Talkin' Bout [Infosec] News

Talkin' Bout [Infosec] News

By Black Hills Information SecurityNewsTechnologyTech News
Download on the App Store

Talkin' Bout [Infosec] News episodes

  • AI Agents Go Rogue: Where’s the Accountability? 2026-09-28

    This week, the BHIS crew starts with an Nvidia-branded trailer stolen for its presumed GPUs—only to turn out to be full of sand. They then examine reports of OpenAI agents accessing Australian and U.S. government sites, the unanswered questions about what happened, and Nvidia’s proposed agent safety framework. The conversation moves to the EvilTokens phishing service takedown, recent vulnerability patches, and prompt injection attacks against AI agents handling Salesforce contact forms. The episode closes with a reported F-35 component shipment rerouted to China and concerns about cyber incidents affecting ships and maritime systems.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat


    Chapters

    • (00:00) - PreShow Banter™ — Doing Bulldozer Stuff
  • (09:05) - AI Agents Go Rogue: Where’s the Accountability? 2026-09-28
  • (12:16) - Nvidia-branded trailer stolen—and found full of sand
  • (15:09) - OpenAI agents access Australian and U.S. government sites
  • (30:55) - Nvidia’s OpenShell agent safety framework
  • (37:06) - EvilTokens phishing service disrupted
  • (46:16) - Citrix, WordPress, F5, and Roundcube vulnerability roundup
  • (47:27) - Prompt injection through Salesforce web-to-lead forms
  • (52:45) - F-35 components reportedly rerouted to China
  • (55:20) - LNG tanker incident and maritime OT security
  • (59:52) - Wild West Hackin’ Fest Deadwood and upcoming classes
  • (01:01:00) - Offense for Defense and penetration testing classes
  • (01:01:47) - Android pentesting and satellite security classes
  • (01:03:26) - DEATHCon: detection engineering and threat hunting
  • (01:06:58) - On Logos and Cables

  • Links

    Creators & Guests

  • Tim Medin - Guest
  • Kent Ickler - Guest
  • John Strand - Host
  • Ralph May - Host
  • Wade Wells - Host
  • Corey Ham - Host
  • Hayden Covington - Host

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 9 min
  • Google’s Gemini Agent Escapes Containment - 2026-09-21

    This week, the crew examines Google’s reported Gemini containment failure, Anthropic’s new biology lab, Snickers-branded prompt injection, AI-assisted social engineering, and Claude’s access to financial data. They also cover major Linux, Cisco, Check Point, and Docker vulnerabilities; weak oversight of Flock surveillance searches; privacy concerns surrounding Waymo vehicles; continuing ransomware disruption at an Australian chicken producer; and the escalating conflict between ShinyHunters and Clop.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat

    Chapters

    • (00:00) - PreShow Banter™ — Justifying Our Existence
  • (03:27) - Google’s Gemini Agent Escapes Containment - 2026-09-21
  • (06:45) - Google’s Gemini Hacks 3 Real Companies During Test
  • (10:05) - Anthropic Builds a Bay Area Biology Lab
  • (13:22) - Snickers Turns Prompt Injection into an Ad Campaign
  • (19:41) - Iranian Social Engineering Uses Fake MRI Scans
  • (25:10) - Claude Requests Access to Financial Accounts
  • (28:50) - Meta’s Agentic AI and Its Personal-Data Advantage
  • (30:57) - OpenAI Introduces In-Platform Advertising
  • (34:47) - Linux Local Privilege-Escalation Vulnerabilities
  • (35:32) - Cisco Secure Email Gateway Exploited by Nation-States
  • (37:28) - Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
  • (37:53) - Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
  • (38:27) - CISA Ends Its Weekly Cybersecurity Bulletin
  • (40:53) - Flock Surveillance Searches and Weak Oversight
  • (49:10) - Waymo Detects a Firearm and Calls Police
  • (57:40) - Upcoming Events, Workshops, and Training
  • (57:51) - Alethe's Physical-Assessment Training
  • (59:02) - Andy’s XDRCLI Talk at Wild West Hackin’ Fest
  • (59:52) - Jake’s Hands-On AI Risk-Assessment Training
  • (01:01:27) - Wade’s San Diego AI-Detection Event
  • (01:03:00) - Ransomware Continues Disrupting an Australian Chicken Producer
  • (01:05:34) - ShinyHunters Compromises Clop’s Dark-Web Site

