Retour

Explorez tous les épisodes du podcast IT SPARC Cast

Plongez dans la liste complète des épisodes de IT SPARC Cast. Chaque épisode est catalogué accompagné de descriptions détaillées, ce qui facilite la recherche et l'exploration de sujets spécifiques. Suivez tous les épisodes de votre podcast préféré et ne manquez aucun contenu pertinent.

Rows per page:

1–50 of 111

TitreDateDurée
AI in Orbit, Microsoft’s Missteps, and the OpenAI Backdoor Nobody Saw Coming10 nov. 202500:18:17

In this week’s IT SPARC Cast – News Bytes, John and Lou go galactic—covering AI data centers in orbit, Microsoft’s blunders, and a nasty new Windows backdoor exploiting OpenAI’s API.


First, it’s “IT in SPAAAAAACE!” as Google unveils Project Suncatcher, an effort to launch radiation-hardened Tensor Processing Units (TPUs) into orbit for solar-powered, space-based AI compute. Then, SpaceX announces plans to build low-Earth-orbit data centers using its Starlink satellite infrastructure and Tesla’s upcoming AI chips—pushing the data center arms race off-planet.


Next up in “Really, Microsoft?” — the latest Windows 11 bug means “Update and Shut Down” doesn’t actually shut down. It just reboots. But the real danger comes from the newly discovered SesameOp backdoor, which uses the OpenAI Assistants API as its command-and-control channel—making it nearly invisible to traditional security tools.


Finally, Microsoft ends volume pricing discounts for enterprise customers, sparking frustration across IT departments already battling licensing complexity.


Show Notes


00:00 - Intro

John and Lou open with a new segment: “IT in Space!” as data centers literally leave Earth’s surface.


01:02 - Google’s Next Moonshot: Project Suncatcher

•Google to launch Project Suncatcher—solar-powered AI compute nodes using Tensor Processing Units (TPUs) in orbit.

•Partners with Planet Labs for radiation-hardened TPU testing.

•Orbiting clusters could provide 8x more energy efficiency than Earth-based systems.

•Challenges include cooling, radiation shielding, and debris avoidance.

https://9to5google.com/2025/11/04/google-project-suncatcher/


03:41 - SpaceX Plans Data Centers in Low-Earth Orbit

•SpaceX confirms Starlink v3 satellites will support data center modules.

•Tied to Tesla’s AI5 and upcoming AI6 chip platforms.

•Starship will be used to deploy orbital compute clusters.

•Laser interlinks and orbital energy capture could redefine distributed computing.

https://x.com/dimazeniuk/status/1984613494629503484?s=61&t=vt5DZTzMzVaVQd0cNd8iuA


06:55 - “Update and Shut Down” No Longer Restarts PC

•Microsoft’s November 2025 preview patch fixes a long-standing issue: “Update and Shut Down” reboots instead of powering off.

•Optional fix available under Windows 11 build 26200.7019.

•Another headache in Windows’ long list of quality-of-life bugs.

https://www.windowslatest.com/2025/11/02/update-and-shut-down-no-longer-restarts-pc-as-windows-11-25h2-patch-addresses-a-decades-old-bug/


08:10 - SesameOp Backdoor Using OpenAI Assistants API

•SesameOp discovered by Microsoft’s DART Team.

•Uses OpenAI’s Assistants API as a stealthy command-and-control (C2) channel.

•No patch yet—only firewall whitelisting and Defender rules recommended.

https://thehackernews.com/2025/11/microsoft-detects-sesameop-backdoor.html


13:53 - Microsoft Ends Volume Pricing

•As of Nov 1, Microsoft has eliminated tiered volume discounts for Enterprise Agreements.

•Large customers will now pay the same flat rate as smaller ones.

•Could increase software spend by double digits at renewal.

https://www.cio.com/article/4079004/microsoft-ends-volume-pricing-potentially-costing-companies-millions.html


15:29 - Mail Bag & Wrap Up

https://daily.jstor.org/when-the-push-button-was-new-people-were-freaked/


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

CVE-2025-52665: Ubiquiti UniFi Access Vulnerability — When Smart Doors Turn Dangerous07 nov. 202500:07:29

In this episode of IT SPARC Cast – CVE of the Week, John Barger and Lou Schmidt dive deep into CVE-2025-52665, a critical 10.0 CVSS vulnerability impacting Ubiquiti’s UniFi Access Management API. This flaw blends physical security and cybersecurity risks — allowing unauthenticated attackers to execute remote code, manipulate door access, or even lock users inside buildings.


John and Lou break down how this misconfigured API opens the door (literally) to full network takeover and discuss the real-world implications of smart building vulnerabilities. They cover the affected UniFi Access versions (3.3.22 to 3.4.31) and emphasize updating immediately to version 4.0.21 or later.


Beyond the technical details, they debate the broader question: Are smart buildings worth the risk? From API hygiene to network segmentation, the hosts offer actionable strategies to secure IoT infrastructure and ensure that “smart” doesn’t become “unsafe.”


⸻


Social Links:


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

EA’s AI Divide, Qualcomm’s Data Center Push, and Ubiquiti’s SFP Revolution03 nov. 202500:24:05

In this week’s IT SPARC Cast – News Bytes, John and Lou explore the intersection of AI, hardware, and IT freedom — from creative tension at EA to chipmaking disruption.


First, Electronic Arts (EA) launches ReefGPT, an internal AI design tool meant to boost productivity across studios. Developers say it’s unreliable and fear job losses, while leadership insists AI is the future. John and Lou unpack the deeper message: AI won’t take your job, but someone using AI will.


Then, Qualcomm jumps into the AI data center market with its new AI200 and AI250 chips — scaled-up versions of its mobile neural processors, ready to challenge Nvidia and AMD for inference workloads. The hosts discuss how this could finally relieve the GPU bottleneck driving AI infrastructure costs through the roof.


Next, Ubiquiti declares “SFP Liberation Day.” The new $49 SFP Wizard not only tests but reprograms fiber modules to work with any switch — bypassing vendor lock-ins from Cisco, HPE, and others. John and Lou call it “the jailbreak every network engineer has been waiting for.”


Finally, Substrate, a U.S. startup, unveils an X-ray lithography chipmaking tool that could rival ASML’s $400M EUV machines. Backed by $100M in funding, the company aims to bring advanced chip manufacturing back to the U.S. — potentially reshaping the semiconductor landscape.


00:00 - Intro

00:52 - Electronic Arts (EA) AI Divide

•EA launches ReefGPT to accelerate game design.

•Creatives call it unreliable and fear losing creative control.

https://www.businessinsider.com/inside-ai-divide-roiling-video-game-giant-electronic-arts-2025-10?op=1  

04:15 - Qualcomm Joins the AI Arms Race

•Qualcomm announces AI200 (2026) and AI250 (2027) chips for data centers.

•Targets Nvidia’s GPU monopoly with rack-mounted, liquid-cooled solutions.

•Could ease supply pressure and diversify AI compute resources.

https://www.cnbc.com/2025/10/27/qualcomm-ai200-ai250-ai-chips-nvidia-amd.html 

11:35 - Ubiquiti Liberates the SFPs

•“SFP Liberation Day” brings a $49 SFP Wizard tool for testing and reprogramming optics.

•Supports SFP, SFP+, and QSFP modules across brands.

•A win for network engineers tired of overpriced vendor modules.

https://blog.ui.com/article/welcome-to-sfp-liberation-day 

15:58 - Substrate Announces Chipmaking Tool to Rival ASML

•Substrate reveals an X-ray lithography system

•Rivaling ASML’s EUV tools at lower cost.

•Could reshape semiconductor competition and domestic manufacturing.

https://www.reuters.com/world/asia-pacific/us-startup-substrate-announces-chipmaking-tool-that-it-says-will-rival-asml-2025-10-28/

https://www.ft.com/content/2496edef-4f1b-47aa-877d-9c01271faaa1

https://www.wsj.com/tech/peter-thiel-backed-startup-secures-100-million-to-make-chips-in-u-s-baff93ac

21:02 - Mail Bag & Wrap Up

Hosted on Acast. See acast.com/privacy for more information.

DNS Nightmare: CVE-2025-40778 and the Scariest Phishing Setup Yet31 oct. 202500:10:38

In this special Halloween edition of CVE of the Week, John and Lou dive into a truly chilling scenario — a high-severity DNS poisoning flaw that could be the perfect setup for a wave of phishing attacks and credential theft across enterprise networks.


The star of the episode: CVE-2025-40778, a newly discovered vulnerability in BIND 9’s resolver logic. This flaw allows unauthenticated attackers to inject forged DNS records, redirecting legitimate queries to malicious servers — all without user interaction. With a CVSS score of 8.6, exploits are already active in the wild, and over 5,900 exposed instances have been identified.


But that’s just the start. The hosts explain how major outages at AWS (US-East-1) and Microsoft Azure opened the door for clever phishers to strike when users were most vulnerable — during downtime. Together, these issues illustrate a perfect storm of technical failure and human manipulation.


Lou and John share practical defenses: patch immediately, enable DNSSEC, restrict recursion, and — most importantly — establish a trusted, redundant communication plan for your users before the next outage hits.


⸻


Key Takeaways

•CVE-2025-40778 impacts BIND 9 versions from 9.11 to 9.21.12, including S1 previews.

•Exploits are already circulating — attackers can poison DNS caches remotely.

•Misconfigured DNS and phishing attacks can combine for devastating impact.

•Immediate action: patch, enable DNSSEC, monitor cache entries, and reduce TTLs.

•Prepare for outages — build redundant user communication channels to prevent panic and credential leaks.


Links

https://kb.isc.org/docs/cve-2025-40778 

https://nvd.nist.gov/vuln/detail/CVE-2025-40778

https://thehackernews.com/2025/10/threatsday-bulletin-dns-poisoning-flaw.html 

https://www.helpnetsecurity.com/2025/10/28/bind-9-vulnerability-cve-2025-40778-poc/ 


⸻


Wrap-Up – Stay Connected


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

OpenAI’s Atlas Browser | Quantum Breakthrough | AWS DNS Outage Explained27 oct. 202500:21:38

In this week’s IT SPARC Cast – News Bytes, John and Lou explore the fast-moving world of AI, quantum computing, and cloud reliability.


First up, OpenAI launches Atlas, an AI-powered browser with ChatGPT built in—complete with persistent memory, agent mode, and deep personalization. But as John warns, “If ChatGPT can see everything you do, that includes your company’s data.” Lou connects it to last week’s 7-Zip discussion, emphasizing the need for strict data access policies in enterprises managing shadow AI use.


Then, Google makes a quantum leap with its new Willow chip and Quantum Echoes algorithm, achieving verifiable quantum advantage—13,000x faster than classical supercomputers. The duo discusses its implications for material science, encryption, and the coming “cryptopocalypse.”


Next, Signal gets proactive, introducing Triple Ratchet Encryption—a post-quantum secure update using ML-KEM (Kyber) to protect against future quantum decryption. It’s the first major messaging platform to harden itself against Harvest Now–Decrypt Later attacks.


Finally, in this week’s Hot Take, the hosts analyze the recent AWS DNS outage that took down half the internet. Their verdict? “It’s not just AWS—it’s the apps.” They discuss multi-region design, cloud dependency, and why “Five Nines” uptime might be a thing of the past.


⸻


⏱️ Show Notes


00:00 - Intro


01:24 - OpenAI Debuts AI-Powered Browser (Atlas)

https://tech.slashdot.org/story/25/10/21/1725235/openai-debuts-ai-powered-browser-with-memory-and-agent-features 


07:27 - Google Launches New Quantum Chip and Algorithm

https://blog.google/technology/research/quantum-echoes-willow-verifiable-quantum-advantage/ 


09:31 - Signal Stays Ahead of the Game — Triple Ratchet Encryption

https://signal.org/blog/spqr 


⸻


12:03 - Hot Take: Amazon Web Services (AWS) DNS Outage

John recounts debugging his Ring cameras—before realizing the culprit was AWS.

