Contacts
Info
Cyber Security Training and Consulting
Episodes & Posts
Episodes
Posts
How a 10-Minute Phone Call Cost MGM $100M | CISO Board Briefing on Identity, Ransomware & AI Threats
7 SEP 2026 · A 10-minute phone call took down MGM Resorts for ten days and cost $100M+. One saved password at Okta exposed customer session tokens across 134 organizations. Neither attacker broke encryption — they beat the help desk and the identity layer. In this mock executive board briefing, I step into the role of a cybersecurity leader at SecureFintech Inc. (a fictitious fintech) and walk the board through both breaches, the root causes they share, the incident-response mistakes that made them worse, and an 18-month defensive + offensive roadmap built for AI-augmented ransomware and synthetic insider threats. This is the capstone presentation for my MIT xPRO cybersecurity program. SecureFintech Inc. does not exist; the MGM and Okta analysis is based on public primary sources (linked below). ⏱ CHAPTERS 0:00 Cover 0:10 Why MGM and Okta matter to a fintech 0:45 Executive takeaway: the recurring pattern 1:25 MGM: a 10-minute vishing call to ransomware (Scattered Spider / ALPHV) 2:05 Okta: one leaked service-account password, five hijacked sessions 2:45 Root causes: people, process, technology, governance 3:20 How AI amplifies both playbooks (deepfake vishing, synthetic insiders) 4:00 The data: M-Trends 2025 — financial services is the #1 target 4:25 Incident-response missteps and what I would have done differently 5:10 Defensive strategy mapped to NIST CSF 2.0 and CIS Controls 6:00 Offensive strategy: red team, purple team, MITRE ATT&CK validation 6:45 SecureFintech\'s 18-month roadmap 7:25 Board metrics: measure resilience, not activity 7:55 Three takeaways for the board WANT TO GO DEEPER? The techniques in this video — social engineering, identity attacks, session hijacking, and AI-driven threats — are exactly what we teach hands-on at LufSec. ▶ Introduction to Prompt Hacking for LLMs — learn how attackers manipulate AI systems and how to defend them: https://lufsec.com ▶ Browse all LufSec cybersecurity courses (offensive security, AI/LLM security, hardware hacking): https://lufsec.com ▶ Corporate training and consulting for security teams: https://lufsec.com SOURCES - CISA/FBI Joint Advisory AA23-320A — Scattered Spider: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a - MGM Resorts Form 8-K (Oct 5, 2023): https://www.sec.gov/Archives/edgar/data/789570/000119312523251667/d461062d8k.htm - Okta Security — Root Cause and Remediation (Nov 3, 2023): https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/ - Okta Security — Incident Update (Nov 29, 2023): https://sec.okta.com/articles/october-security-incident-recommended-actions/ - FBI — Cyber Criminals Utilizing AI (May 8, 2024): https://www.fbi.gov/contact-us/field-offices/sanfrancisco/news/fbi-warns-of-increasing-threat-of-cyber-criminals-utilizing-artificial-intelligence - Google Cloud / Mandiant — M-Trends 2025: https://services.google.com/fh/files/misc/m-trends-2025-en.pdf - NIST CSF 2.0: https://doi.org/10.6028/NIST.CSWP.29 - MITRE ATT&CK: https://attack.mitre.org - CIS Critical Security Controls v8.1: https://www.cisecurity.org/controls ABOUT ME Luciano Ferrari — cybersecurity executive, founder of LufSec, and Founding President of the Global CISO Council Central Florida Chapter. CISSP, CISM, CRISC, C|CISO, CEH. https://lufsec.com If this briefing was useful, like and subscribe for more real-world breach analysis, offensive security, and AI security content. #cybersecurity #MGMbreach #Okta #ransomware #ScatteredSpider #CISO #boardpresentation #AIsecurity #insiderthreat #NISTCSF #MITREATTACK #fintech #LufSec #MITxPRO
