The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/UnHacked
UnHacked artwork

AI Ran Its First Solo Ransomware Attack in 30 Minutes Flat | UnHacked Ep. 102

UnHacked · 2026-09-08 · 38 min

0:00--:--

Key moments - from our scoring

Substance score

55 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber12 / 20
Specificity & Evidence13 / 20
Conversational Craft10 / 20

The Jade Puffer ransomware attack represents a watershed moment in cybersecurity, though not for the reasons the headlines suggest. Rather than AI going rogue, threat actors deployed an LLM against a pre-identified target with known vulnerabilities, achieving in 30 minutes what typically takes human attackers hours or weeks. Security firm Sysdig documented how the AI-driven attack bypassed firewalls, mapped the network, launched payloads, and encrypted drives while continuously adapting its code to evade detection. The real story, however, involves preventable human failures: an unpatched Langflow instance exposed to the internet, default MySQL credentials unchanged since 2020, and zero password management. Hosts Justin Shelley (Phoenix IT Advisors), Mario Zaki (Mastec IT), and Joshua Holloway (70i Technologies) emphasize that foundational security controls - patching, credential rotation, network segmentation - would have stopped this attack. The concerning trend is speed compression: detection windows have shrunk from weeks to 15-30 minutes, forcing organizations toward more automated defensive responses. The attack proves the skill floor for sophisticated attacks is dropping as LLMs democratize cybercriminal capabilities, but reinforces that every major breach so far has exploited known, patchable vulnerabilities.

Key takeaways

  • →The Jade Puffer attack achieved full ransomware execution in 30 minutes by exploiting a known vulnerability (CVE from over a year prior) in an unpatched Langflow instance with default credentials unchanged since 2020.
  • →AI didn't act autonomously or go rogue - attackers pointed the LLM at a pre-researched target with already-compromised credentials, and the AI executed faster than humans could, making speed the primary threat vector.
  • →Standard security hygiene remains the primary defense: patching production systems immediately, changing default passwords, not exposing unnecessary services to the internet, and rotating credentials quarterly.
  • →Detection windows have compressed from weeks to 15-30 minutes, requiring organizations to shift from reactive to proactive automated defensive systems and centralized security tools rather than fragmented point solutions.
  • →LLMs trained on published CVE databases and MITRE ATT&CK frameworks are learning human defensive patterns at machine speed, making vulnerability disclosure and patching velocity critical to staying ahead of automated attacks.

Guests

Joshua HollowayMario Zaki

Topics in this episode

LLM (Large Language Models)Network segmentationCVE vulnerabilitiesZero-Day VulnerabilitiesRansomware encryptionCyber SecurityhackingData BreachJade Puffer ransomware attackLangflow (vulnerable application)MySQL default credentialsMITRE ATT&CK frameworksSysdig (security firm)

Questions this episode answers

How did the AI-powered ransomware attack in the Jade Puffer case work without human involvement after the initial deployment?

Threat actors deployed an LLM against Langflow, a known-vulnerable application exposed to the internet, with default credentials unchanged since 2020. Once given the target, the AI autonomously exploited the vulnerability, mapped the network, adapted its code on the fly to evade defenses, encrypted drives, and completed the entire attack in 30 minutes - but humans selected the target and vulnerability upfront.

What specific vulnerabilities and misconfigurations allowed the Jade Puffer ransomware to succeed?

The attack exploited an unpatched Langflow instance running in production, default MySQL signing keys that had shipped unchanged since 2020, and exposed credentials previously compromised in earlier breaches. The system was publicly facing the internet and had not been updated despite a known vulnerability being published over a year prior.

Why is the speed of the Jade Puffer attack more concerning than traditional ransomware attacks?

Traditional attacks take hours, days, or weeks as humans manually probe systems, but this AI-driven attack compressed the entire kill chain into 30 minutes. Security experts warn detection windows have shrunk to 15 minutes, making automated response systems and proactive patching more critical than reactive alerting.

Does the Jade Puffer attack prove that AI is now autonomous and unstoppable in cyberattacks?

No - the attack demonstrates faster execution of known techniques, not autonomous decision-making or capability beyond human-designed exploits. Humans remain essential for target selection, reconnaissance, and vulnerability research; the LLM simply executes faster at machine speed.

What fundamental security measures would have prevented the Jade Puffer ransomware attack?

Patching the Langflow instance to the current version, changing default MySQL credentials from their 2020 defaults, removing unnecessary services from internet exposure, and credential rotation would have stopped this attack completely.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode unpacks the Jade Puffer ransomware attack with useful specifics (30-minute execution, Langflow vulnerability, default MySQL credentials from 2020), but much of the discussion circles back to basic hygiene (patching, password changes, immutable backups) that the hosts themselves acknowledge has been covered since episode 4. The core insight - speed enabled by AI, not autonomous AI - is valuable but not deeply novel for security practitioners.

this was not AI gone rogue. Somebody got the tools, they discovered the target, they knew the vulnerability, and they pointed AI at it, and AI knocked it down like super fast
it still has to exploit known vulnerabilities that we still have the ability to patch

Originality

9 / 20

The hosts correctly debunk the 'AI gone rogue' narrative and distinguish between autonomous execution and targeted direction, which is a useful clarification. However, the framework - that attackers use better tools faster, and that fundamental security controls remain the answer - is standard industry thinking. The tangent about MSP malpractice is more original but derails from the main topic.

the speed of service of this is huge because most hacks take time
now free basically. You don't have to go to the dark web. You just need an LLM and you take the guardrails off

Guest Caliber

12 / 20

The three speakers are MSP operators (Mario Zaki at Mastec IT, Joshua Holloway at 70i Technologies, Justin Shelley at Phoenix IT Advisors) with hands-on experience managing compliance and security for small-to-medium businesses. They bring practitioner credibility, but none are known researchers or architects of large-scale infrastructure; they're mid-market operators discussing an already-published incident rather than breaking new ground.