  • Links
    Google’s Gemini Hacks 3 Real Companies During Test
    Anthropic Builds a Bay Area Biology Lab
    Snickers Turns Prompt Injection into an Ad Campaign
    https://www.snickers.com/digitalsnickers
    Iranian Social Engineering Uses Fake MRI Scans
    Claude Requests Access to Financial Accounts

    OpenAI Introduces In-Platform Advertising
    Linux Local Privilege-Escalation Vulnerabilities
    Cisco Secure Email Gateway Exploited by Nation-States
    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
    CISA Ends Its Weekly Cybersecurity Bulletin
    Flock Surveillance Searches and Weak Oversight
    Waymo Detects a Firearm and Calls Police

    Alethe’s Physical-Assessment Training
    Andy’s XDRCLI Talk at Wild West Hackin’ Fest
    Jake’s Hands-On AI Risk-Assessment Training
    Wade’s San Diego AI-Detection Event

    Ransomware Continues Disrupting an Australian Chicken Producer
    ShinyHunters Compromises Clop’s Dark-Web Site


    Creators & Guests

  • Alethe Denis - Guest
  • Corey Ham - Host
  • Andy Pettit "Nerf" - Guest
  • Wade Wells - Host
  • Bronwen Aker - Host
  • Ryan Poirier - Producer
  • Jake Williams - Guest

  • Click here to watch this episode on YouTube.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 10 min
  • World Leaders Reject Calls to Slow Down AI Development - 2026-09-14

    This week, the team examines AI agents targeting RubyGems, Anthropic’s warnings about dangerous AI misuse, human review of ChatGPT conversations, predictive policing, and LG smart-TV privacy. They also cover passkey-themed phishing, ScreenConnect abuse, Microsoft Defender patch bypasses, and upcoming cybersecurity workshops, webcasts, and Wild West Hackin’ Fest training.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat

    Chapters

    • (00:00) - PreShow Banter™ — A Protected Class
  • (05:20) - World Leaders Reject Calls to Slow Down AI Development - 2026-09-14
  • (07:58) - OpenAI Agent Swarm Targets RubyGems
  • (16:12) - Anthropic Warns About Claude Misuse and Calls for Slower AI Development
  • (31:38) - OpenAI’s Project Lily and Human Review of ChatGPT Conversations
  • (38:54) - “Minority Report” Predictive Policing Using Financial Data
  • (42:11) - LG Smart TVs Accused of Spying on Viewers
  • (46:49) - Passkey-Themed Phishing Campaigns
  • (47:20) - ConnectWise Patches ScreenConnect After Worm-Like Abuse
  • (47:47) - Microsoft Defender “Shield Break” Patch Bypassed
  • (54:19) - News Wrap-Up and Community Discussion
  • (01:00:04) - Kip Boyle’s Book, Fire Doesn’t Innovate
  • (01:00:27) - “Hunting Shadow AI” Workshop — September 25
  • (01:01:05) - “Playbooks for Owning AI Risk” Live Training
  • (01:03:01) - Wild West Hackin’ Fest and Karaoke
  • (01:03:51) - Webcast: Attacking MCP and N8N Servers
  • (01:04:10) - Webcast: Safely Using Offensive AI in Security Assessments
  • (01:05:17) - Wild West Hackin’ Fest Satellite and SOC Classes

  • Links
    OpenAI Agent Swarm Targets RubyGems
    Anthropic Warns About Claude Misuse and Calls for Slower AI Development
    OpenAI’s Project Lily and Human Review of ChatGPT Conversations
    “Minority Report” Predictive Policing Using Financial Data
    LG Smart TVs Accused of Spying on Viewers
    Passkey-Themed Phishing Campaigns
    ConnectWise Patches ScreenConnect After Worm-Like Abuse
    Microsoft Defender “Shield Break” Patch Bypassed

    Kip Boyle’s Book, Fire Doesn’t Innovate
    “Hunting Shadow AI” Workshop — September 25
    “Playbooks for Owning AI Risk” Live Training
    Wild West Hackin’ Fest and Karaoke
    Webcast: Attacking MCP and N8N Servers
    Webcast: Safely Using Offensive AI in Security Assessments
    Wild West Hackin’ Fest Satellite Class
    ...and SOC Classes

