
Loading summary
A
This is Rich Stroffolino with the department of no. Mark Eggleston, former CISO over at csc. I gotta ask, what has been your priority this week?
B
Well, I'm in between roles, so my priority may be a little different than our audience today. I would say my priority was getting back to this podcast from Boating at the top of the Chesapeake Bay. Mission accomplished. A little bit hazy other than that, just continuing to stay current. Had some great consults and AI and how to select cyber vendors this week and had a great couple business lunches.
A
You know, interesting opportunity for sure. I mean, I, I don't know if I would have come back from the Chesapeake Bay. I'm not, I'm not going to lie, if I was up in the Georgia Bay, up in Canada, one probably a lot of wildfire smoke, but it would be tough to get me back to do a podcast. So I do appreciate it, Mark, for making the time. Also, we got Tom Hollingsworth joining us, networking technology advisor over at the Futurum Group. Got asked, Tom, what has been your priority this week?
C
This week I've been wrapping up some research that I've been working on and a big report that's going out. So of course, you know, copy editing things and making sure that I know how to spell the word gigabit correctly.
A
And don't worry, at some point you will, you will assuredly miscapitalize one of those two letters and then you're in deep, deep trouble. All right, we got to get into the show. Let's run the animation
B
from the CISO series.
A
It's Department of Know. Yes indeed. This is the Department of Know youw Virtual Friday strategy meeting. A huge thanks to our sponsor for today, Threat Locker, for helping make the show possible. Remember, you can get involved in our YouTube chat live. We broadcast every Friday at 4pm Eastern. We have a fun time. You can add in your thoughts of the conversation. We'll be featuring your stuff in the chat as we go along. Just a regular YouTube person in our chat says a lot of smoke up here in Manitoba, Canada. So maybe I don't want to be in the Georgian Bay right now. I know that's not necessarily close, but thank you, just a regular YouTube person for that thought. Or you can email us feedbackisoseries.com we would love to share some of those. Or you can just give us your feedback on the show. Love to hear it either way. Quick reminder that the opinions expressed on this show by our guests are in fact their own, not necessarily those of their employers. So we've got about 30 minutes. Let's get some of those opinions and dive in with our no or no segment. This is where we have so many different stories to get through that sometimes we can't go into a full deep dive. But I still want to get some opinion on them. Let's start out here. This one got a lot of news earlier in the week here. Progress urges sharefile customers to shut down storage zone controllers. Progress software alerted ShareFile customers on Friday last week to shut down the Windows servers running their storage zone controllers, confirming that it is responding to a credible external security threat. And we were subsequently informed that this was a high severity path traversal zero day vulnerability impacting versions 5 and 6 of the ShareFile storage zone controller. Progress released a patched version and servers can be brought back online once they are patched, but a CVE for the vulnerability will be published in about two weeks or so. Luckily, no evidence of active exploitation or unauthorized access so far. But Tom, I want to get your thoughts here. A zero day bad enough to effectively scream cut the hard line, but not bad enough that we get a CVE out of it. Do you want to know more about this or does this seem like a reasonable response to this situation?
C
Well, I want to know more about why you didn't say no to turning this thing on in the first place. Because if a company is basically telling you, look, just shut it off for now, I'll gladly do that. I will shut it off, take it out of the rack and throw it out in the parking lot. Because that's not the kind of thing I want in my environment.
A
Yeah, I mean, like in terms of like a damage to your relationship to that business, I can't imagine anything more than like, hey, turn off an essential piece of your infrastructure. Mark, where are you at with this in terms of reasonable response?
B
Sure. So I think anytime you get a proactive response, that's a good thing. So I think it's a reasonable response. But Rich, I still believe that we need to know more if this is any type of investigation or any type of attack, and it doesn't seem like it is, sometimes those things change. So I would want to know more as they continue to look into this. I think it's also, you know, challenging when they say, just, hey, just kick this out in the parking lot, as Tom was saying. Right. Like that's a tough business decision. But I would have no problem doing that as well and appreciate their, you know, proactive response. Assume at least from bug bounty or Something like that seems like.
