This week on the podcast, we cover a few takeaways from Microsoft's recent Digital Defense Report. Before that, we discuss the recent Citrix Netscaler zero-days that were potentially under active exploit for weeks before disclosure before reviewing an interesting a bug bounty report on a Microsoft internal tool that was exposed externally.
View Transcript
Marc Laliberte 0:00
Hey everyone, welcome back to the 443 Security Simplified. I'm your host, Marc Laliberte, and joining me today is
Corey Nachreiner 0:07
Corey, "jealous of a 16-year-old" Nachreiner. Man, I thought I was smart.
Marc Laliberte 0:13
Funny thing is, I made the same comment to my wife this morning, and exact response was, "Oh, you are jealous. Anyways, on today's episode, we'll discuss a really interesting research post from a 16-year-old security researcher who started last year when they were 15. Before that, we'll cover the actively exploited Citrix NetScaler vulnerabilities that Google Mandiant recently wrote about, and then we get one,
Corey Nachreiner 0:41
Mark. By the way, I do. It's been the top of my AI-based news summaries for four days. That that one goes deep.
Marc Laliberte 0:49
Yeah, and then we will end with the I don't know briefest analysis of a absolutely massive security report that Microsoft just published a couple of days ago, called their digital defense report for 2026, but with that, let's go ahead and I don't know exploit our way in this time.
Marc Laliberte 1:17
Let's talk about these Citrix NetScaler vulnerabilities that just got disclosed and patched on I think it was september 29, but Google Mandiant just published their own threat intelligence brief just last week, walking through what they're seeing as active exploitation of the these vulnerabilities in both the Citrix NetScaler ADC and Gateway appliances. Their publication came just a day after Watchtower Labs published their first write-up of one of the vulnerabilities, and then the same day that they published the second write-up of a second vulnerability, which is the one that Microsoft ended up not Microsoft Mandiant ended up detecting. Quick high-level overview from some of the trends they saw, they said they saw threat actors primarily targeting CVE 2026 88 772, which we'll talk about in a second, against organizations in North America, Europe, North America and Europe, primarily in the government, financial, tech, and education and legal sectors, mostly the sectors that primarily use Citrix NetScaler as a remote access service, and the vulnerability itself is really interesting. So Watchtower, our good friends there, did a very thorough and meme-filled analysis of both this vulnerability, which is in the Datagram TLS or like UDP TLS implementation on Citrix NetScaler. They also had one the day before that was also funny and pretty damning. I have to say, it feels a hell of a lot better not being the vendor on the receiving end of these write-ups that Watchtower does because they are very technical and extremely well written, but very rude.
Corey Nachreiner 3:03
Yeah, we we should wait till the takeaways to talk about that. But in particular, as you say that, I look at this part where we have been on Watchtowers target list before, but as we get into the Citrix one, like you you mentioned, this is being exploited since September. But there's some that say five weeks. So there's a lot of signs that this has been going on for five weeks, and Citrix is not the one that said anything about it until now. And you can tell in this if you're watching the video, they have a picture that you know, Watchtower, a Fortinet crossed out, Juniper crossed out, Ivanti crossed out now Citrix PCRT extension company, where they're alluding that these companies don't do P cert, these companies don't do transparency. So my goal with Watchtower is, you know, sometimes we have vulnerabilities and they'll be snarky at us, but we run a good P cert process. Mark, you have worked directly with these folks, so I hope at the very least they see vulnerabilities happen. I think even Watchtower says that it's how you take care of them and communicate them. So I definitely do not want to be added to this particular focus of Watchtower for sure. No,
Marc Laliberte 4:16
and even before we dive into the vulnerability, like one point there that you made, it's pretty important. Is this has been under active exploit for potentially up to five weeks, and it wasn't Citrix that reported it. But as of September 11th of this year, anyone that sells products like NetScaler or WashGuards Fireboxes into the European Union now has to report when one of their vulnerabilities is under active exploit to Anisa and whatever national CERT organization they partner with within Europe, within in a very short four hours
Corey Nachreiner 4:52
day, it's so this is a huge change to the industry. That doesn't mean they have to tell the world they have to tell, but still, I. Who knows if someone like you know Citrix has been able to do that with this type of thing? Yeah,
Marc Laliberte 5:06
and that's also not to say Citrix didn't make that notification. They by default do stay confidential. It's just Anisa, the European Security Agency, has the authority to disseminate those out to people that might be using that product within the European Union,
Corey Nachreiner 5:21
and you know the exact date, but that didn't that literally happen? Didn't the left start that September? Never forget. Oh wow! I guess it's easy to remember that one. I wonder if they picked it on purpose.
Marc Laliberte 5:32
I suspect. Well, I don't know. I have no idea. Maybe there was some funny guy in the EU Council that decided to pick that date, but anyways, it
Corey Nachreiner 5:42
would be memorable. Also, my dad's birthday, by the way, which I'll never forget.
Marc Laliberte 5:45
Never forget. So, anyways, the vulnerability itself is how it takes place and how the Citrix NetScaler appliance handles DTLS fragmentation. So, DTLS, it's the way to add encryption to UDP packets. There's a bit of a handshake that's kind of different than how you would do it over a TCP-based connection, but it supports fragmenting packets, meaning you can send a larger piece of data over multiple smaller packets. There's different headers that control communicating how big the data is and how many packets are a part of the fragmentation, and basically, long story short, and the way that the NetScaler appliance reassembles these fragmented packets can overflow a memory buffer to a size under the attacker's control and with content under the attacker's control, which is a pretty classic way to gain arbitrary remote code execution on a vulnerable system.
