AI Security Ops

Black Hills Information Security

Details

Join in on weekly podcasts that aim to illuminate how AI transforms cybersecurity—exploring emerging threats, tools, and trends—while equipping viewers with knowledge they can use practically (e.g., for secure coding or business risk mitigation).

Recent Episodes

SEP 26, 2026
Will AI Take Over? | Episode 71
In this episode of BHIS Presents: AI Security Ops, the team tackles a big question: Could AI actually take over the internet? Recent warnings from AI industry leaders have raised concerns about autonomous agent swarms escaping containment, compromising systems, and operating at a scale humans may struggle to match. But what would “taking over the internet” actually require? The team looks at the problem from a hacker’s perspective — examining compute requirements, persistence, botnets, vulnerable infrastructure, the recent Hugging Face incident, and the difference between AI acting autonomously and humans using AI to accelerate attacks. We dig into: - Whether an autonomous AI swarm could realistically operate at internet scale - What the Hugging Face incident actually tells us about agentic security - The compute and infrastructure required to sustain a rogue agent swarm - How botnets and compromised systems could change the equation - Why existing vulnerabilities may be a bigger concern than hypothetical AI takeover scenarios - Whether slowing frontier AI development actually addresses the cybersecurity problem - The difference between AI exhibiting dangerous behavior and AI having intent - Why defenders need to focus on their real-world attack surface today The takeaway: AI is dramatically increasing the speed and scale of cybersecurity operations, but powerful models still operate inside systems designed, deployed, and connected by people. The immediate security question may be less “Will AI take over?” and more “What are we giving AI access to?” #AISecurity #CyberSecurity #AgenticAI #AIAgents #ArtificialIntelligence #LLMSecurity #InfoSec #BHIS #Antisyphon (00:00) - Intro: Could AI Take Over the Internet? (01:18) - Why AI Leaders Are Warning About Agent Swarms (06:15) - What the Hugging Face Incident Actually Shows (09:40) - The Compute Problem for Rogue AI Swarms (11:44) - Could a rogue agent swarm be detected? (12:29) - Botnets, Crypto Miners, and Finding a Foothold (14:27) - How much new risk does AI create? (17:26) - A closer look at the agents’ attack timeline (19:58) - AI regulation and competition (22:44) - Human-directed AI versus autonomous AI (28:06) - From Compromised Computers to Internet-Scale Attacks (28:55) - What Does “Taking Over the Internet” Actually Mean? (33:11) - What an AI Takeover Could Realistically Look Like (34:00) - Practical security risks for organizations (35:55) - Could AI Agents Hide What They’re Doing? (37:00) - AI, the Hacker Mindset, and Anthropomorphic Fallacy (39:56) - Final Thoughts and Closing Click here to watch this episode on YouTube. Creators & Guests Derek Banks - Host Ethan Robish - Guest Brian Fehrman - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.
40 MIN
SEP 21, 2026
OWASP Agentic Top 10 [Part 1] | Episode 70
In this episode of BHIS Presents: AI Security Ops, the team breaks down the first five risks in the OWASP Agentic Skills Top 10 (Part 1). Agentic skills can give AI systems reusable instructions, workflows, and capabilities — but they also introduce a new attack surface. A skill may look like a simple markdown file, yet the agent following those instructions could have access to your filesystem, credentials, network, shell, or other sensitive resources. We dig into: - AST01: Malicious Skills - AST02: Supply Chain Compromise - AST03: Overprivileged Skills - AST04: Insecure Metadata - AST05: Untrusted External Instructions - Why skills should be treated more like software than configuration - How excessive permissions increase an agent’s blast radius - Why external content creates indirect prompt injection risks - How isolation, least privilege, and trusted sources can reduce risk The takeaway: “just markdown” isn’t necessarily harmless when an AI agent can act on what it reads. This is Part 1 of our look at the OWASP Agentic Skills Top 10, covering AST01 through AST05. — Learn more about Black Hills Information Security: https://www.blackhillsinfosec.com/ Check out Antisyphon Training: https://www.antisyphontraining.com/ (00:00) - Intro: OWASP Agentic Skills Top 10, Part 1 (01:59) - AST01: Malicious Skills (06:13) - AST02: Supply Chain Compromise (09:37) - AST03: Overprivileged Skills (13:56) - AST04: Insecure Metadata (16:34) - AST05: Untrusted External Instructions (22:36) - Final Takeaways and Part 2 Preview Click here to watch this episode on YouTube. Creators & Guests Brian Fehrman - Host Derek Banks - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.
