Scinary Information Nexus

Scinary Cybersecurity

Scinary Cybersecurity is here to "Serve and defend those who serve and defend others". To help us "serve and defend" we pull from many different sources - experts, colleagues, industry standards, etc... We hit every subject from all angles making it easy to understand while also letting us go in depth. Making this podcast perfect for cybersecurity beginners and experts alike. Come join us on our journey to constantly educate ourselves and explore the amazing things that are happening in our industry.

  1. 5d ago

    Episode 60: Cloud Persistence: Rogue MFA, OAuth and Passkeys

    Welcome back to the Scinary Information Nexus! This week, the crew had to toss their planned agenda out the window. Richard, Joseph, Mario, and Brazos jump in for an emergency breakdown of an aggressive phishing wave battering K-12 school districts and higher ed institutions. Attackers are weaponizing legitimate Google Docs and using Adversary-in-the-Middle (AiTM) proxies to harvest credentials and bypass traditional MFA. Because the phishing notifications originate straight from Google's own servers, they breeze past standard SPF, DKIM, and DMARC checks. Once inside, threat actors hijack internal distribution lists to spread laterally, creating a virtual denial of service for IT teams through sheer operational attrition. Even worse, standard password resets aren't cutting it. Attackers are locking in persistent cloud access with rogue OAuth application grants, hidden MFA enrollments, and rogue device keys. We break down how this campaign works, examine the CAPTCHA fatigue driving users straight toward ClickFix social engineering lures, and share concrete hardening tactics you can implement inside Google Admin right now to lock down your domain. In this episode: Anatomy of the breach: How weaponized Google Docs bypass email authentication filters. AiTM in action: Why traditional MFA fails against adversary-in-the-middle session theft. Cloud persistence traps: How rogue OAuth permissions and device keys survive password resets. Denial of service by attrition: The hidden toll of high-velocity account takeovers on IT teams. CAPTCHA fatigue: How flagged outbound IPs prime users for ClickFix social engineering. Hardening Google Admin: Disabling student directory lookups and ditching formulaic passwords. The Google Workspace dilemma: Free EDU tiers and gated security features. Has your organization noticed a spike in AiTM phishing or Google Docs lures lately? Let us know in the comments how your team is responding! Connect with Us: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 01:45 Google Docs Phishing & AiTM MFA Bypass 07:00 Cloud Persistence: Rogue OAuth & Device Keys 11:45 IT Attrition & CAPTCHA Fatigue Risks 21:15 Hardening Google Admin & Zero Trust 33:45 Google Ecosystem & Prompt Injections Cybersecurity #InfoSec #Phishing

  2. Sep 25

    Episode 59: Texas Drops TAC 219: What New AI Rules Mean for You

    Welcome back to the Scinary Information Nexus! Texas is teasing us with a little "false fall" weather, and the crew is back in the studio to talk through brand-new state AI mandates, sneaky phishing tricks, and some classic hacker trivia. This week, Richard, Joseph, Mario, and Brazos break down the newly released Texas Administrative Code TAC 219. If you work in Texas local government, a state agency, or a K-12 public school district, big changes are heading your way. From naming an official AI Risk Officer and adopting the state AI code of ethics published by DIR to inventorying AI systems and handling "heightened scrutiny" assessments, we walk through what IT teams actually need to do right now. We also look at a new ransomware-as-a-service strain hitting edge devices, plus compromised Google accounts sharing docs that trigger real Google CAPTCHAs to fool users. To wrap things up on a fun note, the guys face off in a retro cyber trivia showdown featuring phreakers, Cap'n Crunch whistles, the Morris Worm, and Janet Jackson crashing hard drives. In this episode: TAC 219 explained: What Texas's new AI governance rules mean for local government and public schools Designating an internal AI Risk Officer and adopting DIR's AI code of ethics What counts as a "heightened scrutiny" AI system and how impact assessments work The compliance headaches of commercial software with built-in AI features A new Rust and C++ ransomware-as-a-service strain targeting edge devices and SSL VPNs Compromised Google accounts abusing shared docs and CAPTCHAs for phishing Cyber history trivia: Blue boxes, Cap'n Crunch, the Morris Worm, and who really coined "EDR" Is your organization prepared to inventory every AI tool you use, or does TAC 219 feel overwhelming? Let us know in the comments! Connect with us: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 04:50 Cyber News & Google Docs Phishing 11:15 TAC 219: Texas AI Governance Breakdown 37:45 Retro Hacking & Cybersecurity Trivia 48:30 Road to 500 Subscribers & Wrap-Up Cybersecurity #InfoSec #Phishing #Ransomware #TechNews #Compliance

  3. Sep 18

    Episode 58: Is Your MSP Actually Securing Your Network?

