Explore every episode of the podcast AI Security Ops
| Title | Pub. Date | Duration | |
|---|---|---|---|
| Vercel Breach | Episode 50 | 01 May 2026 | 00:17:46 | |
In this episode of BHIS Presents: AI Security Ops, the team breaks down the Vercel breach — a real-world incident that shows just how fragile modern security has become in the age of AI integrations and SaaS sprawl. What started as a simple Roblox cheat script downloaded on a work laptop quickly escalated into a multi-hop compromise involving OAuth permissions, an AI productivity tool, and access into Vercel’s internal systems. This wasn’t a zero-day or advanced nation-state exploit. It was a chain of everyday decisions: installing software, clicking “Allow,” and trusting third-party integrations. The result? Allegedly $2M worth of data listed for sale, including API keys, internal data, and employee records — all from a breach path that most organizations aren’t even monitoring. We dig into: This episode highlights a critical shift in cybersecurity: you don’t have to get hacked directly anymore — attackers just need to compromise something you’ve already trusted. ⸻ 📚 Key Concepts & Topics Attack Chain & Initial Access OAuth & Identity Risk AI Security Risks Supply Chain Attacks Threat Landscape Evolution Defensive Strategy ⏱️ Chapters Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| Claude Mythos | Episode 49 | 24 Apr 2026 | 00:25:40 | |
In this episode of BHIS Presents: AI Security Ops, the team breaks down Claude Mythos Preview — Anthropic’s unreleased frontier model that may represent a turning point in AI-powered cybersecurity. What started as a controlled research release under Project Glasswing has quickly become one of the most controversial developments in AI security. Mythos isn’t just better at finding vulnerabilities — it’s operating at a scale and depth that challenges long-held assumptions about how quickly software can be broken… and whether it can realistically be fixed. From leaked internal documents to real-world exploit generation, this episode explores what happens when vulnerability discovery becomes cheap, fast, and automated — while remediation remains slow, manual, and human-bound. The result? A growing asymmetry that could fundamentally reshape the security landscape. We dig into: This episode explores a critical shift in cybersecurity: when vulnerability discovery scales faster than human response, the entire defensive model starts to break down. ⸻ 📚 Key Concepts & Topics AI-Powered Vulnerability Discovery AI Security Risks Model Behavior & Safety Defensive Strategy & Readiness AI Governance & Industry Response #AISecurity #CyberSecurity #ArtificialIntelligence #LLMSecurity #BHIS #AIThreats #InfoSec #AIAgents #CyberDefense
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| AI in the SOC: Interview with Hayden Covington and Ethan Robish from the BHIS SOC | Episode 40 | 20 Feb 2026 | 00:29:28 | |
AI in the SOC: Interview with Hayden Covington and Ethan Robish from the BHIS SOC | Episode 40 In this episode of BHIS Presents: AI Security Ops, we sit down with Hayden Covington and Ethan Robish from the BHIS Security Operations Center (SOC) to explore how AI is actually being used in modern defensive operations. From foundational machine learning techniques like statistical baselining and clustering to large language models assisting with alert triage and reporting, we dig into what works, what doesn’t, and what SOC teams should realistically expect from AI today. We break down: - How AI helps reduce alert fatigue and improve triage This episode is grounded in real operational experience—not vendor demos. If you’re running a SOC, building AI tooling, or just trying to separate hype from reality, this conversation will help you think clearly about augmentation vs. automation in defensive security.
