Smashing Security

AI gets hacked, and BitLocker gets bypassed


Listen Later

What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told.

Meanwhile, someone calling themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of which lets a thief with a USB stick walk straight past BitLocker. Microsoft is furious.

Plus don't miss our featured interview with Son Nguyen Kim of Proton Pass, who explains why plugging AI agents into your email and calendar without thinking twice is rather like hiring a new employee with the keys to everything - and skipping the background check.

All this and more in episode 472 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.


EPISODE LINKS:


  • ShinyHunters claims 61M Sysco records - Cybernews.
  • Derbyshire police officer under investigation for using AI to create evidence - Derbyshire Times.
  • Maine forced to take down data breach portal after fake notices filed with authorities - Hot for Security.
  • A Fake Bug Report Hijacks Your AI Coding Agent - and Nothing Catches It. - Tenet Security.
  • Agentjacking: a fake bug report hijacks AI coding agents - TNW.
  • When anti-virus goes rogue - A trifecta of Defender zero-days - SolCyber.
  • BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber.
  • Microsoft versus Full Disclosure: The ongoing Nightmare Eclipse saga - SolCyber.
  • BitLocker, Defender, zero-days, and bragging rights: More MS nightmares - SolCyber.
  • Inside the FBI’s Kinetic Cyber Range - FBI.
  • Inside the FBI's Kinetic Cyber Range - YouTube.
  • Computer worm strikes International Space Station - Graham Cluley.
  • Raspberry Pi Zero W - Raspberry Pi.
  • There’s still life in old technology.
  • Smashing Security merchandise (t-shirts, mugs, stickers and stuff)



SPONSORS:

  • Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.
  • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
  • CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.



SUPPORT THE SHOW:

Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


FOLLOW THE SHOW:

Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


THANKS:

Theme tune: "Vinyl Memories" by Mikael Manvelyan.

Assorted sound effects: AudioBlocks.



Privacy & Opt-Out: https://redcircle.com/privacy
...more
View all episodesView all episodes
Download on the App Store

Smashing SecurityBy Graham Cluley

  • 4.5
  • 4.5
  • 4.5
  • 4.5
  • 4.5

4.5

315 ratings


More shows like Smashing Security

View all
Hacked by Hacked

Hacked

187 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

368 Listeners

Risky Business by Risky Business Media

Risky Business

376 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

648 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Click Here by Recorded Future News

Click Here

422 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,068 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

178 Listeners

Hacking Humans by N2K Networks

Hacking Humans

313 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

192 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

136 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

167 Listeners

The AI Fix by Mark Stockley

The AI Fix

33 Listeners