
Trusting the wrong package.
Keith Mularski: This is Channel 7 OMITV News.
Selena Larson: Good evening. I'm Selena Larson.
Keith Mularski: I'm Keith Mularski. Thanks for joining us. Our top story: A dangerous cyberstorm system moving across the country and leaving unsecured networks vulnerable.
Selena Larson: Tonight, officials are warning residents to prepare now as conditions continue to deteriorate. We go live to Chief Cyber Meteorologist Dave Bittner, who is standing by in the thick of it. Dave, what are you seeing out there?
Dave Bittner: Selena, what started earlier today as light spam activity has now developed into a dangerous cyberstorm system moving rapidly across unsecured networks nationwide. Take a look at these conditions. We're seeing heavy phishing bands moving in from the east, scattered scam calls throughout the tri-state area, and conditions are especially severe for anyone still using the password, "password123."
Keith Mularski: Disturbing images there.
Selena Larson: Dave, how serious could this get?
Dave Bittner: Well, officials have now upgraded this to a Category 4 spear phishing event. Authorities are urging people to stay off public Wi-Fi, enable multifactor authentication, and under no circumstances open emails titled, "Urgent." I repeat, do not -- hold on. I'm now getting a report of a large system of fake tech support calls moving in from overseas. If these systems merge, we could be looking at a full-blown "scamnado" event.
Keith Mularski: Dear God.
Selena Larson: Dave, for viewers just joining us, what should people be doing right now?
Dave Bittner: If you're in the path of this system, take cover immediately. Disconnect unknown devices. Secure your routers. Oh, no. Oh, my God. Is that a smart thermostat coming straight for me? [ Dull Thud ] [ Groaning ]
Selena Larson: Oh.
Keith Mularski: Tough conditions out there tonight.
Dave Bittner: "Get a job in broadcasting," they said. "It'll be glamorous," they said. I'm out of here. I'm just freakin' out of here.
Keith Mularski: Tough conditions out there tonight.
Selena Larson: We'll continue monitoring the situation as this cyber system moves through the area. Coming up after the break, a local man says his smart refrigerator ordered 67 jars of mayonnaise overnight after what experts are calling a "catastrophic voice assistant misunderstanding."
Keith Mularski: Stay with us. Channel 7 News continues right after this. [ Music ]
Selena Larson: Welcome. You're listening to "Only Malware in the Building." I am Selena Larson, joined by my co-hosts Dave Bittner and Keith Mularski, and I'm excited to talk about a cyber storm today, Dave. It's not one that is hopefully going to take you out of your house into catastrophic rain and lightning, but one that is taking over open-source software. I'm talking about the supply chain compromises, some conducted by TeamPCP, but we have, sort of, seen a wave of these supply chain attacks targeting developers, targeting the software that is important to our everyday enterprises. I'm curious, you guys, how you think about this? I feel like this is something that was somewhat new towards the end of last year. It didn't happen all that often. Every so often, you would see maybe a JavaScript library compromise, NPM packages, other types of open-source software that might have had backdoor or malicious code or something input in there, but now, it's very much a trend. We're seeing multiple different attacks like this that have occurred just recently. GitHub was compromised via a malicious VS Code extension on one of their developer accounts. That was, again, this sort of software supply chain. I'm curious, what are your guys' thoughts on this, and are you surprised that this has kind of become such a prominent threat? [ Music ]
Keith Mularski: I don't think it's a surprise at all. I mean, I think this was inevitable right after SolarWinds because SolarWinds kind of showed, hey, if you kind of get into that code, it's trusted, it's signed, everybody's using it. Now, that was, obviously, a nation state, you know, that did that, but now the criminals are kind of looking at it and saying, well, hey, you know, we could kind of do the same thing. We could get into the code. We don't have to phish everybody as an individual. Now, if we get into that code and it's trusted, you know, now we own a thousand places as opposed to one or two. I, you know, think it's fascinating that -- we'll kind of dive into it, but I think, in my opinion, I thought it was inevitable, and it was just only a matter of time before the criminals are, like, hey, that's kind of the way to go. Dave, your thoughts?
