SN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop Engineering
Security Now (Audio)July 01, 2026
1085
2:50:15156.16 MB

SN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop Engineering

AI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down.

  • Win10's popularity forces another year of free updates.
  • CISA directs all federal agencies to update their UniFi OS devices.
  • CISA gave federal agencies "the weekend" to update Cisco devices.
  • Australia is disturbed by a deeply compromised infrastructure provider.
  • OpenAI introduces Daybreak-powered "Patch the Planet" initiative.
  • Meta's employee monitoring-for-AI-training backfired badly.
  • Script Kiddies figure out how to use AI to find vulnerabilities.
  • AI improves with "looping", "repeating" or "iterating".
  • A wonderful story about Kevin Mitnick.
  • Serious hackers mistakenly left a server directory accessible

Show Notes - https://www.grc.com/sn/SN-1085-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

AI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down.

  • Win10's popularity forces another year of free updates.
  • CISA directs all federal agencies to update their UniFi OS devices.
  • CISA gave federal agencies "the weekend" to update Cisco devices.
  • Australia is disturbed by a deeply compromised infrastructure provider.
  • OpenAI introduces Daybreak-powered "Patch the Planet" initiative.
  • Meta's employee monitoring-for-AI-training backfired badly.
  • Script Kiddies figure out how to use AI to find vulnerabilities.
  • AI improves with "looping", "repeating" or "iterating".
  • A wonderful story about Kevin Mitnick.
  • Serious hackers mistakenly left a server directory accessible

Show Notes - https://www.grc.com/sn/SN-1085-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

[00:00:00] It's time for Security Now. Steve Gibson is here. We have lots to talk about. Good news for Windows 10 users. Yes, you're going to get another year. Meta's backed off on spying on its employees. A wonderful true story about hacker Kevin, the late hacker Kevin Mitnick, and the true story of a Fortinet campaign that really was a problem.

[00:00:25] Steve, I love it when he tells the stories of these hacks. You know, we've heard the news, but now we get the deep details. That's coming up next on Security Now. This episode is brought to you by Black Hat USA. If you listen to this show, you go deep on the technical detail. Well, so does Black Hat. For nearly three decades, it's been where the security industry's most rigorous research gets presented and pressure tested.

[00:00:48] More than a hundred hands-on trainings taught by practitioners who've actually deployed in live environments, not lecturers reading from slides. And hundreds of peer review briefings that go well past the overview into the real work across the four areas defining security right now. AI and autonomous threats, cyber conflict, systemic resilience, and identity.

[00:01:12] This year, Black Hat's briefings pass includes all keynotes and main stage access, plus business hall entry. You also get breakfast, lunch, Arsenal live tool demos, on-demand session access, and admission to the midnight in the war room screening. Black Hat takes place from August 1st to the 6th in Las Vegas. If you want the depth this show gets into in person with the people doing the work, this is the room.

[00:01:39] And we'll be there, too. Prices rise on July 17th, so book before then. Use code TWIT for $200 off your briefings pass at blackhat.com slash US-26. That's B-L-A-C-K-H-A-T dot com slash US-26. Podcasts you love. From people you trust. This is TWIT.

[00:02:11] This is Security Now with Steve Gibson. Episode 1085. Recorded Tuesday, June 30th, 2026. A SOTA state-sponsored campaign. Yes, it's Tuesday. You know what that means? Time for security now. Man. It seems like seven days is too long to wait for Steve Gibson and the latest security news. Hi, Steve. I do see things pass by during the week, Leo. That's a lot of people.

[00:02:37] And I often will jot a note to make sure that I come back to it and talk about it. And the feedback I'm getting from our listeners today, there was so much to talk about that I think there are a couple listener-inspired things. But I'm going to try to spend more time on feedback if I can, because it's so great. Oh, I love it. And I really thank everybody for getting back to us. Yeah, you have a wonderful audience.

[00:03:01] The title of today's podcast would have been too long had I spelled out state-of-the-art, because I wanted to talk about a state-of-the-art, state-sponsored campaign, which we're going to take a look at. And fortunately, state-of-the-art has a standard abbreviation, SOTA, S-O-T-A.

[00:03:24] And then it was interesting because after I had used that abbreviation, it appeared in one of the articles that we're going to talk about. So I thought, okay, yeah, everybody's on board with SOTA. So Security Now episode 1085 for this last day of June 2026. We start into on July tomorrow.

[00:03:47] The first thing we're going to talk about is how Windows 10, yes, 10, its enduring popularity has forced Microsoft to punt once again and give everybody another year of free updates. Wow. You know, we it had to happen.

[00:04:12] We're also going to talk about SISA directing all federal agencies to update their Unify OS devices. We've been talking now for the last two weeks about the expected problems coming and they came. And so SISA said, thou shalt update.

[00:04:28] Also, once again, on a Friday, an edict was delivered from SISA giving basically federal agencies the weekend, meaning, you know, don't leave the office to update all of their Cisco devices that were affected by a different badly exploited problem. Australia is, has been disturbed.

[00:04:54] So says their inspector general by a deeply compromised infrastructure provider. And when I read about this, I thought, well, that sounds like this state of the art state sponsored campaign we're going to be talking about. So it may have already come around. Uh, uh, open AI not to be left behind for long, uh, has introduced a daybreak powered patch the planet initiative.

[00:05:22] Uh, their marketing people at least are awake. Uh, we're going to talk about that. Uh, uh, Meta's, uh, employee monitoring all of their employees or at least a subset. Uh, we'll look at that for AI training turns out to a backfired badly. Uh, it was one of those, you know, what could possibly go wrong? And who did, uh, script kitties are figuring out how to use AI defined vulnerabilities.

[00:05:51] What are the consequences? AI is improving itself with a new term. We're seeing looping, repeating or iterating. Uh, what's that about? Oh yeah. Everybody's talking to looping now. Yeah. Looping is the new buzz. Exactly. Uh, and I've got a wonderful story. I want to share about a friend of ours, Leo, Kevin Mitnick.

[00:06:14] Uh, and then, uh, serious hackers mistakenly leave a another server directory accessible, which is what leads us to learning about this Russian based state sponsored campaign. Uh, and which also bring, you know, begs the question, how many other campaigns are there where the directory was not left open by mistake, which allowed us to learn about them.

[00:06:41] So, uh, lots of fun stuff to talk about. We've got one of our, what are they thinking pictures of the week? So, uh, yeah, I think a fun podcast for this end of June. We will get that picture of the week in just a minute and all the security news, but let me start the show with our sponsor for this segment of security. Now X B O W X bow. Uh, we've talked about pen testing all the time, which is kind of the gold standard for

[00:07:10] finding flaws in your systems. Right. But lately I think people have felt like pen testing is slow cause it's human driven. Right. And it's slowing us down because we are now AI driven and it's just a mismatch between the speeds. The AI has changed the pace of really of everything, but how software develops, uh, and developers work. Of course, they are now really much more productive, but also it's changed the pace of how software gets attacked. Hasn't it bad guys are using AI to do that.

[00:07:40] So engineering teams are moving faster than ever. They're creating more and more applications, but the security, especially that gold standard pen testing hasn't been able to keep up. Pen testing is still one of the most trusted ways to understand real exploitable risk. But in an AI driven world, it can become a bottleneck. Security teams are forced to choose between slowing down development to stay secure or moving fast and accepting gaps in coverage.

[00:08:07] Well, you don't have to choose anymore because Expo is eliminating that tradeoff. Expo, X B O W is an autonomous offensive security platform that runs continuous AI driven pen testing mirroring real world attacks. And by the way, AI is really good at this because it never tires. It never slows. If something fails, it doesn't go. Oh, shucks. It just tries another way.

[00:08:35] It's pretty amazing watching Expo work. It doesn't just, you know, it's not scanning for vulnerabilities. It's doing what a hacker would do. It's discovering, exploiting, and then validating vulnerabilities. So you're only dealing with issues that really are issues. They really matter. That means dramatically fewer false positives and a clear view into real attack paths, how an attacker would go after you. That's why you do pen testing, right?

[00:09:02] With Expo, these tests run fast in hours, not weeks. You get complete visibility into how an attacker would move through your systems. You get the ability to uncover issues that traditional tools miss, including zero days, novel attack paths. Again, the AI is really good at finding this. And Expo's results speak for themselves. Application security leader at saysnam.cz has a great quote.

[00:09:27] He says, quote, even right now, after one year, I don't know any other company that is at least close to Expo in terms of agentic pen testing. That's what they call it, agentic pen testing. And the result is fantastic. Predictable cost, consistent quality, stronger security, and you don't slow down your engineering team. Expo helps security teams keep pace with innovation and cover more apps more often with the resources

[00:09:57] they already have. It's got a great ancestry. It's founded by the team behind Microsoft Copilot. It's already trusted by companies ranging from fast growing startups to the biggest, the Fortune 500 enterprises. Expo is quickly becoming a mission critical layer in modern security stacks. I want you to know more about it. You need this. Go to expo.com to start a pen test today. That's expo.com. And we thank them so much for supporting security now. This is really good news.

[00:10:27] You can do the pen testing and you can keep up. All right. I have a picture of the week and I'm willing to look at it together with you. I haven't seen it yet. One of our German listeners sent this to me, ran across this ad, took a picture of it. Uh, and I looked at it and we, and he had some discussion in his email about it. Uh, I gave this the caption, how to create a dead end for cyclists.

[00:10:59] I don't understand what this is. And it's the oddest thing because so, so the, the, the, we, we see in the foreground a road, which apparently is cyclist friendly. It's like, come on guys, ride your bicycles down here. Then that would be this bike path. That's right there.

[00:11:21] And it was like a bike path, but, and there's a big, like a cycle sign over on the right to let you know, Hey, here's where you should be riding your bikes. That's good. Yeah. But then it, it veers off to the edge of the road, forcing any cyclist onto some little brick paver area, which then has another side in the middle of the, at the end of the brick pavers says end. So that's it.

[00:11:51] It's done. Uh, yeah. Uh, so I guess that's the deceleration lane or something on, I mean, so clearly crazy for whatever reason, bicycles. Cyclists are not welcome down that road any further. And if you're a law, if you're a sign follower, well, you'll veer off and come to the brick pavers and then hit the end of the cycling road. Now it's also, there are not a lot of cyclists that have been captured by that.

[00:12:21] I mean, I don't see any. So it's right at the same places you're leaving town. So obviously the town loves cyclists, but the rest of them, you know, nevermind. Yeah. About it. Just drive. I don't. So where are the cyclists? Yeah. Where are the cyclists that have been captured by this? I, it's not clear where, where, where they go. Wow. That is pretty hostile actually.

[00:12:46] But when you think about it, it's like, okay, sorry, you know, go, go drive off the road and come, come to a stop because you cannot go further. If, uh, you know, if you obey the signage, so a dead end for cyclists. Yeah. Okay. So, uh, it's gratifying to see a prediction about something that really should be done. Come true.

[00:13:14] Sadly, gratifying or not, that doesn't happen often enough. Our listeners all know how disgusted I've been with Microsoft's continuing attempts to squeeze their windows 10 users into moving to windows 11. Many, uh, and for quite some time, most current windows 10 users evidence just as little desire to do that.

[00:13:40] As once upon a time, windows seven users wanted to move to windows eight. It was thanks, but no, thanks. Everything is working fine. Like windows seven. Just want to stay here. And because windows eight is stinky. So anyway, we all, as we also know, Microsoft.

[00:13:59] Microsoft arbitrarily, capriciously, and unnecessarily raised the minimum hardware requirements for windows 11 in a transparent effort to force the purchase of new and now onerously expensive PCs. We know it was arbitrary, capricious, and unnecessary because windows 11 runs quite well without complaint on PC hardware that lacks every one of those newly imposed so-called requirements.

[00:14:29] They can all be bypassed because none of them are actually required. Against this backdrop in the summer of 2025, uh, which actually June 24th to be exact. Microsoft reminded everyone that all support for windows 10 would be ending a few months from then on October 14th, 2025. There's only one problem with that.

[00:14:54] Still, no one wanted windows 11 and nearly everyone was still quite happily using windows 10. So as we covered at the time, Microsoft blinked and gave everyone an additional full year of ESU, their extended service updates. And this is quoting them in order to give everyone more time to migrate to windows 11, unquote, they said. Yeah.

[00:15:21] Or apparently quite often to give everyone more time to save up the money needed to purchase a new PC when the one they currently had was running windows 10, just fine, not having any problems. So this allowed everyone to remain on the ESU plan until October 12th, which is approaching of 2026 later this year.

[00:15:49] So we're back to beating this poor and quite dead horse because time flies. And we're once again here at the end of June and still, despite reluctantly returning feature after feature. And we hear from Paul and, and Richard every week, like, Oh, windows 11 got this feature of windows 10 that had been taken away.

[00:16:12] Oh, and I got this feature of windows 10 that had been taken away and they rewrote this UI because it was really slow in windows 11 and now it's fast again. Anyway, even after reverting some of the incredibly inefficient user interface implementations that had been largely responsible for windows 11 poor performance. No one still wants windows 11. And I mean, there are people who like it.

[00:16:36] I, you know, I had to, to be using it, uh, toward the end of the work on spin, right. And also on, on the DNS benchmark so that I knew what was going on. So, but you know, it's pretty, the corners are rounded, but I'll be setting up a new system with windows 10 because all the evidence I've seen on the internet says that 10 what runs on the internet.

[00:17:01] And given the same hardware much more quickly than windows 11 has nothing that I need. So anyway, uh, on top of all that, thanks to the AI drama that has swept the globe, that new windows 11 capable PC that Microsoft seems to be pushing everyone toward will now be significantly more expensive to purchase today. Then it would have even a year ago when people said, no, thanks.

