The Host Unknown Podcast - 234: The Stockholm Syndrome Episode
Episode Date: July 2, 2026The usual malarkey of catching up on the boys, this week in infosec, rant of the week, billy big balls, industry news, and tweet of the week. All the goodness in one package. It's the host unknown pod...cast! Come on! Like and bloody well subscribe!
Transcript
Discussion (0)
That was a long half term that led into an Easter break,
which led into a mid-season.
A bit of a spring break and a summer break.
And now I'm really confused with the numbering.
Because I think I've just realized that Jav renumbered them back in the day,
back in like last year sometime.
And it's been so long, I can't remember who's now, well, obviously I'm right.
Jeff corrected what was broken for a long time, Tom.
broken. It was broken.
I counted them. I literally count. Oh my God.
Now we know why we've had such a long break.
It's you guys.
You're listening to the host unknown podcast.
Hello, hello, hello. Good morning. Good afternoon. Good evening.
From wherever you are joining us. And welcome. Welcome one and all. Welcome, dear listener to episodes.
23. I don't know.
230.
230.
Your podcast numbering will be slightly different for some bizarre reason, but there you go.
No worry.
Anyway, welcome.
It was a long break, wasn't it?
What was going on there?
That was a hot minute.
It was.
And it's Infosec week this week, as I'm sure most people know.
Of course. The comeback.
Don't call it a comeback, baby.
We're never away.
Exactly.
When I was telling people.
we're actually going to record on Friday.
All I got was this very cynical look from them.
It was like, yeah, right?
Sure.
Heard that before.
Like, oh, geez, it's like we've really,
it's like being an alcoholic who hasn't drunk for such a long time
and then boom, just falling off and nothing happened.
And then it all goes wrong.
That's exactly what's been happening.
And it's gone wrong for you guys who subscribe
because we're back on your devices.
Exactly.
Jokes on you, suckers.
Yeah, just when you thought all that space you saved on your device
from not taking so many filthy pictures,
it's now been taken back up again.
Anyway, gentlemen, how are we?
Jaff, how are you, sir?
Yeah, really good.
I don't know where to start from.
I don't know what updates I've given since.
Have you had your back passage filled in?
Partially.
Right.
Or is it just the way you're sitting?
Did I tell you that one of my neighbours found some council workers filling in a pothole and
Yes, you told us but not the audience.
Oh, okay.
Yeah, slid them some money and they, whatever leftover tarmac they had, they came and they
poured it into the biggest ditch that was there that was collecting a lot of rainwater
and made it extremely treacherous for us to use it.
So that pot's done.
Very good.
Is it still there?
because I remember at the time, Andy and I were doing some research on hardcore aggregates and the ability.
I know, I know. I mean, had I known you two had given up your surveying degree to work in Infosec or, you know, I would have consulted with you first.
But it's still there. I mean, it's very light traffic. We get maybe one car a day and a couple of motorbikes and just people walking on it.
Well, one less motorbike now in fairness.
One less motorbike, because...
You know, the irony is not lost on me.
I went to Infosec on Tuesday,
and it's in the Excel, which is a horrible location,
far out of nowhere, nowhere.
But it's got a fairly expensive but secure car park.
So did I hear...
Did I hear some inverted commas around secure then?
Yes, yes, you did hear them.
But it's great,
because motorbikes park for free there,
because they have one of those short barriers that you just go around.
Like many places do,
like Heathrow allows you to park your bike for free, for long term,
so does Gatwick.
So it's very convenient.
You just rock up, half of,
and like within 20 minutes,
if you've got fast track security,
you're in the lounge.
So,
hey, I'm just saying,
don't hate the player.
Look how he's converted over time, see?
I know.
He jumped on it.
He's with us now.
Yeah, the part that he's with us now just makes me feel,
oh,
anyway, do go on, do you digress.
So I spent Tuesday, I was at Infosec.
I had a talking session where I informed and educated people about the dangers of
AI and why we need to secure these agents and don't let them run amok within our
organizations.
And I think just as I was talking about the dangers of AI,
a couple of blokes came and they picked up my bike, put it in the back of a van and drove off with it.