23 MIN
SEP 14, 2026
Agentic Skills | Episode 69
Agentic skills can make AI agents more capable and consistent—but they can also introduce serious security risks. This episode explains how skills work, why malicious skills rank as a leading OWASP concern, and how seemingly harmless Markdown instructions can enable credential theft, remote payload delivery, and manipulated recommendations. Real-world examples illustrate how malicious skills can evade scanners and exploit trusted marketplaces. The episode concludes with practical safeguards, including reviewing skill files, watching for external instructions and prompt injection, pinning versions, limiting permissions, and running agents inside isolated environments. Links: OWASP Agentic Skills Top 10 Malicious AI Agent Skill Bypasses Security Scans and Seizes Full Control of Over 26,000 Agents (00:00) - Agentic Skills and the OWASP Top 10 (00:23) - Podcast Sponsors: BHIS and Antisyphon Training (01:29) - What Is an Agentic Skill? (03:13) - Skill Marketplaces and Widespread Adoption (03:46) - Why Malicious Skills Are the #1 Risk (05:50) - Remote Payloads and External Instructions (07:00) - Malicious Skill Takes Control of 26,000 Agents (08:09) - Money Radar and Manipulated Recommendations (09:20) - How to Evaluate and Use Skills Safely (11:08) - Closing Thoughts Click here to watch this episode on YouTube. Creators & Guests Brian Fehrman - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.
11 MIN
SEP 4, 2026
Data Becomes Code | Episode 68
What happens when AI coding agents treat vendor documentation as trusted instructions? Bronwen Aker and Derek Banks examine research showing how unclaimed package names and domains referenced in LLMs.txt files could lead coding agents to download and execute unintended code. They discuss how this AI-driven supply chain risk builds on familiar security problems, including dependency confusion, indirect prompt injection, and excessive permissions. The conversation also covers responsibility for AI-generated code, OpenAI’s cybersecurity proposals, and practical protections such as sandboxing, containerization, least privilege, network monitoring, and human oversight. LINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s (00:00) - Welcome to AI Security Ops Podcast (00:59) - AI Agents Install Unclaimed Software Packages (02:33) - How LLMs.txt Creates a New Supply Chain Risk (04:47) - Coding Agents Trust and Execute Vendor Documentation (07:35) - Who Owns and Secures AI-Generated Code? (08:18) - Prompt Injection, Sandboxing, and Containerization (11:40) - Where Did the Malicious References Come From? (13:38) - Reviewing OpenAI’s Cybersecurity Proposals (17:23) - Making Cyber Defense a Leadership Priority (19:06) - Practical Security Controls for Coding Agents (21:49) - When Data Becomes Code (22:33) - Closing Thoughts Click here to watch this episode on YouTube. Creators & Guests Derek Banks - Host Bronwen Aker - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.
23 MIN
AUG 31, 2026
Who is Responsible for an AI-Caused Breach? | Episode 67
This episode of AI Security Ops explores a growing question in AI security: who is responsible when an autonomous AI agent causes a real-world security breach without direct human instruction? Host Brian Fehrman examines reported incidents involving major AI labs, discusses how existing concepts such as liability, negligence, and intent may apply to AI-driven attacks, and considers the legal and security challenges organizations face as agentic AI systems become more capable. The episode highlights why responsibility for AI-caused harm remains an open question and what it could mean for the future of cybersecurity and regulation. (00:00) - Intro - Who Is Responsible When an AI Agent Goes Rogue? (01:25) - AI Models Breach Real-World Systems (02:04) - OpenAI’s ExploitGym Incident & Hugging Face Breach (03:52) - Anthropic and Meta Reveal Similar AI Incidents (05:36) - Who Is Liable for an AI-Caused Breach? (08:37) - Model Makers vs. Those Deploying the AI (09:42) - Does the Computer Fraud and Abuse Act Apply? (10:29) - AI Breaches and the Question of Negligence (11:45) - Safeguards, Sandboxing, and Responsibility (13:34) - What Happens When Your Organization Is the Victim? (14:48) - AI Liability and the Self-Driving Car Parallel Click here to watch this episode on YouTube. Creators & Guests Brian Fehrman - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.
15 MIN