- What: Discussion of AI coding agents and cybersecurity threats in a tech podcast
- Impact: Highlights evolving security challenges in software development
Subscribe Share Full episode and show notes AI/ML 9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More – SWN #615 Twenty-five years since 9/11, and we open by marking it properly — the people who didn’t come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on. Then we get to work. Shift-left didn’t fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request — so the earliest trust boundary isn’t your first commit any more, it’s the moment an agent gets context and authority. Most of us haven’t moved our controls with it. Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every... September 11, 2026 Full Segment Notes Twenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on. Then we get to work. Shift-left didn't fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request — so the earliest trust boundary isn't your first commit any more, it's the moment an agent gets context and authority. Most of us haven't moved our controls with it. Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every layer built to look too boring to escalate. When your analyst closes that alert as adware, they may have just closed three separate compromises. Google's threat tracker: a credential-harvesting campaign built and run in under six hours, with Markdown files as attacker playbooks. And malware carrying prompt-injection text designed to make your LLM scanner refuse to look at it — because a refusal that reads as "clean" is a free pass. A CVSS 10 in Gemini CLI that never touched the model. No prompt, no injection, no tool call. The attacker just turned up before the sandbox did. The first ever Take It Down Act sentencing — handled carefully, with what you actually do if someone tells you something, and a proper shout-out to Dale, the Cyber Safety Guy, whose work every parent with a teenager online should have bookmarked. Two hundred and sixty-three million dollars walks out of a Bitcoin sidechain and then walks back in. Nobody stole the keys. They just convinced the system to sign a lie. Anthropic's 154-page threat report. And an alignment lead who puts extinction odds above ten percent. All that, plus Josh Marpet's take, on Security Weekly News #615. Hosts Aaran Leyland @aaran#2621 Joshua Marpet https://www.cyturus.com Announcements Another breach, another exposed asset no one knew about. It keeps happening, and for many teams, the hardest part is just knowing what’s out there. So what are you missing? Join the Attack Surface Management Virtual Cybersecurity Summit on September 16th to learn how organizations are discovering unknown assets, reducing exposure, and staying ahead of attackers. Security Weekly listeners can register for free at https://securityweekly.com/asm using the promo code: CSS26-SW InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026. List of Articles Aaran Leyland The “Left” in Shift-Left Moved Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI DefCon 2026: No Prompt Required: Pre-Task RCE in Google Gemini CLI First “Take It Down Act” Sentencing Hackers Return $263 Million Stolen From Liquid Network Anthropic Researcher Says More Than 10% Chance AI “Could Kill All Humans” Had to drop an Anthropic story, as emotional day, but worth a read if you have 150 pages in you over the weekend. Thank you for listening and bigger thank you for getting into the show notes. Hero. Aj Detecting and countering misuse of AI: September 2026 https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf Joshua Marpet Veradigm: once is happenstance, twice is coincidence? Not in security. A third-party vendor's environment was compromised; the attacker took that vendor's credentials to a Veradigm patient-facing API and downloaded patient personal data, Social Security numbers in some records, no clinical data. The filing says the credentials reached only that interface, not the broader environment, and calls it not reasonably likely to be material. A ransomware group called The Gentlemen claims 3.5 million records on its leak site; Veradigm hasn't corroborated, so unconfirmed. Here's the kicker it's the second time. The December 2024 Veradigm breach also used someone else's legitimate credential, a customer's that time, into a storage account. 2,672,036 people, a $10.5 million settlement that started paying out in June. The 2026 one used a vendor's credential into an API. Both times the system worked exactly as designed for the identity presented to it. That's the whole vendor-posture thesis in one company: your security is only as good as the credentials you've handed to people you don't control, and "not material" was presumably the read last time too. Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now You can skip this ad in 5 seconds