CyberWire Daily

The rise of AI-driven cyber offense.

25 snips
Nov 17, 2025
Jared Atkinson, CTO at SpecterOps and red teaming expert, delves into the complexities of identity-driven attack paths. He discusses how attackers exploit transitioned identities to elevate privileges and bypass security measures. Atkinson emphasizes the importance of visualizing risk like adversaries do, and highlights the challenges posed by hybrid attack paths across diverse systems. He underscores the necessity of cross-team collaboration in remediation efforts, providing actionable insights for enhancing cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Unsafe Components Propagate Risk In AI Stack

  • Widespread code reuse and unsafe patterns like ZeroMQ exposure and Python pickle led to ShadowMQ RCE flaws in AI inference stacks.
  • The vulnerabilities exposed prompts, model weights, and customer data on internet-reachable servers.
INSIGHT

Default Passwords Fuel CCTV Exploitation

  • Attackers exploited default or weak CCTV passwords to breach at least 50,000 systems and sell footage on Telegram.
  • The incident highlights how untrained staff and poor device defaults create vast privacy vulnerabilities.
ANECDOTE

CEO Scammed With Atomic Wallet Ruse

  • Kent Halliburton was scammed out of $220,000 after meeting supposed investors and creating an atomic wallet.
  • Scammers likely captured his seed phrase via discrete visual surveillance and drained the funds instantly.
Get the Snipd Podcast app to discover more snips from this episode
Get the app