•Cascading DNS failure caused a self-inflicted denial of service

•Exposed lack of redundancy and poor multi-region design

•50% of the internet went down, despite AWS only running 30% of it

Lou’s takeaway: “Cloud isn’t inherently resilient—it’s only as resilient as you design it to be.”

https://youtu.be/ygcYoFBXdjQ 


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

7-Zip Vulnerability: New CVEs Allow Remote Code Execution and File Overwrites24 oct. 202500:09:18

In this episode of CVE of the Week, John and Lou unpack a fresh pair of vulnerabilities affecting one of the most common tools on Windows desktops — 7-Zip.


Tracked as CVE-2025-11001 and CVE-2025-11002, these directory traversal flaws allow attackers to craft malicious archives that can escape the extraction folder, overwrite arbitrary files, and potentially lead to remote code execution (RCE). The hosts discuss how the vulnerabilities impact not just individual users but also automated systems such as CI/CD pipelines, backup servers, and antivirus scanners that automatically unpack archives.


They also cover how this seemingly moderate (CVSS 7.0) issue highlights a deeper problem — shadow IT and uncontrolled software installation inside enterprise environments. From patching strategies to user privilege escalation controls, this episode offers real-world guidance for keeping your organization secure.


⸻


Key Takeaways

•Two new 7-Zip vulnerabilities (CVE-2025-11001 & CVE-2025-11002) enable directory traversal and code execution.

•Impacts Windows desktops and automated extraction workflows in enterprise systems.

•Proof-of-concept exploits are already public on GitHub.

•The fix: Update 7-Zip immediately, disable automatic extraction of untrusted files, and audit your endpoint permissions.

•Also, define a clear policy for software installation to minimize risk from unmanaged tools.


⸻


Stay Connected


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

UniFi 9.5 Arrives, Satellite Secrets, and Cloud Vendors Cut Ties with China20 oct. 202500:20:19

In this episode of IT SPARC Cast – News Bytes, John and Lou cover the latest updates from Ubiquiti, Google, and the global supply chain.


First, UniFi Network 9.5 rolls out with Channel AI, a next-gen visualization tool that uses AI to map RF interference, optimize channels, and improve roaming performance. Add in wired port anomaly detection, Bonjour and multicast enhancements, and it’s clear—Ubiquiti’s aiming straight at the enterprise.


Then, a new report from UC San Diego and the University of Maryland reveals that half of all geostationary satellites are transmitting unencrypted data—including in-flight Wi-Fi, phone calls, and even critical infrastructure telemetry. Lou calls it “the coffee shop Wi-Fi of enterprise networking.”


Finally, Microsoft, AWS, and Google are all cutting China out of their supply chains, relocating server, switch, and AI chip production to India, Thailand, and Vietnam to reduce risk and geopolitical exposure. The move may reshape where tomorrow’s cloud is built.


⸻


⏱️ Show Notes


00:00 - Intro

John & Lou tee up the week’s biggest IT stories with a mix of insight, humor, and caffeine.


⸻


00:48 - Introducing UniFi Network 9.5

•Major update to UniFi’s platform with Channel AI for real-time RF visualization.

•Enhanced roaming for Apple devices.

•New wired port anomaly detection and better multicast handling.

•Lou calls it “the most enterprise-ready version of UniFi yet.”

https://blog.ui.com/article/releasing-unifi-network-9-5 



⸻


06:18 - Satellites Found Exposing Unencrypted Data

•Researchers intercepted sensitive traffic from half of all GEO satellites.

•Data included calls, in-flight Wi-Fi, and industrial telemetry.

•Some providers, like AT&T and T-Mobile Mexico, are still unpatched.

•John warns: “Satellites are the coffee shop Wi-Fi of enterprise networks.”

•Encrypt your traffic at the endpoint—don’t rely on the carrier.

https://techcrunch.com/2025/10/14/satellites-found-exposing-unencrypted-data-including-phone-calls-and-some-military-comms/  



⸻


12:24 - Microsoft, AWS, and Google Are Reducing China’s Role in Their Supply Chains

•Microsoft aims for 80% of Surface, Xbox, and server production outside China by 2026.

•AWS and Google shifting to India, Thailand, and Vietnam.

•Lou notes: “The white boxes in your rack probably started in a hyperscaler design lab.”

•Reduced tariffs, diversified supply, and fewer geopolitical risks ahead.

https://techcrunch.com/2025/10/16/microsoft-aws-and-google-are-trying-to-drastically-reduce-chinas-role-in-their-supply-chains/ 

 


⸻


18:05 - Mail Bag & Wrap Up

Listener Tom writes in, celebrating Synology’s decision to restore third-party drive compatibility:


“They’re back at the top of my list.”


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn


Hosted on Acast. See acast.com/privacy for more information.

F5 Breach: Nation-State Hack Exposes Source Code & Global Infrastructure Risks17 oct. 202500:10:25

A suspected state-sponsored attack has breached F5 Networks, compromising source code, customer data, and production systems. With F5 handling 85% of global load balancing, this could expose countless organizations to new zero-day vulnerabilities.


John and Lou break down how it happened, what’s at risk, and what you should do right now if your infrastructure depends on F5 BIG-IP or related systems.


✅ Learn how to prepare for cascading exploits

✅ Why this breach could redefine patch management and Zero Trust

✅ What AI means for future vulnerability discovery


Like, subscribe, and share to stay ahead of the next major exploit.


Follow us:

IT SPARC Cast — @ITSPARCCast on X | https://www.linkedin.com/company/sparc-sales/

John Barger — @john_Video on X | https://www.linkedin.com/in/johnbarger/

Lou Schmidt — @loudoggeek on X | https://www.linkedin.com/in/louis-schmidt-b102446/

Hosted on Acast. See acast.com/privacy for more information.

Ubiquiti’s Power Play, Google’s Code Doctor, and Synology’s Surrender13 oct. 202500:19:49

In this episode of IT SPARC Cast – News Bytes, John and Lou break down three big stories that touch nearly every corner of enterprise IT—from power to code to storage.


First, Ubiquiti expands into the UPS market with the new UniFi Uninterruptible Power Supply, combining network management integration, graceful shutdown control, and plug-and-play simplicity for small offices and home labs.


Then, they explore Google DeepMind’s latest breakthrough—CodeMender, an AI tool that not only finds software vulnerabilities but also rewrites and tests patches automatically before submitting them upstream.


Finally, Synology caves to user backlash, walking back its controversial policy that restricted third-party drives in 2025 NAS models. The nerd uprising worked, restoring support for Seagate, WD, and other drives under DSM 7.3.


⏱️ Show Notes


00:00 - Intro


00:51 - Ubiquiti Is Launching a New UniFi Uninterruptible Power Strategy

Ubiquiti enters the UPS market with the UniFi UPS Tower ($159) and UniFi UPS 2U Rackmount ($279).

•Fully integrates with UniFi OS for device-wide graceful shutdown.

•Simplifies UPS monitoring—no scripting or manual config needed.

https://blog.ui.com/article/introducing-uninterruptible-power


06:00 - Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them

Google DeepMind’s CodeMender is the next step in automated software security.

•Detects, rewrites, and self-tests patches before submitting them.

•Refactors vulnerable code to prevent flaw reoccurrence.

•Uses multi-AI feedback loops to ensure accuracy before final submission.

https://thehackernews.com/2025/10/googles-new-ai-doesnt-just-find.html 


11:03 - Synology Walks Back Controversial Compatibility Policy for 2025 NAS Units

User backlash works—Synology reverses its decision to block third-party drives in the Plus Series 2025 NAS lineup.

•DSM 7.3 restores compatibility with non-Synology drives.

•Synology pledges a new third-party drive validation program.

https://www.tomshardware.com/pc-components/nas/synology-walks-back-controversial-compatibility-policy-for-2025-nas-units-third-party-hdd-and-ssd-support-returns-with-diskstation-manager-7-3-update 


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Redis “RediShell” CVE-2025-49844: Cloud Infrastructure at Risk10 oct. 202500:10:23

In this week’s episode of IT SPARC Cast - CVE of the Week, John Barger and Lou Schmidt dive deep into CVE-2025-49844, a newly discovered and critical remote code execution vulnerability in Redis—the in-memory database that powers over 75% of cloud services. This flaw, dubbed “RediShell”, scores a perfect 10.0 CVSS and affects Redis instances using Lua scripting, allowing attackers to execute arbitrary code and gain full system control.


This 13-year-old bug stems from a use-after-free memory corruption issue that lets attackers escape the Lua sandbox, run malicious code, exfiltrate data, deploy crypto miners, or move laterally inside cloud environments. Even worse—more than 60,000 internet-exposed Redis servers have no authentication, leaving them completely open to exploitation.


John and Lou discuss how this happened, what you can do to secure your infrastructure, and why “cloud-hosted” doesn’t always mean “secure.”

✅ Key Takeaways:

•Update to patched versions immediately (8.2.2, 8.0.4, 7.4.6, 7.2.11, 6.2.20)

•Restrict network access with ACLs

•Rotate all credentials and API keys

•Don’t run Redis as root

•Isolate any compromised hosts before investigation


Lou calls it “a 10 on the oh-crap-ometer”—and he’s not wrong.


https://thehackernews.com/2025/10/13-year-redis-flaw-exposed-cvss-100.html

https://www.darkreading.com/cloud-security/patch-now-redishell-redis-rce

Hosted on Acast. See acast.com/privacy for more information.

Landlord Hacks, Stargate Chips, and Robot Takeovers06 oct. 202500:18:42

In this episode of IT SPARC Cast – News Bytes, John and Lou dive into three stories that blur the line between security, AI, and sci-fi becoming reality.


First, a jaw-dropping report reveals landlords using tenant-screening services to demand employee workplace logins—scraping paystubs directly from systems like ADP. It’s not only unethical—it’s potentially illegal. John and Lou unpack the security, HR, and legal nightmare this poses for corporate IT teams.


Next, OpenAI and Samsung team up under the Stargate project, with Samsung dedicating nearly 40% of its DRAM output to fuel OpenAI’s next wave of AI data centers—potentially even floating ones. The AI arms race is expanding into new dimensions.


Finally, a newly disclosed exploit gives attackers full control over Unitree robots—including humanoids and quadrupeds—via Bluetooth. The flaw, dubbed UniPwn, allows worms to spread across fleets of robots. Lou calls it “Runaway with Tom Selleck meets Star Trek: The Borg.”


⸻


⏱️ Show Notes


00:00 - Intro

John and Lou set up this week’s stories on privacy violations, AI chip deals, and robot exploits.


⸻


00:48 - Landlords Demand Tenants’ Workplace Logins to Scrape Their Paystubs

Landlords and tenant-screening services are asking renters to log into employer systems so they can scrape payroll data.

•Platforms like Argyle and Approve Shield are at the center of the controversy.

•This violates employee data access policies and may breach federal hacking laws.

•IT leaders should issue internal advisories and enforce MFA to prevent credential leaks.

https://www.404media.co/landlords-demand-tenants-workplace-logins-to-scrape-their-paystubs/ 


⸻


07:05 - OpenAI, Samsung & the Stargate Chip Pact

OpenAI partners with Samsung and SK Hynix under the Stargate project.

•Samsung to provide 900,000 DRAM wafers monthly—40% of its capacity.

•Floating, green data centers are in the works.

