
Pentagon Plans to Train AI With Classified Data – 2026-03-23
About this episode
This episode covers a range of cybersecurity and AI-related news, including how Pokémon Go players may have unknowingly helped train delivery robots using massive image datasets. The hosts also discuss the Pentagon’s reported plans to train AI systems on classified data and the potential risks of exposing sensitive information. Additional topics include major data breaches (such as a third-party breach impacting Crunchyroll user data), ongoing challenges in cybersecurity practices, evolving AI security concerns, and real-world examples of exploits and vulnerabilities affecting mobile devices and organizations.
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
- (00:00) - PreShow Banter™ — Easier Than Printers
- (05:20) - Pentagon Plans to Train AI With Classified Data – BHIS - Talkin' Bout [infosec] News 2026-03-23
- (06:38) - Story # 1: Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web
- (07:38) - Story # 1b: ALT Link - Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web
- (15:35) - Story # 2: Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway
- (24:31) - Story # 3: The Pentagon is planning for AI companies to train on classified data, defense official says
- (34:04) - Story # 4: CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization
- (37:50) - Story # 5: Warning: Your AI-Generated Password Is a Major Security Risk. Here’s What to Use Instead
- (42:21) - Story # 6: CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)
- (49:57) - Story # 7: Massive China Data Leak: Hackers Access 10 Petabytes of Weapons Testing Data
- (51:28) - Story # 8: Anime fans' credit cards might be stolen from Sony streamer Crunchyroll
- (55:03) - Story # 9: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
Links
Story # 1: Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web
Story # 1b: ALT Link - Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web
Story # 2: Federal cyber experts called Microsoft’s cloud a “pile of shit,” approved it anyway
Story # 3: The Pentagon is planning for AI companies to train on classified data, defense official says
Story # 4: CISA Urges Endpoint Management System Hardening After Cyberattack Against US Organization
Story # 5: Warning: Your AI-Generated Password Is a Major Security Risk. Here’s What to Use Instead
Story # 6: CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)
Story # 7: Massive China Data Leak: Hackers Access 10 Petabytes of Weapons Testing Data
Story # 8: Anime fans’ credit cards might be stolen from Sony streamer Crunchyroll
Story # 9: The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
Creators & Guests
Click here to watch this episode on YouTube.
Click here to view the episode transcript.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
Get every episode summarized
Each time Talkin' Bout [Infosec] News publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
1,304 searchable segments. Every word is indexed and playable.
Full transcript
Talkin' Bout [Infosec] News — Pentagon Plans to Train AI With Classified Data – 2026-03-23. Machine-transcribed; use the interactive transcript above to jump the player to any line.
I've got a couple of good ones today. Pokemon Go players on winnally trained delivery robots with 30 billion images. Oh, yeah. Am I surprised? No. That was amazing. The way they did that was great. And that's been a story, I think, five or six times in the last couple of years, it's really fun. Yeah. I thought I've heard this story before. Yeah. Yeah. I still just like delved stuff. That just cracks me up so bad. Oh. We're live. Well, that's good. I see a stream. Get this whole, this video and audio thing down some day. How long has it been, John? Like, since 2008, it's been a while, I believe in you. It's easier than printers now, at least. Like, I remember days, like, trying to get a webcam to work with so rough, like, trying to go using my PS5, my PS2 webcam on my computer. That was, that was a fun thing. You had a PS2, like, the port, like, the serial port webcam, like, that was good enough.
I don't remember. I want to say it was USB. Yeah. I believe that one. Yeah. Yeah. It was for one of, like, the, one of the videos where they actually tracked you and you could play games. I don't know. And then we never played it. And then I was like, I wonder if this can work on a computer and slowly went down. Always. What was the Microsoft, like, video chat program, the very first one called, um, Dang it. What was it called? Now, look it up. I remember using that. It was, it was bad. It was. I use some. There's like Windows 95 bad, like, that's where we're going back there. I'm not going to mention them. Websets. I was on. It was not the best. Those times. No. This isn't the golden times of the internet, right? This is, I mean, stuff was still dark, stuff was still dark. All I was on was AOL in the dial up days. Like, this was like before the transition to, like, the full internet, you know? And, uh, there's, yeah, it was, it was debauchery. I still, I still maintain the internet was better back then. Yeah.
You just won ISB. So many, so many niche stuff that, uh, you just can't, you just can't find anything like that anymore. I mean, I, I remember a thorough blueprints of like, very, um, out there, Star Trek shot, and it's like, nowadays, it's like, well, if you want that, like, you're just going to be like a, you know, 99 a month subscription. And maybe for a premium, you can get access to the blueprints of this one ship that appeared from this episode. It's like, that was all free back in 95. Somebody was way too much time and like a CAD program. Well, the internet sucks. I was reading the news and I didn't realize I had opened the AI part and I'm just going through it. I'm like, why is every article just AI? Like, I'm like, I want to talk about something other than that.
And then I'm like, no, okay. Yeah. It's just all emojis and EM dashes from here, my friend. There's, there's all the points of three every, it's like, why is there always three bullet points and everything? Oh, that's a good, I'm going to have to go change my slides. I'm very happy. Yeah. All my slides. We can just trade slides. Wait, I'm sure we, we both probably almost wrote the other topic. We could. That would be, that would be pretty good. It'd be really funny. It's one of those like when you're doing cons like slide roulette can be one of the best things at the con and it could also be some of the worst that happens. Bruce, I think it was at Shmucon years ago. Kevin Johnson got women of the TSA and it was just nothing but like the X-ray pitchers and it was so epic. He did such a great job of that. There were so many people that were so offended.
But most of the time what happens at a con is someone just looks at the slide and they're like, um, uh, uh. Yeah. I mean, credit for at least making it work like even if it is. Yeah. You didn't make everybody in the room happy you at least did something more than you would stare at it. Yeah. Never say die. Never say die. Yeah, it's a real art to, I mean, honestly, like I've seen, you know, 90% of them have just been awful. And you got to go in like I go into them with like a game plan, like whatever it's just like a media training. Like you answer the question that you wish they'd asked you to give a slide presentation. You wish they had given you and then you just tie it in and it works out and that's, uh, that's better than trying to work the slides. We didn't want to be sites charm where it was all AI generated slides. This was, I want to say it was four years ago. The AI generated slides were flat out terrifying. We're putting in prompts to come up the slides like multiple reasons why all humans should be exterminated.
And AI was generating the pitchers with the justification. It was like, oh, yeah. Now we got guard rails. All right. Card fails. All right, everybody. Let's get started. Ryan, bring out the cricket finger. Let's get going. Here we go. Okay. Hello and welcome to another edition of Talking About News. My name is John Strand and I'm joined by a whole bunch of other people. This is in Zoom. So the coordination is a little bit different for us because we're trying new platform here. But we have a number of different stories from federal experts officially declaring that Microsoft's cloud is a pile of shit. AI companies training in classified environments where can go wrong. B.H.I.S. finds all kinds of like AI chatbot data exposed. We have in tune issues is more sissa stuff. I'm going to rant on sissa and their kev.