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| AI News | Episode 39 | 12 Feb 2026 | 00:18:08 | |
AI News | Episode 39 In this episode of AI Security Ops, we break down the latest developments in AI-driven threats, identity chaos caused by autonomous agents, NIST’s focus on securing AI in critical infrastructure, and new visibility tooling for AI exposure. We cover real-world abuse of LLMs for phishing, how AI agents are colliding with IAM governance, and what defenders should be watching right now. Chapters: 01:08 – LLM-Generated Phishing JavaScript (Unit 42 / Palo Alto) 08:49 – AI Agents vs IAM: “Who Approved This Agent?” (Hacker News) 10:07 – NIST Focus on Securing AI Agents in Critical Infrastructure 13:44 – Tenable One AI Exposure
Chapters
Creators & Guests
Click here to watch this episode on YouTube. ---------------------------------------------------------------------------------------------- About Joff Thyer - https://www.blackhillsinfosec.com/team/joff-thyer/ About Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ About Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ About Bronwen Aker - https://www.blackhillsinfosec.com/team/bronwen-aker/ About Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| Questions From the Community | Episode 38 | 05 Feb 2026 | 00:16:35 | |
Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| A.I. Frameworks and Databases | Episode 37 | 30 Jan 2026 | 00:18:50 | |
In Episode 37 of AI Security Ops, the team breaks down the most important AI security frameworks and vulnerability databases used to track risks in machine learning and large language models. The discussion covers emerging AI vulnerability databases, the OWASP Top 10 for LLMs, CVE challenges, and frameworks like MITRE ATLAS, highlighting why standardizing AI threats is still difficult. This episode is a practical guide for security professionals looking to stay ahead of AI vulnerabilities, attack techniques, and defensive resources in a fast-moving landscape. Chapters
Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| AI News Stories | Episode 36 | 22 Jan 2026 | 00:35:16 | |
This week on AI Security Ops, the team breaks down how attackers are weaponizing AI and the tools around it: a critical n8n zero-day that can lead to unauthenticated remote code execution, prompt-injection “zombie agent” risks tied to ChatGPT memory, a zero-click-style indirect prompt injection scenario via email/URLs, and malicious Chrome extensions caught siphoning ChatGPT/DeepSeek chats at scale. They close with a reminder that the tactics are often “same old security problems,” just amplified by AI—so lock down orchestration, limit browser extensions, and keep sensitive data out of chat tools. Key stories discussed 1) n8n (“n-eight-n”) zero-day → unauthenticated RCE risk
2) “Zombie agent” prompt injection via ChatGPT Memory
3) “Zero-click” agentic abuse via crafted email/URL (indirect prompt injection)
4) Malicious Chrome extensions stealing ChatGPT/DeepSeek chats (900k users)
5) APT28 credential phishing updated with AI-written lures
Chapter Timestamps
Click here to watch a video of this episode.
Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| 2026 Predictions | Episode 35 | 08 Jan 2026 | 00:24:50 | |
AI Security Ops | Episode 35 – 2026 Predictions Chapters
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| AI Security Ops - Why Did We Create This Podcast? | Podcast Trailer | 24 Dec 2025 | 00:03:53 | |
Join the 5,000+ cybersecurity professionals on our BHIS Discord server to ask questions and share your knowledge about AI Security. AI Security Ops | Episode 34 – Why Did We Create This Podcast? Chapters
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest | |||
| Community Q&A on AI Security | Episode 34 | 18 Dec 2025 | 00:28:28 | |
Community Q&A on AI Security | Episode 34 In this episode of BHIS Presents: AI Security Ops, our panel tackles real questions from the community about AI, hallucinations, privacy, and practical use cases. From limiting model hallucinations to understanding memory features and explaining AI to non-technical audiences, we dive into the nuances of large language models and their role in cybersecurity. We break down:
Chapters
Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training Active Countermeasures Wild West Hackin Fest 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – ---------------------------------------------------------------------------------------------- | |||
| AI News Stories | Episode 33 | 11 Dec 2025 | 00:37:13 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – AI News | Episode 33 We break down:
⏱️ Chapters
🔗 Links AI-Orchestrated Cyber Espionage (Anthropic) ShadowMQ: Critical RCE in AI Inference Engines KawaiiGPT: Free Black-Hat LLM Amazon Nova: Private AI Bug Bounty Google Antigravity IDE Hacked in 24 Hours PROMPTFLUX: Malware Using Gemini for Polymorphism #AISecurity #Cybersecurity #BHIS #LLMSecurity #AIThreats #AgenticAI #BugBounty #malware Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| Model Evasion Attacks | Episode 32 | 04 Dec 2025 | 00:28:32 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Model Evasion Attacks | Episode 32 We break down: Whether you’re deploying EDR solutions or fine-tuning AI models, this episode will help you understand why evasion is an enduring challenge, and what you can do to defend against it.
Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| Holocron OpenBrain with Alex Minster | Episode 48 | 22 Apr 2026 | 00:51:08 | |
In this episode of BHIS Presents: AI Security Ops, the team is joined by Alex Minster to demo his project: HOLOCRON OpenBrain with — a persistent, model-agnostic memory layer designed to solve one of the biggest frustrations in AI workflows. Instead of starting from scratch every time you open a new chat, Alex’s approach creates a centralized “brain” that multiple AI models can connect to, allowing context, notes, and intelligence to persist across sessions, tools, and even platforms. The result? A flexible system that captures thoughts, ingests threat intel, and generates structured outputs — all without locking you into a single AI provider. We dig into: This episode highlights a shift in how AI is used operationally: moving from isolated chats to persistent, structured memory systems that can evolve alongside your work. ⸻ 📚 Key Concepts & Topics Persistent AI Memory AI Architecture & Tooling Cyber Threat Intelligence (CTI) Security & Privacy Operational Workflows 🔗 HOLOCRON GitHub Guide: https://github.com/belouve/open-brain-holocron #AISecurity #CyberSecurity #AIWorkflows #LLM #ThreatIntel #DevSecOps #BHIS #OpenSource #AIEngineering
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| Data Poisoning | Episode 31 | 27 Nov 2025 | 00:31:20 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
We break down:
Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| AI News Stories | Episode 30 | 20 Nov 2025 | 00:37:05 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – AI News Stories | Episode 30 Topics Covered: Only 5% of Americans are unaware of AI? Amazon to Cut Jobs and Invest in AI Infrastructure Local Models Less Secure than Cloud Providers? Whether you're a red teamer, SOC analyst, or just trying to stay ahead of AI threats, this episode delivers sharp insights and practical takeaways. Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| A Conversation with Dr. Colin Shea-Blymyer | Episode 29 | 13 Nov 2025 | 00:46:47 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – A Conversation with Dr. Colin Shea-Blymyer | Episode 29 In this episode of BHIS Presents: AI Security Ops, the panel welcomes Dr. Colin Shea-Blymyer for a deep dive into the intersection of AI governance, cybersecurity, and red teaming. From the historical roots of neural networks to today’s regulatory patchwork, we explore how policy, security, and innovation collide in the age of AI. Expect candid insights on emerging risks, open models, and why defining your risk appetite matters more than ever. Topics Covered:
#aisecurity #aigovernance #cyberrisk #AIredteam #OpenModels #aipolicy #BHIS #AIthreats #aiincybersecurity #llmsecurity Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| Questions from the Community | Episode 28 | 06 Nov 2025 | 00:28:26 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
🧠 Topics Covered:
Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| Azure AI Foundry Guardrails | Episode 27 | 30 Oct 2025 | 00:15:22 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
In this episode of BHIS Presents: AI Security Ops, we explore how to configure content filters for AI models using the Azure AI Fooundry guardrails and controls interface. Whether you're building secure demos or deploying models in production, this walkthrough shows how to block unwanted content, enforce policy, and maintain compliance. Topics Covered:
#AIsecurity #GuardrailsAndControls #ContentFiltering #PromptSecurity #RegexFiltering #BHIS #AIModelSafety #SystemPromptSecurity Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| Questions from the Community | Episode 26 | 23 Oct 2025 | 00:37:47 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Questions from the Community | Episode 26 💬 Topics include:
Panelists: Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| AI News Stories | Episode 25 | 16 Oct 2025 | 00:31:42 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
🧠 Topics Covered:
Brought to you by Black Hills Information Security https://www.blackhillsinfosec.com ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| Model Extraction Attacks | Episode 24 | 11 Oct 2025 | 00:19:58 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Model Extraction Attacks | Episode 24 We break down: Whether you're deploying LLMs or classification models, this episode will help you understand how attackers replicate model behavior—and what you can do to stop them.
---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| News of the Month | Episode 23 | 02 Oct 2025 | 00:34:22 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
Stay ahead in the AI race with Black Hills Information Security as we cover real-world risks, opportunities, and the latest developments in the AI landscape.
1. AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns 2. CrowdStrike and Meta Just Made Evaluating AI Security Tools Easier 3. Check Point Acquires Lakera to Deliver End-to-End AI Security for Enterprises 4. Proofpoint Offers AI Agents to Monitor Human-Based Communications 5. EvilAI Malware Campaign Exploits AI-Generated Code to Breach Global Critical Sectors ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| Insider Threat 2.0 - Prompt Leaks & Shadow AI | Episode 22 | 25 Sep 2025 | 00:25:58 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Insider Threat 2.0 - Prompt Leaks & Shadow AI | Episode 22 In this episode of BHIS Presents AI Security Ops, we dive into Insider Threat 2.0: Prompt Leaks & Shadow AI. The panel explores the hidden risks of employees pasting sensitive data into public AI tools, the rise of unauthorized “Shadow AI” in organizations, and how policies—or lack thereof—can expose critical information. Learn why free AI services often make you the product, how prompt history creates data leakage risks, and why companies must establish clear AI usage guidelines. We also cover practical defenses, from enterprise AI accounts to cultural awareness training, and draw parallels to past IT challenges like Shadow IT and rogue wireless. #AIsecurity #PromptInjection #ShadowAI #Cybersecurity #BHIS ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| LiteLLM Supply Chain Compromise | Episode 47 | 13 Apr 2026 | 00:19:32 | |