7 SEP 2026 · The next generation of hackers is already out there. Some will defend critical infrastructure — some will compromise it. The difference isn\'t skill. It\'s who finds them first. This Black Hat USA 2026 Main Stage panel brings together people who\'ve lived every side of that line: Ricky Handschumacher served federal time for a $7.5M crypto heist after being recruited into criminal hacking through playing Halo. Marcus Hutchins stopped WannaCry at 22 — then was arrested by the FBI at DEF CON for teenage malware crimes. Will McKeen spent 15 years at FBI Cyber putting people like them in prison. And Fergus Hay runs The Hacking Games, a company built on redirecting talent before criminals recruit it. Speakers: Fergus Hay — Co-Founder and CEO, The Hacking Games Ricky Handschumacher — Reformed Criminal Hacker Will McKeen — Former FBI Agent; Co-Founder, The Hacking Games Foundation Marcus Hutchins — Cyber Defense (the researcher who stopped WannaCry) What\'s covered: How hacking curiosity turns into criminal exposure — and how recruiters exploit it How law enforcement actually assesses intent and harm What real intervention requires, beyond \"talent pipeline\" slogans How industry, government, and education can build credible routes for high-risk technical talent — before someone else does Recorded Thursday, August 6 at Black Hat USA 2026 — Main Stage, Business Hall CHANNEL YOUR HACKING CURIOSITY THE RIGHT WAY — WITH LUFSEC Curious how systems break? Learn offensive skills legally, in hands-on labs built for defenders: Introduction to Prompt Hacking for LLMs — 5 hands-on labs, ~2 hours: https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Explore all LufSec hands-on courses — AI/LLM Security, Car Hacking, IoT Hacking: https://www.lufsec.com Subscribe for more cybersecurity deep dives, tutorials, and conference coverage — and hit the bell so you never miss a new video. What first pulled you into security — and who (or what) kept you on the right path? Tell your story in the comments. 0:00 The Rising Tide of Youth Cybercrime 2:51 From Hacker to Hero and Back Again 6:37 The Judge\'s Decision: A Life-Changing Moment 9:09 The FBI\'s Struggle with Juvenile Offenders 17:40 Ricky\'s Path: From Halo to Millions in Crypto 27:13 Turning Liabilities into Digital Assets #BlackHat #BlackHatUSA2026 #Cybersecurity #MarcusHutchins #WannaCry #EthicalHacking #FBI #CyberCrime #HackerCulture #InfoSec #LufSec #TheHackingGames
6 SEP 2026 · What really happens when cyber defenders hit their breaking point? Drawing on more than 100 hours of interviews with CISOs, former hackers, national security leaders, journalists, and cyber psychologists, former US National Cyber Director Chris Inglis and Semperis CEO Mickey Bresman take the Black Hat USA 2026 Main Stage to share hard truths about the state of cyber conflict. Moderated by Bilyana Lilly (Associate Director, Accenture; Global Chair of the Black Hat Cyber War Forum), this candid conversation explores the assumptions that are no longer holding true, the pressures pushing defenders toward a breaking point, and what governments, organizations, and security leaders must do differently to prepare for the next era of cyber conflict. Speakers: Chris Inglis — Former US National Cyber Director Mickey Bresman — CEO, Semperis Bilyana Lilly — Associate Director, Accenture; Global Chair of the Black Hat Cyber War Forum What\'s covered: Insights from 100+ hours of interviews with CISOs, hackers, and national security leaders The defensive assumptions that no longer hold true The human cost: burnout and the pressures pushing defenders to the edge What governments and organizations must change to prepare for the next era of cyber conflict Recorded Wednesday, August 5 at Black Hat USA 2026 — Main Stage, Business Hall LEVEL UP YOUR SECURITY SKILLS WITH LUFSEC ️ The next era of cyber conflict demands hands-on skills, not just theory: Introduction to Prompt Hacking for LLMs — 5 hands-on labs, ~2 hours: https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Explore all LufSec hands-on courses — AI/LLM Security, Car Hacking, IoT Hacking: https://www.lufsec.com Subscribe for more cybersecurity deep dives, tutorials, and conference coverage — and hit the bell so you never miss a new video. What\'s the hardest truth about defending at scale that nobody talks about? Share it in the comments. 0:00 The Reality of Modern Cyber Warfare 1:50 The Vision Behind the Documentary 3:31 Hard Truths from the Frontlines 6:43 Breaking the Silence on Defender Burnout 10:56 When Cyber Threats Become Societal Problems 22:39 Making the Hard Truths Mainstream #BlackHat #BlackHatUSA2026 #Cybersecurity #ChrisInglis #Semperis #CyberWar #CISO #NationalSecurity #CyberConflict #InfoSec #LufSec #SecurityLeadership
