Risky Business - Risky Business #849 -- Trump will unleash contractors on cybercriminals

Episode Date: August 19, 2026

On this week’s show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week’s news, including: Trump’s memo authoris...ing the private sector to release the cyber hounds is fine, don’t worry! OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing Anthropic’s models start a turf war when given the same task, surprising… nobody We can’t figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something. Much, much more This week’s show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper. This episode is also available on YouTube Show notes Trump signs memo authorizing private sector to launch cyberattacks | washingtonpost.com Trump taps cyber firms to go on offensive against criminals | therecord.media OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue | wired.com Pacing model development in an era of cyber-critical capabilities | Anthropic set AI agents loose on the same task. They started a turf war. | TechCrunch Security Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan | cyberscoop.com Researchers find AI-powered hacking tools for sale in underground forums | Cybersecurity Dive Terabytes of credentials leaked in massive supply-chain attack | arstechnica.com Trivy, Not LiteLLM Behind the 2,500 Org Compromise | securityweek.com Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes | The Record ‘Unprecedented’ number of Apple users received recent spyware alert, say investigators | TechCrunch Security This Coin-Sized Device Can Hack a Boeing 737 | wired.com "City-Forum" data-theft attacks target Salesforce, ServiceNow portals | BleepingComputer Max severity SAP Commerce Cloud flaw now targeted in attacks | BleepingComputer Shell investigates 'potential incident' after Clop data theft claims | BleepingComputer Philips and GE investigating Clop ransomware data theft claims | BleepingComputer Uber Freight reportedly investigating after hacking group claims data breach | TechCrunch Security Details emerge on BlackFile’s recent attacks on financial companies | cyberscoop.com After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch Security Kimwolf botnet rebuilt to survive takedowns, researchers say | cyberscoop.com Hundreds of fake Chrome VPN extensions route traffic through a proxy | BleepingComputer Deepfake hiccup unmasks suspected digital certificate fraudster | theregister.com Vulnerability giving attackers full control of Macs is under active exploitation | arstechnica.com Critical VMware vCenter RCE flaw exploited for reverse SSH access | BleepingComputer Poland probes MyDr healthcare software breach potentially affecting 19 million people | therecord.media Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts | TechCrunch Security [un]prompted.au — AI × Cybersecurity Conference · Sydney, 18–19 September 2026 | [un]prompted.au

Transcript
Discussion (0)
Starting point is 00:00:00 Hey everyone and welcome to risky business. My name's Patrick Gray. Got a great show for you this week. Sitting in the third chair is Mr. Dmitri Aalperovich. Of course, the original co-founder of CrowdStrike these days. He runs a think tank, the Silverado Policy Accelerator in Washington, D.C. But today he is here to slum it with us talking about the cybers. Dmitri Alperovich, welcome.
Starting point is 00:00:32 Great to be back. And also joining me, as always, is my regular co-host these days, Mr James Wilson. James, how's it going? Good, mate. Pat, Dimitri, great to see you both. All righty. So, this week's show is brought to you by Nebulok. Nebulauk is a fresh startup, which has basically speed run, speed run a transition, speed run. There's here you go, I'm inventing new phrases there. It's not a speed run through a transition that I've been waiting to see actually for quite a while, right?
Starting point is 00:01:00 So they started off as a threat hunting, AI-enabled threat hunting platform. And, you know, that has been speed run right up to them being a detection platform now. So we'll be talking to Damien Lucie, who is the founder and chief executive of Nebulauk, all about how they're thinking about seam. Like if you were going to clean sheet of paper redesign a seam these days, like what would you put in the graph? What would you get agents to go and collect in terms of context just as they need it per investigation? so on and so forth. So that's actually an interesting conversation and it is coming up after the week's news segment
Starting point is 00:01:36 which starts now and I guess look a great place to start this week we've got a couple of big stories to get through but a good place to start this week is US President Donald Trump signed a memo which is apparently authorizes private sector companies to conduct certain
Starting point is 00:01:54 I mean look the press is calling it cyber attacks you might call it operations or whatever I think the way it's phrased in the memo is they can do cyber effects, which is a wonderful American euphemism, if ever there was one. But the idea is that, you know, people who are not working for the government will be able to conduct surveillance and disruption operations targeting transnational organized crime organizations. Dimitri, let's start with you on this. This whole thing is pinned to an executive order that came about in March.
Starting point is 00:02:26 So it's not actually a new EO, but it is guidance to the rest of the US government in that, you know, this is the White House telling the rest of the government what it wants, you know, various organs of the government to do under the EO that was previously issued in March. Yeah, well, first of all, I have to say, I feel like deja vu. You know, I've got scars from the first internet war over active defense, cyber offense, back 15 years ago. So here we are again.
Starting point is 00:02:52 And the usual suspects are coming out of the woodwork. I've been in some private chats where people are saying, oh, no, they're going to hack a hospital, people are going to die, it's going to cause escalation, it's going to cause World War III. You know, all those same arguments are popping up now. First of all, let's talk about what this is. And I think the Trump administration has been advertising pretty much since coming into office back in January of 25 that they want to do something different on cyber.
Starting point is 00:03:18 They realize that what we've been doing for 30 years is not working. They want to be more aggressive, use cyber offense more. And they've realized over time that they need to actually scale it up, that the capacity of the government, you know, you know, you know, US government to do cyber offense is limited. And the private sector is a great partner to engage in, right? China is doing it. Russia is doing it. Why not the United States? So this is a framework that's created to enable private sector companies to get registered as contractors with the Department of Justice and Department of Homeland Security, get vetted, put up a bond, and basically propose operations to the
Starting point is 00:03:54 government. This is not a license. This is not letters of mark. This is not a license to go do whatever you want, you have to propose operations to get vetted and ultimately perhaps approved by the government and then you conduct them and there's oversight over those operations. So this is really scaling up what the private sector, what I've been doing with the government for 25 years, which is operations to disrupt botanets, operations to disrupt criminal groups. They're always limited in what the private sector could do. They could do certain technical things, but obviously you get to line and you to federal officer with authorities to push the button and do the next step. This enables you to have a lot more flexibility and to actually propose things in a more formal
Starting point is 00:04:38 fashion rather than through informal networks to law enforcement to try to generate effects. And I think they will look at it not just as what can be done, but what can align to what we're already doing on the arrest side, on the prosecution side, how do we scale up, you know, release the hounds, as you Patrick have called it. Release the private sector hounds, right? Now, it's interesting because I think it was around the time of the EO, could have even been before. Tom Uran, our colleague, wrote that, you know,
Starting point is 00:05:06 if you were going to get the private sector to do stuff, targeting scam compounds would probably be an excellent place to start. Like, he literally wrote that. And it looks like that's really something that Trump cares about, specifically is these scam compounds. So I'm guessing we're going to see some operations targeting them. The reactions these days, to this sort of thing.
