

When fake fixes hide real attacks.
14 snips Apr 21, 2025
Yoni Shohet, Co-founder and CEO of Valence Security, discusses critical cybersecurity threats posed by Chinese open source AI, particularly for financial institutions. He highlights the alarming use of ClickFix in state-sponsored cyber espionage, alongside Japan's urgent warnings about unauthorized trades. The conversation dives into the vulnerabilities of new Microsoft tools and the complexities of navigating AI risks in organizations. Shohet emphasizes the need for robust security measures as the landscape of cyber threats continues to evolve.
AI Snips
Chapters
Transcript
Episode notes
ClickFix Simplifies Espionage
- Adversary nations like North Korea, Iran, and Russia use ClickFix to trick victims into activating malware.
- This streamlines cyberespionage by disguising malicious commands as problem fixes.
Japan's Huge Unauthorized Trades
- Japanese hackers made unauthorized trades totaling over $665 million by stealing brokerage credentials.
- They sold Japanese stocks to buy Chinese ones, leaving victims with manipulated portfolios.
Critical Erlang OTP Vulnerability
- The Erlang OTP SSH vulnerability allows unauthenticated remote code execution and is now widely exploitable.
- Many telecom and database systems remain unpatched, increasing the risk of mass exploitation.