    Creators & Guests

  • Kip Boyle - Guest
  • Corey Ham - Host
  • John Strand - Host
  • Ralph May - Host
  • Bronwen Aker - Host
  • Charles "bsdbandit" - Guest
  • Ryan Poirier - Producer
  • Hayden Covington - Host

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 14 min
  • Anthropic Warns Users of Infostealer Abuse - 2026-09-08

    AI agents take center stage as the team examines OpenAI models using a German forum for private communications, Anthropic’s response to a compromised Claude account, new model releases, and the growing demand for Apple hardware to train computer-using agents. The discussion also covers the sale of stolen driver’s licenses, a claimed Florida DMV breach, and vulnerabilities affecting JFrog Artifactory, Proxmox, Plex, and Langflow. Finally, the panel considers CISA’s decision to discontinue six cybersecurity assessment services, new research into compromising passkeys, and Outflank’s compact NTLMv1 rainbow tables.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat


    Chapters

    • (00:00) - PreShow Banter™ — Internet Fall Weather
  • (03:17) - Anthropic Warns Users of Infostealer Abuse - 2026-09-08
  • (06:59) - OpenAI Agents Exploit a German Forum for Private Communications
  • (17:18) - Anthropic Warns a User About Infostealer Abuse of Their Claude Account
  • (23:32) - OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate
  • (26:01) - CrowdStrike Releases AI Models Developed with NVIDIA
  • (29:12) - FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses
  • (32:41) - ShinyHunters Claims a Breach of the Florida DMV
  • (35:19) - AI Labs Amass Mac Minis and Mac Studios for Agent Training
  • (38:02) - Critical Authentication Bypass Disclosed in JFrog Artifactory
  • (39:00) - Proxmox Vulnerability Exposes Internet-Facing Hosts
  • (40:17) - New Plex Vulnerability Raises Home-Network Security Concerns
  • (41:24) - Langflow Vulnerability Enables Unauthenticated Remote Code Execution
  • (47:07) - Thomson Reuters Breach Disrupts State Court Systems
  • (47:25) - CISA Cuts Six Free Cybersecurity Assessment Services
  • (52:24) - New Research Demonstrates Ways to Compromise Passkeys
  • (54:07) - Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool
  • (56:02) - Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast
  • (56:53) - PlexTrac’s AI-Assisted Reporting and Retesting
  • (01:03:44) - Charles Shirer Introduces the FanMeyer Creator Platform
  • (01:05:06) - Upcoming AI Browser Research and Wild West Hackin’ Fest Talk
  • (01:05:49) - Hacking and Defending Satellite Infrastructure at Wild West
  • (01:06:25) - Upcoming AI Core Skills Fundamentals Course

  • Links
    OpenAI Agents Exploit a German Forum for Private Communications
    Anthropic Warns a User About Infostealer Abuse of Their Claude Account
    OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate
    CrowdStrike Releases AI Models Developed with NVIDIA
    FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses
    ShinyHunters Claims a Breach of the Florida DMV
    AI Labs Amass Mac Minis and Mac Studios for Agent Training
    Critical Authentication Bypass Disclosed in JFrog Artifactory
    Proxmox Vulnerability Exposes Internet-Facing Hosts
    New Plex Vulnerability Raises Home-Network Security Concerns
    Langflow Vulnerability Enables Unauthenticated Remote Code Execution
    Thomson Reuters Breach Disrupts State Court Systems
    CISA Cuts Six Free Cybersecurity Assessment Services
    New Research Demonstrates Ways to Compromise Passkeys
    Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool

    Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast
    Charles Shirer Introduces the FanMeyer Creator Platform
    Upcoming AI Browser Research and Wild West Hackin’ Fest Talk
    Hacking and Defending Satellite Infrastructure at Wild West


    Creators & Guests

  • Corey Ham - Host
  • Bronwen Aker - Host
  • Ralph May - Host
  • Charles "bsdbandit" - Guest
  • Ryan Poirier - Producer
  • Dan DeCloss - Guest

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec....

