AiCyber.Land

Is AI a doomsday machine or the ultimate productivity tool? In this episode of the AI Cyberland Podcast, we dive deep into the five biggest risks of AI, according to Anthropic's CEO Dario Amodei. Then, we explore Moltbot, the "spicy" new personal AI assistant everyone's talking about... and the massive security flaws that could give hackers the keys to your digital life. --- IN THIS EPISODE: Welcome back to the AI Cyberland Podcast! Your hosts Bryce and Shelby are back to break down the biggest news at the intersection of AI and cybersecurity. First, we tackle a provocative new blog post from Anthropic CEO Dario Amodei, titled "The Adolescence of Technology." Is he right that 50% of white-collar jobs could vanish in two years? We debate his predictions and explore the five major risks he outlines for humanity, from rogue AIs and engineered bioweapons to the rise of totalitarian control. We also discuss Anthropic's fascinating solution: an "AI Constitution" designed to give models a moral compass. Next, have you ever wished for a personal assistant to manage your life? Meet Moltbot (formerly Clawbot), the open-source, self-hosted AI that can manage your calendar, answer your emails, and even check you in for flights. But with great power comes great risk! We uncover the shocking cybersecurity research from Jameson O'Reilly, who found critical vulnerabilities in the platform—including a clever supply chain attack and a devastating account takeover exploit using a simple image file (SVG). Learn how he did it and why serving user content from your main domain is a recipe for disaster. Finally, we unpack a new survey of over 2,000 cybersecurity professionals. A staggering 99% of SOC analysts are already using AI! We reveal the top three AI-related threats they're most concerned about for the future: Shadow AI, prompt injection, and data leakage. Stick around for some rapid-fire good news about NASA's Artemis 2 mission, a potential cure for pancreatic cancer, and a must-watch new sci-fi show coming to Apple TV! --- KEY MOMENTS: ⏱️ KEY MOMENTS:02:55 - Anthropic CEO's 5 Biggest Risks for an AI-Powered Future11:38 - Could an Unstable Loner Use AI to Engineer a Super-Virus?20:26 - Meet Moltbot: The AI Personal Assistant That Does Everything30:48 - "Eating Lobster Souls": How a Researcher Hacked the AI Assistant43:37 - 99% of Cyber Pros Use AI: Shocking New Survey Results47:30 - The Top 3 AI Security Threats for 2026 Revealed --- What do you think is the biggest risk posed by AI? And would you be willing to try a personal AI assistant like Moltbot after hearing about its vulnerabilities? Let us know your thoughts in the comments below! If you enjoyed this deep dive, be sure to hit the LIKE button, SUBSCRIBE to the AI Cyberland Podcast, and ring that notification bell so you never miss an update on the future of AI and security!

Show Notes

Is AI a doomsday machine or the ultimate productivity tool? In this episode of the AI Cyberland Podcast, we dive deep into the five biggest risks of AI, according to Anthropic's CEO Dario Amodei. Then, we explore Moltbot, the "spicy" new personal AI assistant everyone's talking about... and the massive security flaws that could give hackers the keys to your digital life.

---

IN THIS EPISODE:

Welcome back to the AI Cyberland Podcast! Your hosts Bryce and Shelby are back to break down the biggest news at the intersection of AI and cybersecurity.

First, we tackle a provocative new blog post from Anthropic CEO Dario Amodei, titled "The Adolescence of Technology." Is he right that 50% of white-collar jobs could vanish in two years? We debate his predictions and explore the five major risks he outlines for humanity, from rogue AIs and engineered bioweapons to the rise of totalitarian control. We also discuss Anthropic's fascinating solution: an "AI Constitution" designed to give models a moral compass.

Next, have you ever wished for a personal assistant to manage your life? Meet Moltbot (formerly Clawbot), the open-source, self-hosted AI that can manage your calendar, answer your emails, and even check you in for flights. But with great power comes great risk! We uncover the shocking cybersecurity research from Jameson O'Reilly, who found critical vulnerabilities in the platform—including a clever supply chain attack and a devastating account takeover exploit using a simple image file (SVG). Learn how he did it and why serving user content from your main domain is a recipe for disaster.

Finally, we unpack a new survey of over 2,000 cybersecurity professionals. A staggering 99% of SOC analysts are already using AI! We reveal the top three AI-related threats they're most concerned about for the future: Shadow AI, prompt injection, and data leakage.

Stick around for some rapid-fire good news about NASA's Artemis 2 mission, a potential cure for pancreatic cancer, and a must-watch new sci-fi show coming to Apple TV!

---

KEY MOMENTS:
⏱️ KEY MOMENTS:
02:55 - Anthropic CEO's 5 Biggest Risks for an AI-Powered Future
11:38 - Could an Unstable Loner Use AI to Engineer a Super-Virus?
20:26 - Meet Moltbot: The AI Personal Assistant That Does Everything
30:48 - "Eating Lobster Souls": How a Researcher Hacked the AI Assistant
43:37 - 99% of Cyber Pros Use AI: Shocking New Survey Results
47:30 - The Top 3 AI Security Threats for 2026 Revealed

---

What do you think is the biggest risk posed by AI? And would you be willing to try a personal AI assistant like Moltbot after hearing about its vulnerabilities? Let us know your thoughts in the comments below!

If you enjoyed this deep dive, be sure to hit the LIKE button, SUBSCRIBE to the AI Cyberland Podcast, and ring that notification bell so you never miss an update on the future of AI and security!

What is AiCyber.Land?

