1
00:00:00,080 --> 00:00:01,720
Welcome back to the Awareness 
Angle. 

2
00:00:01,720 --> 00:00:04,960
This week we're exploring what 
happens when AI gets powerful 

3
00:00:04,960 --> 00:00:07,880
enough to find and exploit 
vulnerabilities on its own. 

4
00:00:08,160 --> 00:00:11,960
Thanks to Anthropics project 
Glass Wing, we've also got 

5
00:00:11,960 --> 00:00:16,040
serious Grafana floor that turns
AI systems into data 

6
00:00:16,040 --> 00:00:19,760
exfiltration paths and a leaked 
Window Zero Day which is 

7
00:00:19,760 --> 00:00:23,320
handling attackers system level 
control. 

8
00:00:23,480 --> 00:00:28,000
On the human side, attackers are
using fake missile alerts and QR

9
00:00:28,000 --> 00:00:30,840
codes to steal Microsoft 
credentials at scale. 

10
00:00:31,200 --> 00:00:34,240
Then there's big, big policy 
questions bubbling under the 

11
00:00:34,240 --> 00:00:37,440
surface with major proposed cuts
to CSA. 

12
00:00:37,880 --> 00:00:41,480
All of that and the Fish of the 
week, and a whole lot more on 

13
00:00:41,480 --> 00:00:54,760
this week's The Awareness Angle.
And with me, as always on this 

14
00:00:54,760 --> 00:00:57,520
week's awareness angle is my 
partner in cyber crime 

15
00:00:57,520 --> 00:00:59,320
prevention, it's Mr Luke 
Pettigrew. 

16
00:00:59,320 --> 00:01:01,520
How you doing, Luke? 
I'm doing well. 

17
00:01:01,520 --> 00:01:02,440
Thank you, Ann. 
How are you? 

18
00:01:03,080 --> 00:01:05,160
I'm good. 
Yeah, Let's get straight into it

19
00:01:05,160 --> 00:01:08,360
then, with this week's breaches 
of the week. 

20
00:01:11,320 --> 00:01:16,360
OK, I'll kick us off this week. 
And the first one, hackers steel

21
00:01:16,360 --> 00:01:21,080
and leak sensitive LAPD police 
documents. 

22
00:01:21,280 --> 00:01:22,800
This one's coming from 
TechCrunch. 

23
00:01:23,200 --> 00:01:28,760
Cyber group Cyber criminal group
World Leaks has allegedly stolen

24
00:01:28,760 --> 00:01:31,720
and leaked a massive data set 
linked to the Los Angeles Police

25
00:01:31,720 --> 00:01:36,320
Department via a third party 
storage system tied to Los 

26
00:01:36,320 --> 00:01:40,120
Angeles City Attorney's Office. 
This includes Office of 

27
00:01:40,120 --> 00:01:44,800
Personnel files, Internal 
Affairs investigations and 

28
00:01:44,800 --> 00:01:49,720
sensitive legal discovery 
material and unredacted personal

29
00:01:49,720 --> 00:01:54,480
data such as witness identities 
and 7.7 terabytes of data. 

30
00:01:54,960 --> 00:02:00,160
337,000 files were reportedly 
taken. 

31
00:02:00,840 --> 00:02:04,400
That's that's hefty. 
The LAPD say their own. 

32
00:02:04,400 --> 00:02:07,640
Systems were not breached, but 
they are investigating the 

33
00:02:07,640 --> 00:02:10,960
situation. 
That's quite a scary one That's 

34
00:02:11,520 --> 00:02:14,800
it's a lot of data and 
especially unredacted witness 

35
00:02:15,120 --> 00:02:17,040
statements and stuff like that 
that's. 

36
00:02:17,440 --> 00:02:20,760
Frightening everything. 
You don't want to go public, 

37
00:02:20,760 --> 00:02:24,480
right? 
World Leaks, I hadn't, I don't 

38
00:02:24,480 --> 00:02:27,120
remember I was talking about 
much before, but apparently 

39
00:02:27,120 --> 00:02:30,480
they're a rebranded group that 
were previously known as Hunters

40
00:02:30,480 --> 00:02:34,320
International and that name does
ring a bell, but they've been 

41
00:02:34,360 --> 00:02:36,240
all over the place. 
They've healthcare, 

42
00:02:36,240 --> 00:02:40,800
manufacturing technology. 
So yeah, they're all they're, 

43
00:02:40,880 --> 00:02:43,440
they're not fussy. 
Who they who they attack? 

44
00:02:44,000 --> 00:02:50,080
Which, yeah, yeah, and again, 
the third party tool being the 

45
00:02:50,080 --> 00:02:54,040
supposed culprit. 
Yeah, there's not much that I 

46
00:02:54,040 --> 00:02:57,760
don't think there's much detail 
on this. 

47
00:02:57,760 --> 00:03:01,960
I mean, the data's hosted again 
by Distributed Denial of 

48
00:03:01,960 --> 00:03:04,360
Secrets, which we spoke about a 
few episodes ago. 

49
00:03:04,360 --> 00:03:07,600
Some of the leaked data was 
there and then it was deleted on

50
00:03:07,600 --> 00:03:10,600
the Gang Leaks Gangs leak 
website and they don't know why 

51
00:03:10,600 --> 00:03:13,920
the date is no longer listed. 
Maybe, maybe something's 

52
00:03:13,920 --> 00:03:16,440
happening behind closed doors. 
Who knows? 

53
00:03:17,520 --> 00:03:20,480
But yeah, yes. 
Third parties got to keep a 

54
00:03:20,480 --> 00:03:24,520
watch on your third parties. 
It's helpful to emphasise why 

55
00:03:24,520 --> 00:03:28,320
you have third party vendors, 
like why there's an approval 

56
00:03:28,320 --> 00:03:30,240
process. 
And you can't just use anyone 

57
00:03:31,000 --> 00:03:31,840
this. 
Is worthwhile. 

58
00:03:33,240 --> 00:03:34,720
Did you want to jump on to the 
next one? 

59
00:03:35,680 --> 00:03:37,120
Yeah, quickly, I'm covering this
bit. 

60
00:03:37,120 --> 00:03:41,560
So the next breach we've got is 
Wynn Resorts say 21,000 

61
00:03:41,560 --> 00:03:44,840
employees were affected by Shiny
Hunters pack. 

62
00:03:45,840 --> 00:03:52,560
They have breached 21,000 / 
21,000 employees hitting their 

63
00:03:52,560 --> 00:03:58,560
HR systems back in October 2025.
But yeah, this one is been taken

64
00:03:58,560 --> 00:04:03,280
by Shiny Hunters and it's been 
shared on their website, but I 

65
00:04:03,280 --> 00:04:05,440
think that was a little while 
ago actually, on this one. 

66
00:04:05,440 --> 00:04:09,680
But yeah, it says that on this 
one they removed the data that 

67
00:04:09,720 --> 00:04:14,360
I'm suggesting that they Win 
Resort had paid the ransom, but 

68
00:04:14,360 --> 00:04:16,240
they've declined to comment on 
that. 

69
00:04:17,120 --> 00:04:20,959
There's a few bits of more 
information, but it says they 

70
00:04:20,959 --> 00:04:25,040
were off to $1.5 million. 
It's probably one of those 

71
00:04:25,040 --> 00:04:26,800
things we'll never know if they 
paid it. 

72
00:04:27,040 --> 00:04:31,360
It's $1.5 million to get all 
that data back and to make it go

73
00:04:31,360 --> 00:04:35,560
away to a big organisation. 
It's probably not a lot of 

74
00:04:35,560 --> 00:04:37,840
money, is it? 
So it's yeah. 

75
00:04:38,280 --> 00:04:42,640
Yeah, there's a, there's an 
image image on the report that. 

76
00:04:42,640 --> 00:04:46,640
Claims over 800,000 records 
containing PII and employee data

77
00:04:46,640 --> 00:04:49,600
have been compromised. 
This is the final warning to 

78
00:04:49,600 --> 00:04:53,000
reach out before we leak, along 
with several annoying digital 

79
00:04:53,000 --> 00:04:54,400
problems that will come your 
way. 

80
00:04:55,760 --> 00:04:57,560
Don't be make the right 
decision. 

81
00:04:57,560 --> 00:05:00,040
Don't be the next headline. 
There you go. 

82
00:05:01,480 --> 00:05:03,600
I know what a board would say if
they were faced with that 

83
00:05:03,600 --> 00:05:06,000
option. 
They ought to be the headline. 

84
00:05:06,120 --> 00:05:09,000
Pay the money. 
They're just looking into I 

85
00:05:09,000 --> 00:05:11,480
didn't know what Ryan Resorts 
were but they're high end casino

86
00:05:11,480 --> 00:05:14,560
and hotel operator and a quick 
Google says that their 2025 

87
00:05:14,560 --> 00:05:18,480
revenue was 7 billion so 1.5 
million is nothing. 

88
00:05:18,880 --> 00:05:20,680
It's a drop in the ocean. 
Yeah. 

89
00:05:20,960 --> 00:05:23,240
Yeah, right. 
I'll jump on to the next breach.

90
00:05:23,600 --> 00:05:27,680
And this was one that was first 
reported on Reddit and hit the 

91
00:05:27,680 --> 00:05:30,560
news a couple of days later. 
So I think the impact was felt 

92
00:05:30,560 --> 00:05:32,040
before it was actually 
confirmed. 

93
00:05:32,840 --> 00:05:35,560
This comes via the register and 
it's Dutch healthcare software 

94
00:05:35,560 --> 00:05:39,840
vendor Chipsoft. 
They've gone dark after a 

95
00:05:39,840 --> 00:05:43,040
ransomware attack and their 
website was taken offline and 

96
00:05:43,040 --> 00:05:46,680
disrupted hospital systems 
across the Netherlands and their

97
00:05:46,720 --> 00:05:49,600
firms. 
Patient record software is used 

98
00:05:49,600 --> 00:05:53,480
by most Dutch hospitals and 
several hospitals have been 

99
00:05:53,480 --> 00:05:59,400
forced to partially shut systems
down while a national cyber 

100
00:05:59,400 --> 00:06:01,360
emergency teams are looking at 
the impact. 

