The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Defensive Security Podcast
Defensive Security Podcast artwork

Defensive Security Podcast Episode 351

Defensive Security Podcast · 2026-06-27 · 1h 11m

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber7 / 20
Specificity & Evidence7 / 20
Conversational Craft7 / 20

This episode covers three major security stories affecting enterprise defenders. The first examines a ransomware actor's novel hybrid approach combining social engineering with physical intrusion - calling victims pretending to be IT support, scheduling on-site visits, and delivering USB sticks that either install malware or exfiltrate files via living-off-the-land techniques. The group also escalates through text messages to executives and family members, and in extreme cases uses swatting to pressure negotiation. The second story analyzes a Hacker News report on AI adoption in security operations centers, where only 10% of SOC leaders report excellent value from AI tools. Jerry and Andrew discuss the irony that while companies are heavily investing in AI, they're simultaneously cutting experienced security personnel, creating a moral hazard. They also highlight that point-solution AI implementations across disparate tools (SIEM, EDR, vulnerability scanners) create islands of intelligence rather than coordinated defense. The final segment begins discussing the Dashlane password manager breach where attackers successfully downloaded encrypted vaults - a significant incident affecting users who migrated from LastPass after its high-profile compromise.

Key takeaways

  • →Ransomware actors are combining digital attacks with physical intrusions, social engineering, and real-world harassment including swatting to pressure victims into payment negotiations.
  • →Only 10% of SOC leaders report excellent value from AI investments, while companies simultaneously cut security headcount, creating unsustainable operational models.
  • →AI tools are being deployed as point solutions across security infrastructure without inter-operability or coordination, requiring manual integration work that already-overloaded SOCs lack capacity to perform.
  • →Vendors are consolidating features into single platforms that are 'just good enough' for adjacent capabilities rather than best-of-breed, degrading overall security effectiveness.
  • →Companies are making aggressive AI adoption decisions driven by FOMO and board-level pressure without clear evidence the technology delivers promised value.

In this episode

  1. 1Ransomware Actor Uses Physical Visits and Social Engineering
  2. 2Shiny Hunters Extortion Tactics and Real-World Harassment
  3. 3AI Value in Security Operations and Tool Integration Challenges
  4. 4Concerns About AI Adoption Without Proven ROI
  5. 5Dashlane Password Vault Breach Explanation

Mentioned

Jerry BellAndrew KellettShiny HuntersThe RegisterHacker NewsArs TechnicaDashlaneLastPassCrowdStrikePalo AltoWindowsDropbox

Guests

Andrew Kellett

Topics in this episode

Shiny HuntersRansomware extortionPhysical intrusion attacksSwattingUSB-based malware deploymentLiving-off-the-land techniquesSOC AI adoptionVulnerability scanner AISIEM AI componentsEDR AI components

Questions this episode answers

How are attackers using physical visits in ransomware attacks?

Attackers call victims impersonating IT support, schedule appointments, then show up at offices with USB sticks to either install malware directly or copy files - this hybrid approach combines social engineering rapport-building with physical access to bypass digital controls.

What tactics do threat actors use to pressure ransom payment beyond email extortion?

Actors send threatening text messages and calls to executives and family members, conduct harassment campaigns, and in extreme cases execute swatting attacks (spoofing emergency calls to trigger SWAT deployment) to force victims into negotiation.

Why are SOC leaders struggling to get value from AI tools?

AI implementations are deployed as isolated point solutions across disparate tools (SIEM, EDR, scanners) that don't integrate or share intelligence, and overworked SOCs lack bandwidth and personnel to properly tune and configure them for their environments.

What is the core problem with vendor consolidation strategies in security?

Vendors leverage strong core capabilities to pressure executives toward single-vendor solutions that provide adjacent features that are 'just good enough' but significantly worse than specialized point solutions, while claiming easier integration that rarely materializes.

What long-term risks exist with replacing security staff with AI tools?

Companies are cutting experienced personnel to fund AI investments that haven't proven they work as claimed, and when those senior people age out or leave, organizations lose institutional knowledge needed to operate and adapt security infrastructure.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode surfaces a few genuinely useful observations - physical hybrid ransomware attacks, the business-logic enforcement gap between AI agents and business systems, and the downstream talent pipeline problem - but these are interspersed with extended banter, repetitive AI-skepticism platitudes, and lengthy summaries of articles that add little beyond the articles themselves.

those entry level people are tomorrow's senior people. And uh, maybe we get to a point where the whole, you know, the whole stack is completely AI enabled
there's a missing piece here that sits between the AI agent and the business system that needs to enforce some sort of business logic

Originality

8 / 20

There are a handful of non-obvious framings - treating chatbot social engineering as a form of fuzzing, and arguing LLMs are constrained precisely because security is a creative craft - but the dominant themes (AI is unproven, basics still matter, vendors oversell interoperability) are standard-issue security-podcast commentary recycled without fresh evidence or first-principles reasoning.

it's almost like they're doing fuzzing on the inputs via human language and seeing how it reacts
it does great at things that are known. It's really great at research. It's really great at doing things that are, uh, well established. It is not very good at all at being creative

Guest Caliber

7 / 20

Both hosts have genuine long-tenure senior practitioner backgrounds - including executive-level experience at large enterprises - and their observations reflect real operational experience, but there are no external guests and neither host is a particularly distinguished or widely cited figure in the field.

Having. Having been at the executive level in a very large company, there is a game theory element here
I've been around for a long time, I mean, a very long time, and we can't make like, the basic tools talk together

Specificity & Evidence

7 / 20

The episode references some concrete specifics - Argon2 hashing, 10% SOC satisfaction figure, 20 compromised Dashlane accounts, named actors like Shiny Hunters and Drive Surge, and named tools like Crowdstrike and Palo Alto - but nearly all of it is thin relay of published articles rather than first-hand data, named dollar figures, or proprietary operational metrics.

they got lucky 20 times, uh, before, before they got caught
Dashlane makes this process difficult by using algorithm, uh, known as Argon 2, which makes it much, much harder

Conversational Craft

7 / 20

The hosts have easy, natural rapport and occasionally build well on each other's points, but the format is almost entirely mutually reinforcing - rarely challenging a claim, pushing for precision, or introducing productive friction - resulting in a conversational tone that is pleasant but not intellectually rigorous.

