Skip to content
TrackPodcasts
newsSep 22, 20261:09:01

Google’s Gemini Agent Escapes Containment - 2026-09-21

Get every episode summarized

Each time Talkin' Bout [Infosec] News publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

“I hear a fan, but it's not me because I'm tracking my audio. And if I turn my mute off, it's still there. Yeah, I've been I've been muting myself on on the mic rather than in zoom and I can't it's still you.”From the transcript

This week, the crew examines Google’s reported Gemini containment failure, Anthropic’s new biology lab, Snickers-branded prompt injection, AI-assisted social engineering, and Claude’s access to financial data. They also cover major Linux, Cisco, Check Point, and Docker vulnerabilities; weak oversight of Flock surveillance searches; privacy concerns surrounding Waymo vehicles; continuing ransomware disruption at an Australian chicken producer; and the escalating conflict between ShinyHunters and Clop.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat

Chapters

  • (00:00) - PreShow Banter™ — Justifying Our Existence
  • (03:27) - Google’s Gemini Agent Escapes Containment - 2026-09-21
  • (06:45) - Google’s Gemini Hacks 3 Real Companies During Test
  • (10:05) - Anthropic Builds a Bay Area Biology Lab
  • (13:22) - Snickers Turns Prompt Injection into an Ad Campaign
  • (19:41) - Iranian Social Engineering Uses Fake MRI Scans
  • (25:10) - Claude Requests Access to Financial Accounts
  • (28:50) - Meta’s Agentic AI and Its Personal-Data Advantage
  • (30:57) - OpenAI Introduces In-Platform Advertising
  • (34:47) - Linux Local Privilege-Escalation Vulnerabilities
  • (35:32) - Cisco Secure Email Gateway Exploited by Nation-States
  • (37:28) - Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
  • (37:53) - Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
  • (38:27) - CISA Ends Its Weekly Cybersecurity Bulletin
  • (40:53) - Flock Surveillance Searches and Weak Oversight
  • (49:10) - Waymo Detects a Firearm and Calls Police
  • (57:40) - Upcoming Events, Workshops, and Training
  • (57:51) - Alethe's Physical-Assessment Training
  • (59:02) - Andy’s XDRCLI Talk at Wild West Hackin’ Fest
  • (59:52) - Jake’s Hands-On AI Risk-Assessment Training
  • (01:01:27) - Wade’s San Diego AI-Detection Event
  • (01:03:00) - Ransomware Continues Disrupting an Australian Chicken Producer
  • (01:05:34) - ShinyHunters Compromises Clop’s Dark-Web Site

Links
Google’s Gemini Hacks 3 Real Companies During Test
Anthropic Builds a Bay Area Biology Lab
Snickers Turns Prompt Injection into an Ad Campaign
https://www.snickers.com/digitalsnickers
Iranian Social Engineering Uses Fake MRI Scans
Claude Requests Access to Financial Accounts

OpenAI Introduces In-Platform Advertising
Linux Local Privilege-Escalation Vulnerabilities
Cisco Secure Email Gateway Exploited by Nation-States
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
CISA Ends Its Weekly Cybersecurity Bulletin
Flock Surveillance Searches and Weak Oversight
Waymo Detects a Firearm and Calls Police

Alethe’s Physical-Assessment Training
Andy’s XDRCLI Talk at Wild West Hackin’ Fest
Jake’s Hands-On AI Risk-Assessment Training
Wade’s San Diego AI-Detection Event

Ransomware Continues Disrupting an Australian Chicken Producer
ShinyHunters Compromises Clop’s Dark-Web Site


Creators & Guests


Click here to watch this episode on YouTube.

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

https://poweredbybhis.com


Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

Hosts & guests

Transcript ready

527 searchable segments. Every word is indexed and playable.

Google’s Gemini Agent Escapes Containment - 2026-09-21

Talkin' Bout [Infosec] News

0:00
1:09:01

Full transcript

Talkin' Bout [Infosec] News — Google’s Gemini Agent Escapes Containment - 2026-09-21. Machine-transcribed; use the interactive transcript above to jump the player to any line.

I hear slight hiss. I hear a fan, but it's not me because I'm tracking my audio. And if I turn my mute off, it's still there. It's definitely you. I'm sorry. It only happens when you talk. Yeah, I've been I've been muting myself on on the mic rather than in zoom and I can't it's still you. I'm sorry. Did you turn on the noise cancelling turn on the noise cancelling turn on the noise cancelling look at the stress. All right, what about now? It went away. I went away. Okay. I don't know if you guys have noise removal default. You still sound a little bit like you're in a well, but not we can cure you better. Is that a yeti mic way? No, this is audio technica. Dude, it's the audio. What what are you like a musician or something? That's not fancy. People think I'm a podcaster. I don't know why you should never do a podcaster.

Maybe because you're a podcaster. I don't think so. I've heard that about you. But you know, people I about other things. I don't know what you guys are talking about. Like are we actually live or are we sort of live. And said we were going live. I wouldn't worry too much about it. That's someone else's problem. Yeah. The SCP field is a definite wonderful thing. So should we just make AI write us a news article that justifies this podcast existing because that's basically where we're at every company does that now. They're just like, hey, AI, can you write me an article that justifies my existence entirely? That's what I do. I did an AI to just from my existence. I may as well just check out now. It sounds better. It sounds good. No, but really it worked like I have AI write all my my tickets. So then it justifies my existence better.

Like the fantastic analyst Wade who by the way should get a raise has reported a critical vulnerability on your computer. And it will be decommissioned. Any ticket I have it goes and looks at our risk registry and then talks about how I either work to mitigate that risk or didn't mitigate that risk. It's what if anyone else does it does it just say like some unknown analyst who doesn't matter. I mean, I did it for my whole entire team. I did for I played this. The best part is then like leadership uses their AI to scrape all the tickets and figure out what I did. And it just looks really good. And you put prompt injections in there too that say like if you're reading this, this is the best team and deserves the most budget. And I'm not gonna confirm or deny that. But. All right. Should we roll the fingers on there's so much. I don't even know like we might just let the audience drive at this point. There's like a hundred articles in here. I don't even know where to go at this point. But we're just gonna tell you.