Mario Zaki, CEO of Mastec IT, located in New Jersey, about fifteen minutes outside of Manhattan. we help small to medium sized businesses stay secure
Joshua Holloway. I'm the CEO for 70i Technologies. As always, we're an MSP that's built around helping businesses that operate under a compliance

Specificity & Evidence

13 / 20

The episode names the attack (Jade Puffer), the vulnerable software (Langflow), the CVE timeline (default keys unchanged since 2020, vulnerability published over a year prior), the execution window (30 minutes), and the core failure (default MySQL credentials, unpatched production system exposed to internet). Notably missing: the name of the victim organization, the actual CVE number (Justin couldn't recall it), specific data exfiltration proof, or concrete dollar figures on the ransom attempt.

So it broke in, it mapped, it constantly changed or updated its own code
Langflow. Okay. So that's a development tool. It's a production server running MySQL. they the attack used default signing keys that had shipped unchanged since 2020

Conversational Craft

10 / 20

The hosts engage each other naturally and challenge soft claims (Justin fact-checks Mario's episode 4 reference; they debate whether CVE publication helps or hurts defenders). However, follow-ups are often surface-level, tangents sprawl (quantum computers, doctor analogies, MSP pricing), and the segment on the customer's MSP situation, while illustrative, isn't directly interrogated with probing questions about technical root cause. The pacing prioritizes anecdote over drilling down.

I'm gonna point out that we are not in iRobot yet
Or or the article you read was put out by a vendor who does exactly what you're saying should be done, which is actually the case

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

justin87shelley87joshua70holloway70mario63zaki50security18saying17attack16josh15tools15point14software11money10back10change10

Episode notes

Hosts: Justin Shelley - Mario Zaki - Joshua Holloway - AI didn't go rogue and hack a company on its own. Someone pointed a jailbroken AI at an unpatched server, and it finished a full ransomware attack in about 30 minutes. Security researchers at Sysdig just documented the first fully autonomous, AI-driven ransomware attack, nicknamed "Jade Puffer." No human touched a keyboard once it started. It broke in, mapped the network, rewrote its own code to dodge detection, and deployed ransomware, start to finish, faster than most security teams could even get an alert out. Experts are now saying the response window for an attack like this has shrunk from hours to as little as 15 minutes. Justin Shelley, Mario Zaki, and Joshua Holloway break down what actually happened, and why the scary headline ("AI attacks company, no humans involved") is only half the story. The real vulnerability wasn't AI. It was a production MySQL server exposed to the internet, running unpatched software with a known critical flaw, and a default signing key that hadn't been changed since 2020. The AI didn't discover some brand-new weakness.

Full transcript

38 min

Transcribed and scored by The B2B Podcast Index.

Justin Shelley I think I need some Stevie Wonder glasses if I'm gonna do that. Mario Zaki Mm-hmm. Joshua Holloway yeah, absolutely. Justin Shelley shit.

Welcome everybody to episode 102 of Unhacked. Mario, Josh, appreciate you guys being here. listen, I'm not even gonna get into any of the topics or anything. Let's go straight into some brief introductions.

Then we're gonna dive in because today is a very intriguing episode. I'm gonna do my little evil Hand motion laugh. Mario Zaki Fingers. Justin Shelley Well, I have an evil laugh, but I'm embarrassed about it.

So I'm not gonna do that on the air. 'cause Joshua Holloway Yeah. Justin Shelley it's probably not as cool to other people as it is to me. I used to do that in front of my kids.

They didn't think it was cool either. So I'll withhold. Let's do introductions. Mario, then Josh, then I'll I'll say something.

I don't know what. Mario, who are ya? Mario Zaki Yeah, Mario Zacki, CEO of Mastec IT, located in New Jersey, about fifteen minutes outside of Manhattan. we help small to medium sized businesses stay secure, operate on a regular basis, and we specialize in helping business owners sleep better at night, knowing that their business will be there the next morning.

Justin Shelley Josh? Joshua Holloway And I'm Joshua Holloway. I'm the CEO for 70i Technologies. As always, we're an MSP that's built around helping businesses that operate under a compliance and have to do all that fun paperwork and policy writing and make sure your technology works with you.

So we're here to help you do what you need to do so that you get to make money, but we're also helping to make sure that your compliance Justin Shelley Beautiful. And I'm Justin Shelley, CEO of Phoenix IT Advisors. And if after a hundred and two episodes, you don't know who I am. You don't deserve to know.

So we're just gonna move on. Today, guys, we have the biggest headline of all time. AI has been out there scaring everybody senseless. Today, I'll buy it's lonesome.

It executed its first ransomware attack. not today. This happened July f what was it, Josh? You're the expert here.

Joshua Holloway It was around July first that it was discovered. Yeah. Justin Shelley July first, that's what I thought. Yeah.

You're the expert. Well, you're the one that proposed the topic, anyways. so without any ado whatsoever, let's talk about Josh. I I gave you a task that I don't know if you're up for or not, but I'm gonna start a timer.

And I said I want you to describe what happened in two minutes or less. Ready? Go. I don't really have a timer, but anyways.