Corey Nachreiner 6:44
Because we're joking about how jealous we are of 16-year-olds, I didn't mention the throughline for this. I mean, one of the things for all three of these stories is they're all, I guess, less so for the Microsoft report, but these are all basic, old-class vulnerabilities. They're big freaking deals. They haven't been handled well. Only 10% of the net scaler devices that are vulnerable to this have been patched. So there's 90% of online devices, right? And yet it's it's a heap buffer overflow. And when we get into the other story for the 16-year-old, he found good, hard, hard to find ones. But at the end of the day, just not having signat, not not looking at a signature, you know. So the theme of the vulnerabilities in in the this week, and maybe in in some of the results of Microsoft's report is, it's still the basic foundations that are causing the biggest vulnerabilities in the world.
Marc Laliberte 7:42
Yep. So attackers have been exploiting this vulnerability at least since the end of September, according to some reports. Potentially quite a bit earlier than that. Once they've exploited the flaw, there's a few different paths that they go down. Sometimes they drop a PHP-based web shell on the host. Sometimes they set up a Python-based reverse tunnel to be able to execute commands and connect to systems behind the NetScaler appliance too. There's some interesting evasion techniques that they were using on here. So instead of just dropping a a PHP file, like a server-side scripting file, directly on the file system and using that as a web shell in a way that would stand out like a sore thumb for anyone that's monitoring the file system. They actually modify the web server that runs on these Cisco appliances to treat anything ending in a .deb file extension as a PHP file. So instead of dropping a PHP file, which everyone is looking for for post exploit activity, they drop something that maybe people would just gloss over and continue moving on. In another example, they were using .sig .sig as the file extension, and they went through this elaborate process to set up a rewrite rule on the web server, where if someone sends a web request to a .isco file, an icon, think like the favicon that most websites have. It would rewrite that to a .sig file, which would be served up as a server-side scripting file, a PHP file. So different layers of evasion here to try and make it a bit more difficult for someone that isn't looking deeply into these appliances to catch the potential compromise. Once they set up that web shell, they also modify the the local shell executable itself to make sure everything that runs through it runs as root. It's their way to gain just full control over the system, and then they had a few different ways for how they were interacting with the the appliances from that point on, but one of the more popular ones that Mandiant flagged was setting up a Python based tunnel, basically where the attackers could run a command that would get executed against another system behind the Citrix NetScaler appliance. Basically, a way for them to. To resources through this web shell that are protected behind this remote access tool, so using it as kind of like a jumping off point or a bastion to go hit hosts internally on the network. So I think Corey, this is yet again for the 400th week in a row, another piece of edge networking equipment that is under attack by threat actors out there, and this is yet another example of something where you have it intentionally exposed to the internet. It is a let's say remote access or VPN aggregator type of appliance, and that is what puts the target on its back because there's a service now that's exposed to the internet that has to be perfectly hardened, or else this type of attack can occur.
Corey Nachreiner 10:45
And and and maybe limited hardening because it this is the kind like it has to be hardened exactly like you say, but it can't just be blocked with access control lists because the functionality of it actually depends on people getting to it from anywhere in many cases. So yes, yes, it's it's more edge network remote access and VPN attacks targeting hardware.
Marc Laliberte 11:08
I think like we've said it a few times, but this era of like a like an outward facing type of remote access solution, like Citrix NetScaler or just any general VPN aggregator feels like this era is ending.
Corey Nachreiner 11:24
It has to. This is why we have VPN. I mean ZTNA and other remote access project products that are cloud based and work outside in or inside out. I should say
Marc Laliberte 11:36
because I know like one of the things you pointed out there was only 10% of exposed systems have actually been patched, and I think that's one of the biggest reasons for migrating away from this type of access model and into a zero trust access model. Because, like, one not maybe not complaint, but one thing people tend to say when it comes to like VPN versus ZTNA is you're not really removing that exposed service. It's just you're transferring it to the ZTNA provider's cloud now instead of exposing VPN on my enterprise network. It's you connect to WatchGuard's cloud, for example, and we manage that inbound connection into this mesh network. But the benefit of that is, like providers like WatchGuard or like other services out there, we can near instantaneously patch a vulnerability across the entire exposed surface like immediately. Versus if it's something that you, as a systems administrator, manage, you have to become aware of the vulnerability. You have to get a copy of the the the resolution, the firmware that fixes it. You have to test that firmware. You have to deploy it yourself. And there's all these steps that kind of slow down the response there to a point where it's massively risky, especially in this era. Especially with what we're going to talk about in the report at the end of this episode, where that time you have from when a vulnerability is disclosed to when it's weaponized and under active exploit is just almost zero.
Corey Nachreiner 13:03
Thank you, AI. Yeah, it's worse than ever. Like I completely agree, Mark. But the the funny thing is, we're talking about only how 10% of publicly exposed ones are patched. But this is also a class of vulnerability where patching is not enough. I believe the 88778 vulnerability. Besides applying the patch, you also need to to generate an enhanced ISN separately. So you have to patch and do some work. The upgrade alone doesn't close it. Patching also is not going to remove any existing web shells. So you have to, you know, if 90% haven't even patched, 90% still have not even done any compromise assessment to see if they're affected by this, which is highly likely, with with how long this exploit has been around. I will say that, by the way, I think WatchGuard has released some tools, and there's definitely a crapload of indicators of compromise in Mandiant Google's report, so there's ways you can get some help if you want to find out if you've been compromised. And the final thing I want to say is credential rotation. Like it hasn't been mentioned too much. I think Google Mandian did a bit, but it's not just admin passwords, SSH keys, TLS certificates, and private keys, LDAP bindings, service accounts, Radius shared secrets, TACACS credentials, SMP community. Like I can keep going. This is a device that has a lot of secrets. So say you patch, say you adjust your configuration to actually put deep logging on, so you log more and and have that enhanced ISN generation. Say you you check that it hasn't doesn't have a web sheet. You still may have to rotate everything. So to your point of isn't it nice to have a situation where the vendor themself just has to do an update and you don't have to worry about all that stuff? It it just makes that so much more. We're like. The the solution where your your vendor is taking care of that can be easier for you, even though you still need a vendor that does take care of that.
