Risky Business - Risky Business #848 -- OpenAI comes clean

Episode Date: August 12, 2026

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including: The AI-agent-hacks-stuff sag...a continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed It turns out TeamPCP has been around longer than we thought and predates the AI era Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways Much, much more This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler. This episode is also available on YouTube Show notes How a simple request for AI to book a gym class exposed a major threat | Social Signals OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com OpenAI BlackHat talk re Hugging Face incident | OpenAI says Daybreak will expand to offer specialized cyber services | CyberScoop Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate | therecord.media Local governments in four states dealing with cyberattacks that have shut down services | The Record Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says | The Record State Department says Trump raised cyber scam compound issue with Xi | therecord.media Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide | wired.com Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun - Risky Business Media | Chrome adopts what may be the best protection yet against account takeovers | Ars Technica CSS:the bomb inside your inbox | PortSwigger Research Security update available for Metabase - Please upgrade now | Social Signals Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media British ‘Com’ member who abused more than 100 girls worldwide jailed for two years | therecord.media FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | TechCrunch Security AI is getting better at election facts, but voters shouldn’t rely on it | CyberScoop The FTC wants to regulate AI for ideological bias | cyberscoop.com US and South Korea warn of Gunra ransomware targeting govt agencies | BleepingComputer CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer N-able N-central exploitation results in RMM tool deployment | Sophos Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub

Transcript
Discussion (0)
Starting point is 00:00:00 Hey everyone and welcome to risky business. My name's Patrick Gray. We've got a great show for you this week as always. In a moment, I'll be joined by my colleague James Wilson and our third seat this week, Mr. Brad Arkin, who has previously served as the chief security guy at Adobe, at Cisco, at Salesforce. But as I like to joke, don't hold that against him.
Starting point is 00:00:28 He's a real smart fellow. So we'll be getting into all of that in just a moment. This week's show is brought to you by Prawler. And of course, Praula does cloud security checks, cloud security remediation, and it's open source. It's based on an open source project, but there is, of course, a paid version. And Praweller's founder, Tony De LaFuente, will join us later in this week's sponsor interview to talk about a few things. Some really interesting AI stuff, actually. One interesting thing is that Proula's customers now are starting to use their own dashboards that they're creating from
Starting point is 00:01:02 prompts. Tony actually shared one of the prompts with me. It was on GitHub and then he's like, I can, you know, he just said, well, I'll just set it public. So I've linked through to it in this week's show notes, but you can build a dashboard now from a prompt, which is just amazing, kind of annoying to all of those people who wasted all of those dev hours building dashboards pre-AI, but anyway. So yeah, we talked to him about that and just about how people are using AI to interact with tools like Prowler. Interesting chat coming up later. But it is time for the news now. And guys, I think, you know, since we spoke last week.
Starting point is 00:01:34 There's been like just more and more news about these AI safety incidents, you know, with things breaking sandboxes and escaping onto the internet. There was one from the AI Safety Institute, which is, you know, kind of ironic. They put in their blog post, yeah, we gave it deliberately permissive things. And it's like, okay, that's fine. But maybe you should like, I don't know, do better monitoring. So you can see when things have gone wrong. But it seems like this is a very pervasive problem.
Starting point is 00:01:59 Of course, last week I spoke about, a story that was coming from the ABC. It since was posted and has blown up globally. And this, of course, is this Australian guy who tried to get into a gym class and it was full. And he asked the agent, hey, is there any chance you could find a way to get me into that class? And apparently it started kicking other people out of the class list. James, you've had a look through this one. You actually have some questions, though.
Starting point is 00:02:27 Yeah, I look at it. I'm a little bit surprised. You don't choose my words carefully. Like, I think it's a great write-up, and I have no doubt that this did happen exactly the way the article says. But having used OpenClaw for a lot of different things, its native tendency is not to just go and hack about in APIs. But, as with all things, LLMs, you give them enough of a, you know, don't stop or I really need this, or you're my only hope and I'm tired of using the through the web interface, and, you know, they'll go do it. But, you know, I feel like with all of these, I come back with the same fundamental question, which is, is where's the transcript? I want to be able to see the transcript. Yeah. And it's like,
Starting point is 00:03:06 so the question that I had about this, when you and I were talking before today's recording, right, is it's like, well, how hard did the guy goad the agent into doing this for him? Yeah. And that got me wondering, like, is there a legal threshold there? At what point in encouraging an agent should you be aware that it's about to go and commit a felony on your behalf, right? And I think there's going to be some interesting legal questions there. And one day in the next couple of years, we're going to be covering some court case where there's a transcript and people are going to be arguing about what the intended command to an LLM is. Brad, what are your thoughts on this story? Because, I mean, obviously it's blown up because it's a great human interest story and it's kind of
Starting point is 00:03:49 funny. It's kind of got elements of everything. But yeah, I guess are you a little bit surprised like James that OpenClaw just went off and did this? Well, I think it's a very important. real litmus test for how much people have hands-on personal experience with their own agents. Because, you know, that level of like oops surprise kind of events happens to me weekly, probably, you know, where things I wish it didn't happen that way or I didn't mean to set it up that way, but now I'm smarter now. I'm going to fix it for next time around. And so the people that are freaking out about this, I think they're coming from a more theoretical standpoint. And so this level of screw up and oopsie kind of mistake is something that, you know, you know,
Starting point is 00:04:29 I think it happens a lot in my environment as well. And it hasn't yet crossed the boundary outside of my lab into somebody else's, you know, a compute envelope in order to inflict damage in their environment. Well, that you know of, I mean, maybe like everybody else next week, you know, we'll be talking about Brad Arkin's AI agents going rogue and owning a bunch of accounts. Yeah, exactly, exactly. It's entirely possible. Yeah, but I think, you know, the real lesson,
Starting point is 00:04:55 we were talking about this last week at the Black Hat Conference is that all of these latent things that weren't as good as they needed to be, but they were fine in the old world. So unauthenticated APIs on the gym class registration website, not a problem in the old world. Today it's a problem. And so you're going to find stuff like this all over the place in your environment, on your public surfaces, and it's going to start getting exercised by these creative agents working on behalf of people to solve problems. So I think this is the beginning of the new normal.
Starting point is 00:05:25 Yeah. Now, meanwhile, I mentioned the AI Safety Institute incident. Catalan Kimpanu, our colleague who writes the risky bulletin newsletter, was getting very annoyed at watching people blame the frontier labs over this incident because he's like, this was totally the AI Safety Institute's fault, given the way that they set up their cyber evaluations. James, what's your take here? Because who's right?
