AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]

AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]

July 14, 2026 · 23 min · Season 4 · Episode 339

About this episode

The episode discusses AI-related cybersecurity issues including data exfiltration, vulnerability discovery, and the rise of shadow AI.

• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you used the tool. • Fortinet's take (via Mexico Business News) on AI accelerating vulnerability discovery and exploitation: 24–48 hours from disclosure to active exploitation vs. 16 days to patch — and whether "virtual patching" is a real mitigation or a feat of marketing. • The AI distillation debate: after years of arguing fair use for scraping the internet, frontier labs now object to competitors training on their model outputs — Business Insider's look at the irony, shared by Pascal Hetzscholdt (Wiley). • Neon Cyber's survey on shadow AI rising with seniority: 14% of individual contributors use unapproved AI tools vs. 63.7% of managers and 70% of VPs and above — and why enforcement, not awareness, is the real challenge.

More episodes of The Cybersecurity Defenders Podcast

Explore listener stats, chart rankings, contacts and more on the The Cybersecurity Defenders Podcast podcast page.