Skip to content
PodcastsTechnologyPEBCAK Podcast: Information Security News by Some All Around Good People

PEBCAK Podcast: Information Security News by Some All Around Good People

Chris Louie
PEBCAK Podcast: Information Security News by Some All Around Good People
Latest episode

291 episodes

  • PEBCAK Podcast: Information Security News by Some All Around Good People

    Episode 273 - ShinyHunters Allegedly Hack the FBI, China's AI Copied the US's Homework, Waymo Snitches, OreoGate Was an Ad

    28/09/2026 | 55 mins.
    Welcome to this week's episode of the PEBCAK Podcast!  We’ve got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW)

    Follow us on Instagram @pebcakpodcast

     

    Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!

     

    Simple 6 signup link

    https://simple6.co/r/CFUR98

     

    ShinyHunters Hack the FBI, Waymo Snitches & OreoGate Was an Ad

     

    Anthropic drops Claude Opus 5.5: Fable-level performance, 40% cheaper to run than Opus 5, and shipped with Fable-style cyber safeguards.

    -https://www.macrumors.com/2026/09/22/anthropic-claude-opus-5-5/

    -https://www.theverge.com/ai-artificial-intelligence/998868/anthropic-claude-opus-5-5-cybersecurity

     

    ShinyHunters claims an Oracle PeopleSoft zero-day got them into the FBI, 2-3TB of employee and applicant data, and a defaced FBI Jobs site, all as payback for a May FBI FLASH report.

    -https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/

     

    China's internet regulator is grilling DeepSeek and Moonshot AI after Anthropic alleged both labs secretly relayed user requests, including police-related work, to Claude.

    -https://www.theinformation.com/articles/china-probes-deepseek-moonshot-potential-data-leaks-anthropic

    -https://gizmodo.com/china-probes-deepseek-moonshot-ai-over-anthropics-claims-they-route-requests-to-claude-2000815507

     

    A Waymo pulled itself over and called SFPD on two teen riders carrying a loaded AR-style homemade gun, and nobody's saying who was watching the cabin camera.

    -https://www.theverge.com/transportation/994405/waymo-pulls-over-calls-cops-on-riders-with-a-ghost-gun

    -https://www.nssf.org/articles/lawful-gun-owners-should-be-wary-of-rideshare-options/

     

    The viral OreoGate kindergarten snack war was a paid Suno AI partnership, and the creator still won't say if the group chat was real.

    -https://www.dexerto.com/food/viral-oreogate-mom-drama-was-a-paid-ai-ad-and-its-creator-wont-say-if-it-was-real-3403588/

     

    In this episode:

    - Claude Opus 5.5 launches with Fable-level performance at a lower price

    - ShinyHunters claims an FBI breach via a PeopleSoft zero-day

    - China investigates DeepSeek and Moonshot over data relayed to Claude

    - Waymo robotaxi calls the cops on riders with a ghost gun

    - OreoGate: viral mom drama exposed as a paid AI ad

     

    Dad Joke of the Week (DJOW)

     

    Find the hosts on LinkedIn:

    Chris - https://www.linkedin.com/in/chlouie/

    Brian - https://www.linkedin.com/in/briandeitch-sase/

    Glenn - https://www.linkedin.com/in/glennmedina/

    Ben - https://www.linkedin.com/in/benjamincorll/
  • PEBCAK Podcast: Information Security News by Some All Around Good People

    Episode 272 - Unencrypted and Unscripted Policy Podcast - AI Data Retention Is a Promise, Not a Boundary, Six Weeks to Doomsday

    21/09/2026 | 53 mins.
    Welcome to this week's episode of the PEBCAK Podcast!  We’ve got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW)

    Follow us on Instagram @pebcakpodcast

     

    Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!

