How hackers turned AI into their new henchman episode artwork

EPISODE · Sep 3, 2025 · 45 MIN

How hackers turned AI into their new henchman

from Smashing Security · host Graham Cluley

Your AI reads the small print, and that's a problem. This week in episode 433 of "Smashing Security" we dig into LegalPwn - malicious instructions tucked into code comments and disclaimers that sweet-talks AI into rubber-stamping dangerous payloads (or even pretending they’re a harmless calculator).Meanwhile, new research from Anthropic reveals that hackers have already used AI agents to break into networks, steal passwords, sift through stolen data, and even write custom ransom notes. In other words, one hacker with an AI helper can work like an entire team of cybercriminals.Plus: a joyous geek detour into keyboard history, and the most diabolically annoying, fully functional AI-generated CAPTCHA that you will love to inflict on your friends.EPISODE LINKS:LegalPwn: Abusing Legal Disclaimers to Trigger Prompt Injections - Pangea Labs.LegalPwn: Tricking LLMs by burying badness in lawyerly fine print - The Register.LegalPwn Attack Tricks GenAI Tools Into Misclassifying Malware as Safe Code - HackRead.One long sentence is all it takes to make LLMs misbehave - The Register.Londoners give up eldest children in public Wi-Fi security horror show - The Guardian.Targeted social engineering is en vogue as ransom payment sizes increase - Coveware.State of Malware 2025 - ThreatDown.Cybercrime in the Age of AI - ThreatDown.Threat Intelligence Report: August 2025 - Anthropic.The Day Return Became Enter - Marcin Wichary.Ethan Mollick’s terrible AI-generated CAPTCHAs - Twitter.The very worst AI-generated CAPTCHA? - Claude.ai.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORED BY:Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.ENJOYED THE SHOW?Make sure to check out our sister podcast, "The AI Fix".Privacy & Opt-Out: https://redcircle.com/privacy

NOW PLAYING

How hackers turned AI into their new henchman

0:00 45:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

The Wall Ronald W. Chapman II and Sean Weiss The Wall protects our republic by safeguarding our democratic processes, civil liberties, and national security through laws and institutions. Its role in protecting the republic involves balancing security concerns with humanitarian and legal considerations.With over 50 years of legal and government experience combined, Ron Chapman and Sean M. Weiss pull back the curtain on the US government, the U.S. Judicial System, and some of the most influential trials in history that continue to shape our nation today.Join every week for unfiltered conversations, in-depth analysis, and commentary from some of America’s boldest thought leaders.Be sure to follow the podcast on your favorite platform so you never miss a new episode. From Passion to Profit: Heart Centered Strategies for FitPros Nichola Page Welcome to From Passion to Profit, the ultimate resource for fitness professionals driven by their passion to inspire and empower others on their business journey. Hosted by Nichola Page, a seasoned health and fitness business specialist, this show is tailored for FitPros and Studio Owners looking to supercharge their small business.Discover game-changing strategies and actionable tactics that will not only help you attract and retain clients but also transform your health & fitness venture into a thriving small business. Dive deep into topics like marketing, sales, financials, client retention, and business scalability. Learn how to master the art of growing a health & fitness business, and unlock the secrets to financial security, freedom, and flexibility.Join Nichola each week as she and her industry guests provides invaluable insights to guide you towards a successful and sustainable fitness business. Whether you've had your business for years or just starting ou Iran's Gambit Ali Alfoneh "Iran's Gambit" is a weekly podcast produced by Ali Alfoneh, on Iranian politics, and Iran's national security strategy, intentions, capabilities and impact. Mark Kollar’s Financial Cornerstone Mark Kollar Mark Kollar is a well-known financial educator in the Chicago area and hosts the popular weekly financial radio show, Retirement and Income Radio. He is sought after throughout the state of Illinois for his expertise in retirement planning and retirement income planning. His clients include retirees from United Airlines, AT&T, McDonald’s, Chicago Transit Authority, and HFC.As a retirement and income planning specialist, Mark helps retirees and those near retirement protect their savings, reduce income taxes and taxes on social security benefits and create a retirement income guaranteed to last as long as they do. Mark graduated from Loyola University of Chicago where he received his B.B.A. degree. He is a Registered Financial Consultant and a Certified Estate Planning Professional and has pledged always to put the needs of his clients above his own.

Frequently Asked Questions

How long is this episode of Smashing Security?

This episode is 45 minutes long.

When was this Smashing Security episode published?

This episode was published on September 3, 2025.

What is this episode about?

Your AI reads the small print, and that's a problem. This week in episode 433 of "Smashing Security" we dig into LegalPwn - malicious instructions tucked into code comments and disclaimers that sweet-talks AI into rubber-stamping dangerous payloads...

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Smashing Security episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!