<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Patrick Schlapfer-arkiv - IT-säkerhetspodden</title>
	<atom:link href="https://www.itsakerhetspodden.se/tag/patrick-schlapfer/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.itsakerhetspodden.se/tag/patrick-schlapfer/</link>
	<description>IT-säkerhet med Erik och Mattias som varvar kändisintervjuer med säkerhetssnack i tiden</description>
	<lastBuildDate>Sun, 30 Aug 2026 17:19:52 +0000</lastBuildDate>
	<language>sv-SE</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.itsakerhetspodden.se/wp-content/uploads/2020/04/cropped-sitelogo-32x32.jpg</url>
	<title>Patrick Schlapfer-arkiv - IT-säkerhetspodden</title>
	<link>https://www.itsakerhetspodden.se/tag/patrick-schlapfer/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">171781042</site>	<item>
		<title>#334 &#8211; Angripare tar till ”vibe hacking”</title>
		<link>https://www.itsakerhetspodden.se/podcast/334/</link>
					<comments>https://www.itsakerhetspodden.se/podcast/334/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Sun, 30 Aug 2026 16:49:22 +0000</pubDate>
				<category><![CDATA[Erik Zalitis]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Mattias Jadesköld]]></category>
		<category><![CDATA[Patrick Schlapfer]]></category>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?post_type=podcast&#038;p=7499</guid>

					<description><![CDATA[<p>I dagens avsnitt diskuterar Erik Zalitis och Mattias Jadesköld tillsammans med Patrick Schlapfer på HP. Patrick arbetar till vardags med Threat research och ligger bakom HP:s senaste rapport.</p>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/podcast/334/">#334 &#8211; Angripare tar till ”vibe hacking”</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="576" src="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide-1024x576.jpg" alt="Vibe hacking-avsnittet illustreras av en bild på Patrick Schlapfer." class="wp-image-7500" srcset="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide-1024x576.jpg 1024w, https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide-300x169.jpg 300w, https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide-768x432.jpg 768w, https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide.jpg 1280w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">I dagens avsnitt diskuterar Erik Zalitis och Mattias Jadesköld tillsammans med Patrick Schlapfer på HP. Patrick arbetar till vardags med Threat research och ligger bakom HP:s senaste rapport.</p>



<p class="wp-block-paragraph">Vad är det senaste metoderna som angripare använder? &#8221;vibe-hacking&#8221; &#8211; vad är det? Hur an de komma åt kryptovaluta genom en backupfil? Och hur kan angripare använda ljudfiler för att ta sig in i datorer?</p>



<p class="wp-block-paragraph">Det och en hel del annat i dagens avsnitt som är på engelska!</p>



<p class="wp-block-paragraph"><strong>Inspelat:</strong> 2026-08-26 (publicerat 2026-08-30)<br><strong>Deltagare</strong>: <a href="https://erik.zalitis.se/" target="_blank" rel="noreferrer noopener">Erik Zalitis</a>, Mattias Jadesköld och Patrick Schlapfer.<br>Texten skrevs och sammanställdes av <a href="https://www.itsakerhetspodden.se/author/erik/">Erik Zalitis</a>. Intervjun är på Engelska.<br>Avsnittet presenteras i samarbete med HP.</p>



<p class="wp-block-paragraph">Här är transkriptionen av avsnittet.</p>



<h2 id="h-medan-du-lyssnar-vibe-hacking" class="wp-block-heading">Medan du lyssnar &#8211; Vibe hacking</h2>



<p class="wp-block-paragraph">1<br>00:00:12,654 &#8211;&gt; 00:00:21,262<br>Mattias Jadesköld: I dagens avsnitt tar vi oss en titt på hotlandskapetsammans med HP. Det finns några angrepp som sticker ut under den första delen av 2026.</p>



<p class="wp-block-paragraph">2<br>00:00:21,262 &#8211;&gt; 00:00:42,734<br>Erik Zalitis: Ja, precis. Vibe hacking till exempel, och hur angripare döljer skadlig kod i ljudfiler. Rena agentfilmen. Ja, det kanske är en sanning som kan läsas ut i HP Wolf Security Threat Insights report, som släpptes för ett par månader sedan.</p>



<p class="wp-block-paragraph">3<br>00:00:42,734 &#8211;&gt; 00:01:01,026<br>Mattias Jadesköld: Det ska vi ta en titt på närmare idag, och det gör vi tillsammans med Patrik Schlapfer som arbetar som principal threat research. Vi kommer prata engelska rätt avsnitt av IT-säkerhetspodden som förutom Patrik, då består av Mattiaskö i sin vanligording. Welcome, Patrick.</p>



<h3 id="h-patrick-enters-our-virtual-studio" class="wp-block-heading">Patrick enters our virtual studio</h3>



<p class="wp-block-paragraph">4<br>00:01:01,026 &#8211;&gt; 00:01:04,558<br>Patrick Schlapfer: Welcome. Hey, thank you so much for having me.</p>



<p class="wp-block-paragraph">5<br>00:01:04,558 &#8211;&gt; 00:01:06,990<br>Mattias Jadesköld: Yeah, how how are you?</p>



<p class="wp-block-paragraph">6<br>00:01:06,990 &#8211;&gt; 00:01:11,106<br>Patrick Schlapfer: I&#8217;m all good. pretty good actually today. How are you doing?</p>



<p class="wp-block-paragraph">7<br>00:01:11,106 &#8211;&gt; 00:01:19,310<br>Mattias Jadesköld: Fine, thank you. We had some issues with the sound but now it seems to be working. Eric is happy with the sound solution now?</p>



<p class="wp-block-paragraph">8<br>00:01:19,310 &#8211;> 00:01:23,662<br>Erik Zalitis: It&#8217;s always something is screwing up with the sound and that&#8217;s just how it is.</p>



<p class="wp-block-paragraph">9<br>00:01:23,662 &#8211;&gt; 00:01:33,898<br>Mattias Jadesköld: Right. Okay, so normally you work as threat research at HP. what do you do on a normal basis, Patrick?</p>



