![Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]](https://embed-ssl.wistia.com/deliveries/36dbdd230be5ba99dc8cbf01f51087ed.png?image_crop_resized=3000x3000)
Matt and Chris discuss recent threats in AI security and vulnerabilities in digital infrastructure.
Matt and Chris break down four stories from the week in threat intel: • Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys. • A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad. • Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0. • Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.
Explore listener stats, chart rankings, contacts and more on the The Cybersecurity Defenders Podcast podcast page.