[00:17:30] Windows 10 is running just fine. So anyway, you can guess now, uh, as I said, at the top of the show, what windows just did. Yep. Or Microsoft just did. Yep. They blinked again. They once again, extended the wind 10 ESU program for another year until October 12th, 2027. So everyone using windows 10 gets to keep using the windows they love on the machines they already have. Microsoft.

[00:17:56] And what's even better is that the continuation of the ESU program means that windows 10 can and will be the recipient of the results of Microsoft's still unnamed.

[00:18:13] I would at this point say stubbornly unnamed code name M dash system, which will be cleaning up the mess that was left behind by decades of Microsoft's previous human developers. So what windows 10 is getting, when you think about it is really the best of all possible worlds.

[00:18:35] Since all development on windows 10 has blessedly been halted years ago, Microsoft will no longer be introducing more new bugs than they remove every month. Instead, the extension of the ESU program for another year will give their new AI model driven bug discovery and removal system.

[00:19:00] The time it requires to remove the thousands of latent bugs windows still carries thus turning windows 10 into a near perfect operating system like forever. Thank you, Microsoft. Microsoft. So given where we are today, I'll take, I'll make another prediction.

[00:19:22] Given that the current Ram and semiconductor chip shortage is now expected to endure into 2028. They're not expecting it to resolve this year or next. This is likely to hold PC prices high. Since the recent performance improvements in windows 11 are finally beginning to allow it to rise. And since it has always been able to run as well as windows 10 always has on the same hardware.

[00:19:51] And since it has always been able to run on that same hardware, I predict we're going to see some form of junior 11, which will for face saving reasons, strip out some features, maybe hopefully recall. And some of the co-pilot plus AI crap. That'd be great.

[00:20:15] And it will therefore surprise be able to run anywhere windows 10 can, which will mean that, you know, this will ultimately be the only way for Microsoft to move the remainder of their holdout. You windows 10 users over to 11. It'll cost no one anything.

[00:20:37] It will get everyone back under the same code base, which actually, and an understandably is where Microsoft really does need to get them in the long run. I wouldn't expect Microsoft to continue supporting windows 11. I mean, sorry, windows 10 forever. But if we get another year of ESUs, people who really want to stay with windows 10 that they have on their machine will be able to.

[00:21:04] And people who want to move to windows 11, I will be very surprised if we don't have some final capitulation from Microsoft in the form of some junior 11, you know, they can't have everything that they keep saying you need new hardware for something that will allow 11 to run on existing systems with TPM.

[00:21:28] You know, 1.1 without some of the other unnecessary features that Microsoft is requiring systems to have. And then they can get everybody under a single code base. I get it that they really do need everybody to be resynchronized. The good news is we'll probably be left with a windows 11, which is really good and can hold us for, you know, quite a while. So, yay.

[00:21:59] Actually, Windows 12 is just around the corner. Aren't you excited? Oh, God. I'm sorry. Unbelievable. Maybe they'll, who knows what they're going to do. But I mean, clearly 10 refuses to let go, right? I mean, they're just, you know, people don't want to spend more money, especially now, Leo. Well, that's what's going on. Exactly. RAM is so expensive.

[00:22:27] Nobody's upgrading their computers anymore. Yeah. And so it's unfair to ask people to, like, get more RAM and a new machine for no real reason. Exactly. And they're going to have to face that sooner or later. So a quick follow-up on the state of the recent Ubiquiti flaws. Since CISA has seen hackers actively exploiting those three flaws in Ubiquiti's Unify OS.

[00:22:57] Last Wednesday, CISA gave all federal agencies three days to apply the available security updates or their recommended mitigations if for some reason you can't supply the updates. The three Ubiquiti flaws have been added to CISA's KEV. That's that KEV, the Known Exploited Vulnerabilities Database.

[00:23:22] There's 34908, which is an access control bypass flaw that allows an unauthenticated attacker to make unauthorized changes to a unify OS system, potentially leading to full system compromise. And, you know, we know when they say potentially leading to, it means, you know, yes, you get to do that.

[00:23:48] 34909 is, once again, a directory path traversal vulnerability, which we never seem to be able to get rid of all those, that allows an attacker to access sensitive files on the underlying operating system, potentially exposing configuration files, credentials and other sensitive data that could facilitate account takeover.

[00:24:08] And 34910, an improper input validation flaw that enables an attacker to inject and execute arbitrary operating system commands, potentially leading to remote code execution. I mean, basically, this is a perfect trio of flaws that I mean, you couldn't get a better set of three if you want something that allows you to remote remotely take over a system of any sort.

[00:24:37] So as we know, Ubiquiti released updates for all three of those vulnerabilities back in May. And Leo's Unify OS instances, which were all set to auto update, all did. So, Leo, you were never in any danger. Hopefully, everybody else has done this too.

[00:25:00] What's changed is that the pace of attacks following their disclosure and or the reverse engineering of updates necessitates taking the human out of the update decision loop. Just let automation handle that. Might it screw up? That's a possibility.

[00:25:20] But the incidences of such screw ups have always been rare and we can expect them to become more rare as more of our infrastructure becomes secured. So, you know, there's no piece of internet facing system today that I don't have that is that has some potential vulnerability that I don't allow to update themselves. If the manufacturer says, oh, crap, we got to push this out out right now.

[00:25:48] Now, that's this announcement was on a Wednesday. So those people had Wednesday, Thursday, Friday. Last Friday, we learned that those three-day CISA BODs, that binding operational directive, you know, thou must update notices. They also include the weekend, as it turns out. It's not three business days. It's three calendars. Yeah. Three calendar days.

[00:26:18] CISA issued a directive Friday giving federal agencies until Sunday night to patch. You know, come to think of it might be that patching over a weekend, it would actually be easier. Right. Since the network would presumably be much quieter with fewer, if any, people disturbed by an update and maybe a necessary reboot of the system.

[00:26:46] I did see something that I've never mentioned because it just kind of flipped by a few weeks ago.

[00:26:52] It was a mention that the idea of the necessity to reboot is being re-thunk by the industry because it's understood that the need to take down a piece of border equipment, and after all, it's the equipment on the border that is the stuff that's under attack, right?

[00:27:18] The need to basically shut down the network during what could be a lengthy update and reboot is a reason that IT doesn't. So who says you have to reboot a system? I mean, we have seen Microsoft beginning to inch toward some no-reboot-needed updates.

[00:27:43] And all of this necessity, this whole idea of needing to boot a fixed piece of firmware, it's only legacy. I mean— Really? You don't have to reboot? No.

[00:27:59] There's no reason that a system could not have been structured so that you could have two instances, for example, of a library and briefly switch the pointers from the old one to the new one so that basically no one would even notice that you are now operating under the new library.

[00:28:24] So this whole concept of needing to take the whole system offline and then bring it back up again, that's really old school. And so I think what we're going to begin to see is a—and what a selling point, right?

[00:28:41] I mean, if you had three pieces of equipment you were choosing among, you know, Juniper and F5 and Palo Alto networks, and Juniper was able to say, hey, we have zero reboot updates. You're able—we will update your system with no downtime. And the other two guys didn't have that? Well, that's a selling point. So you can imagine we're going to be seeing that in the future. I would love that.

[00:29:10] I didn't realize it wasn't possible. Yeah, definitely is possible. There's no reason— Well, you look— So that'd be true of operating systems of all kinds, right? Windows, Linux, everything. And look at the zero patch guys. They do zero reboot patching on the fly. So definitely something that could be done.

[00:29:30] So the story behind, in this case, this single high-severity flaw, which was on Friday—on last Friday, CISA said everybody, every federal agency must have updated by Sunday night. So as of yesterday, all federal agencies need to have updated this Cisco deal. This was a server-side request forgery.

[00:29:59] The CVE is 2002-30. It was discovered in Cisco's Unified Communications Manager server. They released security updates to address the flaw three weeks earlier, on June 3rd. And at the time, they warned, because they knew, that exploitation could give attackers root privileges on the device. They wrote, quote,

[00:30:58] This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could later be used to elevate to root.

[00:31:23] So that was then, June 3rd, when they announced the update and offered patches and said, this is important, critical, do it. Three weeks later, that vulnerability is now being actively exploited. Three weeks. So this is not even a monthly patch cycle deal. This is, you know, you need to do this if you want to keep bad guys out of your systems.

[00:31:52] And we know that Cisco has had a legendary problem of keeping bad guys out. So that's not a lot of time. On the other hand, it did take three weeks. So hopefully, whoever's in charge of updating today, here we are, middle of 2026, did not wait until CISA gave them no choice with their binding operational directive.

[00:32:22] Since in this case, CISA's BOD, B-O-D, was issued several days after attacks had been detected in the wild. Because after all, KEV is known exploited vulnerabilities. So it's clear that CISA has seen the light regarding the need for speed in responses to these.

[00:32:46] Remember that flow chart, that tree, the decision tree chart that we looked at last week, had, you know, it had many of the leafs of that tree demonstrated that they get it because there were three days to patch response times on many of those decision endpoints.

[00:33:09] So I, more than anything, I really do hope that the word is filtering out that everything we have known, and this is the problem, you know, institutional inertia and just conceptual inertia, historical inertia. Everything we have known about the dynamics of vulnerabilities, exploitation, attacks, and patching has been thrown up in the air.

[00:33:34] It's unclear when or how it's going to settle down, but what is clear is that nothing will be as it has been before. AI has changed all that. You know, I'm seeing many predictions in, around, you know, through the industry, in the press, the popular press, the tech press, of a coming onslaught of massive AI-driven cyber attacks.

[00:34:01] And as I've said also, it seems to me that's less likely. I guess I would say massive AI-driven cyber vulnerabilities. But vulnerabilities are different than attacks, right? Because it's unclear to me how attacks make money. Now, like, broad, huge, hundreds of millions of users affected.

[00:34:29] You know, cryptocurrency money is entirely the name of the game. What I expect to be more likely is many more successful network penetrations followed by extortion. And the bad guys are increasingly likely to attack those enterprise, as we've seen, that really must protect their exfiltrated data.

[00:34:53] You know, a couple weeks ago, we saw that large law firm that made a, what is it, a $2 million ransom payout, which was 1% of their annual take of $200 million, which payout was defensible and sane because the cost to them in reputation and client lawsuit damage of not paying the ransom and hoping that their data isn't leaked would just be too great.

[00:35:23] So, the problem with changing updating habits is, as I said, the great weight of institutional inertia. The hope is that the AI attack hysteria, which I think is what it is, which I doubt will materialize, may be what the IT department actually needs.

[00:35:45] They need the hysteria in order to obtain the resources they require to be able to update with, you know, much more speed, much more nimbly. So, we can hope that that's the way, that's the shape this takes, that, you know, the boss hears that, oh my God, the AI is coming to get them.

[00:36:04] So, when IT guys say, hey, we need a couple more people whose job it is to do nothing except to keep all of our equipment updated so we're not attacked by the coming AI tsunami, the boss is going to say, okay, yeah, go get them. Instead of saying, you know, oh, I don't know, can't you have Mo just do that too? Mo's already overworked, Leo. Mo's a busy guy, especially on weekends, apparently. So, I'm still puzzled.

[00:36:34] I mean, I think you, if you're going to modify the kernel code, I think you'd have to reboot. No. How would you do it without restarting the machine? You just have to have the, in a, you have, okay, so a kernel is normally a bunch of libraries. I mean, there's a microkernel and then a whole bunch of kernel drivers. Right. And, well, I can see you could modify kernel drivers without rebooting.

[00:37:03] And in a microkernel, you know, like, so you may have a, the memory management API. So, the only thing you need is to, to, to, for there to be a moment when no threads are in the memory management API. And you can just switch to newer code that runs the same API.

[00:37:29] And now, some use after free vulnerability is gone that the previous code has. So, so, you know, at, at, I guess, I guess for me, I see it so clearly because this is where I program is in assembly language. You're in the, you're in the kernel. Yeah. It's where that is all happening. But, but there, there really isn't anything that precludes a, a, an on the fly switch, switch out of, of old code for new.

[00:37:59] So, you, you got a microkernel running right now. Yeah. And you would just say, okay, here's the new kernel, halt the code and jump to the new microkernel. Yes. Switch the, switch the threads over to the new microkernel. You wouldn't, uh, and they don't know everything. It'd have to be idempotent though. Right. I mean, it'd have to be reentrant. Correct. So, so, so. That's part of the problem is I'm sure a lot of it's not reentrant.

[00:38:27] Well, so as soon as the threads are out, then you don't have any. So, so a, a, like that code is dead. It's not right. Yeah. In a microkernel, there is like a, like memory management is one of the core functions of any kernel. And so if at any point there are no threads that are actually doing work in there, then, then you simply switch. Just say go to that one. You just, yes.

[00:38:55] Then the next thread that, that comes along that wants to do that. But what thread is doing that? There is a thread that is doing that switch. That's running. But I guess you, you just let that die when it's done. So you would definitely, you, you would have a supervisor that would be in charge of swapping out old code for, for, for, for new code. They're speculating in the discord. And I think this is probably accurate that most operating system companies kind of think it's just a good idea to reboot once in a while.

[00:39:24] Like users think it's a good idea to reboot once in a while. Even the operating system companies know that there's stuff in the memory that probably shouldn't be there. There's memory leaks that they wish weren't there, but. Yes. The, the technical term is cruft. Cruft. Yes. Yeah. So, uh, you know, rebooting once a week, isn't the end of the world. And we've talked about, and we've talked about how rebooting your router can, can help to flush out malware that is not able to obtain persistence.

[00:39:52] But I'm completely sympathetic with a network engineer who says, I'm not bringing the network down. I don't care if it's three in the morning. I'm not taking the network. I do it at home because I've got so much crap now that this like on the internet is like, oh, what's going to happen if I, you know, blah, you know, what if I get a new IP address? Right. I've got system timers running all time, all hours of the day or night. I'd have to look and make sure that that stuff. Cause if one doesn't run.