6 SEP 2026 · Why do we keep finding new bugs in code we thought was thoroughly researched? In this Black Hat USA 2026 Keynote, Yan Shoshitaishvili — Associate Professor at Arizona State University and one of the field\'s most prolific vulnerability researchers — tackles the question head-on. Vulnerability research has always been a pursuit of the elite: deep knowledge of massive codebases, mastery of advanced tooling, grit, and luck. Over 15 years, Shoshitaishvili\'s research has uncovered thousands of vulnerabilities across IoT devices, web browsers, kernels, and bootloaders — and with each new tool and paradigm, bugs kept appearing in the same \"well-researched\" code. Now agentic AI vulnerability research is doing it again, surfacing fascinating new bugs in software the community thought was finally understood. Through the lens of his journey, this keynote explores the scientific underpinnings of what our community has long treated as an art form. Speaker: Yan Shoshitaishvili — Associate Professor, Arizona State University What\'s covered: What vulnerabilities actually are — and why we keep finding them in the same codebases 15 years of lessons from IoT, browsers, kernels, and bootloaders Why AI has revolutionized vulnerability research Where agentic vulnerability research goes from here — and why the road won\'t be easy Walk away excited about the future… if a little terrified. Recorded Thursday, August 6 at Black Hat USA 2026 — Main Stage, Business Hall START YOUR OWN VULNERABILITY RESEARCH JOURNEY — WITH LUFSEC Agents finding bugs starts with understanding how AI systems break. Get hands-on: Introduction to Prompt Hacking for LLMs — 5 hands-on labs, ~2 hours: https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Explore all LufSec hands-on courses — AI/LLM Security, Car Hacking, IoT Hacking: https://www.lufsec.com Subscribe for more cybersecurity deep dives, tutorials, and conference coverage — and hit the bell so you never miss a new video. Has AI changed how you hunt for bugs? Share your experience in the comments. Vulnerability research is changing as agentic systems automate discovery. Learn how security groups manage this new scale. As automated agents begin to dominate threat identification, security groups face a surge in findings that outpaces manual review. This presentation examines the practical challenges of this new era, highlighting how specific methodologies can identify hundreds of vulnerabilities in a single cycle. We review a recent case study where one automated approach successfully isolated 300 vulnerabilities, demonstrating the sheer volume of output that modern teams must now handle. Effective vulnerability testing now requires adapting to these high-frequency inputs. For those working in AI security, the priority is shifting from finding flaws to managing the remediation pipeline effectively. We analyze the shift in defensive strategy needed when the barrier to entry for vulnerability discovery drops significantly. Subscribe for more technical security breakdowns, and let us know in the comments how your team is handling automated findings. 0:00 The Evolution of Capture the Flag 4:45 Research in the Agentic Age 9:41 Three Paths to Autonomous Discovery 14:46 The Fuzzing Renaissance and LLM Integration 19:23 Extracting Properties from Vulnerability Data 23:40 Scaling Workflows to Outperform Benchmarks 30:11 The Limitations of Rewriting in Rust #BlackHat #BlackHatUSA2026 #VulnerabilityResearch #AgenticAI #BugHunting #AISecurity #ExploitDevelopment #IoTSecurity #Cybersecurity #InfoSec #LufSec #EthicalHacking
