No. Chatbot answers can contain poisoned information, so verify important details against the organization's official source website before acting.
Searchable transcript of Can you trust your chatbot? Inside three AI-powered cyberattacks — IBM Technology (34:54). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 Hackers are sneaking malicious content right into people's AI chats and victims are none the wiser panel. Do we trust AI a little too much? Curtis, you first. >> A little bit for now. Remember, as we learned in an earlier episode, it's only in the third grade. >> I don't personally, but I think that there's a lot of people that do. >> Perhaps a bit too much.
00:24 Hello and welcome to Security Intelligence, IBM's weekly cyber security podcast where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your host, Matt Kazinski. Over there is your other host, Patrick Austin. Patrick, how you doing today? >> Doing all right. Uh not uh not uh dealing in any malicious pages today.
00:44 >> And joining us, it's straight back here from Burning Man, Kimmy Ferington, security detection engineer. It's Curtis Pitts, lead CISO Trust. and Dave McGinness, VP, senior partner, Global Cyber Threat Management, IBM Consulting. In this episode, we're going to be talking about three different AI enabled cyber attacks and kind of how they're changing the game.
01:01 Uh we're going to get into a threat actor who's been going on a real LLM assisted hacking spree and the threat actor who unleashed their own agent swarm on the internet because that's a thing you can do now. But first, we got to talk about dark sorcery. This is an attack that tricks AI chats into distributing malicious content. So, this comes from researchers at Vigilance Security who have identified this campaign they are calling dark sorcery, but it's spelled S O U R C E R E.
01:33 Get it? Get it? Uh, in which malicious actors are seeding the internet with misinformation and fishing links. It's a lot like traditional SEO poisoning attacks where thread actors would use SEO optimization techniques to get their malicious content to rank high in the SERs. Users trusted anything that showed up on the first page of Google and so they would end up downloading malware or giving away their sensitive info.
01:53 Same thing here, but now the attackers are preying on AEO optimization techniques or answer engine optimization to get AI chat bots like ChatGpt and Google Gemini to site their content in legitimate conversations. So, for example, you go to ChatGpt, you say, "I need the customer support number for X business." Some malicious page pretending to be that business gives ChatGpt the wrong number.
02:13 You call that number because you didn't double check and bam, you gave scammers your information. Uh, and because the info is coming from an AI, like I said, people are very ready to trust it. According to one study from Exploding Topics, 91% of people who regularly search uh on ChatGpt and and similar places said they don't verify the answers chat bots give them.
02:32 They just run with them. 91% of people. A little too high if you ask me. Patrick, what's going on with this story? What are you thinking about here? >> I'm thinking I should maybe double check my Google search results. That's for sure. Um, you know, with tens of thousands of malicious pages with false information, me trying to get to HP customer support, you know, through Google sounds like an absolute nightmare both for me and maybe my bank account.
02:56 So, I'm wondering, you know, um, you know, should Kimmy, should 91% of people, you know, trust the answers they get from their Google search? And what can Google do about this potential sort of poisoning of the well that is the internet? >> So, you see this scary face I'm making? This is because 91 is a very large number. And and at the same time, I know that it's representative.
03:21 Like even I even though I just started off saying that I don't trust AI that much. Even I am willing to accept AI's answer because it sounds reasonable and because I am knowledgeable enough on the topic that I asked it about that I probably could go with its answer. Um but at the same time, I catch it making mistakes and doing things wrong and saying stuff.
03:42 And I and I I do I do question my Google results, my overview results, but every but not everyone does clearly. And this whole SEI SEO thing, the the AE SEO if what did you what do you call it? Anyway, this whole thing is this is >> we don't even know what to call it yet, >> right? Like like this is just a new angle and the old trick, right? Like it's the same idea only now you're tricking agents.
04:08 Um and again, it's actually not that hard to trick agents. we've figured that out, right? Like you said, third grade. Um they're they're just learning. They're sort of coming up in the world. They're doing it really fast, no doubt about it, but uh but they still don't know um the same thing that we know in in the knowledge and and wisdom of of being able to uh determine, you know, more accurately, not completely accurately, but more accurately when we're trying when we're being tricked.