Well said, well said.
Yeah, I think you're right.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B64%
  • Speaker A36%

Most-used words

password24point21security20interesting19problem17tools15different13doesn12saying12whole12technology12money11back11email10article10trying10

Episode notes

Please consider supporting the DefSec podcast here . Links to this week's stories:

Full transcript

1h 11m

Transcribed and scored by The B2B Podcast Index.

Speaker A: Sam.

Speaker B: Right. Well, welcome, um, to episode 351 of the Defensive Security podcast. My name is Jerry Bell, and joining me today, as always, is Mr. Andrew Kellett.

Speaker A: Good afternoon or evening, sir. How are you doing?

Speaker B: Awesome. How are you?

Speaker A: I'm, I'm good. I'm. I'm in week beginning week three of my sabbatical career break, whatever you want to call it. So. Did a little consulting last week. No, no, it doesn't. But, you know, I did a little consulting last week, which was nice. And, you know, I'm hoping to do some more of that. So. Yeah, it's good otherwise, you know, just try not to spend too much money because that paycheck thing doesn't exist at the moment.

Speaker B: But that's, that's the, uh, the complete BS part of unemployment is you finally have an opportunity to do stuff that requires spending money, but you don't have the money to spend on doing stuff.

Speaker A: Right. It's fine.

Speaker B: It's utter baloney anyway.

Speaker A: We just need, like, a wealthy billionaire patron.

Speaker B: Exactly.

Speaker A: That's what we need.

Speaker B: Right. All right, A, uh, quick thank you to our Patreon sponsors. Uh, do definitely appreciate your continued sponsorship. And, uh, we've got a couple of new people recently. Hopefully you are finding your money's worth in this. And by the way, for those of you considering would like to support a little enterprise here, you will get episodes a week before everybody else, which is pretty darn impressive indeed.

Speaker A: And hey, honestly, thank you for those who do choose to donate. Really do appreciate it. We don't take sponsors, we don't take ads. Uh, we're self funded. So this, this does really help cover the costs, and we really do appreciate it.

Speaker B: Thank you. And a quick reminder that the thing that the. Where was I going with that? The thoughts and opinions we express on the show are ours and not those of our employers. There you go. I got it out eventually.

Speaker A: It's all good.

Speaker B: All right, so moving into some stories. The first one comes from the register, and the title here is, if you don't fall for these extortionist calls, they'll show up with USB sticks. Kind of a new, uh, a new take on ransomware. Uh, this is, I guess, a fairly well known ransomware actor who has, I guess, developed some new tricks. Uh, what they're doing here is, uh, and I guess their MO Is like a very fast, you know, from, from the, the point of initial contact to the point that they actually demand the ransom is like sometimes a day. So it's, it's a Very fast operation. But they have some kind of novel takes on building rapport with their victims. And so like what they will often do is uh, send their victims a completely benign communication like uh, I guess invoices are the one that they, that they've historically done. They'll send an invoice that is like completely innocuous. It's not, it doesn't have any, you know, malware attached to it. It's, it's sole purpose is to establish contact with somebody at the victim company and give them uh, pretext for making contact, you know, with either further email contact or even a voice call. So uh, they're, they're pretty adept at building rapport in somewhat, you know, novel ways. And one of their, their new techniques is uh, pretending to be tech support which is becoming pretty, pretty common. But they're, their kind of novel take on this is that uh, they're calling and saying that they need to perform uh, you know, work on your computer. And um, you know, because they're, they're part of the help desk or the security team or what have you. Uh, and they'll call ahead, right and, and then they'll show up at your door with usb, uh stick, uh, that they'll, that they'll plug into a computer and it'll either install malware or they'll literally just copy files off and then leave and then you get the ransom. So pretty interesting kind of hybrid attack. I hadn't seen this before but it makes sense. It kind of reminds me of like the old dropboxes we would, you know, we all fretted about in years gone by.

Speaker A: Well it's certainly bold and it certainly is different than some sort of overseas Eastern Europe, China, Russia based threat actor just coming at you digitally only to have people actually show up physically. Uh, is, you know, we sort of, we've kind of gotten out of that mindset a little bit. Uh, not that it ever stopped being a real threat but we just don't talk about it much anymore. We don't talk about people just walking in and you know, know, posing as in this case tech support people. But you know the joke in the past is always you know, wear a UPS uniform, you can walk into any business with a box and get past the front line. So it is, it's interesting too that once they're in, I was reading in the article, you know, they, they'll use a lot of living off the land to transfer stuff out, whether it's copied to the USB drive or if that doesn't work if they've gotten in through uh, some other methodology where remotely they're using Windows components to copy files out. They've even been known to ask the victim to log into a file sharing account, uh, and send it to them. Right. Because the victim thinks they're dealing with standard IT support and they just instruct the victim to send the files out to their controlled Dropbox site or whatever it is. They don't talk about Dropbox. I'm not picking on Dropbox, but just as an example, uh, and it's, it is interesting. I. Another interesting thing that our good friend Bob, who we haven't heard from for a while, apparently he just got out of prison in Argentina. So, uh, good for him.

Speaker B: Good.

Speaker A: He has trouble staying out of trouble. But he was telling me one of the organizations he, he had worked with recently that Shiny Hunters, when they want to extort you, apparently what they'll do is not just send email to whatever email addresses they can find in the company. They'll start looking up any executive cell phone address and start sending them text messages that they should check their email and then emailing as many personal and, and, and business emails of all the leadership they can find in the company. And they go really broad, uh, which I thought was fascinating. Right. It's tough to ignore, tough to contain. In that case. Uh, the other thing that I was reading in an FBI alert that came out that one of the other things that Shiny Hunters or similar groups is doing, uh, is if you're not paying or you're not negotiating with them, they'll start harassing not just the individuals that they know about, but the family members of the individuals, uh, with threatening messages, threatening phone calls, threatening text messages, up to and including swatting people that they want to pressure into negotiating with them. So it's starting to take this stuff back into the real world and could very much cause real world personal harm, which is kind of scary.

Speaker B: That's, I mean it's all insidious. But that is, that takes it to a whole, whole other level.

Speaker A: For those, for those who don't know what swatting is, basically it's somebody faking, spoofing, ah, a phone number to the, of their victim and calling, or some other related number and calling the local police and reporting some incredibly dangerous situation taking place at the home of their target. So this used to happen a lot in video game communities and such. And then the SWAT team in theory will show up, uh, which can be a very dangerous situation for everybody involved. So, um, very frightening and sketchy. For and potentially life ending if not handled correctly. Uh, in that circumstance.