<p class="wp-block-paragraph">10<br>00:01:33,898 &#8211;&gt; 00:02:30,102<br>Patrick Schlapfer: I do. That&#8217;s a good that&#8217;s a good question. Well, I have the fun job to actually look through all the collected telemetry data from our different security solutions, analyze the dead data, and then find all the interesting threats and take them apart. With all the data and the analysis I do, I do then get to write interesting reports such as the quarterly threat insights report. I do also write occasional blog posts, which is published on our threat block and I also do share quite a lot of information with the community because in the end security is a game as a team so sharing is definitely caring. Besides the whole threat research part, I do work together with the defensive security research team so that we can improve security solutions and create new solutions, which hopefully also protect for from the future threats.</p>



<p class="wp-block-paragraph">11<br>00:02:30,102 &#8211;&gt; 00:02:34,766<br>Mattias Jadesköld: Right, okay, so a lot of different tasks during a day, I guess. Yeah. And where are you located?</p>



<p class="wp-block-paragraph">12<br>00:02:34,766 &#8211;&gt; 00:02:42,277<br>Patrick Schlapfer: Absolutely, yeah. I&#8217;m actually located in in Zurich in Switzerland.</p>



<p class="wp-block-paragraph">13<br>00:02:42,277 &#8211;&gt; 00:02:48,320<br>Mattias Jadesköld: Okay. Some it&#8217;s a bit big difference between Switzerland and Sw Sweden, but</p>



<p class="wp-block-paragraph">14<br>00:02:48,320 &#8211;&gt; 00:02:49,304<br>Patrick Schlapfer: Yeah.</p>



<p class="wp-block-paragraph">15<br>00:02:49,304 &#8211;&gt; 00:02:55,330<br>Erik Zalitis: They get them confused all the time, isn&#8217;t it? Like Yeah, Switzerland and Sweden the same country.</p>



<p class="wp-block-paragraph">16<br>00:02:55,330 &#8211;&gt; 00:03:00,950<br>Patrick Schlapfer: Yeah, absolutely. Quite in a different place, but both I would say very beautiful landscapes.</p>



<h3 id="h-the-making-of-an-it-security-pro-how-patrick-got-started-in-the-business" class="wp-block-heading">The making of an IT-security pro &#8211; How Patrick got started in the business</h3>



<p class="wp-block-paragraph">17<br>00:03:00,950 &#8211;&gt; 00:03:10,168<br>Mattias Jadesköld: Yeah, definitely. Right. So it seems like you&#8217;ve been working with IT security for some years now, but how did it all started?</p>



<p class="wp-block-paragraph">18<br>00:03:10,168 &#8211;&gt; 00:04:59,008<br>Patrick Schlapfer: Well, that that was actually quite some time ago. So when I studied at the university, I I grew my interest in security in general. So I decided to take one or the other course in the area of security, like from cryptography to network security to to malware analysis. And I decided that malware analysis is probably the most interesting thing to have a look at because I I quite like to take apart software and understand how it works. So after I finished my degree, I actually had the chance to work as a research assistant directly for the university in a research project. So what we built back then was a dynamic malware analysis sandbox, which we created to through writing a custom Linux kernel module to basically do virtual machine introspection. I was very much into memory forensic at the time, and with the kernel module, we were able to capture the memory of a virtual machine from the hypervisor level. And therefore basically do dynamic analysis without having an in-guest agent. So that was that was the start and that was the whole fun around malware analysis. I later then decided after the research project it would be good to understand how security works in the real world outside academia. So I joined to work for a bank in security operations, and we focused a lot on incident response. but also did a bit of threat intelligence, basically taking apart and analyzing the threats we see and then share it with the community. After working for the bank, I was quite keen to understand malware even more in depth. And that&#8217;s when I actually joined HP as a threat researcher almost six years ago. Yeah, and that&#8217;s been quite an interesting journey and here we are six years in.</p>



<p class="wp-block-paragraph">19<br>00:04:59,008 &#8211;&gt; 00:05:06,840<br>Mattias Jadesköld: Right. So interesting. Yeah, you have a lot of banks in Switzerland, don&#8217;t you? So it&#8217;s a good way to start. Yeah.</p>



<p class="wp-block-paragraph">20<br>00:05:06,840 &#8211;&gt; 00:05:24,492<br>Patrick Schlapfer: Well, I mean I mean back at the time this was one of the I would probably say one of the two main companies who would hire security professionals. The other one was was the government. definitely very interesting project as well, but working for a bank was quite an interesting experience as well.</p>



<p class="wp-block-paragraph">21<br>00:05:24,492 &#8211;&gt; 00:05:46,552<br>Mattias Jadesköld: Yeah. Right, so we&#8217;re gonna dig into this annual report. It&#8217;s as Eric said mentioned in the beginning that it&#8217;s called HP Wolf&#8217;s Security Threat Insight Report. but a bit overall, w w what&#8217;s the reason why this is re report being created annually?</p>



<p class="wp-block-paragraph">22<br>00:05:46,552 &#8211;&gt; 00:06:40,660<br>Patrick Schlapfer: Well, we do collect all this valuable thread information, right? And one thing I&#8217;d like to say is that it does never represent like the full thread landscape. It&#8217;s just yet another different vantage point if we compare it to other security vendors and security companies. And therefore, with all the data we have, we thought, well, it&#8217;s very valuable information, so let&#8217;s share it with the community. First of all, it gives a lot of security awareness to share a bigger picture of the threat landscape, even on a higher level. But there are also technical lug nuggets in the threat insights report, such as interesting techniques which are used by the attackers, which actually help the security practitioners to understand those techniques and then build protections or build detections against those attacks.</p>



<h3 id="h-we-open-the-actual-report-and-patrick-delves-into-the-emerging-patterns-worth-knowing-right-now" class="wp-block-heading">We open the actual report and Patrick delves into the emerging patterns worth knowing right now</h3>



<p class="wp-block-paragraph">23<br>00:06:40,660 &#8211;&gt; 00:06:52,770<br>Mattias Jadesköld: Right. So but if you compare the this report with previous ones, i is there anything that stands out? It&#8217;s a bit different or something?</p>



