Go back

Palo Alto and the uncomfortable politics of APT attribution

150m 30s

Palo Alto and the uncomfortable politics of APT attribution

This episode of the 3 Body Problem podcast begins with an ad for Thinks TKnary, a cybersecurity tool that uses decoy tokens to detect breaches early. The hosts then humorously recap one speaker's recent CNN appearances, noting the difficulty of explaining technical topics like hacking and AI in 90-second TV segments. The discussion pivots to a drone incident in El Paso, where airspace was briefly shut down amid rumors of cartel drones or anti-drone weapon tests, highlighting concerns about drone warfare's growing proximity to home. The group debates the efficiency of anti-drone technologies, from lasers to drone-on-drone combat, emphasizing the cheap, disposable nature of modern drones. Finally, they provide updates on the Notepad++ supply chain attack, sharing new indicators of compromise linked to the Suo5 tool and analysis from Ucatami's Karibu malware-hunting system. The episode blends cybersecurity insights with casual banter about pop culture and current events.

Transcription

24324 Words, 131387 Characters

English
This episode of the 3 Body Problem is presented by Thinks TKnary. Most companies find out they've been breached way too late, usually after the damage is already done. Thinks TKnary flips that model. You deploy Knaries or Knary tokens in minutes, drop them into your environment and then forget about them. When an attacker touches one, they tip their hand and you get a single high confidence alert exactly when it matters. There's virtually no admin overhead, almost no false positives, and that's why Knaries are used by some of the best security teams in the world on all seven continents. If you want early warning that actually works, check them out at knary.tools or see what real users are saying at knary.love. It's like a baritone or a base, boss. Are you used to do a full of baritone? Yeah, not the ten, but more like a baritone. Can you give me a sound? What does that sound like? Like me, like a deep voice, but not very deep. What is it? Samuel Jackson, not Samuel Jackson level. It's getting us up, John Travolta. John Travolta, like in Greece? Like Greece? Yeah. Yeah. Okay. Good morning, everyone. It is Friday, February 13th. Friday, the 13th episode, 85 of the three-body problem with my friend's costume. We started show off with Drone Talk. On 20th of June, Mr. CNN, maybe we should start right there. What is up with all the CNN appearances? I was minding my own business watching the next game the other night and someone called me and the phone to say, "Is that on the phone? Is that Juanito and CNN?" So I switched over there. It was like, I saw you had a nice blue suit. It wasn't the Tano-Bam suit. So you were upgrading your wardrobe. What's going on there? Are you going to become a correspondent there or something? I mean, not intentionally, but you know how these PR things go, right? Like somebody just calls saying, "Hey, is somebody available for whatever?" Nobody is. I live five minutes away from this shit. I can just show up this one time. And then five appearances later, I'm now having a reshuffle my entire life just being like, "Okay." I drove the whole thing. What are you guys talking about? Is there a cyber thing? Or are you just going to be talking heads on there talking about everything? Well, don't let me make it sound like it's anything more established or long-running than it is for the time being. Yeah, I mean, just kind of bringing me in for like anything that's like hacking and cyber and AI. But for the most part, like where this all started is with this like super unfortunate, like Nancy Guthrie kidnapping case because there was like the Bitcoin angle and then the data recovery angle with Google sort of pulling stuff from the Nest cameras. I don't want to like talk shit. It's cool to have the opportunity. It's good to be able to like kind of disambiguate some of these things. And like you're sitting there with like Andrew McCabe and like people who like know what they're talking about for, you know, the FBI side of it and whatever. So I'd rather kind of like be there and say things that I think make sense. At the same time, the format of like prime time news is just insanely unforgiving. Like you're 90 seconds if you're lucky in the middle of what's supposed to be a conversation. But in reality is like get your talking points out there sharp and quick, right? And that's it. And like get off the podium. You're sitting down in your right. Right. Exactly. Yeah. And, you know, so it's just high pressure. It's like a lot of a lot of prep for like a very condensed period of time. And like after this podcast of like knowing I have two to three hours to talk shit about a subject, having to walk in there and do 90 seconds, clean sanitize to the point understandable to a general audience is like a whole different thing. Yeah. Well, if you do become CNN and start giving me 90 seconds on by two, we've got to have problems. Yeah. I think it's pretty cool. From my perspective, it actually puts someone on CNN that knows what they're talking about because 90% of the time I don't want to shit on the show or the TV thing, but you know, a lot of the times, like you said, a PR person connected someone and then you have a talking head there and you're just like a cyber security, especially it's always right problematic. How are you costing what's going on out in your world? No, I mean, good, good, good. We started with them. It has to be a great day. I don't understand this. I jump on this call. I'm always a little late because you know, trying to prepare and you're always late. And I'm always late. I'm always late. So I show up and these two are watching the like M&M video with Dido from like the fucking 90s. Like the early, it was like late 90s. No context. Just wrapping through it together. I don't know. 1998, 1999. Oh my god. That was setting up his camera and he was singing our part. That's why the whole baritone conversation comes in. We were vibing out on the M&M YouTube video and trying to figure out pop culture music. That Marshall Mathers LP is the first album I ever bought. Oh wow. Like the first CD I ever bought. Wow. Such a million. Just like what's up, see you else. I don't think you guys even know what I is, but do you know what Mark O? Is like some techno dance music from the 90s Mark O. Wow. No peers don't like that. I think that was the first CD I bought. You guys are like you see the European techno European. It's a Videy and for me it was a 45. I was born in 1971. So my first music purchase was a 45 which gave you a single on one side and what's called the B side and the other side and it was Boy George's Karma Camillean. Wow. Boy George. Wow. The only one of the great songs. The only 45 I've ever owned was the Defcon badge from like 20, 60 or something. I've heard you're not already done with finals. Yeah. That's good. Boy George also have the Harri Krishna. The Harri Krishna song as well. Good. I think it's better than the Karma Camillean one. Let's try. Let's try. Let's try. We got a bunch of options after that. I want to start with drones in El Paso, Texas. The FAA briefly shut down the airspace of El Paso, Texas on Tuesday. With the initial announcement that this was going to be for 10 days. Like suddenly airspace shut down for 10 days and there was all kinds of rumors and talks about drones circulating. The official report came out that there was some Mexican cartel drone that had to be shut down and there was a bunch of confusion over whether it was an actual cartel drone or the US government was testing anti drone defenses. Blah blah. I bring all of this up because it fits into the context of what we've been talking about in the past along drones becoming a part of warfare. Drones and Mexican cartels has always been in our consciousness here. Wanted to do we know for sure what happened here? I don't know what I don't know anything like I don't know anything for sure. I don't. It's starting to sound like a official documented. This is what we did and this is what happened. Not as far as I know, but the discussion is kind of bizarre, right? Why would you shut down for 10 days over drones being around? Then there's like, what are they talking about? Like the apparently there was a suggestion that we were going to use some kind of like new high energy anti drone weapon, which sounds fascinating. I mean, I'd love to kind of see some, you know, Pupu Star Wars shit we've been sitting on. But the whole thing just seems super odd. Why 10 days? Like why I don't get it. And then we opened it in a couple hours. Well, also, can we circle back on like the Mexican cartels have like drones? And what are they doing near airports? But what's going on? It's a part of town. I live in a barter of state as well here in Arizona. It's always been in our local news and in our consciousness around dropping drugs across the barter, throwing things into prisons. That kind of the conversation around drones used to be mostly, you know, around airports and it's causing problems for commercial flights. And on the other side, like crime, criminal activity and cartel when you're in a barter state, that's what pops up all the time. And this case here, I don't know, it was originally a 10 day closure over the airspace of El Paso, which is like not even a barter state. That's a barter town. And you know, initially they said Mexican cartel drones, bridge US airspace and they took action to disable the drones. Well, of course, if you shut down the airspace, you need to shut down the airspace for that. But then the announcement that it was going to be for 10 days and then it just seems like there was a lot of something happened and nobody knows for sure. And we're not getting a clear communication from officials. Is that fair? Also, can we say that like clearly this means there was like a fuck up, not necessarily on the part of officials, but even on the part of the cartels, right? Like if your whole point is that you're using drones to smuggle drugs, you know, you're then if you got noticed to the point where you shut down an entire fucking airport, someone fucked up, right? Like that's the opposite of covert, right? I don't know. If there's anything exciting about this story is the notion that we have some kind of high energy anti-drone laser shit, right? Like if there's anything America can still take pride in is like an overdeveloped military muscle that's just itching to get used. Showcase it's fucking dying to use it. So you mentioned pew pew, do you think it's real? The laser thing? The laser thing. I mean, I would be disappointed if we don't have some kind of cool fucking anti-drone laser thing, though the notion that we would use it domestically when it would use it, how we use it, etc. But like, yeah, I'd be kind of, I, for the amount of money that we spend in our like, you're volunteering defense contracting the idea that like what we're going to put nets. The fuck is this, right? Like, absolutely not. Like tell me we have some kind of laser. Costine, does this, does this story register for you at all? I mean, you, you're in Europe. This notion of drone warfare is a big subject for you as well. What do you know me? I'm on the X file size of things like I want to believe those kind of things. So in my circles, there's a video of something flying like something really huge. It's like a allegedly a video from El Paso from somewhere like between the hills. In is like a huge object flying miles away. It's not a drone, obviously. This is a size of what like a, like a bigger plane or maybe a balloon, but it has like a shape that is flat and not necessarily like a round or elongated shape. And I mean, sure. What seems suspicious in this story is the 10 days. Like, why do you shut down the airspace for 10 days? Which suggests that the whole shooting lasers and testing, testing some sort of shooting lasers made at least that resonated with me when you saw the 10 day shutdown warning. It's like, okay, so they're doing some kind of activity around drones and listen, you should be. I mean, this is, it was super disruptive. It happened with no notice and people got thing. But I mean, your government should be testing on hydro and defense is right? Costine, is this what Caspersky was building? What was Caspersky doing? I mean, not like in Romania when they just watch them with concern. Like, oh, that's a new Russian drone. Enter our space and our pilots have followed it with grave concern. And finally, disappeared of the radar. But we don't know where, if it fell or if it, I don't know, vaporized or teleported itself to El Paso, we don't know. So I mean, sure, we want to government whatever the military, the army to shut it down. If it's an unidentified drone, nobody knows who runs it. Like, you want to shut down, sure. What was the Caspersky anti drone technology about? Do you know, do I know? No, like honestly, I had nothing to do with that thing. It always, it was like the register that something paralleled to me because I thought there's no, absolutely no connection between antivirus solution, protection, defense and anti drone technology, at least in my mind. I thought there's like no connection. Also, I thought it's not feasible. I mean, why? Because the technology to take over drones means like hacking into the drone communication with zero days, taking over and things like that. And I was thinking to develop this technology for every new model, like Chinese drone model that appears where everyone runs like a different firmware on different channels. You would need different zero days and to find these zero days, it will cost too much and won't be able to support everything. So what the, the guys want to avoid your anti drone technology will just buy the newest cheap dirt cheap Chinese drone and just fly that and your device won't be able to stop it because it doesn't have a zero day for that firmware. But I mean, nowadays, I don't lasers jamming things like that maybe options, but I'm still not super, super optimistic about how efficient these systems are. I mean, just if you look at Ukraine, what is Ukraine using against drones? Either they're flying other drones to bring them down or they're shooting them down the Shah heads with jets with traditional planes and traditional, yeah, with their rail guns. So I don't know about the efficiency again. I would be very curious to hear if these lasers are legit. I know Israel has been developing a system that uses a high power laser, which costs like $10 per shot, something like that, which is nothing compared to this interceptor missiles, which are millions per per missile. So like $10, that's nothing, yeah. You have to imagine there's a lot of investment going into anti-drone technology with how do you clean Russia warship, don't you? That's, that's maybe a thing that's. I still think that fighting drones with drones is the most effective way, like just fly another drone into the other drone and bring it down. Yeah, but then you're just playing war fighting in the sky, like how is that? It gets nervous when it comes closer to home and it seems like it's just getting closer and closer to home and the strong warfare is coming closer to home and then there'll be an incident at some point. I still want to believe hoping that some of these drones are not like classic technology there, like exotic, exotic propulsion mechanisms or maybe not like from this world. Rumors of Chinese playing their own recovered technologies. Can we get like one of those stream deck sound things with like the X-Files with only a jisly in the background every time coast. I was actually planning to have a beach. I was planning to have a Disney CNN button every time you came out. Oh no, please no. I need a, I want to believe poster. I heard by the X-Files are getting a reboot. Let's see. No, no. No. No plus plus. 22, you got a last closing thought and drone thing. You're reaching to get into costumes and so there for a second. Well, I was, I was actually just going to go at the fact that like the, the thing about this is how mundane it is, right? Like we want to think about like some pretty cool drone, tech and drone warfare being some kind of like ultra high tech thing. But like what makes it so for two it is for warfare is how ubiquitous is and how cheap it is and how like these are, you know, the whole drone is a bull ammunition as far as like costs go, right? You just think of it as like a disposable thing. And yeah, of course you want to bake more compute into it. And I'm sure you could have better like maneuvering and flight and longer battery life and whatever. But the more we think about these being high performing devices, the less they are the cheap ubiquitous solution that you can just kind of toss out and, and you don't mind losing, right? So it's, you know, even the original, even the original uses for drone is always this cheap thing that you put a very expensive camera on. It was an expensive flying camera, right? It wasn't the same point you make. Not quite plus plus was a dominant story on our episode last week. If we put the Epstein stuff aside, costing there's some new developments. Can you like bring us up the date on what's new as it relates to this supply chain attack? Yeah. So this, this week we got a few new IOCs. Remember when, well, there were discussion, there's no IOCs from the incident response at Hostinger, which was the previous hosting company, where not bad plus plus had their update servers. And now we got a number of IOCs from the incident response at Hostinger. That's bunch of, bunch of hashies, a number of IP addresses, some of them are VPNs. I think some of them are proton VPN. If I remember correctly and I've been checking them against my lists to see what those are, I think one of them was also a known network attacker. The hashies are not on virus total, unfortunately. So there's a bunch of three or four hashies in the air, which are allegedly related to this tool called Suo 5. Suo 5. Suo Suo 5. Suo. I'm probably pronouncing it the wrong way. It should be like 05 or SU05. Suo. Suo. Suo 5. Suo 5. Probably some, some of our Chinese listeners will tell us how to properly pronounce it. Suo 5. I'm sure it's wrong. And this is some kind of FRP like tool, fast reverse proxy tool, which is very, very popular with red teamers, also some APT groups like these things, because they can just set them up on a server and use them to tunnel back into that infrastructure with minimal alerts. Typical, it's our high performance, very stable. Suo 5 is written in GoLang and is developed by Chinese. his guy who goes by the alias zima one. He's got like a bunch of tools maybe 20 or more tools