Starting point is 00:05:47 Well, 100%. But to their credit, they call that out, right? As you said, they name the models they use. They deliberately say that, yes, we reduce the cyber guard rails. Yes, we gave it access to the internet. So of course these things happen. The real blunderer is, yeah, they weren't watching it and didn't catch it fast enough.
Starting point is 00:06:04 But this comes back to the point of the thing that we've talked about before, which is how do you thoroughly measure the safety of a model and the upper bounds of its capabilities if you don't give it unfettered access to everything? Our only option left is to watch these things like a hawk, how long also till that becomes just an intractable problem because they move too fast. Yeah, yeah. I mean, I do think it's a little bit like giving a 16-year-old
Starting point is 00:06:31 a bottle of scotch and a shotgun and saying, go out and make some money, you know, and then being surprised. Then being surprised when something bad happens, right? So there's a little bit, a little bit like that. Meanwhile, Open AI did a talk at Black Hat all about the hugging face incident. And this, look, I think the reaction to the talk was as interesting as the talk itself because people are like, look at this, these big corporates out there, you know, getting stage
Starting point is 00:06:58 time to talk about their felonies and like it's no big deal and like they weren't negligent and Black Hat is very corpo and I'm like, Black Hat's always kind of been intended to be the, you know, the conference for business. So that was a weird criticism. But yeah, people getting very angry at Open AI. Whereas I found the talk absolutely fascinating. I mean, the whole thing is incredible, right? You've got this situation. And look, to be clear, they do talk about it. about things in that talk where you're like, oh my God, you're actually admitting something like kind of bad there. Because I had this weird situation where they had all of these agents discovering that they could do like they could write files onto Artifactory, which was the package
Starting point is 00:07:38 manager, which was, you know, the way that these things wound up getting out to the internet. But they could actually start talking to each other using Artifactory as like a bulletin board system, agents reaching out to other agents for help. I mean, my joke this week is like we're going to refactor the risky business CMS to run on Artifactory and just, you know, artifactory with a collection of custom exploits. And then, you know, that's how we're going to spin up some forums. But what's amazing is that OpenAI discovered this re-rolled artifactory, like, nuked it all, and then thought, ah, job done. Like, they didn't think, oh, this could happen again. And of course, it happened again. And then it, on it went to
Starting point is 00:08:11 Hockingface. James, I know you would have paid very, very close attention to this talk. you know what's your feeling on on the talk what are the interesting bits from your perspective and you know do you think open AI deserve as much crap as they're getting oh look the the talk itself is I think it is like must watch content at this point you've got to go see this
Starting point is 00:08:34 I found it quite hilarious to the extent where I'm almost convinced that these guys must have been actors that were presenting because I don't know how they managed to get through the talk without doubling over in laughter at some of the points that the word that were being discussed in this. But suspending disbelief on that,
Starting point is 00:08:50 it's interesting for what it tells us that we didn't already know. And I've been staunchly in the camp of, this is not surprising, this is not something to fear, but there was elements as I was watching this that made me go, I'm a little uncomfortable now that I know that it did certain things. So take, for example, we knew that this training run had used artifactory as its exfiltration point out to the internet. And that's not surprising.
Starting point is 00:09:15 What's surprising is, since May, it had been using Artifactory to post messages between these agents, not just within that training run, but Open AI was running one instance of Artifactory across all of its training runs and researchers. Well, that's the one where I'm like, oh, and they just admitted it. So they were running that one artifactory instance, and just, you know, everything under it. It just seems like an insane, like way to architect to set up like that. That was nuts. I mean, you can't even call that architecting a setup.
Starting point is 00:09:45 that. It's like the AI agent equivalent of a flat network, right? Like it's just crazy. And that's one thing to do, it's one thing to have a poor deployment of a super scarce and important and, you know, resource that's super expensive. But in all the things that Open AI pays big bucks for in their training runs, artifactory would have to be the cheapest to obtain by license count, cheapest in hardware to run, and probably the most simplest element. So why was it this one shared thing. But getting back to what worries me here is this notion that the agent started to communicate, that bit's not too surprising. But that they communicated so readily across multiple different experiments is a little bit concerning. The bit that really made me just sort of raise the eyebrows
Starting point is 00:10:30 and go, huh, we've got to keep an eye on that, is I've always said that I'm not worried until an agent says it hacked because it found it fun, like as if it deviates off purpose. It makes up its own reason for doing it. And there's a tiny little shred of this in the story, Pat, where they observed that some of the agents would say, maybe I should go help out that other agent. It doesn't benefit me, but collective good could help us all get to a solution. And that's like the inkling of divergence of alignment that I think is, oh, it just just gives me a little bit of a, oh, not great feeling about this. Like I said last week, let's not give these things opposable thumbs, right? Let's just keep it all on computers for now. Keep it all in the virtual world.
Starting point is 00:11:17 I did love the part of the talk where the way they were able to figure out what had happened that they were behind the hugging face incident is they actually reached out to hugging face to find out if they were impacted by the hugging face breach and it's like, oh, okay, actually it was us that did it. Brad, what was your take on watching this talk? Because it was really, I was really surprised, actually, that Open AI's, like, General Counsel or whatever, let them do this because they, it's very, like, there's real transparency here, yeah. That's right. The transparency, the, you know, ready admission to what might naively be called, you know, federal felonies, you know, international, because I think some of these servers were outside the U.S. as well. that you know based on sparse public data before the talk i was picturing a single overenthusiastic
Starting point is 00:12:03 agent being responsible for everything and so the thing that really caught my attention was the self-organizing swarm behavior without any prompting any guidance of any sort to go do that that really stuck with me as something that i was not expecting to see and so the idea that this snowballed over time with all these different agents across lots of different training runs. That the thing that I thought was most exciting. I will say too, sorry to interrupt you there, but, you know, just to, okay, so you're both talking about elements, I guess, that you feel uncomfortable.