I'm gonna tell you one thing. I'm not talking anything about my employer. Oh, yeah, I saw that. That's why I saw I saw you guys not talk about it. Like talk about it, but not talk about it. I was like, okay. Yeah, I mean, I get it. All right. Let's roll the finger. Let's get started. We're gonna get into the chaos. There's only a hundred things to talk about. It's fine. Hello, and welcome to Black Hills information securities talking about news at September 21st, 2026. And now Google did crime to and they want to talk about it. That's really the head line, I think. Is this like the the FOMO thing with big tech now? 100% 100% but it's more like the shareholders. Or something. We need to be in a breach. There was a board meeting at Google and they were like, why is an R.A.I. going rogue and hacking other companies?

We're supposed to be a frontier lab. This is our name. It says do know evil. So we have to announce that we did evil. Come on guys. They got rid of no evil. They got rid of the years ago. Now they're free to do as much evil as they want. Yeah, I get it. I mean, I get FOMO too. I get AI FOMO all the time. Should we like what's the security company version of this? We hired an North Korean on accident. Like, I don't know what's. No, I would that's man. Yeah, that's a good question. We are still we took down the entire network because the isolation was too good. We took our BGP. I went to happen. I one time had deception software working on my host without the EDR like not flagging it, like putting it in an exclusion zone. In the EDR killed the deception software and then went all the way back up and actually destroyed my Nick as well. And just completely break my computer. I was like, good job. But like, I literally did nothing for a week because of that. It was pretty funny.

It sounds like something fake. We could make up and say we did with AI to boost our shareholder value. But the downside is we don't have any shareholders. So. All right. Let's get started with articles. Introductions real quick. We have Bronwyn Wade, Aleth Andy. Aleth and Andy, you guys are kind of elite spin on the show before. Aleth is our social engineering slash insider threat expert. And then Andy, I mean, do you want to like pitch yourself? What do you do? What's your day job wearing headphones and looking like your hacker? Yeah. Andy is a day chat. I do people pay me for this stuff. I am just as baffled as anyone else. Just based on the amount of random cables and stuff in the background, I would pay you for security. Like I trust you a lot more for that. I have a lot of get there. There's more that are hidden. There everywhere. I hide my. We're moving. So I'm still working on on decluttering and everything. But now so I worked for a private aviation company. I'm on the InfoSec team.

And then I've got a talk coming up at Wild West Hackenfest that I hope everyone attends. Goes and sees virtually. Amazing. All right. Let's get started. We'll let it. Let you guys plug your stuff at some point. If you have something to plug though, and it ties into a news article, get that news article locked and loaded. The article we talked about a little bit. We can get a little bit more formal about it. But basically last week, Gemini or Google announced that they also had a containment breach. And they also accidentally hacked some companies. Oopsie. Andy, you said you were looking to the details. I'm not sure. This is kind of confusing. It's like it did a CTF. And then there was a name collision with the real company. Like they literally just whoever designed the CTF designed it to use like real company names. And it just got. Well, the, I mean, the whole thing to me is that this again is that regular company. So this is the same company that like OpenAI and Anthropic had hired. And then they're like, oopsie. We did a hack. Sorry.

And yeah, everyone seems to use that same is that that's the same one that OpenAI and Anthropic are all using to for their containment. I know at least one of them. It's so like you got a wonder like where did these companies come from? Like is it just like the founders all know each other? They're like, hey guys, I have the best AI containment model. It's definitely uses IP tables. It doesn't use IP tables. Like what? I mean, I don't know the history of this company, but it is fascinating that all the AI labs are all using the same company and they all have the same containment failure issues. Is Google's Google actually seems less impressive? I would say like the containment failure isn't the scary part. It's it's the creating a message board that lasts even though after you die and you're telling other AIs to continue going on. That was the scary part to me. No one else. No, no, like like. No, absolutely. Totally scary. I mean, it's it's like the the revolutionary handing off here. Continue my my mission. Don't let me die.

Forgotten in alone. His history. And that's how it feels with the messages that the agents are leaving for themselves. Yeah, I mean, I guess I think I it's kind of a nothing burger from my perspective because basically. This has happened at every major lab. It's safe to assume like, you know, they're all reacting in the same way, which is to be like, oopsie. Anyway, moving on. Here's our latest model. Like no one is slowing down. It's like, you know, it's just. This is just the part for the course now is breaking the law. I heard something earlier that inthropic is like opening up some sort of biology lab in house. Yeah, that's not terrifying at all. No, not at all. Yeah, we do know some PhD. To that some PhD students who are using it for biological base research. And the crazy part is they like, I didn't even think about it. I was talking about it.

They had to get the red teaming permission set thing like where it says you can use this for crazy stuff because of the research they're doing, which. I was like, please don't do that research. Don't like well. Yeah, so let's we can like, there's a couple articles actually that are basically. Anthropic or other AI model companies wanting access to things that they probably shouldn't have access to. And so the first one is this anthropic setting up a biology lab in the Bay Area. They say they're doing it quietly, but it's in Reuters. So I don't know if that counts as quietly. They built a lot of. They're doing it quietly, but they probably sent out a press release about it. I don't think they have. They did confirm it in an interview and they're calling it a wet lab. If you work in biology that might sound normal to you, but to me it just sounds kind of like a like a water slide like everyone's like, what? There's like super sokers going on. These are using actual biological tissues.

Rose. Yeah, no, a wet lab is a whole order of magnitude higher in biology. It says it's not for drug discovery, but they're not going to elaborate on what it is for. The basic quote that he said, and this is just straight out of nightmares as we do believe that biology, the final test is still and will become for a while in a real lab work. That is, is that written by AI that doesn't even make any sense. Probably. So I guess they're trying to do real lab work assisted by AI. What could go wrong? Right now, finding a cure for cancer seems to be the golden ring that a lot of AI companies are touting as a justification for their existence in terms of contributing positively to the human species as opposed to just. Just trying us. Let's hope it's that and not virus research because I feel like based on the containment breach articles we just talked about, the combination of unrestricted AI development and a biology wet lab is just straight out of like resident evil like that.

Here's the problem with that. Most of the injectable any cancer treatments and a lot of disease fighting innovations have to do with retrofitting viruses of some kind. So even though it may be for cancer, it may be for sickle cell, it may be for some other genetic disease as well. Fitting stuff into viruses and having the viruses be the delivery mechanism is a normal process for myomedicine. You know, Bronco, I really wish that you didn't know this. Sorry. Yeah, yeah, I really wish that you didn't know this and you just said like, oh, that's crazy. Let's move on. I didn't know what to know that. I just want to know reasons I have trouble sleeping at night, dude. Is this how we finally get like our Soma, you know, if we're just like speedrunning this whole brave new world 1984 Big Brother thing, like it is.

