The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Security Weekly Podcast Network
Security Weekly Podcast Network artwork

AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8, Josh Marpet - SWN #593

Security Weekly Podcast Network · 2026-06-26 · 33 min

0:00--:--

Key moments - from our scoring

Substance score

34 / 100

Five dimensions, 20 points each

Insight Density6 / 20
Originality5 / 20
Guest Caliber9 / 20
Specificity & Evidence9 / 20
Conversational Craft5 / 20

Doug White covers seven significant security developments affecting enterprise infrastructure and supply chains. The FortiBleeds attack demonstrates a critical pattern: credential harvesting through unpatched Fortinet Fortigate devices (320,000+ targets), credential stuffing, GPU-cracked hashes from the CVE, and VPN lateral movement into trusted networks where FTP, Telnet, and HTTP run in the clear. The fix requires not just patching but rehashing stored credentials in the new secure format - a lesson applicable beyond Fortinet to Sophos deployments, SQL Server, and Active Directory. Microsoft quietly extended Windows 10 free security updates to October 2027 via an editor's note, offering ESU licensing via Microsoft Rewards or cloud backup redemption (10 machines per account). Separately, a sophisticated phishing kit called Blacksite bundled with Cloaked.gg evasion tool bypasses MFA by reverse-proxying legitimate login pages (Google, Microsoft, Facebook, banks, crypto) and forwarding credentials and MFA codes in real time while blocking VM and scanner detection. PTC Windchill, widely deployed in automotive, aerospace, and defense manufacturing, now carries its first KEV-listed vulnerability for unauthenticated remote code execution via input validation flaws. Cisco CUCM web dialer has a similar flaw with 24-hour time-to-exploit; Josh Marpet reports scanning occurred before public disclosure. The episode closes with discussion of delivery robots entering city sidewalks (BB-8-style systems) and cryptocurrency regulatory definitions from the SEC distinguishing digital commodities from securities.

Key takeaways

  • →FortiBleeed exploits weak password hashing in Fortinet and Sophos systems to gain VPN access, after which attackers can harvest credentials and assume they're trusted on internal networks using clear-text protocols.
  • →Assume your VPN will be compromised and audit internal network security, eliminating clear-text protocols like FTP and Telnet, implementing zero-trust architecture, and assuming internal threats exist alongside external ones.
  • →Blacksite phishing kit uses reverse proxy man-in-the-middle attacks with Cloaked.gg evasion to bypass multi-factor authentication by impersonating legitimate services and forwarding credentials in real-time.
  • →Time-to-exploit for new vulnerabilities has collapsed to under 24 hours after proof-of-concept release, with scanning and tagging of vulnerable systems occurring before patches are even available.
  • →Organizations must dramatically reduce patch timelines and establish clear prioritization frameworks, as current 6-12 month patch cycles cannot compete with attacker response times measured in minutes to hours.

In this episode

  1. 1FortiBleep Attack on Fortinet and Sophos - VPN Credential Harvesting
  2. 2Windows 10 Extended Security Updates Through October 2027
  3. 3Blacksite Phishing Kit and Cloak GG MFA Bypass Tool
  4. 4PTC Windchill Remote Code Execution Vulnerability
  5. 5Cisco Unified CM Web Dialer Server-Side Request Forgery
  6. 6Time to Exploit Acceleration and Patch Management Challenges
  7. 7Delivery Robots on City Sidewalks and Vandalism Concerns
  8. 8SEC Classification of Cryptocurrency Assets and Securities

Mentioned

FortinetSophosMicrosoftPTCCiscoThreatLockerTanium AtlasWindchillFlexPLMBlacksiteCloak GGJosh Marpet

Guests

Josh Marpet

Topics in this episode

FortinetFortiBleeedSophosBlacksite phishing kitCloaked.ggPTC WindchillFlexPLMCisco Unified CMCISA KEV catalogWindows 10 Extended Security Updates

Questions this episode answers

What is FortiBleeds and how does it lead to VPN compromise?

FortiBleeds is a flaw in Fortinet Fortigate (and similar devices in Sophos, SQL deployments) that stores password hashes in an insecure format. Attackers scan for exposed devices, use credential stuffing or brute force, exploit Fortibleeds to harvest weak hashes, crack them with GPUs, and gain legitimate VPN credentials that trust internal networks, bypassing perimeter security.

Why is rehashing credentials necessary after patching Fortinet?

