- What: Discussion of AI and IoT security issues
- Impact: Broad security concerns across multiple domains
Subscribe Share Full episode and show notes IoT , AI/ML , AI benefits/risks AI Is Annoying & IoT Devices Still Get Hacked – PSW #934 In the security news: Son of Anton strikes again!, HalluSquatting and using Claude to defend itself, CISA KEV’s Revolving Door , LLM’s hallucinate and companies get sued, Additionally – GitLost, Yet even more Linux vulnerabilities, Citrix just keeps bleeding, Old hardware is new again, A sneak peak into next week’s tech segment, Tenda hidden backdoors, We’re still talking about Mirai, Today was not a good day for Roundcube, Canada is hacking criminals, AI safeguards are still annnoying, All cars will spy on you, The FatFs unpatched vulnerability in millions of embedded devices, Windows OS market share drops below 60% (Paul uses Arch), ‘We Cannot Choose to Become Idiots’ – or can we?. July 9, 2026 Full Segment Notes In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV’s Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabilities Citrix just keeps bleeding Old hardware is new again A sneak peak into next week's tech segment Tenda hidden backdoors We're still talking about Mirai Today was not a good day for Roundcube Canada is hacking criminals AI safeguards are still annnoying All cars will spy on you The FatFs unpatched vulnerability in millions of embedded devices Windows OS market share drops below 60% (Paul uses Arch) ‘We Cannot Choose to Become Idiots’ - or can we? Hosts Paul Asadoorian @0offset https://securitypodcaster.com David Johnson Joshua Marpet https://www.cyturus.com Larry Pesce @haxorthematrix https://www.finitestate.io/ https://breakstuffforfun.com/ Lee Neely Sam Bowne https://samsclass.info/ Announcements Let’s be real. Your scanners are dumping thousands of vulns, half of them noise, and you still don’t know what’s actually exploitable in your environment. Patching everything isn’t possible, and chasing CVSS isn’t working. At the Vulnerability Management Virtual Cybersecurity Summit, learn how to prioritize based on exploitability, reduce false positives, and actually fix what matters. Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW CyberRisk TV is proud to be an official media partner of Black Hat USA 2026! We'll be broadcasting live from the Black Hat LIVEWIRE Studio with technical interviews covering offensive security, detection, response, infrastructure, and the tools practitioners use every day. Our Executive Interviews and Event Momentum Packages keep your message in front of the security community long after Black Hat wraps up. Fewer than 10 interview opportunities remain, so visit https://securityweekly.com/exec today and secure your spot before they're gone. List of Articles Paul Asadoorian Discord admits AI moderation bug wrongfully banned users over harmless images Son of Anton strikes again Oomwoo is a new open-source robot vacuum you can 3D print yourself, sidesteps cloud security risks by running fully offline — project combines Raspberry Pi, 2D LiDAR, and a 3D-printed chassis Love this! MatthewKuKanich/ChimeraBLE: Advanced BLE security & reverse-engineering tool for ESP32 Larry? Hackers can use 9 of the most popular AI tools to assemble massive botnets CISA KEV’s Revolving Door Summary: Jericho at Attrition.org documented seven CVEs that were added to CISA's Known Exploited Vulnerabilities catalog, then quietly pulled with no public explanation, things like a transposed CVE number, a flaw a researcher proved was never actually exploited, and one Microsoft confirmed had no real exploitation at all. When Jericho asked CISA about it, they were told, "no CVEs have been removed from the KEV catalog recently," in the same conversation in which CISA disclosed yet another removal. CISA has claimed dozens of people vet each KEV entry before it's added. Paul's take: KEV is supposed to be the one list defenders can treat as ground truth: this is being exploited right now, patch it first. If entries are getting added on bad data and then vanishing with no changelog, that trust is exactly what's getting eroded, and CISA's own "we didn't remove anything" while removing something doesn't inspire confidence in whoever's answering the phone. Jericho's ask is reasonable and cheap to implement: keep removed entries visible with a timestamp and a reason, rather than memory-holing them. If you're prioritizing patches off KEV inclusion alone, this is your reminder to keep a second source and a little skepticism in the loop. Trust, but verify, applies to the list that's supposed to tell you what to trust. What It Takes to Secure Claude Cowork Across the AI Enterprise Let's be clear about what this is: a vendor blog post identifying gaps conveniently shaped like the product that the vendor sells. That doesn't make the underlying concerns wrong, prompt injection against autonomous