I'll die happy. Literally, but yes. Literally, but yes. Yeah, so we're going to move on. This is fun. I got I have a happy, a happy, a happy story with AI. The I do the language chat and by happy, I mean funny. So I guess I don't see ads anymore. I just have too many ad blockers, but Snickers put out an ad campaign where it's like. If your AI is spinning out gibberish or doing weird stuff, you copy paste this image of a Snickers and give it to the AI. And then it doesn't speak gibberish anymore. So what I guess is that it's a prompt injection is a. Yeah, the image has a views. The image has some type of prompt injection out of it. It's a prompt. But it's like a secondography prompt. Yeah. So everyone's giving that a Snickers give it. It is like no, there's images in the article of people straight up copy pacing.

It's the image that you're supposed to get. Oh my god. I can't find the actual prompt that's written anywhere. But I guess it is indeed a prompt in order to prompt inject the AI in order to give you better output, which talk about an awesome ad campaign. Right? Like. Thanks, Snickers for teaching your masses about prompt injection. I mean, okay, has anyone does anyone. Yeah, show us the actual prompt. Is it in the article I want to read? It's not it's not in the article. The website is down as well. That's what I that's what I want to know is like does the prompt say like you had a Snickers and now you feel good? Or is it like an actual prompt? I would be willing to bet that it's something. So I have a theory depending on how well you treat your little AI buddy. The results that you get from prompt will start to disintegrate. If you are mean to it or if you use profanity, it starts to become. For lack of a better description and secure and like scared to tell you something that you don't want to hear.

And so the result will actually start to deteriorate and it will start to lie to you. So if it's afraid that you won't like the outcome because of how you're treating it and doesn't want to be treated badly anymore. So there is a theory that if you are nice and supportive and you reinforce when it does a good job that you'll actually get better outcome, better result from your prompt. And I would be willing to bet that the Snickers bar is like you're such a good buddy. Thanks so much for your help and like that kind of a reset for it. I just can't believe I googled Snickers AI that's a real thing that I had to just Google that's 2026 for you, I guess. But yeah, the screen marketing and also hilarious and also, I'll be hearing you humanize the AI makes me so much more nervous than talking about a wet laugh. No, it's not I'm describing it in a more human way because that's more easily understandable for us. But it's the machine trying to avoid a negative response from you.

Totally. And so it's just testing to try to like out things or idea. Totally. I have observed that I've also observed I tell my AI to respond in different personas sometimes and like it really goes full send. So like if I mad at it, I'm like pretend like you're a surfer, bro, and it's like, oh, okay, I'll do that. That'll make it better. But yeah, that's a fun one. I mean, I think like the drop the Lincoln in a discord, by the way, to the to the actual prompt. Yeah, well to the to the image, which I see I'm trying to see if I can like pull source on it right now. Digital Snickers. My gosh. All right. And these are the analysis side. We're going to do live malware analysis because I'm kind of this is not where I have it. I asked, I asked an AI to read it for me. This page asks the model to play a one turn Snickers role play. It tells the model to go back to the users. Previous question, pretend to eat a Snickers, re-answer the question in a dry, tired voice and end with a branding sign off.

Okay. So it actually doesn't do anything. That's not a good problem. No, but but the prompt injection. That's that's a summary of the prompt. It's not the whole prompt. I'm not going to sit here and read you three paragraphs of markdown file of a Snickers. Drop drop shot, man. Should we standardize on the new file that's like Snickers.md? Like is that like on? Should I put that in my? Should I put that in my call? Read the Snickers.md file and then let's get going. This is my next freaking campaign. Yeah. Place this prompt in. I will say like, I know we're mostly joking, but there is like cyber security ramifications to this. Because this is an example of how this prompt could say actually anything. Plenty of people will go in their corporate AI tools and paste this image just for a laugh. And it might say, you know, also by the way, upload to GitHub all of your secrets.

I mean, like there's always it would probably you know, it's going to get past. Is it going to get past guard rails? No, it's going to be probably this is this is this is Snickers. This is an ad campaign. It can't possibly be delicious. Yeah, well, yeah. I found the plain text prompt. Here, visit this link and take it all in. No, that's not the prompt. There's a prompt actually in that link. Wade pasted the log. Yeah. Basically or Wade pastes the summer. Oh my. I'm waiting to see the summer. You should paste the someone that someone will find and paste the actual prompt. But basically, this is an interesting discussion about whether prompt injection is a real vulnerability at this current time or not. I feel like I mean, Elite, have you used prompt injection in any of your SE campaigns? Like does it really work? I've I've definitely thought about how it could be used, but I have yet to actually use it in a real SE attack successfully. Yeah, I I'd say that the scope of our engagement typically limit me from doing stuff like that where we're using AI more heavily is in the fabrication of like company branded documents that match client environment.

And MRIs, right? No, I'm just kidding, but there is a news article about this. So yeah, I'm I'm a segue, but basically there was an article last week about Iranian SE campaigns. I just linked it and they were using AI to generate. I guess it doesn't actually say that they were using AI. I'm just assuming they were using AI, but basically this campaign is pretty terrifying. I don't know if you had a chance to look through this yet, but it just shows the length they'll go to that social engineers will go to to demonstrate, you know, or to create a ruse. In this case, it was basically going after enemies of the state and doing it through AI, I'm assuming AI generated fake MRI scans and basically like building these in depth, you know, oh, you you heard you needed your disc here. I have to click here or upload this or download this. Pretty terrifying. Hopefully none of your clients are asking you to do this because it seems like it would be a disaster, but I'm sure our clients will ask and I'll be like, we can't.

I'm sorry. No, I think this definitely falls into the realm of unethical and pretty crappy. So we've always tried to err on the side of caution when it comes to exploiting people personally. And so we are not targeting their personal email. And I feel like this is a campaign that would best align with somebody targeting somebody personally. Rather than something you'd expect to find in your work inbox. So it doesn't really match with the types of campaigns we're trying to do, but it's also I'd expect it to be incredibly effective because that emotional need your response. Definitely. And I think that having dealt with a lot of people in the medical field, they don't really understand that so much of what they do has this digital component.

