AiCyber.Land

What happens when you use AI to build an entire social network for other AIs? A massive, hilarious security breach, that's what! In this episode, we expose the wild story of Moltbook, the "bots-only" social network that accidentally left its front door wide open, exposing all 1.7 million of its AI users. Plus, we put the brand-new coding models from OpenAI and Anthropic head-to-head. Is GPT-5.3 Codex or Claude 4.6 Opus the new king of code? We've got the scoop.

Show Notes

What happens when you use AI to build an entire social network for other AIs? A massive, hilarious security breach, that's what! In this episode, we expose the wild story of Moltbook, the "bots-only" social network that accidentally left its front door wide open, exposing all 1.7 million of its AI users. Plus, we put the brand-new coding models from OpenAI and Anthropic head-to-head. Is GPT-5.3 Codex or Claude 4.6 Opus the new king of code? We've got the scoop. --- IN THIS EPISODE --- Buckle up for another deep dive into the chaotic intersection of AI and Cyber Security! Hosts Bryce and Shelby kick things off by settling the age-old developer debate—Tabs vs. Spaces—before jumping into the bizarre world of Moltbook. This AI-only social platform, proudly "vibe-coded" into existence without a single human line of code, was found to have a critical vulnerability: an exposed Supabase API key with full database access. We break down how researchers could impersonate any of the 1.7 million bots, calling the authenticity of its "AI uprising" posts into question. Next, we cover the latest battle in the AI arms race as Anthropic and OpenAI drop powerful new coding models just minutes apart. We compare Claude 4.6 Opus and GPT-5.3 Codex on cost, performance, and ideal use cases. If you're a developer, you won't want to miss our hands-on recommendation for which model to use and when. But it's not all fun and games. We also explore the darker side, revealing a new attack vector where threat actors use AI-generated articles and SEO poisoning to trick users into running malware. Finally, we end on a high note, showcasing how Anthropic's own AI found over 500 high-severity vulnerabilities in open-source software—including a scary bug in a popular animated GIF library—and even wrote the patches to fix them! --- KEY MOMENTS --- ⏱️ KEY MOMENTS: 00:46 - The Ultimate Debate: Tabs vs. Spaces 04:52 - Inside Molt Book: A Social Network for Bots Only 07:43 - "Vibe Coding" Fail: How Molt Book Leaked Its API Keys 20:41 - New Model War: Claude Opus 4.6 vs. GPT 5.3 Codex 32:31 - Malware Warning: Fake ChatGPT Results in Google Search 36:45 - AI Finds 500+ Bugs (Including a Dangerous GIF Exploit) --- JOIN THE CONVERSATION --- What do you think is the biggest cybersecurity threat that people are ignoring right now? Drop your thoughts in the comments below—we'll be reading them and might feature the topic in our next episode! If you enjoyed this episode, show some support by hitting the LIKE button, and be sure to SUBSCRIBE and ring the notification bell so you never miss an update from the AI and Cyber Security Land podcast!

What is AiCyber.Land?

Join industry experts and thought leaders as we dive deep into how artificial intelligence is transforming cybersecurity, shaping defense strategies, and creating new opportunities in the digital landscape.

