EPISODE · Aug 26, 2026 · 37 MIN
S0E21: Alabama Comes for OpenAI, WebLogic Comes for Everyone
from Breach Please
Fifteen state attorneys general, led by Alabama, just subpoenaed OpenAI over the Hugging Face breach, demanding the company preserve all evidence related to the intrusion. Jess and Jake break down what that legal hold actually requires, why "mark it ACP" doesn't make a Slack channel privileged, and why the discovery list's question about internal safety concerns might be the part that burns OpenAI hardest. Then: a perfect-10 WebLogic vulnerability, patched back in January, just landed on CISA's Known Exploited Vulnerabilities list, eight months after active exploitation began. Jess and Jake talk through why "patch applied" isn't the finish line and what a post-patch threat hunt should actually look like. In this episode: Fifteen states subpoena OpenAI over the Hugging Face hack and order evidence preservation What a legal hold actually requires (and what evidence spoliation means) Why marking a channel "ACP" doesn't make it attorney-client privileged The discovery request digging into internal safety concerns and model testing A perfect-10 WebLogic CVE, patched in January, added to CISA's KEV eight months later Why "patch applied" doesn't mean "threat hunt done"
Embed this episode
Ready to play
S0E21: Alabama Comes for OpenAI, WebLogic Comes for Everyone
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.