Skip to content
TrackPodcasts
newsSep 5, 202636:07

Radix Malorum

About this episode

OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI

Get every episode summarized

Each time Security This Week publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

657 searchable segments. Every word is indexed and playable.

Radix Malorum

Security This Week

0:00
36:07

Full transcript

Security This WeekRadix Malorum. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Hey, Carl here. We're on a mission to find new fans of the show. I mean, where else can you get real-life comedy and horror in one podcast? You can do your part by leaving us a review on iTunes, Spotify, or wherever you get security this week. Also, you can get an ad-free feed by becoming a $5 a month patron. Go to patreon.scuretythisweek.com and sign up. And don't forget discord.discord.scuretythisweek.com. Lots of good stuff happening there. Yeah, I think that's it. So on with the podcast. Do you suffer from shyness? Do you sometimes wish you were more assertive? Ask your doctor about tequila. Or donut. Side effects may cause beer goggles. When my wife and I started dating, she said, I'm not allowed to drink tequila.

All right, we've got a few stories for you today. This is security this week, by the way. I'm Carl. That's Duane and Patrick. This is kind of good news, I think, but it confirms at least what we've been talking about all the time. Siss of vulnerability review. Old simple flaws drive most breaches. Oldies, but goodies. Oldies, but goodies. Yeah, that's right. Wayne's still using printer like defects from... Oh my God. Years ago. Well, I mean, and sequel injections been on the top of the... Oh, I spilled list for how long, right? It's they started the list. Since the list began, yeah. It's like that FBI's top 10 people to get. It's the same people. The thing here is that we talk about AI being evil and models being evil, which is the title of this show. But in fact, most problems are caused by old issues. Yeah. We'll have the longest time for people to figure out how to exploit them,

because it exploits to mature and get more of that less variable. Yeah, but I'm going to take the negative side of that, Patrick. We've also had a lot more time to understand how they work, so that people, developers, should be actually fixing them. Oh no, I'm all on board. I'm just saying you give the hackers... You give the hacker community a decade, and scriptkitties will even be proficient. Yeah, so it goes through... It's an interesting breakdown. At some point, if you click on the links to the show, you'll see they break down some of the different types of attacks. It's not saying the most dangerous ones are the ones that have been around forever. It's just the most frequent ones. There are input validation errors. How many times have we told you on the show, never trust the user, whether they're talking to you or whether they call you and say they want to switch their bank account, or whether it's their typing data in the browser. Or whether you can imagine how they could exploit it. Yeah, absolutely. Because you can't imagine it, doesn't mean it's not possible.

Yeah, and actually not to foreshadow a little bit, but one of our stories here, we will talk about trusting the user in their browser a little bit too much, which caused untold damages. Yeah, injection issues. Here again, we just talked about SQL injection. So for those of you who may or may not perform injection all the time. Lock that fine line. An injection issue is where you're expecting the user to give you input of some sort. Whether it's, what language do I want the browser in, what data do I want my T-Time at this call course, whatever it may be. Like your fake cooked. Yeah, exactly. Whatever you're expecting the user to give you. Or expecting to come from the user's browser more importantly. Because a lot of people will just assume, hey, I got five fields on this that the user can fill out.

So that's what I'm expecting. But there's 15 other fields I take from it that I'm just holding variables in the browser. X ones are the dangerous ones is the elite. Right, exactly. Developers always assume if a user can type in it, it's dangerous and I should keep an eye on it. But the problem is every field that gets submitted back on that form is something the user can edit. Inject. Yeah, ultimately. Right, and inject into. So these are the types of issues and they pop up. So input validation, memory safety issues. We talk about buffer overruns and that sort of stuff. Injections, access control deficiencies. So we've talked about these are probably the core of most of the stories we've talked about. Yeah. Is, you know, every time it comes back to, oh, and then, you know, the keys were in the page. Oh, then the user did, you know, or one equals one. You got access to the whole site, right? And social engineering tops the list too. I mean, that's kind of the root of all the radix malarium.

