The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The 443
The 443 artwork

The Claude Fable Saga - The 443 Podcast - Episode 375

The 443 · 2026-06-22 · 34 min

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber6 / 20
Specificity & Evidence11 / 20
Conversational Craft6 / 20

Anthropic's release of Claude Fable 5 and Mythos 5 turned into a major regulatory saga when the US Government issued export control directives blocking access to both models just three days after launch. Hosts Mark and Corey examine the tensions between AI safety and innovation: Anthropic implemented safeguards including safety classifiers that block 5% of requests for cybersecurity, biology, chemistry, and model distillation tasks, routing flagged requests to Claude Opus instead. However, the government became aware of a jailbreak method that circumvented these protections, leading to a first-of-its-kind export control blocking foreign nationals from accessing Fable 5 and Mythos 5. The episode explores whether this is legitimate national security concern, political motivation, or regulatory capture - especially given the administration's recent pivot from anti-regulation rhetoric to suddenly restricting a commercial AI product. The hosts also cover FortiGate 'FortiBleed,' where Hudson Rock identified 75,000 compromised firewall credentials across 194 countries, likely originating from a 2022 CVE or stolen configuration files, and discuss practical mitigations including MFA, credential rotation, and zero-trust network access to management interfaces.

Key takeaways

  • →Claude Fable 5 was disabled by US export control directives that mandated blocking access to foreign nationals, likely due to jailbreak techniques being discovered that bypassed safety classifiers protecting cybersecurity and biology tasks.
  • →The FortiBleed credential collection of 75,000 Fortinet devices is likely derived from stolen configuration files exfiltrated via a 2022 auth bypass CVE that let attackers run arbitrary admin commands, with credentials remaining valid due to lack of rotation after patching.
  • →Multi-factor authentication deployment is critical for preventing credential-based attacks, but organizations also need secrets rotation procedures and vulnerability indicators from vendors to detect post-patch exploitation on older vulnerabilities.
  • →Management interfaces for security appliances should never be directly exposed to the internet and should be accessed via Zero Trust Network Access with MFA instead of direct remote access.
  • →Evidence of government regulatory capture may be occurring where Anthropic, advocating for AI licensing requirements similar to firearms, could be coordinating with US authorities to limit competitor capabilities under the guise of safety concerns.

In this episode

  1. 1Anthropic's Claude Fable 5 and Mythos 5 Release and US Government Export Controls
  2. 2Safeguards and Jailbreak Methods in Fable 5
  3. 3Government Block and Regulatory Motivations
  4. 4Fortibleed: 75,000 Compromised Fortinet Credentials Breach
  5. 5Analysis of Credential Sources and Attack Methods
  6. 6Remediation Steps: MFA, Credential Rotation, and Management Interface Security

Mentioned

AnthropicClaude Fable 5Mythos 5FortinetFortiGateHudson RockOpenAIMicrosoftSam AltmanDarius AmodeiKevin BeaumontClaude Opus 4.8

Guests

Corey Wobbly Desk

Topics in this episode

AnthropicUS government export controlsModel DistillationClaude/Fable 5Project GlasswingFortiBleedFortinet FortiGateHudson RockKevin BeaumontZero Trust Network Access (ZTNA)

Questions this episode answers

Why did the US Government block access to Claude Fable 5 and Mythos 5?

The government cited national security concerns, claiming it became aware of a jailbreak method that could bypass Fable 5's cybersecurity safeguards. Anthropic acknowledged the jailbreak existed but argued it only exploited minor, previously-known vulnerabilities that other publicly available models could also discover without requiring the jailbreak.

What safeguards does Claude Fable 5 have that Mythos doesn't?

Fable 5 includes separate AI safety classifiers designed to detect potential misuse, jailbreak attempts, and harmful queries. When detected, requests related to cybersecurity, biology, chemistry, or model distillation are automatically downgraded to Claude Opus 4.8. About 5% of all Fable 5 requests trigger these safeguards.

What is FortiBleed and how were Fortinet credentials compromised?

FortiBleed is a collection of credentials from nearly 75,000 FortiGate devices across 194 countries, likely stolen from a 2022 authentication bypass CVE that allowed attackers to access admin commands by setting proxying headers to localhost. The credentials were then dumped, cracked offline, and packaged for sale as an initial access broker collection.

What should Fortinet customers do if exposed in the FortiBleed breach?