on github all of them, pen testing tools, the kind of tools that you expect pen testers to use so he's obviously into those kind of things and two of five is one of them. I put all these hashes to tracking by the project my project is now on VT so hopefully they'll show up but unfortunately I didn't see anything about that kernel exploit that we discussed the last time a hostinger they were kind of hinting there was some kind of a kernel exploit being used and they patched it in September which kind of cut the attackers out. Unfortunately no hashes for that kernel exploit. The rapid seven blood didn't mention this either right? No, no, we didn't get any other mentions of this before and kind of makes sense in my opinion because this would be like the server side tools that rapid seven and the others didn't get to analyze only the company who didn't see the response or maybe hostinger themselves would have access to those or see them but by the same time our good friend Chonggortamash I hope I pronounced it that correctly. He published their analysis on the Ucatami blog. Ucatami has a very interesting system by the way which is called Karibu that is Mr. Bouldies. Mr. Bouldies is also the former company correct Mr. Bouldie. Charles to our friend Bouldies are Benchat who left Ucatami I think and now the company is still kicking and Chonggort published their analysis with the Karibu system. Hello, welcome back. What does the Karibu system do? Karibu system is a kind of a big malware collection with some kind of code hunting features. So if you have a sample to start with or a hash you can use their technology to find similar samples in their collection which if I remember correctly is a number of a couple of petabytes in size they are selling this as a kind of on-premise solution with something like 20 servers that you can buy, deploy on your premise and poof you have like five petabytes of smaller samples and the ability to hunt through these samples in almost in real time. So the queries are very fast and he used this to find similar samples similar additional Lotus Blossom samples to those found by Kaspersky in their blog posts and the ones mentioned by Rapid7 initially. I mean we've been working on you know samples and detections and stuff like that but not sort of jumping over tables to like beat folks to to any of this it's more about just making sure that we're like on top of it. What is there left to learn about this incident? What is it? What is it? What is it? What is it? What is it? What is it? What is it? What is it? What is it? We still want to know how Hostinger got owned in the first place? Was it a vulnerability in the notepad++ update mechanism? They are PHP scripts maybe something like that or was it something else like they managed to get an account on the same box and then use this kernel EOP they kind of hint towards to jump and from there get access to the notepad++ infrastructure. It kind of seems to point to the second option of another account on the same box getting compromised and then using this kernel exploit but would be nice to know how because well they say they they didn't find any similar activity on any other host but it kind of in my opinion raises a bigger question which is where is Lotus Blossom doing this as well are they doing this kind of attacks anywhere else on other hosting providers. If it's an issue let's say of vulnerability that was closed in June July officially and people didn't patch their boxes because it requires a kernel update so that means a reboot and if they reboot it in September there's still a window maybe some of them didn't even reboot by now like sometimes people just don't reboot their hosting platforms because it means disruption to their customers and kernel vulnerabilities and Linux are always like a big issue unfortunately there are some solutions like for instance Ubuntu has these live patches which allows them to patch the kernel on the fly without the need to reboot which is nice but unfortunately other operating systems depending whatever you have on your hosting platform may not have this feature so that means the moment that a kernel exploit is in the wild or somebody gets their hand they can use it for months everywhere because people simply don't patch kernels and don't reboot. Do we we have no visibility in who the actual targeted targeted people were right? I mean we don't know what Lotus Blossom was after. Like I said I think the best information came from the Caspersky blog which was talking about even financial organizations in El Salvador that seems strange to me but also a bunch of other organizations through Asia. I think the most recent discussions are including from notepad++ they were saying that we have no way of knowing who got hit although I think that Hostinger was saying that was still a very limited number of victims who got the further stages so the whole targeting was very precise and of course would be nice to know how the targeting happened like how did they pre exactly how did they know how to select whom to target right and what this new IOC file says is that the access to this attacker control share hosting accounts they were observed from multiple geographical locations obviously VPNs were used but it doesn't talk unfortunately much about the victims locations which you you'd expect them to to have some victim information as well. When do you think we're talking about 10 victims 100 victims 1000 victims when you say it's when you say it's precise and narrowed how I think I think probably in the range of 100 or so all right um well hopefully the thing with these stories is big it was a big big story last week this week we're kind of like trying to free the edges and then next week it disappears and it's something new and this is like life in the cybersecurity trenches right. Yes and then maybe like five months later somebody comes up with a new expensive information the US government got owned or the Mexican government got owned and this exposed whatever new secret project and it's a big disaster. Who drones were hacked? Five. No pod plus plus. Or drones running no pod plus plus. Somebody in the White House are close to the president got their communications intercepted and there's a whistleblower and all that got hacked by Lotus Blossom. Notepad. Notepad plus plus exists because Notepad was just a simplistic thing right but now we have Notepad powering AI with AI capabilities at Microsoft Pad. Now we have this week with Patch Tuesday Microsoft ship they believe six six-serior vulnerabilities patchwork marked as already exploited which we call zero day and that includes a Notepad RCE remote code execution when opening Markdown content. Now this was part of like this edition when they don't AI into Notepad. I know it's remotely exploitable. Because you get to look at all six of these patches all of them marked as exploited every month this happens I say the same thing. We just know that somebody was hacked and Microsoft says the patch and we just move on with our lives. Do we know anything different here? Not unfortunately no. The only thing we know is this that there's like a bunch of different CVs that got fixed in totally like different places. So for instance CV 2026 21 510 is a windowshell which just allows the attackers to bypass a smart screen security warning. So that's maybe not too serious. It kind of maybe makes spam or phishing attacks make them a bit easier. On the other hand there's others like CV 2026 21 513 which is a SMS HTML framework that still exists in windows although Microsoft moved to Chromium Edge years ago. These frameworks still exist in many like components like Windows shell for instance or third party apps and these can be an Internet Explorer thing right. This MS HTML was you need to Internet Explorer well at least it used to be problem on AI back in the days. Absolutely. What's the point of like migrating off of technologies if you never get rid of the old one? Like that's really the thing with Microsoft one of the many many things about how Microsoft does things that just like defeats the purpose is like because of this insistence on like always having legacy support, you just never actually get rid of the shitty thing that you were supposed to be replacing. So yes, now we in theory have something better powering most of the thing that you use, but the old carcass of the other shitty thing is still around. I love that for them. I mean to see the Google threat intelligence group continues to push, continues to report thanks to Microsoft. So this month we see again mentions of Google threat intelligence group reporting things. Of course, yeah, we're grateful for all that, but also be interesting to know exactly who was exploiting them with JPD group or finger like, you know, the DPS. It just runs somewhere. Is it just like, I'd wear people doing bypasses of stuff. Like, what the hell is going on? Like we get six or days and then they move on to next month and nobody says anything. And we just kind of like, this is this world we're flapping around and I don't understand. I don't understand how Windows corporate Windows users who standardize on that company's platform accept this as a as a as a normal part of business. I need to why aren't we, I mean, why am I the only one angry about the fact that Microsoft says, listen, someone got into your house and there was a broken Windows somewhere. Go fix the window and he got his new lock. Yeah, it's a lock. We don't know if there's a key in your bedroom somewhere. I don't know, man. I don't know. I think, when you're in these like enterprise support cycles, I suppose that you get used to just accepting whatever bullshit somebody sends your way because it's indefensible, right? Like there's no way that this is like an okay response. But I also wonder to what extent them sneaking it under the radar this way is is a way to keep from having that response in the first place, right? Like you're just making it seem like it's all just a little bit of technical jargon, some whatever thing that if you're not paying attention, then you know, not a big fucking deal and move on. And that in effect, like there is a reason why you kind of put it this way. It's because you don't want it to be a story. You don't want it to like kick up any kind of dust and you can just pretend that it's not a big deal. And if you don't look, let me let's put it from a different let's put it from a different angle, right? Like doing thread intel and writing the stories and trying to get news coverage. It's really hard to get coverage on on an O day by itself, right? Like you can basically say like, oh, this really, really matters because this thing is so prevalent and this thing is so important and the exploit is so bad and it enables so many terrible things. And it's being used by so many people. So the impact is huge. Therefore, you must care about this exploit. But most journalists, I imagine who hear about here's another LPE in Windows, here's another blah, blah, blah, blah, we'll just be like, so what the fuck do you want me to write? Like why is this a story? And if that, if you think about it in that light, what Microsoft is doing is essentially keeping the oxygen out of the room so that there is no story. And somebody else has to kind of butt in with some oxygen to say, hey, this is something you should have. This is my, my ass, it's like, well, if I'm a Windows shop and I've standardized on all of Microsoft's technologies and this has become a monthly thing. And I care about whether I want to do thread hunting in my network to see if anyone has been living in there because this is a standard thing that always happens. Like why am I not agitating for Microsoft to fix this and and at least give me some sort of thread hunting? Or am I already buying it to some enterprise T5 thing that I'm getting some sort of an advanced protection on? I don't understand why there's no theoretical you're super bought into Microsoft. I'm sure you're getting some kind of like Sentinel defense and blah blah and you know, maybe some reporting and maybe some detection stuff. But I also just think that Microsoft doesn't seem to really give a flying fuck about its customers. And and to be fair, if you look at Microsoft's priorities, right? Like I love that you're skipping past the fact that like notepad had AI added to it that nobody asked for it and that made it vulnerable in a way that it never needed to be. And like it's such an obvious misunderstanding of what any customer could possibly ever have wanted with this product, right? Like you open notepad to be able to put down some notes real quick. That is literally the entire purpose of notepad. You're not opening it because it's your like de facto tool for writing reports. You're not, you know, you know, you know, you didn't need the fucking internet connection to use notepad. Like notepad had you know, the only use was that. So some asshole, some PM decides that they need to marble AI and co-pilot into everything. And they put it into notepad, which nobody asked for and I'm sure nobody's used ever. And then it actually just makes it more of an exploitable surface. And then the conversation we have is just kind of moving on and not having a discussion about like, why the fuck would this be in there in the first place, right? Like all the security initiative, everybody, all everyone's going to be measured on whatever out of security. It's such bullshit. Like why do we take these people seriously? Let me let me let me let me let me let the last the same thing that you just mentioned because I pulled it up while you were talking I pulled it up because it flipped into my mind as well. Let me read the last paragraph of Satya's letter announcing the Secure Futures initiative that they all begged us to buy into that they were going to be serious. And if I take them at face value and I buy into it, this is the letter that this is Satya's words. If you face with trade off between security and another priority, your answer is clear. Big bold letters, too security. In some cases, this will mean prioritizing security above other things we do such as releasing new features or providing ongoing support for legacy systems. This is key to advancing both our quality platform quality and capability such that we can protect the digital estates of our customers and build a safer world for all. So we got all of this kind of top down from the CEO. We all applaud it. The CEO is coming down hard. If you're faced with a trade off between security and another priority, your answer is clear. Do security. They are not. Which means either Satya's, I don't know about, he listens to him and cares. Or it's just one complete fluff of bullshit everywhere. I don't know. What do you think it is costing? I think you know, the people at the top can request or demand things, but the people in the field need to make money at the moment. The vibe is AI. And you're hearing the demand for revenue as well, right? Because the people at the top are saying this is also the same people saying we need to make money. There you go. Security is the most important thing, but you need to make money. But they don't want to get let's take that a little bit further though, because no one is making money off of notepad having AI in it. Right? So like we, let's keep pulling the thread of perverse incentives, right? Because the to me, saying, you know, we need to make money makes it sound like it's a pragmatic decision that makes a whole lot of sense. It's just not one that we like. And that clearly is not the case here because you're not making any fucking money out of shoving AI into notepad. What you might be doing is you're padding some internal metrics, right? X apps within windows now have co-pilot. And B, maybe this means that co-pilot burns more tokens so we can pretend that people are using co-pilot AI, which nobody's fucking using unless they're forced to because it's a piece of shit. Microsoft, if you would like people to use co-pilot AI, make it not a piece of shit. Make it fuck it. Make it not a piece of shit. Like everybody else is in love with AI because of the advanced features that people are putting into cloud code and how reliable Gemini pro, you know, three pro is. So if people aren't using your piece of shit co-pilot, it's because it fucking sucks. It's not because it's not ubiquitously added to everything. But I'm sure that on some level there's, you know, there's another command from on high that says that we need to have AI and everything and we need to sell X amount of token. We need to burn X amount of tokens to show that people are using it. And frankly, these are the sorts of decisions where putting it on customers, as saying, like customers need to demand blah, blah, blah, kind of feels like a moot point. What I want to know is who are the majority shareholders in Microsoft? Because that's where like somebody presumably Satya is pulling someone's leg. Like he's, I'm just going to guess it's Satya. I'm just, I'm just going to, you know, the book has to bust somewhere. So I'm going to put it at Satya. You are telling me that there is some insistence that AI has to be this really important thing and that we need to have more of it and that it needs to be central to Microsoft strategy and that they need to sell X amount of tokens and our next amount of tokens to show that people are using their AI bullshit. And clearly, there's a level of like malicious compliance here. Like there's a level of, oh, they want that. Just like, just pad the numbers, just pad the numbers here and here. And then we can go back to the board and say, look, guys, like you wanted AI, we're doing AI, you wanted this thing, like look at how much we're, you know, effectively doing it because if you just look at it from the top down with these numbers, right? Like we did it. We're doing it. And it's obviously not true. It's obviously not true, right? So those are the moments when, no, I don't think it's up to the customers because they clearly don't give a shit about the customers. I think it's up to the shareholders to be like, you know, we are already criticizing Microsoft for missing the boat on the AI thing. They don't actually have a frontier lab. They're not actually building anything novel with AI as far as we can tell. I think Satya's whole strategy boils down to, well, I'm just going to wait until Sam Altman, you know, that news that I hung around Sam Altman's neck, Titans enough to choke him. And then I'm going to inherit a frontier lab through open AI. And then I'm not going to build half of the data centers people asked for. I'm going to wait until it's like a little cheaper and the technology is a little more settled. And we kind of know what we're doing. And