    Welcome back to the Scinary Information Nexus! This week, Richard, Joseph, Mario, and Hunter tackle the messy reality of third-party risk and what they call "The MSP Dilemma." First up, the guys look at an incident involving an AI translation device called Timekettle, which was caught routing local Texas government traffic back to Shenzhen, China. The vendor tried to blame "legacy IP attribution," but it's a great example of why you can't just blindly trust your tech vendors. From there, they discuss Managed Service Providers (MSPs) and a major friction point in IT: organizations need MSPs for daily operations, but most providers are built for availability, not security. Later in the episode, the team covers a massive wave of Google EDU student account compromises. Hackers are bypassing traditional MFA and email filters using tactics like AiTM (Adversary in the Middle), ClickFix, and ConsentFix. By automating these attacks and manipulating email headers, threat actors are turning basic student accounts into high-volume threats. Topics covered: The Timekettle incident: When translation devices phone home to China Why 80% of security breaches involve compromised identities The MSP Dilemma: Balancing IT availability with cybersecurity A sneak peek at Scinary's upcoming GRC tool How hackers bypass MFA on Google EDU accounts The rise of AiTM, ClickFix, and ConsentFix tactics Why NIST 800-53 emphasizes strict third-party agreements Is your IT provider actually securing your network, or just keeping the lights on? Drop your thoughts in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 01:30 The Timekettle Debacle 09:45 The MSP Dilemma 24:45 Free GRC MSP Assessments 30:45 Google EDU Compromises 45:15 Wrap-Up & Weekend Banter Cybersecurity #InfoSec #MSP #DataPrivacy #Hacking #Phishing #NetworkSecurity

  4. Sep 11

    Episode 57: Cybersecurity Myths Debunked: AI, VPNs & Cloud

    Welcome back to the Scinary Information Nexus! Richard Martin is back from his month-long break, joining Joseph Hamilton, Mario Ortiz, and Brazos Wortham for a new episode. This week, we're talking about cybersecurity myths that trick organizations into wasting money and weakening their defenses. We look at the marketing hype around AI threats and the illusion of default cloud security. We also talk about why consumer VPNs aren't the privacy shields they claim to be. Plus, we explain why treating a compliance checklist like an actual security strategy is a terrible idea. To wrap things up, we chat about why tools like EDR and MFA aren't silver bullets. As always, basic security hygiene and blocking and tackling are still your best defenses. In this episode: A recent CrowdStrike vulnerability involving malicious macros Why AI is just automating old attacks, not creating new ones The truth about consumer VPNs and online anonymity Why passing a compliance audit doesn't mean you are secure The myth that small businesses are too small to be targeted Blind spots in the cloud "shared responsibility" model How the team phished eighth graders with a fake drink promo Why relying on EDR and MFA as silver bullets is a mistake Which of these security myths surprised you the most? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 05:05 The AI Cyber Attack Myth 12:40 Do Consumer VPNs Keep You Safe? 16:50 Why Compliance Doesn't Equal Security 24:10 Why Small Businesses Are Ransomware Targets 32:00 The Shared Responsibility of Cloud Security 40:40 Phishing Overconfident 8th Graders 47:00 EDR, MFA & Supply Chain Risks Cybersecurity #InfoSec #Phishing #Ransomware #SocialEngineering

  5. Sep 4

    Episode 56: Untitled Episode

    Welcome back to the Scinary Information Nexus! This week, Brazos and Joseph hold down the fort for a two-man episode. We review the new executive order pushing for "free" cybersecurity for critical infrastructure and question how it will actually be funded. We also debate the controversial authorization of private companies launching offensive cyber "hack-backs." Allowing private entities to retaliate against attackers could cause massive collateral damage on shared infrastructure like AWS and Cloudflare. For the main topic, we answer a viewer question: What do you do if you inherit an organization with no cybersecurity? Brazos explains the governance side with a 5-step foundational plan starting with risk analysis. Joseph offers the technical approach, advocating for immediate network segmentation to stop the bleeding. From locking down firewalls to dodging the "bystander effect," we outline how to build a security program that continuously improves. What we cover: The new executive order providing "free" cybersecurity to critical infrastructure The unintended consequences of legalizing corporate "hack-backs" Why risk analysis and strict asset inventory must happen first Governance vs. Action: When to educate leadership vs. when to lock down the firewall Why delegated authority is crucial for enforcing technical controls Deploying critical controls like MFA and backing them up with written policies Avoiding "deferred maintenance" and keeping your security program alive What is the very first thing you would do if you inherited an unsecured network? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 06:45 Free Cyber for Critical Infrastructure 10:15 The Dangers of Offensive Hack-Backs 15:30 Step 1: Risk Analysis & Asset Inventory 25:00 Step 2: Leadership vs Immediate Action 31:30 Step 3: Delegated Authority & IT Roles 51:30 Steps 4 & 5: Controls & Written Policies 59:30 The Final Step: Continuous Improvement Cybersecurity #InfoSec #HackBack #CriticalInfrastructure #NetworkSecurity #RiskManagement #MFA #CISA #AccessControl