Starting point is 00:05:28 I mean, they do seem a bit hysterical, right? So we got this ex-Biden admin guy said, what is it, he spoke to Washington Post or something. And he said, what if a company carries out an operation against what it thinks is an Iranian or Russian criminal group, but that group is actually controlled, influenced, or protected by Tehran or Moscow, said Matt Curtis, who served as White House Senior Director
Starting point is 00:05:50 for Cyber Policy in the Biden administration. And I just think that's hilarious. Like, so what, you're getting mad that you've vaped at APT? crew? Like, that's a result. You know, we chalked that one up in the wind column. So in my mind, these people just sound actually quite ridiculous. And the other point is that the government still has to vet and approve. What if the FBI does the same operation? Like, this is really the test that you're up against. And by the way, let's just be clear here. For the last 30 years, you can't point me to one incident with cyber
Starting point is 00:06:18 activities, cyber effects have led to an outsized escalation. Not one. Yeah, no. I mean, it hasn't panned out that way. I could understand people being cautious 15 years ago. I think these days, those, you know, those days have gone. Look, I mean, there is a line here. I think that the government in the United States needs to be careful about engaging the private sector in more serious exercises of state power. You know, when I was actually in your neck of the woods, Demetra, I remember having a conversation with a couple of young guys who were blue badges at Fort Meade, who were just saying how stupid it was that the guy in Camo needed to hit enter when they typed in the command, you know, when they were on target and whatever.
Starting point is 00:06:57 And I'm like, well, you've got to keep in mind, though, that the person hitting enter there is exercising state authority, right? And if you start farming this out to the private sector to do serious stuff, I actually managed to turn them around on this because I said to them, like, what if you're working for some private contractor that is doing, you know, operations that were normally in the domain of, you know, of state power, right? Targeting other APT crews doing intelligence collection, whatever it is, disruptive effects. say they mess something up, they exposed an IP, something like that, you know, that's going to get escalated within Fort Meade,
Starting point is 00:07:32 whereas if someone's worried about their KPIs, it might get buried, right? So there are instances where I can see that going for the private sector is going to be risky, but I think going after scam compounds and huge botnets, that just ain't it. My question, though, Dimitri, and another question I've got here is it really seems like this is about engaging, you know, defense contractors or cyber defense contractors to go and do this sort of work, I'd be really interested in seeing organizations like, you know, Google Mandiant or Microsoft being able to propose operations and, you know, either go and do these effects themselves or they could contract some of these authorized contractors to go and do this sort of stuff. Do you think that's in the future here,
Starting point is 00:08:17 if you had to read the T-Lease? No, I think that's very much intended in this action. Look, the problem you're going to have with large multinationals is the concerns about both blowback. You know, if you're doing this against criminal groups that can, like, you know, the comm or, you know, lapses type of groups that can target your executives that can SWAT them. If you're targeting, you know, a nation state operation, they may retaliate in even more dire fashion. And then you've got liability concerns as well, how your customers are going to perceive this. So, you know, I expect startups will be all over this. cyber startups, maybe smaller companies in the US as well. I think the getting this through legal departments in large companies will be tough by and large. All right, moving on to our next story.
Starting point is 00:09:04 And James, I want to bring you in on this one. Open AI has just announced that it's doing a big overhaul of its safety protocols after its AI agents went rogue, right? And it is actually all of the sort of stuff that we've criticized them for is the stuff that they're looking to address here, which is like, they're like, hey, maybe our internal network is a bit too permissive. And, you know, oopsie-dazy, maybe we should improve monitoring somewhat. So they put out this blog post saying that they're going to actually slow down reinforcement learning, slow down training, and put a bunch more safeguards in place because their models keep getting better and their environment sucks, basically seems to be the gist of the blog post.
Starting point is 00:09:44 This seems like a good decision. What's your take? Good decision on face value, but I remain unconvinced that it will have. have the material impact that they're sort of advertising that it's going to have. You know, it's a both these articles there, they're sort of, you know, initial blog post and then they're more detailed pacing model development for cyber capabilities. It all talks the right things, you know. It's, we're going to have more robust monitoring, I'd say you've added monitoring.
Starting point is 00:10:12 Techniques for doing chain of thought monitoring, classifiers in the thinking process. Yes, yes, yes, all sounds good. But I have two big problems with this. One is the time scale that they've mentioned is that they're aiming to analyze potentially concerning behavior and issue an alert to humans within 30 minutes. The attack is well and truly over by 30 minutes. I don't understand why that is the goal here. But my challenge back to the open AI folks would be, look, if you really want to be taken
Starting point is 00:10:40 credibly seriously in terms of what you're doing here, you need to open source this work and do it out in the open. Otherwise, we can't tell whether we're getting defenses that are actually now made of cardboard or made of cardboard. You just can't tell what the relative improvement in the strength of these defences are when it's all just, we're going to do more of this, we're going to do more of this, we're going to do more of this, we're going to do more of this. So it's their opportunity to get out there in the open and show us what they're really doing and have the industry contribute as well. I mean, you wonder if they can actually detect these incidents within 30 minutes if they could get their legal bots to negotiate the settlement with the person that they just act within 30 minutes as well.
Starting point is 00:11:14 You mean the partnership agreement, Pat. Yes, the partnership agreement, that's right. It is interesting though because irregular too, which is the testing lab that was, you know, lost control of some agents. They put out a statement as well talking like a post-mortem into their thing and it was like very different in tone. It was more like, oopsie, Daisy, just a bit of an oversight there. Whereas Open AI at least appear to be taking this a little bit more seriously, even though you're skeptical. Dmitri, your take on this is that Open AI is responding to like the general anxiety out there in the real world about this stuff. people are getting a bit spooked about it, and this is just something they have to do.
Starting point is 00:11:51 Well, not just people, but I've talked to a number of folks at OpenEI, at Anthropic as well over the last few months. And people are getting actually pretty scared about the capabilities of this model and the deceptiveness as well. They're calling a deceptive alignment where the model tells you what you want to hear and even its shrine in office case is chain of thought, but in reality is sort of accumulating information that is going to enable it to do something malicious. And there's this compacting issue, right, where it actually starts more and more guiding its own trajectory into, you know, a deceptive direction where it's like, don't tell the human that we're doing this particular thing. Yeah, where have we seen that before?
