Episode #
2

The Call Is Coming from Inside the House

Show Notes

This week on Dragon News Bytes, Eli Woodward and Will Baxter break down the operational fires you need to fight now and the emerging AI threats targeting your internal guardrails. We cover the critical FortiSIEM zero-day RCE, the rise of AI prompt injection attacks across Microsoft Copilot and Salesforce, and the massive 58% year-over-year surge in ransomware victims. Plus, we discuss the strategic impact of the Red VDS infrastructure takedown and our upcoming global event schedule.

Topics & References:

Part 1: Emerging Threats

  • FortiSIEM Zero-Day RCE (CVE-2025-64155): Critical remote code execution via the pH monitor service. If you use FortiSIEM, restrict TCP port 7900 immediately.

  • Red VDS Infrastructure Takedown: Microsoft’s disruption of a major "bulletproof" virtual desktop service used for fraud and financially motivated phishing.
  • Ransomware Surge 2026: A 58% increase in publicly posted victims compared to 2024, with 124 active groups now tracked globally.

Part 2: Emerging AI Threats

  • AI Honeypot Findings: Discovery of automated scanning for Open LLM endpoints (Claude, ChatGPT, Ollama) originating from a single German source.
  • AI Prompt Injection Attacks: New research into malicious prompts embedded in links that can hijack AI agents in Microsoft Copilot, Salesforce, and ServiceNow to steal user tokens and secrets.
  • The Three Pillars of AI Security: A strategic framework for defending from AI attacks, defending the AI your organization uses, and defending using AI tools.

Events & Community:

  • SANS CTI Summit Happy Hour (Arlington, VA): Join Team Cymru and OpenCTI on January 26th.

  • RISE USA (San Francisco): February 18–19 at Stripe HQ.
    🔗 to register: RISE USA
  • Brews and Briefings (Minneapolis): Late February session focused on DPRK threat activity.
    🔗 to register: Brews and Briefings
  • FS-ISAC Spring Summit (Orlando): March presentations on the latest fintech threats.
    🔗 to register: FS-ISAC Spring Summit
  • RISE Ireland (Dublin): April 14–15 at Stripe Dublin.
    🔗 to register: RISE Ireland

Connect with Us:

Disclaimer: The views expressed in this podcast are those of the hosts and do not necessarily reflect the official policy or position of our employers.