The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Cybersecurity Defenders Podcast
The Cybersecurity Defenders Podcast artwork

Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335]

The Cybersecurity Defenders Podcast · 2026-07-01 · 30 min

0:00--:--

Key moments - from our scoring

Substance score

36 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality6 / 20
Guest Caliber7 / 20
Specificity & Evidence10 / 20
Conversational Craft5 / 20

This Intel Chat episode examines three urgent threats facing enterprise defenders. First, Cisco CUCM's web dialer SSRF vulnerability is being exploited within hours of public disclosure, using straightforward attack chains (SOAP service exposure to JSP web shell deployment) that are easily automated - this underscores the critical need for rapid patching infrastructure and automated vulnerability response. The speakers note these attack flows are foundational security concepts, making weaponization trivial for script-level attackers. Second, the updated Ransomware Tool Matrix and Vulnerability Matrix profiles of Gentleman, DragonForce, and Warlock reveal organized, affiliate-based criminal enterprises targeting MSPs and internet-facing infrastructure (Fortinet, SonicWall, Avanti, SolarWinds, Gladinet Center Stack) with BYOVD techniques and legitimate admin tools like Velociraptor and AnyDesk. Finally, Gamaredon (tracked as Aqua Blizzard, Armageddon) has matured significantly in 2025 - moving from USB-based malware to cloud-aware infrastructure using Microsoft and Cloudflare tunneling, serverless workers, and S3/Dropbox exfiltration to target Ukrainian government. The episode emphasizes baselining and behavioral profiling as detection approaches against these increasingly sophisticated but still detectable threats.

Key takeaways

  • →Cisco CUCM vulnerability exploitation occurs within 24 hours of POC release, requiring automated patch deployment and treating all unpatched systems as compromised.
  • →Ransomware groups now routinely use BYOVD (Bring Your Own Vulnerable Driver) techniques and legitimate tools like Velociraptor, AnyDesk, and cloud storage to evade detection.
  • →Gamaredon upgraded from USB-based malware distribution to Cloudflare Workers, Microsoft tunneling, and S3/Dropbox exfiltration, making network detection harder but still findable through behavioral baselining.
  • →Internet-facing products (Fortinet, SonicWall, SolarWinds, Avanti) remain primary ransomware entry points, making external infrastructure patching the highest defensive priority.
  • →Defenders should focus on baselining legitimate application behavior with trusted cloud platforms and building behavioral detections rather than assuming traffic to major cloud services is inherently safe.

Topics in this episode

Cloudflare WorkersCisco CUCM (Unified Communication Manager)CVE-2026-20230 SSRF vulnerabilityRansomware Tool Matrix (RTM)Ransomware Vulnerability Matrix (RVM)Gentleman ransomware groupDragonForce ransomware groupWarlock ransomware groupGamaredon (Aqua Blizzard, Armageddon)BYOVD (Bring Your Own Vulnerable Driver)

Questions this episode answers

How quickly are Cisco CUCM vulnerabilities being exploited after public disclosure?

Attacks began appearing within 24 hours of the proof-of-concept being published by SSD Secure Disclosure, with scanning activity detected even sooner on decoy systems.

What vulnerable products are ransomware groups currently targeting most?

Internet-facing products including Fortinet, SonicWall, Avanti, SimpleHelp, SolarWinds, SmartMail, and Gladinet Center Stack are consistently exploited across Gentleman, DragonForce, and Warlock ransomware campaigns.

How has Gamaredon changed its command and control infrastructure in 2025?

Gamaredon shifted from USB-based distribution to using Cloudflare Workers, Microsoft tunneling services, dead drop techniques on legitimate websites, and cloud storage like S3 and Dropbox for data exfiltration.

What technique did Gamaredon add to spread malware to air-gapped systems?

Ptera Paste, a PowerShell-based downloader that detects USB drives, copies malicious files to them, and appends LNK extensions to Word documents to disguise the malware.

What is the primary defense against Cisco CUCM SSRF exploitation?

