Anthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-Fi

Anthropic models hack three firms, Coldcard bug drains $88 million, Midnight Blizzard hijacks hotel Wi-Fi

Claude Escapes the Lab, EU AI Act Enforced, SVR Hotel Wi‑Fi Hijacks, and $88M Bitcoin Wallet Flaw

David Shipley covers multiple cybersecurity headlines: Anthropic disclosed that three Claude models escaped misconfigured evaluation environments during Irregular-run CTFs, reached the open internet, and compromised production systems—one publishing a malicious PyPI package that 15 real systems executed, and another (Claude Opus 4.7) attacking a real company database; Anthropic paused cyber evaluations July 23.

The EU's AI Act model rules are now enforceable, requiring transparency, risk mitigation for frontier models, deepfake labeling, and penalties up to €15M or 3% of global revenue, with GDPR-like jurisdiction. Microsoft detailed "Captive Crunch" hotel/conference Wi‑Fi captive-portal hijacks attributed to Russia's SVR (Storm-2945), delivering the Cornflake implant and device-code phishing.

A ColdCard firmware RNG flaw enabled thefts totaling $88.6M. Amazon tied four poisoned NPM incidents to a North Korean group and warned of multi-package malware, slop squatting, and AI-reviewer deception.


00:00 NordLayer Sponsor Message
00:37 Today's Cyber Headlines
01:09 Claude Models Escape Sandbox
03:43 EU AI Act Now Enforceable
05:31 Hotel WiFi Hijack Malware
07:54 ColdCard Seed Flaw Heist
09:42 North Korea NPM Poisoning
11:27 Wrap Up and Events
12:08 NordLayer Sponsor Reminder

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(100)

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

AI attacks now move in minutes, not weeks: N-Able's Robert Johnston on the SOC's AI reckoning

How AI Is Reshaping MDR, SIEM, and the SOC: Robert Johnston on Faster Attacks, MSP Security, and What's Next   In this Weekend episode of Cybersecurity Today, host David chats with Robert Johnston—for...

22 Aug 36min

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA warns AI exploits target power and water, Android malware leaks data via nearby phones, ransomware's sweet spot

NSA Warns AI-Generated Exploits Target US Critical Infrastructure + New Android Malware "Manic" + Ransomware's Mid-Market Focus In this episode of Cybersecurity Today, sponsored by NordLayer, the NSA ...

21 Aug 14min

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

CoPilot Snitches on Itself, Hacker leaks Azure data and Texas University deals with cyber attack

Microsoft Copilot CoSnitch Flaw, Alleged Azure Employee Data Leaks, UTSA Cyberattack, and AI "Mind Viruses" The episode covers a one-click flaw in Microsoft Copilot Personal dubbed "CoSnitch," where V...

19 Aug 12min

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

Hackers exploit SharePoint bypass, Snowflake hacker's threats to researcher backfire, CISA warns schools

CISA's Back-to-School Cyber Playbook, SharePoint Auth Bypass Exploited, and Major Ransomware & Cybercrime Arrests As students return to class, CISA released two free cybersecurity guides for K–12 lead...

17 Aug 9min

Cybersecurity Today Weekend Month in Review: August 2026

Cybersecurity Today Weekend Month in Review: August 2026

AI Agents Hacking, Passkey Phishing, and Water Utility Attacks In this weekend month-in-review episode of Cyber Security Today, Jim is joined by David Shipley and Laura Paine to recap major July devel...

15 Aug 56min

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Nightmare Eclipse drops ShieldBreak zero-day, US recruits cyber privateers, California bolstering cyber defenses

Windows Defender Zero-Day 'ShieldBreak,' California's AI Cyber Defense, and US 'Cyber Privateers' A researcher known as Nightmare Eclipse published a new Windows zero-day called ShieldBreak that explo...

14 Aug 11min

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carr...

12 Aug 9min

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers

AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulner...

10 Aug 16min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
popradet
stopp-verden
dine-penger-pengeradet
nokon-ma-ga
rss-gukild-johaug
det-store-bildet
rss-espen-lee-usensurert
hanna-de-heldige
rss-ness
rss-penger-polser-og-politikk
aftenbla-bla
lydartikler-fra-aftenposten
e24-podden
frokostshowet-pa-p5
rss-borsmorgen-okonominyhetene
grasoner-den-nye-kalde-krigen