The root of all evil. Radix malorium malorum. Do you just make that up? Radix malorum. Radix malorum. So it's from the Latin radix malorum est cupiditas. You know, avarice is the root of all evil. Radix malorum. Yeah. I don't even know what to say about that. I went to school. What can I say? I'm sorry. I learned a few things. Patrick, our boy is so smart. You're mom and I are so proud call. Yeah. Okay. Okay. You get back. I'm Arab. Alright. So the next one is kind of seems important. The proof of concept published for Linux kernel privesque flaw. And I was reading it and I was trying to figure out how the heck could, you know, how hard is it to, to, how easy is it for somebody to be exploited? If they have a Linux box that's on the internet, turns out they have to have a user account, right?

Yeah. I mean, this is, this is a straight up privesque and it's interesting. And it's an interesting one. You know, walking through the attack, right? It says the issue resides in the eye. Don't worry about the functions, but the IO pole get ownership function. Okay. Great. So there's some sort of function that pulls ownership. It uses a signed comparison to check a specific slow path. Don't worry about slow path threshold. Signed meaning. But that both negative and positive. Yeah. That's what I want to focus on. Yeah. Exactly. So I had this conversation earlier with one of my children just yesterday actually. And we were talking about the memory structures of variables. And if you take an integer, right, a number, and you make it a variable, there's a certain size that you can store in that structure. And the size of the variable might be, you know, 3, 2, 7, 6, 7, right?

If it's a signed integer, or it might be 65,000, if it's an unsigned integer, because the last bit is generally used as to whether the number is negative or positive. So if you say it's unsigned, right, then you can have a much larger number, but you can't ever have a negative. If you say it's a signed variable, then you have, you know, positive, 3, 2, 7, 6, 7, and negative, 3, 2, 7, 6, 7, let's say. Right. So you have the same kind of amount of variability in there, just whether it's negative or positive. So this is a classic problem, more with C and C++ than other programming languages, where you had to declare whether this was a signed or an unsigned integer. And then when you went to to make a comparison, it would then say, oh, well, I'm comparing this to a particular number. So in this particular case, all right, now that we know what signed is, in comparison, the atomic read function, nobody cares, operates and returns a signed integer.

So if you call IO pole cancel flag, doesn't matter, the value becomes negative during the signed path. So at some point, it's calling this IO cancel flag and the last bit is set, so it assumes the number is now negative. Well, in the world of comparisons, if you do a true false, anything negative is false, anything positive is true. So the number 5 is true. The number negative 3000 is false, right? So it's that weird place where you're using this variable in a way that it wasn't supposed to be used. Right. In this particular case, somebody figured out how you could go from a regular user, and Carl was right here. You have to be a regular user, but you can go from a regular user to an administrative user on these versions of Linux. Wow. Yeah, that's bad. It's not good. Very similar. This reminds me very much of a type confusion flaw.

I haven't seen a lot of really good type confusion flaws lately, but a type confusion flaws is in languages that are not strongly typed. Like JavaScript, for example. Yeah, great point, Carl, like JavaScript. And for those of you, if you want to go a little bit into that, Carl, like for the for our non-developers on the call. Yeah, so JavaScript makes it easy for you just to pull variables out of thin air and say, you know, x equals 1, y equals hello in quotes. And it knows enough to treat the first one as a number and the second one as a string. But then, you know, if you say z equals 1.1, that's different than x equals 1. Right. So behind there, one is an integer. We don't know if it's signed or if it's unsigned. And then the other one, it's sort of a decimal or a numeric. Right. Yeah. And then if you do some weird stuff like, you know, x equals 1 and y equals hello. And you do x plus y.

What happens? Right. Right. So the computer goes, oh, hello must be, maybe it's the ASCII numbers and maybe I should do whatever. There's a place you get to where the developer, the developer may not know what the heck happens when that addition happens. So type confusion is an interesting style of attack. Well, I haven't, like I said, I haven't seen one in a while, but this, this feels very type confusion. Yeah. So I'm going to call a strike in on my own position here, possibly. But I read something or, or there was a story a year ago. I think it was before we started the podcast where they were talking to Linus Corval, who was the guy who started Linux. Right. And they pointed out that there were some problems with the Linux kernel that were architectural and problem. And he's like, no, we're never going to revisit that. And, and you know, fantastic developer, better developer than me. But when one guy writes or one guy supervises the writing of an entire operating system in his spare time, you got to wonder where the, where the, the technical debt sits.