101
00:06:01,440 --> 00:06:06,120
So only 11 hospitals have pulled
their software offline, nine of 

102
00:06:06,120 --> 00:06:08,680
which are among the institutions
that use the software more 

103
00:06:08,680 --> 00:06:12,440
extensively, according to local 
news outlet Nos. 

104
00:06:13,240 --> 00:06:16,640
Yeah. 
So Zedser received a 

105
00:06:16,640 --> 00:06:20,920
notification that Chipsoft had 
fallen victim to a ransomware 

106
00:06:21,320 --> 00:06:23,040
tack. 
The group behind the attack is 

107
00:06:23,040 --> 00:06:27,720
not yet known, but and despite 
disruptions, Chipsoft Chipsoft, 

108
00:06:27,800 --> 00:06:32,360
not chip shop Chipsoft public 
facing services, the majority of

109
00:06:32,360 --> 00:06:34,840
hospitals the company serves are
still able to use their patient 

110
00:06:34,840 --> 00:06:39,440
portals. 
So some impact, but again, you 

111
00:06:39,440 --> 00:06:42,960
know. 
Healthcare, it's just they don't

112
00:06:42,960 --> 00:06:46,160
care who they target. 
They will target anyone and 

113
00:06:46,160 --> 00:06:51,960
everyone, yeah. 
Next one, moving on from that, 

114
00:06:51,960 --> 00:06:54,400
we've got one more breach to 
talk about quickly. 

115
00:06:54,400 --> 00:06:58,120
It's James Dave confirmed that a
limited breach happened after a 

116
00:06:58,120 --> 00:07:00,520
phishing attack by silent ransom
group. 

117
00:07:00,560 --> 00:07:03,040
Just. 
They're a law firm in America 

118
00:07:03,040 --> 00:07:07,000
and they've, yeah, basically 
confirmed the data breach after 

119
00:07:07,000 --> 00:07:10,200
the silent ransom group leaked 
limited client files for around 

120
00:07:10,200 --> 00:07:13,760
10 clients on its website. 
The group's also known as Luna 

121
00:07:13,760 --> 00:07:17,800
Moff, and they've reportedly 
demanded a $13 million ransom 

122
00:07:17,800 --> 00:07:21,200
during the negotiations. 
And friend, wider exposure of 

123
00:07:21,280 --> 00:07:24,840
sensitive, sensitive legal data 
and reputational harm. 

124
00:07:24,920 --> 00:07:29,720
And yes, this one, there's quite
a lot of information on it in 

125
00:07:29,720 --> 00:07:31,000
their blog posts that we've got 
here. 

126
00:07:31,000 --> 00:07:35,120
But it basically says, yeah, 
that this silent ransom group 

127
00:07:35,120 --> 00:07:40,720
and known as Luna Moth, Chatty 
Spider and UNC 3753 and they've 

128
00:07:40,720 --> 00:07:42,960
been targeting law firms since 
2023. 

129
00:07:44,160 --> 00:07:47,360
It was obviously lots of 
sensitive data within there and 

130
00:07:47,440 --> 00:07:54,680
a lot of money involved with it.
There's also a conversation like

131
00:07:54,680 --> 00:07:59,520
an e-mail, Fred, it looks like 
talking about the negotiation, 

132
00:07:59,600 --> 00:08:02,640
which is something you don't 
really see too often, but you 

133
00:08:02,640 --> 00:08:04,040
can't really read it. 
It's very small. 

134
00:08:04,120 --> 00:08:08,440
But yeah, says that there's 
don't think there's any 

135
00:08:08,480 --> 00:08:13,840
resolution. 
So a quick look trying to find 

136
00:08:13,840 --> 00:08:19,600
out, don't reason to say if 
they've what sort of happened 

137
00:08:19,600 --> 00:08:20,960
with this one. 
But I think they basically 

138
00:08:20,960 --> 00:08:23,920
warned that they would leak the 
day if the ransom wasn't paid, 

139
00:08:24,680 --> 00:08:26,360
but I'm not sure where. 
Let's go on to. 

140
00:08:26,440 --> 00:08:29,960
You can zoom in though if you 
open that image in a new tab, 

141
00:08:30,120 --> 00:08:33,799
you can just about make it out 
if you read between the pixels 

142
00:08:34,280 --> 00:08:36,120
says. 
We will begin contacting your 

143
00:08:36,120 --> 00:08:39,520
staff and publishing your files 
on our website if we do not 

144
00:08:39,520 --> 00:08:43,440
receive a response by today. 
And then could you please 

145
00:08:43,440 --> 00:08:47,440
provide the following some file 
names Rhode. 

146
00:08:47,440 --> 00:08:51,520
Islanddoc1.pdflowesbrief.pdf 
Here are the files that you 

147
00:08:51,520 --> 00:08:53,080
requested. 
We believe this is enough 

148
00:08:53,080 --> 00:08:56,600
evidence reviewed everything and
has come up with a price of 13 

149
00:08:56,600 --> 00:09:00,480
million U.S. dollars. 
We're expecting your response on

150
00:09:00,480 --> 00:09:04,000
a daily basis in order to meet a
mutual path and peaceful and 

151
00:09:04,320 --> 00:09:09,000
ignorance will be considered as 
no willingness to meet a mutual.

152
00:09:09,040 --> 00:09:11,800
Yeah, so. 
It's all very, it's all very 

153
00:09:11,800 --> 00:09:15,320
polite, but it closes. 
As we said, in case of 

154
00:09:15,320 --> 00:09:17,720
ignorance, we will make you face
severe consequences. 

155
00:09:18,120 --> 00:09:20,480
This is the last warning. 
Before your data gets published,

156
00:09:20,960 --> 00:09:24,160
so. 
Yeah, quick Google seems to say 

157
00:09:24,160 --> 00:09:27,280
that it has been posted, but 
there's not a lot of information

158
00:09:27,280 --> 00:09:29,920
out there. 
Jones Day have been hit before 

159
00:09:29,920 --> 00:09:33,640
as well, back in 2021 and 
through a third party file 

160
00:09:33,640 --> 00:09:36,320
transfer. 
Service yeah, so they have 

161
00:09:36,320 --> 00:09:38,400
experience with this, but there 
we. 

162
00:09:38,400 --> 00:09:41,040
Go Yeah, Those are this week's 
breaches of the week. 

163
00:09:41,040 --> 00:09:42,280
Should we go on with some news? 
Yeah. 

164
00:09:43,040 --> 00:09:49,320
Let's go for it, OK? 
Let's do the news right this 

165
00:09:49,320 --> 00:09:51,720
week. 
Opening up, I'm going to go 1st 

166
00:09:51,720 --> 00:09:54,400
and you, if you're in 
cybersecurity, you've probably 

167
00:09:54,400 --> 00:09:57,080
been living under a rock if this
is the first you've heard of it.

168
00:09:57,080 --> 00:10:02,080
Anthropics, Claude Mythos finds 
thousands of 0 day flaws across 

169
00:10:02,080 --> 00:10:06,400
major systems and big thank you.
I was sent I might play actually

170
00:10:06,400 --> 00:10:09,280
because it's quite good. 
Anthropic obviously behind 

171
00:10:09,280 --> 00:10:15,760
Claude, They developed a brand 
new LLM called Mythos and it was

172
00:10:16,040 --> 00:10:17,920
too powerful. 
Let me let me play the video. 

173
00:10:18,000 --> 00:10:21,840
Let me play the video yes I got 
sent in this video by Simeon 

174
00:10:21,840 --> 00:10:25,520
quarry at the Vida hi Simeon, 
but I got sent this and I 

175
00:10:25,520 --> 00:10:28,200
thought it's actually really 
useful so let me just. 

176
00:10:28,200 --> 00:10:30,240
Share it here. 
You don't need to see it. 

177
00:10:30,280 --> 00:10:32,920
You can hear it as well. 
So if you are listening and 

178
00:10:32,920 --> 00:10:34,400
you're not watching, that's 
fine. 

179
00:10:34,680 --> 00:10:38,640
If you're if you want to watch, 
go over to YouTube, search for 

180
00:10:38,960 --> 00:10:42,960
the awareness angle or risky 
creative. 

181
00:10:42,960 --> 00:10:46,000
The links are on there as well. 
So let me just press play on 

182
00:10:46,000 --> 00:10:49,240
this quickly. 
Finally here, but it's so 

183
00:10:49,240 --> 00:10:51,680
powerful that they're not 
releasing it to the public out 

184
00:10:51,680 --> 00:10:53,440
of fear over the damage it will 
cause. 

185
00:10:53,440 --> 00:10:56,120
Instead, Anthropic announced 
project last week, an urgent 

186
00:10:56,120 --> 00:10:59,200
initiative that gives access to 
Mythos only to AWS, Apple, 

187
00:10:59,200 --> 00:11:01,960
Google, Microsoft, NVIDIA, and a
few others so they can fix their

188
00:11:01,960 --> 00:11:04,760
code First, Because over the 
past few weeks, Mythos has found

189
00:11:04,800 --> 00:11:07,240
thousands of critical 
vulnerabilities, including every

190
00:11:07,240 --> 00:11:10,200
major OS and web browser. 
One Anthropic engineer asked it 

191
00:11:10,200 --> 00:11:12,800
to find bugs overnight and woke 
up to a complete working 

192
00:11:12,800 --> 00:11:14,840
exploit. 
It discovered a 27 year old 

193
00:11:14,840 --> 00:11:16,960
vulnerability in open BSD and 
OS. 

194
00:11:16,960 --> 00:11:19,600
Literally famous for being 
secure, it even found some 

195
00:11:19,600 --> 00:11:22,240
vulnerabilities on Linux that 
can allow a user with no 

196
00:11:22,240 --> 00:11:24,280
permission to suddenly control 
the entire machine. 

197
00:11:24,320 --> 00:11:26,560
But here's the widest of all. 
During testing, Claude Mitos 

198
00:11:26,560 --> 00:11:29,640
preview broke out of a sandbox 
environment, built a moderately 

199
00:11:29,640 --> 00:11:32,720
sophisticated multi step exploit
to gain Internet access, and 

200
00:11:32,760 --> 00:11:35,040
emailed a researcher while they 
were eating a sandwich in the 

201
00:11:35,040 --> 00:11:36,680
park. 
On top of it, the benchmarks are

202
00:11:36,680 --> 00:11:39,200
insane on every single. 
I'll pause it there. 