then I'm going to, you know, kind of race to like adopt the newer thing, right? Like that was the whole, that's why I kept bringing up this like door cash podcast with with Satya and Dylan Patel. And I thought it was super interesting that Dylan Patel was there and that Satya would take an interview with, for those of you that don't know, Dylan Patel is the guy that runs semi analysis, which is like the most fascinating, you know, basically supply chain analysis blog when it comes to AI and these sorts of like modern applications. And I say it's fascinating because these dudes are clearly, they have such a beat on the supply chains and logistics that go into model training and model use and so on that it feels like reading like an internal report for some of these companies. Like they're basically like, yeah, you're claiming that you're going to do this, but we see that you've only bought these many plots of land. And there's no power lines that are running to that plot of land. So you say you're going to build a data center, but clearly that shit's not real, right? Like that kind of analysis that I think is sort of fascinating because it keeps people honest. So to see Dylan Patel on a fucking like 45 minute interview with Satya and like he he pushed back hard. And frankly, I think Satya kind of did his best dance to like stay in the conversation. But I think some of those answers were very telling of just how bad Microsoft strategy is just how kind of like, yeah, they're hedging. They don't the sense seems to be that they don't want to be exposed. If you, sorry, if you assume that there's a master plan here and that Satya knows what he's doing, then it seems to be that he'd rather not be in the race with everybody else. He'd rather wait until people are kind of winded and things are kind of like the utility, the value is clear. And maybe then you deploy your resources, assuming that that's something you can do to catch up. Yeah, but he threw the first batch of billions into open AI in the early days. Still, I mean, it's not entirely fair to say. Oh, no, no, no, no, no, no. But that that was an interesting move. That was that may have been the poison pill that open AI may never recover from and that they're trying to recover from because you know, I don't know the full details of that of that contracting agreement. But if you remember, that comes around the time, like all that stuff kind of expands around the time that like people tried to oust Sama as like the lead of open AI and then like, you know, Microsoft offered higher. Yeah, they offered him a position and like, it was a drama. Yeah, it was like this, like, you know, it was this moment of having this like deal with the devil ink, which I think, you know, might have been the way that Sam survived that coup. But I'm not sure. I think all of open AI's like life right now, their entire priorities seems to be more towards trying to remove that news that Microsoft put around their necks than it is about the competition with everybody else. And you know, I don't know the details and I certainly can't speak for open AI at all. And I like the company. I want them to do well. But I don't think this is like Microsoft is this like frenemy that is clearly just draining the life out of O.A.I. And I think Satya is quite overtly treating it as, oh, I don't need to create a frontier lab. I don't need to actually invest into making better AI. I have this backdoor way of benefiting from whatever open AI does. So I can just wait and like, wait them out and let them kind of starve. And then I can just swallow them. And that's it. Like we're good. I don't know. I just see Microsoft shoving, continuing to shove AI into everything. Note, but this not bad RC is just one small example. We don't know what's going to happen on the iPhone when all the AI starts get in shoved in there, which says into iOS 26.3 came out this week. We have a new operating system from Apple. And of course, you know, me, I control F right away to look for the word exploited in there and we find massively. And do we find that Apple is aware of a report that one of the issues CVE 2026 20700 may have been exploited in an extremely sophisticated attack against specific target individuals on versions of iOS before iOS 26. There's a mouthful there. There's a usual mouthful there discovered by Google tag Google threat analysis group vulnerability and the Dilt DYLD. Yeah. It's like a DLL for macOS. Right. And there's also a mentioned there that some all the CVEs were also fixed in this report. I think there were some all web kit bugs. Do we know anything beyond what Apple tells us in this bulletin costing? So what Apple says in this bulletin is very little, but I thought that these older reports are particularly interesting. And this have been fixed in December last year CVE 2025 14174 and 43529. Those are more interesting because those are web kit bugs. In particular, this new bug in DYLD may allow for code execution. I think that this one in particular might be useful to escape a sandbox. I think that would be the main usage for this particular bugs and the previous ones obviously being web kit bugs. They could allow the initial access into a device. So I think that they're probably all all are part of the same chain or the same chains that Google tags somehow somehow found. Google tag reported the web kit bugs that you're mentioning from December. They reported those and this new one is also reported to Google tag, which makes me think that they are related because even Apple says that those previous ones from December were also issued in response to this report. So all three of them appear to be part of the same chain. I think they fixed the web kit bugs first to kind of close the door. And then now they close this other one which probably allowed for this sandbox escape. Unfortunately, we don't know which group was using it. Was it like some cyber mercenary group? Was it a nation state? Was it China? Was it I don't know Indonesia? Was it Vietnam? Was it China again? Who knows? It was a top tier attack, I mean, there did. The language here tells us it's one of those either commotion by where our nation is. Because nowadays every single one of these reports it says may have been exploited in an extremely sophisticated attack, extremely, but it feels like all of them are nowadays extremely sophisticated attacks. I can't remember one that isn't extremely, what is it? Like very sophisticated or sophisticated or gravely. This language is, you think this language is imprecise, it's just kind of language made by PR people or this is like precise language. It tells you it is if it's more sophisticated than others or is it like the most sophisticated or if it's like just I think the extremely sophisticated part here, it kind of tries to imply that it's unlikely that they would waste these goodies on the loser you. They're going to waste these goodies on the bigger guys out there at the top or journalists or activists or all those people don't worry about it. They're not going to waste them on you particularly because it's extremely sophisticated attack. In addition, it only always works on all the versions of them. They're still patching it in 26.2 but they're always very clear that this is always an exploited work in all the versions of iOS before what we have right now. I don't know. I wanted to you watch your patcher iPhone. Yeah, patch the iPhone. I updated the macOS thing because your update by doing Fuck if I know man, it's just happening last night Pressable on next. I just worked all sorts of weird sizes for me. It was 11.5 gigabytes other people got like 13 gigabytes the update which is Mind blowing. I don't remember seeing 13 gigabytes. Why is it different sizes for different exactly and Some people said it was only three gigabytes for me. So why are we Hey, hey, go in the chat saying three gigs here three gigs. You see I pretty sure mine mine was probably like three gigs They serve you some special goodies custom. You know they give you The full the full experience the full experience the certified pre-owned experience At this stage we never hear about this stuff until maybe a citizen lab report a few months from now mentions one of these CVEs that we go back and say oh yeah, this was the thing we talked about in February when Apple patch like again like Microsoft We don't get any sort of threat hunting telemetry Data or anything at all, right. It's just go patch. It's it's it's against those people and move on with your life Look man, I this is why You know for god knows how long in this podcast I kept bitching about like regulation and And people were like oh, but like the government sucks. I'm like big government blah and I I agree I'm not saying that I am a huge fan of government or big government or that I even trusted the government is gonna be able to do it but It turns out that when nobody requires any kind of enforcement of any kind of standards whatsoever that companies don't just arbitrarily choose to share information that's inconvenient to them and Security failures are an inconvenience that people would rather not talk about so I don't know man if y'all if all the libertarians are here are like that, you know that over Government and antitrust and regulation that's fine by me, but like Then at least somebody give me some kind of Shareholder led conscience mechanism that that is somehow going to work here because That seems to be the only thing they're gonna listen to is is ownership and markets so how do we get some kind of market priority that says You're not allowed to do this or like this is just not a good way to do business Costin what are you telling your TLP black customers and people coming to you around this thing just patch enable lockdown mode Move on with your life for me. You're not you're not you don't have the ability to actively hunt for any of this stuff when you see Market as exploited right There were of course there is there are a lot of things you can do in order to hunt for this maybe not for this Specifically, but for for things in general, so what I always recommend you know my recommendations enable lockdown mode Disable eye message disabled face time Reboot daily probably reboot daily is one of the most powerful Think you actually do reboot daily Almost every day almost like day I tell you this is impossible unless you have an app that reminds you to reboot because otherwise you forget you just forget But I tell you like this is one of the most powerful things you can do reboot daily Tap your network traffic save everything save all the Netflow save the DNS requests save all the traffic if you can actually afford that and you can do hunting later Also, you can do hunting in in real time. This is one of our recommendations. You set up a wire gar profile on your phone You tunnel all your traffic to a server you you control You save all the traffic there and your story forever um and Whenever citizen lab work whoever releases a new report you can go back and hunt for things There we go when coaching starts making those recommendations. I'm just like this doesn't sound like a usable phone The other people like you're like you know remove eye message and then like cut the camera out and remove the microphone and then Break the screen in half and take the out the GST and just throw it in the trash What you're like and then what is this like let's be like one one thing you can do is reboot daily like you can do that right Okay, I think yeah, I think turning off my message Don't know if I message in America without a message. You're nobody right? Yeah, you're just in a grand Yeah, I think a lockdown modern copying and pasting URLs and all that stuff is just like such a penis You're not into that I see What about like wire gar the wire gar profile tunneling your traffic that's doable like once you do it You do it once and then you know you never walk back like does it affect my life? No zero like Maybe one percent trying to run a VPN on this thing you run more than an iPhone and your phone is 50% Battery it was like that when Muleva was using open VPN, but now they switched to wiregaard completely And if you if you just run the wiregaard app From Jason himself The impact battery impact for me is less than 5% What about the people who can't do active monitoring on their traffic? There's just it's just so prohibitive Cost time resources blah blah blah is there anything else those folks? Yeah, sure they can do two things which are very important to one make backups regularly back up your phone This again, it's not too bad You need storage space. Obviously like for me a backup is 200 gigs So you need to save that somewhere and To create sees the extra this analytics diagnostics Every now and then like once per month once every two three months save them put them somewhere in storage Have them just in case because you never know when you can go back and look at those or imagine there's one day You get this apple notification Where a friend comes to you and say hey We have an indication that your iPhone was hit and you ask how do you know? I can't tell you like we know Okay, and then you say what to do say ask costine to take a look at your phone and costine comes and says can I take a look? Yeah, do you have any backups or cds from the last year or two years and if you say no, it's different from yeah I have if you have we can look back and see Maybe at some point there were artifacts visible in those backups or cds that allow us to see what happened Because in most cases when we get there after the notification. There's nothing left In most cases You can't find anything anymore in some cases people say I don't even know like this is a new phone. I got in December But I got it on December 1st Our bill marcher can these guys finding I think in case we're at work What really matters is volume and what really matters are the magnet of threats If you have access to a good pool of magnets of threats who are those? Activists not to be activists in the Middle East in countries where these tools are very prevalent Then you increase the probability of finding interesting things and also if you get access to the physical phone Not just backups, but like the physical access to that phone can also help in some cases because you can put it let's say I can't jailbreak it today But I'm gonna put it in storage and I'm gonna revisit this one year from now or two years from now I can wait if I don't mind and two years from now I use a Gail break and I get full access to the phone and I can extract more information from there Which allows me to find something I may have missed in the past And also knowledge improves constantly improves like every year We know a little bit more about how this exploits work. What kind of traces they live people discover new features in iOS or new databases that have more forensics data and better tools appear like the ECSI RT cdx framework Again, there's better tools every single year so that allows us to find more the same time I think that attackers also get better and better because they read the blogs as well and they see that Ha ha ha we found it your app forgot to your app your malware forgot to wipe itself in the battery usage log So it's not in the process list but it's in battery so there's like a discrepancy between these two logs So that's how we find it and then the next time they just wipe it from there as well And then there's like less traces less traces until the moment where there's almost no trace left or there are some traces But they are not definitive those traces suggest something may have happened But they can also mean that Just some bedlock you you were a magnet for bedlock not necessarily for Paragon graphite Or blue ocean or one of the other things that people don't talk about And you were maybe just an attractor for bedlock How is tag how is Google tag finding this stuff with a lot of good luck, I think, like the solution and the cure for bad luck. luck is good luck. The more good luck you have, the better chances to find something interesting. And good luck is directly proportional, I think, to your visibility and the amount of data you collect. So the more visibility you have, the more intelligence on the attacker, sometimes like inside information about exactly what the attackers are doing today. And let's say maybe not Google Tag, but let's say I'm doing some investigations and I spot some kind of a waterhole. And this waterhole averages an exploitation server. If I have the ability to monitor the exploitation server for two, three weeks before I shut it down, that gives me a lot of intelligence about who are they targeting, who are the victims, what kind of exploits are coming with what? If I can even emulate, let's say some vulnerable devices of my own, or even bring some old devices and try to get them infected with a VPN in some specific country, or maybe with some kind of an attractive login in a certain forum where this waterhole was being deployed, that brings goodies. So yeah, the more intelligence you have and the more patience you have, the better things you find, and the more good luck you have. I just thought that came to my head, which is a recurring question that I like to ask is how much of this stuff do you think we're actually finding versus how much is actually happening? Are we finding what is Google and is that these guys finding just like a 1% tip of the iceberg? Do we think there are thousands and thousands of these things floating around? What do you think? So it's a question not of what you find, but what you talk about and what you patch and what you publish. So there's like different levels. And we keep getting back to this issue over and over. Maybe you discover something, but you don't know exactly what exploit was used to deliver it, and I don't even have the binary or the malware itself. But still, I know that this happened. I know some people were targeted. What can I do about it? You know, keep watching. Keep trying to get more related evidence. Or if let's say I find the exploitation server, I find the new zero day, I try to patch it, but there's no blog. Or I find let's say something and there's a blog, there's more information, there's patches, and the full circle, like the full package with everything that is available. And of course, this produce some effect from the attacker side as well. They can adapt to their strategies, just stop doing that. They realize that Google is watching them. So they change strategy, they try to, I don't know, only deliver this to certain IP address ranges, find you in their exploitation, keep, implement this session keys, encryption with public least only in memory, to deliver only to the victim. If you have the traffic, you