<p>This episode dives into the economics and competitive dynamics of the AI industry, including discussions on profitability, pricing strategies, monopolization, and the rise of open and distilled models—particularly concerns around Chinese AI competition. The hosts also cover a reported long-running phishing campaign linked to Chinese actors targeting NASA-affiliated researchers and engineers, highlighting how social engineering was used to extract sensitive aerospace information.</p><p>Join us LIVE on Mondays, 4:30pm EST.<br>A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.<br><a href="https://www.youtube.com/@BlackHillsInformationSecurity">https://www.youtube.com/@BlackHillsInformationSecurity</a></p><p>Chat with us on Discord! - <br><a href="https://discord.gg/bhis">https://discord.gg/bhis</a><br>🔴live-chat</p><p><br><strong>Chapters</strong><br></p><ul><li>(00:00) - PreShow Banter™ — Making More Money than OpenAI</li>
<li>(04:58) - NASA Gets Phished by Chinese - 2026-04-27</li>
<li>(07:22) - Story # 1: ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty</li>
<li>(13:07) - Story # 2: A Mexican surveillance giant you’ve never heard of is now watching the U.S. border</li>
<li>(19:59) - Story # 3: Scam messages offering ships safe transit through Hormuz, security firm warns</li>
<li>(24:24) - Story # 4: Apple fixes bug that let the FBI recover deleted Signal messages</li>
<li>(27:49) - Story # 5: Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign</li>
<li>(30:28) - Story # 6: cDc communications | CULT OF THE DEAD COW | The Hacktivismo Declaration: Rebooted 2026-04-21</li>
<li>(34:07) - Story # 7: NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software</li>
<li>(36:29) - Story # 8: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite</li>
<li>(41:34) - Story # 9: Discord group says it accessed Claude Mythos by guessing location</li>
<li>(44:19) - Story # 10: Introducing GPT‑5.5</li>
<li>(46:46) - Story # 11: CERT-In Advisory CIAD-2026-0020</li>
<li>(50:47) - Story # 12: pro j e c t d e a l</li>
</ul><br><strong>Links</strong><br>Story # 1: <a href="https://krebsonsecurity.com/2026/04/scattered-spider-member-tylerb-pleads-guilty/">‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty</a><br>Story # 2: <a href="https://restofworld.org/2026/mexico-seguritech-government-surveillance-profile/">A Mexican surveillance giant you’ve never heard of is now watching the U.S. border</a><br>Story # 3: <a href="https://www.reuters.com/world/middle-east/scam-messages-offering-ships-safe-transit-through-hormuz-security-firm-warns-2026-04-21/">Scam messages offering ships safe transit through Hormuz, security firm warns</a><br>Story # 4: <a href="https://www.bleepingcomputer.com/news/security/apple-fixes-ios-bug-that-retained-deleted-notification-data/">Apple fixes bug that let the FBI recover deleted Signal messages</a><br>Story # 5: <a href="https://socket.dev/blog/bitwarden-cli-compromised">Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign</a><br>Story # 6: <a href="https://cultdeadcow.com/news/declaration_rebooted.html">cDc communications | CULT OF THE DEAD COW | The Hacktivismo Declaration: Rebooted 2026-04-21</a><br>Story # 7: <a href="https://thehackernews.com/2026/04/nasa-employees-duped-in-chinese.html">NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software</a><br>Story # 8: <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware">How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite</a><br>Story # 9: <a href="https://mashable.com/article/discord-group-accesses-claude-mythos-claims">Discord group says it accessed Claude Mythos by guessing location</a><br>Story # 10: <a href="https://openai.com/index/introducing-gpt-5-5/">Introducing GPT‑5.5</a><br>Story # 11: <a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&amp;VLCODE=CIAD-2026-0020">CERT-In Advisory CIAD-2026-0020</a><br>Story # 12: <a href="https://www.anthropic.com/features/project-deal">pro j e c t d e a l</a><p><strong><strong>Creators &amp; Guests</strong>
<ul>
  <li><a href="https://bhisnews.transistor.fm/people/aisling-nic-lynne-siriciryel">Aisling nic Lynne "siriciryel"</a> - Guest</li>
  <li><a href="https://bhisnews.transistor.fm/people/corey-ham">Corey Ham</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/john-strand-8c127856-b150-4e33-af6d-5b9f7f041a37">John Strand</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/ralph-may">Ralph May</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/hayden-covington">Hayden Covington</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/wade-wells">Wade Wells</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/ryan-poirier">Ryan Poirier</a> - Producer</li>
</ul><br><a href="https://www.youtube.com/watch?v=R-24o6i0AMY" title="Click here to watch  this episode on YouTube.">Click here to watch  this episode on YouTube.</a><br>
</strong></p><p><strong><a href="https://share.transistor.fm/s/0cc3b040/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
</strong></p><p><strong>🔗 Register for FREE Infosec Webcasts, Anti-casts &amp; Summits </strong></p><p><a href="https://poweredbybhis.com/">https://poweredbybhis.com</a></p><p><br>Brought to you by:</p><p><strong>Black Hills Information Security </strong></p><p><a href="https://www.blackhillsinfosec.com/">https://www.blackhillsinfosec.com</a></p><p><br></p><p><strong>Antisyphon Training</strong></p><p><a href="https://www.antisyphontraining.com/">https://www.antisyphontraining.com/</a></p><p><br></p><p><strong>Active Countermeasures</strong></p><p><a href="https://www.activecountermeasures.com/">https://www.activecountermeasures.com</a></p><p><br></p><p><strong>Wild West Hackin Fest</strong></p><p><a href="https://wildwesthackinfest.com/">https://wildwesthackinfest.com</a></p>