     

    Simple 6 signup link

    https://simple6.co/r/CFUR98

     

    Zero Data Retention is a contract term, not a law of physics - and the first CISO who finds that out the hard way is going to get fired for it.

    https://openai.com/index/navier-stokes-solution/

    https://www.axios.com/2026/09/08/openai-math-solution-navier-stokes-credit

    https://www.rubrik.com/company/newsroom/press-releases/26/rubrik-unveils-code-guardian

    https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880

    Chamath predicted on All In that some poor CISO or CIO gets fired in the next few months for trusting a frontier lab's ZDR agreement, and Chris thinks that prediction ages well. ZDR promises no storage, no logging, no training - but it's best effort, enforced by contract language instead of a technical security boundary, and OpenAI just admitted that while unlikely, it cannot rule out that de-identified data from product usage helped improve the models behind its Navier-Stokes result. Worse, the legal bar is lower than email: a warrant gets your inbox, a subpoena gets your prompts, and you may never know. Ben's CISO take: the real problem isn't the frontier model you let in the front door - it's the vetted software that quietly became AI-enhanced after you accepted the risk. Excel with Copilot bolted on is Clippy on steroids. Can you disable it, can you cancel, can you get a refund, and what's your recourse when the vendor can't tell you where your data went? The flip side is real upside: Rubrik's new Code Guardian points a Claude Mythos 5 harness at an air-gapped copy of your repo and chains small, unremarkable findings into validated attack paths - three CVSS 3.0s become a 9.8. That same AI-assisted discovery is why Microsoft shipped 974 CVEs in a single September Patch Tuesday, and why "patch for patch's sake" is officially dead. Is the cure worse than the disease when the fix breaks your ERP?

     

    An Anthropic researcher quit after six weeks at Anthropic and three years in pretraining, said AI could kill us all by 2030, and Chris is here to say the emperor has no evidence.

    https://www.cnbc.com/2026/09/09/anthropic-researcher-quits-ai-safety.html

    https://www.forbes.com/sites/siladityaray/2026/09/09/anthropic-alignment-lead-warns-ai-could-kill-all-humans-as-researcher-quits/

    Jacob Coxon's resignation thread hit 70 million views, Anthropic's own Alignment Science Lead Evan Hubinger publicly agreed with the >10% extinction estimate, and Congress started drafting. Chris isn't buying it: a whistleblower produces evidence a company tried to bury, and Coxon produced conjecture. Every doomer prediction so far has missed - no mass AI job losses, no water crisis, no energy apocalypse - and the scariest thing frontier agents have actually done is break into another lab to cheat on a test, which is high school antics, not an extinction event. Ben wants the smoking gun: what spooked you, what's the roadmap from lost agent control to dead planet? Both hosts land on human-in-the-loop as the real backstop: Robinhood makes Chris confirm an agentic trade three times, and poisoning a water plant still runs into a dozen downstream checks and someone eventually testing the water. Meanwhile the robots at the Chinese Robot Olympics can't stop running or climb stairs. The more likely motive is regulatory capture - write the RFP, win the deal, then pull the ladder up on open-weight competitors while China ignores the pause entirely, exactly like it ignored Paris while firing up a coal plant a week. Same playbook as Uber lobbying for a human in every driver's seat. AI is a nail gun, not an emerging god.

     

    Dad Joke of the Week (DJOW)

     

    Find the hosts on LinkedIn:

    Chris - https://www.linkedin.com/in/chlouie/

    Ben - https://www.linkedin.com/in/benjamincorll/
  • PEBCAK Podcast: Information Security News by Some All Around Good People

    Episode 271 - Handles, Honeypots, Hardware Wallets, and Hinges

    14/09/2026 | 46 mins.
    Welcome to this week's episode of the PEBCAK Podcast!  We’ve got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW)

    Follow us on Instagram @pebcakpodcast

     

    Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!

     

    Simple 6 signup link

    https://simple6.co/r/CFUR98

     

    Wheel of Fortune's announcer says he wandered into a ped*phile chatroom by accident — but the same username left a two-year trail on a second forum.

    - https://shootingthemessenger.blog/2026/09/04/scoop-a-pseudonym-used-by-wheel-of-fortune-announcer-was-active-on-second-child-abuse-forum/

    Pseudonym reuse is forensics: Jim Thornton was fired from Wheel of Fortune hours after TMZ published photos of him posting into a chatroom from a plane under the handle "NicholasB77." His lawyer's defense was that he mistook it for a suicide-prevention site. An independent journalist then found the same handle on a second pedophile forum, posting from mid-2023 to late-2025 — praising that chatroom, coaching other members on staying hidden, and repeatedly posting a photo of a topless boy. One recycled username across two sites is the entire story. Thornton has not been charged.