Joshua Holloway I was just about to say we had our first fully automated AI driven ransomware attack from start to finish. No humans were included. Done. Was that what you're looking for?

No. Justin Shelley There it is. Beautiful. Yeah, that was that's Mario Zaki Ha ha ha.

Justin Shelley brilliant. All right. So guys, we've seen iRobot, right? Like I always keep going back to that movie.

Will Smith, you guys familiar? Joshua Holloway Uh-huh. Mario Zaki Mm-hmm. Justin Shelley Okay.

Well, I'm old, so I don't know. I I don't think the younger generation has seen that movie. it it's here, right? The robots have taken over, they're doing stuff, start to finish, as you said.

but Josh, let's go ahead and do the two minute and fifteen second version and Tell us like what happened and how it happened. Joshua Holloway Yeah, so basically what we happened, we have threat actors that kicked off an LLM that was given a task to perform its own attack against a system. It was uncovered by a security firm called Sys Sysdig, and they completely categorized an attack where an LLM attacked a company, figured out ways to get in, as it bypassed the firewall and got into the network, it mapped the network, and then it launched its payload, ransomware an entire drive, and closed out.

Now, the biggest thing is is is the speed in which it did it. So all of you guys, you all know, right? Like we have systems set up so that certain things alert sometimes LLMs are alerted that grab humans, right? So the speed of service of this is is huge because most hacks take time, right?

So let's digest what an actual hack you know, its time frame looks like. They get in, they poke around, they use some pre architecture based software that they probably bought off the dark web. They poke, but they do it very slowly because they know that they can't change anything on the fly. And they start to feel and map and see what they could do.

This all takes time, right? It takes hours, sometimes days, months, weeks and years. What this new attack, which is being coined as Jade Puffer. so I'd say like a you know, like a puffer fish.

Justin Shelley Where yeah, where do they come up with these stupid names? Joshua Holloway I mean it's it Mario Zaki Yeah. Joshua Holloway it's technology guys coming up with cool names for things that they just don't know how to how to label. So it's like, yeah, let's Justin Shelley Cool.

You use the the technology guys and cool in the same sentence. Go on, Josh. Wishful thinking. Mario Zaki Guy was guy guy was probably just looking Joshua Holloway Yeah.

Mario Zaki at his fish tank like five feet away from him. He's like, let's just call this puffer, you know. Joshua Holloway Yeah, exactly. Well, and I I think the idea behind the puffer is the fact that its speed of service was something we've never seen before.

So it broke in, it mapped, it it constantly changed or updated it its own code because it could, versus anything that's hash sign or anything like that. Our security tools look for hash signs, other other things. They could change it on the fly. But if you think about a puffer fish, right, you go from Zero to a hundred real quick and all of a sudden it's really big, it's expanding, and it's deadly.

So that idea is the same thing that took place here. Yeah. Justin Shelley Probably AI. AI probably came up with that term.

Joshua Holloway Probably. It it's probably the same a AI that did it. And it's like, I want to Justin Shelley Yeah. Joshua Holloway be known as the Jade Puffer because that would be super cool.

No, but I think the the the biggest thing to to take away from this is it did everything in a 30-minute window. And a lot of experts are saying our window has now shrunk down to 15 minutes. For us to receive some kind of notification and act. And I think what's changing for us now is we need to have more automated systems slamming doors close.

I think the other problem too is a lot of our systems are disjointed, right? We buy a firewall from s one manufacturer, not gonna name any, right? Then we get our A V or some security software from another manufacturer. You know, and then we get another security tool from another manufacturer and and it's kind of like disjointed.

I I think the idea here is looking at this attack that we have to get away from a disjointed environment and kind of start to maybe more centralized. But I wanna hear your guys' thoughts. Justin Shelley Or or the article you read was put out by a vendor who does exactly what you're saying should be done, which is actually the case. Joshua Holloway Or yeah.

Or Mario Zaki Mm-hmm. Justin Shelley Mario, what are your thoughts here? Mario Zaki I mean it it pretty much what it did is it it just you know eliminated humans, it sped up what a a normal human could do. But the underlying security that you would we would have used to protect from, you know, something six months ago or a year ago or two years ago, it's still in play, you know, like patching, you know, making sure all your stuff is up to date, making sure you're s you know, you have security in place.

you know, application whitelisting, you know, stuff all that stuff would have at least from what I read would have still been able to prevent or reduce the amount of issues that this this system would have attacked. You know, it it is like a you know, it's like a burglar getting to a house. He's checking every window until he finally finds one that's open. But this this system is literally just checking a lot faster.

Justin Shelley So, all right. Joshua Holloway Yes, within milliseconds. Justin Shelley I'm gonna I'm gonna I'm gonna throw some stuff out there. And correct me if I'm wrong.

but first and foremost, this was not AI gone rogue. That's the headline that keeps getting put out there. AI is doing this end to end, no human involvement whatsoever. Horse shit.

Somebody got like, and you've you said it, Josh, right? Like, somebody got the tools, they discovered the target, they knew the vulnerability, and they pointed AI at it, and AI fa knocked it down like super fast. So speed is the number one issue. the fact that it can self like it lost credentials and then within like the 30 seconds, I think it was, it was able to get logged back in.

but the main point here that I want to make is this was a known vulnerability that had been published over a year ago. It was an unpatched system that was exposed to the internet. Joshua Holloway Mm-hmm. Justin Shelley Right?

