<p>This episode covers Mythos uncovering a vulnerability in cURL, a recent Google Threat Intelligence report on a zero-day exploit, and the growing impact of AI on capture-the-flag competitions and bug bounty programs. The hosts also discuss the economics of AI platforms like OpenAI, security research trends, and broader concerns around software vulnerabilities, automation, and defensive tooling.</p><p>Join us LIVE on Mondays, 4:30pm EST.<br>A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.<br><a href="https://www.youtube.com/@BlackHillsInformationSecurity">https://www.youtube.com/@BlackHillsInformationSecurity</a></p><p>Chat with us on Discord! - <br><a href="https://discord.gg/bhis">https://discord.gg/bhis</a><br>🔴live-chat</p><p><br><strong>Chapters</strong><br></p><ul><li>(00:00) - PreShow Banter™ — Token CTFs</li>
<li>(03:18) - Story # 1: Mythos finds a curl vulnerability</li>
<li>(06:36) - Story # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation</li>
<li>(14:47) - Story # 3: The down fall of bug bounties</li>
<li>(15:34) - Story # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’</li>
<li>(40:52) - Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat Robots</li>
<li>(43:51) - Story # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting Obliterated</li>
<li>(49:35) - Story # 5: Windows BitLocker zero-day gives access to protected drives, PoC released</li>
<li>(56:09) - Story # 6: Deal reached with hackers to delete data stolen from the Canvas educational platform</li>
<li>(58:07) - Story # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breach</li>
<li>(58:54) - Story # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible</li>
<li>(01:00:29) - Threat Hunting Summit Talk: Threat Hunting in the Dark: A Practical Approach</li>
<li>(01:04:47) - WEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek Banks</li>
</ul><br><strong>Links</strong><br>Story # 1: <a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">Mythos finds a curl vulnerability</a><br>Story # 2: <a href="https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html?">Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation</a><br>Story # 3: <a href="https://shubs.io/the-down-fall-of-bug-bounties/">The down fall of bug bounties</a><br>Story # 3: <a href="https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633">Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’</a><br>Story # 4: <a href="https://united24media.com/war-in-ukraine/germany-to-flood-ukraines-front-lines-with-hundreds-of-new-gereon-combat-robots-18653">Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat Robots</a><br>Story # 4b: <a href="https://futurism.com/robots-and-machines/delivery-robot-fail-compilation">Wild Video Shows Delivery Robots Causing Havoc, Getting Obliterated</a><br>Story # 5: <a href="https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/">Windows BitLocker zero-day gives access to protected drives, PoC released</a><br>Story # 6: <a href="https://apnews.com/article/canvas-outage-college-students-exams-grades-3d55b9399ae87d49276f354e1c34c180">Deal reached with hackers to delete data stolen from the Canvas educational platform</a><br>Story # 7: <a href="https://www.expressvpn.com/blog/celebrities-stalkerware-data-exposed/">Celebrities’ and influencers’ private communications exposed in stalkerware data breach</a><br>Story # 8: <a href="https://abc17news.com/news/2026/05/15/exclusive-hackers-have-breached-tank-readers-at-us-gas-stations-officials-suspect-iran-is-responsible/">Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible</a><br><a href="https://www.antisyphontraining.com/event/threat-hunting-summit-talk-threat-hunting-in-the-dark-a-practical-approach/">Threat Hunting Summit Talk: Threat Hunting in the Dark: A Practical Approach<br></a>WEBCAST: <a href="https://www.youtube.com/live/CVdsY2aX2Ew">Looking at A.I. Wrong with John Strand, BB King and Derek Banks</a><p><strong><strong>Creators &amp; Guests</strong>
<ul>
  <li><a href="https://bhisnews.transistor.fm/people/john-strand-8c127856-b150-4e33-af6d-5b9f7f041a37">John Strand</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/corey-ham">Corey Ham</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/wade-wells">Wade Wells</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/bronwen-aker">Bronwen Aker</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/ralph-may">Ralph May</a> - Host</li>
  <li><a href="https://bhisnews.transistor.fm/people/shane-hartman">Shane Hartman</a> - Guest</li>
  <li><a href="https://bhisnews.transistor.fm/people/meagan-bentley">Meagan Bentley</a> - Producer</li>
  <li><a href="https://bhisnews.transistor.fm/people/hayden-covington">Hayden Covington</a> - Host</li>
</ul><br><a href="https://www.youtube.com/watch?v=ePhMDIcOzwU" title="Click here to watch  this episode on YouTube.">Click here to watch  this episode on YouTube.</a><br>
</strong></p><p><strong><a href="https://share.transistor.fm/s/f37ea72e/transcript" title="Click here to view the episode transcript.">Click here to view the episode transcript.</a><br>
</strong></p><p><strong>🔗 Register for FREE Infosec Webcasts, Anti-casts &amp; Summits </strong></p><p><a href="https://poweredbybhis.com/">https://poweredbybhis.com</a></p><p><br>Brought to you by:</p><p><strong>Black Hills Information Security </strong></p><p><a href="https://www.blackhillsinfosec.com/">https://www.blackhillsinfosec.com</a></p><p><br></p><p><strong>Antisyphon Training</strong></p><p><a href="https://www.antisyphontraining.com/">https://www.antisyphontraining.com/</a></p><p><br></p><p><strong>Active Countermeasures</strong></p><p><a href="https://www.activecountermeasures.com/">https://www.activecountermeasures.com</a></p><p><br></p><p><strong>Wild West Hackin Fest</strong></p><p><a href="https://wildwesthackinfest.com/">https://wildwesthackinfest.com</a></p>

Talkin' Bout [Infosec] News

Black Hills Information Security

Mythos finds a curl vulnerability - 2026-05-18

MAY 22, 202666 MIN
Talkin' Bout [Infosec] News

Mythos finds a curl vulnerability - 2026-05-18

MAY 22, 202666 MIN

Description

This episode covers Mythos uncovering a vulnerability in cURL, a recent Google Threat Intelligence report on a zero-day exploit, and the growing impact of AI on capture-the-flag competitions and bug bounty programs. The hosts also discuss the economics of AI platforms like OpenAI, security research trends, and broader concerns around software vulnerabilities, automation, and defensive tooling.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis🔴live-chatChapters(00:00) - PreShow Banter™ — Token CTFs (03:18) - Story # 1: Mythos finds a curl vulnerability (06:36) - Story # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation (14:47) - Story # 3: The down fall of bug bounties (15:34) - Story # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ (40:52) - Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat Robots (43:51) - Story # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting Obliterated (49:35) - Story # 5: Windows BitLocker zero-day gives access to protected drives, PoC released (56:09) - Story # 6: Deal reached with hackers to delete data stolen from the Canvas educational platform (58:07) - Story # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breach (58:54) - Story # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible (01:00:29) - Threat Hunting Summit Talk: Threat Hunting in the Dark: A Practical Approach (01:04:47) - WEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek Banks LinksStory # 1: Mythos finds a curl vulnerabilityStory # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass ExploitationStory # 3: The down fall of bug bountiesStory # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat RobotsStory # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting ObliteratedStory # 5: Windows BitLocker zero-day gives access to protected drives, PoC releasedStory # 6: Deal reached with hackers to delete data stolen from the Canvas educational platformStory # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breachStory # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsibleThreat Hunting Summit Talk: Threat Hunting in the Dark: A Practical ApproachWEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek BanksCreators & Guests John Strand - Host Corey Ham - Host Wade Wells - Host Bronwen Aker - Host Ralph May - Host Shane Hartman - Guest Meagan Bentley - Producer Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.comBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com