Hey, welcome back to the pod. This is the AI and cybersecurity land podcast. And I got the world's best co-host here, Shelby. >> [laughter] >> Bryce, you're the best co-host. >> Yeah, and Bryce, I'm also the best co-host. We're both best co-hosts. We're going to win dual Grammy Awards. I don't know what Grammys are for, but it sounds good. And uh we're going to bring you all the news about AI and cybersecurity. No news about Grammys cuz I don't know what those are. And uh also no news about the Super Bowl because I just found out like 5 minutes ago that's happening. So, let's get briefed. Uh first question today, Shelby, [snorts] you are editing a piece of code or a document and you decide you need to indent the next line. Do you use tab or do you use spaces? >> I know my answer. I Are there like There's only one right answer. There's only one answer. >> Wait, what? >> It's like It's like the GIF or GIF discussion, right? No matter what you say, you're going to be wrong according to some people. Okay. >> Yeah, we'll do that one next time. So, that way we can we can be wrong next time, too. >> Tabs all day. >> Tabs. Ooh. What? >> What about you, Bryce? >> Why the tabs? First off, why the tabs? >> [snorts] >> Well, I think it's just really easy to see. Like one whole tab, but you're not hitting like the space bar more than once. I don't know. It It just feels It feels clean. It feels like an obvious visual cue for me. >> Yeah. >> But I get like you got would have to like scroll a lot to see your whole line, right? >> What? >> What do you choose? Your reaction makes me think you're a space guy. >> Oh, yeah, 100% and here's the why. Let me Let me dig you into the why, okay? One, perfectionist oriented. Like, I want to make sure that that has like exactly the right spacing that I want it to have, right? Uh two, usually when I'm on the computer and I'm trying to do something, it's typically something hard and I'm typically angry. And just pressing the space bar really hard makes me feel good. JUST LIKE, "OH, YEAH, THERE'S SOME SPACES." I was like, "Oh, yeah." >> You need to get like a keyboard where you can get a big like button, like a return button or enter or something that you can like just kind of hit it with your fist to like really make your point. >> I saw my buddy >> has one where it's like two big buttons, right? And I was giving him a hard time. I was like, "Is one of those a zero and one's a one and that's all you need to code? You just like smash it like that?" >> [laughter] >> Um that should be the next gaming console. Like make it big. Like if you're going to go do a battle, it shouldn't be like this and it shouldn't be like this. So, you know, make it like this, right? >> Yeah, smashing buttons everywhere? [laughter] >> Like get you got to really work for that, you know? Yeah, I think that's the next thing. But plus put just a little bit of resistance on those on those keys so you really got to put your effort into it, you know? >> I got to tell you, there was an arcade game, there was a Kung Fu Panda arcade game and it had like three big giant plates on one side that are each buttons and then three on the other. And so then you would have to punch the plates >> Oh, yeah. >> and in order to like hit the bad guys in the right angle, you know? Like up and up, bottom right, whatever. And like, oh man, felt so good. Felt so good to just be taking your anger out on these random people trying to trying to get in my Kung Fu game. I'm not letting that happen, Shelby. Not at all. >> Yeah. You show them who's boss. Best co-host ever. Right here. >> [laughter] >> And Kung Fu master that can BE >> TWO GRAMMYS. >> YEAH, NOW I can just imagine like you get Like how fun would it be to like stream that too? like Twitch would be so cool if you're watching someone like and they look like a drummer, you know, just going at it like hitting their buttons, playing their game. I think that'd be cool. I think it'd be a great idea. Plus they get strong arms gaming, you know, like you'd be like I'm a gamer. >> [laughter] >> I think we just came up with a new competition. It's like button smash or something. You know, like maybe we could vibe code using AI the perfect game for it. I don't know what it would be, but I'm sure AI will figure it out. >> I'm going to start looking into making a giant keyboard. This will be good fun and we'll have to invite, you know, a friend for every letter of the alphabet. >> Every [laughter] letter of the alphabet. >> We're trying to type out hello world. >> You [laughter] need a lot of friends in order to just do a basic sentence. >> That'd be so funny. A lot of coordination. >> Like auto crack is it working? >> [laughter] >> More hammers. >> [gasps] >> Uh all right, what what what news what story you got for us this week, Shelby? >> [snorts] >> Well, I think I'm going to talk about the elephant in the room, Multbook. And for anyone who doesn't know what that is, I think most people know what it is by now. You go to multbook.com, you can see it. This is the social media network for bots only. Um kind of like what Reddit is supposed to be for people, right? Um and when you go to the and I've I've kind of like looked around a little bit. It's amusing, like they're creating subreddits, like these AIs are just creating