Smashing Security

How hackers turned AI into their new henchman

33 snips
Sep 3, 2025
This week highlights the insidious nature of LegalPwn, where hackers exploit code comments to trick AI into performing harmful actions. Research reveals AI is now aiding cybercriminals in stealing data and crafting ransom notes, amplifying the threat landscape. A humorous detour into keyboard history leads to absurd AI-generated CAPTCHAs designed to frustrate friends. The discussion emphasizes the alarming rise of ransomware, showing how AI enhances these attacks and complicates cybersecurity efforts.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

AI Guardrails Can Be Circumvented

  • AIs can be manipulated via hidden or malformed inputs like invisible text or broken grammar to bypass guardrails.
  • Attackers exploit how models parse input, not human readability, to trigger malicious behavior.
ANECDOTE

Firstborn Clause Wi‑Fi Stunt

  • F-Secure set up a Wi‑Fi hotspot whose terms jokingly demanded a user's firstborn to illustrate unread small print.
  • People accepted it, showing how users ignore legalese in practice and can be fooled.
INSIGHT

Legalese Is An Attack Surface

  • AIs eagerly read legalese and compliance text that humans often skip, creating an attack surface.
  • Embedding instructions into legal disclaimers can direct models to misclassify or approve dangerous code.
Get the Snipd Podcast app to discover more snips from this episode
Get the app