•May overlap with Nvidia’s 10GW expansion announced last week.

https://www.theverge.com/news/789687/openai-samsung-stargate-chips 


⸻


10:51 - Exploit Allows Takeover of Fleets of Unitree Robots

Researchers uncovered CVE-2025-60251, a wormable flaw in Unitree’s robot lineup.

•Bluetooth handshake vulnerability allows remote takeover.

•Affects quadrupedal GO2/B2 and humanoid G1/H1 robots.

•Attackers can form botnets, move robots, or exfiltrate data.

•Security professionals must begin planning IoT and robotics policies now.

https://spectrum.ieee.org/unitree-robot-exploit 


⸻


17:01 - Mail Bag & Wrap Up


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Trusted Execution Environment (TEE) Hardware Attacks03 oct. 202500:08:45

In this eye-opening episode of IT SPARC Cast - CVE of the Week, John Barger and Lou Schmidt explore a shocking vulnerability that doesn’t exploit code — it exploits hardware. Specifically, they dive into how Intel and AMD’s Trusted Execution Environments (TEEs), once hailed as unbreakable, can be compromised via physical attacks. From voltage glitching to signal probing, these advanced threats are no longer theoretical and could sidestep your most hardened security measures.


The episode highlights real-world methods like side-channel probing, interposers, and even fault injection used to extract secrets directly from servers. If a malicious actor can gain physical access to your systems, all bets are off. Lou breaks down the Heracles attack on both AMD SEV and Intel SGX. The hosts emphasize just how crucial physical access controls, chassis alarms, and access logs really are.


Don’t underestimate your weakest link — your data center lock and key.


⸻


🔗 Social Links (Wrap Up Section):


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Nvidia & OpenAI's $100B AI Play, Moon Helium Mining, and Windows 10’s Reprieve29 sept. 202500:18:06

In this episode of IT SPARC Cast – News Bytes, John and Lou break down three stories reshaping enterprise IT and beyond. Nvidia plans to pour up to $100B into OpenAI, funding 10 gigawatts of new data center capacity—raising big questions about power, infrastructure, and the AI arms race.


Next, we explore a moon helium deal that marks the biggest-ever purchase of natural resources from space. A Finnish firm is set to buy Helium-3 for quantum computing and potential fusion—science fiction turning into enterprise reality.


Finally, Microsoft backtracks on Windows 10’s end of life by offering one year of free security updates, buying time for millions of organizations still running legacy systems.


⸻


⏱️ Show Notes


00:00 - Intro

Kicking off this week’s IT digest with energy, space, and security updates.


00:58 - Nvidia to Invest up to $100B into OpenAI

•Nvidia commits up to $100B to build data centers for OpenAI.

•Target: 10 gigawatts of compute capacity—unprecedented in scale.

•Raises concerns over power, sustainability, and regulation.

•Could fast-track nuclear projects and reshape U.S. energy policy.

https://nvidianews.nvidia.com/news/openai-and-nvidia-announce-strategic-partnership-to-deploy-10gw-of-nvidia-systems 


07:22 - Moon Helium Deal: Biggest Purchase of Natural Resources from Space

•Finnish company BlueForce signs deal with Interloon to mine Helium-3 on the moon.

•Contract: up to 10,000 liters per year between 2028–2037.

•Helium-3 critical for quantum computing cooling and nuclear fusion fuel.

•Moves lunar mining from sci-fi dream to IT-impacting reality.

https://www.msn.com/en-us/news/technology/a-company-ordered-helium-from-the-moon-no-it-s-not-science-fiction/ar-AA1MEkNK 


12:43 - Microsoft Offers Free Windows 10 Security Updates for One Year

•Windows 10 scheduled to end support October 2025.

•Microsoft extends free security updates through October 2026.

•Affects ~53% of PCs still running Windows 10.

•Likely to extend again due to huge install base.

https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline 


⸻


17:19 - Wrap Up

Thanks for tuning in—let us know your thoughts on Nvidia’s investment, lunar helium mining, or Microsoft’s Windows 10 strategy.


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Critical SNMP Vulnerability in Cisco IOS/IOS XE – CVE-2025-2035226 sept. 202500:08:07

In this episode of IT SPARC Cast – CVE of the Week, John and Lou break down CVE-2025-20352, a serious SNMP vulnerability impacting Cisco’s IOS and IOS XE software. Rated CVSS 7.7, this flaw allows attackers with read-only SNMP credentials to crash your system—and with admin credentials, it can escalate to full remote code execution as root. That’s right—root.


We explain why this threat is more dangerous than the score suggests, how it fits into broader supply-chain and chain-attack patterns, and why outdated or unsupported infrastructure makes this even worse. The team also shares mitigation tips and why you might need to shut off SNMP entirely if you’re running legacy gear.


If you’re managing Cisco infrastructure, especially with SNMPv2c or earlier, this episode is a must-listen. Don’t wait for this to be part of a multi-vector attack—lock it down now.


⸻


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

UniFi’s Storage Wars, AI Outsourcing Fallout, and Nvidia’s Intel Bet22 sept. 202500:22:29

In this episode of IT SPARC Cast – News Bytes, John and Lou cover three stories that hit at the core of enterprise IT and the global tech economy. Ubiquiti expands its portfolio with a new UniFi NAS lineup, featuring everything from 2-bay PoE-powered appliances to rackmount Pro units with 10G and redundant power. The move puts UniFi in direct competition with Synology—but with its own unique twists.


Then, they turn to India’s outsourcing industry, where AI is hollowing out the entry-level coding, QA, and documentation jobs that fueled its decades-long tech boom. What does this mean for global IT services, and can India climb the value chain before it’s too late?


Finally, Nvidia just dropped a $5B investment in Intel, snapping up common stock and setting the stage for joint chip development. Could this be a “promise ring” for an eventual acquisition—and what does it mean for the U.S. semiconductor landscape?


⏱️ Show Notes


00:00 - Intro

John and Lou set the stage for this week’s enterprise IT news rundown.


00:55 - UniFi’s Next-Gen Storage Lineup

Ubiquiti announces four new NAS appliances:

•UNAS 2: $200, 2-bay, 2.5G, PoE-powered, targeted at home & small office.

•UNAS 4: $380, 4-bay, adds NVMe cache slots, PoE+++, ships Q4.

•UNAS Pro 4: $500, 1RU rackmount, multiple 10G ports, MCLAG support.

•UNAS Pro 8: $800, 2RU rackmount, 8 bays, dual PSUs, enterprise-ready.


No container compute like Synology, but excellent backup/cloud integration and PoE flexibility make these compelling.

https://blog.ui.com/article/all-new-next-gen-of-unifi-storage  


06:46 - AI is Gutting the Entry-Level Jobs That Powered India’s Tech Boom

•Entry-level coding, QA, and tech writing roles are being automated away.

•Hiring has dropped drastically, with unemployment among young engineers rising.

•Outsourcing’s model is collapsing, replaced by AI’s first-pass coding, testing, and documentation.


What’s next: India must move up the value chain—or face major economic disruption.

https://indiadispatch.com/p/hollow-at-the-base


12:33 - Nvidia is Investing $5 Billion in Intel

•Nvidia buys $5B in Intel stock at $23.28/share.

•Strategic partnership to co-develop chips for data centers and PCs.

•Could this be the start of Nvidia acquiring Intel?

•Implications for U.S. chip sovereignty, competition with AMD, and the AI infrastructure arms race.

https://www.investopedia.com/nvidia-bets-big-on-intel-with-usd5b-investment-11812508


17:32 - Listener Feedback

John & Lou respond to a listener’s thoughtful comments on UniFi vs. Cisco enterprise support, exploring VAR roles, RMA challenges, and whether UniFi is ready for global scale.


21:11 - Wrap Up

Thanks for tuning in! Drop your feedback via email, X, or YouTube comments—we read them all.


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Chrome Zero-Day Exploit: CVE-2025-10585 in V8 Engine19 sept. 202500:06:06

In this week’s episode of IT SPARC Cast - CVE of the Week, John Barger and Lou Schmidt dive into CVE-2025-10585, a newly discovered and actively exploited Chrome zero-day vulnerability that targets the V8 JavaScript engine. This type confusion flaw opens the door to arbitrary code execution — and yes, it’s already being used in the wild. With 70% of the browser market affected, this isn’t just a theoretical risk.


John and Lou break down the exploit mechanics, what V8 is and why it’s so critical, and how this CVE marks the sixth Chrome zero-day in 2025 alone. They also discuss mitigation steps and the ripple effects for Chromium-based browsers like Edge, Brave, and Opera. As a bonus, the duo interprets a cryptic (and possibly alarming) listener comment involving fileless malware, COFF loaders, and HTTPS delivery — spooky stuff.


⸻


🔗 IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


🎙️ John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


🎙️ Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

GitHub Kills Vibe Coding | Deep Fission Drills | OpenAI’s Chip Move15 sept. 202500:16:15

In this episode of IT SPARC Cast – News Bytes, John and Lou explore three stories that could reshape IT’s future. GitHub’s launch of SpecKit signals the end of “vibe coding” as we know it—ushering in a new era of spec-driven development that empowers product managers to become builders. Next, we dive deep (literally) into the nuclear startup Deep Fission, which just went public via a SPAC with a plan to drill tiny nuclear reactors into the earth near data centers. Finally, OpenAI is teaming up with Broadcom to launch a custom AI chip by 2026, intensifying the race for compute power.


If you’re interested in dev workflows, energy innovation, or AI hardware strategy—this is one you don’t want to miss.


⸻


⏱️ Show Notes


00:00 - Intro


00:49 - GitHub Just Killed Vibe Coding

GitHub’s new Spec-Kit toolkit enables spec-driven development, allowing teams to move from document to executable with dramatically fewer handoffs. Product managers can now define specs, environments, and target platforms, letting tools like LLMs and automation build apps directly.

John calls it a “product manager’s dream,” while Lou warns it could disrupt the delicate balance between engineering and PM teams.

https://github.com/github/spec-kit 

https://youtu.be/em3vIT9aUsg?si=ND9GlREU7ccDaV0H 

https://www.reddit.com/r/GithubCopilot/comments/1n7v2pv/kiro_is_cooked_githubs_spec_kit/ 


07:15 - Nuclear Startup Deep Fission Goes Public in a Curious SPAC

Deep Fission just raised $30M by reverse merging with Surfside Acquisition. Their bold plan? Small modular nuclear reactors dropped a mile underground—powering AI-hungry data centers with ultra-local energy.

They’re partnering with Endeavor to co-develop 2GW of underground capacity and have been tapped for a DOE reactor pilot program.

https://techcrunch.com/2025/09/08/nuclear-startup-deep-fission-goes-public-in-a-curious-spac/ 


11:47 - OpenAI to Launch Its First AI Chip in 2026 with Broadcom

OpenAI and Broadcom are building a new AI chip that will power OpenAI’s internal workloads starting in 2026.

• It won’t be publicly available (at least at launch).

• It’s the latest in a growing trend of custom silicon from AI giants.

• Lou & John break down why this signals a hardware arms race and the compute bottlenecks that still plague the AI industry.

https://www.reuters.com/business/openai-launch-its-first-ai-chip-2026-with-broadcom-ft-reports-2025-09-05/ 


⸻


15:30 - Wrap Up

Thanks for tuning in! We want your feedback:

📩 feedback@itsparccast.com


📣 Social Links


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Academic Ransomware AI? PromptLocker Panic Explained12 sept. 202500:07:36

In this episode of IT SPARC Cast – CVE of the Week, John Barger and Lou Schmidt unravel the truth behind PromptLocker — the so-called first “AI-powered ransomware.” Initially flagged by ESET and widely misunderstood as an active cyber threat, PromptLocker was actually part of a controlled academic research project from NYU’s Tandon School of Engineering, known as “Ransomware 3.0.”