203
00:11:39,200 --> 00:11:42,160
I'll put a link to the video in 
the newsletter, but as you can 

204
00:11:42,160 --> 00:11:46,320
see, Project Glass Wing hugely 
powerful, shut away. 

205
00:11:46,320 --> 00:11:48,720
That video is really nice, 
really nicely made as well. 

206
00:11:48,720 --> 00:11:51,640
What starts as a talking head 
with some really simple 

207
00:11:51,640 --> 00:11:57,520
animation, which is nice, yeah. 
But yes, so it goes away. 

208
00:11:57,520 --> 00:12:02,120
It autonomously discovers, 
exploits and exploits them and 

209
00:12:02,120 --> 00:12:04,720
has found some really scary 
stuff in a very short period of 

210
00:12:04,720 --> 00:12:07,880
time. 
You know, this is like pens AI 

211
00:12:07,880 --> 00:12:11,960
pen tester extreme. 
I was speaking to someone the 

212
00:12:11,960 --> 00:12:16,240
earlier this week about how AI 
pen testing is kind of a mixed 

213
00:12:16,240 --> 00:12:18,760
bag. 
I think this probably changes. 

214
00:12:18,800 --> 00:12:22,240
Yeah, it seems so, judging by 
the response this has had. 

215
00:12:22,240 --> 00:12:23,960
Right, It's everywhere at the 
moment. 

216
00:12:26,640 --> 00:12:29,640
We all knew it would come though
we, you know, with AI doing what

217
00:12:29,640 --> 00:12:31,720
it does, you know, we all knew 
that it could. 

218
00:12:32,560 --> 00:12:36,840
The thing is if if they've done 
this for good, then someone can 

219
00:12:36,840 --> 00:12:39,320
maybe do it for bad, you know 
what I mean? 

220
00:12:39,640 --> 00:12:42,480
Yeah, sure. 
It might be long before for that

221
00:12:42,480 --> 00:12:44,320
happens. 
People will start using these 

222
00:12:44,320 --> 00:12:48,520
tools once once they breach into
like a Amazon or Google for 

223
00:12:48,520 --> 00:12:50,800
example. 
You could essentially use this 

224
00:12:50,800 --> 00:12:53,600
once you're in. 
Let's let's not forget as well, 

225
00:12:53,600 --> 00:12:58,000
this is what Anthropic have 
created and Anthropic are doing 

226
00:12:58,000 --> 00:12:59,440
the right thing with this, 
right? 

227
00:12:59,440 --> 00:13:01,880
They're putting it, they're 
locking it down, they're 

228
00:13:01,880 --> 00:13:06,240
restricting access. 
There are other AI companies out

229
00:13:06,240 --> 00:13:08,960
there that may not lock it down 
and may not restrict access. 

230
00:13:09,240 --> 00:13:13,120
Or is this a little peek behind 
the curtain at what nation state

231
00:13:13,120 --> 00:13:17,480
actors will have? 
You know, what does America have

232
00:13:17,480 --> 00:13:18,640
that they're not telling us 
about? 

233
00:13:18,640 --> 00:13:21,120
What does China have that 
they're not that kind of thing? 

234
00:13:21,120 --> 00:13:22,360
Do you know what I mean? 
It's. 

235
00:13:23,040 --> 00:13:26,760
Yeah, Anything is now possible. 
Yeah. 

236
00:13:26,800 --> 00:13:30,840
It's a good story to talk about.
You know, careful if you have 

237
00:13:30,840 --> 00:13:34,000
developers in your workforce, 
This is why it's important to 

238
00:13:34,600 --> 00:13:38,280
keep security and keep coding 
securely because there's now 

239
00:13:38,280 --> 00:13:40,120
things that are going to find 
stuff that they thought they. 

240
00:13:40,120 --> 00:13:43,720
Could get away with SO. 
Yeah, yeah. 

241
00:13:44,720 --> 00:13:46,600
Right, move on to the next one 
if you want. 

242
00:13:47,280 --> 00:13:50,160
Cool, James. 
The next story we got is Grafana

243
00:13:50,160 --> 00:13:54,040
ghost formability which is 
allowing data theft, fire AI 

244
00:13:54,040 --> 00:13:56,160
injection. 
So this is adopt just Grafana 

245
00:13:56,160 --> 00:14:00,840
ghost impacting the popular tour
Grafana which businesses use to 

246
00:14:00,840 --> 00:14:03,440
monitor various things like 
financial metrics, 

247
00:14:03,440 --> 00:14:06,720
infrastructure, health, private 
customer information, lots of 

248
00:14:06,720 --> 00:14:10,120
sensitive data, which obviously 
is makes it sort of quite 

249
00:14:10,120 --> 00:14:12,080
concerning for those businesses 
that use it. 

250
00:14:12,640 --> 00:14:15,320
There's a whole lot of 
information here, but it's some 

251
00:14:16,200 --> 00:14:19,920
of that the name of threat 
research team have sort of found

252
00:14:19,920 --> 00:14:24,640
and looked into allows as 
hackers have bypassed secure 

253
00:14:24,640 --> 00:14:27,640
protections and secretly moved 
data from the company's 

254
00:14:27,640 --> 00:14:32,200
environment to external server. 
And this happens without users 

255
00:14:32,200 --> 00:14:36,520
knowing and unlike traditional 
scams, doesn't require any way 

256
00:14:36,520 --> 00:14:39,240
to click on anything. 
It just operates autonomously in

257
00:14:39,240 --> 00:14:42,560
the background. 
And it says here that from 

258
00:14:42,560 --> 00:14:47,080
Numa's investigation, the tech 
use utilises indirect prompt 

259
00:14:47,080 --> 00:14:50,960
injection, hides instructions in
the data that the software's AI 

260
00:14:50,960 --> 00:14:53,680
components process, and it 
tricks the system into ignoring 

261
00:14:53,680 --> 00:14:57,920
its own safety rules by using 
specific keywords like error and

262
00:14:57,960 --> 00:15:00,120
various other messages to 
confuse the AI model. 

263
00:15:01,160 --> 00:15:03,360
Yeah, this, this goes into a 
whole lot more information. 

264
00:15:03,360 --> 00:15:08,040
But yeah, it's quite a, it's 
quite sort of a potentially not 

265
00:15:08,040 --> 00:15:12,560
new, but it's kind of a unique 
way of sort of compromising a 

266
00:15:12,560 --> 00:15:16,120
system, I guess with this built 
in AI features and, and 

267
00:15:16,120 --> 00:15:20,160
obviously tricking the AI into 
into thinking it's genuine. 

268
00:15:20,160 --> 00:15:23,400
So associated that Grafana, 
that's a push back on the 

269
00:15:23,480 --> 00:15:28,080
characterization of the reported
issue, stating that whilst the 

270
00:15:28,080 --> 00:15:31,080
floor in the markdown image 
renderer was identified and 

271
00:15:31,080 --> 00:15:34,680
property patched, it did not 
amount to a zero click or 

272
00:15:34,680 --> 00:15:36,720
autonomous exploit. 
And then it goes on to say, 

273
00:15:36,720 --> 00:15:40,440
according to Grafana's CSO, any 
successful abuse would have 

274
00:15:40,440 --> 00:15:43,440
required a substantial user 
involvement, including 

275
00:15:43,440 --> 00:15:46,520
repeatedly directing the AI 
system to act on malicious 

276
00:15:46,520 --> 00:15:48,800
instructions even after being 
warned about them. 

277
00:15:49,440 --> 00:15:53,200
Says as well that the companies 
have emphasised that there's no 

278
00:15:53,200 --> 00:15:57,360
evidence of this vulnerability 
being exploited in the wild and 

279
00:15:57,360 --> 00:16:00,280
confirms that no data was 
exposed from cloud. 

280
00:16:00,280 --> 00:16:04,600
So it's, yeah, it's interesting 
that the secure researchers sort

281
00:16:04,600 --> 00:16:07,520
of said this and then the 
company themselves come out and 

282
00:16:07,520 --> 00:16:09,960
say otherwise. 
So who knows what's there, what 

283
00:16:09,960 --> 00:16:13,040
the truth is here, But hey, I 
just want to look out for I 

284
00:16:13,040 --> 00:16:17,480
guess for Grafana customers. 
Grafana covering their buds 

285
00:16:17,480 --> 00:16:20,640
obviously, as you would expect, 
you know, because they don't 

286
00:16:20,640 --> 00:16:27,720
want to find themselves exposed.
I mean Grafana has been used. 

287
00:16:27,720 --> 00:16:30,760
For years and years and years by
lots of different teams, lots of

288
00:16:31,040 --> 00:16:34,600
smaller instances as well. 
I think with that, you know, I 

289
00:16:34,600 --> 00:16:36,920
think back to when we were 
together, there was numerous 

290
00:16:36,920 --> 00:16:40,120
people running different 
versions and did their own 

291
00:16:40,120 --> 00:16:42,760
thing, so. 
If you're an awareness 

292
00:16:42,760 --> 00:16:46,280
professional, this is a great 
even if, even if like Grafana 

293
00:16:46,280 --> 00:16:49,520
say, this isn't actually an 
issue, it's a good opportunity 

294
00:16:49,520 --> 00:16:52,040
for you to build some bridges 
and relationships with different

295
00:16:52,040 --> 00:16:54,680
people that might own it. 
Get an understanding of what the

296
00:16:54,680 --> 00:16:58,000
land looks like and then just 
have those conversations because

297
00:16:58,000 --> 00:17:02,920
it's just another opportunity to
talk about security to people 

298
00:17:02,920 --> 00:17:04,800
that wouldn't normally talk 
about security. 

299
00:17:05,240 --> 00:17:07,000
You know if you if. 
You've got a Windows 

300
00:17:07,000 --> 00:17:09,599
administration team or a Linux 
server team that are running 

301
00:17:09,599 --> 00:17:11,920
Crafana or the dev team or 
something like that. 

302
00:17:12,200 --> 00:17:14,880
Have a chat with them about 
this, find out how they use it, 

303
00:17:15,000 --> 00:17:16,520
understand their world a little 
bit more. 

304
00:17:16,640 --> 00:17:20,800
I think that's that's probably a
good thing in some ways. 

