Latest / Tech Talks With Kinsoft / Nissan – ShinyHunters Turn an Oracle Zero-Day into a Payroll Nightmare
Transcript
- 0:00I want you to imagine something for a second.
- 0:02You wake up on like a perfectly normal Tuesday
- 0:04morning. Right, just a regular day. Exactly.
- 0:07You grab your coffee, you check your phone, and
- 0:09sitting right there in your inbox is an email
- 0:12from your employer. Oh, those are never good
- 0:14when they come in first thing. No, they're not.
- 0:16And it's marked urgent. But it's not about a
- 0:19meeting and it's not about some project update.
- 0:22It's an alert telling you that your most sensitive,
- 0:25completely irreplaceable personal details. And
- 0:29we're talking, you know, your bank account routing
- 0:31numbers, your social security number, your national
- 0:34ID. The really scary stuff. The terrifying stuff.
- 0:38Even your dependents information. It's all been
- 0:40stolen, siphoned right out of the company. internal
- 0:43network Wow and here's the kicker right you didn't
- 0:47do a single thing wrong Right. You didn't like
- 0:49fall for a scan. Exactly. You didn't click a
- 0:52sketchy phishing link. You didn't reuse an old
- 0:55password from, you know, 10 years ago. It happened
- 0:57because of a hidden microscopic flaw in the software
- 1:01that your company relies on every single day.
- 1:04A flaw that absolutely nobody on Earth knew existed
- 1:07until the thieves were already, you know, walking
- 1:09out the door with your identity. It is a genuinely
- 1:12terrifying scenario because it completely shatters
- 1:15that. That illusion of control we all like to
- 1:18hold on to of the digital age. A hundred percent.
- 1:20We want to believe that if we just follow the
- 1:23rules, if we just have good digital hygiene and
- 1:26use two factor authentication, we are safe. We
- 1:29basically treat security as an individual responsibility.
- 1:32Yeah. And that loss of agency is what makes this
- 1:34so chilling. Or doing everything right, but your
- 1:38data is just collateral damage in a war you didn't
- 1:41even know was being fought. Exactly. You're just
- 1:43caught in the crossfire. And that exact nightmare
- 1:45scenario is what we are diving into today. So
- 1:48welcome to our latest deep dive. Glad to be here.
- 1:50Today, we are pulling our insights from an incident
- 1:53report published on July 3rd, 2026. This is by
- 1:56Tech Talks with Kinsoft. And our mission for
- 1:59this deep dive, we are going to completely deconstruct
- 2:02the massive Nissan cyber attack. It's a big one.
- 2:05Huge. We are going to look under the hood to
- 2:08understand the terrifying, invisible mechanics
- 2:11of what the cybersecurity world calls a zero
- 2:13day exploit. Right. And probably most importantly
- 2:16for you listening, we are going to figure out.
- 2:19how organizations and by extension all of us
- 2:22really can possibly defend against an attack
- 2:24that is seemingly unpreventable okay let's unpack
- 2:27this let's do it let's start with the hard facts
- 2:29of the breach itself because the sheer scale
- 2:31here is just staggering on june 29th 2026 Nissan
- 2:36came forward and disclosed that employee data
- 2:39had been exposed across a massive swath of its
- 2:42operations. We're talking the United States,
- 2:44Canada, Mexico and Brazil. Yeah. The geographic
- 2:47spread is imposing, obviously. But the detail
- 2:50that should actually make you sit up and take
- 2:51notice is the nature of the data that was targeted.
- 2:54Right. The Kinsoft report is incredibly explicit
- 2:57about this. Yeah. The attackers didn't walk away
- 2:59with, you know, marketing metrics or a list of
- 3:02email addresses for people who just signed up
- 3:04for a test drive. No, this was the deep. It's
- 3:13a goldmine. It really is. And even records for
- 3:19the employees, dependents and beneficiaries.
- 3:21And I got to say, that last one really gets me.
- 3:24Yeah. They took the data of employees' children.
- 3:27It is literally the ultimate starter kit for
- 3:30identity theft. It really is. And let's actually
- 3:33drill down into why that dependent data. it is
- 3:35so valuable. Because people might wonder, you
- 3:37know, why target kids? Right. They don't have
- 3:40bank accounts to drain. Exactly. But children
- 3:43have completely clean credit histories. So a
- 3:46stolen Social Security number of a dependent
- 3:48allows a malicious actor to commit what's called
- 3:51synthetic identity fraud. Oh, wow. OK, explain
- 3:54that. Well, they combined real data like the
- 3:56kids SSN with fake names and fake birth dates
- 3:58to open brand new lines of credit. That's horrifying.