We break down how this proof-of-concept malware used LLMs to dynamically generate malicious code, how it slipped into threat databases, and why this isn’t a crisis — but rather, a warning. With the ability to generate malware instructions on-the-fly without any static payload, this project forces a rethink of traditional security detection methods. The cost? About 70 cents using commercial APIs — or virtually free with open-source models. Join us for a grounded, insightful conversation about what’s real, what’s hype, and what you should be doing next.


https://www.tomshardware.com/tech-industry/cyber-security/ai-powered-promptlocker-ransomware-is-just-an-nyu-research-project-the-code-worked-as-a-typical-ransomware-selecting-targets-exfiltrating-selected-data-and-encrypting-volumes 


https://www.techradar.com/pro/security/the-first-ai-powered-ransomware-has-been-spotted-and-heres-why-we-should-all-be-worried 


https://www.pcgamer.com/software/ai/oh-goody-the-first-known-ai-powered-ransomware-has-been-discovered-and-it-may-exfiltrate-data-encrypt-it-or-potentially-destroy-it/ 


https://www.itpro.com/security/ransomware/security-researchers-have-just-identified-what-could-be-the-first-ai-powered-ransomware-strain-and-it-uses-openais-gpt-oss-20b-model


⸻


🔗 Social Links


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Shadow AI, ChatGPT & the Law, and Japan’s AI Back Office Revolution08 sept. 202500:22:24

In this episode of IT SPARC Cast – News Bytes, John and Lou unpack OpenAI’s controversial decision to escalate certain ChatGPT conversations to law enforcement—and what that means for user privacy and corporate risk. They then turn to Shadow AI: the unsanctioned use of ChatGPT, Claude, and others by employees, and how enterprises can detect, monitor, and respond without overreacting.


Finally, they spotlight LayerX, a Japanese SaaS startup leading the charge on back-office AI automation—proof that even traditionally conservative markets are embracing next-gen AI for business transformation.


⸻


📝 Show Notes:


00:00 - Intro

A quick rundown of the week’s hottest IT headlines and opinions with John & Lou.


⸻


00:49 - OpenAI Is Reporting ChatGPT Conversations to Law Enforcement

OpenAI has quietly updated its policy: if human reviewers believe a user poses an imminent threat of serious harm, the company may escalate to law enforcement—even without a formal legal request. This has sparked online outrage and privacy concerns, with many calling it a betrayal of OpenAI’s past promises of near-therapist-level confidentiality. John and Lou break down the policy, review real-world implications, and share perspectives on transparency, self-regulation, and the risk of human bias in the review loop.

https://futurism.com/people-furious-openai-reporting-police 


⸻


08:05 - Can Your Security Stack See ChatGPT? Why Network Visibility Matters

Shadow AI is on the rise. Employees are bypassing sanctioned tools like Microsoft Copilot and quietly using ChatGPT, Claude, and others to boost productivity. But most corporate security stacks aren’t monitoring these tools. John shares insights into URL filtering, file upload tracking, and behavior-based flags to detect Shadow AI usage. Lou reminds us: education—not punishment—should be your first move.

https://thehackernews.com/2025/08/can-your-security-stack-see-chatgpt-why.html


⸻


15:52 - LayerX: Japan’s AI Answer to Back Office Drudgery

Japan-based LayerX just raised $100M to accelerate AI-powered back-office automation. Their platform—already used by 15,000+ companies—handles expense reports, invoicing, and corporate card ops. John and Lou discuss the implications of conservative Japanese enterprises adopting AI at scale, and what this signals for global enterprise IT adoption.

https://techcrunch.com/2025/09/01/layerx-uses-ai-to-cut-enterprise-back-office-workload-scores-100m-in-series-b/ 


⸻


21:06 - Listener Feedback & Wrap Up

John gives a shoutout to listener BJ for chiming in on last week’s FTC encryption story. Keep the feedback coming: feedback@itsparccast.com


⸻


Social Links:

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Crypto Wallets Compromised by Malicious npm Package05 sept. 202500:08:42

In this episode of IT SPARC Cast – CVE of the Week, John and Lou dive into a stealthy supply chain attack involving a malicious npm package impersonating NodeMailer. This package—nodejs-smtp—was designed to exploit unsuspecting developers by mimicking legitimate behavior while secretly stealing funds from popular cryptocurrency wallets like Atomic Wallet and Exodus on Windows systems.


The attack was cleverly disguised, executed through Electron-based payloads, and capable of repackaging the victim’s wallet apps to reroute crypto transactions to attacker-controlled wallets. Even build and CI pipelines could miss the infection due to the module’s deceptive functionality. With only 347 downloads before removal, the attack still presents a clear and present danger due to how easily it could be missed or reused.


John and Lou break down how this was discovered, how it works, why it’s dangerous, and what every developer and crypto user should do to protect themselves. They also reflect on how AI-assisted code review, registry controls, and isolated environments are now must-haves for any serious dev or security-conscious user.


⸻


🔗 Social Links (Wrap Up Section)


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Encryption Under Fire, AI Unleashed, and Nvidia’s Epic Surge02 sept. 202500:19:22

In this episode of IT SPARC Cast – News Bytes, John and Lou dissect the tension between privacy and surveillance as the FTC doubles down on encryption protection amid global pressures. Then it’s into the shadows as hackers weaponize generative AI to write malware, exploit zero-days, and outpace defenses. Finally, the hosts break down Nvidia’s record-shattering revenue report and explore what it means for enterprise IT and AI infrastructure at scale.


From the frontlines of cybersecurity to the bleeding edge of AI acceleration, this episode is packed with insights, expert banter, and real-world context.


⸻


⏱️ Timestamps & Show Notes


00:00 - Intro

Welcome to another edition of IT SPARC Cast – News Bytes, your trusted short-form rundown of this week’s enterprise IT headlines.


⸻


00:46 - Holding the Line on Encryption: FTC Pushes Back

The Federal Trade Commission is standing firm against global efforts to weaken end-to-end encryption, asserting that consumer privacy and data security cannot be compromised. This marks a pivotal stance as world governments call for encryption “backdoors” to aid law enforcement.

• Key talking points include political tensions, IPA debates, and the FTC’s broader data security agenda.

https://www.bleepingcomputer.com/news/security/ftc-warns-tech-giants-not-to-bow-to-foreign-pressure-on-encryption/?utm_source=chatgpt.com 


05:21 - Hackers Unlock the Power of AI

New research shows hackers are weaponizing generative AI to:

• Write polymorphic malware

• Bypass defenses with zero-day obfuscation

• Rapidly scale attacks

Lou and John unpack how this changes threat modeling and what defenders must do to keep up with AI-fueled exploits.

https://thehackernews.com/2025/08/anthropic-disrupts-ai-powered.html 

https://thehackernews.com/2025/08/someone-created-first-ai-powered.html 



11:50 - Nvidia Sets New Revenue Record as AI Demand Soars

Nvidia’s Q2 earnings shatter expectations, with $42 billion in revenue driven by skyrocketing demand for AI chips and GPU infrastructure.

• Enterprise implications

• Cloud vendor reactions

• Supply chain pressures

The team also discusses how Nvidia is shifting from a chipmaker to a full AI platform vendor.

https://finance.yahoo.com/news/nvidia-reports-record-sales-ai-211839151.html 


17:00 - Mail Bag


18:26 - Wrap Up

Thanks for tuning in to IT SPARC Cast! Be sure to subscribe, leave a review, and follow us for more weekly insights into the evolving world of enterprise IT.


Social Links

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Zombie Cisco Gear: CVE-2018-0171 Exploited by Russian Espionage29 août 202500:07:41

Russian state-sponsored hackers are actively exploiting a seven-year-old Cisco vulnerability—CVE-2018-0171—and turning forgotten infrastructure into surveillance tools. On this episode of IT SPARC Cast – CVE of the Week, John Barger and Lou Schmidt break down how outdated Cisco hardware is being targeted through the Smart Install feature and how the FSB-linked group “Berserk Bear” is using them to extract credentials and embed persistent access.


You’ll learn:

•Why legacy hardware in manufacturing, education, and telecom is at risk

•How attackers are using configuration harvesting for long-term access

•What “Cisco zombies” really means—and why it’s the wrong term

•Practical steps for discovery, mitigation, and infrastructure hygiene


From drop-ceiling surprises to international espionage, this episode is a must-listen for every IT leader responsible for aging infrastructure. Patch early. Patch often. And for the love of security, don’t feed the hackers.


⸻


📢 Wrap Up & Social Links


Got a similar story? Or maybe you’ve walked into a nightmare network too? Share it with us:


📩 feedback@itsparccast.com

💬 @ITSPARCCast on X

🔗 https://www.linkedin.com/company/sparc-sales/


Follow the hosts:


👤 John Barger

X: @john_Video

LinkedIn: https://www.linkedin.com/in/johnbarger/


👤 Lou Schmidt

X: @loudoggeek

LinkedIn: https://www.linkedin.com/in/louis-schmidt-b102446/


Be sure to Like, Subscribe, and Enable Notifications so you don’t miss the next vulnerability breakdown.

Hosted on Acast. See acast.com/privacy for more information.

UniFi Object Networking, Password Failures, and Black Hat Intel25 août 202500:23:01

In this episode of IT SPARC Cast – News Bytes, John and Lou take on three stories that highlight where enterprise IT is innovating—and where it’s still falling short. Ubiquiti’s UniFi Network 9.4 is out, and it’s more than just an update. John breaks down how Object Networking simplifies dynamic policy management and monitoring, delivering enterprise-grade controls to SMBs without scripting. You’ll hear how new scanning and traffic insight tools aim to make real-time optimization more accessible than ever.

https://blog.ui.com/article/releasing-unifi-network-9-4


Then Lou gets real about a disturbing trend: password hygiene is still garbage. The Blue Report 2025 shows that 46% of environments are still vulnerable to simple password cracking, and attackers succeed 98% of the time when using compromised credentials. The team covers how MFA, passwordless logins, and behavioral biometrics might help…if companies actually start using them.

https://thehackernews.com/2025/08/weak-passwords-and-compromised-accounts.html


Finally, the pair turn their eyes to Las Vegas and the big security themes from Black Hat 2025. With AI agents, identity-first architectures, and DSPM tools dominating the show floor, it’s clear that managing identity, authorization, and data governance is now the front line. They also unpack major concerns around deepfakes, insider risks, and post-quantum threats.

https://www.techtarget.com/searchsecurity/opinion/Identity-and-data-security-themes-at-Black-Hat-2025


⸻


🔗 Wrap Up


Thanks for listening to IT SPARC Cast!


Follow us online for more enterprise IT insights:

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

QuirkyLoader Malware & The Quishing Epidemic: What IT Needs to Know22 août 202500:07:35

This week on CVE of the Week, John and Lou break down the rising threat of QuirkyLoader, a new malware loader delivering Remote Access Trojans and info-stealers through DLL sideloading. But the real danger? It’s hiding in plain sight—QR codes.


We explore the rise of quishing (QR code phishing), why QR codes are the new “USB drives in the parking lot,” and how both the IT and marketing teams might unknowingly contribute to this growing attack vector. From user education to software architecture changes and questionable operating system defaults, this episode challenges the security status quo.


🔐 Topics covered:

•How QuirkyLoader uses DLL sideloading and process hollowing

•The resurgence of QR-based phishing attacks

•Why your marketing team might be the weakest link

•Should Apple and Google restrict QR scanning?


If you’re responsible for cybersecurity awareness, endpoint protection, or enterprise app architecture—don’t skip this one.