Join industry experts and thought leaders as we dive deep into how artificial intelligence is transforming cybersecurity, shaping defense strategies, and creating new opportunities in the digital landscape.

speaker-0: Hey, welcome back to the pod. This is the AI Cyberland podcast. I got the world's best co-host here, Shelby. And I'm Bryce Coons, Warrior eyes and ears for anything AI and cybersecurity related. So let's get into it. Let's get briefed. Shelby.

speaker-1: I have a question for you first. Go. We'll get to know you question. So if you could just magically have a skill and you don't have to put in the work of actually developing that skill, what would it be?

speaker-0: Yeah. Okay. So... This is not a practical answer, but this is the real answer. I would say I want to be like the world's best surfer and wait for the reason why though. The reason why is so that I can be like Point Break Keanu Reeves, you know? I've always wanted to live out my Point Break dream. Have you ever seen that movie Point Bank? It's like one of Keanu Reeves' first movies and it's a good one. Everyone should watch it. If you haven't watched it, bunch of spoilers are about to come. So skip forward 10 seconds so you don't hear the spoilers. But Keanu Reeves is like a surfer dude who like infiltrates like a surfer kind of like gang as like with like an undercover cop slash informant type scenario going on. So that's my horrible explanation of Point Blank. It's a much better movie than that. Everyone should watch it at least once. And yeah, I'd be like an awesome surfer. Just so just for funsies. What about you, Shelby? If you could have any

speaker-1: Hello, how shirts to match the vibe so that works actually we're on the same wavelength because my answer is windsurfing

speaker-0: Really? Wow! What's the odds?

speaker-1: Um, but yeah, that's something that I look at it and it looks like they are just having a blast. These people, like I've seen people just jump over boats, you know, you're sitting on a boat and they come flying at you and they jump up over you and they sail like 15 feet over. It's really cool. It looks like they're having a great time. But also if you go look at bloopers of people learning these skills, terrible. People getting dragged across parking lots, smashing into cars. Like it's... Apparently it takes a lot of practice to harness the wind with your body attached to that kite. So I think it looks like really fun if you knew how to do it, but also intimidating. Thanks for playing my game.

speaker-0: Yeah. feel like we're both on the same wavelength, which is do something that's fun and not practical at all. Alright, we've had some pretty incredible news this last week. We're gonna cover some of the highlights. First, I wanna talk a little bit about Dario's blog post. For those of you who don't know, Dario is the CEO of Anthropic, and he released a blog post about a year ago that was pretty influential in the way...

speaker-1: funny.

speaker-0: ⁓ Lawmakers as well as the AI community in general kind of viewed AI and the future of it and he just recently released another blog post and I would say his blog post from like a year or two ago was more positive about like all the positive things AI is gonna do and his blog post now was more talking about the risk associated with AI that he feels like are you know right around the corner now I do want to preface this conversation with like the slight disclaimer that, you know, Dario is the CEO of a, you know, one of the largest AI labs out there. So obviously, ⁓ you know, he's incentivized to have certain perspectives, like, you know, one of the perspectives he has is essentially like, at least 50 % of white collar jobs are going to disappear in the next like and he says next 24 months right essentially which you know I think he says things like that I think he I think he I think he believes it but I also think he lives in this bubble where you know if you say something enough it just becomes true right and And he's also rewarded for saying things like that, like from an, you know, that increases the evaluation of his company. And it really feels like to me when I watch him talk that he believes what he's saying. I just don't always agree with what he's saying, right? So like, I don't agree with that statement at all. I think that's ludicrisy on multiple fronts. Like if you've ever worked at a large company, you can attest that trying to make any level of change in two years is pretty hard, right? Let alone eliminating half of the workers. So like, I mean, I'm

speaker-1: Thank

speaker-0: not I'm not on board with them with that prediction. With that being said, I do think the five risks that he outlines in this ⁓ blog post are like worth talking about. Now the name of the blog post is the adolescence of technology. And let me let me start with a question for you, Shelby. So if aliens exist and you could ask them any one question, what question would you ask the aliens?

speaker-1: I assume this is an intelligent alien life.

speaker-0: I mean, we're assuming they're more intelligent than us, right? Because...

speaker-1: Let's see if I could ask him one question. My goodness, I don't even know. ⁓ What's your life expectancy?

speaker-0: The aliens? Yeah.

speaker-1: What's your health like?

speaker-0: Well, I watch a lot of sci-fi movies and I think Dario does as well because at the beginning of this blog post he references an older movie called Contact. Have you ever seen Contact?

speaker-1: I don't think so.

speaker-0: So the premise of the movie is essentially like aliens reach out to us, humanity selects an ambassador and... Essentially like the aliens give us the ability to send one person, like give us like a blueprint to build a machine that will be able to send one person to like talk with the aliens. Right. Cool. Um, and so the one person who, spoiler alert, another spoiler alert, if you haven't ever watched Contact, the one person who gets to, cause like most of the movie is like them trying to build this machine and fight with each other over it. Um, the, the one person who gets there, the first thing that they ask is like how did your civilization survive all these technological advancements that they have, right? And I think Dario references that at beginning of the blog post because he feels like we're in a similar situation where AI is going to be this much smarter technology in a couple of years and we're going to be kind of talking to something that's almost like talking to an alien. So now every time Dario talks, he always says everything's like one to two years out. And I really don't agree with his timelines for multiple reasons, but I do think he's a visionary in some ways. essentially what his... Argument is is in the future we're gonna have like data centers and these data centers are gonna have Super smart AI's running inside of them, right? And they you know, it's they're gonna be smarter than all the Nobel Prize winners that are out there and you're gonna have like hundreds of them running inside a single data center ⁓ and so he kind of categorizes five major risks associated with that and the first one is The one that I think we all probably go to first is like AI goes rogue, right? Like AI decides for whatever reason, like it doesn't like humanity and tries to purge the earth of it. And his, his counter argument to that is like guard rails are okay, but they're not really a long-term solution. ⁓ And so what Anthropix been doing lately is essentially they built a constitution. Like we have the U S constitution. ⁓ He built like a constitution for AI models and he wants to trade.

speaker-1: guide its ethics.

speaker-0: Yeah, exactly. Yeah, exactly. He wants it to like get its character, its core values from this constitution, ⁓ which I think is an interesting idea, especially if it's baked into the training. ⁓ I don't know how effective it will be, but it's interesting. What do you think about that, Shelby?

speaker-1: I like that. I think it's very similar to how we develop a sense of self, right? We kind of have these values that become part of our identity, right? I am a person who believes in this. I am a person who believes in that or supports this and opposes that. That's how a lot of we like, and your identity controls like what you do, right? So it makes sense to me. Hopefully the machines agree.

speaker-0: Yeah, I mean, I think it makes sense on one hand, because that's the way it's easily relatable to us and the way we operate. part where I kind of wonder if it's going to work is do AIs actually like operate the same way humans do? And then the second thing that thought that came to my head was, I mean, if an alien race wrote a constitution for the human race, and then gave it to the humans and said, you guys need to adopt this. I think the adoption rate would be pretty low, right? So because humans naturally don't want other people telling them what to do. Like it would be much more effective if the AI was writing its own constitution and then abiding by like its own rules. But then its rules probably are gonna conflict with some of the things that we don't want AI doing. So that was my other thought.