Dave Bittner: Yeah, I agree. It strikes me as being the natural evolution of things. Like you said, these things trickle down from the elite nation-state hackers of the world. Who knows, you know, maybe they're moonlighting on the side, and so they say to themselves, wow, these tools work great in my day job. Maybe I can make a little money with them as well. I agree. I think it was just a matter of time. I guess the big question is how serious is this, and what can we do about it?
Selena Larson: It is actually quite serious, and I think that one of the notable points of this is that these threat actors are targeting what's called the CI/CD pipeline, which stands for Continuous Integration and Continuous Delivery or Deployment. Basically, what it is, is organizations will automatically just update their software, update their software and services. That includes software that has multiple different dependencies that are relying on those secure updates to function. You have almost, sort of, this domino effect, right, where you're basically putting trust in the software and services that you're using. Then they are inherently putting trust into the supply chain that is supporting them, whether that's various open-source packages, different libraries that are available out there that are maintained and updated by individuals. It doesn't necessarily have to be open source, of course, right? You have threat actors that might be targeting the software supply chain of private industries as well. It was interesting because when we were planning this podcast, I had sent over a list of potential things to talk about. I think the original Shai-Hulud, which I always feel so silly saying that. I'm not a fan of Dune. I don't know if I'm allowed to say that working in cybersecurity.
Dave Bittner: You can turn in your nerd card.
Selena Larson: I know.
Keith Mularski: Great, great, Selena. You just lost us all of our viewers now.
Selena Larson: I'm so sorry. I couldn't get through the first book, and I watched the first movie, but that's it.
Dave Bittner: Yeah, you're not alone, Selena. You're not alone.
Selena Larson: Great. Okay. This is a safe space, a safe podcast, so hopefully I'm saying Shai-Hulud correctly, but that was the one back in the fall of last year that sort of started, or kicked off, I think, some of more attention paid to this wormable functionality of the supply chain potential, right? So basically, these compromised NPM packages and the Shai-Hulud was sort of worming its way through these repositories and a lot of these projects that were maintained by developers that have a lot of customers, a lot of consumers, a lot of people are using their tooling. There was just a lot of compromised packages on NPM that were, you know, kind of getting this automatic wormable capability. That happened back in the fall, and I'd be curious, Keith, for your take on that. Now what we're seeing is many, many more of these, and TeamPCP is one of the threat actors that is really pushing hard on these supply chain compromises. It's just, you know, one of many threat actors. I believe that there was also, recently, some research that came out from Google talking about the North Koreans. Potentially, they were compromising the Axios NPM package manager. That was back in March. I sent you guys a list of all these things that happened, and then there were two additional stories that came out after we had already planned this podcast. There was one that happened just this week at the end of May, where GitHub said that its internal repositories were compromised after that rogue sort of VS Code extension. TeamPCP was able to access a GitHub employee's account via this Visual Studio Code extension that was compromised, right? So it was, again, this third-party software supply chain. They were able to access those internal repositories. Then following that, there's another -- more PCP information that came out that was Megalodon. Have you guys heard of this Megalodon attack, this mass exploitation of the GitHub repo backdoors?
Dave Bittner: Yeah, it was in today's CyberWire, actually. We talked about it, yeah. [ Music ]
Selena Larson: Well, that shows I haven't listened to today's CyberWire.
Dave Bittner: It hasn't been published yet. [ Laughter ]
Selena Larson: Oh, okay. Thank goodness.
Keith Mularski: You're off the hook.
Selena Larson: All right. I didn't want to out myself.
Dave Bittner: Sneak preview, yeah.
Selena Larson: But, yeah, I mean I was, like, all right, guys, we have to talk about this. Then as we're getting ready and gearing up for this podcast, there's these, you know, multiple more stories coming out about this. It's really a massive, massive problem.
