Security Weekly Podcast Network (Audio) Meatbags, AI Soul Harvest, DNS, LastPass, GS7, OpenClaw, MYSQL, Aaran Leyland, & More - SWN #556
Feb 17, 2026
Aaron Leyland, a security practitioner focusing on AI, OT/ICS, and critical infrastructure. He discusses AI risks to national infrastructure and real-world OT attacks. The conversation covers DNS-based malware, password manager server compromises, credential-harvesting campaigns, and worries about AI companions and data exfiltration.
AI Snips
Chapters
Books
Transcript
Episode notes
DNS-Based ClickFix Malware Delivery
- ClickFix attacks now abuse DNS responses to deliver PowerShell payloads via nslookup queries.
- Attackers can embed commands in DNS name records to bootstrap malware like Modelo RAT on victims' machines.
Treat Vault Servers As Potentially Hostile
- Use password managers but assume server compromise is possible and monitor for vendor updates.
- Patch promptly and evaluate trade-offs between cloud vault convenience and risk of centralized compromise.
Doppelbrand's High-Fidelity Phishing Campaigns
- GS7's Operation Doppelbrand creates near-perfect imitations of corporate portals to harvest credentials.
- Attackers automate harvesting, fingerprint devices, and exfiltrate results via Telegram bots to scale credential theft.