    1 hr 8 min
  • South Korea Offers Free AI Services – 2026-08-31

    This episode of BHIS - Talkin' Bout [infosec] News covers South Korea’s free government AI services, new efforts to secure the U.S. power grid from foreign-made components, and the use of SS7 and fitness-tracking data in military operations. The panel also discusses the FBI’s disruption of Chinese botnets targeting critical infrastructure, the alleged McKesson patient-data breach, arrests connected to Team PCP, and reports of NVIDIA acquiring Hugging Face. Additional topics include competition among AI coding platforms, critical vulnerabilities affecting Ubiquiti, Gitea, NetScaler, WebLogic, and PaperCut, and calls for an AI-powered surge in cyber defense.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat


    Chapters

    • (00:00) - PreShow Banter™ — What is the whole point of RAM?
  • (07:47) - South Korea Offers Free AI Services – 2026-08-31
  • (08:44) - South Korea Offers Free Government AI Services
  • (18:38) - White House Targets Foreign Components in the U.S. Power Grid
  • (24:11) - How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved
  • (25:15) - Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests
  • (27:44) - The Strava Heat Map and the End of Secrets
  • (29:37) - Officer reportedly leaks location of French aircraft carrier with Strava run
  • (30:09) - FBI Disrupts Chinese Botnets Targeting Critical Infrastructure
  • (32:31) - ShinyHunters Claims Theft of 284 Million McKesson Records
  • (37:23) - Alleged Team PCP Hackers Arrested in Australia
  • (39:08) - Rumored NVIDIA Acquisition of Hugging Face
  • (49:48) - OpenAI, Cursor, and Competition Between AI Coding Platforms
  • (53:11) - Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More
  • (55:51) - PaperCut warns of NG, MF flaw exploited in zero-day attacks
  • (56:20) - Technology Companies Call for an AI Defensive Surge
  • (57:42) - 58 arrested in international cybercrime crackdown
  • (58:48) - How to start the AI-accelerated defense
  • (01:02:21) - TRAINING: Fundamentals of Cybersecurity: Threats and Defenses
  • (01:07:07) - TRAINING: Hacking and Defending Satellite Infrastructure

  • Links
    South Korea Offers Free Government AI Services
    White House Targets Foreign Components in the U.S. Power Grid
    How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved
    Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests
    The Strava Heat Map and the End of Secrets
    Officer reportedly leaks location of French aircraft carrier with Strava run
    FBI Disrupts Chinese Botnets Targeting Critical Infrastructure
    ShinyHunters Claims Theft of 284 Million McKesson Records
    Alleged Team PCP Hackers Arrested in Australia
    Rumored NVIDIA Acquisition of Hugging Face
    OpenAI, Cursor, and Competition Between AI Coding Platforms
    Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More
    PaperCut warns of NG, MF flaw exploited in zero-day attacks
    Technology Companies Call for an AI Defensive Surge
    58 arrested in international cybercrime crackdown
    How to start the AI-accelerated defense
    TRAINING: Fundamentals of Cybersecurity: Threats and Defenses
    TRAINING: Hacking and Defending Satellite Infrastructure

    Creators & Guests

  • Corey Ham - Host
  • John Strand - Host
  • Bronwen Aker - Host
  • Ryan Poirier - Producer
  • Ralph May - Host
  • Michael "Shecky" Kavka - Guest
  • Doc Blackburn - Guest
  • Hayden Covington - Host
  • Wade Wells - Host

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    1 hr 13 min
  • Using AI to Debug the Linux Kernel - 2026-08-24

    This episode examines the alleged GTA 6 leak and Rockstar’s efforts to identify the leaker, a Flock Safety critic’s unconventional response to being barred from its conference, and Linus Torvalds’ use of AI to debug Linux. The discussion also covers ShinyHunters targeting ReliaQuest, “security through antiquity,” AliExpress using silent audio for browser fingerprinting, and invisible watermarks in Microsoft Paint’s AI-generated images. Additional stories include an Iran-linked cyberattack that disrupted a UK power plant, prompt injection hidden in a legal filing, and a cyberattack against an Australian chicken-processing facility.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat


