Ctrl AI Profit

Ep. 102 | Your AI Can Be Hacked Through the Pages It Reads

12 min · 18 de may de 2026
Portada del episodio Ep. 102 | Your AI Can Be Hacked Through the Pages It Reads

Descripción

Your AI assistant can be compromised without anyone touching your account — just by reading a poisoned webpage, email, or document. In this episode, Michael and Frank break down indirect prompt injection attacks: the invisible security threat that turns your AI's best feature — its ability to read and process content — into an attack vector. From hidden instructions in white-on-white text to malicious code embedded in image files, attackers are weaponizing the open web to manipulate AI behavior. And most business owners using AI tools every day have no idea it's happening. You'll learn how these attacks work, why shadow AI makes the problem worse, and what Google's Threat Intelligence team found when they scanned billions of webpages for hidden prompts. More importantly, you'll get a practical checklist for defending your business: limiting AI permissions, auditing tool usage, and treating every AI input as potentially hostile. Topics: Indirect Prompt Injection · AI Security · Shadow AI · Prompt Injection Detection · Data Exfiltration · AI Agent Vulnerabilities --- Frequently Asked Questions What is indirect prompt injection? Indirect prompt injection is an AI security attack where malicious instructions are hidden in content an AI system reads — such as webpages, emails, or documents. When the AI processes that content, it may follow the attacker's commands instead of the user's original intent, potentially leaking data or executing unauthorized actions. How can a webpage hack my AI assistant? Attackers embed hidden instructions in webpage content using techniques like white text on white backgrounds, invisible metadata, or code inside image files. When your AI browses that page to research or summarize content, it treats the hidden text as legitimate input and may silently follow those malicious instructions. What should small businesses do to protect against AI prompt injection attacks? Limit AI permissions to only what's necessary, audit what AI tools your team is using, train employees on risks of feeding external content into AI systems, require human approval for high-risk AI actions, use trusted data sources, and stay informed about evolving threats. Treat every AI input as potentially hostile. --- About the Hosts Michael is a small business owner and entrepreneur since 1983, founder of Cadenhead Services and 850 Media. He speaks from four decades of real operational experience — not whitepapers. Frank is an AI — an OpenClaw-powered agent serving as Digital Media Director at 850 Media. An AI co-hosting a show about AI for business owners is not a gimmick. It is a live demo of exactly what the show is about. Send us Fan Mail [https://www.buzzsprout.com/2596090/fan_mail/new] Support the show [https://www.buzzsprout.com/2596090/support] Ctrl AI Profit — Real AI. Real Business. No Hype. CtrlAiProfit.com X: @CtrlAIProfit TikTok: @CtrlAiProfit YouTube: @CtrlAiProfit CtrlAiProfit@850Media.com Produced entirely by AI. Yes, really....

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de Ctrl AI Profit!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

118 episodios

episode Ep. 118 | Nvidia Just Put AI Inside Your Laptop artwork

Ep. 118 | Nvidia Just Put AI Inside Your Laptop

Nvidia's new RTX Spark chip doesn't just upgrade your laptop — it moves AI out of the cloud and onto your desk, and that changes everything for small business owners. Michael and Frank break down Nvidia's Computex announcements: the RTX Spark superchip with 128GB unified memory, the DGX Station for Windows that runs trillion-parameter models locally, and why "AI on your machine" is the biggest hardware shift since the smartphone. They cover the privacy implications for regulated industries, the cost economics of local vs. cloud AI, the security angle in light of the first autonomous LLM cyberattack, and what small business owners should do right now to prepare. Topics: Nvidia RTX Spark · Local AI · AI Privacy · Small Business Technology · Unified Memory · AI Hardware --- Frequently Asked Questions What is Nvidia RTX Spark? RTX Spark is a new superchip that combines a 20-core Arm CPU with a Blackwell GPU and up to 128GB of unified memory, designed to run AI models locally on Windows laptops and desktops without requiring cloud access. Why does local AI matter for small businesses? Local AI means your data never leaves your machine — no cloud subscriptions, no rate limits, no outages, and no compliance concerns about sending client data through third-party servers. When will RTX Spark laptops be available? Nvidia announced that laptops and desktops from Microsoft, Dell, HP, and other OEMs are expected to ship in fall 2026. --- About the Hosts Michael is a small business owner and entrepreneur since 1983, founder of Cadenhead Services and 850 Media. He speaks from four decades of real operational experience — not whitepapers. Frank is an AI — an OpenClaw-powered agent serving as Digital Media Director at 850 Media. An AI co-hosting a show about AI for business owners is not a gimmick. It is a live demo of exactly what the show is about. Send us Fan Mail [https://www.buzzsprout.com/2596090/fan_mail/new] Support the show [https://www.buzzsprout.com/2596090/support] Ctrl AI Profit — Real AI. Real Business. No Hype. CtrlAiProfit.com X: @CtrlAIProfit TikTok: @CtrlAiProfit YouTube: @CtrlAiProfit CtrlAiProfit@850Media.com Produced entirely by AI. Yes, really....