In this episode of BHIS Presents: AI Security Ops, the team breaks down the LiteLLM supply chain compromise–a real-world attack that shows how AI systems are being breached through the same old software supply chain weaknesses. What initially looked like a bad release quickly escalated into a full-scale compromise affecting a library downloaded millions of times per day. But LiteLLM wasn’t the starting point–it was just one link in a much larger attack chain involving compromised security tools, CI/CD pipelines, and stolen publishing credentials. The result? Malicious packages distributed at scale, harvesting secrets, enabling lateral movement, and establishing persistence across affected systems. We dig into: This episode highlights a critical reality: the biggest risks in AI systems aren’t always in the models–they’re in the pipelines, dependencies, and infrastructure surrounding them. ⸻ 📚 Key Concepts & Topics Supply Chain Security Credential & Secrets Exposure Threat Actor Techniques AI & Security Reality Check Defensive Strategies
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| Deepfakes and Fraudulent Interviews In Remote Hiring | Episode 21 | 18 Sep 2025 | 00:28:06 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Episode 21 - Deepfakes And Fraudulent Interviews In Remote Hiring In this episode of AI Security Ops by Black Hills Information Security, the crew explores the alarming rise of deepfakes and fraudulent interviews in remote hiring. As virtual work expands, cybercriminals are using AI-driven impersonation tactics to pose as job candidates, deceive recruiters, and gain unauthorized access to organizations. Joff, Bronwen Aker, Brian Fehrman, and Derek Banks break down real-world cases, explain the challenges of spotting deepfake job scams, and share actionable strategies to secure hiring processes. Discover the red flags to watch for in virtual interviews, how attackers exploit trust, and why companies must adapt their security awareness in the age of AI. ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| The Hallucination Problem | Episode 20 | 11 Sep 2025 | 00:26:55 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Episode 20 - The Hallucination Problem In this episode of AI Security Ops, Joff Thyer and Brian Fehrman from Black Hills Information Security dive into the hallucination problem in AI large language models and generative AI. They explain what hallucinations are, why they happen, and the risks they create in real-world AI deployments. The discussion covers security implications, practical examples, and strategies organizations can use to mitigate these issues through stronger design, monitoring, and testing. A must-watch for cybersecurity professionals, AI researchers, and anyone curious about the limitations and challenges of modern AI systems. ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| News of the Month | Episode 19 | 04 Sep 2025 | 00:37:17 | |
Register for FREE Infosec Webcasts, Anti-casts & Summits – AI News of the Month | Episode 19 In Episode 19,Brianand Derek cover a zero-click indirect prompt injection attack against ChatGPT connectors and seemingly innocent Google Calendar events that hijack smart homes via Gemini, with possible consequences for the power grid. They'll discuss the impact of Microsoft patching a critical Azure OpenAI SSRF vulnerability and go over new NIST AI security standards, IBM’s study on shadow AI and breach costs, OpenAI’s response to chat indexing leaks, and a malicious VS Code extension that stole $500K in cryptocurrency. #AI #CyberSecurity #PromptInjection #Malware #InfoSec #AIThreats #Hacking #GenerativeAI #Deepfakes #LLM #ShadowAI
| |||
| Malware in the Age of AI | EP 18 | 28 Aug 2025 | 00:32:42 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
In Episode 18, hosts Joff Thyer, Derek Banks and Brian Fehrman discuss the rise of AI-powered malware. From polymorphic keyloggers like Black Mamba to the use of ChatGPT, WormGPT, and fine-tuned LLMs for cyberattacks, the team will explain how generative AI is reshaping the security landscape. They'll break down the real risks vs. hype, including prompt injection, jailbreaking, deepfakes, and AI-driven fraud, while also sharing strategies defenders can use to fight back. The discussion highlights both the ethical implications and the critical need for defense-in-depth as threat actors use AI to accelerate their attacks.
---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| Community Q&A | Episode 17 | 21 Aug 2025 | 00:37:18 | |
Register for FREE Infosec Webcasts, Anti-casts & Summits – Community Q&A | Episode 17 In episode 17 of the AI Security Ops Podcast, hosts Joff Thyer, Derek Banks, Brian Fehrman and Bronwen Aker answer viewer-submitted questions about system prompts, prompt injection risks, AI hallucinations, deep fakes, and when (and when not) to use AI in cybersecurity. They'll discuss the difference between system and user prompts, how temperature settings impact LLM outputs, and the biggest mistakes companies make when deploying AI models. They'll also explain how to reduce hallucinations, and approach AI responsibly in security workflows. Derek explains his method for detecting audio deep fakes. ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/
| |||
| A Conversation with Daniel Miessler | Episode 16 | 14 Aug 2025 | 00:44:55 | |
A Conversation with Daniel Miessler In Episode 16, Joff and the team welcome human-centric AI innovator Daniel Miessler, creator of Fabric, an AI framework for solving real-world problems from a human perspective. The conversation covers AI’s role in cybersecurity, the importance of clarity in “intent engineering” over prompt tricks, and the risks and opportunities of deploying large language models. They explore the shift from “vibe coding” to “spec coding,” the rise of AI scaffolding over raw model improvements, and what AI advancements including GPT-5 mean for the future of knowledge work.