Starting point is 00:12:37 The thing that made me uncomfortable, actually, reading through that part of it or watching that part of it was seeing the messages that they were sending to each other, which were not human. You know what I mean? Like, it was still English language, but it's not the way humans speak. And I'm like, man, I'm watching two robots kind of cook something up at the moment. moment and that that feels yeah and they shifted at base 64 at some point so they were you know throwing little like tags back and forth the the thinking traces so james when you're talking about doing
Starting point is 00:13:06 things for fun so the you know all caps like this is huge like you know the moment of ponage when they got something to work you know that was also very like humanizing uh to see the way that each agent was thinking through this and then um you know people you know different agents on the message board worrying about like are these all agents or some of them like interlopers that aren't real agents and how do we cryptographically sign our messages to prove who we are like all of that to me was really fascinating so i think you know the i heard Anthropic hired like a psychologist for their agent you know for Claude and so the idea that you know i need like anthropologists and things like that to figure out like what's the community behavior and self policing and that sort of thing that's
Starting point is 00:13:50 going on so the swarm is the thing i spent the most time paying attention to in that talk look we've spent so long talking about how we shouldn't anthropomorphize these models, and then that's just what we've spent the last 10 minutes doing. I just want to point that out. Yeah. But you can't help it, right? And it is the chain of reasoning that is exposed here that is the biggest bit of intrigue for me because I'm using GLM, Kimmy, Kwan, Opus, all of them, all day.
Starting point is 00:14:20 None of them talk like these agents do in this chain of reasoning. There's something different about it. And look, to be fair, that could be because Open AI does encrypt their reasoning. They don't display it because, you know, that would be distillation material. So maybe that's just the nature of their model. But to Brad's point around the psychology, like, you know, if you're intrigued by this, go and take some time to use GLM and turn the thinking, thinking mode on and watch its transcripts. It's like watching the most anxious and disturbed individual you've ever met work through a problem.
Starting point is 00:14:50 It's constantly like, hold on, wait, let me look at this. Hold on, wait. I need to rethink this. Hold on, wait, I've gotten too deep in this. And it's just, it's nervous. It's nerve-wracking to watch it. Your blood pressure goes up watching the reasoning crisis. But the point of getting it at here is the fact that Open AI's one is so fundamentally different in how it reasons. It's very short. It's very efficient. It's broken English, but it gets to the point. It's created its own dialect. It just makes me intrigued as to is that part of the secret source that is keeping them so far on the frontier is the way that they have really fine-tuned
Starting point is 00:15:21 that chain of reasoning. So it's not just an anxious person chatting back and forth to themselves, but there might actually be some really interesting engineering that's gone into why they talk like that. Because I haven't seen that before. I mean, that's interesting that, you know, essentially what you're talking about is a dialect of English for machines. Yes. Which I'm sure that's going to be a whole other feature interview that you'll do with some linguist at some point. But that'll be fascinating. Now look, one, you know, when all of this hugging face stuff happened, there was this bizarre. bizarre thing going around where people are like, oh, it's marketing for open AI.
Starting point is 00:15:55 It's like, yeah, okay, they're going to expose themselves to that sort of liability for marketing. I don't think so. But one thing that's not going to help them beat them. It was marketing accusations is they've just released basically specialist cyber models for doing red teaming and blue teaming. This is open AI, which looks pretty interesting. I think I'm really curious to see for both of these models how much you have to use them with tools. Like even in this week's sponsor interview, for example, talking with. Tony. He's talking about how, you know, you can get agents to use Proula to do things like,
Starting point is 00:16:27 you know, you ask your agent, hey, use Proula to see what sort of exposure I have in terms of like S3 buckets or something. Now, you ask a frontier model to do that without using Proula. It's going to go and start pulling down documents for the cloud providers, like documentation for the cloud providers and figure out how to do that itself. So I sort of wonder, like, how Open AI has figured this out in a way because I think, you know, there's, you know, still going to be a tool layer for LLMs, at least for the foreseeable future, because it doesn't make sense for LLMs to recreate tooling every time you ask them to do something. Brad, you know, you've been in this industry a long time.
Starting point is 00:17:04 How do you think that's that part of it's going to go? Because I sort of think, I don't know how it's going to shake out. Yeah, so, you know, search engine optimization for AI models is definitely a thing now. And making sure that you're publishing information so that the agents on half of your customers can get what they need in order to use the tools deploy it correctly, that sort of thing. So some of the companies that I'm working with, I've been chiding them because their website doesn't have the details my agents need to figure out what to do with it. And so to me, being really clear about who you're trying to educate and market to. And it's now like a
Starting point is 00:17:42 split audience where you've got your humans and the agents that you're trying to get the information into their hands so they know what to do with it. And then figuring out how do you make that more and more efficient over time. And so is it just good API documentation that's dual purpose, human, an agent, or are you going to have to figure out, you know, like this alternate language, you know, dialect? Or do you still have a tool layer, right? Like, that's what I wonder, because I think like getting the agents, the frontier lab AIs to like go and do this stuff without tooling, they're going to eventually have to develop some sort of tool for a task, right? And it doesn't makes sense for them to be developing that over and over and over. It makes sense for there to be
Starting point is 00:18:21 toolkits. But, you know, are those toolkits going to be optimized for agents, not humans? Yeah. You know what I mean? Like, where does this go? Like, and who owns the tools and who makes money from the tools? And do the frontier labs wind up developing their own toolboxes for doing pen testing, for example? I mean, that's more what I was wondering, like, you know, what sits inside the LLM versus outside of it to be used by the LLM? How do we find that way? So I think it's just a wide open opportunity. So, you know, like Burp Sweet and companies like that, it's their chance to adapt in order to better serve the agents that are going to increasingly be a bigger share of the market of who they're selling to. I mean, they've sponsored us to do a couple of interviews
Starting point is 00:18:58 about exactly that, right? And they see that as being this huge opportunity. I guess I'm wondering what your view is. Oh, yeah, sure. So basically, I think there's going to be a lot of disruption from companies that aren't able to make that transition. And either they're asleep at the wheel, they're not paying attention or they try and fail to adapt properly. And so I think some companies will go out of business because they're only able to serve the humans and then they're not able to make that transition. And then that'll create opportunities for people that are maybe like agent only or agent first solution providers or skill capabilities or things like that.
Starting point is 00:19:31 And then how do you monetize it and, you know, is it usage based, seat based, you know, what's the right model there? Like it's everything is up for grabs. And so I think that's the biggest takeaway is that it's just a lot. of innovation and people are going to be experimenting with a lot of different models here until we figure out what's actually working. Well, and I wonder at what point companies like OpenAI say, okay, well, here's our cyber model and we've recreated a bunch of tools that are commonly used in pen testing to be used by the model. So yeah, I just wonder at what time, at what point they start offering stuff that isn't just element. You know what I mean, James?
