
Sign up to save your podcasts
Or


This week on AI Security Ops, the team breaks down how attackers are weaponizing AI and the tools around it: a critical n8n zero-day that can lead to unauthenticated remote code execution, prompt-injection “zombie agent” risks tied to ChatGPT memory, a zero-click-style indirect prompt injection scenario via email/URLs, and malicious Chrome extensions caught siphoning ChatGPT/DeepSeek chats at scale. They close with a reminder that the tactics are often “same old security problems,” just amplified by AI—so lock down orchestration, limit browser extensions, and keep sensitive data out of chat tools.
Key stories discussed
1) n8n (“n-eight-n”) zero-day → unauthenticated RCE risk
2) “Zombie agent” prompt injection via ChatGPT Memory
3) “Zero-click” agentic abuse via crafted email/URL (indirect prompt injection)
4) Malicious Chrome extensions stealing ChatGPT/DeepSeek chats (900k users)
5) APT28 credential phishing updated with AI-written lures
Chapter Timestamps
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
https://wildwesthackinfest.com
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com
By Black Hills Information SecurityThis week on AI Security Ops, the team breaks down how attackers are weaponizing AI and the tools around it: a critical n8n zero-day that can lead to unauthenticated remote code execution, prompt-injection “zombie agent” risks tied to ChatGPT memory, a zero-click-style indirect prompt injection scenario via email/URLs, and malicious Chrome extensions caught siphoning ChatGPT/DeepSeek chats at scale. They close with a reminder that the tactics are often “same old security problems,” just amplified by AI—so lock down orchestration, limit browser extensions, and keep sensitive data out of chat tools.
Key stories discussed
1) n8n (“n-eight-n”) zero-day → unauthenticated RCE risk
2) “Zombie agent” prompt injection via ChatGPT Memory
3) “Zero-click” agentic abuse via crafted email/URL (indirect prompt injection)
4) Malicious Chrome extensions stealing ChatGPT/DeepSeek chats (900k users)
5) APT28 credential phishing updated with AI-written lures
Chapter Timestamps
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
https://wildwesthackinfest.com
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com