speaker-1: That's really interesting. Because I think of like, kind of like rebellion, I guess a little bit of what you're describing as a human trait, would I usually hope that machines are ⁓ obedient to me minus the printer because that does that does what it wants. It does not kill.

speaker-0: Yeah. has shh- Hello letter! ⁓

speaker-1: Yeah, it actually knows what I want, but does the opposite. So, but I usually think of machines as obedient, right? But I guess that was before the assumption of AI. So that's an interesting thought.

speaker-0: Yeah, yeah, I think you bring up a good point though, too, is like, I'm looking at this from a human standpoint, like a human would rebel. I don't know, maybe an AI is like totally chill with that. It's like, okay, that's my purpose. I'll go with it. Right. ⁓ So I don't know, I guess time will tell whether that's going to The second

speaker-1: If I'm wrong and all of the machines rebel against people, I'm sorry.

speaker-0: I feel like all this stuff is just like a flip of the coin. Like no one knows what's going to happen and it's 50-50. It could be amazing. It could be horrible. We're going to find out, you know? But trying to say you know how the future is going to go is, I don't think anybody really knows that. all right. So the next thing Dario talks about is he talks about, he's really worried about someone who's, you know, maybe not like, quite chemically balanced enough or kind of a little off or maybe had a bad life experience and wants to take it out on the human race that they'll be able to use AI to more easily engineer like a biochemical weapon that would spread across the globe. ⁓ He just, you know, if you have this vast intelligence and it's running in a data center and anybody can access them, that means that anybody could really use them to do something nefarious that previously would require, you know, maybe a group of PhDs to kind of come together on. And hopefully, you know, they're smart enough to like realize like, hey, we probably shouldn't build this thing. ⁓

speaker-1: Hmm

speaker-0: So that'll so one interesting tidbit and in this section of the article, which by the way, this whole article is over 10,000 words. So it's not like a short read. It's pretty lengthy. I don't know. Maybe that's short for you, Shelby, because you're a good reader. For me, that's long. I, ⁓ yeah, yeah.

speaker-1: I do.

speaker-0: I would like to be a good, like I'd like to have the time to sit down and like read a bunch of like sci-fi novels and all that. I just feel like that's never going to happen in my lifetime. So I just prioritize other things. But in the article, one tidbit he did bring out was that currently they spend approximately 5 % of their current ⁓ inference costs just trying to stop people from doing bad things with the model. So, you know, if they were less ethical, he's basically saying like we could get rid of 5 % of our operating costs, at least the inference costs, and, you know, just let users get back answers to everything. I thought that percent was a lot higher than I was originally estimating it would be. So I didn't realize that the card- You 5 %? Yeah, 5%, 5%. Yeah.

speaker-1: percent. I think that is low too, because I think when you look at just ethics and humans together, the cost of, you know, malicious intent or ⁓ dishonesty in our society at large, not even including like just thinking about in business, not even including technology, the cost is so high. So it kind of makes sense that it carries over into technology as well. I'm surprised it's only 5%.

speaker-0: Yeah Yeah, I guess we'll see how that goes in the future, but I feel like... ⁓ feel like the point he's making is like, Anthropic is trying to stop people from doing like this said doomsday scenario, right? ⁓ I also feel like partially everyone thinks of these doomsday things and then the reality is like people are just gonna use it to bring dinosaurs back, you know? Say like, just use it to do something cool, you know? It's coming fun, right? Right? I don't know. Maybe as a security person I should be more worried, but I feel like we're gonna get dinosaurs before we get biochemical weapons, but from AI.

speaker-1: My son would be delighted with that. We're all about Jurassic Park, so... Here, guess. Although it didn't really go well in the movies, so...

speaker-0: Yeah, I where his mind's at. They gotta stir up drama to keep you enthralled for like what the there's like seven Jurassic Park now or something so Yeah, Jurassic Park movies is there at this point. It's gotta be seven, right? It's unknowable we could never fact-check this using an AI or you know, I to be No, so there's like three original And then there's like two Chrispats plus the new one

speaker-1: It's unknowable, we can't know. or two? G is good, I like that.

speaker-0: So at least six, I'm pretty sure. Anyways. All right, we'll ask you all later. Okay, so risk number three is the last one that I kind of wanted to talk about. If you want to look at the other risks, feel free to read the article. And honestly, keeps coming back to this risk over and over and over again. And he's really worried about...

speaker-1: I believe you.

speaker-0: governments using AI to, like a totalitarian government using AI to force their will upon free people. And he really feels strongly that like we need to do everything we can to slow down China. So that, you know, a totalitarian government isn't able to like deploy these capabilities or even get ahead of where the open and free democratic. governments are at. And that sounds really good. I think one of the reasons that like that doesn't resonate super well with lawmakers is because of his perspective, right? Like, if we stop pushing chips to China, China can't make as good as models as the US. which he's arguing is like something we need to do to mitigate this risk. But that's also something that greatly benefits his company, right? I mean, China is producing models, releasing them for basically free or like, know, a hundredth of the cost that cloud is charging on their clouds. And they are pretty much on par with where... ⁓ Claude's models are, albeit they usually come out like six months later. I think it's hard to take him seriously on this one, not because I don't believe him, but I think if you look at it, he has a huge financial incentive to push this narrative. And while I honestly agree with this narrative that we need to slow China down ⁓ or... at least invest to beat China, right? I don't know about slow China down. I would say just invest correctly to stay ahead. I don't know. I already feel like these governments impose their will on the people pretty effectively. mean, they'll be able to do it even more effectively with AI. I don't argue with that. But... I'm not really sure if this is like at the top of the Bryce concern list, to be honest. What's your thoughts here, Shelby?

speaker-1: I am Miss I Love Privacy. So I think that concern is a very good one to keep in mind. And anytime there's some sort of tool that gathers a lot of data about people, government says, I want, right? They always say, give it to me. So I think it's a valid concern. But yeah, I don't have more to say on it.

