

Talkin' Bout [Infosec] News
Black Hills Information Security
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET
Join us live on YouTube, Monday's at 4:30PM ET
Episodes
Mentioned books

Jan 20, 2026 • 1h 3min
Chinese firms drop US and Israeli cybersecurity software - 2026-01-19
Join Fawn, a malware and C2-focused practitioner, as she dives into the implications of Chinese firms dropping U.S. and Israeli cybersecurity software. The discussion explores how geopolitics shapes procurement choices and the messiness of supply-chain dependencies. Fawn also shares insights on the risks of AI integrations, balancing security with business needs, and the growing challenges in incident response. Expect a lively mix of technical expertise and candid commentary on the evolving landscape of cybersecurity.

Jan 14, 2026 • 1h 1min
BreachForums Doomsday - 2026-01-12
A major breach of a criminal forum reveals how even cybercriminals can fall victim to poor OPSEC. Discussions include the implications of leaked IPs for law enforcement and the reasons these underground markets keep collapsing. The hosts dive into the legal nuances of blockchain tracing and the seizure of mixer funds, highlighting the ongoing tug-of-war between privacy and crime. They also emphasize the importance of practical defense measures, like using unique passwords and monitoring for credential stuffing, ensuring listeners are well-prepared against evolving threats.

Jan 9, 2026 • 1h 9min
US Cyberattacks on Venezuela - 2026-01-05
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chat🔗 Register for FREE webcasts, summits, and workshops - https://poweredbybhis.comIn this episode, we break down the growing debate around U.S. cyber operations against Venezuela—and what it means for modern cyber warfare, critical infrastructure security, and geopolitics. The conversation explores how nation-state attacks can target a country’s power grid, the challenges of attributing cyberattacks, and why industrial control systems (ICS/SCADA) remain a high-impact battleground. We also discuss the strategic value (and risks) of disrupting energy infrastructure, how these campaigns compare to other real-world incidents, and what defenders can learn to better protect utilities and national systems.Chapters(00:00) - PreShow Banter™ — Undisclosed Closets
(09:07) - US Cyberattacks on Venezuela - 2026-01-05
(10:16) - Story # 1:Trump suggests US used cyberattacks to turn off lights in Venezuela during strikes
(11:14) - Story # 1b: There Were BGP Anomalies During The Venezuela Blackout
(21:06) - Story # 1c: Pizza index of war: Late-night traffic near Pentagon surges again as US strikes Venezuela
(32:40) - Story # 2: Finland seizes ship suspected of damaging subsea cable in Baltic Sea
(35:11) - Story # 3: US cybersecurity experts plead guilty to BlackCat ransomware attacks
(35:46) - Story # 4: MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide
(39:06) - Story # 5: Hackers claim to hack Resecurity, firm says it was a honeypot
(42:06) - Story # 6: NordVPN denies breach claims, says attackers have "dummy data"
(42:35) - Story # 7: Hackers say they have stolen 40 million Condé Nast Records - here's how to stay safe
(43:43) - Story # 8: Hacker Dressed As Pink Power Ranger Dismantles Racist Websites Live on Stage
(47:13) - Story # 9: NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
(52:18) - Story # 10: Manufacturer issues remote kill command to disable smart vacuum after engineer blocks it from collecting data — user revives it with custom hardware and Python scripts to run offline
(55:15) - Story # 11: Ben Jordan Exposes Severe Security Vulnerabilities in Flock Surveillance Cameras
(57:26) - Story # 11b: We Tracked Ourselves with Exposed Flock Cameras
LinksStory # 1:Trump suggests US used cyberattacks to turn off lights in Venezuela during strikesStory # 1b: There Were BGP Anomalies During The Venezuela BlackoutStory # 1c: Pizza index of war: Late-night traffic near Pentagon surges again as US strikes VenezuelaStory # 2: Finland seizes ship suspected of damaging subsea cable in Baltic SeaStory # 3: US cybersecurity experts plead guilty to BlackCat ransomware attacksStory # 4: MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation WorldwideStory # 5: Hackers claim to hack Resecurity, firm says it was a honeypotStory # 6: NordVPN denies breach claims, says attackers have “dummy data”Story # 7: Hackers say they have stolen 40 million Condé Nast Records - here’s how to stay safeStory # 8: Hacker Dressed As Pink Power Ranger Dismantles Racist Websites Live on StageStory # 9: NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devicesStory # 10: Manufacturer issues remote kill command to disable smart vacuum after engineer blocks it from collecting data — user revives it with custom hardware and Python scripts to run offlineStory # 11: Ben Jordan Exposes Severe Security Vulnerabilities in Flock Surveillance CamerasStory # 11b: We Tracked Ourselves with Exposed Flock CamerasBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com