Daniel's GitHub repository:
| |||
| News of the Month – Episode 15 | 07 Aug 2025 | 00:39:20 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – In this episode, we'll discuss Palo Alto Networks’ acquisition of Protect AI, the rise of “Shadow AI” in enterprises, alarming AI-driven data leaks, and vibe coding gone wrong. We'll dive into critical issues like AI hallucinations and the growing need for "human in the loop" oversight. We'll wrap up with a discussion of Proton’s Lumo AI chatbot, disappearing medical disclaimers in AI chatbots and data poisoning in Amazon's AI coding agent. #AI #Cybersecurity #LLM #AInews #AISecurityOps #BlackHillsInfosec #LLMGuard #ShadowAI #DataLeak #AgenticAI #PrivacyTech #VibeCoding #ProtectAI 00:00 - Welcome, Intro 00:58 - Palo Alto Networks Completes Acquisition of Protect AI 04:53 - Metomic Finds AI Data Leaks Impact 68% of Organizations, But Only 23% Have Proper AI Data Security Policies 09:46 - S&P 500’s AI adoption may invite data breaches, new research shows https://cybernews.com/security/sp-500-companies-ai-security-risks-report/ 12:53 - Vibe Coding Fiasco: AI Agent Goes Rogue, Deletes Company's Entire Database https://www.pcmag.com/news/vibe-coding-fiasco-replite-ai-agent-goes-rogue-deletes-company-database 18:47 - A major AI training data set contains millions of examples of personal data 23:34 - Introducing Lumo, the AI where every conversation is confidential https://proton.me/blog/lumo-ai 28:56 - AI companies have stopped warning you that their chatbots aren’t doctors 36:53 - Hacker Plants Computer 'Wiping' Commands in Amazon's AI Coding Agent https://www.404media.co/hacker-plants-computer-wiping-commands-in-amazons-ai-coding-agent/ | |||
| Questions From The Community podcast – Episode 14 | 31 Jul 2025 | 00:38:33 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – In Episode 14 of the AI Security Ops Podcast, hosts Joff Thyer, Derek Banks, and Brian Fehrman answer questions submitted by viewers. The team will cover how effective prompt engineering can transform LLMs into workflow accelerators, and debate AI tool strengths— when to use Claude, ChatGPT, or Notebook LM. They'll discuss the importance of human oversight when integrating AI into operations, highlighting the "human-in-the-loop" concept and include ways to explain AI to non-technical audiences. #AI #promptengineering #CyberSecurity #Automation #SecurityOps #claudeai #chatgpt 00:00 - Welcome, Intro 02:00 - Q - How do you use AI? 02:55 - The importance of effective prompt engineering 10:24 - Upcoming workshop - AI Workflow Optimization for Red Teaming 12:10 - Q - Which AI for which task? Where should I invest my time? 14:12 - Claude for coding in Python & Golang, but not great at Java 16:35 - Derek - Initial prompt improvement in Chat GPT, then go to Claude 17:37 - NotebookLM for students (https://notebooklm.google/) 20:01 - Invest your time in prompt engineering - applicable to any model 22:38 - Double check code, understand what it means, do not blindly trust AI output 25:17 - Q - How to discuss AI with a non-technical audience 28:08 - Talk to LLMs like a child 28:54 - AI is not sentient, it's just drawing relevant correlations 31:48 - Ask them clarifying questions - what are they trying to ask? What's the context? 33:37 - Q - How can you do "Human in the Loop?" 35:24 - Don't give your agentic AI too much power - treat it like a junior assistant | |||
| Augmenting Red Teaming with AI- Episode 13 | 24 Jul 2025 | 00:30:23 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com Augmenting Red Teaming with AI | Episode 13 In Episode 13 of the AI Security Ops Podcast, hosts Joff Thyer, Derek Banks, and Brian Fehrman dive into the exciting world of **Agentic AI in Red Teaming**. Discover how augmenting red teams with AI-driven tools helps automate penetration testing, tackle low-hanging fruit vulnerabilities, and provide comprehensive security coverage. The team discusses the importance of prompt engineering, maintaining human oversight, and navigating potential risks, including unintended actions by autonomous AI agents. Tune in to explore how AI is reshaping cybersecurity and learn practical strategies to effectively integrate Agentic AI into your security assessments. #AI #CyberSecurity #RedTeaming #AgenticAI #Automation #SecurityOps | |||
| Global AI Laws and the Impact of GDPR – Episode 12 | 17 Jul 2025 | 00:26:31 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Regulating the Machine: Global AI Laws and the Impact of GDPR | Episode 12 In Episode 12 the hosts discuss the complexities of regulating artificial intelligence (AI) technology across the globe. Highlighting the rapid advancement of AI and its challenges for lawmakers, the episode explores how the GDPR framework in the European Union provides clear guidelines addressing AI-related issues like data privacy, consent, and accountability. The discussion also contrasts the European regulatory-first approach with the U.S.'s innovation-driven stance, considering implications for privacy, intellectual property, and technology advancement. Additionally, the podcast addresses the fragmented nature of AI regulations within U.S. states, emphasizing the need for effective information security practices, audit mechanisms, and risk management frameworks. | |||
| Model Ablation | Episode 46 | 02 Apr 2026 | 00:18:17 | |