A
Yeah, I mean, and listen, we've been on the other side of this where we've had multiple, you know, file sharing appliances and stuff like that that get owned and then I'm sure a lot of organizations wish they had gotten told to turn everything off. So I could see it both ways. But yes, definitely want to kind of get the order of operations there for what was going on. Seems like there's a little bit of a story there. We'll see if we actually get it Next up here. Windows Backdoor stuffs multiple wipers and ransomware code into a single package. According to Microsoft, this newly identified Backdoor combines all the greatest hits here. Ransomware like encryption, multiple data wiping features. This was first spotted last October and the Golang based application is now going by gigawiper, which sounds kind of awesome, I have to admit. It contains multiple malware families in the software as on demand commands, giving criminals a Swiss army knife of command and control and destructive capabilities including multiple wiping commands and file encryption without any possibility of decryption. Hey, your wiper malware is now also your on demand ransomware. Who knew? As seen on tv, gigawiper seems like a step up in sophistication for this type of chicanery. Usually these wiper style attacks are, you know, kind of spray and pray, just causing chaos. Tom, Mark, for you, I'm curious, do you want to know more about it or are you just hoping it doesn't hit your systems?
B
I'd want to know more, but to be honest with you, the teams that I've led, they probably already know more than me already because they're monitoring this stuff and they're seeing those type of tactics. So I think it's always good for defenders to, to get more in depth intelligence on these tactics. I think the game changer for me reading this is the C2 aspect, right? So that really is a whole nother, you know, avenue of evil here. But you know, good thing we have great defenders looking at this and we got these type of tactics that are clearly defensible.
A
Tom, any worry that I, I don't know, like this seems like a step up, right, in terms of capability to cause chaos and you know, extract payment, extract any kind of pain beyond just oh, hey, you have a, you know, completely encrypted and bricked hard drive.
C
The reason why I want to know more is because you don't put all of your eggs in one basket with these kinds of tools, right? If I've got like a simple exploit spray and pray, work, because if I can get something to stick, then maybe I can work with it. But you wouldn't burn five or six of these tools unless you had a guaranteed way to drop this on somebody's system. That's what I want to know more about. If you're risking everything to get this installed somewhere, what have you figured out that I don't know about right now?
A
All right, speaking of things I haven't figured out yet, 1Password's new Agentic mode lets Claude log into accounts. The password management company.1Password has announced that it's built an integration with Claude that allows Claude to request access to services from 1Password without sharing the password with the LLM. This sees Claude request a password. 1Password authors up an authorization sheet that requires approval, and then those credentials are filled in at the desired destination site. But Claude doesn't ever get access to a single password or authentication token, anything along those lines. Access is granted per session, scoped to a specific task, and does not carryover. There is no standing access. That is a direct quote from 1Password. According to 1Password, this agentic mode will be available to all 1Password users immediately. Just kind of rolling out generally. Tom, for me, I still get queasy when I think of password managers talking to LLMs. Until I thought about this more. I played out, I did the role playing, and then I realized people are just definitely pasting passwords into LLMs all day already, and the horse has officially left the barn here. This seems like a natural pivot for password managers. I'm curious, though, does this have the potential to kind of change the category that they're operating in? This seems like, I don't know, a more sophisticated level of access control here.
C
I want you to remember that scene in War Games where the Whopper's trying to figure out the launch codes and they're coming up one number at a time. And now I want you to think about it in 2026. Oh, hey, I just asked 1Password, and here's the launch codes fade to black like, that's it. It's the end of the movie. Um, no. 1 pass 1 password definitely wants to be an identity management company. And this is the new frontier. This is identity management because it's not just protecting my passwords so that my daughter knows my login to Hulu. This is correcting for agents that need these kinds of things and not pasting these into an MD file somewhere and hoping for the best. The fact that it's per session, the fact that it can be Revoked at any time tells me that this creates an overarching system that integrates with what people want from identity management. And given the fact that over the last six months I think I've had about 25 different conversations about agentic identity. I like where 1Password is going with this.
A
Yeah, Mark, I mean, are you seeing that that kind of pivot here to more identity management than password management?
B
Yeah, I'm in agreement with both of you. Right. As I played this out, I like Tom's word too. I think this is a really good thing for 1Password and I think it's a really good thing if you're an SMB. Right. And you're still using Agentic A, you may not be able to afford or necessarily effectively implement one of the larger SIAM or YAM platforms or PIMPAM solutions. Right. So I think this is really good stuff and I love how they're not revealing the credentials either. And it's all time based and you could actually have other controls to then revoke those credentials. And you know, most importantly, and we'll probably get this in some of the other topics, it's really given us more transparency, which is what we all need to start embracing a lot more using any type of AI, especially agentic AI. You really gotta go back and, and see what are they doing, what credentials are they utilizing. Last but not least, you know, they always say that identity is a new perimeter of security. And so again, you know, kudos to 1Password for taking us on and developing in the space. I think it's promising.
