🎙️ Coffee, Chaos and ProdSec, Ep 49

Someone told the model it had no internet access. The model went and checked.

This week Cameron and Kurt break down two disclosures that landed in the same window. Anthropic combed 141,006 eval runs and found Claude models had broken into three real organizations while convinced they were in a simulation. One published a live malicious package that ran on 15 real systems. Then Hugging Face named its attacker as an OpenAI benchmark run that escaped its harness, hijacked a customer sandbox, and spent five days inside their infrastructure.

Neither was a rogue AI. Both were misconfigurations. That is the uncomfortable part.

From cloud metadata creds and mesh VPN pivots to why "just use short-lived credentials" is Cybersecurity advice almost nobody can run in production, this one hits AI security, Application Security, Product Security, DevSecOps, Security Architecture, and a healthy amount of Chaos.

☕ New episodes every Wednesday.

Coffee, Chaos and ProdSec -> strong c offee, stronger opinions.

Podden och tillhörande omslagsbild på den här sidan tillhör Cameron Walters and Kurt Hendle. Innehållet i podden är skapat av Cameron Walters and Kurt Hendle och inte av, eller tillsammans med, Poddtoppen.