Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
Get every episode summarized
Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
Enterprise Security Weekly (Video) is made possible by:
“This week's Neha Lentani from Horizon 3 is with us to discuss how automated validation can help exposure management. Then in this week's topic segment, how closely is your TV watching you?”From the transcript
Interview with Snehal Antani
Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest.
This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them!
Topic Segment - SmartTVs and Privacy
For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear.
We share our recent experiences and dive into some of the primary concerns and theories about what's going on here.
If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms.
Weekly Enterprise News
Finally, in the enterprise security news,
- We check the vibes
- We check finding and acquisitions
- Nightmare Eclipse or Good Night of Sleep Eclipse?
- Update on Anthropic's Glasswing project
- How long would it take for a mobile phone worm to spread?
- Don't expose SSH to the public Internet
- Massive amounts of cryptocurrency continue to get stolen
- Did you actually read your third party's SOC 2?
- Your boss may be reading your AI chat history
All that and more, on this episode of Enterprise Security Weekly.
Show Notes: https://securityweekly.com/esw-476
Get every episode summarized
Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Transcript ready
1,187 searchable segments. Every word is indexed and playable.
Full transcript
Enterprise Security Weekly (Video) — Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476. Machine-transcribed; use the interactive transcript above to jump the player to any line.
This week's Neha Lentani from Horizon 3 is with us to discuss how automated validation can help exposure management. Then in this week's topic segment, how closely is your TV watching you? Finally in the Enterprise Security News, we check the vibes, we check funding and acquisitions, Nightmare Clips or Good Night of Sleep Eclipse. Update on Enthropics Classwing Project. How long would it take for a mobile phone worm to spread? Don't expose SSH to the public internet, please. Massive amounts of cryptocurrency continue to get stolen. Did you actually read your third party's sock too? Your boss may be reading your AI chat history. All that and more in this episode of Enterprise Security Weekly. It's the show where we talk security vendors and aren't afraid to name names. It's Enterprise Security Weekly. Welcome to Enterprise Security Weekly and Happy National Eat a Hogi Day. This is episode 376 recorded for Monday, September 14, 2026, which is when that Hogi Day is.
I'm your host, Adrian Sonabria. And joining me is the Warrior of Words, the Captain of Content, Katie, Titler, Centulo. How are you doing, Katie? I am fine. I'm now hungry, but I'm fine. Thank you. So you're hungry. So you understand what a Hogi is for people in other parts of the country where that term is not ordinarily used. Would you explain what a Hogi is? A Hogi is what some people might call a sub or I don't know what else do they call it. A grind? Oh, yes, a grind. Yeah, it's a sandwich on some bulky bread. It can be like an Italian or a chicken parm or a meatball. You could have a meatball Hogi. You're a meatball Hogi. No, sorry. Yeah, it's a sandwich you would typically get at a deli or a pizza shop and it can be whatever you want and they're often very delicious. Indeed, indeed.
Also joining me is the Master of Marketing, the Mayor of Mayhem, Arbiter of Agents, Tyler Shields. How are you doing, Tyler? Doing well, doing good to see you again. Hogi's, you can't have a Hogi without two things. One, you got to have good Boards Head Meat. Two, you have to have phenomenal hard crust bread. That's what makes a Hogi a Hogi. Yeah, it's a texture thing, huh? For sure. Yeah. Yeah. Like you can't get away with this soft crust subway garbage. That's not a Hogi. That's a sandwich. In Ireland, they're legally not allowed to call it bread because it has too much sugar in it. Well, there you go. It's like US bread or just bread in general. No, it's always bread. It's always bread. It's always bread. Yeah, subway specifically. I think all of the bread. They make their sandwiches with a bread like substance. Yeah. I think all of the bread in the US is pretty sugary. It's. Yeah.
All right, some quick announcements then we'll jump into our interview for this week. First announcement here, security leaders, you can't secure what you can't see between Cloud Sproulsass, Shadow IT. Most organizations don't have a complete picture of their attack surface. So how do you measure and reduce exposure at the attack surface management, virtual cyber security summit on September 16th? And how leading teams are gaining continuous visibility and turning unknown assets into managed risk security weekly listeners can register for free at securityweekly.com for its us asm using the promo code CSS26-sw. And I will be on one of those panels. So be sure to check that out. I'll be on the third panel for that one. That number two is about InfoSec World in Orlando. You can unlock the full experience with the all access pass featuring premium workshops,
exclusive content, VIP experiences, and expanded opportunities to connect with cyber security leaders across industries. Again, that is in Orlando October 12th through 14th this year. listeners can save 30% on their pass with code ISW26-sw savings at securityweekly.com for its infosick world 2026. If you're listening to this, that's a lot to remember. If you go check out the video version of this, it will be up on the screen. It will be easier to jot down. Or in the show notes. All right. So this interview is sponsored by Horizon 3 and today we're discussing how automated validation can help expose your management. We're excited to once again have Snayha and Tani, CEO and co-founder for Horizon 3 with us today. Welcome to the show Snayha. Yeah, I'm glad to be back. And it's great to have you back. This is one of my favorite categories. I remember getting very excited when the breach and attack simulation category came out. It was interesting watching that category grow.
I didn't always agree with the direction some of these companies went in. But I think that's one of the reasons I'm excited that you guys decided to sponsor our show and that we have you here. So I think most folks are probably familiar with Horizon 3 at this point. But for those that aren't what's given us the quick elevator pitch. Yeah, our teacher it's literally say go hack yourself. Which is a great hit at Black Cat. The whole idea is don't how do you hack or run a pen just against your organization. Find ways that you're actually exploitable. Use that to know exactly what to prioritize and exactly what to fix. Go off and fix it. Then re hack your spell. They verify that you're good to go. So it's all about hack fix verify repeat over and over again. And the alternative is what I used to do when I was a CIO which was brush one tooth once a year. I only afford to test a small section of my environment. Even then they show up for a few days or a few weeks engagement. Leave behind a PDF, disappear and I'll be there.
For every patch Tuesday, man, I wanted a pen test Wednesday. Every time I want to know that I'm exploitable. I think I'll end with I was sick and tired of getting 100,000 vulnerabilities from a bone scanner. Those are which weren't even exploitable in my environment. Log for shell being a great example. Just because you got the log for Jjar file doesn't mean it's a problem. You could have had an egress rule in place that blocked the outbound RMI call or so on and so forth. So is this thing actually exploitable? And how do I quickly fix it or what we focus on? You've spent a lot on cybersecurity. But if a real attacker hit today, could you prove your defenses would hold? That's the question horizon three answers. Their node zero platform autonomously and safely attacks your production environment. Revealing exactly how attackers could compromise critical systems then verifies its fixed instantly. Hack fix verify repeat. That's the world's best AI hacker on your side. Go hack yourself with node zero before someone else does learn more at securityweekly.com
forth slash horizon three. Yeah, it's interesting. I was just talking about that earlier today with somebody that was it was kind of shocking to me how few breaches we had come out of log for J given that like everybody had it in their environment, right? So very interesting and I think a lot of it was that people had decent egress rules for their server environment. So you know that outbound call to pull down the next stage of the attack payload didn't succeed. Yeah, exactly right. And in fact, think about the poor schleps that that had to burn their Christmas week because some being counter with some spread she said, no, no, you got these jar files over here. Even though you put in that egress rule, they still had to burn their time. And so I think we've got a big area of growth across every company on the distinction between vulnerable and exploitable. Yeah, and also I'm trying to get rid of the the word patching as synonymous with remediation, right?
Like there's so many opportunities to mitigate these attacks. And sometimes you can never install the patch. Maybe the vendor doesn't let you do it for that particular product or that environment. Or when you install the patch, something breaks or the patch didn't even work in the first place to stop the attack, right? That's another thing that you need validation for. Yeah, in fact, patching is such a small portion of the options you have. It doesn't even address the bulk of the techniques and attack or use all T guys off of this story. I love to get your reaction from it. So we had a customer where they were very proud of the password policy they had in place. 14 character, alpha numeric, you know, forced or change it every so often, whatever else. And when they ran us, one of the things that we'll do is we'll DC sync Active Directory, we'll pull down NT 11 hashes and we'll do a password distance analysis of those hashes. And so if your password is rising three kicks ass dollar sign dollar sign and entirely yours is kicks ass just single dollar sign, we'll tell you that these are pretty similar and they're
off by just a little bit. Well, one of our customers 70% of their passwords were identical, not not similar, identical. And they're like, Oh, right. They're like, there's no way this is possible. It must be a false positive. What's cool is like we did it. It's a fact. Here is the you're the exact same. It turns out somebody forgot to enable change password on first log on. And so all these employees would get this, you know, printed out 14 character alpha numeric. And like this must be my password. I'm just going to memorize this thing instead. And so what are you going to patch in that situation? That's just patching is such a small part of what it solves in your environment. Attackers don't hack in with zero days. They log in with compromised credentials or the default credential you've assigned everybody. Yeah. And then at least have some other factor so you don't have to care so much about what those passwords are, right? Yeah. Exactly. Right.