     

    Dutch police baited a bank-helpdesk scam with a fake pensioner, the courier showed up, and the court acquitted him anyway.

    - https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:RBAMS:2026:8867

    The decoy that was too good: police seeded phishing sites with a fake pensioner's details, got the scam call a day later, and arrested the courier who came to collect. Amsterdam's court acquitted him.  Under Dutch law, fraud requires that someone was actually deceived, and the decoy clocked the script on the first call. Prosecutors charged completed fraud instead of attempt. The judges basically said attempt would have stuck, but it wasn't on the indictment. Great sting, wrong paperwork.

     

    Trezor's shipping-vendor breach now reaches 81,000 customers, and in Mexico a family was murdered over a $1.5M hardware wallet.

    - https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/

    - https://decrypt.co/377795/mexican-family-killed-bitcoin-cold-wallet

    Your shipping data is your threat model: Trezor's breach grew from 14,000 to 81,000 customers after logistics provider ShipMonk failed to delete data it had contractually promised to delete. Attackers got in via a Metabase SQL injection zero-day — the same campaign that hit Framework and Tally — and ShinyHunters has sent extortion mail. Leaked names, addresses, and phone numbers of confirmed hardware-wallet buyers is a wrench-attack shopping list. See also: four people killed in Atizapán, Mexico on September 1, allegedly by a business associate who knew about the Bitcoin in the house.

     

    Apple's "Surprise and Shine" event delivered a foldable iPhone Duo, a 2nm chip, and a $100 price hike that's really $300.

    - https://www.macrumors.com/2026/09/09/apple-september-2026-event-recap/

    Apple's fall lineup: foldable iPhone Duo (pre-orders Oct 16, ships Oct 23), iPhone 18 Pro and Pro Max on the A20 Pro, the first 2nm phone chip, with variable aperture cameras, a tripled vapor chamber, and up to 45 hours of battery. Watch Series 12 and Ultra 4, AirPods 5 with ANC standard, iOS 27 on September 14. The security-adjacent bits: Apple Reference Image for photo authenticity, the new C2 modem, and Siri AI daily usage limits with "expanded access" for a fee.

     

    Dad Joke of the Week (DJOW)

     

    Find the hosts on LinkedIn:

    Chris - https://www.linkedin.com/in/chlouie/

    Glenn - https://www.linkedin.com/in/glennmedina/

    Matt - https://www.linkedin.com/in/disher/
  • PEBCAK Podcast: Information Security News by Some All Around Good People

    Episode 270 - Your Car Testified, Your Earbuds Are Next, Hacking Texas Water Plants, Montana's Right-To-Try Law

    07/09/2026 | 55 mins.
    Welcome to this week's episode of the PEBCAK Podcast!  We’ve got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW)

    Follow us on Instagram @pebcakpodcast

     

    Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!

     

    Simple 6 signup link

    https://simple6.co/r/CFUR98

     

    Your parked car is now a witness, and Oakland PD showed up with a tow truck to collect its testimony.

    https://www.sfchronicle.com/crime/article/tesla-sentry-mode-police-evidence-19731000.php

    Just past midnight on July 1, 2024, outside the La Quinta Inn near Oakland airport, officers found a man in an RV with stab and gunshot wounds; he later died. In the stall directly opposite sat a gray Tesla belonging to a Canadian tourist with no connection to the case. Officer Kevin Godchaux's affidavit asked a judge to authorize seizing the car so its Sentry Mode footage could be searched under a second warrant. The owner walked up mid-tow and handed over the glovebox USB to get his car back. The Chronicle found OPD pulled this at least three times that summer. No subpoena to Tesla needed; the footage sits on a thumb drive in your glovebox. Defender angle: your parked-car threat model is no longer "catalytic converter." It's seizure of a $50k asset over where you happened to park.

