エピソード

  • Google’s Gemini Agent Escapes Containment - 2026-09-21
    2026/09/22
    This week, the crew examines Google’s reported Gemini containment failure, Anthropic’s new biology lab, Snickers-branded prompt injection, AI-assisted social engineering, and Claude’s access to financial data. They also cover major Linux, Cisco, Check Point, and Docker vulnerabilities; weak oversight of Flock surveillance searches; privacy concerns surrounding Waymo vehicles; continuing ransomware disruption at an Australian chicken producer; and the escalating conflict between ShinyHunters and Clop.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Justifying Our Existence(03:27) - Google’s Gemini Agent Escapes Containment - 2026-09-21(06:45) - Google’s Gemini Hacks 3 Real Companies During Test(10:05) - Anthropic Builds a Bay Area Biology Lab(13:22) - Snickers Turns Prompt Injection into an Ad Campaign(19:41) - Iranian Social Engineering Uses Fake MRI Scans(25:10) - Claude Requests Access to Financial Accounts(28:50) - Meta’s Agentic AI and Its Personal-Data Advantage(30:57) - OpenAI Introduces In-Platform Advertising(34:47) - Linux Local Privilege-Escalation Vulnerabilities(35:32) - Cisco Secure Email Gateway Exploited by Nation-States(37:28) - Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root(37:53) - Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files(38:27) - CISA Ends Its Weekly Cybersecurity Bulletin(40:53) - Flock Surveillance Searches and Weak Oversight(49:10) - Waymo Detects a Firearm and Calls Police(57:40) - Upcoming Events, Workshops, and Training(57:51) - Alethe's Physical-Assessment Training(59:02) - Andy’s XDRCLI Talk at Wild West Hackin’ Fest(59:52) - Jake’s Hands-On AI Risk-Assessment Training(01:01:27) - Wade’s San Diego AI-Detection Event(01:03:00) - Ransomware Continues Disrupting an Australian Chicken Producer(01:05:34) - ShinyHunters Compromises Clop’s Dark-Web SiteLinksGoogle’s Gemini Hacks 3 Real Companies During TestAnthropic Builds a Bay Area Biology LabSnickers Turns Prompt Injection into an Ad Campaignhttps://www.snickers.com/digitalsnickersIranian Social Engineering Uses Fake MRI ScansClaude Requests Access to Financial AccountsOpenAI Introduces In-Platform AdvertisingLinux Local Privilege-Escalation VulnerabilitiesCisco Secure Email Gateway Exploited by Nation-StatesCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as RootCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesCISA Ends Its Weekly Cybersecurity BulletinFlock Surveillance Searches and Weak OversightWaymo Detects a Firearm and Calls PoliceAlethe’s Physical-Assessment TrainingAndy’s XDRCLI Talk at Wild West Hackin’ FestJake’s Hands-On AI Risk-Assessment TrainingWade’s San Diego AI-Detection EventRansomware Continues Disrupting an Australian Chicken ProducerShinyHunters Compromises Clop’s Dark-Web SiteCreators & Guests Alethe Denis - GuestCorey Ham - HostAndy Pettit "Nerf" - GuestWade Wells - HostBronwen Aker - HostRyan Poirier - ProducerJake Williams - GuestClick here to watch this episode on YouTube. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 9 分
  • World Leaders Reject Calls to Slow Down AI Development - 2026-09-14
    2026/09/16
    This week, the team examines AI agents targeting RubyGems, Anthropic’s warnings about dangerous AI misuse, human review of ChatGPT conversations, predictive policing, and LG smart-TV privacy. They also cover passkey-themed phishing, ScreenConnect abuse, Microsoft Defender patch bypasses, and upcoming cybersecurity workshops, webcasts, and Wild West Hackin’ Fest training.