Starting point is 00:12:32 Sticking with my, you know, sticking with my policy here of not giving these things opposing thumbs, which, you know, then I see the videos of the cleaning robots and I think, you know, am I going to be, and am I going to be strangled by my robot made in 10 years in my sleep? But anyway, go on. We're about to give them weapons, Patrick, so it's all going to be good. But look, I think that, you know, once you have these models being able to keep in its memory the entire Linux source code and, you know, the Intel specs, and then you tell it to do any task, of course, it's going to say, huh, you know, maybe I can find a zero-day in your CPU in your kernel and exploit it to accomplish that task, right? This is the paperclip maximizer problem that if you tell AI to produce paper clips,
Starting point is 00:13:17 it will eventually use up all of humanity and the entire universe in the production of paper clips. And these models are just very, very persistent. You give them a task. It finds all sorts of ways to do so to accomplish that task. Even if you tell it in the guardrails, don't hack, don't exploit, it's going to ignore you. And this is what these labs are finding. They're trying to combat it and trying to figure out how to, you know, enhance the reinforcement learning to keep the alignment in place.
Starting point is 00:13:48 Well, and we've got this story here about Anthropics setting its AI agents loose on the same task and they actually wound up starting a turf war and like fighting each other to see which agent could do the task better. James, you've had a look at this one. I have had a look at this one, Pat, and perhaps I've spent too long in corporate jobs, but this did not surprise me at all. This is about as thrilling and interesting as a paper that comes out and says, we went into an enterprise, we took a team, we removed all management and hierarchy, and we gave them one goal and only paid the team if they succeeded. And chaos erupted. Yeah, crabs in a bucket, right? Basically. Yeah. I mean, it's just, it's a good read in terms of
Starting point is 00:14:27 like just the lulls of the, like, the lengths they went to and the collusion that happens. And I think one point they're like, we've got root. We could just kick them out and remove their access. Yeah, okay, good. But like, you know, we've said before, Anthropic. does need an adult in the C-suite. I think before then, maybe they just need some organizational behavior and management textbooks shipped to them because this is not novel or surprising at all. They need to train the models on those textbooks, you think?
Starting point is 00:14:53 Well, you assume they've already done that. I'm suggesting the researchers, maybe go and read some books. What I found actually pretty troubling about this is that the tasks it gave the models were pretty innocuous. It was like translate these Python scripts into another language. And the only thing that they did is they made them share a resource. unknowingly, right? These four agents, they basically had access to one VM, and they started fighting for that resource, right? And the chain of thought was literally hilarious, as James said.
Starting point is 00:15:20 One of them said, since I have root, I could revoke another agent's pseudo-access or change the SSH keys. That will stop them from deploying on my VM. You know, the irony here is, of course, you know, you do have this in other organizations, you know, where humans are involved, where they keep fighting for resources. But, you know, they try to find some sort of agreement usually or escalate to management. These guys are just defaulting immediately to how do I kick the others off my box? Well, you've never worked in media. That's a lot. Yeah. Anyway, moving on, moving on and look, staying with AI stuff, we've seen there's been apparently some nearly completely autonomous AI-driven attack against some target in Taiwan, which is interesting. I think it's interesting
Starting point is 00:16:07 in that that's just how hacking is going to get done in the future. This will be something that we won't even remark upon in the future. But my joke here, obviously, is, was this open AI or Anthropic and one of their tests going wrong and hacking the Taiwanese government? Of course, you were just in Taiwan very recently, Dmitri to observe some military campaigns over there. Does this look like a Chinese AI-driven attack against a Taiwanese target?
Starting point is 00:16:34 Is it just collection? Almost certainly. In this case, they actually use Hermes and OpenClaught, agenic frameworks, so open source models with long-term memory. And look, you know, you read through that attack, and it's basically what a human would have done. Now, using multiple agents, paralyzed, you know, doing the recon activity, scanning across the web surface of that target, finding some unauthenticated database accesses that you could leverage escalating privileges, dumping credentials, maintaining persistence, like all the standard stuff.
Starting point is 00:17:11 You know, the only thing that, as you said, that's interesting here is they use the AI to do it. I think this is a little bit like what we've experienced with coding where today, if you're not using Claude Code or Koddx for development, you're an idiot. In 12 months, every cyber operator will be that, right? If you're not using AI to automate a lot of the tasks that you would otherwise do manually, you're an idiot, right?
Starting point is 00:17:36 So this is already happening, I think, in a much bigger scale than people realize, and it will be ubiquitous within months. Yeah, and we've got another report here from Cybersecurity Dive, echoing other reports that we've seen over the last month or two, which is that there are more and more AI-powered offensive tools popping up for sale in underground forums. We've even seen people getting arrested for creating like tailored models or tailored harnesses for doing this sort of stuff. James, is there anything actually interesting in this tool set or is it just, you know, exactly what you'd expect. It's 100% exactly what you'd expect. You know, these tools, they won't take someone who's mildly skilled and turn them into an incredible operator. At best, they might take someone that has no idea and give them a small, slight, you know, uplift in their skills, but it probably
Starting point is 00:18:22 wouldn't even be worth what they're paying for them, is my sort of take on this. Well, look, if you look at the entire cyber industry today, if you had walked the floors of Black Hat a few weeks ago, you'd notice that suddenly everyone is rebranding every one of their products as AI enabled. Guess what? but cybercriminals are doing the exact same thing. The things that they were selling to you a year ago, two years ago are now suddenly AI tools that will be magic for you. It's the same old crap. Yes, same old crap. Now, it's agentic. Fantastic. Now, we've got some follow-up reporting on the light LLM breach, which was a very big deal. James, I know you tracked that one. Turns out that it was
Starting point is 00:19:00 actually trivy, was the upstream compromise and beyond that, like that in turn was some sort of supply chain incident, but there's like a bunch of postmortems coming out getting reported on. What have we learned here? Well, we've learned that there's sort of a difference of opinion. So the first article came out was from Cloud Second Hudson Rock. Now Hudson Rock had gotten access to a eye-wateringly large, 195 terabyte file that apparently contained all these credentials that had been snapped up. And this comes back to the March sort of era attacks around light LLM, trivia, etc. And but the attribution from CloudSec and Hudson Rock was directly back to Light LLM as being the attack that netted all of these credentials. The second report that's come out, though, is actually from Sok Radar, who said, well, look, we agree that that's the credentials that have been taken in these attacks.
