Talkin' Bout [Infosec] News

Black Hills Information Security

Details

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. Join us live on YouTube, Monday's at 4:30PM ET

Recent Episodes

SEP 29, 2026
AI Agents Go Rogue: Where’s the Accountability? 2026-09-28
This week, the BHIS crew starts with an Nvidia-branded trailer stolen for its presumed GPUs—only to turn out to be full of sand. They then examine reports of OpenAI agents accessing Australian and U.S. government sites, the unanswered questions about what happened, and Nvidia’s proposed agent safety framework. The conversation moves to the EvilTokens phishing service takedown, recent vulnerability patches, and prompt injection attacks against AI agents handling Salesforce contact forms. The episode closes with a reported F-35 component shipment rerouted to China and concerns about cyber incidents affecting ships and maritime systems. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — Doing Bulldozer Stuff (09:05) - AI Agents Go Rogue: Where’s the Accountability? 2026-09-28 (12:16) - Nvidia-branded trailer stolen—and found full of sand (15:09) - OpenAI agents access Australian and U.S. government sites (30:55) - Nvidia’s OpenShell agent safety framework (37:06) - EvilTokens phishing service disrupted (46:16) - Citrix, WordPress, F5, and Roundcube vulnerability roundup (47:27) - Prompt injection through Salesforce web-to-lead forms (52:45) - F-35 components reportedly rerouted to China (55:20) - LNG tanker incident and maritime OT security (59:52) - Wild West Hackin’ Fest Deadwood and upcoming classes (01:01:00) - Offense for Defense and penetration testing classes (01:01:47) - Android pentesting and satellite security classes (01:03:26) - DEATHCon: detection engineering and threat hunting (01:06:58) - On Logos and Cables LinksCreators & Guests Tim Medin - Guest Kent Ickler - Guest John Strand - Host Ralph May - Host Wade Wells - Host Corey Ham - Host Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
68 MIN
SEP 22, 2026
Google’s Gemini Agent Escapes Containment - 2026-09-21
This week, the crew examines Google’s reported Gemini containment failure, Anthropic’s new biology lab, Snickers-branded prompt injection, AI-assisted social engineering, and Claude’s access to financial data. They also cover major Linux, Cisco, Check Point, and Docker vulnerabilities; weak oversight of Flock surveillance searches; privacy concerns surrounding Waymo vehicles; continuing ransomware disruption at an Australian chicken producer; and the escalating conflict between ShinyHunters and Clop. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — Justifying Our Existence (03:27) - Google’s Gemini Agent Escapes Containment - 2026-09-21 (06:45) - Google’s Gemini Hacks 3 Real Companies During Test (10:05) - Anthropic Builds a Bay Area Biology Lab (13:22) - Snickers Turns Prompt Injection into an Ad Campaign (19:41) - Iranian Social Engineering Uses Fake MRI Scans (25:10) - Claude Requests Access to Financial Accounts (28:50) - Meta’s Agentic AI and Its Personal-Data Advantage (30:57) - OpenAI Introduces In-Platform Advertising (34:47) - Linux Local Privilege-Escalation Vulnerabilities (35:32) - Cisco Secure Email Gateway Exploited by Nation-States (37:28) - Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root (37:53) - Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files (38:27) - CISA Ends Its Weekly Cybersecurity Bulletin (40:53) - Flock Surveillance Searches and Weak Oversight (49:10) - Waymo Detects a Firearm and Calls Police (57:40) - Upcoming Events, Workshops, and Training (57:51) - Alethe's Physical-Assessment Training (59:02) - Andy’s XDRCLI Talk at Wild West Hackin’ Fest (59:52) - Jake’s Hands-On AI Risk-Assessment Training (01:01:27) - Wade’s San Diego AI-Detection Event (01:03:00) - Ransomware Continues Disrupting an Australian Chicken Producer (01:05:34) - ShinyHunters Compromises Clop’s Dark-Web Site Links Google’s Gemini Hacks 3 Real Companies During Test Anthropic Builds a Bay Area Biology Lab Snickers Turns Prompt Injection into an Ad Campaign https://www.snickers.com/digitalsnickers Iranian Social Engineering Uses Fake MRI Scans Claude Requests Access to Financial AccountsOpenAI Introduces In-Platform Advertising Linux Local Privilege-Escalation Vulnerabilities Cisco Secure Email Gateway Exploited by Nation-States Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files CISA Ends Its Weekly Cybersecurity Bulletin Flock Surveillance Searches and Weak Oversight Waymo Detects a Firearm and Calls Police Alethe’s Physical-Assessment Training Andy’s XDRCLI Talk at Wild West Hackin’ Fest Jake’s Hands-On AI Risk-Assessment Training Wade’s San Diego AI-Detection Event Ransomware Continues Disrupting an Australian Chicken Producer ShinyHunters Compromises Clop’s Dark-Web Site Creators & Guests Alethe Denis - Guest Corey Ham - Host Andy Pettit "Nerf" - Guest Wade Wells - Host Bronwen Aker - Host Ryan Poirier - Producer Jake Williams - Guest Click here to watch this episode on YouTube. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
