E
Emilio Gallegos
Offensive security researcher and adversarial operator at Bishop Fox specializing in application security and vulnerability research.
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
OCT 5
Sep 26, 2026
Zero-Click Exchange RCE, $25 AI Intrusions, and the ShinyHunters FBI Claim
S
34:54Sean McMillanHOST
Did you, did you initially kind of look for some type of chain, like a exploit chain, or is that something that just kind of emerged as you dug deeper?
E
35:05Emilio GallegosGUEST
I mean, I, I'm assuming and I'm hoping that pretty much everyone has a different, um, way to tackle a problem when it comes to reverse engineering.
E
35:16Emilio GallegosGUEST
But in this particular case what happened was that I didn't even wanted to, um, start with the vulnerability itself, um, because again, the, the big news was that there was supposedly active compromises.
E
35:35Emilio GallegosGUEST
So my initial concern was if any of our customers were already impacted, right? Um, and so essentially what I did first was just building a ...
E
35:46Emilio GallegosGUEST
Well, the, the question that I wanted answered was can I safely check for vulnerability or for the indicators of this vulnerability, uh, within our, uh, customers' attack surfaces without, you know, having to do any sort of exploits or, uh, more of a, an active testing, right? So I just built a, a, a little sort of like probe to sort of tell, um, just how it, it happens, SSH, how it authenticates a user.
S
37:02Sean McMillanHOST
But just from a high level, could you kinda talk about the microtrick attack and, like, how that works?