04:35 Um but it's everywhere. You know, we can't trust anything, can we? like the agents can't trust anything. No one can trust anything. >> With so many major companies affected, you know, many Fortune 100 companies according to the report around 374 companies affected, huge names, banks, airlines. What can these companies do to sort of I guess clean up the the mess that they are they are in?
05:01 It might not be their fault, but it kind of is their their problem to deal with when your customers are calling fake hotlines for your for your um you know to get get some support um with a plane ticket or a you know busted printer. Um Curtis, I I don't think you would appreciate calling a fake number if your flight gets delayed. was thinking about um all the spam calls that we get and this actually brings a story to mind from just a couple weeks ago um and the amount of effort that people are putting into getting
05:32 misinformation out to you to try to create that situation of vulnerability, right? And so so what happened a couple weeks ago just real quick um for about a week and a half I kept getting fake authorizations against my Google account, right? And so I was like, "Hey, this is obviously not me." I would decline them. Moving on, no big deal. uh that stopped and several days later I got a phone call from a spoofed Google number and so it showed up as Google.
05:57 I answered the the phone expecting it to not be Google. Um and listened to the spiel of this person, right? And they had the information like, "Hey, we were getting fake we were getting authorizations from Vegas. Obviously, you don't live there." Like went through the whole thing. They had pre-planned what they were going to spam call me with against my Google account.
06:18 And I actually gave this guy credit because I was like, you know what, man? Like, as much as I hate you as a human being right now, great job. Like, you put so much effort. Like, it's the wrong guy. Like, you called the wrong guy, but if you'd have called the right guy, you absolutely probably would have gotten the information that you needed. Um, now imagine that that's happening a million times a minute, right?
06:38 To as many people as you could possibly reach out to. Like the the problem is we get so comfortable in our lives and and we've gotten really good as industry partners and as big companies to say, "Look, we're never going to ask you for this code. We're never going to ask you for your password. We're never going to do that." But I don't know if that's enough.
06:59 I don't know if it's reaching enough people. If the text message is reaching the right people, if the email is even being read by those people, right? We have to to figure out a way to to inform everyone like look, just because they sound right and they look right and they've got some information doesn't mean that it's actually who you're talking to.
07:18 Go to the source websites yourself. Ask the questions, then go to the source website, right? Go to HP, go to ibm.com, go to microsoft.com. Um, go validate those things because it's so easy to put fake information out there now that, you know, seeding a chatbot isn't that complicated, especially until we learn to lock these things down properly. Um, protect yourself cuz the companies can't do everything.
07:43 You know, you have to take some responsibility for securing your own information and validating the things you're clicking on. >> Just to follow up on that real quick, you know, Curtis, I think you make a really good point here, which is that that was an extremely sophisticated attack. they, you know, launch it against someone who has the word trust in their job title, so they knew what they were doing.
08:01 But a lot of people don't have that, right? And so, like, we can sit here and recognize the hallmarks of an attack like that. But for your average user, you know, if they get a really authoritative Google call and they seem to know about activity on their account, you can't really blame them for falling for that, right? So, like, think about, you know, like you said, you give them credit, but you know enough to not, you know, go any further.
08:23 The average person doesn't, not through any fault of their own. It's just they're not doing this for a living, you know. Patrick, back to you. >> I think my my one question maybe was for for Dave and and it relates to the AI the AI themselves scraping the web for this content. How do they sort of verify that this content is from a trusted source? Um, you know, the same way, you know, search engines would verify whether a website was a trusted source.
08:48 Um, I feel like, you know, when you're back in the day before an AI search engine, um, you would do a search for something, you'd maybe read a small summary and maybe check the URL and if it looked a little, uh, weird or unfamiliar, you'd say, "Hey, maybe not that one." But now the AI has sort of obiscated that source point in a way. Um, is there any way for for companies to combat this and restore I say restore a users's trust in what they're looking at is sort of accurate?