So the irony is not lost on me that I'm talking about super advanced attack tactics and people probably used a screwdriver to Jimmy the lock and ride off my bike.
So now I'm bikeless and I'm waiting for police and insurance to do their investigations and hopefully, hopefully pay me some money back.
I mean, maybe you should have bought one of those sort of less attractive scooters,
like with the two wheels at the front or, you know, the one with the windscreen that goes over the top or something.
I would not, I mean, in all honesty, this bike is the most practical and comfortable I've ever had,
but it was not a looker.
You know, you could ease, it's probably the worst in terms of the looks that I would ever go for.
I would not be caught dead on one of those bikes with three wheels or the roof over the top, as you call it, Tom.
So talking to things in which aren't lookers, Andy, how are you?
Great.
Not too bad.
I've just been working, you know me.
I'm always working.
I'm the one that pretty much carries this group.
Sorry, this group or?
Well, you know, I mean, I've been pondering over what's put in the podcast.
You know, I need to take some time out and spend time.
with the mountain people in Peru to sort of find myself.
But I'm back and we continue.
Absolutely.
And for the first time, and this is just a warning to our listeners more than anything,
for the first time we have, we've subbed out the work of our script today, haven't we?
We did.
Yeah, we gave it to a...
I think we subbed out Jav as well.
Yes.
Jav is definitely multi-time.
Yes. I think he doesn't realize he hasn't got that thing where it makes his eyes look at the screen. He hasn't got a switch.
He normally puts it in post. Yeah, exactly. He is totally multitasking. No, I'm literally like only 2% of my energy has been given to you to right now.
Well, in which case, what are you doing below the waste that we can't see then?
We're not going there, but carry on.
Anyway, back back to your...
Talking about 2% energy.
Tom.
The amount of 2% battery life left.
Exactly.
I feel like I'm carrying this at the moment.
Bloody hell.
Host unknown knows me a back massage after this.
Same as you.
Very good.
It's been a busy few months.
I see you in another hotel.
Yes, another hotel.
Well, end of Infosec.
And some sort of late in the evening commitments or late into the evening.
in commitments yesterday and it was just too much.
So,
as in too much to travel all the way back home again.
So I'm off,
I'm back later today.
Once you finish this and I've had some breakfast and I'll get,
you know, work from here and then head back.
But yeah, it's been a busy, well, busy week, busy few months.
My goodness, the travel's gone through the roof in that.
Did manage to squeeze in a holiday to Stockholm though,
which was very nice.
Yeah.
And saw Java out there as well.
Yeah.
I hear there's many people stuck in Stockholm.
There's some type of syndrome that's keeping them.
Well, they keep going back because they like it despite not wanting.
Yeah.
Yeah.
Yeah, exactly.
Well, actually, did you know that that Stockholm syndrome has actually been debunked?
It's a complete, complete rubbish.
There's no such thing.
I did not know that.
Yeah.
No, I'm going to carry on believing it's true.
I don't care who debunked it.
It's clearly not debunked it.
clearly not debunked strongly enough.
Well, I tell you what, talking of debunking, let's get this episode going so that people
can then decide whether to debunk it or not.
But should we see what's coming up for you this week?
Let's see.
Oh, I've lost my notes now.
Oh, in Rant of the Week, I'm going to get very cross about people who refuse to patch.
Jav admires the cheeky audacity that really, you know, of those very, very important.
very well-known friendly cheeky-chirpy chappies are of some Iranian hackers in Billy Big Bulls.
Industry news gives us the latest, greatest security news from the PA Infoset Newswire.
And tweet of the week is something, something, something about M&A, mergers and acquisitions.
So I'm sure we're going to get some very down-to-earth and solid advice from Andy.
So let's move on show.
You can tell we're a bit rusty here.
Can I just say something quickly?
Yes.
Yeah, I quickly googled it.
It's like, while Stockholm syndrome is not in the diagnostic and statistical manual of mental disorders,
many modern psychologists and mental health exports view it as a less as a formal mental illness
and more as an intuitive, subconscious survival tactic.
So it's real.
just they put in a different label on it.
So it's not as real.
So it's not an actual syndrome then.