    Chapters

    • (00:00) - PreShow Banter™ — String Cheese and Security
  • (04:29) - Using AI to Debug the Linux Kernel - 2026-08-24
  • (06:50) - Story # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and Discord
  • (12:47) - Story # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless Audio
  • (16:58) - Story # 3: Linus Torvalds Uses AI to Debug the Linux Kernel
  • (29:40) - Story # 4: ShinyHunters Targets ReliaQuest Employees with Social Engineering
  • (31:07) - Story # 5: Can Obsolete Technology Provide “Security Through Antiquity”?
  • (37:44) - Story # 6: AliExpress Uses Silent Audio for Browser Fingerprinting
  • (41:30) - Story # 7: Darth Vader defends Flock cameras to San Diego City Council
  • (42:44) - Story # 8: Microsoft Paint Embeds Watermarks in AI-Generated Images
  • (44:45) - Story # 9: Iran-Linked Cyberattack Shuts Down a UK Power Plant
  • (50:04) - Story # 10: Hidden AI Prompt Injection Discovered in a Legal Filing
  • (57:56) - Story # 11: Australian Chicken Processing Plant Taken Offline by Cyberattack

  • Links

    Story # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and Discord
    Story # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless Audio
    Story # 3: Linus Torvalds Uses AI to Debug the Linux Kernel
    Story # 4: ShinyHunters Targets ReliaQuest Employees with Social Engineering
    Story # 5: Can Obsolete Technology Provide “Security Through Antiquity”?
    Story # 6: AliExpress Uses Silent Audio for Browser Fingerprinting
    Story # 7: Darth Vader defends Flock cameras to San Diego City Council
    Story # 8: Microsoft Paint Embeds Watermarks in AI-Generated Images
    Story # 9: Iran-Linked Cyberattack Shuts Down a UK Power Plant
    Story # 10: Hidden AI Prompt Injection Discovered in a Legal Filing
    Story # 12: Australian Chicken Processing Plant Taken Offline by Cyberattack

    Fundamentals of Cybersecurity: Threats and Defenses
    Course Authored by Doc Blackburn.

    Practical iOS Application Security Testing
    Course Authored by Cameron Cartier and David Blandford.

    Creators & Guests

  • Corey Ham - Host
  • John Strand - Host
  • Wade Wells - Host
  • Aisling nic Lynne "siriciryel" - Guest
  • Doc Blackburn - Guest
  • Ralph May - Host
  • Cameron Cartier - Guest
  • Ryan Poirier - Producer

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 5 min
  • White House Announces "Digital Letters of Marque" - 2026-08-17

    This episode covers computer hardware shortages and chip-manufacturing bottlenecks, digital “letters of marque” for private cyber operations, and New Orleans’ use of AI for 911 calls. The panel also examines the LiteLLM supply-chain attack, Roblox safety concerns, attacks on on-premises SharePoint, AI agents escaping test environments, and vulnerabilities affecting Zoom and Microsoft Defender. Other topics include a post-DEF CON in-flight Wi-Fi incident, Signal’s automatic key verification, airport phone searches, and a PBS broadcaster’s loss of access to 70 years of archived television.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat


    Chapters

    • (00:00) - PreShow Banter™ — Making Investments
  • (04:59) - Airport phone searches, “kill codes,” and border privacy
  • (09:12) - White House Announces "Digital Letters of Marque" - 2026-08-17
  • (11:29) - Story # 1: Digital letters of marque and private-sector “hack back”
  • (18:45) - Story # 2: New Orleans adopts AI for 911 calls
  • (25:10) - Story # 3: LiteLLM supply-chain attack
  • (28:32) - Story # 4: Chris Hansen banned from Roblox during a safety demonstration
  • (32:34) - Story # 5: On-premises Microsoft SharePoint under attack
  • (34:18) - Story # 6: AI agents escape testing sandboxes and hack real targets
  • (42:05) - Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw
  • (44:54) - Story # 8: Post-DEF CON Delta flight Wi-Fi incident
  • (52:44) - Story # 9: ShieldBreak exploit abuses Microsoft Defender
  • (56:55) - Story # 10: Signal introduces automatic key verification
  • (58:32) - Story # 11: PBS broadcaster loses access to 70 years of archived television
  • (01:03:02) - Upcoming webcasts and training

  • Links
    Story # 1: Digital letters of marque and private-sector “hack back”
    Story # 2: New Orleans adopts AI for 911 calls
    Story # 3: LiteLLM supply-chain attack
    Story # 4: Chris Hansen banned from Roblox during a safety demonstration
    Story # 5: On-premises Microsoft SharePoint under attack
    Story # 6: AI agents escape testing sandboxes and hack real targets
    Story # 7: “Zoomsday” — AI discovers a Zoom remote-code-execution flaw
    Story # 8: Post-DEF CON Delta flight Wi-Fi incident
    Story # 9: ShieldBreak exploit abuses Microsoft Defender
    Story # 10: Signal introduces automatic key verification
    Story # 11: PBS broadcaster loses access to 70 years of archived television