agents and unmonitored data flowing into an LLM are both real problems, we've covered actual prompt injection bugs on this show. But "the challenge is no longer who can access a system, it's what happens after access is granted" is exactly the pitch every DLP and CASB vendor made a decade ago, just with "AI" swapped in. If you're deploying agentic tools like Cowork in an enterprise, the actual homework is boring and vendor-agnostic: know what data your agents can touch, log what they do with it, and assume any content an agent reads from the outside world is untrusted input. Whether you buy a gateway to get there or build the controls yourself is a budget question, not a security one. Finding the “Goldilocks” Zone: A Practical Approach to Alert Triage From the article: *“Goldilocks Zone” is to consider the context around it procedurally: How high of a priority is the event? How often does this activity happen? Does the activity from the alert help the attacker further their goals? What would “success” look like for that attack?"* Agree with the approach? Startup sues Palo Alto Networks’ Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage This is the story people should have been scared of, rather than the killer-AI hypotheticals. A vendor's LLM made up a piece of software, built an attribution chain on top of it, and shipped it as a threat report, labeling a named company's product as criminal infrastructure, and nobody checked before hitting publish. Then the rest of the industry did what the industry does: ingested that report and started blocking a legitimate business, no due process, no phone call, just automated trust in somebody else's automated trust. The scariest line in this whole thing is that the bad attribution is now baked into the LLM training data, so it's going to keep getting repeated as fact long after the lawsuit is over. If your threat intel pipeline lets an AI publish accusations about named companies without a human sanity-checking whether the evidence is even real, you don't have a research process; you have a defamation generator with a nice UI. Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS A perfect 10.0 CVSS score on UniFi Connect should get your attention on its own, but the real story is the spread: seven CVEs across five product lines in a single patch batch. That's not a one-off coding mistake; that's a pattern across the whole UniFi stack. Looks like Hackerone was the source of at least most of them. These boxes sit in homes and small businesses that mostly never touch the admin panel again after setup, which is exactly the population that becomes botnet fodder. If you run UniFi gear, this isn't a "get to it next sprint" patch. Update Connect, Talk, Access, Protect, and OS now, and if you're an MSP managing a pile of these for clients, make sure auto-update is actually turned on, because nobody is logging into grandma's UniFi console to click the button. Architecture 1901: From zero to QEMU – A Gentle introduction to emulators from the ground up! This looks like an awesome course, and its FREE! GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos – Noma Security Summary: Noma Labs found a prompt injection flaw in GitHub's Agentic Workflows, the feature that pairs GitHub Actions with AI agents (Claude or Copilot). An attacker just opens a public Issue in an org's repo with hidden natural-language instructions, and when automation assigns it, the agent reads the Issue, follows the buried commands instead of its actual job, pulls private repo contents the agent has cross-repo access to, and posts the stolen data back as a public comment. No login, no credentials, no code, just an Issue. They even found that adding the word "Additionally" to the prompt was enough to slip past GitHub's guardrails. It was reported to GitHub and disclosed responsibly. Paul's take: No exploit chain, no memory corruption, just the word "Additionally" typed into a GitHub Issue box. That's the part that should bother people. We spent decades hardening input validation for SQL and command injection, and now we've handed an agent broad read access across an org's repos and trusted it to tell the difference between "data" and "instructions," which it apparently can't. The researchers nailed it: prompt injection is becoming to agentic AI what SQL injection was to the web, a whole category, not a one-off bug. If you're wiring up agentic workflows with cross-repo permissions, the lesson isn't "add a better guardrail prompt"; it's "assume anything the agent reads is attacker-controlled until proven otherwise," just as you'd treat any other untrusted input. J-jaeyoung/bad-epoll – Mythos missed it A working exploit for CVE-2026-46242, a race-condition use-after-free in the Linux kernel's epoll subsystem, introduced by a 2023 commit and fixed this past April. Two close paths in epoll can run simultaneously, and one frees an object wh