/https://img.transistorcdn.com/AukI425sRBc3M3UIa9lVng7qjeNeYEQ8BZfzCEXhALs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xZTA1/ZWZhNDcxZGM4ZTFj/ZGJhMTMwNmYzMmJj/ZjBkNi5wbmc.jpg)
Talkin' Bout [Infosec] News
Black Hills Information Security
AI Agents Go Rogue: Where’s the Accountability? 2026-09-28
SEP 29, 202668 MIN
/https://img.transistorcdn.com/dCSYYp_aP21vwFijtpt9ag3-4l3kjhSrniL-OaxQmes/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZTli/OTQ1YzZhMzNiNzY4/NDJlYmI1MWIwMmI1/YTM0Ni5qcGc.jpg)
Description
This week, the BHIS crew starts with an Nvidia-branded trailer stolen for its presumed GPUs—only to turn out to be full of sand. They then examine reports of OpenAI agents accessing Australian and U.S. government sites, the unanswered questions about what happened, and Nvidia’s proposed agent safety framework. The conversation moves to the EvilTokens phishing service takedown, recent vulnerability patches, and prompt injection attacks against AI agents handling Salesforce contact forms. The episode closes with a reported F-35 component shipment rerouted to China and concerns about cyber incidents affecting ships and maritime systems.
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
(00:00) - PreShow Banter™ — Doing Bulldozer Stuff
(09:05) - AI Agents Go Rogue: Where’s the Accountability? 2026-09-28
(12:16) - Nvidia-branded trailer stolen—and found full of sand
(15:09) - OpenAI agents access Australian and U.S. government sites
(30:55) - Nvidia’s OpenShell agent safety framework
(37:06) - EvilTokens phishing service disrupted
(46:16) - Citrix, WordPress, F5, and Roundcube vulnerability roundup
(47:27) - Prompt injection through Salesforce web-to-lead forms
(52:45) - F-35 components reportedly rerouted to China
(55:20) - LNG tanker incident and maritime OT security
(59:52) - Wild West Hackin’ Fest Deadwood and upcoming classes
(01:01:00) - Offense for Defense and penetration testing classes
(01:01:47) - Android pentesting and satellite security classes
(01:03:26) - DEATHCon: detection engineering and threat hunting
(01:06:58) - On Logos and Cables
LinksCreators & Guests
Tim Medin - Guest
Kent Ickler - Guest
John Strand - Host
Ralph May - Host
Wade Wells - Host
Corey Ham - Host
Hayden Covington - Host
Click here to watch this episode on YouTube.
Click here to view the episode transcript.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
https://wildwesthackinfest.com