And I think a lot of it might be in the kernel of Linux based on these kinds of things. This seems like it seems like a mistake that shouldn't have been made in an operating system that's going to be used for the enterprise. Yeah, you would think so. His Linus Torvalds had AI. Do you think that anybody could have come up with that? Could we have a carl X or pad X or Dwaynex? Probably. Heck yeah. That's not a view. I'm going to create my own. I'm going to have to believe that's true. Given that you start with the Unix. Yeah, but we still do it. Yeah. I mean, could I make a, I'm not a version of Linux, but a whole new Unix based operating system. But yeah, you could make your own operating system absolutely right now. And also make your own Bitcoin. It's called Doge. Okay, we moved on. We've moved on. All right. Sonic Wall patches two new actively exploited zero days in SMA 1000 VPNs. Oh no. Zero days. But it patched them. So that's good. They did. Yeah. I know.

Hey Christmas. Yeah. So Sonic wall. These are. I love that band. I know, right? Kids. Yeah, they were great. It's Sonic wall. Okay. Wonder wall. Anyways, Sonic wall patches two new vulnerabilities. This is, so Sonic wall devices are generally targeted to small, the medium businesses. You don't generally, you're not going to see like Apple running a whole bunch of Sonic walls. You know, at the 10. Yeah. Okay. So this is a great point. So this one was marked as a 10 and here it's cured this week. We always like to figure out, is this really a 10 or is this kind of a BS 10 and it should be considered a 7? Well, we want the contagion score, which is how likely are you to get it? No, if you're running this version, you're already in trouble. Okay. Yeah. This is. This takes very little technical knowledge to run. There's already a POC out on the internet and it's not hard to find your patch. Is it patch? Yeah, it's patch. You can absolutely go patch it. But if let's say you're not, like this is targeting small and medium business, right?

Most small and medium businesses, you're running a barber shop. You're not running around, you know, keeping up on security news and patching your Sonic wall. Right? So there's tons of these devices out there. Although I guess what would you do as a barber shop VPNing and back to the shop? Anyways, so there's tons of these devices out there that are unpatched right now. The POC is out there. It is super easy to run. It is a form of SSRF, which is a server side request forgery attack. So for those of you who haven't been familiar with SSRF attacks, an SSRF attack is where I can make a call out to a service, whether it's a web server or in this case a VPN service. Most of the Sonic wall VPN services are a web server, whatever. It doesn't matter really because you go to a website you log in and it gives you access. But you go out to a website and you make a request and what happens is that server then makes a request to itself on your behalf.

So it looks like it's coming from inside. And that's generally what a SSRF attack is. Is me conning the device into doing my bidding for me on a back end channel so that it trusts it. Yeah, so this one does not look good. And this is preauthenticated by the way. That's the other reason that this is kind of a scary attack right now is you don't need a username or password. Just find the Sonic wall on the internet. Run the proof of concept. You grab off a GitHub and boom, you have access. Hey guys, this seems like a good time and place to take a break. So we'll be right back after these very important messages. Don't you go away. So guys, I went to the Humane Society the other day and I got myself a Mirage kitten. And the Mirage kitten is a really interesting kitten because you can see it across the room. But as you get close, it just disappears. What? You can still hear it going. All right.

The story is Iran linked APT Mirage kitten uses fake job tests to spread mulwow. Mulwow. These countries, North Korean Iran are making the world. They're ruined in everything. I know. They give it a nice Mirage kitten. They give you a bomb all over again. So this is a LinkedIn coding test, right? Yeah, absolutely. You apply for a job and you apply for a job and they give you a coat test. And they say, hey, we need you to use, it's actually funny. This exact path, actually, maybe they've been listening to Security this week. This exact path is a path that we presented probably six months ago. Who's the way? We, as in we, the security cabal presented to one of our customers as a viable path to breaking into their organization. Who's the way? Listen, we'll just hire one of your developers who we see does side work and will force them

to use libraries, not force them to say, hey, we'd like you to use this library and this library and this library and they'll be infected. They were horrified. Yeah. And they were like, wait, what? They were like, that's, so we'll absolutely could do that. And apparently Iran's like, you know what? We like that. That's a great path. Let's do that. That's what they're doing. Those fake jobs force you to use, you know, libraries that you don't possibly have time enough to read through. And when you make a call to it and infect your local computer, what's holding information, info stealing, blah, blah, blah. Well, yeah, what's the, what's the why for Iran linked, Mirage, Kitten or whatever? What is the, what is their goal? Do they just want to infect people randomly or do they want to, you said something like information stealing, but what is it going to get them if they get some, you know, out of school code, code or want to be, mean access to their computer? Both Korea does it for the money. They do it so that they can steal the money to, to build missiles.