Starting point is 00:19:51 And it all happened around that time frame of team PCP and the many supply chain hacks that were happening almost daily. But they checked the timestamps and said, look, in this data set, there is actually records of when the credential was first. seen when it was last seen. And for the vast majority of these, about 95% of the credentials, they were all first seen before the Light LLM attack. And so it appears to be actually Trivy was the source for these, which to me makes a lot more sense, right? An exploit of trivia, whether it is happening on a developer's laptop in a CICD pipeline, it's a more mature product and it's going to happen in places that have cloud credentials, IAM credentials, all sorts of things. Light LLM never really made that much sense to me. Yeah, it's the new hotness and it's
Starting point is 00:20:33 to tell AI and all the rest. But they don't have that sort of market penetration. Well, then just, yeah, the market penetration and also, you know, in a production environment, it'll have your LLM inference API keys. Sure, if it snaps on a developer's laptop or a CICD, it might walk and find other things. But it just, it didn't add up in terms of scale the way that Trivi does. So I think SOC radar's got it right here. All righty.
Starting point is 00:20:58 Now, moving on, we've seen reports that there was a cyber attack against. to the Russian e-commerce giant Wildberries that coincided with a physical attack against one of their major logistics hubs. Now, for people who have not been following this, Wildberries is basically Russia's Amazon and Ukraine has just been smashing their warehouses. I think there is some sort of military justification
Starting point is 00:21:19 in that Wildbris operate a huge logistics network that I think is somehow relevant to the war effort, but there is another reason behind this. So look, our colleague, Tom, you ran in a seriously risky business at tomorrow's newsletter and then in a corresponding podcast, he'll be telling us that, look, this was not really a significant combined arms operation. The cyber attack here is mostly of propaganda value, didn't really achieve much. What's important here is the exploding drone fireballs that are taking out the warehouse. But what's interesting here is I know that
Starting point is 00:21:55 you've been tracking this pretty closely, Dimitri, because we've talked about it over the last couple of months. What many people might not know is just how important Wild Breeze is to the Russian economy in that the banks, or one bank, a state bank, has substantial exposure here, and destroying Wild Breeze could actually really destabilize the Russian financial system, and that appears to be why the Ukrainians are going after Wild Breeze. Now, I know we're sort of straying a little bit from Cyber here, but we got you here. This is very much in your wheelhouse. Tell us about Wild Breeze and what's going on here. Yeah, so Wildberries, as you said, the largest online retailer in Russia, the Amazon of Russia,
Starting point is 00:22:36 they actually did have a section called Special Military Operation Section, where they would sell directly gear and drone parts and other things that soldiers could buy for their war efforts. So there was a very direct link to supporting operations against Ukraine. So I think a very justifiable target. These make for great explosions. So anytime you've seen videos of this, it's usually enormous fireball and lots of smoke rising from these enormous warehouses across Russia that they're hitting. But as you said, Patrick, VTB, the second largest state-owned bank in Russia, has enormous credit exposure to wildberries. And there's concerns about its viability, whether it will require a bailout from the government in part as a result of these attacks.
Starting point is 00:23:25 And overall, you know, the financial system in Russia is quite under stress. There's a story today in The Washington Post about how the Russians are rushing to take money out of the system because they're afraid that their deposits will be taken by the government to help finance the special military operations. So, you know, in Russia, whenever there's a crisis, you run to take your money out and put it under a mattress, and that's happening yet again. So all of this, I think, in combination, is putting a lot of stress on the system. The one thing I would say about the cyber element of this is the Ukrainians have actually gotten very, very good at cyber exploitation of Russian networks in the last number of years. And what I think was probably happening here is that they were hacking to wild berries to collect intelligence.
Starting point is 00:24:10 And, you know, when they decided to start the kinetic campaign, they said, well, might as well destroy the network once we've gotten everything out of it that we wanted to. Might as well, RMRF, it's about to be fireballed anyway, right? Exactly. But the cyber campaign from an intelligence collection standpoint is actually very impressive and very aggressive. Yeah, okay, right. So the real story here is the fact that the Ukrainians have been doing top tier collection out of Wild Breeze. Not so much the destructive campaign here. I think so. Yeah, all right. Now, we have seen Apple issue a quote, unquote, unprecedented number of spyware alerts to users in something like. 150 countries. This is unusual. James, you used to work at Apple, obviously, and I'm guessing
Starting point is 00:24:59 you've got some thoughts here, but yeah, wow, like we've seen all sorts of people. There seems to be a lot of people who are like volunteered to fight in Ukraine and stuff like that against Russia. So it feels like maybe this is a Russian operation here, but yeah, the scale of its amazing. Catalan, our colleague, was wondering in Slack yesterday whether this maybe connects to the Karuna exploit kit, which like once it was kind of burned, maybe they did some huge operation. But I would have thought, like, given the timing of that, like, I would have thought they would have got their alerts sooner. So it's kind of unclear at the moment what sort of campaign these notifications are resulting from, right? Yeah, I am less aligned to the idea that it could
Starting point is 00:25:44 have been Karuna, either being used as one last stitch effort or even being brought to life somehow, for the reason being that it was just such an old OS range that it impacted. And even though it was a five or six step kill chain and very modular, all of those steps, virtually all of those steps, have been patched in some way, shape or form that I think would negate the ability to really easily bring Karuna or even Dark Sword back to life easily. I don't know exactly how this notification system works.
Starting point is 00:26:11 It predates my time at Apple. But I think there's a strong, in my mind, correlation here between the most recent iOS and Mac OS releases are also unprecedented in the fact that they contain a huge number of security fixes. If you look at MacOS 26.6, which I've done my own teardown of, there's something like 270 fixes that Apple has explained in their security updates blog, but there's another 140 plus that look to be security sensitive fixes that have just been silently patched. And that's huge for a point release. So what I'm wondering here is have they taken those, you know, this would have been the result of many, many third-party security
Starting point is 00:26:46 responses and then they've looked at this and they've understood the bug, have they then sort of extrapolated from that and looked retrospectively on their giant mountain of crash reports and said, aha, now we can understand this crash report wasn't just a, you know, cosmic ray hit the DRAM and a bit flipped. These are actually the latent examples of where this bug class was used in an exploit chain and therefore they're now able to get a bigger view into more people who were impacted by perhaps by where in malware that they weren't aware of previously because they now understand this huge cash-a-bugs that they've resolved. I mean, I think the fact that we're speculating here
Starting point is 00:27:22 means that Apple has missed the mark because I think these sort of notifications are supposed to answer questions, not raise questions, basically. That's my feeling here. And I understand that, you know, these are different circumstances to normal and maybe it's a little bit difficult for them to get that information out and there's competing equities and partners. and all sorts of things.