Talkin' Bout [Infosec] News

Black Hills Information Security

NASA Gets Phished by Chinese - 2026-04-27

APR 28, 202670 MIN
Talkin' Bout [Infosec] News

NASA Gets Phished by Chinese - 2026-04-27

APR 28, 202670 MIN

Description

This episode dives into the economics and competitive dynamics of the AI industry, including discussions on profitability, pricing strategies, monopolization, and the rise of open and distilled models—particularly concerns around Chinese AI competition. The hosts also cover a reported long-running phishing campaign linked to Chinese actors targeting NASA-affiliated researchers and engineers, highlighting how social engineering was used to extract sensitive aerospace information.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Making More Money than OpenAI (04:58) - NASA Gets Phished by Chinese - 2026-04-27 (07:22) - Story # 1: ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty (13:07) - Story # 2: A Mexican surveillance giant you’ve never heard of is now watching the U.S. border (19:59) - Story # 3: Scam messages offering ships safe transit through Hormuz, security firm warns (24:24) - Story # 4: Apple fixes bug that let the FBI recover deleted Signal messages (27:49) - Story # 5: Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign (30:28) - Story # 6: cDc communications | CULT OF THE DEAD COW | The Hacktivismo Declaration: Rebooted 2026-04-21 (34:07) - Story # 7: NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software (36:29) - Story # 8: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite (41:34) - Story # 9: Discord group says it accessed Claude Mythos by guessing location (44:19) - Story # 10: Introducing GPT‑5.5 (46:46) - Story # 11: CERT-In Advisory CIAD-2026-0020 (50:47) - Story # 12: pro j e c t d e a l LinksStory # 1: ‘Scattered Spider’ Member ‘Tylerb’ Pleads GuiltyStory # 2: A Mexican surveillance giant you’ve never heard of is now watching the U.S. borderStory # 3: Scam messages offering ships safe transit through Hormuz, security firm warnsStory # 4: Apple fixes bug that let the FBI recover deleted Signal messagesStory # 5: Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain CampaignStory # 6: cDc communications | CULT OF THE DEAD COW | The Hacktivismo Declaration: Rebooted 2026-04-21Story # 7: NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense SoftwareStory # 8: How UNC6692 Employed Social Engineering to Deploy a Custom Malware SuiteStory # 9: Discord group says it accessed Claude Mythos by guessing locationStory # 10: Introducing GPT‑5.5Story # 11: CERT-In Advisory CIAD-2026-0020Story # 12: pro j e c t d e a lCreators & Guests Aisling nic Lynne "siriciryel" - Guest Corey Ham - Host John Strand - Host Ralph May - Host Hayden Covington - Host Wade Wells - Host Ryan Poirier - Producer Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com