Cyber Investigations

Five eyes agencies make a memo on AI hacking

Cyber Investigations Media Season 1 Episode 4

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 13:23

This week on cyber investigations we dive into stories that reveal how the next generation of cyber threats extends far beyond traditional hacking.

First, we break down a sophisticated campaign involving malicious npm packages disguised as legitimate PostCSS tools. Learn how attackers weaponise the JavaScript ecosystem, abuse post-install scripts, steal cloud credentials, compromise CI/CD pipelines, and why software supply-chain attacks remain one of the biggest threats facing developers and enterprises today.

Then we leave Earth and head into orbit. We explore the little-publicised U.S. Space Force's Resolute Space exercise and explain why modern space operations are deeply intertwined with cybersecurity. Discover how satellites are defended from cyberattacks, electronic warfare, GPS spoofing, jamming, and supply-chain compromises and why the next cyber battlefield may be 36,000 kilometres above our heads.

Whether you're a penetration tester, SOC analyst, cloud engineer, software developer, or simply passionate about cybersecurity, this episode delivers the technical insights behind the headlines.

contact us cyberinvestigationsau@gmail.com

Thanks for listening.

Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft.

For contact or story tips, email: cyberinvestigationsau@gmail.com

Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

SPEAKER_00

Back to the podcast. Thank you very much for joining me. Got three stories to kick off the week. The first is all the Five Eyes Intelligence Signals Agencies have come together to make what I think is a fairly non-statement. We'll jump into the details of that. And finally, the new space race and the cybersecurity implications that they has that that that has. Okay, let's jump into it. So on the 22nd of June 2026, the FiveEyes Signals Intelligence Agencies have published a what I would say is a directive. Five Eyes agencies will often publish statements, considerations, and comms to the wider cybersecurity industry. And this one they labeled the AI shift in cyber risk, why leaders must act now. At face value, you might think, hmm, that's a yep, that's a good thing to talk about. However, if you read the statement, and I'm reading the one that the Australian Signals Directorate published today, I am underwhelmed. So they go on to say at the start of the publication is that there is a call to action, and they say, well, YLAI will help us improve cyber defense over time. It also accelerates the speed, scale, and sophistication of cyber threats. Yes. Basically, the gist of it is that they are grappling with a new cyber realm where malicious actors weaponize AI tools. And that's fine. This is perhaps an important announcement to make. Where ASD has completely missed the mark is what they call out as practical actions. And the practical actions that they tell cyber defenders to do is old advice. It's advice that we have all heard before that hasn't worked for the past 20 years in in order to stay on top of malicious actors. There is a never-ending revolving door of zero days and malicious actors gaining network access. So I think about this, and they have made this big statement saying we now have this new threat. What's our advice to you? Just do just do what you've always been doing. How is that possibly going to help? So for example, they say practical actions that a cyber defender should take reduce your attack surface. Yes. But how is that going to defend against a new realm of AI-enabled hacking? When agencies, organizations, have been trying to reduce their attack surface long before red teams used AI, and organizations were still getting poled before this new paradigm of AI was introduced. So this old advice is not going to cut the mustard, unfortunately. I'm getting a bit a bit all all emotional here, I apologize, but uh I just thought that ASD has missed the mark and it ultimately doesn't help. Furthermore, the practical actions that ASD has called out in this announcement to the industry is accelerate patching processes. Hmm. How? Patch faster has been the direction, again, for twenty years. You can have a patch as fast as a malicious actor can gain access to an exploited zero day. Address legacy systems, they've also said, review and strengthen identity and access controls is another thing they said. Prepare for incidents before they happen. If you were to take out the dates of this announcement, and you didn't know that it was related to AI, you would not know if this call to action based on ASD's advice was published in 2026, 2016, or even 2007. So I'm I'm calling this out because when governments make grand sweeping statements, but don't actually give cyber defenders any secret source, uh any technical direction as to how can you reduce your tax service faster than that of malicious actors using AI tooling. ASD makes no attempts, from what I can see, to fill to bridge that gap. Anyway, let's move on to story two. I will get off my soapbox. I think let me make one more statement. I