S0:E29 — The GRE Tunnel That Wasn't in the Config episode artwork

EPISODE · Sep 8, 2026 · 38 MIN

S0:E29 — The GRE Tunnel That Wasn't in the Config

from Breach Please

Sygnia published new research on Fire Ant, a threat actor they first tracked in 2025 around hypervisor espionage against vCenter and ESXi. The new report covers something rarer: live compromise of Cisco IOS XR network devices, discovered because a responder noticed a GRE tunnel in network monitoring that didn't exist in the running config and left no trace in the logs. Jess and Jake walk through what that means for defenders, why IOS XR being Linux-based changes the economics of building a backdoor, and why "compromised network devices" remains one of the most underappreciated categories of incident today.They also get into the ongoing mess of threat actor naming conventions (why one group can have a dozen different names across vendors, and why that's not just marketing), and revisit an earlier debate: is network device security part of zero trust, or a separate problem? Jake asked the internet. The internet had opinions.In this episode:Why one threat actor group ends up with a different name at every vendor, and why that's harder to fix than it soundsFire Ant: Sygnia's research on Cisco IOS XR compromise and a GRE tunnel that left no trace in logs or saved configWhy IOS XR being Linux-based lowers the cost of building a persistent backdoor from six figures to a scripting problemThe running-config-vs-saved-config trap during incident responseWhy unencrypted internal traffic means a compromised network device gets credentials, not just topologyMan-in-the-middle terminology, RC4, Kerberoasting, and why alerting on SPN enumeration breaks down for an on-path attackerWhy network device security has to be part of zero trust, not an asterisk on itBreach Please is a production of JWJH Media LLC. The opinions of our hosts are their own. Nothing in this episode is legal, financial, or security advice. Do your homework before pointing anything we said at prod.

Episode metadata supplied by the publisher feed · Published Sep 8, 2026

Embed this episode

Ready to play

S0:E29 — The GRE Tunnel That Wasn't in the Config

0:00 38:32

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Breach Please?

This episode is 38 minutes long.

When was this Breach Please episode published?

This episode was published on September 8, 2026.

Can I download this Breach Please episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!