Black Hills Information Security Podcasts.
We love to share our knowledge with those that want to learn and share their knowledge with others. 

Find our podcasts on your favorite player.

Latest Episodes

Anthropic Warns Users of Infostealer Abuse - 2026-09-08

AI agents take center stage as the team examines OpenAI models using a German forum for private communications, Anthropic’s response to a compromised Claude account, new model releases, and the growing demand for Apple hardware to train computer-using agents. The discussion also covers the sale of stolen driver’s licenses, a claimed Florida DMV breach, and vulnerabilities affecting JFrog Artifactory, Proxmox, Plex, and Langflow. Finally, the panel considers CISA’s decision to discontinue six cybersecurity assessment services, new research into compromising passkeys, and Outflank’s compact NTLMv1 rainbow tables. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters Links OpenAI Agents Exploit a German Forum for Private Communications Anthropic Warns a User About Infostealer Abuse of Their Claude Account OpenAI’s Latest Model Tops AI Leaderboards and Revives the AGI Debate CrowdStrike Releases AI Models Developed with NVIDIA FBI Investigates the Sale of 103,000 Stolen Driver’s Licenses ShinyHunters Claims a Breach of the Florida DMV AI Labs Amass Mac Minis and Mac Studios for Agent Training Critical Authentication Bypass Disclosed in JFrog Artifactory Proxmox Vulnerability Exposes Internet-Facing Hosts New Plex Vulnerability Raises Home-Network Security Concerns Langflow Vulnerability Enables Unauthenticated Remote Code Execution Thomson Reuters Breach Disrupts State Court Systems CISA Cuts Six Free Cybersecurity Assessment Services New Research Demonstrates Ways to Compromise Passkeys Outflank Publishes a Smaller NTLMv1 Rainbow Table and Cracking Tool Dan DeCloss: Turning Pen Tests into Risk Intelligence Anti-Cast Charles Shirer Introduces the FanMeyer Creator Platform Upcoming AI Browser Research and Wild West Hackin’ Fest Talk Hacking and Defending Satellite Infrastructure at Wild West 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com

Data Becomes Code | Episode 68

What happens when AI coding agents treat vendor documentation as trusted instructions? Bronwen Aker and Derek Banks examine research showing how unclaimed package names and domains referenced in LLMs.txt files could lead coding agents to download and execute unintended code. They discuss how this AI-driven supply chain risk builds on familiar security problems, including dependency confusion, indirect prompt injection, and excessive permissions. The conversation also covers responsibility for AI-generated code, OpenAI’s cybersecurity proposals, and practical protections such as sandboxing, containerization, least privilege, network monitoring, and human oversight. LINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com

South Korea Offers Free AI Services – 2026-08-31

This episode of BHIS - Talkin' Bout [infosec] News covers South Korea’s free government AI services, new efforts to secure the U.S. power grid from foreign-made components, and the use of SS7 and fitness-tracking data in military operations. The panel also discusses the FBI’s disruption of Chinese botnets targeting critical infrastructure, the alleged McKesson patient-data breach, arrests connected to Team PCP, and reports of NVIDIA acquiring Hugging Face. Additional topics include competition among AI coding platforms, critical vulnerabilities affecting Ubiquiti, Gitea, NetScaler, WebLogic, and PaperCut, and calls for an AI-powered surge in cyber defense. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters Links South Korea Offers Free Government AI Services White House Targets Foreign Components in the U.S. Power Grid How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved Iranian Cyberattackers Tracked Phones of U.S. Military Personnel, Data Suggests The Strava Heat Map and the End of Secrets Officer reportedly leaks location of French aircraft carrier with Strava run FBI Disrupts Chinese Botnets Targeting Critical Infrastructure ShinyHunters Claims Theft of 284 Million McKesson Records Alleged Team PCP Hackers Arrested in Australia Rumored NVIDIA Acquisition of Hugging Face OpenAI, Cursor, and Competition Between AI Coding Platforms Critical Vulnerabilities in Ubiquiti, Gitea, NetScaler, and More PaperCut warns of NG, MF flaw exploited in zero-day attacks Technology Companies Call for an AI Defensive Surge 58 arrested in international cybercrime crackdown How to start the AI-accelerated defense TRAINING: Fundamentals of Cybersecurity: Threats and Defenses TRAINING: Hacking and Defending Satellite Infrastructure 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com

Who is Responsible for an AI-Caused Breach? | Episode 67

This episode of AI Security Ops explores a growing question in AI security: who is responsible when an autonomous AI agent causes a real-world security breach without direct human instruction? Host Brian Fehrman examines reported incidents involving major AI labs, discusses how existing concepts such as liability, negligence, and intent may apply to AI-driven attacks, and considers the legal and security challenges organizations face as agentic AI systems become more capable. The episode highlights why responsibility for AI-caused harm remains an open question and what it could mean for the future of cybersecurity and regulation. Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com

Using AI to Debug the Linux Kernel - 2026-08-24

This episode examines the alleged GTA 6 leak and Rockstar’s efforts to identify the leaker, a Flock Safety critic’s unconventional response to being barred from its conference, and Linus Torvalds’ use of AI to debug Linux. The discussion also covers ShinyHunters targeting ReliaQuest, “security through antiquity,” AliExpress using silent audio for browser fingerprinting, and invisible watermarks in Microsoft Paint’s AI-generated images. Additional stories include an Iran-linked cyberattack that disrupted a UK power plant, prompt injection hidden in a legal filing, and a cyberattack against an Australian chicken-processing facility. Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team. https://www.youtube.com/@BlackHillsInformationSecurity Chat with us on Discord! - https://discord.gg/bhis 🔴live-chat Chapters Links Story # 1 : Rockstar Pursues GTA 6 Leaker Through Microsoft and Discord Story # 2: Flock Conference Bars Critic Who Then Intercepts Its Wireless Audio Story # 3: Linus Torvalds Uses AI to Debug the Linux Kernel Story # 4: ShinyHunters Targets ReliaQuest Employees with Social Engineering Story # 5: Can Obsolete Technology Provide “Security Through Antiquity”? Story # 6: AliExpress Uses Silent Audio for Browser Fingerprinting Story # 7: Darth Vader defends Flock cameras to San Diego City Council Story # 8: Microsoft Paint Embeds Watermarks in AI-Generated Images Story # 9: Iran-Linked Cyberattack Shuts Down a UK Power Plant Story # 10: Hidden AI Prompt Injection Discovered in a Legal Filing Story # 12: Australian Chicken Processing Plant Taken Offline by Cyberattack Fundamentals of Cybersecurity: Threats and Defenses Course Authored by Doc Blackburn. Practical iOS Application Security Testing Course Authored by Cameron Cartier and David Blandford. 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits  https://poweredbybhis.com Brought to you by: Black Hills Information Security  https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com

Hosts

Ben Bowman

Ben Bowman

Host of AI Security Ops
Brian Fehrman

Brian Fehrman

Host of AI Security Ops
Bronwen Aker

Bronwen Aker

Host of AI Security Ops
Derek Banks

Derek Banks

Host of AI Security Ops