This Week in AI Security - 7th May 2026

This Week in AI Security - 7th May 2026

In this episode for May 7, 2026, Jeremy reports from the sidelines of BSides Luxembourg. This week marks a significant shift in AI-driven vulnerability research, moving from source code analysis to the successful reverse engineering of closed-source compiled binaries.

Key Episode Highlights:

  • GitHub Backend RCE: Researchers from Wiz used AI-augmented binary analysis to find an X-stat header injection vulnerability in GitHub’s Git push pipeline, achieving a CVSS score of 8.7 on closed-source code.
  • The "Copyfail" Crisis: A critical Linux security flaw dating back to 2017 was uncovered using AI-assisted tools. The story highlights the tension between automated discovery and the rise of "AI slop" in automated vulnerability disclosures.
  • CISA Patching Mandates: CISA is considering lowering the required "mean time to patch" from 14 days to just 3 days in response to AI’s ability to find vulnerabilities at an "apocalypse" scale.
  • Shadow AI Exposure: A study by Intruder found over 1 million exposed AI services via certificate transparency logs, with 31% of Meta Llama servers requiring zero authentication.
  • Google "Cosmo" Leak: A massive 1.13 GB system-level agent for Android briefly leaked on the Play Store, revealing an autonomous browser agent with deep system permissions.
  • The Criminal Skill Gap: New research from the University of Edinburgh suggests that while AI is boosting professional developers, most cybercriminals currently lack the skills to weaponize AI at a "weaponizable scale".

Shadow AI and unsecured AI models are the new frontier of enterprise risk. 31% of exposed AI servers are operating with zero authentication. Don't let your infrastructure be the next headline. Get full visibility into your AI environment in 15 minutes. Book your FireTail demo: https://www.firetail.ai/schedule-your-demo

Episode Links

https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

https://cyberscoop.com/copy-fail-linux-vulnerability-artificial-intelligence/

https://www.reuters.com/legal/litigation/us-officials-weigh-cutting-deadlines-fix-digital-flaws-amid-worries-over-ai-2026-05-01/

https://venturebeat.com/security/ai-agent-runtime-security-system-card-audit-comment-and-control-2026

https://thehackernews.com/2026/05/we-scanned-1-million-exposed-ai.html

https://www.euronews.com/next/2026/05/05/cybercriminals-gave-ai-a-go-and-came-away-disappointed-study-finds

https://www.bleepingcomputer.com/news/security/learning-from-the-vercel-breach-shadow-ai-and-oauth-sprawl/

https://azat.tv/en/google-cosmo-ai-leak-privacy-safety/https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(113)

This Week in AI Security - 4th June 2026

This Week in AI Security - 4th June 2026

In this week's episode, Jeremy reports live from the sidelines of Infosecurity Europe in London. As state-sponsored actors turn to thousands of automated recursive prompts to weaponize zero-days, the ...

4 Kesä 14min

This Week in AI Security - 28th May 2026

This Week in AI Security - 28th May 2026

In this episode, Jeremy explores how autonomous model execution is completely upending classical software patch cycles and regulatory risk modeling. From Anthropic’s early access model mapping out tho...

28 Touko 14min

Rich Mogull of Cloud Security Alliance

Rich Mogull of Cloud Security Alliance

In this episode of Modern Cyber, host Jeremy sits down with Rich Mogull, the Chief Analyst at the Cloud Security Alliance (CSA). Jeremy and Rich dive straight into the realities of AI-powered engineer...

27 Touko 48min

This Week in AI Security - 21st May 2026

This Week in AI Security - 21st May 2026

In this episode for May 21, 2026, Jeremy looks at the rapidly compressing timeline of AI-driven exploits. From the first live confirmation of an AI-assisted 2FA zero-day to Microsoft's multi-agent "de...

21 Touko 14min

This Week in AI Security - 14th May 2026

This Week in AI Security - 14th May 2026

In this episode for May 14, 2026, Jeremy breaks down a watershed moment in cybersecurity: the first confirmed case of hackers using AI to discover and weaponize a zero-day vulnerability in the wild. W...

14 Touko 14min

This Week in AI Security - 30th April 2026

This Week in AI Security - 30th April 2026

In this episode for April 30, 2026, Jeremy breaks down a week where the "human-in-the-loop" failed spectacularly. From a production environment deleted in just nine seconds to "Abliterated" models pro...

30 Huhti 14min

This Week in AI Security - 23rd April 2026

This Week in AI Security - 23rd April 2026

In this episode for April 23, 2026, Jeremy explores a week where "first principles" in security are being forgotten in the rush to adopt AI. From guessable API endpoints exposing Anthropic’s most powe...

23 Huhti 15min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
rss-rahapodi
psykopodiaa-podcast
mimmit-sijoittaa
rss-oivalluksia-rahasta-elamasta
asuntoasiaa-paivakirjat
rss-rahamania
hyva-paha-johtaminen
rss-lahtijat
pomojen-suusta
rss-startup-ministerio
rss-viisas-raha-podi
rahapuhetta
sijoituspodi
lakicast
rss-porssipuhetta
rss-doulapodi
rss-inhimillisen-johtamisen-dna
rss-inderes-femme
rss-retoriikan-kesakoulu