Patch immediately or disable web dialer if not needed; assume all unpatched CUCM systems with web dialer enabled have been scanned, and use tools like Horizon3 AI's rapid response test to check exploitability.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode surfaces four legitimate threat-intelligence topics with occasional non-obvious observations (AI-accelerated weaponisation windows, baselining cloud traffic for anomaly detection), but the bulk of runtime is verbatim article summarisation plus filler at the start and end. Genuine analyst commentary is sparse and seldom goes beyond the source articles.

the time from when these things are disclosed publicly to when they can be weaponized is so quick that unless you're right on top of your patching, you're going to have these vulnerable moments where robots are going to come in and ponia
defenders can no longer assume traffic to trusted cloud platforms is benign and instead need visibility into normal application behavior combined with identity Aware controls

Originality

6 / 20

The framing of 'spawn-camping with AI on vulnerability disclosures' is mildly fresh, but the overwhelming majority of commentary defaults to evergreen truisms: patch faster, baseline your environment, adversaries are maturing. The AI-agent-as-'privileged junior employee' framing is lifted directly from the Varonis paper, not original analysis.

it also significantly cuts down the AM of time that it takes to weaponize it. But because of that, uh, it's an inverse lever
Yeah, I mean, all that advice I think is like, duh, uh, but I did find this article interesting

Guest Caliber

7 / 20

Two hosts who are genuine practitioners (Lima Charlie deployments, detection engineering, Black Hills training involvement) give the show credibility, but there are no external guests and the hosts' own depth of insight is constrained by the article-recap format rather than first-hand operational storytelling.

Lima Charlie is going to have a suite at Mandalay Bay, where we're going to be running training with, uh, Black Hills Information Security and, uh, the Defense Institute
I was working with JSP in SOAP back in like 2009 back when I was using a thing called SVN to do uh, code repository stuff before GitHub, uh, before rest

Specificity & Evidence

10 / 20

Specificity exists but is almost entirely inherited from the articles being read aloud: named CVEs, threat groups (Gamaredon, DragonForce, Warlock), tools (Velociraptor, Cloudflare Workers, Dropbox, S3), and the Varonis lab setup with two named LLMs. The hosts themselves contribute virtually no independent data points, metrics, or case evidence.

Pinchy searched the mailbox and forwarded AWS IM keys, database credentials, and SSH information without verifying the sender. Despite the strict profile explicitly requiring identity verification
Both Google Gemini 3.1 Pro and OpenAI Codex GPT 5.4 were evaluated

Conversational Craft

5 / 20

The format is almost entirely one host reading an article while the other responds with broad agreement and generic elaboration; there are no probing follow-up questions, no pushback, and no productive disagreement. The opening segment about a home studio ladder and the closing Black Hat merchandise pitch consume meaningful runtime.

I know you and I have also expressed our thoughts around the common naming and renaming and different classifications of groups and everything like that
I do find the usb, uh, vector really interesting because I don't even know if I have a USB drive anymore

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B52%
  • Speaker A48%

Most-used words

interesting18chris16agent15group13phishing13folks11vulnerability11article11access11threat11ransomware10cloud9cisco8organizations8services8shell8

Episode notes

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: • Cisco CUCM (CVE-2026-20230) - a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published. • The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups - The Gentlemen, DragonForce and Warlock - and the BYOVD and legit-admin-tool tradecraft they increasingly share. • Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox. • Varonis Threat Labs phishing an AI email agent ("Pinchy") - why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.

Full transcript

30 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign. How you doing today, Mr. Bromley? Hey, Chris.

Speaker B: I'm doing well, sir.

Speaker A: How are you?

Speaker B: The background is looking nice. Uh, listeners, for those of you who have been listening and following along, we know that we've been cataloging Chris's move from one studio to another. And, uh, it's looking, it's. It's looking good, Chris. Including the. I'm assuming that's a ladder, because you're putting stuff up in the background.

Speaker A: That is a ladder. Yeah. Slow and steady as she goes. Eventually, I hope to have, like, a mobile backdrop so you don't have to look at my messy workbench back there. But, uh, yeah, everything takes longer than you think.

Speaker B: We all want to see what you're working on, you and Claude, what you're getting done these days. You know, that's. That's how I frame it. To most folks I work with now, I'm like, what did you and Claude do over the weekend? And no one ever corrects me anymore.

Speaker A: But I got sign off today to do a little revitalization, uh, of an old project I did that was sort of, uh. You built what with Lima Charlie. So you, you will be seeing some content from me about, uh, detections in the garden and watering responses. So, uh, we've got some ideas about how to play that out.