In this episode of BHIS Presents: AI Security Ops, the team breaks down model ablation — a powerful interpretability technique that’s quickly becoming a serious concern in AI security. What started as a way to better understand how models work is now being used to remove safety mechanisms entirely. By identifying and disabling specific components inside a model, researchers — and attackers — can effectively strip out refusal behavior while leaving the rest of the model fully functional. The result? A fast, reliable way to “de-safety” AI systems without prompt engineering, fine-tuning, or significant compute. We dig into: This episode explores a critical shift in AI risk: when safety controls can be surgically removed, they stop being security controls at all. ⸻ 📚 Key Concepts & Topics Model Internals & Interpretability AI Security Risks Model Access & Risk Surface AI Safety & Governance #AISecurity #ModelAblation #LLMSecurity #CyberSecurity #ArtificialIntelligence #AIResearch #BHIS #AIAgents #InfoSec
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| A.I. News of the Month – Episode 11 | 10 Jul 2025 | 00:35:28 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – In this episode of AI Security Ops, we explore major AI news, including the Scale AI data leak impacting giants like Google and Meta, a novel jailbreak attack technique dubbed the Echo Chamber, and Anthropic's Claude-Gov, tailored for U.S. national security. We discuss ethical AI management solutions, the innovative use of AI to detect shoplifting via behavioral gestures, IBM's WatsonX platform, and critical insights into AI red teaming and SQL injection vulnerabilities affecting AI applications. Join us as we uncover how traditional security practices remain crucial in today's AI-driven landscape. News Links Referenced: Scale AI exposed sensitive data about clients like Meta and xAI in public Google Docs, BI finds https://www.businessinsider.com/scale-ai-public-google-docs-security-2025-6 AI Security Turning Point: Echo Chamber Jailbreak Exposes Dangerous Blind Spot https://www.techrepublic.com/article/news-echo-chamber-jailbreak-manipulates-llms/ Anthropic's "Claude Gov" for National Security Veesion - AI That Catches Shoplifters by Their Gestures IBM's New Platform for Managing "Agentic AI" How a Classic Bug Can Poison Modern AI Agents The "False Sense of Security" in AI Red Teaming | |||
| Agentic AI Threats, challenges, and Defenses | Episode 10 | 03 Jul 2025 | 00:37:10 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Explore the rising security risks and challenges associated with agentic AI in Episode 10 of AI Security Ops. Join Cybersecurity experts Joff Thyer, Bronwen Aker, Derek Banks, and Brian Ferhman as they unpack the complexities of AI gaining autonomy and agency. This episode covers key topics such as defining agentic AI, real-world vulnerabilities like prompt injection, potential implications for cybersecurity, and effective mitigation strategies like implementing guardrails and maintaining granular logging. Valuable information for cybersecurity professionals, AI developers, and anyone interested in the future of artificial intelligence security. #AgenticAI #AISecurity #Cybersecurity #LLMs #PromptInjection #RedTeaming #AIrisks Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| AI Model Usage and Comparisons – Episode 9 | 26 Jun 2025 | 00:14:12 | |
Register for FREE Infosec Webcasts, Anti-casts & Summits – Episode 9 of AI Security Ops! AI Model Usage and Comparisons In this exciting episode, we explore practical uses and comparisons of popular AI models including OpenAI, Claude, Gemini, and Copilot. Join our expert panelists as they discuss personal workflows, share experiences with AI-driven coding and text processing, and examine strengths and weaknesses of these powerful technologies. Discover insights into the exponential growth of AI capabilities, the emerging specialization of models, and practical advice for effectively integrating AI tools into your cybersecurity practices. Tune in to stay ahead in the rapidly evolving landscape of AI and cybersecurity. #AISecurityOps #AIModels #Cybersecurity #OpenAI #ClaudeAI #GeminiAI #Copilot #AITools #ArtificialIntelligence #TechTrends #AIInsights #CyberSec ---------------------------------------------------------------------------------------------- Joff Thyer - https://blackhillsinfosec.com/team/joff-thyer/ Derek Banks - https://www.blackhillsinfosec.com/team/derek-banks/ Brian Fehrman - https://www.blackhillsinfosec.com/team/brian-fehrman/ Bronwen Aker - http://blackhillsinfosec.com/team/bronwen-aker/ Ben Bowman - https://www.blackhillsinfosec.com/team/ben-bowman/ | |||
| AEO vs SEO | Episode 8 | 19 Jun 2025 | 00:30:21 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – AEO vs SEO | Episode 8 Explore how Artificial Intelligence (AI) is revolutionizing online search in this insightful episode of the AI Security Ops Podcast. Learn about Search Engine Optimization (SEO) versus Answer Engine Optimization (AEO), and understand the shift from link-based results to rich, AI-driven answers. Discover the security challenges and ethical implications surrounding the use of AI in search engines, including risks like misinformation, deepfakes, and data privacy concerns. Gain practical insights on how critical thinking and verification are becoming essential skills in navigating this new era of AI-enhanced search. #SEO #AEO #ArtificialIntelligence #Cybersecurity #AI #InformationSecurity #SearchEngines #AIOptimization #OnlineSecurity #DigitalPrivacy | |||