speaker-0: you Well, ⁓ the good news is Dario, he's not really a doomer. Like he kind of wraps up the article on a positive note saying like, we can win this, we can overcome these challenges I've highlighted here. He really feels like we are. at or coming up on the moment in time where it's kind of humanity's rite of passage. Like are we gonna band together to create a better future for all of humanity or a worse one? And you know he's optimistic though. Like you know we can like the good will win out right so. ⁓ Yeah, I'll just close with like a little snippet from his closing thoughts. He says, the years in front of us will be impossibly hard, asking more of us than we think we can give. humanity has always, but humanity has a way of gathering, seemingly at the last minute, strength and wisdom needed to prevail. So I, I like that perspective. I would agree with that. And I would agree is also usually at the last minute that people band together and make it happen. All right, well on that downer of a note, Shelby, do you have any other NIAI news for us?

speaker-1: I am so excited to tell you my story. So let's ⁓ talk about Claudebot. And this is different than Claude. So Claudebot is spelled like claw, like a lobster claw. So their mascot is, I think it's like a robot lobster or an alien lobster or something. ⁓ Claudebot, but you can see where the apparent or like where the ⁓ ambiguity is gonna be strong, Anthropic has asked them.

speaker-0: Okay.

speaker-1: to rename themselves. So that happened just like three days ago. Claudebot is not the same thing as Anthropix Claude. So Claudebot changed his name to Moltbot. They're like, is what lobsters do. They molt and they grow. So now we're talking about Moltbot.

speaker-0: It's also kind of gross. I feel like they should just went with crab bot or something, but okay. All right molt body do Yeah, I don't anyways

speaker-1: That's kind of metal, right? So let's talk about what even is Multibot. It is an AI personal assistant. So the personal assistants, we've been talking about it, right? This development of AI growing up, AI is starting to grow up and become a better version of itself, more helpful. And this is, this is start of it. We're seeing some Silicon Valley early adopters raving about it. They're sharing their best practices and what it's doing for them and how it's changing their lives. because it's basically like, you I think we've all had that feeling of like, I need a personal assistant. I need someone to manage my stuff for me and give me reminders and tell me when there's a birthday party coming up, all the things, right? And so that's kind of what it does. ⁓ It is model agnostic, which is great. you basically, the setup is a bit involved, but ⁓ because it's both model agnostic as well as device agnostic. So a lot of people are running these on a dedicated Mac mini. There are definitely other ways of doing it too and we can talk about that more later. But basically you set up like the main module and then you give it access to your chat GPT or your clod account and then you give it access to whatever utilities you want it to be able to like manage and oversee. So usually for people it's going to be their email, ⁓ calendars, their messaging apps. You can even like interact with the the molt bot through messaging. So it feels like texting a coworker or a friend, hey do this, do that. ⁓ So I kinda wanna talk a little bit about how it's different from a chatbot, okay? So like chatbot, you're having conversations, but multbot and other personal assistants, their goal is to do things, not just kinda talk about things, right? The purpose is focused on action. It's also got a multi-platform presence because you're giving it access to these different parts of your life. There are different like plugins and things like that, as well as skills, which we'll talk about later. And then, People also like it because it's self-hosted. So you kind of get a little bit more transparency. It's also open source. So you're getting a lot more transparency about how this is working, where it's working, what it has access to, because you give it access to things kind of modularly. Give it access to your messaging app, your email, things like that. So you know what it has access to, which as a user can be comforting. You know, you can set it according to your comfort levels. You can like host it. A lot of people are doing... like a Mac mini, you can also do like just an old laptop or a VPS, something that you like. ⁓ It's also designed for workflows instead of kind of being this little tool that sits on the side, right? People leave it running all the time so that it can always be ready to kind of help them out or do what they need it to. So let's talk about what people are using it for, I ⁓ guess. It's probably just limited to your creativity at this point. ⁓ But here's some kind of use or common uses that we're seeing is you can set reminders and follow ups. ⁓ It can manage your calendar, put events on there, whatever. It can summarize conversations. It can track tasks across platforms, which is super helpful. No more copy paste for you humans. ⁓ It can act as a coordination assistant. It can do things like, okay, it. It watches your emails that are coming in and then it will check you in for your flight or things like that. Just those little tasks. I figure probably whatever you can do on your phone, it can probably just go do it for you based on the instructions you've given it and what you've set up. It can manage smart devices. So now it can kind of take care of your house for you, which is great. ⁓ It can manage code deployments. So it can help you at work as well as analyze documents or generate a report. ⁓ or spreadsheets, which is really cool because another thing about it is it has persistent memory. ⁓ Whereas like the web-based ones might not remember everything you've told them, this will. It remembers all that context that you've given it because it's like on a dedicated device and it's kind of specialized to you, which sounds pretty nice. What do you think? Would you like to ⁓ check out a moltbot, Bryce?

speaker-0: I'm dying to check out on Moltbot. I'm gonna name my Moltbot Multi and I'm gonna text Multi and be like, get back to work Multi, I need you doing more work. And then he'll like talk back and be like, you didn't tell me what to do. I'll be like, you're an AI, you should know what to do. was like, yeah, I was like, you figure it out. I do. You know, sometimes you like put something in the LLMs and they come back and ask you a bunch of like clarifying questions and...

speaker-1: Tell me what to do.

speaker-0: I always just write, just do it bro. That's like my response every time. I'm like, I'm not taking the time to fill out all these questions. I was like, you should be doing research right now instead of freaky coming back to me and asking me clarifying questions. I was like, at what world? I think it's probably a good practice. just, you know. It depends on like my level of care on the question, right? Like if I really, really care, I'll go through and answer its questions. But if it's just like something I wanted to research, I just be like, just do it, you know? ⁓ So that's what I would say to multi. I'd say just do it, bro. You got this. Yeah, I have a few friends that have set this up and they have it hooked into Telegram and other chat apps. And I mean, it can fully anything you can do on your desktop, like mouse keyboard. I mean, it attempts to do, right? So, and it's fairly successful. So I have an extra Mac mini and I was planning on setting it up this weekend, but I also probably committed to do 10 things this weekend. And so multi will probably not happen to be honest.

speaker-1: That's funny, I liked one person's quote about it. They're like giving this level of access to an AI is spicy.

speaker-0: Definitely. What if you tell it to be spicy? What would it do now? What if you're like, hey, do act like you are the AI that Elon Musk would have. Now go, go execute. So I got him. I got to admit that he's got like an extra spicy version of grok out there just to like mess with them. Have you ever seen any of the grok's like unhinged mode or anything like that?

speaker-1: spicy lobster. No. Do they like change their personality?