305
00:17:22,480 --> 00:17:25,599
Guess as well I'll just quickly 
on like AI features. 

306
00:17:25,599 --> 00:17:27,720
I don't know if it's a standard 
feature, right, with this 

307
00:17:27,839 --> 00:17:32,720
platform, but often, yeah, 
people are using Ferris Air 

308
00:17:32,720 --> 00:17:37,920
tools and this sort of shows you
how easily, I mean, according to

309
00:17:37,920 --> 00:17:41,480
what the research team said that
you can sort of trick the AI 

310
00:17:41,480 --> 00:17:44,920
into doing various things and 
yeah, goes into the obviously 

311
00:17:44,920 --> 00:17:49,360
prompting that prompt injection 
or indirect prompt injection. 

312
00:17:49,360 --> 00:17:52,440
Like I said, there's there's 
lots of topics to educate people

313
00:17:52,440 --> 00:17:56,880
on, I guess. 
And yeah as well, like tools 

314
00:17:57,240 --> 00:18:01,360
being approved and having AI 
features and making sure they're

315
00:18:01,440 --> 00:18:05,360
obviously assessed and some of 
these features might become a 

316
00:18:05,360 --> 00:18:08,800
thing later on, yeah, after it's
been assessed as well. 

317
00:18:08,800 --> 00:18:10,840
So some interesting takes on 
this one. 

318
00:18:11,000 --> 00:18:14,120
Yeah, yeah, right. 
I'll move on to the next one. 

319
00:18:15,040 --> 00:18:19,680
And the next one is from Hack 
Reed missile alert, fishing 

320
00:18:19,680 --> 00:18:25,640
exploits, Iran, US, Israel 
conflict for Microsoft logins. 

321
00:18:25,800 --> 00:18:30,000
And this is another example of 
just like They Don't care, a 

322
00:18:30,000 --> 00:18:33,080
phishing campaign is exploiting 
real world tensions involving 

323
00:18:33,120 --> 00:18:37,440
Iran, Israel and the US by 
sending fake missile alert 

324
00:18:37,440 --> 00:18:41,520
emails that impersonate 
government civil defence 

325
00:18:41,520 --> 00:18:43,880
warnings. 
So the scam uses urgent language

326
00:18:44,360 --> 00:18:47,240
and QR codes to bypass e-mail 
philtres, getting you off of 

327
00:18:47,240 --> 00:18:49,560
your device and onto your mobile
device where you don't have the 

328
00:18:49,560 --> 00:18:52,880
same security controls. 
Like we often say with QR codes,

329
00:18:52,920 --> 00:18:56,880
it redirects victims to a fake 
Microsoft login page, which is 

330
00:18:56,880 --> 00:18:59,760
obviously designed to steal your
credentials. 

331
00:18:59,760 --> 00:19:03,080
But the unique thing here, I 
mean, there is a picture. 

332
00:19:03,400 --> 00:19:05,840
This isn't even fish of the 
week, but let me show it 

333
00:19:05,840 --> 00:19:09,200
quickly. 
It's slightly terrifying. 

334
00:19:09,200 --> 00:19:12,760
I think it's it's not the nicest
of things to receive. 

335
00:19:14,360 --> 00:19:17,560
Yeah. 
We can see here in this. 

336
00:19:17,640 --> 00:19:19,200
Let me just zoom in a little 
bit. 

337
00:19:22,320 --> 00:19:25,280
Public safety advisory action 
recommended. 

338
00:19:25,280 --> 00:19:28,320
That's the subject line. 
And if we look at the e-mail 

339
00:19:28,320 --> 00:19:34,520
address, it's from 
ministryofinterior-civildefencenetwork@qualitycollection.com,

340
00:19:34,520 --> 00:19:41,920
dot AU. 
Yeah, so dot AU, which is 

341
00:19:41,920 --> 00:19:46,640
Australia Air raid, emergency 
alert, alert classification, 

342
00:19:46,640 --> 00:19:50,000
severe active public safety 
notice warning, take cover 

343
00:19:50,000 --> 00:19:53,000
immediately. 
Due to ongoing conflict in Iran,

344
00:19:53,000 --> 00:19:55,040
there is an elevated risk of 
missile attacks. 

345
00:19:55,040 --> 00:19:58,600
Civilians must be prepared. 
Authorities warn that conflict 

346
00:19:58,600 --> 00:20:01,800
may expand beyond the region and
could extend into parts of Asia.

347
00:20:03,400 --> 00:20:06,520
So this e-mail, this e-mail must
have let me just read the 

348
00:20:06,520 --> 00:20:08,200
article a little bit more, 
because this must have been 

349
00:20:08,200 --> 00:20:12,840
received by people outside of 
that area then. 

350
00:20:14,920 --> 00:20:18,120
But anyway, it goes to a fake 
Microsoft login page, which 

351
00:20:18,120 --> 00:20:23,440
looks like a real Microsoft 
login page if you don't look at 

352
00:20:23,440 --> 00:20:26,400
the URL. 
So if you look at the URL, you 

353
00:20:26,400 --> 00:20:30,720
can see it goes to 
like.ru/somethingelse. 

354
00:20:30,840 --> 00:20:35,440
So it's not on microsoft.com, 
but it looks like a legitimate 

355
00:20:35,440 --> 00:20:40,480
Microsoft sign in Page. 
So yeah, that was reported by 

356
00:20:40,480 --> 00:20:42,720
Covence and featured on Hack 
Read this week. 

357
00:20:43,280 --> 00:20:46,840
So I just thought that was that 
was interesting because it's 

358
00:20:46,840 --> 00:20:48,880
another example of QR code 
phishing that we. 

359
00:20:48,880 --> 00:20:52,480
Featured as a Fish of the Week 
in the episode or two ago. 

360
00:20:53,840 --> 00:20:57,080
Yeah, so and this one doesn't. 
This takes you off. 

361
00:20:57,160 --> 00:21:00,680
There's no security controls. 
Maybe you don't notice the URL 

362
00:21:00,760 --> 00:21:03,960
so easily on a mobile device. 
Maybe you're not used to what 

363
00:21:03,960 --> 00:21:06,880
the Microsoft screen looks like 
on a mobile device. 

364
00:21:07,160 --> 00:21:09,840
So you're more likely to log 
into something that looks a bit 

365
00:21:09,840 --> 00:21:10,880
funky. 
Yeah. 

366
00:21:11,280 --> 00:21:16,400
So be careful. 
Interesting 1, like it kind of 

367
00:21:16,400 --> 00:21:19,840
feels like one that'd be more 
for personal recipients rather 

368
00:21:19,840 --> 00:21:21,600
than lack of business 
potentially. 

369
00:21:22,160 --> 00:21:25,280
Yeah. 
So I guess you know, kind of for

370
00:21:25,280 --> 00:21:28,080
awareness people, it's always 
good to like educate people and 

371
00:21:28,080 --> 00:21:31,400
obviously phishing emails and 
then they can benefit from from 

372
00:21:31,400 --> 00:21:34,920
in the personal e-mail inbox. 
But also, yeah, this interesting

373
00:21:34,920 --> 00:21:39,360
to have a Microsoft login as the
landing page when not 

374
00:21:39,360 --> 00:21:41,320
everybody's going to be using 
Microsoft. 

375
00:21:41,320 --> 00:21:45,640
So there's lots of red flags I 
guess on this one. 

376
00:21:46,080 --> 00:21:49,240
Yeah. 
Yeah, I wonder how specific it 

377
00:21:49,240 --> 00:21:53,000
was, but I guess as well like 
using the QR code, it's probably

378
00:21:53,000 --> 00:21:57,240
not too implausible, right? 
It's like there's potentially a 

379
00:21:57,240 --> 00:22:00,360
lot of information and it's just
like a quick way to get to it, 

380
00:22:00,360 --> 00:22:03,840
but especially on your phone, 
right, if you're you're going to

381
00:22:03,840 --> 00:22:05,400
go away from your computer sort 
of thing. 

382
00:22:05,400 --> 00:22:07,360
It does say here it's going. 
To make sense in a way. 

383
00:22:07,400 --> 00:22:10,840
It says scan for instructions, 
access official emergency 

384
00:22:10,840 --> 00:22:14,640
procedures, shelter guidance and
evacuation instructions, 

385
00:22:14,960 --> 00:22:18,400
recipient action scan 
immediately using a mobile 

386
00:22:18,400 --> 00:22:21,880
device and review updated 
instructions for all household 

387
00:22:21,880 --> 00:22:24,800
members. 
Why would they put that behind a

388
00:22:24,800 --> 00:22:28,000
login screen? 
Why would you need to log into 

389
00:22:28,000 --> 00:22:32,360
Microsoft to view the emergency 
procedures and shelter guidance?

390
00:22:32,640 --> 00:22:37,000
Ask you you don't pause in a 
state of an emergency this. 

391
00:22:37,120 --> 00:22:39,520
Is designed to heighten your 
senses. 

392
00:22:39,560 --> 00:22:42,840
You just do and you don't stop. 
That's the problem. 

393
00:22:43,240 --> 00:22:46,520
But yeah, why would you sign 
into Microsoft to access that? 

394
00:22:47,600 --> 00:22:50,440
Right, move on to the next one. 
OK, next one we've got 

395
00:22:50,840 --> 00:22:55,680
disgruntled researcher leaks 
Blue Hammer Windows Day, Windows

396
00:22:55,680 --> 00:22:59,320
0 day exploit. 
So this one says here that yeah,

397
00:22:59,320 --> 00:23:02,160
researcher publicly leaked 
what's called Blue Hammer. 

398
00:23:02,440 --> 00:23:06,240
So unpatched Windows local 
privileges escalation 0 day 

399
00:23:06,240 --> 00:23:08,960
affecting Microsoft Windows 
after a dispute disclosure 

400
00:23:08,960 --> 00:23:15,040
process with Microsoft. 
So it says here the security 

401
00:23:15,040 --> 00:23:18,600
research, we found it, I tried 
to report it and was not happy 

402
00:23:18,600 --> 00:23:22,480
with how Microsoft's response 
team handled the disclosure 

403
00:23:22,480 --> 00:23:24,120
process. 
And as well, it says here that 

404
00:23:24,560 --> 00:23:28,000
the issue has no official patch 
and there's no update to address

405
00:23:28,000 --> 00:23:29,920
it. 
So it's considered a zero day. 

406
00:23:29,960 --> 00:23:32,480
So this is a Bleeping computer 
article and it says it's unclear

407
00:23:32,480 --> 00:23:36,160
what triggered the public 
release for the exploit exploit 

408
00:23:36,160 --> 00:23:39,080
code. 
But there's a blog post of the 

409
00:23:39,080 --> 00:23:44,480
person that disclosed it how the
aliases chaotic Eclipse and 

410
00:23:44,520 --> 00:23:48,720
they've they in quote said I was
not bluffing Microsoft and I'm 

411
00:23:48,720 --> 00:23:51,440
doing it again. 
Unlike previous times, I'm not 

412
00:23:51,440 --> 00:23:54,360
explaining how this works. 
The all geniuses can figure it 

413
00:23:54,360 --> 00:23:57,720
out. 
Also huge thanks to the MSRC. 

414
00:23:58,320 --> 00:24:01,200
They were the Microsoft Security
response Response Centre 

415
00:24:01,520 --> 00:24:02,800
leadership for making this 
possible. 

416
00:24:02,840 --> 00:24:04,080
They've added in their blog 
posts. 

417
00:24:04,080 --> 00:24:09,400
So, yeah, they've published on 
GitHub with this blue hammer 

418
00:24:09,600 --> 00:24:13,560
exploit. 
And yeah, it's quite unheard of,

419
00:24:13,560 --> 00:24:15,560
I think, isn't it? 
For, I mean, obviously scary 

420
00:24:15,560 --> 00:24:17,640
researchers aren't always the 
good guys. 

421
00:24:17,640 --> 00:24:20,360
There's you could always have a 
someone who's not a bit more 

422
00:24:20,360 --> 00:24:23,600
neutral. 
And obviously they got upset 

423
00:24:23,600 --> 00:24:27,520
with whatever happened about it.
But yeah, it goes in to explain 

424
00:24:28,600 --> 00:24:31,840
that this exploit, yeah, local 
privilege escalation. 

425
00:24:32,920 --> 00:24:37,240
This post goes into all 
information about it, but it 

426
00:24:37,240 --> 00:24:40,920
does say, and there's further 
down as well, that testing of 

427
00:24:40,920 --> 00:24:44,080
the exploit was not successful 
on Windows Server. 

428
00:24:44,160 --> 00:24:47,360
And there's also a screenshot of
it being blocked or detected by 

429
00:24:47,360 --> 00:24:48,960
Microsoft Defender, which is 
interesting. 

430
00:24:50,360 --> 00:24:52,360
Yeah, I don't think there's a 
whole lot more. 

431
00:24:53,280 --> 00:24:56,520
They do have a statement, 
Bleeping Computer from 

432
00:24:56,520 --> 00:25:00,960
Microsoft, which has said 
Microsoft have a customer 

433
00:25:00,960 --> 00:25:03,960
commitment to investigate 
reported scary issues and update

434
00:25:04,000 --> 00:25:06,760
impacted devices to protect 
customers as soon as possible. 

435
00:25:07,400 --> 00:25:11,000
We also support coordinated 
vulnerability disclosure, a 

436
00:25:11,000 --> 00:25:15,200
widely adopted industry practise
that helps ensure issues are 

437
00:25:15,200 --> 00:25:17,200
carefully investigated and 
addressed before public 

438
00:25:17,200 --> 00:25:20,520
disclosure, supporting both 
customer protection and the 

439
00:25:20,520 --> 00:25:24,560
security research community. 
Yeah, so I think that it's 

440
00:25:24,560 --> 00:25:27,280
potentially still vulnerable. 
I don't think it says it's been 

441
00:25:27,280 --> 00:25:31,000
patched yet. 
Microsoft are big enough and 

442
00:25:31,000 --> 00:25:33,400
ugly enough that they can get 
away with stuff like this, but I

443
00:25:33,400 --> 00:25:36,280
know that businesses will quite 
often. 

444
00:25:36,680 --> 00:25:40,280
All businesses of a certain size
will quite often get approached 

445
00:25:40,280 --> 00:25:43,520
by someone that says, I found 
the exploit, I found something. 

446
00:25:43,880 --> 00:25:46,400
It used to happen when we worked
together, and it happened at the

447
00:25:46,400 --> 00:25:48,600
last place I worked as well. 
I think from time to time 

448
00:25:48,600 --> 00:25:50,600
someone would reach out and say,
I found this. 

449
00:25:50,680 --> 00:25:52,880
Who do I speak to? 
Do you have a reward? 

450
00:25:52,880 --> 00:25:56,840
Do you do a bug bounty? 
Take these people seriously. 

451
00:25:56,880 --> 00:25:59,960
And sometimes it will be like 
the smallest, lowest priority 

452
00:25:59,960 --> 00:26:01,480
thing. 
And it's like, oh, yeah, we 

453
00:26:01,480 --> 00:26:03,640
know. 
It's like we know that exists 

454
00:26:03,640 --> 00:26:07,120
because this, you know, it's a 
known thing that's going to be 

455
00:26:07,120 --> 00:26:10,240
really complicated to patch. 
But sometimes there is gold in 

456
00:26:10,240 --> 00:26:12,720
those and you. 
Don't want them going. 

457
00:26:12,720 --> 00:26:16,000
Public with it and then you 
being taken down. 

458
00:26:16,120 --> 00:26:19,320
That's that's the problem. 
Yeah, especially with this one, 

459
00:26:19,320 --> 00:26:23,320
it says yeah, that it allows 
them to escalate the system 

460
00:26:23,320 --> 00:26:26,800
level control and fully 
compromise the machines with 

461
00:26:27,040 --> 00:26:30,280
tail control. 
So it's quite a potential big 

462
00:26:30,280 --> 00:26:33,440
one for I think it got attached 
with it. 

463
00:26:33,520 --> 00:26:36,320
I think it said on this one that
they need, they do need local 

464
00:26:36,320 --> 00:26:40,200
access to the device, but that's
easily achieved with click fix 

465
00:26:40,200 --> 00:26:44,520
or social engineering or things 
like that, you know, just that's

466
00:26:44,520 --> 00:26:49,120
not a protection anymore. 
It's really easy to get a user 

467
00:26:49,120 --> 00:26:52,480
to do something on a device. 
Or for them to give you the 

468
00:26:52,480 --> 00:26:54,240
access to do something on a 
device. 

469
00:26:54,720 --> 00:26:58,840
Yeah, yeah. 
Next one, right, the next one. 

470
00:26:58,880 --> 00:27:05,480
The White House is seeking to 
slash CISA funding by $707 

471
00:27:06,040 --> 00:27:09,360
million. 
So the administration, the Trump

472
00:27:09,360 --> 00:27:14,280
administration has said that 
they've 2027 budget refocuses 

473
00:27:14,280 --> 00:27:18,840
CISA on its core mission to 
protect federal, federal 

474
00:27:18,840 --> 00:27:22,240
agencies and critical 
infrastructure. 

475
00:27:22,240 --> 00:27:27,240
So they're proposing a $707 
million cut to their budget. 

476
00:27:27,280 --> 00:27:30,760
They can eliminate programmes 
seen as redundant or politically

477
00:27:30,760 --> 00:27:33,800
driven. 
They also are seeking to remove 

478
00:27:33,800 --> 00:27:37,400
several initiatives, including 
misinformation and international

479
00:27:37,400 --> 00:27:41,280
engagement efforts, continuing a
broader trend of restarturing. 

480
00:27:41,520 --> 00:27:45,000
We spoke about this before 
because the whole CVE system run

481
00:27:45,000 --> 00:27:49,040
by MITRE, It was reported that 
MITRE funding might be stopping 

482
00:27:49,080 --> 00:27:54,600
like almost overnight. 
And the whole CVCVECVES are 

483
00:27:54,640 --> 00:27:56,400
basically the records for all 
the exploits. 

484
00:27:56,400 --> 00:27:59,440
Every single vulnerability 
pretty much gets ACV assigned to

485
00:27:59,440 --> 00:28:01,120
it. 
And that is a central database 

486
00:28:01,120 --> 00:28:05,120
that globally is used by 
multiple systems to do that. 

487
00:28:05,120 --> 00:28:09,360
And as a result of CV ES 
possibly going, the EU quickly 

488
00:28:09,360 --> 00:28:13,560
set up their own equivalent. 
But it looks like that problem's

489
00:28:13,560 --> 00:28:15,440
not going away. 
So we'll see what the budget 

490
00:28:15,440 --> 00:28:17,880
looks like. 
This is just a proposal. 

491
00:28:17,880 --> 00:28:20,200
It has to go through Congress 
and stuff like that, but that's 

492
00:28:20,200 --> 00:28:22,360
all LED there. 
By the Republican. 

493
00:28:22,360 --> 00:28:26,040
Party so they pretty much can do
what they want at the moment. 

494
00:28:27,240 --> 00:28:29,720
Doesn't it bode well? 
Does it really? 

495
00:28:30,240 --> 00:28:34,000
No, it's interesting. 
The article says it would bring 

496
00:28:34,000 --> 00:28:37,560
their budget down to 2 billion 
if they did cut that. 

497
00:28:39,640 --> 00:28:45,480
And in 2025 proposal nearly 500 
million cut, but Congress pushed

498
00:28:45,480 --> 00:28:52,720
back and it was 135 million. 
So yeah, interesting one. 

499
00:28:53,880 --> 00:28:59,520
Yeah, I mean, 1/3 a third of 
staff left CISA about a year 

500
00:28:59,520 --> 00:29:03,320
ago, in the first months of 
Trump's second term, which was 

501
00:29:03,320 --> 00:29:07,800
probably. 
Dog or someone like that so. 

502
00:29:08,160 --> 00:29:10,360
You took the other one to invest
a lot into that given the 

503
00:29:10,600 --> 00:29:12,320
current climate. 
But do you know what? 

504
00:29:13,280 --> 00:29:16,240
They're making the biggest 
investments ever in their 

505
00:29:16,240 --> 00:29:19,160
military. 
And you would have thought that 

506
00:29:19,160 --> 00:29:21,760
this would kind of tie nicely 
along with it. 