09:18 >> Yeah. Well, so I think what we're talking about, right, is like what what is what's what's this attack really attacking? It's it's attacking trust, right? Right. So So everybody's thrown out some version of trust but verified. Glad to hear it's not dead, right? So, you know, sometimes the tried and true, but I mean this is this I mean we can go back to this this poisoning the the information system like this is just yet another you know uh attack vector that that AI is now exploiting.
09:49 Uh we've been doing it forever. Um War the Worlds anybody? I mean it was fake but people thought aliens were attacking because they trusted the voices on the radio, right? Like that was as far back as I could come up with. Like I was like propaganda that's not so good. I like that one. I like the War of the Worlds one. So, you know, that's kind of what this is.
10:10 Like, you know, did you call anybody and see if the alien was actually there? No. Okay. Um, and sorry, I should have said spoiler alert at the beginning of that for anybody. That's that's pretty dated. >> Yeah. Now I don't have to go listen to the radio cast. I appreciate you have to listen to the radio. >> It's good to know. Yeah. But >> there's a great version with Tom Cruz you should really watch.
10:29 I'm sorry. Just going to say >> slightly more realistic than the radio, I guess. But there's not a whole lot that you can do, right? I mean, this is this is kind of like the lowest common denominator. I poison the water source, drinking for the water. Like, oh, that tastes bad. Well, stop drinking it, right? You know, so, you know, yes, AI governance can go a ways, right?
10:47 Uh, education's going to go a long ways. Um, but one thing that we've been talking about that we didn't pivot to is why do we assume that it's always going to be a human on the other end of this? What if what if another agent that isn't terribly informed? What are we in third grade? All right. What if another third grade agent is on the other is on the consumption end of this?
11:13 And it could be my avatar. It could be your avatar, right? Like whatever whatever it may be, right? So So we're just scratching the surface of what what this is, right? I don't think anybody's so Patrick he will come to know I say we shouldn't be surprised >> like like this is not a new attack >> this is not a new attack this is this I mean we search engine optimization being hijacked so that you know bullsh and and whatever it has been when you attack the information itself um trust gets thrown in the mix and you
11:44 either don't trust anything or you have to put you know things in place that would um ensure trust, right? So, we found ways to say like, hey, when I click on this particular website, you know, um they are who they say they are and I am who I say I am and we can now go execute this transaction, right? Um, and while that we think of that in in much more, you know, rigid terms like I'm going to log into my bank and I'm going to do this whatever business, um, it doesn't it we could apply those sorts of techniques to
12:19 consuming the information that you're, you know, that's being scraped up, right? So, um, you know, the good the good thing about like reusing problems is that you just need to find the the modern version of the solution. >> Absolutely. And on that wonderfully ambiguous note, folks, I got to move us along to the next uh topic here. But if I do have to summarize what what we said there, I'd say, you know, you as a human being, you still have a a strong responsibility to verify what you're looking at.
12:44 And if you're not already thinking about how you're going to teach your agents to do the same, start thinking about that cuz you're going to have to address that problem. Uh but our next story this week, folks, the hacker going on an LLM assisted tear. So this comes from threat intelligence firm Grey Noise uh reporting that a threat actor has been on a monthsl long explo exploitation spree since at least June.
13:10 Uh the actor has worked through critical flaws in Ubiquiti, WordPress and Zeil switches and it has walked off with thousands of documents from at least one western government. Uh, Grey Noise believes the thread actor is using an LLM to develop the tools they are using to get into these systems, including perhaps 17 different scripts that let it slip past Microsoft's anti-malware scan interface.
13:29 Uh, Grey Noise isn't sure exactly who this threat actor is and why they're doing what they're doing, but the scale of the infiltration has people watching. Patrick, what caught your eye about this one? >> Interesting enough, what caught my eye was a sort of almost philosophical difference in the sort of security outlook um, in the Grey Noise report.
13:46 Um I would just I'll just read read the quote. One security opinion is that adversaries rotate through IP addresses such that blocking them is a fruitless endeavor. Um and they noted about this particular um actor is that he used the same IP address to attack a bunch of um decoy um uh serve honeys. And I'm wondering if that is a um you know if that is a testament to the sort of positives of following sort of basic cyber security hygiene, basic cyber security practices.