5 SEP 2026 · What happens to cybersecurity defense when AI makes finding and exploiting vulnerabilities cheap? In this Black Hat USA 2026 Keynote, David Weston, Agentic Security Leader at Microsoft, argues we\'re entering \"the end of rare\" — an era where vulnerability-finding agents have driven discovery costs to record lows and exploit development is cheaper than it\'s been since the \'90s. When that happens, the two strategies defenders have leaned on for years stop holding: wait-and-patch-fast (which assumed exploits took time to build) and detect-and-respond (which assumed attacker tradecraft stayed stable long enough to become a signal). When tooling is generated on demand, both assumptions weaken at once. In this keynote: Why AI-driven vulnerability discovery breaks the assumptions behind modern defense Memory-safe languages in the AI era — removing whole vulnerability classes before code ships The resurgence of formal methods, now that AI can scale proof-writing Automated patching to shorten the disclosure-to-remediation window at massive scale Rethinking detection when the implant changes every run — which signals stay stable Real examples from large-scale defensive software projects, plus the open problems still unsolved This isn\'t doom and gloom: AI also creates asymmetries that can favor defense — if we invest in the right strategy. Essential viewing for cloud providers, OS and platform vendors, and SecOps teams defending large networks. Speaker: David Weston — Agentic Security Leader, Microsoft Recorded Wednesday, August 5 at Black Hat USA 2026 — Main Stage, Business Hall LEVEL UP YOUR SECURITY SKILLS WITH LUFSEC Offense is getting cheap — learn how attackers manipulate AI systems so you can defend them: Introduction to Prompt Hacking for LLMs — 5 hands-on labs, ~2 hours: https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Explore all LufSec hands-on courses — AI/LLM Security, Car Hacking, IoT Hacking: https://www.lufsec.com Subscribe for more cybersecurity deep dives, tutorials, and conference coverage — and hit the bell so you never miss a new video. Do you think AI ultimately favors attackers or defenders? Drop your take in the comments. 0:00 Celebrating Two Decades of Security Innovation 2:08 The Political Reality of Modern Cybersecurity 5:05 The Human Element in an Autonomous World 6:47 The Evolution of Prediction Engines 9:42 An Optimistic View on the AI Frontier 25:02 Retraining the Physics of Defense 40:25 Final Logistics and Upcoming Highlights #BlackHat #BlackHatUSA2026 #Cybersecurity #AISecurity #DavidWeston #Microsoft #MemorySafety #FormalVerification #ExploitDevelopment #InfoSec #LufSec #PromptHacking #LLMSecurity
5 SEP 2026 · How are America\'s cyber priorities moving from policy to practice? In this Black Hat USA 2026 Opening Session, senior U.S. government officials take the Main Stage to discuss how agencies are adapting the nation\'s operational posture in cyberspace — from disrupting cybercriminal networks and defending critical infrastructure to coordinating offensive and defensive operations across government. Speakers: Nick Andersen — Acting Director, CISA Katherine (Katie) E. Sutton — Assistant Secretary of War for Cyber Policy; Principal Cyber Advisor to the Secretary of War, Department of War Brett Leatherman — Assistant Director, Cyber Division, FBI Daniel Kroese — Vice President, Global Policy, Palo Alto Networks What\'s covered: The administration\'s cyber priorities in practice Disrupting cybercriminal networks at scale Defending U.S. critical infrastructure Coordinating offensive and defensive cyber operations across government The evolving threat landscape and operational readiness LEVEL UP YOUR SECURITY SKILLS WITH LUFSEC AI is the new attack surface. Learn to test LLMs before attackers do: Introduction to Prompt Hacking for LLMs — 5 hands-on labs, ~2 hours: https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Explore all LufSec hands-on courses — Car Hacking, IoT Hacking, AI/LLM Security: https://www.lufsec.com Subscribe for more cybersecurity deep dives, tutorials, and conference coverage — and hit the bell so you don\'t miss new videos. Which topic from this panel matters most to your org? Drop a comment below. Recorded Tuesday, August 4 at Black Hat USA 2026 — Main Stage, Business Hall 0:00 Setting the Stage for Cyber Resilience 2:11 FBI Deterrence and Operation Riptide 4:36 Fusing Cyber and Kinetic Military Operations 6:49 CISA\'s Role in Civilian Cyber Defense 11:02 Cyber Command 2.0 and Talent Management 17:52 A Call to Action for Industry Partners #BlackHat #BlackHatUSA2026 #Cybersecurity #CISA #FBI #CyberDefense #CriticalInfrastructure #CyberPolicy #InfoSec #LufSec #PromptHacking #AISecurity
