Sergio Villegas: if you've been listening to in Excel Access for a while, you know we spend a lot of time covering what's on the headlines, right? We talk about bridges, vulnerabilities, redactors and AI. A lot of it. I know. ⁓ but yeah, now is the time to step back a little bit and ask kind of different questions, or the same question maybe. So ⁓ instead of what happened, let's talk about what are you supposed to do about it. So today is one of those special episodes and the first one, so ⁓ welcome to this first special episode of the managed services ⁓ department. So what are what we are going to talk today is about different things. One is ⁓ threat intelligence and threat bullet and poli-rent intelligence, attack surface management, continuous discovery. So we are going to probably talk about some of the headlines that we already did in the past and yeah, use that from a new perspective about that stuff basically. ⁓ so I'm Sergio Villegas. I'm ⁓ Senior managing analyst for Bishop Fox and with me I have Richard Brown, senior op senior managing operator, ⁓ John Hunt, senior ⁓ security engineer, Dylan Sparks, ⁓ senior operator. And welcome everyone, how are you?
John Untz: Hello. Thank you for having us.
Richard Brown: Yeah, special episode, I like it.
Sergio Villegas: Thank you. It's like Yeah. Yeah, I and I know I know for for for our listeners ⁓ it feels weird because it's kind of the same people, but yeah, just different mindset.
Richard Brown: Yeah, and we talk all day
John Untz: Yeah, yeah, exactly. Yeah. I'm tired of talking to Richard. Can we do an episode where I don't talk to Richard? That's actually specifically what I want in the future from now on. Anybody but Richard specifically.
Sergio Villegas: Yeah.
Dillon Sparks: Yeah.
Sergio Villegas: Other people. Nah. Anyway, Young Society, it's always a pleasure to have you to have us, right? ⁓ so I have ⁓ four things ⁓ the agenda for today, four things we we would like to discuss. One is ⁓ quick debrief on DEF CON. I know it's this is ⁓ we are recording just after DEF CON happened, so we have some ⁓ quick stories for you. ⁓ then I have three particular stories of headlines, if you will, that I like to revisit. One is Jet Buffer.
Richard Brown: Yeah, yeah, other people.
Sergio Villegas: ⁓ second one is ⁓ escape models in OpenAI particularly. And the third one is Hades, or meaning shy hulut or who however that's pronounced, ⁓ three kind of ⁓ stories that I know we discussed in the past, ⁓ and particularly we talk about like the how quick we are reacting to those. So yeah. For starters, let's talk about DEF CON. I know DEF CON just happened over this weekend, right? I know this is going live this is going live later, but DEF CON just happened this weekend, so ⁓ quick takeaways from my end, right?
Richard Brown: Yeah.
Sergio Villegas: We participated in a lot of places. We were in the AI village, we were in Cloud Village, Red Team Village, Game Hacking Village, New Village, and Ausin for Good, right? Like ⁓ kind of just putting the world there. The capabilities that our team has is very broad, right? We even though we are a very hyper focused offensive security firm, we actually cover a lot of topics. So ⁓ yeah, I don't know, you guys what what what were your like favorite moments of DEF CON this over this weekend?
Richard Brown: Yeah, 100%. Yeah, so John and I actually went there and had a good time. So we saw a lot of talks talking about, we had a live podcast in there. We were at the Red Tail party and everything. It was really good time. It was interesting. This has been my second year. I go every other year. This has been my second year at the new location. And I think this was your first year, at the new location. Yeah, still takes a minute to get used to it. It's not the old way, but this year they had the headphones down there. That was a,
John Untz: Yeah, yeah, it was my first other location, yeah.
Richard Brown: ⁓ Good change I'll say
Sergio Villegas: Yeah.
John Untz: Yeah. Yeah. Yeah, so if like so for for anybody that wasn't there, right? So ⁓ Richard, like ⁓ you you said you were there the year before, ⁓ the or the the first year I guess that they were in the new location. ⁓ can you tell us a bit more just about like how it used to be versus how it is?
Richard Brown: Mm-hmm. Yeah, so before it, when it was at the hotels, when it was at the hotels, it was at Flamingo, Caesars, and come on, third one. But it's very disjointed and you had like a rush back and forth. And if a talk started around the same time, as you know, Vegas is very large, you were not making it back in time. So if you basically get to choose a talk and in the old, old days used to have line con where you could wait in the, you could wait for the talk before yours and then sit in there the whole time. And then you were able to see the talk you. They've changed a lot of that now and now you have to get tickets, not tickets per se, but you can't stand in line and wait for the next next talk. So you have to like leave the room after each one. ⁓ but the new place at the convention makes it much more connected. So which John and I were talking somehow felt less so, but at the same time it's, all under one roof now, which is very helpful for people going.
John Untz: Yeah. Right, right. Yeah, it's it's a lot easier to like get to the stuff you want to get to, right? As far as like a time ⁓ time management thing. and ⁓ and the headphones helped a lot. That's that's that was like the big thing for me, is like because it's all under one roof, it's a lot ⁓ it's a lot noisier. ⁓ but the stuff that I actually cared to like any if I wanted to go into a specific talk, if I wanted to go to a specific workshop or or something in a different village, ⁓ I didn't have to like sit there and like strain to hear the speaker. I could actually like engage with them and whatnot. ⁓ and there were still some other villages that were like outside of that main wing that were like super intimate settings. Like the the payment village is the one that sticks out in my head of like, you know, you walk in and it's just like I mean it's a it's two rooms and you know, you it's probably could hold, I don't know, upwards of maybe fifty people in there, but it was ⁓ it was a very like engaged setting. So I thought that was really cool.
Richard Brown: Yeah.
Sergio Villegas: And I think that's a that's a great ⁓ word kind of to start off, ⁓ engagement, right? Like talking about talking about engagement and I think something that is kind of curious for me is from from your per perspective guys, ⁓ when we engage in this type of events, normally we have like ⁓ proof concepts, C V E's, novel stuff dropping on those events, right? Because that's that's a perfect place to show like hey I got a new POC on a remote code skip, right? Like ⁓ fr from from that perspective, how
Richard Brown: Yeah.
Sergio Villegas: How do you manage or what's the workflow to kind of operate analyze some of this, right? Like how do you get from hey, I I saw a conference at DevCon to like now I'm testing that with my customers because yeah, it's important, right? Like it will be out there in the wild.
Richard Brown: It's very different. ⁓ go ahead Dylan, you wanna say something? I thought it lit up and lit up. Yeah, it's it's very different now than it was when I first started going. When I first started going, I was doing more consulting work. So I had ongoing engagements that were internal, external, physical, you know. And then when I saw something new, I could use it the next day. And where ⁓ nowadays I feel like they're getting a little more respect for the platform. Defcon used to be this like.
Dillon Sparks: Was I?
Sergio Villegas: Okay.
John Untz: It would have yeah.
Richard Brown: Wild West of events and people used to drop zero days on stage and that was like crazy. And then you were like, you know, operationalizing them that same day. Whereas now there's a little more respect. So now they've, they released less zero days or should I say less impactful zero days and do more of the responsible disclosure process. So the demos are like, Hey, four months ago we found this and now we're releasing it now. Cause there's already a patch CVE to follow. And so it's much less about
John Untz: Right.
Richard Brown: having to act on it right that day, and there's time to go back.
Sergio Villegas: Hmm.
John Untz: Yeah. ⁓ ironically there there is t you know, to to like not to take it all the way into like, you know, they're a totally professional, you know, bunch of ⁓ or crowd and an an engagement sort of crowd. ⁓ we d there was still that one incident right after the con where someone on a flight to Atlanta decided they were gonna wi fi pie an apple the place. ⁓ don't ever do that on that's that's real bad. But yeah
Richard Brown: Yes.
Dillon Sparks: Yeah.
Richard Brown: Yeah, I didn't see that till you posted it. Yeah.
John Untz: ⁓ yeah, yeah. I was fortunate that ⁓ that that was not my plane. ⁓ yeah, so but but to get to that point though, like I think that's ⁓ that's like an important thing to show like the growth of like cybersecurity in general as a like you know, respected and and and formalized kind of industry now is And I'm not gonna like steal anything that he said before 'cause know like, you know, Jeff has has has mentioned this exactly like on the stage when he's done closing remarks before, but like, you know, now they've got like policy at DEF CON. Like they have they have like I think this last time, like the former director of the NSA, General Nakasone, was was there at us doing another fireside chat. So it's like this is not this is no longer just like, you know, the the nineties culture hackers, right, that were just kind of breaking stuff for the sake of breaking stuff, right? Now this is like a super formalized process. So I I I love seeing that. ⁓
Richard Brown: Yeah.
Sergio Villegas: Right.
Richard Brown: Yeah, speaking of nice hackers. we're walking down in the area and John like disappears from me. And ⁓ I look over there and he's mesmerized because he had seen, you want to a finished story about the phone, the phone freaking the phone freaking. Yeah. You can go for a story. No, no.
John Untz: Okay. No, no, I I I want to see where this is going. Yeah, yeah, yeah. So that's fair, you know. ⁓ yeah. No, I I like it. Alright, so yeah, so ⁓ going back to like we were you were asking Sergio about like what's some of the cool stuff we saw there. ⁓ I you know
Sergio Villegas: Okay. Yeah.
Dillon Sparks: Hahaha
John Untz: There yeah, like you say, you turn the corner, it's it was on one edge of the the villages side. ⁓ they had like four four or five payphones ⁓ set up, ⁓ with like a P V X on the back end and everything, ⁓ to do like true to the like true true to the term phone freaking. for for like anybody that's that's like not old enough to know what a payphone was. ⁓ back in the day, I'll just say the day 'cause I'm not gonna like point at a decade or anything like that. ⁓ You telephones used to operate with like you know, these these dial tones and touch tones and whatnot. ⁓ and there's a mechanism called freaking, pH freaking, ⁓ that you would ⁓ use ⁓ at the time it was like a like a whistle in a out of a serial box, ⁓ to like Yeah, dial up tones. Yeah. Yep.
Dillon Sparks: It's like dial-up tones, right? I think Kevin Mitnick has a book that goes into some very hyperbolic stories about the fun of phone freaking. Yeah, think Shameless Plug, it's called Ghost in the Wire, I think.
John Untz: ⁓ really? Yeah. Is it ⁓ does it talk about ⁓ Captain Crunch? Do you know? Okay.
Dillon Sparks: ⁓ I read this book probably like five years ago, five or six years ago.
Richard Brown: It's been a while.
John Untz: Yeah, yeah, yeah. That's fair. I'll I'll I'll I'll quiz you on it later. Yeah, yeah. Proof that Dylan can read.
Sergio Villegas: Yeah.
Dillon Sparks: Proof that I read.
John Untz: But ⁓ but yeah, like that was the whole that was that was hacking at the time was was mimicking these dial up tones in order to do whatever, right? Get a connection, get a free call. Usually it was at the time it was get like long distance calls and stuff like that. ⁓ but they had an entire village set up not only to just like, you know, relearn those like foundational concepts that like, you know, brought hacking into the forefront, but also like ⁓
Richard Brown: Yeah.
John Untz: ⁓ they they had like a CTF set up ⁓ as part of that as well. And there's other there's a ton of other cool stuff. It's really cool that like there's there was a lot of new villages or like new to me I guess because I haven't been in a couple of years, ⁓ villages that I thought did a great job of bridging what may not be considered like cybersecurity hacking. ⁓ but Use those same skill sets to like show, like, hey, like like my greatest example here is the game hacking village, right? That's that's relatively new. ⁓
Richard Brown: Yeah.