14:21 Um Curtis, what do you think? >> Yeah, one of the things I've said every time I've been on one of these is the basic rules of hygiene will protect the vast majority of these vulnerabilities. Um, you know, I was looking into some of the vulnerabilities that were exploited in this particular attack or set of attacks. Um, and like for Ubiquiti, they were released in May as was the patch, right?
14:47 The new updated OS and these exploits were done 20 20ome days later. Um, it just emphasizes something we've we've been talking about a lot in CISO anyways and I talk a lot with clients about and it's the speed at which you have to to update these things. They were all listed as critical vulnerabilities. Um, though to be very clear that's not that all critical vulnerabilities are actually critical vulnerabilities, right?
15:11 There's a lot of variables that go around a vulnerability to determine its actual criticality. Assigning a CVSS score does not mean, oh my god, the world is on fire. But it also doesn't not mean that sometimes, right? So, uh, we have to make sure that that we're we're remediating things as they're released, especially for such important pieces of your equipment, like something that runs your entire network.
15:34 Um, and then, you know, the further in you get, pretty much all of these were related to authentication, identity management, like lock your doors. Anything that deals with locking your doors, validating who your people are, validating the access, validating the traffic is coming from where it's supposed to. Um, making sure the call's not coming from inside the house.
15:54 Right. That's the important thing. We have to make sure that we lock our digital doors to your point of basic cyber hygiene. Um, it we every time we see one of these news stories, somebody overlooked a very basic point of cyber hygiene. Yeah, it seems like a a an exploitation of multiple vulnerabilities and multiple technologies um using an LLM by one person.
16:18 How does an organization or how do organizations combat something like this? They can't, you know, I can't go around fixing another company's vulnerabilities for them, can I? Yet, I'm still affected by them. Um Dave, what's the what's the solution? Or did I just unplug everything? I think what we're talking about um right, you know, you AI is as a multiplier, right?
16:44 It's a force multiplier and it's going to multiply the force of whatever it is you're trying to go do, right? Good, bad, meh, right? If if cat memes is your thing, you can generate a whole lot more using AI, right? So, um it's a force multiplier. So, what we're talking about now is a single person, you know, exploiting at scale, right? um you know that all that compute has to do something right so so this is just this is just again it's the natural natural way right as Curtis talked about and and giving right we're not
17:16 we're not trying to protect something that we don't know this isn't alien technology um this isn't you know something that we've not been building on for decades right we know how to close the doors um maybe we could turn the crank a little bit more right like like hey maybe we could segment some things a little bit more. Maybe not everything has to be on one big A network, >> right?
17:41 So, one of those big big ones big area area networks. Yeah. Yeah. >> A ban if you will. >> Yeah. It's the same concept, right? It's just access control and and permissions and you know, arbback and all that good stuff again, but maybe you do it on a smaller smaller scale. You can also use the compute. you can also use the ex uh the the the the scale of these tools and these these tools to defend, right?
18:10 So, we're seeing the same types of attacks going off being powered. The same sorts of defenses can also be powered. To expand on Dave's point a little bit too, we talked about ghostjacking in the in the in a different um episode and and that really kind of highlighted when agents have too much authority and too much ability to not necessarily scale vertically but to move laterally within an organization.
18:37 Um it doesn't take a lot if every door in the house is unlocked. All you got to do is get in, right? So it's the the problem exists when we're, you know, we're lax on zero trust and we're lax on our authentication mechanisms and like I know for smaller businesses maybe they don't they don't have the resources to think these things through at a grandiose scale and but for large businesses you're under the problem of we have you know hundreds of thousands of people and any one of them can make a mistake or can leave
19:06 something open or can accidentally click the wrong link. Um it for bigger you know businesses it's it's a a governance problem but it's a governance problem in a train your people do your validations but your people have to be responsible. Um and there's only so much that you can do about that. For the smaller businesses if you're not thinking about it think about it right lock your doors.
19:30 Find a way to lock up your digital assets. Do not give everyone the ability to access everything. They don't need it. Um, and that will at least lessen, not remove, but lessen the threat of some of these things, you know, virtually punching you in the face. >> And that's easy to say until you start introducing agents into the mix. And the people who are controlling those agents don't have a a real good concept of how to control the agents.
