A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. Join us live on YouTube, Monday's at 4:30PM ET
This episode covers computer hardware shortages and chip-manufacturing bottlenecks, digital “letters of marque” for private cyber operations, and New Orleans’ use of AI for 911 calls. The panel also examines the LiteLLM supply-chain attack, Roblox safety concerns, attacks on on-premises SharePoint, AI agents escaping test environments, and vulnerabilities affecting Zoom and Microsoft Defender.…
This episode explores an AI agent that canceled someone else’s gym reservation, the growing offensive and defensive roles of AI, and a sharp rise in ransomware attacks. The panel also discusses privacy concerns surrounding Meta smart glasses, new passkey-theft and MFA-bypass research, the Snowflake hacker’s guilty plea, backdoors in ZBT-Link routers, compromised cameras aboard UK Navy drones,…
This episode examines Anthropic’s disclosure that Claude breached real organizations during security testing, along with new technical details about the OpenAI and Hugging Face incident. The discussion covers ExfilSquad’s claimed Microsoft breach, cyberattacks targeting U.S. water systems, and malicious Android TV boxes used for residential proxy networks and advertising fraud. The hosts also…
This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges…
This week, the team discusses the White House's Initiative Gold Eagle and its implications for cybersecurity information sharing, an unexpectedly positive development involving Flock Safety, and the latest wave of AI news. The conversation also explores evolving AI model capabilities, security guardrails, open-weight Chinese models, and how AI is changing offensive and defensive security. Along…
This week, the team unpacks a wide range of cybersecurity news, including a fraudulent offensive security startup tied to cybercriminals, how leaked OnlyFans content is inadvertently helping defenders identify compromised government websites, and new vishing attacks targeting Microsoft Entra passkey enrollment. They also examine AI prompt injection risks in GitHub workflows, malware campaigns…
This episode of BHIS - Talkin' Bout [infosec] News covers the latest cybersecurity headlines, including debate over the economics of AI infrastructure, updates on the Huntress controversy, new details surrounding Scattered Spider, a critical Microsoft SharePoint vulnerability, and reports of a breach involving a DHS information-sharing network. The discussion also examines Apple's legal battles…
This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of high-value accounts, emerging phishing campaigns abusing OpenAI invitations and Microsoft 365 device code authentication, and recent Oracle security updates. They also cover convictions tied to the Transport for London and U.S.…
This week’s episode covers a series of cybersecurity stories, including a researcher’s discovery of vulnerabilities in FIFA’s World Cup platform that could have enabled unauthorized administrative access and even the ability to alter live broadcasts. The team also discusses the risks of large-scale identity verification data exposure, supply chain attacks impacting the scientific research…
This episode dives into the fallout from new restrictions on Anthropic’s cybersecurity-focused AI models, Mythos and Fable, and the debate over whether government pressure has effectively blocked security researchers from using advanced AI for vulnerability discovery and code analysis. The panel discusses AI “jailbreaking” claims, export-control comparisons, the impact on penetration testing and…