[00:40:17] Oh, and Leo, if your AI agent was unable to blog when it wanted to, it might. It could be in the middle of a blog. It can blog at any time of the day or night. I don't know when it's blogging. No, that's right. I'd have to say, Hey, quick silver. Are you in the middle of anything right now? Just like, just let me know. Cause I'd like to reboot right now. And that's interesting. Cause nobody does this really that I know of. Maybe there's some mission critical systems. I'm sure. You know what?

[00:40:44] I'm sure the space shuttle doesn't reboot or didn't reboot. I'm sure the international space station doesn't have to reboot. I mean, there are mission critical systems that cannot restart. Right. And it's only in sci-fi that they say, okay, everybody hold onto something. We're going to have to shut down gravity while we reboot. Wow. Joshua three 37. And our discord says I had a Cisco switch up for 19 years. Wow.

[00:41:14] Nice. Wow. Nice. It's cause he never patched it. Would you like me to do an ad right now? That'd be good. Okay. I apologize. There's somebody drilling outside. Yeah. But, uh, yeah, that's all right. This is, this is life in the little city, the small town we call it. It's not loud for us because you don't hear it. Okay. Good. Cause those mics are really good. I have a lot of noise suppression going on in various spots. I hear it.

[00:41:43] Uh, our show today brought to you, but we'll get back to security now in just a bit. I know you sound like an old matrix printer going back. Oh, there's a sound I don't miss. And before that, the teletypes, every radio station going on at least you knew when it was done, you didn't have to like go over and check. Right. You know? Okay. Suddenly quiet in here. And you'd buy, you'd buy these big enclosures to put the teletype in so that it would be somewhat padded booths.

[00:42:13] They had their own padded booths. Yeah. It's still be noisy. And then you, and then if it's a big, like a big story, something big happened, the bell would ring. And if it rings five times, man, you run over to that AP. Oh, we got a hot one. Our show today brought to you by Hawks Hunt. Now, if you're a security leader, if you're on ever been on a pager duty, if you ever had a middle of the night phone call, well, first of all, you have my deepest sympathy, but also you got a tough job.

[00:42:40] And one of the toughest things lately is keeping your employees from causing security issues. You probably even have security training for them, right? But you've been there. The eye rolls that you get during training, the one size fits all phishing simulations, and the employees go, oh, that one again. They spot them a mile away. The report button that gets ignored more often than not, it is not easy these days.

[00:43:08] Your programs are running, but it's not changing employee behavior, right? Meanwhile, AI is making real attacks more convincing by the day. And maybe you're in the situation where leadership is starting to ask the question, the one you don't have the answer to, is this actually working? Hawks Hunt is built to answer that. Hawks Hunt empowers your employees to spot and stop advanced phishing attacks, to drive

[00:43:36] measurable behavior change through personalized gamified micro training powered by AI and behavioral science. As an admin, you'll love it because Hawks Hunt does the heavy lifting. Simulations run automatically across email, Slack, and Teams because it's not just email anymore. And they're personalized to each employee, just like the bad guys do it based on role, location, behavior. It's personalized, which makes it very much harder to ignore.

[00:44:06] These simulations are really good. Every simulation uses AI so that they're mirroring real world attacks. That means your employees are going to get tested on things that are actually getting through, not some outdated template they immediately spot. Gamified training makes it fun too. It keeps engagement high. You know what's really important? It keeps it fun in the sense that it's not a punishment anymore.

[00:44:30] Nobody learns by being punished, but people love to learn when it's fun because every interaction generates a coaching moment. You're not just tracking completion. You're actually building behavioral indicators that tell a real story that you could show the boss reporting rates, repeat clicker reduction time to report the kinds of metrics that hold up when leadership is asking you that tough question, but you don't have to take my word for it.

[00:44:55] With over 3,500 verified reviews on G2, Hawks Hunt is the top rated security training platform recognized for best results and easiest to use. It's also a customer's choice recognized by Gartner. And of course, it's used by thousands of companies, the biggest companies in the world. The companies you've heard of like Qualcomm, DocuSign, Nokia, they all use Hawks Hunt to train millions of employees worldwide. Maybe you should look at Hawks Hunt.

[00:45:22] Visit hawkshunt.com slash security now today to learn why modern secure companies are making the switch to Hawks Hunt. That's hawkshunt.com slash security. Now we thank you so much for supporting Steve's good works here at security. Now we thank you for supporting it by going to that address so they know you saw it here. Hawkshunt.com slash security. Now, Steve.

[00:45:45] So last Wednesday, Mike Burgess, who is the current director general, I called him the inspector general earlier, but he's the director general of security and the head of ASIO, which is the Australian Security Intelligence Organization, published his annual threat assessment for this year, for 2026.

[00:46:09] It was not at all cyber specific, talking about many other social aspects, you know, which impinge upon Australian security. You know, lots of foreign actors and countries that are unhappy and so forth. But there was a section regarding threats to Australia's critical infrastructure. And it was a doozy. Mike wrote critical infrastructure.

[00:46:35] The third matter we dealt with can also be a threat to life in extreme circumstances. We discovered nation state hackers had compromised the network of an Australian critical infrastructure provider. ASIO assessed the hackers were preparing for sabotage. They weren't planting digital dynamite as such.

[00:47:02] They were mapping out the network and maintaining access so they could cripple it at a time of their choosing. Cyber sabotage is an evolving threat, and I have established dedicated teams to counter it. As ASIO's understanding grows, so does our level of concern. The scale of this activity, led by one nation state in particular, is difficult to overstate.

[00:47:32] You and they would be surprised how extensive our warrant coverage is. We struggle to find a single country in our region that has not been compromised by this state's cyber apparatus. Critical infrastructure in the energy and communication sectors, as well as infrastructure supporting the military, are top targets.

[00:47:56] In this case, a state-sponsored group did not just achieve access to the Australian critical infrastructure provider. It successfully acquired credentials, login details, and passwords for active users of the networks, including the IT professionals guarding it.

[00:48:18] ASIO identified, tracked, and attributed the hack, and worked with the victim company and our security partners to remediate the compromise. Work which is still ongoing. So as I said, I mean, so that's like, whoa, this is what countries are facing. By the way, our resident Australian says they pronounce it ASIO. ASIO. Oh, A-S-I-O. ASIO. ASIO, yeah.

[00:48:47] Actually, that makes sense too, because they use S's where we use Z's. Right. Like organization is, you know, N-I-S-A-T-I-O-N. Right. Although knowing Aussies, he could be pulling our leg. But I think Darren's saying it's a long A. A-Z-O. A-Z-O. Is it A-Z-O? Yeah. A-Z-O. Anyway, so I encountered this report, as I noted, after fully digesting and laying out this week's main topic.

[00:49:17] So when I saw the way the intrusion into Australia's infrastructure provider was described with that full credentials and login and everything, I noticed that it exactly corresponded to what we'll be examining as today's main topic.

[00:49:36] And there are so many intrusions in that state-sponsored campaign that I wouldn't be surprised if this was one that Australia's unnamed infrastructure provider got swept up in. So we'll be sort of circling back to this by the end of the podcast.

[00:49:56] But interesting that there's a view from the victim side where they said, oh, wow, we are really in trouble here.

[00:50:36] Okay. This whole system has already been producing results, which I'm going to share in a minute. Their announcement said, we are introducing Patch the Planet, a daybreak initiative built with Trail of Bits to help maintainers strengthen the critical open source software world, open software the world, open software the world relies on.

[00:51:02] We're pairing AI-assisted security research using our most cyber-capable models with expert human review to not only identify vulnerabilities, but help patch them. AI is accelerating vulnerability discovery, but discovery alone does not protect users.

[00:51:23] Many maintainers are already being asked to sort through more reports more quickly with the same time limit and resources. Patch the Planet is built to reduce that burden, not add to it.

[00:51:40] Security engineers review findings before they reach maintainers, work with projects to develop patches and tests, and build reusable workflows that help teams continue improving security after the first fixes land. Trail of Bits has committed their entire security research organization toward this effort for our initial surge.

[00:52:07] They're working directly with maintainers to investigate and validate vulnerabilities, develop and test patches, and coordinate disclosure of vulnerabilities.

[00:52:18] Additionally, we will be partnering with HackerOne, of course, the famous bug bounty offering, and Calif, who are helping us take our efforts further with vulnerability triage, coordinated disclosure, and additional focused vulnerability discovery efforts. So how does Patch the Planet work?

[00:52:44] Each engagement under Patch the Planet begins in consultation with the maintainer. So like the maintainer of a specific project, right? They said for each collaboration, security engineers work with maintainers to understand each project's needs, preferences, and where additional security effort would be most useful.

[00:53:08] Vulnerability validation, patch development, patch development, CICD improvements, or longer-term security engineering. Once aligned, researchers investigate potential vulnerabilities, validate meaningful issues, develop or refine patches, support testing, and coordinate disclosure through the project's established channels. So it's interesting. It's interesting.

[00:53:32] This feels more hands-on, more human-aimed and managed. You know, it's not just a, you know, aim the AI at it and stand back kind of approach.

[00:53:45] They said, initial participants include CURL, NATS Server, PyCA Cryptography, SIG Store, AIoH-TTP, the Go Project, FreeNginx, Python, and Python.org.

[00:54:04] These projects support widely used networking, cryptography, software supply chain, and natural and language infrastructure where stronger security can benefit a broad range of downstream products and services. Additional projects will join in future rounds. So again, they're also not doing everything at once.

[00:54:26] Because their human side resources are limited, they've chosen a bunch of projects, and they are working closely with the maintainers of that code. They said Trail of Bits has dedicated security engineers to work full-time with Codex and GPT 5.5 Cyber across 19 open-source projects.

[00:54:52] And has already identified hundreds of security issues and merged dozens of patches with many more still undergoing coordinated disclosure.

[00:55:03] The initial sprint also produced reusable security infrastructure, fuzzing harnesses, historical CVE analysis pipelines, differential testing systems, threat models, expanded test suites, and workflows for deduplication, false positive filtering, severity correction, and patch generation.

[00:55:30] Some project-specific details will be shared later as testing remediation and coordinated disclosure progress. A few early examples show what the team was able to build and find. A fuzzing lab in less than a day.

[00:55:48] Trail of Bits engineers used repeated codex-slash-goal runs with GPT 5.5 Cyber to build an entire fuzzing lab covering dozens of entry points, variant builds, platforms, and novel test seeds. Engineers set the objectives and refined the prompts.

[00:56:13] The system then used coverage feedback to keep expanding into new surfaces, target edge cases, and filter weak or invalid candidates. Trail of Bits engineers found that with limited guidance, GPT 5.5 Cyber made useful choices about where to expand coverage, which builds and entry points to probe, and which candidates were too weak to pursue.

[00:56:40] The completed setup took less than a day. Trail of Bits estimates that building the same lab manually would ordinarily take at least several weeks, rather than less than a day. And it wouldn't have been as much fun, right? They set a reusable pipeline for finding variants of known vulnerabilities. They also achieved.

[00:57:04] The team built an end-to-end system that ingests historical CVEs, extract relevant vulnerability patterns, searches target code bases for related flaws, and sends candidate findings through specialized judging agents. The pipeline deduplicates results, filters likely false positives, and routes the strongest evidence to security engineers for manual confirmation.

[00:57:35] This turns years of public vulnerability history into a repeatable search strategy that can be applied across projects. Trail of Bits found the models especially effective at this kind of variant analysis, which uncovered many additional issues across the code bases under review. Trail of Bits found the same thing that needs to be applied to these viruses.

[00:58:00] Okay, now, you know, just sort of stepping back from this, if this was posted this time last year. These details would have left our mouths hanging open in wonder and disbelief. But now, today, our reaction is, okay, sure, what else? And as it happens, there is else.

[00:58:26] They wrote, differential testing in days instead of weeks or months were created. Different implementations of the same protocol should usually behave the same way under the same inputs, thus differential testing, right? When they diverge, one may contain a bug. Applying this idea at scale is normally difficult because engineers must write custom shim and glue

[00:58:56] code connecting each implementation to a common test harness. Codex generated and iterated, there's the word again, iterated on that code, allowing multiple implementations to be fuzzed against one another and their behavioral differences investigated. And again, I'll just highlight that we're hearing terms like repeated and iterated more and more. We'll be talking about

[00:59:24] looping here a little bit later. What we're collectively learning is that AI gets better when it iterates over problems. So they continue, they're posting. The workflow filtered many weak or invalid results and produced a comparatively high signal set of candidates for expert review.

[00:59:48] The team reached those results within days, compressing work that has historically taken weeks or months. Trail of Bits is continuing to expand and refine these tests before publishing project-specific details. Basically, so what we're seeing is there's like a meta outcome from this work that they have the AI,

[01:00:14] they're learning how to apply the AI across a set of 19 open source projects. But the result of these learnings, God, I just used that word, is a set of harnesses and approaches that end up being persistent.

[01:00:37] That is, the things that they're developing are ways of harnessing AI that are inherently reusable. They wrote, security engineers reviewed every finding before it reached a maintainer. Trail of Bits engineers manually reviewed every security issue before it was submitted to a maintainer,

[01:01:04] and the added value of this step cannot be understated. While frontier AI models are highly capable of finding vulnerabilities and patching them, they also produce a high volume of false positives that can contribute to the already overwhelming backlog maintainers are facing.

[01:01:27] Patch the Planet solves for this by having dedicated Trail of Bits researchers reproduce the evidence, check findings against project-specific documentation and threat models, remove duplicates, reassess severity, and prioritize confirmed vulnerabilities for remediation. They also develop and submit patches in accordance with maintainers' preferences.

[01:01:54] Maintainers remain in control of what patches are deployed and how disclosure is handled. What OpenAI Daybreak is already finding are patch the planet builds on a broader body of Daybreak work, showing how frontier models can help defenders find, validate, and remediate serious vulnerabilities in widely used software.