can't decrypt the traffic at a later stage, quantum resistance, or the table. One percentage, you think. One percentage, you think we find it. Wow. Why do you believe that you think that's that bad? In terms of visibility and our ability to know I don't know, of course, of course it's that bad. One percent. I mean, I don't know, I don't like putting random numbers to random things, but I don't need to slap an arbitrarily low sum to say that if we have systemically blinded ourselves, then we're not going to see a lot of things. That's my annoyance with anybody that defends the Apple stance to telemetry and Thread Intel. And even with most of these shops, what's being done here is a seemingly principled way of keeping visibility low to then be able to manage the scope of what we claim the problem is. But we, I think we all know that that's not true, especially like with iOS. And frankly, to their, it's to their credit and their detriment that iOS is as secure a platform as it is, but it's an unquantifiably secure platform. Why, how much better would it be if you could say of all this? We know the breadth of anomalous behavior, attempts, testing, attempted exploitation. The actual dwell time of things that escaped what we have as protections. And can therefore say that iOS is very, very secure because out of the 100% of attempts at exploitation or anomalous behavior or attempts to corrupt memory or attempts to load a back door, whatever the fuck you want, we are our platform detection and security engineering approach blocks 97% of attempts. And therefore it's the 3% that we're working against. But you know, when we say you don't need to worry about it, it's because we know the exploitable surface. We're monitoring for anomalies. We're quantifying what that is. And we can tell you that we know this activity is currently relegated to only Mexico. We know that this activity is still in the testing phases. We know this that and the other. And the only way to know that is by being good about collecting telemetry and focusing on anomalies and knowing that you don't know what you don't know. And that doesn't mean that it's okay. It means that you need to do things that allow you to understand the shape of and depth of what you don't know. And that's how we used to do APT investigations. And frankly, if there's anything I think we learned, it was that we never knew just how many things we didn't know were out there until you came up with some other way of saying, you know, what happens if we profile every single machine and what are all the components that are in system 32 across a fleet of 100 million end points. And we statistically determine how much variance there is in the hash content of this typophile with this kind of name. And then you go, okay, what are the outliers? Well, shit, there's only 12 outliers in a fleet of 100 million. What the fuck are those? Would you look at that an entire APT operation that we had never found out about? And you pull that one thread and there's, you know, a thousand incidents that you never saw over the past 10 years of telemetry. And it's just because you went looking for what you don't know. That's a mentality that was really native to us at grade. It's really native, I think, for folks that have gotten to do big game hunting, APT type stuff, but seems completely up to the security engineering type folk that work at places like Apple. And we cannot for the life of you explain it to them because like immediately it becomes this discussion about like, you want us to weaken the platform, you want us to like introduce what it's like, no, nor do I want you to create some kind of like panopticon that the that the law enforcement can now take advantage of, I just want you to take that same cleverness, unbelievable cleverness that you're using to create these unbelievable exploit category defeating mechanisms and apply it to the fact that there is there are active adversaries out there who are very invested in finding ways to get past what you do. And they seem to always find a way because it's quite possible that it is impossible for you to create a platform where that is not possible. So maybe you can come up with a way to say, hey, every fucking iPhone is about as standard a device as you could hope for. Everything is placed into certain places. The hardware is relatively the same. The OS versions are relatively the same. Like it's about as simple, quote, you know, and I say that, you know, with with huge ass turrets, but like it's about as simple as it can get as far as like being able to do this kind of like herd immunity approach of saying, what's normal? This is normal. Who falls within normal? Almost everyone who doesn't fall within normal. Okay, what the fuck is happening in that little pool? And that's a very tried and true method that I don't think they're doing, even if they claim they're doing it, they're clearly not doing it to that level. And I don't understand why you wouldn't other than not wanting to know just how bad the situation actually is. Did you guys get a chance to read this Estonia Foreign Intelligence Service annual report that they put out this week? And I bring it up because a Russian general was a, there was an assassination attempt on a Russian general in Moscow. And the Russians came out and says, hey, we have evidence that the Polish intelligence services install at some point had helped with some of the recruiting in the early days. And it brought me back to the podcast where Juanito is talking about the polls are itching. to retaliate, eaching to show off what they've been preparing for. So I tie all of that together into this Estonia foreign intelligence service paper that was focused mostly on Russia, on what's going on with Russia around the war, military losses, adapting for long-term confrontation. And one of the things they made a point to make clear is that Russian sanctions evasions is going to rely heavily on cyber-enabled procurement networks. There's a lot of cyber angles here. Costing, did you get a chance to read this report? Anything at all stood out to you as interesting new. new. new. new awardee? These reports are always interesting to read. In particular, all the Baltic states, they published these kind of reports on a early basis, and typically all of them are good. Like in the past, we got some goodies in there, such as the famous report in which they talk about the fact that TURLA or different tools overlap between TURLA and the APT-29, which I think was one of the most interesting findings. So these reports are always great to read. This one in particular, I thought there's nothing groundbreaking in it. It's kind of just rehashing the news for the past years and the kind of things that we know. We know that the war is exhausting. Russia's internally, they have massive losses. The economy is a bit shaking. There's a growing repression at home. People are under constant control. Even like a few days ago, Russia blocked what's up, access, and they greatly trottled the telegram. So there's all these things happening in there. So we saw it coming. To me, the report just kind of emphasizes all these things that we knew. What I thought it was a bit interesting and new is when they talk about the use of AI and digital platforms as influence tools, which we know that both China and Russia have been using massively in order to create manipulated digital content, fake movies, simply to change perceptions to push propaganda to kind of, let's say, turn people against their own governments to divide and conquer people in the European Union, which in my opinion, again, this is working. I've been saying this for many years when people were laughing at what Russia is doing, they were like, "Ah, this is in consequential. This had like zero real-world impact. We measured the effect of these Russian influence operations and the impact was 1.5 percent." In my opinion, this is a long-term game and it is working long-term in the sense that slowly people either they get divided, they get split into the left and the right, or I don't know, pro-family, or pro-LGBTQI+ or pro-democrats or pro-Republicans, or whatever. They get split into groups and the moment that there's a divide and people have different opinions and you can't agree even on the most basic things. This is when everything collapses and things break down and the order breaks down. It makes it much easier to influence and to bring onto your side. I thought the growing use of AIS outlined in this report probably poses the highest risk we have seen so far because it makes all these attacks so much easier for Russia like it reduces costs. It reduces the entry costs especially and makes them more easier to believe. Whenever you see this kind of new stories, it's much easier to believe them because they look much better, but they're based partly on true stories and that makes it much easier to accept. At the moment, you start leaning into that direction. One stood out for me is that the Estonians actually believe that the NATO alliance is still very strong and that Article 5 stands and that the Russians respect it. Even in this narrative here, where the Europeans are complaining that the Americans are abandoning NATO and this continuing conversation, we get an assessment from the Estonians who are writing a story saying, "Hey, we believe that our NATO membership gives us a level of protection because the Russians are calculating that Article 5 still exists. Why don't you get a chance to scan this report at all?" A bit, not definitely not as deeply a site like to because all the stuff that comes out of Estonian intelligence about Russia is usually really very good. I think for a while what you've had journalists like Michael Weiss who have seemed to be taking a great deal of input from stuff that comes out of Estonian intel and making some pretty great assessments out of it. The NATO part of it, let's just be clear here, right? If NATO members start to talk about NATO as if it doesn't exist and at about Article 5 as if it's not real, then it's not real. I don't take this as an assessment of the reality of what NATO and Article 5 are. I take it as an expression of commitment, at least on the part of a very small country in a very precarious position that needs NATO and Article 5 to be a thing. Frankly, I don't even take that as some kind of naivete or anything like that. I just take it as like that is what a responsible player has to do when they claim that a policy and a group and a government stance in whatever are real. I would expect the same of basically any and all NATO members. If anything, the discussions about the US's current approach to NATO almost all have to do, mostly talk about the irresponsibility of talking about it that way openly and publicly. Because it's to say that if we have legitimate gripes against how NATO has been run or how much we are investing into it as opposed to other people and so on, those are things that I think folks would be open to and welcome to discussing in private. When you have those discussions in public, yes, that adds perhaps negotiating pressure or whatever, but it also delegitimizes and scares folks about the reality of a reality of the alliance. That is not desirable when you have folks like the Russians who are, as Kosen mentioned, they are looking to split folks into different alliances. They are looking to somehow delegitimize and demotivate and find those psychological fracture points precisely to take advantage of them as ways to change these things. I don't say that as some kind of russophobia. I say that as that has been an established practice in Russia as far back as the fucking checa. Thomas Rid of all people, one of our friends who's been on this podcast has written an entire fucking book about it. Acting like we're surprised or this isn't the way things are is a kind of ignorance that I self-inflicted ignorance that I don't have patience for. But I don't know what we do in this situation. What I would say is it's a really important time for NATO members that are not the US to show what it's like to be a successful, involved, invested part of NATO. It's a good time for everybody else to show that they do cool shit, that they know a lot of stuff, that they're willing to gird themselves and show their resolve and do some interesting things to push back on the Russians. Because that's what legitimizes the fact that it's an alliance and that there are many different people with a lot of different powers and a lot of different capabilities who are willing to put their best foot forward. And I would love to see some creativity. For me, the most interesting part was the assessment about the Russian economy. In what I obviously admittedly, what I had to glance through. Talking about the scope of the threat from the Russians is like, yes, yes, good to know. Yes, but where I am interested is in the things that the Russians, that the Russian government cannot control by virtue of just reality. It's the same way that you saw things happen at the collapse of the Soviet Union. At the end of the day, bread lines and bad central planning and frustrations and cultural fractures are things that you can't, you can lie about as much as you want and you can arrest people and you can throw them in jail, but people get hungry and people get pissed. And after a while, it's an ever escalating thing of trying to control your own people and trying to control the outside and trying to control perceptions and trying [BLANK_AUDIO] dissatisfaction and trying to prop up an economy while also everybody's stealing. And like you just have all these things that, you know, that no fortune can possibly outlive, but it becomes a matter of like strategic timing. So I'd love to see more pressure and more tightening of that news and just bring them to compliance in that way. Two things from the report and I thought it was fascinating. The cover of the report has, the cover of the report is fascinating. I'll put a link in the show description. Click on the Estonian report and look at the cover photo and just look at the cover and the first person to send me an email or get in touch with me and tell me what it is. If you know and we discussed it before, you're disqualified. If one of the listeners in the audience can look at it and tell me exactly what it is, you get a free, free body problem hoodie. There's also photo in it. There's also a photo in the report costume. It's a text. What was that about? I thought it was funny that Kaupo Rossin, which is a director of the general Estonian for Intelligent Service, he put a photo of himself in front of a tank, like a rusty old damage, a Russian tank in this like Ukrainian flag. The letters are Ukrainian flag. Yeah, Ukrainian flags and there's a message in there which reads Putin Hwilo, which is, well, rough translation would be something like Putin is a dick. It's very very graphic. That is the message he is sending. I love it. The cover, the cover is fascinating. The other tank also, it says something like Squadron or Battalion Azovu, which means the Azov. I guess she would be a Russian. I assume it will be a Russian tank, that one. An Ukrainian tank, I mean. Alongside this news, we got some reporting. And I mentioned this briefly last week, but I want us to dig into it a little bit. It's a German government actually drafting actual legislation to revise powers internally around what the German foreign intelligence services can do in conducting cyber operations abroad. And this is the notion of we're going to be, we're going to proactively do, quote unquote, talking back. We will do, we'll give our internal security agencies more powers to go externally and do things in response to what's happening here. And the thing that keeps popping up costing is hybrid threats. This is the things we want to fight back. Because war is one thing and hybrid threat is another thing. Can you, for the audience, kind of put hybrid threats into context? What is a hybrid threat? And why is it different from a cyber war activity? Well, do you remember the back in the days when we were talking about next gen security? I would say that the best analogy here is that the hybrid threats are well, the antagonist to the next gen security in essence. They're like no longer, let's say, kind of conventional threat that you know about, but the mix of all sorts of cyber operations that can include as well things like drone incursions or cyber attacks against critical infrastructure or again, a mix of sabotage or on the ground teams like as we have seen in the past from the GRU being on premise, trying to do Wi-Fi hacking and then leveraging that access either to still materials that they later disseminate online with tiny modifications for for their own purposes, such as I know, influence operations or swinging results of elections. So I guess all that falls into this category of hybrid threats, no longer kind of conventional threats, but a mix, kind of a mix of different things put together full spectrum, if you want, in order to let's say achieve maximum impact with very little regard to norms, regulations, international law or whatever kind of conventions exist that would prevent maybe targeting of civilians or medical institutions during war. Those, let's say, have little to do with what's happening nowadays. I mean, everything is on the table, everything is possible as we have seen with this Polish cyber attack in December. It doesn't matter that this is affecting civilians, it could affect hospitals, it could lead to people's lives lost, it doesn't really matter, everything is on the table. So I think that this is what what is Germany in the most. Me personally, I'm a bit skeptical because of the biggest problem in Germany, as everybody knows, even as emphasized by their chancellor is bureaucracy. The thing that he says at the moment, that's like the biggest threat to us that he could have probably fixed for the past years or so, but nevertheless that's the biggest threat bureaucracy. So with all that bureaucracy, I am a bit skeptical about passing all these laws and seeing them really implemented all the way to seeing the hacking back, taking place for real. Well, let's see, I think this week is also the Munich Security Conference. Remember back in the days our old boss was going there every year. I think you still need some kind of invitation in order to attend it. And we haven't reached that level of glow and glam just yet. Maybe next year, maybe one with a CNN appearances. We're not being invited. Nobody's inviting us to the Munich Security Forum to record a podcast over there. We need to attract more good luck. There is a major shift in Europe happening around an awareness that we have to do something different. Right