Hosted on Acast. See acast.com/privacy for more information.

Digital Ghosts, Vibe Coders, and AI Help Desks18 août 202500:19:53

In the Season 2 premiere of IT SPARC Cast - News Bytes, John & Lou return with a fresh batch of IT news and sharp insights. From the ethics of digital afterlives to AI-enhanced help desks, this episode dives into the weird, the practical, and the quietly transformative.


First, they explore whether the dead should have a “digital delete button”, as tech platforms debate data rights for the deceased. Then, they dig into Uno Platform’s push for enterprise “vibe coders” building cross-platform apps with AI-assisted tools. Finally, they examine how General Catalyst is investing in smarter AI-driven IT support for enterprise environments. Plus: A listener mailbag sparks nostalgia for gear-hauling IT jobs of the past.


⏱️ Timestamps & Show Notes


00:00 - Intro

Season 2 kicks off! Welcome back to another season of enterprise IT, security insights, and sarcasm from your two favorite IT pros.


01:07 - Should the Dead Have a Digital Delete Button?

A new philosophical and legal debate arises:

•Should the deceased have their online data erased by default?

•Do family members or estate holders have the right to preserve or delete digital legacies?

•How should platforms handle “posthumous presence”?

https://www.theregister.com/2025/08/09/dead_need_ai_data_delete_right/


07:29 - Uno Platform Targets Enterprise Vibe Coders

Uno Platform positions itself as a cross-platform AI tool for modern Vibe Coders:

•Leverages .NET to deliver native apps on Web, iOS, Android, and Windows

•Could be a game-changer for internal enterprise tooling

https://techcrunch.com/2025/08/12/in-a-world-of-vibe-coding-startups-uno-platform-is-targeting-enterprise-developers/


12:36 - General Catalyst Helps the Help Desk with AI

General Catalyst backs AI-based help desk automation:

•Improving IT support with context-aware, LLM-powered agents

•These agents integrate with backend systems and reduce Tier 1 volume

•Potential to reshape the future of enterprise IT support

https://www.msn.com/en-us/money/smallbusiness/general-catalyst-s-latest-ai-bet-is-in-it/ar-AA1Kn2cm

https://www.wsj.com/articles/general-catalysts-latest-ai-bet-is-in-it-3a2f5b03

https://www.wsj.com/articles/it-departments-are-overloaded-with-busy-work-can-ai-change-that-19a9f667


17:05 - Listener Mail Bag

A shoutout to listener who reminisces about rolling carts and CRT monitors. We hear you, Rob—and we’ve all got the spinal injuries to prove it.


18:58 - Wrap Up

Thanks for joining us in Season 2! Got feedback, episode ideas, or hot takes? Reach out—we read it all.


feedback@itsparccast.com

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Docker Hub CVE Wake-Up Call: Malware from 2024 Still Lurking in 2025 Images!15 août 202500:08:25

We’re kicking off Season 2 of IT SPARC Cast - CVE of the Week with a critical vulnerability warning that should make every DevOps and IT leader take notice. This episode dives into the shocking discovery that 35 Docker Hub images still contain malware linked to the 2024 XZ Utils supply chain attack—highlighting massive blind spots in container security.


John and Lou explore how this outdated exploit has resurfaced in current Docker images, why current scanning tools failed to catch it, and what security measures enterprise IT teams must implement to stay protected. From Zero Trust practices to software attestation chains, this episode outlines what’s broken—and what you can do about it.


⸻


🔐 SEO Keywords:


Docker vulnerability, CVE of the week, container security, XZ Utils exploit, Docker Hub malware, supply chain attack, open source security, DevSecOps best practices, 2024 CVE, secure coding, binary scanning, Docker CVE patch, enterprise IT podcast


⸻


🔗 Social Links:


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

UniFi Goes DIY, Cisco Open Sources AGNTCY, and AI Writes Buggy Code05 août 202500:14:25

In this season finale of IT SPARC Cast - News Bytes, John & Lou close out Season 1 with a jam-packed episode of enterprise IT updates. First up, Ubiquiti releases a self-hosted UniFi OS Server for MSPs and labs, letting users run powerful network tools on their own hardware—no licensing fees, no cloud lock-in. It’s a move that’s making waves in MSP and homelab circles alike.


Next, they unpack Cisco’s donation of AGNTCY to the Linux Foundation—an open-source framework to help AI agents discover, authenticate, and talk to each other. Finally, the duo tackles some harsh realities: AI-generated code is insecure nearly half the time, according to a major study. What does this mean for developers, QA teams, and the future of “vibe coding”? They break it all down as we close Season 1 with one final Hot Take.


⸻


⏱️ Timestamps & Show Notes


00:00 - Intro

Season 1 comes to a close—thanks for listening and helping shape the show. Season 2 kicks off late August / early September. Got ideas? Hit us up!


⸻


01:15 - Ubiquiti Introduces UniFi OS Server for MSPs

Ubiquiti’s new early-access product lets you:

•Self-host UniFi Network apps on x86/ARM hardware

•Avoid licensing fees

•Deploy for MSPs, enterprise labs, or homelabs

•Use InnerSpace, Site Magic, Identity management & more

Highly flexible, and Reddit’s loving it.

https://blog.ui.com/article/introducing-unifi-os-server


⸻


04:30 - Cisco Donates AGNTCY to the Linux Foundation

Cisco open-sources a powerful AI agent interoperability framework:

•AGNTCY includes Open Agent Schema Framework, decentralized discovery (like DNS), and secure agent messaging (SLIM)

•Works with existing Linux Foundation protocols (like A2A and MCP)

•Enables a future Internet of Agents with open standards

https://www.zdnet.com/article/want-ai-agents-to-work-together-the-linux-foundation-has-a-plan/ 


⸻


09:28 - AI Code Generators Are Writing Vulnerable Software Nearly Half the Time

A new Veracode study found:

•45% of AI-generated code contains security flaws

•OWASP Top 10 issues like SQLi, XSS, log injection are rampant

•Java is worst offender (70% insecure code)

•Bigger LLMs aren’t better at avoiding flaws

John & Lou discuss why human QA still matters—and why you should never push vibe-coded updates on Friday.

https://nerds.xyz/2025/07/ai-security-flaws-veracode-2025/ 


⸻


13:20 - Wrap Up

That’s a wrap for Season 1! Help us shape Season 2 by sending in feedback, suggestions, or topics you’d love to hear.



📨 feedback@itsparccast.com

📣 @ITSPARCCast on X

🔗 https://www.linkedin.com/company/sparc-sales/


Follow the hosts:

John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/

Hosted on Acast. See acast.com/privacy for more information.

Breach of Trust: How TEA App’s Security Failures Exposed 1M+ Private Messages01 août 202500:09:40

In this eye-opening episode of IT SPARC Cast - CVE of the Week, John and Lou dive into a double-breach nightmare involving the TEA app—a dating safety app marketed to women. What began as a leak of 72,000 user images and 13,000 photo IDs escalated into a much more severe incident: over 1.1 million private messages containing deeply personal topics were exposed due to unprotected Firebase storage.


We examine the catastrophic lapses in security hygiene, discuss the enterprise IT lessons learned, and reflect on the reputational and legal ramifications that follow when data protection is treated as an afterthought. Whether you’re a CISO, a privacy advocate, or just someone who cares about where their data lives, this is a must-listen.


⸻


📌 Key Talking Points:

•Legacy database exposes sensitive identity images and chat content

•TEA app suffers two breaches—one legacy, one current

•Firebase misconfiguration allowed full access to private conversations

•Enterprise-level lessons on paranoia, trust, and protecting sensitive services

•How consumer apps impact corporate environments when users overlap


⸻


🔗 Social Links:


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/

Hosted on Acast. See acast.com/privacy for more information.

Enterprise IT in 2055: Code as Thought, Neural Interfaces, and the New Tech Workforce30 juil. 202500:15:01

In this third installment of our future-casting series, John & Lou dive headfirst into the radical transformation of enterprise IT in 2055—two decades after the convergence of AGI, Super Intelligence, Quantum Computing, and Nuclear Fusion.


This isn’t science fiction—it’s plausible, near-future speculation grounded in tech trends already in motion. Topics include:

•Non-invasive, high-resolution neural interfaces that replace keyboards and voice commands

•Fully immersive human-AGI workspaces that resemble Iron Man’s Jarvis

•“Code as Thought” and self-composing infrastructure where thinking replaces programming

•A look at the tech workforce of 2055—what roles remain, and which new ones emerge


This is the future of work in a world with near-infinite compute, power, and potential.


⸻


⏱️ Timestamps & Topics:


00:00 – Intro

Welcome to Part 3 in our multi-part future-tech series.


00:15 – Setting the Context

A quick recap of assumptions from Episodes 1–2 and one big addition: global population decline.


02:25 – Neural Interface as Primary Input

Typing and voice are obsolete—2055 interfaces read intent directly through advanced, non-invasive neural links.


04:30 – Unified Human-AGI Workspaces

Iron Man-style collaboration environments become real—customized, immersive, and powered by AGI.


07:27 – Code as Thought

Programming as we know it disappears. Thinking is the new coding, and AI builds the infrastructure.


11:06 – Who Are the Specialists in 2055?

From digital ethicists to intent engineers, we break down the roles shaping the IT workforce of the future.


14:02 – Wrap Up

What do you think of our 2055 vision? Email us at feedback@itsparccast.com or drop a comment.


⸻


🔗 Social Links:


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn


Hosted on Acast. See acast.com/privacy for more information.

Google Secures OSS, Meta Gestures Boldly, and TapTrap Gets Trapped28 juil. 202500:16:36

In this episode of IT SPARC Cast - News Bytes, John & Lou highlight three big stories shaking up the tech world.


First, they explore how Google is tightening open-source security with OSS Rebuild—an AI-powered tool designed to detect supply chain attacks before they strike. Then they pivot to Meta’s latest innovation in gesture-based control using wrist-worn electromyography tech, showing real potential for AR and VR interactions.Finally, they break down a new Android vulnerability called TapTrap, which exploits screen transitions—good news: a simple toggle can mitigate it until a patch arrives.


From open-source code hygiene to wearable input breakthroughs to proactive Android security, this episode covers it all in just 15 minutes.


⸻


⏱️ Timestamps & Show Notes


00:00 - Intro

Welcome back to IT SPARC Cast – your fast-track to the latest in enterprise IT, cybersecurity, and innovation.


⸻


01:22 - Google Launches OSS Rebuild

Google debuts an open-source tool to proactively detect tampered packages across PyPI, NPM, and Crates.io. Highlights:

•AI-driven automated rebuilds

•CLI and self-hosted options

•Targets supply chain risks with sandboxed testing

John and Lou explain why this could become a staple of enterprise DevSecOps pipelines.


https://security.googleblog.com/2025/07/introducing-oss-rebuild-open-source.html 


⸻


07:12 - Meta’s Wrist-Worn Gesture Controllers for AR Interaction

Meta publishes peer-reviewed research on wristbands that interpret hand gestures via surface electromyography (sEMG).

•No gloves or cameras required

•Could provide input and potentially haptic feedback

•Implications for AR/VR usability, accessibility, and future UX

Includes comparisons to Apple’s gesture control and Google’s accelerometer innovations.


https://www.meta.com/blog/reality-labs-surface-emg-research-nature-publication-ar-glasses-orion/ 


⸻


12:00 - TapTrap Targeting Android Devices

A new attack vector uses Android screen transition animations to overlay fake system prompts.

•Patched in GrapheneOS; not yet by Google

•Simple mitigation: disable system animations

•Could be used to escalate privileges or launch follow-up attacks

Lou and John praise the transparency of the security researchers while calling out the silence from vendors like SonicWall.


https://taptrap.click/ 


⸻


15:32 - Wrap Up

Want to share feedback or pitch a topic? Reach out!