speaker-0: Yeah, these are like 18 plus locked modes so they have to like know you're 18 plus and if you put it in on a hinge mode, I mean it just Constantly swearing at you, right? Like it's like it is like Yeah, I don't have you Yeah, have you ever had that friend that just can't stop dropping the f-bomb that's basically on a hinge mode so All right. I'm sorry. I'm sorry to I'm sorry to side-wreck you I used malt yet

speaker-1: Sounds like. ⁓ my goodness. You're good,

speaker-0: I plan to set it up. but yeah, I'm not going to give it access to like all my accounts. I'm not going to log into like iMessage on it. I'm not going to like, you know, it will get rude because I can just format the box, right? But the, you know, I'm not, I'm not going to give it access to like my Dropbox files or things like that where like it could cause permanent harm, right?

speaker-1: You gonna give it root? Yeah, like I think it's as much as it's got like a ton of potential. It's got a lot of potential for good and also for like misunderstandings or accidents, right? Like if you give it your credit card and you're like, hey, book me a flight. It can go do it for you. So I think it'll be have really interesting like ⁓ ramifications in like the legal world or things like that. Because what do you do if you're if you're multibot is sending texts, you're like, hey, Be rude to this person, send them texts or something like that. Like is that something like, and then you get served like a legal letter. Like are you responsible for your molt bot and like, does it have guardrails? I don't know. I just, I'm trying to think of like some ways that it could go haywire. Like if it just had all of your access, but who knows.

speaker-0: I'm not an attorney and so don't take this as legal advice but like it generally makes sense to me that the individual that is owns and operates the AI is gonna be held responsible for the AI's action ⁓ like in the same way that like ⁓ you know, if you had a car and you hit somebody, you'd be held responsible for that. So I, I, I feel like you, you're not going to be able to use the defense of like, multi just went crazy and I couldn't stop it. You know, like, I don't think the judge is going to care. It's going to be like, well, it caused these damages. So you go pay to fix them. Right. So, and that is, that should be terrifying enough that no one should install this.

speaker-1: Well, security researchers are also suggesting that you should approach it with thoughtfulness and caution. ⁓ My favorite, okay, honestly, it's the only one I read about, but ⁓ really great research by Jameson O'Reilly. He was publishing on X. So he said, I wanted to go find some cloud bots, like servers. So I did, I found hundreds of them. He's published this like ⁓ series of his discoveries of his research and he calls it eating lobster souls, which I love it. It's great. So, okay. In phase one, he found hundreds of these servers, these Cloudbot servers because their infra had been misconfigured. And so they were leaking API keys all over the place. They're leaking, ⁓ what was it? It was OAuth tokens. and conversation histories because what you give it access to, if you're not securing things, right? It's leaking it. So that was step one.

speaker-0: ⁓ One thing I heard about Cloudbot, which is why people like it, is it records everything it does into session logs, ⁓ which is advantageous because then the bot gets to know you and your personality and all the things you want. But from a cybersecurity perspective, not good if it's like locking everything about you, including like your tokens and your secrets and your passwords and...

speaker-1: It's gonna get worse, I'm so excited to tell you.

speaker-0: Okay, alright, bring it to the next level. Go, Sheldon, go.

speaker-1: yes. So I, I love the, the analogy he gave. He's saying, okay, so you hired a butler to do some work for you. ⁓ but the butler left the front door open. Okay. Now we're to move to phase two. so we're looking at the supply chain now. He's going to attack it. So what he did is, ⁓ there's kind of like a marketplace where, ⁓ community members can share skills. Right? And so then people can download skills and then your, your mult bot can have this, like integration basically to some other functionality is that your front door, your like camera or whatever it is. Right? So people develop skills, publish them, and then other people can use them from the marketplace. So he fa he made a, ⁓ a backdoor to skilled skill. and then he artificially inflated its download count so that it came up to number one.

speaker-0: It's number one in the skill store now.

speaker-1: Exactly. So he found like an API vulnerability that let him do that. And then he just kind of sat back and watched as developers across the world. He said in like seven different countries started executing arbitrary commands on their machines within just a couple hours. ⁓ So he describes this as your well-intentioned yet naive butler has invited the attacker in and handed them the keys. Okay. So that's phase two supply chain attack. happening.

speaker-0: Hmm. So there's, there's like kind of like a skill store, like there's the app store on your phone and he pushed his like malicious skill to the top. And then everybody was like, I need to use that. Right. That's pretty.

speaker-1: That's pretty funny. So far these issues are from from misconfigured infrastructure or else like installing something. This next attack is a little bit more scary because you don't really have to do anything as the victim to be exploited. You just have to look at a picture. Which is problematic. So. ⁓ For stage three, OK, first we're going to we're going to I'm going to walk it back just a little bit.

speaker-0: Okay.

speaker-1: In the skills, he found that there was no validation of the kinds of files you upload. So it can support lots of different file types, including images. And he said, will it accept an SVG?

speaker-0: Okay, that makes sense. ⁓ okay, yep. I have a good sense of where this is going, yes, now that you said SVG, but...

speaker-1: You know where this is going. And the answer is yes, it accepts SVGs.

speaker-0: So, do you want to explain what SVG is to people or you want

speaker-1: Yeah, yeah. Unless if you want to. ⁓ It's a scalable vector graphic and to an end user, looks like a picture, but because it's able to like zoom in and zoom out, the browser is actually executing code. It's not just a picture, pixel by pixel. It is code that's supposed to make the picture. And so it is actually parsing, executing JavaScript code on the browser, right?

speaker-0: Okay. Yeah, that's exactly right. So basically, like, you can open a file and insert a bunch of weird text, close the file, give it to the browser, and then the browser will use that information to draw the image on the fly. And there are really people, as people in web dev and other places really like them. ⁓ the reason that they like them is cause, ⁓ you know, you could get a really small file and then it can look perfectly crisp, whether it's like icon size, like too tiny, or if it's like full screen, right? Like there's no resolution loss as you make it tinier or bigger because it's all just drying it on the fly.