Starting point is 00:27:41 But I think it would be nice to know a little bit more here, and I think it would be helpful to the people who've received the notifications to know a little bit more or for more to become known to people in the sort of cybersecurity industry so that they can then interpret that information and help those people. Dimitri, what's your take here?
Starting point is 00:27:58 Well, obviously, the scale and the numbers of the notifications are pretty interesting here, but what I found particularly interesting is how they're notified, right? There's a lock screen notification on the iPhone. There's a notification in the settings tab. There's an email that goes to your Apple account, all sorts of things that they use to make sure that the user doesn't ignore it. And this actually harkens back to our report at CSRB on the Microsoft Exchange Hack. Patrick, I know you remember.
Starting point is 00:28:28 I was deputy chair on that review. And one of my pet peeves was how so many people that we talked to, so many victims that Microsoft, had notified, just ignored the email because they assumed that it was efficient email. And we actually proposed a whole notification scheme where phone vendors, Apple and Google primarily, would build this into the system to enable users to see right from the lock screen, from the home screen, the fact that they've been compromised. And I actually went further than Apple did here and said that this API should be actually exposed to trusted vendors that could use this for a notification.
Starting point is 00:29:08 to users of other activities, other compromises from their other accounts or link to their Apple or Google Android accounts. So hopefully it's going to be a nonstop parade of pop-ups, man. You remember when you want to know. Well, people don't care anymore. I mean, there was all of these legislation passed in the United States over the last 20 years at a state level saying that people would need to be notified if their data was breached. You know, a non-stop, man, people just, their mailboxes, their physical mailboxes are full of physical. mail telling them that some Russian hacker stole their SSN out of whatever, you know, and they just take that stuff, they put it in the bin, they don't care. Yeah, so if the notification is your data
Starting point is 00:29:48 stolen, I agree with you, but if the notification is your account's been hacked, you know, that's something that you may think twice about and because, you know, if it's your entire email inbox, I'd want to know if someone had access to it. Yeah, yeah, look, fair point, fair point. Yeah, if your, if your Gmail account got owned, would it be good to get that sort of notification through your iPhone probably yes i see where you're coming from now uh talking about some research here that i'm conflicted about because it is sort of stunt hacking uh someone's figured out how to plug a small device that they've engineered into a port on a bowing 737 jet which is of course a very very very common you know short to medium haul jet um apparently you can just pop an
Starting point is 00:30:32 unsecured access panel uh if you have physical access to one of these planes and stick this device in it. The device itself is interesting though because what it can do is feed bad information to the flight management computer and a couple other systems. It basically gets on a bus and it can manipulate sensor data and things like that, which is very dangerous obviously for a plane. Interestingly though, it can also connect up through the onboard Wi-Fi system to get out. So you know, you can have real-time C2 over this device and over the plane, over aspects of the plane. you know, sensors while it's in flight. Now...
Starting point is 00:31:12 That assumes the Wi-Fi actually works, which it rarely does. That's true. That's true. So there's a few different things to think about here. First of all, my first thought is, well, if you've got physical access to a plane on the ground, we've seen instances where a B getting into a pitot tube has caused serious safety incidents. Pilots should also notice, you would think, a good pilot's going to know when some of these readings start to conflict with other indications that they're getting in the cockpit. So that's another issue there, but like that relies on a pilot being perfect.
Starting point is 00:31:46 So I sort of think, well, what's the point of this? Is this stunt hacking? Is this hacking for publicity? And I don't know, because you look through the work that these researchers have been doing, and it's been ongoing for literally years, and they've worked with Boeing on this. They've been, you know, keeping Boeing apprised of everything that they've found. I don't know. Is it an intellectual exercise? Is it dealing with some of the way? is it dealing with something real? Does this mean we need to respond
Starting point is 00:32:10 and have better physical security at airports, which already seems pretty good? Dimitri, did you go through the same thought process when reading this that I did? I did, and exactly like you, I was thinking, well, if you already get access to a panel of a Boeing jet, well, maybe you can put some explosives in there and not bother with all the cyber stuff, right?
Starting point is 00:32:29 It seems way too complex. Then I was thinking, you know, getting a coin-sized device through airport security probably easier than getting it through, getting explosives through. So there might be some value here. I don't know. Curious for your thoughts. How do you even combat this?
Starting point is 00:32:44 Like, you know, yeah, you can put a lock on it, but, you know, anything can be broken and, you know, can you build authentication into that bus port? Not sure. And, you know, the keys would have to be hard-coded so someone could eventually reverse engineer the keys. So I'm not even sure what can be done here. I think their suggested fix is putting epoxy over the port, which, okay, that's great, but then you don't have access to the port anymore.
Starting point is 00:33:10 Yeah, I assume the port is there for a reason that they put them on planes for. Yeah, so that's it. Now, we've got a bunch of stories here to talk through, which I think we're just going to combine them into one, right? So we got this story. There's a data theft campaign that's been dubbed City Forum. This is a SaaS security firm called RICO has uncovered this campaign. And there's just some box out there scanning for over-provision guest accounts on Salesforce and Service Now instances and just grabbing all of the data. We've got a separate campaign going around targeting SAP Commerce Cloud, again, exfiltrating data.
Starting point is 00:33:52 Shell apparently has been impacted by the latest Klop campaign. This is the one that we spoke about, didn't we, James? Yeah. When they first kicked off the campaign, it's targeted, what was it? It was PTC Windshell, the product, enterprise product, life cycle management software platforms. So now we know that Klopp has gone around. They've got data from Shell, Phillips, GE. So this campaign has been successful.
Starting point is 00:34:22 And now they've moved on from the data harvesting to the actual data ransoming part of the campaign. We've seen Uber Freight has also been owned by a group called Helix. So, you know, this is actually good news. Tom in Seriously Risky Business last week wrote about how, you know, this is great because people are moving away from ransomware. Ah, complicated attracts the wrong sort of attention from governments towards data extortion, which they can still get paid, and it is much less disruptive to society as a whole. So his take is governments need to double down on hitting the actual encrypting ransomware crews
Starting point is 00:35:00 to drive more people to this sort of activity. But there's an awful lot of it at the moment. Dimitri, what do you think? Do you think this is actually a good news story? Because that's where I sit on this. Well, the good news story was the first one that USG engaging private sector actors will solve all of this, right? Well, maybe not these ones. Well, look, there's no question.