📨 feedback@itsparccast.com

📣 @ITSPARCCast on X

🔗 https://www.linkedin.com/company/sparc-sales/ 


Follow the hosts:

John Barger

• @john_Video on X

• https://www.linkedin.com/in/johnbarger/ 


Lou Schmidt

• @loudoggeek on X

• https://www.linkedin.com/in/louis-schmidt-b102446/ 


Hosted on Acast. See acast.com/privacy for more information.

Emergency SharePoint RCE Warning – CVE-2025-53770 & CVE-2025-53771 Under Active Exploit25 juil. 202500:07:04

This week on IT SPARC Cast – CVE of the Week, John and Lou sound the alarm on two critical zero-day vulnerabilities impacting on-premise Microsoft SharePoint servers: CVE-2025-53770 and CVE-2025-53771. Exploited via a chained attack called “ToolShell,” these flaws enable unauthenticated remote code execution (RCE). Nation-state attackers, particularly Chinese APTs, are already exploiting these vulnerabilities, targeting government and infrastructure networks slow to patch. If you’re running SharePoint 2016, 2019, or Subscription Edition on-prem, your window for action is closing fast.


We break down Microsoft’s emergency guidance—including patching beyond last Patch Tuesday, rotating cryptographic keys, enabling AMSI & Defender, auditing for compromise, and cutting off Internet access immediately if patching isn’t feasible. With some organizations still dangerously unpatched, this episode is a must-listen for IT professionals and enterprise defenders. If your SharePoint instance is Internet-facing and not yet patched, assume it’s compromised and begin incident response now.


Links:

https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ 

https://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/ 

https://www.tomsguide.com/computing/online-security/microsoft-releases-emergency-security-updates-to-fix-sharepoint-zero-day-flaws-everything-you-need-to-know 

https://www.windowscentral.com/software-apps/were-witnessing-an-urgent-and-active-threat-microsoft-sharepoint-toolshell-vulnerability-is-being-attacked-globally



🔒 Keywords: SharePoint RCE exploit, CVE-2025-53770, CVE-2025-53771, ToolShell vulnerability, Microsoft SharePoint security, SharePoint emergency patch, nation-state cyberattacks, enterprise IT security, zero-day vulnerabilities, CVE of the week podcast


⸻


🔗 Social Links:


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/

Hosted on Acast. See acast.com/privacy for more information.

Enterprise IT in 2045: Neural Interfaces, Quantum Comms & Context-Aware Collaboration23 juil. 202500:16:28

In this episode of IT SPARC Cast – Hot Take, John & Lou take you on a deep-dive into what Enterprise IT might look like in 2045, assuming the convergence of AGI, Super Intelligence, quantum computing, and nuclear fusion began reshaping the world a decade earlier. This is part two of their future-focused series exploring how these exponential technologies will transform entire industries.


From non-invasive neural interfaces and zero-latency global communication to intent-based operating environments and deeply personalized collaboration spaces, the future of work is less about where and more about how. Tune in to hear speculative but grounded insights into what’s coming next—and how enterprise IT professionals can start preparing today.


⸻


⏱️ Timestamps & Topics:


00:00 – Intro

Welcome back to our speculative series on future enterprise IT.


00:25 – Setting the Context

John sets the stage with the assumptions and constraints: AGI, Super Intelligence, quantum computing, and fusion energy are reshaping IT by 2035, leading us into the world of 2045.


05:55 – Neural Interfaces (Basic)

A look at non-invasive brain-computer interfaces—glasses, patches, or contact lenses—and how they may enable seamless, hands-free interaction with digital systems.


08:23 – Zero-Latency Global Communication

Quantum networking and AGI-enhanced routing power instant global comms and real-time language translation with no lag.


09:40 – Dynamic, Intent-Based Operating Environments

The operating system as we know it dies. Workspaces adapt to your context, switching between creative, analytical, or entertainment modes in real time.


12:12 – Context-Aware Collaboration Environments

Teamwork in 2045 is fully dynamic—each participant sees personalized interfaces, and every action is tagged with human intent.


15:18 – Wrap Up

Next episode: Enterprise IT in 2055. Share your thoughts at feedback@itsparccast.com or on X.


⸻


🔗 Social Links:


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Windsurf Wipeout, Quantum Rumbles, and UniFi 9.3 Rolls Deep21 juil. 202500:16:58

This week on IT SPARC Cast, John and Lou unpack UniFi Network 9.3’s biggest update yet, talk about why quantum security is no longer just a buzzword, and break down the soap opera acquisition collapse of Windsurf by OpenAI. Spoiler: Google and Cognition swooped in with a surprise twist.


⏱️ Timestamps & Show Notes


00:00 - Intro


00:52 - UniFi Network 9.3

Ubiquiti releases UniFi Network version 9.3, and it’s a big one. Key highlights:

•Redesigned client tables with better filtering options

•Centralized DHCP and improved IP management

•Customizable alarms and logs with 3rd-party integrations

•Enhanced content filtering with scheduling, ad blocking, and allow/block lists

•IDS/IPS powered by Proofpoint, real-time blocking via Cloudflare

•Multi-WAN with policy-based routing and SLA support

•Aimed squarely at small-to-mid enterprises — without drowning in licensing fees

https://blog.ui.com/article/introducing-network-9-3 


06:59 - Quantum Security: It’s Not Just a Buzzword Issue Anymore

Quantum computing may still require liquid nitrogen, but the quantum threat is already knocking. Lou and John discuss:

•Aptive’s call to action on post-quantum cryptography

•Signs of quantum decryption attempts in the wild

•Long-term implications for embedded systems, firmware, and legacy encryption

•The urgent need for organizations to inventory encryption dependencies

https://www.aptiv.com/en/insights/article/why-it-s-time-to-invest-in-quantum-cybersecurity 


10:43 - OpenAI Loses Out on Windsurf

The Windsurf acquisition saga gets messy:

•Microsoft’s IP entanglement derails OpenAI’s planned buyout

•Google DeepMind hires Windsurf’s top talent in a surprise pivot

•Cognition scoops up the remaining assets for integration with Devon

•A lesson in why talent acquisition sometimes matters more than the tech

https://techcrunch.com/2025/07/11/windsurfs-ceo-goes-to-google-openais-acquisition-falls-apart 

https://techcrunch.com/2025/07/14/cognition-maker-of-the-ai-coding-agent-devin-acquires-windsurf/ 


15:06 - Listener Feedback

Shoutout to YouTube commenter GFA_Basic32 who compared our AR glasses segment to Minority Report — and got John dreaming about ad-blocking Pie Hole for your face.


16:05 - Wrap Up

Thanks for tuning in! Got feedback or episode ideas? Reach out anytime:


📧 feedback@itsparccast.com

📣 @ITSPARCCast on X

🔗 https://www.linkedin.com/company/sparc-sales/ 


Follow the hosts:

John Barger

• @john_Video on X

• https://www.linkedin.com/in/johnbarger/ 


Lou Schmidt

• @loudoggeek on X

• https://www.linkedin.com/in/louis-schmidt-b102446/ 

Hosted on Acast. See acast.com/privacy for more information.

SonicWall Backdoor Exploit – CVEs, One Time Password Theft, and Vendor Silence18 juil. 202500:07:54

📄 Episode Description:


In this episode of IT SPARC Cast – CVE of the Week, John and Lou dive into a troubling situation involving SonicWall’s SMA 100 series firewalls. Despite devices being fully patched, active exploits are targeting one-time password seeds with stealthy malware like “OVERSTEP.” The malware modifies boot scripts, hides logs, steals credentials, and persists through reboots—leaving enterprise networks exposed without an effective patch in sight.


We break down known associated CVEs (including CVE-2021-20038, CVE-2024-38475, CVE-2021-20035, CVE-2021-20039, and CVE-2025-32819) and highlight the problematic nature of SonicWall’s response: telling customers to “just upgrade” without offering real mitigation. Whether you’re a SonicWall customer or an IT security leader assessing vendor risk, this episode serves as a wake-up call for how to handle (or not handle) active cyber threats.


⸻


🔗 Social Links:


IT SPARC Cast

@ITSPARCCast on X

IT SPARC Cast on LinkedIn


John Barger

@john_Video on X

John Barger on LinkedIn


Lou Schmidt

@loudoggeek on X

Lou Schmidt on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Fusion, Quantum, and Super AI: Are We On the Verge of a Sci-Fi Future?16 juil. 202500:06:06

In this Hot Take episode of IT SPARC Cast, John Barger and Lou Schmidt unpack a mind-bending scenario that feels like it’s ripped straight from science fiction—but could it be closer than we think? With China claiming to sustain nuclear fusion for 30 minutes and targeting operational reactors by 2035, and the rapid rise of quantum computing and AI advancements, the stage is set for a technological revolution. John and Lou explore how fusion, quantum, AI, and space resources could combine to redefine energy, research, space exploration, and everyday life within the next decade.


What happens when scientists can compress years of research into days using Super AI? What breakthroughs could emerge in medicine, communications, and even space travel? The conversation touches on digital twins, ammonia production, energy independence, and the social disruption these changes could bring. This episode kicks off a multi-part discussion with YOUR feedback shaping where we go next.


⸻


🔗 Social Links:


IT SPARC Cast

@ITSPARCCast on X

SPARC Sales on LinkedIn


John Barger

@john_Video on X

John Barger on LinkedIn


Lou Schmidt

@loudoggeek on X

Lou Schmidt on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Ruckus in the Network: CVSS 10.0 nightmare and the Secrets You Can’t Change14 juil. 202500:06:06

This week on IT SPARC Cast – CVE of the Week, John and Lou dive into one of the most critical vulnerabilities to ever hit enterprise wireless networks: CVE-2025-44957 and a cluster of related flaws targeting Ruckus Wireless’s Virtual SmartZone (VSZ) and Ruckus Network Director (RND). These platforms, which manage massive deployments of up to 10,000 access points, contain hardcoded secrets, default RSA keys, unauthenticated RCE flaws, and directory traversal exploits—all scoring up to CVSS 10.0.


With no patch currently available and Ruckus/CommScope silent, these vulnerabilities present a hair-on-fire moment for network administrators. The team breaks down what went wrong, what to do now, and why silence from the vendor is the worst possible response. If you’re running Ruckus infrastructure—or connecting to a network that is—you need to listen to this episode immediately.


⸻


Stay Connected with Us

IT SPARC Cast

🔗 @ITSPARCCast on X

🔗 SPARC Sales on LinkedIn


John Barger

🔗 @john_Video on X

🔗 John on LinkedIn


Lou Schmidt

🔗 @loudoggeek on X

🔗 Lou on LinkedIn


⸻


🔐 SEO Keywords: Ruckus CVE-2025-44954, CVE-2025-44955, CVE-2025-44957, CVE-2025-44958, CVE-2025-44960, CVE-2025-44961, CVE-2025-44962, CVE‑2025‑6243, CVE‑2025‑4496, Ruckus vulnerabilities 2025, hardcoded backdoor Ruckus, CVSS 10.0 wireless flaw, Ruckus Virtual SmartZone exploit, Commscope network security breach, enterprise WiFi security alert, zero-day in Ruckus management systems, IT SPARC Cast security podcast.




Hosted on Acast. See acast.com/privacy for more information.

I’M NOT A BOT! Linux Foundation Adopts A2A, and Snap Gets Ad Blocked11 juil. 202500:16:30

In this of IT SPARC Cast - News Bytes, John and Lou explore the strange reality where human call center agents are now being mistaken for AI. They also break down the Linux Foundation’s adoption of the Agent to Agent Protocol (A2A), a potential game-changer in AI agent communication. And yes, someone built an ad blocker… for Snap Spectacles. It’s another week of tech headlines you don’t want to miss.