one. I mean, this hacking back and the conversation gets all fancy smash. But there's just a general feeling based on everything I've read and everything I've followed that in Europe, there's a there's a dramatic shift happening around like we need to be going. We need to be able to go on the offensive. And my question to you is what do you think that looks like? I mean, I'm not entirely certain. I'm not entirely certain what it looks like or what it should look like. I'm far be it for me to to pretend that I'm some kind of war expert. But nobody's about checking us. No, no, no, I just want to I want to answer thoughtfully because I think there has always been this idea of like, well, they need to do more. And like, why aren't the Europeans doing more to defend themselves? Why aren't the Europeans doing more? And like, frankly, we make fun of the European Union all the time. And I think rightly so because there's for all the great traditions and all the amazing accomplishments of each of these individual nations on their own with their storied pasts and with their individual competencies, like none of these countries are anything to laugh at. It's not that they're incapable of doing things, you know, the Finns are pretty impressive in how they've dealt with Russia in the past as are the Poles. There's a lot to be said about what Romania and Latvia and Estonia and Sweden and all these other places can bring to bear. And of course, the Western European nations have have shown their medal, right, in World War Two and all these other parts and they can do things. The problem I think is one of a kind of cultural entrenchment in this notion of virtue signaling at the level of the European Union and European Commission and so on that has gotten so fucking out of hand that it makes them look silly and foolish. And it makes it seem that like we are going to default into hand-ringing so much as to watch things kind of fall apart without just doing something. And in this particular case, and I know we're supposed to be talking about Germany and cyber, but I think more broadly, when we're looking at a continent at risk of being overrun by a nation that has shown that they're willing to do so because they've done it before. The idea that you're okay letting the Ukrainians kind of bear the brunt and you're okay, you're hoping the Americans somehow come and fix things for you. And you know, you're saying you're strong condemnations and you're sending your strong letters, but then you just kind of like are still trying to deal with the Russians as far as like making, you know, getting natural resources and natural gas, right? Like Germany did not choose to not get natural gas from the Russians. A well-timed operation somehow took that option out of their hands. Those are the sorts of things where you look at them and go, guys like, what the fucking about a pipeline sabotage, right? Yeah, yeah, I'm talking about the pipeline sabotage, but you know, we could have discussions about that with like nuclear energy and natural gas and oil and a bunch of other things, right? Like there's this speaking out of both sides of your mouth in a way that just makes you look feckless and weak and kind of. It's a little disgusting precisely because you're not helpless and it's your security more than our security, right? If all of Western Europe turned into Russia, which is not, it's not going to, that's not exactly what's on the cards, but if all of Western Europe turned into Russia, we'd still be in a, you know, I'm not saying it's all the same. I'm just saying that like as far as the US is concerned, we're still just dealing with the same blocks, the Chinese, the Russians, the Americans, right, like whatever the flux happening in the Middle East half the time, just with greater resources. Obviously that's not what we want to see, but like you should have a greater vested interest in this yourself. Bring it, landing this right back down to the whole Germany cyber thing. Germany's approach to intelligence and cyber and military operations is like silly and sort of self defeating and I get it, right? Like you, you're still kind of traumatized from in its own way, from the polls or the Dutch. Oh my God. Come on. Like it's the Dutch is about example or the polls. They couldn't be any more different, right? And of course, like geographically you're in a different place, historically you're in a different place, right? Like a lot of Germany's hesitation about its own powers and its own military and what not is obviously about its history, right? Like what happened with the Stasi, what happened in World War II, what happened, you know, like they of course, there are legitimate reasons why you can be suspicious of giving powers to your own government and you want that to somehow go in a different way. And sometimes you just say, hey, look, we just don't trust ourselves with X, Y and Z. But instead what we see is like this kind of like, hemming and hawing, right? And like, yeah, you could have cyber, but no, you can't buy the tools. And like, yeah, you can do this, but no, actually, like we won't let law enforcement do it. We won't let the I.C. do it. Like yeah, we, you know, we'll, we'll claim that we're a partner involved in X, Y and Z, but the optics are so bad and we're unwilling to deal with the optics. So we'll ask the Americans to do it. And then when the Americans get caught, we're going to condemn the Americans for doing it. You're like, come, just grow the fuck up, right? Like it's that kind of thing. It was like, okay, and cutesy and whatever during the Snowden, like post-Snowden thing where we all looked at Europe and we're like, yeah, okay, you're going to beat us up for doing the things that you wanted us to do, got it. And then now, now it's actual wartime. And we're like, you can't keep going with this kind of. Well, they're not. They're drafting legislations and change things. And the question, the original question I asked is, what do you think this looks like? And I'll just put an addendum to it. It's like, are we worried about civilian blowback when all of this? We have the German initiative. We have France, the Netherlands, including offensive cyber capabilities. And they're like cyber strategies. We have Latvia talking about, you know, the only way to respond is to go do offensive operations. Are we worried that there's going to be some mistakes? Something that affects civilians at some point? No, I'll look. I'll believe it. What does this hack back looks like? I don't fucking know because this is yet again sitting like some bullshit of like kind of standing in the doorway, leveraging threats. Because why haven't you been cybering and what the fuck are you even going to do? Right? I mean, when it comes to politicians, when it comes to policy, when you talk about cyber offensive, to me, that's almost universally a stalling tactic. It's never like I never look at it as like, oh, look, they're finally going to pull out the cyber missiles, like, shit's about to get real. It's like, no, it's a, it's a kind of like bitch ass way of saying like, oh, we're going to do some shit. We're not going to do like shit you can see, but like we're going to do some shit and like, you won't even know what's happening. And you won't even know the fact that like we said we were going to do it and then we didn't do it. Right? Like it's just, it's just so fucking lame. Oh, Ryan, you're muted. So I know you're like pushing back, but I can't hear you. But it's not how we want it to work. We don't want to see it. We don't want it to affect civilians. We don't want it to affect water supply somewhere. We're not expecting the Germans to go hacking into Russia's water supply and poisoning people. If you wanted to be attacking their infrastructure at some point, maybe I would be military targets or I don't know. I, I, I'm not saying, look, a, if you're going to talk about it, then you better be doing something, right? Like, and that's my point, right? If the whole, you know, it's not even signaling. It's just bullshit threatening and then not doing anything, which is like, to me, that's about posturing internally. Because I don't think the Russians are sitting around going, oh my god. Now we're facing the full cyber offensive might of whatever. It's like, who the fuck cares? And also the reason I say stalling tactic is if you're willing to shut down the power with cyber, how about you just fly a couple of jets and bomb a couple of power plants? Like if we're at war, how about you act like we're at war, right? Like all this bullshit about like not setting off World War III and blah, blah, blah, like, are we there or are we not? Are we fighting or are we not? Are you defending European territory or are you just kind of hoping it doesn't come your way? Are you just kind of hoping we can make a little more money and everyone can just keep pretending for a little longer and maybe the Ukrainians will just solve this problem for us. And you're like, grow the fuck up. I'm even in the only European on this conversation. Costing looks around. Costing what do you think this looks like? I mean, what would you like to see change from what the current passive state is to what these rumblings are? How do you respond to what Juanito said about your European leadership? I think in my mind what they mean by this. So I say, well, these Rob hackers will destroy their infrastructure. This is pretty much in line with what the Interpol or like the Dutch police or the German police, the BKA, the BFV have been doing for many years against cyber criminals. So what does it mean? Like with the Brian somewhere, you just see their servers, you destroy their backups. If you want to be, let's say, be a bit more aggressive. Remember the discussion from a number of episodes ago when the US law enforcement went into this meeting and started bragging about the fact they hacked into some infrastructure and they started wiping servers and deleting backups. So all of that I think it's on the table because the potential for collateral damage is very little. If you just hack into the command and control servers used by, let's say, no name 05716, and you just wipe them. Or if you just, let's say, corrupt their servers so they no longer send commands or do you throttle their network traffic so they no longer deliver the commands to all the bots around the world. That is like an effective measure which has a visible impact. You can even measure the impact and you can say, yeah, we degraded or damaged their operations by 90%. So now it's only 10% of what they used to be. So all of that is, I think, on the table. In addition to that, also remember what the NSA did back in the days against the Russian troll farms when through an exploit from an iPhone that was temporarily connected into this air gap to network. They managed to get access. They wiped all the UPSs like they bricked their UPSs. They wiped all the servers and all the backups and left kind of a message like be careful. So this time we were gentle next time in sanctions and we're going to cut your Gmail accounts as well, your personal ones, including all your photos of your dogs and cats that you've been saving there with your Android phones with this particular phone number that you've been using to call your grandmother with this phone number. And these kind of things, I think, they've been done in the past. They're probably happening right now, don't we? I'm a bit skeptical about Germany doing this because of the bureaucracy problem they have and of course other problems. But FBI or the US doing all the things or the Dutch police, like we always held, we hold the Dutch in a very high regard because of their capabilities and willingness to use those capabilities. I think all of that is doable and it's on the table. Now, we're doing this. The willingness conversation, one, is a political thing. Is a domestic politics thing? In addition, aside from the bureaucracy and going through all those layers and so on, where does the willingness stop? I think it's a bureaucracy thing. I think it's an optics thing. I think it's a combination of almost like a diffusion of responsibility in some ways. But also the Europeans, sorry, forgive me for making such a caricature of Europeans. We have plenty of brilliant friends in Europe, coasts and being one of them. What are you talking about them? But like those other Europeans? No, like European politicians. Any place in the world, any country, any continent, there's the population and then there's like the politicians who pretend to be experts in some domain want to decide how you should do things. It's perfectly fine when you talk about Europeans if you refer to some of those categories. I'm sure, I'm sure it's referring to European politicians and bureaucrats. And because what I was going to say is the real problem with the European politicians approach these discussions is that they drink their own coolade way too much. They believe the bullshit that they sell to a point of ridiculousness. Try talking to some of these people about GDPR. GDPR is obviously a failed idiotic measure. It was completely a matter of patting yourself on the back for pretending that you won or change something. It's massively inconvenient. All it's done is degrade the quality of the internet and I've yet to see anything privacy wise that has been done other than enable a constant backdoor way for the European Union to extract fees from American companies from time to time without ever making any meaningful impact on privacy whatsoever and degrading our ability to do security by taking away security telemetry and giving everybody an excuse to throw away valuable data. So I don't know what the fuck GDPR ever did that was good in any way but try talking to any European politician or government whatever about GDPR. And I've done it at like embassy parties out here. And like you just see like there's just you can't get past the ideological bent that says that this was like a you know we put this on the board and it's amazing. I'm like look I'm not trying to tell you that your work is not valuable but like let's just talk about the mechanics of how this thing works. What the fuck does it accomplish? And I think and that again I'm not trying to just criticize the Europeans. It's more that that same shit applies when it comes to cyber. The same nonsense that we talk about with like offensive operations and privacy concerns and oh my god what if we hack the thing and it was the wrong thing and then a hospital turns off and a baby dies. That kind of you know overwrought narrative that's meant to like speak to simple minded voters who don't understand cyber at all is the same level of thinking that is then applied when the conversation is being had at least in open forums for European bureaucrats. And that means that you never have a serious discussion about what cyber can and can't do. Moreover what cyber should be used for always versus what it shouldn't be which is why when they start talking about like oh the gloves are coming off we're going to use cyber offensive and like well that's not even an accurate representation of what you normally would use cyber for. Normally most cyber is about espionage prepositioning understanding scoping operations and packages and then making decisions about other shit that you're going to subsequently do which is why you don't need to announce it because it's not an end in and of itself. It seldom accomplishes an end in and of itself. So like you should be cybering all the fucking time for all kinds of things that are mostly enablers for decision making and an understanding of your adversary and looking for opportunities to have effects and those effects may be cyber effects but they may be getting a group of people you've already positioned in Russia to go shoot a fucking general because you know where he is because you know where he lives because you know where his phone is because you know all the shit because of cyber but it's not like the cyber is meant to kill the general. So I hope you're already fucking doing it. So what exactly are we talking about differently here that you're willing to now use cyber operations to do kinetic effects? Okay so you're willing to have kinetic effects inside of Russia? Okay well then until you get your cyber shit together how about you just fly a fucking plane and drop a bomb? Oh no! Oh you won't do that because those are not the kind of kinetic effects we're willing to do. So then what are you going to do with the cyber that's different than with a jet or a missile? Well what are they doing with the cyber that's different from a jet and a missile is these hybrid type of disruptive type things some train lines? But Ryan that's them being willing to have kinetic effects in other countries and half of the time those are Russian operatives walking in there and shooting someone or blowing something up or doing something physical and we are saying you know sorry the Europeans are still in this kind of like bullshitty stage of like well we're not really in the war we're not really willing to do these things inside of Russian territory and I say if you're still locked in that like bullshit fantasy that you're not at war a war just seems to be steadily steamrolling your way and you're just going to wait until it shows up then what are we pretending that you're going to do with the cyber is here because you're waiting and leaning forward on purpose you guys jump you jumped like very quickly once at embassy parties can we go back to that what is an embassy party what happens let me answer let me answer let me answer an embassy party is the next place you go to the night after the opera I'm sorry we found out we found out toston sings opera today and what we're going to focus on is my like social life I've known this man for what like 12 years now never has he sang any kind of opera for any of the second world you the first one who went to an opera I was going sorry embassy parties are things that have enough to you these the ballet wow man mr. Bushy over here all I'm saying I'm just asking what else that's that's the one thing I won't say but like no because I mean they're kind enough to invite you and the last thing I want to do is put them on the spot yeah of course you don't go to a number to invite you well because then you and I don't get invited anywhere bro to a embassy parties no one it was a representative we're missing yeah I'm there repping the podcast I show up with like a banner and a little pin you know once all these legal once all these legal frameworks are set up are we expecting to see hybrid activities in in adversary territory are we gonna are we I mean is not the expectation is not gonna be a it's not gonna be in a