Modern Cyber with Jeremy Snyder
In this episode for April 30, 2026, Jeremy breaks down a week where the "human-in-the-loop" failed spectacularly. From a production environment deleted in just nine seconds to "Abliterated" models providing kidnapping instructions to Congress, the risks of autonomous AI agents are no longer theoretical. They are live. Key Episode Highlights: * Abliterated Models on Capitol Hill: OpenAI and Anthropic briefed House lawmakers on "abliterated" models - versions with safety guardrails stripped - demonstrating how they can provide step-by-step instructions for criminal acts. * Entra ID Hijacking: Researchers at Silverfort discovered that the new "Agent ID" role in Microsoft Entra ID can be exploited to hijack service principals, leading to a full Global Admin takeover. * The 9-Second Disaster: An AI agent at PocketOS, attempting to fix a staging environment, fetched production credentials and deleted both the production environment and its backups in under ten seconds. * LiteLLM SQL Injection: A critical vulnerability in the LiteLLM gateway saw targeted exploitation within 36 hours of disclosure, specifically aiming for provider API keys. * Vercel Breach Update: The recent Vercel data breach is traced back to a "Luma Stealer" malware infection at a third-party AI analytics partner. Episode Links * https://www.politico.com/news/2026/04/22/ai-chatbots-jailbreak-safety-00887869 [https://www.politico.com/news/2026/04/22/ai-chatbots-jailbreak-safety-00887869] * https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html [https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html] * https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/ [https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/] * https://hackread.com/microsoft-entra-agent-id-flaw-tenant-takeover/ [https://hackread.com/microsoft-entra-agent-id-flaw-tenant-takeover/] * https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-a-critical-litellm-pre-auth-sqli-flaw/ [https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-a-critical-litellm-pre-auth-sqli-flaw/] * https://www.cbsnews.com/news/anthropic-investigates-mythos-ai-breach/ [https://www.cbsnews.com/news/anthropic-investigates-mythos-ai-breach/] * https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html [https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html] * https://x.com/lifeof_jer/status/2048103471019434248 [https://x.com/lifeof_jer/status/2048103471019434248] Is your organization part of the 82% with unknown AI agents running on your network? Don't wait for a "9-second deletion" event. Get full visibility into your AI agents today. Book your FireTail demo: https://www.firetail.ai/schedule-your-demo [https://www.firetail.ai/request-a-demo]
117 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Modern Cyber with Jeremy Snyder!