Marc Laliberte 15:10
Yeah, exactly. But either way, if you read through the the Mandiant report, the second half of it is just a whole bunch of IOCs and threat hunting guidance on how to determine if you were compromised, and if so, what artifacts might still be present. It's definitely worth checking out if you've got a Citrix NetScaler appliance.
Corey Nachreiner 15:30
Can I talk about a few more things that we might have missed? One of the thing I've said this a long time ago, but I find we didn't really talk about the way that an hacker triggers this is actually by leaving a log. You know the the way you can pick up one of these vulnerabilities is that you know how you're doing something, you're generating network traffic that's not directly going to a port, but it leaves a log that eventually, when it gets parsed, will will start at least one of these vulnerabilities. I always find that an interesting, a novel way. The one side effect is, you know, it could take up to 24 hours for whatever process that's parsing that log to get to it. Although I think Mendian found a way to force that immediately. It
Marc Laliberte 16:14
was Watchtower mentioned at the very end of their report. They found a way that they weren't going to disclose to basically make it instantaneous.
Corey Nachreiner 16:22
Yeah, and then as you said, I'm glad they didn't disclose that. But I found you know a lot of people don't realize they think about open ports and stuff like that, but having a vulnerability just exposed because your system logs. The other thing is the appliance. The appliance itself did not always leave the logs in its own system that would help you as a person monitoring know that something was exploited. So it's an another case where having systems that are paying attention to errors and things like that, like some of these flaws are not going to trigger, you know, something that can tell you that something bad just happened to your appliance and it got popped. So that's kind of interesting to me. I like
Marc Laliberte 17:13
I've heard observability described as one of the important foundations for security. Like we focus on, you know, we got a malware alert or someone tried to log in too many times with the wrong password, but the reality is, like you can catch a lot of what ends up being malicious activity just from an unexpected error or an anomaly in what's normal for an organization. So if you've got like good visibility into how your systems are operating, what their response time is for stuff. What like log messages they typically output, and if you see something just different in there, which you need to use automated tools to catch that type of anomaly, but that can be a big indicator of just something funky going on within the environment that can ultimately help you identify a potential compromise going on.
Corey Nachreiner 18:00
Absolutely, and the last thing I kind of want to talk about is I, I think you and me have some strong respect for Watchtower. I I love how they describe things so people understand, and I I do frankly think they're doing a service despite the fact that they throw some shade. But I also have to push like in this disclosure, a lot of their honesty and shade might be deserved. You know, they are right that they pointed out that Citrix's customers learned about this zero day from every single person except Citrix until it happened. You know, and a screenshot of Citrix's own January blog says secure by design, proven by action. It's fair of watch power to attack that, and I do think there is a place for full disclosure. But I, you, and I also believe in responsible disclosure, which I believe is sometimes like you pointed out, the good thing they're held back, giving the 24-hour or the immediate force to the logging situation, but they also published a working artifact generator within 24 hours of the advisory, and a company called Loopovis saw internet-wide spraying of this exploit within minutes of of Watchtower releasing what is essentially something to go see if appliances are vulnerable or not. So there, this was a targeted zero day, meaning the threat actors were not spraying the internet with the exploit. They released a working artifact generator, which I the good side of that is I do think people need detection tools to find out if they're vulnerable. Although vulnerability assessment should also be able to tell you that, but their their code what what they do release is used by threat actors too, and. At least one company saw an immediate response of internet spraying within minutes. Is that the good guys using their generator to find the flaws, or are those new criminals that just learned of this new toy and are going to increase the mass exploitation of this particular flaw? So while I like Watchtower, clearly, I it's hard not to respect that organization with what they're finding. I I think they're right on the edge of responsible.
Marc Laliberte 20:30
That is where it cuts both ways for responsible disclosure. Like yes, sometimes it can feel justified to throw shade at someone that you feel like hasn't been handling the system responsibly from the vendor perspective, but then dropping a basically, if not the like working exploit, a direct map to how to exploit it means that it's immediately going to get weaponized. Period. And when people haven't had a chance to update, especially in an ecosystem like network equipment, where it does take time for patch uptake on these things, that is directly introducing risk that maybe you didn't need to. But
Corey Nachreiner 21:08
and my issue is it hurts the customer, not the vendor. Like their words alone and what they point out without giving the threat actors an unfair advantage is already going to put egg on that. I I think their intention is to point out when they believe vendors are being too negligent and not taking things like piecer and their vulnerabilities seriously, and that's something I understand. That's something that's well, it's always hard to say justifiable. You know, is I I kind of get it, but as soon as you move to exploit, you're hurting all these customers. These customers don't follow vulnerabilities. They don't follow the vendors' announcements or patch releases as much. You're you're hurting the customers, and they're the innocent ones. They're the ones that, you know, hopefully they pick vendors that help secure them, but they're not responsible for what the vendor is doing, so that's just where I wish WatchGuard would be careful. Watch Town because WatchGuard is very careful. Oh God, that is the worst Frodeian sleep anyone could make. That one should get out in editing, but I'm sure we'll leave it. I too
Marc Laliberte 22:16
wish you were careful, Corey. But thank you. I
Corey Nachreiner 22:19
should be careful with my words, wow! I hate that one immediately. The point is, you know, if you're if you're pointing out the bad things vendors are doing, I get it. But please protect the customers.
Marc Laliberte 22:31
But on the flip side, as a customer, like if you've got a system that is exposed to the internet, know your attack surface, and know that with that, you need to be prepared to resolve that as quickly as possible when you get a patch.
Corey Nachreiner 22:45
I just said customers don't necessarily always do a good job of that, but I agree what Mark said. We sometimes we're aggressively trying to communicate things with you to help you secure yourself, so it is good for you customers to pay attention as well.
