In this solo episode, host Aaron Crow takes us on a fast-paced journey through the latest critical developments in both IT and OT cybersecurity. Aaron breaks down the month’s most pressing zero-day exploits, including high-profile attacks on Microsoft SharePoint and CrushFTP, and explores the implications of rapidly evolving threats - especially as attackers leverage AI for faster, more innovative hacks.
But it’s not all doom and gloom: Aaron dives into how AI is also becoming a game-changer for defense, from Google’s use of AI agents to spot vulnerabilities ahead of attackers, to the promise (and dangers) of deepfake technology. He discusses new policy moves, like the FCC’s proposal to ban Chinese tech in undersea internet cables and the US Coast Guard’s push for cyber resilience in maritime infrastructure.
Throughout the episode, Aaron offers strategic advice for organizations of all sizes - from patch management and digital twins to incident response plans designed for today’s AI-driven threat landscape. Whether you’re in cyber, tech, critical infrastructure, or just want to stay a step ahead, this episode is packed with actionable insights and timely analysis to boost your cyber resilience. Plug in for a conversation that’s equal parts eye-opening and empowering!
Key Moments;
01:20 High-Level Tactical Briefing
05:31 Digital Twin for System Security
09:39 Dual Role of Tools
12:00 Emergency Procedures Reminder
14:24 Challenges in OT System Integration
18:32 Deep Fake Detection and Response
20:12 "AI Persistence and Impact"
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:0.994): Hey everyone. So today is another solo episode. I've got some great recordings coming up with some amazing guests that are coming super excited about that. Seems like some are everybody's schedules are tough. So loving doing doing these able to dive into this. A lot of the things that are going on in real time. So let's dive right in. This week is it's very, you know, it's very much a high level tactical.
Aaron Crow (0:30.838): brief. know, there's everything from critical zero days to, you know, AI threats and defenses, policy moves that are, you know, shifting, you national security and what you can do to stay hit. You know, if you're in cyber tech, energy, critical infrastructure, or you just want to stay a step ahead, definitely this episode's for you. So let's get into it.
Aaron Crow (0:57.644): Let's talk active zero day exploits. This month has been pretty freaking brutal. Microsoft SharePoint, there's been a CVE that came out and it was used to breach over 75 global organizations. Obviously everybody seems to have Microsoft. You use SharePoint, it's kind of part of the system. I've not always really been a fan of SharePoint. I see the value in it, I use it all the time, whether it be storing files or
Aaron Crow (1:26.668): obviously all the use cases that you can do with it. But attackers chained it with a remote access tool and big players got hit. There's a lot of those that are still unpatched. There's big deals. We even saw a hit from Ring. The Ring camera got hit not by this thing, not by SharePoint, but was also impacted this week.
Aaron Crow (1:54.188): That's one to definitely check out. Crush FTP is another vulnerability that came out. The exploit gives full admin access to attackers. So if you're running Crush FTP and you have it patched, you need to get on top of that. Avanti, there's two more zero days used to drop Cobalt Strike. It's really, really impacting a lot of folks. What's the takeaway of these? I don't normally dive into...
Aaron Crow (2:22.536): all the vulnerabilities and all the attacks necessarily. But really, it's more of a bigger picture of what's the point. The point is that we have, especially in OT, have really had an intention of, you know, we don't patch all the time. We don't patch as frequently. Some of these things, obviously SharePoint, you're probably not using SharePoint in OT. You're not
Aaron Crow (2:49.368): probably using it in a lot of your critical systems, but can they get in and then pivot from there, right? It's really around, we're seeing more more weaponized exploits. They're happening faster. So once these things come out, they're weaponizing them so quickly. I'm sure a lot of that has to do with AI. AI is going to make it faster to respond from a bad actor to take advantage of those vulnerabilities and do something with them.
Aaron Crow (3:16.942): we've really got to start looking at, you know, patch management like incident response. Like we are, the incident has happened. We have to stop before we have to start closing the holes before the bad actors get in. Um, and not waiting and pushing it off, you know, weekends, you know, if, if, if you get outside the patch cycle and you have an outage, you know, on the weekend, then it may not be good to wait that long. Not everybody does it that's that quickly or, or, you know, um,
Aaron Crow (3:45.554): It all depends on the criticality and the impact and all those things, right? So, all right. So next is let's dive into AI. AI is always going to be, I think every episode I seem to talk about AI in some form or fashion. Cybersecurity and AI are definitely intertwined from, you know, how can you protect and tools that have are using AI to help see things, pattern recognition, you know, respond quicker.