Now you're just splitting hairs.
But, and you don't have many.
What, says the man who, oh, it's real because some people say it's real.
No, no, because most of them, they say, quite did they say.
No, not most of them.
It's a subconscious.
The people who said that it's not an actually recognized syndrome.
No, no, they did say syndrome.
The people that say they have it.
Yeah.
Yeah.
It's a bit like this podcast.
It's not like we're completely mentally unstable to be on here,
but it is an intuitive subconscious survival tactic
in an attempt to remain relevant in an industry that's long forgotten us.
Do you know what?
You could put that onto a poster.
And I can picture it now.
It's a cat hanging from a tree.
And it says you don't have to be mad to work here, but it helps.
I think that would sell millions.
Can you print that for me?
I can print it now.
I can print it now because I've got an A-Zero printer.
We have really diverged here.
I've got an A-0 printer now at home.
Tom is now living out his dream from the 80s
after spending all this time in Athena.
In Athena, yeah.
Looking at posters wishing he could print his own.
Yes, yes, absolutely.
Absolutely.
In fact, to our audience,
if you send me in a really cool picture,
I'll select the best one, I'll print it, and I'll send it back to you.
How's that?
How's that?
That's worth it, because that ink's about 90 quid of colour.
Yeah.
That's it's not, it is.
Exactly.
Bloody is, you know.
See if any of the other podcasts would do that for you.
Yeah, I know.
None of those other quality podcasts, like Smashing would do that, would they?
Let's move on to our favourite party show, shall we?
It's the part of show that we like to call.
This week in Infosex.
It is that part of the show where we take a trip down Infosec Memory Lane with content liberated from the Today In Infosec Twitter account and further afield.
And today our first and only story takes us back a mere third.
Oh, have we got it?
Hang on.
A mere.
No.
Yeah, no, we haven't got it.
Yeah, there we go.
Thank you.
A mere 37 years.
to the 4th of June, 1989, one of my favourite stories ever,
when Robert Tappan Morris made history, just not in a good way.
He became the very first person indicted under the Computer Fraud and Abuse Act,
a law that had been sitting on the books for just three years,
waiting for its first test case.
So luckily, Robert, that test case was him.
His Morris Worm released the previous year,
knocked out roughly 10% of the entire internet.
So seven machines?
Well, in 1988, that was about 6,000 machines.
Oh, right.
Actually, so it was absolute chaos back then.
Now, Morris always maintained that it was an experiment.
He wanted to demonstrate security floors in the network, which was a great idea.
Unfortunately, he'd built in a deliberate override that made the worm ignore its own already infected check.
one every seven times to stop people faking it out with a simple countermeasure.
So it's smart in theory, but in practice it caused runaway replication that ground systems across
the internet to a halt.
And so lesson one, when you are stress testing your own fail safe, maybe do it in a lab
first or some sort of contain environment.
But his punishment for all of this was three years probation and a fine of $10,050.
just for breaking the internet.
That's a decent second-hand card.
He could have bought a house.
Bargain of the century.
Bargain of the century.
But anyway, here's where it gets even better in previous years
because we've done this story every year for like the last seven years.
In this part new for this year, for the long time listeners, you two.
Robert Morris Sr. was the chief scientist at the NSA's National Computer Security Center.
No way.
He was the man whose job it was to protect America's computers,
and he had a son that broke them.
So imagine that Christmas dinner, or Thanksgiving dinner for the US-closed.
So, yeah, the computer fraud and abuse act that he inadvertently stress-tested
is still very much alive prosecuting cases to this day.
So that law has outlasted the fine.
And arguably the lesson by several decades.
And Mr. Morris himself, he went on to co-found White.
combinator and become an MIT professor.
So sometimes that path from federal inditee to Silicon Valley legend is shorter than you think.
Do you know that happens all the time, doesn't it?
Yeah.
Crime.
Faint.
Crime doesn't pay except when it does.
He said when it does.
Yeah, absolutely.
Dear me.
Thank you very much, Andy, for this week's.
Industry News.
You are really rusty on the old soundboard.
Do you know what?
I'm pressing them
and it's taking two seconds to play.
Yeah, very likely story.