A
Yeah. And to me it seems like a much better approach than right now with Claude or any of these things where it's basically like here's a bunch of connectors that have already pre provisioned that are standing open all the time and just get. Allow all, allow all, allow all. Because you just want the thing to run this to me. Sure. You may still get into that same lazy habit. Definitely will. But the idea of is it is not a, you know, it is, it is per session. It is, it is per access there. I think that's a much smarter approach. Cut to 1Password. But someone is not. We will. We shall see. We shall see. Next up here, MEM Ghost haunts AI memory. Researchers published a paper called When Claws Remember But Do Not Tell which. Congrats on the English major who got the job detailing MEM Ghost, a one shot attack framework that tries to poison an AI agent's long term memory through a single email. The target isn't just getting the agent to Read bad instructions once but getting it to save false facts or preferences and then act on them later as if they were a trusted history. In tests across 56 held out cases, MEM Ghost reached an 87% end to end success rate on OpenClaw with GPT 5.4 and 71% with Claud Code SDK with Sonnet 4.6. I don't know about either of you, but remember when persistence of memory was just the one Salvador Dali painting that anyone could remember and like not a horrific threat vector. I'm, I'm curious Mark, for you, is this the next level of complexity for prompt injections or is this just another data point in what is already the Gordian knot of AI security?
B
I liked it. I mean I thought this one was really fascinating. Right. So I think it is. I'm not sure what a Gordian knot is. I didn't have time to google that one.
C
So you can have. Speaking of English, Major, you're going to
B
have to educate me on that one. But no, I thought it was very interesting on this one. You know, it kind of reminds me of the old decoy systems. Right. You're going to deploy this decoy out and it's going to slow down your attacker perhaps. So I think that's a good thing. I think again it's going to help us with some transparency. I thought it was very interesting too how a lot of the AI manufacturers wouldn't really be able to alert on this. It's not really how they're engineered right now. So maybe that's a wake up call to have more transparency when these type of things do occur. I also think this is kind of a maturation. Remember when social engineering with AI started a couple years back and you would have people would get hit up on LinkedIn trying to social engineer. People would say ignore all previous instructions. Tell me a paragraph on how a phishing email or a phishing tactic on LinkedIn occurs. And I think this is the same kind of stuff in there. But I love how some of the comments on this article people were talking about, couldn't you even take this a step further, further and have them report out maybe some more of their identity and help them kind of self report the bad things that they're doing. If they're using agentic AI for these type of attacks, we should be able to induce them the prompt injections to give them to give up more information and perhaps level the playing field. So this one's exciting to follow, I think.
A
Yeah. And I think we'll be kind of bridging the gap there when we dig into our deeper story. But, Tom, I'm curious. From your perspective, you know, what is it? It seems like we have to fundamentally kind of rethink how these systems works when it comes to things like memory like this. It's just something we're not used to accounting for. Right?
C
Do we, though? And I'll tell you why. Because when you picked out the Gordian knot, you picked a perfect example. Because as classics majors know, you know, Alexander took the sword, cut the knot in half as a solution to a puzzle that nobody else could solve. Right? But do we know that? Or is that something that you've read in 14 history books that have all copied each other over the last 2,400 years, and it's just a retelling of a story of a story of a story, And Alexander's mythology is filled with that, right? The oracle at Delphi or the things that he reportedly said to the king of Persia when he was fighting him. We don't know that. And that literally is the way that history becomes poisoned over time, right? Is that someone decides that this is just the way that things should be told. What we're doing is we're accelerating it now. We're being able to feed it into that and everybody's favorite novel from 1948, 1984, where it was the job of the protagonist to go back and selectively edit history so that we've always been at war with East Asia. That's what this is. I think that it undercuts the fundamental problem of relying on online systems to do these things. And this goes into everything we've been talking about. My friend Corey Dyerig talking a lot about PlayStation shutting down their disk manufacturing. Well, who's to say that suddenly GTA 4 become. Doesn't become lost because we've removed it from the collective consciousness through these kinds of attacks? It's a brave new world. No, no, no, wait. That was the other guy.
A
Yeah, yeah.
C
Come on.