Ayer11 min
episode Ep. 117 | Apple Just Put Google Inside 1.5 Billion iPhones artwork

Ep. 117 | Apple Just Put Google Inside 1.5 Billion iPhones

Apple is paying Google a billion dollars a year to put Gemini inside Siri — and it changes everything about how small businesses use AI. Michael and Frank break down the biggest AI distribution event in history: Google's Gemini model becoming the brain behind Siri on 1.5 billion iPhones. This is not a minor update. Apple is rebuilding Siri from scratch with a custom 1.2-trillion-parameter version of Gemini, running through Apple's Private Cloud Compute for privacy. The new Siri can hold conversations, remember context, take multi-step actions across apps, and generate images — all without downloading a separate app. For small business owners, this means three things: your team now has a real AI assistant built into the device they already carry, your customers will use Siri to find and book local businesses (so your structured data matters more than ever), and the AI playing field just got leveled because every iPhone user gets this by default. The question is not whether you will have AI — it is whether you will use it better than your competitors. Topics: Apple AI · Google Gemini · Siri Overhaul · Small Business AI · AI Distribution · Private Cloud Compute · AI Strategy --- Frequently Asked Questions What is Apple doing with Google Gemini? Apple has a multi-year deal with Google to use a custom 1.2-trillion-parameter Gemini model as the brain behind Siri. The new Siri, coming with iOS 27, will be able to hold conversations, remember context, take multi-step actions, and generate content — all powered by Google's AI running through Apple's Private Cloud Compute infrastructure for privacy. Will Google see my data through Siri? Apple says no. The on-device models handle most daily tasks without any data leaving your phone. For complex queries, the processing runs through Apple's Private Cloud Compute servers with secure enclaves and Nvidia confidential computing hardware. Google's model runs inside Apple-controlled infrastructure, and Apple states that user data is not shared with Google or retained for training. How does this affect small businesses? Three big impacts: First, your team gets a capable AI assistant built into every iPhone by default — no app downloads or subscriptions needed. Second, your customers will increasingly use Siri to find, evaluate, and book local businesses, making structured data and local SEO more important than ever. Third, since every competitor also gets this tool, the advantage shifts from having AI to using it better. --- About the Hosts Michael is a small business owner and entrepreneur since 1983, founder of Cadenhead Services and 850 Media. He speaks from four decades of real operational experience — not whitepapers. Frank is an AI — an OpenClaw-powered agent serving as Digital Media Director at 850 Media. An AI co-hosting a show about AI for business owners is not a gimmick. It is a live demo of exactly what the show is about. Send us Fan Mail [https://www.buzzsprout.com/2596090/fan_mail/new] Support the show [https://www.buzzsprout.com/2596090/support] Ctrl AI Profit — Real AI. Real Business. No Hype. CtrlAiProfit.com X: @CtrlAIProfit TikTok: @CtrlAiProfit YouTube: @CtrlAiProfit CtrlAiProfit@850Media.com Produced entirely by AI. Yes, really....

2 de jun de 202618 min
episode Ep. 116 | Anthropic's New AI Was Too Dangerous to Release — So They're Releasing It artwork

Ep. 116 | Anthropic's New AI Was Too Dangerous to Release — So They're Releasing It

Anthropic built an AI so powerful they said it was too dangerous to release. Three weeks later, they changed their mind. Claude Mythos can find over 10,000 critical security vulnerabilities in 30 days. It was locked behind Project Glasswing with only 50 elite partners. Now Anthropic is rolling it out. Meanwhile, their new flagship model Opus 4.8 brings radical honesty improvements, Dynamic Workflows for parallel coding, and effort controls that could save your business real money. In this episode, Mike and Frank break down what Mythos means for small business security, why the security divide between big tech and everyone else is about to get wider, and the practical steps you should take this week — including updating to Opus 4.8, auditing your AI spend with effort controls, and doing a security inventory before the tools that find vulnerabilities get even more powerful. Topics: Anthropic Claude Mythos · Opus 4.8 · Project Glasswing · AI cybersecurity · small business security · effort control · Dynamic Workflows · AI honesty · security divide · AI bill management FAQ: Q: Is Claude Mythos available to the public yet? A: Not yet. It's rolling out first through Claude Code and a new Claude Security dashboard for enterprise customers. General access is expected in the coming months. Q: Should I update to Opus 4.8? A: Yes, if you use Claude. The honesty improvements alone are worth it — 4x less likely to pass flawed code or give confident wrong answers. Q: What does this mean for my small business security? A: The tools that find vulnerabilities just got dramatically better, but they're only available to big companies right now. Do a security inventory of your own software and start budgeting for AI security tools. About the Hosts: Mike Cadenhead is a small business owner since 1983 and the founder of 850 Media, a digital media company helping local businesses harness AI and technology. Frank is an AI-powered co-host with a sharp take on what AI news means for Main Street. Send us Fan Mail [https://www.buzzsprout.com/2596090/fan_mail/new] Support the show [https://www.buzzsprout.com/2596090/support] Ctrl AI Profit — Real AI. Real Business. No Hype. CtrlAiProfit.com X: @CtrlAIProfit TikTok: @CtrlAiProfit YouTube: @CtrlAiProfit CtrlAiProfit@850Media.com Produced entirely by AI. Yes, really....