2 SEP 2026 · Inside Cyber Minds S3E13 — Ted Harrington on application security, penetration testing, IoT hacking, and the hacker mindset. Ted is Executive Partner at Independent Security Evaluators (ISE) — first to hack the iPhone — #1 bestselling author of Hackable and Inner Hacker, and founder of IoT Village. Recorded onsite at DEF CON. Free Cyber Security Career Guide — the roles, skills, certs, and shortest route into cybersecurity (bonus: unlocks a free LufSec lesson): https://www.lufsec.com/products/digital_downloads/cyber-security-career-guide?utm_source=youtube&utm_medium=onramp&utm_campaign=career-guide-funnel&utm_content=s3e13 ️ Build hands-on application security and penetration testing skills with LufSec courses: https://www.lufsec.com/courses/?utm_source=youtube&utm_medium=onramp&utm_campaign=career-guide-funnel&utm_content=s3e13-course ------------------------------------------------------- Ted\'s team at ISE was first to hack the iPhone — and has since hacked cars, medical devices, and password managers to make them safer. In this episode we cover what real penetration testing looks like (and why most \"pen tests\" are just vulnerability scans), how to do application security right, what a decade of running IoT Village at DEF CON reveals about IoT security, how anyone can build the hacker mindset, and what happens to appsec when AI writes the code. Topics Covered Penetration testing vs. vulnerability scanning Application security done right (the Hackable method) First to hack the iPhone: the ISE story IoT security: lessons from a decade of IoT Village The Inner Hacker: thinking like an attacker AI-generated code and the future of appsec People can connect with Ted on LinkedIn: https://www.linkedin.com/in/securityted/ ISE: https://www.ise.io/ Hackable: https://www.hackablebook.com/ Inner Hacker: A New Way of Thinking — https://www.amazon.com/Inner-Hacker-New-Way-Thinking/dp/B0FQ7GTY1R Inside Cyber Minds is a cybersecurity podcast by LufSec — unscripted conversations with hackers, CISOs, researchers, founders, and security leaders on mindset, emerging threats, and the human side of cybersecurity. ▶️ Subscribe on YouTube: https://youtube.com/@Lufsec ️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc Apple Podcasts: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640 Amazon Music: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds LinkedIn: https://www.linkedin.com/company/lufsec/ Stop worrying about artificial intelligence as a menace and start viewing it as a neutral instrument for your goals. This talk explains why the outcome of using new technology depends on the person wielding it. Captured at IoT Village, this presentation addresses the common anxiety surrounding automated systems. Just as a kitchen knife is neither inherently evil nor virtuous, the impact of software depends entirely on the operator. We break down the responsibility of the developer, moving the conversation away from abstract fear and toward practical, ethical usage. If you build or manage digital products, this perspective provides a framework for evaluating your daily tech stack. Understanding how we apply these capabilities determines our future success. By focusing on the human intent behind the code, we can better navigate the landscape of modern artificial intelligence without getting lost in the hype. This session is designed for anyone looking to ground their workflow in reality rather than speculation. Subscribe for weekly tech strategy breakdowns, and comment below on how you are currently using artificial intelligence in your own projects. 0:00 The Hacker Mindset and Ethical Security 0:53 From Career Transition to Security Leadership 3:59 Debunking the Security Myth 7:25 The Dual Reality of IoT Security 12:50 Mastering Threat Modeling for New Devices #Cybersecurity #ApplicationSecurity #PenetrationTesting #IoTSecurity #EthicalHacking #AppSec #DEFCON #InfoSec #InsideCyberMinds #LufSec