Enable multi-factor authentication on devices, rotate credentials (especially after old vulnerabilities), check if your domain appears in Hudson Rock's FortiBleed lookup tool, harden management interfaces by removing direct Internet exposure, and implement zero-trust network access (ZTNA) with MFA to protect administrative access.

What's the difference between the freely available Fable 5 and the Mythos 5 given to the government?

Fable 5 is Claude's most powerful model released to the general public but includes heavy safeguards and guardrails that downgrade risky requests. Mythos 5 was released to the US Government and Project Glasswing members without the same safety classifiers, maintaining the model's full capabilities for cybersecurity and biology tasks.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode covers real security news with occasional useful observations - the 5% false-positive rate on safety classifiers, the 2022 auth-bypass CVE underpinning FortiGate credential theft, and the Brian Krebs deanonymization of Nightmare Eclipse - but these are interspersed with heavy speculation, casual banter, and jokes that dilute the useful content per minute significantly.

around like 5% of all requests going through, uh, Fable 5 would trigger it and block it and bump it down to opus 4.8
they also noted that their publicly available models, think like Opus 4.8, were able to find the exact same vulnerabilities without requiring a jailbreak too

Originality

7 / 20

The hosts offer a mildly interesting regulatory capture hypothesis and a historically grounded point about Microsoft and the origins of full disclosure, but most commentary is reactive news recap with no first-principles arguments or genuinely contrarian takes that a regular security news reader wouldn't arrive at independently.

it feels like this might be some form of like regulatory capture where they're trying to intentionally lower the ceiling of capabilities for some other ulterior motive
Microsoft was one of the first to start doing trustworthy computing and start to maybe react to researchers and treat them seriously. But now it's like people are getting frustrated again

Guest Caliber

6 / 20

There are no external guests; both speakers are WatchGuard vendor employees doing a news recap. They demonstrate baseline security industry familiarity but no deep practitioner expertise, original research, or operator-level execution experience is on display.

welcome back, man. This is the first time you and I have had a news podcast. We been releasing a lot of cool partner ones on events. We're both back home now
What Ryan, our analyst, wrote about, which is where people are just, you know, we, we found people pretending to have watchguard SSL infrastructure

Specificity & Evidence

11 / 20

The FortiGate segment surfaces concrete figures - 75,000 devices, 194 countries, 1.6 billion credential attempts, the 2022 localhost proxy-header auth bypass CVE - and the Nightmare Eclipse section cites Krebs's LinkedIn evidence; however, a good portion of the episode is speculative and the hosts frequently acknowledge they cannot verify claims.

includes nearly 75,000 unique firewall URLs from over 194 countries and 21,000 affected domains. And it represented roughly 50% of all firewall Fortinet firewall devices currently facing the Internet
there's a CVE that Nightmare Eclipse claimed that Microsoft took a long time to uh, validate. Microsoft credited that CVE to a security researcher based in Germany who on their LinkedIn account uh, lists that they worked for Microsoft from 2022 to 2025

Conversational Craft

6 / 20

The hosts rarely challenge each other; when one floats a conspiracy theory the other quickly agrees or retreats with 'maybe it's just me being cynical.' Questions are mostly rhetorical setup lines rather than probing follow-ups, and no significant claim is pushed back on with evidence or counter-argument.

That seems fair. And maybe it's just me being cynical
I also like, I think that is one highly likely scenario. I also think another scenario is Anthropic's in on this too and this is another kind of marketing ploy

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B59%
  • Speaker A41%

Most-used words

microsoft21fable20vulnerability17mythos14government14back13security13anthropic13credentials13vulnerabilities13access12post12nightmare11model11researcher11saying10

Episode notes

This week on the podcast, we unpack the Claude Fable 5 release and subsequent revocation following an export control directive from the US federal government. After that, we cover the recent FortiBleed credential dump, discussing its likely origins, before reviewing the most recent Windows 0day disclosed by Nightmare Eclipse.

Full transcript

34 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hey, everyone.

Speaker B: Welcome Back to the 443 Security Simplified. I'm your host, Mark the Liberty, and

Speaker A: joining me today is Corey Wobbly Desk, not Grinder. How are you doing, Mark? Uh, oh, I didn't make people sick with that wobble.

Speaker B: I am Mark, uh, super congested, the Liberty. So I guess we're both struggling a little bit today.

Speaker A: By the way, welcome back, man. This is the first time you and I have had a news podcast. We been releasing a lot of cool partner ones on events. We're both back home now. So, uh, nice to see, uh, the news.

Speaker B: Good to be back. And as you're suggesting, we've got a couple of interesting stories to touch on that happened while we were out. First, we will dive into Anthropic's Fable 5 and Mythos 5 and the whole damn saga that happened there.