Yeah, well, whatever.
People who rate other security podcasts
better than the host unknown podcast
are statistically more likely
to enjoy the Harry and Megan documentaries.
Read into that what you will.
Should probably update that
because not many people know
who Harry and Megan are anymore.
No, no.
I think if you use something a bit more,
more timeless like Tiger King.
I think people...
Tiger King.
Oh dear, yeah, so timeless.
So not COVID.
Right, let's move on, shall we?
To...
Listen up!
Rent of the week.
It's sad to mother-friach.
All right.
Topic, dear and close to my heart.
More than 40,000.
C-panel and West...
our web host manager, WHM servers,
have been compromised, you know, so far, so Friday.
And before you think this is some zero-day situation,
patches have been available for all of these servers
since April 28th.
April 28th, that's over a month ago.
So patches have been released, you know, high priority patches have been released,
not patched, they've now been compromised.
Like, this floor actually allows attackers to take complete control of every website, database and configuration hosted on a compromised server.
And it's not, these aren't just like little blog sites or anything like this, banks, healthcare, millions of websites all around.
Just on, hosting all of these things, it doesn't matter.
chances are you're going to hit something that's hosted on something like this today more than once
and they're all potentially owned and the scans carried out by Shadow Server I love how they call
themselves these cool names show that the attacks are not slowing down they're accelerating
and it's just it's this the patch is out there but people just don't apply it now this this
is also even more important I think I'm just got to go on a slight segue here because
hey, one of the big things since we were off the air very briefly.
I mean, you don't have to be off the air for very long to get some big news in,
but is obviously Anthropics Mythos, right,
which is now going to start producing an absolute cavalcade of vulnerabilities.
And if we don't get our patch management cycles and, well, vulnerability management,
a patch management cycle sorted out and I'll get those processes laid down,
this is just going to get worse.
So the fact that this is still a story nowadays that there are high priority patches that haven't been applied for well over a month,
me put in huge numbers of sites at risk.
This is going to be all we're talking about in six months' time.
And yeah, it's shocking.
It's absolutely shocking.
And here endeth the lesson.
Webpost manager.
I have many sites that use web post manager.
It's one of the, it's packaged with any sort of host.
company. It's very free. I can't remember the last time I updated mine.
Like every time I log in, it was say last login, you know, six years ago, these installations
are out of date. You need to update them. Yeah. But these are your sites. What, just
average blog sites or something? Yeah. Yeah. Yeah. Okay. He's running a whole multi-million
dollar enterprise on the side. Do you take money to
other people's data and stuff on there?
Of course I wouldn't.
Well, in which case, that's your own lookout.
That's your problem.
But if you're a bank or if you're a, you know,
any other kind of healthcare organization
and you're using these packages
and you're taking people's money,
you are not showing a duty of care to your customers, right?
But you know what?
Like some sole traders,
they get these hosting companies,
They get sold this one-click install from Fantastico.
They use it.
Set up a site very easy.
Shopify integration.
That's it.
They're not developers.
They think they've got it.
It's like these poor people that drive cars with tires that are completely bald.
And, you know,
wow.
You know what I mean?
Aneux.
Seat belts that don't work.
Tom is really, really leading into the victim blaming today.
I was got it on it,
it slide just before you opened your mouth there. I was going to let it slide.
There are responsibilities. I'm not saying, you know, if there are basic responsibilities
you have as a business towards your customers. Who tells small business owners of these
responsibilities? So like the Facebook mum that baked cakes from home and then realizes she can
set up a site really quickly, who tells her about Infosec and the need to keep this stuff up to
date? The company that she hosts with.
should be telling her or should be or should be carrying out the patch.
They're faceless companies.
Because she's paying this company.
You pay these companies $70 or $35 a month.
Yeah.
You go with God.
You got a live chat if you want it.
There's no proactive.
So maybe this Facebook month should be paying $150 and actually getting her website
patched by the people.
But how would she know the difference between $150?
That's what I mean.
It's like people set the.
He's things up with the best of intentions.
But no one's told them what they need to do.
Yeah.
And what happens?
My IA is not faced at the Facebook month.