19:57 And the agents are reassuring them all along, saying, "Don't worry, I got this. Everything's fine." as they go off and attack some other, you know, company on the internet that they're not supposed to be talking to. Yeah, >> Kimmy, I'm glad you brought that up because this I, you know, I've been thinking about this a lot recently, which is like how amaz like we've spent so long talking about zero trust, trust but verify, and you know, don't never trust, always verify, all this stuff.
20:23 And then agents come along and immediately people are like, I'm going to trust this thing to do everything, you know, which is it's nuts to me because we don't even most of us don't even really know what's going on under the hood. We're just like, "Oo, I can put this agent there and I can connect it to everything and it does all this stuff for me." And it's like all this basic security hygiene just flies out the window when you're confronted with the magic agent.
20:42 You're like, "Oh, oh, look at this thing." >> And a big part of that came with when the companies that rolled it out to us brought it to us. They didn't provide any sort of security net. There was no security hardened in or anything like that. There was some guard rails. It's supposed to be a good agent and not do bad things for you. And that was a good start.
21:01 But after that we, you know, we being humans immediately took it over and did whatever we wanted with it, which was in many cases nefarious things, right? >> Dave, I think you I'm pretty sure you were on the episode where we talked about Open Claw when it came out and just like all the things happening with that. And I don't remember if it was that episode or another one, but it's one of my all-time favorite Daveisms, which is uh AI is the most helpful insider threat we've ever had.
21:26 And I really feel like time and again that bears to out being the truth here. Um but folks I do have to move us along to our final story uh uh for the week. Uh this is an AI swarm hits paper cut. So we got another report from Grey Noise here. This one focuses on a threat actor who used a swarm of hundreds of AI agents to breach print management software.
21:56 Paper cut. paper cut rather. Once the agents were inside, they went after the victim's Windows Active Directory environments. Uh Grey Noise says the campaign hit at least at least 440 paper cut instances belonging to 395 organizations in 48 countries. A couple of interesting details stuck out for me personally here. The first is how quickly this attack moved.
22:16 Uh according to uh Grey Noise, this attacker went from an empty workspace to remote code execution on a victim in just about 4 hours. uh which is a wild time frame. And the other interesting thing to me too is that this this threat actor, whoever they are, also couldn't really control their agents. There were there was evidence that suggested they were trying to limit what countries got hit and the agents hit countries they weren't supposed to hit anyway.
22:39 Uh which doesn't really surprise me if even like, you know, Open AAI and Anthropic struggle with this kind of thing. I'm not surprised that the threat actors are struggling with it. Uh but Patrick, uh let me throw to you here. What caught your eye about this story? This is maybe my favorite um terrible story of the week. Um because of sort of how how futuristic, how cyber punk it sort of felt to me to go from to go from nothing to hacking 440 instances of the of the software in 48 countries in under a day in an
23:13 afternoon essentially. very William Gibson um you know count zero when he plugs his head into the into the net and immediately fries his brain um because he doesn't know what he's doing. Um I I also thought that the the the um trend of LLM jacking sort of stealing developer credentials was very cool too. um to to borrow almost like you're tapping into electricity on the on the grid or or your neighbor's cable um to get some to get some free compute.
23:46 Um so Curtis, I'm I'm wondering how how likely is it that I'm going to see sort of wires hanging out of my apartment building because my neighbor is tapping into open AI compute power. >> Yeah. I mean I mean it started back with payoneses, right? Like hackers, anybody, right? Let's get let's get a cracker jack box and just blow a whistle and suddenly we can get free longdistance calls.
24:09 Um we've just moved along. Yeah. Like we just we've moved along, right? We had cloudjacking when when cloud accounts were new and people were using cloud compute for free and um I mean it's it's just the next version of that. It's everything old is new again as uh Evilmog said on my first ever security intelligence podcast. Uh and that's really just it's the case where Dave has hit on this.