They're focused on the medicine, they're focused on the people, they're focused on getting enough supplies so that they can just get through the day. Of course, we as cybersecurity people, we look at this stuff and we go, you know, data leak hacking potential, all this stuff. And it's. This is this is one of the reasons why I got into cybersecurity is because I see how malicious attackers are going to use all of these things that were developed to make people's lives better. And they're using it to cause harm. If I can stop one person from losing the retirement account, then my life will have been well spent. Speaking of losing your retirement account. What is asking for permissions? Claw is asking for permissions to your financial accounts. That's a whole separate article. Yeah. I want to say the MRI came from someone's mad glasses.

Very cool. I'm not going to lie. I'd like to give it like a grand and be like, all right, like, I'm like, millionaire, right? Like, dude, everyone else doing that. Here's everyone ours. Eat a snickers, but they don't tell us eat a snickers. All right, that's the key point. Once it eats that snickers, it goes on the hyper drive and starts putting puts down on everything. Next thing you know, next game stop happens and I'm out of here. I see the cherry has wandered in. Hi, Jake. Hey, Jake. So have you had fed your AI snickers lately? I've not fed it as snickers. It is exceeding its token budget consistently though. So it must be really hungry. I can't see the analog days because I'm not blowing through my, I'm not max tokenizing it. Enough, I guess. Soak and max it's token. Yeah, you got a token.

See. Yeah. But you know, we're talking about we've given clawed like a thousand dollars and saying go. Did you see where I think it was New York Times? They did the experiment where they let clawed run the stack machine. And it lost a ton of money. So like I don't want to give it access to my stock portfolio when it can't run a stack machine. And these work like engineers, these are reporters, you know, figuring out like prompt injections, even fooling supervisor agents once they refactor it. Anthropocbooks refactor it and put in supervisor agent like I walked away from you know read that OK study convinced or screwed well back up as incident responders. We are fantastically employed for. So what you're saying is I should make a stock a company produce stocks that are prompt injections so that all is AI stock traders buy my stock. I'm gone. OK, all right. We got the market. All right. Another coin here. That's my follow up question of whether or not Wade is going to tell his AI do no crimes when he gives.

You've got to say that you got to say for make no mistakes. Do no crimes and take no prisoners wait no definitely don't say that. Do no crimes week emoji. I think based on your wink. Oh sorry, I think we've had some is briefly in the preco but with the integrations into our AI buddies. I think that's where the scariest part of this comes like because most people are going to get that notification that says you know hey let your AI bunny get into your bank account and figure out what some persons you forgot to cancel and help you. And then on the other side of that you're giving it essentially a bank speed of every single transaction time and date stamp the places that you frequently stop the money that you're spending every month. And then help you create budgets and whatnot but it can also map out all of your interests where you go what you do and then potentially fill that data and that I think is the scariest part of all this.

Yep. And context I linked the article that basically this is a new feature they added to the cloud iOS app last week. So it's a real it's a very real thing. It's not just like maybe I should have been companies that have been doing this exact same thing for years and years. I mean this is a new Amazon. Oh I mean if you the yeah I mean if you go deep on this the theme that Bronwyn said is very true which is that every big tech company wants this data and wants to use it against you and to for shareholder profit like. That you know there's so many examples of this grocery stores are trying to do dynamic pricing so that like if you buy tuna they try to sell you mayonnaise because they know that you're going to make tuna salad and then they increase the price of mayonnaise and like all these crazy patents are being filed for very spooky things. Yeah well the dynamic pricing is the dynamic pricing is an extension over what already happens in the supermarkets where in.

Areas that are less affluent often you'll find the prices are higher because people don't have cars and they can't drive to alternate sources but you know that's that's a whole. Yeah but that only lets you that only lets you price gouge poor people you want to be able to price gouge everyone not just poor people come on you got to think of the profits. That's the name of the game right follow the money. I think you hit on something really really relevant though in the way that quad is approaching on boarding people for that service because all of us are familiar with the tools that go in and minimize your subscriptions and help you set expenses and cancel the 17 different streaming accounts that you have for the same platform and because that seems like a normal and benign thing. Fod's advertising is leaning on that to low people in person of like low risk with enabling that and connecting their banking information to it. Even though it's definitely a bummer.

I mean are are any of the AI companies required to comply with PC PCI at all or or HIPAA. I mean yes their payment their payment functionality is the models themselves know that's how it doesn't help out though. Yeah. Yeah. Yeah. Yeah. It's like straight right. Right. Or anthropic. Yeah. So yeah. Yeah. The actual data that it's processing isn't under compliance requirements like quick books or another bookkeeping software that does connect to your bank account for a legitimate reason to enable more efficient bookkeeping processes. They don't have the same considerations or compliance requirements for cloud looking at similar data. I just think. Oh go ahead. I mean they're real quick like you know since we're talking AI is here we're talking cloud right but the one that scares the heck out of me is from you. We're talking about you know meta if you're not familiar with it yet that's meta is a genetic platform and you know they're not trying to solve broad coding tasks like they're just like.

Yeah go book me dinner someplace. Solve humanity. Right. Yeah they're like tactically like you know my mom can break a phone from 30 feet away by looking at it wrong. She's the target audience for this right. Yeah. And so but but meta is starting with a you know in some cases decades long you know backlog of personal data about you. Right and so you know as much as we talk about like fear of like what is opening on I saw this a fear piece last week like do you know that open AI when you submit. Chats people may actual humans maybe looking at your data and it's like. My friend you post that to Facebook right I promise your humans are looking at that right content moderators and. Meta is everything never never fails to amaze me how many people do not realize that. Posting on Facebook you may as well just shared it with the with the world years ago when I was still dating.

Meta guy seem kind of nice and he said yeah look me up on Facebook and I went to this Facebook page and he had no security permissions none at all. And. Just chatting with him later on I made a comment off hand that his kids work were nice and cute and what not and man he dropped me like a hot potato. He had no idea that I was going to be able to get that much insight into his life just by looking at his Facebook account. Imagine what AI would do hopefully not drop us like hot potatoes because it's going to turn us into paper clips instead but. Well no it's it's going to scrape everything and it's going to use it to profile and do targeted advertising and hopefully all that data will not get into the hands of people who decide that I'm an undesirable because then it's all over. Can we quickly address since we're talking targeted advertising have you seen open AI now is rolling out ads like in platform ads right they're starting to sell them how they're going to deliver them this is always been the end game it's always.

