Sean McMillan: We spend a lot of time talking about new technology on this show. But technology has a funny habit of exposing old problems. This week we're going to be looking at AI agents piecing together attacks from information that looked perfectly harmless, industrial control systems becoming easier to target as AI lowers the technical barrier yet again. And a payment system that trusted a field that was, oops, not protected. Later, I'll share one of my favorite conversations from Black Hat that I had with Kraig Faulkner, field CTO at Infolock, who makes the case that all this excitement around AI is really forcing us to confront something much less flashy: understanding our own data. This is Initial Access. I'm Sean McMillan, community manager here at Bishop Fox, and I am joined today by Kendrick Urbaniak, senior operator and exploit developer. Dillon Sparks, senior operator, and John Untz senior security engineer. Gentlemen, thanks as always for joining.
John Untz: Hello?
Dillon Sparks: to be here.
Sean McMillan: Now before we jump into the headlines, let's take a quick look at some things happening around here at Bishop Fox. We recently wrapped up our black hat and DEF CON coverage, and over the coming weeks, we will be sharing more and more of those conversations we recorded from the show floor. We've already started releasing this on socials. You may have seen some clips, but as we record, today we're featuring one of those interviews in the podcast and it's going live on YouTube. If you enjoy it. smash that like and subscribe, I guess. we also published two new pieces of technical research this week. Jon Williams and our threat enablement analysis team take a closer look at CVE-2026-8452, which is a memory corruption bug in Citrix Netscaler's SAML handling. and they built a safe way to verify whether a virtual server is actually patched without. Causing it to crash or disrupting any live sessions. And Jon Ronan Kervella and the team also broke down two critical flaws in Veeam service provider console that chained together into unauthenticated RCE. They reproduced the chain end-to-end, confirmed the fix, and published a safe detection tool for defenders. You'll find links to that research, the tools, and our black hat interviews in the show notes. Now Let's let's get dirty. Let's talk about this from TechSpot. AliExpress was silently running audio in your browser to fingerprint and track your device. this was a developer troubleshooting a Bluetooth headphone issue that ended up uncovering something pretty weird on AliExpress. The site was running audio processing in the browser, not playing any sound, but it was fingerprinting. the device. So basically it was using tiny differences in how a machine handles audio to identify the user without relying on cookies. when you first hear this issue, I guess what jumps out to you guys?
John Untz: I mean I my first thing is like, cool, another thing that we're being used or we're using to to track people, you know, anonymously.
Sean McMillan: Mm-hmm.
John Untz: something that I think I like immediately keyed in on was the fact that we don't really have tooling built to handle from a user's perspective, right? We we we think in storage for like cookie storage and stuff like that. Like those are the things
Sean McMillan: Yeah.
John Untz: we consider when we consider user privacy or like what are the things that are being stored on my machine. Last I checked, as far as I'm aware, we don't really do a whole lot of like live heuristics kind of, you know, what what is currently being processed in the browser. and I think as we've moved further and further into the like as as we've matured I don't even think mature, just just evolved what what the web looks like. You know, similar to how like exploit dev worked, right? Exploit dev moved from being like land something, you know, land a file on a computer and it starts up at whatever time and you know, that's that's an exploit, right? we've moved more on that front into like stuff that resides only in memory. And so it kinda makes sense that like this is the kind of the same logic of, you know, we're gonna you know, a company that is trying to track customers is gonna do these things that exist only in that that are only gonna exist on at memory. They're not gonna be stored somewhere.
Kendrick: I I do find
Sean McMillan: Yeah.
Kendrick: it annoying that they're tying up my audio lanes though by by having a thread thread going. So I'm not not too excited about that one.
Sean McMillan: Yeah. Don't mess with my audio.
John Untz: Yeah.
Kendrick: No.
Dillon Sparks: Yeah, I think it's a, an interesting angle and something that we touch on a lot here, is inherited or assumed trust, right? And it's like, all of these consumers, there is this level of, you know, like assumed trust that this site that you're visiting is doing their due diligence. And, know, they're not collecting additional data that they don't need, which I mean, we all as American consumers know that, you know, we are the prize, when we walk in anywhere. So.
Sean McMillan: Yeah.
Dillon Sparks: yeah, it's, it's just kind of, I understand it as a technique and like a practicality. but there also has to be this point where we as technical professionals, like understand that regular consumers are not going to have the wherewithal to like know how to detect or opt out of this sort of collection method. Right. And so it's like, where's that line and where is the responsibility?
Sean McMillan: Yeah. No, this was this was found kind of accidentally, right? This was not no one thought anything like this was happening. It was, if I remember correctly, something about plugging in headphones and unplugging it that kind of triggered a WTF moment.
Kendrick: Yeah. It was the transferring of PC to phone audio is how they discovered it and that it w it wasn't happening.
Sean McMillan: yeah, that's right.
Kendrick: So because
Dillon Sparks: Yeah.
Kendrick: it wasn't happening, they're like, why isn't this happening? And that's where it's like, there's still this active audio connection out there that's not disconnecting. yeah.
Sean McMillan: Mm-hmm.
Kendrick: It's that's why I'm more annoyed about that because I'm I'm pretty sure I've had this issue before and this was the this was the reason for it. Not Alibaba but or AliExpress.
John Untz: right. Yeah,
Kendrick: But like
John Untz: I think that's also
Dillon Sparks: Yeah.
John Untz: worth mentioning, right? Like Alibaba got caught, but like that doesn't mean that they're the first or only ones that have been utilizing the same technique. 'cause I'd like you like you said, like I know I've had that exact same issue before where I've tried to like switch to my headphones or something like that and you know, either either a Windows driver or like whatever, like just holds the connection essentially.
Sean McMillan: Mm-hmm.
John Untz: So I don't know, like, yeah, that's I think that's worth a deeper dive for sure of like figuring out like okay who else has been doing this? Because like at least in my case, like I you know, I I'm I'm like a little more privacy focused, so like I I I'm not using like Google Chrome, for example, right? I'm using a different browser and I've got you know I've got Well who knew who knew an advertisement company would be collecting data, right?
Sean McMillan: Wait, Chrome collects data?
Kendrick: No, no, no, no. It's fine. It's fine.
Dillon Sparks: Noooo
Sean McMillan: Right, right.
John Untz: but like I you know, and even when I was using Chrome, like I still had like, you know, blockers and stuff like that to to that that would have mitigated stuff like this.
Sean McMillan: Yeah.
John Untz: 'cause I think I think it was was it Brave browser was the first one to come out and just be like, Yep, we've known about this and we've been blocking it for however long
Sean McMillan: Mm-hmm.
John Untz: and it's like okay, well like that's like one example but there's other browsers obviously and there's other mechanisms to block these scripts.
Kendrick: This was part of their anti-fraud though, like scripting. Like in in theory, yeah. So
Sean McMillan: That's what I was gonna say. That's the that's the the explanation.
Dillon Sparks: Yeah. Yeah.
Kendrick: I I just I just don't know like the technical reason of why this is the main avenue. This like or th this is the avenue you chose to go down for like fingerprinting a user's, like whatever. I mean, maybe I gu I've never built a fingerprint through like every web browser, so maybe this is like the easiest one that all of them have. therefore this is like the utility that you can use most generically across all web browsers.
John Untz: Mm-hmm.
Kendrick: I don't know. It
Sean McMillan: Mm-hmm.
Kendrick: could it could just be one of those things where it was the easiest path because all the other paths aren't universal in nature.