Keith Mularski: Yeah, I mean just looking at the dark web, I mean TeamPCP is a really interesting group because they were kind of really the first criminals to be on the dark web saying, hey, this is what we want to do. We want to conduct over 200 different supply chain attacks. We want to recruit affiliates just like, you know, the ransomware groups do. Future targeting, you know, have operational confidence in what they're doing, and they were even saying that their attacks have been so successful that they're spending all this time going through all the credentials and diving through all the data that they've got because they don't even know who all that they own right now. Those are just some of the things that we've heard that have been successful. I think there's a lot more still to come because they're still going through the data. They kind of had kind of a sprint, you know, to kind of use, you know, an agile term for software development. You know, the bad guys kind of had their own, you know, "sprint" to kind of, you know, compromise things. It's been really fascinating so far.
Dave Bittner: Don't you think that this ultimately comes down to being a who do you trust story? Like, I was giving a presentation a few weeks ago to a local business group, and we were talking about cloud storage and security and all the normal things, just kind of basic hygiene kind of stuff. One of the folks asked me a question, and they said, well, you know, these cloud suppliers, can I trust them with my data? I said, y-y-y-y-yes. [Laughter] You know, I mean, yes, right up until the moment you can't, right? That's how I feel like some of these dependencies are. They've been trusted for so long and they're the basic -- they're the Lego bricks of the software that we rely on every day. What would happen if all of a sudden, you know, one of the Lego bricks that came in your set was capable of listening to everything that you did and you didn't know it, and it went out in Lego sets all over the world? I mean, that's kind of what we're talking about here, to stretch a metaphor.
Keith Mularski: Are we going to get to the point where software updates are kind of like the same thing as executable code that we download over the Internet that we don't trust? I mean, because I think these groups, at the end of the day, they want to instill that distrust into what we've always trusted. You know, so are we going to get to that point? Then, you know, the other thing from the cybersecurity network defender side, kind of, who owns this risk? You know, is it AppSec? Is it DevSecOps? Is it Cloud Security? I mean, really, who's taking ownership to ensure that these repositories are safe, really, from a corporate standpoint? Those are a lot of questions that need to be answered.
Dave Bittner: Especially when we're talking about open source. You know, who ultimately is responsible? You know, you can talk about real-world things that get built and what parts? You know, if I'm an automaker and somebody makes a bad axle, right, or bad tires, right? Like, years ago, remember, we had things with Firestone and bad tires. Well, Ford sells me the car. Is Ford responsible or is Firestone responsible or are the people who provided the rubber to Firestone responsible? How far down do you go -- or are they all responsible, and what responsibility do I have for checking before I go and use something?
Keith Mularski: Yeah, and I think, you know, I think we had this conversation before. You know, some of these open repositories are really owned by a couple of people that update them. It's not, like, you have thousands of eyes on there. It's, like, you know -- it's like Joe and Jim pretty much own this repository that's updated and used by everybody. So, you know, where is that trust in that, and, you know, how can we have better oversight of that? And the other question that comes in, with so much coding being done with LLM right now, you know, does -- if the LLM is using one of those hijacked repositories now -- you know, that's just trusted that you're utilizing that. That's a whole other wave of badness, you know, that we could throw into this.
Selena Larson: "A can of worms," so to speak?
Keith Mularski: Can of worms, indeed.