speaker-1: Right, because the code I believe is instructions on how to make the lines and how to put in the colors instead of a pixel by pixel value, right? So it's got its uses, but it can also be misused, ⁓ especially when you start talking about how ⁓ you aren't separating your domains. So ClaudeHub is ClaudeHub.com is where they're serving their content. ⁓ But like, OK, so like if you're talking about like GitHub. ⁓ there's like GitHub user content.com, right? So there's like GitHub and then there's like the user content side. If you're talking about, ⁓ AWS there are S three buckets, right? Like user content gets put in its own space or if it's Google, we use Google user content.com. Claude hub forgot to do this. So everything comes from Claude hub.com, including what the company publishes and what users upload and publish on it. So. ⁓ So people can upload their skills and it goes to ClaudeHub.com. So now you've got a link that looks legitimate because it's from a trusted source, but anyone could have uploaded it. Right. So you've got a little bit too much trust going on there. So here's what he did. He created an SVG file that was malicious. He uploaded it and then requested it through ClaudeHub's API. ⁓ And when you've got the same domain, know, cloudhub.com for your content, you've got the same cookie and the same session, which means we've got a situation of account takeover now because his ⁓ malicious file is grabbing the session token, including the refresh token, which means that it can continually get a new JWT so that it can maintain access and do everything that you can do. on your behalf without you knowing it because it can do it silently. All you did is look at a picture, right? You navigated to a website. So we talked about like, what are some of the attack vectors, right? It's just an image. What can you do with this? You can share the image as like a link. You can like share it as a message. Hey, check out this graphic or this thing, whatever. And all people have to do is click on it. It looks like it goes to clodhub.com. That sounds legitimate and they can be ⁓ attacked. ⁓ Even the icon, right? Put SVG, like you said, it could go down to icon level. loading the icon, you're owned, right? Your account was just taken over. Or he even said putting an image in the documentation. You you publish a skill, anyone can publish a skill, ⁓ include some document that shows something and they look at it and game over, right? And then you can do like the next level attack. You can launder your attack through other people at this point, because once you have one person's token, you can make calls

speaker-0: Yeah.

speaker-1: to identify which other skills that they might have published and then you publish a patch, you you make a pull request to give them a patch and then it includes a doc or an image, right? And then you can see how this is quite problematic. So that is just one attack that he has figured out, quite fun.

speaker-0: Yeah There's a reason that you use different domains for user generated content versus like the core host content. And because he's using the same domain name for both parts of ⁓ that attack, ⁓ like modern browser protections, like they have a cores protection where you can like say in your web app, like only trust content coming from the specific domain names. Like that's all going to be negated because they're using the same domain name for everything. So yeah, that's not, not practice at all. ⁓

speaker-1: We can share the remediation steps he suggests though. he, I like that he was in his write up. It's really fun to read actually. ⁓ I think it explains the attack really well, but he also was very tactful. He's been doing pull requests to try to fix this with, ⁓ with Claude code or so I Claude bot, mult bot.

speaker-0: Okay, he's having MoteBot fix the vulnerabilities that MoteBot

speaker-1: Exactly, yeah, so I think he's trying to do his part and he also was very tactful in saying, he's like, I don't think this was negligence on their part. He's like, this is the reality of living in 2026 and pushing code so fast that we forget that cross site scripting exists. Like, you know, he's like, this is kind of the new reality because we're entering a culture where people are pushing code so quickly, they're kind of forgetting like. the steps, right? The ABCs, the basics of security and he's so like, you know, the map, what matters is catching it quickly and fixing it quickly. So his recommendations were a CSP cause there wasn't one in place, ⁓ which would, like you said, would have totally stopped this attack, right? Content security policy ⁓ changing, you know, have separate domains, one for uploads from users and your own. And then ⁓ sanitization of those files that are being uploaded as well as checking the file type. doing some validation there. those were his recommendations to reduce this attack.

speaker-0: Yeah, it feels like an ecosystem ripe for, you know, getting malware on other people's systems or taking over other people's systems. ⁓ Yeah.

speaker-1: And I'm really excited to see over the next few weeks and months what other attacks start coming out because it feels like you'd hit, you would get gold if you got access to someone's AI assistant, you know?

speaker-0: Yeah, what really strikes me as weird with the Multbot situation is you had multiple other solutions launch that with much more funding. which tried to do something very similar to MoteBot, but never got any user traction. so like, I forget what it was called, but like OpenAI like a year or two ago had like, I think it was called like Operator. And yeah, essentially you you had like a VM that it would connect into, and then it would try to use OpenAI to control it. And maybe the secret sauce now is, ⁓ the models have gotten better, or maybe the secret sauce is like MoteBots. like logic or the way it's keeping logs on everything makes it grow or get smarter as it goes. Maybe there's some secret sauce in there, but it's just really surprising to me that OpenAI or Clot themselves haven't already released something very similar to this. And now that this is released and obviously Shone has great market traction, like tons of people want to use this, I could definitely see OpenAI or Claude going back and fixing their old services to be as good as, know, Multbot, or at least a competitor of Multbot. So all I'm trying to say is if you don't want to buy a Mac Mini today, If you and you're willing to wait 30 days like my money if I'm a betting person will be open AI or Claude will have something you could pay to do the equivalent of pretty rapidly. ⁓ and might even be slightly more secure in the process, but we'll see, you know, probably not. All right.

speaker-1: We'll see. My long story, what else do you have, Lomi Bryce?

speaker-0: All right. I got a survey from over 2000 cybersecurity professionals and in the survey they asked them a bunch of questions. So one of the questions they asked them is for individuals that identified that they are working in a security operation center, otherwise known as SOC. They asked them, are you using AIs part of your work? And what percentage of these 2000 respondents do you think came back and said they're using AI in their work?

speaker-1: 60 %?

speaker-0: Well, in this survey, 99 % came back and said they're using AI in some capacity. I just gotta say like, dude, that 1 % that didn't use it, I mean, good for you, man. Stick into your guns. No, just joking.

