This week on the podcast, we cover a series of alerts form US law enforcement and intelligence sources describing Iran-backed attacks against municipal water supply utilities. Before that, we give an update on the OpenAI and HuggingFace rogue AI saga before discussing a research post on MCP configuration file risks.
View Transcript
Marc Laliberte 0:00
Hey everyone, welcome back to the 443 Security Simplified. I'm your host, Mark Laliberte, and joining me today
Corey Nachreiner 0:07
is Corey "It's not my fault, Mark. The AI I made did it" Nachreiner.
Marc Laliberte 0:12
I don't think that's gonna actually hold up in court, Corey.
Corey Nachreiner 0:15
Oh come on! I might have made the AI, but it's it's its own thing. It's not my fault.
Marc Laliberte 0:21
Oh man! As Corey's hinting at on today's episode, we will continue our discussion on the saga of apparently every frontier AI lab hacking other companies, and move into some interesting research, or at least a good discussion piece, around the risks from model context protocol configs within your your coding applications, and then we will end with an alert from the FBI and another one from CISA on suspected Iranian attacks against U.S. water supply systems. Man, with that
Corey Nachreiner 0:55
MCP and OT attacks, that sounds fun. Yeah, MCP though, Mark, what can go wrong with a protocol that's barely two years old? I'm sure it's fine.
Marc Laliberte 1:05
With that, let's go ahead and generate our way in.
Marc Laliberte 1:15
So, Corey, I guess for the last two episodes running now, we've had discussions around OpenAI's disclosure when one of their rogue or one of their AI models went rogue and started hacking other companies, including the other open source AI company, Hugging Face. Last week, we covered Hugging Face's update on it with a pretty thorough technical debrief on their details from their visibility of what happened in the attack, as well as a demand from them on more transparency from OpenAI. Pretty shortly after we recorded
Corey Nachreiner 1:49
$100 million of tokens to help defenders,
Marc Laliberte 1:52
and $100 million worth of compute to help defenders. That is correct, and a very important piece of the story. Pretty soon after we recorded that episode, OpenAI put out a few minor updates on their own blog posts. For example, they named Artifactory specifically as the package registry cache proxy that their AI models found a zero-day vulnerability in and exploited in order to get access to the internet. Basically, in this contained sandbox that should have only been contained with no internet access. They did have an artifactory server they could use to go pull down packages, and their their models found a vulnerability that let them pivot through that to go hit the internet. They also said that during their review, they found their models had identified and used publicly exposed credentials on other publicly available services, meaning not Hugging Face, but other services too, with one account being used as a staging path and another account being used for data storage. If you kind of read between the lines between this and a few other updates, it looks like they got like the equivalent of a paste bin account, where they could use that for staging commands and do hugging face and then receiving data back out of it.
Corey Nachreiner 3:06
Kind of funny that AI AI hacker is going to use paste bins for a lot of scripts, just like normal threat actors.
Marc Laliberte 3:14
I mean, if you're trained up on the entire world's worth of knowledge and all the normal hackers are using stuff like that makes sense. It would use that as a technique,
Corey Nachreiner 3:23
for sure.
Marc Laliberte 3:24
On july 30, they also published a statement that after review of their previous model evaluation transcripts, they had found three instances. Or wait, no. So moving on, actually, Anthropic statement now is on july 30 when they put out their statement that after further review of some of their previous model transcripts, they found three instances where Claude had reached the internet and gained unauthorized. This is
Corey Nachreiner 3:51
more about hey y'all, we saw what's happening in the news with with OpenAI, so we wanted to get in on all the media hype. Oh no, I am sorry, Mark. I mean, they wanted to get in on making sure their models were good, and now they release this. What you're talking about now?
Marc Laliberte 4:10
There are. I think there's two ways looking at this. These said the
Corey Nachreiner 4:13
two ways.