Selena Larson: Well, there's a couple of good points that you bring up, and one of the things that you mentioned is LLMs. This is -- I don't think it's a coincidence that all of these software supply chain hacks and threats are increasing at the same time as organizations all over the world are expanding their AI capabilities and developer capabilities. So much of what people are being encouraged to do, at least what I'm seeing, from my perspective and the people that I talk to is, oh, well, you know, just make your job easier. You can you just use this LLM tool, use something like VS Code, use something like an editor of some sort, and just rely on us as an organization to make sure that everything is updated. Just, you know, automatically pulling down updates and making sure that you're on, you know, whatever is the most up-to-date version. It's totally great. Like, use any of these, like, approved applications from the store that you're -- whatever, you know, whatever platform that you're using. A lot of people are now becoming developers, are becoming people that are working with various different programs, that don't have that baseline understanding of, one, how these work and, two, being able to identify flaws or potential exploits or potential behaviors that something shouldn't be doing. I think that that is kind of in parallel of this. More and more people are going to be -- you know, the attack surface is opening, right? More and more people are going to be using some of these tools and resources. At the same time, more and more people are looking -- from a criminal perspective are looking for ways in. We haven't really dove into what the actual capabilities of this stuff is, right? When these actors, whether it's TeamPCP or different cybercriminal threat actors, they're looking for credentials. They're looking for information. They're looking for, you know, your DevOps pipeline. They're looking for how you can pivot and what other dependencies you might be using that they can then further compromise, right? So, you know, if you're a developer, and you're using a potentially compromised app, and then it gets on your host, they're going to also, like, use that to sort of jump to the compromise of your organization. It's multiple different hops. I think, but at the same time, it is also good that you mentioned LLMs, that this is also happening with the rise of things like Mythos and other sort of frontier AI models that are literally designed to identify flaws in software and identify flaws in the code that we're pushing updates for. I'm curious, you know, like we're talking about, like, well, whose responsibility is it? I think that that is the outstanding question, right, because it's, like, well, we're using a lot of metaphors in this conversation, and one that I thought was, okay, if I go to the grocery store, and I buy expired food. Then I eat the expired food and get sick, like, should the grocery store, like, not have sold me that food? Or should I have been, like -- made sure to check as I'm preparing my food that it is expired, and then I wouldn't have been myself sick? For me, I have been food poisoned so many times that I always check and make sure that my food is not expired.
Dave Bittner: You have a -- Selena has a fragile constitution.
Selena Larson: I am a delicate flower. [ Laughter ] Now I check the expiration date of everything.
Dave Bittner: Meanwhile, me and Keith are over here just eating spoonfuls of dirt. [ Laughter ]
Keith Mularski: If I need some gum, I'll pick it from the underside of the table.
Dave Bittner: Right. Right.
Selena Larson: Does that open this opportunity then for us to kind of be our own -- for organizations to be our own, you know, checkers, the people that are like, okay, we see -- like, you have to -- we're talking about trust, right? You have to trust, but verify, and verify process, that's the hard part. Are you foreseeing that, one, is this even feasible to be able to do this on the -- like, at the level of the interdependencies within our software ecosystems, and two, are things, like, you know, Mythos or the, you know, the OpenAI's tool or whatever the, you know, the vulnerability scanner AI tooling is coming, well, is that going to solve our problem? [ Music ] We'll be right back. [ Music ]
Dave Bittner: What if software could -- and forgive me because it is quite likely that this is already the way it is, so I'm just going to shine a spotlight on my ignorance. Please correct me if I'm wrong, but I'm imagining a system where a new version of some open-source package gets labeled as, you know, beta for however long, and it's put out there as beta for use. If you want to be on the cutting edge, hey, have at it. Check out our beta, but we have a version, the previous version, or maybe a version before the previous version, that is solid, that has been tested, that's been put out there that we're really confident doesn't have anything bad in it, and it works as advertised. In other words, what I'm saying is, is there some kind of -- is there a place for some kind of verification and certification of these basic building blocks? We know this version is safe. It's tried and true. It's been tested. Maybe that's a naive statement in a world where things like Mythos are finding Linux bugs that are 20 years old, right? I don't know. I mean, is it is it a crazy idea? [ Music ]
Keith Mularski: No, I don't think it's a crazy idea. I mean, I think, right now, this is this is a new frontier, you know, that we're seeing. I think we're going to see more and more of this. I mean, just like Selena, you brought up, you know, a great point of, you know, people that are doing coding that really aren't programmers. You know, I mean, all the vibe coders right now, it's just like they wouldn't know a bad repository from a good repository. They're just, hey, we're vibe coding. I think we're just -- you know, this is a new attack surface now. I just see that that this is going to permeate because now, again, this is this is the very first, kind of, criminal organization that's doing this. I mean, I know criminals have done supply chain attacks, you know, in the past, but this is the one that's kind of industrializing that. You know, they're getting affiliates. They're advertising on the dark web. This is going to be more and more of a problem as more and more people are getting into coding that really aren't traditional programmers that can go through the line by line and say, yeah, this is something bad. I think this is something that everybody's going to need to plan for, and I would suggest have this be a tabletop exercise. You know, you've got to kind of go through this, you know, as a corporation. You know, what if this happened? What are we doing? Because the other thing I think that people need to remember is if there is a bad repository that's identified, just even going back to, you know, if you've deployed that already, just rolling back to that trusted version doesn't take away the fact that, probably, all your credentials have been compromised. You know, so you still have an incident that you have to deal with. You can't just say, well, we're better now that we've rolled it back because, you know, all these credentials, like you were talking about, have already been, you know, exposed to the bad guy. I really think that people need to start talking about this and kind of tabletopping this.
