Imagine waking on a Tuesday to discover an invisible army has been testing your doors for six days. It doesn’t need fancy zero-days or cinematic cleverness — just agents that can scan, read, adapt and move on. In this episode, we follow a financially motivated attacker using open-source AI tools to run 105 probing projects in under a week, harvesting card data and compromising organisations while the cost of each reconnaissance run averages just a few dollars.
From Gambit Security’s reconstruction of a scaled campaign to New Zealand’s National Cyber Security Centre warning that frontier models accelerate reconnaissance, the story threads together into one uncomfortable observation: the problem isn’t a lack of security technology, it’s the gap between owning features and operating them. A critical TeamCity flaw with a published patch and known exploitation shows how a fixed vulnerability becomes a real ransomware entry when change processes stall and nobody can say for sure what is exposed.
We even wind up in the optical spine of fiber broadband, where Quark’s Lab’s deep dive into passive optical networks exposes a familiar theme — standards and features can support strong protections, but optional choices and careless deployments turn capability into illusion. Whether it’s MFA, backups, EDR or encryption, a green tick on a dashboard is not the same as a control that will actually stop an attacker in the middle of the night.
AI doesn’t need to be a brilliant mastermind. It just needs to cheaply and persistently test the weak signals you left lying around. That changes the economics: the marginal cost of trying the next company collapses, and opportunistic compromise scales. Small businesses aren’t suddenly interesting; they’re suddenly cheap to probe, and automation can take an exploit much further than old scanners ever could.
But this isn’t fatalism — it’s a practical wake-up call. The defence that works is less about buying another product and more about operational discipline: know what your external world can reach, test whether MFA actually prompts for a second factor, restore a backup for real, and rehearse the decision pathways for critical patches. Ask: if someone could attack us cheaply tomorrow, what would make them stop?
We tell the story through people and processes — the helpdesk pressured to reset accounts, the admin on leave, the server thought to be internal but quietly facing the internet — and pull tools into the background. The episode walks you through real moments where security features exist but controls don’t, then hands you a simple, evidence-first checklist to start closing those gaps today.
By the end you’ll see the same pattern in different disguises: AI makes probing trivial, technology contains the answers, and operations decide whether those answers are actually used. It’s bleak, fixable, and urgent — because the next probe might be the one that finds the switch you forgot to turn on.
Find our Skool community here - https://www.skool.com/small-biz-cyber-guy-2008