Speaker A: Sounds like new games. There's new Fable coming. Is this just Anthropic is going into Microsoft games?

Speaker B: Um, possibly. I guess we'll see. Uh, then we will discuss, uh, fortableed, the collection of nearly 75,000, uh, compromised FortiGate devices, or I guess, credentials from 75,000 devices.

Speaker A: Fortinet does Forta everything, so fortibli to some sort of blood donation device, which

Speaker B: is an accurate guess too. And then we will end with the latest zero day from Nightmare Eclipse, which is Microsoft's, I don't know, worst enemy at this point.

Speaker A: We've heard from him before. What would our podcast be without an end of the world zero day?

Speaker B: Yep. So with that, I don't know, let's go ahead and bleed our way in. But, uh, to start with, Corey, when I was out on vacation, uh, quite a bit happened in the world of artificial intelligence. And I think it's worth, uh, taking a look back over the last two weeks and just kind of recapping what went on. And, uh, maybe some hot takes on why we think the US Government has finally stepped in and straight up blocked an AI model through export control. But to, uh, set the foundation, I guess. On June 9, Anthropic announced Claude Fable 5 as a mythos class model, which they made available for general use after adding some, uh, some safety features to it. They described it as their most powerful model they've ever made generally available, saying it was scoring exceptional performance and metrics around software, engineering, knowledge, work vision, and even some scientific research areas too. Uh, that it was designed for longer and more complex tasks. And the longer and more complex the task is, the better that Fable 5 is compared to other models. Um, but they noted that as a Mythos class model. So in the same realm as the, uh, Mythos preview in Project glasswing, it was also really good at cybersecurity related tasks.

Speaker A: Can I just do a simple. Like to me, if we cut through all the blah, blah, blah, business speak, this is Mythos with better, more guardrails. Like my ciso, my mark thinks I'm a four dummies book kind of guy. Reads this as, hey, Fable is Mythos for the public. And we have additional guardrails on it that we don't have in our Mythos preview. Uh, it's still good at everything. Mythos is good at cybersecurity, creating biohazard viruses and whatever else. Uh, but we have a lot of guardrails on it that make it drop down to other models when you start getting into those topics. Is that fair to say, Mark?

Speaker B: That is basically it. They even went on to describe some of their safeguards they put in there, like their safety classifiers, which are a completely separate AI system designed to detect potential misuse, including like jailbreak attempts. And like you said, when it detects abuse or even like any attempt to do something related to cybersecurity, biology, chemistry or model distillation, it automatically drops down to Claude Opus 4.8. And instead to handle those types of requests, um, a couple of those were kind of interesting. So makes sense to block cybersecurity. We've talked a lot about Project glasswing already and how this class of model, uh, seems pretty capable of autonomously finding and exploiting vulnerabilities. But they also said historically they would only block access to, uh, people trying to develop bioweapons using AI. But they said in this post that even that wasn't enough. Uh, now they just block all biology related queries, period. Because they didn't think their initial classifiers are strong enough. Um, they also have had issues with people trying to, uh, basically extract the training or the capabilities of their models, which is called model distillation. And they, uh, have added classifiers to block that as well too, uh, with even more, um, aggression. I guess. They even noted like their classifiers, they're designed for safety and they're erring on the side of safety. And so they're going to block a lot of things that maybe they didn't need to, but they're going to just on the side of like being overly cautious too. In fact, they said around like 5% of all requests going through, uh, Fable 5 would trigger it and block it and bump it down to opus 4.8,

Speaker A: by the way, there's an update on this release though, which is kind of weird. Like, they released Mythos to the US Government and some entities, and Mythos doesn't have the safeguards and has the same strengths. But, uh, I hear we can no longer use Fable.

Speaker B: Correct. So just three days after releasing this model on June 12, or these two models on June 12, they announced that they were abruptly disabling access to both Fable 5 and Mythos 5, which was that one they released to the government and Project glasswing members. They were disabling access to all customers, uh, to comply with an order from the US Government citing national security concerns, where they issued export control directives on top of them. Basically, the directive mandated that Anthropic block access to all foreign nationals, whether inside or outside the United States. And Anthropic basically said the only way they can comply with this reliably is to remove access entirely, um, to all these models. Now in Anthropic's post, they said that their understanding is that the government believes that they became aware of a jailbreak method for Fable 5, basically a way around all those safeguards. Anthropic, um, says that they reviewed a demonstration of a specific technique being used to identify a small number of previously known minor vulnerabilities. Basically, they reviewed evidence that someone had jailbroken Fable 5, used it to discover vulnerabilities. But Anthropic is saying they were previously known in minor vulnerabilities. And they also noted that their publicly available models, think like Opus 4.8, were able to find the exact same vulnerabilities without requiring a jailbreak too. So it's not like it discovered any net new stuff. Um, but it was. Someone was able to get around the cybersecurity prevention safeguards and use it for vulnerability research. Um, they also went into. Oh, go ahead.

Speaker A: No, no, finish. Go for it.

Speaker B: They went through like this big bulleted thing where they talked about, like, all of the, uh, steps they've taken to make sure that Fable 5 is safe. They gave the government and other labs, ah, or other organizations access to Red Team it for thousands of hours. No one found a universal jailbreak. So they threat modeled around just limited jailbreaks, um, and built their protections, which they think are adequate to limit the scope of potential jailbreaks too. They ended it, uh, the whole post with basically, as we've stated publicly, we believe the government should have the ability to block unsafe deployments as part of a statutory process that is transparent, fair, clear and grounded in technical facts. This Action does not adhere to those principles. We apologize for the disruption to our customers. We believe this is a misunderstanding and we're working to restore access as soon as possible.

Speaker A: So that feels like a very diplomatic corporate response. But can I put on my conspiracy hat? Like we all know the story with the US Government when they ripped out Anthropic because of safeguards. They didn't like the safeguards. They wanted to use AI for whatever the heck word they want to do with it and they were mad about safeguards and now they're all happy with OpenAI, but suddenly they're trying to block a commercial product because it doesn't have safeguards. This feels like a very politically motivated administrative thing. Uh, Anthropic doesn't say that. The government's not saying that, but I'm

Speaker B: saying that I also like, I think that is one highly likely scenario. I also think another scenario is Anthropic's in on this too and this is another kind of marketing ploy for it too. So they uh, just this last week was like, I guess the G7 summit with like world leaders from the US, France, England, a few other places. They also invited the, the heads of all the major AI labs like Sam Altman and uh, Darius Almadea to like talk to them as well. And the CEO of Anthropic, Darius Amadeo, uh, I think I'm pronouncing it right, probably not, made one comment where he says he thinks that some of these models should be treated kind of like firearms where you need like a gun license to be able to use them. And so he's not exactly like advocating to leaders that it's safe for use. He seems to be advocating the opposite, that it's not safe for use. And that got me thinking like it feels like this might be some form of like regulatory capture where they're trying to intentionally lower the ceiling of capabilities for some other ulterior motive.

Speaker A: But I, I, maybe I'm too naive, Mark, but I actually this is why I prefer, this is a personal preference only by the way. And I like watchguard uses all kinds of commercial things. Uh, I prefer Anthropic over the other AI companies because they actually uh, they're still profit motivated. I, I don't disagree that they, they like hype on their models but they seem to be ones where they're warning about the power of AI rather than just innovating for profit only reasons and even asking like they're one of the few self regulating ones that I think

Speaker B: as

Speaker A: policies, uh, Changed recently at least in the US where regulation of AI kind of got disappeared for innovation. They seem to want the world to understand the power of what they're building. And honestly that was their whole conflict with the U.S. government. They, the U.S. government wants the unfettered power is how I interpret it without blocks. And is, could this just be legitimate? Is he like saying this is a powerful thing and we want to have this powerful thing? Because by the way the power can be good put to very good use. The cyber security risk is also the cyber security opportunity. The good guys having this model in hands can fix vulnerabilities way faster, can find much more than their humans have been able to in the past is the promise. Whether it's hype or not, that's the promise. That's also the danger. So I think he wants to provide a tool that there is actual good societal cyber security benefit for. But anything that has great power can be used by the other side too. So I, I, I, there could be market like our, our vulnerability hunting and our model is better than yours. Yes, that could be a profit motivated thing. But there seems to be tests around it, there seems to be consensus at least among some of the groups and some of the vulnerabilities found that it's not just pure hype. And if for once, if the CEO is actually this is a great powerful tool, but it's dangerous too. I uh, mean, I think that's kudos. And it's kind of funny that the government is coming off as the one that's now putting safeguards on just this one AI company. Who's the one AI company that seems to be trying to ask for some safeguards and ask for some regulation.

Speaker B: That seems fair. And maybe it's just me being cynical,

Speaker A: but I mean I guess that you're not wrong.