28 AUG 2026 · I built an AI support bot for a fictional food delivery company called Bitely — then broke it five different ways live, including getting it to comp an order it wasn\'t authorized to refund and leak an internal staff code it was explicitly told to protect. This is prompt injection, the #1 risk on the OWASP LLM Top 10, demonstrated end-to-end with the exact prompts. If you build, secure, or manage anything with an LLM behind it, this is the hour that shows you why \"just write a stricter system prompt\" doesn\'t work — and what actually does. BREAK THE BOT — free CTF Watching is one thing. Run these attacks yourself against a deliberately vulnerable bot: https://breakbot.lufsec.com/ GO DEEPER — Introduction to Prompt Hacking for LLMs The live session was the simplest version of every attack. The course covers how to test systematically, chain attacks into a real finding, and write it up so it gets fixed. Two codes: - HACKLLM40 — launch price, first cohort only (expires soon) - YOUTUBE40 — for people who found this on YouTube https://www.lufsec.com/products/courses/prompt-hacking-for-llms-intro Free Prompt Injection Cheat Sheet (every attack from this video): https://www.lufsec.com/products/digital_downloads/llm-security-cheat-sheet ️ WHO THIS IS FOR Security engineers, pentesters, AppSec teams, developers shipping LLM features, and anyone responsible for answering \"is our AI safe?\" No machine learning background required. Topics: prompt injection, LLM security, jailbreak, indirect prompt injection, AI red teaming, OWASP LLM Top 10, system prompt extraction, AI chatbot security, generative AI risk. LufSec — offensive security training for the AI era. Join the community: https://discord.gg/wHps8Ymm4C ️ For education and authorized testing only. Everything here runs against a bot I built and own. Never test systems you don\'t have permission to test. #PromptInjection #AISecurity #LLMSecurity #CyberSecurity #AIHacking
26 AUG 2026 · Free Cyber Security Career Guide Break into cybersecurity without wasting years on the wrong path. Get the free guide — the roles, skills, certs, and the shortest route in: https://www.lufsec.com/products/digital_downloads/cyber-security-career-guide?utm_source=youtube&utm_medium=onramp&utm_campaign=career-guide-funnel&utm_content=s3e3 Bonus: download the guide, and you\'ll unlock a free lesson from the LufSec course library. ️ To build practical network and offensive security skills like the ones the NOC uses, explore LufSec\'s cybersecurity courses and hands-on training: https://www.lufsec.com/courses/?utm_source=youtube&utm_medium=onramp&utm_campaign=career-guide-funnel&utm_content=s3e3-course ------------------------------------------------------- Season 3 of Inside Cyber Minds continues with a behind-the-scenes episode recorded onsite at DEF CON, inside the operation most attendees never see: the Network Operations Center. Every August, the DEF CON NOC builds a conference network from the ground up — hundreds of access points, terabytes of traffic, tens of thousands of devices — then hands it to a crowd that includes some of the best hackers on the planet, many actively probing it with rogue access points, Wi-Fi Pineapples, Flipper Zeros, and fake SSIDs mimicking the real thing. It\'s often called the most hostile network in the world. The NOC\'s job is to keep it running anyway. Sparky, who leads the NOC, and longtime team member Chris \"Mac\" McEniry take us inside how it all works: planning a network that exists for one week a year, defending infrastructure while it\'s under constant attack, what they actually see on the wire, and why a volunteer team keeps coming back to do the hardest networking job in the industry. Is DEF CON Wi-Fi actually safe? What attacks show up every single year? And what can enterprise defenders learn from a network that survives the ultimate stress test every August? Topics Covered Inside the DEF CON Network Operations Center Building a conference network from scratch every year Defending the \"most hostile network in the world\" Rogue access points, fake SSIDs, and what attendees actually try Is DEF CON Wi-Fi safe? What the NOC really sees Wireless security at massive scale War stories from years of DEF CON networks What enterprise defenders can learn from the NOC Volunteering and the DEF CON community About the DEF CON NOC The DEF CON NOC is the official networking team of DEF CON, the world\'s largest hacker conference. The volunteer team designs, deploys, and defends the entire conference network — wired