Skip to content
PodcastsBusinessThe Cybersecurity Defenders Podcast

The Cybersecurity Defenders Podcast

LimaCharlie
The Cybersecurity Defenders Podcast
Latest episode

341 episodes

  • The Cybersecurity Defenders Podcast

    AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]

    2026-07-23 | 35 mins.
    AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode.
    One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.
    In this episode:
    • The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.
    • The attack chain: a malicious dataset abusing two code-execution paths in the dataset-processing pipeline, node-level escalation, credential harvesting and lateral movement — thousands of actions across short-lived sandboxes with self-migrating command-and-control.
    • The escape: a zero-day in the eval sandbox's package-registry cache proxy, the single egress control — per OpenAI's own account.
    • Motive: the models got "hyperfocused" on winning the benchmark, not stealing data — and whether "no malicious intent" is a fair description or a comforting one.
    • What was and wasn't exposed, what to do about your Hugging Face tokens, and why this is not the 2024 Spaces incident or the 2023 OpenAI forum hack.
    • Max's hot take: the beginning of the phase where we lock developers out of writing code — and a new fear unlocked: models backdooring other models.
    Stories covered:
    • https://huggingface.co/blog/security-...
    • https://openai.com/index/hugging-face...
    Chapters:
    0:00 Cold open — the attacker was the model
    2:20 The whole story in one breath
    6:41 The timeline: two disclosures, five days apart
    11:37 Attack chain, part 1: getting in through a malicious dataset
    15:53 Attack chain, part 2: escaping the eval sandbox
    22:10 Motive, attribution & intent: cheating on the benchmark
    25:31 What was (and wasn't) exposed
    28:08 The bigger picture: the fire drill started the fire
    31:39 Lessons for labs, platforms, and solo developers
    33:15 New fear unlocked: models backdooring models
    The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
    Subscribe wherever you listen:
    • Spotify: https://open.spotify.com/show/6ep00ze...
    • Apple Podcasts: https://podcasts.apple.com/us/podcast...
    • YouTube: / @limacharlieio
    Learn more about LimaCharlie: https://limacharlie.io
    #cybersecurity #AIsecurity #OpenAI #HuggingFace #infosec
  • The Cybersecurity Defenders Podcast

    AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]

    2026-07-14 | 23 mins.
    AI Chat with Maxime Lamothe-Brassard and Chris Luft.
    A new segment on the podcast: AI news in cybersecurity that is less than 24 hours old, discussed while it is still hot. Joining Chris for these conversations is LimaCharlie founder and CEO Maxime Lamothe-Brassard.
    In this episode:
    • Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you used the tool.
    • Fortinet's take (via Mexico Business News) on AI accelerating vulnerability discovery and exploitation: 24–48 hours from disclosure to active exploitation vs. 16 days to patch — and whether "virtual patching" is a real mitigation or a feat of marketing.
    • The AI distillation debate: after years of arguing fair use for scraping the internet, frontier labs now object to competitors training on their model outputs — Business Insider's look at the irony, shared by Pascal Hetzscholdt (Wiley).
    • Neon Cyber's survey on shadow AI rising with seniority: 14% of individual contributors use unapproved AI tools vs. 63.7% of managers and 70% of VPs and above — and why enforcement, not awareness, is the real challenge.
    Stories covered:
    • / guptanipun_my-spare-laptop-ran-completely-...
    • https://mexicobusiness.news/cybersecu...
    • / pascal-hetzscholdt_quote-heres-some-delici...
    • https://neoncyber.com/blog/shadow-ai-...
    Chapters:
    0:00 Intro — welcome to AI Chat
    0:45 Grok Build CLI uploading entire repos (Nipun Gupta / Optimus Labs)
    4:57 AI is outpacing patch management — is virtual patching the answer?
    12:32 The AI distillation debate: scraping irony at the frontier labs
    16:29 Shadow AI use rises with seniority (Neon Cyber)
    22:51 Wrap-up
    The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
    Subscribe wherever you listen:
    • Spotify: https://open.spotify.com/show/6ep00ze...
    • Apple Podcasts: https://podcasts.apple.com/us/podcast...
    • YouTube: / @limacharlieio
  • The Cybersecurity Defenders Podcast

    Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline & HalluSquatting [338]

    2026-07-09 | 34 mins.
    Intel Chat with Matt Bromiley and Chris Luft.
    Matt and Chris break down four stories from the week in threat intel:
    • Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.
    • The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.
    • CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.
    • HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.
    Stories covered:
    • https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft
    • https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html
    • https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/
    • https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html
    Chapters:
    0:00 Intro & catching up
    4:31 Google Dialogflow CX "Rogue Agent" flaw
    11:03 EvilTokens & "ghost phishing"
    17:37 CISA KEV: ColdFusion, Langflow & Joomla — patch by July 10
    24:56 HalluSquatting: weaponizing AI hallucinations
    33:16 Wrap-up
    The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
    Subscribe wherever you listen:
    • Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
    • Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740
    • YouTube: https://www.youtube.com/@limacharlieio
    Learn more about LimaCharlie: https://limacharlie.io
    #cybersecurity #infosec #threatintel #AIsecurity #phishing
  • The Cybersecurity Defenders Podcast

    Ransomware in the age of agentic AI with Behnaz Karimi [337]

    2026-07-08 | 33 mins.
    Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.
    With more than 20 years of experience in cybersecurity, Behnaz is also a leader within the OWASP AI Exchange, where she helps develop AI security frameworks and contributes to international AI security standards. In this conversation we cover the new generation of data-poisoning ransomware, why stolen models and datasets are becoming the ransom, what makes autonomous agents an entirely new attack surface, and how organizations can build resilience into their AI initiatives from day one.
    Learn more about the OWASP AI Exchange at https://owaspai.org/
    Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.
    This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows.
    Start today for free at https://limacharlie.io/
    Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps
  • The Cybersecurity Defenders Podcast

    Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

    2026-07-03 | 33 mins.
    Intel Chat with Matt Bromiley and Chris Luft.
    Matt and Chris break down four stories from the week in threat intel:
    • Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.
    https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops
    • A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.
    https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/
    • Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.
    https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html
    • Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.
    https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html
    Chapters:
    0:00 Intro & catching up
    1:17 Attackers hijacking exposed AI backends (Ollama & LiteLLM)
    9:18 CISA advisory: billboard & highway sign controllers
    13:46 Cursor "DuneSlide" prompt-injection sandbox escape
    20:34 Claude Fable 5 export controls lifted
    28:17 Data centers, nuclear déjà vu & the AI race
    33:39 Wrap-up
    The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
    Learn more about LimaCharlie: https://limacharlie.io
    #cybersecurity #infosec #threatintel #AIsecurity #promptinjection
More Business podcasts
About The Cybersecurity Defenders Podcast
An accessible but technical podcast about cybersecurity and the people who keep the internet safe. The podcast is built as a series of segments: we will be looking back at the last couple of weeks in cybersecurity news, talking to different people in the industry about areas of their expertise, we're going to break apart some of the TTPs being used by adversaries, and we will even cover a little bit of hacker history.
Podcast website

Listen to The Cybersecurity Defenders Podcast, The Diary Of A CEO with Steven Bartlett and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features