Fortinet's patch only secures new hashes going forward; older passwords remain stored in the weak format. Simply updating the software or having users change passwords doesn't automatically migrate old hashes. Organizations must explicitly force all credentials to be resaved after patching to ensure they use the new secure hash format.

How does Blacksite phishing kit bypass multi-factor authentication?

Blacksite uses Cloaked.gg to create a reverse proxy that mirrors legitimate login pages (Microsoft, Google, etc.). It captures user credentials, forwards authentication requests to the real site, captures the MFA challenge, and relays it back to the victim, allowing attackers to complete MFA without possessing the actual second factor.

What is the time-to-exploit for the Cisco CUCM web dialer vulnerability?

The vulnerability was exploited within less than 24 hours of the proof-of-concept being published, with scanning detected before public disclosure. Defuse observed adversaries tagging vulnerable systems in advance, meaning organizations running web dialer should assume they've been scanned and possibly compromised.

Which manufacturing sectors are affected by the PTC Windchill vulnerability?

PTC Windchill is widely used in automotive, aerospace, defense, and heavy machinery manufacturing companies. The input validation flaw allowing unauthenticated remote code execution represents the first PTC vulnerability added to CISA's Known Exploited Vulnerability catalog.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

6 / 20

The episode is a lightly-curated news roundup heavily padded with extended humor tangents, analogies, and personal anecdotes. Real technical content (FortaBleed attack chain, CUCM exploit timing) exists but occupies a fraction of the runtime relative to filler.

It was 41 centigrade in Paris this week. Yeah, so hit that like and subscribe button before it's too late.
I put my home address down as a Denny's in New Jersey. I was like, if somebody wants to go there and look for me, feel free.

Originality

5 / 20

Every security takeaway offered is entirely conventional - patch faster, don't trust VPN implicitly, use MFA, pursue zero trust. No contrarian or first-principles arguments appear; the episode's distinctiveness is comedic rather than analytical.

Zero trust is clearly the future as threats get faster, quieter and harder to detect.
rotate your credentials, verify that the hashes have migrated to the secure form, review your VPN and admin activity, which you should. All these are things you should be doing anyway.

Guest Caliber

9 / 20

Josh Marpet references a real, ongoing research effort scanning hundreds of thousands of packages for patch-gap analysis, giving him practitioner credibility, but his segment is brief and pivots quickly to tangential SEC cryptocurrency regulatory commentary rather than deep operational security content.

We scanned 62,000 packages. The next one's coming out in a couple weeks. We scanned about 300,000 packages. That's at valuechainrisk.org
Effectively, from the time the patch code is written, you've got minutes to patch everybody and everything.

Specificity & Evidence

9 / 20

A handful of concrete data points appear - exploit timelines, target counts, package scan volumes - but most news items lack CVE numbers, sourcing, or deeper quantitative context, and the crypto and robot segments are essentially unsubstantiated commentary.

over 320,000 targets were hit just on Fortigate alone
The time to exploit on this was not quite 24 hours after the proof of concept and exploit chain was published.

Conversational Craft

5 / 20

The episode is predominantly solo narration; the Josh Marpet segment features no probing follow-ups, no pushback, and the host openly acknowledges that most of his content has questionable relevance - there is no mechanism for productive disagreement or depth.

I have to say something, though, Josh. When you say, what does this have to do with me? I would say that applies to about 90% of everything I say.
Wow, Josh, you get around 458 embryos in active.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Doug Whitehost81%
  • Speaker B19%

Most-used words

security33patch12sidewalk9problem9microsoft9josh8vulnerability8windows8cryptocurrency8weekly7news7access7credentials7back7different7interesting7

Episode notes

AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8 Sidewalk Bots, Josh Marpet, and More on this episode of the Security Weekly News. Visit for all the latest episodes! Show Notes:

Full transcript

33 min

Transcribed and scored by The B2B Podcast Index.