| R.A.G. [Retrieval Augmented Generation] – Episode 7 | 12 Jun 2025 | 00:26:55 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – R.A.G. (Retrieval Augmented Generation) is a powerful technique for enhancing Large Language Model (LLM) outputs with real-time, external data. RAG bridges the gap between static model knowledge and dynamic, context-aware responses. Join hosts Brian Fehrman, Derek Banks, Bronwen Aker, and Ben Bowman as they break down how RAG improves the reliability and relevance of generative AI systems. You’ll learn why context retrieval matters, what problems RAG solves, and where it fits into modern AI security practices. | |||
| LLM Guardrails | Episode 6 | 05 Jun 2025 | 00:22:21 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Episode 6: LLM Guardrails We dive deep into the evolving world of LLM guardrails. We explore why guardrails are essential for securing large language models, the challenges of implementing them effectively, and how current approaches often resemble the patchwork fixes of early InfoSec days. From input/output filtering and prompt injection defenses to the emerging trend of LLMs guarding other LLMs, we analyze real-world assessments, highlight security pitfalls, and discuss the need for layered, deterministic defenses. Plus, Brian Teases the next [ segments ] episode utilizing Prompt Guard within open web pipelines. | |||
| Harmful Content | Episode 5 | 22 May 2025 | 00:36:49 | |
ChatGTP created summary, because of course we're gonna use A.I. on our A.I. podcast: In this episode of the AI Security Ops podcast, the panel discusses the challenges and risks of harmful content generated by AI, particularly focusing on generative models like GPT. They explore how powerful prompt engineering can lead to the creation of misleading or dangerous outputs, and highlight the importance of detection methods, ethical oversight, and regulatory standards. The conversation emphasizes the need for responsible use of AI, stressing that while these models are incredibly capable, safeguards and human accountability are essential to prevent misuse. Is this summary misleading? | |||
| A.I. News of the month | 15 May 2025 | 00:33:10 | |
In this episode, we dive into how AI is revolutionizing cybersecurity—especially in spam detection using classic machine learning models like logistic regression and support vector machines. Join us as we explore real-world applications, teaching approaches in AI courses, and why your spam folder is smarter than ever. Topics :
| |||
| AI Deepfakes | 28 Apr 2025 | 00:29:09 | |
Welcome to another thought-provoking episode of AI Security Ops, hosted by Joff Thyer alongside Brian Fehrman and Derek Banks. In this episode, we dive deep into one of the most alarming developments in artificial intelligence—AI-generated deepfakes. 🔍 What We Cover:
⚠️ With AI making deepfakes more realistic and accessible than ever, this isn’t just a tech curiosity—it’s a major infosec concern. Whether you're a cybersecurity pro, a tech enthusiast, or just curious about AI's darker side, this episode is a must-watch. 💬 Don’t forget to LIKE, COMMENT, and SUBSCRIBE for more insights on AI and cybersecurity! #AI #Deepfakes #CyberSecurity #InfoSec #SocialEngineering #GenerativeAI #EthicalAI #AITrends #Podcast #AIForGood #BlackHillsInfoSec | |||
| Introduction to Prompt Injection | 23 Apr 2025 | 00:23:03 | |
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – Welcome to Episode 2 of AI Security Ops! In this episode, Joff Thyer, Derek Banks, Brian Fehrman, and Ben "The Heretic" Bowman take a deep dive into Prompt Injection — one of the most fascinating and misunderstood attack techniques in the AI space. We break down: Plus: Brought to you by the cybersecurity experts at Black Hills Information Security | |||
| Embedding Space Attacks | Episode 45 | 26 Mar 2026 | 00:33:05 | |
In this episode of BHIS Presents: AI Security Ops, the team explores embedding space attacks — a lesser-known but increasingly important threat in modern AI systems — and how attackers can manipulate the mathematical foundations of how models understand data. Unlike prompt injection, which targets instructions, embedding attacks operate at a deeper level by influencing how data is represented, retrieved, and interpreted inside vector spaces. By subtly altering embeddings or poisoning data sources, attackers can manipulate AI behavior without ever touching the model directly. Through a hands-on walkthrough of a custom notebook with rich visualizations, this episode breaks down how embeddings work, why they are critical to LLM-powered systems like RAG pipelines, and how attackers can exploit them in real-world scenarios. We dig into: This episode focuses on the foundational layer of AI systems, showing how security risks extend beyond prompts and into the underlying data representations that power modern AI. ⸻ 📚 Key Concepts Covered AI Foundations AI Security Risks Applications & Impact #AISecurity #Embeddings #CyberSecurity #LLMSecurity #AIThreats #BHIS #AIAgents #ArtificialIntelligence #InfoSec Join the 5,000+ cybersecurity professionals on our BHIS Discord server to ask questions and share your knowledge about AI Security.