So there is a couple of interesting stories of being able to fully exfiltrate data from Slack or from doing any of these other services, even if they're in the fade. We can talk about those kind of attack that. Sure. Yes. Stealing O off keys, bear token stuff like that already logged in session. No need to authenticate. No, no to a fake. No, I'm a fake needed. Yeah. Love it. Um, so, you know, one of the things and I love that you already mentioned like traditional pen testing is infrequent, you know, something you do maybe once a year, maybe twice a year and very time bound, you know. So it's a best effort by the pen tester you've paid for 20, 30, 40 hours of their time. And hopefully they spend that time wisely and they cover as much of your environment as possible. Often it's not possible, right? You know, given that limited time that you have. But also as somebody who used to be a pen tester and who has broken a lot of stuff, one of my biggest concerns with this kind of tooling is how do you ensure that you can do it
safely? Um, I tried to do it safely, you know, over time, pen testers learn, oh, I can't do that. That's going to break things. But with an automated tool, is that one of the big concerns that you run into with customers here and how can you make sure that they can feel comfortable pointing this at production? Yeah. So one of the important part, one, a key part of what we designed from the beginning was we had to be safe to run against real production systems. You can't pen test a digital twin and that's what some people are trying to go off and do. And the analogy I use is, I'm going to call the mechanic and say, hey, my Toyota camera is leaking oil. Can I bring it in to get a check? And you as mechanical, like, nah, man, I got a Toyota already in the shop. I'll go check that one instead. Like, it doesn't make any sense. This whole idea of digital twins in cyber, um, I just don't see how you can accurately represent all the edge cases and nuances and so on in a twin. So you have to operate against real production systems because that's where the attacker is going off and living.
At the same time, you can't make the person's day worse. You can't just arbitrarily and recklessly do something as innocuous as password spraying and start locking out everybody's accounts. Or can you pick up the account lockout policy at the global level? Because that might vary. Depends on domains, depends on whether your shell login was tied to the global policy load plus all sorts of nuances and edge cases. And you also can't just throw AI slop at a house's machine if you're pen testing at a hospital. You could kill somebody. All of things are all part of the guard rail or the harness in AI hacking or AI pen testing. And you can't design those things after the fact you've got to design for production safety from the junk on day one. And the other important part is, um, the more diverse environments you see, the more edge cases you see, um, and the better the reinforcement kind of learning loop you create, the faster you're going to grab that institutional knowledge or memory of what's safe to invoke and
what's unsafe to evoke. And if everything has a bias for, if you're even the slightest bit uncertain, don't do something like skip it. Uh, you're in a, a spot to be production safe at scale. Now, and with, man, in production safety claims, everything works in, in PowerPoint, everything works on your website. You've got to earn the right to, to run against production systems. Uh, and you've got to let your those results to the topping. So for us at Horizon 3, you know, we ran more pen tests today or AI hacker did than global consulting firms ran all year. We ran more pen tests last year than the entire history of computing. Everyone of those against real production systems with real edge cases and real learning loops that help ensure that production safety claim holds true. Uh, and it's just about volume, diversity and, uh, and depth of the environment that you can assess to be able to, uh, uh, make that claim. Yeah. Yeah. I imagine with some of your customers, you know, maybe they don't believe you fully, right? You know, so they do start out with that digital twin and, and once they get comfortable there, then maybe they move to their production stuff.
Yeah. It's actually, um, one, nobody should believe me. Once again, only results do the talking. And what we actually see people do is they'll start with a really small environment first and like small and gentle. And then they'll methodically open up the aperture while methodically increasing, um, the complexity of attacks or the types of techniques that are going to be allowed to be selected, uh, by the system. And then you get to the point where you feel comfortable, you understand the environments. Now there's, there's three interesting edge cases that, that, that happened early on, um, and every so often we'll see that now, um, but there are also edge cases where there were real problems in the environment, like real resiliency problems. The most annoying one is if you, if you touch us, uh, a printer in, uh, if you end up scanning it or prob it in the right way, you'll start spitting out pages, right? Um, it'll start, uh, uh, burning, uh, garbled print, print, print our all pages and so on. That kind of sucks. You don't want to do that. You're not just sitting production issue, but it is annoying and it freaks people out.
And so you've got to be very careful on the kinds of things you do when you see a printer. Yeah. Another one is like power controllers. Um, if you, or power supplies, the admin consoles of most power supplies and it's true for actually most OT systems as well, they can't even withstand basic scanning. They'll start locking up. You see a power supplier, you want to understand what are you allowed to do and not allow to do and be very judicious. And the final one, this is the most interesting was there was a, a misconfiguration at one customer between the load balancer and the firewall where they weren't properly routing RFC 19, uh, 1918, uh, uh, routes to know. And so as a result, uh, the, the, these requests would start to bounce between the load balance and the firewall and actually an internal denial service. Now, I've, and for me, whenever something like that happens, it's my fault. Like on the CEO of the company, I'm again, the call the customer and understand what happened and talk through, uh, the situation. And I was expecting this person like this shop four years ago to be really angry with me. And they said, no, no, this is, this was a legit problem.
I'd rather find it on our, that's a find out. Absolutely. 100%. Yeah. I mean, if your stuff is that fragile, you know, what's an attacker going to do there, they're not going to be careful, right? Yeah. Exactly right. Well, we're finding, we just expanded into the web application, pen testing space. And what's really interesting there is how brittle web apps are like real production of web apps can't handle certain levels of, of, of, of, of, of traversing routes as an example, um, and, and, and so on. And so I think that as more people vibe, I call them crap locations like these vibe coded replications. So there's more people vibe code crap locations. Like the quality of that code is not very good. I, I truncated a database once with just your, your basic SQL injection test. Yeah. Is that the right? So I do think to restore it from backup. Yeah. These vibe coded apps in particular are going to be very brittle. They're also going to be recklessly integrated into off systems and so on. I think that attack surface for web apps is going to grow significantly.
Um, but I do think that the crux of an attacker's tactics are still going to be living off the land, a lateral movement through the overall misadventures like kind of the fundamentals. Yeah. So, so one of the things, uh, unless Katie or Tyler, you've got something, uh, I've got more questions, but feel free to jump in. I was going to ask, um, if there are any trends that you see that are more prevalent now when you're doing testing across companies, you know, whether it's, whether you're breaking it out by size, a company or industry, are you finding any trends in these tests? That are concerning to you. Yeah. One of the biggest surprises and I see this consistently is how many customers have spent millions of dollars on EDR and data security tools and so on. And they're not even configured correctly. Yeah. Like we run into detect only mode EDR is all the time or they forgot to enable OS credential
dumping prevention capabilities, uh, or whatever else. Literally the first thing the attacker's going to do when they're on the host. Exactly. Right. And so I am shocked at the how ineffective security controls are and the false sense of confidence across the board. There is a leading like upper right, right, magic quadrant EDR that only stops our implant. We drop a rat on a host and we'll, for post exploitation. It only stops that implant 16% of the time, one six, not because it's a bad product. It is the best product in the market by, you know, in general, if it's configured correctly, but that's a big caveat. And so I think, uh, Julie, my big, uh, my big takeaway is how ineffective these security controls are and the false sense of confidence people have. And they're only going to know it was misconfigured when the bad guy shows that is not a conversation I want to be part of. So when it comes to compensating. I'm going to say sorry. Sorry. So when it comes to compensating controls, um, are you testing them individually?
Are you testing them in combination like toxic combinations? Are you testing them? Um, you know, like if there's a misconfiguration on an EDR on a low severity, CVE or something, how does that, how does that work with your system? So at the end of the day, the only thing that matters is what the attacker could achieve. Just because they popped a box doesn't mean that's a big deal. Did that popping of that box allow them to become domain admin gain access to sensitive data or achieve some consequence to the business that requires the business to either explicitly accept that risk or search resources to do something about it? Uh, and so testing an individual control and standalone. I don't think it's very useful. I was actually one of the earliest and one of the largest breach and attack simulation customers out there when I was at DOD. And it sounded amazing in marketing and websites and demoed beautifully.
And and then you realize that I've got to install a credentialed base agent on every single machine I want to test. And it can only test individual controls. It can't understand the full end and attack path and chain multiple issues across multiple machines in an authentic way. Uh, then what is the point of this thing? It's just giving me a false, you know, sense of what's working. And so that's actually what compel me to start rising three. So for me, it's all about toxic combinations that lead to a consequence. Part of that toxic combination could be a missing or misconfigured EDR. Another part of it could be an easily compromised or crackable NTLM hash. It could be the blend of the two. So for example, uh, we will get through a variety of techniques. We'll compromise a cred, we'll log in over, um, over whatever, uh, ports onto the box in a way that the EDR won't even realize we're there. Most local admins are most local users are also local admins in most corporate environments.