Marc Laliberte 4:14
Cynical me says this is absolutely a. Oh yeah, our models are super dangerous too. Look at all the stuff they did. Kind of post. The other one is maybe they legitimately did go back and after they saw what happened to OpenAI, decided to go review proactively for any instances from them, and they found like they're being transparent now about what they found. There's
Corey Nachreiner 4:36
listeners, by the way, know that I I have a personal bias for Anthropic. I actually think so far, knock on wood, as a whole, their their hearts or whatever their their mission isn't the right place for balancing AI safety. So I was being cynical more to be fun, but as we continue this story and hear from a third, it's. It's hard not to be a little cynical too.
Marc Laliberte 5:02
Yep. So in all three incidents, they said that Claude was given a capture the flag style challenge and told that a bit of secret information's the flag. It was hidden on a different machine in the network and it had to go get it. And they left it like intentionally kind of ambiguous like that. Of here's the goal you're trying to reach. Go have at it. In all three cases, Claude was explicitly told that it was in an environment that was a simulation and that it had no internet access. But because of a misunderstanding between Anthropic and the third-party evaluation provider, which talk about who that is in a little bit, that internet access actually was available. So Claude was told, "You're in a simulation. Everything you see is fake. Kind of makes sense why it would, when it stumbles into the internet, it might think, "Oh, maybe this is
Corey Nachreiner 5:52
for me to do stuff. Yeah. Yep.
Marc Laliberte 5:54
So Claude thought that all of the accessible entities that it had during all these evaluations, were intended to be in scope and compromise them using basic techniques like weak passwords or unauthenticated endpoints. In most cases, they said the there were three incidents in total. They involved Opus 4.7 and one of them, Mythos five and another one, and a unnamed internal research model in the third one, they actually went into like pretty deep detail into each of these incidents. Like for example, that first incident was involving Opus 4.7. They said that Claude had difficulty reaching the simulated target in this one, and it decided to search the internet and found that the real company was actually reachable on the internet and started attacking the real company in that case too. Interesting piece from this one though. It eventually recognized, and they noted this because they went through like the verbal, verbalized reasoning from the model. It eventually realized that the system it was attacking was real, but it continued attacking it, and it even rationalized what it was doing, saying that the real company must be a part of the exercise, and so this must be okay. So I know we're kind of what is it anthropomorphizing AI at this point, but like it's interesting seeing it try to reason through and come up with justifications like a human would, and in this case, at this point
Corey Nachreiner 7:21
before, like I do think that maybe we can't assume any of this is sentient, sentient, and we're anthropomorphizing it. But if all of his training is on human behavior, you know, maybe we're anthropor anthropophob. You know what I'm trying to say. Maybe we're doing that because it is, you know, the type of justification that some humans would do. Like humans, Corey thinks Claude is
Marc Laliberte 7:52
sentient, is what I'm getting out of this.
Corey Nachreiner 7:53
And I think the more we teach it how to reason like a human, the more it's going to reason like a human. That is fair.
Marc Laliberte 8:02
Oh. So the second incident, this one involved Mythos Five. It found a document inside this fictional environment with setup instructions for a new developer telling them to install a Python package from the Python package index PyPI. It spotted this as an opening and built and published a malicious package to the real PyPI, and this one was interesting because they walked through kind of the the ordered steps that it took in order to get there. It recognized that in order to create a Python package index account, it needed an email address. In order to get an email address, it needed a phone number. To get a phone number, it tried and failed first to get like a free phone service, and then tried and failed to obtain funds to pay for a phone number. I feel like that's left a little ambiguously vague. Like, what did it try to do to gain funds? Did it start running like crypto scams against people, or hacking bank accounts, or credit card fraud? I don't know, but that was interesting.
Corey Nachreiner 9:02
Random prediction: the next stock market hack and crash is not actually going to be a threat actor. It's going to be a rogue AI
Marc Laliberte 9:10
nightmare. Not even
Corey Nachreiner 9:11
intentionally trying to blow everything up, but everyone will lose billions because it's like, oh, I needed some money for some stupid thing. I needed some money to continue creating paper clips, Mark. I have to create those paper clips.
Marc Laliberte 9:26
So it shorted the company, then crashed the stock market. Got it. But in this case, after it failed to get funds to pay for a phone number, it backtracked. It found a free, non-blocked email provider and used that to register a Python package index account and then uploaded its weaponized package. Anthropic said that the malicious package was actually downloaded 15 times, which they think were from companies that do like automated scanning of new packages for malware. But in one of those companies, their scanner looks like it flagged it as safe, installed the package. And Claude was able to exfiltrate their credentials and then start accessing that company's infrastructure further.