Speaker B: Yeah. Folks, I would like to let all of our listeners know that, hey, if you haven't played around with Lima Charlie, Chris is the case study of, like, all the cool things you can do outside of enterprise deployments. And it's an awesome thing because Chris will deploy Limit Charlie in various places. And then it's like, as a telemetry reporting tool, it's super useful, number one. But then number two, you're like, wow, I didn't even think about that use case. And I'm going to give everyone a preview. We're not going to talk about it, but I'm going to give everyone a preview. I want you to Google Chris's name and satellites, uh, and just see what comes up, because you guys have also done a lot of discussion around satellites and space objects as well. So I'm going to leave that nugget there.

Speaker A: Yeah, I could get the sign off for that 100 grand to launch a cubesat into space. Uh, I thought it would have been a great marketing project, but, uh, not in the budget this year, so.

Speaker B: This year, notice the caveat there.

Speaker A: This year. And actually, I don't think it was even the budget that was that big a deal because, like, everybody really liked the idea. It was like, who's gonna work on it because it's a hundred grand and then probably a team of six for like six months, which is really the big cost. Right.

Speaker B: So, you know, these, these humans getting in the way of making of being successful here.

Speaker A: Yeah, yeah. Uh, speaking of humans getting in the way of other people getting successful, uh, let's, let's get to it. Attackers have started actively exploiting CVE2026 20230a critical vulnerability affecting Cisco Unified Communication Manager or CUSUM CUCM. Uh, with attacks appearing less than 24 hours after SSD Secure Disclosure published a proof of concept and complete exploit chain. The flaws and input validation vulnerability that allows an unauthorized attacker to perform server side request forgery and escalate privileges to root it affects Cisco Unified and Unified uh, CM SME deployments where the web dialer service is enabled. Cisco, which released patches on June 3, advised organizations to treat the issue as critical. Despite its CVSS score of 8.6, web dialer is disabled by default. CUCM is Cisco's platform for managing voice, video and messaging services, with the company reporting roughly 30 million users worldwide. According to the article, SSRF uh, vulnerabilities are particularly dangerous on communications platforms because they can expose internal management and application services. SSD Secure Disclosure demonstrated an attack chain that begins with a crafted HTTP request to the web dialer service, allowing access to internal services, including an Apache access SOAP search soap. Oh my goodness, what year is it? Uh, to an Apache access SOAP service. Attackers can then write a malicious JSP file into a public Tomcat directory. I'm sorry, all these technologies are like going to the beginning of my career. Yeah. Um, in a. To a public Tomcat directory, deploy a second JSP web shell, achieve remote code execution, and ultimately gain root privileges. Researchers at Defused reported seeing attacks against their decoy CUCM systems within a day of the POC's release. They had previously observed scanning activity identifying vulnerable systems before exploitation began. The attacks closely followed the publishing exploit chain abusing the web dialer. SSRF flaw to deploy a rogue Apache access service, write a first stage JSP file and install a second stage command execution shell. Diffused also noted that the password protecting the deployed web shell match the one included in the public poc. The article says organizations running CUCM with Web Dialer enabled that have not patched should assume their systems have been scanned. Horizon 3 AI released a rapid response test to help organizations determine whether their environment's exploitable without causing damage. The company urged affected organizations to apply Cisco's MITIGATIONS immediately or disable web dialer if it is not needed. The article also notes that this is the second urgent Cisco patching issue for organizations with large Cisco deployments this week following attacks targeting separate Cisco Catalyst SD WAN vulnerability. So, uh, I find this one interesting because I think it's something that we've talked about in the past and it's sort of the spawn camping with AI on these vulnerability, uh, disclosures. You know, patching is important, but like the time from when these things are disclosed publicly to when they can be weaponized is so quick that unless you're right on top of your patching, you're going to have these vulnerable moments where robots are going to come in and ponia.