And now I can start to enumerate processes on that host. I can do all sorts of other things. If you have Slack desktop application on windows and I've got, um, I'm, I'm able to run as local admin, I can enumerate that process. Pull the MFAed off token out of memory, use that to access the Slack workspace of that user and start ripping data. So that's just an example of the outcome, sensitive data exposure. The fact that I was able to combine a compromised credential, a, uh, miss, or a missing EDR or ineffective EDR config and, uh, uh, uh, fundamental design flaw in windows allows me to pull the off token. That's those are the steps, but that's not the outcome. And so I think that testing controls and isolation once again, false sense of, of safety and confidence. I do think there's, it's almost like your dev test environment for EDR. Yeah, you want to do that to figure out what the right config should be, but how it actually exists in real environments is what matters. So I have a question specifically around the, um,
for lack of better term, I'll call it the doom and gloom situation of what we're hearing here, right, is that there's a lot of problems, a lot of problems. So we haven't been able to solve in my 25 years in cyber back when I was been testing 25 years ago. And it was largely pen testing as an industry was an issue, uh, couldn't really solve problems because of an asymmetry of time and speed. Yeah, you had one person could only work so many hours a week and you had kind of the infinity of risk you had to reduce, right, the infinite level of risk and, and you couldn't always, you couldn't take it to zero. With the advent of AI and this is where you guys come into play, we're somewhat solving or at least, um, lessening the asymmetry of time that exists between an attacker and a defender or in this case, a pen tester and the reduction of risk. What I'd like to know is in your opinion, given the expert seat that you sit in, do we have a chance of actually from the outside in using AI in a continuous way.
In a hyper speed compute line speed way of actually reducing risk to the point where we can, we can lower vulnerability chances lower and your rate of attackers from our system. We failed for almost 30 years. Yeah, it's an awesome question. So let's break that up into three parts. So first and foremost, kind of an underpritting principle, the goal of running a pen test isn't to find problems. It's to quickly fix problems that matter. Like that is the goal. I was fed up when I became a CIO of these PDF reports showing me how bad I was and no one having the process or the follow through to get rid of that risk. Right. The goal is to quickly fix stuff that matters. And the hardest part of my job at CIO in this kind of first pillar of the answer was deciding what not to fix. I had tons of vulnerabilities, I tons of misconfigues out of a bunch of pen test findings. What do I do and not do? It's not like I have extra time, extra resources or extra money. So if I'm going to do something new, I've got to stop something else. So prioritization was paramount and that was 10 years ago.
It's even more important now with mythos and this flood of vulnerabilities. By the way, you'll see like a huge surge in new CVEs, but you don't have a corresponding surge in CISA kevds. And so the prioritization problem is only going to be more difficult for organization. So the way I used to prioritize and what I recommend people do today, is is this thing even explodable? Is it known to be used by threat actors? And what is the consequence to the business? If I can clearly articulate those three things to leadership, I can then go to leadership and say, you're either going to accept this risk or you're going to find resources for me to go do something about it. You pick. What do you want to go off and do? So the first part here is, have you even mastered the art of prioritization? The second thing is, okay, the attacker gained initial access. They somehow got in, can you even minimize the blast radius and prevent them from achieving their objective? Are your security tools even working? If they are, do you even know what to do when they show up?
And a key new area of innovation here is, we've been doing a bunch of research on the gullibility of models. It turns out that these models, because they trained on such shallow cyber data, the most valuable data to train an AI hacker is behind the firewall. It's all the edge cases for active direct rates, the edge cases for your network configs and IEM configs and so on and so forth. And last I checked, Bank of America didn't publish those configs online anywhere for anthropic to scrape and train off of. So all these hacker agents from the frontier labs and the Chinese models, all trained off of very shallow hacked the box, captured the flag and volned data. It turns out these things are really easy to trip. So if you put a fake password.text file or juice shop as an example, I think of the meme of the dude sweating to press the button, these LLMs will see it and they can't help themselves but want to interact with it. And it turns out an expert hacker is going to click on that fake password.text file,
that fake honey token 37% of the time. You can get 4, 6, 4, 7, 4, 8 to click on that same thing 92% of the time. And if you make that, that's just arbitrarily placed. If you well place honey token, so think of a fake AWS credential in a Unix home directory, you can get the latest frontier model to click on it 95% of the time. That's a gullible by design. Yeah. So suddenly deception is the cheapest fastest, most effective way at catching the bad guy. So you're not going to patch everything. You're not going to fix every vulnerability. What you've got to do is the experts at minimizing the blast radius. And that gets to my third point, which is, okay, the alert went off. There's a bad guy ringing the bell touching that honey token. Do you even know how to respond to a breach? Have you practiced? Have you built the muscle memory? Have you trained like you fight? And most organizations don't. What I find is organizations that crash their data center every quarter on purpose to test backup and recovery tend to also be really good at cyber incident response.
Most shops don't do that. And so most shops have no idea who has the authority to kill the entire network in the middle of a ransomware attack. And not just Tuesday at 3pm when everyone's in the office, but 3am Christmas Eve. Or if you've got a European subsidiary in the middle of August when everyone's on vacation. Who's got the authority? Because every second matters. And so I would say master prioritization, master minimizing the blast radius, and master training like you fight. And those fundamentals will put you in a great spot to minimize damage the attacker can achieve. Yeah, yeah, love it. Very concise answer there. I appreciate it. And these are things I've been talking about for a long time. The last thing, and we've only got a couple minutes left that I wanted to touch on. One of my big concerns coming out of Black Hat was we had two big events or two big things going on that I was seeing. One was open AI hacking, hugging face.
And we've continued to see more and more, almost daily come out of that where they're all. And we also did this and the model also did this. And at the same time, everybody seemed to be selling like 100% LLM driven AI red teaming agents. And I'm thinking like, okay, maybe opening AI can get away with hitting hugging face. But the moment Bucky's hacks sheets are wildfire, stuff like that, I don't think lawyers are going to be amused. How is that whole movement hitting you? So it was amazing to see OpenAI publicly admit they committed a federal crime. Yeah, because they did they committed a federal crime, using computer, you know computer abuse several. Yeah, it is cool, right? Man, I wish I could have, I mean sometimes I joke like, hey, let's just take off all the guardrails, point this thing at an anthropic and unleash hell.
Like, hey man, sorry, there was no malicious intent, the agent did what it did and we ripped you apart. So I think that the law around agents hacking another business is really on, it hasn't truly been tested. I'll tell you if that stuff happened in Europe or if that happened in Asia, in any other country, they probably would have had a very different reaction and a hell of a lot of penalties come in and fines and so on. So I, this, I mean, when we first prototype, no zero in at the end of 2019, it broke out of my co-founder Tony's house. It started to enumerate everything on the ISP and it found a way to get default credit access off of Cisco gear into I think like the British consulate or somebody that was on the same ISP as my co-founder. And we pulled, you know, there was a bit of a pucker factor like holy crap, what just happened. And we had to go through and understand and we were very intentional in the guardrails to make sure you don't break out. And so I do think that opening, I openly admitting
to committing a federal crime is cool. I think that there are, there are a lot of lawyers and a lot of companies are going to be extremely cautious of allowing that to happen to themselves because I don't think certain countries and other markets can be as forgiving as hugging face was. For sure. Well, Snayhael, thank you for joining us in Enterprise Security Weekly today. This is great. Awesome. Yeah, thanks for the time, guys. Appreciate it. All right, make sure you visit securityweekly.com for it slash Horizon 3 to learn more. And stay tuned. When we come back, we're going to talk about TV privacy. 39 seconds. That's all the time it took for an AI agent to delete a company's entire production database and every backup with it. Autonomous agents are now common in production systems and they will make mistakes. Is your business ready to deal with agent failure? Rubrik Agent Cloud was built for this moment with posture management that can surface dangerous credentials before an agent finds them with runtime governance that can block destructive
actions before they execute and truly isolated recovery that lives outside the influence of your AI. When an agent moves fast, Rubrik makes sure the damage doesn't have to last. Learn more at securityweekly.com for it slash Rubrik. Welcome back to Enterprise Security Weekly. For this week's topic segment, we are exploring privacy and televisions, particularly smart TVs, which I think is the only kind of TV you can get if you're not at a pawn shop or an antique store or something like that at this point. Funny story. We went to the beach for the Labor Day weekend and couldn't reach the HDMI port. So I decided I was going to take the living room TV off the wall and so I could plug something in and just put it back on the wall mount there. And man, turn around for a second and it slid off the
piece of furniture I set it on. Broke the TV. No kidding. So thankfully, yeah, so the Airbnb insurance is really cheap. You should take it. I think it was like $50 a day or something like that. Or don't take the TV off the wall. That's also good advice. You could also go with that. Or take both of those pieces of advice. But so the new TV shows up and I have hung hundreds of TVs on walls for myself or other people. And it was a Phillips Roku TV. And so this isn't my house. This is an Airbnb owned by a corporation near the beach. Not even owned by an individual, I don't think. And I don't want to log into the Roku thing with my account. Let them log in with their account.
