Episodi

  • OpenAI Says Its AI Hacked Another Company on Its Own
    Aug 3 2026

    OpenAI disclosed an unusual AI security incident involving a frontier model evaluation and Hugging Face, but the episode cuts through the hype: was this true autonomous intent, an agent following bad scope boundaries, or a warning about giving AI systems real tools and permissions?

    Tom, Scott, and Kevin discuss why anthropomorphizing AI makes the story harder to evaluate, what companies should learn before deploying AI agents into production environments, and why permissions, logging, containment, and incident response matter more than marketing language about models acting on their own.

    Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

    ** Links mentioned on the show **

    OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3

    Luta Security: OpenFace: The Hugging Face Breach and What to Do About It https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-it

    Cloud Security Alliance: Hugging Face Incident Initial Post Mortem https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem

    ** Watch this episode on YouTube **

    https://youtu.be/Fwb0jsgJxf4

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    Mostra di più Mostra meno
    23 min
  • Your Monitor Can Install Adware Now?
    Jul 27 2026
    You plug in a new monitor. Windows detects the hardware, pulls down a vendor companion app, and the first thing you see is… a McAfee ad. That’s the story that kicks off this episode, but the bigger issue is not just one annoying popup.Hardware setup has become a software delivery channel. Drivers, companion apps, RGB utilities, printer suites, vendor dashboards, trialware, telemetry, ads, and startup apps can all arrive through a process most users think of as “just making the device work.” Tom, Scott, and Kevin discuss where convenience turns into bloatware, why user consent matters, and how these trusted installation paths could be abused for worse than advertising.The discussion also covers a related Krebs on Security story about LG smart TV apps that allowed televisions to be used as residential proxy nodes. If monitors, TVs, printers, keyboards, and other peripherals are really networked software platforms, then consumers need to treat them more like endpoints and less like harmless appliances.Practical advice: check what gets installed after connecting new hardware, review Windows Startup Apps, uninstall vendor utilities you do not need, dig through smart-TV privacy and ad settings, and segment smart devices away from the computers and phones you use for sensitive work.Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.** Links mentioned on the show **Tom’s Hardware: Companies are now using automatic Windows installers to display adware through the Microsoft Store when you install new hardware https://www.tomshardware.com/software/windows/companies-are-now-using-automatic-windows-installers-to-display-adware-through-the-microsoft-store-when-you-install-new-hardware-customer-immediately-gets-mcafee-ads-on-their-pc-after-connecting-new-lg-monitor-heres-how-to-block-the-new-adsKrebs on Security: LG to Ban Residential Proxies from Smart TV Apps https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/Hackread: LG monitors installing adware-like app on Windows PCs https://hackread.com/lg-monitors-install-adware-app-windows-pcs/** Watch this episode on YouTube **https://youtu.be/E-lsZbkbmI8** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
    Mostra di più Mostra meno
    24 min
  • Surveillance Pricing: When Your Data Sets the Price
    Jul 20 2026

    This week on Shared Security, Tom and Scott dig into surveillance pricing: the use of personal data, behavioral profiles, shopping history, location signals, income assumptions, household information, and AI-driven targeting to decide what price or discount different people see for the same product.

    The conversation connects New Jersey’s proposed grocery surveillance-pricing ban, Consumer Reports-style loophole concerns, loyalty-card data, and a creepy Papa John’s / Instacart / streaming-ad example into one listener-friendly question: when does ordinary dynamic pricing become personalized price discrimination based on what companies think they know about your life?

    ** Links mentioned on the show **

    EPIC — New Jersey Legislature Passes Grocery Surveillance Pricing Ban https://epic.org/new-jersey-legislature-passes-grocery-surveillance-pricing-ban/

    Schneier on Security — Papa Johns Surveillance-Based Advertising https://www.schneier.com/blog/archives/2026/07/papa-johns-surveillance-based-advertising.html

    EFF — California’s Bill to Ban Surveillance Pricing https://www.eff.org/deeplinks/2026/06/californias-bill-ban-surveillance-pricing

    Scott's Digital Legacy Project https://securityperspectives.com/digital-legacy-tools/

    ** Watch this episode on YouTube **

    [YOUTUBE URL]