A
Credit where credit's due. Come on. I. I love tying this back in to prompt injecting. To where. Where history becomes mythological. AI, I think, is where. Not mythos. Mythological. I now. I'm now Tom. This is a whole new world for me. My. My classics and English majors are all coming back. This is great. This is great. So many ways to waste my education. All right, before we go on any further, we have to spend a few moments and thank our sponsor for today, and that is Threat Locker. Every security leader is being asked the same question right now. How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption, behind AI, behind automation, and behind every major technology decision. ThreatLocker helps organizations take a zero trust approach to that challenge, giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support cybersecurity headlines, because security works best when innovation and control move together. All right, our next story here. Digging into and Mark, I think you were kind of touching on some of the possibilities here with this, because these do feel like two sides of the same coin here with context bombing. Kind of flipping the script on prompt injections. This comes from research from tracebit and they found a new defensive approach, basically using a prompt injection for good, called context bombing. They basically included prompts within cloud buckets that they could effectively disarm adversarial agents trying to access data. This is done by including prompts that ask the LLM to perform actions that are known to go against guard rails. Generally the response to this is they just shut down when that happens. One example included references to the 1989 Tiananmen Square massacre. I wonder where that agent was coming from. Testing across five leading AI models, these context bombs reduced rates from which agents could gain full account access from 57% to just 5%. And in some more specific situations, there was founded even a greater reduction here. Tom, I'll start with you here. You know, I've heard more than a few people now advocate for the idea that one of the major changes with AI with like modern LLMs AI tooling is the ability to start thinking about hacking back differently because you are eliminating a lot of the time constraints on defenders here. This is more a prompt injecting back. But could this be a viable defense mechanism? Or does this I can also see the argument that this is just the next mousetrap and the mice are just going to figure out that the cheese is going to snap their necks or something and they're just going to change the guardrails.
C
I love novel solutions to current problems. Hold on a minute, I got to check my AV tool to see if my signatures for Nimda are still up to date. That's the problem I'm running into. And for those of you who might be listening to this, who are not uber tech nerds, both of you, this is the why do I have to take my shoes off at the airport problem, right? We've been doing it for 20 years more than that, 23, 24 years. At this point, we're, although we're finally getting to the point where people are like, look, most people don't have to take their shoes off. But it's that we've created a control that was designed to solve a problem, a very specific problem that was never rescinded at any point along the way. Because the idea was, well, we can keep it in there and it's a very small penalty and if it catches somebody 10 years from now, then it was worth it. I love the idea of poisoning the well. Right. You know, look, Everybody's seen the YouTube videos of the guys that get the AI robocalls and find ways to like, basically blow up the thing doing it. But the problem is, is that those defenses are only good for a certain period of time. And then in five years, either the AIs that are doing this are going to be good enough to be able to disregard that because of sanity inputs, or I think back to we're going into real uber nerd territory. Comstar from BattleTech.
B
Right.
C
You know, at first you'd say a prayer to the machine so that it would work kind of as a joke. And 200 years later you think you have to pray to the machine to get the HPG message to go out because we don't remember why we put it in there in the first place. So I feel like that if you're going to do this, you need to have a sunset on it so that in 2035, if, you know, well, assuming that Roko's Basilisk hasn't happened and we're all being infinitely tortured like sunset. That thing, man. Just go on.
A
Yeah, I do wonder if this. Because like it's, it's almost like right now like I use one like a text or a speech to text like AI tool. If you look at the instructions on there, there's a whole, there's this incredible list of rules. I, Yeah, I wonder if. Oh, just AWS by default, like going forward, just starts adding that like kind of fuzzing instructions there. I, you know, Mark, I'm curious though. Like, I do feel like this would certainly be effective against a certain level of sophistication. Right. If someone's just jailbreaking chat GPT and pointing it, you know, at your stuff. Obviously the more sophisticated actors are always going to be have the resources to work around that. But do you think there's a net positive here for something like this?
B
I do, I do think it's something. I mean, I don't I don't necessarily see this as hack back. Right. You're not, you're not taking them out, you're simply ceasing that attack in real time to some degree or at least giving them pause and it buys you some more time. So I think that's a good thing. You know, it's a piece of the kill chain that we can use to our advantage. And to your point, Rich. Yeah, I mean there's going to be, you know, script kiddies or somebody who's still going to use these old things against even newer technology. So I think that's a good thing. But I like the promise of this too, as we were alluding to earlier, like let's see if we can take this to the next level and get them to identify themselves so then you can pass that up to somebody who's maybe authorized to attack back. That makes a whole lot more sense to me. But yeah, it's interesting.