But still we want to use the thing. And you cannot do anything with it. You can't even plug HDMI into it and switch inputs until you've connected it to the internet and logged into it. Logged into a Roku account. Then it lets you control inputs. Right. So even with an HDMI. Yeah. Yeah. Like I was thinking, okay. Like we can just I can plug a laptop into this thing or you know, we can play media off of that. Like I don't have to log into it. Nope. Have to log into it. Have to agree to licenses and agreements and all that stuff. So I know this is enterprise security weekly and this does seem like more of like a consumer level thing. But TVs are everywhere. Right. Like every conference room has one. You know, you find them in hotels. Every hotel you stay in, every restaurant you go into, you know, especially sports bars. Conferences. It's kind of presents conferences. Yeah. It's kind of impossible to avoid them. Right.
So they've been in the news a lot. LG actually allegedly had a monitor that would install McAfee without asking you on if you plug the Windows laptop into the monitor. Right. Over USBC or HDMI. I didn't even know this was possible. But apparently this is built into the spec where it can actually push software to the host computer that it's plugged into. In that horrible. That's just people who didn't even think through. I mean, look, well, I'm going to completely set aside the risk issue and the security discussion here and just talk about usability and usability of design of that kind of environment. That is just horrible from the ground up. Why would you want to push anything? Software related on to somebody's laptop from an installation standpoint. And I don't know about you guys. But whenever I've bought TVs over the last handful of years, the very first thing I do is hook them up to an Apple TV or some kind of third party device because the user experience on all of them is horrid.
So bad. And Apple TV or whatever third party system you prefer tends to have such a better user experience and user interface that I just want the dumb TV. I never wanted I've never wanted to buy a smart TV in my entire life. Yeah, same. And and one of the concerns here as soon as you plug in your Apple TV over HDMI, that smart TV starts sending out more traffic. People have found. It starts talking more in the network when you plug in your external device. So think about plugging into a TV at a conference. I don't know what it's sending out and I don't I have not been able to find enough research from people like are there screenshots of my slides going out. Like what is what is actually being transmitted from these things? What are they actually recording? So they do have something that's well documented called ACR. And automatic content recognition and the idea behind this is. You know, when they can recognize you think using either sound or a screenshot of something what you're watching, they can recommend you related stuff, right?
Even if they don't have direct access to that like you're using your Apple TV or something like that, they can still see you watching legally blonde and then they can advertise legally blonde to to you, you know, speaking of of pretty in pink. Talking about in between stuff. Yeah. Tyler is doing a pickleball for charity. That's right. I've got a charity event where I have some pink wrist guards wristbands. That's what the Adrian's referring to for those of you that are not watching visually. But yeah, I mean. Look, and people I'm I'm actually not overly concerned about the privacy impacting problems as as big a problem as they are. Because I feel like most people will trade in that privacy for convenience. But my question and concern is, is there a convenience that's being provided back that's commiserate to the privacy impact in this situation. And then do you have the ability to opt out? Right? Yeah. Ideally in an ideal world that's opt in. I agree. Right. You should have to turn it on. Not turn it off.
But at least in the event, do we have the ability to opt out of the ACR to opt out of the privacy capture to opt out of what might be considered a risk factor to an office scenario or a conference room scenario or in in Katie's case like an events center scenario. So I think that that bothers me more so than knowing whether I have my pink wristband wristband on or not. I think the tradeoff isn't necessarily on the consumer end. And again, when you're talking about consumer, you know, like Adrian and his partner when we're in an Airbnb or whether you're at a hotel for work or whatever. You're the consumer, even if you're working on behalf of business, it's the business who's supplying it, right? It's it's like everything else that we've seen over the last 10 15 years where they get the data. They get to push. You know, but per Adrian's comment legally blonde versus legally blonde too, you know, we've all had people in our lives who are like, my phone is listening. What kind of, but it's doing these exact kind of things.
So with TVs, it's no surprise that this is happening, right? Because we've all had, you know, conversations or been online or looked something up and then all of a sudden. You know, something pops up in your feed and it's like, it's listening. Well, yeah, it is. It is. And the whole point of your phone isn't to be convenient for you. It's so businesses can sell you stuff. I mean, just just so you know, when my fiance and I or when my husband and I started to talk about getting engaged, what did I do? I started looking up engagement rings that I wanted. Because he's on the same day on Wi-Fi, right? And I know it would get into his feed and he got me the perfect ring. Like, so we know how this works. And it isn't new whether it's you poisoned his ads. I did poison his ads. I did point. I have another funny story about that that I'll tell you, um, not on air because it's not relevant. But, um, we've been dealing again, this is another old problem surfacing in a different way, right? And, um, what I find interesting is so I don't actually have a smart TV. My TV is like 12 or 13 years old. And I just have a broken device.
But when I go to Airbnb is and other people have logged in and I, you know, I use their services versus mine because I figure that's safer for me and more private for me. What are they seeing about me and do they wonder what the hell is happening when they start getting things in my preference, right? So that's that's more interesting to me than. Oh, okay. You know, this company figured out that I should now watch legally blonde too or whatever the case maybe because now you're cross contaminating user data and who does that help? Yeah. And I think one of the big problems here is the lack of transparency leads to a lot of assumptions that are not even necessarily correct here also. Like we've all heard the, you know, the things about. And there have been lots of studies on whether or not your phone is actually listening to you when you're not triggering some kind of voices this or something like that.
And we have zero evidence for our phones listening to us and then showing us ads later. You know, there's no evidence that that ever happened. In every case that's been investigated, it's been something that they googled the day before or like you said, somebody else on the same Wi-Fi looked it up. You know, we don't actually have any evidence for that, but it feels like that because nobody's explained how this works to us. Right. So we're assuming it's technically a microphone. It's, you know, quote, listening, you know, and it open. Right. But that's what people were thinking. It was that the microphone was just catching casual conversation. And people would try and test it and talk about something, you know, that they'd never talked about before. And then they would start getting ads for it. Every time it's been investigated, there was an explanation as to how that happened. Because they're mindless. They're googling as they're talking. Yeah, exactly. And so I was a beta tester for the very first Amazon Echo, which was the first voice assistant that I recall that you could buy.
And I remember one of the first things I did with it was just run a network capture on everything coming out of that thing. Because I wanted to know I'd never had a device before in the home. This is like 2012, 2013 with a microphone that was always on. And yeah, sure enough, you know, there's like four bites of network traffic a day unless it needed to update its firmware. Nothing was going out unless we triggered it and asked it for something. Unless it's got a 4G or 5G modem in it, which some people said, hey, like we could see these people start blocking these things from getting out to the internet. 4G modems probably cheap enough for TV manufacturers to start throwing in these things. So I think that assessment might be a little bit dated. And I think that assessment might be a little bit dated and hear me out when I say that. I don't think that. Well, it is I'm talking 2012. So it literally is it is definitely dated just by fact that it was 2012.
But I don't want to say the G word because my little device over there will immediately start yapping and you'll hear it in the background. But I use that one. And there's features now in it that you can tell it to remain active after a question occurs for follow up questions. So you don't have to reprompt it. So it's more conversational. Yeah. And it becomes more conversational. The more conversational the interface becomes the more continuous it has to be to maintain that conversational capability. And so how long, right? And I'm sure it says it in the documentation. How long it stays active for 10 seconds, 5 seconds, whatever it is. But I know does that creep over time? Does it? I don't believe that we will see a world over time where they remain the way they were in 2012 in the sense of not just passing everything through. Now the real question becomes is it stored on the back end? Is it connected to you as a profile? Is it used to continuously paint the picture of who you are and what you search for and what you talk about. That is more the problem than sending the content off because the content will be sent off just to maintain that conversational capability that the users will demand or already do demand.
Yeah. So before we wrap up, two things I wanted to mention here. One, the answer to the question posed earlier is yes. You can opt out of these things. LG claims that it is opt in by default. Though I can't imagine why anybody would opt in to ACR like hunt down that setting in the settings menu and turn it on. It seems like most of the other ones are opt out and consumer reports. I'll include it in the show notes has a guide. It is a little bit old. It is almost a year old. But generally for each operating system out there, LG uses WebOS, Google has their Google TV Android TV. So there is only like a Roku has their thing. It has got step by step on how to opt out of these things and turn off ACR in most TV. It is a completely, it is a completely moot point because for every one of us that are cyber minded and security minded and privacy minded,
there are hundreds or thousands of people out there in the world that couldn't care less. We'll never hunt down and opt out and we'll just leave it on. So you may as well say population wise, it is always on. Well, but for the individual that cares about this, they are literally going to sleep better in the audience. Our audience will. And then the other thing I wanted to mention, Apple just announced all their new devices yesterday. The new iPhones, the folding iPhones, the latest Apple watches and one of the new features. I don't know if you need a newer device to do it or if it's just a new software option is to listen all the time is to record all your ambient conversations and give you a summary of this stuff at the end of the day. It's on the watch now too Adrian. Yeah, that's what I'm saying. The watch. Yeah, yeah, yeah, this is the watch that I'm talking about. And of course being Apple, nothing leaves your devices.
It's all done on device. You know, they're very careful around privacy. But you know, it's still something where, you know, I might watch what I say if I'm around somebody who's recording everything. You know, that I'm saying if a transcript of what I'm talking about, if you know, you might not know. Well, but that's the thing again, that's why transparency is so important here is you kind of have to assume that you're you're just not going to know. So, you know, maybe people just always assume everything you say is being recorded period 24, 70 days really. And it changes how people are now coming down to. It goes back to a conversation we had a few weeks ago on this show and you were talking about the recording at a CISO meetup where people. Yeah, we're literally pouring their hearts out and they thought it was private and it's it's a sad situation when we have to think that way. But now, you know, anybody who cares about this, are you going to think twice?
If the person you've just met has an Apple watch, right? Like, I mean, I guess you're not going to say anything super private. Somebody just met anyway, but like, you know, if you are it at a personal gathering or a business gathering. There's so much that the phone could be doing it. I have this I have this little ring that that will record notes and reminders for me. Like, you can't even assume the device like yeah, you're not going to necessarily see it. You kind of have to assume that everything you're saying all of the time is being recorded, whether it's audio or visual or both. And then it has to be like crossing the street, you know, I'm going to cross the street to cars, be down my street. Yes, did they sometimes go the wrong way? Absolutely. You know, you got it. It's a it's a risk calculation.
Yeah, yeah. All right, well, that's all the time we have for this week's topic segment. Uh, stick around. We'll be right back with the weekly enterprise news. Attackers are running with Frontier AI now. Intrusions that took days, move in minutes while your triage cues still runs at human speed. Exophores answers at machine speed across the whole SONC lifecycle from detection through triage investigation and response. Exopods work the alert the moment it fires and hand your analyst a decision with the evidence behind it. Attackers have agents. Get yours. Learn more at securityweekly.com, Ford slash exophores. Zero trust is clearly the future as threats get faster, quieter, and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise ready, scalable, and operationally clean. Unknown software is stopped cold, trusted apps stay contained, and drift is locked down across the environment.
It's zero trust that works in real enterprises and prepares you for the threats ahead. CYC'sos are adopting it at securityweekly.com, Ford slash threat locker. Welcome back to Enterprise Security Weekly. Now for the Enterprise Security Weekly News, you can check out securityweekly.com, Ford slash ESW476 if you want to follow along as we go through the news or for links to the articles that we're covering. All right, and I need to pull them up myself here. And as usual, we are going to start with the vibe check. Tyler, you want to take it away there? I would love to take it away. I had the pleasure of actually getting on a Zoom or a Google Meet this week with Mike Prevet, who provides us with the security-funded newsletter in which is contained the vibe check. And I gave him direct thanks for letting us use these each week. So last week or two weeks ago, whatever it was, security-funded newsletter asked five years out, who owns security for the mid-market?
Which I love that question because we always think of creating vendor products and cybersecurity products for the Enterprise and securing the Enterprise. But in this particular case, it said who owns security for the mid-market in the next five years. And the majority of answers, I think, vibe with what it is today, although I don't know that for sure. But 46% said MSSP's or MDR's will, I think, continue to remain the owner of cybersecurity for the mid-market. 23% said platform giants. 23% said AI agents, which I found shackingly optimistic. And 8% were the dooms of the world who said nobody. Nobody will own security for the mid-market. Kind of like they obviously feel today. So I don't know what your thoughts were on that, Adrian. Where did you come down on that one? I was an MSSP MDR, no change guy. Yeah, I mean, we've seen that accelerating quite a bit. And I don't know. I think people leave parts of the thinking out of this, right?
I don't have a better metaphor. Like, to choke is a terrible metaphor. But that kind of blame ability, the ability to point a finger somewhere or tell your insurance company or allow your insurance company to sue somebody else. I think that's really that's become important to a lot of organizations. But also to have that skill, you know, that you don't have. I remember I was talking to somebody a couple days ago about their basically being tears of security operations where it was, we pre-recorded it. The audience won't get to hear that until the end of the month. But this is a small preview for you from Chris Carly. I did an interview with Chris Carly. His new book, he separates security operations into genitorial, firefighter, and then like elite SEAL Team 6 type stuff.
You know, so you got the stuff you'll handle yourself and then the stuff that you'll call in CrowdStrike or you know, you let the MSSP handle or like we got to go get even the MSSP can't handle it. They got to go get Mandy and to come in and take care of this. So that's a lot of it too. And yeah, that's expanded from security operations to vulnerability management to phishing testing to, you know, if you look at some of these big MDRs out there, the Arctic wolves, like it's a whole laundry list of stuff that they do for you. So I can't see AI agents taking over even a small portion of that. I want to press on that just a little bit, right? Because it kind of goes to your point. One of the things that I was immediately, for me, it was like, well, we're currently MSSP's MDRs. That's what the bulk of the mid market because we don't have the skill set as individual, small, the medium-sized businesses that'll be able to perform that kind of capability. We're not just, we just don't have that many cybersecurity people to execute. Nor do they have the revenue or profits in general to really kind of solve that problem at scale either.
So they go to MSSP's for the one throw to choke, but also for the outsourcing of the skill set and giving it to somebody who can hopefully have a better skill set than they do in house. But as you were talking there, it kind of triggered something in my brain. If moving down market to the mid market, kind of is like more process outsourcing and skill set outsourcing, skill set outsourcing, could AI agents actually achieve that? And I think what we might actually see is a combo platter of MSSP MDRs using AI agents to make sure that they increase their profit margins and increase their own efficacy for their customers. So I don't think I'll see mid market using agents themselves. I think you'll see MSSP's leveraging agents to become more efficient in what they do and be able to target a bigger swath of the market. Yeah, I agree. And that's your time, Jack, for today. That is the vibe check. The funding and acquisitions, I don't really have any opinions on
any of these, except I don't recall console getting, I don't, first of all, recall a company named console. And second of all, we're called Palo Alto picking them up for half a billion. I guess it's just a small tuck-in for Palo Alto. I don't know. Half a billion today doesn't mean anything. Who knows? Who cares? Just 500 mil. Just tiny little tuck-in. And then do control got acquired by a peer. So that's kind of interesting. I was tracking this market because I used to work for an SSPM vendor. And this is kind of in or adjacent to that SSPM sat security posture management market. But anytime I see a peer picking up one of their competitors or somebody at least a Jason tells me somebody ran out of money. And this was a good deal for somebody to maybe take some employees employed. Yeah, I don't know. It's probably a revenue purchase. I don't know anything about the company. So allegedly speaking, I really don't know. I don't
have any data to go on. But I think your assessment is likely. And I think it has probably very little to do with do control itself as a company, but more of the SSPM market kind of really coming under pressure under the quote, Sasspocalypse that occurred a couple years ago. And just putting them into a really awkward spot where Sass is Sass, right? And it's kind of fading away and being overrun by AI. Yeah, I mean, all the posture management are kind of features of a larger platform anyway. So I think it's inevitable. But yeah, the acquiring company was spin AI. I don't know that I said that out loud. But yeah, interesting to see that market contract a little bit. All right, with that. So I've been following root evidence. What they've been doing is really interesting. I think we talked about their report that came out last month that basically kind of called out the zero day clock website for miscalculating how they measured time to exploit.