Dec 18, 2025 • 1h 2min
Hot Take Predictions for Next Year – 2025-12-15
Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chat🔗 Register for FREE webcasts, summits, and workshops - https://poweredbybhis.comChapters(00:00) - PreShow Banter™ — testing testing
(00:11) - Hot Take Predictions for Next Year – 2025-12-15
(02:10) - Story # 1: Russian kids revolt as Kremlin bans Roblox, other popular apps
(10:21) - Story # 2: Google's killing off its dark web report because users didn't know what to do with it
(20:05) - Story # 3: Coupang data breach traced to ex-employee who retained system access
(31:13) - Story # 4: Roomba maker iRobot bought by Chinese supplier after filing for bankruptcy
(34:18) - Story # 5: February report from researcher found Chinese KVM had an unclearly documented microphone and communicated with China-based servers, but many of the security issues are now addressed [Updated]
(36:48) - Story # 6: When adversaries bring their own virtual machine for persistence
(41:57) - Story # 7: Oh no! Hackers snuck malware inside uber-popular Windows app Notepad++
(44:20) - Hot Take Predictions for 2026
LinksStory # 1: Russian kids revolt as Kremlin bans Roblox, other popular appsStory # 2: Google’s killing off its dark web report because users didn’t know what to do with itStory # 3: Coupang data breach traced to ex-employee who retained system accessStory # 4: Roomba maker iRobot bought by Chinese supplier after filing for bankruptcyStory # 5: February report from researcher found Chinese KVM had an unclearly documented microphone and communicated with China-based servers, but many of the security issues are now addressed [Updated]Story # 6: When adversaries bring their own virtual machine for persistenceStory # 7: Oh no! Hackers snuck malware inside uber-popular Windows app Notepad++The team looks ahead to 2026 and shares practical, sometimes blunt predictions about where cybersecurity is heading. They discuss how AI will continue reshaping both offense and defense, with attackers using automation at scale while defenders struggle to operationalize AI beyond marketing hype. The conversation highlights growing risk from identity abuse, cloud misconfigurations, and insecure SaaS sprawl, noting that many breaches will still come down to basic failures rather than advanced exploits. They also predict continued burnout in security teams, more consolidation among security vendors, and increasing pressure to prove real ROI from security tools. On the positive side, the hosts see improved detection engineering, better security education, and more community-driven knowledge sharing. Overall, the message is clear: fundamentals still matter, hype won’t save you, and organizations that focus on people, process, and visibility will be better positioned for 2026.Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com

Dec 11, 2025 • 1h 4min
A Live Stream From inside Lazarus Group – 2025-12-08
Dive into a lively discussion filled with cybersecurity humor and chaos as the team tackles the React2Shell vulnerability and its implications. They uncover Lazarus Group's sneaky IT recruiting tactics, complete with webcam leaks. The hosts critique the hiring practices that led to contractors wiping government databases. Apple’s defiance against pre-installing a government app in India sparks a debate on privacy, and Russia's blocking of FaceTime raises concerns about state surveillance. Plus, the shocking truth about a smart toilet camera marketed as secure!

Dec 4, 2025 • 1h 3min
Lawmakers Want to Ban VPNs - 2025-12-01
Lawmakers are pushing to ban VPNs without understanding the technical challenges involved. A critical vulnerability in 7-Zip has surfaced, urging users to update immediately. There's a discussion on the innovative Slop Evader tool filtering out AI-generated content. Reports reveal China's growing espionage activities in Europe, targeting political staffers. Additionally, shocking revelations show that Meta profits significantly from fraudulent ads while applying lax policies on trafficking. Tune in for insights and warnings in the digital landscape!

Nov 26, 2025 • 1h 5min
Shai-Hulud malware leaks secrets on GitHub – 2025-11-24
Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.comChapters(00:00) - PreShow Banter™ — Stressed about lithium batteries
(04:59) - Shai-Hulud malware leaks secrets on GitHub – BHIS - Talkin' Bout [infosec] News 2025-11-24
(05:57) - Story # 1: Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
(11:18) - Story # 2: CrowdStrike catches insider feeding information to hackers
(15:50) - Story # 3: Fidelity sues Broadcom over access to key software to avoid outages
(22:17) - Story # 4: NetApp sues former CTO for alleged data breach
(26:48) - Story # 5: CrowdStrike Research: Security Flaws in DeepSeek-Generated Code Linked to Political Triggers
(36:05) - Story # 6: A major Cloudflare outage took down large parts of the internet - X, ChatGPT and more were affected, but all recovered now
(37:11) - Story # 6b: Cloudflare outage on November 18, 2025
(41:43) - Story # 7: Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt
(46:34) - Story # 8: This Hacker Conference Installed a Literal Antivirus Monitoring System
(51:10) - Story # 9: Microsoft to integrate Sysmon directly into Windows 11, Server 2025
(56:40) - Story # 10: Crypto and Carcasses: Undercover Sting Recovers $700K in Bitcoin Miners, Foils $75K Frozen Turkey Heist
News LinksStory # 1: Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHubStory # 2: CrowdStrike catches insider feeding information to hackersStory # 3: Fidelity sues Broadcom over access to key software to avoid outagesStory # 4: NetApp sues former CTO for alleged data breachStory # 5: CrowdStrike Research: Security Flaws in DeepSeek-Generated Code Linked to Political TriggersStory # 6: A major Cloudflare outage took down large parts of the internet - X, ChatGPT and more were affected, but all recovered nowStory # 6b: Cloudflare outage on November 18, 2025Story # 7: Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike AttemptStory # 8: This Hacker Conference Installed a Literal Antivirus Monitoring SystemStory # 9: Microsoft to integrate Sysmon directly into Windows 11, Server 2025Story # 10: Crypto and Carcasses: Undercover Sting Recovers $700K in Bitcoin Miners, Foils $75K Frozen Turkey HeistBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/