Aaron Crow (4:14.348): you know, get better data, all the things, but it's also can be used to attack us. So Google's big sleep was an AI agent that identified a critical exploit before, before attackers could use it. They detected the vulnerability and flagged it for immediate patching. And, you know, it, it's showing that AI can use, be used to predict and prevent an imminent cyber attack and could
Aaron Crow (4:43.598): could be the future of defense. And this is where I'm really excited about the opportunity to use AI. And even in critical infrastructure in OT, I definitely believe we should be looking at how can we use AI to stay ahead, right? We shouldn't be waiting until someone finds a vulnerability and releases a CVE or a patch.
Aaron Crow (5:10.078): If these AI tools can start finding these vulnerabilities in our systems, that's the way we need to do, especially when you think about how big and complex these systems are. You have all these intricacies and you don't necessarily know, yes, they're patching the system, they're patching SharePoint, they're patching your server, they're patching your firewall, but there's no way they can replicate your entire environment.
Aaron Crow (5:36.194): So it's no way to really understand what the true vulnerabilities are out there because nobody has that exact setup. So imagine a place that you could have a digital twin of your environment and you were able to run a red team. can run having AI sitting there and looking at all of the software and all the things and finding vulnerabilities in code, finding vulnerabilities in your setup and your configuration and your firewall and your network architecture and in any of those types of things.
Aaron Crow (6:5.582): and just continually sit there and run it. Like I've built labs and had amazing value out of them with a human doing things, but it's limited in how many scenarios a human can do just from a timing perspective, not to mention cost of all the things. So AI can really be great in that way. But there's also a dark side to AI. Researchers also trained in AI to bypass Microsoft Defender.
Aaron Crow (6:33.998): They used it, they used reinforced learning. It cost them, I think they said $1,600 and they had a success rate of about 8 % evasion. So obviously that's not a super high percentage, but it's still taught an AI to bypass a security tool to get around it. It knows that, hey, this environment has Microsoft Defender, this environment has, you know, XYZ, firewall, whatever those things are.
Aaron Crow (7:2.710): You can start training AI specifically on this patch, this version, this PLC, et cetera, kind of the inverse of what we were just talking about and using AI to help find those vulnerabilities. We can also use AI to find them from a bad perspective and start to attack them. Hey, I know this place that I want to get into, this environment that I want to get into has these things. How can I bypass those things? The other is not exactly cyber, but it can, obviously it can be used. It's a lot broader, but it's deep fakes.
Aaron Crow (7:31.722): AI is obviously exponentially blowing up deepfakes from celebrities. Any celebrity you see, they have thousands of, you know, vulnerable deepfakes out there that are copying their songs, they're copying their movies, they're using them in advertisements. You really need to think about your incident response plan.
Aaron Crow (7:58.616): Do you have a plan as part of your tabletop, as part of your instant response plan? What if the CEO calls you? We've all gotten the text messages from the CEO from the wrong phone number and we know it's not them or your boss or your mom or whatever. But what if they call you and it sounds like you and it sounds like that person and they know what to say and then you believe like it sounds like, again, I've got hundreds of hours of my voice on the internet from
Aaron Crow (8:27.640): all of my podcast. So someone could very easily make a deep fake of me and my voice and call my wife and say, send me 50 bucks because I lost my card. I need to get whatever. And she could very easily be tricked. So think about that. And how are you protecting that social engineering, that phishing by using deep fakes? AI is going to be able to be more successful in those things that a few years ago was pretty easy to detect.
Aaron Crow (8:57.856): India launched a vast of AI, excuse me, a real time deep fake detection tool. been rolled out into law enforcement and enterprise. But the takeaway there, again, this entire conversation is AI in and of itself is becoming a battlefield. It can be your shield, it can be the sword, it can be the gun, it can be the fortress.
Aaron Crow (9:27.546): the good guy or the bad. And it's going to be both. Both sides are going to use it. They're going to use their own models. They're going to use their own tools. It is a tool, you know, just like a brick in and of itself can build a house or you can throw it through a window. The brick in and of itself is not bad. It is what you wield with it. It's what you do with it. So that kind of moves into the next and that's some moves happening in policy.