Speaker 1 22:59
Yep.
Marc Laliberte 23:00
So moving on to the next story, this one was super interesting. I saw it pop up on I think it was like R slash cybersecurity with a really kind of borderline alarmist but accurate headline of how I could have accessed 17 trillion Microsoft records, and it's basically a write up from a 16-year-old security researcher going by their handle FAV, F-A-A-V, where they discussed finding and ultimately finding a vulnerability in a Microsoft system, which had an exposure of around 17 trillion records, ranging from employee records and emails and stuff to even it was like Bing search engine telemetry from usage as well, but basically it started out with them describing this AI hack bot they created, which what they called Ontaris, which helped them find and ultimately exploit vulnerable systems. They said on August 25 of this year, it found a internal Microsoft service called Titan, which had a VPN required notice on its landing page instructing actual Microsoft employees to connect their corporate VPN in order to access this service. And they thought that was interesting and started trying to find potential vulnerabilities in this application through some sleuthing, they found a Swagger API documentation file. Swagger is a pretty popular format for documenting API endpoints and both request and response parameters around them. But that file can act as kind of a map of what might be available for a web application. In that documentation file, they found four different endpoints. Three of them required Microsoft Azure AD authentication, but one of them was public. And in fact, that endpoint appeared to be a way to just query raw SQL queries in the underlying SQL database behind this application. But even though it was public, it did still require authentication in the form of a JSON Web Token, and so they set their little AI assistant at the task of trying to break into this application, this API, and finding a working JSON web token. It was interesting; like they walked through the process of how the them and their tool kind of tag team trying to get in here. They noticed that if they didn't include a JSON Web Token, they got a 401 unauthorized response, which indicated they needed one. But then, as they started modifying different types of values in this token, they started getting different error messages. Basically, they first got one that said didn't have the right tenant, so then when they changed the tenant to Microsoft, they got a error saying wrong audience. When they changed the audience, they got a wrong application ID. But all of these were indicators that the backend application wasn't actually validating the signature for this web token. Like how JSON web tokens work is they include different parameters like application information and user information. Sometimes even like group or permissions information, but it's all cryptographically signed by a secret that only that application and its servers should know. And that way, you can transmit it clearly across the internet. An attacker or a user can have access to the token, but they can't modify it without screwing up that cryptographic signature. So the fact that this researcher and his AI assistant were able to modify values and get different error messages, and none of those error messages were incorrect signature, meant that the app wasn't validating the signature for this token. So long. Yeah.
Corey Nachreiner 26:41
Go ahead. No, go finish. I well, it can be a takeaway. I find one of besides, like at the end of the day, this is a vulnerability finding, and it's actually a pretty, as I said, part of the theme. Not using the signature of your your token is kind of silly, but the the way that AI assisted a human, like we're finding AI can be completely agentic and can find crap on its own, but this was a situation where also he had to eventually figure out a user, and there was no way, like like the way they were using a particular value, the a UPN was not how it's supposed to be used. AI was confused without the human gut and without the AI. You needed both of them to kind of uncover. So I found it fascinating that humans are good at finding things. AI is really good at finding things, but there's situations where working together, it's going to really elevate the amount of things we find even more that are really complex with lots of weird variables, including just mistakes in how you or or weird ways with how you name things.
Marc Laliberte 27:51
That's I think an interesting thing to dive into. Like one of the fields in that token was the UPN, the user principal name, which UPNs are almost always email style usernames. Think like user at domain, and so their AI tool was trying different combinations of users, like valid Microsoft employees or just like admin at Microsoft, and it was hitting a wall every single time. And this researcher said that he realized that maybe the UPN on the backend, all it was doing was just trying to look up a local user on the application. So instead of trying to do like admin at Microsoft, he just manually changed it to just the word admin, and that's when it ended up succeeding. And he said, like in hindsight, that's obvious. It but it's not a valid UPN, and so the AI tool just never guessed it because it was being very literal about that field type. It's obvious to a human
Corey Nachreiner 28:45
that knows that communication isn't always literal. It's less obvious to a system that is literally trying to figure out how things are in a documented way supposed to work.
Marc Laliberte 28:57
Yeah, he said he stopped taking the field name at face value and thought about what the developer might have just done on the back end, and that's something his AI assist didn't didn't do, which is why it didn't catch it. So once they got that valid user, they had a fully working JSON Web Token for this admin user. They started taking a look at the database, some stats from it. There was 25,000 account and email records in it: 18,000 employee email records, 15,000 organization records, hundreds of 1000s of charts and definitions. But he also found a table that looked like it had a bunch of Bing analytics, so looked like potentially usage data as people were interacting with Bing. It even included like a user unique identification number, so it could have been used for tracking. This is where he pumped the brakes and went ahead and reported to Microsoft everything that he found. But like he did some math calculations to try and figure out based off the number of tables and the number of records per table, like how many records might be in here. And it came to over 17 trillion records. I and I hate to say it doesn't matter for understanding this vulnerability, but I love the anecdotes that people like 1516-year-old, kid. Like he's he said it was two a.m. and I wanted to yell or at least say something out loud, but my parents were like, I like like you could totally understand that. I just found 17 trillion records through a flaw that I can access Microsoft, the biggest
Corey Nachreiner 30:30
you know one of the biggest operating, literally the biggest operating system company in the world, and he's in his parents' house while they're asleep at two a.m. That it just is a fun story to hear. That's pretty
Marc Laliberte 30:40
fun. In terms of like timeline, they reported it to Microsoft on september 5. Microsoft on the next day asked them to stop testing and give their IP so they could make sure that he's the only one that found this potential flaw. They fixed it on the ninth and gave him a whopping $5,000 bounty reward, which feels kind of like peanuts coming from Microsoft for something like this, but
Corey Nachreiner 31:05
still proud of the kid. But this is a this this is a big vulnerability. It feels bigger than that for sure. My only
Marc Laliberte 31:11
assumption is Microsoft determined that like the data in there, even though it clearly included some PII, wasn't like mission critical or business critical data, and even though the volume was high, maybe it wasn't actually massively security impacting. But I mean, this is a 2 trillion, $3 trillion company. What is their market? I'd
Corey Nachreiner 31:33
be trying to hire this kid. Like I would have given a bigger bounty just because I'm. I would start recruiting him right away if I were them, I don't like a kid that's already doing this and was trying to be. I mean, to some extent, I guess he didn't have pre-approved authorization, but he's trying to be a white hat in how he does it. I would go more than 5000, and I would immediately be. And he developed an AI assistant to help him with it too. Like this kid's got a bright future. Maybe we need to go hire this guy, Mark.
