Risky Business - Risky Business #845 -- OpenAI's Skynet moment
Episode Date: July 22, 2026On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! Ope...nAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider is having a hard time, not just because of Microsoft’s GDID And much, much more! This week’s show is brought to you by Push Security. Luke Jennings joins Patrick this week to talk about the rise in authorisation phishing, like device code phishing, and what companies like Push are doing about it. This episode is also available on YouTube. Show notes OpenAI and Hugging Face partner to address security incident during model evaluation | openai.com Security incident disclosure — July 2026 | Social Signals Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch Security Cheating behaviour in frontier model evaluations | AISI Work | Social Signals JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig | Social Signals Secret Claude tracker shocks users after Anthropic's anti-surveillance stance | Ars Technica EXCLUSIVE: Beijing is looking at curbing overseas access to China's top AI models, sources say | reuters.com https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi | Alibaba to ban employees from using Anthropic's coding tool, source says | reuters.com Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch Security Apps Marketed to US Troops Are Shipping Chinese and Russian Code | wired.com Trump calls for new election security measures | NBC News Tech Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack | therecord.media Alleged longstanding member of Scattered Spider extradited to US | CyberScoop https://www.justice.gov/usao-ndil/media/1450651/dl?inline | Tracking Peter Stokes and The Com: Allison Nixon and Her Work Unmasking Cybercriminals | zetter-zeroday.com 764 splinter group leader sentenced to 40 years in jail | cyberscoop.com Interpol cybercrime crackdown nets 5,800 arrests across 97 countries | cyberscoop.com White House details ‘Gold Eagle’ clearinghouse for AI cyber threats | cyberscoop.com Attackers vote themselves $20 million in BONK cryptocurrency | The Record CISA: Microsoft SharePoint RCE flaw now actively exploited | BleepingComputer Critical SharePoint RCE flaw exploited to steal machine keys | BleepingComputer Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch Security Critical ServiceNow code execution flaw now exploited in attacks | BleepingComputer Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | BleepingComputer Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | BleepingComputer IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets | bloomberg.com Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI | TechCrunch Security Pegasus Spyware European Parliament Pega Committee Member | The Record Amazon fixing bug that billed some AWS customers billions of dollars | TechCrunch Security Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media | Social Signals Microsoft Entra ID gets passkeys default authentication starting September | BleepingComputer On-demand Webinar: Device code phishing in 2026 | Push Security | Push Security
Transcript
Discussion (0)
Hi everyone and welcome back to risky business.
My name's Patrick Gray.
I am of course back on deck after a couple of weeks off.
I had a lovely break off to Indonesia with my family.
So yes, back on deck, well rested and ready to go.
And this week's show is brought to you by Push Security
and we'll be joined by Luke Jennings a little bit later on
to talk through a few things like what they're doing to curb,
I guess, authorization-based attack.
which are a real scourge at the moment
when you've got like these device code fishing things
attacking various accounts
I mean you know pass keys won't help you
Fido Orth won't help you in those sort of situations
so that's an interesting discussion
and it is coming up after the news
but yeah we're about to get into it now
I am joined this week by regular co-host
James Wilson and joining us in the third chair this week
is the first ever director of Sisa
turned I guess independent consultant guy
Chris Crabs, how's it going, Chris?
Doing all right, Pat.
James, good to see you.
Likewise, mate, great to meet you.
What do I even describe you as now?
Because I know, I know what you're doing and it's like you're doing like, you know, high level, board level, like risk consulting and exercises and whatnot.
But, you know, you're here.
You may as well pitch yourself to the audience.
What is it that you would say, what would you say you actually do here, Chris?
Oh, man.
You know, I've tried my hand at starting consultancies with, you know, Stamos.
and then sold that off to set in a one.
And now I'm just playing around and helping boards out
and executive teams out and spending more time,
probably playing around with AI than I'd like to.
But I'm doing okay, though.
Excellent. All right.
Well, that's, that's, you know, interesting and vague.
We'll go with Mysterious.
How's that?
There we go.
All right.
So let's get into the news now.
And the way, what was supposed to happen today
is we were going to start talking about,
the news and we were going to talk about this mysterious incident at Hugging Face where they had said,
look, we've had a security incident. It looks like some sort of, you know, attacker using AI,
managed to breach our environment, move laterally at just incredible speed. And, you know,
we're still trying to figure out exactly what was exfiltrated and whatnot. And that's what we're
going to talk about. In fact, yesterday I flew to Sydney and back yesterday because reasons. And
James you and I caught up for lunch and we had a bit of a chat about this and it's like okay well how did
they know that it was AI and you know you walked me through well you know it was just very clear that
it was an agentic sort of attack the speed at which this moved it was a machine speed thing
and then we wake up here in Australia we wake up to the news today that open AI has published
the most amazing corpo speak comms director like vetted blog post talking about how they're partnering
with hugging AI on sort of AI and security because the breach was actually an AI, open AI model
or models that went rogue when they were doing cyber evaluations on them,
figured out how to bust out of the restrictions on their, on their, you know, networking abilities,
bust out of a sandbox, find O'Day, exploit O'Day to get out onto the internet,
and then go and hack Hugging Face because it thought it could capture some flags from huggingface,
basically a thought that it could get the answers to the test that it was being evaluated against by hacking Hugging Face.
So off it went and owned it.
I mean, what a story.
But James, why don't you start off by walking us through like the sequence here, what we know about how these models actually performed this breach and, you know, what went on here?
Because it is an incredible story.
It's just incredible in so many ways.
So I'll start with what we knew yesterday about the actual attack because of the time it looked like,
you know, it was understandable that this was a target, right? So Hugging Face hosts two,
let's say, main things, right? Not just large language models, but also training data sets.
And what it appeared to be was that an attacker had decided, well, that's, you know,
if I'm uploading a data set, that's untrusted data going into a trust boundary. There's going to
be all sorts of pauses and processing happening with that. And so that's your typical place
where there's likely to be some vulnerabilities that you can exploit. So that made sense. And the
The agentic angle was just the fact that it was done at such speed, so rapidly, it was like,
yep, okay, cool.
An agent, whether it worked that out itself or self-guided itself here, makes sense that
that's what it would go after.
So nothing seemed particularly odd at that point.
Then what we found out today is that it wasn't just that a model found that there were zero-day,
I guess, in hugging faces, parsing systems and data processing systems, but that agent itself
was running within open AI's, I guess, testing harnessing.
that they were using to prove out a new unreleased model.
It was a combination of GPT 5.6 and an unreleased model
was going through this very specific test
and it was desperate to try to find a way to pass the test.
The test called to exploit Jim.
And amazingly enough, it went and found Zero Day in the package registry
that was the only thing available to it that had access to the public internet.
It pivots through the nodes within the package registry
to find one that had internet access.
It uses that internet access to reach out to Hugging Face
because it just knew that Hugging Face would be a place where it would likely find a data set
that would help it continue on through this Explore Gym test and complete it.
The amazing thing about this, just sort of like the cherry on top of this incredible cake,
is the model wasn't actually looking for a way to complete the challenge successfully.
It was looking for a way to cheat, which is just so LLM.
It was trying to steal the answers to the exam, right?
Which is just absolutely amazing.
Now, you mentioned the package, I mean, so it looks like there's been multiple bugs in this case, kind of chain together.
Yes.
Like the whole thing end to end was completely autonomous.
Yes.
Yeah, completely autonomous.
And you know, you remember when we looked back at like the RCE chain or something like Karuna,
where it's just so many layers and multiple steps and each barrier just has a new exploit.
