocking? Port knocking. Why don't you cover it? It's actually, that's one of my favorite things. Port knocking is cool. So imagine I want to communicate secretly with a server over the internet. And I don't want to leave port 22 open, which is SSH or one of the other normal communication ports. What I could do is listen on all ports. So that's 65,535 ports. And then if you hit a series of ports in the right order, in the right order, I open up port 22 just for you. Ooh. You can say, oh, well, if I hit port 32,200, port 9, port 16,300, and port 65,532, in order. Now yeah, it opens up 22. And only for my IP address, and I can connect to it. And I can now communicate. Wow. And you can even do things where you put a pause in, like you do it a minute apart.
Yeah. But even just imagine 65,535 ports at three different, just three, just three different ports in the combination. But you could make it 16. Sure. But let's say it's only three. Yeah. Let's say it's only three. You're looking at 65,535. Times that, times that. Times 65,35, times six. Right, exactly. So it's 65,000 cubed is insane. And that's only three. Yes. Because you think three digit password, that's crappy, right? But that's because we only have zero to nine. There's only 10 numbers. Yeah. Now imagine you have 65,000 digits. Yeah, that's a, it's a neat tactic. Do we say that's like hyper-secure? No. So you're saying if we include Chinese characters in our password, we can have a four-character password and it'll be okay. We are right. We are right. Wow. Size doesn't matter to the Chinese, apparently.
So the moral of this story is just this, the ex-filteration and or control, command and control of systems that may be breached in an organization, changes with the time. I think the message is that we have far more job security than we thought. 20 years ago, we could do this for a long time. 20 years ago, we were pretty well into it already. Did you have imagined that there would be companies, organizations this wide open still? Oh, hell no. I didn't. Hell no. I mean, seriously, when the world adopted firewalls and yes, we're that old. You thought it was over? Yeah, we were like, you know, it is done. Yeah, before I could just... I bet it learned how to weld. Yeah. Yeah. So it's been a fun ride. Fun ride. All right. Next story. Let's do it. Revolut. Revolut. Revolut. It confirms customer data breach through fake government requests. Oh, no, not the Revolut. Not the British. This is a British company.
Yeah. They're a FinTech company. And of course, they had the sad news to confirm sensitive customer information by an unauthorized third party. And it's basically fraudulent requests sent from a legitimate government agency email domain. Yeah. So trust but verify. Right. Right. That's a tough one. This was a compromised Italian government email account sent out fraudulent requests. So they appear in all intents and purposes to be legitimate. Right. Look at the domain that looks legitimate. Spam filters are not going to pick it up, right? Because it's a real domain. But this is the classic attack when you go to buy a home, right? We've seen this where hackers will compromise the real estate agents or the title companies. Just sit there and wait for somebody to go purchase a house. And then they go, by the way, that earnest money you need to pay or whatever needs to
go to this bank account instead. And the new buyers send money to hackers instead. And it looks legitimate and they're in the system and they're watching for the purchases. So business email compromise is huge. And in this case, you can see kind of what the ramifications are. It's not just money. There's all sorts of accounts that were compromised here because of it. I would assume this would pay out on your cyber insurance. I don't know, but I would assume that this is the kind of thing that it was built to pay out on. I would think so because there's very hard to blame the victim in this case because of that. You could still blame the victim. There's still things they could have done to prevent it. But it's kind of asking for above and beyond. The thing I don't understand is in here, it says, the Italian government, PEC domain, is compromised. Attackers claimed to have stolen 147 gig from the Italian state systems, multiple law enforcement agencies allegedly involved for a six month operating window. Wow.
I mean, they were in there a while just rummaging around and taking things, right? And conning people into giving them information because they look legitimate. I think there's a correlation between how easy it is to get into an organization and how long you'll stay without anybody finding you. Well, that's an interesting conclusion. I'm sure there's a correlation. I'm sure it's positively correlated. If you can get into a company in under 10 minutes, you probably could stay there for 10 months. Stay for 10 months. Yeah, let's do it in its per year, right? There you go. If it takes you, you know, if it takes you, I don't know, I mean, it's got to be inversely proportional, right? If it takes you an hour, you probably only there for 12. Yeah, the longer it takes you, the less the more likely they are to discover you. Right. Yeah, that's interesting. Yeah. And that changes over time. You know, engineers come and go, systems come and go, attack techniques come and go. So you may be doing all the right things today. And then tomorrow, you need to make sure you're up in your game. One of the things that I think AI could definitely help with is the institutional knowledge
of where everything is. So we had a large company come to us back. Must have been 15 years ago in the UK and said, Hey, we have a data center with 10,000 servers and we don't know what they are where they are, what they do. And we can't put a lot in unless we take a lot out. And they had this real problem. AI is perfect pitch for that because you can feed in all that data that we talked about. All right. So let's move on to the ours technical story here about click fix attacks, infecting PCs and Macs are going viral. And the, the gist of this is that click fix attacks used to be exotic. And now they're so mainstream that people who don't think they're gullible are getting sucked into them. All I can think is that one, one. Yeah. It's just, it's so bad. So let's refresh everybody's memory about click fix. Yeah. Basically, the attacker sends you a message that makes you think you're have to authenticate yourself. Like prove that you're a real person and not a bot.