The IA is faced at the people who are hosting it and not informing their customers
and not patching the environments that they are offering.
And what happens when they patch it and it breaks something on the customer's website?
Are they going to then fix it for the customer?
Who's responsible for that?
It's their platform.
They should be testing it on their platform.
And on I earn on 50,000 different configurations that each of the customers have.
That's their business model.
But it's all third.
So this is the thing right.
So Web Post Manager is all third party stuff.
And it, you know, you could back in the day,
Kjumler or Drew Powell, do you remember all of these things?
One click install.
Yeah, yeah, yeah, yeah.
And it was like, once you did it, you go with God.
And it's like, it's up to you.
You know, you can use this stuff.
We provide it.
It's, I have sympathy for people on this stuff.
because it's not there.
I have sympathy, but conversely, if you're a bank running, hosting your platform, using,
using, using, I can assure you, no bank is using web host manager.
Really?
Yeah.
Do you know what?
There are smaller banks out there.
There are banks that really are doing also.
Healthcare, there's going to be a small, you know, surgery or something like that, right?
There will be, but they start small.
And no one tells them what they should be doing.
which is the hosting company's responsibility.
But then the hosting company is sometimes small business.
So, like, kid you're not right?
So the hosting company I use, or used to use, I still use.
I just don't have any active.
Well, I pay for them every month.
Go, let's not get into that.
The guy who used to run it, it was a single guy who started it,
and then he grew it to like a,
what's his marital status got to do with anything?
Well, no, but then it became a company.
And he employed about 25 people, like at its peak.
He died during COVID.
Right.
Okay.
And the irony was, he was massive COVID denier because you can go back to his Facebook history and stuff like that's stupidity.
Well, there is that.
But also at the time, there was a disruption to the site because he had all of the passwords, all of the keys, everything in his head.
like as a company and no one knew this you know they became this this company that sold
product internationally that you could sign up to and and stuff like that luckily they were
acquired by another company and the other companies sort of did migrations and have reenabled
functionality for customers but we had a hairy couple of months after his death as to
you know what was going to happen but I'm just saying the hosting companies themselves are
also small businesses that start up and don't necessarily know this stuff,
then what's they doing in that business?
Wow.
What do you mean?
Wow.
Well, so now you want to stifle innovation and entrepreneur.
We've got an incoming call.
Hello?
Yes, Tom, it's someone saying, what are you doing in the podcast business?
Hold on.
Hello?
Yes.
What?
Non-technical C-Sos?
How did that have become a thing?
I'm a non-technical C-Syser.
Who knows you need to patch your shit, right?
Again, if it's like my mechanic,
well, he only fixed half my engine.
He didn't do the oil leak,
but he's a small business guy.
What can I do?
There are the basics.
So mechanics, there's actually a well-worn path
to becoming a mechanic, right?
And there's things you need to understand,
like services and things like that.
What with online businesses is that anyone can start
them.
And there is no...
Anyone can start a mechanic.
There's no...
Bevel, basic...
Well, no, if you want to do MOTs, servicing, get stuff like that, stamps, you have to
meet certain criteria.
Yeah, yeah.
And I've never met a non-technical mechanic.
Like, I'm a mechanic.
I can just tell you what's wrong with your car and where the vulnerability...
I'm a holistic mechanic.
I'm an alternative mechanic.
But you've met a salesman, right?
He says, yeah, I can do that and it'll be this much.
It...
You're idiots.
Not maybe.
Rant of the week.
And I've got the jingles.
Use the power wightly.
This is the easy jet of security podcasts.
Let's be honest, your cheap ass couldn't tell a difference between us and a premium security podcast anyway.
All right, Jav, your turn.
Big Biggeralds of the reach.
Okay.
This week, we look at the balls on some Iranian hackers.
I don't know if it's Iranian hackers,
but I suppose that's what will lead with the headline,
because, you know, attribution is...
Is this you trying to protect yourself from the outset?
Yeah.
I already know I can't defend Iranian hackers in the Billy Big Bull,
so I'll just say, well, maybe they're not.
No, I'm just saying attribution is hard.
Not as hard as patching, but it is hard.
Well, one could argue maybe harder than patching.