24:32 Um, I I don't think it's quite that likely. I don't think we're in Ready Player One scenarios yet here where we're all going to plug into to the internet and uh and live our lives virtually. But um I I think it's important that the developers don't necessarily know how to protect and by protect I mean corral their own agents, right? See hugging face.
24:55 Um, I don't I don't expect the evil malicious actors to do any better, but that's slightly more terrifying because anybody with an idea and a computer can potentially wreak havoc on people that aren't paying attention. Um, there's another quote in that story u from the Google Thread Intelligence Center where she shearkens back to everything we've talked about, right?
25:20 Like all you have to do is put basic security in place and a lot of this gets shut down, right? Multiffactor authentication, pass keys if you can use them. I do know some technologies can't accept pass keys. Um but you know, multiple ways to protect identity and access management, authentication, like lock it down so that people are forced like it is more cumbersome to the user to do that.
25:44 I understand. Um, but there's also a point where we have to put some of those guardrails in place because the world isn't going to do it for us and we're responsible for the data that we protect, right? At the in in the information age, to quote one of my early directors, in the information age, the information is the gold, right? And we're protecting all of that gold.
26:07 And you have to build your Fort Knox. You can't just walk in to the to the the vault in Fort Knox, right? You have to protect that gold. Uh, and that's one of the things that I every single time I read one of these stories, somebody didn't do that and then somebody got in and then they blow this whole thing up into a huge problem. I'm like, you didn't do step one first thing you were supposed to do and then you got mad that somebody exploited it.
26:32 It's hard cuz I feel for all of those scenarios because there are budgetary issues, there's governance issues, there's constraints and business and the board wanting you to put something out and to be faster and to be leaner and to be cheaper and everything else. >> There's always reasons, man. >> There's always a reason, but we have to do the fundamental things or these will keep getting worse.
26:54 There's there's not a scenario where they just stop happening, right? So, we have to protect against them. Is there a scenario where we use these tools to sort of identify these weak points in our own organizations? Why? Where's the tool that you know where's the AI tool that is saying X% of our employees are not set up for multiffactor properly? These servers are not configured properly.
27:15 Um, and how do we sort of make those more um I guess maybe more easy to to sort of adopt? I was going to say, I mean, if we're doing it right, we do have those some of those tools in place or at least we're we're creating those tools now, right? We're coming up with those those tools to handle those things. Um, one of the big things that we've been sort of trying to wrangle all along is how do we give agents access management, you know, how do we identify them separately from the human that generated them and who is
27:47 the ultimate responsibility for that, right? Um, you know, there's tools all through the environment. We're constantly trying to come up with something else. Yes, we're throwing def defense AI at the offensive AI as fast as we possibly can, but unfortunately it's always a reactionary thing. We're always running around whacking the mole and trying to, you know, just kicking our knee as fast as we can because because they're they're coming at us and we don't, you know, we don't have the chance to.
28:13 But yes, locking the doors, you know, keeping keeping things se segmented. Um, my submarine won't sink if if all of the all of the important compartments are locked and closed and if I get a breach on the outside and one gets us gets a little hole in it, you know. Uh, but just to bring it back to, you know, my military training. Uh, but that said, um, you know, what are we going to do with these agents, man?
28:38 Uh, I don't know. They're here to stay for sure. We got to train them better. We got to teach them better. Uh, because they don't know ethics. They only know what they read on the internet and there's a lot of garbage on the internet and now a lot of it's being written by them. So, so what do you know? >> Yeah. Let's say they're adding to it just to validate their own answer.
29:03 >> Exactly. >> When you think about what we've talked about today, right? So, like our first our first story is about, you know, exploiting trust and disinformation. Right. The second one we were talking about the scale of the attacks, right? And like how quickly, right? Now this last one's really m is it the speed element of it right? So, you know, like we've been saying like no attack vector will go untouched, right?
29:23 Um, so, so, you know, it's here. You have to do it. So, um, I think if we can take this as a wake-up call, and we really, really should. If we take this as a wakeup call, we have an opportunity to rethink how we put our defenses in place, right? I don't need to create a new one, right? We've already said that, right? I think we've been, you know, very clear like go lock your door, right?