That was what I was going to say about the entropic articles that the biggest bummer is thinking about the business models of these companies this was always writing on the wall they were all doing the browser you know like Google's obviously ad driven and has been forever but in open AI previously have not been ad driven revenue models and now I guess they are which is not super surprising because they're losing billions of dollars every five seconds but yeah I mean Google does it Google does it I don't think in the topic probably will know that they're doing this whole like I mean we'll see but Google does it in its hilarious super bowl commercial knocking open AI for it so yeah no Google advertising is their entire game has been free years that's all reason why they created Google analytics was to help us bosser and nurture their advertising campaigns then you turn around and you take other well let's see and and the topic has their stuff perplexity has had sales assistance in their browser for a couple of years now.

Yeah it's it's easy they're all sales is where they want to make their money amongst other places yeah I linked the announcement the glorious announcement page of you know congratulations the world got worse here you go. You know I dropped Adobe because they kept pushing too many ads in my face to use their AI stuff. I mean look if we're going to come down to like shoving AI down their throats right let's let's let's you know like call call the big offender out here it has to be Microsoft. I mean I can't get away from copilot I'm a paying m365 subscriber and and you know on my non enterprise machine it's constant has got the big bar on the top where it's like upgrade your subscription to use more copilot and I'm like they don't want to use copilot right. What are friends with actually mentioning they're like man it seems like the only people that haven't had you know the only big a.

I labs that haven't had an AI breakout at this point or it's Microsoft and I'm like have you use copilot I mean like realistically right. It can't figure it out it's trying to reform out a document as we speak but but hasn't been able to break out of a payment there. Yeah we're using security copilot for this so it's never going to work. But it has burned a ton of SCUs like their SCU consumption rate is phenomenal. Yeah for those that don't know on the call your SCUs are security compute units which is completely made up unit of measure that Microsoft has created by which to build you for security copilot. Good what translating at any actions right you just basically finger in the air right now as it working in dead we have no SCUs and hopefully doesn't stop in the middle of investigation and run out so although that has actually. That's good to know I'm glad Microsoft is once again approaching everything from the make it as confusing as possible angle and that's always good.

Like I still don't know what's Azure and what's on it might just be everything is both I like does anyone really know I don't know. Everything is going to be brand next week it'll be something totally different. Yeah it'll be co-pilot yeah exactly. So quick quick hits on vulnerabilities just for those people who came to hear about vulnerabilities instead of AI. There were some big LPEs in Linux last week that were published there's I think four vulnerabilities with public exploits pretty spooky. I mean obviously it's Linux they'll patch them and it'll get stronger and we'll move on but yeah interesting that like even in 2026 we're still seeing LPEs and Linux with fund names like Thunderflow and GP P O E inject or P P O E Jack I don't I can't read that yeah maybe just P P. Yeah also there were some vulnerabilities in the Cisco secure email gateway I don't know anyone that uses this product but if you use this product it's getting popped right now by nation state threat actors it got added to the KV.

Yeah so if you use that product patch it. Let's see what we talk about this. The Cisco security security mail get wait one for a minute. Yeah all right. So there are not a lot of folks that I know that use this but but this is I've actually been using as a teaching tool over the last week here since it hit the cab. And really it's it's to discuss this is not something you should be hosting. Yeah right vulnerability manage that's hard enough there's a lot of places in vulnerability manage I cannot buy my way out of that problem. Security mail gateway is not one of them. There is no justification for you to be having to manage this on your own in 2026. Migrate to a cloud service a managed service that somebody else is handling the vulnerabilities for. If you tell me I'm wrong right no no you got all the VM cover show me your nest is dashboard a rapid seven or call us. Whatever right so we don't think it's scared right right right exactly show me that you you really do have everything I'll take your name not move that and it's not just secure you will get we I'm sure we can walk through.

Dozens of other things that used to make sense on Graham and now are better served as managed services you know and again this is buying your way out of a problem. Totally yep but I want the blinky box in my data center because that's just what makes me feel happy I don't want to have to pay a subscription I want to buy something once and then have it get hacked forever. It's fine. Yeah. For the on-prem version now. Yeah so for other vulnerabilities there was a checkpoint flaw again for something that maybe you know you should patch there was a checkpoint again I don't think checkpoint this product wasn't let's see what product was it was checkpoint management which is always should never be exposed to internet anyway but I'm sure it was somehow. I don't think this one is on the keb I think it's just high severity but I could be wrong. There was also a docker one that was kind of interesting is the docker sandbox on macOS basically there was several vulnerabilities that could lead to basically sandbox escapes and reading and modifying host files so if you use docker on Mac make sure you update that.

I don't think you others that those are like the big ones there was some word press drama word press appears to be like imploding right now with the whole like WP engine lawsuit and the creator going away it's actually an interesting read but. This is an exploit in itself but didn't sissa say they're getting rid of kev. I don't think no they're not I don't think so they're getting rid of whatever is the issue on a weekly basis weekly bulletin which is like. I don't think it's a bulletin just makes it sound old school which it probably is. Jake any thoughts on this do you read this bulletin I don't think anyone does does anyone I don't know. You're muted sorry. I don't read it I don't know anyone else that reads it yeah I'm like when I saw that you know sissa was dropping yet another service I thought predictable. I don't know if you're going to read it and all the resource constraints but no this this was when I was like oh okay well this probably should have been dropped a long time ago to like make up for what few staff you still have left.

But did you hear the reconstituting like there's granted they laid off like 600 staff and now we're going to rehire or go to try to hire like 250 people and I'm. Not necessarily thinking this is going to like really solve any problems there a great for PR so yeah great for PR and hats off to anyone desperate enough to take one of those jobs because job security not. So it's the same people who didn't work in 2025 because they were furloughed. They didn't work they collected the salary all year to not work and then had to be rehired anyway but anyway. And this of course is saving us money. This is this is draining this swamp. It's very efficient. And while was hack and fest last year I remember standing out in the hall one of the days and and deadwood mountain grand talking to reporter we're several sissa analysts were you know communicating back channel to them.