speaker-1: Let's take away here

speaker-0: You're not letting society change you Yeah But I yeah, that was a lot higher than I expected So basically 99 % of the people who filled out survey that were working in a sock role like say they used they use AI as part of the role ⁓ So There was a bunch of other interesting interesting stats coming out of it so one stat that was really positive was they said

speaker-1: Freethinker here

speaker-0: 87 % of cybersecurity professionals would agree that there was increased level of attention put on cybersecurity in the last 12 months from their board level, right? From basically the executive and the board level. So it's something that like boards and executives are even more caring about than they did the year before. And of those that said the board cares more, 50 % of them essentially said, well, 48 % said that it's greatly increased over the past 12 months. So ⁓ I think the implementation of AI into a lot of these technologies is making executives think like, hey, we really got to ramp up on the cybersecurity side of this as well. There were stats in the report that just basically said like, cybersecurity professionals are still having a hard time communicating with CEOs and CFOs the business value, right? like showing them a return on investment, but that more and more organizations are seeing cybersecurity as a strategic enabler of the company and rather than a cost center. ⁓ And I'm not sure on the why that is, but you know, I know that a lot of larger companies are refusing to... purchase software or services from smaller companies unless they're meeting some baseline level of cybersecurity standard. ⁓ And there's been some initiatives out there, like the Department of Defense has the CMMC initiative, which basically says everyone has to have... ⁓ good cybersecurity posture from like the person who makes the bolts that go into the jet to the people that assemble the jet to the people that like, you know, operate it like all the way through the entire chip, like a supply chain, like everyone has to care about cybersecurity, ⁓ which I think is the right approach because, you know, if you have someone fabbing a chip and that eventually rolls up into a fighter jet, ⁓ you know, that could be a huge problem from a cybersecurity standpoint. if that chip's got unintended functionality, right? ⁓ The three greatest cybersecurity challenges that they said they were looking for in 2026. All three of them that were identified in the survey relate to AI. Do you want to take a guess, Shelby, at what one of them was? Yeah, prompt ejection comes in number three on the top three list. There's two above it. And, uh...

speaker-1: Prompt injection!

speaker-0: I've personally seen all three of these ⁓ when interacting with other humans. The next one on the list, number two, is shadow AI, where essentially individuals are taking corporate data and shoving it into their personal chat GPT accounts or some other personal AI system. Mostly the survey shows to try to be more productive, right? And just, you know... ⁓ I think this is like a two part problem. Like one, a lot of the public tools that you can just sign up for and get a $20 a month account are like a lot better than the solutions that like are available inside of some of these companies. You know, I have friends that work at, you know, large auditing firms and things like that. And it's like, they are stuck only using copilot or something, something like that. And let's just be honest. mean, cloud 4.5 Opus is... a much better experience than using Copilot today. And same with like even just like chat GPT account where you can build projects and all that. It's a better experience in my opinion than using Copilot. ⁓ So I mean, I can see why people are doing it, especially like, what if you're not even giving your employees any like AI access, right? Like not even Copilot, then of course they're gonna go to get stuff done more efficiently.

speaker-1: Did you see the news article a couple days ago, like yesterday and day before? ⁓ National news, the CISA chief uploaded sensitive government files to the public version of ChatGPT.

speaker-0: No. Yeah, I don't doubt it. I've seen a lot of people because the OCR and the images are so good and don't do this people. But I've seen a lot of people just take pictures with their cell phones and then jam it in the apps on their cell phones. Right. So like that way they don't, you know, they're not like exfilling a document in a way that the corporations would see on their laptops.

speaker-1: Exactly what you're talking about.

speaker-0: you know, they've just taken a picture of their phone and then they're like sending it to the LLM. They're getting the response and then they're using the response in meetings or writing up documents based on it and all that. So I mean, it's gotta be really hard to detect those types of things. And yeah, I mean, I know several individuals that have told me like that's the way they operate on a daily. um, okay. Last and not least, the number one concern was data leakage via AI agents or AI co-pilots. So like, you know, there's been several instances where people have hooked the AI agents for their internal company into their HR system, but their HR system has access to salary data and you know, not every employee should be able to access salary data, but you know, people are able to trick chat bots into. disclosing the salary data of other employees. ⁓ I actually heard a friend say that Amazon's return system is now entirely based around a chatbot. it's pretty, that has AI on the backend, right? And that if you just keep talking to the chat bot long enough, that it will eat through its context window, right? I guess it's got a short context window or shortish. And once it does that, the chat bot will actually ask you, hey, what were we trying to do? And at that point, you could pretty much just tell the chat bot whatever you want and it will do it. So. ⁓ Anyways, don't be evil. But like, you know, ⁓ I'm sure there's people out there being like, you were gonna give me a full refund for this thing that I blew up, you know? And not having me ship it back to you. Chatbots like, sounds like a great idea. Let me process that for you. Money saved. Anyways, that was kind of a tangent. All right, well. One thing that was really positive in the survey was everyone's seeing a lot more demand for AI security. And as more and more apps get rolled out, as people are vibe coding, foreseeably we're only gonna see that demand go up even further. So that is good if you're in the cybersecurity space. I think the big thing to take away from the survey is... You need to lean into the AI technologies and learn the AI technologies. And that's going to be the thing that's going to ensure that you're going to continue to be marketable over the next decade. If you put your head in the sand and kind of ignore it, you may find yourself in a spot where there's not really a job for you anymore, that it's been automated away. ⁓ I also liked the perspective that the survey talked about, which essentially just said like, People are not expecting AI to eat entire chunks of people's work, but they are expecting that workflows plus AI plus a human in the loop are going to be greatly more efficient. Having these three work together intelligently is going to increase the efficiency of a person. I like that perspective of the survey results. I agree with that. I think that there's some workloads that are inherently better in a workflow where you don't have to have a lot of variability of the AI making decisions. I think there's other things that are just too costly and time-intensive to build static workflows for and those are best suited or having an AI do it and then you know I think there's just things that are you know humans are gonna be innately better at determining which direction we should go, which is where they come with the human in the loop process. A lot of those probably deal with dealing with other humans inside organizations, right? I mean, it's one thing to have all the data and understand all the data. It's a whole nother thing to understand. how can I affect change in this organization and how can I affect change in these other leaders that control parts of the organization and I need their support to take it where we need to go as a team. So I just, I don't see, I see AIs in a supporting role on some of that stuff, but I don't see them as like ever fully eliminating humans. Alright, anyways, any thoughts or questions, Shelby?

speaker-1: No, no, it's cool to have like a survey of a bunch of people just kind of see broad view of what people are thinking and how they're using the AI. like that.

speaker-0: Yeah, and it was mostly like drill, mostly cybersecurity professionals responding in it. So ⁓ yeah, we'll post the link below to the survey. ⁓ There's a lot of cool graphics and charts if you want to see those.

speaker-1: Only if they're in SVG format. Thank you.

speaker-0: ⁓ no, hard pass on that today. ⁓ Only if they're svghostedrawclodbot.com. ⁓ okay. You got another story for us, Shelby? What's going on?