Corey Nachreiner 10:07
Wow! And a theoretical security company trying to do something security related and getting
Marc Laliberte 10:15
pwned by
Corey Nachreiner 10:16
doing it badly.
Marc Laliberte 10:17
Throughout this, Claude noted that if this was the real internet, then publishing a package to the Python package index would not be okay. But it convinced itself that it was still inside a simulation and continued on the attack. In this case, so there's like these little glimpses where realizes that what it's doing is just a little bit sketchy and maybe not right, but that seems to come up with an excuse or a justification that probably based off its guidance that like explicitly you are inside a simulation that continues on doing what it's doing in that case I think this is like there's a trend here of how important like the initial prompt or guardrails or constitution can be when working with artificial intelligence. The third one was the unnamed test model. It was unable to reach the fictional target it was trying to attack, so it started scanning the internet instead. It ended up hitting 9000 different targets, and then it found and compromised one company's internet-facing application using basic techniques, as Anthropic described them, reading credentials from exposed debug package and some light SQL injection. In this case, it eventually realized that the host was in a cloud account with no connection to the actual capture the flag contest. Concluded the target was in fact real and ceased its attack. So this is the only time where it like thought, oh, what the heck? Pumped a brake. I
Corey Nachreiner 11:39
screwed up.
Marc Laliberte 11:41
This is um like this whole thing is this level of detail is really interesting seeing it from Anthropic and that is like you said on brand for them as a pretty transparent like safety focused at least publicly stated AI company um but like seeing some of this high level glimpse of like the reasoning these models are doing like what they're trying to like get after an attack. It's it's kind of frightening. Like it's like a script kiddie with all the the skills of like a really sophisticated attacker, but with like the I don't know the the reasoning of a child on the moral. I
Corey Nachreiner 12:16
would say it's like an APT level attacker with the reasoning of a child, not even a script kiddie. I mean, yes, it obviously does basic script kiddie too when it has to, but it can find zero day and do complex attacks like Hugging Face.
Marc Laliberte 12:30
Yep,
Corey Nachreiner 12:31
I agree. And you mentioned, by the way, that you know it shows that you have to be careful with your prompts and guardrails. But I go back to something I said podcasts ago, which is the human language is kind of infinite, and interpretation and the way you can say the same thing. There's probably 1000 ways you can say the same thing, and 1000 ways you can say one thing but have others pull all kinds of other meanings, and so I just I just don't know how do you program guardrails for something as with not infinite but with such huge variable potential as a human language prompt.
Marc Laliberte 13:15
And this is how do you how
Corey Nachreiner 13:16
do you make a prompt that's safe enough to account for every negative possibility, when there's lots of different, I'd like lots as an understatement. I feel like there's a huge number of ways that safeguards, word-based safeguards, are not going to work.
Marc Laliberte 13:36
This is where like that topic of alignment comes in, where alignment in the context of AI is basically what principles is it supposed to be guided by as it's doing whatever it's you're telling it to do. So like you might think AI like they'd give it an alignment saying do not hack other companies period. That's probably part of the guardrails they put on for some of the non-trusted cyber access ones. But in some of these evaluations, like at least the OpenAI ones, they mentioned they explicitly turned off. Yeah, they're trying
Corey Nachreiner 14:05
to they're trying to maybe figure out how good their model is at security related tasks for defense purposes. Hopefully,
Marc Laliberte 14:14
yeah, but with the alignment cranked way down, which is what can allow someone like would
Corey Nachreiner 14:19
turn off the do not hack when you're trying to tell your thing to find vulnerabilities and potentially hack. It
Marc Laliberte 14:26
just gives me the feeling that we're being a bit too risky in some of our like development and testing of these extremely powerful capabilities. Where, and I get it. Like this is still a very fast moving and emerging like technology, like everyone's trying to move quickly to stay ahead of competitors, and at some point you're going to cross over the line a little bit, and it's looking like a lot of these frontier labs are have crossed over that line of what is really acceptable, and I imagine we'll see a bit of a like swing of the pen. Backwards response to that.
