Cybersecurity Today

Ransomware Insider Threats, AI Vulnerabilities, and Major Security Gaffes

Nov 5, 2025
Dive into the alarming world of cybersecurity mishaps, where ransomware negotiators turn into hackers! Discover a new AI vulnerability exploiting Windows' components and how OpenAI's API was misused for malware commands. Also, learn about AMD's flaw in Zen 5 CPUs that threatens encryption. The Louvre's recent heist shines a light on serious security failings, from weak passwords to maintenance issues. This discussion highlights the critical need for basic security measures in an increasingly complex technological landscape.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Negotiators Accused Of Being Attackers

  • Prosecutors allege ransomware negotiators at Digital Mint were running ALF-V/BlackCat attacks against clients and others.
  • The trio reportedly hacked at least five U.S. companies and collected over $1.2 million from one victim.
ADVICE

Treat Local AI Models As Untrusted Code

  • Don't blindly trust AI models downloaded from the internet; treat them as untrusted code.
  • Build security controls around local AI processing and validate model sources before use.
INSIGHT

AI Model Files As A New Attack Surface

  • Malware can hide inside Onyx AI model files and be reconstructed in memory by trusted Windows components.
  • Onyx files aren't signed or scanned, letting payloads slip past antivirus tools in a living-off-the-land style attack.
Get the Snipd Podcast app to discover more snips from this episode
Get the app