- 4:01It is. And the victim often doesn't even find
- 4:04out until they turn 18 and, you know, apply for
- 4:07a student loan or a car loan and realize their
- 4:09credit is completely ruined. That is just brutal.
- 4:12Yeah. And in the cybersecurity industry, we constantly
- 4:15talk about it. company's crown jewels. Right.
- 4:18And that's what's important. Exactly. For decades,
- 4:20the assumption was always that the crown jewels
- 4:22were proprietary source code or top secret product
- 4:26designs or unreleased financial earnings. Like
- 4:29the recipe for Coca -Cola or something. Exactly.
- 4:32Yeah. But this report rightly emphasizes a major
- 4:35paradigm shift. Today, a company's HR systems
- 4:39and their ERPs. their enterprise resource planning
- 4:43systems, those are the true crown jewels. I want
- 4:46to pause on that term for a second, ERP, because
- 4:49it gets thrown around in corporate meetings a
- 4:50lot. But for you listening, think of an ERP as
- 4:53like the digital central nervous system of a
- 4:56business. That's a great way to put it. Yeah,
- 4:58it's the software that ties everything together.
- 5:00Payroll, supply chain, human resources, accounting.
- 5:04It's not just a fancy spreadsheet. It's the actual
- 5:07engine running the company. Right. And because
- 5:09it runs the company, it holds a... massively
- 5:11concentrated density of human identity. What's
- 5:14fascinating here is the fundamental shift in
- 5:17how we have to view corporate vulnerabilities.
- 5:19Tell me more about that. Well, we are rapidly
- 5:22moving from an era where the primary goal of
- 5:24cyber warfare was stealing corporate intellectual
- 5:27property to an era where the ultimate liability
- 5:30is the human workforce's personal data. It completely
- 5:34flips the script on a heist movie, doesn't it?
- 5:36It really does. I mean, imagine a crew of highly
- 5:39sophisticated, heavily armed bank robbers breaking
- 5:42into a heavily fortified corporate headquarters.
- 5:45They get inside and they completely bypass the
- 5:48massive titanium vault containing all the corporate
- 5:51secrets, the cash, the blueprints for the next
- 5:53generation car engine. Right. They just walk
- 5:55right past. Yeah. Instead, they pick the lock
- 5:58to the employee locker room and they steal everyone's
- 6:00wallets, home addresses and family photos. Exactly.
- 6:03Because in today's digital economy. exploiting
- 6:06the identities of the workforce is actually faster,
- 6:09easier to monetize, and far more lucrative than
- 6:12trying to, like, fence a stolen blueprint for
- 6:15a steering wheel. It's a brutal reality. I mean,
- 6:17stealing a credit card number is a short -term
- 6:19win for a hacker. The card just gets canceled
- 6:22in a day. Right. The bank flags it immediately.
- 6:24But stealing a Social Security number and a tax
- 6:28profile, that is a permanent, lifelong vulnerability
- 6:32for the victim. Which is exactly what makes it
- 6:35so highly prized on the dark web. Okay, I'm tracking
- 6:38the value of the data. I get why they want it.
- 6:41But I'm kind of hung up on the logistics here.
- 6:43OK, sure. Nissan isn't a mom and pop shop with
- 6:45some, you know, $50 router they bought at a big
- 6:49box store. They have mass or IT budgets. Right.
- 6:51Enterprise grade security. Exactly. So how does
- 6:54a thief actually get their hands on an ERP system
- 6:57in the first place? How do you bypass all those
- 6:59expensive firewalls? Yeah. And this is where
- 7:02the story shifts from a data privacy tragedy
- 7:04to a really hardcore infrastructure engineering
- 7:07problem. The attackers didn't guess. a password.
- 7:10They didn't trick an employee with a phishing
- 7:12email. They exploited a critical vulnerability
- 7:15in a software platform called Oracle PeopleSoft.
- 7:18And Oracle PeopleSoft is ubiquitous. I mean,
- 7:20it's the HR and payroll backbone for a massive
- 7:23percentage of the Fortune 500. Which is exactly
- 7:26what makes it a very attractive target. If you
- 7:28find a flaw in PeopleSoft, you suddenly have
- 7:31a skeleton key to thousands of the world's Let's
- 7:43break down that acronym real quick for the listener.