<p class="wp-block-paragraph">24<br>00:06:52,770 &#8211;&gt; 00:09:13,346<br>Patrick Schlapfer: Well that&#8217;s that&#8217;s a wide question, I think. But there are definitely four I would say like well a couple different things that stand out. well if if if we look back about ten years ago or so, we were used to having those classic attacks with Word documents containing macros, which are then sent as an attachment to the user. And only with probably like one or two clicks your device was infected. Back at the time, like emotet one of the big moller families, which is luckily not not around anymore. nowadays it&#8217;s it&#8217;s quite a bit different. So from those two clicks, I would say it&#8217;s like a click to infection. This increased quite a bit. So nowadays we see that an infection requires more clicks because the user has to open a file, open an archive file, type in a password, and then open. Yeah, probably a script inside it and such kind of things. So this whole amount, number of clicks to infection increased, which also means that attackers and threat actors are focusing a lot more on social engineering. So the social engineering component in the beginning of an attack becomes very relevant for them. So they invest quite a bit of resources to make them more convincing. So the attacker actually Well, performs a specific task. Most often they try to blend in with standard business operations. So it&#8217;s very difficult for a user to distinguish between something legitimate and something malicious. Then another thing we&#8217;re seeing is that there have be has been this shared intermediate stage. Now, if we look from a higher level at an infection chain of such a cyber attack, we can probably split it into two. into three different stages. We have the initial infection with the social engineering. Then we have an intermediate stage with all the scripts which are running, basically which are responsible to then install the final payload. And then in the end we do have the final payload. And one of the things we&#8217;re seeing lately is that not only the social engineering and the final payloads are shared amongst thread actors, but also those intermediate stages. And this tells us that it&#8217;s not</p>



<p class="wp-block-paragraph">25<br>00:09:13,346 &#8211;&gt; 00:10:44,416<br>Patrick Schlapfer: This one man show where a hacker tries to target an organization, but it&#8217;s a full ecosystem of cybercrime that works together. So threat actors can go and buy malware families, intermediate stages, or also all kinds of different lures off the shelf from hacker markets or from hacking forums and such kind of things. And then there&#8217;s one thing I didn&#8217;t mention yet, but AI is of course also a part of the thread landscape and how it evolves over time, right? So one thing I can see up fr say up front is that we haven&#8217;t seen autonomous attacks as they are like shown in the movies. But attackers are making very much use of AI models to then create all kinds of different stages. For example, the intermediate stage which is responsible to install the final payload is very often created through Vibe WIPE coding or so-called white hacking. So they use a model and then they tell the model, hey, in in normal language, create me this specific infection stage, do this and that. And then it creates this very well. And it also works quite well for the social engineering engineering laws in the beginning. So if they want to create like a simple website or if they want to create a simple document or something like this. The AI models are very, very helpful for the attackers in this case. So that would probably be the four main things I would say.</p>



<h3 id="h-the-door-within-your-computer-how-hackers-use-remote-tools-to-take-control" class="wp-block-heading">The door within your computer &#8211; how hackers use remote tools to take control</h3>



<p class="wp-block-paragraph">26<br>00:10:44,416 &#8211;> 00:11:11,566<br>Mattias Jadesköld: Yeah, we&#8217;re gonna dig in a bit more on some topics and some of them are vibe hacking as Erik mentioned as well. But I I found three interesting topics w which from this report I think we should dive into. So let&#8217;s start with the first one. This is about remote tools that hackers are using remote tools like Log Me In or Screen Connect. How does this work?</p>



<p class="wp-block-paragraph">27<br>00:11:11,566 &#8211;&gt; 00:12:48,096<br>Patrick Schlapfer: Well, that&#8217;s a good question. So, first of all, that&#8217;s not something that is entirely new, right? we have seen such attacks in the past, like attackers using official and legitimate remote access tools to to compromise devices. That&#8217;s been around for quite some time. Now what&#8217;s different now is that we have seen quite an uptick over the last quarter, over the last half a year. So that&#8217;s something that stood out. And the second thing is that in the past, whenever I did an analysis of such an installer, I noticed that the thread actor actually modified the installer to connect to attacker control servers, right? So in this case, the whole infrastructure of the legitimate service, such as remote administration tool, is not in the whole scenario. So it&#8217;s directly connecting to attacker control servers. What they are doing now is that they take it as is and install it on a victim&#8217;s device. Now, this remote access solution then connects to the official service provided by by the application company. And therefore, it is very difficult to distinguish whether this is something malicious or something clean. And the thread actor, all he all they do is basically they have a login to this service. And then they see all the different devices which are connecting to the service, and then they can execute various different commands on the device and basically control it.</p>



<p class="wp-block-paragraph">28<br>00:12:48,096 &#8211;&gt; 00:12:57,034<br>Mattias Jadesköld: Okay. So these are all the so these are not just hacking tools, these are like normally remote tools that the hackers are using.</p>



<p class="wp-block-paragraph">29<br>00:12:57,034 &#8211;&gt; 00:13:58,434<br>Patrick Schlapfer: Exactly. And that makes it so very difficult, right? those are legitimate tools. Lots of organizations actually use those tools specifically in IT support organizations. So whenever someone has an issue with their device, they they can remote in and fix the problem directly on their device. and it it&#8217;s it&#8217;s a very similar thing for for all kinds of different software solutions or tools, such as for example, take PowerShell. PowerShell is a brilliant tool for to do like system administration. But in the end, it&#8217;s also a very common tool to be used by attackers because it has a lot of possibilities to interact with with the device in the end. So with those remote access tools, attacker are using legitimate software in a malicious way. And in the end that&#8217;s very, very difficult to figure out in a network. Because maybe the organization is using specifically such an organ such an application as well themselves.</p>



<p class="wp-block-paragraph">30<br>00:13:58,434 &#8211;&gt; 00:14:07,320<br>Mattias Jadesköld: But how how how can I prevent these type of attacks, for example, if I&#8217;m working in an IT department in on an organization?</p>



<p class="wp-block-paragraph">31<br>00:14:07,320 &#8211;&gt; 00:15:22,326<br>Patrick Schlapfer: Well it&#8217;s it&#8217;s definitely not an easy task third to attack from such an attack, yeah. it might be probably quite a boring answer, but in the end it is it is also an o an evergreen, but a and and you know this for sure, it&#8217;s like have a good inventory. I know it always sounds so easy and it never is because having like a clear and and a complete inventory is pretty much impossible. But having an idea of specific services you&#8217;re using can be quite helpful. So if you know that, hey, are you using this or the other remote access tool, then you can monitor for other remote access tools to be used within the same organization, which is probably a lot not legitimate in this case. And then the other thing is that, well, try to install software only from trusted sources. Now in those specific campaigns, thread actors are actually installing the software. So it&#8217;s not a user installing the software, but it&#8217;s a thread actor. And last but not least, if you control the admin privilege on a user device, then they have less capabilities to install such potentially malicious software on their operating system.</p>