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — A Protected Class(05:20) - World Leaders Reject Calls to Slow Down AI Development - 2026-09-14(07:58) - OpenAI Agent Swarm Targets RubyGems(16:12) - Anthropic Warns About Claude Misuse and Calls for Slower AI Development(31:38) - OpenAI’s Project Lily and Human Review of ChatGPT Conversations(38:54) - “Minority Report” Predictive Policing Using Financial Data(42:11) - LG Smart TVs Accused of Spying on Viewers(46:49) - Passkey-Themed Phishing Campaigns(47:20) - ConnectWise Patches ScreenConnect After Worm-Like Abuse(47:47) - Microsoft Defender “Shield Break” Patch Bypassed(54:19) - News Wrap-Up and Community Discussion(01:00:04) - Kip Boyle’s Book, Fire Doesn’t Innovate(01:00:27) - “Hunting Shadow AI” Workshop — September 25(01:01:05) - “Playbooks for Owning AI Risk” Live Training(01:03:01) - Wild West Hackin’ Fest and Karaoke(01:03:51) - Webcast: Attacking MCP and N8N Servers(01:04:10) - Webcast: Safely Using Offensive AI in Security Assessments(01:05:17) - Wild West Hackin’ Fest Satellite and SOC ClassesLinksOpenAI Agent Swarm Targets RubyGemsAnthropic Warns About Claude Misuse and Calls for Slower AI DevelopmentOpenAI’s Project Lily and Human Review of ChatGPT Conversations“Minority Report” Predictive Policing Using Financial DataLG Smart TVs Accused of Spying on ViewersPasskey-Themed Phishing CampaignsConnectWise Patches ScreenConnect After Worm-Like AbuseMicrosoft Defender “Shield Break” Patch BypassedKip Boyle’s Book, Fire Doesn’t Innovate“Hunting Shadow AI” Workshop — September 25“Playbooks for Owning AI Risk” Live TrainingWild West Hackin’ Fest and KaraokeWebcast: Attacking MCP and N8N ServersWebcast: Safely Using Offensive AI in Security AssessmentsWild West Hackin’ Fest Satellite Class...and SOC ClassesCreators & Guests Kip Boyle - GuestCorey Ham - HostJohn Strand - HostRalph May - HostBronwen Aker - HostCharles "bsdbandit" - GuestRyan Poirier - ProducerHayden Covington - HostClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 14 分
  • Anthropic Warns Users of Infostealer Abuse - 2026-09-08
    2026/09/09
    AI agents take center stage as the team examines OpenAI models using a German forum for private communications, Anthropic’s response to a compromised Claude account, new model releases, and the growing demand for Apple hardware to train computer-using agents. The discussion also covers the sale of stolen driver’s licenses, a claimed Florida DMV breach, and vulnerabilities affecting JFrog Artifactory, Proxmox, Plex, and Langflow. Finally, the panel considers CISA’s decision to discontinue six cybersecurity assessment services, new research into compromising passkeys, and Outflank’s compact NTLMv1 rainbow tables.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Internet Fall Weather(03:17) - Anthropic Warns Users of Infostealer Abuse - 2026-09-08(06:59) - OpenAI Agents Exploit a German Forum for Private Communications(17:18) - Anthropic Warns a User About Infostealer Abuse of Their Claude Account(23:32) - OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate(26:01) - CrowdStrike Releases AI Models Developed with NVIDIA(29:12) - FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses(32:41) - ShinyHunters Claims a Breach of the Florida DMV(35:19) - AI Labs Amass Mac Minis and Mac Studios for Agent Training(38:02) - Critical Authentication Bypass Disclosed in JFrog Artifactory(39:00) - Proxmox Vulnerability Exposes Internet-Facing Hosts(40:17) - New Plex Vulnerability Raises Home-Network Security Concerns(41:24) - Langflow Vulnerability Enables Unauthenticated Remote Code Execution(47:07) - Thomson Reuters Breach Disrupts State Court Systems(47:25) - CISA Cuts Six Free Cybersecurity Assessment Services(52:24) - New Research Demonstrates Ways to Compromise Passkeys(54:07) - Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool(56:02) - Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast(56:53) - PlexTrac’s AI-Assisted Reporting and Retesting(01:03:44) - Charles Shirer Introduces the FanMeyer Creator Platform(01:05:06) - Upcoming AI Browser Research and Wild West Hackin’ Fest Talk(01:05:49) - Hacking and Defending Satellite Infrastructure at Wild