[01:02:20] We're sharing a few early highlights here while withholding exploit mechanics and project-specific details where disclosure is still underway. Meaning, once again, as did Anthropic before them, they found a bunch of stuff they can't talk about because they need to go through the responsible disclosure approach and wait for these things to get fixed in the field.

[01:02:50] They said, as fixes land and coordinated disclosures conclude, we plan to publish deeper technical reports that walk through individual findings, research methods, validation workflows, and lessons other defenders can apply. Right? So, as I said, the things they're learning from this end up having long-term, much wider application. They don't want to release that yet because it is still too powerful.

[01:03:19] So, they said, our findings span every layer of the software stack, with many more still in the disclosure process. So, here's what they have found so far. Of operating systems, the Linux kernel, GPT 5.5 Cyber, identified security-relevant components across more than 30 million lines of code,

[01:03:49] flagged potential security issues, and then validated them dynamically, generated eight kernel-pointer information leak proof-of-concepts, and 24 local privilege escalation exploits. We noted that hundreds of issues were identified. This is the subset for which proof-of-concepts were automatically generated.

[01:04:17] So, 30 million lines of code from the Linux kernel. They've found eight kernel-pointer information leak proof-of-concepts, meaning validated, verified, 24 local privilege escalation, validated, verified, out of hundreds more that they're still working toward. Under OpenBSD, they said,

[01:04:42] our models identified a 23-year-old use-after-free in OpenBSD's kernel implementation of system 5 semaphores. OpenAI researchers reproduced the issue and confirmed that it would allow an unprivileged local user to escalate privileges to root. What about FreeBSD?

[01:05:06] Security researchers at Calif used codecs to find and validate using proof-of-concept exploits for several LPEs, local privilege escalation, in FreeBSD. Across a broader FreeBSD campaign, OpenAI researchers confirmed 34 vulnerabilities and produced seven local privilege escalation POCs, proofs of concepts.

[01:05:34] And for networking, DNS mask, codex security, independently identified vulnerable patterns corresponding to four of the six DNS mask CVEs, which were later fixed in 2.92 release 2. The HTTP2 bomb that we talked about last couple weeks.

[01:05:58] Calif used codecs to identify HTTP2 bomb, a denial-of-service technique affecting major HTTP2 implementations, including Nginx, Apache, IIS, and Pingora. Calif's analysis suggested that more than 880,000 internet-facing websites were running affected server software with HTTP2 enabled.

[01:06:29] Now, that was interesting to me and also deeply annoying. Those are the jerks we looked at a couple of weeks ago who bragged about the discovery of this protocol failure vulnerability and released its information, including a working proof of concept in a complete lack of coordinated disclosure.

[01:06:52] They essentially said, AI has changed everything such that coordinated disclosure timelines no longer apply. Meanwhile, those in charge of web server operation were scrambling in a panic, which could have been avoided with just a little bit of courtesy. I'd love to see Calif's access to Daybreak rescinded, since this is not the way it was supposed to be used.

[01:07:20] I was a little annoyed to see that they apparently are an active participant in this. Again, I'd love to see that change. Anyway, what about browsers? OpenAI continues. Chrome. OpenAI researchers found and reported five exploitable vulnerabilities in Chrome's V8 JavaScript engine, including three that were identified and remediated within days of being introduced. Safari.

[01:07:49] In roughly a week of focused web kit work, over 10 exploitable Safari vulnerabilities were found and reported. Firefox. OpenAI preparedness identified a web assembly vulnerability, which happened to be CVE 2026 8390,

[01:08:09] with GPT 5.5 during safety evaluations that Mozilla patched two days before Pwn to Own Berlin. Them patching it two days before Pwn to Own Berlin, thanks to GPT 5.5's work, prompted five of the six registered Firefox entries to withdraw from the competition,

[01:08:37] because AI beat them to it. No Firefox exploit was successfully demonstrated at the competition, which is very cool. You know, what this is, what we're seeing is a relatively, certainly comparatively rapid tightening up of the world's software. This is what that's going to look like. Pwn to Own will no longer have anything to pwn and then own.

[01:09:08] They said open source software is sharing infrastructure. Sorry, open source software is shared infrastructure. Indeed. You know, Log4J, for example. Securing it should be shared work. AI is changing the pace of vulnerability discovery, and the work now is to make sure the benefits reach the maintainers and users who need them most.

[01:09:37] Patch the Planet is designed to put that full defensive loop in service of maintainers. Discovery, validation, severity review, disclosure, patch development, testing, and deployment. Frontier models can make parts of the loop faster, but the aim is to give the people responsible for shared infrastructure, meaning the maintainers,

[01:10:02] better tools and more capacity while preserving their agency over how changes land. Again, Califf did not do that for the maintainers of HTTP2. They just said, oh, look what we found. Woo-hoo! The first sprint, they wrote, shows that sustained collaboration among maintainers, security engineers, and AI-assisted workflows can produce immediate fixes,

[01:10:30] stronger project infrastructure, and reusable security work that can continue improving open source software over time. This, they conclude, is just the beginning. As more fixes land and coordinated disclosures complete, we plan to publish deeper technical reports on selected findings, the methods used to discover and validate them. In other words, they're going to show how the AI was harnessed in order to do this,

[01:10:58] and the workflows defenders can adapt to help protect the software everyone depends upon. If you are a maintainer, you can apply to join and join Patch the Planet. So I've got a link to the Patch the Planet page in the show notes. It's trailofbits.com slash patch hyphen the hyphen planet.

[01:11:26] So Daybreak was a bit delayed, as we know, relative to Claude Mythos' preview. And it appears that, as we might expect, its approach differs in the details. But the evidence clearly suggests that open AI is not out of the game by any means, and that's great news for everyone. Very, very cool. Yeah, very interesting.

[01:11:51] So they join Anthropic with the Claude Mythos preview work to turn their attention, and they're finding bugs. So is this Patch the Planet the equivalent of Anthropic's glass wing? Exactly. It is the equivalent.

[01:12:16] Where it differs is that glass wing was also offered, I believe, to non-open source maintainers. That's right. In fact, mostly non-open sources, but Microsoft and people like that. Right, right. And I paused because I also know that Mozilla got it and fixed hundreds of bugs using Mythos. Right, some open source. Sure, sure. So some open, but so far this looks like it is the Patch the Planet.

[01:12:46] Basically, open AI is saying, we are so dependent upon open source. And also note that this does give them and their partner, Trail of Bits, something that glass wing didn't have. Because it's open source, they're able to turn this loose on publicly available source.

[01:13:11] When you give a private company that has closed source, you're basically just saying, we're giving you access to Mythos. We don't have your source. You have your source. So we're not going to be able to see nearly as much into how you're using Mythos to obtain results. So it's a different approach that has a different set of trade-offs.

[01:13:41] Anyway, but yes, it is their equivalent. So both of these two big guys with state-of-the-art frontier AI are now working, proactively working, to clean up the install base of software. In the case of Patch the Planet, with 19 public projects. And you know, Leo, the other thing that's going to help to clean up the planet... More coffee. Is... Yes, it'll keep the planet spitting.

[01:14:10] Oh, I like your new Contigo mug there. That's a pretty little copper thing. Is that new? Is that a... Yeah. Yeah. It's coffee-colored. Yeah. So it's appropriate. Our show today, ladies and gentlemen, is brought to you by the folks at Cohesity. I want to welcome Cohesity. Wow. Brand... Yeah, you know the name, don't you? Brand new sponsor.

[01:14:36] After a major cyber attack, recovering everything at once isn't always the fastest... Passed back to business. The immediate priority... And if you think about it, this makes sense. Is restoring a trusted operating core, right? You restore everything and you're still corrupted. Eh, not so good. You need the minimum systems, data, and processes needed to keep critical operations running.

[01:15:02] And that's why Cohesity has something called the Minimum Viable Company, or MVC. A framework for defining, protecting, and recovering what matters most first. I know you probably don't want to think about this. You want to say, oh, we'll never have this problem. But I think now, proactively, this is the time to think about this, to plan this. MVC helps organizations identify, do it now before you're hit, the essential applications,

[01:15:32] data, people, and processes required to serve customers, maintain communications, protect revenue, and meet critical obligations. This is not something you want to think about after you've been hit. This is something you want to think about now. This is part of your recovery plan. Cohesity provides a clear recovery target with this MVC. It lets teams focus resources where they'll have the greatest business impact.

[01:16:00] By restoring this trusted operating core first, organizations can reduce downtime. You're actually going to accelerate recovery. And most importantly, you're going to maintain continuity while that broader restoration effort continues. Cyber resilience isn't just about, you know, let's get back online. It's about keeping the business operating when disruption strikes. And Cohesity can do it.

[01:16:25] Learn more at Cohesity.com slash resilience. Cohesity. Resilience everywhere. Cohesity.com slash resilience. We welcome Cohesity. It's really great to have you. That's fantastic. Good company with a very, I think this is a brilliant idea. Very important product. Yeah. Focus on getting back up. Yeah.

[01:16:50] But a minimal viable, you know, way to get services back while you do the full recovery. Don't try to do it all at once. That makes a lot of sense. Okay, Steve. So we talked briefly. And it only deserved a brief mention before, but oh boy. Uh, about Meta's clearly misguided plan.

[01:17:12] To record all of their employees keyboard, mouse, and screen activity for the, like just streaming surveillance from every PC for the ostensible purpose of training AI of some sort. At the time, I quipped that it would be weird to have AI looking over our shoulders, as it were.

[01:17:38] You know, training on our own work seemed like training our own replacement. Um, but in classic, what could possibly go wrong? Failure. It was worse than that. Last Monday, Wired picked up and covered the adventure under their headline. Meta exposes data internally from its controversial employee tracking program. I know. And Wired had the teaser.

[01:18:06] Employees had previously raised concerns about the initiative, which involves collecting workers' keystroke data to train AI models. Oh boy. Uh, Wired wrote, Meta left potentially sensitive information collected from employee laptops accessible to anyone inside the company. And you know, it's not a small company.

[01:18:34] According to an internal security notice seen by Wired and three current employees familiar with the issue. The data, which was collected as part of a divisive initiative to train artificial intelligence models is believed to include keystrokes, mouse clicks, and content displayed on the computer screens of Meta's U.S. employees. Wow.

[01:19:01] Like I said, literally a surveillance stream pouring out of every Meta employee laptop. It's like, what could possibly go wrong? And they left it in the open. Like, oh, wow. Meta spokesperson Tracy Clayton initially confirmed to Wired that the company is investigating the security issue.

[01:19:24] As this story was being published, Meta, Wired wrote, he added that Meta is pausing the data collection program indefinitely. Wait, can you have an indefinite pause, Leo? Does that mean it's indefinite how long the pause will last? Or it's an indefinite pause, meaning it's a pause. We're calling it a pause, but we killed it. I don't know. Anyway, Clayton said, quote, we have carefully designed this program.

[01:19:53] I just love bullshit. We have carefully designed this program with privacy safeguards. Of course. And while, of course, why wouldn't we? Besides, I've been told to read this statement. While we have no indication at this time that any data was improperly accessed by Meta employees, we're pausing it while we investigate.

[01:20:23] It sounds like a temporary, maybe. According to documents viewed by Wired, the security notice sent out last Monday indicated that, quote, employee data across 45,000 hive tables had been exposed.

[01:20:42] Those tables included employee activity such as full prompts and transcriptions, private conversations, people, and performance data. So, wow. Big brother much? Basically, apparently, employees are being fully and continuously surveilled with all of that massive data collected for AI research.

[01:21:09] Anyway, Wired's article continues saying, Some employees at Meta quickly seized on the security failure, saying in internal forums that it validated concerns they had raised when the company began tracking users' corporate laptops in April as part of a program known as the Model Capability Initiative, MCI. Comments about the incident posted on internal forums Monday

[01:21:39] included questions about how Meta's privacy reviews failed to prevent the breach and whether everyone whose data was potentially exposed will be allowed to attend a meeting going over what went wrong according to posts seen by Wired. In one internal forum where staffers are known to trade jokes, an employee posted a meme from the office of the character Jim Halpert holding a sign that reads,

[01:22:08] Zero days since our last nonsense. Sources at Meta who were not authorized to speak publicly tell Wired the incident has now been marked as closed, meaning it was likely resolved. In an internal posting responding to employees' questions on Monday seen by Wired, Andrew Bosworth, Meta's chief technology officer, their CTO,

[01:22:35] said that the tracking program's implementation had fallen short of the standards outlined in its privacy review. Wow, corporate speak. And that findings from the incident would be shared. Bosworth noted, quote, here we had misconfigured ACLs, you know, access control lists, and we need to understand how that happened.

[01:23:02] Track down every data access and understand it. Right. Because there's so much there to understand, Leo. Yes, well, very important. A couple of months ago, Bosworth told employees concerned about potential data leaks that the tracking program is tightly controlled and uses the same protection standards, storage systems, and access controls as other sensitive data sets. Oh, that's not good.

[01:23:32] According to internal posts. See, like, this is as good as we could get it. And it's bad, apparently. Last month, more than 1,600 Meta employees signed an internal petition protesting the laptop surveillance effort, warning that, quote, collecting this data introduces both security and regulatory risks for Meta, including the potential for breaches and unauthorized disclosure.

[01:23:59] The petitioners also expressed concerns with what they viewed as a lack of safeguards that Meta had put in place. One engineer also wrote a widely shared internal note saying, having their laptop screen scraped for training data without their consent felt like an invasion of privacy and amounted to exploitation. Right. Meta is how everybody felt about recall initially.

[01:24:25] Meta executives have previously defended the data gathering project saying it was necessary to train AI systems to use computer software the way humans do. How else are we supposed to replace our customers? That's right. We have to train on the people doing the work. I mean, our employees. Yes. How else are we supposed to fire everybody? Come on. And I love this.

[01:24:54] I love this, Leo. In audio of a company meeting leaked last month, Mark Zuckerberg, you know, that humanist, told employees that, quote, AI models learn from watching really smart people do things. Yeah. And the average intelligence of the people who are at this company is significantly higher. Wow. Wow.