<p class="wp-block-paragraph">32<br>00:15:22,326 &#8211;> 00:15:31,694<br>Mattias Jadesköld: Yeah. Erik y you work as a pen tester. Have you ever experienced that that these type of attacks using remote tools?</p>



<p class="wp-block-paragraph">33<br>00:15:31,694 &#8211;&gt; 00:16:01,426<br>Erik Zalitis: Well, as a pen tester, I&#8217;m trying to do the same, pretty much. So I I can&#8217;t say that but as working with this SOC at the Security Operations Center, which I can help at my company, the company I work for, that is. Yeah, we we&#8217;ve seen they&#8217;re trying stuff like that. Mostly they&#8217;re trying stuff like that with phishing attacks. But of course, that&#8217;s not the only show, so to speak. So yeah, that&#8217;s a thing. No disagreement.</p>



<h3 id="h-your-money-at-risk-how-crypto-wallets-get-stolen" class="wp-block-heading">Your money at risk &#8211; how crypto wallets get stolen</h3>



<p class="wp-block-paragraph">34<br>00:16:01,426 &#8211;&gt; 00:16:24,888<br>Mattias Jadesköld: Okay, that&#8217;s good. Okay, let&#8217;s jump to the next topic, which is also kind of interesting. a bit outside my comfort zone because it&#8217;s about crypto w wallet wallets and and restore. that it&#8217;s mentioned in the report that is false restoring of crypto wallet wallet wallets. How how does it with this work?</p>



<p class="wp-block-paragraph">35<br>00:16:24,888 &#8211;&gt; 00:16:34,519<br>Patrick Schlapfer: Well, it&#8217;s Yeah, that&#8217;s that&#8217;s definitely interesting. So did you ever lose your own crypto wallet?</p>



<p class="wp-block-paragraph">36<br>00:16:34,519 &#8211;&gt; 00:16:40,750<br>Erik Zalitis: Don&#8217;t have any trouble. That seems like a smart thing. The only way to win this game is not playing it.</p>



<p class="wp-block-paragraph">37<br>00:16:40,750 &#8211;&gt; 00:17:31,562<br>Patrick Schlapfer: Exactly. Well, definitely, definitely on my side here as well. Yeah. Well, yeah. what is it? Well, so a crypto wallet i i it&#8217;s basically the key to the kingdom, right? So it&#8217;s basically a a key that you have locally on your device. if you decide to have it locally, it&#8217;s a private key, which allows you to gain access to the whole crypto assets you have. the crypto assets themselves are actually stored on the blockchain, such as Bitcoin as an example, but the the private key is something you keep to yourself, in hence the name private key. Now, if an attacker is able to get access to such a private key, then they basically control all the funds you have on the specific blockchain, which is quite a big disaster in this case.</p>



<p class="wp-block-paragraph">38<br>00:17:31,562 &#8211;&gt; 00:17:38,506<br>Mattias Jadesköld: Yeah. Because the banks cannot help you in this case because it&#8217;s decentralized, like Bitcoin, for example.</p>



<p class="wp-block-paragraph">39<br>00:17:38,506 &#8211;&gt; 00:18:43,360<br>Patrick Schlapfer: Exactly. it&#8217;s decentralized. So there&#8217;s no help from from anyone. and if if if an attacker controls the private key, they can basically redirect all your bitcoins or whatever cryptocurrency you are you are using to yet another wallet because they have the private key and with the private key they can easily sign new transactions, which then sends the money to someone else, which presumably in this case will be a tactor in its own. That&#8217;s why our attackers are so interested in finding local crypto wallets and exfiltrating those private keys. So this is a very common technique when we look at all kinds of different information stealers. They are usually built in a modular way where they have like all kinds of different capabilities, such as like password stealing or I don&#8217;t know, browsing history stealing. And one of those modules is definitely always like crypto wallet stealers. Because a crypto wallet can contain quite a lot of money in those days. So if they get hold of one of those wallets, then well, they might be rich at some point.</p>



<p class="wp-block-paragraph">40<br>00:18:43,360 &#8211;> 00:18:50,954<br>Mattias Jadesköld: Okay, but how does it work with with restoring a crypto wallet?</p>



<p class="wp-block-paragraph">41<br>00:18:50,954 &#8211;&gt; 00:20:27,803<br>Patrick Schlapfer: Now this is this is actually the interesting part because this is this is just use as the lure, right? So imagine yourself you lost your crypto wallet on your device and now you&#8217;re quite desperate because this is a lot of money. And you want to find this crypto wallet again. so what&#8217;s the steps you take? Well, in this desperation, you probably reach out to the internet and search for tools that can recover your crypto wallets because it&#8217;s a a lot of money. And that&#8217;s basically where the users get trapped. Because the attacker set up this GitHub repository to tell the user, hey, I built this solution, and this solution will actually help you to find your lost crypto wallet on your device. In reality, in reality, it doesn&#8217;t do it. In in reality, what happens if you download this crypto wallet recovery tool is that, well, It exfiltrates all kinds of interesting and sensitive information. At some point, they do promise what they claim. They do indeed recover your crypto wallet, but they don&#8217;t give it to the user. But they simply exfiltrate this crypto wallet and send it to the attacker&#8217;s server. So besides system information, passwords and browsing data, as I mentioned earlier, they of course also collect crypto wallets. They are They they compress it in an archive file and then they send it to an attacker control server in this case. So yeah, unfortunately no crypto wallets recovery tool here.</p>



<p class="wp-block-paragraph">42<br>00:20:27,803 &#8211;&gt; 00:20:31,775<br>Erik Zalitis: All I can say is empathy is not a thing with them.</p>



<p class="wp-block-paragraph">43<br>00:20:31,775 &#8211;&gt; 00:20:35,119<br>Patrick Schlapfer: No, absolutely not. No.</p>



<p class="wp-block-paragraph">44<br>00:20:35,119 &#8211;&gt; 00:20:44,482<br>Mattias Jadesköld: But how c how can I if if I&#8217;m having if I&#8217;m worried about this, how should I avoid these type of attacks?</p>