I mean, like ransomware. Yeah. Like ransomware, but in this case, also think about the fact that you control the job posting. Yeah. So if I say, oh, I need a candidate that's TSSCI, right? So top secret, secure compartmentalized information knowledge. They're certified to deal with US secret government, you know, stuff. Korea job might be US secret government. Right. So when they say, oh, you know, we're a division of the, you know, DOJ and we need build of whatever. And this is a, you know, we need you to go through this task to see whether you're, you know, smart enough to develop whatever. Now when I get on your computer, there's probably, I mean, I mean, if you're following all the regs with TSSCI and zipper and nipper and all that good stuff, you shouldn't have anything secure on your, on your, your computer, but chances are they might get garter access or information that'll help. So that way, I would guess that's a RANs target. The Maraj kit and is let's see what type of sensitive things we can pull from people

and then just gain and continue access, maintain access to those devices. Okay. Is there anything that we can do to protect ourselves except for don't answer stupid emails and click on links? This is a tough one. I, this is one of the reasons we proposed to this to attack our customer because it's like, I could spin up a real company with a real name, with a real 800 number, with real people on LinkedIn and it could literally look like a normal job posting. Okay. Let's talk about this then. If you were somebody who really wanted to apply for this job, you checked out the company and they came back legit because they did all the things in their nation state, but the way I would approach it if you decide you're going to have to do this is you set up a segregated VM. You download the things there. You run it with separate accounts on that VM. You get AI to talk to look at all the libraries ahead of time to see if there's anything untoward

in them because it can look through all the code even if you can't. And you do that test on a throw away VM. That's the problem is it's a lot of work. It's not easy. That's an interesting point though, Patrick. In nowadays with AI, it could be I spin up a VM, I have a trash VM, whatever, but I also could have cursor read through the library and be like, give me an initial understanding what this thing does. If they're giving us the code. Now, if they're giving us just a DLL that we call entry points on, I don't know me personally, I'd reverse engineer the DLL and strip it apart, but normal humans might be, okay, I'm going to do this on a throw away VM and just destroy it. The mythos. Yeah. Yeah. But still, even if you did it just in a segregated environment, I mean, hell, rent a VM on a hosting provider for a month and use it there and then throw it away. The problem is cost and time. And right now the job market is so obscene.

Right. Companies that are listing jobs that don't exist because they're trying to hype up their company as a growing company. They're AI that's a friend of ours, Ted Newert had a post where somebody he knew, I think it was somebody he reposted, was a hiring manager and they couldn't understand what HR just said, no qualified applicants. And he needed somebody for his team. So he took his resume, changed the names and the dates, submitted it within six minutes. The company's AI rejected him as a candidate for a job he was fully qualified for. He was looking for react dot JS with a certain capitalization and punctuation just said, react. It's it's it. Oh, you don't have the right technologies and threw you away. Wow. So it's we're just in such an idiocracy in terms of the job space. I can see people being desperate to find something if they've left the job. Right. And we miss right away. But it's a trap. It's a trap.

Be careful. I said, all right. Hackers push malicious virtualizer update in BGP hijacking attack. What's BGP? BGP, big, great. You know, I can't even come up with a with a real funny thing. Yeah, exactly. Yeah, exactly. The call has been around forever. Yeah, exactly. So a border gateway protocol is how the whole internet works. Right. You're making this up. So let's assume. No, seriously, if like, yeah, it's that magic thing that nobody understands, but that's how all my bits get to your bits. So imagine you want to go to an IP address. So OK, let's say let's imagine you want to go to Google's DNS to talk to it. Google's DNS is eight dot eight dot eight. The reason I use that one is super simple. So my computer is going to try and reach out to eight dot eight dot eight on my local network. Obviously, it's not here.