Speaker B: Yeah, there's been at least one that I know of. One person was, was killed in a swatting incident. So. Yeah, it's not, not a joke.

Speaker A: No. So uh, yeah, it's, it's. I mean again, going back to, to the article and talking about the, the on site stuff, I, I think this just goes back to. You need decent physical, physical controls, right? Verify that this person is who they say they are. Don't trust them until you've gone through some other verification mechanism that you know of and you control like reaching out to the head of IT in your company through some internal mechanism, not a mechanism this person provides for you or having the front desk people verify or something or you know, probably easy to double check, but we as humans don't like to be unhelpful and impolite and that's what they're using against us.

Speaker B: Yeah, they give, at the end of the article they give some recommendations which, which I think are hopefully pretty self explanatory, you know, like checking IDs and make, you know, making sure that people have an appointment and whatnot. But I would say one of the, one of the challenges with this actor's approach is that they, they may actually be able to get past that because of the way they're building rapport and it, I wouldn't be surprised for example if they actually set up a uh, schedule like set up a meeting. And, and so we're, we're an expected visitor. So like that's not necessarily a front guard against calls.

Speaker A: Right? The front desk calls against calls, their victims. So. Oh yeah, I'm expecting you know, Tracy from it. Sure, send her up.

Speaker B: Exactly. It's uh, it's interesting. The other, there was one other aspect that I thought was pretty interesting and it's, you know, given the work that I've been doing. We do a lot with uh, enclaves, cloud based enclaves where we contain data to um, a very tightly controlled environment that you can only access through VDI and you're not able to copy files in or out or anything like that. Uh, but this actor by the way is known for uh, even attacking those. Uh, what they've taken to doing is tricking victims into um, somehow through various means, compromising their personally owned computers that they use to access the corporate vdi, which is again often used for remote access or a variety of different things, and then then using that access that, that personally owned computer to uh, have their way through the VDI client So they might not be able to make a direct connection, but. But they're able to remotely control that VDI session and then, uh, you know, launch whatever they're trying to do from kind of the keyboard, video and mouse connection through the, through the vdi. So. Interesting stuff. They are, they're. They're pretty, um. Resourceful, I guess, is the word I'll use.

Speaker A: Yeah. Hey, there's money to be made. People find a way.

Speaker B: It's true. All right, our, uh, next story comes from the Hacker News, and the title here is 10%. Only 10% of socks say they're getting excellent value from AI. Here's what the second wave has to deliver. I, I really don't care too much about the second wave at this point because that's, well, not here yet. I thought it was interesting that, uh, the 10% number for a couple of reasons. One is we hear a lot of discussion about general IT projects and how. I think the last number I saw was about 5% of AI projects actually have, you know, have return or. And I don't know how that's calculated. Like, I don't know if that means that only 5% have met their business case or, you know, only 5% have actually worked at all. I, I don't have that, um, I don't have that insight. But so point. Point being, it's actually a little bit ahead of the rest of it if, if, you know, depending on how you're measuring things. So that was, I suppose, a bit interesting. Perhaps. The more, I guess, problematic thing for me was, uh, we have another story coming up in a little bit about this. The impact on talent. Right. So we are, you know, kind of wholesale starting to automate things. And this particular article talks about, you know, one of the big challenges we have today with the way the AI is kind of being infused into socks today is it's kind of on a, on a point system. By point system basis. It's like, you know, your, your vulnerability scanner has an AI component, your SIM has an AI component, your EDR has an AI component. And they're all kind of little islands and, you know, the, the next generation, what they're. What they're really calling the second wave is thinking about how all those things need to kind of cooperate. And I've been around for a long time, I mean, a very long time, and we can't make like, the basic tools talk together, uh, and work together.

Speaker A: We have tried a common API backbone between security tools over and over and over and over in my career and the vendors just can't play nice enough for it to work out and things just move too fast, it seems. Yeah, I'm trying to think of dozens of vendors who have tried this in the past or have signed agreements or have made coalitions that have fallen apart or just nobody else signed into to have this interoperability layer between security tools. Now of note with this particular article is it is a little bit of vendor fluff. It is coming from one particular vendor who has one particular solve to this problem. Right. So they are, you know, kind of writing the problem and the problem solve as the solution they think they have. So they're defining the problem as the problem they can solve, as it were. Uh, but I do think there's some interesting takeaways here regardless of that, because they're talking about a third party report and they're trying to draw conclusions of that third party report and then how their magic solution fixes it. But what I take away from this, from this third party report is, is we still have this mad rush to embrace this technology, AI technology, whether it's purposefully, whether it's built into existing tools, whether it's, and it hasn't really proven itself yet. There's, there's usually early adopters who will jump into some new technology and pave the way for others. We seem to. And then there's middle adopters and late adopters. As the technology gets proven out, we seem to have completely thrown that model out the window. And I have rarely seen a rush to a new unproven technology as intense as this and as universal as this. It feels, uh, without that, sort of like, hey, here's how early adopters sorted this out. Everyone just feels, uh, it feels like it's existential that they have to embrace this technology now and they don't know what to do with it yet. And I'm sure we'll start to figure it out. I'm not saying that it's bad technology, but we don't know what we're doing yet. And that's what I think is somewhat apparent in this article. The other thing I found interesting was that a lot of the people they interviewed, or at least they gathered information on, were willing to admit that they weren't seeing much value yet, which in a corporate environment that's actually, there's, there's a lot of pressure not to say that you usually have this pressure from, from executive leadership to, you know, your budget may be threatened if you admit that this was a bad purchase or something along those lines. There's you know, you don't want to show up with negatives. So normally you get this positive spin, but if you've got enough people admitting, hey, we have, we have these tools, we're being forced to use these tools, we don't know how to get value out of them yet. Could be that's a learning curve thing. Could be that's a refinement thing. And they talk about, hey, those who really build and get into it and tune it and understand it, do do better. But then again, at the same time, I'm looking at, okay, if you, if you've got people who are already running at 80, 90% capacity doing their sock job, who's got time to go build this new tool? Unless you purposely hire people to go do that, I don't know that's happening. They're just throwing tools at the soc and saying, here, this should make your life easier. Figure it out. And the sock's going, what, what do I do with it?