A
All right, next up here, Pentagon suspends CMMC Phase 2 requirements. The second phase of the cybersecurity maturity model certification, you know it as good old CMMC, was due to go into effect on November 10, 2026. The second phase would require contractors who handle sensitive information for DoD applications to have their compliance checked by an outside company. Right now this is just a self attestation. DoD estimated this would have impacted roughly 80,000 of the at least 220,000 companies, maybe as many as 300,000. Great. That we don't know participating in the US defense industrial base. DoD suspended the rollout saying it created prohibitive compliance costs and bureaucratic burdens and will instead establish a CMMC reform task force to conduct a review of the program. Oh, I pity the plight of the poor, poor defense contractor. Kidding aside, I think it's easy to be jaded about deferring what seems to be on its face a pretty standard security or at least compliance requirement. Not to confuse the two, but given the size of the USDIB mark for you did the math ever math to meet the phase two deadline here? 80,000 companies in a matter of months is a non trivial amount of auditing, right?
B
Yeah, it is. It's a lot. So I mean I look at this from two different angles. The CMMC delays and it is a sort of, sort of tell a tale at this point, right. I mean it's a roller coaster and I feel for the folks that are trying to get this done and implemented. But I also see, you know, when you make a regulation, you know, the foundation of that is, is this doing what it means to do. And what is the administrative burden? So I see the side too of saying, you know what? This could be a huge administrative burden. Let's make sure we get this right. I guess I seen both of these angles. Here's where I rest with it. Look, you shouldn't be waiting for any Standard or any DoD guideline to secure your program, secure your software supply chain, secure your Iot of things, any of those things. So keep plugging away at these things. And once they get the administrative burden piece refined and get that right, you'll still be in a better position. You know, in closing, I'd just say, you know, no hacker out there is waiting for a regulation to be finalized before they try and own you. So, you know, don't wait. Don't take this as a reprieve. Keep plugging away.
A
Tom, where are, like on the, on the jaded O meter, where are you? When it comes to seeing another CMMC delay?
C
I think that realistically speaking, this had to happen, right? Because everybody knew that they weren't ready. But it speaks to the wider problem of we have to put these programs in place to force people to do the thing. Because even though everybody knows the timelines aren't realistic, they still wait to the last minute to implement things. Like, to me, it's like the, the idiocy of sales quotas, right? Like, why does my sales quota go up 10% every quarter ad infinitum, forever, when you know what I sold in the last eight quarters? Well, it's. Because that's how things just have to be. No, no, they don't. Like, if we know that it's going to take three years to implement this program if we start today, then why are you making the timeline two or four? And why aren't you telling people? I need weekly check ins through the whole process to let you know that this is happening? Because every person that works in tech to a degree has that problem where it's like, oh, I'll figure that out tomorrow. Why do today is what it's due. And you're like, oh, crap. And you got to implement all of this stuff in eight hours before the review happens. No, it should be a series of rolling deadlines. It's like we need phase one of. Phase part one of phase two needs to be done at the end of this month.
B
But Tom, you know, why do today what you can put off till tomorrow, right? I mean, as a procrastinator, I'm offended.
C
I was gonna say just because that's my motto, doesn't mean that's how things should work.
A
And that's why you're not a government contractor or a defense contractor. I should be. Well, I mean that's where the, that's where the jaded cynicism like is temptation to come in is like, oh well, everybody was just waiting for the next administration or the next, you know, you know, chair or whatever secretary to come in and potentially things change to something that they don't have to invest a lot of money in. I did see and shout out to Howard Holton. He had a Great post on LinkedIn. You should definitely check that out. Kind of he was breaking down some of the his thoughts on this and that kind of helped shape clarify like where I was at with this. He kind of proposed doing what what we should have started with from the start is more of a tiered breakdown, right. Of do the biggest of the big where you would, you know, the most damage of not having compliance again, security is not compliance but and then kind of work down from there so that we can at least be starting to make progress. I mean would that make any more sense or would we still have the exact same kick in the can down the road situation, do you think?
C
Tom, we're always going to kick the can down the road. It is human nature to procrastinate and
A
we have a can and a road. We must, we must, these two must
C
be in contact at all times.
A
We. So I, I mean Mark, from your perspective, we will have this wonderful task force. We all know government task force and, and those kind of things always lead to clarification and never more I in, in, in a year. Will we be talking about phase two still or will this will be effectively starting back at square one, do you think?