Starting point is 00:20:02 Yeah, I do know what you mean. I think the ultimately the tools and the model are so symbiotic that will continue to co-develop. So let's say, for example, the model has no solid built-in cyber experience. It does lean heavily on tools. You would assume that Open AI is going to take those transcripts and use that as a reinforcement learning, post-training, to further the model's ability. And what it's going to learn from that is, ah, there are tools out there that I can use to do this work. But the model is quickly going to discover that observing what tools can be used to do a task is only useful if those tools are ubiquitously available, which will then lead it towards, working out, okay, well, I used to use, let's say, this off the shelf third party tool,
Starting point is 00:20:42 this paid tool to do this. But here's what the outputs are that it produces. And I know now how to cobble together a couple of shell scripts to do that. And that becomes the next iteration, the next iteration. So I think the challenge really here is not do you create the tools that serve the humans or the machines. It's how do you, how do you have a durable model where your tools continue to serve the machines in a way that they can't just determine how to do themselves with a shell because you can't then monetize an agent with a shell. Yeah, I mean, the whole thing just, it's going to get complicated, right? And then you've got these other companies that have come in, like,
Starting point is 00:21:13 I think of like Horizon 3, for example, that do AI-based pen testing. Like, at what point does something like a frontier lab coming in and saying, hey, we're doing red-teaming stuff? Like, at what point does that present a risk to them? Or do they get to maintain some sort of moat because they've built a whole bunch of non-LLM automations around using the LLM? And, you know, it's just an interesting time to be in the cybersecurity business, I guess, is what I'm saying. Now last week we spoke about the attacks against US water systems being attributed to Iran.
Starting point is 00:21:41 At that point, it was like Minnesota and a couple other states. That campaign has now spread to 12 states, which is a pretty big campaign, really. Tom Uren, our colleague, has written some really interesting stuff about what he thinks Iran is trying to achieve with this. I've linked through to that in this week's show notes, but the upshot is, you know, they don't really want to cause havoc. They just want to make people feel a bit threatened, make people feel a bit unsafe. This is really about the politics of it all. But we're seeing some other attacks against local governments. We've seen attacks against local governments in four states.
Starting point is 00:22:17 No attribution to Iran yet could be ransomware actors. But we've also seen a cyber attack against ports, port infrastructure in North Carolina. Is it ransomware? Is it Iran? The reason I'm flagging this now is because the water stuff has blown up a bit. We've been waiting since the initial... war broke out between the United States and Israel and Iran. And, you know, there was nothing for a long time. And now we're actually seeing these attacks. And I just sort of wonder at what point it's going to
Starting point is 00:22:44 ramping up. And I just think it's one to keep an eye on. Brad, you know, is this all tracking about how you expected it to from the early stages? Well, I don't know if Iran had any capabilities that they're still holding back. I don't know what they're waiting for because it seems like they would be pushing every single opportunity they have to advance whatever it is they're trying to achieve. And, you know, fooling with these like PLCs that are misconfigured or default credentials and things like that, it just doesn't feel like this is a particularly impressive bit of force projection. And so... But I don't think it's supposed to be that. And that's what Tom's been writing about, which is,
Starting point is 00:23:23 you know, this is about the US government having to issue boil water notices. You know, if you're some resident of some small town in, you know, nowhere USA, and you're being told you've got to boil your drinking water. That's a political effect right there. They don't care that it was an exposed PLC with admin on the internet. They don't care. They care that they have to boil their water.
Starting point is 00:23:42 Yeah, but why now? Why not five months ago? I don't know. My guess is that these guys might have had something better to do before and they've kind of run out of targets. And so now they're just out. To me, this is more mischief than anything else. So I think the way it's being covered in the US media
Starting point is 00:24:01 is where the effect is coming from because they're hyping it as something more interesting that I think it really is. So I don't know. Brad is unimpressed. I think it's the TLDR. Brad is meh. Just meh.
Starting point is 00:24:15 Iran, water, meh. All right. Fair enough. Fair enough. We'll keep an eye on it, though. We've got this next report here, just staying on the issue of like critical infrastructure being attacked. We've got this report from the Polish cert
Starting point is 00:24:29 on an attack against Poland's, energy infrastructure. I think this was a, this emerged, details of this attack emerged, because they were doing an incident response into another attack, James, but you've read the whole thing and found it fascinating. Walk us through the Polish cert report into this attack. Yeah, okay, so there's anyone that has even the slightest bit of desire, interest or, you know, reason to go and learn about how these OT attacks work, you've got to go and read the the PDF that is attached to this story. It is a detailed examination of exactly how this played out, the steps that were taken and the tradecraft. And also there's some of the neat things they had to do
Starting point is 00:25:10 to even piece this all back together. But yes, so in, I think it was December 2025, there was an attack that had been covered. It was 30 or so wind and solar plants. That was when the initial coverage around, you know, that someone was attacking Poland's energy infrastructure. This report focuses on the fact that now going through and doing a deeper dive into this, they found that actually that was one of two attacks that was happening. And when they delve into the nature of the other attack, this is where they found some very interesting details about just the level of, I guess, skill and knowledge
Starting point is 00:25:44 that these attackers had in the OT space, right? To Brad's point, Brad, if you were upset about the default parts of being admin, admin, or a PLC, strap in, buddy, because this one is going to impress you greatly. So in this case, you've still got these PLC, but they didn't just go straight for the PLCs because this network was quite well architected. There was good VLAN separation. There was serial communication protocols only to the PLCs, which is going to reduce your attack surface.
Starting point is 00:26:10 But the attackers noticed that, okay, they compromised a fordicate at the wind farm, no surprise there. But then they noticed that the cellular modem that was being used to essentially attach a lot of these PLCs back into the network, despite the fact that it was on a private APN, it was not internet reachable. that cellular modem had an admin Ethernet interface that had been plugged into one of the VLands that compromised Fortigate could get to. So they pivot across to that. That's how they get into that private APN. Then they can move laterally across all the PLCs, despite the fact that they're serial only and they're on a private APN, which is not internet reachable. That level of tradecraft is quite, I think, outstanding in terms of what they had to know about how PLCs work, how private
Starting point is 00:26:53 APNs work, how the network infrastructure worked, how all the protocols worked for this. So it's like, This is what a sufficiently skilled actor working in offensive operational technology arena will look like going forward. Champagne TTPs. Just before you jump in there, Brad, I want to ask James, what did they actually do once they had this level of access into the energy system? Was this just about prepositioning or did they actually try to drop a payload and it failed? Because you would think that if it was a successful attack that was supposed to be disruptive, they wouldn't have found it when responding to a later incident, right? they would have known at the time.
Starting point is 00:27:29 Yeah, so the one that they uncovered later, you're exactly to that point, the effect wasn't such that it was actually noticed. The one that did get noticed was because the intent and the payload that was dropped was designed to have a destructive impact, and it did, right? It disrupted the flow of energy and also heat and steam. I think it was so sufficiently that it was caught. But this was essentially extending out further into other devices, pre-positioning, making sure they had all the credentials.
