Dark mode: ON

Infosec Decoded Season 5 #23: Transformers

With Doug Spindler and sambowne@infosec.exchange

Recorded Tue, Mar 26, 2025

Politics

Why are other universities silent in condemning Trump’s attacks on Columbia?

The Trump Administration Accidentally Texted Me Its War Plans

Law firms refuse to represent Trump opponents in the wake of his attacks

Biden-era officials said they’re having trouble finding lawyers willing to defend them. The volunteers and small nonprofits forming the ground troops of the legal resistance to Trump administration actions say that the well-resourced law firms that once would have backed them are now steering clear.

New Trump demand to colleges: Name protesters — and their nationalities

The demand for student information came after the administration promised to deport non-citizens who participated in what it called “pro-jihadist protests”

Infosec

I helped build a government AI system. DOGE fired me

It was an "AI sandbox". Our goal: let federal software devs test out AI tools in a safe way. They demonstrated the tool as if it were amazing. Musk's GSA head Stephen Ehikian asked GSAi to "write me a website." The output was not compliant with federal law. It said "Welcome to Our Company" on it and did not resemble a federal website at all.

Part 2: Validating the Breach Oracle Cloud Denied – CloudSEK’s Follow-Up Analysis

On 21st March 2025, a user named rose87168 posted on BreachForums, claiming access to Oracle Cloud’s login servers and offering sensitive data. Oracle, later on the same day, responded with a categorical denial: “There has been no breach of Oracle Cloud.”

While the threat actor was able to share a sample list of customer details, the threat actor also provided evidence of the attack by uploading a file created on "login.us2.oraclecloud.com" and archiving the public URL, with the attacker's email within the text file.

A Sneaky Phish Just Grabbed my Mailchimp Mailing List

An emotion-inspiring message: "spam complaint," and an overlooked warning: password manager didn't automatically fill in the password.

The Device Throttling the World’s Electrified Future

A shortage of transformers is causing delays to power projects everywhere, holding trillion-dollar industries hostage—and that was before tariffs.