A rogue AI model. Keyboard sounds turned into text. Hotel Wi-Fi redirected by attackers. Corey and Marc break down what these threats could mean for security teams.
This week on the podcast, we review HuggingFace's technical write up of their recent run in with a rogue OpenAI model, as well as their CEO's demands from OpenAI in response. We then cover an interesting research whitepaper that describes a side channel attack that could let AI transcribe typed text by an audio recording alone. We end with a threat intelligence report about DNS Poisoning attacks against hotel Wi-Fi systems.
A stolen password should not open the front door to your entire network. Traditional VPNs were built for a different era. Once a user gets in, too much of the network often becomes reachable. That broad, implicit trust gives ransomware exactly what it needs: an entry point, a path to move, and room to spread.
This week on the podcast, we cover the crazy saga that unfolded between the popular open-source AI platform Hugging Face and the frontier AI lab OpenAI. After that, we discuss a recent WordPress remote code execution vulnerability WP2Shell and the research process that Searchlight Cyber followed to uncover it sing artificial intelligence. Finally, we end with a quick analysis of Palo Alto Global Protec's authentication bypass vulnerability CVE-2026-0257.
This week on the podcast we cover the key takeaways from the just-released Cyber Hygiene Report from WatchGuard. After that, we discuss a recent alert from CISA and other international security agencies on state-sponsored attacks against network equipment. We end with an interesting research post on exfiltrating data from Claude's memory.
Every time a client gets breached through a cloud app, it's the MSP who gets the call. Compromised Microsoft 365 accounts, unauthorized AI tools, and misconfigured sharing settings. Attackers aren't breaking in anymore. They're logging in through gaps that your endpoint, firewall, and MDR tools were never designed to see.
This week on the podcast, we review an after action report from CISA on a security incident they responded to back in May. After that, we cover a vulnerability in Amazon's Q Extension for VSCode before covering a research post from Microsoft on Giga Wiper.