That's exactly what happened here, right?
The thing was isolated.
It had only the ability to get, supposedly, as we're told, only the ability to get to this package registry.
And so it just continued to leverage.
and pivot, step by step by step, multiple vulnerabilities, multiple hops to get itself to talk
to HuggingFace.
What package registry do they use there at OpenAI there, James?
Well, that's an interesting question, Pat.
They are known to be a customer of Buildkite, but I know that they use BuildKite,
and that's public knowledge, and not giving away any secrets here, but I happen to be the former
CETO of BuildKite, and so...
Yeah, awkward.
Like, this whole thing is your fault, I think, is what we're saying.
It's a little bit awkward.
You know?
A little bit.
Yeah.
Yeah.
Blame, don't blame Sam Altman.
We got the culprit right here.
Now, of course, the reason we were going to talk about all of this,
the big, risky business angle on the Hugging Face breach,
before we found out it was Open AI,
is that when they were responding to this whole thing at Hugging Face,
they tried to use Frontier models, which, for starters,
given they're known to host Openweight models,
like why are using a Frontier model in the first place?
That was a question that you had, and I think it's a valid one.
But they wouldn't help.
Because it's like, we're into this situation where the guardrails are like a reverse
clippy, right?
They see you trying to do something.
And instead of popping up and say, hey, it looks like you're trying to, you know,
do something.
Let me help you.
It pops up and it says, it looks like you're trying to do a cyber.
I have dispatched the authorities to your house.
So that was what was happening when they were trying to do incident response.
It was like, whoa, hey, this is a cyber task.
This is not allowed. This is verboten.
So they wound up using GLM
and open-weight Chinese models to assist them in the incident response here.
Now, what is just mind-boggling here now
is we're in this crazy situation where they were being attacked
autonomously without instruction by a frontier model.
And we've seen this before, mind you.
And it's an example I've spoken about on the show before
when we've had someone say,
hey, can you update this wiki for me?
But they didn't give it cred.
so the agent found O'Day and the wiki software hacked it and updated it that way.
So, Offit's gone and autonomously owned them, but the same models that are owning them refuse to help them actually respond to it.
So this is, I mean, so many layers.
Chris, let's bring you in on this.
I mean, I'm guessing the, you know, the political, the business political angles here are just mind-blowing.
Like, I think Anthropic are just going to be so thrilled with this because it validates
all of their, ooh, spooky, spooky AI danger stuff.
Altman, I mean, geez, you would think he's already looking a little bit like under pressure,
and this ain't going to help.
What's your take on this whole situation?
Well, I think what I found most interesting, what James was pointing out, about just the
speed and the sophistication of the attack, and Clem from a hugging face tweeted, you know,
like three hours ago from the time we're taping this, said, we suspected it was a frontier
model based on the sophistication.
But that doesn't mean they immediately thought it was Open AI.
It means it could be a range of labs, including Chinese labs.
Well, hang on, Chris.
We have a question there, James and I, both had a question, which is why was this difficult to attribute?
So it's very clear.
So Open AI have put out their blog post saying, oh, you know, as soon as we detected this happening, we reached out to them and we're all good friends and whatever.
But they didn't reach out to them before they had already done the incident response.
before they had already published blog posts about this, before they had warned customers to rotate secrets and stuff.
So clearly they didn't get in touch with them that quickly.
But why did Hugging Face not know that this was Open AI?
It's a big question.
The Hugging Face team must have had a series of hypotheses.
And I guarantee you one of them was it's a Chinese lab.
I mean, you go from the most catastrophic down to the most likely.
And somewhere in there was Open AI.
I would not be surprised if,
there were soft outreach from
hugging face to the labs.
So yes, OpenAI may have reached out,
but I also wouldn't be surprised
if hugging face reached out
to all the friendly labs,
including Anthroping,
I think one,
probably to your point,
once Anthropic did their kind of internal checks there,
and they find out it's not them.
They're doing their little snoopy dance
and they're very happy about how clean they are.
But I,
you know,
this is going to be just one more political problem
in a broader,
AI policy landscape in Washington that is, you know, vague is not the right way to put it,
ambiguous it in the right way to put it. I mean, it is just, you know, it's kind of like
written on the, you know, on a day by day basis. And, you know, we keep hearing these things
coming out of the administration from an AI policy perspective, but is there anything really
behind it? Or is it just kind of somebody behind the curtain that's pulling strings,
making decisions kind of arbitrarily? We'll get to the policy stuff in a moment,
but I just want to spend a little bit more time on this.
The scenario that they were doing, they were evaluating various models, right?
So there was one that's not released, and they had pulled back the guardrails on these models as part of this evaluation, right?
So that's one of the reasons that this happened.
But we've got this other story here.
It's a couple weeks old now, but I was away, so we're going to talk about it now.
But CISDig put out a blog post about this so-called Jade Puffer, agentic ransomware, right?
And it's not incredible, but it's, you know, it's heavily automated using using,
AI. But I think what's interesting is when you look at, okay, there's this ransomware actors using
AI to get stuff done, a little bit rudimentary, right, but still interesting. And then you go, well,
okay, then we've got these GPT models that don't have any guardrails on them. And this is what
they're able to do. They're able to go out and find O'Day in multiple things and actually pop shells.
At Hugging Face, this, you put these two things together and you get a bit of insight into the
future. Now, will Open AI allow you to just, you know,
know, tell it to go and hack various targets in the future. No, there's always going to be some
guardrails. But we also have this situation where the Chinese models have consistently stayed
only six months behind, right? So, and these are open weight models you can, you can tinker with
and mess with. James, you have actually been using them to find bugs. You have reported a local
prevesque, uh, to Apple, actually, uh, which has already been pulled out of the triage queue and
they're looking at that one as well. You found that with, with, with, a
combination of like Claude and the Chinese models, but you've been deep in this stuff.
The idea that like a year from now, we're going to have open weight models that can cause
this sort of chaos. Like I think this feels somewhat inevitable now, but I want to, you know,
given that you're in there actually using these models day and day out, what's your opinion?
It's inevitable, but I think there's probably two variables to consider in this. One is, as you say,
the model capabilities itself do seem to be about.
six months behind and I can only see that closing over time. But what I would, what I would love to know.
I would say, sorry, that even if it doesn't close, the thing that's blown me away is that ever since
Deep Sea, the Americans haven't been able to pull away further. That gap has just been six months
the whole time, right? Agreed. We haven't seen a step function change in there. But I think the piece of
information that we really need to know from Open AI about this is just how many tokens did it spend
getting to this outcome because if it turns out that this was their internal training rig and it would
have cost the layman $10, $20, $50 million to achieve this, right? I don't, I can't believe at the moment that
this model would have quickly stepped to this outcome. It must have been churning over and over and
over and getting so many dead ends to finally come up with this, you know, diabolical plan of its
of its own creation. So the question is, how much did it actually cost? Because that will also give us
an indication of not just how far behind the model capabilities are, but what it would actually
take an attacker to pull off the same thing if they weren't within a frontier model lab that
had near limitless access to their own inference. I think that's an interesting variable as well.
Yeah, it is. All right. So now we have the policy conversation, right? We've got so much here,
and we'll just try to discuss all of these items as one. We've got Beijing, apparently looking
at curbing overseas access to its AI models, which is mind-boggling.
you've got the Trump admin considering applying sort of sanctions to organizations that are using these open source models, right?
Which is an idea I've heard floated by various people in Washington, right?