John Untz: My I I I you know, I didn't look at like as every facet of like how you can fingerprint via like browsers, but I have I I assumed this was just like one approach in a multi layered approach that they're taking where it's like, yeah, this is the one that we just happen to stumble over and it's weird, right? It's not something that we're we're used to seeing. You know, but they are
Sean McMillan: Mm-hmm.
John Untz: still doing like everything else, right? They are still doing, you know, c cookie inspection and and and all of the things that we're already used to like looking for from a privacy perspective.
Sean McMillan: Yeah, I think we
Kendrick: And important.
Sean McMillan: all just kind of well, not maybe not all of us, John, but
John Untz: Yeah.
Sean McMillan: I think a lot of us just kind of like accepted the cookie thing. We just have taken the lumps and said, you know what? Sure, they're tracking us. But I feel like I feel like this kind of crosses a line from any kind of fraud prevention or convenience that cookies can offer. I mean, it just it just feels like.
Kendrick: But at least it's not your mic
Sean McMillan: Obvious tracking.
Kendrick: it's not your microphone though. So I we call this a win.
John Untz: Right. Yeah, I mean that's fair. I mean it could have been in the other direction. Yeah,
Sean McMillan: Yeah, yeah, that's true.
Dillon Sparks: Yeah, yeah.
John Untz: I didn't I didn't even consider that. What if they were turning on your microphone? I mean that's you know I'm sure they would l love
Kendrick: That's level.
John Untz: to, but
Sean McMillan: I have a physical mute button on my control panel here that I leave on almost all day so that no one hears me burp on a Teams call. And I
John Untz: Yep.
Sean McMillan: think it might have saved me something.
John Untz: Yeah, right.
Sean McMillan: okay. So we also have another another one from Bleeping Computer this time. US warns of AI-powered attacks on Siemens PLCs in critical infrastructure. They put out a joint advisory this week warning that attackers are using AI-generated scripts against internet exposed Siemens S7 PLCs. The targeting itself is pretty basic. It's scan for exposed devices, weak credentials, default configs. the difference here is how much expertise you need to find one. AI is quite famously in cybersecurity. Eliminating that floor. so is is this is this any different than AI just generally lowering the the the barrier in any meaningful way?
John Untz: No, not in any way. Like I that's least I like that's my take is like you're not gonna this isn't like increased how many PLCs are out there exposed to the internet. Right, all this has done is lowered the bar as far as how easy it is to talk to those protocols. Right. A lot of those are gonna be like custom binary protocols or something like that that you have to do,
Sean McMillan: Mm-hmm.
John Untz: you know, previously a lot of manual time reverse engineering, and now you can just throw AI at that part of the problem and say, Hey, figure out how to talk to this specific device or talk to this service, which is exactly what AI is being used on like other sides of reverse engineering. It's literally that same piece of the puzzle that is
Kendrick: AI is
Sean McMillan: Yeah.
Kendrick: really good at talking to things. It will get it wrong
John Untz: Yeah, yeah.
Kendrick: 90% of the time, but it'll keep on trying to talk to it.
John Untz: Right.
Sean McMillan: Is it as patronizing to these PLCs as it is to me? Is like, is that why it's just such a smooth talker?
Kendrick: I'm sure, I'm sure. Yeah.
John Untz: Probably worse.
Dillon Sparks: It's really interesting as on the T team, as we kind of look through these CVEs that come out daily and we're reviewing things. It's so interesting to see how many CVEs now. Clearly we're like AI generated in this perfect like ecosystem where they're like, yeah, it's totally mass exploitable. There's this very specific bug that does this thing. And then you like, read through the actual blog post about it, and then at the bottom, it's like, performed in a vacuum under perfect conditions with all default configurations that normally cancel out all of these features. And you're like, great. So all I have to do is turn off all of the safety features. And now it's exploitable. And it's kind of the same
Sean McMillan: Mm-hmm. Yeah, who'd a thumb.
Dillon Sparks: thing here. it's like PLCs that are running
Sean McMillan: Okay.
Dillon Sparks: outdated tech exposed to the internet are at risk. Wow.
Sean McMillan: Yeah. So
Kendrick: Yep.
John Untz: Who knew?
Sean McMillan: do we think
Dillon Sparks: Yeah.
Sean McMillan: that's a big problem though? Like is that like this is a news story. This is this an well, obviously it's a big problem, but
Kendrick: Yes, it
John Untz: Yes.
Dillon Sparks: Yeah, it's an issue.
Sean McMillan: I mean like how wide is that is that widespread or it's like literally every time it happens we're seeing it in a news story. Do you think that's something more people need to worry about or or just they've all been burned?
Kendrick: It so think about it on a global scale, yes. I would say, you know, not not saying the US is better in this regard, but they tend to have a little bit better regulations on, you know, safeguards to some degree, like a
Sean McMillan: Mm-hmm.
Kendrick: little bit more hardened, but still you can still find stuff all over the globe that is is vulnerable or outdated or somebody forgot to plug in the the USB drive to that one machine one time and now it's twenty versions, twenty years of old software but it's still talking on the internet, so it It it's it's a global problem, not it's
Sean McMillan: Yeah.
Kendrick: it's gonna be a problem
John Untz: Yeah.
Kendrick: forever.
John Untz: Yeah, and I think like, you know, to your point, right? US does better. Like I you know, we can all sit here and say that like, you know, whatever power plant like whatever's in the news with this one, right? It's always yeah, a water treatment facility, a power plant, like anything that's being
Sean McMillan: Mm-hmm.
John Untz: run on these devices, certainly everybody can do better. US is certainly doing better than most. but you're gonna see, you know, we're we're we're definitely gonna get hit more frequently now because of the accessibility factor. But I think like to like the specific question of like the the ease by which this is being accomplished, or or the the the risk of, you know, un no not or default creds and and and whatnot, you gotta think right, like this is not typically like a power plant isn't being set up by a cybersecurity firm, it's being set up by power plant engineers. It's a diff you right, like the mindset that the trade is totally different. And so for for them it's like these are these are facilities that are d running services. Those services have to just come up and be up and like I think for decades, you know, at this point, the the mindset has not been security because the uptime is the is the is the entire
Sean McMillan: Mm-hmm.
John Untz: call, right? Just make sure this thing functions. And Yeah, yeah, like honestly.
Sean McMillan: Duct tape it if you have to, but keep it keep it online. Yeah.
Dillon Sparks: Yeah, keep the lights on.
John Untz: Right. Keep the lights on. Exactly. and so yeah, I think, you know I I I hope this like will definitely like trend more towards the security side of things of like well we keep the lights on a lot more of the time if we change the password, for example. but I think Right, make sure you even have one, yeah. Yeah. Right.
Sean McMillan: Mm-hmm.
Kendrick: having a password and like making sure you have one on the device, yes, yeah.
Sean McMillan: Right, yeah, yeah. USA
Dillon Sparks: Yeah, yeah.
Sean McMillan: one two three.
John Untz: Yeah. But
Dillon Sparks: That's right.
John Untz: like, you know, w I think this wasn't a problem that we encountered that much before because we didn't know how to talk to the p to like like the the average, you know, script kitty hacker didn't know how to talk to whatever Siemens PLC, right? Didn't even know how to look for it. And so
Sean McMillan: Yeah.
John Untz: like that's like I said before, that's the that's the factor that AI is is enabling here.
Sean McMillan: Now this also this advisory comes very shortly after Iranian linked actors were suspected in disruption of all those Minnesota water utilities. Does that change your perception of this story or how seriously you read something like this?
Dillon Sparks: I think... I think... What it highlights is something that always happens whenever there's global conflict, right?
