On this week’s show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week’s news, including:
- The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot
- Somehow OpenAI’s legal team allowed the company to spill all the Hugging Face tea at BlackHat and it’s hot and delicious
- More details emerge about Iran’s hacking campaign against US water utilities, but Brad is unimpressed
- It turns out TeamPCP has been around longer than we thought and predates the AI era
- Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways
- Much, much more
This week’s show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler.
This episode is also available on YouTube
Show notes
- How a simple request for AI to book a gym class exposed a major threat | Social Signals
- OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com
- OpenAI BlackHat talk re Hugging Face incident |
- OpenAI says Daybreak will expand to offer specialized cyber services | CyberScoop
- Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media
- Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate | therecord.media
- Local governments in four states dealing with cyberattacks that have shut down services | The Record
- Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska
- Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says | The Record
- State Department says Trump raised cyber scam compound issue with Xi | therecord.media
- Open-source software’s archenemy TeamPCP goes back further than anyone thought | CyberScoop
- A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide | wired.com
- Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun – Risky Business Media |
- Chrome adopts what may be the best protection yet against account takeovers | Ars Technica
- CSS:the bomb inside your inbox | PortSwigger Research
- Security update available for Metabase – Please upgrade now | Social Signals
- Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media
- British ‘Com’ member who abused more than 100 girls worldwide jailed for two years | therecord.media
- FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | TechCrunch Security
- AI is getting better at election facts, but voters shouldn’t rely on it | CyberScoop
- The FTC wants to regulate AI for ideological bias | cyberscoop.com
- US and South Korea warn of Gunra ransomware targeting govt agencies | BleepingComputer
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer
- N-able N-central exploitation results in RMM tool deployment | Sophos
- Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security
- mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub