Dark mode: ON

Infosec Decoded Season 5 #78: War from Within

With Doug Spindler and sambowne@infosec.exchange

Recorded Fri, Oct 3, 2025

AI

OpenAI's New Social Video App Will Let You Deepfake Your Friends
Sora users can give their friends -- or, if they're feeling bold, everyone -- permission to create "cameos" with their own likeness using the new video model, which is dubbed Sora 2. The person whose likeness is being generated is a "co-owner" of that end result, OpenAI employees said, and they can delete it or revoke access to others at any time.
Salesforce launches enterprise vibe-coding product, Agentforce Vibes
This new tool includes an autonomous AI coding agent named Vibe Codey.

This release comes at an interesting time for the vibe-coding industry.

Many vibe-coding startups are continuing to raise large funding rounds at eye-watering valuations from investors. Vibe-coding startup Lovable, for example, is allegedly turning down unsolicited funding offers from investors after garnering a $1.8 billion valuation just eight months after launching.

Vibe-coding startup Anything recently claimed to hit $2 million in annual recurring revenue (ARR) just two weeks after launching.

Despite the hype, the long-term success of these platforms is less clear. Due to the sheer volume of large language model usage required to run these platforms, costs for these companies are high and resulting margins are tight.

Politics

Trump’s Speech to Generals Was Incitement to Violence Against Americans
Yesterday morning, U.S. President Donald Trump and Secretary of Defense Pete Hegseth behaved reprehensibly. Their speeches before several hundred assembled military commanders and their senior noncommissioned officers (NCOs) were tantamount to incitement—a genuinely dangerous effort to suborn the military’s oath and condition them for using violence against their fellow Americans.

Their words should leave no doubt in anyone’s mind that the civilian leadership intends to use the threat and actuality of violence to infringe on Americans’ constitutional rights.

Hegseth Is Teaching a Masterclass on Bad Leadership
Hegseth embodied three of the most common failures of leaders who are, by both temperament and skill, simply not up to the job:
  • Prioritizing the superficial over actual substance
  • Using their institution and its people for their own self-aggrandizement
  • Disrespect for those who report to them
Pete wants to run for Governor of TN, and, from Pivot, even for President.
Trump Administration Asks Colleges to Sign ‘Compact’ to Get Funding Preference
The compact would require colleges to freeze tuition for five years, cap the enrollment of international students and commit to strict definitions of gender. Among other steps, universities would also be required to change their governance structures to prohibit anything that would “punish, belittle and even spark violence against conservative ideas.”
Jane Fonda leads hundreds to re-launch a McCarthy-era committee to defend free speech
Committee for the First Amendment

Infosec

ICE to Buy Tool that Tracks Locations of Hundreds of Millions of Phones Every Day
The data is gathered from SDKs and real-time bidding for ads, and sold by data brokers.
Block ransomware proliferation and easily restore files with AI in Google Drive
Ransomware represented 21% of all the intrusions observed by Mandiant last year, with an average ransomware or extortion incident cost exceeding $5M.

We're enhancing Google Drive for desktop with AI-powered ransomware detection to automatically stop file syncing and allow users to easily restore files. We’ve built a specialized AI model, trained on millions of real-world ransomware samples, to look for signals that a file has been maliciously modified. The detection engine adapts to novel ransomware by continuously analyzing file changes and incorporating new threat intelligence from VirusTotal.

Gmail business users can now send encrypted emails to anyone