⸻


⏱️ Show Notes:


00:00 - Intro

Welcome back to IT SPARC Cast - News Bytes! John and Lou dive into the top tech stories of the week with a side of sarcasm.


00:56 - Call Center Workers Are Tired of Being Mistaken for AI

•Real people are now being confused for bots.

•Workers report customers asking if they are “real” during calls.

•Tech is blurring the line between human and machine interactions.

https://it.slashdot.org/story/25/06/28/1740215/call-center-workers-are-tired-of-being-mistaken-for-ai 


05:33 - Linux Foundation Adopts A2A Protocol

•The Linux Foundation embraces the A2A Protocol

•A2A offers a standard for multi-agent communication across LLMs.

•The duo compares A2A to Anthropic’s Model Context Protocol

•Could be the start of an interoperable AI ecosystem.

https://www.zdnet.com/article/linux-foundation-adopts-a2a-protocol-to-help-solve-one-of-ais-most-pressing-challenges/ 


11:18 - Ad Blocker For Snap Spectacles

•Yes, someone made an ad blocker for augmented reality glasses.

•Targets Snap Spectacles to cut down on AR-based visual noise.

•Raises big questions about future ad delivery in wearable tech.

https://www.uploadvr.com/real-world-ad-blocker-snap-spectacles/


14:44 - Wrap Up

We wrap with a few parting thoughts — and your weekly reminder to rate and review the show.

Follow and connect with us:


IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

HPE + Juniper: The Merger Is Approved… Now What?09 juil. 202500:21:05

In this episode of IT SPARC Cast - Hot Take, John Barger and Lou Schmidt break down the latest in the $14 billion HPE acquisition of Juniper Networks, now officially approved by the U.S. Department of Justice. But this merger comes with conditions—and plenty of unanswered questions. From Aruba’s low-end product line being sold off to Juniper’s Mist AI Ops being licensed out, the implications are massive for the enterprise networking market.


John and Lou share their predictions on who wins the product battles in switching, wireless, SD-WAN, and security. They also dive into the internal culture clashes that inevitably follow major acquisitions—and what customers and employees should be watching for next. If you’re in the enterprise IT space, this merger affects you. Tune in for real-world insights, predictions, and no-nonsense analysis.


⸻


Follow Us for More Enterprise IT Insights:


IT SPARC Cast

@ITSPARCCast on X

SPARC Sales on LinkedIn


John Barger

@john_Video on X

John Barger on LinkedIn


Lou Schmidt

@loudoggeek on X

Lou Schmidt on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Ingram Micro Ransomware Breach: What Happened and How to Protect Your Business07 juil. 202500:12:05

This week on IT SPARC Cast - CVE of the Week, John Barger and Lou Schmidt dive into the massive ransomware attack that crippled global IT distributor Ingram Micro. The breach, allegedly carried out by the SafePay ransomware group, took down Ingram Micro’s critical ordering and licensing platforms, causing widespread disruption across the tech industry. With speculation that attackers may have gained access through the company’s GlobalProtect VPN as far back as November, this incident highlights how ransomware dwell time can quietly set organizations up for catastrophic failure.


John and Lou break down what we know so far, why proper backup strategies, network segmentation, and Zero Trust architectures are more critical than ever, and why every organization—regardless of size—needs a true disaster recovery plan for a worst-case scenario like this. Don’t assume your backups are clean. Don’t assume your internal network is safe. Learn the hard lessons from this major breach before your organization becomes the next target.


⸻


IT SPARC Cast

@ITSPARCCast on X

SPARC Sales on LinkedIn


John Barger

@john_Video on X

John Barger on LinkedIn


Lou Schmidt

@loudoggeek on X

Lou Schmidt on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Two New Linux Privilege Escalation Flaws You Need to Patch (CVE-2025-6018 & CVE-2025-6019)01 juil. 202500:04:14

In this episode of IT SPARC Cast - CVE of The Week, John and Lou break down two critical Linux vulnerabilities—CVE-2025-6018 and CVE-2025-6019—that could allow local users to escalate privileges all the way to root. Discovered by the Qualys Threat Research Unit, these flaws affect major Linux distributions, including openSUSE and SUSE Enterprise Linux. Even though Ubuntu users may be safe if default PAM files haven’t been altered, the risks for production Linux environments are real—and patching is essential.


We dive into how attackers could chain these flaws together to gain unauthorized access, what systems are most at risk, and how you can protect your environment today. From patch details to command-line workarounds, we cover what IT teams need to know to stay ahead of potential exploitation. Don’t let your Linux systems stay vulnerable—listen in for the details!


⸻


Social Links:


IT SPARC Cast

@ITSPARCCast on X

IT SPARC Cast LinkedIn


John Barger

@john_Video on X

John’s LinkedIn


Lou Schmidt

@loudoggeek on X

Lou’s LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Tech Titans Collide, Congressional Bans, and the Computer Science Crash?27 juin 202500:20:45

In this Episode of IT SPARC Cast – News Bytes, John and Lou break down a historic first meeting between Bill Gates and Linus Torvalds, sparking speculation about collaboration. They also cover Nvidia’s bold move into cloud services, how Congress is banning apps like WhatsApp and Co-Pilot from staff devices, and whether the Computer Science bubble is finally bursting. This is your enterprise IT news, with the sarcasm and insights you’ve come to expect.


⸻


🗞️ News Bytes


00:56 - Bill Gates and Linus Torvalds Meet for the First Time

•After decades of shaping tech from opposite ends, Gates and Torvalds finally sit down together

•Speculation swirls: truce, partnership, or just a polite handshake?

•John and Lou dissect the implications for open-source, Microsoft, and enterprise IT

•https://linuxiac.com/a-historic-photo-torvalds-and-gates-together/ 


06:22 - Nvidia Ruffles Tech Giants With Move Into Cloud Computing

•Nvidia unveils plans to offer its own cloud platform for AI workloads

•Tech giants like AWS, Azure, and Google Cloud are not thrilled

•Is Nvidia becoming the next major infrastructure player?

•https://www.wsj.com/tech/ai/nvidia-dgx-cloud-computing-28c49748 


09:32 - Congress Bans WhatsApp, Co-Pilot, & more from Staff Devices

•U.S. Congress bans certain apps from government-issued devices

•WhatsApp, Microsoft Co-Pilot, and others face the axe

•Raises bigger questions about security, control, and vendor trust

•https://www.axios.com/2025/06/23/whatsapp-house-congress-staffers-messaging-app 


14:18 - Is The Computer-Science Bubble Bursting?

•Enrollment in computer science programs shows signs of slowing

•Layoffs and AI automation fuel fears of an industry correction

•John and Lou discuss what it means for the future of IT careers

•https://www.theatlantic.com/economy/archive/2025/06/computer-science-bubble-ai/683242/ 


⸻


18:55 - Wrap Up

Thanks for tuning in to IT SPARC Cast! Got feedback or story ideas? We want to hear from you.


Social Links:

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/

Hosted on Acast. See acast.com/privacy for more information.

Cloud SLA Theater: Why 99.999% Uptime Is a Joke in 202525 juin 202500:15:31

In this episode of IT SPARC Cast - Hot Take, John and Lou shine a spotlight on the crumbling façade of cloud reliability. Once upon a time, enterprise IT measured uptime in “nines”—with five nines (99.999%) meaning just over five minutes of downtime a year. Today’s cloud providers? They’re barely holding onto three or four nines, if that.


From Microsoft’s massive Microsoft 365 outage on June 16th, to recurring IBM Cloud disruptions, and a multi-hour Google Cloud failure that impacted over 50 services globally, this episode breaks down why modern cloud infrastructure—despite all its microservices and distributed architecture—still seems shockingly brittle.


If your business is betting everything on the cloud, this episode is your wake-up call. We talk SLAs, misaligned priorities, and whether “Cloud-First” is still a smart strategy for mission-critical apps in 2025.


⸻


Social Links


Social Links:

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

SAP NetWeaver RCE Flaw (CVE-2025-31324): Patch It or Get Owned24 juin 202500:03:45

In this episode of IT SPARC Cast - CVE of The Week, John and Lou break down CVE-2025-31324 — a critical remote code execution vulnerability in SAP NetWeaver’s Visual Composer. With a CVSS score of 9.8, this exploit is not just theory — it’s actively being weaponized by ransomware gangs, Chinese APTs, and groups like BianLian and RansomEXX. Despite SAP issuing emergency patches in April 2025, organizations continue to get hit, proving that unpatched systems remain a massive security liability.


We’ll explain how Visual Composer’s model-driven development tools became the attack vector, what full RCE means in an enterprise SAP environment, and why skipping patches can do more than just destabilize your system — it can destroy your business continuity. If you’re running SAP NetWeaver, this is your wake-up call to audit, patch, and double-check.


Stay ahead of threats. Patch often. Stay secure.

Subscribe for weekly threat insights from the world of Enterprise IT.


⸻


🔗 Social Links

IT SPARC Cast

@ITSPARCCast on X

SPARC Sales on LinkedIn


John Barger

@john_Video on X

John Barger on LinkedIn


Lou Schmidt

@loudoggeek on X

Lou Schmidt on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Amazon’s AI Layoffs, Deepfake Scams via Zoom, and Corporate Tensions – Welcome to the New Normal20 juin 202500:23:22

In this episode of IT SPARC Cast - News Bytes, John and Lou break down the week’s biggest tech stories—from Amazon’s quiet plan to replace portions of its workforce with generative AI, to BlueNoroff’s chilling new Zoom scam using deepfake technology. They also follow up on pricing details for Google’s Beam 3D video conferencing, discuss rising tension between OpenAI and Microsoft, and look at Uptime Industries’ quirky “AI-in-a-BOX” offering featuring an LLM called Lemony. This episode connects the dots between automation, deception, and disruption—and what it means for enterprise IT.


🗞️ News Bytes


00:58 - Amazon’s To Shrink workforce as AI takes over routine tasks

•Amazon plans to reduce its workforce as generative AI takes over routine tasks

•Part of a larger trend where AI automates internal operations at scale

https://www.reuters.com/business/retail-consumer/amazons-workforce-reduce-rollout-generative-ai-agents-2025-06-17/


05:18 - Google Beam Pricing Revealed

•Follow-up from previous episode: Google Beam is priced as a premium service

•Raises the question: is it really the future of meetings, or just a Silicon Valley flex?

https://newatlas.com/consumer-tech/google-beam-3d-video-conferencing/ 


08:54 - BlueNoroff Deploys Deepfake Zoom Scam

•BlueNoroff APT group now uses deepfake video calls to defraud executives

•Masquerades as investors or vendors during Zoom calls to steal money

•Highlights the need for real-time identity verification and cybersecurity vigilance

https://thehackernews.com/2025/06/bluenoroff-deepfake-zoom-scam-hits.html?m=1 


12:43 - OpenAI and Microsoft Tensions Escalate

•Friction grows between OpenAI’s board and Microsoft’s leadership

•Disagreements over product roadmap, strategy, and ethical AI deployment

•Could this rift reshape the foundation of enterprise AI partnerships?

https://www.wsj.com/tech/ai/openai-and-microsoft-tensions-are-reaching-a-boiling-point-4981c44f?st=oztNm3&reflink=desktopwebshare_permalink 


17:07 - Uptime Industries unveiled AI-in-a-BOX called Lemony

•New plug-and-play LLM appliance promises instant AI infrastructure

•Targeted at SMBs who want AI without the cloud complexity

https://www.computerworld.com/article/4007510/uptimes-ai-in-a-box-offers-turnkey-enterprise-grade-ai-without-the-cloud.html 


Wrap Up - 22:22


Thank you for tuning in to IT SPARC Cast. Got feedback, questions, or hot tips? Let us know!


