Then, Rob Allen from ThreatLocker joins us to default allow, and why that is still a really bad idea.
Rob Allen is a highly regarded IT expert with over 20 years of experience in the field. Throughout his career, he has shaped the narrative on how businesses can embrace technology to drive innovation while mitigating cyber risks. With a career rooted in technical field as a system administrator, technician, and engineer, Allen’s hands-on background uniquely positions him to bridge the gap between technical execution and business strategy.
Throughout his career, Allen has been a trusted advisor to small and medium-sized businesses while also supporting large enterprises, gaining invaluable insights into their distinct security and operational challenges. This extensive experience has cemented his reputation as a leading expert in cybersecurity and endpoint resilience.
Since joining ThreatLocker in 2021 as VP of Operations for EMEA, Allen played a pivotal role in driving the company’s regional growth through his deep technical acumen and focus on customer success. Now serving as ThreatLocker Chief Product Officer, Allen is at the forefront of developing groundbreaking Zero Trust security solutions that empower businesses to operate confidently in an increasingly hostile cyber environment.
Recognized as a trailblazer in Zero Trust endpoint protection, Allen has been instrumental in championing a “deny-by-default, allow-by-exception” philosophy to harden endpoints and networks. Allen’s thought leadership and practical insights have made him one of the most sought-after voices in the field of Zero Trust endpoint protection.
Security Weekly listeners save $100 on their RSAC 2026 All Access Pass! RSAC 2026 Conference will take place March 23rd to March 26th in San Francisco. To register using our discount code, please visit securityweekly.com/rsac26 and use the code 56U5SECWEEKLY! We hope to see you there!
While certainly not new, this new release, according to some, accomplishes the following:
Agree or disagree? I also find it interesting that Google itself gives you the outdated/legacy gsutil command to download them. This is the command that is running in the background on my Linux system:
Also, keep in mind that you will need at least 8TB of space to store them. Also, if you have not stocked up on storage, its too late, AI has already driven prices through the roof for RAM and storage, though I did manage to find a few remaining deals..
Really awesome Meshtastic device as Lilygo has taken the T-Display S3 and added a LoRa radio, antennas, and a battery. For around $65, its a nice looking device:
Before you poo-poo this, I believe it's actually awesome. This did not look like a script kiddie using AI, this looks more like an advanced team that actually knows how to use AI to assist with development. Their process: "From a methodology perspective, the actor used the model beyond coding, adopting an approach called Spec Driven Development (SDD), first tasking it to generate a structured, multi-team development plan with sprint schedules, specifications, and deliverables. That documentation was then repurposed as the execution blueprint, which the model likely followed to implement, iterate, and test the malware end-to-end."
I'm not certain exactly how this technology works, but here is what Crowdstrike is claiming to defend against BadUSB:
Given that, what happens when a device such as an IP-KVM or Webcam conducts BadUSB attacks? These do have to register as a keyboard at some point. I like the Kaspersky approach of requiring the user to enter a pin when a HID device is attached. I am also curious if they can detect USB device ID spoofing. The thing with a KVM is that its just a Linux device that you would normally allow HID access, so blocking this in the way Crowdstrike descibes would not be all that effective, yes/no?
This is a great find; vulnerable code has been there since 2015. AI actually provided an accurate summary:
"telnetd constructs the login command line from a template that, on non-Solaris systems, expands to something like: PATH_LOGIN " -p -h %h %?u{-f %u}{%U}". The %U expansion pulls directly from the client’s USER environment variable, which can be controlled via telnet -a/--login, and is not sanitized before being passed as the final argument(s) to login. If the attacker sets USER="-f root" and uses telnet -a localhost, telnetd ends up running /usr/bin/login -p -h -f root, which tells login to skip authentication and log in as root."
Also, this totally works on the latest release of Manjaro. Like a champ:
WhisperPair is a set of attacks against poorly implemented Google Fast Pair in Bluetooth audio accessories that allow attackers to forcibly pair with devices and, in some cases, track users via Google’s Find My Device/Find My-style network. Some facts:
Jericho's articles are a great read. I am pulling this out of context purely as a discussion point: " If there was a CVE assignment for every known or documented insecure behavior, it means one for every router with HTTP as a non-default option, any software that offers FTP even if not a default, etc. The amount of noise would make CVE even more worthless than it is." - My gut reaction is to disagree. Perhaps it would create A LOT of CVE entries, but if the point of CVE is to have a reference for as many vulnerabilities as possible, then why not? Who gets to decide what is a vulnerability and what is not? Perhaps context matters, as in, don't add it for all applications and devices, but only those that are popular and important? But again, who decides what's important and what's not? Do we need a different type of CVE record that catalogues this behavior? I don't have all the answers, but I am in favor of more CVE records and more importantly, properly funding resources for existing and expanded programs that deal with vulnerability databases and disclosure.
I'm not certain of the source of this information, but Bleeping Computer claims that the original patch does not work and attackers are still able to exploit patched Fortinet devices. If so, this is kind of a big deal:
I actually wrote this vulnerability here: - Its an authentication bypass, which is pretty bad.
Really cool: "This article explains how to turn a cheap unmanaged Ethernet switch into a firmware-defined data diode that enforces one-way network traffic using only EEPROM configuration changes on the switch."
Neat project, you could probably use your phone with an app, however, using the Flipper Zero is cooler and allows for others to contribute more easily.
Neat technique: "The decoded PowerShell script acts as the first stage downloader. Instead of fetching an executable from some disposable domain, it downloads a PNG image from archive.org, a legitimate and well-known website. When analysts review network logs and see traffic to archive.org, it typically doesn’t typically raise flags. The attackers are using the site's reputation as cover. But this isn't actually a standard PNG. Well it is, but with extras. The attackers embedded a Base64-encoded payload after the IEND chunk of the PNG, which marks the official end of the image data. The file still renders as a valid image in any viewer. The actual malware sits between two custom markers, BaseStart- and -BaseEnd." - Not a new technique, but using archive.org is a newly observed behavior.
This is an amazing project, discovery, and research: "This research shows that intentionally vulnerable training apps (like DVWA, Juice Shop, bWAPP, Hackazon) are very often exposed to the internet, tied to real cloud identities, and actively exploited as initial access for full cloud compromise." It gets better:
Love this project so much!
Awesome project: "This project describes how to modify a standard solderless breadboard so it properly fits wide microcontroller boards like the Raspberry Pi Pico and common ESP32 dev boards, while restoring ample prototyping space around them. It does this by reusing the original breadboard’s metal spring contacts inside a custom 3D‑printed body that preserves a full 63×5 layout plus dual side power rails, but with the inner rows spaced to match the wider MCUs so that four holes per pin remain accessible for wires and components."
"Trend Micro’s ÆSIR is an AI-augmented vulnerability research platform designed to find zero-days in AI infrastructure at machine speed while keeping humans in control of direction, validation, and disclosure. It has already yielded 21 CVEs across NVIDIA, Tencent, MLflow, and MCP tooling since mid‑2025, with multiple patch-bypass cycles caught and remediated."
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