69 MIN
SEP 16, 2026
World Leaders Reject Calls to Slow Down AI Development - 2026-09-14
This week, the team examines AI agents targeting RubyGems, Anthropic’s warnings about dangerous AI misuse, human review of ChatGPT conversations, predictive policing, and LG smart-TV privacy. They also cover passkey-themed phishing, ScreenConnect abuse, Microsoft Defender patch bypasses, and upcoming cybersecurity workshops, webcasts, and Wild West Hackin’ Fest training. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — A Protected Class (05:20) - World Leaders Reject Calls to Slow Down AI Development - 2026-09-14 (07:58) - OpenAI Agent Swarm Targets RubyGems (16:12) - Anthropic Warns About Claude Misuse and Calls for Slower AI Development (31:38) - OpenAI’s Project Lily and Human Review of ChatGPT Conversations (38:54) - “Minority Report” Predictive Policing Using Financial Data (42:11) - LG Smart TVs Accused of Spying on Viewers (46:49) - Passkey-Themed Phishing Campaigns (47:20) - ConnectWise Patches ScreenConnect After Worm-Like Abuse (47:47) - Microsoft Defender “Shield Break” Patch Bypassed (54:19) - News Wrap-Up and Community Discussion (01:00:04) - Kip Boyle’s Book, Fire Doesn’t Innovate (01:00:27) - “Hunting Shadow AI” Workshop — September 25 (01:01:05) - “Playbooks for Owning AI Risk” Live Training (01:03:01) - Wild West Hackin’ Fest and Karaoke (01:03:51) - Webcast: Attacking MCP and N8N Servers (01:04:10) - Webcast: Safely Using Offensive AI in Security Assessments (01:05:17) - Wild West Hackin’ Fest Satellite and SOC Classes Links OpenAI Agent Swarm Targets RubyGems Anthropic Warns About Claude Misuse and Calls for Slower AI Development OpenAI’s Project Lily and Human Review of ChatGPT Conversations “Minority Report” Predictive Policing Using Financial Data LG Smart TVs Accused of Spying on Viewers Passkey-Themed Phishing Campaigns ConnectWise Patches ScreenConnect After Worm-Like Abuse Microsoft Defender “Shield Break” Patch BypassedKip Boyle’s Book, Fire Doesn’t Innovate “Hunting Shadow AI” Workshop — September 25 “Playbooks for Owning AI Risk” Live Training Wild West Hackin’ Fest and Karaoke Webcast: Attacking MCP and N8N Servers Webcast: Safely Using Offensive AI in Security Assessments Wild West Hackin’ Fest Satellite Class ...and SOC Classes Creators & Guests Kip Boyle - Guest Corey Ham - Host John Strand - Host Ralph May - Host Bronwen Aker - Host Charles "bsdbandit" - Guest Ryan Poirier - Producer Hayden Covington - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
73 MIN
SEP 9, 2026
Anthropic Warns Users of Infostealer Abuse - 2026-09-08
AI agents take center stage as the team examines OpenAI models using a German forum for private communications, Anthropic’s response to a compromised Claude account, new model releases, and the growing demand for Apple hardware to train computer-using agents. The discussion also covers the sale of stolen driver’s licenses, a claimed Florida DMV breach, and vulnerabilities affecting JFrog Artifactory, Proxmox, Plex, and Langflow. Finally, the panel considers CISA’s decision to discontinue six cybersecurity assessment services, new research into compromising passkeys, and Outflank’s compact NTLMv1 rainbow tables. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — Internet Fall Weather (03:17) - Anthropic Warns Users of Infostealer Abuse - 2026-09-08 (06:59) - OpenAI Agents Exploit a German Forum for Private Communications (17:18) - Anthropic Warns a User About Infostealer Abuse of Their Claude Account (23:32) - OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate (26:01) - CrowdStrike Releases AI Models Developed with NVIDIA (29:12) - FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses (32:41) - ShinyHunters Claims a Breach of the Florida DMV (35:19) - AI Labs Amass Mac Minis and Mac Studios for Agent Training (38:02) - Critical Authentication Bypass Disclosed in JFrog Artifactory (39:00) - Proxmox Vulnerability Exposes Internet-Facing Hosts (40:17) - New Plex Vulnerability Raises Home-Network Security Concerns (41:24) - Langflow Vulnerability Enables Unauthenticated Remote Code Execution (47:07) - Thomson Reuters Breach Disrupts State Court Systems (47:25) - CISA Cuts Six Free Cybersecurity Assessment Services (52:24) - New Research Demonstrates Ways to Compromise Passkeys (54:07) - Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool (56:02) - Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast (56:53) - PlexTrac’s AI-Assisted Reporting and Retesting (01:03:44) - Charles Shirer Introduces the