Speaker B: That's exactly my, that's, that is, that's exactly my concern with all of this is, is, you know, executive leadership has been enamored with IT tools. And security is certainly no exception there for a long time. And so in the current mode of operation, we are in a downturn from an investment, at least headcount standpoint in the security field. And so to some extent, buying these new tools are kind of throwing sandbags on top of your boat that's already taking on water. And at the same time you're cutting people who are responsible for bailing out the boat so that you can afford more sandbags. And uh, it's, you know, I think it's a kind of a moral hazard that we have going on here. And I think if I look at it kind of more holistically and take a step back, I think it's very naive to say that we're going to be able to automate things end to end in a way that is contemplated here. And I know this is kind of written from the perspective of a particular vendor. And look, uh, every vendor is going to be doing that. Um, like I said, I've been in this business for a very long time and so many companies have claim to have end to end security solutions. And the reality is like either, either they, they actually do and none of them are good, or they have one thing that is worthwhile and the rest of it's a bunch of crap that isn't going to change. Right. And so companies are still going to be wanting to do Best of breed, right? They're going to want to have their crowd strikes and they're going to want to have their Palo Altos and they're going, you know, but there is, that's just the way it is.

Speaker A: There is this pressure that I've often seen from executive leadership to consolidate on a single vendor and save money regardless of the capabilities and the efficacies of their adjacent solutions. And so that's the game the vendors are playing. They're like cool, we're really good at, at this core, but we want to get all this other money and these other things. So we're going to make something just good enough to check the boxes and then go pressure your executive leadership that it would be cheaper. You know, why do you have a point solution? This point solution that everything just works other better and it doesn't. And everything just talks to each other and it doesn't. It's all single pane of glass and it isn't. And then these point solutions that you got rid of best of breed from suck. And I mean there's a few rare examples where this hasn't been the case. But in general that's what I see happen especially in the 1.0 and 2.0 efforts of these vendors with a very strong core that they want to move into adjacent areas to get more total addressable market. Those areas usually suck, but they're banking on that relationship getting in there, you know, uh, and playing the sales games they play. And. But to your point, I vastly prefer finding a best of breed technology. And in theory, the way things are supposed to go with AI, with MCPS and whatnot, I should be able to build this interoperability on the back end. Assuming I've got somebody with a skill set in the time and I don't need tools to all talk to each other with their own native technology. I can build a middle layer. I don't know. We'll see. I interrupted you, sorry.

Speaker B: No, it was a really good thought. I think we're taking something that is generally a little bit dysfunctional and struggling and we're adding more dysfunction and more friction. Uh, some companies are going to figure this out. They'll do great. They'll figure it out. But I think this is going to be a major confounding factor that's going to lead to some problems and it's going to lead to more burnout. I think we don't yet have a good handle on the long term impacts of kind of trading technology or trading people for technology especially as we start to see, uh, you know, older people, more senior people age out or, or you know, move on, I think that's going to be a big, a big headwind that we have to deal with too. The other challenge I see, and now this is maybe not necessarily a big problem for, for here, but I don't know yet how this is all going to come together. We're in the midst of, uh, we were talking about this before the show. We're in the midst of a big change in the AI industry in terms of how AI is consumed and built. And so a lot of what has come up to now has been, I won't say free flowing because we've seen some pretty big, pretty big bills coming down the line recently. But I think that as the, is the usage starts to, um, be, I should say it differently, as the charges start to be normalized to the investments that these AI companies are making, I think the economics of some of these tools might not make nearly as much sense as they do. And so one of the concerns I have is that companies, even if they're wildly successful, they end up building a program around something they can't, uh, afford in a year. Uh, it's a rough and you know, unvarnished.

Speaker A: They've gotten rid of their good, expensive people to pay for it.

Speaker B: Right, exactly. So we shall see.

Speaker A: It just, it just feels like an unproven path forward. Like what, what has convinced folks of this so aggressively? Normally you see, hey, those early adopters willing to take the, take the chance and pave the blaze the trail. And now there are people just like, now we got to do it. Okay, good luck.

Speaker B: It's fomo. I mean, it's, it's, I think it's part fomo. It's part, you know, I, I think, I think at a, at a macro scale, I think companies have not loved the whole situation with, you know, with, with how much they've had to pay for it and security people. Right. Look, we've both been the beneficiary of this industry. If you were at the right place at the right time and had even a little bit of aptitude, you were able to make some serious money for quite some time. And that I don't think companies really loved. And so now I think companies are seeing an out and I think they're trying to use it. I think that there's also, you know, uh, part of the reality is that companies are just needing to, or wanting to downsize. I think a lot of companies, I mean, look, the other Having. Having been at the executive level in a very large company, there is a game theory element here. Right. When you, when you are in that position, you're looking at what is everybody else doing. And so everybody else is replacing people with AI, even if they're not. So now I need to go and replace people with AI, otherwise my board thinks I'm incompetent and I'm not with the program because they, you know, uh, it's. For the better part of 30 years the mantra has been automation. And reality is like AI is just another. The next iteration of, of displacing people. You know it. People through automation. So yeah, that's not. I don't think we should be surprised by it, but I think we're. I think it's the pace at uh, which is happening like it's the complete disregard for what might happen is where I think the peril.

Speaker A: And to be. To be clear, I'm not against AI and I'm not against. I'm not a Luddite about it. I'm not a. I think my fundamental commentary on this is that I don't think this has been proven to work the way you think it works yet.

Speaker B: Mhm.

Speaker A: And you're making a whole lot of assumptions. You may be right, but I haven't seen the evidence yet. And if you're wrong, it's going to hurt a lot. So maybe take a breath and think about it. But that's. What do I know? I'm an unemployed bum. Nobody's listening to me right now.

Speaker B: All right, moving on to our next story. This one comes from Ars Technica and the title here is Dashlane Explains How Attackers Managed to Download Encrypted password vaults. This was a big story when it first happened because there were lots of Dashlane's pretty popular, uh, password manager, especially after the LastPass breach a couple years ago, everybody left, or a lot of people left LastPass and I think some of them went to Dashlane and you know, especially in the, in the security field. So I remember, you know, seeing all sorts of social media posts about oh my God, I just got locked out of my account. So that, that was uh, that was a. Kind of an exciting time. Uh, but what I thought was, was interesting is the parallels between.

Speaker A: I have no idea what you said for the last two minutes, but I'm sure it was very insightful.