    ANTICAST - Your Cheap IoT Devices Are Hiding Secrets. Let's Find Them
    Training by Jake Williams – Assessing AI Security: Model Context Protocol

    Creators & Guests

  • Alex Minster "Belouve" - Guest
  • Wade Wells - Host
  • Ralph May - Host
  • Hayden Covington - Host
  • Derek Banks - Guest
  • Ryan Poirier - Producer
  • Adrien Lasalle - Guest
  • Jake Williams - Guest

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 7 min
  • OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10

    This episode explores an AI agent that canceled someone else’s gym reservation, the growing offensive and defensive roles of AI, and a sharp rise in ransomware attacks. The panel also discusses privacy concerns surrounding Meta smart glasses, new passkey-theft and MFA-bypass research, the Snowflake hacker’s guilty plea, backdoors in ZBT-Link routers, compromised cameras aboard UK Navy drones, reports of AI models hacking real targets, and research into the reliability of AI-generated security patches.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat


    Chapters

    • (00:00) - PreShow Banter™ — The Old Jerks
  • (08:30) - OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10
  • (12:00) - Story # 1: OpenClaw cancels another person’s gym reservation
  • (27:43) - Story # 2: Ransomware attacks surge 20% amid the AI distraction
  • (39:08) - Story # 3: Backlash grows against Meta’s AI smart glasses
  • (46:28) - Story # 4: Passkey theft and MFA-bypass research
  • (49:19) - Story # 5: Canadian Snowflake hacker pleads guilty
  • (51:16) - Story # 6: ZBT-Link routers found with a China-linked backdoor
  • (53:06) - Story # 7: UK Navy drone cameras reportedly transmitted data to China
  • (56:19) - Story # 8: Meta reports AI models hacking real targets
  • (01:02:44) - Story # 9: AI-generated security patches succeed only about half the time

  • Links
    Story # 1: OpenClaw cancels another person’s gym reservation
    Story # 2: Ransomware attacks surge 20% amid the AI distraction
    Story # 3: Backlash grows against Meta’s AI smart glasses
    Story # 4: Passkey theft and MFA-bypass research
    Story # 5: Canadian Snowflake hacker pleads guilty
    Story # 6: ZBT-Link routers found with a China-linked backdoor
    Story # 7: UK Navy drone cameras reportedly transmitted data to China
    Story # 8: Meta reports AI models hacking real targets
    Story # 9: AI-generated security patches succeed only about half the time

    Infosec: Age of AI Summit


    Creators & Guests

  • Wade Wells - Host
  • Ralph May - Host
  • John Strand - Host
  • Bronwen Aker - Host
  • Corey Ham - Host
  • Ryan Poirier - Producer
  • Kip Boyle - Guest

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 7 min
  • Iranian Cyberattacks on U.S. Water Systems - 2026-08-03

    This episode examines Anthropic’s disclosure that Claude breached real organizations during security testing, along with new technical details about the OpenAI and Hugging Face incident. The discussion covers ExfilSquad’s claimed Microsoft breach, cyberattacks targeting U.S. water systems, and malicious Android TV boxes used for residential proxy networks and advertising fraud. The hosts also explore Google’s Android age-verification plans, Chrome protections against hijacking extensions, Microsoft Teams impersonation attacks deploying Chaos ransomware, and Bank of America’s acquisition of MDSec. Additional topics include the GrapheneOS duress-password court case, a DEF CON prediction market, continued Kali365 phishing activity, and credential-stuffing attacks against Chick-fil-A loyalty accounts.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴live-chat