K, whatever. They're commonly exploited database. We've got a lot going on. Let's go ahead and get started. Ralph, do you want to pick the first story, sir? Oh, wow. You were talking. You had one that you thought was pretty, pretty good. So do you want, because there's a lot here. So kicking it over to you, man. What do you want to start with? Oh, let's do. Do you actually want to start off with your own with your own like B.H.I.S. Let's talk about. Let's talk about. Oh, okay. You want to talk about Jeremiah. Yeah. So yeah, basically Jeremiah spends a lot of time. So Jeremiah Fowler has been with us for a little while at B.H.I.S. And he spends a lot of time specifically going through and trying to identify exposed like databases and things that might be useful in what's going on in Ukraine and Russia because he has family ties there. And he stumbles across some pretty terrifying things every once in a while. And this one he was able to identify a bunch of phone calls
where the audio was recorded and was exposed to the open internet. And then he started, you know, kind of working with that. And this one kind of scares me the whole, like whenever you're calling in and it's like, this will be shared for quality assurance purposes and also marketing of a security firm at some point in the view. I was going to say the rest of the internet will be shared with rest of the internet. Well, we shared, it's like they say whatever happens in Vegas stays in Vegas isn't it's probably the internet's purpose and shared with everybody. I just, it's been like this Jeremiah Fowler was surprised because it takes a lot to surprise Jeremiah these days. But is this really all that much of a surprise? I mean, the type of data it is, the chatbot data. I guess it's kind of novel in that respect, but what is it? It's 1.4 million audio files. And then the plain text transcripts basically out there as well. So it looked like just reading between the lines here. This was a web interface that went to it or a CVS file or CSV file,
excuse me. And in that file, we're a bunch of URLs for audio files and chat history, right? And let's not forget the most surprising thing about this. Is apparently sears still exists? Yeah, there's that. There was also the ambient audio right there. Yeah. The ambient audio right there. You thought the call had ended and then you're still. I don't think you're still. Okay. I was at a phone call or was it over like a web browser? No, no, it's a phone call. You could literally hear the ambient conversations. And I don't know if you all have noticed this, but there's a certain percentage of people that when you're talking to them on the phone, they expect you to hang up. Oh, yeah. That's my wife. If you just don't hang up, they'll accept their phone down and walk away. I don't know what percentage of the population that actually is. But apparently there was a handful of those like that worth. They just stopped and they expected the sears chatbot to hang up. I didn't like to live. I didn't know already.
I did think it was funny though, because like the one thing it did say in the article was that like we're reading into some of these conversations. The bot would be or the AI would be like, I totally can help you. You don't need an agent and then fail at helping them. And then say we're going to send you to an agent. And people got increasingly more angry and aggressive with Samantha saying, I want to talk to a person. I need a technician. How, how, how much data was this? Like it doesn't say in size. Like you would have 3.7 million chat logs and 1.4 million audio, audio files, which is a lot. Like I'm just surprised that you just let storage overflow that much. Does that just mean no? Like I will have a long time there. Sears is hurting for money for sure. Like no one's watching those storage fees. I'm just in cold storage. Well, obviously nobody's watching anything over there. That's it. Okay. Like nobody, nobody cares. Like they set it up.
They sold it. And they were like, okay, we'll just forget about it. I guess, right? I mean, that's not. Okay. So that gets into a larger issue. Like, you know, I talked about this. I think in previous episodes talking about the coming SaaS apocalypse, right? Because anybody can develop any, well, not anybody. But any medium to large size organization can look at the SaaS products that they have. And they can very quickly develop their own products utilizing AI and many times poorly. So now instead of somebody buying and like everybody kind of coalescing around one SaaS offering. Now all of a sudden people can just start creating their own crap SaaS offerings. And these things don't die. They don't go away. They don't get patched. They don't get updated. They don't get looked at. And that's one of the reasons why when we're looking at computer security. I hate a lot of people in security like, oh, AI, it's the end of security. I'm like, are you out of your freaking mind? It's just moving the technology profile a little bit more. And there's going to be a lot more of stuff like this. Because you know, there's a bunch of custom software underneath this. That was just absolute garbage.
Essentially what you're saying is from a high level. You can develop quickly. And you're just going for your customer not to say you should or shouldn't, right? Just that you can you like most of these founders have an idea. And they're like, let's build this as fast as possible. And then they can build it really fast. And then they get it out there. They get those customers. But security is kind of like, well, what? It's like a trend with all the AI providers right now. Is they all have some product that's brand new and very expensive that does security audits and security reviews and like anthropic came out with one recently. And it was like, atrociously expensive per like PR review because they're running so many different agents on it. But at a certain point, like, you can build anything. Like we talked about that some last week. But I'll show you. Should you? And I guess it depends like, is it more costly to get breached? Or more costly to buy this tool? Like which one is worse? Well, that's a good one. And I want to bring Bruce in on this, right? Because I remember years and years ago,
there was lots of conversations, especially in the early web days where it was like, no, any time you get a urge to say, I'm going to redevelop an entire package from scratch and not go with an open source product. You were told, don't do that. Lay down on the ground and then take a breath and wait for the urge to pass. Now all of a sudden, those guardrails are gone. Man, like it's just flat out so fast that people can do this. And I don't think we can fight it. And also going back to what Hayden was just talking about. I don't know if the code that for traditional companies, SaaS companies that are out there is going to be that much better than the crap that people are going to produce anyway. Yeah, I think that's the unfortunate reality is software development is not evolved all that far in the last 25 years when it comes to software assurance and code quality. I will say, I think what's interesting is if you can vibe code an app, you can use that same technology to do the assessment for you and try to help you do it more securely in that kind of thing. And the models have been trained reasonably well against that stuff.
And I've seen at least with the people I've talked to, pretty good results. But you have to be thinking, I have to care about not just the functionality but the security of the thing. And this is where the 80-20 rule kicks in. People are like, I got 8% there. It works. I'll ship it. We'll see what happens. And that 20% is the part that's going to kill you. Right. And that's the big crossover. There's probably not a huge crossover between the people that are like, I'm going to spin up cloud code and build an app real quick. And the people that actually want to do security that may not be instant and very quick, either. Well, that's not a big, big diagram. That's me. That's me. But I'm going to say that security is still hard. And the reason why I'm going to say that is, an app is just not its code. It's the ecosystem that it's running in. A lot of these vulnerabilities are more like infrastructure-style vulnerabilities that come back and bite someone in the ass. Or like, like, like, you can have your code is really good. But if you're shuttling that data that is produced off to somebody else's platform, we see time and time again with third parties are getting breached, right?