Speaker B: Exactly.

Speaker A: At the end of the day there's a board with profit. So things change.

Speaker B: Yep. But even the way that even still it's been a week and it is still offline. Fable 5 and Mythos 5 for members of Project Glasswing are still not available. And so they do seem to be working. Ah. Still struggling to work through some form of approval from the government.

Speaker A: To be honest. Internally we were excited about seeing Fable because it was giving us a version of Mythos we could use. So we tried to go through an approval process quickly to start using it. And the same day we were like, yes, we're going to allow this use in this situation. Bam. Oh, guess what? There's no Fable anymore.

Speaker B: Yep, exactly. But it Is. I mean, it's still crazy seeing how fast some of the stuff is moving. This was like the first case of the US government at least stepping in and putting export controls on a model like this.

Speaker A: So they're funny because they've been going to these same global conferences saying, we need to stop regulating AI. Yeah, the world is saying, regulate AI. EU is saying, check out this EU AI act. And our administration is saying, stop that crap. We need to innovate. But no way changed our mind. I wonder why.

Speaker B: Uh, I'm still looking forward to us getting our hands on Mythos 5 and being able to use it with our own internal projects as well. But, uh, until then, I guess we're stuck with Opus 4.8. Unfortunately,

Speaker A: we're not talking about the biological threat, man. We're talking about our industry. But I guess the biological threat is one that I just don't want to think about.

Speaker B: That one is also interesting. They are starting a separate kind of pre approval process to grant access to biological research using Fable 5 once it comes back online. Um, while still trying to heavily monitor for people creating bioweapons.

Speaker A: Huge power. It's such both ways. I mean, imagine genetically catered to your specific body medications, which AI may help bring humanity to, but then also perfectly catered to your body bioweapons. Fun time.

Speaker B: It is. It's pretty awesome. Like in their initial announcement post, they gave some like, specifics around like virus research and biology research and its capabilities. Flip side, they also gave some evidence like they had it play Pokemon Fire Red and it was able to play it entirely through just a GUI interface and beat the game too. So Fable's pretty good at a lot of things, it seems.

Speaker A: Hopefully they'll release Fable so I can set up Fable to play the new upcoming Microsoft Fable game and see if Fable can beat its own name game.

Speaker B: Sounds like it might be able to by the time we get that one released too. I guess we'll see. Anyways, uh, moving on to the second story though. So last week, researchers, uh, at Hudson Rock published a blog post describing what they called fortibleed, which is a collection of credentials that they claimed are from nearly 75,000 Fortinet firewall devices. Uh, the collection was originally discovered by a different security researcher who claims he found them just on a server. Didn't give any description of what he was doing on said server, um, but says it includes nearly 75,000 unique firewall URLs from over 194 countries and 21,000 affected domains. And it represented roughly 50% of all firewall Fortinet firewall devices currently facing the Internet. Uh, the original researcher made some honestly kind of confusing claims. If you look at their uh, X, uh, post or LinkedIn post, uh, they said that like the attackers executed 1.6 billion credential attempts, over 320,000 Fortigate targets as well as 2.1 billion attempts for 160,000 SQL servers. He also claimed, which I thought was a bit dubious and maybe we can talk about it, that the attackers were actively intercepting SSL VPN authentication hashes and cracking them using a dedicated 45 GPU cluster. When I saw that bit I thought my first thought was evidence please on that because making claims that people are intercepting SSL VPN authentication attempts at this kind of scale is kind of insane. That's a lot of man in the potential man in the middle stuff to be going on. Um, more realistically. So Kevin Beaumont, former uh, Microsoft employee and pretty prolific security researcher, he uh, made a blog post with his own analysis and he thinks that all these came from just stolen configuration files um, exported from vulnerable Fortinet uh devices over the last couple of years because some of them included like admin credentials as well too which you can.

Speaker A: It's also something that happened before even I think two years ago. There was a story of a bunch of fortigate VPN attacks that were, they were getting popped with credentials and it turned out it was from a VPN vulnerability but a VPN vulnerability that was patched a year ago. But the problem is first of all if people didn't patch when the people were exploiting this, they would have gathered credentials then if they didn't patch when the patch came out, they could continue to gather credentials. If they didn't change credentials after the patch, it doesn't matter that you have it. I think Kevin Beaumont is correct. Uh, obviously this is a big threat to Fortinet but to some extent it feels very much like ah, at some point there's a customer and for our customer managed service provider responsibility to pay attention to updates and to consider types of vulnerabilities on updates. Like there's some updates where if you're patching the flaw that was even partially zero day for a period of time changing credentials could be necessary. Uh, because you don't know if someone popped it and may not be lurking on the device right now or even anytime soon, but they downloaded a config file like you said or a credential file or whatever. This could obviously fortinets a big target and this guy has very specific information about a campaign that's affecting a lot of boxes. We've seen ourself that credential stealing and brute force attacks are affecting every edge device right now.