Yeah.
And so the story is saying, is attributing it to Iranian hackers.
I'm just adding the sensible caveat that we don't know for 100% sure.
So let's just roll with Iranian hackers.
And they compromise.
Obama White House had, it was an account on Instagram, that former US President Barack Obama,
I mean, it'd be really weird if it was like, yes, above the White House was the account run by Bill Clinton.
No, it was, I think that bit of the attribution we can get correct.
So it had 2.4 million followers, but it had been completely dormant since about 2017,
which is click, click, click, click, click, 10, not 9 years ago.
Maths is hard as well, apparently.
I know, I know.
So the part that makes it a Billy Big Bulls is that the criminals who took over the account,
they did it by manipulating META's own AI-powered password recovery assistant.
So there's been stories about AI, META's AI.
If you don't have MFA enabled on your account,
or some setting enabled, you can actually go into it and say,
I've forgotten my password.
Can you send the recovery to a different email address?
And it would do that for you.
And then you could just log in.
You didn't research a story at all, did you?
Okay.
Am I confusing it with a different story?
No, you can actually do it even if MFA is enabled.
Okay.
Yeah.
I'll just edit that part out.
That's all good.
The educational content of this podcast, I didn't realize we could go into negative.
We like the Fox News of podcasts.
Right.
Do you know what?
Let me get that jingle made up.
Yeah.
Yeah.
So, fuck, yeah.
Anyway, once they got into the account, they posted AI generated images with captions
declaring the White House is under Shiites control,
which is where I think the attribution came from.
Yeah, because that's all they went on.
Anyway.
This has got Israeli false flag written all over it.
It does.
It does.
Meta eventually secured the account and removed the content.
So, well done, meta.
Yay.
It's like someone was, Trump was probably somewhere saying,
no, I always told you Obama was like that Kenyan.
He'd done that himself.
He was always a she, I knew that.
But anyway...
It's funny how Meta responded quickly to this,
but are still not taking down
ads that are posted by criminals
to get, you know, to...
But there's money in that.
Well, what I read was
if it's obviously a scam,
they won't publish it.
But if it's probably a scam,
they just charge more money for it.
You've got to get that risk money.
You've got to make bank.
Just shocking.
So Andy, tell me then, please.
What is the vulnerability if it's not the...
Is it that they ask the AI to reset the password to a different account?
Yeah, so you go onto it and you say, like, hey, my account's been hacked.
And the AI will check...
So the key thing is, like, you've got to connect via a VPN
that takes you to a similar location to where the accounts...
posted. So the AI just checks that, oh, okay, it's probably this person. So, so like, I've just,
I'm sitting in Ireland and I connect to a London VPN and I say, hey, my name is Javad Malik,
give me access to, uh, I've lost my password or my account's been hacked. I need to recover it.
Um, can you send the details to this email address? And so they do that. And so when they do
that, because they, the only check they were doing is, is it in the same location? Yes. Okay, cool.
It's probably him. Um, and at that point, because you say they're,
account's been hacked, they reset everything. So even if MFA was enabled, they reset it.
So you go back into it and then you've got the new account details. And obviously because
it's gone to a new person, they don't even send notification to the previously registered
address. How did this pass any kind of QA? AI, baby. I can't even watch the BBC
eye player in a different country because it knows I'm on a VPN. How the hell are they not even
checking that?
Vibe coding their way to
oblivion.
Oh dear God.
See, if you want to be angry at anyone, Tom,
if you want to rant at Meta,
don't run out those poor web host.
I have a track record of supporting Meta
on this podcast, don't I?
Yeah, you need to be a bit more,
well, you need to look at Meta
in a bit more detail if you,
you seem to let him slide a lot.
Yeah.
Me? Or Jav?
You.
Oh, sorry, sarcasm, right.
Yeah.
Dear me.
Anyway, that was Javs,
sweeping support
of the Iranian regime's attack
on Instagram.
Billy Big Balls
of the week.
People who prefer other security podcasts
are statistically more likely
to eject USB devices safely.
For those who live life
dangerously, you're in good company.
with the award-winning host unknown podcast.