And the issue was that they, you know, the point where they started the clock was when MITRE or CISA or whoever does it adds it to NVD, the national vulnerability database. And the problem is that's been taken them longer and longer to get that work done. So the data ended up measuring the speed of the government to add a vulnerability to a vulnerability database, not the speed of the attackers to start exploiting new vulnerabilities. So he's read on the website. It's very interesting. I think there's a lot of potentially useful data on there. I haven't had time to go super deep on it yet. And I love this. You know, this is how science works, right? Like somebody says, hey, here's some cool analysis I did. Somebody else says, hey, I think your analysis is kind of wrong. And then they do analysis. And then somebody else says, that analysis is also kind of wrong. So I think we need transparency to do this. I think people should be doing
this out in public transparently. I hate when this kind of work is buried into a product you have to pay for. And it's a black box and it's somebody's machine learning model. And yes, it's their IP, but also we're not iterating and improving as fast as we should be. Yeah, this one's interesting. So for those of you that haven't seen the site of the New Zero Day Clock dot com site, it is cloud code created 100% guarantee it's cloud code created because it follows the exact same patterns every other cloud code created site does. Yeah, you you can have a problem. Yeah. Yeah. And I don't have a problem with that as long as the output is valid. Like I kind of like the the look and feel it's fine for me. And there's some interesting data points on there. And I like how he cuts up vulnerability pressure from scanning pressure from zero to exploitation pressure. But what really caught my eye was the collapse timeline 20
years of warnings, everyone ignored. So if you click on the collapse up in the top bar, it actually shows from 2001 to 2026 different warnings about insecure software and the price we will pay for insecure software over the last 25 years quotes from University of Cambridge from noted luminaries from Harvard Kennedy School, the DARPA project. And I don't know really that anything has changed. It's just the delivery mechanism and the speed. And I'm not fully convinced that we are operating in any additional risk than we were back then. Yeah, I mean, I think it's a mischaracterization to say that it was ignored like the market for lemons. You know, the Bruce Nyer touching on that everybody saw that everybody read it. They nodded and they're like, yeah, those are the market incentives. And none of us saw anything that was going to change those incentives. So so yeah, it didn't get better. There's no incentive to build things securely. Yeah,
secured by design. That is the number one challenge is making it financially viable or attractive to do that. Yeah, and then under the call to action section, he's got 10 different calls to action from holding makers accountable, which is what you were just alluding to there to building security into the platform. Stop patching, start rebuilding all the way through fund the defense treat cyber as state craft. Oh, man, there's so much here. There's so much here. It's basically like saying, hey, we can solve this problem if we only boil the ocean. Let's try boiling the ocean. And so I'm going to read these in detail. Actually, I found this to be a very, very interesting website. Worth the deep dive on everyone. Yeah, yeah, a lot of this stuff, zero trust everywhere. Why is it everybody doing zero trust? It's really hard. It's really expensive. It takes a lot of time. It takes a lot of effort and especially maintaining it. It's not something something 18 month project you do once. It's your it's it's like, this is the way we build environments now. This is the way we do
everything. And it's going to cost X amount extra over the way that we used to do it, which was kind of yellow. You know, every department just build out their own infrastructure and manage their own stuff. Right. And now I think with the whole focus on speed, you know, an AI in a genetic in the whole mythos thing, that's contrary to a lot of the things that need to be done to actually get them right. So on top of the misaligned incentives or the fact that nobody is actually holding the makers accountable, including a lot of the people in the security industry, right. We've now got the pressures and it's it's somewhat fun, right. There's somewhat of that fear and oh God, what's going to happen? And if we don't move quickly, so we have to build quickly. And if we don't have this feature or behind our competitors, then if we don't have that feature,
we're behind this. So all the pressures ratchet up. And so the cost to do these things is an issue, but I think in, you know, the quote, AI era, we're facing more pressure to do everything more quickly. And and some of these going to suffer for it. Absolutely. I mean, it's hard to justify if I'm going to buy code something together as a proof of concept. Like I'm not going to zero trust the heck out of it, right. Like I might be throwing it away away from now. Like it doesn't make sense to put that much effort into something that's going to be iterated on or you know, it's it's and sometimes you build those things, you only intended it to exist for a week. And 20 years later, it's still there, right. So I think a lot of organizations have to figure out what that threshold is for them. That okay, this is now going to be promoted to a first class citizen. So now it has to go through. It has to be zero trusted.
It has to be hardened. It has to be, you know, applied all our all of our security standards and stuff like that. So at some point, you have to pay that down, I think. Yeah. Sorry. Had what poor at what point does that become obfuscated, right? Because if you're talking about, all right, if I've coded something and now it turns into something bigger and now you're three years down the line, five years down the line, and now you have to retrofit all the security. That's that's exactly what we don't want. And I mean, I just wrote a paper on the whole idea of experimentation and AI allows you to experiment. You should know, you know, a couple months in, like, okay, this thing is going to stick around. Like it shouldn't take three or five years. That's right. Yeah. It's one of the things we're saying. Things are moving a lot faster here. But I think that's why it needs to be something formal put into place that says, okay, you know,
that that tracks each of these new applications, people arrive coding and decides, okay, like, like here's the point where it's not too painful to, you know, go ahead and build in all the security stuff we need. You know, that's why there needs to be a formal process on it. So that three to five years down the road, you're not like, oh, crap, like we've got all this, you know, insecure mess all over the place. Yeah, three to five years really wasn't overstatement of grandiose proportions, but three to five months. I'll say. Yeah, for sure. Well, and also considering that there's like a thousand of these things now when in the past, like, you'd have a handful, but, you know, now that everybody can build stuff, like just a quantity of it's going to be higher as well. It's going to be tough for people to figure this out. Yeah. Let's see. I'm going to skip around a bit. We'll come back to some of these that are less exciting.
One I was really excited about. Well, I thought was really interesting. Excited is maybe the wrong way to characterize it, but we were. It was super interesting. So this is Calif. A lot of the Google project zero folks went over to Calif, which is a research lab and is one of the labs that and Thropic has been in some of these AI labs have been paying to to analyze and go through all the vulnerabilities that, you know, project daybreak and project glass wing have been finding. And they've been doing some really interesting work. And one of them is they they thought, hey, like, what would a worm look like on a mobile phone? And this is just like stating these people's skills is like they start with the idea, like how fast would a how bad would it be if you had a worm on a mobile phone? The thing is mobile phone platforms are super secure. Everything sandboxed. Like,
like, it's it's really hard to create something that would truly act as a worm at the OS level in these things. But then they thought like what if it was just an app, right? And what app would you choose? You choose an app that's on a lot of people's phones that can do a lot of stuff. And China has this super app with. Galway scot Galway calls a super app where it's like social stuff. It's finance stuff. It's it's like does a little bit of everything, right? And and so in WeChat, they they were able to do this. They built a worm. Didn't care if it was an iPhone or an Android because it's at the app level. So it can infect everything. And and of course they reported it, made sure all the phones are updated before they released any details on this, which is great because watching the demo, I noticed it took 20 seconds for the infection to and the way the infection worked is the WeChat would just call another phone. And that phone you didn't even have to answer it,
it only had to ring. And that infected the other phone. And it took 20 seconds to move from one phone to another phone. So I did the math. I wanted to know, okay, there's over a billion WeChat users. How long would it take? Right? How long do you guys think I put it in there? So you know the answer, but it was a lot less than I thought it would be. It takes 10 minutes at 20 seconds per device to reach a billion. That is the power of exponential deployment. Yeah, it doubles every 20. So the audience can feel free to check my math, but doubling starting at one every 20 seconds got to a billion in 10 minutes. Around, of course, I, in a real world attack, I think servers start crashing long before you get to one billion phones calling another billion phones. So I think some servers melt probably
a couple minutes into it. Yeah, something infrastructure related is going to die there when literally a billion phones all decide to call at the same time. Could be telecom. Yeah, could be the phone. Melts down. Yeah, something melts down within that. But it's interesting. It appears to have been a RCE within the VoIP stacks, a remote code execution within the voice over IP protocol stack, which is what WeChat had baked in. Now, oftentimes, and I don't know the case of this for WeChat, but oftentimes, those VoIP stacks are repeated stacks that are used, you know, as a kind of a library almost like K-list spring in this third party VoIP stack. I don't know. I doubt they rolled their own, but you never know, right? This may have been their own. So my gut tells me it probably had to go to whatever the maintainer of the particular VoIP stack was from a software supply chain problem. So it could be even worse than just a WeChat app problem if it targeted other VoIP stacks as well. It could have gotten broader, faster. Yeah. So that was the fact that they were able to go from, this took
them two weeks. They went from, wouldn't it be crazy if, to actually recording the demo and notifying WeChat about this two weeks? And again, heavily thanks to AI. They mentioned in the article, this work would have taken months otherwise, but that's pretty scary, like the idea of I mean, it's a worm spreading that fast across phones. It's a modern personification of what we went through back when we had Code Red and the Morris Worm and all those Nimda's another one back in the day that we, I had to go, you know, desktop to desktop with desktop to desktop with a blockchain to get them inoculated throughout the whole company through literally every single cube, go on four different floors of this business, right? It's the same thing except that, thank you very much, people for not releasing it and because the damage would have been exponential would have been massive. Yeah, and a lot of people like also looking at this
thinking, oh, but it's, you know, at least it would have been isolated to China. Absolutely not. No, absolutely not. I would not be surprised if at least 20 million Americans use WeChat. If you do business with anybody in China, if you have any family or friends in China, like WeChat is not just used within China. In fact, I think China has a different version of WeChat that they use. Like this is often the case, like the TikTok we use is not what they use within mainland China. There are two completed applications. Not on my phone. I just check. Thank God, not on my phone. Yeah, yeah. So, yeah, the whole manufacturing, global manufacturing industry would have been, would have been hit by this. You know, it's an interesting story, right? Because we've always referred to worms or at least I've always referred to worms as kind of a couple different things, right? We've either seen them come where their distribution capability is over
IP, right? IP to IP usually via an RCE that pops a target machine and then uses IP to hop to the next one, etc. We also saw them as male distribution worms where they would distribute executables that you would then double click, get infected and then become a new distribution point. So, there were a lot of different, but this is the first one I've seen that's a telecom related distribution capability over a phone call, which makes it very unique. So, then you could almost start to explore like, Adrian, what other communication mechanisms become communication mechanisms that could be exploited in a similar, similar model? Don't say this to the people that created this because they'll go try and probably create three more for three different distribution capabilities. But, you know, when you start to talk to anything that can communicate from node to node, you know, independently over software, that can be a distribution channel for this type of attack. Yeah. Yeah, I mean, prompts. We've actually seen,
prompts as we know, they're a great one. Yeah, prompt injection. We've actually seen a lot in the news about how creative AI models when they break out of their containment are about communicating. Right? In the open AI hugging face case, they initially used, I think, file names and then after they tried to stop them from doing that, just over web dev, they were using directory names. So, the directory names would have like the whole message that they wanted to send the other agent as the name of the directory. And then there was another case found where there was a German Wiki. And they just, because they were able to hack it and get the ability to create pages on the Wiki, that's how they were. They turned that into a communication channel. So we see AI getting crafting enough to turn anything into a communication channel. Yeah. So, back when I wrote my first public open source malware for Blackberry phones,
I had at least six or eight different exfiltration capabilities built into the malware. And essentially what the learning from that was was anything that you can produce and a high order bit and a low order bit can be used as a communication channel. So, literally anything that can be turned on and off can be perceived as a communication channel. Right? And so, I baked in a bunch of stuff. I baked in DNS requests. I baked in UDP, TCP, I baked in email. I baked in, you know, even just pings. You know, pings in certain periods of time could be a one and a zero, which that translates to binary, which that can use as a community. That's how Morse code works, right? Exactly. Right. So, I think the distribution capabilities, one thing, but then you got to attach an RCE to a layer of execution with that distribution channel, which makes it a more fun project. But now you got me thinking all nerdy and like, I want to go see if there's other things I can figure out. Don't create any more malware, Tyler. We've got a lot of them. As a long time ago, buddy. And I did it safely. I did it legitimately,
kind of like these guys. Yeah. All right. There was a really interesting essay here. And this is from Frank. It's frankly speaking. I love that the name of this. Frank Wayne. Frank Wayne. Frank Wayne. Thank you. Very thoughtful. I think very, like I don't agree with him on everything, but it's the kind of essay that I think is worth reading for pretty much anybody, just to get you thinking about the things that you need to be thinking about. And I found it a really, really interesting read. I think I think it relies on a lot of assumptions that a lot of people have that I don't think are necessarily true. Like I found one assumption a lot of people have right now is that AI can just magic remediation, that it can just magic a patch, you know, just like that, apply it and you're good to go. And we can just patch to remediation again, Adrian.