Doug White: It's the Security weekly news, episode 593, which adds up to 17, which is kind of nice. Uh, but it is Friday, the 26th day of June 2026. I'm Doug White. Welcome to the show. We have AI Brain Harvest for the Bleed, Win 10, Black Site, Windchill, Cisco, Sidewalk Bots, Josh Marpet and more. On this episode of the Security Weekly News, we interrupt our program to bring. It's the show that keeps you up to date on the latest security news twice a week, your trusted source for accurate security information and expert analysis. It's time for the Security Weekly News. All right, I'm Doug White, and welcome to the Security Weekly News. It was 41 centigrade in Paris this week. Yeah, so hit that like and subscribe button before it's too late. I mean, it won't help anything, but your mouse may melt or who knows what. But it's definitely not a great day to sit on the sidewalk and drink wine. Actually, it's okay. They actually banned it. Paris said you could not drink wine on the sidewalk this week because they were afraid you would die and the wine would boil in the bottle. So. But hey, whatever, go swim in the Seine. Um, every week there's another breach tied to an unpatched vulnerability. And with thousands of new CVEs each year, most teams simply can't keep up. So what actually deserves your attention? Join the Vulnerability Management Virtual CyberSecurity Summit on July 29th to hear how security teams are prioritizing real world threats, reducing exposure, and staying ahead of exploitation. Security Weekly listeners can register for free at. Vuln Management using the promo code CSS26SW. So check that out. If you're trying FortaBleed, it's Fortabad for Fortinet and Fortayou. Sorry, Fortinet. Um, this story was about Fort a bleed, and it's a really good article that provides this comprehensive look at the whole cycle for things that go on in this kind of attack. So it's actually relevant even if you don't use Fortinet or Sophos or any of the things that were immediately vulnerable to this. Because it's not really, uh, a vulnerability per se. It is, but it isn't. Uh, over 320,000 targets were hit just on Fortigate alone. Uh, basically what they do is they find your device by just scanning, uh, the Internet, looking for fingerprinting. They then use credential stuffing, which is the most likely. Or they brute force it and they get in. Once they get in, they use the Fortibleed flaw to gather all the hashes from the machine which are insecure and they can crack them with GPUs and that gives them VPN access. And this is where the problems really start. Because once they get in your VPN with legitimate credentials that they have cracked, they're inside the perimeter. And once they're there, they can pretty much do whatever they want. If you trust your VPN connections, which a lot of people do, mostly what they do is immediately harvest even more credentials, anything they can get out of that network. Uh, so this same problem is affecting Sophos, user portal instances, SQL Server deployments, Active Directory VPNs and other services. The main problem is that VPN access, though a lot of setups pretty much trust VPN access. I saw that over and over again and they just felt like VPN saves us. And it means those internal networks which are only accessible by VPN may have very little security. I mean, if you're an auditor, you've seen this for sure. It's kind of like you have a bank vault and it's guarded by rabid velociraptors and laser motion sensors and only Catherine Zeta zones can slink through there. But there is this convenient subway tunnel right underneath the vault and Don Cheadle can use a cockney accent to get through the floor where all the money is laying around in bags with swag written on them. Internally, companies are notorious for using things like FTP, HTTP, Telnet and other in the clear protocols where they go, hey, nobody can get to it, it's VPN protected. Maybe you have active directory and you've never heard of Mimikatz or you use that uh, ever convenient statement. Well, they'd have to get in through the VPN to do that. Yeah. So Fortinet fixed this hash problem in an update, but the problem persisted because older passwords were stored using that older hash format that was so weak. So unless you updated all those credentials and re saved them, and even if you update the credential, change the password, whatever, and you don't resave it, it's still in that old format. So you have to, you know, you need to upgrade the software, you need to patch, and you still, after all that, need to resave all the hashes for the credentials, you can't just let people change their passwords and call it good. So one, assume you're going to be compromised. Really? I mean, assume your VPN is going to go down. It will happen. Two, what will happen to you when they can access Your internal private networks through the vpn. How trusted are they? Can they scrape all the credentials? Can they run mimikats? Can they upload scripts? What I mean threats are not just outside your network, they are in your network too. Insider threat is a real problem. But this is a really good article that is well written, it's well put together, it's easy to follow, Almost anyone could read it. Uh, the guidance in the article is rotate your credentials, verify that the hashes