- 7:45CVE stands for Common Vulnerabilities and Exposures.
- 7:49It's essentially a global registry, right? Like
- 7:52a dictionary maintained by cybersecurity professionals
- 7:55to track known software flaws. So everyone is
- 7:58speaking the exact same language when a crisis
- 8:00hits. Yeah, think of it like the CDC tracking
- 8:03a new viral strain. Oh, that's a good analogy.
- 8:05And this specific strain, this CVE, was absolutely
- 8:08disastrous. The technical details are really
- 8:11vital to understand here. It was classified as
- 8:13an unauthenticated, remotely exploitable bug.
- 8:16And the CDSS, which is the scoring system used
- 8:19to grade these threats, gave it a severity rating
- 8:21of 9 .8 out of 10. Let's translate that into
- 8:24plain English because those sound like very dry
- 8:26technical terms, but they actually explain the
- 8:28sheer mechanics of the disaster here. They do,
- 8:30yeah. So unauthenticated means the attacker does
- 8:33not need a username. They don't need a password.
- 8:36They don't have to exist in the system at all.
- 8:38Right. To use a physical analogy, normally accessing
- 8:41a system requires authentication. It's like going
- 8:44to a super exclusive restaurant. You walk up
- 8:46to the host. You give your name. They check the
- 8:48reservation list. And if you're on it, they seat
- 8:50you. Right. You prove who you are. Exactly. But
- 8:54an unauthenticated exploit. bypasses that entirely.
- 8:57It's like standing outside the restaurant and
- 8:59sliding a highly specific kind of malformed note
- 9:02under the door directly into the kitchen. Okay,
- 9:05I like this. And this note is written in such
- 9:07a weird, confusing way that it tricks the kitchen
- 9:10staff into immediately opening the back door.
- 9:13Completely bypassing the host stand out front.
- 9:15That's wild. So the software just blindly executes
- 9:19a command because the programmers never anticipated
- 9:21someone sending a request formatted in that exact
- 9:23bizarre way. Precisely. They just didn't see
- 9:26it coming. And then the remotely exploitable
- 9:28part means they are sliding that note under the
- 9:31door from like. a laptop in a basement halfway
- 9:34across the world they don't need to be physically
- 9:36standing on the nissan campus not at all now
- 9:39about that 9 .8 out of 10 score i mean if 9 .8
- 9:43is this bad what separates it from a perfect
- 9:4610. well a 10 out of 10 usually means the vulnerability
- 9:50is incredibly easy to execute requires Basically
- 9:53zero technical skill and grants total unfettered
- 9:57administrative control over the entire network
- 9:59immediately. Oh, wow. OK. Yeah. So a 9 .8 is
- 10:03essentially a five alarm fire. The door is wide
- 10:05open and anyone with the right script can just
- 10:07walk right through. That is terrifying. But the
- 10:09detail that elevates this from a serious engineering
- 10:11problem to a full blown absolute crisis is the
- 10:14timeline. because this was a zero -day exploit.
- 10:17Right, and the Kinsoft report states that attackers
- 10:20were actively using this vulnerability in the
- 10:22wild between roughly May 27th and June 9th, 2026.
- 10:25Yeah. But Oracle didn't release an advisory or
- 10:28emergency mitigations until June 10th. Wait,
- 10:30so for two weeks, companies were essentially
- 10:32sitting ducks through no fault of their own.
- 10:35How is it fair to expect a company to defend
- 10:37against a ghost? It's, I mean, your pushback
- 10:39about fairness is the exact question keeping
- 10:42every chief information security officer awake
- 10:45at night right now. I bet. A zero day simply
- 10:48means the software vendor has had zero days to
- 10:51prepare a patch because the attackers discovered
- 10:53the hole before the good guys did. Right. And
- 10:56during that window, there is no patch. You literally
- 11:00cannot apply a fix that has not been invented
- 11:03yet. So what do you do? Well, to answer your
- 11:05question about how a company defends against
- 11:07a ghost, we have to look at the other major failure
- 11:10the Kinsoft report points out. There were reportedly
- 11:14hundreds of these highly sensitive PeopleSoft
- 11:16systems sitting exposed directly to the public
- 11:19internet. Wait, meaning anyone with a web browser
- 11:21could theoretically find the login page? Exactly.