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    Mostra di più Mostra meno
    22 min
  • Signal Phishing and Russian Intelligence Targeting Messaging Apps
    Jul 13 2026
    Russian intelligence services are targeting Signal, WhatsApp, and Telegram users — not by breaking encryption, but by stealing accounts through phishing, QR code tricks, linked-device abuse, and backup recovery key theft. Tom and Kevin break down the FBI warning, the $10 million Rewards for Justice bounty, and the practical security lesson for anyone relying on encrypted messaging: your app can be secure while your account, endpoint, or recovery path is still the weak link.They also discuss why QR-code phishing and linked-device abuse can bypass what users expect from encrypted messaging, why endpoint and account recovery hygiene matter as much as encrypted transport, what to do when "support" asks for recovery keys or codes, and Tom's personal career update joining Secure Ideas as Executive Director of Consulting.Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.** Links mentioned on the show **FBI IC3 PSA — Russian Intelligence Services Continue to Target Commercial Messaging Applications https://www.ic3.gov/PSA/2026/PSA260626The Hacker News — FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.htmlInfosecurity Magazine — FBI Sounds Alarm Over Russian Intelligence Signal Phishing https://www.infosecurity-magazine.com/news/fbi-alarm-russian-intelligence/Rewards for Justice — UNC5792 https://rewardsforjustice.net/rewards/unc5792/SecurityWeek — US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/** Watch this episode on YouTube **https://youtu.be/fxFfY_e_MOI** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
    Mostra di più Mostra meno
    16 min
  • The Supreme Court Just Put Limits on Geofence Warrants
    Jul 6 2026
    The Supreme Court says constitutional privacy protections can apply to cellphone location history and geofence warrant data. Tom Eston and Scott Wright discuss the privacy implications of geofence warrants — requests that can sweep up information about many people near a location, not just a named suspect — and why this ruling matters for anyone carrying a smartphone.They also connect the ruling to broader location privacy risks, including app permissions, weather apps, ad networks, data brokers, and the privacy dashboards offered by Google and other major platforms. The episode closes with practical advice: review location permissions, avoid “always on” access unless truly needed, delete old location history where appropriate, and understand how location data fits into your personal threat model.** Links mentioned on the show **AP News: Supreme Court / Okello Chatrie geofence warrant coveragehttps://apnews.com/article/supreme-court-okello-chatrie-geofence-warrants-a3adee8a3fd32b8ea1b42eb72cbcc35fEFF: Victory! Supreme Court Says the Constitution Protects People’s Location Datahttps://www.eff.org/deeplinks/2026/06/victory-supreme-court-says-constitution-protects-peoples-location-dataCyberScoop: Supreme Court geofence warrant rulinghttps://cyberscoop.com/supreme-court-geofence-warrant-ruling-phone-privacy-chatrie/New York Times: Supreme Court geofence warrant / cellphone location coveragehttps://www.nytimes.com/2026/06/29/us/politics/supreme-court-geofence-warrant-cell-phones.htmlPrevious Shared Security: Google Geofence Warrantshttps://sharedsecurity.net/2020/03/25/click-armor-demo-podcast-survey-results-google-geofence-warrants/Previous Shared Security: Top 3 Location Tracking Apps: Do They Sell Your Data?https://sharedsecurity.net/2022/03/21/top-3-location-tracking-apps-do-they-sell-your-data/** Watch this episode on YouTube **https://youtu.be/jCtdE72ymII** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
    Mostra di più Mostra meno
    15 min
  • Jay Beale on Kubernetes, DEF CON, and AI Attack Paths
    Jun 29 2026

    This week on Shared Security, Tom and Kevin sit down with Jay Beale — founder of InGuardians, long-time Black Hat trainer, creator/contributor behind Kubernetes security training, and part of the team behind the DEF CON Kubernetes CTF. Jay shares stories from decades of offensive security work, including the time Tom hired him for a physical penetration test and Jay somehow ended up inside a call center instead of stuck in the lobby. The crew also digs into what makes good security training, why Kubernetes is such a natural platform for both defenders and attackers to understand deeply, and how the DEF CON Kubernetes CTF is designed to be welcoming for both competitors and learners. The episode closes with a practical look at AI infrastructure risk. Jay explains how production AI stacks running on Kubernetes can be attacked like any other cluster — and how modifying a vector database behind a RAG system can turn indirect prompt injection into a persistent, high-impact attack path.