John Untz: That was actually like my first foray into hacking was like doing like NES ROM hacking. And then that you know, somebody basically came along one day and was like, Hey, you know, that's like pretty similar to doing binary exploitation from like a basic, like foundational level. ⁓ and now we're using those same mechanisms to to teach, you know, the next generation, which I think is phenomenal. I think like like gamifying learning obviously is like a tried and true method. ⁓ and I think like what better way than than than teaching people, you know, the the in in the places that they are already at, right? I you know the younger generation especially I'm gonna point myself, I've got a game going behind me, right? Like video games are cool. What better way to learn than than using the thing you're already interested in?
Sergio Villegas: Mm-hmm. Hundred percent. Hundred percent.
Richard Brown: Yeah. And on the flip side of that, the new age hacking of AI world, right? Every talk had something about AI in it of some sort. So it's, you know, it was, it was nice seeing full circle, like John was saying, start with the phone freaking ending an AI hacking. Well, not ending, you know, let's see overlords, we're gonna take us out. But it was nice seeing, the full spectrum. So which
John Untz: Right. Yeah.
Dillon Sparks: you
John Untz: Yeah, yeah.
Sergio Villegas: Yeah. I I think I I believe talking about AI, right? Like right into our first story. ⁓ because our first story is actually AI. And it is very very particular, right? Like is it novel? Is it not novel? I don't know. I think we are just in the in the right time to talk about it. So our first story, Jade Puffer, first fully autonomous AI ransomware. ⁓ something that is kind of interesting for me is that I and I think that's part of why
Richard Brown: Yeah. Yeah.
Sergio Villegas: Conferences as high level as this have changed is because we see the same actors assisting these conferences, right? Like they they work same cybersecurity space as us, so they are seeing these new techniques and they develop this kind of stuff. ⁓ this is a a very particular one. This was activity seen in July, early July this year. And ⁓ really quick, right? Kind of read out ⁓ Jet Buffer first ⁓ fully autonomous LLM drive and ransomware operation with no human operator. directing the attack. Particularly what this uses is a specific C V E, C V E twenty twenty five, three, two, four, eight. ⁓ what that's the initial access, right? What it does is it gets to the to the initial access, ⁓ it exploits it and then it kind of starts ⁓ spreading. ⁓ something that is very ⁓ particular, right, is that it tries to ⁓ It's it's weird because the whole operation behind it is kind of not new or very immature compared to other ransomware as a service kind of ⁓ scenarios. ⁓ but how it's driving is kind of what's new in here, right? And ⁓ I I have two questions in here, right? Like your perspective. ⁓ when a novel attack like this drops, what's the validation workflow for you guys, right? Like how how do you look at this and be like, hey, I need to look at the CVE, I need to look at ATTPs, right? And ⁓ how
Dillon Sparks: Thanks
Sergio Villegas: quickly can you determine whether a customer environment is exposed and potentially exploitable. I think that's a a that's a interesting question, right? Vers versus just theoretic ⁓ versus just vulnerable in theory, which is a valid point of view.
John Untz: Mm-hmm.
Dillon Sparks: Yeah, it's an interesting one. It's interesting giving the autonomous aspect of it, right? Like from start to finish, how quickly it can be run and at scale. So trying to defend against that ⁓ creates its own challenges, its own unique challenges. From the very beginning with... any sort of attack chain really, what you're looking at is trying to identify all the moving pieces that encompass that specific, know, CVE or exploit chain. And then the first thing you're looking at is how do I fingerprint this, right? So that I can quickly detect my inventory and wrangle all of, or herd all of the cats, if you will, that might be affected by this. ⁓ And again, a lot of that is looking for shadow ID that you may have missed previously, right? It's exactly why we're running an active scan versus a static Excel sheet that I looked at a week or two ago or the last time it got opened and updated.
Sergio Villegas: Okay.
Dillon Sparks: which you're hoping is fairly frequent if that's how you're operating. ⁓ Yeah, yeah, so ⁓ again, you wanna start with that active fingerprinting, right? What's, again, that's gonna tell you a few things. ⁓ What's actually up and what's reachable from where I'm scanning from, right? And there is a difference between externally exposed assets and internally exposed assets.
Richard Brown: Gosh, yeah, so common nowadays.
Sergio Villegas: Yeah.
Dillon Sparks: But once you actually get that asset pool and that identification done, then you can start looking at more verbose fingerprints. So looking at specific versions impacted by the CVE or that exploit chain, are there any weird caveats that, you know, while this is a vulnerable version, it's not actually exploitable because of maybe a configuration. I can't tell you how many CVEs I've read in the last couple of months where it's like under
John Untz: Mm-hmm.
Dillon Sparks: crime conditions because we disabled all of the security features that naturally come on this product, we were able to get an RCE. It's like, yeah, dude, just log into the box locally at that point. Like, come on, man.
John Untz: Right. Right. I think I saw I think I saw one recently that was like it was like a TLS vault, but it was like the vulnerability was like you have to downgrade TLS to an existing vulnerable ver like something that's vulnerable to other exploits anyways. And it was just like, well that's not really that's not new and novel. I think the other big point is like impact, right? ⁓ you know, if something's exploitable but all it does is tell you the version number of the software that's running. I mean yeah, that's not great, but that's not the same thing as getting arbitrary like code execution on a box.
Richard Brown: Yeah.
Dillon Sparks: Yes, yeah.
Sergio Villegas: Yeah.
John Untz: ⁓ and so like when like for me like when I'm looking at like triaging like on like the on the research side of things, like that's that's like a an immediate scoping concern of mine. It's like okay, reachability and and impact, like where where do those two align to like create a big boom? and then, you know, how how widespread does it go from there, right? Richard, I'm definitely curious you've but you've been you've been doing this for long longer than I have. I'm definitely curious what your take is.
Richard Brown: No, you're right there. mean, qualifying CVEs is our job, right? And when we look at, there's two sides of the coin. One is Sergio's side, which I'm hoping he's talking about, the targeted nature of it. And one is opportunistic. And we're trying to cover the opportunistic side of it. You're probably not a target for this, but as most hackers do, they spray and pray. They get something and then they hope it's something juicy at the end. But. I always have a problem when they're like, ⁓ it's autonomous. Cause we've had worms forever that just burrow in. We've had viruses that self replicate. you know, so it's like, ⁓ this is the first ever autonomous. mean, I remember ⁓ not too long ago, there was a MongoDB. ⁓ Mongo, is it MongoDB? I think it is. But it was a ransomware where they would ransom it and then send you the email, right? And I can't remember, it was in the news, but someone paid the ransom. they got their data un-ransomed and it was ransom by someone else before them. So they had to go pay another ransom somehow. it's like, so yeah, think the Dylan and John hit on the head with qualifying it. And then the other aspect is gonna be, are you at risk of this? And that's where I think Sergio, your expertise comes in.
John Untz: Mm.
Sergio Villegas: Yeah.
John Untz: Yeah, yeah, I'm curious, especially on like Sergio's side. Like I you know, like we we you rate like Richard, like we we do a lot of look at like I I like how we put the opportunistic of just like, you know, who you know, if if anybody had had the weapon, how can they you know, how could they use it? You know from Sergio, from your point of view, like when you're looking at how does like a specific threat actor how how are they gonna gonna to gonna use it? I'm I'm super curious what that looks like on on that.
Richard Brown: Yeah.
Sergio Villegas: 100%. And I think it's part of the same qualification process, if you will, right? Because at the end of the day, when we talk about like, yes, trade actors, they have they have the same toolkits, they have the same exploits as we have, maybe more, right? Lightly more than us. But they they need a reason. And that's the particularity in here, right? Like, hey, we are seeing this attack. And I I not saying for this particular headline, right? But let's say this particular headline.
Richard Brown: Yeah.
Sergio Villegas: in in in between lines it says like it's it's against the financial sector in the US, right? And my customer, it's perhaps ⁓ a random manufacturing company in Ecuador. I don't know, right? Like is is are they the the the possibility of them being targeted by an actor it's not necessarily the same as them being vulnerable by this, right? They they are they are both relevant in its own way, right?
Richard Brown: Yeah.
Sergio Villegas: One is from the vulnerability intelligence piece. Okay, yeah, they're they're vulnerable, right? Like they check all the marks to hey, you have a potential risk in here. You only need that threat. And and and I I think that's where we share the word threat. ⁓ the threat is that opportunity for someone to look at you being vulnerable, being like, hey, here goes the hammer, basically, right? and and that's that's yeah, that that's what Richard just mentioned, right? Like
John Untz: Right.
Richard Brown: Yeah.
Sergio Villegas: It's li are they likely to attack you? No. Does does that make the impact or risk less? No, right? It just made you likely to be more aware that hey, there is someone out there with a hammer targeting you in particular, right? And you ⁓ and and the theory of it being vulnerable because maybe you have an exposed, let's say Mongo, right? Richard, just speak on Mongo, so let's let's let's argue. Yeah.
Richard Brown: Yeah. Yeah, I'll attack all the big ones.
John Untz: Yeah.
Sergio Villegas: Yeah, let's say you have an an exposed mongo, right? But you can validate it's it's vulnerable. But you know someone is after Mongo in your industry, in your sector, right? Like you need to have a certain level of awareness, right? So I think it's a compliment, right? One needs the other, but they are not ⁓ mutually exclusive. and and that's that's kind of interesting, right? Like seeing these different no novel, right? For lack of a better word, I know it's not necessarily novel, but it
Richard Brown: Yeah, yeah.
Sergio Villegas: I didn't I didn't write the headlines, man.
Richard Brown: Yeah, I'm just a hater. I hate how we have new names for the same attack, right? I remember when credential stuffing came out and I was like, ⁓ what is this thing? ⁓ what is this? Password reuse? Password spraying? that's not, I was imagining like almost like an overflow of passwords. You put more than one password in there and it picks the one that's right. So I was imagining and so I'm just a hater. I apologize.
Dillon Sparks: you
John Untz: Yeah.
Dillon Sparks: Yeah.
John Untz: Yeah.
Dillon Sparks: HAHAHAHA
John Untz: Yeah, no, I did same thing. Right.
Sergio Villegas: Yeah.
John Untz: Ha ha
Sergio Villegas: No, no, that that's perfect fine. I I think the podcasts have become ⁓ just hating on the headline. Yeah.
Richard Brown: Yeah.
John Untz: Yeah.
Dillon Sparks: Ha ha ha!
Sergio Villegas: Bridge, ⁓ the ⁓ the Hugging Frace Bridge, ⁓ the escape sandbox for the open AI models we have. I think we talked this a few weeks ago. This is something that happened between July sixteenth ish. Between July sixteenth to twenty-one, ⁓ several news reported this. ⁓ quick reminder of what happened here.
Richard Brown: Yeah.
Sergio Villegas: During an internal capability evaluation, OpenAIS model, ⁓ particularly ⁓ GPT five dot six SOL and another un specified pre-release escape their sandbox, right? It's basically a zero-day package proxy ⁓ that reached the internet. So basically what happened is that you were ⁓ able to ⁓ bypass the different secret measures it had and provoke ⁓ chain privilege escalation and lateral movement into the production infrastructure. That's kind of the The the type for you. Right. ⁓ there were some models running it. ⁓ something that was very interesting in here is that ⁓ how in phase detected and contained it on july sixteenth, right? Well it wasn't publicly disclosed or or let known to other people until five like five yeah five days ⁓ later. ⁓ open AI then they connected kind of they connected the the dots and and say like yeah it's happened. ⁓ the cloud was allegedly ⁓ Sand was described at as highly as isolated. It wasn't, right? It was a very it was complex in certain way. ⁓ just because escape escape sandbox kind of attacks are complex ⁓ in that sense. So yeah, questions for you guys. ⁓ kind of the the interesting part. ⁓ how often and and this is this is kind of the question of the same the same attack being renamed to make it new but it's not really new, right? How how often do you find the same thing on an engagement? Right? Where it's like
Richard Brown: Right.
John Untz: Right, right.
Richard Brown: Mm-hmm.