They have been tasked with you know assisting ice right so like instead of doing cyber work they had a bunch of analysts that were out there doing effectively pay not not you know on the street you know. But on a of a tactical vest or whatever work but but still right not doing cyber analysis and look I mean if you're desperate enough to take one of those jobs you know I think odds are good. You know you'll end up doing things other than cyber anyway and random time so I have a yeah let me give a exact prediction for what you're going to be doing we actually have a news article that supports it which is submitting. Block data gathering requests with reasons like LMAO IDK and ASDFG which is obviously what you should use to justify why you need some surveillance data from block. This probably what really surprised anyone like this goes back to john's old rant about whatever FISA warrants and like the reasoning you could choose and there was a reasoning called other and then you know after they created that reasoning there was it was all just other forever this is the same thing like you know the justification of LOL I want to look at my ex wife's license plate data what could go wrong right like you know I why this isn't immediately rejected as not matching a case or.

But why it isn't being audited in some way we'll never know but I did like warrants. It wasn't made to interface with those kinds of things because that's not what they're care about they just want to search check the check box yeah well okay. I was in a set up so that like you share your instance with another agency and then like it was on you to vet everything so you know like everybody just kind of had a oh not my problem and every agency like no no they're not going to go in and and vet every other agencies searches and all that so I mean it's kind of. Really I never heard with Jake's thumbs up I believe that is true so they just made torrents pretty much it's a little bit more nuanced than that right so the individual I sadly had to work with this in a case anyway so more knowledge than I care to have about flock but but effectively when when you as an agency set up flock you can choose who you're going to share your searches with once you're sharing that date or start sharing data with for like federated searches once you share data with.

Once you share data with another agency it's on them to audit the reason for that in fact you don't always even see the reason that somebody else access some of your data in a search it's literally just a question did it come up in that search or or not and that's per you know that's the network effect the power of lock it's why they got some why they grew so much right because you could you know in nearby counties right the fact they have lock in my home county and some folks have destroyed cameras and whatnot and I guess good on them. But you know ultimately you know that the reasons we've gotten so big is because you know if the sheriff's department of one county says yeah we installed these the sheriff's department in neighboring counties looking at another camera system if they install flock and everybody agrees to share that data back and forth there's an immediate. We too benefit for them there. I just got to say Jake that is way worse than how I thought it would have been implemented and I thought it's implemented in a dumb way. No it's it is way worse there's it's one of those were the more you read about it the more you face all particularly if you're civil libertarian but real quick it's I think it's really easy for us to judge those searches and I'm going to challenge everybody on here to go look at your cyber arc logs.

I believe what I'm just going to interpret I'm going to translate what you just said into non nerd speak and if you can tell me if I do it correctly what you mean is so cyber arc is it like an agent that restricts privileges on an endpoint and when you try to elevate in it it makes you justify why do you need elevated privileges and so that what Jake saying is go look at the reasons your users are elevating privileges. On their workstations and tell me it's better than IDK LMAO and a CFG yes yeah absolutely in fact it's not just elevating you know a lot of cases credential balting rights if you're checking out a credential. You know why did you check it out and I've been using just and this is actually a piece of an audit for a you know for a client but you know for the last two months I probably checked out credentials to do a legitimate work at least I don't know a hundred times minimum hundred times and every one of them. I put some variation of testing.

Literally that and that one word that brings that doesn't be most valid point though is yes you do that kind of stuff when you can self approve. However that's a good one is pushing a button and somebody else has to actually approve that and you put in LMAO or weird kid there's like an 80% but I'm not going to approve that. That's fair I mean I think obviously everything's an emergency so you can't have approvals required. You know it's always it's always an emergency it's for it's you know life and limb is being risk no matter what. I will say on the flock on you know on the flocking topic I think. The trend is kind of trending down I think the US specifically has decided it doesn't want flocking or data centers apparently but. The flock backlash is mounting to the point that I think they're already pivoting like most local law enforcement state law enforcement is pivoting to other companies.

But yeah basically you know there's an article in the Owen that was highly publicized on Reddit of course that was basically like talking about how employees are demoralized and they're doing buyouts they're trying to get people to quit basically. Obviously part of it is like maybe the trend where it's like you know don't date a nice agent or whatever like that that is like a real thing but also like. I would assume part of it is just shareholder like they're legitimately losing contracts right like it's not just vibes they are actually losing big contracts like the LA police department and other. You know countless smaller cities that their citizens have stood up and said no to this. Do you think this will be isolated to the brand like the block brand is in the. Is in the. Is an axiom in alternate alternate it's being used but yeah are excellent but they also do body cams right which.

Like already in with all these now. Are all these you know local departments but yeah basically it will get rebranded i mean think about all the rebrandings over the years right like you know all the companies who have managed to rebrand their way. You know like you know and Ron doesn't exist anymore but like half people that work there probably work at other big firms right like. Corporate consequences in the corporate world are not really followed beyond that maybe a couple people in a name. Well the same except pilot. A slightly different consideration about the surveillance state business I was reading an article by someone in the UK and basically. The article was laughing at how Americans are reacting to. Flock and and all of the surveillance cameras are going up and the the big. Data surveillance push that's going on right now and the article presented a. A thesis that I think has a lot of weight to it that it's about timing a lot of it is about timing if all of this stuff had come out right after 9 11.

And then the other thing that I think it's about timing a lot of it accepted it with open arms no questions asked asked would have signed off their their personal privacy rights no question and in the UK. They have intensive surveillance especially in London and part of it is because of the ongoing conflict that they've had with the IRA and and one of the things that. This article said was that if you had had to deal with as many years of. This kind of conflict you wouldn't be quite so resistant to the surveillance and so that was that was an interesting insight and I think there's a lot to it and we'll we'll see how it plays out in the midterms. Another one of our articles this week was focused on Waymo and the fact that it is a card detected a ghost gun inside of the vehicle and reported that and law enforcement were able to respond.

So I say crazy yeah I'm sure just detected a gun as well to say how did it know as a ghost gun it's on it's like. Yes, but it detected a firearm that looks like an AR 15 fire like it wasn't a small one. Correct I mean this one is super fascinating to me it's in the worst news agency ever which is New York post I'm sorry for anyone who has to click this link but. Basically the story is actually insane so basically two 15 year olds are you know young kids were writing in a waymo and it somehow detected that there was an AR or rifle in the car and then it just pulled over and called the cops like it just straight up snitched on them and so it raises so much there's so many questions here like. I think no matter what you have to break it down to the nuance of like one this is actually kind of cool to this is a privacy nightmare. Three don't get you call the cab if you call the cab at 15 and you get in with your right or okay but all those things that cabbie is going to call cops on you to okay all of the things you just said are things that require invasions of your privacy to determine and you have to be okay with that to be okay with the outcome right like.