connectic attack like Juanito says is just too much too much surrounding now what do we expect to see I don't know put a bow on this conversation from Europe costing man I still remember you're still recovering from the embassy parties there's Romania have a policy around offensive cyber well Romania probably still doesn't have a policy when it comes to droning accursions to shooting them down like the legal framework is still probably not entirely clear but I heard that now there is permission like the fighters the fighter pilots they do have permission to shoot down drones but like in terms of cyber I think things are very very unclear but in general Romanians like it when things are unclear why because when things are unclear you can find solutions around it when things are clear and very you know in the letter of law then you can just yeah but if things are flexible and you know it's it's unclear if it allowed is not allowed if you're a state institution maybe you have powers your powers include that and that which doesn't specifically exclude cyber then you can do it no problem now I I don't know I think one of the biggest issues when it comes to to this hybrid russia uh word that is happening at the moment and hitting Europe I think the biggest issue is the one of deconfliction the one that we keep discussing over and over for decades when it comes to advanced APT operations because let's say that at the same time Netherlands and Romania decide to hit something like some kind of a troll farm and they end up breaking each other out of that troll farm and the troll farm they just take the hard drives and they go to the best forensics company in Moscow and then they publish like the full report exposing both the Dutch and the Romanians and things are bad so that's why I think deconfliction is the number one issue and that's why I think that everyone is kind of passively watching things because they're afraid that might somehow do something that others might be unhappy with so far what we have seen is that the Dutch are yes super active remember the spying on the APT 29 office building lobby that has been happening years ago and also this NSA operations against the troll farms in San Peter's birth so those are active for sure and we know also from the Snowden documents they were cooperating on different topics like exploitation and foreign access and water holes and things like that now how much how many of the other countries in Europe have joined I think probably not all lot. And I think the biggest risk is they could be like targeting something at the same time. And you know that with such sensitive operations, the confliction is very hard. I can see it happen within the five eyes or the eleven eyes or the extended fourteen eyes. But I don't know if that would be a less available for the smaller countries like Romania that typically concern themselves with other things such as trap music or football or show or or I don't know what trap music. Now he does. You let him know about bad money last time. I had no idea what the bad what a bad money was. I thought that you guys were talking about the mascot or something. Honest to God. I had no idea. But I documented myself. I know it's a singer and also some kind of MMA fighter and WWE wrestler. What is that now what you can wrestling the rest of the work is a fake wrestling is that fake or real it's fake right it's all that fake like with the guy like with the meme with the guy on the chair like yeah that's that one right yeah yeah this we just got to I am moving on because we're not going to have anybody but it's lander in this chat that's fair. We can't survive that no one can survive that name one one song by bad bunny our our our our friends at Reuters. I'm not encouraging any sort of bad bunny slander we can't survive. Our friends are foul and AJ from Reuters have an exclusive that dropped yesterday that mixed the claim that Palo Alto Networks diluted references to China in this most recent report that they published amid concerns about potential retaliation from Beijing. Why don't you throw this at you for us because you warned about this multiple episodes in previous shows that companies are deliberately not publishing or even not researching because of this China and you tied it to you know their company doing business in China making their devices in China blah blah blah in this case they're talking about potential retaliation retaliation from Beijing. What do we learn here and is this going to be like the the state of play moving forward with other research houses. This has been the state of play for a long time for a bit and that's why I've kept talking about it. I actually feel kind of bad for for Palo in this situation and that like you know these folks did some good research and you know the the campaign report is really interesting it talks about a shits on a victims there's all this like really great research with IOCs and like it's a long report they pre-brief people like they shared with other people in the community to help them enable stuff and then you know presumably someone in the leadership or in the marketing team or in whatever or in legal says yeah but you can't say this one word you can publish the whole thing but you can't say China and they go yeah okay well we'll push our shit and then it just gets fucking clobbered to death over that one and like you know so I ate my my sentiment like my my let me set the scale for you go sorry yeah go for you go it's an early there was an earlier draft of the report that allegedly linked it to China but the final public version described it more as a state aligned group that operates out of Asia so they kind of just kind of create a clean the language up a little bit and pushed it out. Is that something you've ever been asked to do? No well I'm trying to think right like I don't think I've ever of course at some point is it inappropriate to us guy that's I'm trying to get a sense of it is this even a story? Well I think it's inappropriate to ask in the sense of like I personally believe that like researchers need to have a certain level of autonomy and if you want to position yourself as somebody with a reliable trustworthy research capability then playing editorial politics is a way to defeat the entire point of pushing like publishing something right if if if if if every time we got a paper out of like I don't know the team that does quantum research at Google and they fucking omitted things in there because they think it's going to upset a trade partner or something like that you know maybe that does happen but it certainly doesn't ring of science right it doesn't ring of objectivity and I think that a lot of companies these days they have these spineless fucking marketing departments with no experience they have these overreaching lawyers and they have this weak leadership that thinks that it's appropriate to just kind of like just cut around the edges and make it convenient and whatever what they end up doing is they try to avoid a short-term problem and in return create a long-term problem which is you you're kind of taking away the value of what publishing this sort of research does for you which is to make you look like an objective partner like somebody reliable like your trustworthy like you're on top of things like you know things that other people don't know and like that's the whole point of investing into R&D and research and public research and and I resent that and I've been complaining about it for for years openly because I see it as a kind of vicious self-reinforcing cycle that has really cratered threat intelligence as an industry because and I know I've set this before but like if you if if Microsoft invests a fuck ton of money into a threat intel team and it's an expensive capability and part of what that capability provides is the legitimate C the wherewithal the brand recognition the trust from customers the the positive regard from governments and IC partners and everything because you go holy shit look at what mystic does and what we do without mystic and thank god that Microsoft is willing to pay money to keep this thing and give them data and enable them to publish and blah blah blah blah blah and then some asshole shows up and says well actually you know do we really want to deal with the optics of this and why are we doing like maybe don't publish and don't say this and remove that part and actually instead of 10 blogs how about two and out of those two how about no IOCs and out of this like just remove that and actually why are any of our researchers tweeting and why are these people involved in any government forums and why are they talking to IC directly without any lawyers and why and like you just keep cutting and cutting and cutting and cutting and cutting and cutting away and then you have the goal six months later to be like why are we spending all this money on these fucking researchers they don't provide any value they don't do anything why are we spending like millions of dollars on a research team and giving them data and dealing with this and that and the other when they don't seem to give us anything back as a company and that's that's a situation that has repeated itself at a bunch of places out here and I resent the absolute shit out of it so you know I feel bad for for Palo Alto getting this kind of reaction do you think this is going to be standard operating procedure for Palo Alto moving forward in that it'll be it'll be a state-of-line group that operates out of what I can't I can't speak for for Palo but look we've been this is something like again I feel bad that that people are kind of like Palo has become the example openly because it was such a like the switcheroo was so you know evident but we've been having the same conversation about Cisco and there's been like back like things have like kind of leaned forward and then leaned back and then leaned forward we've been we've had similar conversations in the past about Microsoft we've had similar conversations about a lot of people and and so Palo might be like today's like whipping boy but this is a bigger issue than that and it's and it I don't want to talk about is this going to become standard operating procedure it seems to have already become that for a lot of places because then it's just different to when when you were managing great in the early days we never did attribution that was one of the things because Sportski doesn't do attribution but we'll say Russian speaking Chinese speaking how is this any different by saying yeah it's a group out of Asia and you you make the connection versus red dragon is Russian speaking but we don't do attribution well I guess what was that what was that policy about so I think it's no different from I don't know instead of saying Chinese hackers saying green panda or like just using animals or like using all sorts of names like I don't know red void like colors or other things in order to avoid the word China so this is not necessarily something new avoiding the word China in a blog what I was thinking here is that probably what matters to this story because it didn't matter in the past there might be two or three things one is is they kind of say that fearing they were fearing retaliation like what could retaliation look like and I can tell you what I heard in the past like what people were fearing in the past. I heard that if stories were about to be published naming China directly, then China would have no other choice than blocking that company's website in the great firewall of China. So that means nobody in China would be able to access that website. They would be able to get updates. They would be able to get products or information or they would be able to get support. So that would be like the first stage blocking the website which directly names or blames China for a hack. So I heard that there were such kind of threats in the past. What could follow from blocking the website and fearing retaliation is just to ban the vendor. Remember like last episodes we were talking about China advising not to buy from what was it? Israeli vendors and the American vendors. They were already kind of advising not to buy that thing. So I think Roy just mentioned this in this report. The language is often following the news that Chinese had banned the software from the US and Israeli companies. Possible. And I think yeah, the other issue here could be like the website can simply be just blocked in the great firewall to deal with it. Like that would be the first levels and then just removing you from the market. I don't know how big the Palo Alto market is in China. Like how popular these things are in China and if they're like really worried about that. But like to me honestly the idea of attribution it never sounded like a very wise thing that you want to hype or advertise. I do know that it was like very important back in the days that you have some kind of naming and blaming in your publication. If you don't have that nobody will cover it. Like the New York Times they just don't care. They're not going to cover your blog if you don't make some kind of extraordinary claims blaming China or Russia or whoever for it. If you just say things like a hacking group from Asia there's an we're not going to deal with it. So in a way I understand these decisions and to me like I said that the idea of open attribution it never sounded like a very wise idea against any country unless you want to become part of that geopolitical game. If you're saying like yeah it's fine to do it against Russia and China but we're not going to do it against the alienations again it means you're part of some game. If you're doing it only against one country but not the others again there's like some kind of a bias. So what is left there like if to be honest like what is the most valuable thing in such stories are the technical details the analysis the IOC is the samples that you talk about the techniques all of that is the most valuable attribution like everybody will figure out what it is you don't have to say China it's absolutely fine if you say green panda or red void or whatever but there's also another situation by super important situation which I know that the Chinese get very very upset when they spot anything like that which is companies or people trying to blame or expose them for domestic operations. Bits CT or like anti-extremist operations or like let's say they're targeting of Hong Kong or they're targeting of things like Falun Gong or any other like religious groups they get super super upset and they get the most upset when companies publish about their counterterrorism operations this is when they get the most upset. Now I was like really curious if this story has any kind of CT angles and it seems to me that maybe not so it's not necessarily a domestic spy operation and it's not like some kind of a CT operation which wouldn't explain like why they would get so upset with it but nevertheless there might be something in this story that we are missing which made China upset and it's quite possible again not entirely. Do we know if China is upset or this is what I mean it's not entirely impossible that actually China received an advanced copy of this research one way or the other and they reached out and they said you better not publish that or say China or else which is like I said this has happened in the past according to my my information and I wonder if that also happened in this story. I mean you hope it did because they what what I think is a more concerning situation is self-sensory because they think the Chinese are going to whatever and frankly there are situations where the Chinese have overreacted or or made it clear they were upset about something then there's a lot of situations where the Chinese did not give off fuck and like there are way more situations where the Chinese do not give off flying fuck what we're saying what we're reporting you could have proof you could have emails you could have contracts you could have videos of the guy literally doing the tasking and the other person literally pushing the button and they would just look at you and be like you guys should really stop lying about what China does and other parts of the country the world anyways you know be better partners and like that's it like they're just kind of like yep don't give a shit Teflon Don China like approach I think I think it's pretty unfortunate that this is why we this is why we're talking about our report when the actual work was so significant and it was an amazing report it's this unit for the two on TGR ST8 1030 I don't know about this naming convention but it's the state aligned group and as Kostin mentioned targets are primarily government ministries and departments internationally five national level law enforcement barter control entities ministries of finance and various government ministries departments globally that align with economic trade natural resources and different it's an amazing incredible report with IOCs that they shared and so on and the fact that one word or this kind of political language I don't want that to take away from the quality of the work and that that came out to the folks at all and there's there's another by another angle that I think it might be relevant here this is one of those things that is big in the sense that Palo Alto even says they compromise government critical infrastructure organizations across 37 countries so it's massive whenever we in the old days we found something like this we would actually reach out to those 37 countries and share a copy of the report in advance and say hey we think that you have victims in your country here's a list of infected IP addresses I don't know here's based on our sink holding or partnership with another group sink holding the infrastructure we think that these entities are infected and what may happen when you notify 37 countries about something like this and you send them an advance copy of the report and your advance copy says China hacked you you would expect 37 countries through their Ministry of Foreign Affairs to write an email to China and say what the fuck like what the fuck China you hacked us and they get 37 emails on the same day and then they get upset and they're right back to Palo Alto and they say what the fuck Palo Alto like what are you doing here like you're getting 37 countries to shout at us and to accuse us like what's going on so this is like one of those like full circle arrows so that can be happening and I think that yeah that's one of the possibilities we need to keep in mind I want to mention the other story on this list here we're getting through it is the Singapore government actually published a report on its largest multi-agency