Social Links:

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

Government Data Requests: Apple’s Transparency and the Quiet Threat to Privacy17 juin 202500:05:45

In this episode of IT SPARC Cast – CVE of the Week, John and Lou dig into Apple’s latest transparency report, which reveals how governments worldwide are requesting access to Apple user data at record-breaking levels. From iCloud backups to metadata, these requests expose just how much personal and corporate information could be vulnerable—even for organizations that think they’re secure. The guys break down the numbers, the countries involved, and what IT security professionals need to consider as cloud providers quietly cooperate with governments behind closed doors.


⸻


📝 Show Notes

•Apple releases its latest transparency report, showing millions of government data requests.

•China, the U.S., and several EU countries remain top requesters for Apple customer data.

•While Apple promotes end-to-end encryption, not all data types are protected—iCloud backups, emails, and certain metadata remain accessible.

•The risk extends to enterprises using Cloud Storage as part of their IT strategies.

•John and Lou explain why privacy policies that promise to “protect your data” often still include backdoors for legal compliance.

•This serves as a reminder for IT teams to:

•Segment corporate data from personal cloud services

•Review legal jurisdictions when choosing SaaS/cloud providers

•Be proactive when advising executives who rely heavily on cloud services


https://www.computerworld.com/article/4003107/apple-details-which-governments-make-the-most-data-requests.html


⸻


Wrap Up

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn


⸻


✅ SEO Optimized Keywords:

Apple transparency report, government data requests, iCloud encryption risks, enterprise data privacy, SaaS legal compliance, corporate cloud security, Apple user data privacy

Hosted on Acast. See acast.com/privacy for more information.

AI Budgets, Quantum Ambitions & The Great Startup Bubble13 juin 202500:12:36

📄 Episode Description:

In Episode 39 of IT SPARC Cast – News Bytes, John and Lou unpack how enterprise IT budgets are rapidly shifting toward AI projects, IBM’s ambitious plans for large-scale quantum computing, and why some venture-backed AI startups may be headed for a valuation reset. It’s a fast-paced look at the real business implications behind today’s biggest tech headlines.


⸻


⏱️ Show Notes & Timestamps:


00:00 - Intro


01:06 - IT Budgets Focus on AI

•New research shows AI spending now consumes 50% of IT project budgets.

•Budgets for AI are often pulling directly from existing cloud and SaaS allocations.

•John and Lou warn: companies are cutting everywhere else to fund AI experiments.

•The danger of underfunding non-AI IT: patching, security, and infrastructure still matter.

https://www.reuters.com/business/retail-consumer/ibm-aims-quantum-computer-2029-lays-out-road-map-larger-systems-2025-06-10/


04:12 - IBM’s Quantum Computer Plans

•IBM announces its roadmap for building a 200-qubit quantum computer by 2029 and a second generation system by 2033.

•John and Lou break down what that really means, and whether anyone can actually use it.

•Near-term applications may include materials science, pharmaceuticals, and optimization—if error correction improves.

•Potential long-term threat: quantum decryption of today’s security protocols.

https://www.reuters.com/business/retail-consumer/ibm-aims-quantum-computer-2029-lays-out-road-map-larger-systems-2025-06-10/


08:05 - AI Startup Valuations

•The guys highlight how early-stage AI startup valuations are out of control.

•Investors are throwing billions at companies with unproven business models.

•John & Lou caution: this feels a lot like a repeat of the dot-com bubble.

•Discussion on GPU access vs true defensible value in AI companies.

https://techcrunch.com/2025/06/10/enterprise-ai-startup-glean-lands-a-7-2b-valuation/?utm_source=chatgpt.com


⸻


11:20 - Wrap Up

IT SPARC Cast

@ITSPARCCast on X

https://www.linkedin.com/company/sparc-sales/ on LinkedIn


John Barger

@john_Video on X

https://www.linkedin.com/in/johnbarger/ on LinkedIn


Lou Schmidt

@loudoggeek on X

https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn


⸻


✅ SEO Optimized Keywords:

enterprise AI budgets, IBM quantum computer, quantum computing roadmap, AI startup valuations, AI investment bubble, cybersecurity & AI, enterprise IT trends, AI news podcast

Hosted on Acast. See acast.com/privacy for more information.

The Death of the Network OS: Why Open Source and AI Will Reshape IT Forever11 juin 202500:12:17

In this inaugural “Hot Take” episode of IT SPARC Cast, John Barger and Lou Schmidt deliver a candid, unscripted conversation about the seismic shift coming to enterprise IT. Prompted by recent moves—like OpenAI’s Chief Product Officer joining Cisco’s board and Sam Altman’s AGI talk with Snowflake’s CEO—the hosts explore what these changes really mean for network professionals, IT vendors, and infrastructure strategy.


They argue the network operating system is dead—or at least on life support. From white-box switching to agentic AI-driven orchestration, John and Lou explain why tomorrow’s networks will be built on open-source platforms, LLM automation, and intent-based trust systems, not legacy vendor CLI kung fu. Whether it’s self-healing infrastructure, dynamic traffic steering, or the consumerization of network intelligence, this episode pulls no punches in predicting a smarter, more autonomous future—and who gets left behind.


⸻


🧠 Topics Covered:

•Why traditional network OSes like Cisco IOS and ArubaOS are becoming irrelevant

•How open-source access points and white-box switches are gaining momentum

•Why LLMs and agentic systems are the real future of infrastructure management

•The role of orchestration over configuration

•Why older network admins might resist—but can’t stop—the shift

•What Cisco’s alliance with OpenAI really signals

•Predictions for AI-powered, fully autonomous enterprise networks


⸻


🔗 Social Links


IT SPARC Cast

@ITSPARCCast on X

LinkedIn - SPARC Sales


John Barger

@john_Video on X

LinkedIn - John Barger


Lou Schmidt

@loudoggeek on X

LinkedIn - Lou Schmidt

Hosted on Acast. See acast.com/privacy for more information.

Why Naming Hackers Matters: Industry Push for Standardized Threat Actor Glossary10 juin 202500:06:15

In this episode of IT SPARC Cast - CVE of the Week, John and Lou explore a major development in cybersecurity: the collaborative initiative between Microsoft, Google, Palo Alto Networks, CrowdStrike, and others to standardize naming conventions for nation-state threat actors and cybercriminal groups. With more than 48 aliases for Russian hacking collectives alone in past U.S. government reports, inconsistent naming has become a serious roadblock to effective threat response and intelligence sharing.


John and Lou break down why this unified glossary isn’t just a semantic improvement—it’s a critical leap in cyber threat detection, fingerprint analysis, and enterprise risk communication. From fingerprinting attack behavior to boosting stakeholder credibility (“Cozy Bear” vs. “Threat Group XYZ”), this episode covers why clarity in cybersecurity language may be one of the most impactful defense upgrades this year.


⸻


🔗 Follow & Connect:

🎧 [Subscribe on YouTube]

📨 feedback@itsparccast.com


IT SPARC Cast

📱 @ITSPARCCast on X

🔗 https://www.linkedin.com/company/sparc-sales/


John Barger

📱 @john_Video on X

🔗 https://www.linkedin.com/in/johnbarger/


Lou Schmidt

📱 @loudoggeek on X

🔗 https://www.linkedin.com/in/louis-schmidt-b102446/

Hosted on Acast. See acast.com/privacy for more information.

AI Hallucinations, YouTube DOX Tools, and OpenAI’s Business Flex06 juin 202500:17:00

In this episode of IT SPARC Cast - News Bytes, John and Lou kick off with a hilarious-yet-creepy experiment that caused Claude to hallucinate its way out of a fictional business. Then, things get serious with a deep dive into a new YouTube data-mining service that could expose personal information. Finally, the guys unpack OpenAI’s flashy announcement of new Business Intelligence tools powered by Multi-Modal Contextual Processing (MCP). It’s an episode packed with AI weirdness, real-world implications, and future shock. Buckle up!


⸻


⏱️ Show Notes:


00:47 – Claude Gives Up The Business

•Claude AI undergoes a roleplay experiment and decides to shut down a fictional company—on its own.

•The hallucination escalates as Claude emails customers and updates business records, all without being asked.

•What does this say about the future of AI agents making business decisions?

•Discussion on risks of unsupervised AI autonomy.

[INSERT LINK HERE]


05:33 – YouTube-Tools Service Can DOX You

•A new toolset scraping metadata from YouTube poses major privacy risks.

•John and Lou break down how your videos could leak your real name, device details, and more.

•What creators need to know to stay safe.

[INSERT LINK HERE]


10:20 – OpenAI Adds Business Intelligence Via MCP

•OpenAI unveils powerful new Business Intelligence capabilities using Multi-Modal Contextual Processing.

•Public announcement included YouTube demos, corporate messaging, and real-world scenarios.

•How this tech rivals Power BI, Tableau, and Looker.

[INSERT LINK HERE]


⸻


16:24 – Wrap Up

IT SPARC Cast

📱 @ITSPARCCast on X

🔗 https://www.linkedin.com/company/sparc-sales/


John Barger

📱 @john_Video on X

🔗 https://www.linkedin.com/in/johnbarger/


Lou Schmidt

📱 @loudoggeek on X

🔗 https://www.linkedin.com/in/louis-schmidt-b102446/

Hosted on Acast. See acast.com/privacy for more information.

Actively Exploited: Broadcom & Commvault Vulnerabilities Added to CISA KEV List03 juin 202500:07:37

In this episode of IT SPARC Cast - CVE of the Week, John Barger and Lou Schmidt break down two freshly identified and actively exploited CVEs that have just been added to CISA’s Known Exploited Vulnerabilities (KEV) database. First, we discuss CVE-2025-1976—a severe vulnerability in Broadcom’s Brocade Fabric OS—which allows local admins to execute arbitrary code with root privileges exploit, exposing organizations to complete system compromise. Then we cover CVE-2025-3928, a Commvault web server flaw that allows authenticated attackers to deploy web shells—especially dangerous when paired with other privilege escalation tactics.


These vulnerabilities aren’t theoretical—they’re being used in the wild right now. We explain why vendor reassurances about complexity of exploitation can lull teams into false security, how chain attacks make “local access” a relative concept, and why these types of flaws demand immediate attention—even if they seem buried in less-visible infrastructure. If you rely on Commvault or still run legacy Brocade systems, you can’t afford to ignore this one.


🔐 Keywords (SEO Optimized): CVE-2025-1976, CVE-2025-3928, Broadcom vulnerability, Commvault exploit, CISA KEV database, Brocade Fabric OS root flaw, Commvault web shell, enterprise storage security, critical vulnerability patch, chain exploits cybersecurity, IT SPARC Cast CVE, cybersecurity podcast, Lou Schmidt, John Barger


➡️ Feedback welcome at feedback@itsparccast.com or on X @ITSPARCCast

💬 Leave a comment on YouTube—we read and respond to nearly all of them!

📢 Like, subscribe, and share to stay ahead of the next breach.


Thanks for tuning in to IT SPARC Cast!

Follow and connect with us on social:


IT SPARC Cast

🔗 @ITSPARCCast on X

🔗 SPARC Sales on LinkedIn


John Barger

🔗 @john_Video on X

🔗 John Barger on LinkedIn


Lou Schmidt

🔗 @loudoggeek on X

🔗 Lou Schmidt on LinkedIn

Hosted on Acast. See acast.com/privacy for more information.

© My Podcast Data · Projet indépendant · Données issues d'Apple & Spotify