{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"The Cybersecurity Defenders Podcast","title":"AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/4669697e\"></iframe>","width":"100%","height":180,"duration":1398,"description":"• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you used the tool.\n• Fortinet's take (via Mexico Business News) on AI accelerating vulnerability discovery and exploitation: 24–48 hours from disclosure to active exploitation vs. 16 days to patch — and whether \"virtual patching\" is a real mitigation or a feat of marketing.\n• The AI distillation debate: after years of arguing fair use for scraping the internet, frontier labs now object to competitors training on their model outputs — Business Insider's look at the irony, shared by Pascal Hetzscholdt (Wiley).\n• Neon Cyber's survey on shadow AI rising with seniority: 14% of individual contributors use unapproved AI tools vs. 63.7% of managers and 70% of VPs and above — and why enforcement, not awareness, is the real challenge.","thumbnail_url":"https://img.transistorcdn.com/sQVL4Dw1YKvU3ChkRRBR7pa4FGTwkeVb6_WJLMwkgNA/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wYWM3/Zjc5ODIwM2E4YmQx/ZTE3YWVlZDVhZjc3/YmQzNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}