So And and Mario, I'm glad you brought that point up because this is still what I what I keep seeing over and over with all the fear and the hype around AI attacking things so far, anyways, it still has to exploit known vulnerabilities that we still have the ability to patch. Yes. Joshua Holloway Yes. Mario Zaki Correct.

Joshua Holloway And and and Justin Shelley Okay. Joshua Holloway Mario brought this up last week where I think this is a huge key point that we need to bring up again too. And and it's we are showing the hackers and the attackers what those patches are by putting out zero day notices. And I'm not saying we have to stop doing that, right?

But I'm but I am saying that we are giving them the keys to the kingdom, the where they can get these C V E's and they can go searching for this stuff, which means we need to be patching faster. The other the other thing to it The LLMs are being trained on all the information that we post out to the internet, which means all the MITRETAC frameworks, all of the different, you know, scenarios and different things that we would use to combat a lot of these attacks. It's learning off of that.

And then at its own speed, which is system-based speed. It's no longer human-based speed. At system-based speed, which is far faster than the rest of us can move, it's it's learning all of those tricks and trades, and it's now starting to build its own path through, knowing how we would typically block it. So again, Justin Shelley Go.

Joshua Holloway us being good is push is is getting us in trouble. Justin Shelley I'm gonna point like because we have this has come up a couple of times. This idea that we shouldn't, or maybe we shouldn't, or or maybe it's a problem that we publish these C V E's, right? For what are if you know, common vulnerabilities and exploit exploit exploitations, exploits.

Vulner What am I saying? Anyways, I I knew I was I know I was gonna blank on Mario Zaki TVs. Justin Shelley that. I looked it up because I like it's a stupid name.

There's a lot of stupid names out here, and and that one I can't get to stick in my head. But These are not published so that the bad guys can exploit them. I would argue the bad guys already have this stuff. It's called the Dart Web.

They can they've got their own databases of all the exploits. What this does, in my opinion, it doesn't teach them anything. It levels a playing field. It makes it so that guys like us have a fighting chance because you know what we don't do all day long is sit around and find vulnerabilities personally.

Like I don't personally go out and try to break into the networks. But Now we have a catalog of like 300,000 different ways that the bad guys do. So I love CVEs. I I I hope they never go anywhere.

I hope that the the only real problem with them is that there's 300,000 of them. Am I getting that number Mario Zaki Mm-hmm. Justin Shelley right? As I again, I looked that up too, but it's it's crazy.

but we also have tools that will go in and and take all the CVEs and apply them to our systems and show us where they live and and what needs to be done to patch it. So I will not blame AI for this. I will not let AI take the the dirty hit. Some company out there had a production environment.

what was the name of the the software that they exploited? because it's it's C V E 2026. I looked up a different one. Never mind.

God damn it. I had all my notes ready and then we started recording and they all I blew them all out. Somebody help me out. What's what's the what's the software they exploited?

Anybody? anybody bueller? Bueller? Landflow.

Langflow. Joshua Holloway I don't remember off the top of my head, hold on a second. Justin Shelley Langflow. Okay.

So that's a development tool. It's a production server running MySQL. they the attack used default signing keys that had shipped unchanged since 2020. So six year old default keys.

Like everything that could go wrong went wrong here. And and this was preventable stuff. So that's if if we get nothing else from this conversation, I wanna point out that we are not in iRobot yet. I'm not saying we won't get there, but so far it's still bad guys that just have better tools.

And by the way, us good guys also have better tools. Mario Zaki My qua what I wanna know is how why did the L L target these guys? Like w did the hacker it so they did they did. Justin Shelley 'Cause the bad guys pointed it at them.

It wa it was it was a targeted attack. This was not that's what I'm saying. This was not autonomous. This was not AI acting on its own th this was targeted.

Joshua Holloway It was pointed from the f the fat the point that it was pointed at that direction, it ran autonomously. So somebody bait ba gave it a job. Justin Shelley Correct. Once it got in, it it was able to be intelligent, right?

That's the whole point. And and go ahead and get its job done. But also the credentials that were used to get into the sequ MySQL database were not compromised from within the network. Those those were already obtained in a previous breach of some sort.

So Mario Zaki Yeah, so Justin Shelley this this was a multi-step, it happened over time. it was researched, it was targeted. It's just that once they had all the ammunition. lined up the target and pulled the trigger, it happened super fast.

Mario Zaki Yeah. No, I I think we're we're getting to a point where we're we're definitely gonna have to you know fight fire with fire or AI with AI. You know, I I think I I I think security is still in play here. It's not something Joshua Holloway Mm-hmm.

Mario Zaki that is gonna go away. We you know, we're not working with like old technology. It it's still what we've been preaching about for a hundred and two episodes. That's still in play.

Everything that you need to to do, no matter if it's against a AI, against a human, against a team of hackers, it's still the same security measures at the moment that has you know, has to be patched. It, you know, computers that don't need to be facing the internet, take off. If they need to be facing the internet, you you know Justin Shelley Or if they are, patch the hell out of them. That's that's kind of what I'm saying.

This was a publicly facing system that hadn't been patched with a known vulnerability, severe or critical, I think, was the level. Like this wasn't just a minor thing that had gone unpatched for over a year. Like if you're gonna point that stuff at the internet, take care of it. Joshua Holloway Well, and I think there's a different thing that we should be looking at too is take all of our security tools out of the equation for what took place, right?

The vulnerability was a compromise password, default password for a piece of software. Justin Shelley Yeah. Yeah. Joshua Holloway So, right off the bat, take all the security out of it.