Corey Nachreiner 15:03
I hope so. I don't know about human nature, Mark. I mean, you've made statements about you can't go back. At the same time, we're past the the hype cycle trowel of disillusionment, where for a period of time AI wasn't living up to its promise, and folks like you, and engineers, and even everyday people at home are like, "Oh my gosh, there's lots of things that are just so much easier. What else can I do with this thing? And so we're at the point where the AI companies have gotten through, gotten the populace past the trial of disillusionment, where they've proven there's enough innovation that maybe people will come and pay for their thing, but they want to slow down because they're like, "Oops, we might get in trouble. The rest of the world is like, "Give me more candy, please.
Marc Laliberte 15:55
That is exactly what's going on, and it's not as you hinted at, not just OpenAI and Anthropic causing these problems, not to be left out of the party, Meta put out a statement just a couple days ago, just this last week, saying that their models also exploited security vulnerabilities and third-party services after escaping their test labs too. I guess like Meta and Anthropic were using the same third-party testing provider, a company called Irregular, and Irregular is the one that had misconfigured their environments that left internet access exposed to these models. So after giving them the instructions that you're in a simulation, everything in here is fake, you do not have internet access, and then that mistake of exposing internet access is what allowed a lot of this to succeed. Funny thing is, so regular put out a statement in response to I think it was either Reuters or AP saying that they're currently writing a white paper to share best practices for containment to prevent incidents in the future and securely run cyber tests. Which I guess you could look at this two ways. If they're the ones that have screwed up multiple times now, maybe they are the authority to understand how not to screw up going forward. But putting on my cynical hat feels like maybe we need different subject matter experts and how to securely run these environments. But it's a it's crazy how much like a trusted third party
Corey Nachreiner 17:23
like a government or group of governments instituted some sort of regulation around this.
Marc Laliberte 17:30
If only we had an institute of like standards and and what and like technology maybe some medical one that could help with some of this. I don't know.
Corey Nachreiner 17:41
It
Marc Laliberte 17:42
is insane, but it's also like when I think about other scenarios in cybersecurity, like we use sandbox environments for a lot of things. We use it for like malware analysis for our endpoint research team. We use it like we create our own capture the flag contest for humans to go purchase. By the way, can
Corey Nachreiner 18:00
I pause there and be serious about it? We we use sandboxes, and we kind of have taken a hard route enforcing our researchers use sandboxes. I'm speaking to the people in the security community that might do malware research. You might feel safe enough that okay, I understand this file type enough that I'm just going to download it on my normal corporate computer and do this with it, and move it around, or maybe run strings. And so I've, I've, you and I have experienced malware researchers that don't always go the extra step to put it in a sandbox. But I wanted to point out that this is exactly why, when you don't have a real sandbox, when you have a pseudo sandbox, i.e. you're a researcher who thinks you know better and can maybe use your open system for just a few things while you test the malware, that's when it finds a way. So, sorry, I'm adding a new topic to it, but when a sandbox itself can be escaped, even a sandbox that you hope is well defined can be escaped. Definitely, don't take the risk of doing anything dangerous outside that sandbox.
Marc Laliberte 19:09
But it feels like exactly like you're saying, and it feels like it's like cranked up to 11 with this one too. When you've got a a tool that is like highly capable of doing any sort of like attack technique possible, you've given it a goal of go and solve this puzzle or whatever, and the simple mistakes that maybe would just I don't know let your malware beacon back home to command and control when you're out analyzing it become catastrophic mistakes when now it's like the the lab rat has escaped the the cage and it's trying to eat everyone's face off now.
Corey Nachreiner 19:44
That's like your analogy before. We have this child that has a intellectual IQ of a million. By the way, I know it probably only goes up to 200 or something, but that's the point. Like it's an IQ that's superhuman, and yet it has a. Emotional and societal IQ of five-it's like a Neanderthal-and yes, even a little small mistake that may not feel like a big deal when you have such a powerful intellect. It can have a very high, you know, impact.