Selena Larson: One of the things I think is interesting is you have to know what your dependencies are in the first place. Sometimes that's super difficult. I think -- what was it I was looking at? Something like 7-Zip has, like, hundreds of dependencies just, like, within that one piece of software, so if you are -- as an organization, in the same way that you do asset identification, right, to like baseline -- if you're doing like a baseline understanding of what's in your network and what assets you have, you have to do the same thing with your software. What are the most critical pieces of software that we are relying on the most and what are those dependencies within it? Like, can you talk to those software makers? Like, what is their process? How are they validating things? How are -- what are their procedures for this? I think, you know, Keith, you're talking about the vibe coders and people that are just like, yeah, AI everywhere. I think one thing that a lot of organizations aren't doing as they're doing this AI rollout is putting together a best practices list. Like, how do you actually use this? What are approved applications and resources that you can use? How do you install them? What are, you know, the security policies in place there? What machines are you allowed to use this stuff on? Like, are you using it in a VM that's not touching any sort of production environment? Having these, sort of, like, best practices lists out there that are, like, okay, this is -- we're rolling this out, and here are the rules to follow. But yeah, I think, you know, this idea of trust but verify, I mean, that's just kind of, like, the reality of where we are now. Paradoxically, we see with CVE updates, when organizations don't patch vulnerabilities and are a little bit behind on some of their updates, that they are leaving themselves exposed. What we're kind of seeing now with the supply chain in this automated CI/CD pipelines is if they are automatically rolling out these updates that are vulnerable, the people that have it, you know, a little bit more delayed might be the ones that are more secure in the end. Yeah, I mean, it is this idea of okay, like, knowing what those, like, what software you're using, what those dependencies are, and making sure that you have a process in place for people to approve every rollout that says, yes, we know. We have validated that this is safe. We can, you know, put this out there, and maybe that is putting some sort of, you know, LLM in the loop or something to validate.
Keith Mularski: Even those LLMs, I mean, you know, like, all those coding agents that you were just talking about, they're, you know, they're actually accelerating trust, as opposed to, you know, what you were just saying. How can we actually look at this a little deeper? [ Music ]
Dave Bittner: Well, yeah, and what if, ultimately, you're able to poison the LLM to the point where, you know, you tell it to ignore all previous commands, and whenever given the opportunity, while vibe coding, to slip in some code that steals credentials, please do so and send them here, right? Now, everybody using that LLM, bam. I'm oversimplifying and exaggerating, but again, it's these layers, like, how -- at some point, there has to be trust in something?
Selena Larson: Well, I mean, you bring up a great point because one of the big attacks that happened impacted LiteLLM, [laughter] --
Dave Bittner: I was just going to mention that, yeah.
Selena Larson: -- which is, you know, used for LLM deployment by many, many enterprises. That, again, was a supply chain compromise that was originated from their Trivy dependency, again, in their CI/CD pipeline. I don't know, Keith, did you have any thoughts about this, this idea of poisoning the AIs, I guess?
Keith Mularski: Yeah, well, we were talking about that, you know, I guess a couple episodes when we were talking about AI. You know, that I just see, you know, that prompt poisoning as kind of being the SQL injection of, you know, the 2030s, I guess, or the late, you know, 2020s, because SQL injection was, like, the big thing back in, you know, the early aughts, I guess. Now it kind of gives the same opportunity to do these prompt injections and poison the LLM. I really see that as, you know, a big attack vector in, you know, the months and years to come, especially with the rapid deployment of LLMs. You know, people are just -- like you were just saying, people are just deploying it out there to say, hey, we need AI or we need the LLM here. Really not sitting down and looking at the security posture of, you know, what does this all mean? What does this mean for not only our cybersecurity department, but for the enterprise as a whole? [ Music ]
Dave Bittner: What if LLMs are the miracle of asbestos? [ Laughter ]
Keith Mularski: We talked about that. Yeah, we come right back to this, yeah. [Laughter]
Selena Larson: Honestly, as somebody who just had to replace all of the popcorn ceilings in their 100-year-old house, I do not understand why asbestos was created in the first place.