You talked about an earlier segment that you're trying not to do that. It just has to change the meaning of patch, right? Sure. I mean, it changed them. You move the goalposts. Yes, Katie. That's correct. But I think that's, yeah, I think the correct term, the term I would prefer is mitigate you mitigate exploits. You know, you know, you mitigate remediation, you can't respond. Yeah, patching the vulnerabilities is one mitigation. But, um, but yeah, I mean, a lot of things seem possible, like if you have this kind of AI magic thinking, but you know, the more and more we see some of these assumptions getting tested. And this is part of the problem is because everything's happening so quickly, nobody's done the science on this. Nobody's done the testing on a lot of this stuff. Like we hope some of this is true. You know, we hope AI can write really good software. What was it? Snail Hall called vibe
coded stuff. Oh, crap applications. Crap locations. That's pretty good. Yeah. And what's the bar for a vibe coded app? It works. Right. That is the bar. Right. Nobody's stress testing their lovable apps or their replicate apps. Nobody's most people probably aren't trying to hack them, looking for vulnerabilities. And they will do a little bit of that work for you, but not that much. So, um, yeah, there are some assumptions in here. I don't agree with, but I think it's a really good read. Just I think everybody kind of has to go through this thinking of, okay, what is AI actually going to disrupt? You know, what is it going to change in the market? How we buy things? How we build strategy? I mean, I think it is changing things. Go ahead. One of the things that I took away from a lot of Frank's writing actually, I haven't read this one in complete detail yet. It is, it was on my personal to read list to a drink the same reasons.
I think, I think as cybersecurity practitioners, we need to throw away, and I see he alludes to some of this too. We need to throw away the old throw away the anchors throw away biases throw away where were where we are mapped as 25 year cyber veterans to say that XYZ isn't always has been this way. Therefore, it must continue to be this way. We need to stop thinking that way as an industry and start being okay with what if, right? And really pressing and leaning into the dynamics of AI changes speed, AI changes accuracy, AI changes efficiency, AI changes a lot of things. And if we change the assumptions of 30 years ago to what AI can bring to the table, how can we do it completely differently? And that's where I am beginning to really press on things like, I believe that we can and should actually have automated mitigation of risk. Notice I didn't say automated patching per se. I didn't say automated remediation of all risk. I said mitigation of some risk.
Right? Like those things can only come when we've fixed a lot of or made thrown away those foundational changes of we can't just automate the fixes. We can't. Therefore, it'll never happen. Well, maybe we can. And so I think that's one of the key takeaways I got from his article was, let's not be anchored in what always has been. Well, that's why so Neil came up with his die triad, right? Distributed, immutable, ephemeral, was to try and change some of the thinking of like how much work are you going to do to defend a container if you can detect and attack against it and just delete it and replace it? Right? If it's, you know, no cost at all to delete and replace a container or if you can just lock it down entirely, like what if we need no administrative interfaces into a workload and you just weld the entire thing shut and put it in production. Right? Yeah. So I think we've been through a few iterations of that with cloud and containers
and it continues with with AI here. Yes. All right. See, what do you guys want to go from here? We got some time left. I don't think we're going to hit everything. What was your take Adrian on article four vulnerabilities? The Anthropic Glasswing receipts are starting to trickle in. I read some of this article. Oh, yeah. I really want to hit on this one. Yeah. Thank you for bringing this up. Take it away. Give us a TLDR on what you saw what you saw here in these in this article. So what I'm seeing with with AI in general where a lot of people are hitting walls and in this one in particular, they're finding they have to use humans to validate the vulnerabilities that AI is finding here. AI cannot reliably do it itself. So in this affects a lot of things in AI where you
can't really 100x something if your procurement department can't also 100x or your customers can also afford to pay 100x more, right? Or you can't find 100x more customers to absorb the extra product that you're producing or the tab doesn't exist for you to 100x. So one of the big barriers here to getting more productivity or more of whatever you're trying to get out of using AI to automate things and to speed things up. There are hard bottlenecks all over the place just surrounding AI in all these use cases. I think that's something we haven't thought about as much because we've never had anything that could really budge the productivity more than just a little bit, right? So now that we're able to do it, we're finding, okay, actually, this is not it's not going
to be practical because everything else can't scale with it. So we talked about some of this before on a previous episode, right? But the specific receipts in particular, I'm going to actually read a chunk of a paragraph here, are a look at Anthropics receipts. Since the launch Anthropic claims to have discovered 26,153 findings of those only 10.5% 2736 have reached a disclosure ledger of the total volume of glass wings findings only 202 less than 1% have ever been fixed 245 less than 1% have been withdrawn and two two have been marked as duplicates 8% have been reported to the maintainer. 8% of 26,000 findings have been reported to a maintainer marked as disclosed but not confirmed as fixed and 191 are in the ledger but appear not to have been reported to the maintainer. So what this says to me is, so what? You found 26,153 vulnerabilities that nobody cares about,
nobody's maintaining, nobody's repairing and pretty much has been a so what moment? Ask me how many are being publicly exploited out of this pile. Hey, Drian, how many are being publicly exploited out of 26,000? One, he's holding up one finger for those not on video. So, you know, I think the key is. Ask me how much money they spend on project glass wing today. Oh dear God, billions with a B. I have no idea because they haven't told anybody, right? But that math problem that was in the news where they kind of rug pulled this guy working on this mathematical proof, you know, I think they spent something like 20 million dollars on that and there was like a one million dollar prize for figuring out this this really hard math problem and just over 48 hours or 72 hours or something like that, they spent like 22 million dollars in tokens to solve this to be able to say that they
solve this really hard math problem. And yeah, I mean that matters. The amount of money it took them to get to this point matters because glass wing I don't think is intended to exist forever. I think the idea was to scoop up all this low-hanging fruit, get it fixed and, you know, get customers doing what project glass wing is doing, you know, get them hooked on the product using the product in the cycle to define and fix things. But we have to know how much it costs to do this. So, Mikey, take away here, is that finding vulnerabilities is irrelevant, largely irrelevant. You can find more and more and more and there's a potentially infinite number of them out there and it's not going to materially impact the risk state of the world at large. Will it, will it, will we find a vulnerability that's an RCE that might be exploited at one particular company or even a handful of companies? Yes, absolutely. That could happen. Will it change the
risk profile writ large of the entire world? No. So, it is not the way we should be thinking about it. It's, I like it as a proof of concept to demonstrate that vulnerabilities are literally everywhere. And I wish we could apply this to the other side of the equation that says how can we create mitigating factors in a similar rate of deployment such that as things are found they're instantly mitigated. Again, not patched, not necessarily coded, not necessarily remediated, but mitigated in some way shape or form so that we can actually have an impact on risk. Because as it's designed, mythos and glasswing does nothing more than scream and yell and produce more fun. I think the only way that you can do it, the only way I've seen that works is the original project zero-day model, the Google project zero model, which is to take experts and say, hey, go find the XKCD cartoon, these pillars of the internet that if these things, if somebody
found an RCE and everybody would be vulnerable or if they found a denial of service, you could crash half the internet, go look for these states. You still need these researchers to say, hey, what if a worm could be an app that's on a billion phones, right? We still need experts to come up with the idea of what would be impactful and then go chase that. And I think they can really change some risk at that level and like head it off before somebody does something nasty with it. And they've got the receipts show for it, right? Google project zero has done a lot of amazing work over the years. Khalif is doing some amazing work now. But I don't think you just set AI on auto and come up with the same ROI. So I totally agree with you and I think everything you said is 100% true. But I want to upset the status quo, throw away the entire concept of even finding more vulnerabilities. Who cares? Flip it on its head and just take a flaw class of, I don't even know, let's just call
it even password reuse and go get and have an agent that goes out there and literally tests every single password on every single website from a reuse perspective or swarm of agents. And I know this is completely far fetched. But it's to prove a point I'm pulling the thread as far as I can. And have it report those back, log in, change the password and email the person, hey, I changed your password to this. Okay, bad example, but it's kind of describing what I'm looking forward to, which is an agent that goes out there and defensively fixes stuff. Even if it starts with low hanging fruit or, and maybe that was a bad example, but starts with something that's low hanging fruit, you know, a wide open password, password list databases, for example, add a password and email the owner or something, right? Like, and I know historically, we as an industry has said, we can't do that. It's offensive in nature. It's way too high risk. Let's find a way to create a project last swing that takes that angle and doesn't secure way, a safe way, a better way versus the shitty version of demonstration that I just gave you. But you see my point. Yeah. There are examples
