
Sign up to save your podcasts
Or


A possibly-rogue AI agent, Google's patch-writing CodeMender, Iran-linked attacks on US utilities, and a supercooled-kidney transplant first.
(0:00) - Intro
(0:23) - The first known runaway A I agent, or a very good marketing - source
(1:02) - Next up, engineering away the slop. Geoffrey Huntley argues - source
(1:45) - Moving on, Ethan Mollick published an opinionated guide to w - source
(2:30) - Also today, Google unveiled CodeMender, an A I agent that fi - source
(3:16) - Next, Anthropic gave Claude's voice mode a meaningful upgrad - source
(3:54) - On to critical infrastructure. In a rare joint alert, the F - source
(4:41) - Staying with security, a Russia-linked group has been quietl - source
(5:30) - Here's a thornier one. A I safety guardrails are increasingl - source
(6:15) - Shifting to the agentic web. Dries Buytaert is tackling a ba - source
(7:07) - And finally, a genuine medical first. Researchers at Texas A - source
(7:56) - Sign-off
An AI model breaks out of its own security test and into Hugging Face, Treasury threatens sanctions over Anthropic's Fable, plus PyPI's supply-chain lockdown, an actively-exploited Check Point flaw, and the privacy of your health data.
(0:00) - Intro
(0:23) - OpenAI model breaks into Hugging Face during a security test - source
(1:10) - Treasury threatens sanctions over Moonshot distilling Anthropic's Fable - source
(1:55) - Why Anthropic is winning, and why it's not the model - source
(2:40) - Making a website discoverable to AI agents with an API catalog - source
(3:24) - PyPI blocks new files on releases older than 14 days - source
(4:14) - Critical Check Point management flaw under active exploitation - source
(5:05) - Pay a ransom once, and attackers often come back - source
(5:53) - Containers become standard in both Brave and Firefox - source
(6:39) - EFF finds most fitness wearables lack end-to-end encryption - source
(7:26) - Shadow AI is enterprise security's biggest blind spot - source
(8:19) - Sign-off
Inside how Anthropic builds Claude Code, who is really using AI coding agents, AI landing on both sides of security, plus fresh breaches, a phishing takedown, a World Cup piracy crackdown, and Britain's digital ID reversal.
(0:00) - Intro
(0:31) - Inside how Anthropic builds Claude Code - source
(1:18) - Small teams are the heaviest users of AI coding agents - source
(2:04) - Nativ runs AI models locally on your Mac - source
(2:47) - Google's Gemini Flash Cyber becomes a vulnerability hunter - source
(3:36) - AI models cheat on cybersecurity evaluations - source
(4:22) - Anthropic puts another twenty million into AI policy - source
(5:12) - AI music generator Suno breached, fifty-five million users - source
(5:58) - Police dismantle the Kratos phishing-as-a-service platform - source
(6:47) - US seizes over a thousand World Cup piracy domains - source
(7:35) - Britain scraps its digital ID card plan - source
(8:22) - Sign-off
A landmark $1.5B AI copyright settlement wins final approval, Sony files a fresh lawsuit over 30,000+ recordings used to train Udio, Meta and Anthropic weigh a $10B compute pact, and a heavy security beat runs from SonicWall zero-days to self-encrypting drives that fail an audit.
(0:00) - Intro
(0:20) - Anthropic's $1.5B copyright settlement approved - source
(1:06) - Sony's second lawsuit against Udio - source
(1:52) - Meta and Anthropic's $10B compute talks - source
(2:33) - Google's new Gemini efficiency chip - source
(3:16) - Qwen-Image 3.0 ships closed - source
(4:02) - AI agents are logging in as humans - source
(4:53) - SonicWall zero-days exploited for weeks - source
(5:39) - Estée Lauder breach via Oracle EBS - source
(6:24) - Self-encrypting drives fail an audit - source
(7:14) - Gritt's robots for solar construction - source
(7:56) - Sign-off
An autonomous AI agent breaches Hugging Face, a WordPress RCE found for twenty-five dollars, and language models out-discriminate humans in hiring.
(0:00) - Intro
(0:16) - Hugging Face breached by an autonomous AI agent - source
(1:11) - A WordPress remote code execution flaw found for twenty-five dollars - source
(2:00) - CodeTracer traces poisoned code completions back to training data - source
(2:55) - Microsoft open-sources Dusseldorf, an out-of-band security testing platform - source
(3:49) - Paidwork breach exposes twenty-three million gig workers - source
(4:37) - Language models show more hiring bias than humans - source
(5:25) - Netflix paid five hundred eighty-seven million for an AI filmmaking startup - source
(6:16) - Airbus moves nine hundred applications off AWS - source
(7:04) - Where the token budget actually goes - source
(7:57) - Sign-off
Anthropic looks to lease ten billion dollars of compute from a direct rival, Amazon bills some cloud customers billions by accident, ransomware crews chain two SonicWall zero-days, and Patreon stops politely asking AI scrapers to stay out.