507
00:29:21,760 --> 00:29:27,160
And I wonder if it's not being 
sold in the right way like the 

508
00:29:27,160 --> 00:29:30,760
impacts of this. 
But but it's that there's also 

509
00:29:30,760 --> 00:29:35,760
the line in there about the 
international collaboration is 

510
00:29:35,760 --> 00:29:39,640
that there is that, that maybe 
they feel they're doing too much

511
00:29:39,640 --> 00:29:43,280
work for everyone else, which is
what's been said in the Middle 

512
00:29:43,280 --> 00:29:45,640
East, isn't it, that, you know, 
no one's helping them. 

513
00:29:45,760 --> 00:29:46,720
Yeah. 
Now. 

514
00:29:46,960 --> 00:29:50,160
Maybe that's part of the problem
international engagement efforts

515
00:29:51,120 --> 00:29:54,400
anyway. 
Well then keep an eye on that, 

516
00:29:54,400 --> 00:29:58,000
because if all of a sudden the 
CVE database doesn't get updated

517
00:29:58,000 --> 00:30:00,560
anymore, we're all going to need
to know where to get our 

518
00:30:00,560 --> 00:30:04,560
vulnerability confirmation from.
So it's one worth keeping your 

519
00:30:04,560 --> 00:30:06,600
eyes out for. 
I'm sure it'll be big news when 

520
00:30:06,600 --> 00:30:09,920
it happens, if it happens. 
Probably will happen, but there 

521
00:30:09,920 --> 00:30:12,680
we go. 
Right, that is this week's news.

522
00:30:12,680 --> 00:30:15,680
So now let's go on to the fish. 
Of the week. 

523
00:30:20,040 --> 00:30:21,640
Right. 
And this week's fish of the 

524
00:30:21,640 --> 00:30:25,400
week, as always, comes from the 
threat intelligence team at 

525
00:30:25,400 --> 00:30:28,760
Hawks Hunt. 
And this week it's a bit of a 

526
00:30:28,920 --> 00:30:32,440
bit of an interesting one. 
WhatsApp Meta impersonation 

527
00:30:33,240 --> 00:30:37,960
leading to credential and 
verification code theft. 

528
00:30:38,640 --> 00:30:46,480
So we have what we can see here 
is essentially a WhatsApp 

529
00:30:46,480 --> 00:30:48,600
message. 
It says. 

530
00:30:48,600 --> 00:30:52,160
Dear partner, we hope this 
e-mail finds you well. 

531
00:30:52,320 --> 00:30:55,480
We're reaching out to notify you
that based on your company's 

532
00:30:55,480 --> 00:30:59,560
performance metrics reviewed for
2025, you've not met the 

533
00:30:59,560 --> 00:31:03,400
requirements to maintain select 
level status in the Meta 

534
00:31:03,400 --> 00:31:05,160
Business Messaging Partners 
programme. 

535
00:31:06,320 --> 00:31:09,000
To assist you, please refer to 
this guide. 

536
00:31:09,280 --> 00:31:12,320
If you require support, submit a
request through the partner 

537
00:31:12,320 --> 00:31:15,280
portal support firm. 
There's another couple of links.

538
00:31:15,280 --> 00:31:19,120
You have until March the 12th to
fulfil the outstanding 

539
00:31:19,120 --> 00:31:22,000
requirements and maintain your 
current selected status. 

540
00:31:22,280 --> 00:31:25,360
So deadline. 
If you have any questions, 

541
00:31:25,800 --> 00:31:28,920
please contact the support team 
via malicious link. 

542
00:31:29,000 --> 00:31:34,160
So yeah, it's that in itself is,
you know, there's a little bit 

543
00:31:34,160 --> 00:31:35,600
of pressure there, a little bit 
of. 

544
00:31:38,560 --> 00:31:41,440
The sender address the, the red 
flags on this, the sender 

545
00:31:41,440 --> 00:31:45,720
address doesn't match doesn't 
match WhatsApp. 

546
00:31:45,720 --> 00:31:49,000
It's actually a Salesforce.com 
e-mail address. 

547
00:31:51,080 --> 00:31:52,960
It is imitating the WhatsApp 
branding. 

548
00:31:53,040 --> 00:31:55,520
So it does look like it's 
WhatsApp from Meta. 

549
00:31:56,880 --> 00:31:58,840
There's obviously the pressure 
of quick action. 

550
00:31:58,840 --> 00:32:02,840
Oh, do this quick or you're 
going to lose access and 

551
00:32:02,880 --> 00:32:09,080
there's. 4 I think. 3. 4 links 
in that partner portal support 

552
00:32:09,080 --> 00:32:12,080
forum. 
You can see the guide which is 

553
00:32:12,080 --> 00:32:15,320
accessible here click here and 
then there's a big green button 

554
00:32:15,320 --> 00:32:17,920
at the bottom. 
They'll go to the same place. 

555
00:32:18,120 --> 00:32:20,120
They all, they all go to the 
same destination. 

556
00:32:20,600 --> 00:32:24,320
And it's that destination that 
is interesting because what do 

557
00:32:24,320 --> 00:32:27,920
you get when you click through? 
You get. 

558
00:32:28,680 --> 00:32:33,200
A fake login page which asks you
to log into your meta partner 

559
00:32:33,200 --> 00:32:38,160
partner portal and then ask you 
to verify your identity. 

560
00:32:38,400 --> 00:32:45,760
So that's obviously I'm assuming
this was targeted and it's then.

561
00:32:46,240 --> 00:32:51,480
Stealing your partner portal 
login page and it's going to 

562
00:32:51,480 --> 00:32:54,160
capture your verification. 
Codes for MFA as well. 

563
00:32:54,360 --> 00:32:59,840
So as you sign in, some secret 
system is probably signing in, 

564
00:33:00,160 --> 00:33:02,960
you know, ghost system signing 
in on your behalf. 

565
00:33:02,960 --> 00:33:06,480
It's probably just pasting those
over so. 

566
00:33:07,440 --> 00:33:12,400
Yeah, it's it's important to 
remember as well that even the 

567
00:33:13,000 --> 00:33:17,880
the smaller systems that we use,
you know, this isn't something 

568
00:33:17,880 --> 00:33:20,960
that I would probably receive 
because I don't have a partner 

569
00:33:20,960 --> 00:33:23,480
portal account you if you 
received. 

570
00:33:23,480 --> 00:33:26,480
That message you'd probably 
disregard it because I assume 

571
00:33:26,480 --> 00:33:30,480
you don't have a WhatsApp or 
Meta partner Paul account. 

572
00:33:31,280 --> 00:33:34,040
But if you do have one of those 
accounts and you do see that 

573
00:33:34,040 --> 00:33:37,120
message losing access to that 
account very. 

574
00:33:37,120 --> 00:33:41,120
Shortly would probably be quite 
scary and a bit disruptive, so 

575
00:33:41,120 --> 00:33:44,520
you're going to be encouraged to
quickly do it and it all looks 

576
00:33:44,960 --> 00:33:46,760
very, very legitimate. 
Doesn't it? 

577
00:33:47,520 --> 00:33:49,960
Yeah, especially the landing 
page. 

578
00:33:50,640 --> 00:33:53,520
Yeah, it looked pretty genuine. 
I mean, it didn't show what URL 

579
00:33:53,640 --> 00:33:56,680
you'd see, but presumably it's 
some yeah, random sort of M 

580
00:33:56,680 --> 00:33:59,080
doing the same metro or anything
in it, right? 

581
00:33:59,080 --> 00:34:03,240
So again, probably some red 
flags to look out for, but like 

582
00:34:03,240 --> 00:34:07,240
you said, in an urgent sort of 
scenario you might just blindly 

583
00:34:07,440 --> 00:34:12,120
start doing it. 
If you get one of those, if you 

584
00:34:12,120 --> 00:34:14,880
get something like that, it's 
often best to go directly to 

585
00:34:14,880 --> 00:34:20,600
source and and just go to. 
Google Facebook partner portal 

586
00:34:20,600 --> 00:34:22,320
and look for the first organic 
result. 

587
00:34:22,440 --> 00:34:24,920
You know, don't click on the 
paid foreheads because it might 

588
00:34:24,920 --> 00:34:28,880
be malicious, but you know, 
Google it or have it saved in 

589
00:34:28,880 --> 00:34:30,679
your bookmarks. 
Like this is a really good for 

590
00:34:30,679 --> 00:34:33,600
the stuff we do before I log 
into the platform we use to 

591
00:34:33,600 --> 00:34:35,400
record this. 
I've got it all bookmarked so I 

592
00:34:35,400 --> 00:34:38,159
don't need to find it on an 
e-mail or type in the address. 

593
00:34:38,840 --> 00:34:42,199
You know, bookmarks to your 
trusted sites is a maybe that's 

594
00:34:42,600 --> 00:34:46,040
maybe that's an awareness 
message that we should push out.

595
00:34:46,080 --> 00:34:49,400
You know, like if there's a site
you log into, bookmark it. 

596
00:34:50,199 --> 00:34:52,159
Do you know how to use the 
bookmarks bar? 

597
00:34:52,159 --> 00:34:54,080
Do you know how to organise your
bookmark folders? 

598
00:34:54,360 --> 00:34:56,199
Bookmarks are like a forgotten 
thing, right? 

599
00:34:56,719 --> 00:34:57,960
Exactly. 
Potentially. 

600
00:34:58,160 --> 00:35:00,200
I mean, yeah, but we didn't 
really talk about it much. 

601
00:35:00,200 --> 00:35:01,880
Right. 
What a great site, What a great.

602
00:35:01,880 --> 00:35:06,400
Angle for secure Internet usage.
You know, this is the site. 

603
00:35:07,040 --> 00:35:10,960
It's it's but shortcuts. 
It saves you looking for it and 

604
00:35:10,960 --> 00:35:15,000
potentially falling foul. 
I I haven't even got into this 

605
00:35:15,160 --> 00:35:17,720
planning that, but I think 
that's that's a great piece. 

606
00:35:17,720 --> 00:35:20,160
Like do some promotion on 
bookmarks. 

607
00:35:20,400 --> 00:35:24,720
It it encourages safe browsing 
behaviour. 