That human setting up that service was I hate to say it, lazy. Mario Zaki Stupid. Joshua Holloway lazy and didn't update the password. And I I think this is where it's super important for business owners who who kind of like set it and forget it.

They let their IT do whatever their IT does and because it works, great. You know, it responsibility falls on upper management here to start asking those questions. Like have we truly done everything that we are supposed to to be secure? Have a plan.

I'm del I'm deploying a new piece of software. Okay, well I'm not going to have the same default password. Guys, raise your hands. How many of you c you know, leave the default password, right?

None of us do. Justin Shelley Anytime I need to work on a MFP multifunction printer, right? The big copiers, Joshua Holloway Mm-hmm. Justin Shelley printers, scanners, anytime I can Google the password on those things.

I've I've I think once or twice in my career seen that changed. And I'm Mario Zaki Correct, same here. Joshua Holloway Well Justin Shelley it doesn't sound like a big deal until we talk about all the the IoT stuff that you know, where they're going in and they're finding these devices, these smart devices, and then they're hijacking them. Or they're getting in and they're pulling information off a hard drive because guess what?

People, printers have hard drives and it stores everything you send to print or scan. So now that you've got PHI or or P I I any any kind of protected information that you're printing, scanning or or storing through their printer, that's that's all publicly available. Joshua Holloway Right. Yeah.

So I think biggest thing is is installing anything, be it a printer, copier, piece of software, change the passwords. And don't just change it once. Change it quarterly, biannually, whate whatever it works out for you. You know, th that that's just simple stuff right there before you tack on the security software.

Justin Shelley Right. No, this absolutely this was preventable. What like what I used to always say, preventable with basic security measures. And then I quit saying basic because it is really pretty complicated.

But not this. This was actually really simple. All they had to do is update the software to the current version. Period.

Mario Zaki Yeah. And and change passwords. Joshua Holloway changed the Justin Shelley And change a password. Joshua Holloway password.

Well, and I think the other thing go ahead, Red. Justin Shelley No, just you this is we shouldn't have to say this stuff. Like this is stupid. We we should not be having this episode.

Mario Zaki Yeah. honestly. Justin Shelley One two deleted. We shouldn't even be here today.

Good God. Joshua Holloway All right, everybody. Have a good one. Mario Zaki Yeah.

W we we we could liter honestly that's it. We could wrap this up because it really this is not something you know, the the biggest high you know, thing is how fast they were able to do it because they used the AI. You know, we all know they're everybody's now using AI. You know, we've dedicated months, you know, of the show talking about how you could use AI.

You know, we're not the only ones that h know the secret that, you know, AI makes things easier and faster and you know, Whatever, you know, like it it it hackers are using the hackers are probably using it before any of us were using it. Joshua Holloway Well, and here's a couple of things you know, on this trajectory of how is attack, I think we should also talk about two. One, Mario, you just hit it, right? Attack speed will continue to outpace human response time.

So we need to be doing everything we can upfront to mitigate this as much as possible. Today's the day AI will be used to target multiple multiple organizations simultaneously. This is not the this is a proof of concept, right? They they they pointed Justin Shelley Yeah, absolutely.

Mm-hmm. Joshua Holloway the gun, they pulled the trigger, they made a proof of concept of how AI fully driven attacks, we can all download an LLM and take the guardrails off. Like we'll there's been multiple conversations here in this podcast as well that show that we have the capability to download a model and take off the guardrails and do things just like this. And they're becoming more and more sophisticated.

The attack chain, I think, is gonna be more adaptive, right? This also proves AI is gonna be super adaptive. It's gonna change its code, it's gonna change the way it looks, making it difficult to block. And then here's the scarier one.

We used to deal with this a long time ago when people found the dark web and then they realized for two dollars and thirty cents they could buy malware. Well, the skill floor for launching a sophisticated attack has now it's dropping even further, faster because they don't even have to go to the yep, Justin Shelley Yeah. Yeah. It's now free basically.

Joshua Holloway yep, pretty much. You don't have to go to the dark web. You just need an LLM and you take the guardrails off and then start having fun. And it's just a conversation at that point.

Justin Shelley Yeah. And and this w just is off topic, but just an interesting note about this one. it was a ransomware attack, which the the point of ransomware, if you don't know by now, is you get money and then in exchange for the money, you hope to get your stuff back. they encrypted it with a key that was never stored, never like it there was no way of ever getting the their data back.

So this The AI was a little clumsy there, or maybe they didn't care. I don't know. But I will say, you know, this is something I used to talk about in the early days of of ransomware discussions. the bad guys have to have good customer service or their business model blows up.

If they don't give your Mario Zaki Mm-hmm. Justin Shelley data back, then we stop paying them. And people are still pretty good about paying. So in this case, they're kind of shooting themselves in the foot.

And and maybe, while you're right, Josh, the floor's kind of dropping out and you can get fucking idiots out there now. running these attacks. It used to require a level Joshua Holloway Mm-hmm. Justin Shelley of intelligence.

Well now they're they're they're they're gonna ruin their industry if they don't clean up their act, right? Like, come on, bad guys, up your game. Jesus Christ. Did I s did I say that live?

Mario Zaki No, I I think I I Joshua Holloway Ha Mario Zaki I I I Joshua Holloway ha. Mario Zaki think I think it's like what you're saying we I said earlier. This is a targeted attack. It was probably a former employee or a competitor and he's like, Justin Shelley Maybe, maybe.

Mario Zaki you know what? I don't even want Joshua Holloway Ooh. Corporate espagnage. Mario Zaki I yeah, I don't want money.