Marc Laliberte 32:10
100% And he even ended his post with like a bit of like philosophical things, where he said that like the only reason he found this was because AI and human intuition compounded together. That the AI piece it did 10 days worth of work that he didn't have to do, but then it got stuck on something simple like that UPN field, and the AI wouldn't have gotten there alone, and he wouldn't have gotten there on his own. So it was only the combination working together that they were able to find it. I thought, I mean, that's just very true of where we're at right now. Absolutely, I'm not convinced that's where we're going to stay going forward. And I'm willing to bet that, like, had he had access to the Mythos class model from Anthropic, for example, it probably would have tried other combinations of user input in that field, and that is the capability that we're up against now when it comes to AI. But this 16-year-old kid hanging out in his bedroom managed to go find this pretty serious flaw in at least this one application in Microsoft, thanks to his little power in combination with AI. It's pretty cool.
Corey Nachreiner 33:12
By the way, the one thing I forgot to mention-I probably didn't show when I was showing video of this story-but right at the beginning, this is more like gossiping scuttlebutt, but at the beginning of his post, he states that Microsoft required editorial control of this blog post we were showing, and Microsoft cut sections and figures and reshaped the impact description.
Speaker 2 33:37
Yeah,
Corey Nachreiner 33:38
so I that's the only to me that's the only dart. Like he he he doesn't seem particularly mad about it. He he stated that he stated it quite plainly and matter of factly, but it that does make me wonder a little bit. Should a vendor have editorial control of a write up? It makes me I'm I'm
Marc Laliberte 34:00
on the fence for this. Like
Corey Nachreiner 34:02
we're a vendor, so of course we are.
Marc Laliberte 34:04
I could see a scenario where some a 16 year old kid, not to throw shade, but maybe inflated the actual impact of what this is. Not like high
Corey Nachreiner 34:18
business connotations.
Marc Laliberte 34:19
Correct. And we've actually we've been on the receiving end for this. We had a I think it was last year a researcher, despite us being a certified numbering authority at WatchGuard, responsible for opening CVEs and managing CVEs for everything under our scope. We had a third party researcher go straight to MITER as the CNA of last resort and open a CVE for something that ultimately was not a vulnerability. It was a misconfiguration in their deployment that they tried to flag as a actual software vulnerability. I remember all the details. I just remember being kind of pissed at the time wasted at the time. But they even went out and created like a big LinkedIn post. They created a GitHub with this quote-unquote. Quote proof of concept for this thing, but the reality was it wasn't a vulnerability, and so I can understand why a vendor like Microsoft might want to have at least some oversight, or at least give some like, hey, you know what you're putting here is factually incorrect. Please adjust it to this type of interaction. But I think to your point, like there is a line, and like full editorial control, and even preventing people from disclosing a vulnerability might be crossing that line. And Microsoft's done that in the past too. Now that they own GitHub, their policy is to take down proof of concept exploit code, especially in Microsoft products, from GitHub repositories, and that is a change from historically how researchers were able to be transparent about stuff. So, off my soul, interesting.
Corey Nachreiner 35:47
Like I said, it was it was it was just a little bit of drama for the detail, but yeah, I could see both sides, just like you said.
Marc Laliberte 35:55
Yep. But great report. This kid has a very bright future ahead of that.
Corey Nachreiner 36:00
The thing is, if he never said he was 15 or 16, this would have been a great like it stands alone on its technical detail and rigor. The fact that he's 1516, is just an interesting neat that makes it neater. But he didn't even have to say that, and I would have respected this research.
Marc Laliberte 36:17
Yeah, if if you're listening, listening, Mister Fav,
Corey Nachreiner 36:21
Fav,
Marc Laliberte 36:22
I'm sure you can find my email. Reach out, and we'll find a way to give you an internship. But, anyways, moving on to the last story today, and I feel like this last one we could probably split over multiple podcasts, and so we might come back to it over time. I
Corey Nachreiner 36:39
haven't even been able to consume the whole thing. I'm just in summary mode on it. It's quite a big, big report.
Marc Laliberte 36:45
Microsoft just published their 2026 digital defense report, covering their view of security operations and security practices across their entire 15,000 partner ecosystem. And this report is a doozy. It's 108 or 103 pages, chock full of detail and trends and stats, and instead of going like start to finish through everything in it, I found a few takeaways that I thought were pretty interesting that I'll bring up and chat about. And once I've personally finished reading all 103 pages, hopefully in the next week or so, maybe we can
Corey Nachreiner 37:20
easy chat about it going to a big partner conference and and speaking and releasing our own data. Yeah, that'd be easy. You'll read this in your your your copious free time.
Marc Laliberte 37:30
I do have a decent amount of flight time coming up though, so I might be able to knock out some of it.
Corey Nachreiner 37:35
I'll be practicing presentations, unfortunately, during my flight time.
Marc Laliberte 37:39
Well, you don't just hop up on stage and wing it. Just open your mouth and see what comes out.
Corey Nachreiner 37:43
Hey, stop giving away my secrets.
