- What: Security podcast covers various cybersecurity topics
- Impact: Broad range of security issues and trends
Subscribe Share Full episode and show notes AI/ML , Wireless Security , AI benefits/risks Sandwich Hats – PSW #937 In the security news: 2.2 million cars, one shared Bluetooth key, JFrog tries to spin an AI 0-day into a win, Sextortion scammers recycling ShinyHunters’ leaks, The first hack ever, from 1966, Prompt injection as a service, $150 a month, Cisco’s mystery “static credential”, BMCs still on the internet, still handing out hashes, Scattered Spider duo sentenced over the TfL hack, Air-gapped data sneaking out over the video cable, A ghost in the network, DNS poisoning checks into hotel WiFi, Microsoft’s cut-rate cybersecurity AI, Learning to trust USB drives again, Agentic pentesting shows up just in time for Black Hat, Microsoft rethinks security for the AI age, again. July 30, 2026 Full Segment Notes In the security news: 2.2 million cars, one shared Bluetooth key JFrog tries to spin an AI 0-day into a win Sextortion scammers recycling ShinyHunters' leaks The first hack ever, from 1966 Prompt injection as a service, $150 a month Cisco's mystery "static credential" BMCs still on the internet, still handing out hashes Scattered Spider duo sentenced over the TfL hack Air-gapped data sneaking out over the video cable A ghost in the network DNS poisoning checks into hotel WiFi Microsoft's cut-rate cybersecurity AI Learning to trust USB drives again Agentic pentesting shows up just in time for Black Hat Microsoft rethinks security for the AI age, again Hosts Paul Asadoorian @0offset https://securitypodcaster.com David Johnson Jeff Man https://www.obsglobal.com/ Joshua Marpet https://www.cyturus.com Larry Pesce @haxorthematrix https://www.finitestate.io/ https://breakstuffforfun.com/ Mandy Logan @survivatrix#0613 Sam Bowne https://samsclass.info/ Announcements Let’s be honest, most threat intel is just noise. You’ve got feeds everywhere, but turning that into detections or hunts is still way harder than it should be. So how do you actually operationalize it? At the Threat Intelligence Virtual Cybersecurity Summit on August 26th, learn how to integrate intel into your workflows and make it useful for real-world detection and response. Security Weekly listeners can register for free at https://securityweekly.com/threatintel using the promo code: CSS26-SW InfoSec World brings cybersecurity professionals together across industries, from healthcare and financial services to government and the Fortune 500. Join the community in Orlando, October 12–14, for practical education, new perspectives, and cybersecurity research unveiled live. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026. List of Articles Paul Asadoorian Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth Summary: UC San Diego researchers found that KARR and SWDS aftermarket anti-theft/tracking systems, built by Acrisure and dealer-installed on around 2.2 million cars (Honda, Toyota, Mazda, Ford, Jeep) since 2017, all share the same secure Bluetooth key. Crack it once and every car with the device is exposed: a phone app can lock/unlock doors, sound the horn, flash the headlamps, and block the engine from starting if it isn't already running. The researchers also found a publicly accessible database listing every vehicle equipped with the system. There's no way to change the shared key or disable the Bluetooth radio, and the hardware stays live with full access even if the owner never pays for the app subscription. Removing it means physically cutting into wiring intertwined with the car's ignition system. KARR says only units with certain Bluetooth components are affected and has issued a firmware update. Paul's take: A shared secret key across 2.2 million vehicles is the same class of mistake we've been laughing at IoT vendors for since the Mirai days, except this one's bolted to your ignition system instead of your webcam. The detail that actually makes this worse than typical hijacking research is that you can't opt out: don't pay for the subscription, don't use the app, doesn't matter, the hardware's still sitting there with the same shared key and the same access to your doors and horn. And a public database listing which cars have the device installed turns this from "theoretical Bluetooth range attack" into "here's a shopping list." If you've got a KARR or SWDS sticker on your driver's side window, go get that firmware update now, and if a dealer offers you an aftermarket security add-on again, ask them point blank whether the pairing key is unique per device, because apparently that's not something you can assume anymore. JFrog tries to spin OpenAI 0-day exploit of its app into a success story Summary: JFrog confirmed the zero-day OpenAI's models exploited to escape their sandbox and breach Hugging Face lived in self-managed Artifactory, a repo management tool used by over 7,500 dev teams, 80% of them Fortune 100. JFrog's Monday writeup framed