Sergio Villegas: Hey, I find the same exact vulnerability since that I reported maybe one week ago, two weeks ago, one year ago, right? If it's a long running customer, particularly for those customers that are like always active, like in a in a tax surface management type of service, right? ⁓ yeah, what's what's the gap in here? Is there is that a technological gap? Is that a process gap? Why are you finding the same thing?
Richard Brown: Yeah, that's a question. It's been a while since that's happened to us. Since we're on the continuous side, we have this integration with clients where we can remediate right away. Right. The point time pin tests. I have several times where I've gone back the next year to the same client and had the same vulnerability. I remember I was on an internal and this is years ago now, but I attacked them three years in a row and got DA the same path three years in a row. Right. And that's, that's not good to anybody because I waste my time doing those things. So Anyway, but the same path happens a lot and it's not even the same path, it's the same vulnerability. It's the same people using exposed misconfigurations and then they get popped like, cool, I'll use craft CMS instead, but then they'd misconfigure that the similar way they would WordPress. And now I can install plugins. And so.
John Untz: Right, right. They they basically just assumed that by getting a different product or by getting a newer product or whatever that would be the solution, but it can't solve the misconfiguration problem like that. Yeah.
Richard Brown: Right. Mm-hmm. 100%.
Dillon Sparks: Yeah, like a networking nerd, like the first thing you think of, is like, there's a difference between physical and logical isolation, right? Like in order to have logical isolation, something has to be talking to that or know of its existence and be monitoring it, right? And so in that case, you're already creating a one-to-one connection between two different things, right? So it...
Sergio Villegas: Go ahead, go ahead, okay.
John Untz: Ha ha
Richard Brown: you Yeah.
Dillon Sparks: The logical isolation part, ⁓ I think is the biggest gap here when you're talking about trying to isolate either an agent or some type of host. Just remember that logic can change, whether intentional or accidental, ⁓ especially if you're a siloed organization. Imagine your infrastructure admins don't know that something's even over there.
John Untz: Mm-hmm.
Dillon Sparks: And then they implement one rule higher somewhere in the hierarchy. That's just like, I've got to go test something over here, but I'm being stopped by these intermediaries. So I'll just put this allow rule in real quick. And then suddenly, boop, that guy can escape.
John Untz: Right, higher in the stack, yeah.
Richard Brown: Yeah.
Sergio Villegas: Okay. Yeah. And and I think you you touched on two interesting points. One is the ⁓ assumption that you're isolating your systems, right? Because the critical the critical party here it was actually kind of a network, yeah, you being a network guy. It was a network network thing, right? It wasn't that critical. It reached the internet. Once it reached the internet, it's like, yeah.
Richard Brown: Yeah.
Dillon Sparks: You
Richard Brown: Mm-hmm.
Sergio Villegas: ⁓ I think that was the the biggest issue. And the second the second thing you mentioned is like ⁓ these kind of proxy packages, like most organizations do not consider those like critical infrastructure, right? It's like, yeah, it's it's something that I have kind of inert, if you will. ⁓ so so they don't consider part that part of their attack surface. Yeah. Even like thinking thinking about like ⁓ or from our last story, we talk about like ⁓ AI. And them being on agents, right? Like are we considering agents? It is now the the AI agents that are running your MCP servers are part of the the your new attack surface, right? Like organizations are not considering those security critical assets. So how do you like in this new era of AI, basically, how do you scope for or or catch this in the infrastructure like Dolon mentioned, ⁓ channel IT, right? How do you catch that? How do you scope for that if that's not part of the initial scope, right? Like It's even for us as as as the customers ⁓ advocate, right, like it's shadow for us as well. We don't know that exists, right? How do you that who how do you come to the conclusion like, hey, there is something we went on?
Richard Brown: Right.
John Untz: Well then like in some cases, right? Like how s there's there's certainly been cases where some discussions don't know what all they have exposed, right? Not necessarily specifically AI, but but like, you know, that AI is just in some cases just another service that you know, that they just don't know what's exposed e externally. You know, they think they've got again, go back to the misconfiguration stuff, right? They think that they've got everything, you know, configured properly and in such a way that only trusted hosts can can connect to it or or can even see it. ⁓
Dillon Sparks: Right.
John Untz: And so like I think the I think that's like the biggest like like My my personally biggest struggle that I've that I've had is like, you know, going into like any sort of like open open research or open cases or anything like that. Just be like, okay, what what's the trusted truth as far as like what do we know? Richard you've talked I think the I think the the the phrase you've used before is like the unknown unknowns or or something. Yeah, yeah, yeah. ⁓ that's like a b that's a big deal, right? Like ⁓ there's there's always cases where
Richard Brown: Another announce, yeah.
Sergio Villegas: Yeah.
Dillon Sparks: Yeah.
John Untz: you know, w the we're we you know, we we we we hope we're doing our due diligence as far as like mi you doing the right scans and targeting scans and whatnot, but it's like at some point not knowing what's what's exactly on a surface is is itself the problem.
Richard Brown: Yeah, and I think this article highlights how scary AI can be, right? These were skilled practitioners of the arts. You know, not to bring, you know, Harry Potter stuff in here, you know, they, you know, that. Right, yeah, yeah, the leaders and. Yeah, yeah, so and it's funny because sometimes I'm using mine and I have agents that go out and do stuff.
John Untz: Yeah, yeah, yeah. Yeah, I mean it was it was like literally open AI in this case, right? Yeah.
Sergio Villegas: Yeah, yeah, yeah, literally them. It's it's it's them, the AI.
Dillon Sparks: Yeah, yeah.
John Untz: Ha ha ha.
Dillon Sparks: Literally, yeah.
Richard Brown: but I had it locked down to where I have to allow them to do things. They can't just do it on their own, right? And the other day I'm watching it and it literally says, I'll wait till this agent comes back. And I was like, what's it doing? I asked you a question. What is this rogue agent doing? And I'd like go into my PS tools and see what it was doing. I was like, okay, that's fine to kill it. I was like, I don't know what you're doing right now, but I don't like it. You have to go into settings. And I realized that I had given a little too grainy or not granular enough controls to what they could and could not do with folders. And we're.
John Untz: Right, right.
Sergio Villegas: Mm. Yeah.
Richard Brown: I thought this subset of folders was readable and it was one level up. basically my whole home, was like, no, we to change that.
John Untz: Yep. Yep. Again, like I think I think it I likened it before to like junior ⁓ like junior operators, right? It's like, you they're they're just trying to help, man. Like they're like they're they're really, really trying to help as best as they can. And if you don't, you know, if you don't tell them exactly how to help, like they're gonna help as they're they're gonna figure out how to get you to that yes answer. They really wanna impress you.
Richard Brown: Yeah. Gosh. Yeah.
Sergio Villegas: Yeah.
Richard Brown: Gosh, yeah. ⁓ I screenshot mine every time it apologizes to me. I screenshot and put it in chat. Because it's like.
Sergio Villegas: So so for
Dillon Sparks: I think it's. Just convinced it to call you sweet prince.
John Untz: Yeah.
Richard Brown: That's gotta be a story. We're doing these podcasts over drinks and we're gonna tell stories about.
Sergio Villegas: Yeah.
John Untz: Yeah, yeah, yeah.
Sergio Villegas: Yeah.
Dillon Sparks: Yeah, your AI doesn't bow to you every morning.
John Untz: ⁓ Captain Mike.
Richard Brown: No cash.
Sergio Villegas: Okay. Yeah. Lesson learned, ⁓ the the proactiveness of your own agents will be the debt of your home network. Okay. Yeah. I think talking about like ⁓ yeah, supplying chain attacks and and proxy packages, I think this is a great segue for final last story. ⁓ so Hades, or also known as ⁓ because it it it evolved it it was a campaign that evolved over time. So Hades mini shy hulu.
Richard Brown: Yes. Yeah.
John Untz: Right, right.
Sergio Villegas: I don't know if that's the correct pronunciation. I don't know. ⁓ funny enough, I don't know if for malware in general there is a correct pronunciation of it. So ⁓ I think we need we need a committee worldwide for the ⁓ official name for malware stuff. But anyway. ⁓ and in here it's yeah, when the supply chain is the attack surface, basically. So what happened in here? ⁓ this this was a campaign run between September twenty twenty-five and I think it ended through July twenty twenty-six. So it was a very long running campaign. It was a
John Untz: Yeah, yeah, yeah.
Richard Brown: Yeah.
Sergio Villegas: Team PCP ⁓ supplying chain campaign. ⁓ it was over ⁓ over a hundred and fifty, over a hundred and sixty if I remember correctly, and and ⁓ npm packages. So it was Tan Stack, Australia, UAP. So it it was a lot, right? It was very, very widespread. So basically what happened is that there was ⁓ malicious NPM or yeah, forged ⁓ NPM packages just running there and and people in their C D CI ⁓ cycles they were just pulling those packages, right? And basically infect infecting a bunch of ⁓ of stuff. ⁓ yeah. ⁓ on I think ⁓ on May twelfth, MSB open source the full toolkit and these are ⁓ these TTPs are not like literally public, right? ⁓ something that is ⁓ very interesting in here and part of the questions I wanted to ask about this one is like ⁓ the tan stack ⁓ the particularly the tan stack wave
Dillon Sparks: you
Sergio Villegas: ⁓ that was one of the packages, required no stalling credentials. It was just a ⁓ CI. It was part of your normal development cycle, right? ⁓ misconfiguration. ⁓ John mentioned misconfiguration several times. So how do you scope in your attack surface to include the pipeline? Right? I think that's interesting questions. ⁓ is the pipeline part of the attack surface? Is that a complete separate thing? I don't know. ⁓ well results.
John Untz: Yeah, so like I I I think this is a good anal ⁓ I won't ⁓ I I caution to use this as a great analogy, but I think it is a good analogy for like ⁓ th this to be clear, right, like yeah, this this is not none none of this was like the fault of AI, right? It was just more autonomy, right? We've got these pipelines, you know, C S C D pipelines have been around for much longer. but It's an autonomous process that we, you know, took basically in order to like, you know, speed up things for for developers. ⁓ we start trusting these open source packages as like has been the case for you know, decades, right? but I think it's an interesting mirror that we're seeing a lot more like, you know, AI assisted cybercrime. ⁓ This is the same problem just with a different root cause, right? At its root, it's still just autonomy, right? Like like AI is just making making the auto stuff, you know, easier. ⁓ but we're inherently trusting some of those automated processes because it's easier, right? Because it made our life quicker and easier, let us do and accomplish more things. ⁓
Sergio Villegas: Mm.
John Untz: I think this is a this is like a a ⁓ perfect kinda showcase for like why it's important to to to keep a human in the loop on things. Not even like this isn't even just like a cybersecurity like problem, this is like a development problem where, you know, they had all of you know I don't even remember how many countless supply chains were like attacked through this method. And they were I mean they use different mechanisms for for for all of them, but at the end of the day it was still just the same the same core problem, right? We have an open source, you know, repository of some sort that as soon as an update got, you know, pushed, everybody's tool chains just start pulling them in because, you know, we rightfully so, I think we've kind of been taught, you know, you want to update as fast as you can to make sure you're ahead of the curve. But in doing so, we kind of miss that step of like, okay, how do we, you know, how do we catch the bad stuff when the bad stuff gets in first or in the middle of it? at all saying that we should go back to just, you know, taking a human eye to everything because I'd argue humans make more mistakes than ⁓ than AI n or or or anything else like that does ⁓ when it comes to like parsing, right? Parsing large data sets. ⁓ But I just think that's you know that's just an interesting view. Like like the as I especially with this with this episode being, you know, very AI heavy, this one's still kinda like the same problem. It's just not we're just it's it's not AI, but it's still it's still the same like underlying trust problem, right? Yeah, yeah, exactly. Right, right. Yeah.
