{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"The Cybersecurity Defenders Podcast","title":"Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/f9846799\"></iframe>","width":"100%","height":180,"duration":2033,"description":"Matt and Chris break down four stories from the week in threat intel:\n\n• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a \"security auditor\" — enabled by no-auth defaults and placeholder API keys.\n• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.\n• Cato's \"DuneSlide\" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.\n• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.","thumbnail_url":"https://img.transistorcdn.com/sQVL4Dw1YKvU3ChkRRBR7pa4FGTwkeVb6_WJLMwkgNA/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wYWM3/Zjc5ODIwM2E4YmQx/ZTE3YWVlZDVhZjc3/YmQzNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}