John Untz: Mm-hmm.
Dillon Sparks: Cyber attacks related to global conflicts, whether armed conflicts or political through sanctions, et cetera, there always seems to be some sort of infrastructure related fallout between
Sean McMillan: Mm-hmm.
Dillon Sparks: the host nations of that conflict. That's not new. What I will say though is, as AI lowers the barrier to entry and increases accessibility. I do think you're going to start to see a few more nation states out there using AI to kind of get a seat at the table and leverage that now. Whereas like they may not have had those capabilities years prior. And so it was a little easier to, you know, not have to negotiate with them, so to speak, over any issues. So I think again, I think it's just kind of lowering the barrier to entry. So we might start to see a shift in some of the global socioeconomic
John Untz: Mm-hmm.
Dillon Sparks: powers.
Sean McMillan: Yeah. Yeah. well, let's let's talk about this zombie card attack. We should I feel like every Halloween there's some kind of zombie themed or ghost themed story or something. We should maybe hold this till then, but no. Hacker News, zombie card can zombie card attack can revive expired Visa cards for contactless payment. So this is researchers at UMass Amherst. That found a way to make an expired Visa card work again for contactless payments without cracking any cryptology or anything. They just changed the expiration date. my first question is how?
Kendrick: It well, first off, this is a very so d we just talked about very ideal conditions. This is
John Untz: Yeah.
Kendrick: one of those exploits that is very ideal conditions for this to happen.
Sean McMillan: Yeah.
Kendrick: It was one specific kernel or one specific card running this kernel three, whatever that is in in Visa land, It's just like, okay, yes, it is possible on this particular card to do it. It did it's not a huge exploit out there, but yes, it it's it's possible on this one. So it was changing the date because it wasn't part of the cryptographically signed sections that were being transmitted. So
Sean McMillan: Yeah.
Kendrick: all they had to do was say it wasn't expired and poof, now it's not expired, it gets accepted at the tr the terminal and we're off to the purchasing whatever they were trying to purchase.
Sean McMillan: So that old idea of your expired Visa card, cut it up into a million pieces and scatter it across an entire continent still still holds true.
Kendrick: far but I yeah, I I still I still personally shred
Sean McMillan: That's what I've always done.
Kendrick: all my cards when they expire, so technically I think you're supposed to mail them back. They or they want you to mail them back. They give you that nice little envelope. Yeah, yeah, yeah.
Sean McMillan: do they really? I used to
John Untz: I didn't know that.
Sean McMillan: work at a bank and I don't know that.
Dillon Sparks: No shot. No shot, brother.
John Untz: There's no way.
Kendrick: Yeah. Yeah yeah. They give you a little envelope to mail them back if you have like the metal cards. If the metal ones. 'Cause
John Untz: I definitely did do that. I I definitely like did like some some surgery on my my metal my when I had the whatever the Amex card was.
Kendrick: Yeah. Yeah. They give you
Sean McMillan: Huh.
Kendrick: like a little nice little envelope sometimes to send them back. Because you're because I think they th think you can't shred them, so they're like,
John Untz: Right.
Kendrick: you know, how do you dispose of this? Send it, you can you know, here's this envelope to send it back to us.
Dillon Sparks: I just melt
Sean McMillan: That's fascinating.
Dillon Sparks: my Amex down to make musket balls. Like a good patriot.
Kendrick: Ha ha I see, I see.
Sean McMillan: It's not defacing money, it's defacing credit. Fantastic.
John Untz: Right, yeah.
Dillon Sparks: That's right. It's different.
Sean McMillan: so this is if I'm understanding this correctly, the expiration date that the terminal reads isn't bound to data that the terminal verifies. So it sees a date that just kind of this is again assumed trust from a terminal here. do you see this as just like this is one little thing that needs to be switched, or is there like a bigger kind of systemic thing for this? I mean, you you mentioned it's only one type of card, but I mean, hey, if I have that card, I don't care how many types of cards, you know, if I'm the one that that gets burned.
Kendrick: True. yeah. I I I mean it is a so in theory it shouldn't be. Like everything that everything that should go through the the point of sale terminal should be verifiable. because that's the whole point of it. That's why we in the US at least we're we're pretty late adopters to the the chip in the card
John Untz: Right.
Kendrick: process. that that's essentially why we moved from the mag strip to the chip so that we can make sure that things are cryptographically signed and that everything in
Sean McMillan: Mm-hmm.
Kendrick: theory sent between the point of sale and the card is verified, so that then it they can trust that you actually are the owner of that card to like do the transaction well not the owner of the card, but like that card it says it's the owner of that card at least, hopefully, and then you can make your your purchase. So it's it's a very trust oriented thing. we're still we're still living in a society where it's still up to the point of sales person to verify that you're doing not doing anything shady while you're standing there at the point of sales terminal.
Sean McMillan: Yeah.
Kendrick: 'cause 'cause we're not that far from, you know Caching bad checks at these
John Untz: Mm-hmm.
Kendrick: places. it's really just we develop technology to mitigate that risk as much as possible, and there's still workarounds up out there probably for these. We've seen point of sales terminals be hacked in steal cred steal credit card information. I'm sure they could probably j just fake a sale and all that fun stuff related to the point of sale terminal. So
Sean McMillan: Yeah.
Kendrick: we we we've gone a long ways, but I'm sure we'll still find stuff in the future about point of sales issues.
Sean McMillan: I think this was tested at three US banks, right? yeah, three major US banks at real world retail and grocery terminals. and one bank approved it, the others all denied it. So it's like it's not maybe necessarily as widespread. Does this feel like just kind of like an academic, hey, isn't this kind of neat or more
Kendrick: It reminds me of a
Sean McMillan: problematic than that.
Kendrick: story many years ago with a Visa card. They I don't remember the exact details, but they were able to clone your card.
John Untz: Mm-hmm.
Kendrick: And it w it it looked really suspicious what they were doing, but like, you know, in a real world scenario, they had a a fake card where they could inject into the chip of the card the information that they were able to, you know, swipe as from you as you walked by. So this kind of reminds me of the we're kind of in the same little little nuanced I mean it's a great marketing thing. I think they sold a lot of those RF reader blockers. so I
Sean McMillan: Right, yeah. my goodness.
Dillon Sparks: Yeah
Kendrick: I'm sure that industry is booming and would love more stories about RF attacks, but yeah. See, yeah, RF, yeah.
Sean McMillan: It's still yeah, it's still huge. Still huge. I see yeah, there we go. Dylan, our own Dylan has one.
Dillon Sparks: That's right, baby.
Sean McMillan: Why not? You know, why not? Why not block it?
Kendrick: Yeah. Yeah. It's just it's just another one of those things where it's it's on paper academically possible, but it's definitely one of those things where you try it out in the real world and there's major consequences if you get caught, so
Sean McMillan: Yeah. And I
John Untz: Yeah. Not just leaving not just being
Sean McMillan: mean, it does it does kind of feel like one of those things like the scare of well like we talked about recently with the DEF CON plane situation with public Wi-Fi and like suddenly one thing happens and the general public were like, Are they is everyone gonna be afraid of Wi-Fi again? And now is everyone afraid of people walking by and scanning my back pocket and stealing? My visa card now. doesn't seem i it's it's it's a a level of risk appetite, I guess, that
John Untz: Yeah. I mean the
Sean McMillan: Check with Visa if you've got one of these cards, check with Visa.