And the other point about it is you may be, let's say you code something fantastic today, right? It's done perfect. You lock it into a time box. And then you open it up two years from now. It's going to be hidden hideously and secure. And it comes back to the hygiene associated with security. It's still very much missing, right? We're still back into that it works. This developer that's a cousin of mine put this thing together. It looks great. Let's get it out there. You're still not part of a hygiene and making sure that the libraries are up to date and any new security vulnerabilities and infrastructure don't have vulnerabilities that are showing up on it as well. It's just, like I said, people can make bad decisions faster now than they ever could before. Yeah, I think there's more to review them. Yeah. And I think there's the non-functional requirements of the system have always been the ephemeral thing that requires, like, you know, skill and experience and whatever to figure out. And the functional requirements are like, I made an address book. You know, people can build that and understand it. But performance and security and scalability, that still requires expertise.
Even if the AI is writing the code, like it requires the guidance from someone who's been there and done that before to guide the system to the right place. Yeah. All right. I got another story. This one cracked me up. And there's a couple of really painful stories this week. I just shared it in chat, Ryan. This one is federal cyber experts called Microsoft's Cloud, a pile of shit and approved, approved it anyway. The reason why this, this hurts for me is I've been part of these conversations in the government. And what they're predominantly talking about is they kept asking Microsoft questions. Like, how does end-to-end encryption work? Is it actually end-to-end encrypted? Can you prove it? Can we get some documentation? Can we see how it's like works on the back end? And Microsoft could not answer a whole bunch of these different questions. And the refused to answer these questions. And then provided documentation that was subpar, and it was just bad all the way through. And having worked on the government side in DOD,
I've seen this again and again and again, where you sit down and you ask a very large vendor back in the day, it was Oracle for me. Oracle was hideous to work with on this stuff. It was like, screw you were Oracle. And they just refused to answer any questions. And then once again, no one gets fired for hiring IBM. No one gets fired for hiring Oracle. No one gets fired for hiring Microsoft. And it went through. And I'd like to get you guys' take on this particular story and your experience on this as well. I have a quick point I want to make. Is the headline is very sensational. It is in like the first couple of paragraphs where it mentions like, when they call it a piece of shit, they're talking about the documentation that Microsoft provided them. And the answers to their questions. I will withhold my opinion on Microsoft's platform. But that is the part they're calling a piece of shit. I feel like, all right, we talked about the two things about programming that are difficult, right? Like the design and then scalability. So I think, and I believe that whenever you get at the scale of Microsoft,
doing security at scale gets really difficult as well, right? Especially when we're dealing with tons of data. And at the end of the day, they're looking at how do we make money? So they're going to take shortcuts to allow that to happen while, you know, hope having enough security, like enough is, you know, at scale. And that's probably what we're looking at here too with the documentation not having all of this stuff, you know, different groups and people all working on it. And it kind of got broken into pieces. So it's good to hear that you Microsoft has problems doing their diagrams and everything too. Well, Microsoft is a 50 year old company. Yeah. I mean, seriously, I saw that the other day. It was crazy. It was crazy. And, you know, the tale that they have and they brought with them to the cloud is really long. And I think it shows and when you compare them to the other large cloud infrastructure providers, like you can see the age in the system from the documentation all the way down to the technology.
Well, most people don't probably go through the whole process of the Fed ramp stuff, right? So like they spend all this time building out all of this like essentially documentation and in like how it should be secured. Like Microsoft probably didn't do that when they built this. They were like, you know, just trying to build it and then eventually got to that point. Now that they get all this documentation, they're like, shit, I don't think anyone's going to ask these questions. I think I've been at a couple of companies now that have tried to go Fed ramp and the keyword there is tried, right? Yeah. From my experience from smaller companies, it is a difficult thing. So to hear that, like it's not surprised that Microsoft got passed on it, but I'm sure like the bar is high. I guess John, you would know that more than I, because I never actually got to work at a Fed ramp organization. But I have a friend that's trying to just develop, he's a very small, small shop. It's basically him and a couple of other developers and they're trying to do like all the stuff Fed ramp compliant and it's conflicting, it's will break a lot of the stuff that's in the cloud.
And he's pretty much given up on it, but it's become like a pet project of his. He's like, nah, I'm going to get this. But his takeaway from that is anybody comes to you and says that they're completely Fed ramp compliant. They're livers. And that's how they got Fed ramp compliant in the first place. So I just remember doing the Stig Hardening guides for systems. Right. And like the reason I bring this up is because if you go through and apply everything in the guide, the thing just won't work anymore. Yeah. So they had something a long time ago called the Disagold Discs. Yeah. You put in this ice, you burnt this ISO to a CD. And then you ran the Disagold Discs for Microsoft or whatever, Linux or Solaris. And you literally had this wonderful button that was like apply Stigs. And you click that button. And by all the configuration, you could not log into it. And I was on a project. I'm going to talk about the, it's kind of weird, but the next story that's going to be coming up, you know, training classified data and classified data and AI.
And we had a DA was a designated programming authority and a PA programming authority rep come in and they basically sat down at all the systems. And I went through and I tuned all of this crap made sure that the system still worked. And these two guys showed up and they just hit that button and they knew our systems. Right. Like nothing worked. And it turned into this huge thing was like, you know, I got blamed initially. Well, he didn't secure it hard enough. I'm like, it doesn't matter to fall out of the box. It breaks it. And I had to demonstrate that. But. Yes. And I remember on those that you also had like the, like the sum of supplemental test plans. And then we're. That's where. It seems so, you know, relevant here that it's like it's difficult to be that momentum against. What like just the standard is because even with the test plans, what you say, hey, here's this thing that. Is is not secure. Like it's it's a new thing. It's an emerging thing. You know, it's a problem. Here I can show you on the server that we don't have this secured.
If it wasn't part of the current test plan, they're like, well, don't worry about it. It's. But that was all. And so. And then. Lo and behold, like four months later, they're like, this is now part of the current test plan. Drop everything and fix this and you're like, that's the thing that I talked about. Four months ago that I said, hey, as long as we're in here, why don't we patch this thing? And it's like, no, it's don't, don't be an instigator, Alex. Like just. Well, in flow. And this. Coming back around this time with the, you know, hey, this isn't. This stuff is, you know, like you know, they said you want to pile a shit. And it's like, well, don't be an instigator. Just sign off on it. Don't be the first person to push against the norm. The norm is just accept this go with it. Well, in kind of like, like the piggybacking on top of Bruce said, like Microsoft has this huge amount of bag. It should carry us with it. And a lot of it, it doesn't even know. One of one of my favorite stories is the people that were coming up with some by years ago. They were trying to come up with something that would be compatible and communicating with Windows systems.