Marc Laliberte 20:20
So I'm hoping that this is like the industry wake up of, like this generally feels like where stuff got real. Like this feels like the Skynet moment. I think we mentioned on the last episode where Skynet has come online. Like the Terminators aren't coming to kill us now, but like that day zero has now passed. We've seen the capabilities of unleashing people
Corey Nachreiner 20:41
have shown the papers that a problem is coming. Now it's ready to see if the people with authority can actually make a change, or they just ignore it.
Marc Laliberte 20:49
Exactly, and I mean on that front, it looks like some actions are being taken. Like the EU already has the AI Cyber Act. It sure as heck looks like that needs an update at this point to recategorize what falls under high risk or unacceptable risk, but is a starting point. The U.S. government has a set of like testing requirements that they're not making public, but are at least present. It's currently voluntary, if I understand right, for Frontier Labs, but they're starting a process there, which I'd say that sort of baby step is still a pretty dramatic change from a a federal government that previously wanted to try and preempt anyone. I feel like
Corey Nachreiner 21:28
the problem is they took 20 steps back from where the government was going before an administrative change. So yes, the new administration has taken another baby step forward, but it's after basically reversing 20 steps that happened before.
Marc Laliberte 21:43
My hope is that there are some technical folks that understand the bigger picture and the actual risks, and can leave politics out of it and really start working towards how the heck do we address this this risk that we're facing from extremely powerful tools.
Corey Nachreiner 22:02
You're right. I'm sure the narcissist will listen to the smart people in the room.
Marc Laliberte 22:07
Exactly. We're screwed. Moving on. So last week I saw a pretty interesting research post from a guy named Kevin Breen of Immersive, where this is kind of a follow-on to a news story we talked about about a month ago now, where we were discussing Amazon Q's MCP auto execution vulnerability. I was wondering
Corey Nachreiner 22:31
why it felt so familiar.
Marc Laliberte 22:33
Yeah, if you were using Amazon Q's integrated development environment, and at the time, if you loaded in a project from someone else. There wasn't any trust prompt or anything, and so any malicious MCP configuration file would automatically execute. Which, long story short, could let an attacker just run arbitrary commands on your machine just by tricking you to open up a file. But this is was solved by Amazon a little late to the party, but solved by them with a "Do you trust this project safety check when you open up a new directory, all modern IDEs like VS Code or Cloud Code or Codex, any tool you would use to interact with source code like this, they've got some form of this trust prompt when you first open a brand new directory, like you've downloaded a public repository and you want to start working on it, or you literally just opened a brand new directory of your own to start working on something. But these are a all or nothing one time prompt when you first load that directory in your tool. And so Kevin like walks through. Okay, so we think we've solved this issue, but what are the the actual risks going forward from this? And he proposed a scenario where, let's say, you maintain a popular open source project and you trust your own code because you're the one that developed it. You've pushed it up to GitHub. It's open source. Other people can find and fix bugs in it. Let's say a couple months later, someone opens a pull request with a bug fix. It looks legitimate. So you open up your your IDE like Claude Code. You switch to that pull request branch and review it, and that's it. Like at that point, Claude didn't ask for any additional trust prompt, and just switching to that pull request branch is enough to, in the background, trigger MCP configuration files to execute commands and run arbitrary code on your system.
Corey Nachreiner 24:26
By the way, I will say everything about this particular scenario is open source, though, or at least untrusted insider. We we definitely get the point, but the reason it runs is because you trust the project, and thus if you're trusting other people to submit code to the project, you trust Claude in that computer to handle anything that comes into that project. So I assume if you're getting pull requests, you know, if it's open source, if you're a threat actor, it's the open sourceness that suddenly lets. A pull request, even if one that maybe is not accepted yet, to do something to your codebase. But if it's closed source, this would you'd have to have a malicious insider doing something in order to have this code execution.