John Untz: Yeah. Well like Kendrick, like you were saying, this is like such a the number of steps required, like the feasibility of somebody standing in a Walmart and like going through all of the proper steps to like get this to work is not feasible. Like it's not
Sean McMillan: Yeah.
John Untz: like you said, not real world applicable.
Kendrick: You could you can maybe do it this once or twice, but like they're gonna look at the security camera video when like they come back to investigate and they're gonna be like, That guy Like
John Untz: Ha ha ha.
Dillon Sparks: Yeah.
Sean McMillan: The the type of characters I have at my Walmart. Yeah, yeah. It'd be pretty
John Untz: Ha ha.
Sean McMillan: quick to find the guy that's capable of doing this. well, we've spent the episode looking at specific attacks and techniques. But one thing they all have in common is that they expose assumptions organizations were not aware they were making. While I was at Black Hat, I had the chance to sit down with Craig Faulkner. Field CTO at InfoLock and we started by talking about all the AI noise surrounding the conference and then kind of got into something a little more nuanced, why AI is forcing organizations to finally understand their own data. Something he feels very strongly about. Here's that conversation.
Anna Vanderberg: First thing we like to ask people is just what is your role? Tell us a little about yourself and what brings you to Black Hat. Yeah, so I'm the field CTO at InfoLock. Info Lock is a data risk management advisory firm. So we do manage DLP, manage DSPM, data classification, all the things around data security. what brought me to Black Hat is to meet with everyone, see old colleagues, see new colleagues, right? Meet with partners. and just experience what BlackAph has to offer, right? So Yeah. As you no doubt have noticed, there is plenty of actual like literal noise happening out there. Yes. And then when we leave the convention, there is still noise in the industry from your perspective. What's the noise that everyone's kind of losing sight of the the picture? What's what's everyone yammering about? Yeah, everyone's yammering about AI. I'm sure that's when everybody's But I'm gonna spin that a little bit, right? Sure. So the reason why it's hot and I care about it so much is because we look at it from a different perspective. We look at it from what is your data, what is the context of that data, leveraging DLP and DSPM tools to understand what that data is and how it ties back to the business. So we want to understand the context of the data. AI has just made more data and it's made people care about that data now. And so now we're really evangelizing, hey, all of this data that you're using, creating, curating. We need to secure it and put guardrails in place. So that way it is used effectively, it's secure, you're not getting rid of your crown jewels, things like that. So for us it's all about the data within AI, not so much the agents or hype or anything like that. So that's definitely hot for us right now. And I'm I mean you y you see so many boots just from here you can see like a hundred that have AI in their title. Yeah. It's it's really kind of everywhere. Yeah. Now it's just like like We're an AI company. Every company's an AI company. So how has that kind of changed your perspective? How has that been a challenge for what you do? Yeah, I think honestly, I I don't know if it's been as much of a challenge as it's been an opportunity for me to learn and grow. Right. So the ability to I do a lot of thought leadership and blogs and podcasts and things like that and going and finding some of those things, finding events, things like that, it took a lot of man hours. I don't have to use those man hours anymore. We have AI that can go and curate the internet and find those things for us. Yeah. be able to, you know, find what's relevant to what I need to speak on and go and find those events and things like that. So I actually have really enjoyed the productivity game that I've gotten out of using AI. Now, on the flip side of that, my family is also using AI. Right? So there's a scary aspect of it too of you know The layman, if you will, is using a technology they literally know nothing about. So it's magic. It's a genie in a bottle. Absolutely. Yeah. My kids don't touch it. Yeah, they know about it. They don't touch it. I I dabble, you know. Yeah. My wife dabbles, but then you up the risk and we look at other generations dabbling in it. And I think that that's a a a place where they don't have those same kind of data concerns that A a big organization that would seek out your services would. and I think that's that's the new world. Interesting point though, we saw I don't know, 10, 15 years ago with ransomware them shifting to extortion and then doing all these other tactics, and it went from personal, like people, to businesses. Now we've seen it kind of go back to individuals again. Yeah. Is that what's gonna happen with AI? This is what I'm saying? Yeah. I I kind of see it already. Yeah. I see it in in not just in the cybersecurity industry, but friends of mine that are in totally other job roles. And I see their bosses implementing AI. And they're not they're not checking all the boxes. They're just like, hey, what if, you know, now we can do this. So let's do it. And so I think that's probably like a a big wake-up call for a lot of organizations to see that. Holy smokes. We need something like like what you're doing because plausible deniability is gone. It is. Right? Like, with all the tools we've seen come out because of AI, the visibility and exposure of data now within an organization, AI doesn't know where to go look for information. It just looks at all of it. Well that completely eliminates our legacy rollback role based access to controls that we've implemented in every technology from the beginning of time. Because AI goes around all of those controls and looks at everything, right? So it's a very interesting dynamic we're in now of of what's gonna happen and where it's gonna go forward. Well everyone's so focused on implementing AI and all that stuff. So if that's clearly got some noise to it, what where's the signal? What what do people need to be getting right? I think first and foremost, you gotta understand where your data is. Like in order to have a successful AI strategy. And have your employees and your business partners, third parties using these tool sets. Yeah. You've got to understand where that data is, right? There's many stories out right now of third parties getting breached and impacting the original company's data, the partner's data. You know, we're seeing things in healthcare where they're using AI for modeling and things like that. I actually have a friend that her husband recently had surgery and They modeled what they were gonna go do surgery on and actually only modeled fifty percent of what they needed to do surgery on. And actually it was a more intense surgery once they got in. Yeah. Because they relied on AI to model what it was that they were doing and they missed the connection with the MRI to the AI model. There was something there that becomes the I I feel like every conversation comes back to implementing AI, monitoring it. Yes. Implement it smartly and and keep an eye on that AI. Yeah, for sure. Yeah. Set it and forget it is not something we can do in the realm of AI. Yeah. And I think we've gotten really comfortable as an industry on set it and forget it. Mm-hmm. So we've got to get back into that mentality of really just back to the basics of good security hygiene, good IT hygiene, understanding what our business is doing, all of that. Yeah, absolutely. That's that's that's the key. Well I think We often ask like what the signal is, what the noise is and it it all does kind of tie back together, I think. Often when I ask what's the signal, it's like well they they kind of just said it, you know? Yeah, exactly. Well and it's interesting too that signal it's we've been concerned about threat for a long time. Then we started kinda being concerned about identity and now AI is merging both of those concerns at the same time because they are it's a potential threat, but it's also an identity that it is. So I've changed my talk track to talking about entities. It's not about humans anymore. It's not about workers. It's not about process. It's about entities. Cause there's so many entities now that can interact with a business, both human and non-human. So Yeah, I think it's key knowing where your data is, how it works, and not just asking Chat GPT how you can implement AI, because I know you know there are people who do that. And you're gonna get a wonky answer. Yes. Or what it thinks is the right answer. Yeah. Right. Or most common answer, right? It yeah. Yeah. There's a lot that we need to learn. For sure. Well, you ready to get back out there and do some learning? I guess. Let's leave our comfy little booth. back to work. All right. Thank you very much. Appreciate it. Thanks.
Sean McMillan: Thanks again to Craig for joining me. That was a lot of fun. And thanks to Kendrick, Dylan, and John for another great discussion. If you enjoyed
John Untz: Always a good time.