think that the announcement from ASD today meant well. The announcement from the Five Eyes agencies meant well, but I don't think it's simply missing that element of secret source as to how defenders can get on top of accelerated AI actors and how they can change their defensive posture based on advice that is seemingly 20 years old. That's disappointing, if you were to ask me. So story two. This one comes from Hacker News, which reports that malicious NPM packages. Yeah. NPM, again, has been compromised. NPM packages are masquerading as post-CSS related tooling. Okay, so for listeners that may be unfamiliar with post-CSS, it's one of the most widely used tools in modern web development. Post-CSS processes CSS through plugins. And because it's integrated into countless front-end frameworks, developers routinely install post-CSS related packages without much security. It's one of those packages that has just had so much history. Developers will NPM install without batting an eye. Unfortunately, this is exactly what attackers are counting on. NPM is has been why has NPM become such an a valuable target is because the dependency tree is so large in the Node.js environment, developers can rely on typosquatting effectively. So many malicious NPM packages rely on this evolving technique of typosquatting and npm install commands. For example, post-CSS. When your npm install a package name, you might be installing, let's say, for example, post-CSS tools or post-CSS helper or post CSS utils. And at a glance they would appear trustworthy. A developer searching quickly might accidentally install the malicious version that looks identical to the post-CSS package that they are wanting to, but there's very minor changes in the numbering or the lettering of the NPM install. So a post-install phase is particularly dangerous once a successful typos squad of an NPM install has occurred. The NPM installs, it automatically executes the JavaScript defined within the package metadata. This means malware runs immediately after installation without the developer ever importing the package into their application. And from there, the technical attack chain typically includes it looks something like the developer installs the package, PostScript installs script launches automatically, and malware fingerprints the system, environment variables are harvested, credentials are collected, data is exfilstrated, exfiltrated to attacker infrastructure on a CG server sitting outside the environment. I think NPM install typosquatting has become so successful as of late, is because it's so hard to detect. One challenge defenders are facing is that malicious actors increasingly resemble legitimate software. Recent academic research into NPM malware detection found attackers are moving away from obvious malicious behavior and to a towards subtle chained actions that blend into normal developer activity. As a result of this, detection becomes far easier when tools analyze behavior sequences rather than individual API calls. The bigger problem here, I think, and what's particularly concerning is the scale of the NPM ecosystem. More than a million JavaScript packages found over 60% rely on downstream dependencies, and more than 20% contain at least one known vulnerability somewhere within their dependency chain. The cybersecurity industry as a whole has not yet figured out the dependency issue. And I think this problem is just going to get bigger, as as this recent attack has shown. Let's quickly move on to the third story today. And this one is very cool. A military space exercise has occurred that you probably didn't know about. This one was supported on Rs Technica. The United States Space Force recently conducted a major space operation exercise called Resolute Space. So what I find particularly interesting what exercises like Resolute Space are testing. Exercises like this are from reading the publication are designed to simulate real world disruptions. Saying war gaming but in space. I think this is new in the cybersecurity industry. So participants practice operating under degraded conditions, for example, GPS signals becoming unreliable, com satellites being jammed, so on and so forth. I think this shows a shift towards faster satellite deployment. One of the major goals highlighted by the Space Force is reducing satellite deployment timelines from years to weeks. I think this matters because Warfare is increasingly assuming that satellite assets will be targeted. And for those that are in and around the space industry, you know that there is a shift towards smaller satellite constellations. Instead of relying on one billion dollar satellites operators deploy hundreds of smaller satellite systems. While this creates redundancy, it also creates what is probably a difficult management scenario. And so it was just, I just thought it was interesting to see how wargaming scenarios are increasingly becoming space based. I'll close out the episode for today. Thank you very much for listening. I'll see you next time.

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Cyber Investigations Artwork

Cyber Investigations

Cyber Investigations Media