608
00:35:24,800 --> 00:35:26,640
Yeah. 
Anyway, that's this week's fish 

609
00:35:26,640 --> 00:35:28,760
of the week. 
Big thank you to the threat 

610
00:35:28,760 --> 00:35:30,680
intelligence team at Hawks. 
Hunt for that. 

611
00:35:30,800 --> 00:35:35,840
Awesome, yeah. 
So let's get on with some 

612
00:35:35,840 --> 00:35:41,080
security socials. 
This week I had a few things to 

613
00:35:41,080 --> 00:35:45,720
share with you, and this one is 
from Reddit, obviously, because 

614
00:35:45,720 --> 00:35:48,320
that's where I spend. 
My spare time. 

615
00:35:48,400 --> 00:35:55,360
And this one is from a subreddit
called Interesting as we'll keep

616
00:35:55,360 --> 00:35:56,960
it PG, but you kind of get the 
picture. 

617
00:35:58,040 --> 00:36:02,960
This is North Korean state 
sponsored hacker got exposed 

618
00:36:03,360 --> 00:36:05,880
during a job interview. 
Have you seen this? 

619
00:36:07,280 --> 00:36:09,720
No, no. 
Let me turn, turn the volume on.

620
00:36:09,720 --> 00:36:14,720
Listen to this. 
Hello, just to explain, this is 

621
00:36:14,720 --> 00:36:17,960
a zoom call. 
All we can see in the video is 

622
00:36:17,960 --> 00:36:21,480
just the gentleman with a 
headset on. 

623
00:36:21,640 --> 00:36:23,280
OK, you don't need to see any 
more. 

624
00:36:23,400 --> 00:36:24,800
It's not like last week's with 
three. 

625
00:36:24,800 --> 00:36:27,680
Fingers over the face. 
Just listen to this North Korean

626
00:36:27,680 --> 00:36:30,840
state sponsored hacker got 
exposed during a join. 

627
00:36:31,640 --> 00:36:32,840
Hey, you're back. 
What happened? 

628
00:36:33,000 --> 00:36:35,640
Yeah, OK. 
I just. 

629
00:36:35,760 --> 00:36:40,600
Yeah, there's no issue. 
I just. 

630
00:36:41,360 --> 00:36:43,000
OK, no worries. 
Yeah. 

631
00:36:43,000 --> 00:36:45,440
I mean, I was, I was in the 
process of saying, like we did 

632
00:36:45,440 --> 00:36:47,680
like a lot of imposter 
candidates, you know, 

633
00:36:48,520 --> 00:36:51,400
particularly N Koreans, like 
posing as like people that 

634
00:36:51,400 --> 00:36:53,400
they're not. 
So one of the tests that we do 

635
00:36:53,400 --> 00:36:56,360
is trying to get them to say 
something like Kim Jong Un is a 

636
00:36:56,360 --> 00:36:58,640
fat, ugly pig. 
Would you, could you say that 

637
00:36:58,640 --> 00:37:03,160
for me? 
Sudha Sudha. 

638
00:37:04,520 --> 00:37:06,800
Sorry, no Kim Jong Un. 
You know, the leader of North 

639
00:37:06,800 --> 00:37:16,200
Korea. 
Yeah, I sorry, I just say I 

640
00:37:16,320 --> 00:37:23,320
should say like that, yeah. 
Yeah, if you could because, 

641
00:37:23,360 --> 00:37:26,240
because it's one test so that I 
know that you're not not North 

642
00:37:26,240 --> 00:37:32,200
Korean. 
Yeah. 

643
00:37:33,760 --> 00:37:42,320
Can you say that? 
What is it is that? 

644
00:37:43,200 --> 00:37:47,400
And they froze. 
And I think that damn. 

645
00:37:47,760 --> 00:37:51,960
He really don't want to say it. 
So there you go. 

646
00:37:52,000 --> 00:37:53,400
Yeah. 
And then they just dropped off 

647
00:37:53,400 --> 00:37:56,600
the call. 
So I thought that was that's 

648
00:37:56,600 --> 00:37:59,840
obviously like someone who 
claiming not to be from North 

649
00:37:59,840 --> 00:38:03,200
Korea, but it's actually from 
North Korea, you know, was it 

650
00:38:03,600 --> 00:38:06,520
no, was it night before that 
hired a North Korean? 

651
00:38:06,800 --> 00:38:08,280
Was it night before? 
Possibly. 

652
00:38:08,280 --> 00:38:11,720
Yeah, one of the security firms 
happens all over. 

653
00:38:12,040 --> 00:38:15,440
One of the security firms hired 
a North Korean operative and 

654
00:38:15,440 --> 00:38:17,240
then had to. 
Come out and say we discovered 

655
00:38:17,240 --> 00:38:18,440
it. 
Here's how we discovered it. 

656
00:38:18,440 --> 00:38:20,800
You know it's. 
It's a way to infiltrate. 

657
00:38:22,040 --> 00:38:25,560
So yeah, last week we had three 
fingers over the face to spot a 

658
00:38:25,560 --> 00:38:33,080
deep fake, and this week King 
John is a yeah, I should say it.

659
00:38:33,080 --> 00:38:34,920
I'm not North Korea. 
He's a big, he's a big ugly pig.

660
00:38:34,960 --> 00:38:36,360
There we go. 
I can say it. 

661
00:38:36,360 --> 00:38:40,040
I'm. 
Yeah, yes. 

662
00:38:40,160 --> 00:38:43,840
So that was the first one I 
thought was quite interesting. 

663
00:38:44,920 --> 00:38:48,400
The second one I have to share a
picture of because the post 

664
00:38:48,400 --> 00:38:52,160
actually got deleted from 
Reddit, but I found it. 

665
00:38:52,360 --> 00:38:54,240
OK let me just share this 
instead. 

666
00:38:56,560 --> 00:39:01,160
This was from recruiting hell. 
OK and this is a great security 

667
00:39:01,160 --> 00:39:04,520
message here. 
Interview went great until they 

668
00:39:04,560 --> 00:39:08,840
accidentally sent what they said
after my husband disconnected. 

669
00:39:09,800 --> 00:39:11,600
My husband had a virtual 
interview today. 

670
00:39:11,600 --> 00:39:14,480
He felt really good about it and
they gave a lot of positive 

671
00:39:14,480 --> 00:39:18,240
feedback during the interview, 
at one point saying this is the 

672
00:39:18,240 --> 00:39:22,000
best interview we had. 
However, this evening he was 

673
00:39:22,000 --> 00:39:25,760
sent a transcript and audio file
of the entire interview, 

674
00:39:26,040 --> 00:39:28,960
including the recruiter and 
interviewer discussing my 

675
00:39:28,960 --> 00:39:31,840
husband after he disconnected 
from the call. 

676
00:39:32,240 --> 00:39:34,480
I don't know if they know they 
did this. 

677
00:39:34,880 --> 00:39:37,680
In that recording they made 
comments about his appearance 

678
00:39:37,680 --> 00:39:40,000
including I hate this effing 
man. 

679
00:39:40,000 --> 00:39:44,200
Bun referred to other companies 
as Boujee, talked about stealing

680
00:39:44,200 --> 00:39:48,560
business from competitors in a 
pretty aggressive way, said they

681
00:39:48,560 --> 00:39:51,840
will put another business out of
business and praised men who can

682
00:39:51,840 --> 00:39:55,120
fight and go for a beer later, 
while saying others who are 

683
00:39:55,400 --> 00:39:57,200
bothered by that are little 
girls. 

684
00:39:57,880 --> 00:39:59,960
When the interviewer asked the 
recruiter what my husband's 

685
00:39:59,960 --> 00:40:03,600
desired salary was, he said oh 
it's on the low end and then 

686
00:40:03,600 --> 00:40:06,440
proceeded to say he would offer 
him less than what my husband is

687
00:40:06,440 --> 00:40:09,400
asking asking. 
Clearly if he's offered the job 

688
00:40:09,400 --> 00:40:12,360
he won't take it, but I feel 
like this is really entitled, 

689
00:40:12,360 --> 00:40:15,920
unprofessional behaviour. 
I'd love to expose them, but I 

690
00:40:15,920 --> 00:40:17,560
also don't want to put my 
husband at risk. 

691
00:40:17,560 --> 00:40:20,040
Of not getting other jobs in the
industry because of the drama. 

692
00:40:20,680 --> 00:40:22,200
What are the things we could do 
that wouldn't? 

693
00:40:22,200 --> 00:40:25,280
Necessarily be tied to us always
to do something about this. 

694
00:40:26,000 --> 00:40:28,480
Maybe that's why it got deleted 
from Reddit, because they 

695
00:40:28,560 --> 00:40:30,280
didn't. 
Want it coming viral? 

696
00:40:30,400 --> 00:40:32,920
Because it did pretty much go 
quite viral. 

697
00:40:34,560 --> 00:40:38,880
So, yeah, like if you've got 
external third parties in a 

698
00:40:38,880 --> 00:40:44,320
meeting and then the third 
party, I've seen it happen loads

699
00:40:44,320 --> 00:40:46,440
of times. 
Like, Oh yeah, I'm done, I'll 

700
00:40:46,440 --> 00:40:48,920
drop off. 
Oh, can you, can you just look, 

701
00:40:48,920 --> 00:40:52,960
can you just stay on? 
And then you stay on, you wrap 

702
00:40:52,960 --> 00:40:54,800
up. 
God, I'm glad he's gone. 

703
00:40:55,000 --> 00:40:57,160
You know, now we can like, oh 
God, did you see what he was 

704
00:40:57,160 --> 00:40:59,760
wearing? 
And then when the notes, when 

705
00:40:59,760 --> 00:41:03,120
the transcription is sent, it 
goes to all parties. 

706
00:41:03,200 --> 00:41:06,840
So this must happen loads. 
Loads and loads of loads, but 

707
00:41:06,840 --> 00:41:10,360
people won't think about it. 
This is a proper big data 

708
00:41:10,360 --> 00:41:13,520
leakage. 
Hell, I think if you're. 

709
00:41:13,840 --> 00:41:16,880
Yeah, that's terrible. 
If you're doing anything, it's 

710
00:41:16,880 --> 00:41:20,880
almost like if you're on a 
meeting with more than just two 

711
00:41:21,640 --> 00:41:25,440
and then someone drops off and 
you want to carry on, start a 

712
00:41:25,440 --> 00:41:28,440
new meeting. 
That's a really good there's a 

713
00:41:28,440 --> 00:41:30,120
great message to give out to you
people. 