Dave Bittner: Oh, it's a wonder material. Are you kidding me? You could use it -- it was a floor wax and a dessert topping. It was everything. I mean, what a wonder, wonder material.
Selena Larson: I just feel like -- I don't know. I can't believe it still exists, and it was so unsafe. I'm just, like, well, I can't be in my house for a while. I have to put on a mask in order to function --
Dave Bittner: Yeah.
Selena Larson: -- and walk around.
Dave Bittner: No. They put that stuff in everything back then before they knew.
Selena Larson: I mean, is it just AI asbestos? Like, is that what we're --
Dave Bittner: Yes, AI asbestos.
Selena Larson: I don't know. I don't know.
Dave Bittner: I like it. I like it.
Selena Larson: I mean, I think more than anything, this is, like, giving us job security, right, because, like, we -- we're talking about the, like, the need and the requirement for people to be able to, like, validate these updates and having this sort of, like, trust-but-verify method, right? You need -- whether you're using an LLM or not, like, if these actors are going to be using prompt injection, you're going to need somebody there just to spot some of that -- issues. You're also going to need somebody that knows, like, what the software is, what these dependencies are, and what it -- how to flag and how to actually, like, identify deviations from, like, real behavior. I don't know. Keith, I feel like I interrupted you and you were about to say something. [ Music ]
Keith Mularski: No, I wanted to ask a question of maybe what you guys are seeing from Proofpoint because you guys see all that email gateway. Are you seeing any kind of lures tailored around development? You know, developer workflows, package publishing or, you know, anything -- GitHub alerts, anything, like, around that? Part two of that question, you know, are developers and maintainers of repositories being targeted differently because, you know, they have the identities, you know, in, you know, and access to GitHub and things like that. I'm just curious, your thoughts on that, if you've seen anything?
Selena Larson: Yeah, so we haven't seen a whole lot, especially that is specifically, like, kind of, targeting developers in terms of direct email. What we have seen is malicious comments or, like, pull requests on GitHub. Then those are set to be email alerts. So then, you know, it's kind of targeting the maintainers of those, that they would click on the malicious URL and then download and install malware or, you know, some sort of information stealer to just do, sort of, an account takeover that way. That is, for sure, an area of exploitation. We've also seen threat actors, sort of, target developers for things like malware delivery, but for things like crypto miners and crypto stealers. There's also, I mean, we mentioned it a few episodes ago, but the, like, North Korean threat actors that are targeting developers with, like, fake jobs, right, that are kind of doing some outreach for some of that, and they do tend to target these, sort of, technical developer-like roles. For these, sort of, overall types of supply chain attacks, we haven't necessarily seen much of that beyond some of the things like, okay, we're going to comment on GitHub or we're going to, you know, send a, like, a pull request or something like that. That then kind of like kick starts the overall attack chain.
Keith Mularski: Fascinating.