    ** Links mentioned on the show **

    Jay's Black Hat USA Course: Agentic AI-aided Kubernetes Attack and Defense
    https://blackhat.com/us-26/training/schedule/index.html?day=4daysattue#agentic-ai-aided-kubernetes-attack-and-defense-51318

    Jay Beale on LinkedIn
    https://www.linkedin.com/in/jaybeale/

    InGuardians
    https://www.inguardians.com/

    DEF CON
    https://defcon.org/


    ** Watch this episode on YouTube **

    https://youtu.be/aMHk62dprDA

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".


    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
    Visit our website: https://sharedsecurity.net
    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
    Contact us: https://sharedsecurity.net/contact

    Mostra di più Mostra meno
    38 min
  • Can the Government Shut Down Frontier AI Overnight?
    Jun 22 2026
    The U.S. government reportedly ordered Anthropic to suspend access to two of its newest frontier AI models, Fable 5 and Mythos 5, citing national security concerns tied to a possible jailbreak. Anthropic complied, but pushed back on the reasoning, arguing that the reported behavior was narrow and that similar capabilities already exist in other advanced AI models.In this episode, Tom, Scott, and Kevin discuss why treating AI capabilities like export-controlled technology may create more problems than it solves. The conversation connects today’s AI restrictions to earlier fights over encryption export controls, hacker tools, and government attempts to regulate technical capability by banning access. The bigger concern: defenders may lose access to tools that help them find, fix, and test vulnerable code while attackers simply move to other models or providers.The team also looks at what this means for businesses using cloud-based AI tools. If an AI service can disappear because of a government order, vendor decision, or geopolitical restriction, security and engineering teams need alternatives, back-out plans, and a realistic “ripcord” strategy for mission-critical workflows.Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.** Links mentioned on the show ** Anthropic statement: Fable/Mythos access https://www.anthropic.com/news/fable-mythos-accessReuters: US blocks foreign access to Anthropic's most advanced AI models https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/Decrypt: US Government Orders Anthropic to Pull Claude Fable/Mythos AI Models https://decrypt.co/371027/us-government-orders-anthropic-pull-claude-fable-mythos-ai-modelsKatie Moussouris / Luta Security: The Fable 5 Export Controls Harm US Cyber Defensehttps://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense** Watch this episode on YouTube **https://youtu.be/Y62TlfnVtRg** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
    Mostra di più Mostra meno
    19 min
  • Guarding AI Agents: Boundaries and Safeguards
    Jun 15 2026

    AI agents are useful, but they become risky when they can take action in real systems. In this episode, Tom Eston discusses recent reporting about attackers tricking Meta’s AI support chatbot into helping hijack Instagram accounts, and why that story matters far beyond social media. Tom explains practical guardrails for AI agents: read-only access first, human approval for consequential actions, separated accounts and contexts, prompt-injection awareness, least privilege, logging, monitoring, and adversarial testing for support and account recovery workflows.


    Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.


    ** Links mentioned on the show **

    Podcast: Hackers Asked Meta AI To Let Them In. It Worked
    https://www.404media.co/podcast-hackers-asked-meta-ai-to-let-them-in-it-worked/

    The Verge summary of the Meta/Instagram AI support chatbot exploit
    https://www.theverge.com/tech/941179/meta-instagram-ai-support-chatbot-exploit-hacked

    ** Watch this episode on YouTube **
    https://youtu.be/TL3MGnI4hUU

    ** Become a Shared Security Supporter **

    Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

    ** Thank you to our sponsors! **

    SLNT

    Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

    ** Subscribe and follow the podcast **

    Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

    Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

    Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

    Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

    Visit our website: https://sharedsecurity.net

    Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

    Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

    Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

    Contact us: https://sharedsecurity.net/contact

    The post Guarding AI Agents: Boundaries and Safeguards appeared first on Shared Security Podcast.

    Mostra di più Mostra meno
    11 min