have migrated to the secure form, review your VPN and admin activity, which you should. All these are things you should be doing anyway. But look internally, get rid of clear text protocols, please die FTP, please get better identity management, use, multi factor, all that stuff and I agree on every point. But don't wait for this to catch up to you because you feel that you're safe because you use a vpn. I mean really, I mean even if you don't use fortinet, something else is coming. Zero trust is clearly the future as uh, threats get faster, quieter and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold, trusted apps stay contained and drift is locked down across the environment. It's Zero trust that works in real enterprises and prepares you for the threats ahead. See why CISOs are adopting it@securityweekly.com ThreatLocker uh, Microsoft has quietly extended free Windows 10 Extended Security Updates for an additional year to 12 October 2027. They didn't really make a big fuss about this and it was only found in an editor's note in the Windows Experience blog because we all read that um, and they posted this on the 25th of June. So if you are still running Windows 10 or you have those pesky laptops that can't be upgraded although they could be upgraded to Linux. But I'll try not to say that too many times they have given you an extra year of time. Um, I put Linux on all my laptops. That would not allow me to upgrade to Windows 11 where they kept telling you you'll need a whole new piece of hardware to do this. Uh, but Windows 10 originally hit end of support in October of 2025 and Microsoft no longer provides much of anything for it unless you have a long term service agreement and you get security updates to get that you can pay $30. Uh, that's one way to do it. Apparently you can just back up your Windows settings to your Microsoft account and they will give you a license for this. You can redeem 1,000 Microsoft reward points. I have no idea how you get those. Uh, or in the European economic area, you can log into a Windows 10 machine with a Microsoft account and apparently it will extend this for you. That ESU license can be used uh, on up to 10 machines with the same Microsoft account. Or Linux. You wouldn't need it if you had Linux, but I'm just saying. A new phishing kit called Blacksite comes bundled with an evasion tool called Cloaked gg. Now this thing is a tool. Cloak GG is a tool that allows adversary in the middle attacks that has avoidance detection for anti phishing tools per abnormal AI. Both of these things were developed by an attacker named Kira Payload who started uh, advertising black site on various criminal, you know, uh, Dark web forums and Telegram, uh, earlier this month. Cloak GG first appeared in September of 2025. Uh, and the overall kit uses a bunch of adversary in the middle approaches to allow bypass of multi factor authentication. It uses a reverse proxy mirror to make it look like a legitimate site while capturing and sending all the victim's inputs and service responses in real time. It can impersonate pretty much anything but they focus on Google, Microsoft, Facebook, Instagram, banks, corporations and crypto wallets that are well known. So you think you're logging into that Microsoft request login screen and you're really logging into this thing which then sends all your credentials, get your multi factor information and also forwards that. They just pop that login up and you try your login, it forwards all those requests uh, to the actual site so that multi factor request occurs and you put that in and well, now they got you. Uh, Cloak GG is used to block traffic from automated scanners. So they look at it and say, yeah, don't use this, don't use that. And they also look for analysis tools, VMs, all kinds of things. And it has very customizable rules. It's a really nice piece of software. It's very sophisticated. So I'm afraid to log into anything anymore. It may all be fake. My car, I got a new car urgently because my other car suddenly decided to basically detonate and the repair bill was higher than the value of the car. So I traded it and the new used car I got was asking for lots and lots of login information. Not to mention it maintained the login information of the previous owner and had their home address, their birth date, all kinds of information about them including their logins. And yeah, I was Thinking maybe I shouldn't give my car any of this information. I put my home address down as a Denny's in New Jersey. I was like, if somebody wants to go there and look for me, feel free. On Call is a kind of humorous yet sadly true column that often reflects help desk experiences. And I like it. And not just for the humor, but it makes me think, too. Uh, one time I was trying to help this doctor's office with hipaa, and I told them they would need to use passwords on their laptops, because they didn't. And the owner, head doctor, said, that's fine, that's fine. But the problem was the doctors did not want this. They were adamant that the staff would use it, but they didn't want it. So basically what they did was they wrote the password for each laptop on the case with a Sharpie. Yeah, I mean, this particular story is about upper management not wanting to be held to the same security standards as