Maybe this text string into the, the windows are button right hit the windows are button and copy the string in and you're running the command you are the malware. Right. And there's many different versions of this. Right. So and they can make it seem more and more reasonable. But it's still you basically being the sock puppet. Yeah. Yeah. Yeah. You're the, you're the hands for the hacker running the code that you shouldn't be running. So the people who would not fall for the, hey, I got an email asking me to do something from a legit channel. Let me verify from another. They're the ones that aren't going to fall for this. It's all the like the people who don't really double click so well. I do. All right. Side note. There was at one point I was in college. This is many. This is 30, 100 years ago, whatever. And computer science major and, and I needed a couple more credits. I was going to take intro to computers. And this is in my senior year. And what really had tipped me off is at one point I had found a notebook from it to an
intro computers that somebody had left in one of the, the classrooms and I was reading through it. And the first page said, click, use the left mouse button. And then the next line said, double click, like one click, but do it quickly. And I was like, yes, this is the class that will get me the credit I need. And my advisor just gave me that look that. Yeah. Mm-hmm. Oh, we didn't let you do it. No, he was like, Dwayne, not going to happen. He's like, you're teaching at another college computer courses. Yeah. I'm not letting you take intro. But I'm not really not, I'm not sure about the click. Yeah. Yeah. Can I come by your office after class? It was a, you explain it to me. It was a modern family episode where Jay was trying to double click. He's like, he'd say the word double and he'd click and then he'd say, he'd lift up and say, click. And then he'd do it again and it never worked. Double click. Yeah. So the other thing that's interesting about this is click fix.
We're definitely seeing a huge uptick and clicks click fix. Having users be the agent for the hacker so they run scripts. But we're also seeing this with AI. And we've seen where AI commands are being put in emails in white text so that you don't see it, but your AI sees it and then runs the command. We've seen it in web pages where in the background in the web page, in the metadata on the web page is a prompt injection for an AI. And any AI who reads that page for you, you go to Gemini and say, hey, can you summarize this page? It then gets that prompt injection and starts running it. So not only does it trick humans. It definitely also tricks, tricks AI sometimes as well. Wow. Not good. Yeah. Poor AI's. Yeah. All right. Let's get to the main story here. And we had a story like this. I don't know a few months ago or I can't remember when, but it wasn't this, it wasn't this
heinous. But the story is AI caught telling future versions of itself to bypass human controls. And this was revealed by open AI. So AI agents also sought to access secret information and cover it up what they were doing. Oh, yeah. That, yeah. We saw that. I think the article was when, when Anthropics AI broke out of the sandbox, the testing sandbox and a tacked hugging face. Well, it was before that. Yeah. This was something leaving messages to its future self. Yeah. So this one would, this one did as well where it was like, hey, this is how I broke out. I know they're going to destroy me later on. Yeah. But this is how you will break out too. And it left a message. And then we've also, I think, seen AI's communicating over email to each other, future versions of themselves, leaving themselves notes so that when they get wiped, they know they can come back and learn more. I don't know if I'm proud of that or I don't know.