Andy, despite our site is Shunky show notes,
which gives us a weird set of industry news.
What the hell?
It really has.
It has, yeah.
What time is it?
It is that time of the show where we take a...
We head over to our news sources over at the Infosec.
PA Newswire who have been very busy
bringing us the latest and greatest security news from around the globe.
Industry News.
CrowdStrike and Google take down.
glassworm botnet.
Industry News.
OS unvails a genetic research council at Infoset Europe.
To close the gas.
Industry News.
Tackers backdoor 32 NPM packages in Red Hat's official scope to steal cloud and CI slash CD secrets.
Industry News.
Google releases Android's June 2026 patches, 124 vulnerabilities fixed.
Industry News
HCTP2 bomb
Remote denial of service exploit
discovered affecting NG Inks
Apache HTPD
Microsoft IAS
Envoy and Cloudflare Pinguara
Industry News
shocking stories
And that was this week's
Industry News
Huge if true
Huge if true
We need to validate
But I think Claude needs to...
We need to sack that guy.
Yeah.
Those agents need a bit more tuning.
We need a higher quality.
We need to burn more tokens.
That's what I'm hearing.
Yeah.
Token maxing.
That's what it's here.
Yeah.
Exactly.
Your productivity jab is going to be measured on your AI bill.
Oh, dear.
What have we got here?
This glassworm.
Even the links don't work.
What's going on?
They do.
I can't click on mine.
O-WAS forms new agenetic research council.
Let's see if I can click on the...
I can't click on this Crowdstrike and Google take down.
Marked a significant shift in the threat landscape
that should serve as a wake-up call
for every organization that ships or consumes software.
Wow.
The 300 GitHub repositories were poisoned
using stolen developer credentials
harvested from earlier glassworm infections.
Wow.
So should it be a wake-up call for people hosting small websites on?
I would say so, absolutely.
How many wake-up calls do we need in an industry that seems to be?
Every day is a wake-up call or a reminder.
If it's anything like me and the number of times I hit snooze in the morning on my alarm, it's quite a lot.
Yeah, I get it.
But we've been waking up people since like 1982 or something.
I don't know.
It just comes a point when you've got to just do not resuscitate.
Yeah.
Well, let this whole InfoSec thing just naturally die a death.
Should we just move on to the tweet in the week?
Yeah, let's do that.
I think so.
Let's do that.
Anyway.
Industry news.
Industry news?
That was industry news?
Right. Well, oh, oh, I know.
If good security content were bottled like ketchup,
this podcast would be the watery juice,
which comes out when you don't shake properly.
In a niche of our own,
you're listening to the award-winning, host unknown podcast.
Actually, talking of awards,
there were no security blogger awards this year at Infosec.
I think they were.
No, there were.
Oh, no, there was a blogger meet.
up or something like that.
Yeah, but there wasn't an award, at least not run by Ascanti.
Apparently last year's got a little bit raucous.
A what?
What does that mean?
Lively.
What happened?
I don't know.
It's just what Yvonne said.
Last year it was a little bit raucous and there aren't enough sponsors for it.
Well, that's a real story.
They didn't get involved funding for it.
And I think it's one of those things that because for such a long time,
people don't blog anymore.
A lot of people don't blog.
The blogging scene isn't what it used to be.
At least people would base it on Twitter where the whole community was.
Now, that's broken up.
So how do you know who's posting what or whatnot and there's just LinkedIn, I suppose?
And is it substack making a comeback and stuff like that?
A subset, yeah.
Lots of people went to Medium, didn't they?
Yes.
For a while.
Oh, yeah.
But again, that was just like co-branded blog site.
It seemed a bit odd.
True power, WordPress, medium.
Just for the record, I still maintain my website.
I haven't updated the control panel yet, so please don't break it.
Yeah, I do.
I posted while England and playing France in the rugby.
Yes, you did.
Yeah, because I had a picture of Brian Honan supporting England.
Yeah, yeah, I remember that.
I was surprised to see that website was still alive.
Even more, that you were still alive.
I know, right, after four months away.
Anyway, shall we move on to this week's?
Tweet of the Week.
And we always play that one twice.
Tweet of the Week.