Speaker B: It's all good. What I was saying was I was interested in how this attack seems to parallel what's become known as the device code phishing attacks. Against Microsoft, um, uh, entre ID and whatnot. In this particular attack, what, what the bad guys were doing was trying to add new devices to existing Dashlane accounts, which caused an email, like a verification email with a, with a verification code to go to the email address of the owner. But that code is like just a six digit number. And so what they were doing was hammering the API, trying to add devices to like all sorts of uh, accounts and then just stuffing the random codes in. And apparently they got lucky 20 times, uh, before, before they got caught. Now the good news is that, I mean the bad news is that the devices were added and the bad guys were able to download the password vaults. The good news is the password vaults were apparently still encrypted and would have to be decrypted using the master password. So. Not terrible. The thing that I wanted to talk about is that, you know, we've all, and for good reason have been, you know, moving in the direction, uh, with, with haste toward password managers. At the same time, password managers are becoming very centralized and there's some sensibility in that because, you know, they can typically manage their infrastructure pretty securely. There's an economics of scale there that most of us can't afford. We can't store our password vault in a, you know, in a, in a fedramp high environment or whatever. You know, that's just not usually within the reach of most people. But it also creates concentration, risk. It creates like this very appealing central attack point. If you can get that, if you can figure out a way to get at those passwords, it's going to be disastrous. You look across the landscape with uh, the repo worms and, and all this stuff that's going on there, there's a lot of focus on credential theft, like uh, you know, hyper focus on credential theft. And I think this is another symptom of that, you know, of that problem. And so I think we need to be cognizant of that shift, uh, that's, that's happening. You know, I know that as we talked about in recent, um, story like hacking, you know, vulnerability, exploitation is like the, the way that people are getting in now. But I suspect that we're going to see that pendulum swing back to identity theft.

Speaker A: Yeah, it is an interesting problem. I think on balance I would not let this stop me from recommending a proper password manager to people. And I think a valid, strong master password helps a ton. In fact, from the article they even talk about, hey, even though they got the vault, it's encrypted and they've got a cracked master password. And Dashlane makes this process difficult by using algorithm, uh, known as Argon 2, which makes it much, much harder, uh, slows it down and increases the cost dramatically to target that cryptographic hash and find the collision and brute force it. Uh, and it becomes tremendously time consuming and makes it really hard to do. Not impossible, but really hard to do. And that means that if you have a good strong master password, it would take a lot of time, energy and cost. Hopefully you've also got time to rotate passwords in the meantime or whatever, or maybe they never potentially get in. Uh, so I think the larger risk is people reusing passwords and I think a password manager for the vast majority of people is a safer solution. It's not perfect. And what, what frustrates me about this is we'll have people in the industry who just like nothing more than just crap all over everything say this is why a password manager just isn't, isn't good. And the only way you should use is one that you locally control and like a very complex, complicated, technically out of reach for a lot of people recommendation where I think for the average person who isn't deep into this world, a cloud based synced password manager amongst all of their devices is the best way to get them to adopt it and then use it and then have a strong unique password per account and protect them from that sort of problem where that one account gets popped and it can't be used elsewhere. I still think on balance this is the lesser of the two evils.

Speaker B: Well said, well said. I think, um, and look, I think that's the advantage of the commercial password managers which almost, as far as I know are all cloud based. Um, maybe there's one or two that aren't, but they've done a lot of work on usability and so getting people to use them is going to address the most common challenges that people are falling victim to. It's again, password reuse and uh, weak passwords and whatnot. So I think uh, I definitely agree this is not the last pass breach was bad. I mean I'm not going to, you know, not going to try to sugarcoat that that was pretty bad. Uh, but I, I think that most of the other players are, you know, from what I understand have done a pretty responsible job of, of designing their uh, their environment to be the kind of ecosystem to be secure, not, not necessarily just the infrastructure side but like the whole, the whole program. So I, I think it's you know, for me it's, you know, it's uh, it's a usability thing. And you know, if, if uh, I, I suspect strongly I'm much more likely to, to lose my password because I've managed to uh, get some kind of credential stealer on my computer than somebody breaking into my password manager. It's the way it is.

Speaker A: I would agree.

Speaker B: So moving on to our next story. This one comes from Bleeping Computer and the title here is Hackers Hijack Thousands of Sites for Click Fix and Fake Update Attacks. And if you thought you were safe on Macs, I got some news for you. So just get rid of the people is a. What's that?

Speaker A: Just get rid of the people.

Speaker B: Well that's true. Then your open claw can fall victim to the um, social engineering attacks.

Speaker A: All right, I'll work on.

Speaker B: So anyway, the deal here is that uh, there's an actor known as Drive Surge that's been hacking uh, thousands of websites. I suspect a lot of them have been through in various uh, WordPress plugins and Drupal vulnerabilities. And uh, lots of opportunities for that. Um, but not for the purpose of defacing the site or altering the site in a detectable way, but for the purpose of injecting um, what they call a tds, a traffic distribution system, which in concept is very much like an ad network. It's causing your computer to reach out and download some code from uh, an attacker controlled site. And that code is basically triaging your system and trying to figure out what is the best way to attack you. And it has a couple of options. One option is that it pretends to be a cloudflare banner which is trying to confirm that you're not a robot. And in doing so it gives you a set of instructions that you have to you know, hit Control C to copy to your clipboard and then you hit Control R and then Control V and then you hit Enter and, and then now you're run, you're running some, some script that the attacker uh, has just tricked you into executing, which is amazing. And that's the click fix attack. And then the other, the other common attack that they're doing is they'll present you with uh, basically a blank web page that says that your browser has uh, is out of date and needs to be updated. And keep in mind, you know, you are visiting probably what you consider to be an otherwise reputable site, right? This is, this is going after the trust that people have in websites. It's not like some you know, random porn site. It's, or maybe it is, I don't know, I can't say for sure. But anyway it's, it's also legitimate sites. Uh, and it, it will pop up a little box and say that you have to update your browser which of course offers a download for it to install, which of course is not actually a browser update but rather is in fact malware. And they, and they by the way, they have updates that have coverage for all the major browsers, including ones I've never heard of. So, but, but they also have special, special coverage for macOS. They've observed a obfuscated JavaScript payload specifically designed to target macOS systems delivered via a uh, verification themed click fix attack.

Speaker A: So they're becoming more and more prevalent especially for creatives and developers. So makes sense.

Speaker B: So we've talked in the past about the futility of security awareness training and my take has long been, and I'm going to reiterate it here, I think it's important to do training but I think it's kind of outmoded to tell people hover your mouse over the link to see if it goes where you think it's going to go. I think we need to be teaching people about contemporary attacks. I think, you know, if we're going to, if we're going to occupy people's time with mind numbing security training, it should be about stuff that's actually happening in the world. Like we should be teaching people about quick fix attacks and you know about these, these uh, browser update attacks and things like that. So that's my takeaway. It's what I wanted to say about that.