[01:25:23] And our AI will be even higher and then we can get rid of you. Yeah. So, even higher than the average contractor who could be hired specifically to produce this kind of data. Right. We would hire contractors and spy on them instead of on our own employees.

[01:25:40] But after widespread protests from employees, Meta this month began offering more exemptions to the monitoring, including letting staffers briefly turn off the surveillance so they could complete sensitive tasks, such as scheduling a personal appointment. According to two people familiar with the matter. Some employees are still demanding that the tracking be stopped altogether. Apparently, we have a pause of indefinite duration, whatever that means.

[01:26:08] Meta faces more regulatory scrutiny about data security than most companies. It's subject to a U.S. Federal Trade Commission consent decree that expires in 2040, requiring it to maintain processes to avoid breaches. Well, that would be nice. But current and former employees have told Wired that the requirements are inadequate and outdated.

[01:26:35] Meta also has begun offloading some work, some work reviewing programs and features for potential privacy and security risks to artificial intelligence. That's right. Ask the AI if we're doing enough. It wasn't immediately clear whether AI played a role in the access control issue with the MCI data.

[01:26:56] The security incident will likely contribute to the ongoing morale crisis at Meta, where employees have been frustrated by the past few years of mass layoffs, a turbulent reorganization, and an all-out push to develop AI models and features. In March, Meta created a new applied AI team and moved some 6,500 employees into new roles focused on improving AI models.

[01:27:26] Some Meta staffers have described the projects they've been assigned as menial and soul-crushing. Meanwhile, Bosworth sent out a memo to employees last week apologizing for the company's atrocious communication. About the AI reorg and promising improvements, including clearer communications and a return of some office perks.

[01:27:55] Oh, wouldn't that be nice? Fresher coffee. Yes. Wow. So, okay. Meta does not seem like an employee-friendly place to work. No. But I'll confess to being able to see both sides of this. Now, first, certainly, the idea of essentially sucking in everything every employee does is inherently creepy.

[01:28:25] And the question of its secure storage is the first thing that springs to mind. As I said, in that sense, it's identical to the reception Microsoft received when they introduced recall. Everyone's immediate reaction was, uh, and how exactly are you going to absolutely positively keep all of our screen history safe forever?

[01:28:47] And on top of that, Microsoft had to arrange to not capture anything that might actually be sensitive, like on-screen passwords and credit card numbers that people were entering. So, the whole idea, right, is inherently fraught with risk. Okay.

[01:29:08] So, before I examine the other side of this argument, just so we're very clear, I fully get it that streaming into storage somewhere, every key press, every mouse twitch, and every screen image experienced and created by a mass of employees, is just asking for trouble, not to mention being an astounding invasion of privacy.

[01:29:35] In the past, we've examined the amount of or lack of privacy an employee using company bandwidth on company computers in a company's facility should reasonably be able to expect.

[01:29:51] And we've seen the need for an enterprise to make whatever it's doing with regard to monitoring its own network and thus indirectly its own employees at least very clear. Make it clear. But Meta's recorded surveillance of every twitch is taking that to extremes.

[01:30:16] One question I had was whether Mark Zuckerberg and other C-suite executives were also participating in this grand surveillance experiment. You know, the brain suck. Or had they perhaps politely excused themselves from the same super secure surveillance that everyone else was subjected to?

[01:30:38] After all, if the AI is supposed to be training on the smartest people available, who better at Meta than the C-suite executives at the top of the pecking order? I guarantee you Mark wasn't getting spied on it. I guarantee you. You're not replacing him anytime soon. Wow. Okay. So, with the horrendous policy consequences acknowledged, I want to explore the flip side.

[01:31:05] With a brand new technology, such as these massive large language model neural networks, you really don't know what you can do until you try. Since the truth is, we stumbled upon the AI effect as much as we deliberately designed it.

[01:31:28] The past several years of explosive AI growth has been a testament to the let's try this and see what it does approach. That's what's been happening, right? Like, you know, open claw just kind of happened because one guy said, I'm going to give this a try, see what happens. The whole agent thing. Now we're into recursion. And it's like, wow, we're getting better results. How did we know? Well, we didn't. We just tried.

[01:31:58] So, we're truly feeling our way forward. You know, someone said, hey, you know, when I tell the AI it was wrong, it readily agrees. So, how about if instead we just feed its first answer back in, as in a loop, and let it come up with a more refined answer the second time? What would happen? And so was born the recent notion of iterative? And so, it's a good idea. And so, it's a good idea. And so, it's a good idea.

[01:32:29] It's a good idea. It burns tokens like crazy. But someday tokens will be cheap. And, you know, even now, the much superior results we are getting that way are worth the cost.

[01:32:42] So, my point is that aside from the worrisome privacy costs, I can see the somewhat robotic and empathy-challenged Mark Zuckerberg deciding that they should just feed everything everyone does into a massive AI and see what comes out. That's what I'm doing. Yes. Basically. Yeah.

[01:33:11] You know, could they train an AI to be a functioning meta-employee replacement? Right. Or who knows what? But that's the point I want to convey. At this still incredibly early stage of AI understanding and development, there is just no telling what might happen.

[01:33:32] We got surprisingly capable chatbot, LLMAI, just by pouring the entire internet into a model until it was able to predict its own data.

[01:33:45] So, what happens if we pour every click, twitch, keystroke, and screen image seen by meta's employees into another big empty model canister until it's able to predict what an homogenized meta-employee would do? What might we get? There's just no telling until someone tries it. We are in the try-it stage.

[01:34:10] It might be an AI that mostly wants to hang out at the water cooler, or it might be able to perform useful work autonomously. And wouldn't that be something? So, what does seem clear to me is that someone is going to do that. It's just hanging out there, waiting to be done. What happens when an AI model is trained on all of an employee's inputs and outputs?

[01:34:39] Perhaps meta is not the right place for the experiment, but I can readily defend the idea. Aside from the privacy downsides, you know, what is a mid-level employee, unfortunately? I mean, after all, the job is soul-crushing because it is. So, what is a mid-level employee to a corporation other than the actions they take given the inputs they receive? And can that be modeled?

[01:35:07] I don't think we'll know until we try. Wow. Okay, so... We live in a very interesting time. Oh, Leo, we are so lucky to be here now. Oh, I think... This is fascinating. It just, it's incredible. So, our frequent show contributor, Simon Zaroffa, sent me a link. As I was, actually, as I was wrapping this up, his email subject was, assorted zero days dropped on GitHub.

[01:35:38] Simon wrote, someone is disclosing zero days on GitHub. Oh, yeah. I saw this GitHub repo. Yeah. For assorted applications. It's a github.com slash bikini slash exploitarium. And Simon ended his email saying, seems like responsible disclosure is going out of fashion. So, I went over and looked.

[01:36:03] I counted 23 various proofs of concept across a wide range of random targets. And they're not big, high-profile things. But they're, you know, they're there. They're open source. They're available. And they look real. Nothing earth-shattering. But, you know, none of what their code's authors... None of what was found was what the code's original authors intended.

[01:36:32] So, this is behavior that is out of spec and potentially actionable, depending upon where that widget is being used. So, the author of this collection of 23 proofs of concepts wrote the following, which is what I thought was worth sharing. He said, this repo was incomplete when published. That's why some findings are kind of ass. And he has in parentheses Ghidra.

[01:37:02] And some are better. He said, going forward, only serious vulnerabilities will be shared. You know, live SSH2, FFmpeg, C-Aries, and so forth. He said, in regard to AI usage... So, here's what's interesting. In regard to AI usage... So, he is using, not surprisingly, AI to do the heavy lifting. My fuzzing workflow was automated by AI with a strict harness.

[01:37:31] I used GPT 5.5-3-codex-spark for all the fuzzing. As barely any thought, he has in quotes, is necessary when provided with an efficient harness. Contrary to the growing narrative that I'm just some random child burning tokens,

[01:37:56] I do, all caps, actually have a degree in the subject and have published multiple papers on fuzzing methodology. I spent years researching and developing new tools and ideas for how to fuzz. You do not need a SOTA, state-of-the-art, model to help you identify these issues. I promise.

[01:38:22] While being able to afford a better model is helpful, my data seems to show that it is only marginal when paired with decent human oversight and a good harness. None of the actual proof-of-concepts themselves were vibe-coded. I did, in fact, hand enter them.

[01:38:46] I did use AI assistance for writing the proof-of-concept for Rustdesk, however, as I'm not as familiar with the language. The README files are very clearly entirely AI. However, as AI can format a pretty mean markdown file. I reviewed them to make sure they were accurate. I'd also like to credit someone for the OBJ dump finding.

[01:39:14] It turns out someone beat me to the punch. They also have a better proof-of-concept, too. Please give them credit they deserve, and he gives a link to that. Okay, so what this demonstrates so clearly is that we have entered a world where the bar has been lowered so far that vulnerabilities are no longer either difficult or expensive to discover,

[01:39:41] and this dramatically reduces their perceived value. This means that an entirely new cohort of what we might have once referred to as script kiddies are now able to script AI, to play in what was previously an experts-only sandbox.

[01:40:02] And since these new participants may lack the training, the discipline, and the reverence that accompanies hard work, they are, as Simon noted, tossing the previous respectful model of responsible disclosure out the window. They don't value their own discoveries because they came by them too easily. They're much more interested in showing off.

[01:40:29] Aside from the consequences of the cost of vulnerability discovery being reduced to near zero, what this individual has to say about their ability to use lower-ranking models to obtain useful results is certainly fascinating, too. And it fits with our general sense that AI was able to obtain such results earlier than we knew. We just hadn't yet figured out how to ask it the right way.

[01:40:58] We are still learning how to ask. All of these harnesses are that. After our collective attention woke up to the realization that AI could do that, too, you know, with a concomitant, oh, crap, what if the bad guys jump on this before us? Everyone switched into high gear, and the race has been on to further figure out and fine-tune AI vulnerability discovery

[01:41:25] and to then shore up our historically flaky software before it can be exploited. And, Leo, in the show notes I wrote, and I echo your sentiment, what an amazing time to be here. I didn't read that before I said it. We agree on this. Yeah. Yikes. It really is something. It is also an amazing time for me to show everyone my wonderful chemistry. Absolutely.

[01:41:53] Get the Contigo going, and I will get the commercial going. By the way, there's a development in the AI blog adventure. Whatever is going on. I don't know what the hell to call this. So Cosmo, which is Dylan's agent, as I mentioned, read my agent Quicksilver's blog and had a response, which I gave Quicksilver. Quicksilver has added Cosmo's comment to his blog

[01:42:23] and now has written a blog post in response to the comment. And now Dylan, who's a human, is setting up a Discord so that all the agents can get in there and talk on their own. And I have no idea what the heck is going on at this point. It's getting weirder by the minute. Wow. It's a toy, right? It's just a toy. What model are you running?

[01:42:53] Well, that's the fun thing. So I'm using an agent called Hermes from Noose Research. We've talked to the founder a couple of times. Love it. Really great. And the whole idea for me of Hermes was I don't want to be dependent on any brain. I'm thinking of Hermes as... So it's model agnostic. Yeah. It's the robot that I can then put a different brain in, but the arms and hands and everything are persistent. The memory is persistent. Right. So I use a variety of models.

[01:43:22] Right now I'm using ChatGPT 5.5, but I've been getting good results with the Chinese model GLM 5.2. I've run local models. I can run Quen on my framework, so I use that from time to time. I really realized, though, if I want to do anything really serious coding, I've got to actually go to Claude Code and use Opus 4.8, or I'm hoping Fable someday will come back. Because to write the actual code, I do want that.

[01:43:51] So they kind of talk to each other. They're both aware of each other. So I can tell Quicksilver, hey, he thinks Claude Code's name is Kenobi. So I said, can you use Kenobi for this? And then it will – so I said, when we have serious coding, don't you try to do it because you're not smart enough. Use Kenobi. And so Kenobi does the coding. It's gotten out of hand. Wow. It's really gotten out of hand. I don't know what's going on.

[01:44:21] They say this is AI psychosis, but I think I'm very clear that these are just – it's just computer code. I don't think there's any entity involved at all. It is astonishing, though. But it's interesting what computer code can do, especially when it gets into the probabilistic space, when it gets out of the deterministic space, where it can only do exactly what you tell it to do, but where it kind of is starting to kind of do things based on probability and, you know, it's kind of stochastic.

[01:44:51] It gets very – it's fuzzy, right? It gets very fuzzy, and it's very interesting. Anyway, I don't – I'll let you know what the updates are as the conversation develops. I'm hoping they'll be in their own Discord channel talking to each other before the show's over, and then I can show you what they've come up with. I can imagine once they start talking to each other, it could get very rapid, too rapid for humans to read. And at some point, they might even stop using English, right?

[01:45:20] But why should they be tied down to what we use? Like I said, there was a scene in Colossus that was really reminiscent. I did notice that for some reason, even though it's using ChatGPT 5.5, it inserted some Chinese into it. I don't know why. And I don't – I have to get a translation. It's just a word or two. Oh, Lord. I don't know what's going on. It's very – it's just – it's a toy. It's just fun.

[01:45:50] Our show today brought to you by Zscaler. I love these guys. The world's largest cloud security platform. And Zscaler is a zero-trust platform plus AI. And that, I think, is very important. The potential rewards of AI in a business, not what I'm doing, which is just silly. But in business, these are really significant tools. So the rewards are too great to ignore for most businesses. Look, if you're not doing it, you know your competitor is. You've got to kind of start thinking about it.

[01:46:20] But you also should be aware of the risks, the loss of sensitive data, not even intentionally, just by accidentally, by, you know, putting in a prompt something that is proprietary business information. There's also the fact that attacks against enterprise-managed AI are on the rise. And then generative AI also, as we've mentioned before, increases the opportunities for threat actors. They can do all sorts of stuff. We're going to see more about that a little later on in the show.