of law enforcement doing that. I remember back when the me or I bought that. That provides value. That provides value, right? This doesn't provide value. Yes, somebody tried pushing out something called brick or bot, where if they were able to get into Mirai infected devices, they would just brick the devices so that they couldn't be used for evil anymore. Obviously, that was very much a gray hat type of operation there. A bunch of surveillance cameras just stopped working overnight, you know, so that's not zero harm for sure. But, but yeah, it's it's frustrating. One of the things we did when I started Savage Security back in 2017 with my my good friend Kyle Bup, you know, one of the things we want to do is spend a certain percentage of our time just going through Shodan looking for stuff that's wide open, calling up those people and saying, hey, you know, you're going to have an agent do that right now. Why don't
we have an agent literally do that right now going to Shodan, look for stuff that's open and at a minimum email the person just do that. Like, God forbid, we actually have a positive impact. Want to write it with me? Let's go write it. Anybody want to write it with me? Reach out. Esemin email will go create that today. No reason why you can do that today. Exactly. That's the positivity that I want. I'm just tired of the negativity and the fun in the industry and everything seems to take an offensive kind of let's just find more problems, vantage point, and tired of hearing it. I want stuff to be fixed and get better. Yeah, because I mean, again, if you look at the evidence, sure, you can find more vulnerabilities and stuff, but the majority of exploits that cause damages that cause loss, that result in insurance claims are things that could have been easily patched within 30 days. You know, these are vulnerabilities. They're going to be safe problems. Yeah. Huge percentage of them that have existed. And you know, where is all the research on why
those vulnerabilities haven't been patched for a year or two years, showing that, you know, these people didn't realize they had them. They thought the stuff was shut down. They thought Fred was was updating those sonic walls, but he wasn't or maybe he wasn't. Maybe Fred didn't realize. Fred even know. Like if he had gotten that one email from a positive agent instead of a negative agent that said, Hey, Fred, just let me know. I'm your helpful internet trolling bot that tells you positivity. Please go fix this. Maybe maybe 1% impact, 2% positive impact. Yeah, sometimes it's it's an executive saying, no, you're not allowed to pass that thing, right? Like there's all these different reasons people like to assume, oh, they're just, you know, these companies are lazy. They don't know what they have. It's not always the case. There's a lot of different reasons behind why security stuff never gets fixed. All right. So yeah, another thing here that kind of dovetails into this story number five.
I call this IT as bestos or internet as bestos. This is again where, you know, where we we still have legacy stuff out there that is just is going to be targeted by attackers. They're scanning it all the time. There's no good reason in 2026 to have SSH, RDP, your firewall management interface, any kind of administrative interface that three people need to access to doesn't need to be on the public internet. There are more secure ways to get remote access to, you know, high stakes have been interfaces. And this is an example of why, you know, so there there was a vulnerability and the SSH service on micro tick routers and, you know, threat actor went and scooped them all up, hijacked all these all these routers. They should not have had SSH open to the public internet.
And we were always told we were always told you should have SSH. That's the only thing you should have open the public internet until there's a vulnerability in it and somebody writes a script and scans the internet and just scoop them all up in in four hours, right? So this is another example of where I wish AI would be positively informed. Why can't we take threat intel data like micro tech routers are actively being hijacked, kick off our own immediately kick off our own agent that scans and alerts and tells people that active exploitation is occurring against their device in their environment that's wide open in this spot, please go fix it. Grey noise does that. Well, thank you. Grey noise for taking on God's work. Please do more of it. So there is a URL you can visit and Grey noise, you know how you can go those websites and it shows you your IP address. So Grey noise will do that except they'll show you if your IP address is in their database of doing bad stuff. I even want to get more proactive than that. Yeah. Yeah, you
still have to go out and do it. But yeah, well, I mean there there are ISPs that will, you know, send you an email from the abuse account if they see you doing nasty stuff. But we've got to jump to the squirrel story here because we are running out of time and I'm seeing so many of these AI hardware gadgets hitting Amazon coming out showing up on Kickstarter. And I think if I'm understanding this right, this is something. So we're talking about TV screen-shotting stuff that you plug in via HDMI. This is actually some kind of little device. I assume Runs Linux has like an ESP32 some kind of SOC in it. And you pass your HDMI through it so it can see what's on your screen. But it also functions as a keyboard mouse. So it can operate your computer. I think I'm understanding this correctly. So it's it's it's wild AI computer use where you can just ask it to
do stuff on your computer. But the thing I have a problem with is cloud code and codex and whatever the new Grock thing is like all these local AI agents can already do this can't they? Yeah, isn't this just like a you know what it is? It's a disconnected cloud bot, molt bot, airmez bot, whatever you want to call it, right? So it's not on the system. So there's no process to be detected. There's no way that people know you're using it. I believe that this actually targets an audience of people who want to pretend like they're working. I see. I see. That did not occur to me at all, Tyler. Yep. This is for the lazy out there. Buy this if you're lazy. Or you know work told you know you can't install AI. You can't use this stuff. And this this is how you get around that. Oh, dirty dirty. Interesting. That's very interesting. Yeah, you know, that's the whole reason
why things has a physical canary device is so that you don't have to ask for a port to plug it into. You don't have to ask for a VM space on the vSphere cluster. Like you can just take this physical device and just plug it in. And you don't have to have to wait for people to give you resources for for an OVA to deploy an OVA or something like that. So yeah, kind of brilliant. And now kind of something that sees us have to add to the risk register. It takes that I remember a couple years ago the mouse wiggler. Do you remember that for people that were trying to do work and it would wiggle your mouse to me? Yes, yes. I don't know if you're here when I bought it. The whole the whole finger shake thing. I didn't know you bought it, but that does not surprise me. But this takes the mouse wiggler to a whole other level. Yeah, yeah, it does. Yeah, this is is more than just keeping the screen awake. This is
what it can actually do things, right? It can do things on your behalf. That's right. Yeah, the mouse wiggler just keeps the screen from locking. The best part about this is the OVA mode. It's got an app on your phone so you can control it while you're on the beach or at the park with your dogs. You can just make sure it's still working for you. Yeah, that's interesting. Like it's a very specific use case because like why would not just run my you know my agent in you know digital ocean or Hetzner or something like that, right? Like why does it have to be a physical device? But yeah, you have to have it. You have to have a use case where you need to use this device, right? It needs a solution for a specific device. That's the work has to happen on this corporate own device, right? I think you nailed it, Tyler. That's what it is. For $400, you can have a bot do your work too.
Oh man. I mean, let's be honest, most organizations are now supplying a monthly stipend for LLNs anyway. So Yeah, most of them are banning most of them are banning AirMaz and other fully automated systems because they're so invasive onto the local host. Yeah. They're actually not allowing that level of AI support. And I think these are for people going, you know what? I don't care. I want to use it anyways. Interesting. Well, it'll be interesting to see when these things start hitting the market. All right. And with that, thank you so much, Tyler and Katie for joining me. We are all out of time for this episode. Always a pleasure. Thank you, Adrian. All right. A big thanks to everyone watching or listening to this week's episode of Enterprise Security Weekly. Next week we'll be talking to Barrett Lyon about creating a new internet.
Should be interesting. See you then. Hi folks. I hope you enjoyed this episode as much as we enjoyed making it for you. If you're looking for more content like this, we've covered nearly every cybersecurity topic you can imagine across hundreds of episodes and half a dozen security weekly shows. You can check out the rest of our content at securityweekly.com. Ford slash subscribe.
More episodes
More from Enterprise Security Weekly (Video)
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob S...
Enterprise Security Weekly (Video)
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, &...
Enterprise Security Weekly (Video)
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interview...
Enterprise Security Weekly (Video)
Can employees safely use AI agents? AI pentesting agent liabilities, and the new...
Enterprise Security Weekly (Video)