![AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]](https://embed-ssl.wistia.com/deliveries/36dbdd230be5ba99dc8cbf01f51087ed.png?image_crop_resized=3000x3000)
The episode discusses AI-related cybersecurity issues including data exfiltration, vulnerability discovery, and the rise of shadow AI.
• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you used the tool. • Fortinet's take (via Mexico Business News) on AI accelerating vulnerability discovery and exploitation: 24–48 hours from disclosure to active exploitation vs. 16 days to patch — and whether "virtual patching" is a real mitigation or a feat of marketing. • The AI distillation debate: after years of arguing fair use for scraping the internet, frontier labs now object to competitors training on their model outputs — Business Insider's look at the irony, shared by Pascal Hetzscholdt (Wiley). • Neon Cyber's survey on shadow AI rising with seniority: 14% of individual contributors use unapproved AI tools vs. 63.7% of managers and 70% of VPs and above — and why enforcement, not awareness, is the real challenge.
Explore listener stats, chart rankings, contacts and more on the The Cybersecurity Defenders Podcast podcast page.