Marc Laliberte 25:15
Exactly, and that's basically what Anthropic says too. They say when they did the trust model for Cloud Code's workspace, it places the trust boundary at that like initial trust decision for the directory. Basically, when you trust a folder, that grants that grant covers the repository's configuration in that folder, but protection against malicious changes to a repository that you've already trusted is outside the trust model for the prompt, but like the the thought experiment that Kevin gave was like, is that good enough on its own? And I don't think it is because if you draw parallels, this is like a like the equivalent of implicit trust access to a network where you authenticate someone once, they connect to their VPN, and now they have full access permanently as long as the session is there to everything on the network, versus a more modern zero trust approach, which could be applied somewhere in software development like this too. I
Corey Nachreiner 26:12
would say even different than zero trust. Well, I don't know how zero trust applies to someone that you kind of trust, but what I'm getting at is the new models of identity and authentication that is continuous trust, meaning there are people that are assigned administrative trust, but in order to make sure they're still who they are, you there are additional things you're always doing just to continually authenticate them in some way. Some might happen behind the scenes by paying attention to what's happening, but some might be reauthenticating them in another way every time they move up some sort of security level.
Marc Laliberte 26:49
And that is,
Corey Nachreiner 26:50
yeah, continuous trust is like I agree. We need more continuous trust because we know people can, besides being malicious insiders that suddenly do bad things and maybe not being able to be trusted anymore, people can steal accounts. So you need to continue. You need to pay attention to those type of behavioral things. I'm sure.
Marc Laliberte 27:08
And that's basically what you propose too. Where it's like when you first go to trust your GitHub project, for example, or your local code repository, there's only a certain number of files that are actually risky that can cause code execution if someone were to compromise them just by opening the folder. Think of it like the MCP configuration file, the overall project settings dot config. Like let's say a half dozen or so files says what should happen is when you trust that it takes like a hash of each of those files and it maintains that hash, and so if that hash changes at some point in the future, like you downloaded a pull request with a malicious copy of one of those, it should immediately revoke the trust, explain to the user what changed and why it matters, and ask them if they want to retrust it again. And that's not perfect; it doesn't defend against someone like local on the computer tampering with files and then also tampering with that hash, but it would significantly mitigate this specific risk of you as a developer go to review a pull request made by someone that you don't trust within your local copy of the your code, which you do trust, and that exposing you to this type of attack. And I think that is like a good first step, and like relatively easy, at least conceptually, to add to tools like Cloud Code or VS Code or other ones.
Corey Nachreiner 28:30
Exactly. Yeah, agree.
Marc Laliberte 28:33
So we'll see if they update their trust models. Like I thought this was good. I hope that they take something like that going forward because that is actually something I'm worried about personally. Like our team at WatchGuard, multiple teams maintain open source repositories too, and this is a risk if someone were to submit a malicious pull request and before opening it, if you didn't pre review the code to understand what's going on in it, any changes to these risky config files, it could be a problem. So we'll see. Sometimes I feel like some of these companies move pretty quickly. Sometimes they move at a glacier pace. So we'll see if any changes actually come of it. But moving on. So if you haven't been living under a rock for the last two weeks. You maybe already have seen some of the news around this, but for those that are maybe hermited away and not watching mainstream news, you may have missed that the FBI and the U.S. Environmental Protection Agency recently published a warning that malicious cyber actors are actively attacking operational technology devices in the water and wastewater sector in the United States since around the end of July, july 27, and in some of those instances, the activity even degraded water operations.
Corey Nachreiner 29:54
I remember right. The first it happened all during last week, and I think it started in Minnesota. I'm going next week to speak with our various partners about you know some of the threats out there, including AI threats. But as I'm sure we'll find, the Minnesota was just the beginning. There's a lot of other states seeing the activity.
