A Live Stream From inside Lazarus Group – 2025-12-08
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.comJoin us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord!https://discord.gg/bhis🔴live-chatA Live Stream From inside Lazarus Group – 2025-12-08This BHIS episode blends cybersecurity humor, hacker culture, and livestream chaos as the team jokes about nation-state threats, leaked webcams, OPSEC mishaps, and technical glitches. With unscripted banter and light industry insights, it’s a fun, energetic listen for fans of ethical hacking, infosec podcasts, and behind-the-scenes security chatter.Chapters00:00 - PreShow Banter™ — Industry Leaders02:34 - A Live Stream From inside Lazarus Group – 2025-12-0804:24 - Story # 1: React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability08:58 - Story # 2: A Live Stream from Inside Lazarus Group’s IT Workers Scheme20:37 - Story # 3: Contractors with hacking records accused of wiping 96 govt databases26:44 - Story # 4: Apple refuses to pre-install government app on iPhones in India37:42 - Story # 5: Russia blocks Apple's FaceTime in mounting push against foreign tech platforms44:55 - Story # 6: ‘End-to-end encrypted’ smart toilet camera is not actually end-to-end encrypted57:53 - Story # 7: Flock Uses Overseas Gig Workers to Build its Surveillance AIBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
(00:00) - 00:00 - PreShow Banter™ — Industry Leaders
(02:34) - A Live Stream From inside Lazarus Group – 2025-12-08
(04:24) - Story # 1: React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability
(08:57) - Story # 2: A Live Stream from Inside Lazarus Group’s IT Workers Scheme
(20:37) - Story # 3: Contractors with hacking records accused of wiping 96 govt databases
(26:44) - Story # 4: Apple refuses to pre-install government app on iPhones in India
(37:41) - Story # 5: Russia blocks Apple's FaceTime in mounting push against foreign tech platforms
(44:55) - Story # 6: ‘End-to-end encrypted’ smart toilet camera is not actually end-to-end encrypted
(57:52) - Story # 7: Flock Uses Overseas Gig Workers to Build its Surveillance AI
--------
1:03:30
--------
1:03:30
Lawmakers Want to Ban VPNs - 2025-12-01
Register for FREE Infosec Webcasts, Anti-casts & Summits –https://poweredbybhis.comChapters(00:00) - PreShow Banter™ — The Problem With Extensions
(03:10) - Lawmakers Want to Ban VPNs – BHIS - Talkin' Bout [infosec] News 2025-12-01
(03:47) - Story # 1: Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)
(12:05) - Story # 2: Lawmakers Want to Ban VPNs—And They Have No Idea What They're Doing
(21:18) - Story # 3: Critical 7 Zip Vulnerability With Public Exploit Requires Manual Update
(25:48) - Story # 4: 'Slop Evader' Lets You Surf the Web Like It’s 2022
(37:07) - Story # 5: China’s Espionage in Europe is Deepening and More Sophisticated than Acknowledged, Expert Says
(39:10) - Story # 6: Apple Update Warning For All iPhone 17, 16 And 15 Users—Act Now
(42:38) - Story # 7: Meta is earning a fortune on a deluge of fraudulent ads, documents show
(50:22) - Story # 8: Meta had a 17-strike policy for sex trafficking, former safety leader claims
(52:40) - Story # 9: Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison
News LinksStory # 1: Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)Story # 2: Lawmakers Want to Ban VPNs—And They Have No Idea What They're DoingStory # 3: Critical 7 Zip Vulnerability With Public Exploit Requires Manual UpdateStory # 4: 'Slop Evader' Lets You Surf the Web Like It’s 2022Story # 5: China’s Espionage in Europe is Deepening and More Sophisticated than Acknowledged, Expert SaysStory # 6: Apple Update Warning For All iPhone 17, 16 And 15 Users—Act NowStory # 7: Meta is earning a fortune on a deluge of fraudulent ads, documents showStory # 8: Meta had a 17-strike policy for sex trafficking, former safety leader claimsStory # 9: Man behind in-flight Evil Twin WiFi attacks gets 7 years in prisonBrought to you by: Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
--------
1:02:47
--------
1:02:47
Shai-Hulud malware leaks secrets on GitHub – 2025-11-24
Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.comChapters and News Links(00:00) - PreShow Banter™ — Stressed about lithium batteries
(04:59) - Shai-Hulud malware leaks secrets on GitHub – BHIS - Talkin' Bout [infosec] News 2025-11-24
(05:57) - Story # 1: Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
(11:18) - Story # 2: CrowdStrike catches insider feeding information to hackers
(15:50) - Story # 3: NetApp sues former CTO for alleged data breach
(26:48) - Story # 5: CrowdStrike Research: Security Flaws in DeepSeek-Generated Code Linked to Political Triggers
(36:05) - Story # 6: A major Cloudflare outage took down large parts of the internet - X, ChatGPT and more were affected, but all recovered now