And they had no idea how like Landman was working. Right. And they had no idea how net NTL and V2 worked and all of this different stuff. And they were talking about going through like a memory dump of Windows computer system because they were trying to find a key that that Landman was using basically. They were trying to figure out how it was using des to encrypt. It was using your password as a password to encrypt a string. And they didn't know what that string was. And they're going through memory. And they saw KGS exclamation point at pound dollar sign. And they're like, is that it? And it turns out it was. And rumor has it that was the initials KSG or KGS was the initials of the guy that wrote that protocol. That Microsoft. And the point was no one knew. And they think that that was his password that he literally hard coded it. So it used your password to encrypt that string using des for Landman. With net NTL and V2 going back to that again, there's a whole bunch of fields in that protocol. No one knows what the hell they do.
And I was talking to some Microsoft engineers. Look, if we have to figure out if something works as ours, we go look at other people's documentation that has reversed engineered it. Because we don't have that documentation play. And going back Alex, you know, we talk about, you know, things being ignored. I keep telling people all the time, you know, in every security standard that exists on the face of the planet, right? I don't care if you're working CIS or you're working this. They say absolutely no clear text authentication protocols. And Microsoft, like net NTL and V2 is a clear text authentication protocol. If you look at how it works and how it actually runs. You have a challenge, an 8-byte challenge. That is sent in the clear. The response with a password hash is sent and it uses the password hash as the verification mechanism. All of that is reversible. All of that is sniffable. But it's one of those things where you have to be like, we're just going to pretend everything's okay. Because of the legacy technologies, because if you start trying to peel back that and trying to fix it, your Bay is going to shut down windows completely from a lot of these things.
So this is tough with legacy technologies that has this huge amount of Bay. It's a huge amount of baggage that they continue to carry forward. So Microsoft is junk. But we have a solution. We have a solution. And that is to use AI for classified data. Yeah. I thought you were going to say just lie. I thought you were going to say just lie. I think my word count on this episode is already exceedingly high. Do you want to take this one? Yeah. So the Pentagon is planning for AI companies to train on classified data. Right. So that's the article. And, you know, the wild part about this is, you know, classified. So supposedly we're supposed to be using classified data centers for this. Obviously to, you know, house this classified data. And then they're going to train on it. Right. That's the big idea. But it seems like the beginning of Terminator. I just feel like that. That was like the whole thing. They gave the machines like access to the military and like all of this information. I know I know I'm kind of joking around that, but I guess, you know,
obviously they have like a clawed gov and like other things to isolate these things out. But yeah, what do you, what do you guys think about this? Or even the idea of classified information with AI, right? I think there's a, there's a real challenge around access control. I mean, it kind of ignore the, the moral issues of like what they could do with it. And whatever for a second. But, you know, classified information access is really, you know, geared around, you know, need to know. And there's this, it is far and away. The most complex, you know, tagging and, and, you know, kind of compartmentalized a universe that's ever been created by mankind. And at the end of the day, like, you know, these LLMs have shown that if you ask them the right questions, they will regurgitate the training material that they were given. Right. And so I think that there's this question of like, how do you provide there's this question of like, how do you protect need to know classified information? If you can just ask the LL on the right thing, how are they going to actually constrain that? I don't know that there's, at least publicly been a lot of discussion around how they're going to enforce that.
There, there's a couple of products out there that, uh, right now take all your data, all your notes and all your information. And then supposedly give it back to you if you have access to it. Think about it as a like one stop shop for your entire org. Uh, I have seen it both work and of course not work, uh, and give notes on a particular document that a user wasn't supposed to have access to. But then also the same thing with like Slack messages and there are group channels and stuff like that. Right. And I'm kind of interested to see what they do with the security because I think if they can implement some like exactly access control policy, it would, it would trickle down to the public sector. It would be pretty cool. Just to like level the field, right before we get into like the government has been doing AI kind of adjacent stuff with classified information, right? Like just databases full of this to try to analyze as fast as they can. So like none of this is necessarily new. I think the new part is just how good these models are and the fact that they weren't developed specifically in the government.
Right. And it has to be like, well, maybe I'm giving them too much credit. I was going to say it has to be like a calculated risk of some of our theoretically most valuable information is going to be classified in some way. And we want to use these models for warfare. So like if we can give them access to this to train on it, whatever bad could come out of that is theoretically offset by the good we can do with a model that knows how to, you know, overthrow governments and things. It's just, I can understand the reasoning behind it. It doesn't mean that I don't, I don't necessarily think it's a good idea. I think it's a fantastic idea. And I know that that's weird because I'm usually over paranoid. Chad just told to this head. Let me explain why I think it's a fantastic idea. And now there's a specific utilization of what I'm talking about. I'm not talking about let's have it make decisions to kill people. Once again, I'm with them. Tropic on that we should not have a make the most. It would definitely not kill itself. But I want you guys to think of a scenario.
Let's say that there is an arm sale for X number of AK-47s from an African nation buying it from North Korea, right? And I want you to look at all the different types of ints to basically let us know like the intelligence sources that you would get, right? You would have humid, right? You would have human intelligence saying that this deal is going down. You would have SIGINT where you'd be able to identify and track, you know, what is the shipping within North Korea going to this specific ship that's going to be moving across the ocean and tracking that ship? You would have all kinds of different like geo ant where you can actually see that. You would also have financial intelligence and that financial intelligence can be part of the banking system. And it can also be cryptocurrency transfer where you know roughly this is how much this many AK-47s costs. We've seen this transfer and this much Bitcoin from this wallet to this wallet correlating to all of this stuff. Now, if you take all of those different things, right? In hindsight, when you see that, you can pull all of those data sources together and you can see it.
And a really good example of this is go back and read the report on September 11th with kind of tracks like CIA had a lot of data, but it wasn't their job and where they give it to. How would they give it to? What would be all of that? Now, all those hints that I talked about when you're tracking SIGINT, you're tracking signals from literally billions of devices, right? When you're tracking financial information, whether or not you have warrants as a whole another series of conversations we can get into, you're tracking a lot of data, right? So AI is really good at these types of problems, right? I want you to be able to identify patterns like these following or 15 patterns we can train it on. So it can start trying to identify these type of geopolitical and these types of criminal underground and these types of military actions. And that's fantastic. And that's specifically the area that I was working in and it was literally just thousands of people working their asses off. And they were only seeing one little tiny piece of the puzzle like they would say we just saw a massive amount of Bitcoin go from this wallet to this wallet.