a staff. I mean, we've all been yelled at by a CEO, a senator, a cio, a ciso, a senior VP of Marshall Marketing, uh, a provost, a dean. Sorry. I mean, I'm just listing the titles, all the people that yelled at me. But you probably have some more. I mean, what do you do when the CEO calls you and says, look, we have absolute trust in the C suite. There's no need to use multi factor or even logins there. It's just silly for us. We're the C suite. Turn it off. I mean, turn it off now. I mean, what do you do, you know? I mean, you, uh, know, this got me back to the CISO reporting the CIO as well. I never liked the idea that the investigators were answering to the investigated. Who's watching the watchman? I mean, I usually recommended they report to internal audit, but that was still a problem in a different way. But this little column made me think about all that. Like, I've seen it. I mean, I had a bank president one time order me not to require his password to be reset. M. And to make it four digits. I mean, what do you do? You know, I had a CEO who said, no door shall be barred to me. My badge will open any door in this entire company, anywhere, anytime. No supervision, no logging. I do not want it. Turn it off. And, you know, I suggested he tested on the nuclear waste storage bins. But, you know, it's an. It's an interesting problem. And the article kind of made me think about that and how you have to deal with. With that kind of stuff, because We've all dealt with it and we will continue to do so. Cisa, uh, the Cybersecurity and Infrastructure Security Agency in the United States added a vulnerability to the known exploited Vulnerability Catalog or KEV. The issue and vulnerability affects PTC, Windchill and FlexPLM products where an input validation flaw can be used to allow remote unauthenticated attacker to execute arbitrary code. About the worst thing that you could possibly have, I guess it was sort of infamous for. This is the first ever PTC vulnerability that was recorded and added to the kev. But hey, welcome aboard pcc. German police issued a warning about this back in March and patches were starting to roll out in June. Now, ptc, if you aren't familiar with them, um, make products for manufacturing and enterprise and windchill is widely used in industrial and manufacturing companies in the automotive, aerospace, defense and heavy machinery companies. I'm sure Matsumura, Fishworks and Tamarabuki heavy manufacturing concern all use it. Mr. Sparkle. Look, if you don't get Simpsons jokes from 1997, well, these kids today with their vines and dubstep remixes. What? That's. That's still dated. Oh, uh, okay. Six, seven. No, get off of my. Yeah, six, seven. In your skibidi toilet. There you go. Are those already dated too? I don't know. Get off of my lawn. I know you aren't getting back your Roblox or whatever else you lost in my yard, you punks. Yeah, I'm turning into Clint Eastwood circa, you know, 2010 kind of thing. I'm just going to be, you know, having an empty chair on the stage and ranting about the clouds or something. Sorry, Clint. Please don't come hurt me. Um, now I'll be paranoid every time I see an El Camino driving around. Um, a vulnerability in Cisco, Unified CM or cucm M, uh, and Unified CM SME, that's like, wow, Alphabet soup. Unified CMSME deployments, uh, that have web dialer service enabled have an input validation problem that could allow an unauthenticated remote attacker once again to perform server side request forgeries and escalate to root as well as dialing any number. All kinds of stuff, very scary stuff. But, uh, it's not on by default, but you should probably check and it's bad. So patch it or mitigate it or whatever. But here's the point. The time to exploit on this was not quite 24 hours after the proof of concept and exploit chain was published. I mean, think about that. Days before this defused observed someone scanning for and tagging vulnerable systems. So before it even came out, people knew about it and they were looking for it. Uh, Defuse went on and said that if you have a CUCM with web dialer enabled and you haven't patched it, you should assume you have been scanned and tagged and possibly compromised. So, you know, I get it. How many patches a day get released for stuff that you have access to that has access to something else, that has access to something else in Augustus de Morgan. But how do those patches interact with other patches and systems? How do they affect your operations? You know, we patched the Plumbus and it caused the Chimera holding tanks to fail open due to the Weebel Feaster API dependence on version 1.2.1 of a Perl script called Simply Mike, which all relied on a 32 bit Java runtime authenticated against an abandoned Windows NT domain. And the vendor was bought by Broadcom. So our support contracts are now $4 million an hour and resulted in a PDF advising not to patch. It's tough. I mean, but the time to exploit is falling. I mean, falling like a greased arrow dropped from a dirigible at 20,000ft. Ooh, math. That sounds like one of my programming problems. Uh, okay, so V equals the square root of 2gh, where g is 32.17ft per second squared, and h equals 20,000. So a greased arrow would strike the sidewalk on West 54th street at about Mach 1. I mean, we're assuming there's no