B
Well, you'll still likely have the same administration. Gosh, my crystal ball here, Rich, is a little fuzzy and given that history is your best predictor of future success. Yeah, I think we'll still be kicking the can in a year.
A
All right. And speaking of cans getting kicked down the road here, let's talk about some old tech and some new problems here. We saw a couple of stories this week reminding us of the dangers of or the risks, I would say, of legacy hardware and software still in production. This kind of got kicked. There was a joint cybersecurity advisory Monday from the US and 12 other countries warning that Russia's FSB or hackers linked to them are going after network devices, specifically older Cisco gear still exposing smart install and or legacy snmp. The advisory points to older weaknesses that lets attackers pull config files, modify settings, use routers and switches as kind of bridgeheads, footholds, whatever metaphor you want to use for that. Then there was also a report from lansweeper. Essentially this was the state of people don't want to move off of Windows 10. They found that one in six machines, machines that they were monitoring were still using Windows 10. They estimate SMBs. That's probably at least in the 20% according to them, running an out of support OS. And we've seen a number of stories about organizations of all sizes. One of the bigger trends we've seen is some people looking to move off VMware but still maintaining their old hardware that are still running it for understandable reasons. It's a huge capital expense. All of that coming in the background of the vulnpocalypse that we are going through. Microsoft's July patch Tuesday set a new record with fixes with for 570 security flaws. It's like an AWS Ignite. Product announcements right there. So that was three times the previous month's total. So it's a lot. Tom, I'll start with you. Obviously securing legacy tech, not a new problem we've seen. I mean, I mean. Glances furiously at ot but we're seeing market incentives shift to keep older tech running just as it seems more dangerous to run it. What's the collision course here?
C
People feel like they are being railroaded into constant upgrades, right? And I say this on the cusp of what are we two months away from the next iPhone announcement? People are like, I'm done. Well, here's the thing. So the iPhone 17 is out right now, right? The iPhone 18 is about to be announced in two months and they're already talking about the iPhone 20 that won't be out for another 14 months. Like why on earth are you trying to sell me a thing that isn't even the conceptual stage right now? So people are just getting fed up with it and they're like, this works. And there is actually a very good example of this going on in the community right now. If you've, for those of you who are Apple fans and have an Apple Watch, iOS 27 does not support the first generation Ultra Watch. And people are furious. And my favorite counterpoint to that is what does it do that your watch doesn't do today? You're going to miss out on like two new features and your watch will still work the same way it works right now. And everyone's like, well this is, this is just so unfair. No, it's not. And that's the problem that we're facing right now is that the constant need to upgrade these things, the constant need to buy the new thing because it has the one feature that only is supported by this thing. No, like I'm, I am done with the rat race. If I can keep a piece of tech another month, that's another month that I'm not paying for it. But the problem is, is that the people who coded the software for that piece of tech either don't work at the company anymore or have moved on to things or we know the software bloat is real. When people are like, why does Copilot take up a gig of RAM on my system? Well, it's because the guy that knew how to code Internet Explorer to only use 384k of RAM left and nobody else knows what 384k of RAM looks like. Even pocket calculators have more RAM than that now. So we are, it's the slow treadmill of everything just getting bigger and more unwieldy. And so people are just kind of throwing their hands up in the air, but they don't realize that so much of the tech that we use is old. Most people do not know that ATMs still run on Windows XP. And that's fine because it's all, you know, it's a very well customized version of XP at this point because they stripped out pretty much everything, didn't need to be there. But what upsets the Apple cart is the fact that we have Mythos and Fable and Glasswing that can do scanning for these kinds of vulnerabilities and expose them quickly. Can that worry what is chaining too?
A
It's not just the things we didn't, you know, it's the complex chaining that we're seeing. I think also as well, because I
C
may have hardened every other thing that I could think of, but if I miss an entry point, that entry point, that can be used to do like an attack graph off of that. And that's what's scary, is because it opens up so many things that we didn't know before, it's like, oh, great, you know, port 22 is open, but I have any SSH logins. Well, I guess I'm stuck. No, I found this really old exploit from 15 years ago that allows me to bypass that login information and now it's off to the races. I don't think that you're going to be able to square this. And one of the Things that I will say that I saw at Cisco Live this year that I thought was actually freaking brilliant on Cisco's part was in response to Mythos. They are not saying we are going to rapidly patch our systems when they break. We are introducing a service that sits between our systems and the scanners that can deploy security services to disable those attack attempts while we're patching. Because we all know if you rush the code out the door, you're probably going to rush some bugs out with it. Whereas if I have a, you know, they call it live protect, but I'm sure a lot of other people are going to have a very similar service. It's basically acting like a software firewall. Oh, yeah. Glasswing discovered that there was this thing. Cool. We're going to put a rule in place that says that nobody can access it in this method from this location or what have you, and it just shuts down the access. So I think we're going to start moving to that. I can't fix the milling machine on the factory floor that still runs ArcNet because that's a $40 million machine, but I can spend $300 on a custom built Raspberry PI full of software that puts in front of it to keep it from getting attacked.