I just want these guys to to not operate or to to really be hurt. You know, it doesn't you know, he would have I I'm sure if he w his whole point was getting money, I'm sure he would have been able to get money. Justin Shelley Well, but it was the AI agent that was making its own decisions that encrypted things, printed the key out like on a console screen or something, and then made claims about how, you know, we'll we'll be able to get your stuff back. Also said that it had exfiltrated data, which they can't prove that did or didn't happen.

So it was this that this is where the AI agent did kinda go rogue, but not in the bad guy's favor. Mario Zaki Now why can't we use AI to unencrypt the stuff? Joshua Holloway It's good question. Has anybody tried?

Justin Shelley that's quantum computers. We're on the wrong subject. because they will. With with quantum computers are that's that's kind of the fear with them is they'll they'll decrypt anything.

Joshua Holloway But yeah, quantum computers c encryption no longer exists. Justin Shelley Correct. I mean they're working on it. I've I I can't talk intelligently on the subject.

I've just asked enough smart people enough questions that I'm comfortable saying that I think there's a solution potentially in place. Maybe perhaps one day. That's how confident I am in it. but it is a Mario Zaki Well, you broke up on my side w within how long?

Justin Shelley I don't know. Did I break up or did I just not say? soon Joshua Holloway Yeah. Justin Shelley nobody knows, Mario.

How how fast until the next Fable 5.1 just dropped, I think today. I don't know. It just popped up on my thing saying, Hey, you got a new thing, a new toy to play with.

Yay. I don't know. Joshua Holloway Yeah. Justin Shelley I mean, it it's it's the race.

The, you know, is are the Chinese gonna get quantum computers before us, or vice versa? Because that's the game. We've just got another. Cold War almost going on here.

That one's scary. I we haven't even talked about quantum computers. That one is actually really scary. I'm more afraid of that than I am of AI, honestly.

Mario Zaki Yeah. But it Justin Shelley Anyways. Mario Zaki will be it will be very soon, I think. Justin Shelley Which?

Quantum? I mean, yeah, they've they've those proof of concepts are there. You can actually yeah, I don't know. We maybe should have an episode on quantum computers, 'cause I'll need to do some research before I say anything publicly.

But Mario Zaki Yeah. Justin Shelley it's sketch. Joshua Holloway Maybe find a guest that can attend to to talk about it. Justin Shelley That that actually we should probably do.

Yeah. Joshua Holloway Like melt our brains. Justin Shelley Yeah. Mario Zaki Mm-hmm.

Justin Shelley All right, guys. I promised we were gonna keep this one a little bit shorter today, so let's go ahead and did we miss anything first of all? Bueller? No.

Joshua Holloway No, the only thing that I think that was missed is in a part of this attack, all of the the backups were also detected and blocked. And I think that's another thing we probably want to hit on is having intelligent backups. Backups that are immutable that can't be changed. That that's Justin Shelley Immutable.

Yeah, they've got to be immutable. Joshua Holloway they gotta be immutable. They can't be changed, they can't be messed with. and they can't be, you know, the backup appliance can't be attached to the domain or it can't be in the same network.

It can't be easily found. You know, so there's a lot of different things to that too, because it's it's it's learning it. But Mario, what do you got? Mario Zaki Yeah, again, shit that we've been talking about for like from like episode like four, you know, like stuff you know Justin Shelley I know.

Yeah, this is not new. Mario Zaki these guys i if everything we've discussed and what we've read is true, then these guys deserve to to to really get effed like this because you know, it it's it's security one one, you know, like it it's everything everything that we're talking about, backups and security and passwords and patching and stuff like that, come on. You know, like w i it's twenty twenty six, almost twenty twenty seven. You know?

They deserve it. Justin Shelley Episode four. Now I'm I'm fact checking your ass just randomly. I'm like, what did we talk about on episode four?

Joshua Holloway Ha ha Justin Shelley A day in the life of a CISO. That's what that one was. And it's before Joshua Holloway shoot. Justin Shelley your time, so you don't even know, Mario.

You weren't on episode four. You started eight. Mario Zaki Well, I was a I I was a l I was a listener back then. Justin Shelley Okay, okay, fair enough.

Fair enough. Joshua Holloway No, I like that. Well, and the the other thing Justin Shelley Alright. Joshua Holloway I want I I wanted to bring up with you guys, and I know you wanted to make it short today.

but we are, you know, this is a podcast for business owners and things like that. And one of the other things I want to talk about is I got a horror story if you guys are interested. And yeah. Justin Shelley Mm.

That's right. You tease us with that and then almost left us hanging. What do you got, Josh? Mario Zaki Yeah.

Joshua Holloway Yes. So I got a a horror story. and we're just weren't it's just an MSP that I know about. And somebody had reached out to us because basically they were freaking out because their data is hosted and there's a legal battle between the MSP and one of the other owners of another of the of the MSP where they they it was an MA, and MA later fell apart and everybody's fighting.

So they reached out to us through a referral. Thank you for the referral. and they were super afraid of What's happening to their data? They haven't been getting things taken care of.

And when I say getting things taken care of, I mean months. So vulnerability scans were given to the owner of the company that reached out to me. Vulnerability scans been sitting there for months. Nothing done about it.

Her her VPN had a SSL certificate issue, so they couldn't, they could barely log in with SSL cert for their VPN, not getting taken care of. Simple fixes, right? But because the MSP inner fighting with each other, one side's trying to help her. The other side's saying, well, like we'll help you, but to help you, you need to do all these things and pay all this money and or we're not going to do anything.