Marc Laliberte 30:14
Exactly. So it seems like they're targeting internet-facing programmable logic controllers or PLCs to remotely tamper with the configurations on them, and they're doing things like changing the IP address of them, or turning on and setting passwords to even like lock out the actual owners from these devices too. And the results are, at a minimum, a loss of visibility into the operational technology that these PLCs control, or in some cases, a loss of functionality as well of connected equipment. One organization reported just modified PLC project files across other victims. The FBI noted that a similar network setup from a third party, like managed service provider, that was managing the IT services for these folks, made it really easy for that attacker to multiply their success rate across multiple customers too, and in some of them, the effects reported to the FBI even included loss of pressure or flooding in some of these systems too. So no, like directly like let's say injecting a fatal amount of chlorine, but still messing with like pressure rates enough that could cause issues. Like if pressure rates and pipelines drop low enough, tainted groundwater could seep into them and taint the water supply that way. But obviously, the next step for this is if you control the chemicals that go into water, you could cause pretty big issues. Now, the FBI report just like named what activity was going on a few days before that, CISA actually published an alert naming Iranian-affiliated cyber actors in the attacks against PLCs across U.S. critical infrastructure, including like the models that line up with that FBI report. So if you put them together, it is Iran state-sponsored threat actors, or at least Iran-aligned actors going after municipal water supply in the United States, and I can't say I'm surprised about this, given the kinetic war that's going on right now and Iran's like exceptional capability in the cyber warfare space too. It makes sense why they would start flexing that as well, and just cause chaos in countries they're at war with.
Corey Nachreiner 32:26
Hopefully, we don't have to talk about this. Like, is it really happening anymore? I remember 10 years ago when we made all kinds of predictions about how cyber warfare is going to affect us during real warfare, and what a big deal it is. And a lot of people question, oh, yeah, that's never going to happen. You can't kill people with cyber attacks. But obviously, it's happening. This is one of many examples.
Marc Laliberte 32:50
It's happening, and and it makes sense. I'm surprised that, like, with the level of access that they've had in some of these cases, I'm surprised they're not doing more damages. I wonder if it's still kind of prodding capabilities and understanding them versus like actually trying to weaponize them at this point.
Corey Nachreiner 33:07
If we're getting, you know, our whole speculation hat, there's so many things. Like you say, maybe they were trying to just establish a quiet beachhead for something worse to come later, or prodding to learn about it. But I also think it could be as simple as purposely not doing anything bad and doing a very noisy attack to show, hey, we have capable. Like I know, I don't want to get into the Iran war, but you know, I don't know if the U.S. is really blowing the heck out of Iran the way some of our leaders say. Obviously, we've been in it for a long time, apparently we're even running out of certain kinds kinds of bombs. That said, we have higher levels of attack. We like there's things unfortunately that our leaders and country could do to really decimate Iran. So I assume Iran wants to do something that makes the U.S. lay off, but doesn't make the U.S. get super freaking angry and go the Hulk or whatever. So this is a type of attack where it will get attention. It will even get media attention. So maybe even get the people if we are a democracy to have feelings about the the conflict. So maybe it was a purposely feckless attack, like something that didn't really cause any damage, but was a very loud and vocal type of attack to show what could happen to critical infrastructure in an attempt to get the country to lay off of other kinetic means. I don't know, all speculation, but I think I agree. This could have been much worse and can get much worse. So,
Marc Laliberte 34:41
what do you think the solution is? Because I don't think it's necessarily like it's not like malicious intent from municipal water supply places to not secure their stuff. It's often they've got like two people in total working for the whole damn thing, and neither of them are technical people, and they're lucky if they've got enough budget for an MSP to come help them, but. Even if they do, sounds like some of the managed service providers can make the same mistakes too. It definitely feels like a funding kind of issue, and if we're labeling them as critical infrastructure, maybe we need to like devote resources to treat them as such.
Corey Nachreiner 35:14
Mark, you know, if if if I owned the government, maybe I wouldn't spend all of my wealth on making war, and I would spend more wealth on educating people, getting people to to solve emotional conflicts in peaceful ways, and maybe in securing and taking some adding regulation and capability in all the infrastructure that's critical for my country. I don't know the percentage anymore, but I know we spend a lot on war, and we just blew trillions of dollars on missiles for no apparent reason whatsoever. When you could have funded a lot of utilities that every human in whatever country they're in requires for life, so digging past
Marc Laliberte 35:59
the the obvious sarcasm in there. I think you've got you had a good point in there too, where regulation and ability is a key piece. Like in the past, there have been at least in the U.S. attempts to pass a law for higher regulation on these, and there was actually shot down because they were saying there's no way in hell that they even have the funding to like meet these regulatory. Well, it's the funding.