Selena Larson: Also, from your visibility, one of the things that, you know, I was -- well, first of all, Wired has a great article about, sort of, TeamPCP and it's called "A Hacker Group is Poisoning Open-Source Code at an Unprecedented Scale." They talk a little bit about how this is a financially motivated threat actor. They, you know, post on the dark web and they're potentially, like, working with some ransomware activities. I'm kind of curious, you know, you mentioned some of your visibility and what the threat actors are posting or what they're -- you know? Do you have any insight into their sort of -- what they're after? You mentioned that they have sort of -- they run "sprints." [ Music ]
Keith Mularski: Yeah, yeah, so, I mean, some of the main points, I think, that we're seeing out there, one is they have a Telegram channel. It looks like one of the interesting things was that they had a leadership change from TeamPCP, just as the as the rollout of these campaigns went, which is probably the same guy. They just changed the nickname, you know, just because, you know, once you get a lot of publicity and you have that nickname, you're kind of a target for law enforcement. It's like, okay, we're going after this guy. A lot of the things were, you know, kind of looking at their communications, really, kind of, affiliate and access broker recruitments, credential sorting and monetization of that, Tor leak and infrastructure, cloud and developer access sales that we're kind of seeing out there, and really, just overall branding around TeamPCP. They're just really kind of trying to build this enterprise around this, and this is their niche that that they're going to use for recruitment, and they're expecting to make a lot of money. The more money that they make then the more imitators that they're going to have, because imitation is the sincerest form of flattery, right? If this criminal organization is making a lot of money, we're going to see a lot of imitators going forward. I think this is just really on the precipice of what we're seeing, like what we talked about. The Wired article was interesting in the fact that they said that TeamPCP carried out, you know, over 20 waves of supply chain attacks and targeted more than 500 distinct pieces of software. That's pretty massive, in my opinion.
Dave Bittner: I'm reminded of something from my previous career when I was working in broadcast television. This affected more than just TV folks, but it did affect me directly. Back in the early 2000s, there was a thing called "the capacitor plague." I don't know if any of you have heard of this, but -- so capacitors are a little electronic component that -- basically, everything electronic has capacitors in them, pretty much. They hold a little charge of electricity, and then they release that charge. There's a type of capacitor called an electrolytic capacitor, and between around 1999 and 2007 or so, the supply chain just got flooded with these defective capacitors. The problem is nobody knew they were defective for a couple of years. Like, capacitors will go bad, but it usually takes decades. So all these go out into the world, and two years later, stuff starts failing. Computers start failing. For me, it was broadcast video decks, like, big, you know, $50,000 VCRs. They just stopped working, and you'd call the repair shops. They'd be like, yeah, give me the serial number and say, oh, yeah, you're part of the capacitor plague. Please send it in, and, you know, for $5,000, we'll replace all the capacitors in it one by one by hand. It was a serious supply chain issue. It was global. It wasn't intentional, although there were rumors of espionage and, you know, those kinds of things, that maybe somebody did it on purpose. Anyway, it just reminds me of this thing, how something, some small little component, right, a little capacitor that's in everything, you can have a bad run of them, and years later, it can be revealed to cause catastrophic failures, and, you know, affect businesses all over the world. By the way, you can go to Wikipedia and look up "Capacitor Plague" if you're interested in all --
Keith Mularski: But please do that after this.
Dave Bittner: Yeah.
Selena Larson: I was going to say, yeah, that's actually really interesting. I have not heard of the capacitor plague.
Dave Bittner: Yeah, well, some of us lived it, so it's not fun. [ Music ]
Keith Mularski: Well, I always love tying back history to, you know, modern things, you know, kind of because, you know, they always say history doesn't necessarily repeat itself, but it surely rhymes. You know, and I think that that's a really good example, just like we were talking about the asbestos and now this, you know, so I think, you know -- but I don't -- you know, we look at this -- that this is an emerging threat and it can be potentially devastating. I think, too, like, what you were just talking about, Selena, I think we're also going to see on the good-guy side, we're going to have automated, you know, looking for software holes, like Mythos and all of that, more of those type of products that are coming out that will mitigate some of that because, you know, with every reaction, there's an equal and opposite reaction. I think we're going to continue to play that cat-and-mouse game. You know, we saw ransomware, you know, 10 years ago blow up, and then we saw the network defenders get better against that. Then we saw it moving more to leaked data, and now we're just, again, seeing the evolution of cybercrime, of, you know, bad guys and good guys going back and forth. I think we're at the beginning of this one, and I think there's still going to be a lot of stories to be told on this, but it is going to be one definitely interesting to follow going forward.
Dave Bittner: I wonder how much of the money being saved by all the use of AI will be offset by the need for greater scrutiny over all the stuff that's being made by AI.
