EPISODE · Apr 17, 2026 · 5 MIN
The Arms Race Is Live
from CyberPulse · host Tushar Vartak
A rival AI company officially launched GPT-5.4-Cyber, a frontier model optimized for defensive cybersecurity, days after Project Glasswing — making the AI cyber arms race live with two competing frontier models now shipping for enterprise security. A critical authentication bypass (CVE-2026-33032, CVSS 9.8) was discovered in the Model Context Protocol (MCP) integration for nginx-ui, allowing any network attacker to invoke all MCP tools without authentication. Patch Tuesday zero-days identified: CVE-2026-32201 (SharePoint spoofing, in KEV, deadline April 28) and CVE-2026-33825 (Defender privilege escalation to SYSTEM, the "BlueHammer" disclosure). A new cybercrime platform ATHR offers fully automated voice phishing using human operators and AI agents. Attackers are exploiting Marimo Python notebooks to deploy NKAbuse malware hosted on Hugging Face Spaces.
NOW PLAYING
The Arms Race Is Live
No transcript for this episode yet