Aaron Crow (9:54.434): The FCC is proposing a ban on Chinese technology in undersea internet cables. And this impacts 99 % of global traffic. But the concern is that they will be able to do surveillance and sabotage on that. And obviously that's a huge concern. The internet, everything goes across it, even if it's VPNed with quantum computing coming.
Aaron Crow (10:23.426): with them expecting to be able to in the future break encryption. What if they just stored all of that data until they had an opportunity in the future to use a quantum computer to just break everything? Those are big rules and big scary things. US Coast Guard made a cyber rule. The new requirements for maritime and infrastructure to report incidents, cyber, excuse me, report cyber incidents. Annual training.
Aaron Crow (10:50.414): and then having formal plans by 2027, which it's midway through 2025. So that's not too far away. They're pretty basic, but still these are good moving in the right direction of having formal plans, having training. You should be doing tabletops. I know I've talked about it many times, but the auto tabletop that we use is so, in my opinion, revolutionary in that it's not the traditional physical old school tabletops.
Aaron Crow (11:19.094): It's really the ability to run that through AI, right? You'll be able to pivot and do this, you know, almost like a Dungeons and Dragons or choose your own adventure, but you can use it as training. Like you can really get everybody in the game, as they say, to actually understand just like we do in a fire drill. I know I say this all the time, but you know, we do fire drills and buildings. And the reason is because we want you to know how to respond in a safe environment so that if that bad thing does happen, you already know, hey,
Aaron Crow (11:46.894): I know I don't take the elevator. I know I take the stairs. The muster point is in this corner of the building or this corner of the parking lot. Everybody meets out there. You don't leave until like all of these things we know because we've gone through it so many times. Even if it's just once or twice, like you still remember a lot of those things and and then you're you're it's easier to be triggered to remember when somebody so yeah, remember the muster point. Don't take the elevator like oh yeah, that's right, right. So.
Aaron Crow (12:11.180): That's really what our training should be. It should be so that it's not the first time somebody's experiencing it. It's not the first time that they're thinking about, this thing is happening. How am I supposed to respond? Who should I call? Who's the right person to bring in? Do I have authority to shut down the network? Or what is the step that I should take in scenario A, B, and C? So finally, the State Department. I'm sure everybody has seen many changes in the last
Aaron Crow (12:39.276): six months with firings and Doge and all the things, but the State Department just cut cyber and AI staff. We're talking dozens of roles eliminated. The exact moment global cyber diplomacy is actually needed. So the takeaway is government's trying to tighten the screws, cut costs, all the things, but our infrastructure is important and we need to be protecting it.
Aaron Crow (13:7.950): And we need bodies that are looking at cyber, they're looking at AI and how's that going to impact infrastructure? How's it going to impact the grid? How's that going to impact our train and our transportation systems and our water? All of those types of things, right? resilience is kind of the next piece. So we've already talked about quite a bit in the, you know, from incidents, from vulnerabilities to policy even.
Aaron Crow (13:35.603): We're about a year out from the CrowdStrike outage. Everybody remembers the CrowdStrike outage. Where were you when that happened? A new study shows that more than 750 hospitals, US-based hospitals, experienced downtime. Patients diverted, delayed care. It's the next want to cry moment. Unfortunately, we're still vulnerable, right?
Aaron Crow (14:3.810): We're vulnerable beyond, and it's not just a CrowdStrike issue, it's a policy and going back to the training. We've got to understand how these systems and how the tools that we're adding and the configurations, going back to the lab and the testing I was talking about earlier, we really need to understand at a very, very finite level how all these things tie together. It's one of the reasons why we don't change things in OT so often, because we don't want a whole bunch of software
Aaron Crow (14:33.684): adding new tools and installations and clients and all the things, because it just makes it that much harder to install. When I worked in a nuclear facility, nuclear power plant in Texas, we were installing weather stations and emergency satellite communications at all of the plants and the buildings and all the things. And I installed it across our fleet. I think I had like a month and a half because a whole bunch of things happened, but I needed to do it very quickly. So I was able to install
Aaron Crow (15:3.892): again, satellite communications in the control rooms in downtown Dallas on top of a 50-story skyscraper and get those into the boardroom and get those into the emergency response rooms, all that. It took me a year and a half to get something into the nuclear control room at the nuclear facility. Why is that? Well, because to do a penetration into a control room at a nuclear facility takes a lot of paperwork.