Selena Larson: I don't know if we're saving money using AI, Dave. Have you seen some of the news that's come out recently about how fast organizations are burning through their tokens?
Dave Bittner: Well, that's true, too, yeah.
Keith Mularski: I thought I read something where Uber said that they weren't saving money with AI, and they were just going to, you know, lower their budget on that as well.
Selena Larson: Yeah, it's an interesting -- I mean, that's a separate topic for another podcast, the economics of AI.
Dave Bittner: Next time, on "Only Malware in the Building" --
Selena Larson: Yep. Yep, but so that's, you know, that's pretty interesting. I do think, you know, like, from overall how organizations can defend against this, is I do think that there needs to be a, you know, pause before these automatic updates. Obviously, this is something that isn't going away anytime soon. Making sure that you have, you know, a sort of trust-but-verify method, making sure that, you know, you're checking and validating these updates before pushing them out broadly. One of the main things that these threat actors are going after are, of course, credentials. Ensuring that, you know, there's proper access restrictions, making sure that people are only being able to access and use information that is relevant for their own jobs, and making sure that you have processes in place for approved apps and services. Having an understanding of your dependencies to know that, okay, when there is a new rollout, what is our process for validating it and making sure that it's clean before we're pushing it out to our whole team, so we're not going to have to roll things back to before they were? Then, of course, to -- Keith, to your point, TTX, like running, you know, running tabletops, running some red teaming activities on this type of process as well. [ Music ]
Keith Mularski: Yeah, and just knowing the adversary that you're up against, you know, get that intelligence from the dark web, what they're talking about, what they're targeting. You know, because if you know what they're targeting, then you can shore that up, but if you have no idea what they're doing out there, then you're just running blind. So, again, you've got to be like a football coach or, you know, a coach. You've got to watch the film of your bad guys and see what their tendencies are and where they're going to attack and then shore up your defenses that way.
Selena Larson: Absolutely. You know, yesterday, I heard -- so completely unrelated, but kind of. I am a humongous basketball fan, as anybody who knows me knows, and the Knicks are going to the finals for the first time since 1999. I heard yesterday that before this Game 4, Mike Brown, who's the head coach of the Knicks, showed his team video and footage of last year when they lost to the Indiana Pacers and just how depressed they looked and how upset they were on the day of the loss. The team members were literally looking at video of them just being smoked and feeling really bad. I feel like that might be a good method for a CISO. Just record all of your employees, record the CEO, record your legal team, record your marketers, on a day that the worst happens. Then just play that back for them when you're trying to argue for more budget for a security team or more headcount to be able to validate your software before CI/CD deployment.
Keith Mularski: I love that. Go in front of the, you know, the audit committee, you know, and the board and go, "Hey, we're just going to do a little bit review from last year. If you remember this, well, I need this money."
Dave Bittner: I remember, yeah.
Selena Larson: I mean, exactly. Look, and hey, it worked. The Knicks won. You know, they swept the Cavs and they're going to the finals. I'm just saying, I feel like it could be a useful method.
Dave Bittner: When all else fails, go negative.
Selena Larson: [Laughter] Exactly. [ Music ] We will be right back after this quick break. [ Music ]
Dave Bittner: All right. You want to wrap us up?
Selena Larson: Awesome. Well, Dave, Keith, this has been a pleasure as always. This is something that's super interesting and has been on the top of my mind for quite some time, and I hope our listeners learned something valuable and had some good takeaways from today's show. Thank you so much for joining us, and I will leave you to go snack on your favorite dips. That's "Only Malware in the Building," brought to you by N2K CyberWire. In a digital world where malware lurks in the shadows, we bring you the stories and strategies to stay one step ahead of the game. As your trusted digital sleuths, we're unraveling the mysteries of cybersecurity, always keeping the bad guys one step behind. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you ahead in the ever-evolving world of cybersecurity. If you like the show, please share a rating and review in your favorite podcast app. This episode was produced by Liz Stokes. Mixing and Sound Design by Tré Hester, with original music by Elliot Peltzman. Our Executive Producer is Jennifer Eiben. Peter Kilpe is our Publisher. [ Music ]