So it's going to go to the router and or gateway and say, hey, I need eight dot eight dot eight. My router and gateway is then going to upstream it to my ISP and say, hey, do you know where eight dot eight dot eight is? And my ISP, for me, here is Phidium, then is going to use BGP to say who is announcing that they own that range? Oh, OK. And that's going to come back to you. So it's Google owns that range or it's, you know, whatever, it's usually a major provider. It's not like, you know, Pulse or Security owns that range. So it's sort of like DNS for IP addresses? Exactly. That's a great analogy. It's like a phone book. Yeah, exactly. And it's interesting because DNS ultimately comes down to IP and then IP then comes down to BGP. So BG, when I say it's how the internet works, it's literally, yeah, the internet works. Not how a network works, but how the internet works. Yeah, that makes sense. So they don't go into, so if I can hijack a particular broadcast, I can say, oh, I'm

eight dot zero dot zero dot zero slash, you know, whatever. Then I own that IP and anybody who goes there is going to come to me. So this is dangerous because it's so fundamental. It's so low level. Yes. It's like drawing the phone company, switching. Yeah, exactly. It's, well, let me put it another way. I mean, most brainwashing happens when somebody is told and eventually believes that some fundamental fact that all of your other facts are stacked upon something at the lowest level is was true. And now it's false. The sky is green and the grass is blue, right? And the card said there are two lights. Yeah, three lights. Three lights. There are three lights. Yeah, exactly. Some fundamental belief is twisted and then your whole house of cards comes crumbling down. And that's exactly what I see here because it's so low level that it affects everything

upstream. Yeah, exactly. So in this particular case, so I don't get the thing wrong. And urgent notice from the vendor will you to see around August 30th, an attacker routed a block of Hetzner hosted IP addresses in a BGP hijacking attack. What they, an essence we're doing was they were saying we are this range. And then a certain number of people believed it and started coming to them for updates. They were attacking this virtualizer software, which is a control panel for virtual private servers for the PCs on the internet by a company called soft delicious soft, soft, soft a cool. Yeah, I don't know. It looks like soft delicious, which sounds weird. It does soft soft a cool. It looks soft soft a cool. Yes. Anyways, so what would happen is now legitimate requests for updates for this panel would

actually go to the attackers instead of actually going to the legitimate backend source. And it would be hard for you as just a normal human updating your software to see the problem because you don't have control over it. You're just routing where the internet is telling you to route. What I will tell you though is if a software update, like, okay, how do I protect myself? A software update designed properly from the software vendor would actually have probably signed the update with their own key. And when it makes it down to the software, it then checks the signature before it applies it. So my guess is, as we dig deeper here into this article, there wasn't. They didn't actually properly sign this. Those updates. Human error. Yeah, so it's interesting. I mean, secure. We talk about all the, hey, you should do this and you should do that and blah, blah, blah. But somebody actually BGP, there isn't much you can do other than... Yeah, I hope.

Yeah, even lower. Hope the vendor does something right. Okay, extortion group, Fulcrum Sec claims 86GB Manchester Airport's group data theft. Too close to home. Is it? No, not that, man. Actually, I got this one from Cliff. I think one of probably two guests we've ever had on this show, but... Yes. That's right. So Cliff posted this in the Discord. Actually, this is probably a good point for me to bring up. The Discord now also has, although we've been getting a ton of new users, which is awesome. I've also added a Cyber AI channel. Oh, because we've been talking a lot more about Cyber and AI. I figured there's probably a good place for us to put some stuff down there. Okay. Yeah, so Cliff hit me up to this morning and was like, hey, have you seen this? And I started reading through it. It is an interesting attack. These guys, the Fulcrum Sec group, they've been hitting some pretty big targets, and they've

made a name for themselves as the no BS attackers. If they call you up and say, hey, we have 100 gig of your data, they have 100 gig of data. Oh, believe them. Yeah, believe them. The bleeping computer actually reached out to them when Manchester Airport Group disclosed this breach and was like, all right, show us some of it. And sure enough, they showed them some of the information they have. And what's interesting here is the spin. The Manchester Airport Group mag is like, oh, listen, no credit card data was bleat bleat. So you're good. Everything's great. Right? If you take a look at the data that was actually bleak airport Wi-Fi registrations, fast track bookings, license plates for your car, vehicle registrations, your zip code. And in the UK, there's like, it brings you down to like 12 different homes.