West(01:06:25) - Upcoming AI Core Skills Fundamentals CourseLinksOpenAI Agents Exploit a German Forum for Private CommunicationsAnthropic Warns a User About Infostealer Abuse of Their Claude AccountOpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI DebateCrowdStrike Releases AI Models Developed with NVIDIAFBI Investigates the Sale of 103,000 Stolen Driver’s LicensesShinyHunters Claims a Breach of the Florida DMVAI Labs Amass Mac Minis and Mac Studios for Agent TrainingCritical Authentication Bypass Disclosed in JFrog ArtifactoryProxmox Vulnerability Exposes Internet-Facing HostsNew Plex Vulnerability Raises Home-Network Security ConcernsLangflow Vulnerability Enables Unauthenticated Remote Code ExecutionThomson Reuters Breach Disrupts State Court SystemsCISA Cuts Six Free Cybersecurity Assessment ServicesNew Research Demonstrates Ways to Compromise PasskeysOutflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking ToolDan DeCloss: Turning Pen Tests into Risk Intelligence Anti-CastCharles Shirer Introduces the FanMeyer Creator PlatformUpcoming AI Browser Research and Wild West Hackin’ Fest TalkHacking and Defending Satellite Infrastructure at Wild WestCreators & Guests Corey Ham - HostBronwen Aker - HostRalph May - HostCharles "bsdbandit" - GuestRyan Poirier - ProducerDan DeCloss - GuestClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec....
    続きを読む 一部表示
    1 時間 8 分
  • South Korea Offers Free AI Services – 2026-08-31
    2026/09/01
    This episode of BHIS - Talkin' Bout [infosec] News covers South Korea’s free government AI services, new efforts to secure the U.S. power grid from foreign-made components, and the use of SS7 and fitness-tracking data in military operations. The panel also discusses the FBI’s disruption of Chinese botnets targeting critical infrastructure, the alleged McKesson patient-data breach, arrests connected to Team PCP, and reports of NVIDIA acquiring Hugging Face. Additional topics include competition among AI coding platforms, critical vulnerabilities affecting Ubiquiti, Gitea, NetScaler, WebLogic, and PaperCut, and calls for an AI-powered surge in cyber defense.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — What is the whole point of RAM?(07:47) - South Korea Offers Free AI Services – 2026-08-31(08:44) - South Korea Offers Free Government AI Services(18:38) - White House Targets Foreign Components in the U.S. Power Grid(24:11) - How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved(25:15) - Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests(27:44) - The Strava Heat Map and the End of Secrets(29:37) - Officer reportedly leaks location of French aircraft carrier with Strava run(30:09) - FBI Disrupts Chinese Botnets Targeting Critical Infrastructure(32:31) - ShinyHunters Claims Theft of 284 Million McKesson Records(37:23) - Alleged Team PCP Hackers Arrested in Australia(39:08) - Rumored NVIDIA Acquisition of Hugging Face(49:48) - OpenAI, Cursor, and Competition Between AI Coding Platforms(53:11) - Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More(55:51) - PaperCut warns of NG, MF flaw exploited in zero-day attacks(56:20) - Technology Companies Call for an AI Defensive Surge(57:42) - 58 arrested in international cybercrime crackdown(58:48) - How to start the AI-accelerated defense(01:02:21) - TRAINING: Fundamentals of Cybersecurity: Threats and Defenses(01:07:07) - TRAINING: Hacking and Defending Satellite InfrastructureLinksSouth Korea Offers Free Government AI ServicesWhite House Targets Foreign Components in the U.S. Power GridHow Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has EvolvedIranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data SuggestsThe Strava Heat Map and the End of SecretsOfficer reportedly leaks location of French aircraft carrier with Strava runFBI Disrupts Chinese Botnets Targeting Critical InfrastructureShinyHunters Claims Theft