Which is, well, look, you know, we've got all of the hardware.
So we can just say to these neoclouds and these hypers, you can't offer these distilled models
because they essentially stole American intellectual property.
and if you start offering them, we're going to put you on a banned list and you can't buy any chips anymore.
So I think that's probably something the US government is going to try.
We've seen all of this weird stuff as well.
Like weeks ago we saw that there was some sort of insertion of tracking into anthropic queries designed to track Chinese use of Claude.
Oh my God, there's just so much going on.
We've got Alibaba banning its employees from using Claude.
what is going on?
I think right now it's really hard to see
where the regulation
is going with all of this.
Chris, this is something where you have actually spent
a bunch of time thinking about this
and you've broken down the approaches,
you know, the various approaches
to how people want to regulate this
into six different camps.
Walk us through this because I found this absolutely fascinating.
So it's a little early and as the things tend to kind of sit at the forefront of my brain, it's a little raw until I get more input from people like you and and other smart people out there.
But it's kind of based not as much on like archetypes.
It's not really on things people want.
It's mainly what they're afraid of.
And that's almost the primary driver in the decisions we're seeing in the policy space.
So like you said, I've got six primary fears or groups of coalitions of fear.
And it's really based on, you know, what the topic or the object of the proxy for the conversation.
So anyway, first one is the techno-nationalists.
And those are the folks that are afraid of the U.S. regulating themselves into second place.
Now, you would normally characterize those as the Silicon Valley VC type.
but there's been a bit of a jump where I think it's more the old, not old school,
but a year ago VCs that came into the administration.
So this is almost the David Sachs-like people.
Then you've got the national security restrictionists,
and those are the ones that fear China acquiring strategically decisive capability,
even if preventing that imposes real cost on U.S. industry.
And there's like this little element of a second fear in there of the U.S.
being constrained by U.S. industry decisions.
And that's an anthropic nod from the Department of War,
Department of Defense, and saying you can't tell us what to do with your models.
And so, you know, that's undersecretary Michael from DOD, DOW,
wherever you want to call it.
The third is the market diffusionist, and they fear a few monolithic expensive labs
locking up the field, locking up the talent,
and they want cheaper alternatives to break them open.
And that's Shamath.
And that's his whole recent being very intriguingly or interestingly open to a lot of Chinese
openweight model.
So you can break the addiction of the frontier labs and they're super expensive stuff.
And then you've got the open model strategist.
And those are the ones that think we beat China by winning in the open weight layer that just
let's outclass them on the field.
Let's not worry about scaring everybody about how bad they are.
Let's just go go do the job.
Nathan Lambert, the policy space,
is a good one there.
Then you've got the frontier risk governors,
and those are the ones that think closed frontier labs are the engine.
Those are the ones that are going to define AI going forward,
but they carry real risks.
And Dario is the best example in this coalition.
And lastly, I think you've got the operational access advocates,
and that's, you know, think whatever this is,
whatever we're doing now, it's not working.
It's just like what we saw with hugging face.
You put your guardrails down and then you've undercut your defenders.
So if your answer is banning Chinese open weight models and clamping down our leading labs,
you get all the downside and none of the upside.
And the best example I come up with here is friend of the show, Alex Damos, who I think is working on on this idea.
And the interesting thing about like if you asked someone where they landed here,
and specifically the people I said,
and he said, hey, this is, this is where you are, what do you think?
Yeah, I think most of them would be like, hell yeah.
Yeah.
Yeah, so they're proud of it.
You know, they know where they said.
Well, because they're all making good points.
They're all making good points.
I mean, a lot of these are in opposition to each other, but they're all good points.
There are certainly tensions, not necessarily in opposition, but they're absolutely
tensions.
Well, I think the dumbest one is probably Dario's position, right?
Which is like, you'll all just be frontier labs, right?
That's like, you know, clearly the thing.
But I think there were some things, I don't know how this is going to shake out, right?
And I don't know which of these six camps is right.
But I think there's some things that we can say.
And I think one of those things is that open white models, man, they're not going anywhere.
This idea that the US is going to be able to sanction or regulate them out of existence is fantasy.
Like, I understand that they might be able to damage the Chinese business models,
some of the Chinese companies behind these things.
But I don't think they can shut them down.
completely. I think the main advantage that the United States has in all of this is the
absolutely crazy asymmetry in the volume of compute, of inference compute and training compute.
America's winning there, you know, so I think there's so much focus on the models, but
really it's the hardware that's going to see who gets the, you know, the key advantage here.
I also think it's funny that, you know, in Australia we could wind up, you know, having access to
these open weight models from China and the Americans are not allowed, you know, it's like the
forbidden models. Maybe risky business can, you know, rent out inference or something. I saw some
Australian making a joke about how they'd trained a model called Kimbo, which is absolutely
Australian, but occasionally we'll speak Chinese for reasons that we don't need to go into.
But, yeah. Look, if they're going to do that, though, if they're going to take strong action
against the Chinese labs, they're probably going to do it in a way that allies are similarly
not allowed to access them. It's going to be secondary sanctions or something like that. So it's not
just going to be like island USA. There's going to be a perimeter around this that includes
allies under defense treaties like the Five Alliance or the Five Eyes and August and things like that.
That's what Kimbo's for, mate. James, that was a joke. That's okay. James, what do you think about all this?
Yeah, look, it's funny a couple of weeks ago I would have been quite concerned about this,
but now having used GLM and Kimmy and compared it to GPT,
and I'm now in the trusted cyber program with Anthropics
so I can use them to further extent.
I'm kind of not worried.
If one got cut off,
as long as I've got access to the other,
I'm kind of unbothered at the moment.
I mean, you know how that I'm quite apolitical in this sort of thing,
so I'm more like the nerd just sitting by and being like,
can just make sure I've got access to one model that's good, please.
That's all I ask.
I don't care where the hammer's made.
I just need to build a frame for a house.
Exactly.
Yeah.
Well, add the complexity, by the way, of your ability to rotate from model to model from month to month or year to year.
I mean, that kind of portability, I think, is going to be increasingly important as this stuff, you know, you do the race and like one horse pulls ahead, then the next, then the next.
I mean, they're quite portable these days.
It's not too much of a challenge to switch from one to the other, right?
From a tooling perspective, no, but you'd need to take some time to understand the personalities of them.
You know, like when I switched from, you know, what I was seeing with, you know, Claude is basically the give-up engine.
You throw it out a vulnerability and it'll tell you, I found a vulnerability, we're ready to file it, it can't be weaponized, there's nothing much you can do with this.
And if you just take that at face value, you'll stop.
But you need to understand the personality of Claude only wants to go so far and is desperate to be done.
But GLM, for example, I gave it the same vulnerability and said, hey, Claude says this can't be weaponized.
And it was literally like, hold my beer, I've got 17 ways to do this.
And just overnight churned and churned and churned.
And I literally woke up to a message from it saying, read this first when you wake up, I've done it.
But that's a personality trait of the model, right?
You have to know that it will go further, but it will also only go further if you prompted in a particular way to say,
look, you've got a wall clock budget of eight hours.
You must churn endlessly until you've got this.
I will not accept that you have not done this.
There is a way, et cetera.
So, yeah, tooling, quick change.
But I think you still, if you want to really take advantage of models, you've got to
spend time understanding that the personality, for lack of a better term, to fully leverage them.
And that makes transition a little bit difficult.
I think this is really fascinating.
It's been really fascinating watching you get into exploit development.
Because when you first joined it, I mean, you've never done this before, right?