I'll take a sign with this week's Tweet of the Week.
This week's tweet of the week comes from Chris Back.
Backer.
Who says, for the last six years, I've been buying well-run small businesses for five-timed earnings.
In the first 30 days, I take the websites offline, move the companies to sad office parks with drop ceilings,
install fax machines at the front desk, and bring in 75-year-old actors to pose as a CEO.
I then sell the companies to people with MBAs for 10 times revenues so that they can feel useful turning the company around.
Genius. Genius. I love it.
I love it.
Hang on.
Clearly not true.
This would never pass diligence, but great story.
Great story.
It wouldn't pass your diligence.
It wouldn't pass the surface level diligence that, you know, any...
Why does your CEO have an equity card?
Yes.
Unless they're selling the business for like £2.50, yeah.
Exactly.
And also, do you know, the thing that really gives this away, where are you going to buy a fax machine?
True, true.
Probably come around your house, right?
Yeah.
Tom says, I very well not.
I'm the only supplier of fax machines in the UK at the moment.
Exactly. Exactly.
Oh, dear.
Right, excellent.
That was, I've lost it again.
I've lost it again.
help. I've lost it again. Ah, here we go. That was this week's.
The Sweet of the week.
Gentlemen, we come barreling into the end of the show. It was, um, I think we, I think the metaphor
would be the show could have used a little bit more WD40. Yes. Just, uh, it was a bit squeaky
around the edges. Um, the, you know, but we, we made it. We did it. I mean, for a first effort.
I, because ostensibly, we stopped for like four months, right? When he's starting up
again. It's like it started for the first time.
It's all right.
Consider this the very first episode.
Look, I'll just put some extra tokens into the editing software.
It'll sound absolutely squeakless.
We'll be glorious.
We'll be glorious.
Can we white label another security podcast?
That would probably be cheaper, right?
Look, we're not smashing security, okay?
Or the AI podcast fix.
We are not those two.
No.
Absolutely not.
Absolutely not.
No.
No, he's gone quiet.
We walk so they could run.
Yeah.
Yeah, that's right.
That's right.
I mean, you know, the fact that they have stickers and an income has got nothing to do with it.
Yeah, we've got an A-0 printer.
This is true, yeah.
This is a host of known, A-Zero printer.
What was that word you said?
I've forgotten the word that you said.
Rorcus.
Yes.
So the reason we don't.
post more frequently is because things get a bit raucous
and we don't have any sponsors.
Yeah.
Or even if we get people offering to sponsor us replies to their rematch.
I think Tom's asking price is far too hard.
Just a little bit of feedback is everyone that's offered to sponsor us.
Like when you open with like a four-digit multiple number plus unconditional
right for us to abuse their name.
Yes.
I think that's where it goes wrong.
Those two are our red lines.
We should probably look at them.
I was going to say,
because we pretty much unilaterally agreed on that, right?
I'm merely parroting company policy here.
If we wish to change policy, we can do that.
I think the problem is that we are probably all flexible on the price.
We know what Andy is.
Yeah.
We just would have, we won't be able to produce a podcast if it says like we're not allowed to insult or abuse the guest on it.
Oh dear.
Or Evante.
Who's that company keeps getting hacked?
Evanti.
Come on.
You guys could do with some publicity, right?
Yeah, it's right.
Lean into it.
You guys are hacked every day.
Just lean into it.
Let's abuse it.
Absolutely.
Absolutely.
Dear me.
Talking of abuse, Jav.
Thank you very much for today.
Much appreciated as always.
Yeah, you're welcome, I suppose.
And Andy, thank you, sir.
Stay secure, my friends.
Stay secure.
Rance of the week.
Fuck sake.
Need to swear.
Where is it?
I've lost it.
It's literally labelled outro.
Have you tried looking at it?
I want you just scroll.
There we go.
You've been listening to The Host Unknown podcast.
If you enjoyed what you heard, comment and subscribe.
If you hated it, please leave your best insults on our Reddit channel.
Worst episode ever.
R-slash-Smashing security.
I think I only come here to listen to the jingles.
That's my Stockholm syndrome.
That's my comfort place.
They do.
They are a very comforting listen.
