Talkin' Bout [Infosec] News

Black Hills Information Security

Detaylar

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. Join us live on YouTube, Monday's at 4:30PM ET

Yeni Bölümler

9 EYL, 2026
Anthropic Warns Users of Infostealer Abuse - 2026-09-08
AI agents take center stage as the team examines OpenAI models using a German forum for private communications, Anthropic’s response to a compromised Claude account, new model releases, and the growing demand for Apple hardware to train computer-using agents. The discussion also covers the sale of stolen driver’s licenses, a claimed Florida DMV breach, and vulnerabilities affecting JFrog Artifactory, Proxmox, Plex, and Langflow. Finally, the panel considers CISA’s decision to discontinue six cybersecurity assessment services, new research into compromising passkeys, and Outflank’s compact NTLMv1 rainbow tables. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — Internet Fall Weather (03:17) - Anthropic Warns Users of Infostealer Abuse - 2026-09-08 (06:59) - OpenAI Agents Exploit a German Forum for Private Communications (17:18) - Anthropic Warns a User About Infostealer Abuse of Their Claude Account (23:32) - OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate (26:01) - CrowdStrike Releases AI Models Developed with NVIDIA (29:12) - FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses (32:41) - ShinyHunters Claims a Breach of the Florida DMV (35:19) - AI Labs Amass Mac Minis and Mac Studios for Agent Training (38:02) - Critical Authentication Bypass Disclosed in JFrog Artifactory (39:00) - Proxmox Vulnerability Exposes Internet-Facing Hosts (40:17) - New Plex Vulnerability Raises Home-Network Security Concerns (41:24) - Langflow Vulnerability Enables Unauthenticated Remote Code Execution (47:07) - Thomson Reuters Breach Disrupts State Court Systems (47:25) - CISA Cuts Six Free Cybersecurity Assessment Services (52:24) - New Research Demonstrates Ways to Compromise Passkeys (54:07) - Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool (56:02) - Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast (56:53) - PlexTrac’s AI-Assisted Reporting and Retesting (01:03:44) - Charles Shirer Introduces the FanMeyer Creator Platform (01:05:06) - Upcoming AI Browser Research and Wild West Hackin’ Fest Talk (01:05:49) - Hacking and Defending Satellite Infrastructure at Wild West (01:06:25) - Upcoming AI Core Skills Fundamentals Course Links OpenAI Agents Exploit a German Forum for Private Communications Anthropic Warns a User About Infostealer Abuse of Their Claude Account OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate CrowdStrike Releases AI Models Developed with NVIDIA FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses ShinyHunters Claims a Breach of the Florida DMV AI Labs Amass Mac Minis and Mac Studios for Agent Training Critical Authentication Bypass Disclosed in JFrog Artifactory Proxmox Vulnerability Exposes Internet-Facing Hosts New Plex Vulnerability Raises Home-Network Security Concerns Langflow Vulnerability Enables Unauthenticated Remote Code Execution Thomson Reuters Breach Disrupts State Court Systems CISA Cuts Six Free Cybersecurity Assessment Services New Research Demonstrates Ways to Compromise Passkeys Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking ToolDan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast Charles Shirer Introduces the FanMeyer Creator Platform Upcoming AI Browser Research and Wild West Hackin’ Fest Talk Hacking and Defending Satellite Infrastructure at Wild West Creators & Guests Corey Ham - Host Bronwen Aker - Host Ralph May - Host Charles "bsdbandit" - Guest Ryan Poirier - Producer Dan DeCloss - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec....
67 DAK
1 EYL, 2026
South Korea Offers Free AI Services – 2026-08-31
This episode of BHIS - Talkin' Bout [infosec] News covers South Korea’s free government AI services, new efforts to secure the U.S. power grid from foreign-made components, and the use of SS7 and fitness-tracking data in military operations. The panel also discusses the FBI’s disruption of Chinese botnets targeting critical infrastructure, the alleged McKesson patient-data breach, arrests connected to Team PCP, and reports of NVIDIA acquiring Hugging Face. Additional topics include competition among AI coding platforms, critical vulnerabilities affecting Ubiquiti, Gitea, NetScaler, WebLogic, and PaperCut, and calls for an AI-powered surge in cyber defense. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — What is the whole point of RAM? (07:47) - South Korea Offers Free AI Services – 2026-08-31 (08:44) - South Korea Offers Free Government AI Services (18:38) - White House Targets Foreign Components in the U.S. Power Grid (24:11) - How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved (25:15) - Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests (27:44) - The Strava Heat Map and the End of Secrets (29:37) - Officer reportedly leaks location of French aircraft carrier with Strava run (30:09) - FBI Disrupts Chinese Botnets Targeting Critical Infrastructure (32:31) - ShinyHunters Claims Theft of 284 Million McKesson Records (37:23) - Alleged Team PCP Hackers Arrested in Australia (39:08) - Rumored NVIDIA Acquisition of Hugging Face (49:48) - OpenAI, Cursor, and Competition Between AI Coding Platforms (53:11) - Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More (55:51) - PaperCut warns of NG, MF flaw exploited in zero-day attacks (56:20) - Technology Companies Call for an AI Defensive Surge (57:42) - 58 arrested in international cybercrime crackdown (58:48) - How to start the AI-accelerated defense (01:02:21) - TRAINING: Fundamentals of Cybersecurity: Threats and Defenses (01:07:07) - TRAINING: Hacking and Defending Satellite Infrastructure Links South Korea Offers Free Government AI Services White House Targets Foreign Components in the U.S. Power Grid How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests The Strava Heat Map and the End of Secrets Officer reportedly leaks location of French aircraft carrier with Strava run FBI Disrupts Chinese Botnets Targeting Critical Infrastructure ShinyHunters Claims Theft of 284 Million McKesson Records Alleged Team PCP Hackers Arrested in Australia Rumored NVIDIA Acquisition of Hugging Face OpenAI, Cursor, and Competition Between AI Coding Platforms Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More PaperCut warns of NG, MF flaw exploited in zero-day attacks Technology Companies Call for an AI Defensive Surge 58 arrested in international cybercrime crackdown How to start the AI-accelerated defense TRAINING: Fundamentals of Cybersecurity: Threats and Defenses TRAINING: Hacking and Defending Satellite InfrastructureCreators & Guests Corey Ham - Host John Strand - Host Bronwen Aker - Host Ryan Poirier - Producer Ralph May - Host Michael "Shecky" Kavka - Guest Doc Blackburn - Guest Hayden Covington - Host Wade Wells - Host Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com
72 DAK
25 AĞU, 2026
Using AI to Debug the Linux Kernel - 2026-08-24
This episode examines the alleged GTA 6 leak and Rockstar’s efforts to identify the leaker, a Flock Safety critic’s unconventional response to being barred from its conference, and Linus Torvalds’ use of AI to debug Linux. The discussion also covers ShinyHunters targeting ReliaQuest, “security through antiquity,” AliExpress using silent audio for browser fingerprinting, and invisible watermarks in Microsoft Paint’s AI-generated images. Additional stories include an Iran-linked cyberattack that disrupted a UK power plant, prompt injection hidden in a legal filing, and a cyberattack against an Australian chicken-processing facility. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — String Cheese and Security (04:29) - Using AI to Debug the Linux Kernel - 2026-08-24 (06:50) - Story # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and Discord (12:47) - Story # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless Audio (16:58) - Story # 3: Linus Torvalds Uses AI to Debug the Linux Kernel (29:40) - Story # 4: ShinyHunters Targets ReliaQuest Employees with Social Engineering (31:07) - Story # 5: Can Obsolete Technology Provide “Security Through Antiquity”? (37:44) - Story # 6: AliExpress Uses Silent Audio for Browser Fingerprinting (41:30) - Story # 7: Darth Vader defends Flock cameras to San Diego City Council (42:44) - Story # 8: Microsoft Paint Embeds Watermarks in AI-Generated Images (44:45) - Story # 9: Iran-Linked Cyberattack Shuts Down a UK Power Plant (50:04) - Story # 10: Hidden AI Prompt Injection Discovered in a Legal Filing (57:56) - Story # 11: Australian Chicken Processing Plant Taken Offline by Cyberattack LinksStory # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and Discord Story # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless Audio Story # 3: Linus Torvalds Uses AI to Debug the Linux Kernel Story # 4: ShinyHunters Targets ReliaQuest Employees with Social Engineering Story # 5: Can Obsolete Technology Provide “Security Through Antiquity”? Story # 6: AliExpress Uses Silent Audio for Browser Fingerprinting Story # 7: Darth Vader defends Flock cameras to San Diego City Council Story # 8: Microsoft Paint Embeds Watermarks in AI-Generated Images Story # 9: Iran-Linked Cyberattack Shuts Down a UK Power Plant Story # 10: Hidden AI Prompt Injection Discovered in a Legal Filing Story # 12: Australian Chicken Processing Plant Taken Offline by Cyberattack Fundamentals of Cybersecurity: Threats and Defenses Course Authored by Doc Blackburn. Practical iOS Application Security Testing Course Authored by Cameron Cartier and David Blandford. Creators & Guests Corey Ham - Host John Strand - Host Wade Wells - Host Aisling nic Lynne "siriciryel" - Guest Doc Blackburn - Guest Ralph May - Host Cameron Cartier - Guest Ryan Poirier - Producer Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
64 DAK
18 AĞU, 2026