What the hell is this associated with? And if you had the financial side of it, you could say well, that almost exact amount was transferred from this bank account in Switzerland to this bank account in Switzerland. Now we've tied those bank accounts to a Bitcoin transfer. There's a lot to this that is very powerful. And I can totally see how this would work for something like that. Now where it gets really scary is like Bruce was talking about and you know Hayden had talked about it, right? How the hell are you going to secure AI data whenever it drops in and you have multiple classifications of data? You're going to have to either specifically what Bruce was talking about would be like Sapsar program special access programs that you have to be read in to get the data associated with that. And even whenever you're moving between the towers, you're moving between the CIA, the NSA, the NRO. They can all have data classified at top secret and maybe SCI that doesn't mean that anybody can read that SCI data. So that's where this gets really dicey.
So there's applications where this makes absolute sense. And there's applications where I'm like, well, this is some of the most terrifying shit I've ever seen. The agents and asking each other. You know, with all the, you know, the assembly of all that data and it's looking at all the information. The question still is or one of the questions is how did you control for all like the inherent biases and all like this historical data? You know, then make sure that it doesn't hallucinate things or it's not like a sick event being like well, I looked at all this and I'm not able to give you the answer that you want. But based on our history as a country and the things that we like to do when we can't find the answer. You know, like we referenced like September 11th, they would probably put a lot of bias into some outcomes there as well. Is it going to look at the same things going on and going, you know, in the absence of anything definitive? I'm just going to kind of take a guess that's going to make my handlers happy and here you go.
The person is good for it. There's an, there's an arm steel going on. Yeah, I'm going to kind of make some stuff up that there's so much data that who's going to go through and double check your work. I have no problem with that Alex too. And the reason why I don't have a problem with that is that already exists today. When you're working in these intelligence places, you constantly have humans that bring those biases to the table. And with you 110% is you can hold somebody accountable. When it's AI, you don't have that level. You can't check their work like a person you can go. They can go. These are the things that looked at either the conclusion you go right here. This is where you made your error versus AI is going to be like trust me because who's going through all those 10 decades worth of. It's going to take you 10 years for a person to double check it or you have another AI that fact. Or you have another. Oh, there we go. Oh gosh. What then happens if they disagree because AI's love to disagree. They will fight with each other like, oh my god. It's going to be the 10 GBT and have an anthropic look at it. They're going to be like, no.
I mean, rock makes the final call. Like the tie breaker. Like I'm definitely blowing something up. Well, just strike. Launch it. Yeah, just jump. Just kind of just launch a strike. So making up strikes. So, sis, I guess is urging endpoint management systems for hardening after the cyber security attack. Obviously against US organizations. Right. I think this is related to striker. Yeah, striker and the old Microsoft in tune. I mean, you know, I definitely get the alert here. Right. I think it's just more, you know, more of a general thing to be like, hey, we're kind of under cyber attack for organizations across America. Right. But yeah, endpoint management systems are the fun way to gain big access. I did see a lot of ways. And I don't think they've really, I haven't been able to find anybody talk about how it happened because we talked about that with some of our stock customers last week.
And so all we could really do is talk about how that group normally gains access to an organization. And we could give recommendations around that. But ultimately, like the only thing we can talk about is how to make sure that they don't use your intune to destroy your own environment. Right. But looking at the steps that it would take in order to do this and get to that level of access as well as then what does it look like when one of these does fire? Or like when a large amount of them all of a sudden start getting wiped, right? That is, I've seen several conversations around that. And like pretty much what are the triggers up to this final point, which for me, this is, let's just a destruction of data technique, right? Which is honestly like by the time you're detecting that, you're kind of screwed. I mean, I've done this on multiple red teams where as soon as you get access to a privileged account in a sure you'll see what if they have into an access or if they're using into. That's a great way to spread quickly into the internal environment. So I mean, it's it's been known for a while. Like you said though, how did they get that level of access so quickly?
I think that's kind of like the shock shock. I think I think the reason why we don't have that answer is I don't think they have the data. Yeah, it's one of those things were described to the plus plus. Yeah. The blog that you need for Microsoft. Yeah. I like, and this is a thing, right? Like you can see how companies respond to preaches. They're like, we were compromised. This is how it came through. Usually I say we've we've brought on Mandy into some other high. Yeah. We brought on Google to secure Microsoft with it. So. But they have like the flow of how it happened and that, you know, what are they doing to deal with it? A lot of the companies were they're just not saying how it happened. It's it's scarier to me because that means they do know thinking about it. Thinking about like the last couple of big name breaches. I haven't seen one of those reports in a while. True. Right. Like full breakdown of TTPs and what went through unless you're a customer of them and you're like screaming at them.
That's the only time I've actually besides maybe some of the Salesforce stuff that happened. Yeah. Yeah. I was going to say I just want to like almost theorize like put on the tinfoil hat and say like, oh, they're trying to keep things secret. Like this is something that we also want to use too. I doubt that's the case. But that's a good point. Wade is that's it's becoming like a more recent trend with a couple of these big ones where it's like, how did this happen? We don't know. But everything that happened afterwards. Like you take your credit card. Take your credit monitoring and go away. Yeah, exactly. Right. We went into the long business. I should have started a credit monitor and company because they always. They always win. They always get paid. Right. They always get paid. I was also going to bring up the the other thing not to roll back to to AI's. But I think this does go to to hardening, which is a password. Right. So we had another article in here about AI generated passwords. I guess people are using their assistant to ask her passwords.
Right. Yes. Yeah. And so if you don't know, the magic of AI systems or LLMs is pattern recognition. Okay. They inherently create patterns. Right. And when you have a password, you want it to be random as random as possible. Right. So how can I say this? Don't do that. I think it's fine. I disagree. I'm being very caught wearing today. I think it's fine if you call up serious and you ask it's chatbot. What does it recommend for you? Oh, that's right. What's the data to pull from? It's got so much data. It's so much for 64-digit character password, right? Like, yeah. In the end game, unless they get access to your chat logs, does that matter? Never happen. Never. Ah. We also convinced everybody that like pass phrases are the vibe. So if we're doing shitty poetry the whole time.
Like, you got MFA installed. You're cool, bro. Don't worry. Are you Reagan on emo? Are you Reagan on emo password security? Listen, I don't think generative models are good at emo lyrics yet. Not yet. Emo is not good. Emo is not good. So I think the bigger thing is don't don't try to use LLM to like generate secure stuff for you. You know, I didn't know that had to be said, but I guess it does. And so don't. I mean, the bar is like your password managers are so easy now. Like, you go to log in and it's like, do you want us to log in and create your account and save everything for you? And then like, it'll probably mail you a click of it again. Yeah. It's like, as long as you pay us $30 a year, we'll like show up at your house and give you a hug at the end of it all. Like, it's the bars there asking chat GPT like 5.1 for your password or whatever. You know what? I'm just going to say this is another good idea because when I work with my family and they get breached or family and friends, and it's almost always the same thing. They're like, yeah, my PayPal got hacked.