wind. Or maybe they were trying to hit a Denny's in Newark and there was wind and it blew it a little off course. But. So, you know, what the hell are we even talking about? Oh, oh. Time to exploit. So what is your patch process? How long does it actually take you to be notified and get a patch in place or a mitigation? Do you even know right now what needs patching? What is four patches back? What is the most dangerous thing you have in your system? That is on version 7 and the current is version 11. And, oh, yeah, we can't even upgrade that without a memory increase. And on and on and on. It's scary. We. I mean, we all try to rank patches. I do it. I mean, you know, how do you prioritize this? Like, how do you know? You know, is it time to patch times severity times negative, mitigation times criticality of the system? I don't know. Uh, the CEOs peloton, you know, the CEOs peloton can't be down even though it doesn't appear it's ever used. How do you score that? It's a tough one, but we're going to have to move towards a lower time to patch or, uh, we're just going to live in a world that's like driving a 1972 Ford Pinto Runabout Orange and notice that there is a burning oily rag stuck in a fuel filler on the left side, but you're being chased by flesh eating toads from the wasteland. And a guy whose lips are sewn shut with a head on a stick and the head is Billy Bob Thornton's and it's singing illuche van la stela. And then I woke up. I don't know. But you need to figure this out regardless or I'll have more of these dreams and that's not a good thing. Uh, coming soon, or maybe already to you. Depending on where you are, you may be sharing the sidewalk with delivery robots. And you know, in addition to that guy with no pants and that scary woman that I think lives in the turret on the Ansonia and gazes down while stirring pots of weird, goofy. Yeah, robots. Maybe like those scenes in iRobot, you know, where there's robots walking everywhere and carrying things and whatever. The book's better, but the, uh, scene's more visual. So initially robots have sort of focused on being these cute things like BB8, you know, rolling along and delivering pizzas or whatever it is they want to deliver. But more people are starting to find them annoying, according to this article. Now San Francisco has started limiting them because I guess they're interfering with all the homeless encampments on the sidewalk. Um, you know, I mean, like, you don't want robots stirring up the, uh, fentanyl addicts. But Toronto banned them from sidewalks in 2021. Sorry, San Francisco. You know, I love you and it's a great city. Don't get me wrong. I love going there. Please have me back. Um, but Toronto banned them in 2021. Chicago has banned them from some small areas of Chicago in the UK where a lot of testing for this has been done. Some of them have been vandalized in Sheffield. I mean, what doesn't get vandalized in Sheffield? Give me a break. But I mean, you know, look, in New York you share the sidewalk with everything. Some guy named Bert who only bathes when the Yankees have a rain out game or, you know, not to mention old Red who seems to have bathed in pickle juice and panther sweat. I, um, don't know, a rat named Carl. Um, but I Mean, I think this is coming. It's just like when they started replacing horses with cars, people didn't like it. People started vandalizing cars because, you know, horses were, you know, the best thing that ever happened, despite all that waste. But change is hard. And sharing the sidewalk with a cute robot who's just trying to deliver a six pack is happening. Now some of the robots are going to get vandalized and robbed and graffitied and shanked and spat on and peed on both human and animal varieties and. And also stolen. But that already happens. I mean, all those things happen to people all the time. I've never been graffiti, mind you. Um, I did see a guy squeeze a glass of sweat out of a T shirt one time. That was pretty interesting. But I was on 8th Avenue. My friend was like, wow, there's not as many dangerous people around as there used to be. And I was like, oh, look at this guy, here he comes. And he's like, hey, you want some? I was like, okay, yeah, this is. This is definitely weird. But I mean, wait till these things get hacked, though, because all their code is written in Visual Basic 6. And then they decide to deliver your six pack of rolling Rock with military grade enthusiasm. Here, have another beer. Here, I have another beer. Yeah, I'll let you. I'll leave it to you to imagine where the beers are being shoved. But the threat landscape just shifted under your feet. Attacks move at machine speed now, and you can't defend what you can't see. Tanium Atlas has changed that one prompt and it queries every endpoint in your fleet. Surfacing machines exposed to a live Axios supply chain compromise in seconds. This is live State, not a stale cmdb. It pinpoints which endpoints are truly compromised and traces the attacker's command and control. Atlas then secures the business by isolating, patching, and remediating all at once. Tanium Atlas. See everything, act instantly. Find out more@securityweekly.com Tanium but look, if anyone can reach a peaceful understanding with the bourbon delivery bot, it's going to be Josh Marpet. Hi, Josh.