Aaron Crow (15:32.386): and you've got to do a lot of studies and you got to make sure that, you know, by doing this, you're not impacting the ability for, you know, for that room to withstand the nuclear reactions going on outside, all those types of things, right? And for good reason. They understand absolutely everything that goes into that space. Just putting a cat five cable into that room, takes a lot of tests, a lot of understanding. They don't change things like the architecture, the design, the tools, the gear has to stand up.
Aaron Crow (16:1.090): the test of time and they have to know everything about it from, you know, the time the material was picked up out of the dirt until that bolt shows up at the facility. They have to really be able to understand it. So I'm not saying that we obviously we can't afford to necessarily go to that level of detail and everything, but we really need to be deeper diving into, you know, cyber informed engineering and really understanding what our systems do and where the impacts can be. They're not always going to be cyber impacts, of course.
Aaron Crow (16:30.296): but they're going to be impacts to our system. Like if this thing goes down, this may shut this down. And then what is the impact of that? The risk to the business. Cloudflare and Palo Alto networks are going all in on AI driven security. Everything from anomaly detection to, know, SASE integration. And it's really where the next war is going to be fought. CISOs are ranking AI enabled threats as like top three global risk factors. And they're not raw.
Aaron Crow (17:0.172): So, you know, the takeaway is backup, train, detect, automate, resilience. We focus on it so much in OT from operational. We're, you know, triple redundant systems and safety systems and backup systems, and we do safety training and, you know, we do pre-job briefs and we talk about things before they implement. You know, what's the potential impact? What's our, what's our back out plan? Are we doing that everywhere? Should we?
Aaron Crow (17:30.574): Right? Resilience isn't a buzzword. It's making sure these systems are functional, making sure that they're the critical environments and whether it's not, you know, it may not be a critical infrastructure. So your business may not be running a power plant, but you know, your system is, that system is critical to your business and having it up and running incapable. Maybe you're a small business and your website, you're selling things on your website. If that thing goes down, you don't make money. If your store can't, you know,
Aaron Crow (17:59.070): If you run a liquor store or a gas station, you can't pump gas. You can't make money. Those are all impacts. And understanding what the risks are from the systems and how they all tie together and how everything works is super important. So making sure that we're patching. Run AI threat simulations. Look at digital twins. Can your team spot a deep fake? Again, are you telling your team?
Aaron Crow (18:25.430): a safe word or what is your policy on, you know, if the CEO, the CFO, the engineering manager, the plant manager, whatever those things are, if they call and say to do something out of the ordinary, how do you, how can you train your team to spot that? And what procedure process can you implement that doesn't make it too difficult, but still there's some kind of check safe, you know, that, that enables this to not spin out of control. you know, update your incident response plans.
Aaron Crow (18:54.306): You know, include AI in both voice cloning scenarios. Review the dependencies for your vendors. You know, it's super easy to deep fake credentials, badges. You know, it's very easy to grab a hard hat, put the right sticker on it, show up with a badge that looks right. It's got the contractor badge. I take a picture of it. I recreate it myself. Like there's all these things that are super easy. So think about that process. The good thing is a lot of, you know,
Aaron Crow (19:23.470): power plants, et cetera, they're small enough, they have few people on them. So if I showed up in that space and somebody doesn't know me, they may not let me in. But if I'm good enough at what I do or they're busy or whatever, I can get through. So that's the whole social engineering side. But I think the bigger piece is just to be proactive, right? Don't wait for a breach to tighten your defenses. And unfortunately, some of the things that we see in the industry is that we don't really see
Aaron Crow (19:52.960): a big change many times until something bad happens. Maybe it doesn't happen to you, maybe it happens to your neighbor, it happens to your competitor, whatever. And we use those to benefit or to justify the budget, the cost, the overhead, the implementation. But don't give up, like keep fighting, right? AI is rising, zero days are accelerating. All these things are not going to change. But yeah, that's it guys. Thank you for listening.
Aaron Crow (20:23.694): The AI thing is here to stay. It's really exciting. I love that a lot of the things that we talk about and that we're digging into are AI focused, but even beyond that, it's really just like, it's also scary at the same time. A lot of the guests that I ask, if you've listened to podcast, I always have that final question at the end where it's, in the next five to 10 years, what's one thing that's exciting come up over the horizon and one thing that's scary? Many times AI is both of those answers and it's both sides of the coin.
Aaron Crow (20:52.920): Till next week.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.