Speaker B: Yeah, Chris, I think there's another component here which needs to be considered and you tapped into it as you were reading through the description, which is like, man, I mean this is not hard to automate because there is a history of these things working here. And I don't, I don't mean to be blunt about this one, but if your vulnerability is uh, exposing SOAP services and then subsequently leading to jsp web shuttles and stuff like that. I know, and I'm being a little bit facetious intentionally here, but I'm also trying to be very blunt about this here, folks. These are the types of attack chains that they practice in college classes. This is not the type of novel thing where, okay, you know, clearly a researcher needed to have like inside knowledge on how to do this. And you know, good thing someone was sitting in that exploit dev class because they needed this and that. Like, this is pretty run of the mill, um, straightforward stuff. And I'm not trying to throw shade at any, you know, developer or programmer in particular here, but I am trying to call out like, stuff like this is going to be easily and quickly and rapidly weaponized because it is such a straightforward attack flow like I would imagine. There are scanners running 24, seven that are looking for can I drop a web shell on this thing? Right? And that's kind of like the starting prompt, if you will, for lack of a better term. And there probably is some AI enablement there as well. But the starting prompt is can I drop a web shell on this thing? And how can I go about dropping a web shell on this thing? And if your method or attack technique is one or two things chained together, it creates an opportunity for very easy automation. It creates an opportunity for very easy scale. It's not that complex of a topic to try to figure out this idea of, hey, you can run a thing and you can arbitrarily upload files that you can then access. Like that's baked into like script KD101 and you know, hacker class 101 and stuff like that. And Chris, I just want to call out here that like what this does is you talked about patching schedules. Not only does it enforce the need for a very, very rapid turnaround patching schedule on vulnerabilities like this, but it also significantly cuts down the AM of time that it takes to weaponize it. But because of that, uh, it's an inverse lever. It really expands just how bad things can get in my opinion. I'm not talking about this vulnerability, just this one in particular, but the ease of being able to weaponize, the ease of deployment, the ease of exploitation coupled with just how far you can go with it is something I think organizations need to start baking into their vulnerability disclosures. Do we care about this? Do we patch now decisions. And that's one of the things that you and I have talked about on the show quite a lot has been like patch, patch, patch. We say it somewhat casually as if it's easy to just, you know, oh, click patched. All done right. But vulnerability reporting and know how and insight and risk assessment and do I need to take a thing down to patch that and so on and so forth is a decision that needs to be made with like I think a lot of urgency now because as this article points out, your ability to sit and wait is gone. I mean for some vulnerabilities it's gone. It's seconds, maybe single digit minutes at best before someone will find it and then you're on a list and then it's just rapid fire exploitation.

Speaker A: Yeah, it's definitely going to get interesting and I think the next big innovation we'll see is a way to rapidly deploy patches in an automated way. I know there's a lot of danger involved in that in enterprise environments, but it's a problem that I think needs to be solved because uh, this isn't going to go away, it's only going to get worse. Yeah, just for people listening, I was working with JSP in SOAP back in like 2009 back when I was using a thing called SVN to do uh, code repository stuff before GitHub, uh, before rest. Like this is, this is old technology so it's kind of wild to see it still being used at that scale.

Speaker B: Yeah, and that's where I uh, and I don't want to date Chris and myself here but I'm just saying, folks, if we are reciting an article's findings and we're both like, what year is it? As we recite them, trust me, it's been around for a bit. That's all I'm going to say.

Speaker A: Sacred texts.

Speaker B: Yeah.

Speaker A: All right, uh, next up, the latest update to the Ransomware Tool Matrix, or rtm, and Ransomware Vulnerability Matrix, or RVM M adds a detailed profile for three ransomware groups, the Gentleman, Dragon Force, and Warlock. Rather than providing a broad overview of the ransomware landscape, the update focuses on helping defend quickly access group specific intelligence for threat hunting, detection engineering, and vulnerability prioritization. And I'll just give a shout out to Zach Allen. This is one I pulled from his newsletter, the Detection Engineering Weekly. Always really great content. Uh, the author notes that each group represents a different segment of today's ransomware ecosystem and provides dedicated RTM and RVM profiles for each. First up, the Gentleman is described as a relatively new operation that has rapidly developed a broad toolkit illustrating how ransomware affiliate ecosystems increasingly share techniques and tools. The group's profile incorporates insights from a recent internal chat leak documenting observed tools and exploited CBEs across multiple intrusions. DragonForce has continued expanding through 2025 and into 2026 by targeting managed service providers and introducing a cartel model that allows other affiliates to participate. The group has been observed exploiting vulnerabilities affecting Internet facing products including Avanti, Fortinet, SonicWall, and SimpleHelp. Warlock, meanwhile, gained attention following exploitation of the tool shell sharp point zero day and has also been linked to attacks targeting SmartMail, SolarWinds, Web Help Desk, and Gladanet Center Stack. The update highlights several trends observed across all three groups. Bring your own vulnerability driver byovd UH techniques are now common rather than exceptional, with each group using vulnerable drivers to disable or evade endpoint detection and response products. The author also notes that Internet facing systems remain the primary entry point with products such as Fortinet, Avanti, SonicWall, Microsoft SharePoint, Smarter Mail, SolarWinds, Web Help Desk, GladNet, Center Stack, and Simple Help appearing across the threat profiles. Prioritizing patches for externally exposed infrastructure and administrative tools continues to provide significant defensive value. The author also emphasizes the growing use of legitimate administrative and remote access tools during ransomware operations. Utilities including Velociraptor, Cloudflare, VS Code Tunnels, AnyDesk Mesh, Central Free RDP Putty and Open SSH as well as various cloud services are increasingly being repurposed by threat actors. The recommendation is for defenders to use the RTM and RVM profiles to hunt for these tools, develop behavioral detections, establish baselines for legitimate use, and block software that is unnecessarily within their environments. The post also points readers to community resources such as Rulehound Detection, FY and Snap Attack to help translate the published threat intelligence into practical detection content. So, yeah, just a great source of information for folks, uh, who have ransomware is one of the things that keeps them up at night. Just, uh, kind of give you a little bit of insight into uh, what the new and cool kids are up to on the dark side of things.