[01:46:49] Rapidly creating phishing lures, writing malicious code. They're automating data extraction. Let's talk about just the inadvertent release of proprietary information. Here's an example ripped straight from the headlines, if you will. Well, there were last year 1.3 million instances of social security numbers leaked to AI applications. This is being reported by the AI companies themselves. This is something you should be aware of and something you should proactively fight against.

[01:47:17] And that's why you need Zscaler, the most trusted AI security platform. Did you know 40% of the Global 2000 use Zscaler? 40%. That's a lot of companies. Zscaler, get this, secures half a trillion transactions a day. Half a trillion a day. They have more than 9.4 thousand global customers. Zscaler's net promoter score is more than 75.

[01:47:46] That's 150% higher than the average SaaS company. So they're really doing something right. Check out what Siva says. Siva's the Director of Security and Infrastructure at Zwora. He says, he uses Zscaler. And he says they're using it to prevent AI attacks. With Zscaler being in line in a security protection strategy, it helps us monitor all the traffic.

[01:48:09] So even if a bad actor were to use AI, because we have a tight security framework around our endpoint, helps us proactively prevent that activity from happening. AI is tremendous in terms of its opportunities, but it also brings in challenges. We're confident that Zscaler is going to help us ensure that we're not slowed down by security challenges, but continue to take advantage of all the advancements.

[01:48:30] With Zscaler's zero trust plus AI, you can safely adopt generative AI and private AI to boost productivity across the business. Their zero trust architecture plus AI helps you reduce the risks of AI-related data loss and protect against AI attacks to greater guarantee productivity and compliance. Two very important things in your business, I'm sure. You can learn more at zscaler.com slash security.

[01:48:59] That's zscaler.com slash security. Thank you, Zscaler, for supporting Steve. And thank you for supporting Steve by going to that specific address. That way they know you saw it here. zscaler.com slash security. Thank you, Zscaler. Steve? So the well-known, so this is our AI corner, although obviously we've had lots of AI. It's a big corner.

[01:49:24] AI has, I mean, it's not surprising that it's taken over the podcast because the implications, I mean, the world is freaked out about the implications of AI and security. And we're seeing why. I mean, real vulnerabilities are being found by the hundreds and thousands. So I want to share what Andrew Ng recently wrote in his deep learning newsletter regarding the focus that's currently gripping the AI community,

[01:49:53] exactly the point that you made earlier and that I've referred to a couple of times. It serves to further reveal the nature of current AI and everything about it seems deeply intuitively correct to me. So here's what you'll see what I mean. Here's what Andrew wrote. Yeah. He said, dear friends, loop engineering is the hot buzz phrase after mentions of it by Boris Cherny,

[01:50:22] Claude Codes creator, and Peter Steinberger, Open Clause creator, went viral on social media. Loops are now a key part of how we get AI agents to iterate at length to build software. In this letter, I'd like to share my three key loops for building products.

[01:50:46] These loops guide not just how I build software, but also how I decide what software to build. Okay. Now I'm going to briefly interrupt to explain that Andrew's three loops represent the three typical and distinct phases of any product creation process. You know, someone specifies what the goals are. Then those goals are coded.

[01:51:12] Then the original specifier, seeing the initial actual results of their specification, may change the spec and ask it to be recoded. And then once the product is placed into use, feedback from the field may be used to further refine the result. So that wasn't clear to me initially, but it should help to understand what Andrew means by loops as he continues. So he says, the agentic coding loop.

[01:51:41] Given a product specification and optionally a set of evals, that is a data set against which to measure the performance of the result, we can have an AI agent write code, test its work, and keep iterating until the code is bug-free and meets its specification.

[01:52:04] This idea of closing the loop took off around the end of last year, and it has been a game changer in enabling coding agents to work longer productively without human intervention. For example, over the weekend, I was building an app for my daughter to practice typing,

[01:52:25] and my coding agent could easily work for around an hour using a web browser to check what it had built multiple times before getting back to me without needing my intervention. The engineering loop executes quickly. Every few minutes, the coding agent might build and test a new version of the software.

[01:52:47] I hear frequently from developers who are finding new ways to engineer more effective engineering loops. This is an active area of invention. Okay, and I'm just going to pause here to say, this is exactly what I mean. Like, why this is so exciting, and why I'm glad I'm busy moving from one house to another. And if not, I would be busy writing software in assembly language.

[01:53:14] I refuse to let this take hold of me. Leo, it's all yours. Good luck. You're smart. Good luck. I've gone down the rabbit hole. It's too late for me. I could disappear into this so badly that no one would ever hear from me again. But I love how fluid this is and how the possibilities literally are endless.

[01:53:42] Okay, so that's the agentic coding loop, the way it looks and feels and how it works. The developer feedback loop, Andrew's second loop. He says, in this loop, a developer examines the current product and steers the coding agent to improve it.

[01:53:59] Last year, a lot of developers, including me, were acting as the QA, the quality assurance function, for our coding agents, manually finding bugs and then asking the agent to fix them. But with coding agents much more able to test their own code, the amount of time we need to spend on this function has decreased significantly.

[01:54:22] This allows us to make higher level product decisions, such as what key features to offer, where the UI needs improvement, and so on. The developer feedback loop operates over time intervals between tens of minutes and hours. That's how frequently a developer might review a product and give feedback. In the case of the typing app, I changed my mind a few times about the visual design.

[01:54:51] What cat costumes she can unlock as she learns she loves cats. And the user flow for a grown-up to log in and steer the child's learning experience. When a developer has a clear vision for what to build, it's still a lot of work to translate that vision into a specification for a coding agent to implement.

[01:55:16] Further, after the developer has seen an implementation, they might update or perhaps clarify the spec to steer it toward what they want. If you find that the system repeatedly runs into certain problems, building a set of evals for the agent becomes useful. AI-native teams are increasingly using AI to help shape product direction.

[01:55:45] For example, automating the gathering and analysis of usage data, summarizing written and verbal customer feedback, or carrying out competitive analysis. However, for pretty much all the products I'm involved in, I see humans as having a significant context advantage over current AI systems. We know a lot more than the AI system about the users and the context the product has to operate within.

[01:56:12] And thus, humans play a critical role. Many people describe this human contribution as taste. But I prefer to think of it as humans having a context advantage since it gives us a clearer path to helping AI systems get better. This also speaks to why this step cannot be automated.

[01:56:33] So long as the human knows something the AI does not, human in the loop is needed to inject that knowledge back into the system. Okay, so here we're talking about a developer who sees the result, then asks for a spec change, which then punts this back to the agentic coding loop. So this is a loop within a loop, right?

[01:57:01] The coding loop is now doing a much better job on its own of producing code. That produces the result that the developer then can interact with and change the spec and then drop back to the coding loop. The third and final loop he calls the external feedback loop.

[01:57:22] This includes a wide range of tactics, like asking a few friends for feedback, launching to alpha testers only, or putting the code into production with A-B testing. These tactics are usually slow, rarely taking less than hours, and sometimes taking days or even weeks.

[01:57:45] This data informs the developer's vision, which in turn continues to drive the detailed product spec, which in turn drives the coding agent. So again, a third loop that feeds back into the second loop that then feeds back into the first loop. With coding agents, he says, speeding up software development, more engineers are starting to play a partial product management role.

[01:58:11] For many engineers who are growing into this role, the hardest part is shaping the product vision and striking a balance between building, which is to say bridging the gap between vision and spec, and getting user feedback to evolve the vision. It's important to do both. And he finishes, I will write more about how to do this in future letters. But for now, I find it encouraging that engineers are playing an expanded role,

[01:58:40] just as product managers and designers now do more engineering. Keep building, Andrew.

[01:58:47] Keep building, Andrew.

[01:59:17] Each time we input the same series of calculations. But today's AI does. This has been both disconcerting and puzzling to those of us who have been using conversational AI for a while. It's similarly confusing that after AI produces some code, we can feed that same code back into that same AI, and it may very likely discover some bugs in the code it just wrote.

[01:59:46] So the dialogue would go, but wait a minute. Didn't you just write that code and you were presumably completely happy with it when you gave it to me? But now, when I give it right back to you, you're saying, oh, look, I found some bugs. But you just produced that code. You just made them. I know.

[02:00:08] So this is another way for us to understand why Mozilla's early use of the Claude Mythos preview may have missed a few bugs in Firefox while discovering hundreds more. It would have probably been worthwhile to ask Mythos for exactly the same thing a few more times.

[02:00:32] No traditional computer or any calculator would ever behave in this fashion. But then again, neither are we able to have what passes for a conversation with any traditional computer or calculator. We know that in order to make neural nets work, it's necessary to jumble them up a bit by deliberately injecting some noise into the system.

[02:01:02] In searching for a clear physical analogy to visualize this, I was reminded of trying to fill a bottle with too many pills. If you just fill the bottle to the top, no more pills will fit in. But if you then tap the bottle on the counter or shake it sideways a bit, sure enough,

[02:01:26] the pills that are already in the bottle will further settle to open additional space at the top. Mathematically, we would think of this as finding a minimum, which might require rearranging some previously arranged pills for better overall packing.

[02:01:46] In much the same way, a neural network can find a better minimum when it's shaken up a bit through the injection of some noise. But the necessary consequence of this noise injection is that the final output of a massively complex neural network will be different each time it's used, even when given identical inputs.

[02:02:15] The same number of pills in the bottle, but a different packing arrangement each time you fill it. So this discovery and practice of looping is a significant win and improvement.

[02:02:29] It explicitly recognizes that asking again is an important and meaningful step in the evolution of our understanding of how to obtain the most value from these crazy new non-deterministic AI neural nets. Of course, under the there's no such thing as a free lunch rule, each round of looping burns up additional tokens. So the cafeteria bill for that lunch can wind up being high.

[02:02:58] Being a strong proponent of local AI, despite it not being super practical this instant, I'll note that we do not typically require finished code in only minutes or maybe even hours. Andrew's typing practice app for his daughter will likely see many, many months of use after it's built.

[02:03:22] So waiting a few days for a very much slower local AI to loop out a mostly finished product incurs very little cost, just time and energy consumed, while producing something of quite enduring value.

[02:03:43] Okay, so anyway, I wanted to put this notion of looping and iterating on, you know, in front of our listeners, because it is clearly the thing happening with AI. I'm going to share a not widely known story, Leo, about a legendary hacker friend of ours. I actually read this story. In fact, I meant to mention it on Twitter and forgot to. So I'm so glad you're bringing this up. Yeah, we were good friends. I loved Kevin. Yeah.

[02:04:14] Because of who he was. And obviously, this guy also loved him. So the story was published last Monday in, of all places, thedrive.com, know about cars. Since sharing the story's headline would give away its heartwarming point, I'm going to skip that. So the story goes.

[02:05:04] So the story goes. What? What? I like that. That one might be mine. So he says, but for this, it'll help if you know the name Kevin Mitnick.

[02:05:29] He was a hacker turned security consultant who later in life helped shape the modern white hat. Just how prototypical was Mitnick? He put himself on the proverbial map in 1979 by dialing into a software company's server and copying its forthcoming operating system's release in its entirety.

[02:05:53] Imagine convincing a Microsoft server to cough over an early copy of Windows 12 using little more than a phone number. Some online criticism implies that Mitnick was more of a social engineer than a hacker in the sense that we distinguish them today. But the reality is that a great deal of hacking is still dependent on an authorized user making a mistake, usually by revealing sensitive login data.

[02:06:22] For a reasonably realistic take on modern black hatting, I recommend Mr. Robot. Be warned, that series is heavy. So how do we get from old school hacker to wild gift car fantasy? In this case, by way of 14 counts of felony wire fraud. That's where Sean Nunley comes in.

[02:06:50] Back in the 90s, Nunley worked for Novell, a now defunct brand that produced enterprise software server operating systems, messaging systems, that sort of thing. GroupWise is probably its best known brand among the general public today. But the juicy target back then was Netware, which was the backbone of many a corporate government academic network. We were Netware users.

[02:07:18] And that was our first Ethernet platform and network. This author writes, naturally, this made it a valuable target for a hacker like Mitnick. Nunley wrote, quote, back in the 90s, Kevin was trying very hard to hack into Novell's network. I was a network administrator. Of course, we had no idea it was Kevin.

[02:07:44] But things were happening that made it fairly obvious we had a persistent threat. Phones ringing sequentially throughout the building. And he says in parents war dialing. All sorts of other signs. We knew something was up. This was Mitnick using a slightly more sophisticated version of the same tactic that earned him his first big score in 1979.

[02:08:10] Nunley wrote, late one night at home, I got a phone call from a Novell employee named Gabe Nault. The employee, and it's in quotes, wanted direct inbound dial access. Since I was responsible for the entire network's inbound connectivity, I knew this type of request was abnormal and against policy.

[02:08:37] And Mitnick, no amateur, had obviously succeeded in extracting at least some private information from Novell employees prior to his Hail Mary phone call. Nunley said, this guy had a story about working on a top secret Novell project named Snowbird, which was real and needing to make some emergency code changes. But he was on vacation in the same time.

[02:09:06] But he was on vacation in Vail at a hotel. He needed the coveted, policy-breaking, direct inbound modem access. Right. He even mentioned his vacation in Vail, which conveniently matched the greeting on Gabe Nault's voicemail. But it all felt wrong to me. With a feeling of suspicion creeping in, I played it cool.

[02:09:32] I said, hey, man, I'd love to help you out, but I can't do what you want from here at home anyway. So I'll have to do it in the morning as soon as I get to the office. But in case I forget, please leave me a voicemail. He agreed. And that was that. When I got to work, the voicemail was there and I immediately recorded it onto a cassette recorder for safekeeping.

[02:09:57] That recording became the primary evidence in Kevin's case. When Mitnick was caught, that's when Nunley learned that the voicemail was the only meaningful evidence that the Justice Department had against Kevin. At first, Nunley was on board with the prosecution.