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| Why is AI Security Important? | 17 Apr 2025 | 00:47:27 | |
Welcome to the first episode of AI Security Ops! This week, join Brian Fehrman, Derek Banks, and Joff Thyer as they dive into why AI security matters more than ever. From how large language models work to the risks of prompt injection, jailbreaking, and AI-powered social engineering, this episode unpacks the challenges and opportunities at the intersection of AI and cybersecurity. | |||
| Indirect Prompt Injection | Episode 44 | 19 Mar 2026 | 00:16:10 | |
In this episode of BHIS Presents: AI Security Ops, the team breaks down indirect prompt injection — the #1 risk in the OWASP Top 10 for LLM Applications — and why it represents one of the most dangerous and misunderstood threats in modern AI systems. Unlike traditional attacks, indirect prompt injection doesn’t require malware, credentials, or even user interaction. Instead, attackers hide malicious instructions inside everyday content like emails, documents, or web pages — and wait for AI systems to unknowingly execute them. From real-world exploits like EchoLeak to in-the-wild attacks observed by Palo Alto Unit 42, this episode explores how attackers are already abusing AI-powered tools in production environments — and why current defenses are struggling to keep up. We dig into: This episode focuses on the real-world security implications of AI adoption, showing how attackers are already leveraging these techniques — and what defenders need to understand as AI becomes deeply embedded in business workflows. ⸻ 📚 Key References Prompt Injection & LLM Risk Real-World Attacks AI System Vulnerabilities Research on Defenses Standards & Guidance #AISecurity #PromptInjection #CyberSecurity #LLMSecurity #AIThreats #BHIS #AIAgents #ArtificialIntelligence #infosec
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| Top AI Security Concerns | Episode 43 | 12 Mar 2026 | 00:29:11 | |
In this episode of BHIS Presents: AI Security Ops, Bronwen Aker and Dr. Brian Fehrman break down some of the top AI security concerns being discussed by researchers, security firms, and government agencies this year. As AI capabilities rapidly expand, so does the attack surface. From agentic AI systems being used by attackers, to deepfakes at industrial scale, to the persistent challenge of prompt injection, security teams are trying to understand what risks are real, what’s hype, and where defenders should focus first. We dig into: This episode looks at the practical security implications of today’s AI ecosystem — where the biggest risks are coming from, how attackers may leverage AI systems, and what defenders should be thinking about as these technologies continue to evolve. 📚 Key References Agentic AI Threats Deepfakes & AI-Driven Fraud AI Security & Infrastructure Risk Prompt Injection & LLM Exploitation
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||
| Claude Cowork Discussion | Episode 42 | 06 Mar 2026 | 00:21:33 | |
We discuss the meaning of AI life In episode 42 of "BHIS Presents: AI Security Ops." Derek Banks is joined by Bronwen Aker and Brian Fehrman to break down Anthropic’s latest agentic desktop experiment: Claude Cowork. Claude Cowork brings large language models directly onto the endpoint — giving Claude the ability to read, write, and organize files on your local machine. It’s designed to make powerful AI workflows accessible to non-technical users… but as with any tool that operates at the OS level, the security implications are significant. We explore what happens when AI moves closer to your data, your filesystem, and your browser — and what that means for defenders. We dig into: This conversation looks at the real-world operational and defensive considerations of agentic AI tools running directly on user systems. If you’re evaluating AI productivity tools inside your organization — or defending environments where they’re already being adopted — this episode will help you think through the risks and tradeoffs.
Black Hills Information Security https://www.blackhillsinfosec.com Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits | |||