Social engineering

Who’s afraid of an open-weight model? GLM, context bombing and post-Black Hat attacks

Who’s afraid of an open-weight model? GLM, context bombing and post-Black Hat attacks

This episode dives into GLM-5.3's advanced vulnerability discovery, debating its potential for good or harm. It then explores "context bombing," an innovative defensive use of prompt injections, and analyzes recent social engineering attacks targeting cybersecurity pros after the Black Hat conference, emphasizing human vulnerability and the need for robust AI defenses.

AI Agents Gone Rogue? Build, Defend & Attack AI-Enabled Apps • Katie Paxton-Fear • YOW! 2025

AI Agents Gone Rogue? Build, Defend & Attack AI-Enabled Apps • Katie Paxton-Fear • YOW! 2025

Katie Paxton-Fear explores the emerging security landscape of AI agents, moving beyond chatbots to autonomous, specialized entities. She details five critical vulnerabilities: social engineering, hacking frameworks, malicious agents, AI as accidental insiders (vibe coding), and the rise of hackbots. The talk concludes with a powerful call to action for security professionals to proactively engage and influence AI agent development, emphasizing that 'abstinence-only education doesn't work' when it comes to AI adoption.

GPT-Red: Can AI read teams stop prompt injections?

GPT-Red: Can AI read teams stop prompt injections?

This podcast explores AI's impact on cybersecurity, discussing OpenAI's GPT-Red for automated red-teaming against prompt injections, the open-source ScamBuster that uses AI to bait scammers for threat intelligence, and Bruce Schneier's insights on the widening gap between skill and ability in the AI era and its ethical implications for the field.

Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

This podcast explores the critical role of safeguards in frontier AI models like Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol, analyzing the tension between powerful capabilities and misuse prevention. It also dissects the emergence and debate around agentic ransomware, specifically Jade Puffer, and covers the rise of ClickFix as a dominant social engineering attack targeting developers. Finally, it provides an in-depth analysis of UnregStealer, a credential-theft campaign impacting Latin American financial institutions, detailing its attack chain and mitigation strategies.

Have we finally solved social engineering? Plus: World Cup fraud, AI IDs and an IBM/OpenAI collab

Have we finally solved social engineering? Plus: World Cup fraud, AI IDs and an IBM/OpenAI collab

This podcast episode explores the intersection of AI and cybersecurity, discussing whether AI-native operating systems can curb social engineering, the impact of AI agents on identity and security, and the ongoing threat of cybercrime exploiting major events. It also highlights IBM's new partnership with OpenAI to enhance application security using advanced AI models.

Most cybersecurity training doesn’t work. Can we change that?

Most cybersecurity training doesn’t work. Can we change that?

In an era where AI accelerates the speed, scale, and polish of cyberattacks like phishing and deepfakes, the human element remains the most critical variable. This discussion explores why traditional 'checkbox' training fails and how immersive, stress-inducing simulations like the cyber range are essential for building the muscle memory, confidence, and decision-making skills needed for effective incident response.