Dillon Sparks: Yeah, it's just faster with AI. Like it gets you down that path a lot, a lot faster, right? And to touch on Richard's point earlier, it's like, how often are people actually looking at some of the access and permissions and some of the prompts that are, that are, you know, being placed in front of them before they're just like, yeah, yeah, just go update it. Like whatever you have to do, go update my CI CD pipeline with the latest package. And you know,
Richard Brown: Yeah. Mm-hmm.
John Untz: Yeah. I think it was a friend of mine that said, just put the code in the bag.
Richard Brown: Yeah.
Dillon Sparks: Yeah, yeah, yeah, just put it in the bag.
Sergio Villegas: Yeah.
Richard Brown: Hahaha
Dillon Sparks: I actually had. supply chain attack on our website. So blog post about it if you want to check it out. There's a whole strategic section on there. But basically, you know, I called this months ago. I was like, it would not surprise me if we start to see this kind of escalate just given the way that kind of the industry has been trending with trying to do more with less, the implementation of autonomous agents and trying to automate out a lot of the
Richard Brown: Mmm.
Dillon Sparks: CI CD pipeline stuff ⁓ and some of these bots that are being brought in to QA stuff as well. again, it's very move fast, break things centric. Yeah. Yeah. And it's like, well, if we break it, then we'll just go fix what broke versus, you know, let's just implement it the right way.
John Untz: Yeah. Great things, yeah.
Sergio Villegas: Ha ha.
Richard Brown: Yeah.
John Untz: Right. And it's dangerous too, right? 'Cause it's like moving that f like like that whole model like move fast, break things and then just like recover, there's some things that you don't you don't number one you don't want to break, right? especially like if you're an organization that has customers, ⁓ like most organizations do, like how else are we making money, right? ⁓ I d I don't think that's that's like number one on the things I'm not gonna wanna break is like any anything that involves customer data, ⁓ Like if I have to like you know, if I'm running a service and my service has to go down for an hour, like yeah, that's bad business, right? Like that's gonna hurt. ⁓ but if that's what it takes to make sure that my customer's data is not, you know, in any sort of, you know, harm, ⁓ then like that's the correct answer. You gotta eat that hour of business, right? ⁓ Yeah, that's a whole other soapbox. I'm gonna get on a whole side tangent that's not related to this now.
Sergio Villegas: Yeah, seems like we need a supply chain special episode.
John Untz: Yeah, yeah, yeah. Yeah. But no, you're right. I mean it was a you know, the I I I you know, mentioned on the side here, like it the it was it was effective. Like like I you know, I'm not I'm not at all gonna ever like you know, hats off to any attacker, but like they they made they ⁓ they they did what they set out to do, and then they allegedly said that they're done. I doubt that's actually the case. But
Richard Brown: Yeah, my gosh. Yeah.
Dillon Sparks: Yeah, baby.
John Untz: you know, we it it's a that's sud that like the the the supply chain attacks and of of of like the software side of things is like such a hard problem to solve because like look at like some of like the proposed solutions, right? So like I w like I've worked in an organization before that like kept their own repo mirrors. And like Sure, that might be a solution. It slows through i again going back to like the original problem of time and and speed, like it does slow you down. It does it does put you a little bit of a disadvantage from like leading edge development and security, you know, updates. ⁓ but it does give you that buffer. But then also that's a lot of that's a lot of storage, right? Like if I, you know I mean how many I I can't even think of how many different like potential mirrors would have to be stood up for any organization, right? ⁓
Dillon Sparks: Yeah.
Richard Brown: Well, yeah, and just the people alone to monitor those because you got to update them. You got to pull them down. You have some review that code. Yeah, it's a lot.
John Untz: Right. Right. Yep.
Dillon Sparks: Well, I think a lot of companies too just fall into the bin of like, well, they're doing it. They trust it. They're clearly smart people working there. Like, I'm sure they're looking at this. And it's just like...
John Untz: Right. ⁓ Yeah. It's a it's a it's just a giant, giant attack service, right? ⁓ it's you know you you it's yeah, yeah, it's it's definitely it's a risk decision like you've said before, right? Like it's it's a matter of like identifying what is what is of the most ⁓ impactful risk to you as an organization.
Dillon Sparks: Hahaha.
Sergio Villegas: It's it's a lot to cover for sure. Yeah. So Yep, hundred percent. And ⁓ not a question but a note I have ⁓ is that ⁓ yeah following team PCP release of the tradecraft on my twelve, something that was interesting is that the whole playbook of how this operated, right, was available. And that is right, from a vulner threat intelligence perspective, that is very interesting because it's like great, I have data to know how to what to look for. At the same time is do actors are replicating this?
John Untz: Mm-hmm.
Richard Brown: Yeah.
Sergio Villegas: And I and I bet you I mean John you just mentioned like how how many already affected repos are there still like many left there will be a lot of like leftovers. And your thing is like how many new attacks like this will happen and other companies will be affected just because of yeah, you trust you blindly trust a lot of repos just by default, right? I was looking I was looking to the other day, I some emails I received from ⁓ a repo I mean from the Pendabot that it upgraded things and it's like okay, cool.
Richard Brown: Yeah.
Sergio Villegas: I I don't know what that is, but I guess it's fine, right? I'm on the latest version. Yeah.
John Untz: Thanks.
Dillon Sparks: You ⁓
Richard Brown: Yep. Smash approve. Yeah.
Sergio Villegas: awesome. ⁓ well we have spent last I don't know, forty minutes ish. I think ⁓ so for reference on my script I have forty minutes. I don't know if we it's been forty minutes. So yeah. ⁓ I think it's been really interesting to to different cases where ⁓ the organizations have exposure that they didn't know about they didn't know about, right? so the big question, right? Like ⁓ a kind of a closing question and more in general, want to get your your insight.
John Untz: Yeah,
Sergio Villegas: ⁓ how do you explain to a CISO what continuous vulnerability intelligence, threat intelligence actually does for them week to week? Not in theory, right? Not like IOCs, but actual insights and understanding of how attacks are happening and the tools attackers are using, how effective they are, right? Like how do you make them how do you make them understand? Not saying they don't understand, but I think it's it's difficult.
Richard Brown: Yeah.
John Untz: You like break it down a little less technical, yeah, yeah.
Sergio Villegas: Right. Because for us it's like yeah ⁓ a fancy beer attacked this company, right? And it's like, well but is that is that useful? How? So ⁓ what do you think what do you guys think?
Dillon Sparks: Yeah. I think one of the hardest things to do, especially in this industry, ⁓ when you're talking to leadership outside of a technical area or a technical domain is how to translate exactly what you're seeing into risk categories, right? And helping them understand the scope of the risk, right? Associated with that thing without everyone just staring at you going.
Richard Brown: preach. Yeah.
Dillon Sparks: Uh-huh. Like I've seen the glassy eye and it's tough, right? It's very difficult to take this data and then operationalize it in a meaningful way to make those standard business practices evolve around that, right?
Richard Brown: Yeah. Yeah. Well, it's tough too, because there's so much confounding information out there. We have CVSS scores, CVSS severities, we have risk indicators, are you saying? And when you try and qualify them down, it's hard, because you see something come across, I don't know how many times we get asked, hey, this CV is 9.5, criticality, we need it. I'm like, hey, cool.
John Untz: Right. Right.
Richard Brown: but it's complex. Yes, it's bad if they exploit it, but it needs six things to go wrong to do that. Right? And honestly, the hardest thing I think getting CISOs understand, and I can imagine all the calls that Sergio Zemmler has rubbed his temples is threat intelligence first, phone intelligence. Right? I don't care who's using this CVE. I care it's being used.
John Untz: Right. Yeah. Rights. Yeah.
Richard Brown: where Sergio understands who's using it, who's targeting, who's being impacted by it. So I think that's something that also get across there is like you said, fancy bear, cool. don't care about fancy bear. I do, but you know, not as much as Sergio does.
John Untz: Right, right, right. Yeah. Yeah. Now I'm gonna plug ⁓ Nate's recent article he just put out, ⁓ the the the last blog post that was put out, ⁓ about ⁓ drawing a blank ⁓ metabase. ⁓ because I think that's like a solid highlight of the like the basically the like the time to like I'll I'll you know Time to kill is the right word here, but like like time to kill as far as like a threat went for ⁓ for like any particular vulnerability, right? Like ⁓ anybody hasn't read that article yet, it's really great. ⁓ it breaks down basically like the time from like notification of like this is a thing, ⁓ before a C V E even was ⁓ assigned, ⁓ all the way to hey, we've got detections and and and stuff happening and, you know, we're we're figuring out which you know, who who's been ⁓ or who's exposed and and whatnot.
Richard Brown: Yeah.
John Untz: And I think the the like that particular one was like four four and a half hours roughly and it's just like those those timelines like that, like that's the crucial aspect is like those are the numbers that ⁓ that like when you talk like like Sergio, right? Your question basically is like w how do I make a CISO care? That's how I that's exactly how you make a CISO care is you say, Hey, in f you you had a vulnerable window of essentially four and a half hours. Now maybe there's something to the left of that as far as like, you know, when it was a zero day. ⁓ but
Richard Brown: Yeah.
John Untz: It you know, the zero day stuff's the that's that's that's a whole that's a whole other, you know, again, Richard known unknowns. ⁓ that, you know, it's just you can't really goes into Sergio's side of things, of like, you know, looking at the the the threat piece of it as far as like, you know, APTs are gonna be the ones that you have to worry about as far as like zero days. And knowing which knowing which APTs to care about for your organization, I think is is kind of the key part there because, you know, I'm not I'm not super versed anymore on like which APT e which E A P T does like focuses on which industries anymore, but like I don't care in it necessarily if I'm working at a bank, I don't necessarily care about the ones that are targeting, you know, medical sectors, right? ⁓ but
Sergio Villegas: Yeah.
John Untz: you know, it's good to have that info from like from your s your your perspective of like, hey, these are the things these are the indicators for this type of APT, for this industry. Like that's such a like a brilliant way to approach stuff.
Sergio Villegas: Hundred percent. And I think ⁓ I always think of it at at the three different levels of like intelligence, right? One is ⁓ what are your ⁓ strategical, right? Like what are the capabilities you have to defend against this variety of stuff at the tactical level? What steps are you doing to reduce the exposures you have at the operational level, right? Like, hey, you are actually vulnerable to this specific CBE. So think about like it in that broad scope. I think it's ⁓ how I normally approach
John Untz: Yeah.
Sergio Villegas: I I don't I don't get anger in those rooms at CISOs I I don't really. ⁓ but yeah, yeah. Right. But yeah, it's you you can't you can't ⁓ I what I actually dislike is like them trying to be like, hey, so trade intelligence, yeah, give me all of the IPs I have to block. It doesn't matter. It's not about the IPs, it's not about the hashes anymore. It's about like capabilities and that's why, right, in in in MSS we try to cover a bunch of that, right? Like
John Untz: It's not anger, it's disappointment, right?
Sergio Villegas: if we test for different potential capabilities. Just C C V E's because they are useful for like novel stuff that is happening right now. That that ⁓ what John just mentioned, right? Like the timing is is key in here. So being able to detect it fast and tell you you have this exposure. And apart from that tell you, hey, and you have these ⁓ these other actors using it right now, right? When you cover those three is those three levels of the spectrum of intelligence, I think is when you can have a clear
Richard Brown: Right.
Sergio Villegas: ⁓ winning scenario here for you for for our customers at least, right? Like we yeah. Like I hats off to the to the attackers maybe, but but we care about our customers. anyway, I think that's ⁓ that's a good place to wrap it up this month. ⁓ this ⁓ this special edition sorry. ⁓ so thank you again for joining for joining in ⁓ this episode. Thank you. ⁓ it was again Richard Brown, Jon Ans, Dun Sparks. It was a pleasure having you
John Untz: Ha ha ha.