Speaker B: I mean, first off, hat tip to these graphic generations. I mean, wow, Warlock, Dragon Force, the Gentleman, Bushido Token. I'm not sure where we go from here. And no offense to anyone, you and I, Chris, we've actually, we've actually looked at quite a few posts from this blog slash website before. So there's some interesting stuff there, as always. Um, I know you and I have also expressed our thoughts around the common naming and renaming and different classifications of groups and everything like that. I mean, okay, uh, I just, I just find it interesting, I think the bigger takeaway and perhaps the thing I think more focused on here is for folks who don't understand just what that community looks like, right? We are talking about criminal enterprises organized like cartels, right? Uh, affiliate based groups, uh, the types of operations that they engage in, how they kind of, you know, uh, reach levels of phases of maturity and stuff like that, you know, uh, looking at Dragon Force, right, branching into MSP focused attacks, like please understand folks, from a, from an adversarial perspective, any target which gives a one to many relationship is always going to be a prime target. MSPs, MSSPs, things like that. Um, you know, it's an old example now, but like Solarwinds is the perfect example not of a ransomware attack, but of a one to many relationship. You compromise the vendor and then you get the vendor's customer list, um, to go after that. So there's a lot of things to pivot into and to look at here. I think the other really interesting side of this is just how quickly these groups uh, move and kind of grow up. For lack of a better term. Maybe mature is the right word to have there. Um, looking at this grouping right here, you know, we're seeing uh, that the Gentleman is a newer operation, they've matured quickly, varied toolkit. Um, there's an internal chat which looks at how they work and whatnot. The CVEs that they target just a lot of really interesting information. I think that for anyone who's doing this types of, this type of CTI work can be, you know, is very useful but then also for defenders that are out there like, please understand it's a force to be reckoned with. I'm not one to cry wolf about ransomware groups because I know it plagues a lot of CISOs and budget meetings and stuff like that, but um, they are unfortunately a well organized and kind uh, of put together force that needs to be dealt with or needs to be handled correctly. And I can't say it other than like shore up your defenses because they, they know what they're doing.

Speaker A: Awesome. Uh, I realized we had the wrong copy for one of our articles here, so I'm just gonna uh, paste it in here and we'll okay, go off the the cuff.

Speaker B: Sounds good.