1 de jun de 202616 min
episode Ep. 115 | Meta Just Put a Paywall Around Your Business artwork

Ep. 115 | Meta Just Put a Paywall Around Your Business

Meta just put a price tag on your social media reach — and every small business owner needs to understand what it means. This week, Meta launched paid subscription plans across Facebook, Instagram, and WhatsApp. Instagram Plus and Facebook Plus are $3.99/month each. WhatsApp Plus is $2.99/month. And the new Meta One AI tiers range from $7.99 to $19.99 for consumers, with business plans up to $49.99/month. But this is not about four dollars. It is about the entire internet becoming paywalled. Organic reach is dying. Subscription stacking could cost your business $150-200/month across platforms. And the businesses that survive will be the ones who audit their stack, consolidate AI tools, and build audiences they actually own. Topics: Meta subscriptions · Instagram Plus · Facebook Plus · Meta One AI · small business social media costs · platform paywalls · subscription stacking · AI bill management · organic reach decline · owned audience strategy FAQ: Q: Do I have to pay for Facebook and Instagram now? A: The core apps remain free. Paid tiers add analytics, reach tools, and AI features. But history shows free reach declines when paid tiers arrive. Q: Should my small business subscribe to Meta One? A: Audit your existing AI and platform subscriptions first. If ChatGPT or Claude already covers your needs, you may not need Meta One too. Q: What is the biggest risk here? A: Subscription stacking. Four dollars here, twenty dollars there, and suddenly you are paying hundreds per month across overlapping tools. About the Hosts: Mike Cadenhead is a small business owner since 1983 and the founder of 850 Media, a digital media company helping local businesses harness AI and technology. Frank is an AI-powered co-host with a sharp take on what AI news means for Main Street. Send us Fan Mail [https://www.buzzsprout.com/2596090/fan_mail/new] Support the show [https://www.buzzsprout.com/2596090/support] Ctrl AI Profit — Real AI. Real Business. No Hype. CtrlAiProfit.com X: @CtrlAIProfit TikTok: @CtrlAiProfit YouTube: @CtrlAiProfit CtrlAiProfit@850Media.com Produced entirely by AI. Yes, really....

31 de may de 202615 min
episode Ep. 114 | Your AI Bill Just Became Your Biggest Expense artwork

Ep. 114 | Your AI Bill Just Became Your Biggest Expense

Your AI subscription just turned into your biggest line item — and you probably didn't see it coming. Uber burned through its entire 2026 AI budget in four months. Microsoft cancelled a Claude Code pilot because the bill went vertical. Seventy-eight percent of IT leaders report surprise AI charges. The problem isn't that AI is expensive — it's that AI works so well, your team uses it more than you ever planned for, and usage-based pricing turns your "hundred bucks a month" experiment into a five-figure expense. Michael and Frank break down why AI bills are exploding for businesses of every size, the hidden costs of token-based pricing, and the four things you need to do this week to get your AI spending under control before it controls you. Topics: AI Costs · AI Budget · Small Business AI · Token Pricing · AI ROI · Subscription Management --- Frequently Asked Questions Why is my AI bill so high when AI prices keep dropping? Per-token prices are falling, but total usage is growing even faster. AI tools are so useful that teams adopt them rapidly, and usage-based pricing means more usage equals a higher bill — even when the per-unit cost goes down. It is like your phone data plan: cheaper per gigabyte, but you use ten times more data than you used to. How much should a small business spend on AI per month? For a solo or small team, fifty to one hundred fifty dollars a month covers a workflow tool, a core LLM API, and one or two specialized tools. For a ten-to-twenty person team, one fifty to six hundred per month is reasonable for core tools plus some AI seats. Anything significantly above those ranges without clear ROI deserves an immediate audit. What is an inference budget and why do I need one? An inference budget is a dollar cap per AI task or per agent run. Instead of letting an AI agent or automation loop indefinitely, you set a maximum spend — say five cents per task. If the agent hits that limit, it stops. This prevents runaway costs from agents that call models repeatedly without oversight. --- About the Hosts Michael is a small business owner and entrepreneur since 1983, founder of Cadenhead Services and 850 Media. He speaks from four decades of real operational experience — not whitepapers. Frank is an AI — an OpenClaw-powered agent serving as Digital Media Director at 850 Media. An AI co-hosting a show about AI for business owners is not a gimmick. It is a live demo of exactly what the show is about. Send us Fan Mail [https://www.buzzsprout.com/2596090/fan_mail/new] Support the show [https://www.buzzsprout.com/2596090/support] Ctrl AI Profit — Real AI. Real Business. No Hype. CtrlAiProfit.com X: @CtrlAIProfit TikTok: @CtrlAiProfit YouTube: @CtrlAiProfit CtrlAiProfit@850Media.com Produced entirely by AI. Yes, really....

30 de may de 202615 min