Sean McMillan: this episode, we'd really appreciate it if you share it with a friend or coworker. It helps more people discover the show and helps us keep having conversations like these. And if you'd like to keep the conversation going, by all means, come visit the Bishop Fox community, we are active on Reddit, r/bishopfox Discord, discord/ what do you think? bishopfox and we we talk about what we talk about on the show, share research, share tools, workshops, that kind of stuff. and if you like today's conversation with Craig, be sure to check out the rest of our Block Out the Noise series on the Bishop Fox YouTube channel. We've got conversations with researchers, CISOs, students, and more. And plenty more still to come. You'll find links to all that, along with everything we discussed today, in the show notes. Thanks for listening. Stay safe. Catch you next week.
John Untz: Hello?
Dillon Sparks: to be here.
Sean McMillan: Now before we jump into the headlines, let's take a quick look at some things happening around here at Bishop Fox. We recently wrapped up our black hat and DEF CON coverage, and over the coming weeks, we will be sharing more and more of those conversations we recorded from the show floor. We've already started releasing this on socials. You may have seen some clips, but as we record, today we're featuring one of those interviews in the podcast and it's going live on YouTube. If you enjoy it. smash that like and subscribe, I guess. we also published two new pieces of technical research this week. Jon Williams and our threat enablement analysis team take a closer look at CVE-2026-8452, which is a memory corruption bug in Citrix Netscaler's SAML handling. and they built a safe way to verify whether a virtual server is actually patched without. Causing it to crash or disrupting any live sessions. And Jon Ronan Kervella and the team also broke down two critical flaws in Veeam service provider console that chained together into unauthenticated RCE. They reproduced the chain end-to-end, confirmed the fix, and published a safe detection tool for defenders. You'll find links to that research, the tools, and our black hat interviews in the show notes. Now Let's let's get dirty. Let's talk about this from TechSpot. AliExpress was silently running audio in your browser to fingerprint and track your device. this was a developer troubleshooting a Bluetooth headphone issue that ended up uncovering something pretty weird on AliExpress. The site was running audio processing in the browser, not playing any sound, but it was fingerprinting. the device. So basically it was using tiny differences in how a machine handles audio to identify the user without relying on cookies. when you first hear this issue, I guess what jumps out to you guys?
John Untz: I mean I my first thing is like, cool, another thing that we're being used or we're using to to track people, you know, anonymously.
Sean McMillan: Mm-hmm.
John Untz: something that I think I like immediately keyed in on was the fact that we don't really have tooling built to handle from a user's perspective, right? We we we think in storage for like cookie storage and stuff like that. Like those are the things
Sean McMillan: Yeah.
John Untz: we consider when we consider user privacy or like what are the things that are being stored on my machine. Last I checked, as far as I'm aware, we don't really do a whole lot of like live heuristics kind of, you know, what what is currently being processed in the browser. and I think as we've moved further and further into the like as as we've matured I don't even think mature, just just evolved what what the web looks like. You know, similar to how like exploit dev worked, right? Exploit dev moved from being like land something, you know, land a file on a computer and it starts up at whatever time and you know, that's that's an exploit, right? we've moved more on that front into like stuff that resides only in memory. And so it kinda makes sense that like this is the kind of the same logic of, you know, we're gonna you know, a company that is trying to track customers is gonna do these things that exist only in that that are only gonna exist on at memory. They're not gonna be stored somewhere.
Kendrick: I I do find
Sean McMillan: Yeah.
Kendrick: it annoying that they're tying up my audio lanes though by by having a thread thread going. So I'm not not too excited about that one.
Sean McMillan: Yeah. Don't mess with my audio.
John Untz: Yeah.
Kendrick: No.
Dillon Sparks: Yeah, I think it's a, an interesting angle and something that we touch on a lot here, is inherited or assumed trust, right? And it's like, all of these consumers, there is this level of, you know, like assumed trust that this site that you're visiting is doing their due diligence. And, know, they're not collecting additional data that they don't need, which I mean, we all as American consumers know that, you know, we are the prize, when we walk in anywhere. So.
Sean McMillan: Yeah.
Dillon Sparks: yeah, it's, it's just kind of, I understand it as a technique and like a practicality. but there also has to be this point where we as technical professionals, like understand that regular consumers are not going to have the wherewithal to like know how to detect or opt out of this sort of collection method. Right. And so it's like, where's that line and where is the responsibility?
Sean McMillan: Yeah. No, this was this was found kind of accidentally, right? This was not no one thought anything like this was happening. It was, if I remember correctly, something about plugging in headphones and unplugging it that kind of triggered a WTF moment.
Kendrick: Yeah. It was the transferring of PC to phone audio is how they discovered it and that it w it wasn't happening.
Sean McMillan: yeah, that's right.
Kendrick: So because
Dillon Sparks: Yeah.
Kendrick: it wasn't happening, they're like, why isn't this happening? And that's where it's like, there's still this active audio connection out there that's not disconnecting. yeah.
Sean McMillan: Mm-hmm.
Kendrick: It's that's why I'm more annoyed about that because I'm I'm pretty sure I've had this issue before and this was the this was the reason for it. Not Alibaba but or AliExpress.
John Untz: right. Yeah,
Kendrick: But like
John Untz: I think that's also
Dillon Sparks: Yeah.
John Untz: worth mentioning, right? Like Alibaba got caught, but like that doesn't mean that they're the first or only ones that have been utilizing the same technique. 'cause I'd like you like you said, like I know I've had that exact same issue before where I've tried to like switch to my headphones or something like that and you know, either either a Windows driver or like whatever, like just holds the connection essentially.
Sean McMillan: Mm-hmm.
John Untz: So I don't know, like, yeah, that's I think that's worth a deeper dive for sure of like figuring out like okay who else has been doing this? Because like at least in my case, like I you know, I I'm I'm like a little more privacy focused, so like I I I'm not using like Google Chrome, for example, right? I'm using a different browser and I've got you know I've got Well who knew who knew an advertisement company would be collecting data, right?
Sean McMillan: Wait, Chrome collects data?
Kendrick: No, no, no, no. It's fine. It's fine.
Dillon Sparks: Noooo
Sean McMillan: Right, right.
John Untz: but like I you know, and even when I was using Chrome, like I still had like, you know, blockers and stuff like that to to that that would have mitigated stuff like this.
Sean McMillan: Yeah.
John Untz: 'cause I think I think it was was it Brave browser was the first one to come out and just be like, Yep, we've known about this and we've been blocking it for however long
Sean McMillan: Mm-hmm.
John Untz: and it's like okay, well like that's like one example but there's other browsers obviously and there's other mechanisms to block these scripts.
Kendrick: This was part of their anti-fraud though, like scripting. Like in in theory, yeah. So
Sean McMillan: That's what I was gonna say. That's the that's the the explanation.
Dillon Sparks: Yeah. Yeah.
Kendrick: I I just I just don't know like the technical reason of why this is the main avenue. This like or th this is the avenue you chose to go down for like fingerprinting a user's, like whatever. I mean, maybe I gu I've never built a fingerprint through like every web browser, so maybe this is like the easiest one that all of them have. therefore this is like the utility that you can use most generically across all web browsers.
John Untz: Mm-hmm.
Kendrick: I don't know. It
Sean McMillan: Mm-hmm.
Kendrick: could it could just be one of those things where it was the easiest path because all the other paths aren't universal in nature.
John Untz: My I I I you know, I didn't look at like as every facet of like how you can fingerprint via like browsers, but I have I I assumed this was just like one approach in a multi layered approach that they're taking where it's like, yeah, this is the one that we just happen to stumble over and it's weird, right? It's not something that we're we're used to seeing. You know, but they are
Sean McMillan: Mm-hmm.
John Untz: still doing like everything else, right? They are still doing, you know, c cookie inspection and and and all of the things that we're already used to like looking for from a privacy perspective.