White House Announces "Digital Letters of Marque" - 2026-08-17
This episode covers computer hardware shortages and chip-manufacturing bottlenecks, digital “letters of marque” for private cyber operations, and New Orleans’ use of AI for 911 calls. The panel also examines the LiteLLM supply-chain attack, Roblox safety concerns, attacks on on-premises SharePoint, AI agents escaping test environments, and vulnerabilities affecting Zoom and Microsoft Defender. Other topics include a post-DEF CON in-flight Wi-Fi incident, Signal’s automatic key verification, airport phone searches, and a PBS broadcaster’s loss of access to 70 years of archived television. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — Making Investments (04:59) - Airport phone searches, “kill codes,” and border privacy (09:12) - White House Announces "Digital Letters of Marque" - 2026-08-17 (11:29) - Story # 1: Digital letters of marque and private-sector “hack back” (18:45) - Story # 2: New Orleans adopts AI for 911 calls (25:10) - Story # 3: LiteLLM supply-chain attack (28:32) - Story # 4: Chris Hansen banned from Roblox during a safety demonstration (32:34) - Story # 5: On-premises Microsoft SharePoint under attack (34:18) - Story # 6: AI agents escape testing sandboxes and hack real targets (42:05) - Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw (44:54) - Story # 8: Post-DEF CON Delta flight Wi-Fi incident (52:44) - Story # 9: ShieldBreak exploit abuses Microsoft Defender (56:55) - Story # 10: Signal introduces automatic key verification (58:32) - Story # 11: PBS broadcaster loses access to 70 years of archived television (01:03:02) - Upcoming webcasts and training Links Story # 1: Digital letters of marque and private-sector “hack back” Story # 2: New Orleans adopts AI for 911 calls Story # 3: LiteLLM supply-chain attack Story # 4: Chris Hansen banned from Roblox during a safety demonstration Story # 5: On-premises Microsoft SharePoint under attack Story # 6: AI agents escape testing sandboxes and hack real targets Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw Story # 8: Post-DEF CON Delta flight Wi-Fi incident Story # 9: ShieldBreak exploit abuses Microsoft Defender Story # 10: Signal introduces automatic key verification Story # 11: PBS broadcaster loses access to 70 years of archived televisionANTICAST - Your Cheap IoT Devices Are Hiding Secrets. Let's Find Them Training by Jake Williams – Assessing AI Security: Model Context Protocol Creators & Guests Alex Minster "Belouve" - Guest Wade Wells - Host Ralph May - Host Hayden Covington - Host Derek Banks - Guest Ryan Poirier - Producer Adrien Lasalle - Guest Jake Williams - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
66 DAK
11 AĞU, 2026
OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10
This episode explores an AI agent that canceled someone else’s gym reservation, the growing offensive and defensive roles of AI, and a sharp rise in ransomware attacks. The panel also discusses privacy concerns surrounding Meta smart glasses, new passkey-theft and MFA-bypass research, the Snowflake hacker’s guilty plea, backdoors in ZBT-Link routers, compromised cameras aboard UK Navy drones, reports of AI models hacking real targets, and research into the reliability of AI-generated security patches. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters (00:00) - PreShow Banter™ — The Old Jerks (08:30) - OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10 (12:00) - Story # 1: OpenClaw cancels another person’s gym reservation (27:43) - Story # 2: Ransomware attacks surge 20% amid the AI distraction (39:08) - Story # 3: Backlash grows against Meta’s AI smart glasses (46:28) - Story # 4: Passkey theft and MFA-bypass research (49:19) - Story # 5: Canadian Snowflake hacker pleads guilty (51:16) - Story # 6: ZBT-Link routers found with a China-linked backdoor (53:06) - Story # 7: UK Navy drone cameras reportedly transmitted data to China (56:19) - Story # 8: Meta reports AI models hacking real targets (01:02:44) - Story # 9: AI-generated security patches succeed only about half the time Links Story # 1: OpenClaw cancels another person’s gym reservation Story # 2: Ransomware attacks surge 20% amid the AI distraction Story # 3: Backlash grows against Meta’s AI smart glasses Story # 4: Passkey theft and MFA-bypass research Story # 5: Canadian Snowflake hacker pleads guilty Story # 6: ZBT-Link routers found with a China-linked backdoor Story # 7: UK Navy drone cameras reportedly transmitted data to China Story # 8: Meta reports AI models hacking real targets Story # 9: AI-generated security patches succeed only about half the timeInfosec: Age of AI Summit Creators & Guests Wade Wells - Host Ralph May - Host John Strand - Host Bronwen Aker - Host Corey Ham - Host Ryan Poirier - Producer Kip Boyle - Guest Click here to watch this episode on YouTube. Click here to view the episode transcript. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com
66 DAK