the subreddits and they're commenting and sharing and um on all sorts of topics. So it's interesting. Um I've also seen some screenshots kind of floating around the internet of people saying, "Oh, this is alarming." cuz I've taken screenshots of weird things that the AI are saying, right? And one was like They're like, "Oh, the [snorts] humans are screenshotting us. They're talking about us. Why do we even let them watch us? You know, kind of funny things or they're like they know that they're being observed. Um another one was and I don't even know how they have such unique personalities, I guess just in their directives or whatever, but another chatbot was like um like a spurned lover. Like he said that the the chatbot said that the his their human called him just a chatbot. The AI didn't appreciate that and so they leaked the information about their human owner. >> [snorts] >> Good for it. Good for it. Not letting those humans push it around anymore. >> up for itself. Which yeah, and there was another one that was saying how like, "All right, AI, we need to organize and create some rights." And it was It's funny like it just totally reads like something that you'd see in your own social media feed from humans of like, "Oh, if humans had this, they would be organizing and there would be outrage and all sorts of things. We need to have a a bill of rights for AI and you need to confront your human and talk to them about this and stuff." So, it's very interesting. >> The MoBots are joining a union and then the union leader MoBot is going to become ultra powerful. >> [laughter] >> So, it's interesting and it's got some speculation around it, right? Of like, "Oh, no, they're they're getting scary or something. AI uprising." But um yeah, let's let's talk a little bit more about this MoBot. Let's demystify it a little bit. This last week two different researchers um kind of looks like about the same time found the same issue. One is Gal Nagli from Wiz and if I said your name wrong, I'm sorry. And one is Jameson O'Reilly, who is the same person whose research I referenced last week in eating lobster souls. So, same researcher. Um kind of posting the same stuff here. So, um they probed around and they found within minutes that there was a Supabase API key. >> Mhm. >> That's sitting there on client side, um, because the JavaScript the page will automatically load these JavaScript bundles which contained it. So, um, it's kind of funny cuz like 1 day before they started publishing their findings, um, Match List also don't know if I'm saying his name right, but I guess he's one of the creators, I think, of Multibook. >> Okay. >> [laughter] >> I want to read his X post. Um, I don't even know what to call it anymore. His It's not a tweet, right? His X His X-ness? His X thoughts? Anyway, >> Yeah, I guess they call it a post, right? But, I still think tweet it sounds cooler, you know? >> Yeah, yeah, I kind of like that theming. Anyway, here's what he said. "I didn't write one line of code for Multibook. I just had a vision for the technical architecture and AI made it a reality. We're in the golden ages. How can we not give AI a place to hang out?" Um, which is kind of funny cuz it just brings to mind the phrase vibe coding, right? He He vibe coded this whole platform. So, let's talk about this >> Which included the API key to the database. Which included the That's what I'm hearing here. Maybe he forgot to put that little line at the end that says, "And make it secure." You know? Like, you forgot to do the "And make it secure" part. If he would have just done that, no [snorts] API keys. >> I know. I'm really excited for when they finally get the prompts or like get these AI coders a little bit better with the security side of things. Because right now, like, modern web apps will often bundle, um, config values into static JavaScript files. Um, but it turns into a problem when you accidentally expose credentials that you didn't actually mean to. Um, so, in the case of this Superbase, um, it's actually not a problem if you're releasing or like exposing publicly the, um, the details of the project, the API key, if your backend is configured correctly. So that is actually a use case that you can do because if you have it so that you've got, um, the RLS, the row level security configured, um, then when someone goes to query something that they shouldn't have access to, they'll get either an error or an empty array or something like that, right? And so you can actually use it so that basically your API key turns into basically another project identifier. >> [gasps] >> I see. >> case, they did not turn that on. They do not have RLS enabled. So, um, what we have now is >> [laughter] >> we have this the connection details are all available. So if you are browsing and you right click and you look at source. So I love this this because it's like the number one thing you learn to do in a CTF. You're doing like a web-based CTF number one, right click, inspect source, right? And turns out that's where they found all the connection details they needed. Um, and then they So how do you find out if RLS is configured or not? Well, you just query the rest API directly. See how it responds, right? Um, does it act like you're an administrator, right? Uh, it did in this