Speaker B: Yeah, and uh, I saw actually a Reddit post on this where someone commented that their account rep claimed that the configuration, uh, files were stolen from a 2022 CVE and Fortigate devices. There was a, uh, auth bypass vulnerability that let attackers just run arbitrary admin commands by setting the proxying headers to localhost 127001 back in 2022. And that makes sense that they would dump these credential databases and then crack them offline or, and then build up a collection of valid credentials and then turn around and try and sell them on the underground, which is what it looks like they're preparing to do with this one by packaging them up with information about the uh, organization that they belong to, including like vertical and size and stuff like that. This looks like a, uh, like initial access broker kind of collection that they were building up.

Speaker A: And I gotta tell the. I mean people listening probably know this, but anytime public underground boards, you start to see bulk sales of credentials. They're probably a year old. Like they've been out there for a long time and they've probably leveraged all the good ones and they're just so. Yeah, to me, this, the 2020 thing, the Reddit post, I believe it. I, like, I. It seems like a likely possibility.

Speaker B: One thing that was an interesting, um, bit of info on this is that some of the passwords were really complex, like 20 character random strings. It looked like in my head that means difficult. That sounds difficult to brute force a random 20 character string like that.

Speaker A: You stole them in an unhashed form. Because I feel like even a weaker hashtag other than a completely broken hash, 20 characters is, uh, we've gotten 14, maybe 15, 16, but it takes exponentially longer for 20.

Speaker B: So it makes me wonder if this is like a collection of credentials stolen from a bunch of different means. Like some of them could be configuration, uh, files they cracked offline. Some could be like info stealing malware on someone's machine. Absolutely. They got the.

Speaker A: What Ryan, our analyst, wrote about, which is where people are just, you know, we, we found people pretending to have watchguard SSL infrastructure, but once we poked into that, we found out it was Cisco Fortinet, it was every vendor's infrastructure, and they would just steal a credential through a fake SSL or VPN app. So it could just Be a stolen credential through a phishing. And maybe some of them are from a vulnerability, but they're mix them all together in some bulk scale.

Speaker B: Yeah, that's my assumption that this is like multiple sources for these credentials. And both like Hudson Rock and Kevin Boomot did like independently verify a bunch of them were still valid too. And so even if they're old, it's unrotated stuff.

Speaker A: But we have plenty of practical tips to talk about after this then.

Speaker B: Yeah, like what? Enable multi factor authentication.

Speaker A: Yeah, that's the first that to me that's a primary one. All of these devices ours for sure support it. Um, I still think uh, there are cases where you can't have multi factor on system or uh, non human accounts. So you still need to have good strong practices. And when you can't have multi factor, I do think rotation is a bigger deal, but I think the biggest deal and it's something vendors have to help with. We have had vulnerabilities before where we uh, know changing passwords on a hardware device is hard. Like when you have to change secrets. When you have a hardware device that's handling security, it's not just your users changing passwords, it's perhaps certificate or digital key based authentication. There's a lot of secrets you may have to change on the device that is hard. I do think we have to think about vulnerabilities, even old ones, and not just I patched but if I don't know if I was affected by this two years later, even after I patch, things can happen. So as you're looking at hardware and you're seeing things that are remote and give access to credentials or for rce it might be the type of thing where you not only have to patch but you do have to rotate all your secrets. And we recently had a flaw where we would at least give you the indicators of attack. Like uh, it's a pain in the butt to do that if you don't think you've been hacked. But if the vendors can share, here's what you can look for to see if anyone exploited this. The second you see signs of it, change those passwords because otherwise it will come and bite you again five years later.

Speaker B: Yep, I agree entirely. And uh, then like just in general, like hard pardon your endpoints too. Like it seems like at least some of these were probably stolen from configuration files using a vulnerability on the management interface.

Speaker A: Management interface?

Speaker B: Yeah, and there is no need for that to be exposed to the Internet, period.

Speaker A: If you've listened to us more than two years you've heard us harp on how to secure management interfaces. Uh, no more direct remote access to anything that has a public ip. Use ztna, use ZTNA with MFA and then access the private side of a management interface.