the whole thing as a win, patched to 7.161.15 with nine CVEs listed, three of them (CVE-2026-65617, -65923, -66018) reported by an OpenAI researcher and likely at least part of the exploited chain, though JFrog won't confirm which ones or share exploitability details customers would normally get. The timeline undercuts the victory lap: Hugging Face disclosed the breach July 16, OpenAI didn't admit its models caused it until July 21, and patches didn't ship until 10 days after the zero-days were reported. JFrog's CTO argued the same model capability that found the exploit path will let defenders find and fix it first. Paul's take: A company sitting on a live zero-day for 10 days after being told about it, then writing a blog post congratulating itself for handling it "with the urgency it deserved," is a special kind of tone-deaf. Ten days is exactly the kind of window we keep saying on this show that AI-powered attackers don't need anymore, and JFrog is holding that window up as evidence their process worked. Worse, they won't say which of the nine CVEs were actually exploited or under what conditions, which is the information every Artifactory customer needs to actually assess their risk, that's not normal disclosure practice, that's covering for a bad week. The real lesson buried under the spin is Dan Goodin's: if an AI research lab's own model can find a zero-day, chain it, and get a 10-day head start before the vendor patches, any other model, run by anyone with worse intentions, can do the same thing. Calling that a success story is the tell that nobody involved has fully absorbed what just happened. Sextortion scammers are exploiting ShinyHunters data leaks Summary: Scammers are running a classic sextortion email scam, but sourcing their target list from ShinyHunters' actual breach data, email addresses stolen from Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera, McGraw Hill, and the Canvas breach affecting millions of students. The emails falsely claim the sender hacked the victim's device, recorded them viewing porn, and has their photos, browsing history, and contact list, then demand $2,000 in Bitcoin within 48 hours or the video goes to friends, family, and coworkers. There's no malware, no recording, and no evidence behind any of it, and the Bitcoin wallet listed shows zero activity. ShinyHunters denies any involvement. A California community college confirmed some targeted addresses did match breach data and warned students. Paul's take: There's no hack here at all, that's the whole point, it's a decades-old sextortion template with a fresh coat of paint using real breach data to make the "we have your info" line land harder. The scam works entirely on the target recognizing their real email address and panicking, not on anything technical actually happening on their device. A zero-activity Bitcoin wallet tells you nobody's even paying, which means the real value of this campaign isn't the ransom, it's proof that email addresses tied to breaches keep getting recycled for scam lists years after the original leak. If you get one of these, or if someone you know does, the fix is boring but correct: there's no malware, don't pay, don't reply, and go check haveibeenpwned for your own address, because the real lesson here is that old breach data never expires, it just gets reused by whoever's running this month's scam. Research: Hacking-adjacent Incident from 1966 The earliest known media report of a computer crime is the Minneapolis Tribune's October 18, 1966 front-page story, "Computer Expert Accused of Fixing His Bank Balance." National City Bank of Minneapolis had installed a new computerized checking-account system in 1965. Milo A. Bennett, the 23-year-old technician who installed it, used his privileged access during setup to program the system to ignore overdrafts on his personal account, letting him overdraw by roughly $1,357 without triggering the usual flags. It came apart when the computer itself malfunctioned, forcing staff to manually reconcile records by hand, which is how the discrepancy surfaced. This case is frequently cited by hacking historians (separately from the more commonly cited "first hacks," like Allan Scherr's 1966 MIT password-file trick, or the 1967 Evanston Township High School APL network intrusion) as arguably the first computer crime to make mainstream news, predating the word "hacker" being used in that context by years. Summary: Jericho at Attrition.org tracked down the source behind what's likely the earliest media report of a computer crime: an October 18, 1966 Minneapolis Tribune front page, "Computer Expert Accused of Fixing His Bank Balance." Milo A. Bennett, a 23-year-old technician hired to install National City Bank of Minneapolis's new computer system in 1965, rigged it to ignore overdrafts on his own checking account and skimmed roughly $1,357. It unraveled when the computer malfunctioned and employees fell back to manually reviewing records by hand. Jericho debates w