Sean McMillan: Yeah, I think we
Kendrick: And important.
Sean McMillan: all just kind of well, not maybe not all of us, John, but
John Untz: Yeah.
Sean McMillan: I think a lot of us just kind of like accepted the cookie thing. We just have taken the lumps and said, you know what? Sure, they're tracking us. But I feel like I feel like this kind of crosses a line from any kind of fraud prevention or convenience that cookies can offer. I mean, it just it just feels like.
Kendrick: But at least it's not your mic
Sean McMillan: Obvious tracking.
Kendrick: it's not your microphone though. So I we call this a win.
John Untz: Right. Yeah, I mean that's fair. I mean it could have been in the other direction. Yeah,
Sean McMillan: Yeah, yeah, that's true.
Dillon Sparks: Yeah, yeah.
John Untz: I didn't I didn't even consider that. What if they were turning on your microphone? I mean that's you know I'm sure they would l love
Kendrick: That's level.
John Untz: to, but
Sean McMillan: I have a physical mute button on my control panel here that I leave on almost all day so that no one hears me burp on a Teams call. And I
John Untz: Yep.
Sean McMillan: think it might have saved me something.
John Untz: Yeah, right.
Sean McMillan: okay. So we also have another another one from Bleeping Computer this time. US warns of AI-powered attacks on Siemens PLCs in critical infrastructure. They put out a joint advisory this week warning that attackers are using AI-generated scripts against internet exposed Siemens S7 PLCs. The targeting itself is pretty basic. It's scan for exposed devices, weak credentials, default configs. the difference here is how much expertise you need to find one. AI is quite famously in cybersecurity. Eliminating that floor. so is is this is this any different than AI just generally lowering the the the barrier in any meaningful way?
John Untz: No, not in any way. Like I that's least I like that's my take is like you're not gonna this isn't like increased how many PLCs are out there exposed to the internet. Right, all this has done is lowered the bar as far as how easy it is to talk to those protocols. Right. A lot of those are gonna be like custom binary protocols or something like that that you have to do,
Sean McMillan: Mm-hmm.
John Untz: you know, previously a lot of manual time reverse engineering, and now you can just throw AI at that part of the problem and say, Hey, figure out how to talk to this specific device or talk to this service, which is exactly what AI is being used on like other sides of reverse engineering. It's literally that same piece of the puzzle that is
Kendrick: AI is
Sean McMillan: Yeah.
Kendrick: really good at talking to things. It will get it wrong
John Untz: Yeah, yeah.
Kendrick: 90% of the time, but it'll keep on trying to talk to it.
John Untz: Right.
Sean McMillan: Is it as patronizing to these PLCs as it is to me? Is like, is that why it's just such a smooth talker?
Kendrick: I'm sure, I'm sure. Yeah.
John Untz: Probably worse.
Dillon Sparks: It's really interesting as on the T team, as we kind of look through these CVEs that come out daily and we're reviewing things. It's so interesting to see how many CVEs now. Clearly we're like AI generated in this perfect like ecosystem where they're like, yeah, it's totally mass exploitable. There's this very specific bug that does this thing. And then you like, read through the actual blog post about it, and then at the bottom, it's like, performed in a vacuum under perfect conditions with all default configurations that normally cancel out all of these features. And you're like, great. So all I have to do is turn off all of the safety features. And now it's exploitable. And it's kind of the same
Sean McMillan: Mm-hmm. Yeah, who'd a thumb.
Dillon Sparks: thing here. it's like PLCs that are running
Sean McMillan: Okay.
Dillon Sparks: outdated tech exposed to the internet are at risk. Wow.
Sean McMillan: Yeah. So
Kendrick: Yep.
John Untz: Who knew?
Sean McMillan: do we think
Dillon Sparks: Yeah.
Sean McMillan: that's a big problem though? Like is that like this is a news story. This is this an well, obviously it's a big problem, but
Kendrick: Yes, it
John Untz: Yes.
Dillon Sparks: Yeah, it's an issue.
Sean McMillan: I mean like how wide is that is that widespread or it's like literally every time it happens we're seeing it in a news story. Do you think that's something more people need to worry about or or just they've all been burned?
Kendrick: It so think about it on a global scale, yes. I would say, you know, not not saying the US is better in this regard, but they tend to have a little bit better regulations on, you know, safeguards to some degree, like a
Sean McMillan: Mm-hmm.
Kendrick: little bit more hardened, but still you can still find stuff all over the globe that is is vulnerable or outdated or somebody forgot to plug in the the USB drive to that one machine one time and now it's twenty versions, twenty years of old software but it's still talking on the internet, so it It it's it's a global problem, not it's
Sean McMillan: Yeah.
Kendrick: it's gonna be a problem
John Untz: Yeah.
Kendrick: forever.
John Untz: Yeah, and I think like, you know, to your point, right? US does better. Like I you know, we can all sit here and say that like, you know, whatever power plant like whatever's in the news with this one, right? It's always yeah, a water treatment facility, a power plant, like anything that's being
Sean McMillan: Mm-hmm.
John Untz: run on these devices, certainly everybody can do better. US is certainly doing better than most. but you're gonna see, you know, we're we're we're definitely gonna get hit more frequently now because of the accessibility factor. But I think like to like the specific question of like the the ease by which this is being accomplished, or or the the the risk of, you know, un no not or default creds and and and whatnot, you gotta think right, like this is not typically like a power plant isn't being set up by a cybersecurity firm, it's being set up by power plant engineers. It's a diff you right, like the mindset that the trade is totally different. And so for for them it's like these are these are facilities that are d running services. Those services have to just come up and be up and like I think for decades, you know, at this point, the the mindset has not been security because the uptime is the is the is the entire
Sean McMillan: Mm-hmm.
John Untz: call, right? Just make sure this thing functions. And Yeah, yeah, like honestly.
Sean McMillan: Duct tape it if you have to, but keep it keep it online. Yeah.
Dillon Sparks: Yeah, keep the lights on.
John Untz: Right. Keep the lights on. Exactly. and so yeah, I think, you know I I I hope this like will definitely like trend more towards the security side of things of like well we keep the lights on a lot more of the time if we change the password, for example. but I think Right, make sure you even have one, yeah. Yeah. Right.
Sean McMillan: Mm-hmm.
Kendrick: having a password and like making sure you have one on the device, yes, yeah.
Sean McMillan: Right, yeah, yeah. USA
Dillon Sparks: Yeah, yeah.
Sean McMillan: one two three.
John Untz: Yeah. But
Dillon Sparks: That's right.
John Untz: like, you know, w I think this wasn't a problem that we encountered that much before because we didn't know how to talk to the p to like like the the average, you know, script kitty hacker didn't know how to talk to whatever Siemens PLC, right? Didn't even know how to look for it. And so
Sean McMillan: Yeah.
John Untz: like that's like I said before, that's the that's the factor that AI is is enabling here.
Sean McMillan: Now this also this advisory comes very shortly after Iranian linked actors were suspected in disruption of all those Minnesota water utilities. Does that change your perception of this story or how seriously you read something like this?
Dillon Sparks: I think... I think... What it highlights is something that always happens whenever there's global conflict, right?
John Untz: Mm-hmm.
Dillon Sparks: Cyber attacks related to global conflicts, whether armed conflicts or political through sanctions, et cetera, there always seems to be some sort of infrastructure related fallout between
Sean McMillan: Mm-hmm.