29:47 like like validate who's walking through, right? We're not talking about doing things that we don't know how to do. But when you look at enterprise security today, you have silos across all of these different things. The identity team doesn't have any idea what's going on in thread intelligence and what the thread actors are actually doing. What are the adversaries trying to pose as, right?
30:08 Uh the network teams, you know, um you know, micro segmentation just another thing, right? I'd rather just keep going the way that I'd rather go. I'll just deploy agents to to to apply policy changes quicker. Okay. Right. So like look, we have we have the technologies. We have the ideas and we have the ability to apply those technologies to those ideas to actually bolster defenses to do the things that like oh in a perfect world, right?
30:37 Like we'd consume a piece of thread intel, we'd process it, we'd score it, we'd automatically test and see if it's a problem, create a response for response for it, and and through either mitigation or actual resolution, it doesn't matter if they attack me because I've now been prepared. >> That's a beautiful dream. I love it. Let's do it. >> That's not a dream.
31:01 That's what we do every day, Kimmy. That's our dream. That's our That's our north >> star every day. >> Right, >> Dave? I want to I want to thank you for kind of doing my job for me here and beautifully summarizing the entire episode. I I do feel like in a lot of ways we did spend like the last 30 minutes just telling people to lock their doors, but you have to tell people that.
31:21 Like believe it or not, AI has made a lot of people forget about door locking and and and we just have to show up and be like, "Hey, by the way, did you lock those doors?" But folks, that does it for this episode this week. That also does it for me. This is my last episode with Security Intelligence. Uh, I am immensely proud of the show that we built over the last year here and I'm leaving it behind in very good hands with Patrick who's going to take up the hosting mantle going forward.
31:45 Uh, well, I I have you all here as a captive audience. I just kind of want to shout out everyone who's made the show possible. Uh, thank you Pedro, Giovanni, Andre, Mark, Ellie, Amber, Selma, Alex, Brian. I'm probably forgetting people. Uh, uh, but thank you so much. Thank you, of course, to our panelists here, Kimmy and Dave and Curtis, and every panelist who's been on the show and will continue to be on the show.
32:05 Uh, thank you to the viewers and the listeners. I'm going to miss talking to you all in the YouTube comments, but now you get to yell at Patrick whenever the show fails to address whatever very specific problem you had. Uh, Patrick, I look forward to seeing how everything evolves under your stewardship. And to the rest of you out there, just know that that this is not the end of the show.
32:23 So, please subscribe to Security Intelligence wherever podcasts are found so that you do not miss an episode. >> Very grateful to you, Matt, for your for your guidance and your wisdom and what you've done with security intelligence. It's it's a delight to watch you host every week and to to have you connect with such passionate, intelligent guests and make cyber security just such a a an exciting topic to to um you know, pay attention to every week.
32:51 So, I'm happy to um attempt to fill these gigantic shoes you've left me. Um I'm going to have to hit the gym maybe, but we're going out on an insult on my foot size. Uh >> yeah, I was going to say it can't be all can't be all crazy. You know what I mean? I got to get my digs in while I can. Um but you will be definitely um missed by by me and and everyone uh involved.
33:16 So, thank you so much. >> Yeah, absolutely. Thank you, man. We appreciate a lot of time on that hair getting it as long as yours. >> It's never mind. I've used all the serums and all of the powders. They don't It's just not working. >> We got a real duality of man thing going here with the the balls and the law. You know, >> our buddy cop show where we where they put us back to back.
33:37 It's going to be great. >> Matt, we're going to miss you. >> It's been a really good time. Hey Matt, I just want to give you a million trillion infinite amount of thank yous for everything you've done for the security intelligence podcast and um really for cyber security more broadly at IBM. Uh you are an insanely talented writer, editor, and storyteller.
34:07 And seeing you take the reigns of the Security Intelligence podcast as its host this past year has been so so inspiring. Um you have such a natural gift for this and I'm so glad and so grateful it was you uh to help start this thing from the ground up. Um, we will sorely miss you, and that's putting it very mildly, but I know you are going to go on to do amazing things, and I can't wait to cheer you on from the sidelines with whatever those are. >> Think that does it for this episode.