<p class="wp-block-paragraph">45<br>00:20:44,482 &#8211;&gt; 00:21:45,394<br>Patrick Schlapfer: Well, if you actually lost your crypto wallet on your device, then yeah, it is very frustrating. I do understand this, but don&#8217;t act too fast. First of all, I would probably try to investigate well, where is this crypto wallet actually stored on the device? Like in which folder does it normally reside? And I think that&#8217;s very different depending on the blockchain you&#8217;re using. Yeah. Then in the end you have different names, right? Different file names. So what I would suggest if you actually lost it, go and search and investigate how this crypto wallet is built, where it usually resides and what the fail file name is. And then use like built in Windows tools or Linux tools if you&#8217;re if you&#8217;re using Linux to search for the files in the different folders. That&#8217;s definitely better than downloading a random application from an untrusted source. Yeah. Because yeah, well In this case, they were definitely proved to be something malicious.</p>



<h3 id="h-clickfix-the-word-you-need-to-know" class="wp-block-heading">ClickFix &#8211; the word you need to know</h3>



<p class="wp-block-paragraph">46<br>00:21:45,394 &#8211;&gt; 00:22:08,640<br>Mattias Jadesköld: Right, okay. Let&#8217;s go to the third topic, I guess. This called ClickFix campaign. this was there was this was this some sort sort of recent attack related to clickfix. What is clickfix?</p>



<p class="wp-block-paragraph">47<br>00:22:08,640 &#8211;&gt; 00:22:46,112<br>Patrick Schlapfer: Well, ClickFix has actually been around for well, I don&#8217;t want to say anything wrong, probably one or two years now. So it&#8217;s been around for quite some time. But during this time, they did evolve the attacks and the campaigns. So ClickFix is in the end a social engineering technique. So what happens is that an attacker builds like a social net social engineering website or a social engineering image. Which convinces the user to basically paste some malicious codes into the local Windows run box and then execute malicious code.</p>



<p class="wp-block-paragraph">48<br>00:22:46,112 &#8211;&gt; 00:23:22,028<br>Erik Zalitis: I actually interesting you would say that because I actually investigated such a code a few weeks ago. and it was extremely clever. It tried to look like some kind of cloud flare warning that says please click and execute this in in the runbox. And I actually looked through the code and it was extremely well obfuscated, w sending those deobfuscator tools into some sort of eternal loop. The obfuscation level of that was like eleven out of ten. Enormously well done. Seriously.</p>



<p class="wp-block-paragraph">49<br>00:23:22,028 &#8211;&gt; 00:23:32,235<br>Patrick Schlapfer: Yeah, I I totally believe that. We have seen so many different, like specifically obfuscated scripts which are terrible to analyze and I definitely like I I do understand your frustration. I&#8217;ve spent hours picking apart like JavaScript code or BB script code, which is like it&#8217;s unbelievable what kind of techniques attackers can make use of to to obfuscate their scripts.</p>



<p class="wp-block-paragraph">50<br>00:23:32,235 &#8211;&gt; 00:23:46,934<br>Erik Zalitis: Like yeah, I know.</p>



<p class="wp-block-paragraph">51<br>00:23:46,934 &#8211;&gt; 00:23:53,954<br>Erik Zalitis: I I don&#8217;t like hackers very much, but I respect them. I y begrudgedly I do respect them.</p>



<h3 id="h-captchas-annoying-but-obviously-needed" class="wp-block-heading">CAPTCHAs &#8211; annoying but obviously needed</h3>



<figure class="wp-block-image size-full"><img decoding="async" width="222" height="406" src="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/image-3.png" alt="En seriestrip från serien XKCD. En person vid en dator får följande från från websidan han försöker nå: &quot;To prove you're human click on all the photos that show place you would run for shelter during a robot uprising&quot;." class="wp-image-7515" srcset="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/image-3.png 222w, https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/image-3-164x300.png 164w" sizes="(max-width: 222px) 100vw, 222px" /></figure>



<p class="wp-block-paragraph">52<br>00:23:53,954 &#8211;&gt; 00:25:10,008<br>Patrick Schlapfer: Well, in this case, I I actually have to give it to them specifically for for the idea to create such a social engineering lure, right? I mean in the past, like if you remember the good old Word and Excel documents where they tried to convince the user to click the enable button to basically run the in included VBA macros. Now this was quite basic and this this was around for probably like ten, fifteen years or so. Now, this is a totally new concept. And I I think that is quite interesting. And now if you think around, well, it&#8217;s been this Cloudflare cap cap capture you mentioned, if you think back like many, many years ago, those captures are not something that are new, right? Because in the end it&#8217;s it&#8217;s like just the idea to distinguish whether you&#8217;re an actual user or if you&#8217;re a robot or if you&#8217;re some kind of crawler accessing the website. I remember like Many years ago, like even like simple web forms had such a very simple CAPTCHA where you get like two numbers, so you have to add them together, and then you have to type in the number in a specific field and only if the answer was correct your form was submitted, basically to prevent automated attacks.</p>



<p class="wp-block-paragraph">53<br>00:25:10,008 &#8211;&gt; 00:25:24,450<br>Erik Zalitis: Yeah I remember that too, I remember that too. Th the the kind of distinction between them were there were two kinds they were super secure and no human beings could solve them, or they were very easy to solve and any hacker could solve them.</p>



<p class="wp-block-paragraph">54<br>00:25:24,450 &#8211;&gt; 00:25:44,846<br>Patrick Schlapfer: Yeah, I mean that that&#8217;s absolutely true. I mean I remember well when when you get like those other captures like hey yeah click on all the pictures which contain a mountain, click on all the pictures which contain I don&#8217;t know, a bicycle or a car. And I and I remember sitting in front of the PC like like clicking all the images and then next and then there&#8217;s the next coming up.</p>



<p class="wp-block-paragraph">55<br>00:25:44,846 &#8211;&gt; 00:26:12,898<br>Erik Zalitis: It felt like never got it right. It&#8217;s like, what the heck? That&#8217;s supposed to be a mountain, but obviously not for some reason. And another thing was back in the day of PHP BB, if you remember that forum, it had the worst capture ever. No humans could solve it because it was slanted R&#8217;s and S and X and nobody see. Is that a Y or is it a W or whatever? I can&#8217;t see it. And the hackers had no problems breaking it for.</p>