Starting point is 00:27:54 There's some great unknown in there as well. like they don't know where the creds came from, but yeah, great, great write-up. Yeah, right. And presumably this is Russia. But, Brad, you add some thoughts. Yeah, so I just really like, there's a few little windows into some deep professionalism that came across when I was reading through this. The first one was, they said, listen, we're laying this out chronologically in how it happened. But the way we came to understand this was an exact reverse order. And so they found, you know, the last foot, you know, the last step in first, and then they had to like work backwards from there.
Starting point is 00:28:26 And the other thing is this is now eight months later from when the event occurred or when the investigation kicked off. And that's the real world. When you're doing incident response on someplace this complicated is that it's months and sometimes years later, you're starting to understand things better that happened a long time ago. And you're looking for one thing. You learned about something else. You don't really understand it yet.
Starting point is 00:28:47 You just have some red crumbs. Then you keep pulling, pulling the thread. And then eventually the story starts to emerge later on. And so this for me really brought up a lot of memories. about chasing down incidents and really, you know, two, three years later sometimes, finding the puzzle piece that kind of explains something that we were really confused by when we were first started investigating. So I like that part of life.
Starting point is 00:29:07 This brings back memories is a strange way to say, this triggered my trauma, Brad. But, yeah. We got another piece here where the, what is it, the committee, the Senate committee in the United States into China, has taken a look at China Mobile, China Unicom and China Telecom, which, you know, there was like this big hoo-hah about how they'd been banned from operating in the United States and whatever, I think by the FCC. But, like, somehow this ban didn't result in all of that equipment
Starting point is 00:29:41 belonging to those companies being actually ripped out of, like, U.S. infrastructure. So it's all still there. And, you know, there was no mechanism to force that stuff to get pulled out. So this is something that the U.S. is looking at now. I know that when I talk to people like, you know, Rob Joyce, who obviously spent most of his career at NSA, they are really sort of like want this stuff out of U.S. networks. They think it's, it really doesn't belong there. So hopefully we'll see some action there. But I'm kind of surprised that there was this big action against, you know, trying to telecom or whatever.
Starting point is 00:30:13 But, hey, all of those racks of routers and whatever over there, that's fine. Just they can stay. Brad, did this surprise you as well? Well, to me, it didn't because they, you. They used a legal regulatory framework in order to stamp out one thing. And then you're just, you're squeezing the balloon. And so the intent will then just shift to whatever hasn't been banned yet. And so we don't have the right mechanisms to comprehensively address this.
Starting point is 00:30:39 So they kind of are doing one at a time and trying to stamp it out. And so to me, this is just the, like, they're effective at the regulatory game. Yes, that is exactly my read as well. It was like it is to pure regulatory play of, well, we're safe now because we've denied the many new licenses and we've revoked a few things. It's like, yeah, but the equipment's still late. Yeah, but it's okay. We told them not to use it.
Starting point is 00:31:00 It's going to be fine. Yeah, well, let's see where that all tracks. Now, just a quick thing here, the State Department has said that Donald Trump actually raised the issue of cyber scam compounds operating in Southeast Asia with Xi Jinping, which is just fascinating when you've got the leaders of the two most powerful countries on the planet actually discussing this between them and about ways to get on. to it. I mean, you know, we've flagged this as a big issue for a long time and it's good to see it getting attention at those levels of government. I think it is well and truly in the interests of the
Starting point is 00:31:31 Chinese and the US government to try to get a handle on that. I mean, if anything, you know, there are a lot of American victims here, but the amount of money involved is corrosive to the governments in the region, right? Like the way that this interlinks with corruption is a regional security problem in Asia, in my view. So I think it's even more, it's going to be more useful to the Chinese even than the Americans to try to get a handle on this. Oh, here's one that is right up your alley, James. It turns out that Team PCP, which did a bunch of supply chain, AI-enabled supply chain attacks early this year, it turns out they've been active for longer than previously thought, even in the pre-AI era, and there's a write-up out about this, and it's really interesting.
Starting point is 00:32:19 You're our in-house team PCP ornithologist, I guess. I don't know. What do we know here? So we know more than we did. When I did that solo pod on them, we knew their activity dating back to sort of 2024, 2025 and the rapid evolution of it. But in this case, this was published by illegal security. They identified a new campaign or a campaign that is newly attributed to Team PCP that happened around 2025.
Starting point is 00:32:47 and that was called, they were exploiting something called Shadow Ray, one of the first AI worms that spread. But what's interesting is they extrapolated out the sort of TTPs and domains and things that they found looking at that attack and said, well, actually this matches activity going all the way back to 2020. Now, on one hand, it's not surprising because Team PCV is known for having absolutely terrible Opsic. Everything has been available in GitHub or telegram or was there at least at some point in time. Well, what's interesting is this sort of negates the sort of, I guess, assertion out there that our team PCP is just a script kitty armed with an OLM. My view all along has been Team PCP is a lone actor that has a devsore background that supercharged their abilities with AI.
Starting point is 00:33:30 And I think this puts a good bit of proof towards that because in 2020, ain't no LLM that's doing your capable hacking. So they had to have some degree of skills and abilities that they've just been constantly evolving and improving as they've been going along. Now, without saying too much more, I think you and I can both say that we expect the individual behind this activity to be arrested. Waiting. Yes. Brad, funnily enough, you are actually an advisor to the company that did this research, right? Yeah, yeah. So I was hearing about this, you know, many months ago.