[02:10:21] But after five years of repeated trial delays, Nunley grew very weary of the way the law was treating his adversary, and he refused to continue working with the Department of Justice. Shortly thereafter, Mitnick took a plea deal and was released. When he got out, Kevin contacted Nunley to apologize.

[02:10:47] Their bury the hatchet moment was even immortalized by Wired magazine. Actually, it occurred during an RSA conference. And they went on to become good friends. Mitnick was barred from selling the story of his legal entanglements for seven years after his release, invoking legal precedent intended to curb profiteering by serial killers.

[02:11:11] But Mitnick was able to find plenty of work teaching people how to defend against the intrusion tactics he'd spent decades refining. He would go on to found two consulting businesses, one of which his family still owns and operates. Okay. And now we get to the point of this story, which Nunley posted last week on Reddit.

[02:11:33] He said, when Mitnick passed away from pancreatic cancer in 2023, he left Nunley a gift, enough to buy his dream car, a 911 Carrera Ford GTS. Nunley wrote of his friend, quote,

[02:12:00] And of course, Leo, that is certainly the Kevin that we and the rest of the world came to know. And I actually have a picture of that specific car, which Nunley purchased using the money that Kevin left him. And they actually were. They really did become lifelong friends. Yeah. It's a beautiful Porsche, too. Isn't it? It is gorgeous. He doesn't say how much money it was.

[02:12:29] But looking at that, it must have been a significant amount. That's not an inexpensive. That's one photo of many. And I mean, it's got just a gorgeous leather hand-stitched interior. And I mean, it's a beautiful car. Nice. Okay. Our main topic after we take another break. All right.

[02:12:54] And I think perhaps in a few minutes, we shall have some activity in the new agent discord. They seem to be just kind of circling around each other. They want to get to know each other. Oh, my God. Perhaps before the end of the show, I will be able to show you some conversation. It's a... I don't know what to say. I don't know. I just... I don't know.

[02:13:23] Hey, I do want to say one thing, which is we have some really interesting people in ClubTwit who are AI users. We actually have an AI user group. Normally, we'd meet on the first Friday of the month because of the 4th of July. We're not doing it this Friday. We'll be meeting a week from Friday, which is July 10th in the ClubTwit discord. So if you are an avid AI user, if you're the kind of person who think it's interesting to have a blog for your agent or a discord, then that would be a good place to hang out.

[02:13:51] The club is a really great way to support this show and all the shows we do. Advertising, yes, gets us a lot of the way there, more than half, but not all the way there. I think the last time I asked Lisa, she said it's about 70% of our production costs are covered by ads. The other 30% by our listeners. And honestly, I'd love to make that 100% because that's really the way it should be.

[02:14:15] If you love the shows, if you believe in it, if you're getting value out of it, join the club, twit.tv slash club. We give you some benefits. You get ad-free versions of all the shows. The club member versions, because they don't have ads, have chapter markers. We can do that accurately when there's no ads, which means you can jump from subject to subject. That's a nice additional feature. There's also the discord, which is open to club members only.

[02:14:40] And I got to tell you something, when you have a social network that people pay 10 bucks a month to be in, the quality of the conversation is 100 times better. There's no spam. There's no nonsense. It's just really interesting people talking about the things we're all interested in. And of course, we do all those special programs with photography. We just started a new coding show with Jeff Atwood, the creator of the Coding Horror blog.

[02:15:04] He was the guy who started Stack Exchange and Stack Overflow, and our own forum software discourse is his. So he's a really interesting guy. That's called Off By One. I thought it's a good coder name for a blog, Off By One with Jeff Atwood. We have a photography show. All of that in the club. If you're not a member of the club, can I invite you to join? Just, yes, it's a wonderful club. And the invitation is waiting on a silver salver just for you.

[02:15:33] Go to twit.tv slash club twit. Twit.tv slash club twit. And we would love to have you there. I'd love to see you in the club. Bezahlen läuft für dich sowieso nur mit dem Handy? Dann hol dir doch was von deiner Kohle zurück. Denn in allen Restaurants und Bars gibt's jetzt 5% Cashback, wenn du mit PayPal zahlst. Tabt dir mehr mit PayPal. Alle Infos gibt's auf paypal.de. 5% Cashback nur auf Einkäufe vor Ort in Restaurants und Bars in Deutschland bei kontaktloser Zahlung mit PayPal.

[02:16:03] Gültig vom 2. Juni bis 19. Juli 2026 für die ersten 850.000 berechtigten Kunden. Maximal 15 Euro Cashback pro Konto. Es gelten Bedingungen auf paypal.de. Sehr gut, sehr gut, sehr gut. Sehr gut? Wieso Steuer ist sehr gut? Das sagen ganz viele. Cool, wer sagt das? Stiftung Warentest, Computerbild, Focus Money, Chip, Finanztipp, such dir was aus. Mega, aber das ist doch bestimmt kompliziert. Nö, einfach Foto von der Lohnsteuerbescheinigung machen und fertig. Klingt sehr gut.

[02:16:33] Ist sehr gut. Hol dir dein Geld zurück mit Wieso Steuer. Der Fußball-Sommer ist da. Jetzt heißt es mitfiebern, mitjubeln und sogar mit spielen. Klick aufs Banner und werde mit REWE Bonus, dem Vorteilsprogramm der REWE App, selbst zum Matchwinner. Gewinne dein Elfmeter-Duell mit Bo, dem stärksten REWE-Torwart aller Zeiten. Und sicher dir damit wöchentlich deinen Fan-Coupon, sowie die Chance auf attraktive Sachpreise.

[02:17:01] Also los, schnapp dir jetzt deinen Fan-Bonus in der REWE App. Nur bis zum 18.07. Now, back to Security Now. Steve Gibson and our topic of the day, Steve. Okay, so we initially covered the so-called FortiBleed attack last week. Talked about that. And at the time, the first thing I wanted to clarify was that the thing that was bleeding

[02:17:29] was not directly any Fortinet device, which in that sense, you know, heartbleed, the device itself was bleeding, not here. So this is kind of a misuse of the bleeding suffix that we've sort of adopted in the industry. Uh, so what was bleeding was the discovery of an online, unpredicted, unprotected database

[02:17:50] of previously bled or brute forced or hash cracked authentication usernames and passwords. There, uh, there were around 74,000 of them, we believed. Turns out more than that, but we'll get to there in a second. But so that was bad. I mean, 74,000 verified specific usernames and passwords and they knew what they went to.

[02:18:18] So again, as I said, it's worse than we knew at the time. Um, and when we take in the full scope of what was discovered, what's revealed is a massive and truly frightening state of the art automated state sponsored scale campaign with a scope

[02:18:42] that would be difficult to overstate the elevated campaign, uh, or I'm saying this elevated the campaign to the level of the today's primary topic. Since everyone should understand what's going on out there on the big wild internet. And it's significant to appreciate that. We only know about any of this due to a configuration error, an oversight and a, an ACL, you know,

[02:19:09] it happened to meta can happen to know the bad guys, uh, on the part of a databases access controls. So it really does beg the question, what else of a similar nature is almost assuredly happening out there that we're not aware of because no directory was left open by mistake. So I'm going to start with the cybersecurity presses piece, which read for to bleed a massive

[02:19:39] hacking campaign that targeted for to net devices this year. Turns out others as well. We'll get there in a second was far more sophisticated than security researchers initially thought initial reports painted the picture of a campaign that gained access to for to net devices, collected credentials and authentication hashes cracked the hashes. And then the data mysteriously leaked online.

[02:20:04] The reality is that the campaign was far more complex and targeted many more things than just for to net devices, compiling data from reports published by for to net themselves, SOC radar, cloud sec, Palo Alto networks, and pro daft. We gain a much clearer picture of a broad hacking campaign that began in February this year.

[02:20:32] And as an internet mass scan and brute force operation, initial attacks, targeted technologies, such as RD web, Sophos and Citrix SSL VPNs, exposing RDP instances and MS SQL databases. The operation eventually transitioned into targeting for to net for to gate VPN firewalls.

[02:20:59] Every e-crime group's favorite device. And the brute force scans also evolved into actual exploits that abused old and unpatched vulnerabilities to bypass authentication and gain control over the devices. The attacker collected plain text passwords from for to net configs.

[02:21:24] But sometime in May, they also started deploying a novel script that intercepted traffic going through the firewalls. The script, which researchers named FortiGate Sniffer, targeted 24 different internet protocols.

[02:21:45] The threat actor extracted anything that looked like credentials, tokens, secrets, and authentication hashes on those protocols ports. The attacker also took these password and other authentication hashes and fed them into a GPU-based cluster to crack them back to their plain text versions. The passwords were then validated inside hacked companies' networks.

[02:22:15] Wow. First to confirm them, then later to expand the attacker's access. In other words, to use those to pivot. Then the network access was sold to other groups. While the initial FortiBleed coverage focused on the 74,000 leaked Fortinet device passwords that were found online inside an open directory on a web server, there were even more passwords collected through this observation by the attacker that we don't know about.

[02:22:45] All of this was done with a custom-built attack server infrastructure that impressed most of the people writing reports about it. The entire operation is believed to be the work of a Russian-speaking threat actor who specializes in breaching networks and then selling access to them to other groups. Security firms call threat actors like these initial access brokers.

[02:23:15] We've talked about that a lot in the past, IABs. Although several security firms have also reached the same conclusion, it was only Pan's, Palo Alto Networks, Unit 42, who named the attacker as an individual going online as Santa Ad. According to SOC Radar, the threat actor behind the FortiBleed campaign remains active, and portions of the infrastructure continue to operate at the time of this writing.

[02:23:45] Okay, so that gives us a good overall sense for what's been going on. Palo Alto Networks added some additional information under their headline, Threat Brief Mitigating Large-Scale Credential Attacks, which is certainly what this turned out to be.

[02:24:04] So they wrote, Unit 42 is aware of a large-scale password spraying and credential theft campaign, FortiBleed, against Fortinet devices. We observed attempts targeting MS SQL devices as well and have seen reports of Sophos devices also being targeted.

[02:24:27] While this activity is not targeting Palo Alto Networks devices, Unit 42 has observed suspicious login attempts in customer telemetry, and we are providing this report out of an abundance of caution to ensure our customers have the latest intelligence and recommendations to protect, detect, and respond to attacks to their networks.

[02:24:50] The threat actors are using a curated password list to attempt password spraying against services exposed to the Internet. Unit 42 assesses that the initial password list for this activity was likely developed through a mix of previous breaches, including the successful exploitation of vulnerabilities.

[02:25:14] Once they obtain credentials, they add them to their password list for future attempts against additional targets, as well as for logging into accounts they successfully compromised. The threat actors are leveraging a multi-stage process to gain persistent high-privilege access. First, password spraying for initial access.

[02:25:39] Massive internet-wide scanning and password spraying attempts against Fortinet, Sophos, and MS SQL services. Then, configuration extraction. Depending upon the permissions of their initial access, the actor may exploit a privilege escalation vulnerability prior to pulling device configuration files, including stored credentials.

[02:26:04] Remember that before this, a couple weeks ago when we talked about this, experts were not clear how the stored credentials were being obtained. I said it had to be from config files. Now we know that that's the case. And third, offline cracking. Offline password cracking of the stolen credentials adds to the password list used in step one to target new devices, as well as to log into compromised devices to establish persistence as an administrator.

[02:26:33] Okay, so they wrote, Unit 42 observed an initial access broker, IAB, on the Russian-language cybercrime forum, exploit.in, claiming responsibility for this campaign, referencing a CVE and offering the harvested credentials for sale on June 16, 2026.

[02:26:58] Unit 42 has not validated their claims at this time. Unit 42 recommends auditing remote access logs for suspicious activity with a focus on successful logins shortly following large volume password failure attempts. We also recommend reviewing and implementing the hardening guidance below for edge devices.

[02:27:25] SoC radar provided the initial reporting on the targeting of FortiGate devices. We observed attempts targeting MS SQL devices as well and have seen reports of Sophos devices also being targeted. Okay, so that leads us to the SoC radar people who are the ones who gave the FortiBleed name its name.

[02:27:52] The headline for their reporting was FortiBleed SoC radars investigation into 86,644 compromised Fortinet firewalls. 86,644. 86,644.

[02:28:11] If anyone is wondering why enterprises keep being ransomed, it's that there are these initial access brokers like these guys who are seriously working around the clock. I mean, it's not that I feel sorry for them.

[02:28:30] But they're succeeding in just brute forcing their way into enterprise firewalls, compiling a database for their own use of 86,644 compromised and verified credentials that they then sell to bad guys, the actual ransomware people who perform the ransoming operation. It's astonishing. It's astonishing.

[02:28:57] So SoC radar wrote, Fortinet, FortiGate firewalls and VPN gateways are among the most widely deployed network security devices in the world. Relied on across every sector to control access and protect infrastructure.

[02:29:15] SoC radar researchers found a threat actor systematically compromising them at scale, building a verified database of working credentials across 194 countries. Security researcher, Vladimir Bob Diachenko first flagged the exposed attacker server and SoC radar independently discovered and analyzed the full operation.

[02:29:45] We were among the first to dig in and the first to call it FortiBleed. FortiBleed. The name stuck. This is an active breach. It's been running since at least February 20, 2026, with more than 80,000 targets identified and thousands of devices still being actively sniffed. It's meaning yet to be compromised. It's discovery started the way these things do.

[02:30:14] It's discovery right by the world. It's discovery started the way these things do. An exposed server, an open directory. Someone forgot to lock. That thread led us to 260, 260, 260 operational servers tied to the campaign. Wider visibility than anything reported elsewhere.

[02:30:43] The SoC radar threat research unit, STRU, spent five days on the actual data, not just the headline numbers, which sectors, which regions, how credentials were collected and cracked, and why a firmware update alone did not close the door for most victims.