(37:11) - Story # 6b: Cloudflare outage on November 18, 2025
(41:43) - Story # 7: Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt
(46:34) - Story # 8: This Hacker Conference Installed a Literal Antivirus Monitoring System
(51:10) - Story # 9: Microsoft to integrate Sysmon directly into Windows 11, Server 2025
(56:40) - Story # 10: Crypto and Carcasses: Undercover Sting Recovers $700K in Bitcoin Miners, Foils $75K Frozen Turkey Heist
Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/
--------
1:05:01
--------
1:05:01
A.I. Transcription Startup Was Just A Guy Taking Notes- 2025-11-17
Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00:00 - PreShow Banter™ — The Way the Community Rumbles00:08:21 - A.I. Transcription Startup Was Just A Guy Taking Notes - BHIS - Talkin’ Bout [infosec] News 2025-11-1700:09:01 - Story # 1: New data shows companies are rehiring former employees as AI falls short of expectations00:18:06 - Eric & Whitney’s “Podcast” [webcast] on training your own LLM00:22:12 - Story # 2: Founder Admits His “AI Transcription” Startup Was Just Him Joining People’s Meetings and Taking Notes by Hand00:26:20 - Story # 3: Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies00:37:35 - Story # 4: Google is easing up on Android’s new sideloading restrictions!00:43:44 - Story # 5: Google is collecting troves of data from downgraded Nest thermostats00:44:58 - Story # 5b: Hackers are saving Google’s abandoned Nest thermostats with open-source firmware00:51:34 - Story # 6: FFmpeg to Google: Fund Us or Stop Sending Bugs01:00:40 - Story # 7: Teens are Hacking School Systems. Let’s Teach Them to Protect Communities Instead01:05:55 - Story # 8: Disrupting the first reported AI-orchestrated cyber espionage campaign01:14:58 - Discord CTF Winners
(00:00) - PreShow Banter™ — The Way the Community Rumbles
(08:21) - A.I. Transcription Starup Was Just A Guy Taking Notes - BHIS - Talkin' Bout [infosec] News 2025-11-17
(09:01) - Story # 1: New data shows companies are rehiring former employees as AI falls short of expectations
(18:05) - Eric & Whitney's "Podcast" [webcast] on training your own LLM
(22:12) - Story # 2: Founder Admits His “AI Transcription” Startup Was Just Him Joining People’s Meetings and Taking Notes by Hand
(26:20) - Story # 3: Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies
(37:34) - Story # 4: Google is easing up on Android's new sideloading restrictions!
(43:43) - Story # 5: Google is collecting troves of data from downgraded Nest thermostats
(44:58) - Story # 5b: Hackers are saving Google's abandoned Nest thermostats with open-source firmware
(51:33) - Story # 6: FFmpeg to Google: Fund Us or Stop Sending Bugs
(01:00:39) - Story # 7: Teens are Hacking School Systems. Let’s Teach Them to Protect Communities Instead
(01:05:55) - Story # 8: Disrupting the first reported AI-orchestrated cyber espionage campaign
(01:14:58) - Discord CTF Winners
--------
1:16:33
--------
1:16:33
Louvre’s Video Security Password Was ‘Louvre’ 2025-11-10
Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com Chapters00:00 - PreShow Banter™ — Humans are Done03:04 - Louvre’s video security password was ‘Louvre’ – BHIS - Talkin’ Bout [infosec] News 2025-11-1005:11 - Story # 1: I Tried the Robot That’s Coming to Live With You. It’s Still Part Human.15:14 - Story # 2: How to trade your $214,000 cybersecurity job for a jail cell25:14 - Story # 3: The Louvre’s video security password was reportedly ‘Louvre’29:04 - Story # 4: Dangerous runC flaws could allow hackers to escape Docker containers32:58 - Story # 5: List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities40:00 - Story # 5b: GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools56:37 - BHIS Webcast – X-Typhoon - Not your Father’s China with John Strand
(00:00) - PreShow Banter™ — Humans are Done
(03:03) - Louvre’s video security password was ‘Louvre’ – BHIS - Talkin' Bout [infosec] News 2025-11-10
(05:10) - Story # 1: I Tried the Robot That’s Coming to Live With You. It’s Still Part Human.
(15:14) - Story # 2: How to trade your $214,000 cybersecurity job for a jail cell
(25:13) - Story # 3: The Louvre’s video security password was reportedly ‘Louvre’
(29:03) - Story # 4: Dangerous runC flaws could allow hackers to escape Docker containers
(32:58) - Story # 5: List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities
(40:00) - Story # 5b: GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools
(56:37) - BHIS Webcast – X-Typhoon - Not your Father's China with John Strand
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET
https://www.youtube.com/@BlackHillsInformationSecurity
Brought to you by Black Hills Information Security.
https://www.blackhillsinfosec.com