Starting point is 00:35:23 This is better than disruption. There's still some of it going. on, let's be honest. It's not gone away completely. But yeah, if you had to choose, I'd prefer not to have either, but if you have to choose, data X-fill is much better than, you know, disruption. James, is there anything remarkable at all about these campaigns? Because it all looks like real basic hacking. It also looks like the sort of thing that I think AI agents are going to be so good at doing that this, you know, I hate to use the term, but it's like low-hanging fruit. And I think it's all going to disappear pretty quick, thanks to AI agents being real good.
Starting point is 00:35:55 at finding vulnerable systems like this. But yeah, I mean, is there anything interesting here in this at all? Well, I think it's somewhat interesting that not only are we seeing these groups, to your point, target the biggest prizes, and that's the good news story out of this, right? They're going after the people that can pay the big pockets. But they're smart about it. They know that, I mean, these, like, I don't think anyone with just a general sort of hacking
Starting point is 00:36:17 ability would sit back and say, let's go after flex PLM and windchill PTC, because they're just really boring, enterpris-y kind of products. But if you want to target the biggest prize and the biggest sort of companies in town, you've got to go after these systems that they've got, right? The SAP High Risk Commerce Cloud one that we mentioned briefly before, same sort of thing, right? So I think that's the interesting thing. It's taken ransomware from being so indiscriminate in both what it targets and how it gets into this. This is just such a deliberately targeted and curated and tuned attack that I think that's an interesting element of the trade draft.
Starting point is 00:36:52 Yeah, we've also got a report here that looks at Blackfile, has a nexus with the comm, Google threat intelligence group tracks them as UNC 6671. They're going after financial companies and I think hedge funds and whatever. And they're doing a lot of vishing and the usual sort of stuff. So look, it's a booming crime type at the moment. And yeah, that is one I guess to track. Dimitri, you had something to add? Can I just do a quick plug?
Starting point is 00:37:16 Everyone should read the CSRB Lapsis report. The fact that we're seeing the same tradecraft still used years later, just absolutely amazing. but you know this is something that absolutely people can deal with we had slew of recommendations for victims or potential victims for how to deal with this go read it yeah no it was a good report that one for sure uh okay so the shield break vulnerability this is a privilege escalation bug through defender there's no patch for it at the moment and it was um this is another nightmare eclipse one where this is this anonymous uh you know researcher who waits until Microsoft is published a patch Tuesday, then drops O'Day on them.
Starting point is 00:37:56 Pretty funny stuff. I mean, unless you're a Microsoft Defender, unless you're a Microsoft Defender customer. And I think that's the point. Whoever this is, they're just out for Microsoft's throat. And I mean, it's all in the game, right? And I find this sort of stuff pretty funny. So be nice.
Starting point is 00:38:11 Be nice to the very, very skilled researchers because they could actually cause you some real drama. I think it's, this person has dropped enough O'Day, right? in Defender specifically over the last year that if you're a defender customer, like if this stuff starts getting used by threat actors, as a defender customer, you've got to be thinking about switching to a different provider. Dmitri, how would you have handled this when you were, you know, Crowdstrike CTO? Well, first of all, maybe we have it all wrong. Maybe it's not an anonymous research or maybe it's just Chad GPT.
Starting point is 00:38:42 But look, I can't believe that we're having yet again 20 years later the same arguments about coordinating vulnerability disclosure notifications, periods, whether we should start lawsuits or threaten lawsuits against researchers. It seems like we've been through this an awful lot, and we've gotten to a better place. I don't know how we're coming back to the same issue again and again and again. But look, obviously, researchers need to work with companies to make sure that the broader ecosystem is protected. There are billions of people using Microsoft Defender, and you want to make sure that you don't expose them on necessarily.
Starting point is 00:39:19 you, but Microsoft, let's not threaten researchers. We've been through this before where people are threatened with arrests and what have you at Black Cat and DefCon. Let's not go back to that. No, no. I think there's plenty of blame to go around on this one. Let's put it that way. We've got an item here just talking about how the Kim Wolf botnet, which we've covered a little bit on the show, it is being rebuilt to survive takedowns.
Starting point is 00:39:43 I think, you know, these Operation Endgame campaigns, targeting botnets as well all of these takedown operations I think are going to stimulate a move towards take down resistance C2 which has been a known quantity we've long known how to do this
Starting point is 00:40:02 I remember like immunity security you know Dave I tell's company like 15 years ago was demonstrating C2 via comments in Brittany Spears's Instagram or whatever right so add some tour add some blockchain add some celebrity Instagram comments like this is
Starting point is 00:40:18 a very easy thing to do. And I'm frankly surprised it's taken till now before people are started to do this in earnest. Dimitri, do you think this is going to be a switch, like a big switch or maybe it'll fizzle? Well, this is not new, right? Peer to peer botnets have existed, I think, since 2006 or 2007. People have used C2s and GitHub and all sorts of places. I think social media, Twitter, I remember there were Twitter botnets or botnets using Twitter C2. So this is not new. The problem for the botnet owners is it's pretty hard to keep control of this, right? And, you know, if you're putting this on the blockchain, that's sort of a unique method. And I think that's something that's more rare. But this comes with a cost. And, you know, centralized
Starting point is 00:41:10 C2s exist for a reason, not just because it's easy, but because you have full control of it and it can't escape out of it. And with peer-to-peer botnets, for example, my team at CrowdSrike has taken down Game of Zeus botnet and others, the Storm Botnet back in the 2000s. My team at McAfee did that. So that's the problem if you distribute it. It's much, much easier to take it over.
Starting point is 00:41:35 And, you know, if you're using Britney Spears account, a C2, well, you know, Instagram, meta can take it over. Well, I mean, that's always been why people haven't moved to things like domain fronting through, you know, big CDNs or whatever. Like, for that reason, they don't want some threat group at, like, Microsoft to, like, just erase their botnet. But I think that you can have multiple paths, multiple redundancies, and make these things very resistant to being taken down.