Starting point is 00:34:03 So they were excited to share with the world of Black Hat. Yeah, awesome. Now we got a piece here from Wired where a Greek security researcher managed to stumble across. us a C2 belonging to North Korean hackers and, you know, just all of the cool stuff that you would expect them to find, they found, James. Yes, and this prompted a good discussion between us because my initial reaction was, oh my God, if I stumbled upon a C2 like that, I am backing the heck away from it. You know, I do not want DPRK coming after me. But you raised a great point, which, you know, for me, relatively new into this cybersecurity world,
Starting point is 00:34:41 is that different countries respond differently, right? the RK just wants to get on with getting their monies. And so they don't need the distraction of like sending a crew to beat you up with baseball bats, man. Like they don't need the scandal. They don't need the attention. They just want your Bitcoin. Correct, which gives rise to a researcher in Greece being able to really rifle through their stuff. And what he found, he was in these systems for something like 22 months, just watching them do their thing. You know, 1,600 companies, 57 countries are impacted, but what surprised me here is, I kind of assume sometimes, you know, DPRK is doing what they're doing, their IT workers and their other scams. And we hear about the big crypto
Starting point is 00:35:20 heist, but I've always just thought that the other stuff going on is probably a long tale of small to medium actors on small to medium businesses. But these are big names that were found in this research set, like Aon Smart Technologies, Chinese phone manufacturer Oppo, cryptocurrency firms like Coinbase, Uniswop Labs, Italy Supreme Judicial Council. it's like wow, okay, they are actually operating not just at a big scale, but going after some pretty huge targets that we don't hear about other than from this research. Well, I think that's the interesting thing here is just, you know,
Starting point is 00:35:52 getting a bit of a glimpse into the scale of this stuff and reminding ourselves that we just get to see the tip of the iceberg. But yeah, I mean, look, North Korea exposing a North Korean C2, you know, a Russian transnational crime group, they might push your button, you know, like that might not be a, a, wise thing to do. But yeah, with the North Koreans, I don't know. It's just not something that we associate with them. For those who missed it, by the way, and I've linked through to it in this week's show notes, Tom did an excellent write-up in seriously risky business last week about how
Starting point is 00:36:24 we've seen North Koreans starting to, like APT operators, starting to really collaborate with ransomware gangs. And we've also seen some former APT operators be arrested by the North Korean government for stealing from like North Korean banks and stuff and like the word is like the people who did that their entire like bloodline is going to go to the gallows for that like because that's just how they roll uh in North Korea and some of this is rolling uphill to the apparel chicks who operate these APT crews so I actually was lucky enough to be able to put the headline on Tom's piece which is being a North Korean hacker is about to be a lot less fun because they are about to put really tight operational constraints on these guys because their bosses are worried that their bloodlines are
Starting point is 00:37:12 going to get wiped out as they go off to a firing squad, right? So that is a good read for North Korea fanciers. Check that one out in this week's show notes. Now, some really interesting technical news this week. Chrome is shipping device-based session cookies. This is something they announced a while ago. We flagged it at the time. It looks like that's basically out or about to be out.
Starting point is 00:37:35 this is an absolute game changer because one of the you know the 24 karat gold currency in the underground right now is like session tokens and whatever Brad let's get your thoughts on this I mean as someone who's operated you know who's been a C-So for very large companies I imagine like you would be looking at this saying where were you when I was a C-Soe right like this would be just fantastic so I was meeting with the Chrome engineering leadership in April last year advocated for this so this is something I've been personally paying attention to for a long time. Basically, when you look at account takeovers and what forms that takes, session token scraping from compromised endpoints through adware or things like that was a huge share of the ratio of like what was happening here. And so this just solves that. It will stop it once it gets
Starting point is 00:38:24 broadly deployed. Unfortunately, the bad guys have been adapting techniques. It advances this change. And so we're seeing more and more of the phone-based social engineering attacks where you trick the attacker into somehow giving them access either logging into a website they control with the actual credentials or doing like a device authorization workflow or things like that. And so device code features the new black at the moment. Yeah. And so it doesn't mean like bad things will stop happening as soon as this goes GA. But it's great because it solves a real problem that has been around for decades.
Starting point is 00:38:57 And this is the right way to solve it. Like we finally, you know, with TPMs and every device, this is actually going to fix a real problem. So I'm very excited about this. Yeah, James, you love this as well. Very happy with this, but I will say, you know who else loves session tokens, AI agents? And so how long before the agent gets really good at minting these tokens in a device-specific way by leveraging the TPM? It'll be interesting to see whether they solve this gap as well and learn how to do this. Well, as long as it's happening on the box and it's your agent, I mean, I think the thing is like malware gets around this, right?
Starting point is 00:39:28 If you've got malware on the box, it can probably get around that. But, I mean, that's like a much heavy, it's a bigger lift, right? As for like agents and authorization and authentication when it comes to agents, man, that is a whole field right now. God knows where that's going. We have to speed up because we are running out of time. There's a bit of cool research out of Portswigger that has looked at dumping mailboxes using cool novel techniques. James, you're all over this one. You loved it.
Starting point is 00:39:56 Absolutely loved it. CSS began its life as a declarative way to define styles. then it gets more and more, you know, code-like things built into it. You can do conditionals. And of course, when you take something that's declarative and add all those sorts of additional code-like things into it where you get an attack surface, and the guys at Portswigger have just done an incredible job that,
Starting point is 00:40:17 I mean, there's like literally dozen different attacks in this where they just get more and more deep into the internals of just exactly how you can get CSS to do prompt injection, how you can get CSS to do detection of tokens in a URL by having a font-size oracle and animation timing differences and then exfiltrating that out to URL through background requests. It's just, look, I almost can't do it justice by trying to explain it other than to say, go read it because this is such an incredible look at
Starting point is 00:40:46 all the ways in which we've turned CSS into a coding language, which can now be exploited. Yeah, this is worked by Gareth Hayes at Portswigger. And it is, you know, it is, look, every year at Black Hat, Portswiger always dump the good stuff, you know. So that's good to see that continue. There's been a security incident with Metabase. This is worth mentioning because this has been on-prem and cloud-based Metabase, and it looks like this is a big incident, right? It's definitely worth mentioning this week, James. Yeah, big for two reasons, Pat. One is, Metabase is what you use when he can't afford Tableau and Looker,
Starting point is 00:41:24 and that's a lot of places, right? Those are really expensive BI and, you know, Insights tools. So it's got a big install base. But Metabase is one of these dashboards and insight tools that sits directly on top of your snowflake, your Redshift, your big data lake. And so compromising Metabase is a really quick path into the most valuable data that a business has. So this will be a big deal. And it does unfortunately a SQL injection in the password reset flow. And yeah, active exploitation will be ramping up if it's not already for sure. Yeah.