- 11:24Why would a company put their most sensitive
- 11:26database on the open Internet? That seems totally
- 11:28counterintuitive to basic security. Oh, it is.
- 11:31But it comes down to the eternal tension between
- 11:33security and convenience, especially during the
- 11:36massive shift to remote work. Companies wanted
- 11:39their employees to be able to, you know, check
- 11:41their PTO balances or download a pay stub or
- 11:44update their direct deposit from their smartphones
- 11:46while sitting at their kitchen tables. Right.
- 11:48Nobody wants to jump through hoops just to check
- 11:50their vacation days. Exactly. Forcing an employee
- 11:53to boot up a clunky corporate VPN just to check
- 11:55a pay stub causes friction. So IT departments
- 11:59basically poked holes in their firewalls to make
- 12:02the HR portals accessible from anywhere. So they
- 12:05prioritized convenience, and in doing so, they
- 12:09massively increased their attack surface. They
- 12:11absolutely did. Which brings us back to defending
- 12:14against a zero day. You don't patch your way
- 12:17out of it. You architect your way out of it.
- 12:19Interesting. The defense requires limiting what
- 12:22is Internet facing. If a system holds your absolute
- 12:25crown jewels, it should never, ever be reachable
- 12:28from a public Web browser, no matter how convenient
- 12:30it is for the staff. Wow. OK, so we understand
- 12:33the weapon here. The unauthenticated zero day
- 12:36sliding a confusing note under the door. We understand
- 12:39the target, the exposed PeopleSoft HR data. Now
- 12:43we really need to look at the people wielding
- 12:45the weapon. The report identifies the crew behind
- 12:48this specific attack as shiny hunters. Yeah.
- 12:51And Shiny Hunters is a prolific name in the threat
- 12:53intelligence community. They operate basically
- 12:55as a cyber criminal syndicate focused heavily
- 12:59on data theft and extortion. And the report notes
- 13:02this wasn't just a surgical strike on Nissan.
- 13:04No, not at all. It was a massive sweeping campaign
- 13:07hitting over 100 organizations with a surprisingly
- 13:10heavy focus on the education sector. Right. But
- 13:13the Kinsoft report flags a really vital detail
- 13:16regarding Shiny Hunters public statements. The
- 13:19group took to the dark. web and claimed they
- 13:21had stolen tens of millions of records across
- 13:24this entire campaign. Yeah, huge numbers. Right.
- 13:27However, independent verification shows the actual
- 13:30numbers are coming in far, far lower. The report
- 13:33explicitly warns that this crew has a known track
- 13:36record of wildly inflating its claims. Here's
- 13:38where it gets really interesting. Why would hackers
- 13:41exaggerate their haul? Is extortion essentially
- 13:43just a perverse form of PR for these threat actors?
- 13:46If we connect this to the bigger picture, extortion
- 13:49is absolutely a form of dark public relations.
- 13:53Wow. Dark PR. Yeah. You have to stop thinking
- 13:55of these groups as, you know, lone hackers in
- 13:59hoodies and basements and start viewing them
- 14:01as illicit corporations. Because they have structures,
- 14:03right? Oh, absolutely. They have marketing strategies.
- 14:06They have customer service desks to help victims
- 14:08buy cryptocurrency to pay the ransom. Wait, customer
- 14:11service desks? That's insane. It is, but it's
- 14:14true. Their alternate goal is to force a victim
- 14:17to pay up. either to decrypt locked systems or,
- 14:21in the case of shiny hunters, to prevent the
- 14:23public release of the stolen data. It's literally
- 14:25just digital blackmail on a corporate scale.