Speaker A: Yeah, I think that's fair. I do think that there's at some point there's a limit to how many different techniques and ideas and sort of defenses the average non security person could keep in their head. And so I think we have to be careful about what we choose to teach them because I think there's a finite amount of room that we can occupy with that knowledge. So what's most impactful, what's most important

Speaker B: in my opinion, and I guess I'll go, I should not also uh, discount my other thought which is if we're relying on people to not fall victim to this and having that result in some catastrophe to our network, I think we've done our job wrong. We shouldn't be completely dependent on someone, you know, not like the security of our data and our customers should be dependent on someone realizing that that box is not actually asking me to install an update on my browser. Like, there should be other things in our security program that is preventing that from turning into a catastrophe.

Speaker A: Yeah, if you can't survive one click, you've got other problems. But that's a flippant way of saying don't put it all on your user. You have to help protect them. I agree.

Speaker B: All right, our next story comes from Krebs on security. I think this is two weeks in a row we've had a Krebs article. Holy cow.

Speaker A: And yet he doesn't, uh, he doesn't send flowers, doesn't send chocolates.

Speaker B: Sad.

Speaker A: Doesn't even know we exist.

Speaker B: Title here is Hackers Using Meta as AI Support Bots Seize Instagram Accounts. You know, I know lots of people this, it's, it's fun and cool to hate on Meta and Instagram and Facebook and that's all great, but I thought this particular tech was kind of novel and I suspect not going to be the only time we see this sort of thing happening.

Speaker A: Agreed.

Speaker B: And so I thought it was worth, worth talking about. Uh, so what happened here was a, uh, couple days ago, uh, Barack Obama and I think the head of Space Force in the US And a couple of other high profile accounts had their Instagram accounts hacked and they were posting pro Iranian propaganda, which happens during conflicts like we're seeing now. And that's kind of beside the point. Uh, but the way they did it was very interesting. So Instagram or you know, Meta generally, because they have so many freaking users, they don't really have a help desk per se like you. You know, their people are getting constantly locked out, their account stolen and all sorts of stuff. Um, and so they've, they've attempted to automate a lot of these processes and the latest iteration of that is, is actually chatbot, ah, which will help you recover your password. And apparently they tried to be kind of clever about it. They made sure that, you know, if you were going to ask for a password reset or try to get back into your account, they tried to make it so that your, you know, you had to be geographically close to where you normally log in from. Well, I guess the Iranians figured that out. And VPNs are cheap. And you know, most, most VPN major VPN companies will let you come out, you know, pop out onto the Internet wherever you want, like thousands of cities across the world. And they've realized that and they figured out like, you know, where these people live and so they set their exit node to locations, uh, in the, uh, you know, in the, in the local geography, close to, uh, you know, close to, to, um, Barack Obama and whatnot. And just asked the chatbot to change the email address on their account and the chatbot did it, which is kind of amazing.

Speaker A: It was helping.

Speaker B: It was helping. So we have talked about this in the past, and one of the challenges with chatbots is that they kind of fall victim to the same kinds of attacks that humans can. You can socially engineer a help desk person if you're good enough and there aren't robust enough processes to mitigate it. You know, you can, you can fool a person into doing your bidding. And it's not an entirely different thing that the mechanics of how it comes to be are certainly very different. But in, in broad, broad terms like the business end of the social engineering attack looks, you know, very similar. Ah. And you can, the way that you mitigate that in meatspace, as it were, is you basically force limitations on the workflow of how these processes work. You have to have another person, you have to have a manager approve it. You have to have something else approve it. And what occurs to me is that there's a missing piece here that sits between the AI agent and the business system that needs to enforce some sort of business logic, kind of like the help desk system of an agent would, that is clearly missing here. And I suspect, again, the reason I wanted to talk about this is not because I thought it was of security infosec interest that, um, Instagram got hacked, but more that most of our employers are off building chatbots that are doing increasingly novel stuff and trying to replace people. And I think that making sure that we are designing that kind of business logic enforcement layer in the middle is super important because, you know, you, you aren't gonna, you aren't clever enough to build high enough guardrails around your chatbot to prevent social engineering attacks of all types. It's just not going to happen. And so you're going to have to have some other m. Mechanism, um, of enforcement that just hard limits what agents can do under what circumstances.

Speaker A: Yeah, I think you're right. I took a lot of notes on this one and you hit a lot of the points I was going to make. And I think you hit it right that the bots can be socially engineered. They are unconstrained, they in this case had a lot of power to change the assigned email address and trigger out a recovery code to that newly assigned email address. And it's not like this is an automated system that has a very clear logic tree that's being followed a very if then logic tree. This is a bot that can do many different things in many unforeseen, unexpected ways. So it's almost like people are. So we can't predict how it's going to react. We can't easily build programmable constraints around it because of the way bots inherently and AI LLMs operate. And so I wrote down, it was kind of like they're social engineering. It's almost like they're doing fuzzing on the inputs via human language and seeing how it reacts. And they're finding, and they're going to keep finding novel ways to get them to do things that weren't intended. And I think this is going to keep happening until we as an industry have run into enough of these scenarios that it becomes scar tissue in our brains and we start building controls around this. And to your point, or limit the ability, which, uh, I know that a lot of businesses will push back on that. Limiting the ability of these chatbots limits their functionality, which limits their value. But you know, how many times have we seen this story or, you know, uh, a car dealership's chatbot agreed to sell a car for $1 or whatever, right? Like, we don't know the edge cases yet. We don't know how they're being abused. And this goes back to what we were talking about earlier. We've embraced this stuff without really understanding it. And it's gonna keep happening, I think, until m. There's enough pain that business starts to actually invest in learning about these problems and finding actual valid solutions to them. Uh, but I think to your point, the right, the easy solve is, hey, limit what the chatbots can do until you have people involved. I don't think businesses are going to go down that path, though. I think they're incentivized not to do that. So.

Speaker B: I may be a little more pragmatic on that. What I'm envisioning is it's not like not allowing them to change a password. What I'm saying is that you define, think about how you would limit what, under what constraints would you allow a human help desk agent to change a password?

Speaker A: Never.

Speaker B: They would have to have.

Speaker A: Passwords are forever.