Dillon Sparks: the host nations of that conflict. That's not new. What I will say though is, as AI lowers the barrier to entry and increases accessibility. I do think you're going to start to see a few more nation states out there using AI to kind of get a seat at the table and leverage that now. Whereas like they may not have had those capabilities years prior. And so it was a little easier to, you know, not have to negotiate with them, so to speak, over any issues. So I think again, I think it's just kind of lowering the barrier to entry. So we might start to see a shift in some of the global socioeconomic
John Untz: Mm-hmm.
Dillon Sparks: powers.
Sean McMillan: Yeah. Yeah. well, let's let's talk about this zombie card attack. We should I feel like every Halloween there's some kind of zombie themed or ghost themed story or something. We should maybe hold this till then, but no. Hacker News, zombie card can zombie card attack can revive expired Visa cards for contactless payment. So this is researchers at UMass Amherst. That found a way to make an expired Visa card work again for contactless payments without cracking any cryptology or anything. They just changed the expiration date. my first question is how?
Kendrick: It well, first off, this is a very so d we just talked about very ideal conditions. This is
John Untz: Yeah.
Kendrick: one of those exploits that is very ideal conditions for this to happen.
Sean McMillan: Yeah.
Kendrick: It was one specific kernel or one specific card running this kernel three, whatever that is in in Visa land, It's just like, okay, yes, it is possible on this particular card to do it. It did it's not a huge exploit out there, but yes, it it's it's possible on this one. So it was changing the date because it wasn't part of the cryptographically signed sections that were being transmitted. So
Sean McMillan: Yeah.
Kendrick: all they had to do was say it wasn't expired and poof, now it's not expired, it gets accepted at the tr the terminal and we're off to the purchasing whatever they were trying to purchase.
Sean McMillan: So that old idea of your expired Visa card, cut it up into a million pieces and scatter it across an entire continent still still holds true.
Kendrick: far but I yeah, I I still I still personally shred
Sean McMillan: That's what I've always done.
Kendrick: all my cards when they expire, so technically I think you're supposed to mail them back. They or they want you to mail them back. They give you that nice little envelope. Yeah, yeah, yeah.
Sean McMillan: do they really? I used to
John Untz: I didn't know that.
Sean McMillan: work at a bank and I don't know that.
Dillon Sparks: No shot. No shot, brother.
John Untz: There's no way.
Kendrick: Yeah. Yeah yeah. They give you a little envelope to mail them back if you have like the metal cards. If the metal ones. 'Cause
John Untz: I definitely did do that. I I definitely like did like some some surgery on my my metal my when I had the whatever the Amex card was.
Kendrick: Yeah. Yeah. They give you
Sean McMillan: Huh.
Kendrick: like a little nice little envelope sometimes to send them back. Because you're because I think they th think you can't shred them, so they're like,
John Untz: Right.
Kendrick: you know, how do you dispose of this? Send it, you can you know, here's this envelope to send it back to us.
Dillon Sparks: I just melt
Sean McMillan: That's fascinating.
Dillon Sparks: my Amex down to make musket balls. Like a good patriot.
Kendrick: Ha ha I see, I see.
Sean McMillan: It's not defacing money, it's defacing credit. Fantastic.
John Untz: Right, yeah.
Dillon Sparks: That's right. It's different.
Sean McMillan: so this is if I'm understanding this correctly, the expiration date that the terminal reads isn't bound to data that the terminal verifies. So it sees a date that just kind of this is again assumed trust from a terminal here. do you see this as just like this is one little thing that needs to be switched, or is there like a bigger kind of systemic thing for this? I mean, you you mentioned it's only one type of card, but I mean, hey, if I have that card, I don't care how many types of cards, you know, if I'm the one that that gets burned.
Kendrick: True. yeah. I I I mean it is a so in theory it shouldn't be. Like everything that everything that should go through the the point of sale terminal should be verifiable. because that's the whole point of it. That's why we in the US at least we're we're pretty late adopters to the the chip in the card
John Untz: Right.
Kendrick: process. that that's essentially why we moved from the mag strip to the chip so that we can make sure that things are cryptographically signed and that everything in
Sean McMillan: Mm-hmm.
Kendrick: theory sent between the point of sale and the card is verified, so that then it they can trust that you actually are the owner of that card to like do the transaction well not the owner of the card, but like that card it says it's the owner of that card at least, hopefully, and then you can make your your purchase. So it's it's a very trust oriented thing. we're still we're still living in a society where it's still up to the point of sales person to verify that you're doing not doing anything shady while you're standing there at the point of sales terminal.
Sean McMillan: Yeah.
Kendrick: 'cause 'cause we're not that far from, you know Caching bad checks at these
John Untz: Mm-hmm.
Kendrick: places. it's really just we develop technology to mitigate that risk as much as possible, and there's still workarounds up out there probably for these. We've seen point of sales terminals be hacked in steal cred steal credit card information. I'm sure they could probably j just fake a sale and all that fun stuff related to the point of sale terminal. So
Sean McMillan: Yeah.
Kendrick: we we we've gone a long ways, but I'm sure we'll still find stuff in the future about point of sales issues.
Sean McMillan: I think this was tested at three US banks, right? yeah, three major US banks at real world retail and grocery terminals. and one bank approved it, the others all denied it. So it's like it's not maybe necessarily as widespread. Does this feel like just kind of like an academic, hey, isn't this kind of neat or more
Kendrick: It reminds me of a
Sean McMillan: problematic than that.
Kendrick: story many years ago with a Visa card. They I don't remember the exact details, but they were able to clone your card.
John Untz: Mm-hmm.
Kendrick: And it w it it looked really suspicious what they were doing, but like, you know, in a real world scenario, they had a a fake card where they could inject into the chip of the card the information that they were able to, you know, swipe as from you as you walked by. So this kind of reminds me of the we're kind of in the same little little nuanced I mean it's a great marketing thing. I think they sold a lot of those RF reader blockers. so I
Sean McMillan: Right, yeah. my goodness.
Dillon Sparks: Yeah
Kendrick: I'm sure that industry is booming and would love more stories about RF attacks, but yeah. See, yeah, RF, yeah.
Sean McMillan: It's still yeah, it's still huge. Still huge. I see yeah, there we go. Dylan, our own Dylan has one.
Dillon Sparks: That's right, baby.
Sean McMillan: Why not? You know, why not? Why not block it?
Kendrick: Yeah. Yeah. It's just it's just another one of those things where it's it's on paper academically possible, but it's definitely one of those things where you try it out in the real world and there's major consequences if you get caught, so
Sean McMillan: Yeah. And I
John Untz: Yeah. Not just leaving not just being
Sean McMillan: mean, it does it does kind of feel like one of those things like the scare of well like we talked about recently with the DEF CON plane situation with public Wi-Fi and like suddenly one thing happens and the general public were like, Are they is everyone gonna be afraid of Wi-Fi again? And now is everyone afraid of people walking by and scanning my back pocket and stealing? My visa card now. doesn't seem i it's it's it's a a level of risk appetite, I guess, that
John Untz: Yeah. I mean the
Sean McMillan: Check with Visa if you've got one of these cards, check with Visa.
John Untz: Yeah. Well like Kendrick, like you were saying, this is like such a the number of steps required, like the feasibility of somebody standing in a Walmart and like going through all of the proper steps to like get this to work is not feasible. Like it's not
Sean McMillan: Yeah.
John Untz: like you said, not real world applicable.
Kendrick: You could you can maybe do it this once or twice, but like they're gonna look at the security camera video when like they come back to investigate and they're gonna be like, That guy Like
John Untz: Ha ha ha.