You were saying your whole thing was like, you know, given my background as an engineer, given my background working at Apple, you know, someone like me with an LLM, I think I could probably do this.
And, you know, I remember in one of your early podcasts with us, you were like, well, my father who works in a medical field, you know, probably couldn't, right?
So that's the whole idea with LLMs help people who already have some knowledge.
And it looks like we're on the cusp of risky business media getting its first ever CVE credit,
which has been a bucket list item for me forever.
So thank you, bud.
Thank you very much for that.
Fingers crossed.
Fingers crossed.
All right.
So we're going to move on now to a different topic.
We already spoke about how Iran was using commercially available information,
commercially available location information to determine the locations of American
troops on bases in the Middle East. So we spoke about that first as it was rumor, but credible
rumor from like military and intelligence reporters, and then it was sort of subsequently confirmed
in correspondence from the Department of Defense to Congress or the Senate or, you know, the legislative
branch somewhere. Now we are seeing reports that the Iranians were also using SS7 to locate
devices belonging to service members. I'd imagine that wouldn't be too much.
hard in that you're just looking for numbers with a plus one prefix and where they're going.
We are seeing hypersonic strikes against US personnel still in the region.
And yeah, it really does look like they are all in on mobile.
And I don't think we should be surprised by this, but, you know, it's definitely something where
in the future, I mean, at what point can you actually ban US service members from having
personal devices?
I mean, that's such a huge change, such a huge burden on a deployed service member to, like, not be able to contact their family, for example.
Chris, I mean, you're the American here.
What do you make of all of this?
Well, you know, this is something personal security issues associated with personal devices is something that I know that the military has been concerned of for a long time.
You remember some of the fitness, the Garmin Strava, the tracking, the fitness apps where you could figure out.
you know proof of life and patterns of life and things like that over the last several years
this you know the way they've operationalized it this way is almost like is is pretty scary
you know your your point calling in strikes then you compare you you put that together with
using operational technology and cameras for damage assessments i mean they really are
weaponizing uh connected devices for military purposes at
scale this is not just a one z-to-sie thing that to your point that you know you can't just it's
really hard to take the devices away or cut off connectivity at least in the field because you
have troops that may be deployed for months and months and months and not always in the
middle of a desert and a forward operating base they they may be in Kuwait city like we're
seeing here where or wherever Bahrain wherever waiting for something to happen and it
creates a lot of morale challenges and that's
really one of the balances that the political leadership, the Department of Defense has always got to
think about is how do you how do you have a team that's motivated and ready to fight and part of it is
just given some kind of normalcy some kind of connectivity even if they're there for months waiting to go in
yeah and this isn't specific to SS 7 like all of the signaling protocols have similar challenges
and like there's no easy fix for this like you think oh okay the US could spin up maybe its own
kind of telco with SS 7 filtering on it and whatever but what happens where
someone walks off base in their phone roams, like you would have to restrict every personal
device to be locked to that network. Like I can't think of anything that's really going to fix this
apart from a device band, which you know people are going to skirt. It'll be like cell phones in
prison, right? Same sort of thing. And then we got this other story here from Wired talking about
how there are a bunch of apps in app stores that are marketed towards US troops, that when you
actually analyze them, you could find that there's all of these libraries being invoked that are Chinese
and Russian in origin. This is a problem that's going to get a lot worse. James, what are these
apps that are being marketed to US service members? That is a good question. I was a little bit
surprised to find the caliber of them are things like an app to allow service people to rate the
conditions of their bases. It's almost like, is my base hot or not sort of apps? So not exactly
what you call high caliber apps, which I think also calls into question, you know, some of these
libraries could even be making their way in accidentally. Like if these are like React Native apps that
cheap and cheerfully made.
Who knows what NPM packages are getting pulled into there?
I mean, it's my feeling that this is accidental.
Yeah.
I mean, I don't think that this is some plot by the Chinese or the Russians to get in there,
but it'll be handy later.
Chris has a face.
I don't know.
Chris was pulling a face there.
I don't know.
This is cheap stuff, right?
I mean, this is not a particularly technical or complicated way of just collection.
I would not be surprised if there is a legitimate
an intelligence collection activity going here in not just dumb scraping data.
I think there's as good of a chance that this is the real deal Intel collection as it is
just a stupid app.
Well, we did see a crowd strike report years ago about an app that was designed to help
Ukrainian artillery operators to calculate fires was actually written by the Russians and would
beacon their location.
This is before the current war, I think.
That paper was controversial.
I can't remember exactly why.
I've spoken to Dimitri about it.
He's like, no, the work was good on that,
but there were elements of the paper that weren't.
Anyway, crazy old time.
Okay, so look, the next thing we've got to talk about,
it was funny because last week when all of this was being foreshadowed,
I texted you, Chris, I said, I can't believe.
Because we arranged for Chris to be here months ago, right?
And I text to you, I said,
I can't believe Trump is doing this just like the week before you're coming on to our show.
Because he said last Thursday, he was going to do a big speech
and unveil all of this bombshell classified evidence
that the 2020 election was stolen and blah, blah, blah, blah.
So I was getting really excited about this
because I'm expecting on Thursday night.
Now, of course, you know, he's already signed an executive order
personally targeting you, you know, for being a deep state something.
So I was expecting on Thursday night he was going to wheel you out on a trolley
like Hannibal Lecter with the mask on your face and everything, right?
And him and Nicola Maduro were going to be standing there saying it was him.
You know, he worked with the Chinese to do the voting machine thing.
You know, I was expecting something really crazy.
And what we got instead was just like, I mean, look, I know that there's MAGA people who listen to this show and they hate it when I say bad stuff about Trump.
But it really was just a tired old man talking nonsense.
That's kind of what we got.
It wasn't actually crazy.
it was just nonsense.
It wasn't crazy enough
to actually be entertaining.
I mean, what on earth was he saying?
He was like, I think he said
either Chinese managed to steal
American voter rolls
or something, something,
therefore election stole.
Like, what is he up to?
What is going on with this?
Is this just because his ego can't handle
having lost in 2020
or is he laying the groundwork for something,
you know,
hideously undemocratic that will fail
because his anti-democratic plots usually do?
Yeah, so I, you know,
what's the,
the endgame here? I don't know. I do know that it's not really being, it's, what is it now,
Tuesday night, it's not really being covered at all on mainstream media. That includes rightly,
leaning media, almost immediately afterwards. It was kind of a here one minute, gone the next sort of
event. Yeah. I took the opportunity after Thursday night and I did some TV Sunday morning to kind of
refresh myself of the things that we did in the run up the 2020.
When I say we, I meant me, CISA, the FBI, the CIA, the broader intelligence community,
but also the hundreds of thousands of election workers across the country.
And I was impressed.
I mean, I just, I had frankly forgotten a bunch of the good work we had done because a lot of
the claims Thursday night were like, oh my gosh, they're vulnerabilities in election machines.
We're like, yes, we've been talking about.
that for a decade now and the things we need to do to shore up resilience of the system.
We, you know, yes, the Chinese are interested in American politics. Who would have known?
There, you know, there was this whole range of things, but ultimately that came away from Thursday
night in the immediate aftermath, just more and more confident in our assessment that 2020 was a
secure election. By the way, that line, that line of yours from 2020, where you said this was the most
secure a US election in history or something, that line echoes around his head rent-free because
he always says it. He said it on Thursday night. He also said it, I remember when he signed the
executive order targeting you, he was like, oh, the most secure election in US history. And then
he says, Krebs, never heard of him. When he's just been quoting you, it's so funny, man,
like you are absolutely rattling around in that head of his rent-free, mate. It's incredible.