Speaker B: They would have to have a manager approval or whatever it is. What I'm saying is that there should be something in the middle that enforces that. Whatever those constraints are, the business logic constraints have actually been met. And you're not leaving it up to the chatbot to figure out if they've been met. You actually have Some sort of non AI based business logic enforcement that sits between the AI, uh, agent and the systems that it's trying to control. That was, that was where I was.

Speaker A: Have you considered maybe an A manager AI bot that oversees the chat bot?

Speaker B: Well, I mean, how are performance reviews going to happen if you don't have that?

Speaker A: Just rub some more AI on it. And then every so often you reorganize the, the chat bots into different departments.

Speaker B: Right, right. And then you have to, you can promote like some chatbots will be better than others and they'll get promoted. You know, we work harder and longer.

Speaker A: This is not far away anyway.

Speaker B: I know.

Speaker A: Anyway, it is. Uh, yeah, it goes back to, I think what we were saying earlier. Companies are embracing this without really understanding it. And maybe, maybe that's how it's always been with technology and maybe that's how it needs to be. But we are well behind the curve from a security perspective on how to know how to manage and monitor these things. Uh, and yet nobody wants to hear that. They want to hear, go find a vendor who fixes this. What if there isn't one?

Speaker B: Yeah, I would, I would like to say that, you know, this in, in times gone by, I would say, well, this is, you know, this uh, assures US employment, but I guess now it just means that some other AI vendor is going to sell another incident response. Bottom Moving on. Our, uh, last story is from Cybersecurity Dive. And the title here is Don't Panic AI Reality Check Dominate Major Cybersecurity Conference. So there were two things about this that made me want to talk about it. One was it hit my confirmation bias, which I always, I'm always going to pull in a story that, that hits my confirmation bias. And then the other one is talking about career paths and resources and whatnot. So I wanted to talk about that too. So, uh, this is a recap of a conference where Gartner spoke about the impacts of AI. Obviously there's still lots of consternation about the impact of Mythos. And, and by the way, we are starting to see a substantial volume of vulnerabilities coming out of the likes of Microsoft and Apple and Oracle and whatnot. So clearly things are happening. Right. Uh, is it all Mythos? I don't know. But the point of this speech was our reaction isn't necessarily different. Like the, the kinds of things we need to be doing, maybe we have to do them faster and more of it, but they aren't radically different. It's the same kind of basic block and tackling. It's getting rid of the old out of, out of date, end of life stuff. It's reducing our, uh, our surface area, our tech surface. It's, it's, it's those sorts of things that are even more important, but they've been important all along. And so that's, I think that's hopefully, uh, resonating. The other point was, I would say I'm paraphrasing. While you have the stage, you might as well use the opportunity in the, the paranoia that come along with, uh, Mythos. The threat of Mythos to go ask for more money, like, can't hurt, right?

Speaker A: Never let a crisis go to waste.

Speaker B: Can't hurt. So you might as well say, look, if we don't add more people, Mythos is going to cause our data center to catch on fire. So, you know, let's get on that.

Speaker A: Yeah, it was an interesting article and there's a couple of things that I kind of took away from it. One, it's heavily leaned into the vulnerability management side of it. But I think there's another big aspect that I've seen CISO struggle with, which is governance of data and sensitive data being sent to AI and how it's being potentially exfiltrated, used, abused, etc. And especially when you've got a bunch of shadow AI going on. And how do we manage that? How do we account for that, how do we see that? And at the same time, you're seeing this mad rush of vendors saying, oh, I can fix that problem, but can they? And so you've got all these little point problems that different vendors say they can solve. That's going to cost a lot of money. You're managing all that, uh, stuff. I see another side of this, which there is this pressure not just on the vulnerability manager side, but how do we, how do we do governance over AI? And I don't think we have a good solve yet. Uh, I think there's a lot of vendors throwing a lot of FUD and talking to a lot of executives and saying, we can solve that problem for you. I don't think it, I think this, this industry is moving. This portion of the industry is moving so fast and the AI tools are so far ahead of the governance and management tools, uh, that we don't have good solved yet. And I think those who say we do are either misinformed, misleading, or selling you something.

Speaker B: Yeah, I would say I think the tools are accelerating away from us too.

Speaker A: It's, it's very executive of you.

Speaker B: Problem is Getting worse.

Speaker A: That's a nice way to say that. That's very, very thought leadership.

Speaker B: I, I try, I try. You know, I was, I was in

Speaker A: that chair once with electricity jolted through your body every couple of days.

Speaker B: I had hair when I started. Um, so, so one, I guess one of the other. You know, one of the frustrations, I suppose, and this is very similar to kind of the early days of Cloud, is that we talk about AI as if it's one thing or, you know, AI risk as if it's one thing and you know, it's, it's really not. It's going to manifest itself in terms of a huge increase potentially. Uh, uh, if you believe the marketing of vulnerabilities we have to patch, it's going to increase the number of zero days and it's going to reduce the complexity or increase the number of people who have the sophistication to launch advanced attacks on us. It is a set sets of tools that our people are going to be sending sensitive data that they really don't or aren't allowed to do. And, and they might not even realize or giving permission.

Speaker A: Giving permissions they don't understand. They're giving.

Speaker B: Right. It's building AI chatbots that we don't really understand how they can be abused given the level of access that they, that they have. I mean, it's not one thing, it's a whole herd of different things. And I am a little concerned that we keep talking about if it's one kind of homogenous thing, and it's really not, it's a whole bunch of different cuts. So that's one thing. The other thing that I thought was worth talking about a little bit, we may have talked about this before, but probably not enough is, and they cover this in the last part of the article and that's the impact on staffing and obviously, you know, whether or not you, you buy the marketing, like there are people. I have, my, my LinkedIn DMS are filled with people looking for jobs because they got displaced because of AI. Whether or not it was really AI, I have no idea. I mean, maybe they were told it was AI, maybe they weren't. Maybe like, I, I don't know, I don't know. But there's a lot of people being displaced for one reason or another. And the other observation is that AI is displacing or it is, um, and it makes sense, right? It's being used to replace a lot of the junior roles in security. You know, that's, that's where we're focusing because it's kind of the low hanging fruit. It makes sense. It's the things that are probably the most easy to automate. I mean within, within reason. I mean I'm not, I'm not saying it's uh, like a complete replacement for a person. I don't mean to imply that, but I'm saying that that's where I think a lot of the focus is and, and has been. And so I don't know that there's anywhere close to the job market for kind of the entry level people. And one of the concerns I've got is like those entry level people are tomorrow's senior people. And uh, maybe we get to a point where the whole, you know, the whole stack is completely AI enabled and like we don't need anybody anymore. But I am really concerned about the ecosystem of IT and InfoSec and cybersecurity people and what that job market, the people filling the job market, what that population looks like over time. Because the complexity of our systems and environments is going up, it's going up radically. Um, but we're starting to have a downward trend in the number of people and the roles that do exist are uh, trending more senior. So it's hard to find an entry level job now. It's, it's hard because they're, they're, you know, we've concentrated them for a long time. We've concentrated them into MSPs and MSSPs and whatnot. And now the MSSPs and the MSPs are like, well, you know, like if I can automate my level one people, like I can save a whole bunch of money. And now you've displaced again tomorrow's senior people. So I'm um. Time will tell if this is a rational concern or not, but it seems like we're building a problem, talent problem that is going to manifest itself in five or 10 years.