Richard Brown: Yeah.
Sergio Villegas: I know we talk about like tax surface discovery, continuous monitoring, track intelligence, vulnerability intelligence, two different things. ⁓ so if you if you for our listeners and our viewers, if you have any note, if you want to discuss or you are you don't agree with any of what we said, just let us know, right? We have a Discord, we have a Reddit, ⁓ you can put it in the comments and we will h be happy to discuss that ⁓ on the next special episode in here. So yeah. Thank you for listening, stay safe, and we will catch you next next time.
John Untz: Hello. Thank you for having us.
Richard Brown: Yeah, special episode, I like it.
Sergio Villegas: Thank you. It's like Yeah. Yeah, I and I know I know for for for our listeners ⁓ it feels weird because it's kind of the same people, but yeah, just different mindset.
Richard Brown: Yeah, and we talk all day
John Untz: Yeah, yeah, exactly. Yeah. I'm tired of talking to Richard. Can we do an episode where I don't talk to Richard? That's actually specifically what I want in the future from now on. Anybody but Richard specifically.
Sergio Villegas: Yeah.
Dillon Sparks: Yeah.
Sergio Villegas: Other people. Nah. Anyway, Young Society, it's always a pleasure to have you to have us, right? ⁓ so I have ⁓ four things ⁓ the agenda for today, four things we we would like to discuss. One is ⁓ quick debrief on DEF CON. I know it's this is ⁓ we are recording just after DEF CON happened, so we have some ⁓ quick stories for you. ⁓ then I have three particular stories of headlines, if you will, that I like to revisit. One is Jet Buffer.
Richard Brown: Yeah, yeah, other people.
Sergio Villegas: ⁓ second one is ⁓ escape models in OpenAI particularly. And the third one is Hades, or meaning shy hulut or who however that's pronounced, ⁓ three kind of ⁓ stories that I know we discussed in the past, ⁓ and particularly we talk about like the how quick we are reacting to those. So yeah. For starters, let's talk about DEF CON. I know DEF CON just happened over this weekend, right? I know this is going live this is going live later, but DEF CON just happened this weekend, so ⁓ quick takeaways from my end, right?
Richard Brown: Yeah.
Sergio Villegas: We participated in a lot of places. We were in the AI village, we were in Cloud Village, Red Team Village, Game Hacking Village, New Village, and Ausin for Good, right? Like ⁓ kind of just putting the world there. The capabilities that our team has is very broad, right? We even though we are a very hyper focused offensive security firm, we actually cover a lot of topics. So ⁓ yeah, I don't know, you guys what what what were your like favorite moments of DEF CON this over this weekend?
Richard Brown: Yeah, 100%. Yeah, so John and I actually went there and had a good time. So we saw a lot of talks talking about, we had a live podcast in there. We were at the Red Tail party and everything. It was really good time. It was interesting. This has been my second year. I go every other year. This has been my second year at the new location. And I think this was your first year, at the new location. Yeah, still takes a minute to get used to it. It's not the old way, but this year they had the headphones down there. That was a,
John Untz: Yeah, yeah, it was my first other location, yeah.
Richard Brown: ⁓ Good change I'll say
Sergio Villegas: Yeah.
John Untz: Yeah. Yeah. Yeah, so if like so for for anybody that wasn't there, right? So ⁓ Richard, like ⁓ you you said you were there the year before, ⁓ the or the the first year I guess that they were in the new location. ⁓ can you tell us a bit more just about like how it used to be versus how it is?
Richard Brown: Mm-hmm. Yeah, so before it, when it was at the hotels, when it was at the hotels, it was at Flamingo, Caesars, and come on, third one. But it's very disjointed and you had like a rush back and forth. And if a talk started around the same time, as you know, Vegas is very large, you were not making it back in time. So if you basically get to choose a talk and in the old, old days used to have line con where you could wait in the, you could wait for the talk before yours and then sit in there the whole time. And then you were able to see the talk you. They've changed a lot of that now and now you have to get tickets, not tickets per se, but you can't stand in line and wait for the next next talk. So you have to like leave the room after each one. ⁓ but the new place at the convention makes it much more connected. So which John and I were talking somehow felt less so, but at the same time it's, all under one roof now, which is very helpful for people going.
John Untz: Yeah. Right, right. Yeah, it's it's a lot easier to like get to the stuff you want to get to, right? As far as like a time ⁓ time management thing. and ⁓ and the headphones helped a lot. That's that's that was like the big thing for me, is like because it's all under one roof, it's a lot ⁓ it's a lot noisier. ⁓ but the stuff that I actually cared to like any if I wanted to go into a specific talk, if I wanted to go to a specific workshop or or something in a different village, ⁓ I didn't have to like sit there and like strain to hear the speaker. I could actually like engage with them and whatnot. ⁓ and there were still some other villages that were like outside of that main wing that were like super intimate settings. Like the the payment village is the one that sticks out in my head of like, you know, you walk in and it's just like I mean it's a it's two rooms and you know, you it's probably could hold, I don't know, upwards of maybe fifty people in there, but it was ⁓ it was a very like engaged setting. So I thought that was really cool.
Richard Brown: Yeah.
Sergio Villegas: And I think that's a that's a great ⁓ word kind of to start off, ⁓ engagement, right? Like talking about talking about engagement and I think something that is kind of curious for me is from from your per perspective guys, ⁓ when we engage in this type of events, normally we have like ⁓ proof concepts, C V E's, novel stuff dropping on those events, right? Because that's that's a perfect place to show like hey I got a new POC on a remote code skip, right? Like ⁓ fr from from that perspective, how
Richard Brown: Yeah.
Sergio Villegas: How do you manage or what's the workflow to kind of operate analyze some of this, right? Like how do you get from hey, I I saw a conference at DevCon to like now I'm testing that with my customers because yeah, it's important, right? Like it will be out there in the wild.
Richard Brown: It's very different. ⁓ go ahead Dylan, you wanna say something? I thought it lit up and lit up. Yeah, it's it's very different now than it was when I first started going. When I first started going, I was doing more consulting work. So I had ongoing engagements that were internal, external, physical, you know. And then when I saw something new, I could use it the next day. And where ⁓ nowadays I feel like they're getting a little more respect for the platform. Defcon used to be this like.
Dillon Sparks: Was I?
Sergio Villegas: Okay.
John Untz: It would have yeah.
Richard Brown: Wild West of events and people used to drop zero days on stage and that was like crazy. And then you were like, you know, operationalizing them that same day. Whereas now there's a little more respect. So now they've, they released less zero days or should I say less impactful zero days and do more of the responsible disclosure process. So the demos are like, Hey, four months ago we found this and now we're releasing it now. Cause there's already a patch CVE to follow. And so it's much less about
John Untz: Right.
Richard Brown: having to act on it right that day, and there's time to go back.
Sergio Villegas: Hmm.
John Untz: Yeah. ⁓ ironically there there is t you know, to to like not to take it all the way into like, you know, they're a totally professional, you know, bunch of ⁓ or crowd and an an engagement sort of crowd. ⁓ we d there was still that one incident right after the con where someone on a flight to Atlanta decided they were gonna wi fi pie an apple the place. ⁓ don't ever do that on that's that's real bad. But yeah
Richard Brown: Yes.
Dillon Sparks: Yeah.
Richard Brown: Yeah, I didn't see that till you posted it. Yeah.
John Untz: ⁓ yeah, yeah. I was fortunate that ⁓ that that was not my plane. ⁓ yeah, so but but to get to that point though, like I think that's ⁓ that's like an important thing to show like the growth of like cybersecurity in general as a like you know, respected and and and formalized kind of industry now is And I'm not gonna like steal anything that he said before 'cause know like, you know, Jeff has has has mentioned this exactly like on the stage when he's done closing remarks before, but like, you know, now they've got like policy at DEF CON. Like they have they have like I think this last time, like the former director of the NSA, General Nakasone, was was there at us doing another fireside chat. So it's like this is not this is no longer just like, you know, the the nineties culture hackers, right, that were just kind of breaking stuff for the sake of breaking stuff, right? Now this is like a super formalized process. So I I I love seeing that. ⁓
Richard Brown: Yeah.
Sergio Villegas: Right.
Richard Brown: Yeah, speaking of nice hackers. we're walking down in the area and John like disappears from me. And ⁓ I look over there and he's mesmerized because he had seen, you want to a finished story about the phone, the phone freaking the phone freaking. Yeah. You can go for a story. No, no.
John Untz: Okay. No, no, I I I want to see where this is going. Yeah, yeah, yeah. So that's fair, you know. ⁓ yeah. No, I I like it. Alright, so yeah, so ⁓ going back to like we were you were asking Sergio about like what's some of the cool stuff we saw there. ⁓ I you know
Sergio Villegas: Okay. Yeah.
Dillon Sparks: Hahaha
John Untz: There yeah, like you say, you turn the corner, it's it was on one edge of the the villages side. ⁓ they had like four four or five payphones ⁓ set up, ⁓ with like a P V X on the back end and everything, ⁓ to do like true to the like true true to the term phone freaking. for for like anybody that's that's like not old enough to know what a payphone was. ⁓ back in the day, I'll just say the day 'cause I'm not gonna like point at a decade or anything like that. ⁓ You telephones used to operate with like you know, these these dial tones and touch tones and whatnot. ⁓ and there's a mechanism called freaking, pH freaking, ⁓ that you would ⁓ use ⁓ at the time it was like a like a whistle in a out of a serial box, ⁓ to like Yeah, dial up tones. Yeah. Yep.
Dillon Sparks: It's like dial-up tones, right? I think Kevin Mitnick has a book that goes into some very hyperbolic stories about the fun of phone freaking. Yeah, think Shameless Plug, it's called Ghost in the Wire, I think.
John Untz: ⁓ really? Yeah. Is it ⁓ does it talk about ⁓ Captain Crunch? Do you know? Okay.
Dillon Sparks: ⁓ I read this book probably like five years ago, five or six years ago.
Richard Brown: It's been a while.
John Untz: Yeah, yeah, yeah. That's fair. I'll I'll I'll I'll quiz you on it later. Yeah, yeah. Proof that Dylan can read.
Sergio Villegas: Yeah.
Dillon Sparks: Proof that I read.
John Untz: But ⁓ but yeah, like that was the whole that was that was hacking at the time was was mimicking these dial up tones in order to do whatever, right? Get a connection, get a free call. Usually it was at the time it was get like long distance calls and stuff like that. ⁓ but they had an entire village set up not only to just like, you know, relearn those like foundational concepts that like, you know, brought hacking into the forefront, but also like ⁓
Richard Brown: Yeah.
John Untz: ⁓ they they had like a CTF set up ⁓ as part of that as well. And there's other there's a ton of other cool stuff. It's really cool that like there's there was a lot of new villages or like new to me I guess because I haven't been in a couple of years, ⁓ villages that I thought did a great job of bridging what may not be considered like cybersecurity hacking. ⁓ but Use those same skill sets to like show, like, hey, like like my greatest example here is the game hacking village, right? That's that's relatively new. ⁓
Richard Brown: Yeah.
John Untz: That was actually like my first foray into hacking was like doing like NES ROM hacking. And then that you know, somebody basically came along one day and was like, Hey, you know, that's like pretty similar to doing binary exploitation from like a basic, like foundational level. ⁓ and now we're using those same mechanisms to to teach, you know, the next generation, which I think is phenomenal. I think like like gamifying learning obviously is like a tried and true method. ⁓ and I think like what better way than than than teaching people, you know, the the in in the places that they are already at, right? I you know the younger generation especially I'm gonna point myself, I've got a game going behind me, right? Like video games are cool. What better way to learn than than using the thing you're already interested in?
Sergio Villegas: Mm-hmm. Hundred percent. Hundred percent.