<p class="wp-block-paragraph">56<br>00:26:12,898 &#8211;&gt; 00:27:17,430<br>Patrick Schlapfer: Yeah, exactly. And and is it like is it uppercase or is it lowercase? Yeah, I I know exactly what you mean. And and and in the end, like let&#8217;s be honest, that that&#8217;s been one of the issues for the user here, right? I mean, like we can come up with so many different types of captchas that we have seen over the last, I don&#8217;t know, maybe twenty years or so that for a normal user who is not like used to work with like those captures every single day, it&#8217;s very difficult to know well, what is the next technique a company like figures out to hip to build such a capture. So like at some point it&#8217;s you have to select the mountains in another, you have to like have this like maps puzzle, like and and and whatnot. So it can very likely be that at this point you have to execute the specific commands of of of key combinations. So like pressing like Windows R, control V and enter doesn&#8217;t seem to be so far fetched. And in the end the normal user has no idea what Windows R does, does do they? So that&#8217;s very tricky.</p>



<p class="wp-block-paragraph">57<br>00:27:17,430 &#8211;> 00:27:28,802<br>Erik Zalitis: Y d how do you teach people not to do stupid things when everything that&#8217;s stupid looks exactly the same way thing f way that things that are smart?</p>



<p class="wp-block-paragraph">58<br>00:27:28,802 &#8211;&gt; 00:27:45,110<br>Patrick Schlapfer: They have absolutely no idea. And and if you remember, the user went to this website for a specific purpose. They want to consume the content on this specific website. So all they want is to to get this capture out of their way so they can actually access the website they were looking for.</p>



<p class="wp-block-paragraph">59<br>00:27:45,110 &#8211;&gt; 00:28:13,292<br>Erik Zalitis: And people don&#8217;t expect that to happen because one of the things where I was checking a few weeks ago, that was like a food site, like a restaurant here in Sweden that was hacked. So it wasn&#8217;t like malicious, but it had been hacked by WordPress, if if you know, and and that kind of injected code in the JavaScript that ran this Cloudflare fake. So people weren&#8217;t expecting. I mean, you go to a restaurant site, you don&#8217;t expect to get hacked.</p>



<p class="wp-block-paragraph">60<br>00:28:13,292 &#8211;&gt; 00:28:45,190<br>Patrick Schlapfer: No, not at all. That&#8217;s definitely the case. And it&#8217;s been the case for so many different websites, especi especially like like in in industries which are not that close to IT and are even further away from IT security. All they need is they need to have a simple website to show what is going on within their organization, to promote like the daily dish or something like this. So so that&#8217;s definitely a good target for an attacker and definitely difficult for a user to understand. That something is wrong on this website.</p>



<h3 id="h-clicking-images-to-prove-you-re-human-isn-t-an-easy-task-for-everyone" class="wp-block-heading">Clicking images to prove you&#8217;re human isn&#8217;t an easy task for everyone</h3>



<p class="wp-block-paragraph">61<br>00:28:45,190 &#8211;&gt; 00:29:01,870<br>Mattias Jadesköld: Yeah. And as a user is it&#8217;s kind of stressful because a lot of things is on stake because in the beginning they say if you don&#8217;t succeed in this capture, you&#8217;re not human. It&#8217;s like i if I if I can&#8217;t find all these mountains or traffic signs, then I&#8217;m then I&#8217;m a robot, obviously, or something.</p>



<p class="wp-block-paragraph">62<br>00:29:01,870 &#8211;&gt; 00:29:26,348<br>Erik Zalitis: The problem is also you can expect people to be the same, but they aren&#8217;t. I mean that&#8217;s to say some people may actually be old and they have problems understanding these things because they don&#8217;t they don&#8217;t have the skills. Some people may have some kind of mental deficiency, making it possible impossible for them to solve the captions. This is not the level of playing field.</p>



<p class="wp-block-paragraph">63<br>00:29:26,348 &#8211;&gt; 00:29:30,059<br>Patrick Schlapfer: Yeah, absolutely agree with that. Yeah.</p>



<p class="wp-block-paragraph">64<br>00:29:30,059 &#8211;&gt; 00:29:39,022<br>Mattias Jadesköld: about this clickfix campaign that was mentioned in the report, there was something about malicious code within a sound file. How how does that work?</p>



<p class="wp-block-paragraph">65<br>00:29:39,022 &#8211;&gt; 00:31:54,882<br>Patrick Schlapfer: Exactly. Well, if we look like quickly at the evolution of those click fix campaigns, it&#8217;s that basically what happens is that the attacker copies malicious code into the clip port of the user. Then the user wants to fulfill the capture, so they press the key combination like Windows R, Ctrl V and turn. That&#8217;s basically how they execute the malicious code, right? And in the beginning, The thread actors always use PowerShell because PowerShell is just so common. You execute PowerShell, you can supply an encoded command in base64, and then the whole device is infected. Now, of course, various different solutions which build detection in A-B systems actually kept up and improved their detection and are therefore able to block such an attack. But yeah, attackers usually find a way around it. So what the attackers did is instead of launching PowerShell, they decided to use MSHTA. And MSHTA is very often used to display those help messages if you press F1 in an older program. It it shows up and then you have a library of all kinds of different documentations. But what you can do in this case, you can also simply supply an HTML document which contains script code, which is then Executed on the host system because there is simply no sandbox. So what the thread actor did in this case is that they simply put in the command line MSHTA and then a link to a sound file. Now, this is not actually a sound file, but it is just using the extension of sound files. And the reason here is that if you look at the web gateway logs, which is something the Security Operations Center usually does. Then they will realize that okay, a sound file was downloaded to the specific device, but it doesn&#8217;t suspect anything malicious. Now, in reality, the sound file is actually a script file. In this case, HTML file contained with JavaScript. An MSHTA doesn&#8217;t really care what kind of file extension you&#8217;re using. So you can use like any kind of like</p>



<p class="wp-block-paragraph">66<br>00:31:54,882 &#8211;&gt; 00:32:36,790<br>Patrick Schlapfer: Sound file or picture or movie file, it simply executes and renders the files in HTML within this box. And that&#8217;s basically the a trick we see quite often used by thread actors, basically assigning either a wrong file extension or assigning double file extensions. So for example, if a user by default hides file extensions, then there tricked with a double extension to think that an executable file might be a PDF or that an executable file might be a Word document or something like this. So this is quite a common technique used by Chad Actor nowadays.</p>