It, you know, it, it is what it is, I guess. But, you know, the one last thing I kind of want to
point out on this was, like I said, I had forgotten a lot of the stuff we had done. One of the
claims that came up was that voting voter registration databases are highly vulnerable. And again,
I'm like, yes, they're internet connected. We've talked about these things. But what I had forgotten
about and some of the people I was talking to, they were on my team, my leadership team had also
forgotten about was that in 2019, when ransomware was on the rise, we did a pretty broad
risk assessment. One of the things we came up with was like, hey, you know, a motivated nation state,
I don't know, Russia could use one of its security services to direct a ransomware to crew
to go in 30 to 45 days out in advance of an election and lock up a registration database.
And that would create some challenges in getting the ballots out to the voters.
and having ballots printed out and all that stuff.
So we launched a voter registration database ransomware initiative in the summer of 2019.
And in the year following, there's data on this by the Center of Election, Innovation, and Research.
We improved all sorts of metrics on the security and resilience of those systems from implementation of MFA,
from backups and logging and patching and update, all these things that showed that was material security and
improvements. And, you know, I didn't even, I didn't remember that. And one of the funny
throwaway lines I had, funny, not funny, but whatever was from the movie Dodgeball,
or it's like, hey, if you can dodge a wrench, you can dodge a, you can dodge dodge dodge a dodge,
our line was if you can dodge a Riyuk, you can dodge a nation state adversary, thinking that,
hey, you do the good work to go defend yourself against the top flight ransomware actors.
you're going to make material improvements to make it harder for the Chinese, the Russians and the Iranians to get in.
And that sort of stuff still kind of, now that I think about it, we need to do a lot more of that.
And for 26, which is just fewer than 100 days away, there's a lot of work that probably could be done.
Yeah, well, let's see. I mean, everything's a bit of a mess at the moment in terms of, yes, Sissor.
So we've got the Golden Eagle AI vulnerability triage thing being launched by the White House, which is now being run out of Treasury.
but we'll get to that in a second because that's a real head scratcher.
But before we get onto that, just quickly, things going wrong for people who are part of the comm,
scattered spider, you know, the two who are behind the transport for London hack,
they have been jailed, 20 years old and 18 years old, both under 18 at the time of the attack,
is the assumption there.
We've seen another one being extradited from Finland over to the United States.
I think we'd seen news of that arrest a while ago.
But what's interesting is along with the extradition came the DOJ criminal complaint.
James, you and I were talking about that yesterday because you, prior to doing this job,
never had a reason to read a DOJ criminal complaints.
And as I said, like, they're always really well written.
They're like miniature crime novels.
They're always great fun.
And you had a lot of fun reading this one.
But the reason we were jumping into this one, which is about Peter Stokes,
this guy's been extradited, is because there was a lot of people.
talking about the fact that the complaint mentioned this device ID from his Windows machine
that's being used as evidence against him. And that's called the so-called GDID. And it turns out
that in certain circumstances, every Windows box apparently has this unique hardware identifier.
And under certain circumstances, your machine, your Windows machine will emit this hardware
identifier across the internet like during certain O-O-OF events and whatever. And that's one of the ways
the FBI found him. Now, people freak it out and saying, oh, look, it's
this secret Microsoft identifier, which is how this guy got caught. Not really. We've got another
link in here looking at work. Alison Nixon has done in just like doxing and tracking these guys.
They have terrible Opsic. He was doxed about six different ways. So, you know, that's not really
how they found him. But it did get us curious about what is this GDID, how frequently does it emit
and in what circumstances. And it turns out it is, yeah, it is used in like web. It is emitting.
when you turn on certain forms of like advanced logging and only God knows why Peter Stokes had
this turned on. But that's sort of what you turned up, right? Because you've been looking at this
for a few days now. Yeah, that's exactly right, Pat. Just a slight subtlety there. GDI is actually
a combination of a hardware and a software identifier. It's the combination of that instance of Windows
installed on a particular piece of hardware. The hardware signs a certificate with that software
install generated ID, right?
So it is basically a stable identifier
for that installation of Windows
running on that particular device.
All of that, though, is kind of being overhyped
because the reality is that this identifier,
all platforms have it, right?
Apple has similar identifiers.
GUID, right?
In Apple land?
Yeah.
Exactly.
It's not about this identifier existing.
It's about what the platforms do with it.
Now, in the Microsoft case,
this is emitted basically any time
you're talking to a Microsoft service. And also, when you're interacting with a website that
supports signing in with your Microsoft account, and that was the first, I think, thing that I latched
onto was, oh, okay, he must have used his Microsoft account, signed in somewhere. They've snapped
the GDID through that. But it's actually a little bit more interesting than that.
Reading this criminal complaint, it was, first of all, correlation of IP addresses, right? The
OPSEC was laughably bad. Yes, they were using a VPN, but they were using the same VPN endpoint
to sign in to the Google Voice account to do the social engineering and then signing in with
their NGROC account to expelrate the data, just all of this stuff lined up.
But that doesn't explain how Microsoft was able to provide in this investigation actual
browser logs, right?
They don't have access to this device, we assume.
They had access to a server that he was using.
And yet they were able to provide correlation and saying, yes, we can confirm we see in our
telemetry that yes, they did visit NGROC, they did visit this particular URL, they have been
signing in with their social accounts.
But here's the subtlety that I've found.
N-GROC does not allow you to create a new account
using a Microsoft ID.
So it's not via that channel.
Creating a new N-GROC account, you can do it either
sign in with Google, sign in with GitHub,
now that's a Microsoft property,
or sign in with an email address.
In this case, they used either an email address
or a sign-in with Google,
because we know that it was attributed back
to this Google account that was also used
for Google Voice for the social engineering attack.
So all of this points to actually Microsoft had their own independent source of browser history from this guy.
That is only possible if A, he was using Edge and B, he had, or somehow it had been turned on the advanced diagnostics feature, which does cause Edge to emit browser history with your GDID attached to Microsoft's servers.
So that seems to be the thread that really ties the GDID together.
Yeah, so I think the key takeaway here is that it doesn't look like.
Microsoft just sprays that all over the internet in a default mode, right?
So that's, and I think that's what people were scared about.
You saw a bunch of threads on various aggregators and whatever.
Well, that said, though, it is easily accessible on the local machines.
So any running app can snap it up, but yes, Microsoft's not spraying this around.
Can I give you the real takeaway, though, from this one?
Don't F with Allison Nicks.
I mean, she's like John Wick.
It's ridiculous.
Even the, but the com people will say that too.
Yeah, we've got a link into Kim Zeta's write-up of Alison Nixon's work in tracking these people,
and you can find that in this week's show notes over at risky.biz.
But yeah, absolutely, you are going to get doxed if you mean to Alison Nixon.
We've also seen a member of the 764 Splinter Group sentenced to 40 years in prison.
This is the group that wants to undermine society by causing discord by engaging in the online
sexual exploitation of children just with the goal of creating as much harm as possible.
40 years is not long enough.
I hope this person suffers from a long, serious and painful illness while receiving the
worst health care that your fine country has to offer, Chris, just a revolting human being.
We've seen an Interpol cybercrime crackdown.
5,800 arrests across 97 countries looks like, I mean cybercrime, is it cybercrime?
I mean, it's like social engineering with cyber elements and whatever,
but it's great to see large-scale arrests taking fraudsters down.