Speaker A: You and I are going to be hanging out at the retired community at the Villages, sipping margaritas. Somebody's going to pull up a black sedan.

Speaker B: Gerry, Andy, the helicopter is going to.

Speaker A: We need you. It's a DNS problem. Nobody knows DNS anymore.

Speaker B: Go to back door.

Speaker A: The AI. Ah, can't solve it. Please.

Speaker B: Yeah, well we had that with the year 2036 problem coming up. Right.

Speaker A: So look, if I'm still doing this job in 10 years, something has gone radically wrong.

Speaker B: Fair.

Speaker A: I'll be in my compound in Montana running my cult.

Speaker B: Good on you. Good on you. So anyway, I thought it was an interesting uh, interesting discussion. Um, again I want to reiterate the importance of the basics. There's so much noise in the system about all sorts of novel technologies. And I think it is more important than ever to focus on the basics. And I fear that we're seeing a shift, uh, and we're rewarding people who are specializing to a fault. And I see this in my work that I don't see a lot of focus on basics anymore or I see a lot of like super niche attempts at solving problems that you know, uh, are uh, leaving gaping holes open because they, they just don't have the, the whole picture in their mind. And that's very concerning to me. So please focus on the basics.

Speaker A: We've lost generalists in the industry. Everybody's specialists now. And who knows, I mean it could be AI uh becomes that generalist for us. Maybe it, it becomes that knowledge set that, that we're losing. But AI has intelligence. It doesn't have, it doesn't have wisdom. So I do think there's still, at least for now a value in having an experienced human wisdom applied to problems. But I could be an old fuddy duddy who's standing in the way of progress and, and bitching about cars, putting buggy drivers out of, out of jobs. I don't know. We'll see.

Speaker B: I mean in time. It's inevitable. I think the question is what does it look like between now and then and what problems do we have along the way? And everybody wants to think about well what is it going to be in 10 or 15 or 20 years? But we have to get up and go to work tomorrow and next week and next month. Things aren't going to materially change by then.

Speaker A: I don't know. It's an interesting thing to go through. Uh, and I wonder if this is how things felt when we started industrializing and all the factory workers and such are like wait, what about my job?

Speaker B: That was so, so interesting that you say that. That was the other completely random thought I had while I was walking the dog about, about this security. Unlike um, a lot of uh, uh, engineering disciplines, security and it generally programming, they are as we've talked about it in a long, long ago, like they're, they're trade crafts. They are, you know, they are not like definitive sciences. There's a thousand known ways to design a network and it, you know, that are all secure and it's an almost an art form. It occurs to me, you know, that's not where I, I am, uh, you know, I use Claude and OpenAI pretty extensively. Uh, just because I have to. And it does great at things that are known. It's really great at research. It's really great at doing things that are, uh, well established. It is not very good at all at being creative, like inventing things that don't currently exist. And so that's where I, uh, you know, and again, it's not always going to be like this. There'll be, you know, I think the current approach to AI is probably going to run its course in the near future and something will replace it. And so this might be a temporary problem. But you know, I, I think that's where people are still, are still important to be involved because it has uh, such a reliance on creativity anyway, I guess my, my one, my one ray of sunshine for today.

Speaker A: Yeah, I think you're right. But I also think that the models will get better and better and better at emulating that and we'll see how it ultimately comes out.

Speaker B: Yeah, yeah. And by the way, I don't, I. While I agree with you, I also don't think it's going to be in the approach. Like I think LLMs, I think their days are numbered. Like I think we're, we're going to be tapped out on that approach to AI at some point and it'll go to something else. I don't know what that something else will be. And that something else might have a very different set of constraints and capabilities that might change that dynamic. All right, all right, so that is the show. Thank you. If you want to find links to the stores we talked about today, you go to our website. It's defensivesecurity.org, look for episode 351. You can follow us on YouTube. It's @Defensive Podcast. It's still the best, best thing ever, I think. Uh, if you want to support a show, it's patreon.com defensivesec and uh, where can people find you if they would

Speaker A: like to get on both X and your phenomenal Mastodon instance Infosec Exchange at lurg l erg. And you can find me on LinkedIn, you know, uh, under my name, Andrew Kellett.

Speaker B: With job offers of course.

Speaker A: You know, in all seriousness, I'm very open to consulting and part time work and fractional work. So hey, if, if you think I would be valuable to whatever you got going, hit me up.

Speaker B: He is pretty damn smart.

Speaker A: By the way, is my mom still paying you to say that stuff? Because that's weird.

Speaker B: Anyway, you can find me. Uh, it's erinfosec.exchange. and, uh, I'm pretty easy to find. Most people know how to get a hold of me these days. And with that, you've reached the end. I hope you have a wonderful week ahead. And, uh, we will talk again next time.

Speaker A: Have a great week. Thanks, everybody.

Speaker B: Bye. Bye. Take care.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Incident Response 101: What to Do When You’re Under AttackSecure AF · on Shiny Hunters66 / 100
  • Cybercrime News For Jul. 2, 2026. 19-Year-Old Alleged Hacker Extradited. WCYB Digital Radio.Cybercrime Magazine Podcast · on Shiny Hunters43 / 100

More from Defensive Security Podcast

All episodes →
  • Defensive Security Podcast Episode 350
  • Defensive Security Podcast Episode 349
  • Defensive Security Podcast Episode 348
  • Defensive Security Podcast Episode 347
  • Defensive Security Podcast Episode 346
Explore the best B2B Ops podcasts →
All Defensive Security Podcast episodes →