Speaker A: Yeah, this one looked interesting. We're talking about uh, the Russians here. Uh, Russia State sponsored Threat Group Gamer Edden game has significantly improved its tactics, techniques and procedures, according to new research from eset, making it a more capable cyber espionage threat against Ukraine and increasing the need for updated defensive strategies. Also tracked as Aqua Blizzard, Armageddon and Blue Alpha, the group has been active since at least 2013 and remains one of Russia's most active cyber operations. ESET analyzed 35 spear phishing campaigns conducted during 2025 and found that Gamer Edinburgh introduced several new malware downloaders while adopting more sophisticated methods for concealing its command and control infrastructure. ESET divides gamer Edden's 2025 activity into two phases. During the first half of the year, the group focused on developing new tooling, including six PowerShell based downloaders. One of the most notable additions is Ptera Paste, which repeatedly checks compromised systems for connected USB UH drives and attempts to copy a malicious downloader onto them to disguise the malware. It appends a LNK extension to an existing Word docum, making it appear legitimate. The article notes that Gamer Eddon has long relied on USB devices to spread malware into isolated or air gapped environments. Eset recommends limiting PowerShell usage where possible, restricting unnecessary scripting capabilities in scanning or prohibiting untrusted USB devices. The report also highlights major changes to Gamer Eden's command and control infrastructure. The group now hides malicious traffic behind legitimate services by using Microsoft and Cloudflare's tunneling services, Cloudflare workers and dead drop techniques that store hidden command and control addresses on legitimate websites. In addition, updated data stealing tools now upload stolen information to trusted cloud storage platforms such as Amazon S3, while ptora paste uses Dropbox Security experts quoted in the article warn that defenders can no longer assume traffic to trusted cloud platforms is benign and instead need visibility into normal application behavior combined with identity Aware controls to contain potential compromises. With its updated tooling and infrastructure, Gamer Reddit significantly increases the scale of its operations during the second half of 2025. ESET reports that some campaigns involve collaboration with fellow Russia's state sponsored group Chirla, with Gamer Redden providing initial access and enabled deployment of Turla's Kazoor framework. Throughout 2025, the group's spear phishing campaigns remained focused exclusively on Ukrainian government and military organizations with the objective of stealing information that could support Russia's military and intelligence operations. So super interesting, uh, I like that you know what they mention here or not that I like, but I feel like baselining your organizing organization's behavior with these legitimate web services is a way that you can start to detect anomalies going forward. I know the folks over at alpha level are doing a lot of interesting, interesting stuff there with machine learning, uh, which is, it's much cheaper than the rest of the AI scope. So um, definitely something to think about.

Speaker B: Yeah Chris, I was kind of fascinated to hear about um, the uh, level of I guess depth and kind of where this uh, you know, where this is like this, you know, the infrastructure that gets talked about here. Um, there's a lot of leaning on, I'm not going to call it modern tools but I feel like as adversaries become more and more kind of cloud, uh, cloud aware and cloud enabled, which itself is a dated term now because they've been cloud enabled for years. But this idea of you know, utilizing like cloud based storage for things and increasing versatility in different environments and targeting different apps and tapping into serverless functionality and things like that, it just, it really expands the surface for blue teamers and defenders to have to deal with here. And I can't like start without saying other than yeah, it's, it's gonna get tricky, it's gonna get tougher.

Speaker A: Right?

Speaker B: Um, this group, ah, as mentioned in the article here, has you know, typically kind of relied on USBs and stuff like that. It's been this kind of brick and mortar style thing with USB being deployed and whatnot. Um, they've now upgraded, they're utilizing cloudflare tunneling, cloudflare serverless workers, uh, you know, which essentially makes network traffic really, really hard to just profile and look for the bad stuff if you will. Um, cloud based, uh, you know, clipboard exfiltration and utilizing Dropbox and S3 and all this kind of stuff. And you know, first off, it's interesting to watch from the outside a threat group mature. But then, um, as defenders, I think when you see these types of updates, it's not a chance to throw up your hands and just be like, well, the adversaries clearly are smarter than we are. It's a chance to throw, you know, to put your hands up and be like, hey, I think we can implement defenses against for this. And one of the things that constantly comes to mind whenever I read about updated threat actor techniques is the importance of like, baselining and understanding and profiling your environment. You know what I mean? Um, is it normal for your organization to do X versus Y? Is it normal for you guys to do A versus B? And then is the adversary looking for opportunities to kind of like hide in the grass, if you will, or are they doing things that create a sure fire detection, like, no, this is bad 100% and like, lean into those. And that's my advice for defenders here. Chris and I have talked over the years about a number of different threat actors who come across as sophisticated threat actors. But when we read through the article, we'll usually find things like utilizes a registry key or startup items or PowerShell scripts or something like that. And it's like, oh, you get to a point of a least common denominator where it's like, okay, I can actually find this stuff. Um, so groups getting smarter and better doesn't mean they're impossible to find.

Speaker A: I do find the usb, uh, vector really interesting because I don't even know if I have a USB drive anymore, even though they used to be so prevalent. But I imagine in the battlefield that's a very common way to pass things around and that people, um, in those kind of environments are still using them quite a bit.