FanMeyer Creator Platform (01:05:06) - Upcoming AI Browser Research and Wild West Hackin’ Fest Talk (01:05:49) - Hacking and Defending Satellite Infrastructure at Wild West (01:06:25) - Upcoming AI Core Skills Fundamentals Course Links OpenAI Agents Exploit a German Forum for Private Communications Anthropic Warns a User About Infostealer Abuse of Their Claude Account OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate CrowdStrike Releases AI Models Developed with NVIDIA FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses ShinyHunters Claims a Breach of the Florida DMV AI Labs Amass Mac Minis and Mac Studios for Agent Training Critical Authentication Bypass Disclosed in JFrog Artifactory Proxmox Vulnerability Exposes Internet-Facing Hosts New Plex Vulnerability Raises Home-Network Security Concerns Langflow Vulnerability Enables Unauthenticated Remote Code Execution Thomson Reuters Breach Disrupts State Court Systems CISA Cuts Six Free Cybersecurity Assessment Services New Research Demonstrates Ways to Compromise Passkeys Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking ToolDan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast Charles Shirer Introduces the FanMeyer Creator Platform Upcoming AI Browser Research and Wild West Hackin’ Fest Talk Hacking and Defending Satellite Infrastructure at Wild West Creators & Guests Corey Ham - Host Bronwen Aker - Host Ralph May - Host Charles "bsdbandit" - Guest Ryan Poirier - Producer Dan DeCloss - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec....
67 MIN
SEP 1, 2026
South Korea Offers Free AI Services – 2026-08-31
This episode of BHIS - Talkin' Bout [infosec] News covers South Korea’s free government AI services, new efforts to secure the U.S. power grid from foreign-made components, and the use of SS7 and fitness-tracking data in military operations. The panel also discusses the FBI’s disruption of Chinese botnets targeting critical infrastructure, the alleged McKesson patient-data breach, arrests connected to Team PCP, and reports of NVIDIA acquiring Hugging Face. Additional topics include competition among AI coding platforms, critical vulnerabilities affecting Ubiquiti, Gitea, NetScaler, WebLogic, and PaperCut, and calls for an AI-powered surge in cyber defense. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — What is the whole point of RAM? (07:47) - South Korea Offers Free AI Services – 2026-08-31 (08:44) - South Korea Offers Free Government AI Services (18:38) - White House Targets Foreign Components in the U.S. Power Grid (24:11) - How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved (25:15) - Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests (27:44) - The Strava Heat Map and the End of Secrets (29:37) - Officer reportedly leaks location of French aircraft carrier with Strava run (30:09) - FBI Disrupts Chinese Botnets Targeting Critical Infrastructure (32:31) - ShinyHunters Claims Theft of 284 Million McKesson Records (37:23) - Alleged Team PCP Hackers Arrested in Australia (39:08) - Rumored NVIDIA Acquisition of Hugging Face (49:48) - OpenAI, Cursor, and Competition Between AI Coding Platforms (53:11) - Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More (55:51) - PaperCut warns of NG, MF flaw exploited in zero-day attacks (56:20) - Technology Companies Call for an AI Defensive Surge (57:42) - 58 arrested in international cybercrime crackdown (58:48) - How to start the AI-accelerated defense (01:02:21) - TRAINING: Fundamentals of Cybersecurity: Threats and Defenses (01:07:07) - TRAINING: Hacking and Defending Satellite Infrastructure Links South Korea Offers Free Government AI Services White House Targets Foreign Components in the U.S. Power Grid How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests The Strava Heat Map and the End of Secrets Officer reportedly leaks location of French aircraft carrier with Strava run FBI Disrupts Chinese Botnets Targeting Critical Infrastructure ShinyHunters Claims Theft of 284 Million McKesson Records Alleged Team PCP Hackers Arrested in Australia Rumored NVIDIA Acquisition of Hugging Face OpenAI, Cursor, and Competition Between AI Coding Platforms Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More PaperCut warns of NG, MF flaw exploited in zero-day attacks Technology Companies Call for an AI Defensive Surge 58 arrested in international cybercrime crackdown How to start the AI-accelerated defense TRAINING: Fundamentals of Cybersecurity: Threats and Defenses TRAINING: Hacking and Defending Satellite InfrastructureCreators & Guests Corey Ham - Host John Strand - Host Bronwen Aker - Host Ryan Poirier - Producer Ralph May - Host Michael "Shecky" Kavka - Guest Doc Blackburn - Guest Hayden Covington - Host Wade Wells - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com
72 MIN