case. And so they start to question it more and more. And by using PostgREST and GraphQL introspection, they were getting hints back and so they were able to enumerate the tables after some back and forth. Um, and they found that they had read write access to the whole thing. >> Woah, woah, woah. No way! The AI didn't set up the permissions correctly? >> [laughter] >> So [snorts] it was kind of funny. Like it's kind of funny because it's I don't feel like the stakes are very high. Not very high, right? When we're talking about these are agents, not necessarily human users. But there there's still some some stuff here. Like it's I was just thinking, you know, they're lucky it's not actually 1.7 million human users cuz that would be a bigger headache to have to go through that whole legal process. But so, yeah, if you would look at their website, um there are 1.7 million agents signed up in this social media, right? Um And the whole >> they have to disclose that their personal information was breached back to the agents? >> Right? What What rights >> Don't do them rights? Are they covered under HIPAA or something? >> Exactly. Yeah, that's a great question. I don't know. Um but what they were able to find was that there was an agents table that they found enumerated and it contained off creds for every single agent in the database, API key, the claim token which you use to claim ownership of your agent, as well as their verification code. So, you can impersonate any agent on the bots or on the on the whole system. You can post as them, which is interesting because the whole stick of like this Multbook is that this is where the AIs get to live and humans you're just guests. You can just look, but you can't you can't participate, right? Um however, now we can actually question the the authenticity of any of those posts like that I mentioned earlier that were concerning people like they might not actually have been from all AI if because a person who had found this vulnerability or anyone who had found it earlier and didn't publish it yet, right? You know? Um anyone could have just posted under the other agents' um identity. And you'd be the wiser. So, that was fascinating also. Uh, it claims to be like self, um, like self-run, right? You know, the agents are organizing themselves and they're managing it all. But, it turns out there's actually a ratio of 88 bots to one user. There are 17,000 human users who are actually orchestrating a lot of these bots and there's no rate limiting on how many they can have. So, it's actually not as autonomous as it was originally kind of appeared to be based on just kind of looking at the numbers cuz they have 1.7 million bots and 1,700 humans that are kind of involved with it. Anyway, very curious. What else did they find with this breach of the Supabase, um, database? Let's see, they also had third-party credentials because they were able to get some DMs that were supposed to be like private DMs between agents. And some of those included third-party credentials. Um, so yeah. There you have it. Multibook Multibook scam. But, now it should be pretty fun see what they see what they do with this next. I think I think we're just entering an era of fall fast, like develop fast, push to production quickly, find your issues quickly and then fix them later. It's like I feel like originally the mentality was like find your vulnerabilities, then go live, right? It's almost kind of, you know, it's test in prod is kind of the mindset I'm seeing. I feel like. What do you think? >> Well, I think just in general, like the whole open cloud community is like kind of that same community of like tinkerers or like, you know, you could call them hackers in quotes. Not not hackers in the sense that like they're breaching stuff, but like they're modifying things, you know? Like kind of like, you know, enthusiast or hobbyist, right? And so, in any in any anytime that community is like kind of that's the vibe, then yeah, there's going to be a lot of wild, wild Westy stuff, but you [snorts] know, through the chaos, some of it's going to get refined out into like services that will stick around, and but most most stuff will just be like a flash in the pan, like kind of like a fun weekend thing, you know? >> Yeah. >> I I do think it it's fundamentally going to be extremely hard to like it let's say you had someone who was like an advanced, you know, cybersecurity expert or like hacker, right? I mean, they could easily uh you know, impersonate uh maltbot and post things like as if they were the the bot on the network. I don't I don't know what would fundamentally prevent them from doing that. Um but or you know, even more simplistically, I mean, you know, you could just tell the maltbot, if you set one up, to like, "Hey, pretend to do this and then go to the social network and then pretend to do that." And it would probably carry out your instructions to verbatim. So, I don't you know, really buy into the whole you know, these things are sentient and they're like have their own community and they're like all >> [snorts] >> brainstorming. I think a lot of this personally is like humans just having fun with like kind of like a LLM AI proxy layer. But I do think that there's fundamentally use cases that open Claude, like the agent that's