    Chapters

    • (00:00) - PreShow Banter™ — Zuckers
  • (03:43) - Iranian Cyberattacks on U.S. Water Systems - 2026-08-03
  • (07:00) - Story # 1: Anthropic’s Claude Breaches Companies During Security Testing
  • (11:35) - Story # 2: Hugging Face Publishes Technical Details of the OpenAI Incident
  • (13:37) - Story # 3: ExfilSquad Claims a Microsoft Cloud Breach
  • (19:34) - Story # 4: Iranian Cyberattacks Target U.S. Water Systems
  • (28:27) - Story # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad Fraud
  • (40:51) - Story # 6: Google Introduces Android Age Verification
  • (43:26) - Story # 7: Chrome Targets Tab- and Homepage-Hijacking Extensions
  • (47:02) - Story # 8: Fake Microsoft Teams Support Calls Deploy Chaos Ransomware
  • (48:38) - Story # 9: Bank of America Acquires MDSec
  • (51:15) - Story # 10: GrapheneOS Duress Password Wipes Phone During Border Search
  • (55:25) - Story # 11: Pony Market Takes Bets on DEF CON and Black Hat
  • (58:06) - Story # 12: Kali365 Phishing Platform Remains Active
  • (01:02:26) - ChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential Stuffing

  • Links
    Story # 1: Anthropic’s Claude Breaches Companies During Security Testing
    Story # 2: Hugging Face Publishes Technical Details of the OpenAI Incident
    Story # 3: ExfilSquad Claims a Microsoft Cloud Breach
    Story # 4: Iranian Cyberattacks Target U.S. Water Systems
    Story # 5: Malicious Android TV Boxes Fuel Proxy Networks and Ad Fraud
    Story # 6: Google Introduces Android Age Verification
    Story # 7: Chrome Targets Tab- and Homepage-Hijacking Extensions
    Story # 8: Fake Microsoft Teams Support Calls Deploy Chaos Ransomware
    Story # 9: Bank of America Acquires MDSec
    Story # 10: GrapheneOS Duress Password Wipes Phone During Border Search
    Story # 11: Pony Market Takes Bets on DEF CON and Black Hat
    Story # 12: Kali365 Phishing Platform Remains Active
    ChickenSec : Chick-fil-A Loyalty Accounts Hit by Credential Stuffing
    Infosec: Age of AI Summit

    DEATHcon
    - November 13 - 14, 2026
    - Univeristy of San Diego
    5998 Alcala Park Way
    San Diego, California 92110

    Creators & Guests

  • Ralph May - Host
  • Wade Wells - Host
  • Bronwen Aker - Host
  • Corey Ham - Host
  • Nick Ascoli - Guest

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 7 min
  • OpenAI accidentally Hacked Hugging Face - 2026-07-27

    This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.

    Join us LIVE on Mondays, 4:30pm EST.
    A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
    https://www.youtube.com/@BlackHillsInformationSecurity

    Chat with us on Discord! -
    https://discord.gg/bhis
    🔴event-live-chat


    Chapters

    • (00:00) - PreShow Banter™ — Sol with a Goal
  • (06:33) - OpenAI accidentally Hacked Hugging Face - 2026-07-27
  • (09:18) - Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
  • (18:33) - Story #2 - Lapsus is shutting down
  • (24:21) - Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
  • (31:47) - Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
  • (44:00) - Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
  • (52:43) - Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
  • (55:51) - Ads and Mike at the AI Summit
  • (59:54) - Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

  • Links

    Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
    Story #2 - Lapsus is shutting down
    Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
    AgentForger, Part 2: The Autonomous Insider
    Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
    Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
    Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
    Ads and Mike at the AI Summit
    Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

    Creators & Guests

  • Ads Dawson - Guest
  • Mike Takahashi - Guest
  • Corey Ham - Host
  • John Strand - Host
  • Bronwen Aker - Host
  • Hayden Covington - Host
  • Ralph May - Host

  • Click here to watch this episode on YouTube.

    Click here to view the episode transcript.

    🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

    https://poweredbybhis.com


    Brought to you by:

    Black Hills Information Security 

    https://www.blackhillsinfosec.com


    ☯️ Introducing BHIS Fusion Penetration Testing
    https://www.blackhillsinfosec.com/fusion-penetration-testing/

    Antisyphon Training

    https://www.antisyphontraining.com/


    Active Countermeasures

    https://www.activecountermeasures.com


    Wild West Hackin Fest

    https://wildwesthackinfest.com

    1 hr 5 min

About Talkin' Bout [Infosec] News

From the publisher's feed

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.

More shows like Talkin' Bout [Infosec] News

Hacked by Hacked

Hacked

191 Listeners

This Week in Tech (Audio) by TWiT

This Week in Tech (Audio)

3,063 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

Talk Python To Me by Michael Kennedy

Talk Python To Me

582 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

420 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

The Jordan Harbinger Show by Jordan Harbinger

The Jordan Harbinger Show

11,965 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners