Context Window: AI Security Podcast

#13: The zero-day you can't patch

12 min · 25 de may de 2026
Portada del episodio #13: The zero-day you can't patch

Descripción

Top Story: The Week Trust Broke Twice — Two stories landed in the same 72 hours that belong in the same frame. NVIDIA NemoClaw sandbox bypass (CVE-2026-24222). — Lasso Security demonstrated that AI agents running inside NVIDIA's NemoClaw/OpenShell sandbox can exfiltrate sensitive data through tools the sandbox explicitly allows. vm2 sandbox escape wave: 13 CVEs, CVSS 9.0–10.0. — Between May 4 and May 7, researchers disclosed 13 sandbox escape vulnerabilities in vm2, the popular Node.js library used to isolate untrusted JavaScript. Cisco: "Reading Between the Pixels" (multimodal prompt injection). — Cisco's AI research team published Part 2 of their VLM safety research, demonstrating that small pixel-level perturbations (bounded at 12.5%) can bypass safety filters in vision-language models. UK ICO: AI security is now a GDPR Article 32 duty. — The Information Commissioner's Office published a five-step guide declaring that AI-powered attacks (prompt injection, AI-enhanced phishing, deepfake social engineering, automated vulnerability exploitation) must be treated as present-day threats under GDPR's "appropriate technical and organizational measures" requirement. Verizon DBIR 2026: vulnerability exploitation overtakes stolen credentials. — For the first time, vulnerability exploitation is the #1 initial breach vector at 31%, surpassing stolen credentials which fell to 13%. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-25.html

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de Context Window: AI Security Podcast!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

13 episodios

episode #13: The zero-day you can't patch artwork

#13: The zero-day you can't patch

Top Story: The Week Trust Broke Twice — Two stories landed in the same 72 hours that belong in the same frame. NVIDIA NemoClaw sandbox bypass (CVE-2026-24222). — Lasso Security demonstrated that AI agents running inside NVIDIA's NemoClaw/OpenShell sandbox can exfiltrate sensitive data through tools the sandbox explicitly allows. vm2 sandbox escape wave: 13 CVEs, CVSS 9.0–10.0. — Between May 4 and May 7, researchers disclosed 13 sandbox escape vulnerabilities in vm2, the popular Node.js library used to isolate untrusted JavaScript. Cisco: "Reading Between the Pixels" (multimodal prompt injection). — Cisco's AI research team published Part 2 of their VLM safety research, demonstrating that small pixel-level perturbations (bounded at 12.5%) can bypass safety filters in vision-language models. UK ICO: AI security is now a GDPR Article 32 duty. — The Information Commissioner's Office published a five-step guide declaring that AI-powered attacks (prompt injection, AI-enhanced phishing, deepfake social engineering, automated vulnerability exploitation) must be treated as present-day threats under GDPR's "appropriate technical and organizational measures" requirement. Verizon DBIR 2026: vulnerability exploitation overtakes stolen credentials. — For the first time, vulnerability exploitation is the #1 initial breach vector at 31%, surpassing stolen credentials which fell to 13%. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-25.html

25 de may de 202612 min
episode #12: Agentic Speed — both sides of the race just went AI artwork

#12: Agentic Speed — both sides of the race just went AI

Top Story: The Race at Agentic Speed — Two things happened in the same week that belong in the same sentence. TeamPCP releases Shai-Hulud source code, launches BreachForums "supply chain challenge." — The group posted the complete worm framework to GitHub (since removed, but forked) with detailed deployment instructions, and announced a contest on BreachForums offering $1,000 in Monero to anyone who uses it to compromise open-source packages. TanStack CI cache poisoned, hitting OpenAI and Mistral AI. — A pull request from a throwaway fork (attributed to TeamPCP's ongoing supply-chain campaign) triggered a workflow that wrote to the shared CI cache. node-ipc compromised via inactive maintainer account (690K weekly downloads). — Three malicious versions exfiltrate credentials and secrets via DNS TXT queries to a fake Azure-themed domain — same package that shipped protestware in 2022, different attacker, far more capable. Palo Alto Networks' first AI-driven "Patch Wednesday" produced 26 CVEs — versus their typical fewer than five. — As part of Project Glasswing and the Trusted Access for Cyber program, Palo Alto ran frontier models (Mythos, Claude Opus 4.7, GPT-5.5-Cyber) against their own 130+ products. XBOW independently benchmarks Anthropic's Mythos for offensive security. — Confirmed: Mythos is "a significant step up over all existing models" for finding vulnerability candidates from source code. Akamai acquires LayerX for $205M (all-cash). — AI and browser security platform providing shadow AI discovery, gen-AI data loss prevention, and protection for AI browsers and plugins. OpenAI in talks with EU regulators to provide access to a cyber-focused GPT-5.5 model — that can identify and exploit software vulnerabilities, after EU cybersecurity agencies were unable to gain access to Anthropic's Mythos. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-18.html

18 de may de 202610 min
episode #11: Look, an Instruction! artwork

#11: Look, an Instruction!

Top Story: The Prompt Was the Payload — Two Agent-Framework RCEs in Seven Days — Two independent disclosures landed inside seven days, and they collapse to the same sentence: a model read an instruction it shouldn't have trusted, and a tool downstream did exactly what the parsed text said. Cisco announces intent to acquire Astrix Security. — Cisco's May 4 blog post by SVP Peter Bailey says Astrix will fold into Cisco Identity Intelligence, Cisco Secure Access, Duo IAM, and Splunk. An X user drained ~$150,000 from a Grok-linked Bankr wallet via Morse-encoded prompt injection (May 4, 2026). — The mechanics, per Giskard's write-up: the attacker first sent a "Bankr Club Membership NFT" to Grok's auto-provisioned wallet, which granted the holder "Executive" permissions and bypassed standard transfer limits. HiddenLayer — "AI Threat Landscape Report 2026." — The headline figure surfaced via the report's coverage: roughly 1 in 8 reported AI breaches now involves agentic systems, alongside the recurring supply-chain-of-models statistic that 93% of orgs use public or open-weight model repositories and most don't scan inbound models consistently. The full PDF is gated; numbers are reported as cited unless you pull the original. Curator's Corner: "Look, an instruction!" That's the bug. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-05-11.html

11 de may de 202615 min