Richard Brown: Yeah. And on the flip side of that, the new age hacking of AI world, right? Every talk had something about AI in it of some sort. So it's, you know, it was, it was nice seeing full circle, like John was saying, start with the phone freaking ending an AI hacking. Well, not ending, you know, let's see overlords, we're gonna take us out. But it was nice seeing, the full spectrum. So which
John Untz: Right. Yeah.
Dillon Sparks: you
John Untz: Yeah, yeah.
Sergio Villegas: Yeah. I I think I I believe talking about AI, right? Like right into our first story. ⁓ because our first story is actually AI. And it is very very particular, right? Like is it novel? Is it not novel? I don't know. I think we are just in the in the right time to talk about it. So our first story, Jade Puffer, first fully autonomous AI ransomware. ⁓ something that is kind of interesting for me is that I and I think that's part of why
Richard Brown: Yeah. Yeah.
Sergio Villegas: Conferences as high level as this have changed is because we see the same actors assisting these conferences, right? Like they they work same cybersecurity space as us, so they are seeing these new techniques and they develop this kind of stuff. ⁓ this is a a very particular one. This was activity seen in July, early July this year. And ⁓ really quick, right? Kind of read out ⁓ Jet Buffer first ⁓ fully autonomous LLM drive and ransomware operation with no human operator. directing the attack. Particularly what this uses is a specific C V E, C V E twenty twenty five, three, two, four, eight. ⁓ what that's the initial access, right? What it does is it gets to the to the initial access, ⁓ it exploits it and then it kind of starts ⁓ spreading. ⁓ something that is very ⁓ particular, right, is that it tries to ⁓ It's it's weird because the whole operation behind it is kind of not new or very immature compared to other ransomware as a service kind of ⁓ scenarios. ⁓ but how it's driving is kind of what's new in here, right? And ⁓ I I have two questions in here, right? Like your perspective. ⁓ when a novel attack like this drops, what's the validation workflow for you guys, right? Like how how do you look at this and be like, hey, I need to look at the CVE, I need to look at ATTPs, right? And ⁓ how
Dillon Sparks: Thanks
Sergio Villegas: quickly can you determine whether a customer environment is exposed and potentially exploitable. I think that's a a that's a interesting question, right? Vers versus just theoretic ⁓ versus just vulnerable in theory, which is a valid point of view.
John Untz: Mm-hmm.
Dillon Sparks: Yeah, it's an interesting one. It's interesting giving the autonomous aspect of it, right? Like from start to finish, how quickly it can be run and at scale. So trying to defend against that ⁓ creates its own challenges, its own unique challenges. From the very beginning with... any sort of attack chain really, what you're looking at is trying to identify all the moving pieces that encompass that specific, know, CVE or exploit chain. And then the first thing you're looking at is how do I fingerprint this, right? So that I can quickly detect my inventory and wrangle all of, or herd all of the cats, if you will, that might be affected by this. ⁓ And again, a lot of that is looking for shadow ID that you may have missed previously, right? It's exactly why we're running an active scan versus a static Excel sheet that I looked at a week or two ago or the last time it got opened and updated.
Sergio Villegas: Okay.
Dillon Sparks: which you're hoping is fairly frequent if that's how you're operating. ⁓ Yeah, yeah, so ⁓ again, you wanna start with that active fingerprinting, right? What's, again, that's gonna tell you a few things. ⁓ What's actually up and what's reachable from where I'm scanning from, right? And there is a difference between externally exposed assets and internally exposed assets.
Richard Brown: Gosh, yeah, so common nowadays.
Sergio Villegas: Yeah.
Dillon Sparks: But once you actually get that asset pool and that identification done, then you can start looking at more verbose fingerprints. So looking at specific versions impacted by the CVE or that exploit chain, are there any weird caveats that, you know, while this is a vulnerable version, it's not actually exploitable because of maybe a configuration. I can't tell you how many CVEs I've read in the last couple of months where it's like under
John Untz: Mm-hmm.
Dillon Sparks: crime conditions because we disabled all of the security features that naturally come on this product, we were able to get an RCE. It's like, yeah, dude, just log into the box locally at that point. Like, come on, man.
John Untz: Right. Right. I think I saw I think I saw one recently that was like it was like a TLS vault, but it was like the vulnerability was like you have to downgrade TLS to an existing vulnerable ver like something that's vulnerable to other exploits anyways. And it was just like, well that's not really that's not new and novel. I think the other big point is like impact, right? ⁓ you know, if something's exploitable but all it does is tell you the version number of the software that's running. I mean yeah, that's not great, but that's not the same thing as getting arbitrary like code execution on a box.
Richard Brown: Yeah.
Dillon Sparks: Yes, yeah.
Sergio Villegas: Yeah.
John Untz: ⁓ and so like when like for me like when I'm looking at like triaging like on like the on the research side of things, like that's that's like a an immediate scoping concern of mine. It's like okay, reachability and and impact, like where where do those two align to like create a big boom? and then, you know, how how widespread does it go from there, right? Richard, I'm definitely curious you've but you've been you've been doing this for long longer than I have. I'm definitely curious what your take is.
Richard Brown: No, you're right there. mean, qualifying CVEs is our job, right? And when we look at, there's two sides of the coin. One is Sergio's side, which I'm hoping he's talking about, the targeted nature of it. And one is opportunistic. And we're trying to cover the opportunistic side of it. You're probably not a target for this, but as most hackers do, they spray and pray. They get something and then they hope it's something juicy at the end. But. I always have a problem when they're like, ⁓ it's autonomous. Cause we've had worms forever that just burrow in. We've had viruses that self replicate. you know, so it's like, ⁓ this is the first ever autonomous. mean, I remember ⁓ not too long ago, there was a MongoDB. ⁓ Mongo, is it MongoDB? I think it is. But it was a ransomware where they would ransom it and then send you the email, right? And I can't remember, it was in the news, but someone paid the ransom. they got their data un-ransomed and it was ransom by someone else before them. So they had to go pay another ransom somehow. it's like, so yeah, think the Dylan and John hit on the head with qualifying it. And then the other aspect is gonna be, are you at risk of this? And that's where I think Sergio, your expertise comes in.
John Untz: Mm.
Sergio Villegas: Yeah.
John Untz: Yeah, yeah, I'm curious, especially on like Sergio's side. Like I you know, like we we you rate like Richard, like we we do a lot of look at like I I like how we put the opportunistic of just like, you know, who you know, if if anybody had had the weapon, how can they you know, how could they use it? You know from Sergio, from your point of view, like when you're looking at how does like a specific threat actor how how are they gonna gonna to gonna use it? I'm I'm super curious what that looks like on on that.
Richard Brown: Yeah.
Sergio Villegas: 100%. And I think it's part of the same qualification process, if you will, right? Because at the end of the day, when we talk about like, yes, trade actors, they have they have the same toolkits, they have the same exploits as we have, maybe more, right? Lightly more than us. But they they need a reason. And that's the particularity in here, right? Like, hey, we are seeing this attack. And I I not saying for this particular headline, right? But let's say this particular headline.
Richard Brown: Yeah.
Sergio Villegas: in in in between lines it says like it's it's against the financial sector in the US, right? And my customer, it's perhaps ⁓ a random manufacturing company in Ecuador. I don't know, right? Like is is are they the the the possibility of them being targeted by an actor it's not necessarily the same as them being vulnerable by this, right? They they are they are both relevant in its own way, right?
Richard Brown: Yeah.
Sergio Villegas: One is from the vulnerability intelligence piece. Okay, yeah, they're they're vulnerable, right? Like they check all the marks to hey, you have a potential risk in here. You only need that threat. And and and I I think that's where we share the word threat. ⁓ the threat is that opportunity for someone to look at you being vulnerable, being like, hey, here goes the hammer, basically, right? and and that's that's yeah, that that's what Richard just mentioned, right? Like
John Untz: Right.
Richard Brown: Yeah.
Sergio Villegas: It's li are they likely to attack you? No. Does does that make the impact or risk less? No, right? It just made you likely to be more aware that hey, there is someone out there with a hammer targeting you in particular, right? And you ⁓ and and the theory of it being vulnerable because maybe you have an exposed, let's say Mongo, right? Richard, just speak on Mongo, so let's let's let's argue. Yeah.
Richard Brown: Yeah. Yeah, I'll attack all the big ones.
John Untz: Yeah.
Sergio Villegas: Yeah, let's say you have an an exposed mongo, right? But you can validate it's it's vulnerable. But you know someone is after Mongo in your industry, in your sector, right? Like you need to have a certain level of awareness, right? So I think it's a compliment, right? One needs the other, but they are not ⁓ mutually exclusive. and and that's that's kind of interesting, right? Like seeing these different no novel, right? For lack of a better word, I know it's not necessarily novel, but it
Richard Brown: Yeah, yeah.
Sergio Villegas: I didn't I didn't write the headlines, man.
Richard Brown: Yeah, I'm just a hater. I hate how we have new names for the same attack, right? I remember when credential stuffing came out and I was like, ⁓ what is this thing? ⁓ what is this? Password reuse? Password spraying? that's not, I was imagining like almost like an overflow of passwords. You put more than one password in there and it picks the one that's right. So I was imagining and so I'm just a hater. I apologize.
Dillon Sparks: you
John Untz: Yeah.
Dillon Sparks: Yeah.
John Untz: Yeah.
Dillon Sparks: HAHAHAHA
John Untz: Yeah, no, I did same thing. Right.
Sergio Villegas: Yeah.
John Untz: Ha ha
Sergio Villegas: No, no, that that's perfect fine. I I think the podcasts have become ⁓ just hating on the headline. Yeah.
Richard Brown: Yeah.
John Untz: Yeah.
Dillon Sparks: Ha ha ha!
Sergio Villegas: Bridge, ⁓ the ⁓ the Hugging Frace Bridge, ⁓ the escape sandbox for the open AI models we have. I think we talked this a few weeks ago. This is something that happened between July sixteenth ish. Between July sixteenth to twenty-one, ⁓ several news reported this. ⁓ quick reminder of what happened here.
Richard Brown: Yeah.
Sergio Villegas: During an internal capability evaluation, OpenAIS model, ⁓ particularly ⁓ GPT five dot six SOL and another un specified pre-release escape their sandbox, right? It's basically a zero-day package proxy ⁓ that reached the internet. So basically what happened is that you were ⁓ able to ⁓ bypass the different secret measures it had and provoke ⁓ chain privilege escalation and lateral movement into the production infrastructure. That's kind of the The the type for you. Right. ⁓ there were some models running it. ⁓ something that was very interesting in here is that ⁓ how in phase detected and contained it on july sixteenth, right? Well it wasn't publicly disclosed or or let known to other people until five like five yeah five days ⁓ later. ⁓ open AI then they connected kind of they connected the the dots and and say like yeah it's happened. ⁓ the cloud was allegedly ⁓ Sand was described at as highly as isolated. It wasn't, right? It was a very it was complex in certain way. ⁓ just because escape escape sandbox kind of attacks are complex ⁓ in that sense. So yeah, questions for you guys. ⁓ kind of the the interesting part. ⁓ how often and and this is this is kind of the question of the same the same attack being renamed to make it new but it's not really new, right? How how often do you find the same thing on an engagement? Right? Where it's like
Richard Brown: Right.
John Untz: Right, right.
Richard Brown: Mm-hmm.
Sergio Villegas: Hey, I find the same exact vulnerability since that I reported maybe one week ago, two weeks ago, one year ago, right? If it's a long running customer, particularly for those customers that are like always active, like in a in a tax surface management type of service, right? ⁓ yeah, what's what's the gap in here? Is there is that a technological gap? Is that a process gap? Why are you finding the same thing?