Dillon Sparks: Yeah.
Sean McMillan: The the type of characters I have at my Walmart. Yeah, yeah. It'd be pretty
John Untz: Ha ha.
Sean McMillan: quick to find the guy that's capable of doing this. well, we've spent the episode looking at specific attacks and techniques. But one thing they all have in common is that they expose assumptions organizations were not aware they were making. While I was at Black Hat, I had the chance to sit down with Craig Faulkner. Field CTO at InfoLock and we started by talking about all the AI noise surrounding the conference and then kind of got into something a little more nuanced, why AI is forcing organizations to finally understand their own data. Something he feels very strongly about. Here's that conversation.
Anna Vanderberg: First thing we like to ask people is just what is your role? Tell us a little about yourself and what brings you to Black Hat. Yeah, so I'm the field CTO at InfoLock. Info Lock is a data risk management advisory firm. So we do manage DLP, manage DSPM, data classification, all the things around data security. what brought me to Black Hat is to meet with everyone, see old colleagues, see new colleagues, right? Meet with partners. and just experience what BlackAph has to offer, right? So Yeah. As you no doubt have noticed, there is plenty of actual like literal noise happening out there. Yes. And then when we leave the convention, there is still noise in the industry from your perspective. What's the noise that everyone's kind of losing sight of the the picture? What's what's everyone yammering about? Yeah, everyone's yammering about AI. I'm sure that's when everybody's But I'm gonna spin that a little bit, right? Sure. So the reason why it's hot and I care about it so much is because we look at it from a different perspective. We look at it from what is your data, what is the context of that data, leveraging DLP and DSPM tools to understand what that data is and how it ties back to the business. So we want to understand the context of the data. AI has just made more data and it's made people care about that data now. And so now we're really evangelizing, hey, all of this data that you're using, creating, curating. We need to secure it and put guardrails in place. So that way it is used effectively, it's secure, you're not getting rid of your crown jewels, things like that. So for us it's all about the data within AI, not so much the agents or hype or anything like that. So that's definitely hot for us right now. And I'm I mean you y you see so many boots just from here you can see like a hundred that have AI in their title. Yeah. It's it's really kind of everywhere. Yeah. Now it's just like like We're an AI company. Every company's an AI company. So how has that kind of changed your perspective? How has that been a challenge for what you do? Yeah, I think honestly, I I don't know if it's been as much of a challenge as it's been an opportunity for me to learn and grow. Right. So the ability to I do a lot of thought leadership and blogs and podcasts and things like that and going and finding some of those things, finding events, things like that, it took a lot of man hours. I don't have to use those man hours anymore. We have AI that can go and curate the internet and find those things for us. Yeah. be able to, you know, find what's relevant to what I need to speak on and go and find those events and things like that. So I actually have really enjoyed the productivity game that I've gotten out of using AI. Now, on the flip side of that, my family is also using AI. Right? So there's a scary aspect of it too of you know The layman, if you will, is using a technology they literally know nothing about. So it's magic. It's a genie in a bottle. Absolutely. Yeah. My kids don't touch it. Yeah, they know about it. They don't touch it. I I dabble, you know. Yeah. My wife dabbles, but then you up the risk and we look at other generations dabbling in it. And I think that that's a a a place where they don't have those same kind of data concerns that A a big organization that would seek out your services would. and I think that's that's the new world. Interesting point though, we saw I don't know, 10, 15 years ago with ransomware them shifting to extortion and then doing all these other tactics, and it went from personal, like people, to businesses. Now we've seen it kind of go back to individuals again. Yeah. Is that what's gonna happen with AI? This is what I'm saying? Yeah. I I kind of see it already. Yeah. I see it in in not just in the cybersecurity industry, but friends of mine that are in totally other job roles. And I see their bosses implementing AI. And they're not they're not checking all the boxes. They're just like, hey, what if, you know, now we can do this. So let's do it. And so I think that's probably like a a big wake-up call for a lot of organizations to see that. Holy smokes. We need something like like what you're doing because plausible deniability is gone. It is. Right? Like, with all the tools we've seen come out because of AI, the visibility and exposure of data now within an organization, AI doesn't know where to go look for information. It just looks at all of it. Well that completely eliminates our legacy rollback role based access to controls that we've implemented in every technology from the beginning of time. Because AI goes around all of those controls and looks at everything, right? So it's a very interesting dynamic we're in now of of what's gonna happen and where it's gonna go forward. Well everyone's so focused on implementing AI and all that stuff. So if that's clearly got some noise to it, what where's the signal? What what do people need to be getting right? I think first and foremost, you gotta understand where your data is. Like in order to have a successful AI strategy. And have your employees and your business partners, third parties using these tool sets. Yeah. You've got to understand where that data is, right? There's many stories out right now of third parties getting breached and impacting the original company's data, the partner's data. You know, we're seeing things in healthcare where they're using AI for modeling and things like that. I actually have a friend that her husband recently had surgery and They modeled what they were gonna go do surgery on and actually only modeled fifty percent of what they needed to do surgery on. And actually it was a more intense surgery once they got in. Yeah. Because they relied on AI to model what it was that they were doing and they missed the connection with the MRI to the AI model. There was something there that becomes the I I feel like every conversation comes back to implementing AI, monitoring it. Yes. Implement it smartly and and keep an eye on that AI. Yeah, for sure. Yeah. Set it and forget it is not something we can do in the realm of AI. Yeah. And I think we've gotten really comfortable as an industry on set it and forget it. Mm-hmm. So we've got to get back into that mentality of really just back to the basics of good security hygiene, good IT hygiene, understanding what our business is doing, all of that. Yeah, absolutely. That's that's that's the key. Well I think We often ask like what the signal is, what the noise is and it it all does kind of tie back together, I think. Often when I ask what's the signal, it's like well they they kind of just said it, you know? Yeah, exactly. Well and it's interesting too that signal it's we've been concerned about threat for a long time. Then we started kinda being concerned about identity and now AI is merging both of those concerns at the same time because they are it's a potential threat, but it's also an identity that it is. So I've changed my talk track to talking about entities. It's not about humans anymore. It's not about workers. It's not about process. It's about entities. Cause there's so many entities now that can interact with a business, both human and non-human. So Yeah, I think it's key knowing where your data is, how it works, and not just asking Chat GPT how you can implement AI, because I know you know there are people who do that. And you're gonna get a wonky answer. Yes. Or what it thinks is the right answer. Yeah. Right. Or most common answer, right? It yeah. Yeah. There's a lot that we need to learn. For sure. Well, you ready to get back out there and do some learning? I guess. Let's leave our comfy little booth. back to work. All right. Thank you very much. Appreciate it. Thanks.
Sean McMillan: Thanks again to Craig for joining me. That was a lot of fun. And thanks to Kendrick, Dylan, and John for another great discussion. If you enjoyed
John Untz: Always a good time.
Sean McMillan: this episode, we'd really appreciate it if you share it with a friend or coworker. It helps more people discover the show and helps us keep having conversations like these. And if you'd like to keep the conversation going, by all means, come visit the Bishop Fox community, we are active on Reddit, r/bishopfox Discord, discord/ what do you think? bishopfox and we we talk about what we talk about on the show, share research, share tools, workshops, that kind of stuff. and if you like today's conversation with Craig, be sure to check out the rest of our Block Out the Noise series on the Bishop Fox YouTube channel. We've got conversations with researchers, CISOs, students, and more. And plenty more still to come. You'll find links to all that, along with everything we discussed today, in the show notes. Thanks for listening. Stay safe. Catch you next week.