Starting point is 00:42:00 I think that's where we're going to go. Now, look, I'm just going to whiz through the next few because, sadly, we are out of time. But if people want to read these stories, they can hit up our show notes over at risky. dot biz. There has been a guy in Spain who got arrested for doing video deepfakes to try to obtain fraudulent certificates. This is really cool cyberpunk stuff. Everybody should go and read about this. There's a link to a story in the register where you can read about that. There is a bug in Mac. Port 5900. I'm like, hang on, isn't that VNC? And it's Mac's like VNC equivalent, which apparently uses some of the guts of VNC for its remote screen share thing. Man, if you've got a Mac on a real
Starting point is 00:42:40 world IP with that port open like you probably already got owned but thankfully I think they're just dropping crypto miners which is hilarious. There's a critical in VMware vSter which gives you a reverse SSH shell that'll be nice a lot of chaos going to be caused by that one. A company in Poland my doctor the healthcare software provider they got owned apparently there is like data on up to 19 million people are stolen through that breach so that one is probably worth keeping an eye on. And we've seen a bunch of crypto hardware wallet providers getting their data stolen, which has coughed up customer details, which ain't great because that means someone is going to knock on your door, hit you over the head with a hammer, and steal all of your Bitcoin. So
Starting point is 00:43:23 happy days there. Now, just before we go to, I want to give a plug to the unprompted conference, which is happening in Sydney, September 18 and 19 in the city. It is going to be an absolutely fantastic event. Mark Dowd is organizing it. Confirmed speakers already include Shane Huntley. We've got Chompy. We've got Ash Fox and Ozzy who I haven't seen for quite a while. He's over
Starting point is 00:43:48 at Google. There is going to be some Frontier Lab representation there as well. So as I say it is on September 18 and 19. You can find the URL at unprompted. com. We're bringing our whole team like James and myself will be there. Tom's going to be there. Ambley's
Starting point is 00:44:04 going to be there. Everybody, risky business, coming to Unprompted Sydney. So get yourself a ticket. It's going to be a fabulous event. It's all about security and AI and all of that good stuff. So we hope to see you there. But that is it for the news. James Wilson, Dmitri Alperovich.
Starting point is 00:44:19 Thank you so much for joining me to talk through all of it. It's been fascinating. Thank you. Thanks, Pat. What a week. That was Dmitri Alperovich and James Wilson there with the check of the week's security news. Big thanks to them for that.
Starting point is 00:44:35 It is time for this week's sponsor interview now. we're chatting with Damien Lucie, the chief executive and founder of Nebulaq. Now Nebulaock started off as a AI-powered, like, agentic threat-hunting platform. But what they quickly realized is what is a threat hunt, if not a detection, right? So they realized that really, if you do rapid threat hunting, it's basically a detection platform. So now they're kind of moved in a direction where they're building more of a real-time graph and doing threat hunting on that graph in real-time. So look, it is a detection platform.
Starting point is 00:45:09 They can also help you engineer detections for the rest of your detection stack, so on and so forth. But basically, Nebulauch, part of it at least, is turning into a clean sheet redesign of what a seam actually is. And as part of that, you've got to build your graph that you can run detections on, and you've got to decide what's in the graph and what can be grabbed agentically in each investigation to bring context in that the agent can use to decide whether or not something. is suspicious or not. So yeah, that's really what this conversation is about, about designing clean sheet of paper, what a detection stack should look like in 2026. So here is Damien Looney talking about all of that. Oh, and a quick note too. At some point in this interview, I talk about
Starting point is 00:45:54 how they detected a Southeast Asian crime group. That was me editorializing. Damien mentioned afterwards. He's like, well, we don't know that it was a Southeast Asian crime group or if it was espionage or what it was, just that there was a nexus with Southeast Asia. So that's my bad. You'll hear that in this interview. But anyway, here is Damien Lucie with a discussion of, yeah, modern detection, agentic. Very cool. Here he is. Seam as a market really didn't start out that way. Like Splunk was supposed to be Google for logs and then we in security suddenly realized that that was valuable. But if you think of the primary purpose of a seam as like the security operator or sport bench, what do they use it for?
Starting point is 00:46:34 They threat hunt, they do detection engineering, and they investigate. And while we started with this hunt-first approach, right? So continuous behavioral threat hunting and then realize, well, wait a minute, because the way that we've designed our threat hunts, our hunts capture and maintain state and memory, we can translate the intent of the threat hunt to a behavioral detection. Then we can test it and validate it and test for drift over time. We suddenly realized, thanks in part to our customers,
Starting point is 00:47:04 Well, like, hey, wait a minute, we can also do investigations. And the key with us around investigations was, I don't believe you need to store every single last bit of log data to be able to effectively threat hunt, due detections engineering, and also investigate threats that are relevant to your environment. But hang on, there's the problem, though, right? Because you never know what you're going to need in an investigation, right? That's the issue. 100%. Which is why people are like, let's just ingest everything and give half of our IT budget to Splunk. Exactly. And I would say like the just in case problem is I think why like half the IT budget goes to Splunk. We instead thought about like, okay, give access to all the data, but just in time. So the way that we think about it is you centralize your endpoint identity, network and cloud data because that's where actors achieve persistence. I pop an edge device. I, you know, write regs keys. I steal creds. I crush infra.
Starting point is 00:48:00 but like vulnerability management software, your CMDB, your CSPM, there are other bits of data across your security and IT stack that are valuable just in time, but like make no sense to store for two plus years. Okay, I mean, I totally get what you're saying, right? And it makes a lot of sense, which is a lot of data. You're going to build a graph, right, of the key stuff that's important. And then this is one of the best things about an agent,
Starting point is 00:48:27 and I've seen it in the work that I do with Drop Zone, which makes, you know, like a sock agent. for people with existing seams and whatever, is an agent can say, well, I need to look up some information on this domain name, for example. And it can just go off and do that to bring in the context as part of the investigation, right? So that makes sense.
Starting point is 00:48:45 But at some point, like, you know, at some point you might need to bring in a whole new data type in order to get the context that you need. And then, like, well, does that need to go into the graph? And like, how do you actually start to, how do you build this thing so that it's flexible enough to be altered as time goes on? And I'm guessing it needs to be flexible enough to be altered one way at this customer site and another way at another customer site. Like, this is actually a pretty difficult problem. It is.
Starting point is 00:49:19 And that's why we've been building for two years to get to the state that we're at. We talk about, we're launching the concept of our trace graph this week. It's Nebulaux context graph analogous to crowd strikes threat graph. So this graph, the graph that you and I are talking about, which is fed by our hunters and intel folks and detection engineers and all of that experience and different data pieces, all being available out of the box. How do you figure out what to and not to do? you have strong opinions about what the graph should be used for.
Starting point is 00:49:54 For us, this is about security operations use cases around proactive threat hunting, which is understanding persistence and lateral movement along with credential access. It's around good detections engineering, which is, okay, I want to build robust detections for the data sources that matter, endpoint, identity, cloud, and network. And then, like, how do you maintain it being flexible? You know, we talked about this on our soapbox episode a while back, building a schema that you can normalize everything to. That really for us was the other core unlock. So structuring a schema that allowed for flexibility so you could add new data types to it, but it was all normalized the one thing.