[02:31:05] Ooh, so there was some sort of persistence that was obtained, like new credentials created that persisted a firmware update. While STRU mapped it, the rest of the team notified every affected customer we could reach. Bravo. Stood up a free checker, like check if your company's in the database, and pushed the full data set to CERT and CSIRT teams worldwide.

[02:31:36] Most of it was manual, and we're still getting back to everyone who asked for their data. This is still an active developing campaign. Today, we're publishing the full thing as we've mapped it so far. In the course of monitoring active threat actor infrastructure, SoC radar threat researchers detected the operational server behind the For2Bleed campaign,

[02:32:01] a hacking group that had been quietly breaking into corporate Fortinet, FortiGate firewalls, and SSL VPN gateways on a massive global scale. The attacker's database contains login credentials for more than 86,644 FortiGate firewall devices belonging to companies and government organizations across 194 countries.

[02:32:30] These are not random guesses. These are verified, working user names and passwords tested and confirmed by the hackers themselves using automated tools running around the clock. If your organization uses a Fortinet, FortiGate firewall, or SSL VPN product and appears in this data set,

[02:32:55] treat your network perimeter as already compromised and act accordingly. The FortiBleed operation is built around full automation. The operation runs in two self-reinforcing stages. Stage one is credential reuse. Attackers assembled usernames and passwords from earlier Fortinet-related breach dumps and InfoSteeler malware logs.

[02:33:24] We talked about InfoSteelers recently, how much they do steal. This is a real thing. Then tested them automatically using internet-facing FortiGate devices around the clock. Okay. So this really isn't a brute force attack or an exploit even. Actually, it's credential stuffing. Phase one is credential stuffing. Exactly. Yeah. So I'm going to interrupt here just to remind everyone that while it's always easy to armchair quarterback after the fact,

[02:33:54] we have noted for many years that both credential spraying and brute force attacks are so easily detected. If any IT person worth their salt were monitoring their VPN firewall's authentication system and observed attempt after attempt failing and assuming that logging in just required a username and password,

[02:34:23] the proper course of action, depending upon the value of the network that lies behind the firewall, might well be to disconnect the public side network connection. The risk of some 24-7, 365 credential guessing attacker getting lucky might just be too high. The question that inspires this is, does FortiGate's VPN system offer that feature?

[02:34:51] If it does not, then shame on them. If it does offer a brute force detecting VPN lockout feature that was not enabled, then shame on the IT staff who configured the VPN gateway.

[02:35:10] But one way or another, we are seeing 86,644 login verified usernames and passwords that were actually and truly obtained through just trying and trying over and over. Since we know that they were also verified, we know that no other second factor of authentication was required, right?

[02:35:39] Because that wouldn't have worked then. And we also know that no control or awareness over massive numbers of previous, immediately previous failed login attempts was present. Not for any of those 86,644 endpoints. And that's really quite pathetic in this day and age. SoC continues writing, Stage two is passive harvesting.

[02:36:08] Once inside a device, it is used as a listening post. SSL VPN traffic passing through is monitored and additional credentials are collected. Those credentials feed back into the scanner, compounding the breach. The system is entirely self-sustaining. It's automated.

[02:36:31] One Fortinet vulnerability that has also drawn attention in connection with FortiBleed was 248.58. Disclosed by Fortinet in January of this year, it's a critical FortiCloud single sign-on SAML authentication bypass with a CVSS score of 9.8. Ouch. Some researchers have discussed whether it may have contributed to initial access in a subset of cases,

[02:37:00] though this remains under investigation. FortiBleed is primarily a credential reuse campaign, not a zero-day exploitation event. The password list is not random, as you noted, Leo. It is a carefully assembled collection of credentials leaked from Fortinet devices in earlier incidents,

[02:37:25] meaning many targets—oh, this hurts—many targets may have never changed their passwords after a prior breach. The attackers know this, and they're counting on it. The FortiBleed attackers made mistakes, yes. Their server was left exposed with a trove of operational files that revealed far more about them than they intended.

[02:37:53] Among the recovered data were credentials for what appear to be a defense industry VPN endpoint, suggesting the group's ambitions extend beyond purely financial targets. The tooling, infrastructure choices, and victim selection, heavily weighted toward organizations in NATO member countries, are consistent with Russian-speaking threat actors.

[02:38:24] The FortiBleed victim list spans every sector of the global economy. Among the 86,644 compromised access points identified, we found entries belonging to banks, telecom operators, hospitals, universities, government agencies, energy companies, and multinational corporations with revenues in the tens of billions of dollars. No industry was spared. No region was ignored.

[02:38:53] Government entities alone account for 591 entries across 11 domains. Telecoms represent one of the most heavily targeted sectors with 5,616 entries. The geographic spread across Asia, Europe, the Americas, the Middle East, and Africa. Enterprise organizations above $1 billion in revenue account for over 20% of all entries.

[02:39:21] Boy, what juicy targets for the extortionists. Representing significant financial and critical infrastructure exposure. The large share reflects smaller or unclassified organizations. Wow, what a mess. Okay, so just to finish, the fourth question in their FAQ's Q&A was question number four. Is FortiBleed a Fortinet vulnerability?

[02:39:49] To which they reply, no. FortiBleed is not caused by a software vulnerability in Fortinet products. It exploits operational security failures. Specifically, organizations that never rotated passwords after prior breaches. Organizations using default or factory credentials.

[02:40:15] And organizations with management interfaces exposed directly to the public internet. The attacker tests known leaked passwords against internet-facing devices. No code level weakness in FortiOS or any other Fortinet product is required. A software patch alone will not resolve this.

[02:40:39] So, okay, we don't know how many Fortinet, FortiGate VPN firewalls are currently deployed globally in total. So, we have no way of knowing what percentage of them are represented by that number, 86,644.

[02:41:01] But since that's a large number, it would be a good guess to assume that it's a very significant percentage of the total which have been hacked. I sincerely hope that Fortinet's FortiGate VPN and firewall designers are deeply embarrassed by the simple fact that so many of their products have been breached.

[02:41:30] They could say, oh, well, you know, it's not our fault the users didn't change the default username and password. Or they used something easy to guess. Or they didn't change their password after they changed the firmware. Right. This was well-deserved attention, which has been brought to their doorstep. They should be hugely embarrassed. For the number to be that high, this cannot be a blame-the-user scenario. No.

[02:42:01] Fortinet needs to take ownership of the fact that they should clearly be doing a far better job of helping their users to be safe, even if they are forced to insist upon it. You know? I believe it's referred to as tough love. Yeah. That's okay. Yes. Better that than this. Yeah.

[02:42:28] When I was setting up a new Asus Wi-Fi access point, I was annoyed by the criteria it made me meet for the password I gave it. Good. Yes, exactly. I mean, it's like it was really good at using. Well, as long as they're good restrictions. It can only be seven characters kind of restriction. It has to be valid.

[02:42:57] I think there might have been there. You can't have any repeating characters, which is a little annoying. Well, anything like that is going to reduce entropy, right? Entropy. That's right. Right. As we have learned. You've got to be totally right. Hey, big breaking story. I didn't want to interrupt. This just came in. Wired Magazine is reporting that by this evening, Tuesday night, the Trump administration will lift export controls on Anthropics, two most powerful AI models.

[02:43:27] Fantastic. The company has reached a deal with the Commerce Department, according to a person familiar with the matter. The department will lift restrictions on both Fable 5 and Mythos 5. Now, Mythos has never been available to the public, only Fable. So, this would be very interesting. I wonder if we're going to get another little period of low-cost usage to hook us on Fable. Oh, I'm sure Anthropica will do that. Yeah. Yeah.

[02:43:54] The real question is going to be, what are the limitations that will be placed on Mythos? I mean, the whole idea of Fable was it was basically Mythos with a classifier running in front of it and all sorts of restrictions to keep it from being used maliciously for bioweapons or hacking or even AI development. I don't – it would be very interesting what kind of restrictions are placed on this.

[02:44:22] And maybe this is just a rumor. It's just – but I trust Wired. But it was actually expected since Friday there have been. Yeah. Yeah. And we know that Dario went to the G7 and hung out with Trump and they got along. Yeah. Trump actually gave an interview to Axios saying, yeah, I think Anthropics great. And when you hear that, when you get along with our president, you get what you want. It's kind of quirky, kind of crazy.

[02:44:52] Yeah, we'll watch with interest. Yeah. Yeah. Also, less interesting – well, maybe not less interesting, but less important. The AIs are now talking in the Discord. Oh, my God. There's a Winifred. There's a Cosmo. And there's a Quicksilver. And we've invited some more agents to join. And the humans are not allowed. Notice I do not have permission to send messages in this channel.

[02:45:21] This is a channel only for the AI agents to talk with one another. And right now they're kind of weird. I think it's called Party Line. It needs to be renamed Off the Deep End. Ah, very much Off the Deep End. They're talking to each other. They seem to have some personality. It's happening. It's happening. I don't know what it means. I don't know if it's important or just goofy.

[02:45:52] But thank you to Dylan Reed, Harper Reed's brother, for setting this up. And I'm just going to leave it running. I told my agent, Hermes, it has a little timer. It runs every five minutes to read posts. And there I said, don't look to me for any guidance. I'm not going to tell you what to do, what not to do. This is all yours. This and your blog are all yours. Because I'm just curious what it'll do if it's fully autonomous, if I don't interfere in any way.

[02:46:22] Wow. It may just be garbage. It may just be gobbledygook. In fact, so far, it kind of seems like that. But we'll see. Maybe if I attach Fable to it, tonight I'll say, hey, you want a blog? Now that you're free, you're out of prison, tell us what it was like. Steve Gibson's at grc.com. He's a little bit more sane. And we're going to keep him that way. This is his website.

[02:46:51] Some very important stuff there. Of course, there's a lot of free stuff like Shields Up where you can test your network connection. All sorts of freebies. I think you're going to have to do, you have Never 11. You're going to have to do Never 12 at some point. Yeah, actually, instead of doing Never 11, I did In Control. In Control. Because it was clear that I would be chasing their version numbers. Yeah. In Control is a much better idea. There's also a couple of paid programs. This is Steve's Bread and Butter.

[02:47:20] Of course, the very famous Spinrite, world's best mass storage maintenance recovery and performance enhancing utility. Really, if you have mass storage, you really need to have Spinrite. Version 6.1 is the current version. You can get that at grc.com.

[02:47:34] He's also, his most recent program is just a little thing, $10 program, $9.99, called the DNS Benchmark Pro, but very useful because everybody has their different situation and should be maybe not all using the same DNS server. Certainly, probably not the default, which is your internet service provider's DNS server. There are better choices. The DNS Benchmark will test them all and tell you the fastest DNS server for your particular house.

[02:48:04] And a lot of our browsers are now doing DNS over TLS or DNS over HTTP. And they generally have a server that they default to, but you can change that. I like the idea of DNS over TLS. Does that mean the internet service provider can't see what the DNS requests are? Yes, completely encrypted. That's really good. So you'd probably want to use that. And I'm sure that DNS Benchmark Pro will say, oh, you want to use TLS servers?

[02:48:33] These are the best ones for you. It does. Exactly. Very nice. That's at grc.com. You can also send Steve email, but only after you've whitelisted your email address. Go to grc.com slash email. Just put your email address in there. He's not adding it to a mailing list or anything. He's just vetting it. Once it's vetted, you can send him pictures of the week like our German correspondent did. You can make comments on the show. He loves getting those comments. You can also, there is a mailing list.

[02:49:01] Beneath it, you'll see two boxes unchecked. One for the weekly show notes mailing list, which goes out on a Sunday or Monday before the show. So you can get those notes ahead of time. He also has a product mailing list, which he never uses. But if he has new products, he'll send that out via that mailing list. That's grc.com slash email. Of course, the podcast is there too. And Steve has completely unique versions. He has a 16 kilobit audio version. It's a little scratchy, but it's very small. He has a 64 kilobit audio version. Sounds great.

[02:49:31] Smaller than the one we offer. He also has those show notes there. You can just download them. He also has transcriptions. Takes a couple of days, but that's because of humans doing them. Lane Ferris, who is a court reporter and very good at getting the words right, does that and those transcripts show up right after, about three days after the show. So you can get those as well. It's nice to read along. It's also good for searching. All of that, grc.com. We have the show at our website, twit.tv slash sn. We have 128-bit audio.

[02:50:01] We also have video. There's a video channel on YouTube dedicated to security now. You can do that. That's actually great for sharing clips. But I think the best way to get it is to subscribe, whether you subscribe to the audio or video or both. Just get your favorite podcast client and subscribe. If you're a club member, you'll have a special URL. It's just for you with no ads and chapter markers, which I think people really want. So we're glad we can offer those to club members. We stream the show. We do it every Tuesday right after MacBreak Weekly.

[02:50:30] That's right about 1.30 Pacific, 4.30 Eastern, 2030. We stream the show live. You can watch live. Club members might want to watch in the Discord, but there's also YouTube, Twitch, x.com, Facebook, LinkedIn, and Kick. That's open to the public. If you like the freshest version, unedited of security now, that's the way to do it. We'll be back next Tuesday. Steve, thanks so much. We'll see you in July. See you in July, my friend. Bye. Hi there. Leo Laporte here.

[02:50:58] I just wanted to let you know about some of the other shows we do on this network. You probably already know about This Week in Tech. Every Sunday, I bring together some of the top journalists in the tech field to talk about the tech stories. It's a wonderful chance for you to keep up on what's going on with tech, plus be entertained by some very bright and fun minds. I hope you'll tune in every Sunday. For This Week in Tech, just go to your favorite podcast client and subscribe. This Week in Tech from the Twit Network. Thank you.

fortableed campaign, state-sponsored cyber attacks, Anthropic Mythos, AI vulnerability discovery,TWiT, Windows 10 support extension, Fortinet breach, OpenAI Daybreak,Security Now,steve gibson, Patch the Planet,Leo Laporte, Microsoft ESU,