CyberWire Daily

AI chips flow east.

Sep 16, 2025
Spencer Thelmann, Principal Product Manager at Palo Alto Networks, dives into the complex world of AI security. They discuss a controversial U.S.-UAE deal allowing access to advanced AI chips and the risks of using generative AI tools in the workplace. The conversation highlights crucial threats like account takeover vulnerabilities and emerging social engineering tactics targeting vulnerable populations. Spencer also reveals the dangers of AI agents with extensive permissions, underscoring the urgent need for robust security strategies in today's digital landscape.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Geopolitics Threaten AI Supply Chain

  • Exporting US AI chips to the UAE risks models or hardware flowing to China and undermining export controls.
  • Critics also warn of conflicts of interest tied to parallel crypto investments, compounding security concerns.
INSIGHT

Immediate Patch Needed For FlowiseAI Flaw

  • A critical FlowiseAI flaw lets attackers reset passwords and fully take over accounts in cloud and self-hosted setups.
  • Users must update immediately or block public access to password reset endpoints.
INSIGHT

FileFix Uses Explorer And Steganography

  • The FileFix campaign tricks victims into pasting commands via a fake Meta suspension page and Explorer address bar.
  • It uses steganography-hosted images to eventually deploy the SteelC infostealer and harvest credentials and keys.
Get the Snipd Podcast app to discover more snips from this episode
Get the app