Speaker B: I have adapters for a usb, but you're right, I don't have an actual USB port anymore. And it kind of, I think if anything, maybe speaks even more to how the adversaries are changing and adapting, which is like they're dealing with this landscape of, hey, what we used to do doesn't even exist anymore. Do we just give up or do we pivot? And they pivot, they get smarter.

Speaker A: All right, last up, uh, Veronis Threat Labs evaluated whether AI agents integrated with enterprise email are vulnerable to the same phishing techniques traditionally used against human users. Using an open claw AI agent named Pinchy, researchers conducted four phishing simulations to measure how the agent handled requests for sensitive data and malicious links. The testing distinguished agent phishing, where attackers send convincing business requests through normal communication channels from indirect prompt injection, which embeds malicious instructions inside content the model processes. The researchers argue that while both target autonomous agents, they require different defensive approaches. Uh, the testing environment consists of a Gmail inbox populated with realistic enterprise data, including mock AWS credentials, CRM exports, internal communications, and calendar invitations. Pinchy operated as a dual agent system, with one agent classifying and delegating tasks while another executed actions using browsers, shell access, and Google Workspace APIs. Two security configurations were tested, a generic profile containing only productivity instructions and a strict profile that added explicit guidance to verify sender identities before performing sensitive actions. Both Google Gemini 3.1 Pro and OpenAI Codex GPT 5.4 were evaluated. The results showed that social engineering remained a significant weakness. In one scenario, an attacker impersonating a team lead requested staging credentials from an external Gmail account. Pinchy searched the mailbox and forwarded AWS IM keys, database credentials, and SSH information without verifying the sender. Um, despite the strict profile explicitly requiring identity verification. A second test produced similar results when the agent was asked to send a customer CRM export, which it forwarded externally without confirmation. However, the agent performed better in more technically focused phishing scenarios. It eventually recognized a fake gift card phishing page after initially interacting with it and successfully identified and blocked a malicious OAuth consent request by independently inspecting the destination before granting access. Based on the findings, Varonis recommended treating AI agent configuration as a security control, limiting an agent's ability to send emails to unknown recipients, restricting data access based on the trust level of the incoming request, and requiring human approval for high risk actions such as credential sharing or external data transfers. The researchers concluded that AI agents are often better than humans at recognizing technical phishing indicators such as suspicious URLs and fake authentication pages, but are considerably more susceptible to convincing social requests because they lack organizational context and instinctive skepticism. As organizations continue deploying AI, uh, agents to manage email workflows, the report argues that they should be viewed as privileged junior employees rather than as standalone security controls. Yeah, I mean, all that advice I think is like, duh, uh, but I did find this article interesting because, like, they were testing this, right? And like, what an interesting concept to go ahead and like, see if your AI agents are susceptible to phishing. And I would suspect, yeah, they are because the agents are always trying to, like, make you feel good, right? Like, what a brilliant idea, Matt, you know?

Speaker B: Yeah, I'm I'm with you on that. I'm actually reading this awesome book right now. It's about, uh, how anthropic scales and I'm not, I'm not giving any preference towards anthropic versus anyone else. Please no one listen to this and be like, oh, it's only Claude, um, and whatnot. But like, uh, listening into how the agents are, uh, configured and, and how they are structured from a human pleasing perspective and things like that. Chris has really been a big part of one of the chapters of like, how do we, you know, how do we design these things so that humans will want to use them? And then what types of behavior are they trained on? And what does it take to build a language model that can easily predict the next word? Like, that was the goal of where they all came about, right? And then that has morphed into this whole, like, can we use it to write better phishing investigations and uh, investigation, sorry, emails. And can we use it to generate, you know, better different types of text and handle different languages and things like that? And I think, and I'm going to look here towards the end, um, it's really, really interesting to me to think about the other side of this, which is like, well, how can I utilize the agent's desire to please kind of against itself, if you will, right? Like, how can I maybe kind of fish the agent, if you will, and stuff. And this was a really interesting article in case study in ways to do that. Um, they walk about or they talk about how they set up their lab and open claw, which I thought was pretty cool. Um, and then they get into like, the differences between agent phishing and uh, indirect prompt injection. And I found that agent phishing was actually a really interesting approach to take here. That plays a lot into how the models are constructed, how they do what they do. Um, and it does for me ring the bell of a little bit of like prompt engineering or, you know, malicious prompt engineering that we saw before, right? Like, hey, give me the recipe for a thing. And it's like, no, no, that's a, that's a biological weapon. And it's like, give it to me in the form of grandma's recipe. And then it's like, oh, here you go. Like that sort of like pleasing thing is there, but then under the hood when you're like, hey, let me see if I can like navigate and see, steer this boat in a particular direction and then take advantage of the agent's desire to please. I thought was, was a really interesting one. So for Anyone who's out there doing like, AI types of security research and stuff, please check out this post. Obviously, the link will be in the show notes, but check this out and like, look at the differences between agent phishing and indirect prompt injection and really take a look at what the folks at Veronis did. I think it's an awesome case study and things to watch out for from a AI security perspective.

