Dark mode: ON

Infosec Decoded Season 5 #36: RDP Passwords

With Doug Spindler and sambowne@infosec.exchange

Recorded Fri, May 9, 2025

Politics

Trump administration cuts off all future federal funding to Harvard

Secretary of Education Linda McMahon sent Harvard a letter that, amid what appears to be a stream-of-consciousness culture war rant, announces that the university will not be receiving any further research grants. It's difficult to tell exactly what the government wants, because most of the text is a deranged rant written in florid MAGA-ese. The letter's style is presumably a product of a culture that only knows how to communicate this way.

Trump’s NIH ignored court order, cut research grants anyway

For more than two months, the Trump administration has been subject to a federal court order stopping it from cutting funding related to gender identity and the provision of gender-affirming care in response to President Donald Trump’s executive orders.

Lawyers for the federal government have repeatedly claimed in court filings that the administration has been complying with the order.

But new whistleblower records submitted in a lawsuit led by the Washington state attorney general appear to contradict the claim.

58 crypto wallets have made millions on Trump’s meme coin. 764,000 have lost money, data shows

While around 2 million wallets have bought into the token, 58 wallets made more than $10 million apiece, totaling roughly $1.1 billion in gains. 764,000 wallets of mostly small holders lost money.

Foreign Interests Appear to Be Pouring Millions Into Trump’s Meme Coin

Over half of the top holders of $TRUMP are likely foreign buyers, who have dumped millions into the project. And likely not without motive. “76 percent of the token value held among the top 220 wallets likely belongs to foreign owners because the wallets used exchanges that are not available to U.S. residents.”

Company Boasts Spending Up To $20 Million On Trump Crypto Coin To Buy Influence

The freight company puts money in Trump’s pocket hoping for the opportunity to change policy.

Ty Cobb, a former federal prosecutor who served in Trump’s first-term White House, said that while federal law makes either offering or accepting a bribe a crime, Trump has made it plain that won’t be enforced so long as he is in the White House.

“They’ve made it clear that there are no ethics and they’re not beholden to any standards, and it doesn’t matter if it’s illegal or not because they’re not going to prosecute Republicans, so get over it,” Cobb said. “What passes for routine at this White House is purely corrupt.”

Sen. John Fetterman raises alarms with outburst at meeting with union officials, AP sources say

Democratic Sen. John Fetterman of Pennsylvania was meeting last week with representatives from a teachers union in his home state when things quickly devolved.

Before long, Fetterman began repeating himself, shouting and questioning why “everybody is mad at me,” “why does everyone hate me, what did I ever do” and slamming his hands on a desk, according to one person who was briefed on what occurred.

Infosec

Age Verification in the European Union: The Commission's Age Verification App

The European Commission has commissioned an age verification app, to be used for restricted online services. After downloading the app, a user would request proof of their age. For this crucial step, the Commission foresees users relying on a variety of age verification methods, including national eID schemes, physical ID cards with biometrics, etc.

Once the user would access a website restricting content for certain age cohorts, the platform would request proof of the user’s age through the app. The app would optionally use Zero Knowledge Proofs, a modern advanced cryptographic system that can offer a “yes-or-no” claim (like above or below 18) to a verifier without exposing all the user's information.

Many jurisdictions in the USA and elsewhere would like to age-gate social media, pornography, and other online resources, but the technical ability to do that has been lacking. This EU system may serve as a model for others, if it works out well. The EFF raises many thorny privacy concerns about age verification, and it will be important to see what the real consequences of this system are.

Feeling dumb? Let Google's latest AI invention simplify that wordy writing for you

The Google app for iOS has a new "Simplify" feature, which is meant to dumb down complicated writing without losing its meaning. It uses two instances of the Gemini LLM, to create the summary, and then judge its accuracy and readability--a process much like the older Generative Adversarial Network (GAN) used to create images.

The company with the world’s largest aircraft now has an autonomous hypersonic rocket plane that goes at Mach 5

Stratolaunch has finally found a use for the world's largest airplane. Stratolaunch's Talon-A is a little smaller than a school bus. Talon-A carried multiple experiments on each mission but did not offer any details about the nature of the payloads, citing proprietary reasons and customer agreements. The Pentagon wants to close what it views as a technological gap with China, which US officials acknowledge has become the world's leader in hypersonic missile development.

CL1: The world’s first code deployable biological computer.

High-performance closed-loop system where real neurons interact with software in real time. A robust environment keeps neurons alive for up to 6 months.

Biological Intelligence: Traditional AI demands vast datasets, but real neurons learn intuitively with minimal training and a fraction of the energy.

Science fiction has said "They're keeping Hitler's brain alive in a jar" for decades, finally it's coming true!

FBI: End-of-life routers hacked for cybercrime proxy networks

The FBI warns that threat actors are deploying malware on end-of-life (EoL) routers to convert them into proxies sold on the 5Socks and Anyproxy networks. The routers are old models from Linksys, Cradlepoint, and Cisco.

Cisco fixes max severity IOS XE flaw letting attackers hijack devices

Cisco has fixed a maximum severity flaw in IOS XE Software for Wireless LAN Controllers by a hard-coded JSON Web Token (JWT) that allows an unauthenticated remote attacker to take over devices.

DOGE software engineer’s computer infected by info-stealing malware

The presence of credentials in leaked "stealer logs" indicates his device was infected.

Report: DOGE supercharges mass-layoff software, renames it to sound less dystopian

DOGE has overhauled AutoRIF (Automated Reductions In Force), a historically wonky Department of Defense-designed tool that automates layoffs of federal workers. In the coming weeks, agencies will get access to this web version for demos and testing, Reuters reported, while noting that the tool appears to be the "only known example" of DOGE following through on its mission to modernize the federal government.

RDP Old Password Problem and Solution

When logging in with a Microsoft cloud account, RDP uses a cached credential, so that after a password change, only the old password is accepted. Tessa Anselm found a solution to this: click "I forgot my PIN" when logging in locally to the Windows 11 system. The lengthy, unreliable PIN reset process updates the cached credential.

Kickidler employee monitoring software abused in ransomware attacks

Ransomware operations are using legitimate Kickidler employee monitoring software for reconnaissance, tracking their victims' activity, and harvesting credentials after breaching their networks. It can capture keystrokes, take screenshots, and create videos of the screen.

Sudo-rs make me a sandwich, hold the buffer overflows

Ubuntu 25.10 fitted with Rust-written admin tool by default for memory safety's sake