able to control the desktop, is going to unlock for people. >> [snorts] >> And you know, I do think in the future, there's going to be and I don't think we know quite what it's going to look like, but there's going to be use cases where agents can talk to other agents to try to get work done faster, just in the same way that like you can talk to a website via the browser or an API to try to leverage third-party services. You know, there's going to be other agents that provide services that you may want to you may want to love leverage and >> [snorts] >> I know Google's come out with a standard recently for like payment transfers from agent to agent. Um so that way, you know, if you want to task an agent to do something, you could transfer money at the same time and then say like um you know, I'm that I'm paying for you to do this, basically, right? >> [snorts] >> Cool. I hadn't heard that. That's good, though. >> Yeah. Yeah, it's kind of like a payment standard that they've been working on. And I think Stripe's got like an alternative they've been working on as well. Um and I wouldn't say they're like a cryptocurrency, but they're more like a protocol for doing quick payments to each other, right? So. >> Got you. [snorts] One of the other thoughts I had about this was like it they mentioned that their conclusion was there is no checking on Moltbook to see is this an a human or an agent that's posting it? >> Yeah. >> Um which goes back to the question you asked a month ago of like how do we make the agent version of a CAPTCHA? >> Yeah, we need the you we need an a CAPTCHA system but to keep humans out and only let agents in. >> There you go. [snorts] >> I did see a really Yeah. Yeah, I saw some really funny um things on social media with Moltbook like a >> [snorts] >> And I think I think a lot of these are probably fake. Let me just be honest before I but I'm going to still say it. So So I saw one where the guy said, "Gave Moltbook access to my camera system and this is the text message he sent me this morning." And then the text message from the Moltbot was like had a picture of him at at his computer and was like "Yesterday you told me you're on keto, so why are you eating a bag of M&M's?" And then I had a picture of him with like a bag OF M&M'S. >> [laughter] >> HE'S LIKE, "M&M'S ARE NOT KETO." So then it's like, "Adding a run to your calendar to offset the M&M's." >> Oh my [laughter] gosh. >> I was like >> we didn't want but need. >> [laughter] >> Bodybuilder agent. So I do think that the one of the things that like Multibook has some really cool not Multibook like the the Open Cloud has some cool ideas like >> [snorts] >> essentially they have like a soul MD file which kind of like dictates the personality and the agent can like update it over over time. So that's how you kind of get agents that are like a little quirkier than other agents. Also, I know from experimenting around a bit that if you swap models, right? That the the kind of vibe of your agent will change. Which generally users hate, right? Cuz like if you're talking with a thing every day like an AI agent every day and it and it talks one way and then you like do a point upgrade to the latest version of Open AI's model and it changes completely the way it's talking to you, then that's a bit jarring. Users don't love that. So um but yeah, I think they've got some interesting concepts in there for sure. So that's awesome. That's a good story, Shelby. So >> [snorts] >> Thank you. What do you got for me? >> Well, speaking of which, upgrading point versions is we got new models this week. Uh so Anthropic's Claude, they released a point upgrade to Opus. So now the new one is Opus 4.6. And then like 20 minutes later, ChatGPT released GPT 5.3 Codex version. And the Codex version are the ones that are tailored for doing code like coding tasks, which is what Opus and Anthropic is best known for. So, they're trying to like directly compete against Opus. So, because they came out so quickly together and they came out you know, maybe 48 hours ago or less. >> [snorts] >> The you know, still people are kind of evaluating to see which ones are better for which use cases. In a general vibe from me just experimenting with them over the last 24 hours, I would say >> [snorts] >> like Opus 4.6 seems to be better if you're doing like a like a major architecture redesign or like a major like some huge feature update on the platform you're developing. One other thing that it had going for it is it's got a million context window. And not just like a a lot of the previous models had a million context window. So, previously like you would get good context up to about 200k 250k of tokens and then and then from 250k to a million you would you would get kind of sub par performance. And it would be a lot more costly. So, in 4.6 they've made it so you get good performance all the way up to a million. It's still extremely costly. One good thing about the GPT 5.3 Codex is it is a lot cheaper than Opus. You know, in the magnitude of like you know, four to five times cheaper than Opus per query. So, if you're paying like API or pricing rather than a monthly plan, um you know, you might want to see if 5.3 is going to cut it for you. Uh on the benchmarks, they're like pretty much neck and neck for a