Speaker B: Yep. Heck yeah. But so if you are listening and you are a Fortinet customer, uh, or an MSP that deploys Fortinets, Hudson uh Rock has a pretty good utility on their website if you search for fortibly where you can look up a domain and see if it was included in this breach. Uh, kind of like a uh, have I been pwned Kind of tool for.

Speaker A: For debate.

Speaker B: Exactly. But it's I wonder if we should

Speaker A: get the uh, the test products we have for comparison and see if any of those show up. I'm sure we used email addresses that were a different domain.

Speaker B: Not a bad idea, but uh, man. Still yet another reason to uh, move off of traditional mobile VPNs and onto ZTNA style tools. Anyways, moving on to the last story for today. Microsoft's uh, nightmare continued this month when the security researcher known as Nightmare Eclipse dropped yet another zero day, this time immediately following a patch Tuesday update that resolved two other zero days that they had dropped just before. I think they're up to what like 67 now?

Speaker A: By the way, this researcher, we've talked about his post before. I uh, like that he's trying to secure Defender, but that is kind of a little shady like dropping something crappy booty after a patch that's. Come on, you can't even pretend you're working for Responsible Disclosure anymore if you're doing that.

Speaker B: Yep. So the ones that were resolved in uh, June's patch Tuesday were green plasma, which was a local privilege escalation vulnerability, and yellow key which was a bitlocker bypass vulnerability. Uh, those were patched uh, just a week or so ago. And right after that he dropped Rogue Planet, which is a local privilege escalation vulnerability that allows an attacker to open a command prompt with system level privileges on the machine. Uh, so Nightmare Clip said that it's a race condition and so on some Machines it works 100% of the time, while at others they struggled uh, to get it working. He also said it was a full remote code execution vulnerability until Microsoft silently hardened Defender uh, back in mid May, which forced him to rewrite the exploit and only achieve local privilege escalation. Then he ended by saying that uh, this actually was pretty draining doing all the rewriting. So he's going to take a month off from finding and dropping new vulnerabilities and uh, might return sometime in July or so. Um, but I think it's safe to say that Microsoft is off this researcher and uh, this is, I think it's vulnerability number six now that they've released uh, as a zero day since then. But interestingly so I saw Microsoft is

Speaker A: happy for a summer break if he really does take a month off. But is that like a red herring and he'll release two more while they go on summer break?

Speaker B: It's funny, he's not the only one taking a break. I saw uh, the maintainer, the lead maintainer for Curl, the Linux utility for web requests announced that they're not going to accept any vulnerability reports for the month of July so that all of their ah, their team can have the summer off to either take a vacation or work on their backlog of just bugs.

Speaker A: There's a big zero day, we're just not hackers. Have at it for a month.

Speaker B: That is basically what they said is like if there's something important in there they'll deal with it when they get back. They did say that like they've got paid support contracts and so they'll continue working with paid support contracts but basically said we're drowning and welcome to open source.

Speaker A: I uh, I wonder if the days have changed when we all assumed open source was more secure.

Speaker B: It's tough when it's only being maintained by a couple people.

Speaker A: That's why like I, I'm not blaming them, they're I, I guess on the flip side these ones that have contracts are getting paid for those support contracts but if you're not getting paid for it you don't have the responsibility. So what made us think they'd ever be more secure other than the fact that theoretically other people could find vulnerabilities easily.

Speaker B: But back to Nightmare Eclipse. I saw a post from Brian Krebs on the uh, Infosec Exchange social media site uh where he gave a bunch of evidence that Nightmare Eclipse is actually a former Microsoft employee that worked for Microsoft from 2022 to 2025. He gave a few pieces of evidence. One of them was uh, there's a CVE that Nightmare Eclipse claimed that Microsoft took a long time to uh, validate. Microsoft credited that CVE to a security researcher based in Germany who on their LinkedIn account uh, lists that they worked for Microsoft from 2022 to 2025. Um, that same researcher was credited on another vulnerability that Nightmare Eclipse is also claiming credit for and uh, their HackerOne profile that Krebs dug up has a lot of similar style of vulnerabilities and other vendors products as well too. So this looks like a. Someone's a security researcher, got hired by Microsoft, maybe left or got affected by the layoffs back in 2025 or something. And maybe that was part of the straw that broke the camel's back for this personal vendetta against them as well.

Speaker A: But uh, that was an interesting mark spilling the tea. I feel like I need to get some tea for this juicy gossip. But Brian Krebs is a great researcher man, so.