Your booking reservation, so they know when you're going to be out of the house and they know when you're going to be out of the country. So it's much more devastating than credit cards, like whatever credit cards you can just rotate. Right. Right. And I can just call up and get a new one. But this stuff, you just can't go get a new license plate easily, right? Or rotate your phone number easily. So this is kind of a big deal. So okay, you go, okay, well, the breach happened. They were notified. They don't look like they're going to pay the crew. So my guess is 86 gig worth of data is going to get leaked. How did it happen? Like how what type of amazing zero day attack got them there? By the way, you're talking, I think it's going to be relatively simple. Like somebody got called up and asked for it or something. Big Carl. If you had a super, I'm just asking you to lie as a professional developer. If you had a super secret API key, yeah.

Here's the one place you probably wouldn't put said super secret API key in code. In code. In home page. Yeah, I wouldn't hard code it into a GitHub repo or something. Would you put it in JavaScript? No. Because that's secure. It's not secure. Of course not. That's what they did. This super secret back in API credential and they put it in JavaScript and they said, I'm sure the client browser won't tell the user what it is. Oh my God. And that's that was it. That was the whole hack. They looked at it and went, wow, there's a key coming to my page to my browser. I'm just going to call the API. Isn't that just looking? Yeah, exactly. Yeah. So I'm not saying this crew is not talented. I'm sure they're talented in breaking into places and there's tons of breaches that have been attributed to them. But in this particular case, the Manchester airport group actually put a API key that had

admin level credential access, level access to everything in JavaScript. Because they were like, well, this key has to be able to look up whether there's a spot available in the garage and what your license tag would be and what your reservations are. So we know whether you know what I mean. So they're like, well, let's just give the key access to everything and they did that and then gave it to every user who ever browsed the website. How do I imagine that this decision was influenced by Tequila? No, I think we're in the wrong business. I think I'm going to be the next Jeff Foxworthy. You know, you might be a redneck if, but my routine is going to be you might be an idiot coder if. You're anybody can break into your system by view source. Right. Exactly. I think we once thought a website that that should have known better that had pictures of people and that the label on the picture was the so secure number.

Yeah. Yeah. We're like, come on. What could have yes. Yeah. All right. And that brings us to our top story. Open AI Astra brings autonomous zero day exploitation to AI. So if this is what I think it means, that means this Astra is using is an AI model that can just completely devastate the world. It's a AI saying we have a mythos too. That's what that's my take on it. We pass the cyber bench. And by the way, most people are starting to come around to the fact that these benchmarks are tests that the AI study to. So the question then becomes is open AI trying to just get regulated so that it's an advertising stunt. They'll have their fable mythos moment, their glass wing moment.

I don't know. It's inevitable that we're going to see models who get better and better at cyber. Yeah. But you know, just the fact that it's passed a bench test, there's a motivation now for them to say they have their me too moment as far as mythos goes. What do you think? Yeah. So let me just explain what it is. So this Astra can, according to open AI, autonomously find zero days and build exploits. So that's the key. How is that right? You've been talking about for six months. Right. It's funny before the show started. I was like, oh, that's cute. I mean, we've had it for nine months now, but that's adorable. I'm glad open AI caught up. I mean, and it's funny because we don't submit our AIs and harnesses to get awards and blue ribbons. In this case, this is the first to reach this cyber classification of critical designation of which whatever, like this, and we've talked about this, the harness matters just about

as much as the model itself. And there are plenty of harnesses out there at this point that can go full attack. You point at a target, it pulls down software, it creates zero days, it tests them in the virtualized environment, it creates, and then it'll go out and attack it. We've seen this. We've seen these entire frameworks. Sure. So the fact that open AI is announcing Astra is amazing. I agree with that, this is all just marketing ploy. The model 5% of what it takes to use these AI systems, the harness is 95%. Yeah, I agree. Yeah, the harness pattern. We model and do incredible damage with the right harness. And you can take the best model and not be able to find anything. Yeah. Right. If you don't have the right harness. And for those who've never heard that term harness, the harness is like your Claude code app or your GitHub, Copilot CLI. It's the judgment. It's the pipeline. It's the average. Yeah, so the LLM has no state.

So the harness is the thing that keeps track of the state and the memory and all that and makes it a worthwhile experience. Everything that's moved us past prompt engineering. Right. Yeah. Okay. I think that's a show, guys. What do you think? I agree. I think that's a lot of fun. And thanks Cliff for sending in this story. Always. It means keep sending in stories we appreciate. Yeah. And check out our discord. And well, G Wiz, that's what we talked about from last week and we'll see you next week on Security this week. Bye bye.

More episodes

More from Security This Week

View all episodes →