AI gets hacked, and BitLocker gets bypassed

AI gets hacked, and BitLocker gets bypassed

What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told.

Meanwhile, someone calling themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of which lets a thief with a USB stick walk straight past BitLocker. Microsoft is furious.

Plus don't miss our featured interview with Son Nguyen Kim of Proton Pass, who explains why plugging AI agents into your email and calendar without thinking twice is rather like hiring a new employee with the keys to everything - and skipping the background check.

All this and more in episode 472 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.


EPISODE LINKS:




SPONSORS:

  • Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.
  • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
  • CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.



SUPPORT THE SHOW:

Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


FOLLOW THE SHOW:

Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


THANKS:

Theme tune: "Vinyl Memories" by Mikael Manvelyan.

Assorted sound effects: AudioBlocks.



Privacy & Opt-Out: https://redcircle.com/privacy

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(483)

Never say this to a robot dog

Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a P...

19 Aug 45min

This is the AI service you should never sign up to

This is the AI service you should never sign up to

Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fr...

12 Aug 45min

How a fake police officer nearly stole Graham's cryptocurrency

How a fake police officer nearly stole Graham's cryptocurrency

Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrenc...

5 Aug 59min

This job interview could destroy your company

This job interview could destroy your company

You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is iro...

29 Jul 58min

How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken...

22 Jul 50min

Remote-control rickshaws and rogue book marketers

Remote-control rickshaws and rogue book marketers

An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and L...

15 Jul 38min

JadePuffer - the AI that ran a ransomware attack all by itself

JadePuffer - the AI that ran a ransomware attack all by itself

A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic A...

8 Jul 46min

Polymarket can predict the future. So how did it miss this hack?

Polymarket can predict the future. So how did it miss this hack?

Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the cu...

1 Jul 42min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
popradet
stopp-verden
nokon-ma-ga
dine-penger-pengeradet
lydartikler-fra-aftenposten
det-store-bildet
rss-espen-lee-usensurert
hanna-de-heldige
rss-gukild-johaug
rss-ness
aftenbla-bla
e24-podden
frokostshowet-pa-p5
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
grasoner-den-nye-kalde-krigen