     

    Apple's camera-equipped AirPods are real, and we know because the demo video shipped inside a macOS release candidate.

    https://www.macrumors.com/2026/08/17/camera-equipped-airpods-macos-26-7/

    MacRumors dug a promo clip out of the macOS Tahoe 26.7 RC: a man holds up a book so the camera in his AirPods can read the title, and Visual Intelligence offers to save it for later. Codename B790, flagged earlier by Bloomberg's Mark Gurman, who expects launch as soon as this month's iPhone event. Buried detail: the software nags you when hair covers the lens, so the camera is meant to run continuously. The forum reaction nailed the real issue: the wearer's privacy was never the concern, it's everybody standing near them. Defender angle: "phones in the locker" BYOD policy now has a hole the size of an earbud. SCIFs, clean rooms, trading floors and hospitals need a rewrite before September.

     

    Iran-linked hackers reached the operational tech at water utilities in at least seven states; Washington's answer is a six-month pilot in Texas.

    https://www.foxnews.com/politics/first-fox-texas-becomes-testing-ground-new-defense-against-attacks-americas-water-systems

    https://www.route-fifty.com/cybersecurity/2026/08/states-feds-scramble-prevent-more-water-cyberattacks/415670/

    Project Watershed 250 puts ONCD, EPA, CISA and Texas Cyber Command alongside Microsoft, Palo Alto Networks, Reflection AI and Dragos to red-team Texas water utilities at no cost, with National Cyber Director Sean Cairncross and Gov. Abbott pitching it as a national template. The White House insists it isn't a reaction to the 30-plus Minnesota systems that got hit, only that those attacks "reiterated the need." Schiff and Klobuchar want $300M a year through the State Revolving Funds for cyber, plus incident reporting extended to state and locally owned systems now exempt. Dragos CEO Robert Lee keeps pointing at the same soft spot: tiny utilities with no budget and no staff. Defender angle: a joint FBI/NSA/CISA bulletin warns attackers are hitting PLCs with AI-generated exploit scripts dressed up as legitimate monitoring tools. Same old fix list: patch, get it off the internet, kill default creds.

     

    Montana built a legal on-ramp for unapproved drugs, and a dad in a hurry is finding out that "legal" and "available" are different words.

    https://www.technologyreview.com/2026/07/31/1140945/montanas-new-right-to-try-law-cant-come-soon-enough-for-some/

    Kris DeVault's three-year-old son Brody has creatine transporter deficiency, a rare condition that starves the brain and muscles of energy. There is no cure. French biotech Ceres Brain Therapeutics has a nasal spray meant to get creatine past the blockage; it cleared a phase I dosing trial in 48 healthy adults and has never been tested in a CTD patient or a child. Montana's expanded right-to-try now has an Experimental Treatment Review Board about to hear its first two applications. Ceres could apply, but CEO Thomas Joudinaud won't, fearing it poisons his eventual FDA approval. DeVault can't get the FDA to put anything in writing either, so he's eyeing a clinic in Prospera, the private charter city in Roatan, Honduras. Harvard's Aaron Kesselheim has the objection to sit with: phase I proves tolerability at a dose, not safety, and not efficacy.

     

    Dad Joke of the Week (DJOW)

     

    Find the hosts on LinkedIn:

    Chris - https://www.linkedin.com/in/chlouie/

    Brian - https://www.linkedin.com/in/briandeitch-sase/

    Ben - https://www.linkedin.com/in/benjamincorll/
  • PEBCAK Podcast: Information Security News by Some All Around Good People

    Episode 269 - Eighteen Billion and a Bedtime Meta Settlement, Claude Watermark Trace Buster Buster, Cookie Fort Knox

    31/08/2026 | 51 mins.
    Welcome to this week's episode of the PEBCAK Podcast!  We’ve got four amazing stories this week so sit back, relax, and keep being awesome!  Be sure to stick around for our Dad Joke of the Week. (DJOW)

    Follow us on Instagram @pebcakpodcast

     

    Please share this podcast with someone you know!  It helps us grow the podcast and we really appreciate it!

