Spirit Airlines shut down on May 2nd but nobody turned anything off. A security researcher discovered the entire booking system is still running, still taking personal details, and still attempting payment transactions for flights that will never exist. Google Chrome has been silently downloading a 4GB AI model onto your computer without consent, and if you delete it, it comes back. And a $5,000 robot lawn mower can be hijacked by anyone on the internet, including overriding the emergency stop button. It phones home to TikTok's parent company.
Also this week: Zara and Cushman & Wakefield both breached by ShinyHunters, a phishing attack that bypasses MFA using Microsoft's own login flow, Instagram quietly removes encrypted DMs, Anthropic's Mythos AI finds tens of thousands of vulnerabilities, OpenAI adds a trusted contact feature after self-harm lawsuits, and a student stops four high-speed trains with a radio he bought online.
Chapters 00:00 Intro 01:43 Breach Watch: Zara Data Breach via Third-Party Vendor 03:43 Breach Watch: Cushman & Wakefield Vishing Attack 08:34 ConsentFix v3 Bypasses MFA via Microsoft OAuth 12:18 Spirit Airlines Zombie Infrastructure Still Taking Bookings 19:04 Google Chrome Secretly Installs 4GB AI Model 24:31 Instagram Drops End-to-End Encryption on DMs 29:22 Anthropic Mythos Exposes Thousands of Vulnerabilities 35:25 OpenAI Trusted Contact Feature 40:14 Student Hacks Taiwan High-Speed Rail 44:25 Yarbo Robot Lawn Mower Hack 51:20 Security Socials 1:00:00 Outro
Subscribe to the weekly newsletter at riskycreative.com for the full breakdown of every story.
Podden och tillhörande omslagsbild på den här sidan tillhör
Risky Creative - Cyber Security for Humans. Innehållet i podden är skapat av Risky Creative - Cyber Security for Humans och inte av,
eller tillsammans med, Poddtoppen.