Speaker B: Yep. And also gave credit that that very first episode we started talking about Nightmare Eclipse. They were originally named Chaotic Eclipse so I was correct at that point too. Either way, uh, it's if you feels a bit more icky now if they are a former employee that's now going and finding and dropping zero days against Microsoft that I don't know if one of our security researchers started doing that I'd be pretty.

Speaker A: I have to admit while it's uh, kind of interesting to see all these defender flaws, this guy has never been a responsible disclosure. He's been a. And I, in a way I believe a malicious full disclosure not giving uh,

Speaker B: at least not this year. So like looking through their HackerOne reports like there is a history of them like giving even more than the traditional 90 days working with vendors. But you can see them getting progressively more frustrated over time, uh, working with vendors and now they just seem to have flipped a switch and turn into a completely unethical researcher.

Speaker A: Which I guess if you think about it, Microsoft was the one that started full disclosure. I mean Microsoft was where researchers back this is now 20 years ago man, before they had trustworthy computing. It was really most of the time researchers sharing Microsoft issues that Microsoft never looked at that eventually started full disclosure which was purposely meant to be punitive because there was no way for these security researchers to get attention. It's like it came full circle. Microsoft was one of the first to start doing trustworthy computing and start to maybe react to researchers and treat them seriously. But now it's like people are getting frustrated again. Huh? Huh?

Speaker B: Yeah, it's funny. Time is a flat circle.

Speaker A: How will AI? There won't be researchers now. There'll be a AI vulnerability submission at Microsoft and AI vulnerability hunters.

Speaker B: If that means I get to go hang out like on a beach or in the woods somewhere and you no longer have to work, then I'm on board with that 100%. More realistically I imagine I'll be doing the job that only a a meatbag human can do that. AI still hasn't figured out to do on do on their own. So I guess we'll see.

Speaker A: We're profit off of AI quick so you can buy that secluded island somewhere and stay on the beach.

Speaker B: There we go. Maybe use AI to launch my own cyber attack. We'll see.

Speaker A: Oh, don't do that, Mark. You're a good guy.

Speaker B: You're never going to catch me to the fence. No. Uh, realistically, uh, I think you are hitting the nail on the head though that we are moving very quickly towards an AI versus AI even in the software development and vulnerability discovery era. I mean, crap, it feels like we're already there, but crazy, crazy times. And uh, I'm looking forward to seeing what Mr. Nightmare Eclipse comes up with. After their summer vacation, they've had a chance to chill.

Speaker A: I hope they got a lot of bug bounties to make it a good vacation.

Speaker B: Hopefully. Hey everyone. Thanks again for listening. As always. If you enjoyed today's episode, don't forget to rate, review and subscribe. If you have any questions on today's topics or suggestions for future episode topics, you can reach out to us on. Um, Blue sky. I'm at itsmark me. Corey's Secadept. Um, the both of us are at watchguardtechnologies. Uh, thanks again for listening and you will hear from at least me next week as Corey takes his own vacation. My Nightmare clips Maybe.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The 18x Midas Lister Betting $3B on AI (and calling most of it fake) | Navin Chaddha, MayfieldThe Peel with Turner Novak · on Anthropic91 / 100
  • How SSW turned AI into ½ their pipeline - Ulysses Maclaren, COO of SSWSaaS Stories · on Anthropic86 / 100
  • Unscripted with Victor: Agentic AI, Fintech's Future, and the Death of the App EconomyVentures from The Valley · on Anthropic83 / 100
  • Fighting Fire with Fire: How CyberProof Is Automating Cyber Defense with Edy AlmerCyber Sentries: AI Insight to Cloud Security · on Anthropic80 / 100
  • John Suarez on How Businesses Should Actually Use AI Without Losing Human JudgementMarketing for SMEs · on Anthropic78 / 100
  • Who Gets to Shape the AI Future? | AI4, Agents, Open Source, and Small BusinessAGI - Advance, Grow, Innovate with AI · on Anthropic77 / 100

More from The 443

All episodes →
  • Iran Hacks the US Water Supply - The 443 Podcast - Episode 38277 / 100
  • HuggingFace's List of Demands - The 443 Podcast - Episode 381
  • OpenAI's Models Go Rogue - The 443 Podcast - Episode 380
  • WatchGuard's Cyber Hygiene Report - The 443 Podcast - Episode 379
  • Lessons from a CISA Security Incident - The 443 Podcast - Episode 378
Explore the best B2B Engineering & DevTools podcasts →
All The 443 episodes →