Marc Laliberte 37:45
Anyways, yeah, for something like impact, absolutely not. For other conferences, sometimes that's just how I operate. But
Corey Nachreiner 37:53
to be fair, we actually know enough about the industry that we can talk about most subjects with some experience and knowledge.
Marc Laliberte 38:00
Yep. Anyways, to the report because it is interesting. Like it started out by laying out basically 10 high-level security priorities for organizations, covering things like governance and identity management and exposure management. But it gets really interesting once you get into some of the weeds for it. Like early on in the report, I think it's page like 1210, or 12 or something. They start talking about just vulnerabilities in the age of AI, and a couple of stats stood out to me here. And I'm curious what your thoughts are on them, Corey. They said 2026 is on track for 72,000 CVEs published, which will be a record, and I'm seeing that across the board. Microsoft's own Patch Tuesday, 999
Corey Nachreiner 38:48
or 74, depending on if you count certain external products. Biggest ever, and I think they were just over 12,000 the year, 12,000 for all of 2025 up to a month that had 999. We
Marc Laliberte 39:03
um we manage a bug bounty program on HackerOne as a platform, and in a recent call we had with some of their product management, they actually showed me a graph that was just this astronomical hockey stick of the number of reports they're getting in across their whole platform across everyone that participates in that for bug bounty, so it makes sense, and we're absolutely seeing that. Another one was that the median time to discovery for in the wild weaponization is now quote well below 24 hours. So from the point where a vulnerability is disclosed to the point where Watchtower creates a report and everyone starts exploiting it on the internet is now less than a day. Some of the other ones in there, they talked about autonomous attacks. They mentioned that open weight models, so think open source AI, are only lagging the frontier models by about seven months. That's something that we discussed recently with some of the Hugging Face capabilities, where like. We're all worried about the frontier models, but the reality is the free stuff, the open weight stuff, is not very far behind. And
Corey Nachreiner 40:07
the other thing is the open weight ones are the ones that can be used without guard. Like the the the company and or threat actor does not have to implement the guardrails that the frontier models-they don't have
Marc Laliberte 40:22
input and output classifiers, making sure you're not trying to exploit a vulnerability on them. It's just literally the capabilities distilled down into weights. That was pretty nuts. They also talked about a specific ransomware operator called RAID Puffer, which was the first automated ransomware extortion attack? They discovered it in July of 2026. So fully autonomous ransomware threat actor and operator now. Glad we've automated that capability. They talked a bit about prompt driven malware. So there was a malware variant called Lame Hug that asks a LLM for the commands at runtime that it should run. Basically, the malware itself, all it does is open up a shell and then it queries some external LLM, saying, "Okay, what should I do next in this situation? So it's like a I don't know automated hands-on keyboard kind of attack where historically it would be a human interacting and manually doing reconnaissance, and then finding something to go attack and whatever. Now that human piece with the hands-on keyboard can be automated with an LLM. That was pretty interesting. In one of the sections, they talked about Microsoft's internal red team. I found this one very interesting, where they mentioned just to start the section that durable security still just comes down to the fundamentals, and that even the most damaging intrusions still relied on just stuff that was already out there. They rarely had to develop anything novel. That makes makes sense. Like what AI is doing, it's not necessarily creating entire new techniques and attack vectors. It's just making them faster and exploiting them at machine speed. That totally makes sense. Another, I liked
Corey Nachreiner 42:13
just while we were talking about distillation and AI. I liked a part of it where they talked about we talk about living off the land attacks, but they talked about living off the AI. I recently did a cybersecurity tip, basically reminding people that agentic AI means you're giving AI the kings, the keys to your kingdom. And they talk about how signed, allowed, listed AI CLIs become loll bins with reasoning, web access, and code execution attack are attached, and so just this idea of living off the like, it's part of identity. It's related to their number two thing, which identity is where all the risk is right now. Stolen identity, but I I don't think everyone is realizing the difference between shadow AI and shadow IT is that AI has our identity when it goes agentic, and I agree that living off the AI is going to become the modern type of identity attack scenario.
Marc Laliberte 43:09
They had a really big stat in there too, where 88% of organizations are experience experimenting with agents, and that by 2028, there's going to be 1.3 billion AI agents in production. Like remember when we used to talk about like IoT as the big risk for organizations, and there were going to be like billions of IoT devices connected to networks that that would meaningfully impact risk for companies. I mean, don't get me wrong; it still does if you set them up incorrectly. But think about 1.3 billion AI agents with all the power of employees and none of the oversight, in many cases, that is a meaningful risk for companies. When it comes to AI usage, they had another interesting section where they talked about internally in Microsoft using AI to try and find vulnerabilities. They said source code analysis was an area it does super well, and like speaking from experience at WatchGuard, that is absolutely the case. They said that in the past, like trying to find vulnerabilities by reviewing source code could take a skilled worker multiple weeks to go through a codebase by hand, but now it's something closer to just continuous, which is exactly what we're doing internally at WatchGuard. We're going to talk more about it at the Impact Conference. I guess this week, at the time where this this episode,
Corey Nachreiner 44:27
depending on when it's published, I think it's like at 4p.m. You and I will be talking about it directly.