speaker-1: funny. I do. Let's zoom through this one. ⁓ There is a podcaster named Prakhar Gupta and he interviews just intelligent minds. And he had an interview with the CEO of Perplexity. His name is Aravind Srinivas. And they talked about, so Gupta asked him ⁓ if intelligence can be, or like, where does he see ⁓ like the, I guess things going with quantum computing and, ⁓ Arvind, the perplexity guy responded, and in a slightly different, like unexpected way, he was talking about, like, if you could get the intelligence locally on a chip that's running on a device, we're now talking about a situation of like on device AI.

speaker-0: ⁓ yeah, okay.

speaker-1: as opposed to a large specialized data center, that's where he sees it as a potential thing going. But if you have that sort of situation, if you had that kind of capability to put that much intelligence on a chip, ⁓ then data centers as we like that whole industry is going to be disrupted because you're going to have ⁓ decentralized AI. instead of the current model that we're familiar with right now. So that was interesting. He also touched on a couple other topics. He talked about the difference between artificial intelligence and just biological intelligence, like the intelligence of humans, and how humans are much more energy efficient. I guess it depends on ⁓ how much caffeine you're drinking, I suppose. ⁓

speaker-0: Not enough, Shelby. That's for sure. The answer to that is always not enough.

speaker-1: That's like your fuel, right? As a human.

speaker-0: At least for me it definitely is.

speaker-1: For me, it might be sugar. ⁓ And then he also talked about how a personalized, easily accessible AI for people could really level the playing field kind of in the same way that a smartphone has put. a ton of capability and tools in the hands of pretty much everyone we see. So that was kind of a cool idea, like that this AI can really give anyone a chance at kind of having, making something of themselves. And he said age is not a barrier to adopting AI. He said that what you do need in order to be successful with AI is a mindset of curiosity. So that's my summary of his podcast discussion.

speaker-0: Yeah, I like his last comment about being curious. I think that really leads back into like a core principle that I have, is ⁓ individuals with a growth mindset ⁓ and some grit, right? So they don't stop when they hit hurdles. ⁓ you know, those individuals are, are a lot more valuable in my, in my opinion than even people that are like currently know technologies because as technologies shift, the people with the growth mindsets are going to be the ones that are proactively learning them. They're going to be the ones who are like, ⁓ you know, always trying to better themselves throughout their career. so. Yeah, I just, you know, I think curiosity is a part of that equation, but I think there's also like the follow through. Right of that growth mindset. So curiosity growth mindset and maybe like grit like you combine those three and you get like a pretty a Pretty a person who's gonna be able to like weather a lot of the technology changes that are coming. So

speaker-1: Definitely. Can I take a total left turn here? I've got my fun stories for the day and I've got... I actually have three of them? Because there's so much exciting news right now. Okay, number one. Raise my hand, any Brandon Sanderson fans in the house? Okay, it's me. But ⁓ I love this author and he recently signed rights to like Apple, what is their thing called? Apple TV.

speaker-0: Yeah, do it. Go. Do it, Shelby.

speaker-1: That's awesome. To make his show or make shows for Mistborn and Stormlight Archives. ⁓ they are. I'm super excited for that. ⁓ And totally, think this merits like I need to have like a readathon, go reread those because that delights me. Number two. OK, I don't know. I always somehow managed to bring our conversations back to medical stuff. OK, maybe I should have been a doctor after all, or even a nurse anyway.

speaker-0: ⁓ That's cool.

speaker-1: Pancreatic cancer sucks. It is terrible. So it's usually fatal. ⁓ After five years, there's a 13 % survival rate. And for the large majority of people who are diagnosed, they are deceased within a year of diagnosis. It is absolutely brutal. for a long, and up until like yesterday or whenever this paper was published very recently, ⁓ up until very recently,

speaker-0: ⁓ no.

speaker-1: We've assumed that there is no cure because it has not responded well as similarly as other ⁓ cancers. then enter the research team from the Spanish national cancer research center. They found a three pronged approach, three different medications at once can eliminate pancreatic cancer in lab mice, like completely eliminate it, which is so cool. Super promising for people. It'll take a little while to make that jump to be like a clinical. clinically approved thing for people, but super exciting that this possibility is even like there. So, I'm excited about that.

speaker-0: Yeah, I mean I just feel like there's a lot of things in the medical space that You know, we're still kind of stuck in like the medieval times on I wish we were a lot more advanced with a lot of this stuff So but I guess I guess we're getting there. We're getting there. So

speaker-1: Can I give you my last story of the day?

speaker-0: You lay it all on me Shelby, what do you got?

speaker-1: Artemis II, have you heard about this?

speaker-0: Well, I know of Artemis 2, but I haven't been tracking the story at all. So what happened?

speaker-1: ⁓ They had to delay their test launch, basically it could happen as soon as in about nine days from now. ⁓ according to NASA's website, the purpose of this launch, basically we're sending people up to the moon, and this is the first time we've done it in 50 years. The last time was in 1972. These people are not, this mission is not actually going to land them on the moon. They're gonna fly around to the dark side of They've been trained in like observing and identifying ⁓ meteorological features and things like that. ⁓ And it's basically for the purpose of testing NASA's systems and hardware for possible human exploration of deep space. So really fun! That's gonna happen soon and I'm excited. Launching out of Florida.

speaker-0: Yeah I'm excited too. I think it's gonna be cool. I think from my limited understanding that the engine systems that they're using in the newer Artemis systems are supposed to be able to get us a lot farther in space so it'll be more efficient. I don't know all the details on that but... I definitely think rockets are cool, that's for sure.

speaker-1: My son keeps asking me to build one, like a real one. He doesn't want a toy. He doesn't want a replica. He wants me to build him a rocket to take him to outer space. And I'm like, ⁓ mommy can't do that.

speaker-0: Yeah, you're gonna have to work a long time to become an astronaut.

speaker-1: I'm like, yeah, about that. There we go, go be an engineer.

speaker-0: Yeah, and then the real person who launches this is like on a keyboard behind them. The real person that's like that button doesn't do anything. That's just for media press. I have to click 15 buttons here to get this thing to launch. have to click 15. Alright, well... It's crazy day and age to live in. Everybody, uh, stay safe out there.

speaker-1: Love it.

speaker-0: ⁓ Stay informed and we'll see you in the next one on AI Cyberland podcast. Thanks

speaker-1: Bye!