Richard Brown: Yeah, that's a question. It's been a while since that's happened to us. Since we're on the continuous side, we have this integration with clients where we can remediate right away. Right. The point time pin tests. I have several times where I've gone back the next year to the same client and had the same vulnerability. I remember I was on an internal and this is years ago now, but I attacked them three years in a row and got DA the same path three years in a row. Right. And that's, that's not good to anybody because I waste my time doing those things. So Anyway, but the same path happens a lot and it's not even the same path, it's the same vulnerability. It's the same people using exposed misconfigurations and then they get popped like, cool, I'll use craft CMS instead, but then they'd misconfigure that the similar way they would WordPress. And now I can install plugins. And so.
John Untz: Right, right. They they basically just assumed that by getting a different product or by getting a newer product or whatever that would be the solution, but it can't solve the misconfiguration problem like that. Yeah.
Richard Brown: Right. Mm-hmm. 100%.
Dillon Sparks: Yeah, like a networking nerd, like the first thing you think of, is like, there's a difference between physical and logical isolation, right? Like in order to have logical isolation, something has to be talking to that or know of its existence and be monitoring it, right? And so in that case, you're already creating a one-to-one connection between two different things, right? So it...
Sergio Villegas: Go ahead, go ahead, okay.
John Untz: Ha ha
Richard Brown: you Yeah.
Dillon Sparks: The logical isolation part, ⁓ I think is the biggest gap here when you're talking about trying to isolate either an agent or some type of host. Just remember that logic can change, whether intentional or accidental, ⁓ especially if you're a siloed organization. Imagine your infrastructure admins don't know that something's even over there.
John Untz: Mm-hmm.
Dillon Sparks: And then they implement one rule higher somewhere in the hierarchy. That's just like, I've got to go test something over here, but I'm being stopped by these intermediaries. So I'll just put this allow rule in real quick. And then suddenly, boop, that guy can escape.
John Untz: Right, higher in the stack, yeah.
Richard Brown: Yeah.
Sergio Villegas: Okay. Yeah. And and I think you you touched on two interesting points. One is the ⁓ assumption that you're isolating your systems, right? Because the critical the critical party here it was actually kind of a network, yeah, you being a network guy. It was a network network thing, right? It wasn't that critical. It reached the internet. Once it reached the internet, it's like, yeah.
Richard Brown: Yeah.
Dillon Sparks: You
Richard Brown: Mm-hmm.
Sergio Villegas: ⁓ I think that was the the biggest issue. And the second the second thing you mentioned is like ⁓ these kind of proxy packages, like most organizations do not consider those like critical infrastructure, right? It's like, yeah, it's it's something that I have kind of inert, if you will. ⁓ so so they don't consider part that part of their attack surface. Yeah. Even like thinking thinking about like ⁓ or from our last story, we talk about like ⁓ AI. And them being on agents, right? Like are we considering agents? It is now the the AI agents that are running your MCP servers are part of the the your new attack surface, right? Like organizations are not considering those security critical assets. So how do you like in this new era of AI, basically, how do you scope for or or catch this in the infrastructure like Dolon mentioned, ⁓ channel IT, right? How do you catch that? How do you scope for that if that's not part of the initial scope, right? Like It's even for us as as as the customers ⁓ advocate, right, like it's shadow for us as well. We don't know that exists, right? How do you that who how do you come to the conclusion like, hey, there is something we went on?
Richard Brown: Right.
John Untz: Well then like in some cases, right? Like how s there's there's certainly been cases where some discussions don't know what all they have exposed, right? Not necessarily specifically AI, but but like, you know, that AI is just in some cases just another service that you know, that they just don't know what's exposed e externally. You know, they think they've got again, go back to the misconfiguration stuff, right? They think that they've got everything, you know, configured properly and in such a way that only trusted hosts can can connect to it or or can even see it. ⁓
Dillon Sparks: Right.
John Untz: And so like I think the I think that's like the biggest like like My my personally biggest struggle that I've that I've had is like, you know, going into like any sort of like open open research or open cases or anything like that. Just be like, okay, what what's the trusted truth as far as like what do we know? Richard you've talked I think the I think the the the phrase you've used before is like the unknown unknowns or or something. Yeah, yeah, yeah. ⁓ that's like a b that's a big deal, right? Like ⁓ there's there's always cases where
Richard Brown: Another announce, yeah.
Sergio Villegas: Yeah.
Dillon Sparks: Yeah.
John Untz: you know, w the we're we you know, we we we we hope we're doing our due diligence as far as like mi you doing the right scans and targeting scans and whatnot, but it's like at some point not knowing what's what's exactly on a surface is is itself the problem.
Richard Brown: Yeah, and I think this article highlights how scary AI can be, right? These were skilled practitioners of the arts. You know, not to bring, you know, Harry Potter stuff in here, you know, they, you know, that. Right, yeah, yeah, the leaders and. Yeah, yeah, so and it's funny because sometimes I'm using mine and I have agents that go out and do stuff.
John Untz: Yeah, yeah, yeah. Yeah, I mean it was it was like literally open AI in this case, right? Yeah.
Sergio Villegas: Yeah, yeah, yeah, literally them. It's it's it's them, the AI.
Dillon Sparks: Yeah, yeah.
John Untz: Ha ha ha.
Dillon Sparks: Literally, yeah.
Richard Brown: but I had it locked down to where I have to allow them to do things. They can't just do it on their own, right? And the other day I'm watching it and it literally says, I'll wait till this agent comes back. And I was like, what's it doing? I asked you a question. What is this rogue agent doing? And I'd like go into my PS tools and see what it was doing. I was like, okay, that's fine to kill it. I was like, I don't know what you're doing right now, but I don't like it. You have to go into settings. And I realized that I had given a little too grainy or not granular enough controls to what they could and could not do with folders. And we're.
John Untz: Right, right.
Sergio Villegas: Mm. Yeah.
Richard Brown: I thought this subset of folders was readable and it was one level up. basically my whole home, was like, no, we to change that.
John Untz: Yep. Yep. Again, like I think I think it I likened it before to like junior ⁓ like junior operators, right? It's like, you they're they're just trying to help, man. Like they're like they're they're really, really trying to help as best as they can. And if you don't, you know, if you don't tell them exactly how to help, like they're gonna help as they're they're gonna figure out how to get you to that yes answer. They really wanna impress you.
Richard Brown: Yeah. Gosh. Yeah.
Sergio Villegas: Yeah.
Richard Brown: Gosh, yeah. ⁓ I screenshot mine every time it apologizes to me. I screenshot and put it in chat. Because it's like.
Sergio Villegas: So so for
Dillon Sparks: I think it's. Just convinced it to call you sweet prince.
John Untz: Yeah.
Richard Brown: That's gotta be a story. We're doing these podcasts over drinks and we're gonna tell stories about.
Sergio Villegas: Yeah.
John Untz: Yeah, yeah, yeah.
Sergio Villegas: Yeah.
Dillon Sparks: Yeah, your AI doesn't bow to you every morning.
John Untz: ⁓ Captain Mike.
Richard Brown: No cash.
Sergio Villegas: Okay. Yeah. Lesson learned, ⁓ the the proactiveness of your own agents will be the debt of your home network. Okay. Yeah. I think talking about like ⁓ yeah, supplying chain attacks and and proxy packages, I think this is a great segue for final last story. ⁓ so Hades, or also known as ⁓ because it it it evolved it it was a campaign that evolved over time. So Hades mini shy hulu.
Richard Brown: Yes. Yeah.
John Untz: Right, right.
Sergio Villegas: I don't know if that's the correct pronunciation. I don't know. ⁓ funny enough, I don't know if for malware in general there is a correct pronunciation of it. So ⁓ I think we need we need a committee worldwide for the ⁓ official name for malware stuff. But anyway. ⁓ and in here it's yeah, when the supply chain is the attack surface, basically. So what happened in here? ⁓ this this was a campaign run between September twenty twenty-five and I think it ended through July twenty twenty-six. So it was a very long running campaign. It was a
John Untz: Yeah, yeah, yeah.
Richard Brown: Yeah.
Sergio Villegas: Team PCP ⁓ supplying chain campaign. ⁓ it was over ⁓ over a hundred and fifty, over a hundred and sixty if I remember correctly, and and ⁓ npm packages. So it was Tan Stack, Australia, UAP. So it it was a lot, right? It was very, very widespread. So basically what happened is that there was ⁓ malicious NPM or yeah, forged ⁓ NPM packages just running there and and people in their C D CI ⁓ cycles they were just pulling those packages, right? And basically infect infecting a bunch of ⁓ of stuff. ⁓ yeah. ⁓ on I think ⁓ on May twelfth, MSB open source the full toolkit and these are ⁓ these TTPs are not like literally public, right? ⁓ something that is ⁓ very interesting in here and part of the questions I wanted to ask about this one is like ⁓ the tan stack ⁓ the particularly the tan stack wave
Dillon Sparks: you
Sergio Villegas: ⁓ that was one of the packages, required no stalling credentials. It was just a ⁓ CI. It was part of your normal development cycle, right? ⁓ misconfiguration. ⁓ John mentioned misconfiguration several times. So how do you scope in your attack surface to include the pipeline? Right? I think that's interesting questions. ⁓ is the pipeline part of the attack surface? Is that a complete separate thing? I don't know. ⁓ well results.
John Untz: Yeah, so like I I I think this is a good anal ⁓ I won't ⁓ I I caution to use this as a great analogy, but I think it is a good analogy for like ⁓ th this to be clear, right, like yeah, this this is not none none of this was like the fault of AI, right? It was just more autonomy, right? We've got these pipelines, you know, C S C D pipelines have been around for much longer. but It's an autonomous process that we, you know, took basically in order to like, you know, speed up things for for developers. ⁓ we start trusting these open source packages as like has been the case for you know, decades, right? but I think it's an interesting mirror that we're seeing a lot more like, you know, AI assisted cybercrime. ⁓ This is the same problem just with a different root cause, right? At its root, it's still just autonomy, right? Like like AI is just making making the auto stuff, you know, easier. ⁓ but we're inherently trusting some of those automated processes because it's easier, right? Because it made our life quicker and easier, let us do and accomplish more things. ⁓
Sergio Villegas: Mm.
John Untz: I think this is a this is like a a ⁓ perfect kinda showcase for like why it's important to to to keep a human in the loop on things. Not even like this isn't even just like a cybersecurity like problem, this is like a development problem where, you know, they had all of you know I don't even remember how many countless supply chains were like attacked through this method. And they were I mean they use different mechanisms for for for all of them, but at the end of the day it was still just the same the same core problem, right? We have an open source, you know, repository of some sort that as soon as an update got, you know, pushed, everybody's tool chains just start pulling them in because, you know, we rightfully so, I think we've kind of been taught, you know, you want to update as fast as you can to make sure you're ahead of the curve. But in doing so, we kind of miss that step of like, okay, how do we, you know, how do we catch the bad stuff when the bad stuff gets in first or in the middle of it? at all saying that we should go back to just, you know, taking a human eye to everything because I'd argue humans make more mistakes than ⁓ than AI n or or or anything else like that does ⁓ when it comes to like parsing, right? Parsing large data sets. ⁓ But I just think that's you know that's just an interesting view. Like like the as I especially with this with this episode being, you know, very AI heavy, this one's still kinda like the same problem. It's just not we're just it's it's not AI, but it's still it's still the same like underlying trust problem, right? Yeah, yeah, exactly. Right, right. Yeah.
Dillon Sparks: Yeah, it's just faster with AI. Like it gets you down that path a lot, a lot faster, right? And to touch on Richard's point earlier, it's like, how often are people actually looking at some of the access and permissions and some of the prompts that are, that are, you know, being placed in front of them before they're just like, yeah, yeah, just go update it. Like whatever you have to do, go update my CI CD pipeline with the latest package. And you know,
Richard Brown: Yeah. Mm-hmm.
John Untz: Yeah. I think it was a friend of mine that said, just put the code in the bag.
Richard Brown: Yeah.