of 284 Million McKesson RecordsAlleged Team PCP Hackers Arrested in AustraliaRumored NVIDIA Acquisition of Hugging FaceOpenAI, Cursor, and Competition Between AI Coding PlatformsCritical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and MorePaperCut warns of NG, MF flaw exploited in zero-day attacksTechnology Companies Call for an AI Defensive Surge58 arrested in international cybercrime crackdownHow to start the AI-accelerated defenseTRAINING: Fundamentals of Cybersecurity: Threats and DefensesTRAINING: Hacking and Defending Satellite InfrastructureCreators & Guests Corey Ham - HostJohn Strand - HostBronwen Aker - HostRyan Poirier - ProducerRalph May - HostMichael "Shecky" Kavka - GuestDoc Blackburn - GuestHayden Covington - HostWade Wells - HostClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.com
    続きを読む 一部表示
    1 時間 13 分
  • Using AI to Debug the Linux Kernel - 2026-08-24
    2026/08/25
    This episode examines the alleged GTA 6 leak and Rockstar’s efforts to identify the leaker, a Flock Safety critic’s unconventional response to being barred from its conference, and Linus Torvalds’ use of AI to debug Linux. The discussion also covers ShinyHunters targeting ReliaQuest, “security through antiquity,” AliExpress using silent audio for browser fingerprinting, and invisible watermarks in Microsoft Paint’s AI-generated images. Additional stories include an Iran-linked cyberattack that disrupted a UK power plant, prompt injection hidden in a legal filing, and a cyberattack against an Australian chicken-processing facility.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — String Cheese and Security(04:29) - Using AI to Debug the Linux Kernel - 2026-08-24(06:50) - Story # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and Discord(12:47) - Story # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless Audio(16:58) - Story # 3: Linus Torvalds Uses AI to Debug the Linux Kernel(29:40) - Story # 4: ShinyHunters Targets ReliaQuest Employees with Social Engineering(31:07) - Story # 5: Can Obsolete Technology Provide “Security Through Antiquity”?(37:44) - Story # 6: AliExpress Uses Silent Audio for Browser Fingerprinting(41:30) - Story # 7: Darth Vader defends Flock cameras to San Diego City Council(42:44) - Story # 8: Microsoft Paint Embeds Watermarks in AI-Generated Images(44:45) - Story # 9: Iran-Linked Cyberattack Shuts Down a UK Power Plant(50:04) - Story # 10: Hidden AI Prompt Injection Discovered in a Legal Filing(57:56) - Story # 11: Australian Chicken Processing Plant Taken Offline by CyberattackLinksStory # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and DiscordStory # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless AudioStory # 3: Linus Torvalds Uses AI to Debug the Linux KernelStory # 4: ShinyHunters Targets ReliaQuest Employees with Social EngineeringStory # 5: Can Obsolete Technology Provide “Security Through Antiquity”?Story # 6: AliExpress Uses Silent Audio for Browser FingerprintingStory # 7: Darth Vader defends Flock cameras to San Diego City CouncilStory # 8: Microsoft Paint Embeds Watermarks in AI-Generated ImagesStory # 9: Iran-Linked Cyberattack Shuts Down a UK Power PlantStory # 10: Hidden AI Prompt Injection Discovered in a Legal FilingStory # 12: Australian Chicken Processing Plant Taken Offline by CyberattackFundamentals of Cybersecurity: Threats and DefensesCourse Authored by Doc Blackburn.Practical iOS Application Security TestingCourse Authored by Cameron Cartier and David Blandford.Creators & Guests Corey Ham - HostJohn Strand - HostWade Wells - HostAisling nic Lynne "siriciryel" - GuestDoc Blackburn - GuestRalph May - HostCameron Cartier - GuestRyan Poirier - ProducerClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 5 分
  • White House Announces "Digital Letters of Marque" - 2026-08-17
    2026/08/18