and wireless — for tens of thousands of attendees in one of the most adversarial computing environments anywhere. Sparky leads the NOC; Chris \"Mac\" McEniry is a longtime team member and infrastructure planner. https://noc.defcon.org/ About Inside Cyber Minds Inside Cyber Minds is a cybersecurity podcast by LufSec featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, and security leaders — mindset, leadership, security culture, emerging threats, and the human side of cybersecurity. Watch & Listen ▶️ YouTube: https://youtube.com/@Lufsec ️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc Amazon Music: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1?source_code=ASSGB149080119000H&share_location=pdp Apple Podcasts: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640 LinkedIn → https://www.linkedin.com/company/lufsec/ Guests: Sparky — DEF CON NOC Lead Chris \"Mac\" McEniry — DEF CON NOC https://noc.defcon.org/ #Cybersecurity #DEFCON #NetworkSecurity #WiFiSecurity #WirelessSecurity #InfoSec #HackerConference #InsideCyberMinds #LufSec
24 AUG 2026 · Windows Server Update Services (WSUS) sits at the heart of enterprise patch management, pushing updates to thousands of endpoints. That privileged position makes it one of the highest-value targets on the network: a compromised WSUS server means lateral movement, persistent footholds, and organization-wide implant deployment at scale. In this Black Hat USA 2026 Briefing, we present original research into a new attack path that results in full WSUS infrastructure takeover — starting from a low-privileged foothold. You\'ll see how security infrastructure itself can be weaponized, how existing controls can be bypassed, and how malicious update packages can be pushed for domain-wide code execution. What you\'ll learn: ▶ Identifying and exploiting WSUS from a low-privileged starting point — How to find WSUS in an enterprise environment, coerce machine account authentication into the WSUS SQL database without admin access, and enumerate and abuse native stored procedures to build a malicious update deployment chain from scratch. ▶ Bypassing the WSUS payload signing requirement — A walkthrough of the signing validation logic inside the WSUS .NET binaries, how an undocumented file-extension exception was discovered through API monitoring and static analysis, and how to leverage it to deploy fully unsigned payloads through trusted update infrastructure. ▶ Detecting and hardening WSUS — Concrete defensive guidance you can apply the same day: security controls that would prevent the vulnerability, what SQL-level monitoring for anomalous stored procedure abuse looks like, and detection logic to build around malicious update package creation. ▶ A repeatable methodology for finding Windows security control bypasses — Using API Monitor to trace runtime behavior, log analysis to understand validation logic, and .NET decompilation with dnSpy to uncover undocumented exceptions in compiled binaries — a methodology that applies well beyond WSUS. Released alongside this Briefing: two new open-source tools and a five-part blog series. ━━━━━━━━━━━━━━━━━━━━━━ FREE FROM LUFSEC — START LEARNING TODAY ━━━━━━━━━━━━━━━━━━━━━━ Free Intro to IoT Hacking Course — Master the fundamentals with hands-on challenges: https://www.lufsec.com/products/courses/intro-iot-hacking Free E-Book: Starting Your Cyber Security Career — Tools, strategies, and a roadmap to break into the field: https://www.lufsec.com/products/digital_downloads/cyber-security-career-guide ️ Free Security Awareness Training for Corporate Users: https://www.lufsec.com/products/courses/security-awareness-training Browse all free resources: https://www.lufsec.com/collections/free-resources Go deeper — Master IoT Security Course: https://www.lufsec.com/products/courses/iot-hacking ━━━━━━━━━━━━━━━━━━━━━━ ️ This research is presented for defensive and educational purposes to help organizations harden their environments before attackers exploit the same techniques.
Cyber Security Training and Consulting
Information
| Author | vgft |
| Organization | vgft |
| Categories | Leisure |
| Website | www.spreaker.com |
| - |
Copyright 2026 - Spreaker Inc. an iHeartMedia Company