  6. Aug 28

    Episode 55: ClickFix & Phishing Attacks: The Back-to-School Surge

    Welcome back to the Scinary Information Nexus! While Richard is away enjoying his August hiatus, Brazos, Joseph, and Mario are holding down the fort. With the back-to-school season in full swing, the SOC team has been battling an absolute blazing inferno of cyber threats. The guys debrief on two major attacks currently hammering networks: highly evasive "ClickFix" malware campaigns and relentless Business Email Compromise (BEC) attacks. Threat actors are getting clever, injecting fake CAPTCHAs into legitimate websites to trick users into running malicious PowerShell scripts. Meanwhile, credential harvesters are using trusted services like Google Docs to bypass email filtering and build massive databases of compromised accounts. Ultimately, these attacks expose a real problem: modern cybersecurity education is failing. Because end-users have become overly trusting of automated security tools, they've let their guard down. The crew debates how to fix this broken system, joking about the ineffective "D.A.R.E. program" style of current compliance training. In this episode, we discuss: The massive back-to-school surge in SOC alerts and incidents. How ClickFix uses fake CAPTCHAs to trick users into executing malware. Why threat actors use trusted sites like Canva and Google Docs to bypass filters. The rise of Initial Access Brokers and credential harvesting through BEC. Why traditional compliance-based cybersecurity training is failing end-users. How to modernize user education with real-world, local examples. The debate over implementing consequences for "habitual clickers." Do you think employees should face real consequences for continuously failing phishing tests? Let's discuss in the comments. Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 04:30 The ClickFix Epidemic & Fake CAPTCHAs 19:30 BEC & Google Forms Credential Harvesting 31:00 Why Cybersecurity Education is Failing 41:00 Rethinking Training & User Consequences Cybersecurity #InfoSec #ClickFix #Malware #Phishing #SecurityAwareness

  7. Aug 14

    Episode 54: The Consumer Cybersecurity Gap: Botnets, Gamers & ClickFix

    Welcome back to the Scinary Information Nexus! Brazos, Joseph, and Mario are holding down the fort. After reviewing this week's beer selections (and swearing off Jeppson's Malort forever), the guys tackle the grim realities of critical infrastructure attacks. With water treatment facilities and power grids being targeted by nation-state actors, why is the general public left with survival-level advice like "learn how to boil water"? The team then breaks down the consumer cybersecurity gap and explains why the industry naturally chases enterprise money, leaving everyday users with weak, fragmented protections. Relying on built-in tools like Windows Defender or forced bloatware like McAfee creates a dangerous false sense of security. Since government guidance from agencies like CISA is hopelessly outdated, you need to understand the actual threats hitting your home network. In this episode, we discuss: Why critical infrastructure prioritizes availability over security, leaving utilities vulnerable to nation-state actors. The consumer cybersecurity gap and why everyday users are ignored by enterprise security vendors. How "free" antivirus and forced bloatware like McAfee create a false sense of security. Social engineering on Steam forums and how gamers are tricked into installing ClickFix and XMRig. Why modern malware doesn't slow down your computer, but quietly drafts you into botnets instead. The alarming rise in DDoS attacks fueled by compromised residential proxies. A debate on who is really responsible for security: the user or the software developer. Are you relying too heavily on built-in protections, or have you upgraded your home security setup? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 05:45 Critical Infrastructure Attacks 15:15 The Consumer Cybersecurity Gap 32:15 Gamers in the Crosshairs: ClickFix 38:15 Outdated Advice & The McAfee Problem 46:00 Botnets, DDoS & The Blame Game Cybersecurity #InfoSec #Privacy #Malware #Botnets #Hacking

  8. Aug 7

    Episode 53: Cybersecurity Tool Overload: Are You Wasting Money?

    Welcome back to the Scinary Information Nexus! Brazos takes the director's chair this week (filling in for Richard) and brings a highly structured and highly debated topic to the table: Defense in Depth. Joined by Joseph, Pierre, and Alexandra, the crew unpacks the reality of layered security and whether having more tools actually makes you safer. We kick things off by debating classic cybersecurity analogies (is your network a Swiss cheese model, a Jenga tower, or Shrek's onion?) before getting into a core industry problem: alert fatigue. The discussion highlights how complexity is the true enemy of security. Pierre and Joseph share horror stories of default firewall configurations erasing gigabytes of log memory and tool alerts spamming admins into creating dangerous auto-delete rules. The takeaway? A few well-configured foundational tools are better than a massive stack of redundant solutions. We also run through a fun thought experiment: what would the team build with an infinite budget versus a shoestring budget? In this episode, we discuss: The "Swiss Cheese" and "Onion" models of Defense in Depth. Why adding too many security tools can actually become a liability. Logging nightmares: How default firewall configs can erase vital data. Alert fatigue and why admins ignore critical security warnings. The Shoestring Budget: Top priorities when you can only afford one tool. Why attackers target basic misconfigurations over expensive zero-days. The Infinite Budget: TSA checkpoints, air-gapped networks, and pen-and-paper security. Have you ever dealt with serious alert fatigue in your environment? Let's discuss in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/

5
out of 5
5 Ratings

About

Scinary Cybersecurity is here to "Serve and defend those who serve and defend others". To help us "serve and defend" we pull from many different sources - experts, colleagues, industry standards, etc... We hit every subject from all angles making it easy to understand while also letting us go in depth. Making this podcast perfect for cybersecurity beginners and experts alike. Come join us on our journey to constantly educate ourselves and explore the amazing things that are happening in our industry.

You Might Also Like