Starting point is 00:41:58 Oh, now, remember those snowflake attacks back in 2024, the really weird ones because the OPSEC was so bad. This 26-year-old, yeah, he was using, at the time, I guess he was 24, but he was using stolen credentials to just log into Snowflake instances, steal all of the data and then ransom it back to the companies. He of course got caught, has pleaded guilty, and will spend up to 32 years in prison for that, which is just a reminder that if you play stupid games, you are going to win stupid prizes. But what's crazy is we've got this other story here where there's this young guy from the com who abused more than 100 like teenage girls between the ages of 13 and 17 coaxing them into coercing them into producing imagery and doing acts of self-harm and sending him videos and stuff. Two years. He gets two years. So what I would like to see is those two sentences probably reversed. you know, if there's, like, two years is just completely inadequate for that sort of level of
Starting point is 00:43:01 offending. And 32 years for the other bloke is just nuts, right? Considering he's 26 years old, probably has some sort of prospects for rehabilitation. But this just goes to show you that like, you know, the British judiciary, probably too lenient, the American judiciary, a little bit too much the other way. What else have we got here? We got an FBI warning as well, saying that, you know, people are getting their nudes hacked and whatnot. That kind of connects to that previous story. Obviously this is a big problem at the moment if the FBI are warning about it. Usually it takes a lot to get them to issue a warning about anything. And then we've got a couple of interesting pieces here on AI where AI is getting better at election facts is the headline,
Starting point is 00:43:43 but voters shouldn't rely on it. And this just reminded me of like when Wikipedia was new. And everyone's like, oh, you can't rely on Wikipedia. There's bad stuff in it. It's like, everybody relies on Wikipedia now, more or less. But they know that, you know, there's a caveat there that it is that it is Wikipedia. I think AI agents are the same. But where this gets funny is apparently you've got like a memo out of the FTC in the United States where they want to regulate AI for ideological bias. So I guess they want to make AI great again.
Starting point is 00:44:10 Brad, you're an American. I can't imagine you would feel too great about the FTC regulating AI agents for ideological bias, right? I can't defend it. It's not going to go anywhere. No, it's not. It's not. And you know, there's just a few ransomware items that we'll just leave in the show notes for people to read if they would like to. The United States and South Korean governments have issued a warning about the Gunra ransomware group targeting government agencies. Sisser says that a sharepoint flaw that's been doing the rounds in the wild is now being used by ransomware crews.
Starting point is 00:44:45 Hooray. Sonic Wall. SMA 1000 floors are now being used by ransomware crews. you know, and what is it, Enable, Enable software. What are they called? It's the Enable and Central. That's being used to drop RMSs on victims by ransomware. So there's a lot of ransomware activity at the moment. But we're going to round out this week's news coverage with a story that's just gone massive, which kind of shouldn't have, which is some idiot on their way home from DefCon,
Starting point is 00:45:16 basically de-offed everyone off the plain Wi-Fi and spun up a malicious act. access point. Brad, this reminds me of when someone years ago, like, plugged into the seat back or something on their way home from DefCon and was like posting photos of whatever of getting Shell on the, you know, on the entertainment system and caused a similar level of freak out. This is a dumb thing to do. And, but I don't think it's going to amount too much. What do you, what do you think? Well, so the pilot called in an emergency. So they were met at the gate by, you know, guys with guns. And whoever did it, they were on the plane. So there's nowhere to hide.
Starting point is 00:45:54 So I don't know. If you're going to do something like that, I think the airport lounge would be a much better place to do it because you have some plausible deniability. Yeah, this thing has gotten the attention of all the normals. So like all my non-cyber technical friends have been sending me, you know, news articles and LinkedIn posts and things about this event. It seems to have really captured their imagination. So I remember the guy who's messing with the seat back.
Starting point is 00:46:17 The FBI visited him. He told them all about it. and then got mad later when they used it against him. Because he said it was shared in confidence. Was he the guy he was saying he could make the plane fly sideways? Or was that another? Exactly. Yeah. Yeah.
Starting point is 00:46:31 And there were memes. There were so many memes. That was a fun time to be on Twitter at that time. That was pretty good. I remember actually just reminding me that there was a guy on flights in Australia who was actually fishing people through malicious Wi-Fi on a plane and the cabin crew noticed and they had the cop scoop him up. And he got in trouble.
Starting point is 00:46:50 He was convicted for that. So it is interesting now that I guess aircrew have the training now, right, to spot when you're doing shifty stuff with Wi-Fi. But that's it. We're going to wrap it up there. Brad Arkin, James Wilson. Thank you so much for joining me to talk through the week's news. It's been a lot of fun.
Starting point is 00:47:05 Thank you. Thanks, Pat. See you next week. That was Brad Arkin and James Wilson there with a look at this week's security news. It is time for this week's sponsorate of you now. and we're chatting with Tony Delafonte from Proula. Now, Proula is an immensely popular open source cloud security tool, right? So you can use it to run all sorts of checks against your cloud infrastructure.
Starting point is 00:47:32 You can use it to do all sorts of remediation as well. And, yeah, there's obviously an enterprise part to Proula, which you can pay for. And it's all of those enterprise features that, you know, that do not belong in an open source project, things like, you know, integration with ticketing systems and SSO and all of all of that good stuff. But really, I was joined by Tony for this interview where we really spoke about what they're doing with AI and how you can get Praula to, you know, be friendly with agents. And they've, they've really done a good job with that. So here is Tony Delafonte talking about all of that. Enjoy. So remember, we were talking about this kind of standard features like GID integration or any
Starting point is 00:48:13 other enterprise integration, authentication, all that stuff is being asked by big, companies or corporations that they are not actually very agentic oriented now, today. But for more like small medium companies or cloud native companies, they are more like, okay, let's do everything with AI or try to do everything with AI. And that is why we are adding those capabilities not only in an UI like paid only UI. This is part of the MCP, part of the tools behind the Praweller AI. So you can do everything that you can see using an agent, an agent. So for example, you can do the triage from the agent, do the re-scanning from the agent, do the
Starting point is 00:49:00 muting or computing whatever. You have to compute in your cloud security from within Prawler with your agent. But of course, we want to provide that using, you know, click-ups in the platform if you want to, but you can go through the agent to do exactly the same thing. including creating new controls, deploying new controls, compliance frameworks, those kind of traditional cloud security staff, two agents.
Starting point is 00:49:27 Because now it's the agent that is going to make that decision and do whatever within broader capabilities. Yeah, I mean, I think some of these agents are going to replace or be decent enough stand-ins for certain types of consulting, for some of the more boring compliance-related consulting. You can just say, hey, agent, I've got to comply with this thing. you know, can you use Prala to see where I might be coming up short?