I'm like, well, did you have to factor on no, no, I know you told us about that. It thinks giving you went on this long thing. I wouldn't let it get on my head. I didn't do that. And I'm like, what was your password? What was my name? What was my name? My dog. I can't help but think that chat GPT would give you a better password option. Right. True. True. I haven't pitched about that in a long time on this show. I haven't had any. I think my family members now know not to go to me. They're like, you need to talk to John. They're like, hell no. Don't talk to John. I'm not. I'm not. Tell him. It can have all my money. I don't want to go through that. I don't want to talk to John. I told him he talked about it on his podcast. The judging asshole. Yeah. Through and explained everything about how I didn't listen to it. Didn't want to like the regulatory people change their password? Who is the one? The one people you always hit on for always having a short password. Oh god damn PCI.
They did. They did. But I think they went to like 12 characters instead. For those of you that don't know. You know, this has been one of the things I've been ranting against for a long time. It was like up until like last year that PCI finally up to their password complexity requirements from seven characters. I think they did it to 12 characters, which is still bad, right? And the reason why I hate this so much is I think Ralph was on a pen test when he was still at BHIS. We cracked like 90% of their passwords. And they were like, well, that can't be a finding. Like, why can't that be a critical finding? Like, well, because we're in complying with PCI. I'm like, you don't understand. It's just nerve racking. And then I started calling it out. And then I literally had people that would contact me. But like, dude, you better not start beef with PCI. Those people will destroy your life. Like, look, there's the PCI mafia and computer security. Like, I'm not that worried about that. But they finally updated. I don't even know Ralph.
You got me on this tangent. So screw you. Oh, no, I didn't. I got it. Yeah, it was Ralph. It was Ralph. It was me. It was at the person who was in a password company. It wasn't Mr. One password himself. What? Somebody else just mentioned the OSI model and completely sent me into work. Right? I just, I just hate it. And this, I'm going to get. So the next story I want to talk about, I just put this in. I hate this. And I want to, am I over thinking this? I hate the commonly exploited vulnerabilities from Sissa. I just, it makes me so mad at because you have a whole bunch of organizations out there that don't patch it unless it shows up on Sissa's commonly exploited vulnerabilities. And I think it's a few hundred right now. Like, there's literally probably, I think maybe we have a million. I don't even know what tenable and quality tools, how many vulnerabilities they're scanning pool. It's got to be hundreds of thousands, right? And the attackers are going to exploit any of them that show up in your environment.
They're not going to be like, oh, well, it's not on the commonly exploited vulnerabilities. We're not going to exploit that to meet. It's, it, it just makes me mad because there's so many organizations that are looking to meet the minimum. And this is creating yet another minimum for them to meet. And I want to know my off base on this. I don't know. I think we've gone over this before where we just need to have some company who just writes about vulnerabilities and then gets them to go viral. And then you just point at that article and be like, hey, look at this vulnerability. He's being like, submit a vulnerability here so we can write about it. So your company will see this article and then patch it. But I agree with you like this list, like, I've dealt with it too. And as like an intel side of it, right? I would then pivot and find other people writing articles or doing something if it's not on this list. But like, hey, here's seven other things just because it's not on Sissa's list. Doesn't mean it's not screw it. Let's, let's, let's buy code this app. Let's start a startup right now. We're going to start this company where you pay us money, right?
And then if you want something patched, you come to us and you say, hey, I need an article saying that this is actively being exploited by the Russians of Chinese. I needed to hit these following points to get management to agree. And then we will write that article and post it. Yeah, I will write that article. Oh, yeah. I wrote the bot to make whatever I can be all talk about, but it was on restream. That was the thing we had restream plugged in. Now, hey, didn't I have to rewrite the bot for zoom because we're doing it on zoom today? Do it on that. Never talk to you. Compliant. And it's going to post it. It's going to post it to like Instagram, Facebook, LinkedIn. It's going to have like influencers and Reddit. So it looks like it's a big, big deal. So if I could interject, I think the one thing to keep in mind with Sissa not to defend them necessarily. But I mean, their mission is protection of federal government assets and critical infrastructure and that kind of thing. And there's been a historic gap in the federal government around who's there to help the private sector and who's tracking it and whatever.
And there's ISACs for, you know, kind of designated critical infrastructure verticals and that kind of thing. But in general, like, you know, we look at Sissa be like, come on, be better. And you poke over the stick, but the reality is like they're their first and foremost trying to protect federal agencies and just telling them like these cats are like, you got to do this thing by this date. And that's why they issue it. And then private industry has been like, oh, we'll use that too. But it's a terrible barometer to your point of private industry because attackers are going to, they're going to hack, right? Criminals are going to crime. And they're going to figure out the best way to do it. Sissa is, I mean, there is no federal agency that has the edict to protect the, you know, the citizenry and the businesses at large. All right, I got it. I got it. So we do it. We pull a card out of the better business bureau and we become the private sector cyber security bureau where people think you are government. But we're really not. You know what I mean? So in, in for the, like, the CSIC have, like, it depends on like what the capacity is of the organization. So I know we look at it from a lot of the organizations that have the capacity to do a lot of patching.
And then they go, we can only, we're only going to patch like the CSIC have stuff. But there are a lot of organizations and I do this as you like a volunteer for the Wisconsin cyber response team. We help out a lot of like, you know, school districts, local libraries, stuff like that that they do not have a huge amount of staff. They have a fishing incident. You have to explain a lot of the basics to them. Sissa Kev is going to be the same type of thing where you go. Okay, where do you start with the patching? You got to start somewhere because you don't have the capacity to do a lot of patching. But yeah, we look at it from the viewpoint that, you know, yeah, you're, you know, billion dollar company. And that's just looking at the CSIC have been going to just patch those. That's bad. But also government agencies when we're testing, like once again, some of the stupid conversations we've had. And once again, I don't know why anyone does business with BHIS sometimes, where we have these conversations. Chad's going to take that. He's going to cut it. And that's going to be an advertisement. Right? It'll be a teacher.
But, you know, with these federal agencies once again, they're like, yeah, you exploited that. But it wasn't in the cab. So we don't have to patch it. I'm like, that's not what its point was, right? Like, and these, these are not conversations that happen a lot, but they do happen. And I don't know how we push past that, right? How do we get people to stop constantly looking for the absolute minimum? Or do we just let nature take its course? You know what? Whatever hackers will show you the error of your ways in a matter of time. It's just fine to let that happen naturally. I think that's true. And what I've been thinking this whole time is there isn't a ground level for security for anyone. So if they pick the cab, that's like pretty decent, because I'm used to talking to like middle and smaller large size orgs. So they're like, it's fine. It works. And that's like what I've talked about with aerospace people too. Like everybody's kind of mad that nobody thought about security for 30 years or something. And now we're like, whoopsies. Now we can destroy the universe by accident. Then you get into that cycle, then you get into that cycle.