Nov 21, 2025 • 1h 17min
A.I. Transcription Startup Was Just A Guy Taking Notes- 2025-11-17
This discussion features two insightful panel contributors: a frequent expert on AI and security implications, and a skeptical voice critiquing AI trends with humor. They explore surprising developments like the rehiring of former employees as AI struggles to meet expectations. The conversation dives into the revelation that an AI transcription startup was just a guy taking notes, illustrating the gap between hype and reality. They also tackle identity scams and the evolving threat landscape, making for a riveting examination of tech and security.

Nov 13, 2025 • 59min
Louvre’s Video Security Password Was ‘Louvre’ 2025-11-10
Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Chapters00:00 - PreShow Banter™ — Humans are Done03:04 - Louvre’s video security password was ‘Louvre’ – BHIS - Talkin’ Bout [infosec] News 2025-11-1005:11 - Story # 1: I Tried the Robot That’s Coming to Live With You. It’s Still Part Human.15:14 - Story # 2: How to trade your $214,000 cybersecurity job for a jail cell25:14 - Story # 3: The Louvre’s video security password was reportedly ‘Louvre’29:04 - Story # 4: Dangerous runC flaws could allow hackers to escape Docker containers32:58 - Story # 5: List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities40:00 - Story # 5b: GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools56:37 - BHIS Webcast – X-Typhoon - Not your Father’s China with John Strand
(00:00) - PreShow Banter™ — Humans are Done
(03:03) - Louvre’s video security password was ‘Louvre’ – BHIS - Talkin' Bout [infosec] News 2025-11-10
(05:10) - Story # 1: I Tried the Robot That’s Coming to Live With You. It’s Still Part Human.
(15:14) - Story # 2: How to trade your $214,000 cybersecurity job for a jail cell
(25:13) - Story # 3: The Louvre’s video security password was reportedly ‘Louvre’
(29:03) - Story # 4: Dangerous runC flaws could allow hackers to escape Docker containers
(32:58) - Story # 5: List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities
(40:00) - Story # 5b: GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
(56:37) - BHIS Webcast – X-Typhoon - Not your Father's China with John Strand

Nov 6, 2025 • 1h 4min
Ransomware Victims Stop Paying Hackers – 2025-11-03
Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00 - PreShow Banter™ — Musical Views of the Universe04:05 - – BHIS - Talkin’ Bout [infosec] News 2025-11-0304:39 - Story # 1: Ransomware profits drop as victims stop paying hackers06:22 - Chart since 201916:06 - Story # 2: More than a million people every week show suicidal intent when chatting with ChatGPT, OpenAI estimates33:02 - Story # 3: 10M people watched a YouTuber shim a lock; the lock company sued him. Bad idea.41:18 - Story # 4: ‘Dangerous’ YouTube videos struck down for bypassing Windows 11 account setup [Update: Restored]47:13 - Story # 5: Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says51:08 - Story # 6: Microsoft: DNS outage impacts Azure and Microsoft 365 services54:33 - Story # 7: EY Data Leak – Massive 4TB SQL Server Backup Exposed Publicly on Microsoft Azure55:22 - Stordy # 8: Black Hat Europe 2025 Arsenal: 8 AI Security Tools Transforming Cybersecurity
(00:00) - PreShow Banter™ — Musical Views of the Universe
(04:04) - Ransomware Victims Stop Paying Hackers – BHIS - Talkin' Bout [infosec] News 2025-11-03
(04:38) - Story # 1: Ransomware profits drop as victims stop paying hackers
(06:22) - Chart since 2019 (thumbnail)
(16:06) - Story # 2: More than a million people every week show suicidal intent when chatting with ChatGPT, OpenAI estimates
(33:02) - Story # 3: 10M people watched a YouTuber shim a lock; the lock company sued him. Bad idea.
(41:18) - Story # 4: ‘Dangerous’ YouTube videos struck down for bypassing Windows 11 account setup [Update: Restored]
(47:12) - Story # 5: Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says
(51:07) - Story # 6: Microsoft: DNS outage impacts Azure and Microsoft 365 services
(54:33) - Story # 7: EY Data Leak – Massive 4TB SQL Server Backup Exposed Publicly on Microsoft Azure
(55:22) - Story # 8: Black Hat Europe 2025 Arsenal: 8 AI Security Tools Transforming Cybersecurity