Speaker B: Hey, Doug. How are you? By the way, I got to tell you your story about less than 24 hours and our patch gap. Uh, I literally wrote a report on that. It's a quarterly report. The next one's coming out in a couple of weeks. It's worse than you can possibly think of. Uh, effectively, from the time the patch code is written, you've got minutes to patch everybody and everything.

Doug White: That's what I've Been telling people, too. I mean, I've just been like, look, I realize you think that it can take six to 12 months before you can have a patch plan in place, but the bad guys are taking six seconds, uh, from the time this comes out. And if you're vulnerable, they've already scanned you. They already know you're vulnerable. They know you've got that whatever router, that whatever firewall, and they know that in advance of the announcement, so they respond almost immediately because they know they don't have that much time. But, yeah, I completely agree.

Speaker B: It's bad. But if you want to see the report, it goes into great detail. We scanned 62,000 packages. The next one's coming out in a couple weeks. We scanned about 300,000 packages. That's@valuechainrisk.org but anyway, let's talk about something even more fun than patching, and that's cryptocurrency and crypto assets. Because the SEC just came out and like. Wait, wait, wait. This is Security Weekly News. What does this have to do with me? There's, uh, the methods in the madness. Bear with me for a second. The madness is in the method. I don't know.

Doug White: Whatever. I have to say something, though, Josh. When you say, what does this have to do with me? I would say that applies to about 90% of everything I say.

Speaker B: Yeah, that's actually probably true, but let's get over that.

Doug White: Okay?

Speaker B: Okay. So the SEC came out with a new definition of what is a security in relation to cryptocurrency. And they actually have five different categories now. Okay, So a digital commodity, Bitcoin, Ethereum, etc. Their stores of values, those are not a security.

Doug White: Okay?

Speaker B: They're just money. Digital collectibles. NFTs, because NFTs were so popular. Um, meme coins and similar assets like Dogecoin. Not a security. Digital tools. These are functional tokens. These are utility tokens. People call them not a security. This is the interesting one. Stablecoins. The SEC took a sidestep on this because the genius act regulates stablecoins. They are not a security. They declined to assert independent SEC jurisdiction. That is just crazy. But whatever. The only thing that they said is a digital or cryptocurrency style security is a tokenized version of a traditional security. In other words, if you take a stock or a bond and then you wrap it. Okay, which wrapping and staking for, uh, cryptocurrency advocates, uh, if you wrap it and convert it into a security or securitize it, but you have to start with a traditional security. That is interesting because they've been wrapping and staking all kinds of different assets and treating them like securities. But this new nut legislations regulation from the SEC states that they are not. Okay, so what does that matter to us as security experts? Well, if you're working in cryptocurrency, own cryptocurrency, uh, use cryptocurrency in any form or fashion, especially for the people that work there. Because there's a lot of jobs in cryptocurrency these days. Okay. Your company that you're working with could potentially walk away from any securities, um, basically cases that they are, that they're involved in. Effectively. This now gives the defense counsel a lot of ammunition to say, oh, uh, hey, this was never a security in the first place. This case is over. And it's, it's fascinating. The idea here was that the, the prior enforcement approach, okay, the prior compliance system, which was basically, if you see something radically bad happening, go after the people doing it. But, but the definition of what radically bad was, was not really well defined. Was the wrong way they wanted to define it. And I'll be honest, I'm not really averse to that. I'm not certain I agree with the way that they've defined it. But the idea of defining it is a good one. Okay. The point here is that we now have strict lanes of what a security is and what a security is not. With the genius act that has come out about stablecoins that allows any bank to issue a stablecoin or work with a stablecoin issuer. And those stablecoins are in fact legal US currency as I understand it. And now they've stated specifically that the SEC is not going to be looking at anybody that plays with stablecoins. Does this mean that there's going to be non bank banks doing stablecoin stuff? Does this mean that as we start dollarizing risk to under. To make executives understand risk, we need to stablecoinize risk. Does this. Like there's so many different aspects when you bring in other currencies that are literally exchangeable easily for US dollar because they are stablecoin pegged at US dollar but they have arbitrage available. But like oh, uh, yeah, yeah, this is sort of at the level of business rather than the level of a

Doug White: hack or a patch.

Speaker B: But can you imagine how much less security the stablecoin issuers are going to have on their systems than say Swift, which already has interestingly bad security or any uh, kind of wire Transfer system, any kind of money movement system, any kind of dark trade, dark island or island trading system. Now they have to keep track of 500 different currencies. It's going to be interesting in the security world to lock down all of these different securities, all of the different ways these securities are used. Oh wait, I'm sorry, not securities. Currencies, stablecoins, utility tokens. Oh, they're totally not securities. They're totally not being sold for profit or loss. Oh, and by the way, the interesting thing also in that piece, uh, of regulation before, if you invest in something, you're doing it from the premise that I'm going to make money out of it, hopefully at the end of it. Right. So it's a security throughout its entire lifespan. What they've stated now was if you invest in something and it matures to a self sufficient ecosystem, it's no longer a security. The securities aspect just dissolves. Does that mean my capital gains taxes dissolve as well? I think that the ramifications and consequences of these regulations are going to be similar to the ramifications and consequences of Texas saying that embryos are babies. If I can claim, if they're babies, I can claim them on my taxes. I have 452 dependents now, thank you very much. Okay. Similar kinds of consequences and ramifications that may not have been thought through. We shall see. Time will tell. Thank you Doug. Back to you, sir.