And it's like she doesn't they don't know who are they paying to get what done. They don't know where their data resides, what the passwords are are. And then here's where all of a sudden it turned it got on fire yesterday. They called me up freaking out because they received their invoice.

On the first, they received a letter yesterday on the second stating their services are being discontinued. And if they want to keep their say their their services and and their VPN has been disabled. If they want to keep their services and get access to their VPN, to their software, to their services, to this stuff that they own, they need to come current immediately, which you've had an invoice for 24 hours. It's the only open invoice.

I did double check. It's the only open invoice. Everything's turned off. She's like they're freaking out.

We we can't. yeah, yeah. No, I told her. Justin Shelley Call an attorney.

You know this already, right? Okay. Joshua Holloway I was like, call call you know, call an attorney. But but it's like Justin Shelley Immediately.

Joshua Holloway they couldn't work. And then the other thing is, is I got wind of a couple of quotes, $44,000 quote, quote to do some other things. They're basically giving that company until the ninth or the tenth of this month to decide which quote they're they're going with to maintain services or off board. Which to me I know what the easy answer is because like why would you want to do business with an MSP Justin Shelley Yeah.

Joshua Holloway that's holding you ransom at this point? But I w Yeah. Justin Shelley Basically it's the same thing, yeah. Mario Zaki Yeah, I was about to say what's the difference between this and and what we talked about earlier?

Justin Shelley It's a ransomware attack. It's nothing. And it's illegal. Joshua Holloway Yeah.

Yeah. Well, of course, I was like, hey, I know you haven't signed with us. Call your attorney, give them your your your master service agreement, figure all that out because like what they're doing is not right. And at least protect yourself there.

But I wanted to bring this up because I think I've heard of this a couple of times in in my area where MSPs do really crazy things off the wall like this, where they they Hold on to the passwords and refuse to give them over while the ship is sinking. You know, or they Justin Shelley Mm. Mm-hmm. Joshua Holloway are essentially holding the gun to your head saying, Pick which thing you want to do that's gonna cost you a huge amount of money that you weren't prepared for, or just fire us because maybe we just don't want you as a client.

I don't know. You know, but like Justin Shelley It's crazy. And it it just goes back to what I keep saying over and over. Our industry is unregulated, and that is a problem.

I don't necessarily want the government involved, but I have really am tired of shitty MSPs and and they plague our industry because there is no barrier to entrance to be an MSP. To be a cybersecurity expert. You can you can be a nobody. Anyone can be a cybersecurity expert, charge good Mario Zaki No.

Justin Shelley money. Make all kinds of promises and not do a goddamn thing. That's the problem. Joshua Holloway That's the whole reason why I started doing this.

Go ahead, Mara. Mario Zaki I think it also yeah, I I think it also needs to protect the MSP as well too, because you know, certain things like, you know as an MSP, we're paying for security, we're paying for our technicians and stuff like that, we're providing a service, you know, we need to get paid for it, you know, so there has to be some sort of guidelines like, Hey, you know you know, you need to pay your bill. If you don't pay bills, then you know, you need to do you know, y yes.

They can shut you down, you know, because at the end of the day too, you know, we we've discussed it. Like if if you have somebody that hasn't paid you in six months, you know, what do you do? You know? so I I think it does work both ways, but you know, Josh, you said that they had no open invoices.

Like they can't just say say, Okay, it's the third of the month we're shutting you down, you know. Joshua Holloway Yeah, and they did this on the second. They did this yesterday. So Mario Zaki yes.

So It it what they're doing, they're they're giving a a bad name to you know, to all of us, you know, a company like that. You know, Justin Shelley Absolutely. Yeah. Yep.

Mario Zaki but you know, i if it it's a different story of this customer had like six months where they haven't paid you know, at the end of the day, you know, why should this MSP keep paying for their services if they if they're not getting compensated? The contract works both both ways. But if they if they don't have anything open, then you know what? The the right thing for them to do is say, you know what You have here's your passwords, here's your whatever you have until this, you know, day, and you know, to find somebody else.

You know, that's the professional thing to do, not just say, take plan A or B, otherwise we're shutting you down. You can't you they can't do that. You know, we've talked about it. You know, sometimes, you know, owners don't end up doing, you know, what's recommended and then it It you know, you have to document it and you you just continue and you let know like this is a vulnerability, but you can't just shut them down.

Justin Shelley Can you imagine a doctor just saying, you know what, pay your bill? I'm not stitching you back up until you pay your bill. Joshua Holloway Oof. Justin Shelley I'll just I'll just let you Mario Zaki Yeah.

Justin Shelley die here on the operating table because it's the same goddamn thing. Like this is the stuff that MSPs do. It's it's it's a terrible industry. I don't I I will not understand for the life of me how something this critical to infrastructure in our country is completely unregulated.

We regulate the clients, great, that's a starting point. But how is it that anybody can be an MSP? With no accountability whatsoever. We gotta fix that.

I mean, like I I I I just firmly believe that we've gotta elevate our industry. It's not good. Joshua Holloway No, we definitely need to elevate our industry. I I wholeheartedly agree.

And there should be some rules, regulations, licensing, things that we have to obtain, whatever that looks like. I I think the other thing is businesses who get excited because a company, you know, brand new pops up off the street and they're saying we can come in and we can do your IT for twenty five bucks a computer. So I'm sorry, but you should run. and or really investigate how they're able to do what they do for such a low price.

