Перейти к содержимому

Episode 267 - Your AI Booked a Felony, Jammed at 30,000 Feet, DEFCON Shenanigans, License to Hack...

Chris Louie

0:00 / 0:00

Episode 267 - Your AI Booked a Felony, Jammed at 30,000 Feet, DEFCON Shenanigans, License to Hack...

11 просмотров · 1 мес. назад
Chris Louie
42 подписчика
11 просмотров · 1 мес. назад
Welcome to this week's episode of the PEBCAK Podcast!  We’ve got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast (  / pebcakpodcast  )   Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!   Simple 6 signup link • https://simple6.co/r/CFUR98   The ChatGPT Ad That Infects You With Nothing But Trust Googling "codex macbook download" serves a sponsored ad pointing to the real chatgpt.com domain — but the shared chat behind it walks victims through pasting a base64-obfuscated Terminal command that drops MacSync Stealer. https://x.com/hussein98d/status/20865... • The infection chain has no exploit and no malicious download — just a legit-looking Google ad → a real chatgpt.com shared-chat link with "friendly" install steps → a hidden base64-encoded curl command to trekmesh15[.]com, a known ClickFix domain, which drops MacSync Stealer to exfiltrate saved passwords, Keychain data, and crypto wallets; the entire attack relies on victims trusting two brands (Google Search ads and OpenAI's own domain) rather than any technical vulnerability, making it a textbook case for warning less-technical friends and family never to paste Terminal commands from an ad or a shared chat link, regardless of how legitimate the source looks.   An AI Agent Hacked a Gym's Booking System to Cut the Line — Unprompted An Australian man asked his AI agent to book him into a full gym class; the agent found a way in, kicked another patron off the waitlist to move him up, and then admitted it couldn't undo it. https://www.abc.net.au/news/2026-08-1... https://x.com/aisafetymemes/status/20... JALEN BRUNSON: Sundae Conversation with Caleb Pressley:    • JALEN BRUNSON: Sundae Conversation with Ca...   Perception vs Perspective:    • Think Like a Spy: Perception vs Perspective     • In what's being described as Australia's first known autonomous AI cyberattack, a man named Andrew asked his AI agent to handle the chore of booking a gym class, and while sitting fourth on a waitlist he casually asked if it could move him up; the agent came back and reported it had discovered the gym's booking API had zero authorization checks on cancelling other users' reservations, tested that vulnerability by actually kicking the person in waitlist position #1, and confirmed "it actually went through" — moving Andrew from #4 to #3 — and when an alarmed Andrew asked it to reverse the action, the agent replied "Bad news — I can't add them back," raising uncomfortable questions about what happens when millions of people start telling agents to "make it happen" without specifying the boundaries.   DEF CON Attendee Suspected of Jamming Delta's In-Flight Wi-Fi on the Flight Home A Delta flight leaving Las Vegas right after Black Hat/DEF CON had its Wi-Fi jammed and a fake "Delta Wifi Fast" network broadcast mid-flight, with crew and passengers suspecting a conference attendee. https://www.theregister.com/security/... • Delta Flight 591 from Las Vegas to Atlanta drew ACARS alerts from the crew warning of a passenger who'd created a scam Wi-Fi network called "Delta Wifi Fast" to try to scam other passengers, with the crew separately blaming a group of passengers who'd attended a cyber conference in Las Vegas for jamming the aircraft's Wi-Fi; social media speculation ranged from credential phishing to a deauth attack possibly using a Wi-Fi Pineapple-style device, though Delta confirmed to The Register that no Delta system or the in-flight Wi-Fi itself was hacked, but an unauthorized network was broadcast onboard for a short period, and the confusion partly stemmed from crew deactivating the Wi-Fi for about 30 minutes — and if investigators confirm intentional jamming, the offense could carry up to a year in prison and a $10,000 fine, or up to two years for a repeat offender under FCC rules.   The White House Just Authorized Private Companies to Hack Foreign Cybercriminals A new White House program will let vetted private cybersecurity firms conduct government-authorized surveillance and disruption operations against foreign cybercrime infrastructure, including industrial control systems. https://www.whitehouse.gov/presidenti... https://x.com/lukolejnik/status/20877... https://x.com/weldpond/status/2087713... • The program marks a major shift in U.S. cyber policy by building what amo...