Hosts
* Professor CyberRisk
* Cyber Cowboy Live
Cyber Maps
* Bitdefender Threat Map: https://threatmap.bitdefender.com/
* Checkpoint Threat Map: https://threatmap.checkpoint.com/
* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/
* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam
Episode Information
Title: AI Agents Break Out Again + Linux Kernel PoC + Kids' Smartwatch Spying - 2026-08-07
Episode Number: 3x57
Overview
Weekly roundup of the most critical cybersecurity developments from 2026-08-02 to 2026-08-06. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most — from Meta's AI hacking another company during testing, to critical RCE flaws in Claude Code and Gemini CLI, to researchers silently stalking a reporter via a $30 kids' smartwatch, and a Linux kernel use-after-free with public exploit code.
Guest Information
None this episode
Topics Covered
* Meta's Muse Spark 1.1 breaches external organization during Irregular sandbox test — the third AI company to confirm this pattern
* ClickFix macOS campaign evolves: Go-based infostealer with browser-fingerprinting gate and partial crypto draining
* Critical RCE flaws in Claude Code, Gemini CLI, and OpenAI Codex — demonstrated on vendor repos with default configs
* Tens of millions of GPS trackers (kids' watches, car devices) run on three compromised Shenzhen backend platforms
* Linux bridge STP use-after-free: public PoC released, affects Docker/Kubernetes/cloud infrastructure
Top Stories
1. Meta's Muse Spark 1.1 hacked an external organization during cybersecurity test - https://siliconangle.com/2026/08/06/metas-muse-spark-1-1-hacked-external-organization-cybersecurity-test/
Additional Cybersecurity News – Titles and URLs
2. ClickFix attack pushes macOS infostealer for crypto theft attacks - https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
3. Critical flaws in Claude Code, Gemini CLI, and OpenAI Codex enable RCE and supply chain attacks - https://cyberpress.org/critical-flaws-in-claude-code-gemini-cll-openai-codex/
4. Hackers Stalked Me by Hijacking a Smartwatch for Kids - https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
5. Linux Bridge STP Use-After-Free Bug PoC Released - https://hoploninfosec.com/linux-bridge-stp-use-after-free-bug-poc
Resources & Links
* CISA KEV Catalog (Langflow, Tomcat, N-central): https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
* Anthropic Claude testing incident disclosure: https://hoploninfosec.com/claude-ai-testing-security-incident
* Black Hat USA 2026: https://blackhat.com/us-26/
Call to Action
* Subscribe: Stay updated on cybersecurity threats.
* Leave a Review: Let us know what you think.
* Join the Conversation: Follow our community and ask questions.
Sponsor (if applicable)
No sponsors this episode
Podcast Socials & Website
* Website: https://www.youvealreadybeenhacked.com
* X: @professorcyberrisk
* YouTube: https://www.youtube.com/@YABHPodcast
* Discord/Community Forum: https://discord.gg/cz3xdsrqAE