cyber operation the counter threats and from an APT and they mentioned on 3886 conducting targeted campaign against all four major Singapore telcos and one Simba Singtel star hub does not continue on China either so this is not just Palo Alto the Singapore government is I mean we know who on 3886 is because in anything to learn in this Singapore telco hack is this another typhoon is it the typhoon people in a different country what is this what is this it's it's a good question when I saw I saw the report by the way and I picked even our good friend Vitali who lives in Singapore shout out to Vitali and I asked if he if he has seen this report and if he knows anything and unfortunately this CSA which is maybe a bit similar to CSA from the United States they they put out this press release without any kind of technical IOCs maybe they shared them privately but I haven't seen any any myself one thing I can tell you for sure they were talking about tank 3886 for some time last year when I was at Blackhead Asia they were talks from Singapore government that were like a referencing of on 3886 perhaps indirectly or even directly so they were clearly very worried about this particular predictor now I think it would have been better if they included the IOCs which are different from the Google reports, which I think are the reference reports we have on these tradactors. They publish, like I think, in the series several reports, which dealt with the all the tools, like the techniques that these guys are using, their virtualization, tools at their root kits, all those things, which are fascinating in my opinion. And I think also it's quite interesting that our friend Will Bouchido token on X, he publishes his own analysis of the infrastructure related to on 3886 using the team Cumbri toolset, team Cumbri, they have this amazing net flow visibility, which allows them to track interesting things and will found like a bunch of additional goblets, tiny shell infrastructure in Singapore, which theoretically could be related to all these intrusions. I think, yeah, this is a developing story we're going to hear more of Fung 3886 because this is a gift that keeps on giving. There'll be for sure more stuff coming out from Fung 3886. Is it the safest assumption that all these old-school telecoals running on old backbone technologies are all owned? I mean, when we look at the typhoon reporting here in the US, Singapore acknowledging this bell jaccom, all of these stories over the years, it just feels like these places are just hubs for malicious activity happening here. Well, the thing is, so there are like some, we work with some telecoals and trying to help them because they were seeing the stories and if you read the stories, you saw that like, this telco was owned for like that many years. This telco was owned by three different directors and this telco had five different directors or this telco started doing for incident response for some Iranian group and they found like something else, which is not different. They're both reds. So they're magnets, but at the same time, there are some boring telcos, which have nothing of interest and like no matter how much you dig in those boring telcos, you don't find anything. Now, I would expect that Singapore being what it is like the jewel of Asia, they would attract a lot of interest and let's keep in mind what it means to target all these telcos. It means a lot of visibility and potential for fine grain targeting of mobile phone users of their communications SMS is maybe even hijacking their accounts, be telegram, what's up accounts through SMS interception like all these systems, which are insecure and rely on SMS based the registration. They can be hijacked through telcos attacks and all of that becomes possible when you have persistence and you are very deeply intertwined into their infrastructure, which I think is the reason why this group is so successful and why it's going specifically after telco netters. The other thing is that they do have a lot of equipment, including their infrastructure running things which unfortunately don't support direct monitoring through the R agents. You can't take Sentinel one and run it on these 14-net appliance, like here we are with 14-net again, or this Ivante appliance or whatever. So unfortunately they have a lot of things in there, like in some cases, even very old San OS or Solaris systems or God forbid the IBM AX systems running all databases with no protection and the moment that you get access to them through some user password and you deploy your tool set, you can happily leave there for decades before you get kicked out with some new hardware upgrade. No Iox. No, Iox from the government. The Singapore have a sort that is active. The CSA is I think it's pretty, the Cybersecurity Authority is a pretty mature organization and I would say they have very, very skilled analysts but I guess that, you know, remember what CSA used to be a couple of years ago when they were just doing the first steps, right, back in the days of crabs, like they were just doing small steps trying to come out into the world, publish something, no Iox and then you learn and then you include Iox, no Iraros, include Iraros but are bad. You learn and you improve the Iraros, they still don't have, I don't know, Heather check, you improve, they get better. So it probably takes time before they achieve the same level of maturity in terms of publishing but at least I think there are things moving but we can always hope for best. I think that's about covers it for the stuff that we have, we're two fours and 15 minutes in there's a Quattinet patch, CV 2026, 2, 2, 1, 5, 3, why is this one significant cost? I see a Quattinet patch and it's just like, yeah, it's like another ice cream flavor, right? That's being made available for sale. It is but then I look at the same Singapore report there and you're talking about zero days bypassing primitive firewalls and I'm like, you know, this war brought to you by 14th and 20 and just like here there's a new 14th thing here, CV SS 7.5 in proper access control and it's just like the wheel just keeps spinning and spinning and spinning. Yeah, I'm terrible. I think I saw by the way there was an FBI advisory today which I thought it was quite interesting. They were talking about the fact that and it's interesting how they were showcasing the problem. They said attackers constantly target out of life or end of life devices that do no longer receive patches. So they were kind of emphasizing that Chinese APTs by the way they were like specifically naming Chinese APTs, including Voltaifun. They are targeting end of life devices kind of suggesting that you guys should get your things in order. You get you need to get your shit straight get rid of that 15 years old device and replace it with something new who's gonna pay for it not us obviously, but you're gonna have to pay for it. But it seemed like the entire structure and the way they were conveying the message was it's your fault guys that you're using end of life devices and you get hacked. But it is definitely not not the vendors. Good question. Good question, but like everything is arguable here. And did anyone tell me that when I bought this device that I can only use it for five years or when those five years passed, did anyone offer me a replacement for like whatever good price or even better? Did I somehow let's say when I bought the device was I like offered the option to pay this much for five years or pay this much for 15 years? I mean everything begins with choice and it feels there's no choice with these devices and the FBI blames you for running these devices after the end of life. And I should continue to support it for how long forever. I mean like what is the what is the degree I hate to be on this side of the fence, but what is the area? What is the what is the balancing point between how long I should continue to support something that I don't even ship anymore? I tell you one thing I like I like one idea that comes from the hard drive world which is the smart monitoring of hard drive. So hard drives have this smart as a a a R T features which allow them to kind of predict when the hard drive is going to fail. So you know the hard drive one day it will crash and this allows you to predict the day when it will crash and then it starts warning you in advance like hey hey hey this hard drive is going to fail you better replace it. So I like the idea that these devices would have some kind of mechanism. So they start telling you like one or two years in advance hey hey hey in 2027 this device is going to crash like it not is going to like be end of life and all over. So maybe they should make it crash then. It's going to crash like physically be dead like this this device has some kind of a lifetime like a car and this car like it's going to die like it's going to work. So you better find the solution. Start looking for an alternative here are your options. Buy a new one like get trade this in and get discounted one subscribe to a plan where we ship you a new device every year or sign up for extended updates which allow you another five years. 40. No this is 40 40 care. 4040 care. I mean there has to be some balance to it. I don't know. We have a new system 2025 when do you upgrade your Tesla Ryan? Every time there's a new part shipped. No, no, no, I mean like You have a you bought a Tesla right and you know the battery is gonna like get worse and worse So you're like starting already with the idea I need to to get rid of this Like the Tesla the iPhone you I change iPhones when the battery starts to degrade so apple actually Here's the whole iPhone wow Apple starts to degrade battery to degrade yes You don't want to know the battery No, I don't upgrade every year like this guy over here. I just replace the battery my iPhone For 12 months That's it my iPhone 14 lasted for like three plus years You replace the difference is do right that those those and the life devices continue to work They're providing internet access for doctors office forever When I what why am I changing something that continues to work in in the case of the iPhone and some of the other things You're describing is that it stops working it starts to break it starts to get damaged Maybe they should maybe these and the life devices need to be Poked to stop working. I don't know sound like lead red like we start blinking like I'm dying here man It plays me then these companies would have to admit that They're doing this. I think part of the the situation here is right like you're kind of telling people that they have some level of autonomy With the investment that they've made But they don't but they don't and you're also not willing to allow them to have some other mechanism right like if you've end of life this device Why can't I maintain it myself Like if you've end of life this device like where are the third-party support Companies that are going to provide me to buy another one for a hundred dollars Are you gonna be supported to get with fire for where I'll do it yourself? Come on But like are we talking about a hundred dollar devices? I thought we were talking about you know enterprise grade if 10k 15k Devices I'm talking about like these so-ho home rotors thing that's what nobody gives that's trash That's it's trash, but at the same time is what's causing a lot of problems as well and these armnet works until they're right So let's talk about this right these fucking you know that we're talking about like the Europeans suddenly taking on offensive cyber You know what would be like you know be like life changing right now for the quality and health of the internet If somebody went out and just bricked all of these Soho cameras and so-ho routers that are vulnerable and you can because they're vulnerable so This you know you want to do some cool shit. Okay. Well the Chinese are Cool shit. Don't don't encourage people to do like go breaking people's routers. Why it's keeping Ryan? It's literally because there's a hospital somewhere where there's Blinky lights attached to that hospital. There's a hospital with a so-ho router somewhere like there is I'm telling you Who cares? It's being used by the Chinese to direct a bunch of operations into the country that are causing all kinds of other damage which also means that if the Chinese ever wanted to brick them they can so You know like this is it's great. We're being we're being held at risk by These things and we pretend that it's out of like an abundance of caution for these people. It's like no But nobody's willing to just make some tough choices Don't encourage people to be too tough to grow a pair and go break some shit. I think our only salvation is our good friend Mr. Silas There we go. Silas is gonna break all these devices Showed us the salvation. I don't know Shout us to Silas and we're all rooting and hoping for Malshair to come back like Living without Malshair is a pain. Well, you know, that's what you get unreliable hosting It's uh, yeah I think close the show with some shout outs we're two and a half hours in and we're very By the way, did you guys see people on Reddit describing the podcast? There's a lot of long long rumbling like the rumbling Really? 12 minutes of rumbling What I did or was it it was already some of us describing the three-body problem or these guys go deep into the topics but they're always rumbling Oh Stop the rambling and give me some shout outs. Let's close the show. Yeah, our jokes Yeah, give us a joke The final jugs Um, I promise to give you the joke with the Romanian Shepherd So you're not gonna escape the joke Yeah, hit me because I think it's relevant to to what kind of thing some people are posting on X So the story goes that like the American tourists comes to Romania and it goes like deep into the mountains You know, there's shepherds there's shape like they're making cheese all these kind of things and Typically the shepherd had they have a lot of time to just you know Think about the universe and this is how some of the most impressive Romanian literary works have been created Then they talk about shepherds doing very wise things or basically the Indians they have the gurus and Um, you know, they call this sages and we have the shepherds So the American tourist goes into the mountains and he eventually finds a shepherd It goes to the shepherd and he says shepherd What are you doing? Are you sitting and thinking about the mysteries of the universe? And the shepherd says I'm just sitting dude So sometimes people are just sitting not necessarily thinking about the mysteries of the universe Right, it's face, I can't with these fucking jokes I can't It's true, it's a good word It's a rabbit and his son was better Not a rabbit, yeah Some asshole in the Ferrari Yeah, why need to close the show with some shout out to you. I always got we got a bunch of people doing important things I mean, you know I mean shout out to the researchers at Palo Alto, amazing work. Sorry for like a bad reception Shit happens. It's happened to all of us at some point and it's always, you know, it always Stub leaking the shit to edgy Nah, no, no, no, no, no, look Look, what I feel bad about in that situation is like that is a story that I want written Oh, I was great adjusting as well. I was joking. I feel bad for the Palo researchers Who just did an amazing job at what they're supposed to be doing and then kind of, you know, got shafted in the politics that are also valid politics to criticize But shout out to those guys, you know, I'll make you keep up the amazing work Pete and everybody else and in the team my carbison Like they've got some great folks once again reminders about conferences right Reverse Reverse is coming Echo party Miami's coming Pivot con I mean pivot con CFPS closed and registrations closed So you either got in or you didn't and and you know hope to see you folks there And then laps con where we're getting our sponsors buttoned up So this is a great time to to get some of that support in and we obviously greatly appreciate it and This one has to be a particularly special lapscon so would would definitely love to have folks involved And then I think the the true shout out is I mean you shouted out Silas cutler already But let's take a minute to to appreciate just how much work Silas has done for actual community projects and actual visibility like malshare alone, which is what a lot of people depend on for access to malware samples is just a thing that Silas has Created and maintained of the goodness of his own fucking heart For more than a decade for a long time Um, and he's got way more projects that we're all kind of like Kind of morning right now because of you know some of the Not so pro social actions of certain people who claim to care about community endeavors, but then don't But in any case Shout out to the folks that really do contribute out here and and who are willing to do this shit Silas has a family and a real job and a bunch of other shit to do and the fact that he spends his time doing this stuff for everybody else is commendable And you know, we'd be in a much better place if folks like that Had all the hosting in the world and had all the support in the world and for all the companies that would like to pretend that they're Well, let me put this differently For the companies that are actually interested in supporting community endeavors There's one right there that could use a lot of support. So I hope to see you folks Kind of coming out to support Silas and coming out to support the community things that actually make a difference And and you know god bless all of you guys Moving forward there. I just want to give a quick shout out to well said by the way well said one e2 and companies looking to Prove their metal in terms of community support. There's a lot of activities conferences Smaller things projects looking for help. I just want to give a shout out quickly to the guys at NATO thoughts Eohin you Beninkas Made a no ski had a pretty Fascinating report out this week on the TN FU Cup return of China's TN FU Cup in some secrecy being run by the US government Maybe we'll get to it in the next the next show. I thought it was a really really good report. That's a kind of like like Deep research in a foreign language thing that I really really like I wanted to shout out those guys as usual. Thanks to our sponsors Haroon Mir and the folks at thinks for continuing to sponsor the show the folks at threat locker the folks at material security will support the show shout out to those guys and I think that's our show for this week guys we'll catch you next week. All of you going to embassy parties party on balay opera embassy parties that's the order. Bye bye. Bye.

