Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.
No prep doc, no script: just what Matt and Chris were actually hearing on the floor.
• Shai-Hulud is back. The self-replicating npm worm returned on August 4, trojanizing the keyv / cacheable family and spreading to 400+ packages within hours. Chris reads through Datadog Security Labs' analysis of the Shai-Hulud 2.0 wave: 796 packages and 1,092 versions, 20M+ weekly downloads, credential harvesting with TruffleHog, GitHub repositories used for both exfiltration and command and control, and a worm that reads its own code to propagate without a C2 server.
• The LLM that downloaded the malicious package by itself. A researcher asked a frontier model about a compromised package, and the model decided the best way to help was to go fetch a copy — tripping the SOC's alert and bypassing the company's centralized package clearing house on the way.
• Non-human identity as the new perimeter. Every agent you introduce is another identity: who created it, what can it reach, how long should it live?
• "Computer says no." Matt's colleague hit a refusal from Opus 5, and the session automatically downgraded to 4.8 and completed the task. Which raises the real question of the episode: do security teams now need model pinning, the way we once needed certificate pinning? And if defenders pin to older models to keep working while adversaries use the newest ones, have we rebuilt the same gap all over again?
• AI governance and change control — which models are approved for which tasks, and what happens when a vendor ships a new version or deprecates an old one.
• Token spend as a CISO budget line item. Enterprises buying tokens at a scale their vendors can't match and pulling those vendors onto their plan, token burn as an insider-threat vector, and why $100,000 of tokens is not $100,000 of productivity.
• Defender takeaways: pin your npm packages, get security off its island and talk to your developers, build approved paths before detections, least privilege and key rotation, and network-gated pushes as a deliberate chokepoint.
Stories covered:
• https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain
• https://research.jfrog.com/post/shai-hulud-is-back-august/
• https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/
• https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/
• https://unit42.paloaltonetworks.com/npm-supply-chain-attack/
Chapters:
0:00 Live from Black Hat, in person for once
0:48 How Black Hat has changed
4:31 No prep — let's talk about what's actually happening here
4:57 Shai-Hulud is back: supply chain compromise
6:23 The LLM that downloaded the malicious package
7:19 Inside Shai-Hulud 2.0
10:34 When attackers and defenders use the same tools
11:39 Non-human identity is the new perimeter
12:13 Opus 5 said no, so the session downgraded itself
15:23 Do security teams need model pinning?
18:20 Three companies, very nebulous rules
18:35 AI governance: which model for which task
21:19 Token spend hits the security budget
22:58 Is token spend a productivity metric?
25:46 Pin your packages
26:25 Get security off the island
29:17 Least privilege, key rotation, chokepoints
32:55 Why it's called Shai-Hulud
33:25 Wrapping up at Black Hat
The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
Subscribe wherever you listen:
• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740
• YouTube: https://www.youtube.com/@limacharlieio
Learn more about LimaCharlie: https://limacharlie.io
#cybersecurity #infosec #threatintel #AIsecurity #supplychainsecurity
Fler avsnitt av The Cybersecurity Defenders Podcast
Visa alla avsnitt av The Cybersecurity Defenders PodcastThe Cybersecurity Defenders Podcast med LimaCharlie finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.