- 14:28Exactly. And in the blackmail business, leverage
- 14:31is your only currency. Generating massive terrifying
- 14:34headlines in the mainstream media is a highly
- 14:37calculated tactic to force negotiations. Oh,
- 14:39I see where you're going with this. Yeah, imagine
- 14:41a company's board of directors waking up to a
- 14:43news alert saying 50 million records stolen in
- 14:46devastating breach. The internal panic, the shareholder
- 14:50pressure, the regulatory scrutiny, it all just
- 14:52skyrockets. Right. The pressure to just quietly
- 14:55pay the ransom to make the negative PR go away
- 14:58becomes immense. Exactly. Even if the hackers
- 15:01actually only managed to steal, say, 50 ,000
- 15:04records, they are weaponizing the media cycle
- 15:07against the victim. Which is why the Kinsoft
- 15:09report gives such vital advice for all of us
- 15:12as consumers of information. When you hear a
- 15:15giant, eye -watering number attached to an extortion
- 15:18campaign, you really need to treat it as an unverified
- 15:21marketing claim from a criminal enterprise. That
- 15:24makes total sense. Yeah, the real figure is often
- 15:26just a fraction of the headline. If we blindly
- 15:29repeat their inflated numbers on social media
- 15:31or news broadcasts, we are doing their PR work
- 15:34for them. We're helping the bad guys. We are
- 15:37feeding the exact panic cycle that they rely
- 15:39on to get paid. That is a completely fascinating
- 15:41psychological element to this. It's like psychological
- 15:44warfare layered right on top of digital warfare.
- 15:47It really is. OK, so we've seen the devastation
- 15:50of the zero day. We've analyzed how the attackers
- 15:53manipulate the narrative with their dark PR.
- 15:56Now. We have to talk about the aftermath because
- 15:59the story absolutely does not end the moment
- 16:02the data is stolen. No, the theft is just the
- 16:04beginning. Right. How a company navigates the
- 16:07fallout in the hours and days after a breach
- 16:09is what determines whether they survive it or
- 16:12whether it snowballs into an absolute catastrophe.
- 16:14Yeah. And the Kinsoff report specifically highlights
- 16:17something Nissan did incredibly well in their
- 16:20incident response. Yes. And it's a mitigation
- 16:22strategy that every single organization running
- 16:25a payroll system needs to take notes on immediately.
- 16:28So according to the report, after the breach
- 16:31was discovered, Nissan didn't just try to apply
- 16:33the Oracle patch and cross their fingers. Right,
- 16:35which is what a lot of companies do. Yeah, but
- 16:37Nissan implemented a concrete structural change
- 16:40to their internal business processes. They completely
- 16:43restricted any changes to employee pay slip and
- 16:47direct deposit details over the open internet.
- 16:49If an employee wanted to change the bank account
- 16:51their paycheck was routed to, they had to be
- 16:54physically connected to the internal corporate
- 16:56network or connected via a highly secure multi
- 16:59-factor VPN. Furthermore, Nissan added strict
- 17:03manual... identity verification steps before
- 17:06HR would process any of those payroll changes.
- 17:09This is such a brilliant example of anticipating
- 17:11the attacker's ultimate goal. The Kinsoft report
- 17:15notes that this specific action is the perfect
- 17:18defense against payroll diversion fraud. OK,
- 17:21let's define that for you listening, because
- 17:22this is how the criminals actually turn your
- 17:24stolen data into cash. Payroll diversion fraud
- 17:27is basically the second act of the play. Right.
- 17:30The attackers steal the data in act one. In act
- 17:33two, they use that stolen data, the passwords,
- 17:36the personal details, the routing numbers to
- 17:38log back into the HR system. Right. They become
- 17:40the employee. Exactly. They impersonate the employee.
- 17:43And then they. change the employee's direct deposit
- 17:45information so the next paycheck goes to a bank
- 17:49account controlled by the hackers, not the employee.
- 17:51And they are very sneaky about it. Oh, totally.
- 17:54They usually do this quietly, like two days before
- 17:56the end of the month, so nobody notices until
- 18:00payday arrives and the money is already gone.
- 18:02The data theft itself is merely the reconnaissance
- 18:04and preparation phase. The payroll diversion
- 18:06is the actual monetization of the attack. So
- 18:09what does this all mean? It's like realizing
- 18:12someone copied your house key. OK, I like this
- 18:14analogy. Right. And you could just change the
- 18:16locks on the front door. But you have no idea
- 18:18if they made a copy of a different key or if
- 18:20they found like a loose window around back. Right.
- 18:23So instead of just focusing on the perimeter,
- 18:25you go inside your house. You put a heavy padlock
- 18:27on your safe. You install motion sensors in the
- 18:30hallway and you bolt the jewelry box to the floor.
- 18:33Exactly. You operate under the assumption that
- 18:35they will eventually get back inside. So you
- 18:37neutralize what they can actually do once they're
- 18:40standing in your living room. You make the stolen.