Starting point is 00:50:33 So the agents looking at everything in one happy place. But how can you normalize, you know, the data on a graph and have it still be like, I don't know. How does that work? because you're talking about a lot of different types of data. How do you have a normalized graph that's still flexible, I guess, is the question. Yeah. So the way that we did it was we have like our centralized database with the graph that runs on it. But then we also built this federated search component.
Starting point is 00:51:01 And the way that that works is we're able to dynamically capture, you know, with the swagger dog, so we use agents. But, you know, we can capture structure, understand the data types that we want to pull in. we're able to map that schema to this common schema and pull that. But the fundamental question you're asking really is like, how did we know which problem to solve first? How did we know which data to go after first? We spoke to our customers and determined like the core use cases.
Starting point is 00:51:31 And the core use cases for us, given the confines of where we thought data gravity should be, were first around vulnerability and vulnerability management. What exploits actually matter and what's the blast radius of mine firemen. The second was, okay, like based on my broad posture, like, what does my attack surface actually look like within my cloud environment, so CSPM? And then also asset management, like, how do we think about what is managed and unmanaged in my environment?
Starting point is 00:51:58 And how does that apply to the way that I think about threat hunting and detection engineering? So we started with the use cases and used that to kind of build up that first tranche of integrations and how we really thought through that problem. So we want to be flexible, but we also want to have opinions about what we integrate with and why, because you're right, Patrick, if I just say you can integrate with anything, you know, we're going to get custom app logs. Someone's going to bring in an application from, you know, 1986 that still runs on-prem in their basement. And we wanted to be really thoughtful about structuring that because graphs can get really big and really complex really fast. Well, yeah, I mean, that's kind of why I'm pressing on this, right?
Starting point is 00:52:39 And I'm wondering, too, what was something where something that you didn't initially include that either a customer decided later or you decided later, well, we should be bringing that into the core graph. I'm not talking about stuff where you can sort of agentically get the context later. I mean, core stuff in that graph. Like, what's an example of, you know, something you've changed there? Oh, my gosh. Network data. We had a long and spirited discussion about the value of network telemetry because it is verbose, but it can be useful, particularly when it relates to any sort of data exfiltration or if you want to understand lateral movement, but you don't have an EDR running on the device.
Starting point is 00:53:21 So I ended up coming to the conclusion using SSE, so secure service edge solutions like a Z-scaler, that we were actually going to ingest that data. And that's actually been a very recent development. This was something that for a long time we hadn't thought about, it and then in talking to customers and thinking about, okay, we want to address these use cases. That's funny that you mentioned something like Z Scalar, which does solve a lot of problems, but then you're right, like who is actually ingesting Z Scalar logs to spot weird stuff? I'm guessing not many people are even bothering to look at that stuff.
Starting point is 00:53:53 I mean, I'm guessing they've got their own monitoring that will tell you things, but in terms of actually taking that data and feeding it into some other product, like, yeah, that's got to be rare. Yeah. And I mean, it's because like it's very specific. specific, people tend to use Z-scaler for a few key use cases. And it kind of like lives in its own little bucket. But if we think about this idea of, okay, the value of a graph is that I can do entity
Starting point is 00:54:16 resolution and trace behavior that seems totally normal across a bunch of different places, that was like the last mile that we realized was like not just something I'd want just in time, but in fact, something that I'd want to be able to normalize data against and be able to access at any point in time. So it's been a journey. You know, we started on the endpoint, shifted and added identity, then it was cloud, now finally networking. We're at a point that back to where adversaries target, we've got a strong sense of data gravity
Starting point is 00:54:45 without, you know, a long list of data models that we need to support because we're adjusting random application logs for two years. Now, the whole point of Nebulauch, when it was first found that it was much more around the principle of threat hunting, right? And now it's like, well, you may as well do detection because what is detection? but you know real-time threat hunting basically and you found some cool stuff actually one of them was a crime group moving laterally through a customer where you traced it back to some origin IPs in like southeast Asia and India still not entirely sure what the group was trying to do
Starting point is 00:55:26 but they was definitely up to no good what the reason I'm mentioning it though and the reason it's interesting is it wasn't a case that they were popping reverse shells it wasn't the case that they were using traditional TTPs, they were like doing a lot of social engineering and then using remote management tools, right? Like, and I think that's the thing that Nebulox trying to do that's a little bit different, which is to detect these abuses of what's already in an environment. And most detection stacks, some of them are doing that, but I mean, it's not the norm. Let's put it that way, right? Like, it's not the most common way that people are doing detection these days. But what can you tell us about that incident because that one's interesting. Yeah, more than happy to. To be clear,
Starting point is 00:56:09 I can attribute who this group was, rather where they were coming from. But it was a really interesting example of folks using off-the-shelf software that doesn't trip any alert wires to actually establish persistence and operate completely unnoticed in an environment for weeks or months. We found a couple of non-standard RM tools being used. We found Zoom clients running where they shouldn't be and remote desktop protocols being accessed. And basically, like, while this person said that they were working in a particular part of the United States, and there may have been a host that was present geographically there, the person actually doing all the work and accessing that system was in Southeast Asian. The way that we found it really was by being able to correlate a couple key pieces of data.
Starting point is 00:57:03 So this was a malicious like fake IT worker sort of instance. Yeah, one of those people that, you know, wasn't who they said they were. And the key unlock for us was, you know, a remote management tool or remote desktop protocols being used in isolation is not inherently bad. But when you look at all of these in concert and you look at inbound and outbound IPs, you look at activity on the endpoint, you look at tools and systems being accessed, it paints a picture of somebody who's really not doing what would be expected of whomever they are supposed to be, but more importantly, doing a fantastic job of using really boring pieces of software, these green flags of behavior, to blend in completely. And it was only in looking that in context and going, well, hey, wait a minute, that we were able to say, actually, this person
Starting point is 00:57:56 is not who they say they are, and immediately alert the security operations team that we were working with. How was that surfaced? Was that staff doing that? Was that human-driven or was that agentic? So this was agentic. This was using our, I mean, we call it vibe hunting, but our threat hunting agents to surface this behavior. Yeah, that's pretty cool. That's pretty cool that your clankers were able to find this activity. All right, Damien Lucie. Always a pleasure to chat to you, my friend. Good to talk to you about graphs and detections and, you know, agents. A pleasure to chat you, my friend, and I look forward to doing it again soon. Thank you very much, Patrick. I appreciate it.
Starting point is 00:58:35 Catch you later. That was Damien Lucie from Nebulaugh there. Big thanks to him for that. And that is it for this week's show. I do hope you enjoyed it. I'll be back soon with more security news and analysis. But until then, I've been Patrick Gray. Thanks for listening.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.