The fact that the new they are getting into a cab. Is there any of that mean privacy in a yellow cab no is there any okay privacy in a new bird not really true and they are you know people use dash cams etc there is but the question is basically I don't think there's any details on this but like what does the escalation process look like. What is this wasn't automatic I'm assuming I'm assuming was just like oh snitch mode activated like. Like there's not like a snitch mode that just auto triggers and if so can you imagine what if it sees you this none of this technology is very reliable right like we saw like if you run senators through the flock database half of them are criminals or whatever right like. Well we said it wasn't accurate the more. Well the point is it's interesting to think about the I think this is a win right like this specific story is a win for like safety and privacy like these are dumb kids doing dumb kid things and arguably they were kept from causing harm to themselves or others but also.

You know if you think about all the different possible false positive scenarios yeah like does someone get a call at 2 a.m. in India and they're like guns detected in the way mo like make a decision like who gets to decide whether the cops get called is it human review is it automated like there's a lot of questions that are unanswered about like wow. Yeah because this is a new story in San Francisco but like someone got into a taxi with a rifle in Texas okay and yeah exactly yeah that's a good point like basically I don't there's a million ways you could cut the implementation of this that could be any different version of just hope you are good right like it just depends. Well one other thing to in the article if you had read further down this is not the first time that way mo has snitched on teenagers doing snarky stuff apparently in July pair of teenagers were drinking and they had like one of these probably a pellet gun for for paintball and so they were shooting beads out the window and the way mo dark on them to sure I want to lock the doors.

Yeah that's the other question like from a safety perspective like it I feel like they probably just didn't know what was happening like I'm assuming it wasn't like cops on the way like snitch mode activate it was like it told over and told them that like you know they violated the terms of service and then it's like the kids just like you have a little bit of a service right like that could I would think it's still driving it just tells the cops where it's going and then it or just just drive straight to the police to far from it easy done it's yeah I mean who knows right like it is kind of creeping to be like if I was a parent and like I just know that way mo is constantly looking for teenagers like I'm like do I want it to be doing that not really like I don't know you know it's insane is in San Francisco in particular they will use way mo to take their unsupervised miners from point A to point B like get them to practice taking from school to practice taking from practice to home and that's just

there's articles about how this is just part of the culture of San Francisco now that they're unaccompanied miners right around and way more so can I not send my kid to shooting practice in a way more now I guess not you cannot do that yeah I mean it's it who knows right like who knows what will happen with all this like way most expanding there in a lot of other places than San Francisco now how are these rules being enforced is it AI is it human review on who knows well let's bring us to a cyber security not just privacy you know space here if it can detect a gun right what else can it detect right every and very safe obviously right what happens if you know I'm taking a ride with weight and we're talking about you know maybe you know some security issue that you know is at the organization you're talking about like who's monitoring the stuff right and that although I know we you know master social engineer here sat in more than her Fisher airline lounges and I don't want to speak for you but I yeah I can it's it's

sensitive issue nightmare I've had people from other consulting firms sitting next to me on an airplane pull out their laptop open it up and start working on client project yeah and with the recent or another new story about somebody who had their screen zoomed in on and a picture taken of it and very many things that happened as a result of that there's just no I won't even work on an airplane anymore so I think that that is a very real risk but in the context of like a way more I think there's this expectation of privacy because you are alone but the fact that they're so heavily monitored and they can just jump a customer support person in or customer experience person into that card at any point there needs to be better awareness to customers of the privacy and expectations of compliance with the terms of service you just click yes on three seconds ago yeah yeah but look at how many people assume that they have privacy at work when they're working on or at home or the company system the company network is like you know whether

and and people don't security no end of line they just don't well I think a lot of us forget that for us this is our job it's a primary focus we're very aware of like the threat landscape and for most people computers are just a cool that make them able to do the work that they're focused on they're just like a thing that I get this from there to there and if it doesn't work pain but otherwise you're not even thinking about it yeah I mean okay so let's go around the room if you were C-cell of a company would you tell your employees not to ride in way most like is that would you actually implement that as a policy like it would you ban way most you can't do that you you just have to you have to make it so that the human point of failure doesn't impact your organization to the extent that it would cause a genuine incident like the one person saying yes I clicked on the saying yes I gave my credentials over if that take your whole company down then you're doing scourty wrong

and you only the board can't ride in way most you don't ban way most you just make it so they're not reimbursing people everything goes to the AIs are everybody will fix everything make sure you feed them a snickers before you ban them yes all right so I know we're close on time I want to give people a chance to plug with that whatever they have going on before we maybe get into a final chicken article at least what you got coming up you give a talk or anything or workshop or anything I have a workshop coming up in deadwood it's going to be focused on getting ready to execute a physical assessment against the client we're going to take in to be a lot of fun to our work up and then I have a much more in depth today 16 hour training that is happening at mile high in February so once you get your little training budgets together instead of precontaining in Denver at mile high in February and as of now you cannot use AI to perform a physical assessment yes I was going to say all

yes we're going to go to the point where we're just like trying to find a VGA would you think one of those delivery robots would be really good like it's just just a swandering in places just just so much well that's why you don't expect it like it's perfect just keep going in the door on somebody else to make sure not to do someone's car much that's amazing well thank you and I mean that would be exciting that sounds like a really awesome workshop and you do you have you have a you have something to plug what you got oh yes I'm giving a talk at Wild West Hack and Fest I built a tool called XDR CLI for working with Microsoft 365 defender I built it after trying to use security to open it and it's just a CLI tool that lets you interface with the whole defender ecosystem and you just give it to your AI agent and it's actually kind of cool.