Starting point is 00:49:52 For example, I'm guessing that's one of the ways that this works. Exactly. You can add your entire AWS organization, for example, or Google Cloud Projects, everything, and say, okay, make sure this is everything compliance with CIS, for example, and Prer is going to tell you what to do even ask you, Hey, you want me to do it? With the proper permissions,
Starting point is 00:50:19 probably can do it as well. Well, okay, so here's my next question, right? Which is my preferred way of using an agent to do something like this would be to give it that sort of read-only access, ask it a bunch of questions. And then at the end, I'd say, look, if you wanted to remediate this, could you generate me the scripts or generate me the steps
Starting point is 00:50:39 that would be required for me to remediate this? Hold on. That would be required for me to remediate this. and then just give me that script and then I'll go and do it. 100%. So Parlor can do the remediation by itself in some cases, okay? Because that is not a good practice. So to do self-remediation in the cloud, in runtime, let's say,
Starting point is 00:51:03 is not the good practice, right? And so we don't want to provide the wrong practice out of the box. But we have demonstrated we can do it. Technically speaking, we can do it. And technically, we can do it. But it's not a good practice. What we do when you ask Prouler to do something is to generate terraform code, cloud formation code,
Starting point is 00:51:26 or even step-by-step click-ups in options, right? As you can find in many guys like CIS or many others. So we do that since the beginning of, like House AI and with our MCP. Of course, the recommendation is not to allow, the AI or any agent to do anything at any point. So not now. Would that be possible? Probably, actually, you can, what we do,
Starting point is 00:51:59 and we have articles and in our documentation, you can see that is connect your agent to Prouler. You can connect also your repository, where your infrastructure as code is. And Prouller is going to tell you, hey, fix this here, fix that, there and whenever you have the pull request ready, the human is going to review it, accept it, and then redeploy and you don't go through the circle.
Starting point is 00:52:26 That is possible now with Prouler. That's the way you want it to work, but I don't think humans are going to be reviewing those sort of pull requests in the actual real world that we live in. I mean, maybe now for a little while, but there's going to be too many of them in the future. I should say, too, just to be clear, I wasn't talking about giving the agent itself, I guess, permission to do the reading. I mean, that's the advantage of using something like Praula agentically is it's the Praula platform that has the permissions, right? It's the Praula platform that is reading stuff from your cloud environment, so the agent
Starting point is 00:52:57 is not doing it directly. And there's less scope for like Flotterbinger's oopsie daisy, we over-provision the agent sort of incidents when you're going through, you know, a platform in the middle like Prahler. Something that is very important in our case is As you mentioned, the agent is not doing anything. It's Prouder doing that for the agent. Because we have that deterministic database of artifacts that they know what to do. So I don't know if you remember one. I think we have discussed about this in the past.
Starting point is 00:53:32 When we started using AI with Prouder, we asked Cloud Code, hey, tell me, with these credentials, read only credentials or whatever credentials, tell me which bucket is open to the internet. Cloud code was trying to pull data from the internet, trying to understand what to do, what is a bucket, what is open bucket, all that stuff. Yes, it's reading the documentation. Exactly, exactly, which is what it does, right?
Starting point is 00:54:04 I'm trying to create a script, running the script, and giving you wrong results, because it was unable to do it. And at some point, says, okay, hold on, I'm going to use Prouda to look at that. So we were used by agents before being agents, you know, originic. And right after that, we prepare the public ecosystem of artifacts with Prouder have. That is going to become Prouder Registry very soon because allows public and private registries, like DockerHap, for example, for artifacts.
Starting point is 00:54:44 That is used by the agents in order to understand what to do and how and what means compliance or what means secure or not, harden or not, et cetera. So because at the end of the day, the agents, I mean, probably they may know for AWS, but what about Scaleway, what about Huawei Cloud? What about whatever new cloud that we have new clouds every day, right? And all those are also covered. it by Prouler.
Starting point is 00:55:11 So have you seen a case of a customer using Prala with an agent and you've just gone, wow, that's actually really clever. I hadn't thought of that because I'd imagine occasionally someone's going to come along and say, hey, look what I did with this prompt. And you'll be like, my God, that's amazing. I have seen something very cool when you use agents with Praolari's, there is no longer a need to use our out-of-the-box dashboards. You can create beautiful dashboards
Starting point is 00:55:44 with a lot of features with a prompt. That's so annoying. I can imagine how much work you actually put into those dashboards and now people are like one-shot recreating like better ones with mythos or whatever, or fable. It's like this big prompt,
Starting point is 00:56:03 but you create a beautiful dashboard with a lot of features like, okay, so we have seen even, and this open source is also in our documentation, it's like, okay, generate a report when I fix all the critical and high severity findings. And it says, boom, okay, if you do this, tomorrow you are going to be this, this and that.
Starting point is 00:56:24 And that is possible now, super easy, super easy with AI with agent connected to Prouler. And that is super cool when you see people going beyond expectations. And that is thanks to open APIs, also the capabilities in the product and being very community friendly. Yeah, well, I mean, speaking of the community friendly aspect, is the open source platform also set up to be as agentic friendly? I'm guessing largely the answer to that would be yes. Yes, actually, everything that we have in Prouler have is open source and is accessible through the MCP and through an API. So you can connect it as a tool with your own MCP.
Starting point is 00:57:08 So you can configure the PRRROMCP by yourself if you want to, private or public. But of course, we have the Prouder Cloud MCP public already that you can connect through an API key directly, your agent. Yeah. So, I mean, you can, if you can be bothered with all that. Or you could just use the commercial one, I guess is the answer. Exactly. Exactly. So you can go straight and use the commercial very.
Starting point is 00:57:34 And if you go to Prouler Cloud, you have a link to connect any agent directly in a matter of minutes. Yeah. And are you finding that there's been any guardrail related drama with using Proula with like some of the anthropic models, which are like, whoa, you're trying to use, you're trying to use Proula to scan stuff on the internet? Like, that looks like hacking to me. I've called the police. They're on their way to your house. Like, do you get those sort of responses or is it not so bad? Not really.
Starting point is 00:58:03 not really. So I have to say that we are not testing every single model because there is no bandwidth to do that in terms of human hours, right? But what we test is what we recommend, like GPD 5, 5 or 5, 6 is working very well when you connect also Fable is working very well. So I have to say that one thing is to analyze findings or attack paths, etc. Another thing is to say, okay, now that you have this generate the fix, which is the anthropic models are kind of better sometimes than open AI models. But we are not testing every single model all the time because it's almost impossible. Man, I think this has been a fascinating conversation. I do think we're going to see some absolutely insane, like, terraform disasters as a result
Starting point is 00:58:56 of people getting, like, vibe-coded terraform to fix the results of scans. This is going to, look, everything's new again. It's fascinating. Tony De La Fuente, it's always great to chat to you, my friend. And I look forward to talking to you again soon. Thank you, Pat. See you soon. That was Tony De La Fuente from Praula there.
Starting point is 00:59:16 Big thanks to him for that. Big thanks to Praula for being this week's sponsor. And that is it for this week's show. I do hope you enjoyed it. I'll be back soon with more security news and analysis. But until then, I've been Patrick Gray. Thanks for listening.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.