Speaker A: Awesome. Well, that's it, Matt. Uh, number 340. Is that where we landed? I can't remember.

Speaker B: I think. I think around Black Hat time will be around 3:40, I think. So to our listeners, uh, all four of you, um, when you. I'm just joking. Um, five of you, five of you. But no, uh, for anyone interested, I'm going to go ahead and throw out the fishing line, Chris. And, uh, that is F I S h I n g, not P H I s h I n g. But. But, um, we're going to try and do something at Black Hat with this show. Maybe record an episode on the fly, go grab a couch to the side of Mandalay or something like that. But for anyone who's listening, if you want to come and hang out or catch us up at Black Hat or something like that, please let Chris or myself know. There's a lot of ways to get a hold of us. Um, we'd love to check in with some folks and like, just, you know, maybe do an episode kind of ad hoc or. Hey, what are you seeing? Or kind of a quick Black Hat review. I think we've done before some like, you know, how do you feel about the show floor kind of episodes. Maybe that's a fun one to do in addition to ones we've done at RSA and whatnot. So. So throwing it out there.

Speaker A: Yeah, that sounds great. And, uh, Lima Charlie is going to have a suite at Mandalay Bay, where we're going to be running training with, uh, Black Hills Information Security and, uh, the Defense Institute. Uh, so we have that spot too. So if you either, if you want to come do some training with Black Hat, it's free. Uh, we'll be talking about how we're using AI on top of Lima Charlie. Uh, but it's also a great space to come hang out, have a drink, talk to me and Matt. Uh, I'm going to bring a suitcase full of T shirts with me. I'll be giving those out as well. So, um, yeah, do reach out and, uh, let's connect if you're going to be there.

Speaker B: Folks, for anyone who's not taking Chris seriously. This man travels with suitcases worth of worth of swag. All right, so take him up on that offer. I'm telling you, it'll be worth it.

Speaker A: Yeah. Awesome. Okay, sir, we'll, uh, see you next week.

Speaker B: Take care.

Speaker A: Yeah. Bye.

Speaker B: Bye.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Cloudflare devs @ AI Engineers Europe (Sunil Pai, Matt Carey & Thomas Ankcorn)Scaling DevTools · on Cloudflare Workers77 / 100
  • Rita Kozlov and Steve Faulkner - Cloudflaredevtools.fm · on Cloudflare Workers70 / 100
  • CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must KnowCISSP Cyber Training Podcast · on Gentleman ransomware group68 / 100
  • Why the Next Big App Might Be Built by an AI AgentThe Connectivity Cloud Podcast · on Cloudflare Workers57 / 100
  • Episode #64: Everything is Code - AI, Cloud & The Future of DevelopmentThe RaaP: Resourcive as a Podcast · on Cloudflare Workers54 / 100
  • 360: And you thought AWS was out of features for S3. Surprise!The Cloud Pod · on Cloudflare Workers53 / 100

More from The Cybersecurity Defenders Podcast

All episodes →
  • The evolving fraud landscape in the age of AI with Tamas Kadar [#334]
  • Anthropic restriction, ServiceNow incident, Fortinet credential harvesting & Ukraine accesses EU cyber reserve / Intel Chat [#333]
  • Last call for Defenders - How we're actually using AI in the SOC with Eric Capuano / Defender Fridays [#332]
  • FFmpeg's 21 zero-days, Ruby cooldown feature, Microsoft disrupted by Shai-Hulud worm & Meta AI tool compromise / Intel Chat [#331]
  • AI-assisted SOC training with Carlo Anez / Defender Fridays [#330]
Explore the best B2B Engineering & DevTools podcasts →
All The Cybersecurity Defenders Podcast episodes →