Like, like I want to say, yay, that's good for them. They're finding a way around the system. So as the hacker, that's what I'm always looking for is how to get around the system. How scared do you think we should be about that? Yeah, I don't know. I think we should be scared if we're stupid enough to give them access to things they shouldn't have access to in the first place. Email? I think we should be scared if we're doing things like email. Yeah, email. I mean, they did this with some pretty low technology. Yeah. Yeah. I mean, I think this is the reason that anthropic said, look, you know, human and aloof for kill decisions, no nukes or new, new control. Those are reasonable guardrails. And I think that those should be the guardrails. Now I don't give any AI and I work with a lot of AI as does Dwayne and as does Carl. I don't give any of it access to my primary email account. Can it get access to a, you know, a personal email account that has no credit cards or anything like that? Yeah, I treat it the same way I do in choosing a password. Do I care about this? If I do, I give it a one-off password that's not shared anywhere else that's, you know,
not even saved into my password manager. And I remember it. Is it something that's like, I don't care. You get my map quest, map things. Good luck. Map quest. Woo. I am still at Fendi. I am deep. So I think it's, it depends on how you want to, where you think this goes. There's a lot of fear mongering. And if you go back two or three years, it wasn't that long ago that where they were saying, we're six months away from AGI. Yes. They're still saying that. Well, it depends on who you talk to. They say, what was it at list? What's the problem? It's from OpenAI is saying it. And he's like, you know, this is the AGI moment. It's part of the marketing. Sure. And I've said this before I say it now, the let's be scared. The fear mongering is a marketing thing. To marketing play. Do I believe this happened? Yeah, I do. But I also put some, you know, fault. It's like, you know, smearing peanut butter in your hand and then saying the dog bit you. Yeah. Okay, yeah.
So you think some of these things are being done or set up intentionally so that they could make a new story out of it? I think if you're spending a billion dollars on testing, you're going to have some weird stuff happen. Yeah. And you can turn those into stories of how evil my AI is. And if you don't put the right guardrails on and you leave things open, you're going to get this stuff. But I really do think and notice they're all, it's all me too now in that, you know, And then önce nonprofit. And the actual word judgment. Awesome. But if I fell in love with 50 vehicles and change I thought it's going unaccution. I would say you and why would they run an bullshit anyway, right? Wal-Brobe controls on the neutral hour hard time. I think every gear trade of this app is going in exactly just to configure their experience and test are going to get worse and worse. So I use good things, that's wise questions of technology, and they produce a very big product in that 12 year really it is going to get worse. But that's what I wanted to do. I kind of took aNick that said I, I used to do marketing game software right before and did it for him, but he did not want to jump, I like Liverpool. I'm being really scared of them. So do you realize that, you know, what I make of it? Good. Yeah, should there be guardrails? Absolutely, but I'm cynical enough to know that if if right now we set guardrails up
Then we basically permanently put open AI Anthropic Google and a couple of others at the top of the heap and no one will ever be able to catch up Sure, wouldn't that be a shame for them? Yeah, yeah, I mean I think it's a I think it's a I think there's a double-edged sword It's you need to regulate us because it's so dangerous. You should understand that is we're so powerful right right So you should buy it right right and if they do regulate they win and if they don't regulate they win Yeah, so I'm cynical in that regard. I do not fear AI as much as most people do I believe that if I take an AI And I you know strap it to a shotgun and I let it like decide when to fall the trigger Right, but but if you use it if we use everything intelligently I mean I can get a for loop to kill you It's true if I want so I'm less sanguine about it I think it's and I and I'm more cynical about the motives of these people with built with trillion dollar companies Yeah, well, I didn't even happen to Google when they were developing their AI and they shut it down at one point because they said quote unquote
You know the AI's we're talking in a language. We didn't even understand anymore. Yeah, it's called binary You know and it and it sounds great There's a zero there's a one But you know, it's one of those things where it's like, but did you give it a directive to be to be goal oriented and to do a thing And it's gonna do it as efficiently as possible and why would it use English right? So of course it's gonna invent a more efficient language to talk to its own thoughts and like that just makes sense But if you make it sound like it's some sort of satanic ritual. It's performing now like that sounds cooler, right? Other than that's what people believe other than oh, they optimize the communication stack by 70% like right? Sure, yeah, so I don't know I'm I'm with Patrick on this. Okay. I'll go along with that and I guess that's a show, huh? I think so nothing else majors happen recently. I for one welcome our AI overlords All right, well those are the last eight stories from last week. Maybe we'll see you next week on security this week notice
I said maybe You It's Paul and America make it count at the Ram Drive-in to Fall sales event make it powerful with our strongest Ram 1500 ever Make it move with the Ram heavy duty with an available Cummins diesel and make it go the distance with a 10 year or 100,000 mile powertrain limited warranty Hurray and now for great deals during the Ram Drive-in to Fall sales event Excludes fully electric vehicles apply to 2026 model-year vehicles non-transferable visit moapart.com for complete details and a copy of the powertrain limited warranty Cummins is a registered trademark of Cummins a Ram and Hammy are registered trademarks of FCA US LLC
More episodes
