{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"AI Security Ops","title":"Data Becomes Code | Episode 68","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/0f86e0d8\"></iframe>","width":"100%","height":180,"duration":1399,"description":"What happens when AI coding agents treat vendor documentation as trusted instructions? Bronwen Aker and Derek Banks examine research showing how unclaimed package names and domains referenced in LLMs.txt files could lead coding agents to download and execute unintended code. They discuss how this AI-driven supply chain risk builds on familiar security problems, including dependency confusion, indirect prompt injection, and excessive permissions. The conversation also covers responsibility for AI-generated code, OpenAI’s cybersecurity proposals, and practical protections such as sandboxing, containerization, least privilege, network monitoring, and human oversight.\nLINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s\n\nBrought to you by:\nBlack Hills Information Security \nhttps://www.blackhillsinfosec.com\n\n☯️ Introducing BHIS Fusion Penetration Testing\nhttps://www.blackhillsinfosec.com/fusion-penetration-testing/\nAntisyphon Training\nhttps://www.antisyphontraining.com/\n\nActive Countermeasures\nhttps://www.activecountermeasures.com\n\nWild West Hackin Fest\nhttps://wildwesthackinfest.com\n🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits\nhttps://poweredbybhis.com","thumbnail_url":"https://img.transistorcdn.com/mN9_Xu9UJwoaajIvIvLd-Yygv-Vh_nJwEDItjPY09kA/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYjBm/MzE1MWI2YmE4ZGJh/MDQ3MmJkMTkxZGNl/MjBjNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}