Marc Laliberte 44:34
Exactly, and that is one area where we've seen like AI frontier models being highly capable, and as when it comes to like being used for good internally in a company, they talked about some attacks against AI agents. They said 52% of attacks involved malicious link injection. Think of that as like a way to potentially exfiltrate data out of a model or an environment. By having a malicious link that has data encoded in it, they talked a bit about memory poisoning within AI agents, where and primarily through email-based prompt injection, where they could create a persistent backdoor of sorts within an AI agent by poisoning its memory with prompt injection. Think like if it interprets a malicious email that's got prompt injection that says, "Okay, in this scenario, take this action. And then at some point in the future, they send another email that triggers that scenario, and then maybe exfiltrates data out of the company. That felt like an interesting technique. And then the last bit, like I skimmed through the threat landscape, which was like the second half of the report, and there were some interesting trends in there. Like they talked about click fix style attacks, so that whole fake CAPTCHA trick a user into copy pasting and running something on their computer. They said they grew 23 times in popularity between December of 2025 and May of this year, and almost all of them were used to deliver malware onto endpoints. They said that Teams vishing, so using Teams calls this was
Corey Nachreiner 46:08
one I was going to talk about. So yes, said
Marc Laliberte 46:11
volume went up by 502% That's crazy, and that 93% of attackers kept the target on the line for over 20 seconds, which is a long time, and that makes sense. This is an area that AI is very helpful in creating or copying personas to make it sound like it's Corey on the call telling Mark to go do some action when in reality. By the way,
Corey Nachreiner 46:35
related, I I definitely keyed on the voice phishing one because you and I both know, deepfakes with video and voice will get better. But they also mentioned in general there were 46 million plus business contact impersonation attacks. Meaning, besides the voice nature, people are finding real business contacts, maybe even the CEO of your company, and using that in phishing. It's it's increased quite a bit.
Marc Laliberte 47:01
Let's talk about that for a second, because what they're talking about in the report is actually coining an entirely new term. Like historically, we've talked about this type of activity under the umbrella of business email compromise (BEC) and what Microsoft is saying is there's actually two things going on in there, and we need to talk about them separately because they are separate issues. Up until now, business email compromise has both been someone pretending to be a CEO trying to get you to do something, and also someone that has actually compromised that CEO's email account and is using that to try and get you to do something. And so they're proposing splitting those, having business email compromise be like literal email compromise being used for social engineering, and this new BCI or business contact impersonation as a different category of technique, and that's the one where 46 using the
Corey Nachreiner 47:51
name, and they're using the name whether it's your CEO or someone you know on LinkedIn, but not necessarily. That doesn't mean they've been hacked. It just means they're trying to masquerade,
Marc Laliberte 48:02
and what they talked about in their report is exactly what we're seeing internally, like at WatchGuard Two, managing our security. Is most of these start out with just a very simple "Hey, do you have a minute? type of message, either over Teams or email or a text or
Corey Nachreiner 48:16
text. Yep, we're seeing a lot more text being targeted,
Marc Laliberte 48:19
and if you're not properly trained to spot it, and you see a text claiming to come from your CEO saying, "Hey, do you have a minute? you might be tricked into starting a conversation with them that ultimately turns towards something malicious, like, like maybe best case scenario, getting tricked to go buy a bunch of Apple gift cards and sharing the codes with them, or worst case scenario, completing a transfer of funds or giving up credentials to something important,
Corey Nachreiner 48:46
or somehow installing something later that gives them complete access to your company.
Marc Laliberte 48:51
Yeah, we've seen a just anecdotally an uptick in that targeting WatchGuard employees too. Internally, we've got like I would like to say very good social engineering training and awareness within WatchGuard. So we actually have entire Teams channels built around people sharing what they're seeing too. It's funny we have
Corey Nachreiner 49:09
an automated report mechanism, but they also want to just share. Yeah, which I actually think is good. They they have a button they can press that is enough that gives us everything we need, but they they like to talk about it and share it with each other on teams, so it's a level of culture and vigilance I like.
Marc Laliberte 49:26
Exactly, and like the simple fishes of just someone pretending to be Joe Smolarski, WatchGuard CEO, and trying to convince people into doing stuff are really on an uptick. And even with just recently hired employees, we had someone that's only been with WatchGuard a couple of weeks now. Report a fish claiming to become coming from Joe, so they're like actively monitoring social media of new hires. Maybe they updated their LinkedIn profile to say they're working here now, and immediately go after targeting them. And I think that's an important piece too. Like sometimes you give new. Hires, let's say, a month or 90 days to complete their security awareness training, depending on the company. Like the reality is, you need to make sure that new hires are trained up probably before they get access to any important systems. Like immediately after joining, that should be a day one thing because they are actively targeted immediately after joining. But like in Microsoft report, one other thing that stood out just for me to close, I guess, was they recommended fixing externally exposed vulnerabilities within 72 hours because of all the trends they're seeing and the mean time to exploit or mean time to weaponize just plummeting, and that's different than historically, even recently, what the industry would recommend of 30 to even 60 days in some cases is the amount of time you have to fix something external. Now it's three days is generally what you should do.
Corey Nachreiner 50:52
I have a couple more, but the good news is they're high-level business ones. I one of the things I thought was interesting when they talked about attack fruit to goals, government is now the most targeted sector at 27% which is up 10 points from last time. So they also talked about industrial manufacturing, telecommunication, and media-all the verticals. But apparently, government is now officially in their report the most targeted sector. They mentioned publicly facing applications exploitation of that rose 24 to 24% of incident response findings, which I thought was interesting. I won't get into the numbers, but part of their report had kind of a finding that cut against the grain. One was dwell time increased, as we talk about agentic attacks. In no mean time to detect and mean time to remediate are really important, and all of that is to cut dwell time. You don't want attackers sitting on your network for a long time because with agentic attacks they can take things fast. But apparently, dwell time has increased statistically significantly. Meanwhile, attacker activity duration has stayed flat, and the one other one, not super, you know, important, but I thought it was interesting because you and I, when we do our our quarterly, or I'm sorry, our our global threat report as we're releasing this year twice a year, it's out now. By the way, you guys can check. In fact, we haven't done a podcast on it yet, Mark. Maybe we should. Damn! But it's out now. We'll have a webinar on it soon. But one of the things we noticed is our our network attacks, which is based on IPS, is always old stuff. And one of the things they found is 58% of exploit detections is a six year old vulnerability. It was something I believe it was specifically one in something called Xero Login, which is not even. I mean, maybe a kind of popular app, but not the most popular. So they are finding old vulnerabilities, you know, being the thing that is targeted quite a bit, and at the end of the day, I also think they ended on, you know, that a lot of you know the most damaging intrusions they modeled were rarely depending on anything novel. They depended on fundamentals that were missing, like misconfigured, bypassable, just bad configuration, missing controls. So while there's a lot of scary news, and I the AI section is the most interesting to me, it's actually still the basic blocking and tackling. The last thing I might say, Mark, is in the report. I guess they didn't spend much time specifying channels, but they they talked a lot about critical sector and stuff like that. There was only one sentence that mentioned small to medium businesses, and no one ever mentions managed service providers. There, there was zero mention of MSPs or the channel, and we I've talked to to Andrew Morgan of Right of Boom about this in context of frontier models too, but all of these reports where they're focusing on critical sectors like water, energy. When it comes down to it, these are actually small businesses that tend to be state and local, and it's really managed service providers that are are the ones providing the security and the IT for this? A lot of the time, these companies don't have their admin reading this report because they're not even the ones providing their own IT, let alone anything else. So, I I would find it interesting if if Microsoft actually somehow focused more on managed security providers in their findings because those are the people that I think will actually fix this issue.