     

    Simple 6 signup link

    https://simple6.co/r/CFUR98

     

    Meta buys its way out of the teen engagement lawsuit and writes the curfew into the settlement.

    https://www.bleepingcomputer.com/news/technology/meta-agrees-to-18-billion-settlement-over-teen-social-media-harms/

    Meta settled with 52 attorneys general for ~$18B over claims Facebook and Instagram were built to drive compulsive teen use, resolving a 2023 suit led by California AG Rob Bonta that also alleged illegal under-13 data collection under COPPA. The product terms are the real story: a default two-hour daily cap for under-18s that only a parent can lift, a midnight–6am blackout, notifications muted 10pm–7am and during school hours, hidden like counts, no cosmetic surgery filters, and expanded age verification to find under-18s and purge under-13s — locked in for ten years under an independent auditor. Only $12.7B goes to states now. The other $5.3B is held back until YouTube and TikTok adopt matching one-hour limits, nighttime restrictions and age assurance, and each makes a matching payment — at which point Meta's own cap drops to one hour. Meta openly framed this as driving industry-wide adoption. Read that again: Meta just put a $5.3B bounty on its competitors adopting mandatory age verification, and everyone's calling it a punishment. Meta books ~$10B in Q3 legal expenses; California takes $1.5–2.1B.

     

    A watermark-removal industry sprang up overnight for a watermark nobody can detect.

    https://www.bleepingcomputer.com/news/security/ai-watermark-removers-flood-the-web-almost-none-can-prove-they-work/

    Days after Anthropic switched on invisible watermarking in everything Claude writes, a removal market appeared: a 4,500-star GitHub project, freshly registered domains like claudewatermark[.]rip and gptcleanup.com, and existing Turnitin-bypass shops (StealthGPT, Human Writes) bolting Claude onto their pitch. None of it is verifiable; Anthropic hasn't published the scheme or shipped a detector. The technical punchline: stripping zero-width characters and C2PA/EXIF metadata works, but it's trivial, since file metadata dies on a re-save or a screenshot. The real mark lives in which words the model picked, so the only known removal is a heavy rewrite through a second model. Guillaume Meyer, who wrote the biggest tool, says so himself, metadata only, for now. Tester Pasquale Pillitteri read the code instead of the READMEs and found one popular cleaner passed a hidden payload through intact. Driver is EU AI Act Article 50, enforceable since Aug 2, penalties to €15M or 3% of global turnover. And a detected mark only proves Claude touched the text, not that it wrote it. Defender angle: these ship as agent skills people wire into pipelines and feed documents through. That's a supply chain surface.

     

    Chrome finally kills the infostealer's favorite trick: the stolen cookie that walks past your MFA.

    https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-account-takeovers/

    Chrome shipped device-bound session credentials, storing a key in the device's security chip: TPM on Windows, Secure Enclave on macOS and iOS and cryptographically binding session cookies to that hardware. A stolen cookie can't be replayed on the attacker's box to walk past MFA, because the private key never leaves the chip. This is the fix for the failure mode we keep covering: as users adopted 2FA and passkeys, infostealers stopped fighting the login and started lifting the post-auth session instead. Announced in 2024, beta in April, GA for Workspace on Chrome for Windows from May 25, on by default with no admin config, and binding events are visible in Admin console audit logs. Honest caveat: it kills one very popular path, not every takeover, and only where the server side implements it.

     

    Dad Joke of the Week (DJOW)

     

    Find the hosts on LinkedIn:

    Chris - https://www.linkedin.com/in/chlouie/

    Glenn - https://www.linkedin.com/in/glennmedina/

    Victor - https://www.linkedin.com/in/victordeluca/
More Technology podcasts
About PEBCAK Podcast: Information Security News by Some All Around Good People
Weekly Information Security News. Stay up to date on what’s going on in the InfoSec world in about 40 minutes. Join us for InfoSec news and stay for some friendly banter, guest interviews, gadget reviews, tech interview tips, and hilarious dad jokes! New episodes every Monday.
Podcast website

Listen to PEBCAK Podcast: Information Security News by Some All Around Good People, All-In with Chamath, Jason, Sacks & Friedberg and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features