    This episode covers computer hardware shortages and chip-manufacturing bottlenecks, digital “letters of marque” for private cyber operations, and New Orleans’ use of AI for 911 calls. The panel also examines the LiteLLM supply-chain attack, Roblox safety concerns, attacks on on-premises SharePoint, AI agents escaping test environments, and vulnerabilities affecting Zoom and Microsoft Defender. Other topics include a post-DEF CON in-flight Wi-Fi incident, Signal’s automatic key verification, airport phone searches, and a PBS broadcaster’s loss of access to 70 years of archived television.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Making Investments(04:59) - Airport phone searches, “kill codes,” and border privacy(09:12) - White House Announces "Digital Letters of Marque" - 2026-08-17(11:29) - Story # 1: Digital letters of marque and private-sector “hack back”(18:45) - Story # 2: New Orleans adopts AI for 911 calls(25:10) - Story # 3: LiteLLM supply-chain attack(28:32) - Story # 4: Chris Hansen banned from Roblox during a safety demonstration(32:34) - Story # 5: On-premises Microsoft SharePoint under attack(34:18) - Story # 6: AI agents escape testing sandboxes and hack real targets(42:05) - Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw(44:54) - Story # 8: Post-DEF CON Delta flight Wi-Fi incident(52:44) - Story # 9: ShieldBreak exploit abuses Microsoft Defender(56:55) - Story # 10: Signal introduces automatic key verification(58:32) - Story # 11: PBS broadcaster loses access to 70 years of archived television(01:03:02) - Upcoming webcasts and trainingLinksStory # 1: Digital letters of marque and private-sector “hack back”Story # 2: New Orleans adopts AI for 911 callsStory # 3: LiteLLM supply-chain attackStory # 4: Chris Hansen banned from Roblox during a safety demonstrationStory # 5: On-premises Microsoft SharePoint under attackStory # 6: AI agents escape testing sandboxes and hack real targetsStory # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flawStory # 8: Post-DEF CON Delta flight Wi-Fi incidentStory # 9: ShieldBreak exploit abuses Microsoft DefenderStory # 10: Signal introduces automatic key verificationStory # 11: PBS broadcaster loses access to 70 years of archived televisionANTICAST - Your Cheap IoT Devices Are Hiding Secrets. Let's Find ThemTraining by Jake Williams – Assessing AI Security: Model Context ProtocolCreators & Guests Alex Minster "Belouve" - GuestWade Wells - HostRalph May - HostHayden Covington - HostDerek Banks - GuestRyan Poirier - ProducerAdrien Lasalle - GuestJake Williams - GuestClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 6 分
  • OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10
    2026/08/11
    This episode explores an AI agent that canceled someone else’s gym reservation, the growing offensive and defensive roles of AI, and a sharp rise in ransomware attacks. The panel also discusses privacy concerns surrounding Meta smart glasses, new passkey-theft and MFA-bypass research, the Snowflake hacker’s guilty plea, backdoors in ZBT-Link routers, compromised cameras aboard UK Navy drones, reports of AI models hacking real targets, and research into the reliability of AI-generated security patches.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — The Old Jerks(08:30) - OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10(12:00) - Story # 1: OpenClaw cancels another person’s gym reservation(27:43) - Story # 2: Ransomware attacks surge 20% amid the AI distraction(39:08) - Story # 3: Backlash grows against Meta’s AI smart glasses(46:28) - Story # 4: Passkey theft and MFA-bypass research(49:19) - Story # 5: Canadian Snowflake hacker pleads guilty(51:16) - Story # 6: ZBT-Link routers found with a China-linked backdoor(53:06) - Story # 7: UK Navy drone cameras reportedly transmitted data to China(56:19) - Story # 8: Meta reports AI models hacking real targets(01:02:44) - Story # 9: AI-generated security