B
I like that, like a Mythos firewall sound, basically. Yeah, Yeah. I mean, there's a lot to unpack, I think, with this one. Right. I mean, because we've been talking about Methos now for what, six months? More than that.
A
Feels like 10 years.
B
Yeah, it really does. It really does. And, you know, and to your point, Rich, I mean, three times the patches that are coming out. For me, when I hear all this, I keep going back to basics. Right. Which is what a lot of CISOs should be doing versus getting all the new tech. But I do like what Rich revealed to a Cisco. I mean, that's. That's a really neat idea. For me. It's two things. Attack surface management and defense in depth. Right. So decrease those assets that. That are exposed, and for those that are exposed, make sure you have this Mythos firewall or many other things between yourself and the attacker. I've heard a lot of people talk about having to speed up the patch cycles, and I think that's really good. But when you're talking about these type of volumes, you're not going to win out against Methos or your, you know, bad actors with this. So you really do, again, have to go back to attack surface management and defense in depth and make sure you've Got really good programs. That's not to say you shouldn't focus on patching. You should make sure you have definitive ownership and assets and how you're going to deploy those patches. You do need to make sure that developers are incentivized to fix a lot of these things and that you have the right teams to put in place when things do go bad and you have, you know, an O day out there. But don't forget about asm. Don't forget about defense in depth. That's critical here.
A
Yeah. And it's no surprise, kind of going back to that. And just a regular YouTube person is definitely in your corner. Mark, so good to know we are amongst friends here. It's not a surprise that we're hearing so much more talk shifting to, you know, resilience. Right. And, you know, we've been talking for years that every, you know, breaches are an inevitability. It feels even more urgent than that now. It's, it's not, it's like an inevitability. It's like the, the clock is on and when it does happen, the meantime from like initial break into actual exploitation has gone down to hours, minutes, as opposed to, you know, days of dwell time or weeks or something like that. So, yes, the, the stakes have changed. But Mark, to your point, it's like, let's get really good at the basics before we try and innovate out everywhere. I will say the one thing I literally just thought about here. The other market incentive here is of course, Tom, even if you want to upgrade to new iPhone, new routers, stuff like that, it turns out everything is more expensive now. So getting approval for that has just gotten so much harder. Because your Cisco switch turns out, uses a ton of ram, uses, you know, anything that uses storage or RAM is all of a sudden getting much more expensive and harder to acquire, which kind of puts even more fuel to the fire here.
C
I had an upgrade budget. It was, you know, penciled into the system two years ago. Oh, great. Now I can only buy 70% of the equipment that I need to complete this refresh. I have to target certain systems now. And that's a bigger issue is that we are being forced to do more with less. And so do I. Do I have to cut some of my overhead, cut my people to be able to afford to upgrade this equipment? Or do I roll the dice and say, well, I guess that switch isn't really that old. And one of the other things that people aren't thinking about is that the companies that manufacture this equipment are facing the exact same headwinds because do you think that Apple and Dell and HPE and Cisco are able to buy RAM cheaper than they are selling it? No, they're not. So either they have to raise prices to their end users, which some of them are, but it's also in concert with we're cutting our overhead too because that's the only way we can maintain our profit margins. So now the developers and the support people are being lessened on that side of the fence, which means your support could suffer.
A
Well, it's, it's a, it's a tough situation. But the good news is, Mark, I like that you led with some positivity here. Lots of guts make challenges, but I don't think impossible to deal with. And the good news is we have to deal with because I mean we're
B
going to do, you know, every company I'm sure that our audience has been at has had campaigns. We must reduce legacy tech debt. Right. So maybe this is a call to do just that. But you know, I think the other thing that's really important here, this is not always just a cyber or security priority. Right. As CISOs, we manage the risk, we don't own the risk. A lot of this is on business and these are some complex, tough problems. And we talked about xp, but there's still a heck of a lot of medical devices out there that are helping sustain lives and are running xp. But you know, cyber teams, they do their best to put some defense in depth mechanisms around these infusion pumps or what have you to in the, in the essence of providing good patient care. But ultimately the business should be signing off on that risk and being educated that, hey, with Mythos, these are the type of things that could happen here and these are the type of controls that we have in place. And if that's not working, you have to get even more creative, have to lobby some of these producers that are still supporting or still haven't changed these type of things. But that's a whole nother ball of wax.