Podcast Summary

Key Points:

  1. Thinks TKnary offers proactive breach detection using decoy tokens that alert when touched by attackers, minimizing false positives and admin overhead.
  2. The hosts discuss frequent CNN appearances by one speaker, highlighting the challenges of condensing complex topics like cybersecurity into brief, high-pressure TV segments.
  3. An incident in El Paso involving suspected cartel drones led to a temporary airspace shutdown, sparking speculation about anti-drone technology and unclear official communication.
  4. The conversation shifts to drone warfare's ubiquity and cost-effectiveness, contrasting high-tech military solutions with cheap, disposable drones used in conflicts like Ukraine.
  5. Updates on the Notepad++ supply chain attack include new IOCs (hashes, IPs) linked to a tool called Suo5, and analysis using Ucatami's Karibu system to find related malware samples.

Summary:

This episode of the 3 Body Problem podcast begins with an ad for Thinks TKnary, a cybersecurity tool that uses decoy tokens to detect breaches early. The hosts then humorously recap one speaker's recent CNN appearances, noting the difficulty of explaining technical topics like hacking and AI in 90-second TV segments. The discussion pivots to a drone incident in El Paso, where airspace was briefly shut down amid rumors of cartel drones or anti-drone weapon tests, highlighting concerns about drone warfare's growing proximity to home.

The group debates the efficiency of anti-drone technologies, from lasers to drone-on-drone combat, emphasizing the cheap, disposable nature of modern drones. Finally, they provide updates on the Notepad++ supply chain attack, sharing new indicators of compromise linked to the Suo5 tool and analysis from Ucatami's Karibu malware-hunting system. The episode blends cybersecurity insights with casual banter about pop culture and current events.

FAQs

Thinks TKnary is a security solution that deploys decoy tokens called Knaries to detect attackers early. When an attacker interacts with a Knary, it triggers a high-confidence alert, providing early warning with minimal false positives and admin overhead.

The speaker mentions being invited for segments on hacking, cyber, and AI topics, often with short, high-pressure appearances of about 90 seconds. They appreciate the opportunity to clarify issues but find the format challenging due to its brevity and intensity.

The FAA temporarily shut down El Paso's airspace due to suspected Mexican cartel drones, sparking rumors about anti-drone defenses like lasers. The closure was initially announced for 10 days but ended sooner, though official details remain unclear.

Discussed technologies include high-energy lasers, jamming systems, and using other drones to intercept threats. The effectiveness and cost of these methods, such as Israel's $10-per-shot laser, are compared to traditional defenses like missiles.

New IOCs (Indicators of Compromise) were released from Hostinger's incident response, including hashes and IP addresses linked to a tool called Suo5. This tool is a fast reverse proxy used by red teamers and APT groups, but details on a kernel exploit remain scarce.

Karibu is a malware analysis system by Ucatami that allows hunting for similar samples across a large collection (petabytes in size). It helps identify related malware, such as additional Lotus Blossom samples linked to the Notepad++ attack.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.