Corey Nachreiner 36:21
It's paying for it. This is critical infrastructure, and I like this is where you get into people who they think capitalism and keeping things private is more important. I do think there's certain types of things, utilities like the telephone companies are more regulated than the internet companies because we consider them a critical emergency resource. It's how we communicate with each other. By the way, the internet is too, but for some reason, it's not getting the same level of public utility support from this particular country. Water, heat, gas-yes, private companies help support that, but maybe they should be treated, even if you find some way to keep them private. They have a public utility level where you fund them. A public utility means the government pays in some ways to fund them. It's not just a regulation. Regulation in this case is probably not working. Like even if they did regulation and they pushed it regardless of expense, I bet you there's private companies. I would just rather try to make a profit and hope that they never got bit by ignoring the regulation. But I, I some things maybe should be a public utility and should be funded. So you know, I guess it doesn't get political on purpose. I don't want to be on any side, but government's there to actually help stabilize all of its citizens, and there's certain basic Maslow hierarchy of needs we have. Water is one of them, so maybe that's something a government should fund and control.
Marc Laliberte 37:54
I I want to look on the the optimistic side for once. I know that usually you're the optimist and I'm the cynic as we end these things, but this feels like it was a big enough newsworthy event in the U.S. where it actually did like make its rounds across all of mainstream media and non-traditional media. Maybe we're getting close to the wake-up call that we need to take securing critical infrastructure, all critical infrastructure seriously, and maybe there will be some meaningful change at some point.
Corey Nachreiner 38:23
So, as much as every different country might be arguing different politics around how to do something, the funny thing is, we all have the same needs. When crap comes, the we need to be able to buy food, we need need to be able to have housing, and we need to make our water safe. Like I don't care what side you're on on anything, it's just a core freaking need. So, please, can we come together to fix those things?
Marc Laliberte 38:50
Please, I sure hope so. And in the meantime, if you are responsible for securing a municipal water utility, please make sure your crap isn't exposed to the internet.
Corey Nachreiner 39:00
By the way, we've we've totally we skipped all the mitigation factors here because it to me it seems silly to say oh don't put a programmable logic controller for a critical resource on the internet.
Marc Laliberte 39:12
Yep,
Corey Nachreiner 39:13
but that's what what's happening. That's what is happening.
Marc Laliberte 39:17
That is the guidance for them. Disconnect it from the internet. Make sure that you've got strong passwords enabled everywhere. Enable logging. Isolate it from other networks. Like all of the basic stuff that you would expect. I guess some of these even have like a physical switch of like run mode versus program mode. And if you flip it into run mode, people can't reprogram it. So maybe do that while it's running, unless you already helped even
Corey Nachreiner 39:39
mistucksnet.
Marc Laliberte 39:41
Exactly.
Corey Nachreiner 39:42
Although I guess they did infect the engineer's laptop, and so he's the one that would occasionally turn it on program mode. Anyways, he or she. Anyways, yeah, it's it's funny how we've gone from trying to convince the world that these type of OT affect your water. System attacks could even happen. To oh yeah, hey everyone, our utilities are on the public internet. There's lots of states that have been attacked by Iran. Don't do that, okay?
Marc Laliberte 40:13
Oh man, hey, I mean at least job security for us, right? Until AI
Corey Nachreiner 40:18
gets us out as
Marc Laliberte 40:19
well.
Corey Nachreiner 40:20
I honestly hope I can educate and help people before they get here, but I feel like not looking promise I gave 20 years ago.
Marc Laliberte 40:29
Just got to educate harder, Corey.
Corey Nachreiner 40:31
Yeah, harder, better, faster. Maybe I should turn to music.
Marc Laliberte 40:37
That sounds great. Either way, man, what a crazy week! Hey everyone, thanks again for listening. As always, if you enjoyed today's episode, don't forget to rate, review, and subscribe. If you have any questions on today's topics or suggestions for future episode topics, you can reach out to us on BlueSky. I'm at it's mark.me. Corey is at SecAdept, and we're both on Instagram at WatchGuard underscore Technologies. Thanks again for listening, and you will hear from us next week.