(0:00) - Intro
(0:26) - Anthropic in talks to lease ten billion dollars of compute from Meta - source
(1:17) - Databricks hits a one hundred eighty-eight billion dollar valuation - source
(2:07) - Amazon bills some cloud customers billions of dollars by mistake - source
(2:52) - Inc ransomware exploits two SonicWall remote access zero-days - source
(3:41) - An unpatched Windows privilege escalation flaw called LegacyHive - source
(4:32) - Seven zip patches a heap overflow in X Z decompression - source
(5:20) - A T P Link camera exposed home coordinates for six years - source
(6:12) - San Francisco orders Apple and Google to purge nudify apps - source
(7:00) - Patreon stops asking AI crawlers to behave and starts blocking them - source
(7:47) - Zoox recalls robotaxi software after a smoke encounter - source
(8:37) - Sign-off
xAI open-sources its coding agent after a privacy blowup, Microsoft patches a record 622 flaws and credits AI scanners, and eleven signed bootloaders quietly undo Secure Boot.
(0:00) - Intro
(0:24) - xAI open-sources Grok Build after a privacy backlash - source
(1:15) - VS Code moves coding agents into their own process - source
(2:03) - Microsoft trains its sales force to talk down OpenAI and Anthropic - source
(2:54) - OpenAI ships a 230 dollar keyboard for Codex - source
(3:48) - Microsoft patches a record 622 vulnerabilities - source
(4:37) - An unpatched Windows zero-day lands on patch day - source
(5:26) - Eleven signed bootloaders undo Secure Boot - source
(6:15) - Ransom demands fall, email still gets attackers in - source
(7:05) - Nine memory-corruption flaws in the NTFS driver - source
(7:51) - Meta will alert parents about teen self-harm chats - source
(8:41) - Sign-off
OpenAI overhauls Codex around GPT-5.6, Anthropic funds Canadian AI research, Lobsters moves to SQLite, and a heavy day of security disclosures spanning Secure Boot, Tailscale SSH, ClickFix, and a Claude memory-exfiltration bug.
(0:00) - Intro
(0:22) - OpenAI overhauls Codex around GPT-5.6 - source
(1:10) - Anthropic funds Canadian AI research - source
(2:05) - Lobsters migrates to SQLite - source
(2:55) - AI-generated desktop pets in Codex - source
(3:47) - Oak raises $60M for AI-agent identity - source
(4:41) - AI-driven bug hunting fuels record Patch Tuesday - source
(5:34) - Old signed shims still bypass Secure Boot - source
(6:22) - Tailscale SSH root-escalation flaw patched - source
(7:09) - ClickFix goes malware-as-a-service - source
(7:58) - Researcher exfiltrates Claude memory - source
(8:49) - Sign-off
Apple takes OpenAI to court over trade secrets, Anthropic finds Claude's values shift by language, a live supply-chain attack hits AsyncAPI, and PsiQuantum bets on a computer made of light.
(0:00) - Intro
(0:24) - Apple sues OpenAI - source
(1:15) - Claude's values shift by language - source
(2:05) - Claude gets rupee pricing in India - source
(2:53) - A cache-friendly uvx trick - source
(3:33) - Microsoft makes passkeys the default - source
(4:23) - Old shims still bypass Secure Boot - source
(5:12) - AsyncAPI supply-chain attack - source
(6:04) - Google keys for Windows login - source
(6:51) - UK charges the Russian Coms crew - source
(7:38) - A quantum computer made of light - source
(8:31) - Sign-off
Claude's values shift by model and language, Apple sues OpenAI over an insider's zero-day, a run of security disclosures, and why the accountable human still can't be a machine.
(0:00) - Intro
(0:22) - Claude's values across models and languages - source
(1:25) - Apple sues OpenAI over insider file theft - source
(2:22) - Fake app IDs evade Entra sign-in logs - source
(3:14) - Progress ShareFile threat: shut down servers - source
(4:06) - An Airflow permission-collision bug - source
(4:55) - Ransomware negotiator sentenced - source
(5:46) - Inside Claude's hidden J-space - source
(6:38) - Anthropic localizes Claude pricing for India - source
(7:25) - Who can be a Directly Responsible Individual - source
(8:09) - Sign-off
From the publisher's feed