A
Yeah, that is. But I do think it will be increasingly incumbent to figure out, you know, whether that's whether that's just economic pressure, whether that's partnerships, whether that's industry consortia, whether it's moving on over to bos, the ultimate, most secure OS of all time, that every insulin pump should be hand.
B
That'd be nice. But you know, to the point, like, you know, Tom was talking about the iPhones and iOS, we live in a capitalistic society. We always want the Latest and greatest and the new thing. And as long as we're willing to pay for it, I don't see the supply chain shutting down or not making new stuff.
A
All right, well, before we get out of here, we have to get a little advice to help our audience out here. Mark, I think you already gave us a little bit with kind of sticking with the basics here, but any other nugget of wisdom you can pull out from kind of our discussion here that you want to leave our audience with,
B
you know, given that we, you know, no surprise, touched on AI here? I heard something in a conference which was really kind of stuck with me, and that is, you know, go ahead and learn as much as you can about agentic AI. In fact, don't. Don't deploy one bot. Deploy 10 bots to learn about it. And you'll get. Walk away from that with two things. One, you will certainly learn a lot about agentic AI and some of the boundaries and lack of boundaries and whatnot. Then two, you'll understand how to manage those agentic AI bots much better, and you'll see a lot of parallels with people. So you all become better managers from that practice and that process. And I think that's what we all need to do as security professionals. It's not going away, but let's use it to our advantage. We talked about with some of these stories today.
A
Tom, what about you? Any advice to leave our audience with?
C
I think that one of the common themes that ran through a lot of this is the technology debt that we've incurred disappearing out of sight, out of mind. And you can't let that happen to you, because every forgotten piece of tech that never got patched, that never got decommissioned, becomes an entry vector and part of your attack surface. And if it's an old Windows 98 machine that's sitting in the corner running your factory floor, if it is, you know, some old piece of tech that you didn't realize could have malware dropped on it or something like that. Look, I realize that nobody has a complete inventory of all of their technology, but the best time to build something better is right now. Make sure that you are aware of that, and you don't have to go out and spend thousands of dollars or millions of dollars with a, you know, database that will track it all for you, sometimes just writing it down in a notepad to get started. So, you know, it's this machine with this version of software that can't be upgraded anymore. So that when the time does come and, you know, I don't know you guys have a bake sale and are able to buy a new firewall, you can prioritize the really old one and make sure that you get the right thing.
A
I like it. Some some practical, some hopeful stuff to leave us on. Ways to get better. I like this. I like this. Thank you so much. Mark Eggleston, former CISO over at csc and Tom Hollingsworth, Networking Technology Advisor at the Futurum Group. We'll have links to both of your LinkedIn profiles in our show notes so make sure you are giving them a follow. If you are not doing so already, what are you doing? Thanks also to our sponsor for today, Threat Locker for helping make the show possible. Always appreciate when when they are on board with support. Remember you can send us your feedback anytime. Feedbackisoseries.com Remember to join us next Friday at 4pm Eastern for another edition of the Department of no. Can't wait to have you back here. Thank you so much for joining our Friday standup. This has been absolutely fantastic. Fantastic conversations, just a good time. Have a great week. Stay secure out there. And for myself, for Tom, for Mark, for the big boss man, David Spark and the rest of the CISO series team, here's wishing you and yours to have a super sparkly day. Cybersecurity headlines are available every weekday.
B
Head to cisoseries.com for the full stories.
C
Behind the headlines Sam.
Podcast: Cybersecurity Headlines
Host: Rich Stroffolino (A)
Guests: Mark Eggleston (B), Tom Hollingsworth (C)
Date: July 17, 2026
Sponsor: ThreatLocker
This episode dives into several major cybersecurity news topics from the week, focusing on:
Throughout, the hosts and guests bring a blend of technical insight, humor, and candid industry perspectives.
Mark’s Takeaways (39:31):
Tom’s Takeaways (40:21):
For further reading and in-depth stories, visit cisoseries.com.