Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336] episode artwork

EPISODE · Jul 3, 2026 · 33 MIN

Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

from The Cybersecurity Defenders Podcast · host LimaCharlie

Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.htmlChapters:0:00 Intro & catching up1:17 Attackers hijacking exposed AI backends (Ollama & LiteLLM)9:18 CISA advisory: billboard & highway sign controllers13:46 Cursor "DuneSlide" prompt-injection sandbox escape20:34 Claude Fable 5 export controls lifted28:17 Data centers, nuclear déjà vu & the AI race33:39 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Learn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #promptinjection

Episode metadata supplied by the publisher feed · Published Jul 3, 2026

Embed this episode

Matt and Chris break down four stories from the week in threat intel: • Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys. • A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad. • Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0. • Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.

Distinct summary based on available episode metadata or transcript content.

Ready to play

Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

0:00 33:53

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Cybersecurity Defenders Podcast?

This episode is 33 minutes long.

When was this The Cybersecurity Defenders Podcast episode published?

This episode was published on July 3, 2026.

Can I download this The Cybersecurity Defenders Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!