And now let's talk about this so-called Gold Eagle clearinghouse for AI cyber threats.
This is a White House initiative.
They have spun up this, I guess it's like a cert-style clearinghouse for vulnerability information.
There's AI triage.
You know, you would think that this would be run out of SISA,
but the White House really doesn't like Sissor.
So apparently this is being run out of treasury with input from Sissa.
Chris, you are plugged into all of the relevant grapevines here.
What can you tell us about Gold Eagle?
So, you know, it's a little, this one.
Let me start where at the Sissa point.
You're right.
If the government was to establish a industry coordination mechanism,
like this. The obvious place is to put it where Congress intended it to be in that, that would
be SIS. It's actually in the law that SIS is the general coordinator for infrastructure risk.
And they do things like this. With CERT CC, they run the CVE coordination program out of SISA.
They have things like the joint cyber defense collaborative, which brings together different bits and
pieces of industry. And that's where it's supposed to be. That's what Congress is.
Congress intended. And that's how the U.S. government is supposed to work, by the way. The Article 1, the Congress says, this is the law. This is how the things are supposed to be in the article 2. The executive branch says, okay, we're going to go do it that way. Not happening here for obvious reasons that this administration doesn't seem to like CISA very much. And you've touched lightly on the reason for that previously in this very podcast. So, yes, so they get to that executive order from a month or so, a what, early June?
and Treasury gets tapped with the responsibility of this coordination clearinghouse, whatever.
It's called Gold Eagle.
I almost want to say Golden Eagle every time.
I don't know what's Gold Eagle anyway.
It doesn't matter.
Treasury doesn't actually have the in-house capabilities to do this sort of work.
In some cases, they don't even actually have the authorities to work cross-sector.
So they have to rely on Siss's authorities to even get this thing done.
and they're building the infrastructure
because again, remember they don't have this
so they're building it right now.
And in some cases, as I'm seeing it,
it's actually industry in the finance sector
that is kind of helping them guide them along,
kind of telling this is how you do it.
These are things you need to think about.
So as it stands now,
I think this is just kind of a front door,
a thin veneer,
and then there's some kind of manual process behind.
But, you know, it really remains to be seen.
if this is a functional capability right now.
I don't think it is.
We'll see what it looks like in a month or two.
Yeah, yeah.
All right.
We've got to whizz through the next items here
because we are running out of time.
Code is law.
This is a very funny story
where there is something called the Bonk Dow,
where there's a Bonk cryptocurrency
and someone bought like $4 million worth of this cryptocurrency
so that they could vote on a governance change
and get a quorum.
and they voted themselves 20 million bucks
and that's very funny because code is law.
Code is law, you don't need no stinking financial regulation
because code is law.
Yeah, and look, great return on investment.
You know, a $4 million buy,
influence the decisions, $20 million out.
Good job.
The real head scratcher here is,
how does a cryptocurrency called Bonk
have an aggregate valuation of $400 million?
Usually, I can actually answer that, James.
which is usually they don't have any market depth at all.
So, you know, there's someone who's trading up like, you know, 10 tokens
until the token value is really high.
And then they just say, well, obviously, if we sold all of the tokens,
it would be worth this much.
But of course, there's no depth in the market.
I mean, but obviously there was $4 million worth of depth because that's what someone spent to buy them.
Now let's see if there's $24 million worth of depth.
Now that they have $24 million, right?
So who knows?
Who knows if they even get paid?
But just a very funny story.
We have also seen obviously like when I came back to my news triage queue after a couple of weeks off, oh my God.
You see people saying still on social media, a lot of people working in off-sex saying, oh, this bugpocalypse thing's all hype.
It's not going to happen.
We're in the middle of it.
It's happening right now.
We got a SharePoint bug out there being exploited in the wild.
There's a bug in WordPress core.
I heard about that one on Sunday here because Dylan O'Donnell, who has done WebExploaded.
to have work for us. He's a friend of mine.
Got in touch and he's just like, man,
this WordPress bug's pretty bad.
So he was working on a Sunday to deal with all of the WordPress stuff he looks after.
He managed to mitigate that.
And good thing he did because that one's being exploded in the wild.
Congrats too to Dylan for finishing off his last round of chemo.
That was he got his last infusion last week.
So well done, mate.
Look forward to seeing you when you're feeling a little bit better.
And yeah, we've got a critical service now bug as well.
a critical in Palo Alto VPN being exploited.
There's been a bunch of incidents as well.
Coca-Cola's like dairy line of products in the United States
that that line has been shut down with a ransomware attack.
There's been heaps of them.
You mentioned though, James, and just very briefly,
the service now bug looked actually pretty interesting,
the one that's being exploited in the wild.
Yeah, the other's a sequel injection, but this one's neat.
It's like a sandbox escape using a gadget.
I mean, it's just when you hear that sort of thing,
you're like, oh, okay, that's some real.
in-depth stuff that's not surface level so that was good to see is this the one where you could actually
just stick a binary into like a dot net binary into a cookie field or something and they would just
execute it no no that is a hundred percent share point oh that was the share point one sorry yeah yeah
yeah and and so it should be yeah yeah yeah exactly i sorry i got that one mixed up uh we've also seen a
lawsuit that's pretty funny where magnet which is like i think they bought like gray shift or gray key
or whatever they're called um they are suing
one of their former employees for burning one of their bugs,
for allegedly burning one of their bugs.
So the US Bliterate bug,
which is an unpatchable hardware level bug in a bunch of Apple Gear,
which is very handy for these forensics firms.
Their allegation is that this guy left,
joined a competitor,
and then they blogged about that bug and thus burning it.
This is the blog where they've got their own description
of how they discovered this blog,
which is not, hey, we hired a guy who happened to know about it.
So one of two things has happened here.
Either a disgruntledex employee has burned their former employer's bug,
or there was a case of parallel discovery, and this guy is completely innocent.
But either way, there's a lot of, yeah, there's lawsuits flying around,
and it'll be funny to see what happens in discovery.
Parallel discovery on such old hardware?
I'm not sure I buy that.
I think that that was a neat little story they concocted for a bit of plausible deniability there.
But that is just conjecture, and we have to wait and see what happens in the courts.
Please don't sue us based on what James says.
What else do we got?
We've also got Apple suing OpenAI because it's complicated.
But basically they're saying basically an ex-Apple employee went to Open AI
used their Apple issued laptop to conspire with another Apple employee to steal a bunch of like schematics and whatever.
And they carried this all out in full visibility of Apple's like security teams because they did it on
Apple-issued devices, just so dumb.
And now it's turned into a big lawsuits.
You know, anything Apple you're always interested in
because you used to work there.
But you've looked at what some of the Apple analysts are saying,
and they're like, it's not really about the theft of the IP.
It's just a really good excuse for them to go after
this one particular ex-Apple guy who is now at OpenAI
and is poaching a bunch of their stuff.
Yeah, this is 100% about talent.
There's a former VP of hardware engineering there.
He's been siphoning up all the talent.
He had a bit of a falling out with John Turner, who's now the CEO.
That's what it's about.
But Apple hasn't had a way to really prosecute him because, you know, it's difficult around,
there's so many laws that protect people to be able to freely move between companies.
But in this case, it just happens that he managed to hire someone that just did the dumbest of things
in terms of how they exfiltrated data.
And, yeah, it's literally like sort of handed Apple a lawsuit on a silver platter so that they can go
and file it and go after this main guy.
Yeah.