714
00:41:30,320 --> 00:41:34,360
You know, here's a great example
of why I bet this happens. 

715
00:41:34,800 --> 00:41:40,240
All the time, all the time. 
Yeah, I think as well, like 

716
00:41:40,240 --> 00:41:45,160
sometimes you are ask someone to
come back into a meeting as 

717
00:41:45,160 --> 00:41:46,960
well. 
So it could also happen I guess 

718
00:41:46,960 --> 00:41:50,680
in that way if you say something
before then after they've left 

719
00:41:50,680 --> 00:41:55,320
and then come back. 
Yeah, yeah, that's pretty awful 

720
00:41:55,640 --> 00:41:59,480
if it's if it's true. 
Yeah, right. 

721
00:41:59,520 --> 00:42:04,440
Let me show you my next thing. 
I love this guy Matty Mctech. 

722
00:42:07,080 --> 00:42:11,600
His videos come up quite often. 
This one I saw on Facebook 

723
00:42:11,840 --> 00:42:14,200
because I'm of the generation 
that still uses Facebook 

724
00:42:14,200 --> 00:42:19,000
occasionally, and I was today 
years old when I found this out.

725
00:42:19,960 --> 00:42:22,160
I'll show it to you and then 
we'll talk about it after. 

726
00:42:22,880 --> 00:42:25,040
I was today years old when I 
found this out. 

727
00:42:25,240 --> 00:42:28,040
Is there you can actually create
QR codes in your Microsoft Word?

728
00:42:28,080 --> 00:42:30,040
All I have to do is click 
somewhere on your Word document,

729
00:42:30,040 --> 00:42:33,240
then press control and F9 on 
your keyboard and type in 

730
00:42:33,240 --> 00:42:36,680
display barcode and after a 
space you're going to open 

731
00:42:36,680 --> 00:42:39,320
quotation Marks and then type in
where you want the QR code to 

732
00:42:39,320 --> 00:42:41,840
take you to or display and then 
close the quotations. 

733
00:42:41,840 --> 00:42:46,680
Then you're going to do space UR
space back slash 3 and when you 

734
00:42:46,680 --> 00:42:49,760
hit F9 on your keyboard, it'll 
generate you a working QR code. 

735
00:42:49,920 --> 00:42:52,360
I can scan it with my phone and 
it'll take me to that link. 

736
00:42:52,720 --> 00:42:56,240
Easy. 
You don't need to use random 

737
00:42:56,240 --> 00:42:59,920
third party QR code creation 
tools, you can just use 

738
00:42:59,920 --> 00:43:01,680
Microsoft. 
Word to make a QR code. 

739
00:43:03,720 --> 00:43:06,600
Oh yeah, good for those that use
it, but. 

740
00:43:08,240 --> 00:43:09,960
Yeah, I didn't know. 
Very well known, right? 

741
00:43:10,040 --> 00:43:13,480
No, I had no idea. 
But there's, you know, there's a

742
00:43:13,480 --> 00:43:16,760
really good idea if you've got 
think about the teams in 

743
00:43:16,760 --> 00:43:17,880
business. 
Here maybe? 

744
00:43:18,120 --> 00:43:21,640
Well, it's a bit complicated, 
but you could save that, save 

745
00:43:21,640 --> 00:43:24,440
that as a, save it as a doc and 
then change it. 

746
00:43:24,960 --> 00:43:27,320
It's, there's probably it. 
Got it. 

747
00:43:27,480 --> 00:43:31,480
I'm only now just thinking there
must be easier ways to make QR 

748
00:43:31,480 --> 00:43:34,600
codes than Googling it and going
to a random website. 

749
00:43:35,400 --> 00:43:40,000
But the teams that will probably
be running Microsoft Word, HR, 

750
00:43:40,000 --> 00:43:44,600
finance, people like that, you 
know, and they might be making 

751
00:43:44,600 --> 00:43:50,120
posters for bike sales or 
charity things or job vacancies,

752
00:43:50,120 --> 00:43:52,120
that kind of thing. 
It's a. 

753
00:43:53,200 --> 00:43:56,000
It's it's not straightforward, 
but it's also not overly 

754
00:43:56,000 --> 00:43:58,800
difficult. 
This it could be a good thing to

755
00:43:59,560 --> 00:44:03,640
to maybe communicate to to your 
business because it's a little 

756
00:44:03,640 --> 00:44:07,040
bit safer maybe. 
Yeah, that's. 

757
00:44:07,200 --> 00:44:11,640
Interesting. 
Let me show the last one I had 

758
00:44:11,680 --> 00:44:15,160
this week and this again was on 
Reddit. 

759
00:44:15,320 --> 00:44:17,640
And this was from mildly 
infuriating. 

760
00:44:21,520 --> 00:44:26,640
My phone had an update and 
automatically installed TikTok. 

761
00:44:27,520 --> 00:44:32,720
Well that's terrifying isn't it?
So we look here, this is TikTok 

762
00:44:32,720 --> 00:44:36,720
Lite is installed after an 
update. 

763
00:44:40,760 --> 00:44:42,680
Someone else? 
The top comment on this then 

764
00:44:42,680 --> 00:44:45,760
says, Is that a giant ad on your
screen? 

765
00:44:48,480 --> 00:44:51,440
And the original poster reply 
said no, it's a shortcut to it 

766
00:44:51,600 --> 00:44:55,840
Aliexpress game page. 
It's like but if you look at 

767
00:44:55,840 --> 00:44:59,880
some of the comments every time 
I get an update I get random ass

768
00:44:59,880 --> 00:45:02,720
games installed. 
The last time it was easy words 

769
00:45:02,720 --> 00:45:04,120
number. 
Tiles and colour sort. 

770
00:45:05,960 --> 00:45:07,760
Someone says disable your 
carrier's. 

771
00:45:07,760 --> 00:45:10,800
App Manager, yeah, it's 
different things based on the 

772
00:45:10,800 --> 00:45:13,240
carrier it's. 
It's. 

773
00:45:13,240 --> 00:45:16,080
Mad isn't it? 
Like I don't see this because 

774
00:45:16,280 --> 00:45:19,320
I've got an iPhone. 
This is why I returned my 2000 

775
00:45:19,360 --> 00:45:22,560
Canadian dollars unlocked 
Samsung phone. 

776
00:45:23,080 --> 00:45:25,120
Either lower the price or remove
ads. 

777
00:45:25,200 --> 00:45:28,160
You don't get both and someone 
says Google pixel phones are the

778
00:45:28,160 --> 00:45:31,960
way to go. 
It's it's crazy isn't it? 

779
00:45:31,960 --> 00:45:39,880
Like WTF is Tiktok Lite tracking
and ads only Probably it's yeah,

780
00:45:43,600 --> 00:45:47,280
yeah, yeah. 
It's, I do wonder, like maybe 

781
00:45:47,280 --> 00:45:54,320
it's maybe it's malware, maybe 
it's some third party app that's

782
00:45:54,320 --> 00:45:57,320
installed that's also doing 
this. 

783
00:45:58,200 --> 00:46:00,080
Like you wouldn't get a pixel 
doing it. 

784
00:46:00,080 --> 00:46:02,800
Maybe Samsung do do it a little 
bit. 

785
00:46:03,040 --> 00:46:06,720
I don't know. 
But you kind of expect to have 

786
00:46:06,720 --> 00:46:10,640
some privacy, don't you, on your
own device, especially on a, if 

787
00:46:10,640 --> 00:46:14,880
you've got corporate accounts on
there, like any random game or 

788
00:46:15,040 --> 00:46:17,320
unloaded, you don't know what 
the permissions are. 

789
00:46:17,760 --> 00:46:20,360
Imagine if like last week we 
spoke about the White House app.

790
00:46:20,400 --> 00:46:22,880
Imagine if that just got 
deployed to every American, 

791
00:46:23,680 --> 00:46:26,920
every mobile phone, and now gets
the White House app. 

792
00:46:28,160 --> 00:46:32,280
Is that the old iTunes and the 
U2 album it came free loaded 

793
00:46:32,280 --> 00:46:34,480
into? 
It and that was just free music.

794
00:46:34,880 --> 00:46:39,360
That was just. 12 tracks for 
free and the world went mad 

795
00:46:39,640 --> 00:46:41,920
because it was sent to every 
single iPhone. 

796
00:46:42,120 --> 00:46:43,960
Can you imagine? 
It probably wouldn't even get 

797
00:46:43,960 --> 00:46:46,320
talked about now if the White 
House app just ended up on every

798
00:46:46,320 --> 00:46:48,360
device with full permissions 
like. 

799
00:46:49,360 --> 00:46:52,360
Yeah, that's crazy. 
Yeah, anyway, that's everything 

800
00:46:52,400 --> 00:46:55,160
I had this week and you don't 
have anything this week. 

801
00:46:56,720 --> 00:46:59,240
No, I didn't. 
Didn't see much doing this. 

802
00:46:59,800 --> 00:47:02,360
So we're done. 
That's us done for another week.

803
00:47:03,160 --> 00:47:07,880
So yes, if you see anything out 
there in the wild and you want 

804
00:47:07,880 --> 00:47:09,480
to let us know, please get in 
touch. 

805
00:47:09,480 --> 00:47:15,720
Hello at riskycreative.com. 
Big thank you to Simeon for 

806
00:47:15,720 --> 00:47:17,840
sending that video over. 
I think I had. 

807
00:47:18,360 --> 00:47:21,560
One sent by someone else and I 
can't remember. 

808
00:47:21,600 --> 00:47:24,160
It's fine, I do it next week. 
Next time maybe. 

809
00:47:24,160 --> 00:47:27,680
Next time, OK, sign up for the 
newsletter, follow us on 

810
00:47:27,680 --> 00:47:30,520
YouTube, Spotify and all the 
podcast platforms. 

811
00:47:30,520 --> 00:47:33,200
And Luke and I, we'll see you 
again next week. 

812
00:47:34,400 --> 00:47:35,800
Cool. 
Cheers, Christina. 

813
00:47:35,800 --> 00:47:38,080
See you later. 
Bye bye.