- 18:43key useless for the thing they actually want
- 18:45to steal. That's spot on. Taking your analogy
- 18:48a step further into the digital realm, what Nissan
- 18:51did was shift from a perimeter defense model
- 18:55to an immune system model. Oh, an immune system.
- 18:58Okay. Yeah. The human body doesn't just rely
- 19:00on the skin to keep viruses out, right? The skin
- 19:02gets cut. It's inevitable. Right. The real defense
- 19:05is the white blood cells circulating internally.
- 19:09constantly looking for abnormal behavior inside
- 19:12the bloodstream. Ah, I see. By locking down the
- 19:15specific mechanism of payroll changes, Nissan
- 19:18essentially deployed internal white blood cells.
- 19:21They assumed the perimeter was compromised and
- 19:23focused entirely on protecting the specific internal
- 19:26organs the attackers were trying to reach. It's
- 19:29treating security as a living, breathing strategy
- 19:31based on human behavior rather than just, you
- 19:34know, a checklist of software updates provided
- 19:37by a vendor. It really reinforces the absolute
- 19:40core lesson for anyone listening who manages
- 19:42IT infrastructure or even just manages their
- 19:45own digital life. Security must be a layered
- 19:48defense in depth. Right. Multiple layers. Organizations
- 19:51have to audit their internet facing applications
- 19:53relentlessly. They have to understand exactly
- 19:56what internal organs are exposed to the outside
- 19:59world. And they have to lock them down behind
- 20:01VPNs or zero trust architecture before a zero
- 20:04day vulnerability forces them into crisis mode.
- 20:07Because you can't wait for the crisis. No, because
- 20:09as this Oracle PeopleSoft incident proves, the
- 20:12window of time between a vulnerability being
- 20:15discovered by bad actors and your entire database
- 20:17being compromised is shrinking to essentially
- 20:20zero. It truly is a race against an invisible
- 20:23clock. And in this case, the bad guys had a full
- 20:26two week head start. Yeah, they're really good.
- 20:28Well, let's briefly recap the mission we set
- 20:31out on for you today. We've explored the sheer
- 20:33devastation of the Nissan cyber attack and the
- 20:36invisible mechanics of the Oracle PeopleSoft
- 20:38breach. It's a lot to take in. It is. We've looked
- 20:41at why HR data, rather than corporate secrets,
- 20:44is the new highly prized crown jewel for cyber
- 20:47criminals. We unpack the terrifying reality of
- 20:50an unauthenticated zero -day exploit, a flaw
- 20:52that basically bypasses the bouncer entirely
- 20:55and leaves companies defenseless for weeks. We
- 20:58discussed the psychological dark PR games played
- 21:02by extortion groups like shiny hunters to weaponize
- 21:04the media and inflate their leverage. And finally
- 21:07we looked at the crucial concrete lessons in
- 21:10incident response. The absolute necessity of
- 21:13minimizing your Internet exposure prioritizing
- 21:16security over convenience and actively closing
- 21:19the internal doors like Nissan did with payroll
- 21:22changes to prevent the secondary fraud that inevitably
- 21:25follows the initial theft. It is a. A massively
- 21:28complex, multilayered crisis. But pulling it
- 21:31apart and understanding the anatomy of how it
- 21:33actually functions mechanically and psychologically
- 21:35is really the only way organizations can build
- 21:38resilient defenses moving forward. I completely
- 21:40agree. And I think that leaves us with a final
- 21:42lingering thought for you to mull over as we
- 21:44wrap up this deep dive. We've spent this entire
- 21:46time talking about how zero -day vulnerabilities
- 21:48mean the initial breach is, in many cases, almost
- 21:51inevitable. Right. If you can't patch a hole
- 21:53you don't know exists, are you ever truly safe?
- 21:56It raises a provocative question. Does the concept
- 21:59of a completely secure system even exist anymore?
- 22:02That's a huge question. Or As we move into the
- 22:05future, will we stop measuring a company's security
- 22:08by the height and thickness of its digital walls
- 22:10and instead measure it purely by the speed, the
- 22:13intelligence, and the adaptability of its internal
- 22:15response when those walls inevitably fall? The
- 22:19lock on the front door might always be vulnerable
- 22:21to a new kind of lockpick. The real question
- 22:24is what the system does the exact moment the
- 22:26door swings open. Thank you so much for joining
- 22:29us on this deep dive today. Keep asking questions,
- 22:31keep looking under the hood, and we'll see you
- 22:33next time.