Doug White: Wow, Josh, you get around 458 embryos in active.

Speaker B: Yeah, well as a guy that's like one. Nevermind.

Doug White: Yeah, let's not go there. All right, thank you, Josh. Um, finally, international intrigue. The Soviets produced a car called the Gaz 13 Cheka. Uh, I don't know how to pronounce it, sorry Russian friends, but it looked an awful lot like a lot of American cars in the 50s, right? It kind of looked like a 1957 Chevy. Uh, there was a Datsun Type 11 that Austin Motors complained about because it looked real similar. Well, Anthropic has accused Alibaba of trying to clone Claude. Oh, it's a modern day arms race, right? AI brain harvesting. Igor, head down to the AI cemetery and get me a Claude. Mythos to the monster. Modern Prometheus, but only really modern. I mean, Anthropic wants them punished. But I hate to tell you Anthropic, it's going to be tough. You know, my publisher wouldn't allow me to take copies of my exciting book getting started Quickly with Microsoft Visual C because they said if I did and I Let anybody have a copy of it, it would immediately be reproduced and sold internationally illegally without them getting a cut. So I'm not sure what Anthropic's going to, uh, you know, actually be able to do about this. And I do believe there's going to be rogue AIs very, very soon. I mean, there already are, but I mean, in widespread, you know, Claude, without safety rails, you know, designing killer beer delivery bots to eradicate the sidewalk overcrowding. You know, I asked Claude something yesterday and it got really worked up that I was going to do something bad and suggested I contact law enforcement. I was like, dude, relax, relax. Hang on, hang on, hang on. I'm not actually going to do this. I was just talking. Claude listens to what I have to say, unlike some of you. But. And speaking of that, go write some nice comments about our show because I. We were doing a review and they were like, wow, you have so few comments about your show. And I'm like, that's because everybody loves me so much and is terrified of saying anything. But write some comments. You can talk about Josh if you want to, but anyway, I think all this is coming soon. Next week, uh, a special show on Tuesday. You'll have to tune in to find out. Uh, and a holiday interview show on Friday. That's the, uh, for the 4th of July. It's actually the 3rd of July, but it's the 4th of July. We have an interview with Gib Witham, who's the president of Hack the Box. So I hope I'll see you there, uh, especially on Tuesday, because you're going to want to see that. It's going to be interesting. But anyway, thank you, Josh. Thanks all of you for being here. We'll see you next time on the Security Weekly News Sa.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Open Book Problem 1: How Your Public Records Become an Attackers' RoadmapThe Small Business Cyber Security Guy · on Fortinet90 / 100
  • E198 - What GTM Leaders Can Learn from the Innovation Ecosystem featuring Dave & Joe O'CallaghanTech Sales Insights · on Fortinet63 / 100
  • “Soft Market Surge: Capital Floods In as Risk Industry Eyes New Frontiers”Insurance Intelligence Daily · on Fortinet39 / 100
  • FortiBleed Attacks: Turning Fortinet Firewalls into Credential StealersSecure AF · on Fortinet34 / 100
  • Ep. 20: Dave Neuman On Software Supply Chains & Small Business Security AdviceThe Threat Show · on Fortinet

More from Security Weekly Podcast Network

All episodes →
  • Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet,.. - SWN #59765 / 100
  • Cloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #93275 / 100
  • The Strategic Human Firewall as AI Impacts Regulations, Cyber Pros, and Employees - Robert Siciliano - BSW #45368 / 100
  • AI Is Annoying & IoT Devices Still Get Hacked - PSW #934
  • Why AI Just Broke Traditional IT Security as Leaders Clash Over AI's Value and Hiring - Matt Quinn - BSW #455
Explore the best B2B Engineering & DevTools podcasts →
All Security Weekly Podcast Network episodes →