It's like, well, legacy technology, all over OT. We haven't done security. We haven't done security in 30 years. And it would break everything if we started now. So we're just going to continue not doing security because everything, right, is on fire. So no, these are tough problems. It's like, I had that one lady. She would just got a SISO position at a very large company. And I went down and visited her down in Tennessee. And we did a security assessment of all of their apps. And they had a ton of apps that were access data. You remember in access, you could publish a web page that had the access app, quote unquote, that you created. They had a bunch of mission critical web apps that were generated access databases. And we found thousands of critical vulnerabilities. And she cleared the room. And she's like, what do I do? And I'm like, here's what you do. You stay here for a year, go someplace else. Because the only way that this gets fixed is if it all gets burned to the ground.
And I just met your developers. That ain't happening. And that's exactly what she did. I mean, there's sometimes where you're just like a purging fire would be a good thing in some organizations. Right. And I, and I think that we're getting into a situation where there's a lot of organizations that are doing things really, really, really, really well. And not everything is moving in that positive direction all the time. There's a bunch of organizations that are still doing horrible. So, I have one. But again, BHS, we can convince your SISO's to quit. Put that on a shirt. Put that on a shirt and wear it at a conference. Yeah. So normally we have a bunch of like breach stories. I did want to bring up just one breach story that I thought was somewhat interesting mainly from the person in the size. So supposedly there was a massive China data leak of 10 petabytes of weapons testing data. Oh, good. Yeah. What I think is interesting is that we normally don't see like Chinese, the Chinese government usually getting breached, right?
I just don't see it very often. I'm sure it's happened before. But 10 petabytes, and they're like offering to sell it on telegram. I'm like, where are you even storing that? We have that we have the same problem. We talked. It's the last thing with this. I think they're just making up numbers. This is like, who's buying this thing? That's got to be a made up number at that point. Yes. Yes. I bet $10 that this is going to end up on like World of Tanks. Or. Yeah. Yeah. No, it's a well, a thunder or something. Or thunder. Or thunder. There you go. That's where you go for all your military secrets. Don't ask me how I know. Yeah. And you think security geeks are horrible to be around when they're arguing with each other. Those forms are awful. Oh, yeah. I bet. What is the range of this particular like vehicle? It's like, and they will fight to the death on that stuff. You've got to cite your sources. You do. You definitely have to cite your sources. Yeah. I just thought I was interesting. Not the actual breach of what equates to just. It was from the National Supercomputing Center in China. But just the amount of data supposedly much of it classified.
I'm like, what? This is. I think it's a pretty cool truck. Yeah. That's not seen like Chinese breaches is just news bias. I'm sure they happen all the time and they get reported on in China. I know. You're also probably correct, right? Yeah. We're looking for something. I think the more important breach here that we didn't talk about was the crunchy roll breach. Oh, yeah. I don't have any. A lot of people. Yeah. That's the shiny hunters are taking on the weeps. That's all that's going on pretty much. I think so many folks that they're like, I was right to pirate all my enemy. So it was a third party actor who had access to Crunchyroll's data who is owned by Sony. I didn't know Sony owned Crunchyroll until this. Yeah. No clue. Right. It sounds like Info Steeler to tell you the truth. Third party got breached. That third party had access to Crunchyroll, then they extracted. I think it was only around 100 gigabytes worth of data, IP addresses, email address, credit
cards and PII, right? Nothing too crazy. Nothing too sensitive. But if you had your credit monitoring company, you'd be getting paid right now. They definitely know I watched only all of attack on Titan now as well as I still need to catch up on. All of your viewing history for the world, like the question like attack on Titan and one piece like do you ever like say, okay, I'm going to sit down and watch this and you realize they're into thousands of episodes and it's like so for one piece for what I will put this out there for one piece. There's actually a side one called one pace that gets rid of all of the filler stories and it cuts down on the episode count quite a lot. I will put that. You need to send that thing for that. Oh, yeah, I'll read the main gut so much better. Like real time or anything from oh my gosh, you just literally the only other. I don't even know how people approach Warhammer 40,000 or it was at 40K or whatever, like
you're here. It's like this seems like a lot of people are into this. How do I get started? And God forbid do you talk to a fan? Once again, I'm sure the computer security people are like that. You know, like how should I get started in computer security? Well, the first thing that you got to understand is that absolutely nothing secure. Your lamp, your TV, your fridge, it's all spying on you, man. Just like, oh, God, thank you for getting this room. It's John's house. There have been so many poor bartenders at security conferences where they're like, oh my gosh. They're like, please. There's this also book out encryption and like all the mathematics and it's all rooted in like these algorithms and everything. The bartender is like, I, oh, I hate this guy. It's no worse. So years ago at Sands, we were doing a conference at the Wardenban Park and we were doing faculty faculty shot Fridays where we'd all go down during lunch and we'd take a shot, which was a horrible idea. We did that like once and it was over and we were talking to him and the bartender was like, so what are you guys here for?
What's the conference? And I'm like, oh, it's a computer security conference in Bruce Lee because she's like, I was stuck here during a snow storm with a bunch of security professionals and she went off on the snowmageddon conference and it's like, you people are awful. No, my God. That's great. That's us. We drink a lot. So apparently we ran them out of liquor. Yeah. And they had to, they had to sleep in the hotel that year because nobody could get in around. And so some people were on shift basically for like a day and a half during the snowmageddon schmuckon. That was one of my favorite, actually, that was one of my favorite memories ever in computer security, like walking across that bridge when there's no cars and it's like a foot and a half a snow and nothing. That was so cool. So I put one more in dark sword, iOS exploit chain. When Google does a write up, they do a write up, holy crap, I just put this in chat and they're going through this entire toolkit that you can get specifically targeting iOS and it
has exploits in it for like, you know, what does it snap chat? I think was one of them in here. There's all kinds of, it's just, just, this makes me cry with joy whenever I see this level of writing kind of breaking down these particular kits and all the different aspects of it. But this particular exploit, they think it's associated with Russia. I find it interesting that they can't directly attribute it to any threat actor, but it's been used in Saudi Arabia, Turkey, Malaysia and Ukraine. I had seen some people talking about it saying, yeah, it looks like it's Russia. Other people think it might be in Israeli kit that's being used, but, you know, basically going after iOS versions 18.4 to 18.7 has six different vulnerabilities to deploy a number of different malware families. The malware families are ghost blade ghost knife and ghost saber has mirrors the Cortana iOS exploit kit as well, which was, I believe that that one was confirmed as Russian, but
I'm not 100% sure on that. But just a really nice write up on this and the delivery mechanisms, like I always kind of talk about the NSO group and how delivery mechanisms that we see in a lot of these nation-state level boils down to utilizing ad delivery networks and the complications of actually doing that are pretty substantial, but a really great article of, you know, how these work and the thing that I keep coming back to, they have all these IOCs and stuff. Anybody monitoring their mobile devices? Like, do we have any logs that we're getting off them? Are we getting any? We're in protection on these devices, so we installed it. We installed iTunes on everyone's iPhones. And iTunes is in tune, my bad. You put iTunes on there, me too. Yeah. What's the, like, one of the first things I think I've always done when you get to a network is figure out what people's guest Wi-Fi is and immediately take whatever that network is
and do not alert on it, because the amount of garbage when someone connects with that gets bad things. Yeah, there's no way, like, I put three EDRs on my iPhone. That's how you keep up to date with it. And you got those from the store. I'm out of money. This one looks good. It's got five stars and four reviews. I'm sure it's like, well, I downloaded off the app store. It said it was good to go. Like, it said, like, secure your phone. I keep getting ads. Still weird. Yeah. This is really dark sword, and it's like, icon. Yeah, what was it? Remember when adblock plus got pulled? Adblock plus was trying to, it was proxying all the traffic through itself, and they could filter out ads globally, not just in your browser on your device, but all ads in any app. And Microsoft and Apple were like, no, not today, Satan. So I think it's very difficult for any application to get the level of visibility into a phone to do that level of security just because of the way their security models are built.