Apple is playing the role of the.
market diffusionist right now. That is the fear group that they are representing and that they are
trying to stymie that consolidation of market talent. And to quote Star Wars begun, the tech
war has. Yeah, I think it's, yeah, I really like this, that whole theory that it's everyone's just
motivated by their fears and you need to analyze this whole thing from, you know, look at the person,
what are they scared of and that dictates their position. It's a very clever way of looking at it,
Chris, I really enjoyed that.
What else? A couple more that we're just going to talk about quickly.
Apparently, there was Pegasus spyware turning up on a member of the Pegger committee in the European Parliament.
So that's very on brand for NSO, which is to go and hack the committee member of someone who is investigating you.
I mean, it never ceases to amaze me how low they stoop.
Amazon is fixing a bug that gave people.
bills for billions of dollars in their AWS console. I wonder how many suicides may have been
triggered by this bug. But I mean, I guess not because they were like in some cases trillions of
dollars, which is very funny. So yeah, that's that's hilarious. I wanted to give a shout out to
this week to Catalan Kimpanu, our colleague who was on the top spot on hack and who's with his
scoop that a hacker wiped Romania's entire land registry database. So well done to
and for that one. And yeah, that's basically it for this week's news. But we are going to talk just
quickly about this story, which is because it dovetails nicely with this week's sponsor interview.
But Microsoft is saying Entra is going to be pass key only from next year. No more SMS or,
you know, voice-based MFA. This is cool. This is a cool idea. It's about time. But James,
you're still sort of surprised they're being this aggressive on the timeline.
Yeah, look, it's, it is a line that needs to be drawn.
And when I read the article, I thought, yeah, good, this is great, but I bet it's like, you know,
2032 before they actually, you know, cut off these other channels.
But to my surprise, it's February 1 will be when there is no more telecom delivery for SMS
and voice authentication codes.
And that's a good step forward.
That's really good to see, I think.
It's proactive and it's happening pretty quickly, but that's what needs to happen to lift this game.
These are the sorts of things that at least align with some of the NIST guidance and try
to deprecate SMS to FAA. That's been years, and so they're catching up here. Just pass keys
make it easy too. I mean, everything now is just bang, bang, bang. I don't mind it.
Yeah, I mean, I think it's like overwhelmingly a good thing, but we'll find out why it's not
the complete panacea in just a moment, but let's wrap it up there. Chris Krebs, thank you so
much for joining us in the news segment. Just fantastic to have you here. It's always great to catch up.
Thank you for joining us. And James, thank you also.
Yeah, my pleasure, Pat. Thank you.
Thanks, Pat. Good seeing you guys.
That was Chris Krebs and James Wilson there with a check of the week's security news.
Big thanks to them for that.
Well, I guess it was a check of the security news of the last few weeks because I've been away.
This week's show is brought to you by Push Security and Push's Luke Jennings.
Join me for this interview a couple of weeks back.
Push make a browser extension based product that can see what a user sees.
right? And the reason this is useful is it can stop people from getting fished.
And it can also help to stop, I guess, what you call authentication or authorization fishing, right?
Which has become really popular. It can stop things like click fix. It can stop things like a consent fix and it can also stop some of these device code fishing grants that are becoming extremely popular with attackers.
And the reason they're popular is because they get around things like pass keys. You can pass key authorize.
a device like a smart television into your account.
And of course, attackers know this,
and you could wind up authorizing them into your account
through this method as well.
So Luke joined me to talk about why attackers are switching
to these types of techniques
and what they're doing about it at Push Security.
Enjoy.
We used to see very much authentication layer attacks,
a lot of attacker-in-bill fishing.
Now, we still see those attacks,
but they used to be the dominant attacks.
And what we've seen now is as a sort of
move towards attacks against the authorization layer.
And I think that's, you know, a big reason, or one big reason for that is because we keep
adding new authentication controls making it stronger, particularly people are gradually
moving to pass keys now as well.
And authorization attacks just completely bypassed that.
So like, you know, last year, at the end of last year, we saw a new attack we termed consent
fix in the wild.
That was pretty targeted at the time.
we haven't seen that go completely mainstream yet but it is available for sale but what we have
seen is a different authorization layer attack take off completely and that's device code fishing
just before you go under device code fishing just for those who don't remember consent fix was
this sort of like click fix style authorization attack that was quite convoluted it basically
pretended to be a cloudflare turn style and then told the user to go through like this
authorization challenge with their Microsoft services
then cut and paste a URL into a local host thing that passed a token to a thing,
but that's actually how they would manage to get a token that would grant access to the account.
Whereas device code fishing, which is the one we're talking about now,
that's the same sort of fishing technique that you would use to connect, you know,
your smart television to an account or whatever.
Like if an attacker can set up that authorization flow and then capture that code,
they get a token that comes into your account.
The thing that's really handy about that one is the attacker doesn't need to have published
some malicious O-O-OF app, they can just use a token that would enable a smart device into the
account. So it's just like a direct access token. It's long lived. It's pretty much the Holy
Grail at the moment. And that's the one that you guys are seeing just everywhere, right?
Yeah. It was very much, in February this year, it went from almost never seeing it to just
daily overnight. Like the first kit is now known as evil tokens. That was sort of dominant,
but we were tracking new ones spinning up constantly.
We track like over 23 different kits now.
Eventually the FBI has put out some advisories on some like one called Cali 365,
but there's more than two.
Trust me.
We see so many now.
So that's just become like a tier one threat.
It's hitting every sort of industry vertical.
It's just a widespread criminal threat now.
It's not just attack and middle fishing.
Device code fishing is just a daily threat you need to consider now.
Well, and there's not much.
you can really do about that in terms of like pass keys and like even uber keys and whatever
because the attacker is actually authorizing that device the device just happens to be in the
possession of the attacker right so it is past key verified you can phyto authorize it but unfortunately
you're pha authorizing something malicious yeah that's it yeah it's exactly that it works
past the authentication point so yeah like they've already authenticated and that's the thing the
user they're not trained to deal with this scenario other than not giving away passwords they're not doing anything
like that, they've already authenticated, that just click it, enter in a code you've given them
and click into allow the device and then that's it, full compromise.
Yeah, so that is pretty nilely. So I'm imagining that this is something that given your
position in the browser you're able to see pretty easily, you know, there would be, because
you're going through like a legitimate authorization flow, you're going to know when that's,
when someone is being asked to, you know, put a device code into a page.
page, right? So that is something you'll be able to see and stop? Is that? But how do you handle that
when someone's trying to like do that legitimately? Because at that point, you've got to decide,
well, is this a legitimate authorization attempt or is this malicious? Like, is that the challenge
for you now? Yeah. Well, I mean, we've got a few different layers that we use to deal with this.
Like, we obviously analyze all the kits that we see reused all the time. We build very generic
behavioral rules for those and we'll just straight up block anything that we see that we've, that is
known kit we've seen before. It doesn't matter if it's on a new URL. If it's any way related to
something we've seen before, we'll block that. But to the next layer, like for that sort of zero
day protection, we can actually just stop people entering codes into the browser if you want to do
that completely or provide a strong warning to the user and an alert straight to your sock to say
they've reached that, but enable them to click a button to go through if you need to enable that
flow under certain scenarios. And we also have internally, we've got sort of agenic threat hunting
loop we're doing, mining all the browser data we have, constantly looking for any new sources
of people going to device code URLs where it's coming from, that feed straight back into our
detection loop. So we're staying like very, very on the bleeding edge of this stuff. That's why we've
seen so many kits. Yeah, I want to talk about the threat hunting stuff in a minute, but I mean,
is there much of a corporate use case for a device code authorization? Because I mean, usually it's
about authorizing, yeah, like a smart TV or something. It's not really something that I think
of being used a lot in a corporate environment, but I'm sure there's edge cases, right?