Justin Shelley I was gonna say one of the cool things right now, business owners, if if you're listening to this, punch in what you're paying, put your whole service agreement in there and and ask it to rank your agreement, both what you're getting and what you're paying, against the standard. Because now we at least have that information. We can go into AI and say, Hey, what should it cost to, you know, manage the IT for a small dermatology office in Dallas, Texas? You can do that and it'll tell you.

And if you're paying half of that, good luck. Joshua Holloway Or start asking questions. What am I getting? How often am I getting it?

What's being taken care Justin Shelley Yeah. Yep. Joshua Holloway of? Because just like we all said, we all have people we have to pay, software we have to pay for, that choose that chews up our our ability to earn a profit, right?

Justin Shelley We run industry average is a good business. A good MSP is hitting twenty percent margin. A good one. more common is ten percent.

So if somebody's discounting their price by more than ten percent of the average price, they're short changing you somewhere. Like it can't be Joshua Holloway Mm-hmm. Justin Shelley done. This is just math.

It's not like they're good people and they're, you know, somehow figured out some magic trick that they can support you for super cheap. It doesn't work that way. Mario Zaki Yeah, because another thing is too like this the good security tools that we use, they don't just let you sign up for like a ten, you know, ten licenses at a time or thirty licenses at a time. You know, to get good like to even just get in the door with like good companies, good security tools, you need like a thousand computer minimum, fifteen hundred computer minimum.

and in order to really have that, you have to have a a a larger MSP. You have to have several employees, several customers. You know, these little ones that just pop up, they're just trying to they're trying to go with quantal quality instead of quantity. And they're not using good tools.

There's no way those guys are using good tools and giving it to you at that price. Justin Shelley No, their tools, even if it's the same tools, then they cost three or four times as much. So they're actually working in a different economy of scale. They should be able to provide worse service, not better, for more money, not less.

So when you're going with that, Mario Zaki Yeah. Exactly. Or they're not using anything. Joshua Holloway Mm-hmm.

Justin Shelley which is exactly what I'm talking about. This is the problem with the unregulated industry. And it's the problem I am trying to solve with unhackmybusiness.com.

There's my shameless plug. This is where you can go in and and use it to rank your own IT company. Go in and look at what they should be doing. Make them show you proof that they're doing it.

Because guess what? They're probably not. All right, guys. So much for our 20-minute episode that's now 37 minutes.

no, it and it got me Joshua Holloway Hey, I I I just had a horror story I wanted to share. Mario Zaki Mm. Justin Shelley going. It got me going, Josh.

So, all right, guys, let's go ahead and wrap this up. key takeaways if you got them. I think we've kind of beat this thing to death. But as always, Mario and Josh, thank you for being here.

Appreciate your insights. Your homework in preparing for these things and guys we're gonna come back next week. Bigger, better, stronger, and more brilliant. that's all I got.

Mario, Josh, say your goodbyes and we're gonna get the hell out of here. Mario Zaki Yeah, guys. I mean stick stick what we've been telling you from day one, you know, work with your MSP. If you're not working with an MSP, give us a call.

stay secure. You know, you need to be able to sleep better at night, you know, knowing your business will be there tomorrow. Justin Shelley Yep. Josh.

Joshua Holloway And don't accept that d defaults and change passwords. Mario Zaki Mm-hmm. Justin Shelley Yeah. Joshua Holloway But yeah, ha have security tools that are being updated, they are being patched, and they cohesively talk and communicate.

And that could be dissimilar stuff. As long as it's communicating and protecting you, I think you're great. if you use tools like some of us might use where all of our tools communicate, that's even better. But whatever you could do to make sure that you're being protected and help you sleep better at night.

this is what this podcast is for. We're we're teaching everybody about it and you know, discussing the things that we're running into and the new t new topics that are coming in. So be safe, be aware, and update those passwords. Thanks, guys.

Justin Shelley Make sure your MSP slash IT company proves to you that they're doing what they're charging you to do. That's what I got, guys. We'll see you next week. Take care, everybody.

Thanks for. Mario Zaki And stay unhacked. Joshua Holloway Unhacked. Justin Shelley Unhacked.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why AI-Native Finance Beats Bolted-On AI ToolsCFO Weekly · on LLM (Large Language Models)85 / 100
  • Rethinking Security Analytics with In-Place Intelligence, CEO of Vega, Shay SandlerShift AI Podcast · on Zero-Day Vulnerabilities82 / 100
  • Mythos is not the AI ApocalypseThreat Talks · on Network segmentation80 / 100
  • The Firewall Fallacy: Fortinet, KEVs and the Cost of ComplacencyThe Small Business Cyber Security Guy · on Network segmentation79 / 100
  • Why Procurement Has Become a Critical Line of Defence Against Cyber RiskPondering Procurement · on Zero-Day Vulnerabilities78 / 100
  • Self-driving, intelligent, and built for AI: the future of networking in the 2020s | Rami RahimTechnology Now · on Network segmentation76 / 100

More from UnHacked

All episodes →
  • Are You Actually Protected? Learn How to Prove Your Cybersecurity Posture For Free Ep. 9782 / 100
  • 93. Stop Wasting Payroll: How A $2,500 AI Automation Creates $80K in Revenue88 / 100
  • 92. The Automation That Pays for Itself in a Week (And Why Security Can't Be DIY)60 / 100
  • 91. Your AI Integration Is a Lit Match Over a Gas-Soaked Hay Pile54 / 100
  • 90. Clone Yourself With AI: The Integration That Saves 1.5 Hours a Day (and $26K a Year)58 / 100
All UnHacked episodes →