Yeah, yeah, the phones are, the phones overall are pretty locked down, even though there's definitely ways to abuse them, you know, and so are they though? I mean, that's one of the things that bothers me. It's like, yeah, the phones are pretty locked down. We hear about these exploit kits. We hear about companies that are doing it, and it's so locked. I think it's locked down so security researchers have a hard time like doing any security assessments in it, but is it just like, no, no, it's locked down? Trust us kids. It's fun. It's not like a general purpose computer, where any kid with a dream who lives in Norway can start taking a part of patchy, right? It's a little bit varied. Entry is a little bit higher. Like it went when, hey, didn't have you ever seen mobile device logs? Forensic. That's not the same. That's not the same. I mean, like, that is, yeah, right? Like, I would say there's like no security on cell phones, whatsoever. And that is like a ripe attack vector, right?
Because there's everything that's on your computer is going to be stored on there, and as well as access to MFA. When I think that the threat model is really, you know, one Z2Z, right? Like, you got to be a target. I think that the, I mean, to go all the way back to being in the show, talking about compromise by the end two. The only reason that's possible is because in tune, there's install that every endpoint, you need to pop the MDM and you just go on everything. You know, at least with cell phones, like, it's trench warfare. And, you know, they got to go like, they have to be interested in you as a person. And what you have access to to go get it. And then they're going to spend that. And then they might get caught, right? It's a really expensive. And it's more Intel than cybercrime. I think, actually, because we've seen enough infostealer malware where everyone gets it, right? With different browsers. What if an infostealer malware targeted cell phones? And then custom saw that, right? What they do, and, you know, when we're looking at the cost, I actually somewhat disagree, right? If you're a nation-state level adversary, right? And you're going after a particular organization,
it becomes a lot easier, like, to target one of their systems administrators to gain access to their phone. The initial cost would be high as a per-device calculation. But you can actually specifically target individuals that are high-value targets off the gate. And that's some of the things that we've seen, like I said, I keep talking about, like, NSO Group's capability of doing highly targeted malbertiesments where you can identify a specific ad profile for a specific individual. You don't have to provide their name. So, yeah, it's more expensive for exploiting per device. But I think with some of the targeting tools that are out there, do you get that return on investment a lot faster because you can target those specific individuals? You're going to say, like, to be able to move faster, chain things better, and get to be able to make better use of it for, you know, get that hash. That's just AI, and everything, just making things move quicker. You're seeing a lot of the low vulnerabilities
getting chained together and getting exploited. But I think, yeah. But either way, kind of getting back to the point in the logs, though, Alex, we're still just sitting in the cave, making shadow puppets on the wall. We don't have logs off of these devices. How can we make a determination one way or the other if we don't have visibility? And if we don't have visibility into a particular part, do we have security? And, you know, at BHIS, we've got a huge amount of pushback. It's going to happen one way or the other, folks. Where we are now, you're putting the security tools on your device or you're going to run a dedicated BHIS device. And then we have the visibility that we need. And that is such a cultural shock even for people in security to say, wait a minute, I don't have full privacy on this. It's like, no, if you have corporate data on it, I need to have visibility into that, right? Either A, you're running one that I give you explicitly for this task, or I'm going to put some software that gives me the visibility that I need to be able to see what's going on. But we're so caught up into, like, letting go of this binky, shiny metal box that we have
that we think is our universe, that people I don't even think they want to have visibility into at the vast majority. And it needs that shift away from the, I'm not a target. Like, you understand, there's like that threat modeling. Don't be like, you know, sky is falling and everything. But it's just if we don't have these those logs, we don't have that visibility. If we don't know how we're saying, like, hey, I'm not, you know, we're not targets. We're not interested in me. It's like, okay, and we haven't gotten it. And we haven't gotten into ads. This time, Alex, it's just weird because you're on the show. Usually we go down that path. But the reason why they don't want us to have that visibility is because then we would have visibility into the amount of privacy violations that are happening on those devices. Because if I can hook at the kernel level, if I can hook and do a full packet capture on what's going on and decrypt what's going on on this device, then you're going to know just exactly how much data Alexa and Siri and all this shit is getting on you, right? Exactly, that nobody wants that. A lot about you. And then when you're able to see those logs, everything that people have about you, then you go, hey, wait a minute. Maybe I am part of this threat model.
Maybe we do have to start worrying about it. Maybe we do have to loosen our grip on that that security blanket chat. GPT is about to drop their ads. Everyone's about to start getting them. No, really? I didn't see that. Why didn't we talk about that? I mean, it's next week, next week. Yeah, they talk about the Super Bowl. They've been like hating it hard. But yeah, there's going to be a bad thing. Yeah. Yeah, all right. We'll say that from next week. Hey, thank you, everybody, for coming. Let's bring out the cricket finger. Thank you so much. And we'll see you next week. All right.
More episodes
More from Talkin' Bout [Infosec] News

Anthropic Warns Users of Infostealer Abuse - 2026-09-08
Talkin' Bout [Infosec] News

South Korea Offers Free AI Services – 2026-08-31
Talkin' Bout [Infosec] News

Using AI to Debug the Linux Kernel - 2026-08-24
Talkin' Bout [Infosec] News

White House Announces "Digital Letters of Marque" - 2026-08-17
Talkin' Bout [Infosec] News