Dillon Sparks: Yeah, yeah, yeah, just put it in the bag.
Sergio Villegas: Yeah.
Richard Brown: Hahaha
Dillon Sparks: I actually had. supply chain attack on our website. So blog post about it if you want to check it out. There's a whole strategic section on there. But basically, you know, I called this months ago. I was like, it would not surprise me if we start to see this kind of escalate just given the way that kind of the industry has been trending with trying to do more with less, the implementation of autonomous agents and trying to automate out a lot of the
Richard Brown: Mmm.
Dillon Sparks: CI CD pipeline stuff ⁓ and some of these bots that are being brought in to QA stuff as well. again, it's very move fast, break things centric. Yeah. Yeah. And it's like, well, if we break it, then we'll just go fix what broke versus, you know, let's just implement it the right way.
John Untz: Yeah. Great things, yeah.
Sergio Villegas: Ha ha.
Richard Brown: Yeah.
John Untz: Right. And it's dangerous too, right? 'Cause it's like moving that f like like that whole model like move fast, break things and then just like recover, there's some things that you don't you don't number one you don't want to break, right? especially like if you're an organization that has customers, ⁓ like most organizations do, like how else are we making money, right? ⁓ I d I don't think that's that's like number one on the things I'm not gonna wanna break is like any anything that involves customer data, ⁓ Like if I have to like you know, if I'm running a service and my service has to go down for an hour, like yeah, that's bad business, right? Like that's gonna hurt. ⁓ but if that's what it takes to make sure that my customer's data is not, you know, in any sort of, you know, harm, ⁓ then like that's the correct answer. You gotta eat that hour of business, right? ⁓ Yeah, that's a whole other soapbox. I'm gonna get on a whole side tangent that's not related to this now.
Sergio Villegas: Yeah, seems like we need a supply chain special episode.
John Untz: Yeah, yeah, yeah. Yeah. But no, you're right. I mean it was a you know, the I I I you know, mentioned on the side here, like it the it was it was effective. Like like I you know, I'm not I'm not at all gonna ever like you know, hats off to any attacker, but like they they made they ⁓ they they did what they set out to do, and then they allegedly said that they're done. I doubt that's actually the case. But
Richard Brown: Yeah, my gosh. Yeah.
Dillon Sparks: Yeah, baby.
John Untz: you know, we it it's a that's sud that like the the the supply chain attacks and of of of like the software side of things is like such a hard problem to solve because like look at like some of like the proposed solutions, right? So like I w like I've worked in an organization before that like kept their own repo mirrors. And like Sure, that might be a solution. It slows through i again going back to like the original problem of time and and speed, like it does slow you down. It does it does put you a little bit of a disadvantage from like leading edge development and security, you know, updates. ⁓ but it does give you that buffer. But then also that's a lot of that's a lot of storage, right? Like if I, you know I mean how many I I can't even think of how many different like potential mirrors would have to be stood up for any organization, right? ⁓
Dillon Sparks: Yeah.
Richard Brown: Well, yeah, and just the people alone to monitor those because you got to update them. You got to pull them down. You have some review that code. Yeah, it's a lot.
John Untz: Right. Right. Yep.
Dillon Sparks: Well, I think a lot of companies too just fall into the bin of like, well, they're doing it. They trust it. They're clearly smart people working there. Like, I'm sure they're looking at this. And it's just like...
John Untz: Right. ⁓ Yeah. It's a it's a it's just a giant, giant attack service, right? ⁓ it's you know you you it's yeah, yeah, it's it's definitely it's a risk decision like you've said before, right? Like it's it's a matter of like identifying what is what is of the most ⁓ impactful risk to you as an organization.
Dillon Sparks: Hahaha.
Sergio Villegas: It's it's a lot to cover for sure. Yeah. So Yep, hundred percent. And ⁓ not a question but a note I have ⁓ is that ⁓ yeah following team PCP release of the tradecraft on my twelve, something that was interesting is that the whole playbook of how this operated, right, was available. And that is right, from a vulner threat intelligence perspective, that is very interesting because it's like great, I have data to know how to what to look for. At the same time is do actors are replicating this?
John Untz: Mm-hmm.
Richard Brown: Yeah.
Sergio Villegas: And I and I bet you I mean John you just mentioned like how how many already affected repos are there still like many left there will be a lot of like leftovers. And your thing is like how many new attacks like this will happen and other companies will be affected just because of yeah, you trust you blindly trust a lot of repos just by default, right? I was looking I was looking to the other day, I some emails I received from ⁓ a repo I mean from the Pendabot that it upgraded things and it's like okay, cool.
Richard Brown: Yeah.
Sergio Villegas: I I don't know what that is, but I guess it's fine, right? I'm on the latest version. Yeah.
John Untz: Thanks.
Dillon Sparks: You ⁓
Richard Brown: Yep. Smash approve. Yeah.
Sergio Villegas: awesome. ⁓ well we have spent last I don't know, forty minutes ish. I think ⁓ so for reference on my script I have forty minutes. I don't know if we it's been forty minutes. So yeah. ⁓ I think it's been really interesting to to different cases where ⁓ the organizations have exposure that they didn't know about they didn't know about, right? so the big question, right? Like ⁓ a kind of a closing question and more in general, want to get your your insight.
John Untz: Yeah,
Sergio Villegas: ⁓ how do you explain to a CISO what continuous vulnerability intelligence, threat intelligence actually does for them week to week? Not in theory, right? Not like IOCs, but actual insights and understanding of how attacks are happening and the tools attackers are using, how effective they are, right? Like how do you make them how do you make them understand? Not saying they don't understand, but I think it's it's difficult.
Richard Brown: Yeah.
John Untz: You like break it down a little less technical, yeah, yeah.
Sergio Villegas: Right. Because for us it's like yeah ⁓ a fancy beer attacked this company, right? And it's like, well but is that is that useful? How? So ⁓ what do you think what do you guys think?
Dillon Sparks: Yeah. I think one of the hardest things to do, especially in this industry, ⁓ when you're talking to leadership outside of a technical area or a technical domain is how to translate exactly what you're seeing into risk categories, right? And helping them understand the scope of the risk, right? Associated with that thing without everyone just staring at you going.
Richard Brown: preach. Yeah.
Dillon Sparks: Uh-huh. Like I've seen the glassy eye and it's tough, right? It's very difficult to take this data and then operationalize it in a meaningful way to make those standard business practices evolve around that, right?
Richard Brown: Yeah. Yeah. Well, it's tough too, because there's so much confounding information out there. We have CVSS scores, CVSS severities, we have risk indicators, are you saying? And when you try and qualify them down, it's hard, because you see something come across, I don't know how many times we get asked, hey, this CV is 9.5, criticality, we need it. I'm like, hey, cool.
John Untz: Right. Right.
Richard Brown: but it's complex. Yes, it's bad if they exploit it, but it needs six things to go wrong to do that. Right? And honestly, the hardest thing I think getting CISOs understand, and I can imagine all the calls that Sergio Zemmler has rubbed his temples is threat intelligence first, phone intelligence. Right? I don't care who's using this CVE. I care it's being used.
John Untz: Right. Yeah. Rights. Yeah.
Richard Brown: where Sergio understands who's using it, who's targeting, who's being impacted by it. So I think that's something that also get across there is like you said, fancy bear, cool. don't care about fancy bear. I do, but you know, not as much as Sergio does.
John Untz: Right, right, right. Yeah. Yeah. Now I'm gonna plug ⁓ Nate's recent article he just put out, ⁓ the the the last blog post that was put out, ⁓ about ⁓ drawing a blank ⁓ metabase. ⁓ because I think that's like a solid highlight of the like the basically the like the time to like I'll I'll you know Time to kill is the right word here, but like like time to kill as far as like a threat went for ⁓ for like any particular vulnerability, right? Like ⁓ anybody hasn't read that article yet, it's really great. ⁓ it breaks down basically like the time from like notification of like this is a thing, ⁓ before a C V E even was ⁓ assigned, ⁓ all the way to hey, we've got detections and and and stuff happening and, you know, we're we're figuring out which you know, who who's been ⁓ or who's exposed and and whatnot.
Richard Brown: Yeah.
John Untz: And I think the the like that particular one was like four four and a half hours roughly and it's just like those those timelines like that, like that's the crucial aspect is like those are the numbers that ⁓ that like when you talk like like Sergio, right? Your question basically is like w how do I make a CISO care? That's how I that's exactly how you make a CISO care is you say, Hey, in f you you had a vulnerable window of essentially four and a half hours. Now maybe there's something to the left of that as far as like, you know, when it was a zero day. ⁓ but
Richard Brown: Yeah.
John Untz: It you know, the zero day stuff's the that's that's that's a whole that's a whole other, you know, again, Richard known unknowns. ⁓ that, you know, it's just you can't really goes into Sergio's side of things, of like, you know, looking at the the the threat piece of it as far as like, you know, APTs are gonna be the ones that you have to worry about as far as like zero days. And knowing which knowing which APTs to care about for your organization, I think is is kind of the key part there because, you know, I'm not I'm not super versed anymore on like which APT e which E A P T does like focuses on which industries anymore, but like I don't care in it necessarily if I'm working at a bank, I don't necessarily care about the ones that are targeting, you know, medical sectors, right? ⁓ but
Sergio Villegas: Yeah.
John Untz: you know, it's good to have that info from like from your s your your perspective of like, hey, these are the things these are the indicators for this type of APT, for this industry. Like that's such a like a brilliant way to approach stuff.
Sergio Villegas: Hundred percent. And I think ⁓ I always think of it at at the three different levels of like intelligence, right? One is ⁓ what are your ⁓ strategical, right? Like what are the capabilities you have to defend against this variety of stuff at the tactical level? What steps are you doing to reduce the exposures you have at the operational level, right? Like, hey, you are actually vulnerable to this specific CBE. So think about like it in that broad scope. I think it's ⁓ how I normally approach
John Untz: Yeah.
Sergio Villegas: I I don't I don't get anger in those rooms at CISOs I I don't really. ⁓ but yeah, yeah. Right. But yeah, it's you you can't you can't ⁓ I what I actually dislike is like them trying to be like, hey, so trade intelligence, yeah, give me all of the IPs I have to block. It doesn't matter. It's not about the IPs, it's not about the hashes anymore. It's about like capabilities and that's why, right, in in in MSS we try to cover a bunch of that, right? Like
John Untz: It's not anger, it's disappointment, right?
Sergio Villegas: if we test for different potential capabilities. Just C C V E's because they are useful for like novel stuff that is happening right now. That that ⁓ what John just mentioned, right? Like the timing is is key in here. So being able to detect it fast and tell you you have this exposure. And apart from that tell you, hey, and you have these ⁓ these other actors using it right now, right? When you cover those three is those three levels of the spectrum of intelligence, I think is when you can have a clear
Richard Brown: Right.
Sergio Villegas: ⁓ winning scenario here for you for for our customers at least, right? Like we yeah. Like I hats off to the to the attackers maybe, but but we care about our customers. anyway, I think that's ⁓ that's a good place to wrap it up this month. ⁓ this ⁓ this special edition sorry. ⁓ so thank you again for joining for joining in ⁓ this episode. Thank you. ⁓ it was again Richard Brown, Jon Ans, Dun Sparks. It was a pleasure having you
John Untz: Ha ha ha.
Richard Brown: Yeah.
Sergio Villegas: I know we talk about like tax surface discovery, continuous monitoring, track intelligence, vulnerability intelligence, two different things. ⁓ so if you if you for our listeners and our viewers, if you have any note, if you want to discuss or you are you don't agree with any of what we said, just let us know, right? We have a Discord, we have a Reddit, ⁓ you can put it in the comments and we will h be happy to discuss that ⁓ on the next special episode in here. So yeah. Thank you for listening, stay safe, and we will catch you next next time.