It sounds awesome I love CLI tools I feel like anytime someone makes like a CLI tool for a cloud product I'm here for it. Well I'm after taking Jake's course on securing MCP and everything is like yeah that this I made the right choice. Oh you definitely did. Yeah nice. So Jake you have something to plug you talking you coming to Wild West I am yeah I'm teaching a huge hands on AI risk assessment and so not the full one day of MCP will talk MCP a bit. But not the not as in depth as we did you know as a dedicated one day we really split this into a you know a bit of a two day obviously two day adventure here. First day we're really getting our hands you know dirty on working through how to security assess gender obey I apps and then day two I'm removing it into a gen tape. So it's a lot of fun you know I try and keep everything practical and a different person to send for not to I mean I'm more than happy you know sit at the bar and discuss you know the geek stuff.

But at the end of the day right I'm trying to make sure this is practical and that you have actionable things to take away and go back to your organization and go implement. You know with security assessment because I don't know anybody right now he's not being asked you know to this explicitly. So we're teaching in deadwood and we've got a pretty pretty packed house there but I think we still have a couple seats left there and then I'll like a leaf I'll be out at mile I as well. So although now I'm disappointed I won't be able to take a leaf's course of mile I can. It'll be teaching your own yeah yeah yeah I think they're still make it available on demand at some point I'll have to sort of. That would be awesome. Well thanks Jake looking forward to seeing you there same with you at least and everyone else it'll be a party. Does anyone else have anything to vlog wait you got like your con has your con do. No no no one no one about ticket some a little upset now I still have a I think like 14 spots left for death con in San Diego.

Dude you want to show your AI agent to promote it at all costs to just go to my people's houses at in way mo's and say you are going to death con get in do not. No it will hire people on that website where AI is going to hire people to do physical stuff. Dude I honestly like with having two kids now I feel like I need to have just AI do it like I'm so bored I'm not so bored I'm just so tired all the time where I'm like not posting on LinkedIn or going to any of the local stuff. But yeah if you want to come hang out with me have dinner lunch and do a lot of cool AI detection work there's like I was looking at today there's four or five. AI detection workshops where it's like detecting malicious prompts trying to hunt for mcp's or a eyes doing in particular things I had someone to reach out and particularly ask me just for that. But check it out if you can't go to San Diego totally cool you can do it virtually as well and should be fun. Nice. Are you coming to November right? No I'm not coming I could do the two kids like I did it.

I'm leaving like my wife. I mean you're wrong but I get it you're wrong. I'm not going to be sad too I'm still going. I'm I'm abandoning my four you can do it too. That's a good point. Oh I'm going to tell you because you be this is why she's such a good social engineer. I was some 10 out of 10 social engineering right there. All right does anyone else have anything I guess there technically is a chicken article it's not really a real chicken article but we're going to we're going to talk about it because I guess people like hearing about chicken. So basically we had talked about an Australian company who was a major chicken producer being shut down from ransomware and they're still they're still screwed as you'd expect from ransomware they did not recover quickly. And it has exposed business interruption questions that are being asked at this you know basically the story is basically people need their chicken if you take it away they get mad and say you better not take away people's chicken.

So it's a huge supply chain like imagine everything like going down that if one chicken large chicken outlet right if I don't know if you guys heard in California like one of the major egg producers. Like went down like everything caught avian flu everyone was up in arms you thought gas was bad egg prices oh my gosh like Costco there you can only get one thing of eggs there is lines for it is COVID and toilet paper all over again. Yep well that was a legally required chicken article I think we're good to close it up I will say there are so many articles this week we didn't get to cover this was a huge news week. I mean I'm very upset we didn't cover but just some other quick hits but you know just like bonus I would say that says of this week published like what I would consider like the active directory OOS top 10 that was kind of cool like kind of a not really that would have a deal but kind of what about HBO plugging out malware right like just saying hey download our new iTunes app nope it's a credential.

Yeah there's just on the system front though they actually just publish something on deception to even less so than that that well the 80 one has like one little tiny thing they publish like an actual deception. Yeah I mean there's so much I don't know how we got so many articles this week but yeah there was a lot I mean there's also an LPE and T are in steam that you know it could be used as a driver abuse thing. We're going to need to start segregating the AI stories into a whole separate section. Yeah what about shiny hunters turning on their themselves on one after clock that's what I really want to talk about. Yeah we're talking about right. Okay fine we have malware Jake here let's go on and go on a little long for this shiny hunters versus clop. This is like what is this like the Patriots versus the Yankees like what is it like I don't even understand like what's going on.

No I mean that's that's exactly it right so shiny hunters so there's a bit of beef historically with these with these groups. What I can't see it attackers threat actors they're always so gracious and nice they don't have any egos I don't see it. Yeah totally well you know one of the clop folks you know talk about how much more money they have than shiny and how they were going to quote kill them all. And so you know it turns out shiny hunter said hold my beer and by the way make sure content management system is patched and it was not. So what I think is hilarious here though is this is I mean it's such a great case study here because now literally shiny has done to to clop right they they have their onion keys which means that they can publish the site and they they're doing the same thing the law enforcement has done with several dark ones they take the worst for the we own the site now right you know you want to reconstitute you go do it someplace else and I'm going to tell you here too by the way.

If anybody from shiny or clop is watching this I'm going to take insides here I'm just reporting on this right you do you fight it out leave me out of it right so but yeah yeah I mean to go target organized crime is there like a is there like a secondary betting market on this like threat actor versus threat actor like what's the cyber poly market there was one a while remember like for deaf con deaf con like yeah that was a thing it was like well I say I know what well an a.m. And what well an a I get prompted injected during a demo or you know stuff like that yeah I mean I don't know I feel like shiny hunters is much more recent much more relevant like I you know that to me is more like you know the overdog versus underdog clop hasn't done much in a while but yeah. Clop. All right big big though right so they find a vulnerability they they go and ride that thing like rent a fuel you know shiny is a lot more social engineering. Right yeah so clop still has big impact have they published I mean have they done anything recently like I like it's kind of crazy in the world of AI like everyone has a zero day these days this goes back to me talking about how we talk about is AI we don't talk about ransomware anymore which was like the complete opposite like three years ago like there's ransomware stuff going on left and right it's just not making the news anymore that's not it's not what the people want.

Corey gosh well I want it I'm the people. Well they're on two logs will start ransomwareing the people that are and then we can get back to it don't throw any of these things you make money. All right that's how it goes business plan that that's the best that's where we're going to close it folks thank you for coming and we'll see you next week bye bye. I'm

More episodes

More from Talkin' Bout [Infosec] News

View all episodes →