<p class="wp-block-paragraph">67<br>00:32:36,790 &#8211;> 00:32:46,892<br>Erik Zalitis: That seems old, doesn&#8217;t it? I mean the whole thing with double extensions is like &#8221;I love you&#8221;, virus days. That&#8217;s still a thing you should. Yeah.</p>



<p class="wp-block-paragraph">68<br>00:32:46,892 &#8211;&gt; 00:33:50,135<br>Patrick Schlapfer: Yeah, it&#8217;s it&#8217;s super old. I mean like so many techniques are so super old and they still work nowadays, which is to me on the one hand quite surprising. But on the other hand, like we didn&#8217;t solve the simple security problems probably as an industry. And that&#8217;s that&#8217;s quite difficult. How do you teach a user to not click on a specific file? Like We usually get also the question, well, if you have this archive file which is distributed by an attacker, and within this archive file there&#8217;s a script file, such as like JavaScript or VPS. Why should a user open this specific file? Because it&#8217;s not a document, is it? Well, in the end, the user has no idea, right? The user has no clue whether this is an actual document or if this is a script file or or or if this is an executable file or whatever. A normal user doesn&#8217;t even know what a script file is. And that&#8217;s how we have to look at it. And that&#8217;s why we have to build like technical protections against such attacks.</p>



<p class="wp-block-paragraph">69<br>00:33:50,135 &#8211;&gt; 00:33:51,674<br>Mattias Jadesköld: Yeah.</p>



<h3 id="h-nothing-new-under-the-sun-hackers-find-new-use-for-old-attacks" class="wp-block-heading">Nothing new under the sun &#8211; hackers find new use for old attacks</h3>



<p class="wp-block-paragraph">70<br>00:33:51,674 &#8211;&gt; 00:34:09,144<br>Erik Zalitis: This is kinda scary because nothing of this feels new. It feels like you&#8217;re using very old technology onto the user because I do believe that many of those health file files is that f really used anymore? Isn&#8217;t that kinda a legacy component?</p>



<p class="wp-block-paragraph">71<br>00:34:09,144 &#8211;&gt; 00:34:57,570<br>Patrick Schlapfer: That that is a really good question. And I so in new applications, if you press one, you&#8217;re usually redirected to a website, right? Yeah. I still imagine that there are quite a lot of older applications which do have this helper function implemented through MSHTA. but yeah, that&#8217;s that&#8217;s actually a really good question. I haven&#8217;t come across many of those, but certainly MSHTA is still part of the operating system, which makes it in in in some sense even more dangerous for an organization, because an organization might lose track of such an executable, and therefore they don&#8217;t track it anymore in their detections and then in their protection mechanisms and therefore open yet another hole and attack infection vector for threat actors.</p>



<p class="wp-block-paragraph">72<br>00:34:57,570 &#8211;&gt; 00:35:24,462<br>Erik Zalitis: was thinking about is it using the Trident engine? That&#8217;s like Internet Explorer. Could it be that old? I mean that&#8217;s a thing to just like thinking about because Windows such as it is has a lot of legacy code, stuff that was around in the nineteenth and the 2000s, such as it was. And that is not secure. And a lot of it is kind of abandoned but still for some reason works.</p>



<p class="wp-block-paragraph">73<br>00:35:24,462 &#8211;&gt; 00:36:37,670<br>Patrick Schlapfer: Totally, totally agree. I mean, if you remember, it&#8217;s it&#8217;s a long time ago, but to be honest, we&#8217;re still seeing them. Remember the equation editor exploits? Like where you had like a malicious RTS document, and then there was a a vulnerability within the Word&#8217;s equation editor and the thread actor was actually able to well, exploit this vulnerability and download and execute the file from a remote server. Now, this has been legacy code for a very long time. And this has been on Windows system for ages. And in the end, Microsoft actually got rid of this whole equation editor because they had a very new version in new office installations. But nevertheless, we still see attackers using this specific exploit and targeting all kinds of different users. I I believe myself that this equation editor is gone on most devices nowadays because that&#8217;s been like twenty seventeen actually. But for some reason they&#8217;re still using it. So probably there is still one or the other device which contains this equation editor and therefore is still vulnerable to this exploit.</p>



<h3 id="h-from-observing-to-protecting-how-do-you-get-there" class="wp-block-heading">From observing to protecting &#8211; how do you get there?</h3>



<p class="wp-block-paragraph">74<br>00:36:37,670 &#8211;&gt; 00:36:45,314<br>Mattias Jadesköld: Right. And how how do I prevent these attacks from happen for me?</p>



<p class="wp-block-paragraph">75<br>00:36:45,314 &#8211;&gt; 00:38:41,698<br>Patrick Schlapfer: Well, to prevent such a click fix attacks is certainly not something that is easy, right? in the end well well, you&#8217;re on Linux, even though well if you&#8217;re around Linux you do have different distributions and you have like like T shortcuts and so on. In the end it&#8217;s it&#8217;s very difficult also for a user to understand. But nevertheless, I think this this whole concept of the social engineering technique should be part of like an awareness program where you tell the users how to behave. in the end, however, this doesn&#8217;t solve the problem, right? Awareness is just one aspect, but you have to have a technical solution to protect the users. So one thing I I can think of is that in most cases they use Windows R, which opens the runbox. Like a normal user in everyday work, they don&#8217;t use the runbox at all. So what you can do is you can use group policies, for example, to disable the runbox entirely. An alternative solution is that, well, if you have a secure browser, so so HP basically has this kind of isolation technology where we embed a browser within a micro VM, and there you can disable the clipboards from being used by the website. Because a normal website can usually simply write to the clip port if the user clicks a button. There is different permissions you can also set in an in a regular browser, but as far as I know, in most cases it is very difficult to determine from reading from the clipboard, which is very sensitive and can be restricted, to writing to the clipboard, which is often not possible to restrict by the normal user or in the normal browser. So there were various different approaches to protect from such an attack. And I think in the end it has to be a combination of all of those.</p>



<p class="wp-block-paragraph">76<br>00:38:41,698 &#8211;&gt; 00:38:45,644<br>Mattias Jadesköld: All right.</p>