patches succeed only about half the timeLinksStory # 1: OpenClaw cancels another person’s gym reservationStory # 2: Ransomware attacks surge 20% amid the AI distractionStory # 3: Backlash grows against Meta’s AI smart glassesStory # 4: Passkey theft and MFA-bypass researchStory # 5: Canadian Snowflake hacker pleads guiltyStory # 6: ZBT-Link routers found with a China-linked backdoorStory # 7: UK Navy drone cameras reportedly transmitted data to ChinaStory # 8: Meta reports AI models hacking real targetsStory # 9: AI-generated security patches succeed only about half the timeInfosec: Age of AI SummitCreators & Guests Wade Wells - HostRalph May - HostJohn Strand - HostBronwen Aker - HostCorey Ham - HostRyan Poirier - ProducerKip Boyle - GuestClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 7 分
  • Iranian Cyberattacks on U.S. Water Systems - 2026-08-03
    2026/08/05
    This episode examines Anthropic’s disclosure that Claude breached real organizations during security testing, along with new technical details about the OpenAI and Hugging Face incident. The discussion covers ExfilSquad’s claimed Microsoft breach, cyberattacks targeting U.S. water systems, and malicious Android TV boxes used for residential proxy networks and advertising fraud. The hosts also explore Google’s Android age-verification plans, Chrome protections against hijacking extensions, Microsoft Teams impersonation attacks deploying Chaos ransomware, and Bank of America’s acquisition of MDSec. Additional topics include the GrapheneOS duress-password court case, a DEF CON prediction market, continued Kali365 phishing activity, and credential-stuffing attacks against Chick-fil-A loyalty accounts.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Zuckers(03:43) - Iranian Cyberattacks on U.S. Water Systems - 2026-08-03(07:00) - Story # 1: Anthropic’s Claude Breaches Companies During Security Testing(11:35) - Story # 2: Hugging Face Publishes Technical Details of the OpenAI Incident(13:37) - Story # 3: ExfilSquad Claims a Microsoft Cloud Breach(19:34) - Story # 4: Iranian Cyberattacks Target U.S. Water Systems(28:27) - Story # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad Fraud(40:51) - Story # 6: Google Introduces Android Age Verification(43:26) - Story # 7: Chrome Targets Tab- and Homepage-Hijacking Extensions(47:02) - Story # 8: Fake Microsoft Teams Support Calls Deploy Chaos Ransomware(48:38) - Story # 9: Bank of America Acquires MDSec(51:15) - Story # 10: GrapheneOS Duress Password Wipes Phone During Border Search(55:25) - Story # 11: Pony Market Takes Bets on DEF CON and Black Hat(58:06) - Story # 12: Kali365 Phishing Platform Remains Active(01:02:26) - ChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential StuffingLinksStory # 1: Anthropic’s Claude Breaches Companies During Security TestingStory # 2: Hugging Face Publishes Technical Details of the OpenAI IncidentStory # 3: ExfilSquad Claims a Microsoft Cloud BreachStory # 4: Iranian Cyberattacks Target U.S. Water SystemsStory # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad FraudStory # 6: Google Introduces Android Age VerificationStory # 7: Chrome Targets Tab- and Homepage-Hijacking ExtensionsStory # 8: Fake Microsoft Teams Support Calls Deploy Chaos RansomwareStory # 9: Bank of America Acquires MDSecStory # 10: GrapheneOS Duress Password Wipes Phone During Border SearchStory # 11: Pony Market Takes Bets on DEF CON and Black HatStory # 12: Kali365 Phishing Platform Remains ActiveChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential StuffingInfosec: Age of AI SummitDEATHcon- November 13 - 14, 2026- Univeristy of San Diego5998 Alcala Park Way San Diego, California 92110Creators & Guests Ralph May - HostWade Wells - HostBronwen Aker - HostCorey Ham - HostNick Ascoli - GuestClick here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com
    続きを読む 一部表示
    1 時間 7 分