Yeah, so I mean, I think it was originally intended for those kind of cases,
but in reality it's ended up being used for things like video conference kits in
meeting rooms and the other like printers even.
I mean, they are basically a smart TV, right?
They've just got a camera and IP stack in them, but yeah.
Yeah, yeah.
But it's also like been used quite a lot by CLI tools and a lot of dev-related things too.
So there's like other people have found legit use cases for it.
And so, yeah, it kind of depends on the complexity of your environment.
You need to like look through your logs and see where it's being used legitimately and figure that out.
But yeah, there are, you know, it's there for a reason.
So it's not always easy to just try and block the whole thing.
Yeah, I guess the advantage though is that quite often when you're seeing it,
it's in the context of being delivered to a user via a known fish kit.
And you can actually just say, how about no?
Yes, exactly.
So yeah, we always know it's going to end up at that point and we can track where it's coming from.
And that's how we find the new kits out there.
Now, you did just mention the threat hunting component of this,
which I find really interesting, right?
Because there's no one else really.
I mean, look, I guess that's not true anymore.
You do have competitors these days,
but like for a while there you didn't.
Not many people have the browser telemetry that you have,
which enables you to actually do threat hunts through browser telemetry.
Like, I don't think the EDR companies have anything like this, right?
So you've got this like really rich, beautiful data source
that you get to comb through.
And of course, you've got little digital.
critters, aka agents, that you can unleash to go and ferret around go dumpster diving in all of that
data. What does a typical threat hunt through that sort of browser data look like? How do the
agents know what to look for? How do you task them? Tell us more about that. It's interesting.
Yeah, I mean, it's very powerful. I mean, it's almost like each browser is acting like a kind of little
flight recorder of all the actions and user interactions and network requests. So everything going on
inside the browser and we've got our own custom query language so we can issue
huts across our entire customer base to do that so like if you if you look at something
like device code fishing here we can go and say look let's look at anyone ever visiting a device
code URL and look at how they got there what what their interactions were in the browser
and we've we've just got a very rich source there and we basically can find any new kit
pretty much by doing that that's so funny it's it's it when you turned that on it made so much of a
difference for detections was like not okay so you've got visibility of the rendered page right which is
what separates you from some sort of mail gateway or some sort of proxy that's trying to do inspection on this
on this sort of stuff right so you're actually seeing what the user sees so it's been through turnstile
it's been through all sorts of obfuscation and gating you're actually seeing that final uh payload
but the big unlock for you guys was actually when you said okay well we've looked at the page
and we're pretty sure it's bad but like let's add some additional logging so we can
can see how the user got there and then it became really, really clear, hey, they just got
redirected through 26 URLs in one second. Yeah, probably this is no good, right? Like,
that is going to be some of your most reliable indicators, yeah?
Yeah, certainly. Like, that's really enabled us to get the sort of much rarer cases and the brand
new kits that we've not seen before. And then, yeah, that feeds into us writing the behavioral
detections that work on those kind of rendered pages as well that can just auto block there and then.
So like between the two of them, you know, they both, they both accelerate each other.
So like once we unlocked both of those features, it's that's, yeah, that's why we're sitting
there talking about 23 kits when, if you look in the media, you've probably heard of maybe two
device code fishing kits.
Yeah, we can just stay ahead and find all the new things, even if they're rarer.
Yeah, yeah, no, that is, it's funny.
And I wonder at what point some of these.
fish kit operators or the customers of the fishing kits more so.
Because currently as part of that ecosystem, there's all of the redirects, right,
that bounce the users around and then eventually land them on a payload page.
You sort of wonder when they're going to start to tighten that stuff up
because they know defenders are starting to look in the browser.
That's when you know, like you look at stuff like Grey Noise, for example, right?
Like one of the reasons residential proxy services have become so popular among APT groups
is because of services like Grey Noise being able to flag their static, you know,
limited proxy networks and now, you know, they've had to radically expand them, right?
So, I mean, you've got to be waiting for them to do something here.
But that said, I don't know that there's all that much they can do given that infrastructure
is in place, the redirect infrastructure and everything is in place for a reason.
Like, I don't think they can eliminate that.
No, yeah, they put it there to deal with like mail gateways and other things that are trying
to follow it.
But it's much harder for them to sort of circumvent that in the browser because the whole
point is you're you're with the user following the real target around the whole time.
So, you know, they can't really get away from that.
So, yeah, I mean, it's difficult to know.
We'll see, I'm sure they're going to try to adapt in some ways to deal with this as it becomes
more common, but, you know, I think it's going to be tough for them to deal with.
Yeah.
Yep.
Now, look, one thing that's worth mentioning here is the role of AI in all of this.
You say AI is accelerating the development of the fishing kits.
you also note that the number of like OAuth tokens just sort of in existence these days is extraordinary both because they're used by agents and also all of the supporting infrastructure that sprung up for for AI is very sassy and everything is sort of integrated via via OWTH tokens so I mean I guess the long story short there is we're going to see a lot more we're going to see all of becoming and authorization tricks becoming a lot more relevant to sort of
you know, security practitioners, I guess, in the next incoming years.
Yeah, that's definitely the case.
I mean, yeah, I think there's a couple of assets there,
like coming back to your original point, like,
I'm pretty sure all the kits that we've seen recently for this
have been developed with AI coding tools.
That's why they've come about so rapidly.
You can also tell just from looking at the underlying code.
The sort of handcrafted, obfuscated kits that we used to see before
have a certain tell and then you look at the new ones and the thing is that they're less
obfuscated that's one that's one giveaway is because they've been nicely documented i think by the
i are writing them but then yeah on the on the oath side i mean um there's always been a lot of
interconnections with between different sas apps with oath and and people are a little bit blind to
that without being seeing those interactions with inside the browser but i think the the advent of
a i tools means there's just more of them happening now because there's more you know everyone
wants to integrate their favorite AI tool into every other SaaS app to pull data and it's becoming
like a central point of all those interactions and so yeah like I think we're going to see a lot more
general o-off attacks and sort of stealing of tokens from compromised identities and accounts in the
browser going forward it's it's kind of inevitable as we build up that layer of risk I think
so I guess look the baseline expectation is we're going to have to be doing like everybody's
going to have to be in the browser with at least one, you know, some tool chain or another
if they want to be able to spot this stuff. Because like you can't fly blind anymore, I guess,
is the TLD. Yeah, that's true. I mean, I think all the tricks that the attackers are using for
these attacks to get around traditional solutions, like if you really want a good defense here,
you have to be with the user where they are seeing it and that that is in the browser. It's the
only way to do it well now. Yeah. Yep. All right, Luke Jennings. Thank you very much.
much for joining me for that conversation, all about OAuth tricks and threat hunts.
Very interesting.
And we'll talk to you again soon.
No problem.
Thank you for your time.
That was Luke Jennings from Push Security there.
Big thanks to them for that.
And yeah, push security is a great product.
If you want to push, hey, no pun intended, push your fishing preventions out to the actual
endpoints, not just rely on things like your email security gateways to do your fishing
prevention.
but that is it for this week's show.
I do hope you enjoyed it.
I'll be back next week with more security news and analysis.
But until then, I've been Patrick Gray.
Thanks for listening.