Marc Laliberte 54:49
Agreed, 100% So I mean, with that said, that was a maybe 5% overview of this giant report. So we'll keep digging into it, and if there's any other interest. Takeaways will definitely bring them up on a future episode. If you feel like reading through a 103-page report, definitely recommend checking it out. If you'd rather read through a shorter 35-page report, should also check out the WatchGuard Security Report, WatchGuard.com/securityreport, which we'll discuss on a future episode too.
Corey Nachreiner 55:20
And before we close, can I do one thing which we didn't do up front, but for anyone that is still listening, maybe some of you have dropped off. There are a couple really quick, interesting updates to last year's story, or at least interesting to me. Please take like one minute. Last year we talked about shiny hunters talking about how they popped the FBI and stole information, and at the time the FBI had not commented, but since then the FBI confirmed with the register, the register, which is a media organization, that it was tied to their FBI jobs.gov. So they've confirmed it, and they officially declared an internal cybersecurity incident, and a memo leaked about it to the New York Times, which shares details about the PII we were talking about, including things like psychiatric and drug test records. So it is pretty clear that the FBI breach was real. Shiny Hunters now says it will never publish. Don't know what changed, don't know why, but they say that there's still a threat actor. So I'm not sure how much you trust it, but that was interesting. And kind of a separate, related thing, by the way, the Dutch police confirmed the arrest of a 24-year-old Amsterdam man that's being held, which is the the man named by Krebs as the convicted extortionist. So interesting stuff. The only last thing is the whole remember the Australia Open AI sure do accidentally hacked you. There were four other agencies that have been named, but more importantly, there's it continues to happen. Canada has had similar things happen with the Library and Archives of Canada, and the Senate, you know, here in the United States, is is starting to open investigations around this type of thing to a task force in the Senate. Testimony has been announced that I, I think actually might, might happen very soon, and we've even seen our administration respond to this. By the way, apparently we can't call it AI anymore. We have to call it SI, according to the leader of our country. SI is the new name for AI? He had Google and Elon Musk and everyone else up with him when he claimed that.
Marc Laliberte 57:26
Did you see the signature line on that executive order and the title Unitas
Corey Nachreiner 57:32
States? Yeah, I guess does it count if it's not even accurately spelled for the country? And I didn't see that. Some super levels. Yeah. Anyways,
Marc Laliberte 57:44
but anyways, that I mean, maybe just to spend 30 more seconds on that piece, like it feels like something has to come of this because you like you can't just plead, oh crap, like oopsie, when you go and compromise now potentially dozens, multi dozens of organizations and government entities from rogue AI agents. Like, I don't know. There's got to be some accountability and some meaningful change or oversight that comes from it. Is my opinion now?
Corey Nachreiner 58:12
Yeah, was it the FCA also? I'm going to save some of this for impact because it comes from our guest Andrew Morgan. But the FCA also announced, like basically the same thing you and I talked about before. I, in my opinion, it technically broke the law, and trying to figure out who's accountable for that when it's an agent is interesting. And I think something does have to come from
Marc Laliberte 58:34
it.
Corey Nachreiner 58:34
But then also, we'll save this because maybe it's a discussion later. But how does insurance handle this? If every business is starting to use agentic AI, and we've seen the actual AI giants own models hack other people, what if you have agentic AI and one of your agents goes a little off the leash to follow something you told it, and it breaks the law?
Marc Laliberte 58:59
I'm assuming I agree. This is
Corey Nachreiner 59:00
not going to cover that. I don't think
Marc Laliberte 59:02
you're saying I don't get a oopsie get out of jail free card because it was AI and not a human doing it.
Corey Nachreiner 59:08
I don't think. I think you have to pass go and not collect $200, Mark.
Marc Laliberte 59:13
Dang, that's going to change everything I'm working on. But jokes aside, this is uncharted territory that needs to get charted at some point very soon because it's already happening. These attacks are already occurring, and now we're trying to figure out what it actually means. But that sounds like a question to answer on a future episode, I think. And yeah, I guess with that, by the time this publishes, see you all at WatchGuard Impact, and you're probably seeing us right on stage right now. That's exciting.
Corey Nachreiner 59:50
Best part of the day, I think.
Marc Laliberte 59:52
I think so too.
Marc Laliberte 59:56
Everyone, thanks again for listening. As always, if you enjoyed today's episode, don't. Forget to rate, review, and subscribe. If you have any questions on today's topics or suggestions for future episode topics, you can reach out to us on Blue Sky. I'm at it'smark.me. Corey's at SecAdept, and the both of us are on Instagram at WatchGuard underscore Technologies. Thanks again for listening, and you will hear from us next week.