<p class="wp-block-paragraph">77<br>00:38:45,644 &#8211;> 00:38:48,682<br>Mattias Jadesköld: Any idea, Erkc? How to print this?</p>



<p class="wp-block-paragraph">78<br>00:38:48,682 &#8211;&gt; 00:39:37,964<br>Erik Zalitis: Yep, that&#8217;s the problem. Should you teach people not to do dumb dumb stuff? Should you lock their computers down? Depends on. I mean, when people are taught not to do stuff, the hackers kinda mutate the attacks. So they don&#8217;t look like what the people were taught not to do. And secondly of all, all those mechanisms also suffer the same fate. Basically put, everything looks good now, but the hackers always evolve the attack. Try something a little bit differently. It passes through whatever you lock down. That that&#8217;s a problem. It&#8217;s very hard. You can of course say don&#8217;t do stuff that feels wrong. If it feels like the gut feeling is like this is weird. Should I really click? Should I really really do this? If the website says click this and this combination, is that really a good thing to do? I I think that&#8217;s the b only thing you can do, basically.</p>



<p class="wp-block-paragraph">79<br>00:39:37,964 &#8211;&gt; 00:39:54,590<br>Mattias Jadesköld: Yeah. Right. So yeah, a lot of interesting topics that you can read more about in this report. And and that is public available, right, Patrick. So I can we can share this this the link to the report</p>



<p class="wp-block-paragraph">80<br>00:39:54,590 &#8211;&gt; 00:40:23,370<br>Patrick Schlapfer: Exactly. Yeah. The report is available on on our on our blog websites. There is also there are all kinds of other blog posts we usually publish around like different malware campaigns, but around all kinds of other security topics as well. If people are interested to have a look there as well. And there&#8217;s actually a new report coming, probably mid end September, which will be published pretty soon. So I&#8217;m actually doing the analysis at the moment for this specific report.</p>



<h3 id="h-hp-s-report-something-you-can-count-on-coming-out-often" class="wp-block-heading">HP&#8217;s report &#8211; something you can count on coming out often</h3>



<p class="wp-block-paragraph">81<br>00:40:23,370 &#8211;&gt; 00:40:26,434<br>Mattias Jadesköld: I thought this was an annual report, but no, okay.</p>



<p class="wp-block-paragraph">82<br>00:40:26,434 &#8211;&gt; 00:40:53,166<br>Patrick Schlapfer: No, it&#8217;s actually a report we do four times a year. right. So we usually try to cover like each quarter of the year. so we&#8217;re doing this for a couple of years now. So having the capability to actually look back, hey, how did everything like start like seven, eight years ago? And how does it look today? How did the thread landscape change? And there were definitely a few quite interesting changes, as I mentioned earlier in this talk.</p>



<p class="wp-block-paragraph">83<br>00:40:53,166 &#8211;&gt; 00:40:58,770<br>Mattias Jadesköld: But I hope this was not outdated information that we just gave.</p>



<p class="wp-block-paragraph">84<br>00:40:58,770 &#8211;&gt; 00:41:31,495<br>Patrick Schlapfer: No, no, no, no. No, no. Definitely not outdated. I I think like most of those, like most of those techniques are being used by thread actors for quite a long time. I mean what what you mentioned earlier is that thread actors adapt very, very quickly to smaller techniques. So they try to get around your protection mechanism. They try to trick their user into installing something. But in the end, over the long term, that the techniques and tactics stay more or less the same if we look at a higher level at it.</p>



<p class="wp-block-paragraph">85<br>00:41:31,495 &#8211;&gt; 00:41:40,758<br>Mattias Jadesköld: Yeah. Right. Is there anything you would like to add? what we miss?</p>



<p class="wp-block-paragraph">86<br>00:41:40,758 &#8211;&gt; 00:42:05,068<br>Patrick Schlapfer: I think we did quite cover quite a lot of different topics. Yeah. So doesn&#8217;t come anything specific to mind. just have a heads up when you&#8217;re seeing the next capture, if it&#8217;s a real one or if it&#8217;s a fake one. Don&#8217;t affect yourself with malware. Yeah. Don&#8217;t go and search for your lost crypto wallet with fake tools. yeah, stay safe out there.</p>



<p class="wp-block-paragraph">87<br>00:42:05,068 &#8211;> 00:42:15,310<br>Mattias Jadesköld: Yes. Good. thank you so much, Patrick Schlapfer, that you for joining IT-säkerhetspodden.</p>



<p class="wp-block-paragraph">88<br>00:42:15,310 &#8211;&gt; 00:42:19,544<br>Patrick Schlapfer: Thank you so much. It&#8217;s been a very interesting discussion. Thank you for having me.</p>



<p class="wp-block-paragraph">89<br>00:42:19,544 &#8211;> 00:42:22,544<br>Erik Zalitis: Thank you much.</p>



<p class="wp-block-paragraph">(Denna transkription är automatiskt genererad och kan innehålla felhörningar)</p>



<h3 id="h-lankar-ai" class="wp-block-heading">Länkar – AI</h3>



<ul class="wp-block-list">
<li><a href="https://threatresearch.ext.hp.com/hp-wolf-security-threat-insights-report-june-2026/" target="_blank" rel="noreferrer noopener sponsored nofollow">HP Wolf Security Threat Insights Report: June 2026</a></li>
</ul>



<h2 id="h-felaktigheter" class="wp-block-heading">Felaktigheter</h2>



<p class="wp-block-paragraph" id="h-felaktigheter">Inget att rapportera denna gång. Kommentera gärna om ni <s>inte håller med om</s> hittar fel i något vi sagt.</p>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/podcast/334/">#334 &#8211; Angripare tar till ”vibe hacking”</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.itsakerhetspodden.se/podcast/334/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://traffic.libsyn.com/itsakerhetspodden/334.mp3" length="61394240" type="audio/mpeg" />

		<post-id xmlns="com-wordpress:feed-additions:1">7499</post-id>
		<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide-150x150.jpg" />
		<media:content url="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide.jpg" medium="image">
			<media:title type="html">334_wide</media:title>
			<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/334_wide-150x150.jpg" />
		</media:content>
		<media:content url="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/image-3.png" medium="image">
			<media:title type="html">image</media:title>
			<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2026/08/image-3-150x150.png" />
		</media:content>
	</item>
	</channel>
</rss>