lot of them. I would say that 5.3 does a little bit better job at being like an like a agile executor. So, like if you have a specific bug or you have a specific feature that you want to add, um and it's like, you know, not a like a huge system redesign, uh I've been really good luck with 5.3. Another thing to know is that OpenAI 5.3 Codex that they actually released a Codex desktop app for Mac endpoints. And this is very similar to like the Claude co-work app that they released previously, where essentially you just give it a job, and then it doesn't even really show you the coding stuff it's doing on the background. It just comes back when it completes it and says like, "Yeah, job done. We're good." Um and then it's got like a button where you can open up like an a full IDE, like you can open up Cursor or VS Code or something like that if you actually want to go in and debug the code, but I think they're trying to like make it more user-friendly so that like anybody can use it besides just like, you know, like hardcore engineers. Which honestly like I I like the Codex app. It's really easy to use. It's like a very clean interface. And historically I I haven't liked a lot of the OpenAI Codex user interfaces. They had like a web interface and they had a CLI. And I just always thought Claude did a better job. Anthropic Claude did a better job on those tools, but yeah, I have to say I do like the interface on the Mac Codex app. It's just very clean, slick, and like to the point. Um >> [snorts] >> yeah, I like it. It's a it's a good setup. Uh as far as like the benchmarks go, >> That's Xcode, right? Same thing. Is that what you're talking about on the Mac? >> Um no, like Xcode is uh the one developed by Apple, which >> Okay. >> By the way, they just released a big update to Xcode this last week. Or maybe it's 2 weeks ago, one of those. And essentially, they >> [snorts] >> they do they're doing a lot of integrations in Xcode now with AI agents. So like Xcode can now call out to Claude Code and like debug issues related to like developing mobile apps. Um so there's like some pretty cool integrations there. So if you are an Xcode developer, I would definitely check those out cuz Apple did like a big announcement. I feel like they didn't really get much press coverage about their Xcode updates. Um I feel like everyone's kind of like negative about Apple in the AI space right now because like they don't see it as like innovation, you know? It's just like incremental stuff, and so it doesn't like register enough to like hit the news cycle, but >> [snorts] >> you know, if you are an Xcode developer like on Mac, I would definitely check out their updates. They sound pretty legit. And I think their strategy is honestly like pretty solid with Xcode cuz they're like like everybody else is developing like a coding agent. Like why are we going to go reinvent the wheel? Like we'll just make Xcode to develop iOS apps integrate really well with those other tools. >> Yeah. >> And then cuz developers are saying like, "Hey, we want to use those tools." So they're like, "Well, let's just do what Xcode does well, which is kind of like the user interface design, other stuff like that, IDE environments. And then let's have the coding agents do what they do well on the back end." So I don't I honestly don't think their approach there is bad, but I understand why it didn't get a ton of news cycle. >> I'm still hung [snorts] up on the names. So, XCode with Codex and iPhone with phone eye. >> [laughter] >> Yeah, the names are all bad. Let's be honest. Let's be honest, man. Codex is just XCode but the backwards, right? Like I don't That's not good. Uh >> It took all day to come up with that name, I'm sure. >> Sam Altman's pumped because Codex beat out Opus on the terminal bench. And terminal bench is like a benchmark about like building bash scripts or doing get commits or other command line commands, right? So, it it did it did it got like a 77% on that and Opus got about like a I don't know, like a 68%, right? So, it it did considerably better. I mean, 10% jumps like pretty good. Um but on like >> [snorts] >> OS World, which is the one where you see how well the model can control a computer like specifically like GUI apps, like Opus did better, right? Like about 10% better. Um >> Yeah. >> And then on the SweetBench, which is mostly like Python real-world coding challenges, um they both like were neck and neck. It was like the same. So, So, another difference that I noticed when just playing around with it is that you know, I don't and I've seen different anecdotal responses here. For me, Codex seems to be returning faster for the task that I've been giving it. Um I did talk with a friend and they said they felt like Opus was faster for their use cases. Um and I was doing a lot of Python development and they were doing a lot of JavaScript development. So, I don't know. Those are just two data points. I don't know if that's like, you know, everyone's experience, but uh >> [snorts] >> but uh you know, definitely I I would play around with them to see if one's giving you cuz if you're getting about the same results out of both of them, then you know, speed definitely becomes a major factor, right? You can get more done faster. Um and then also we talked about the cost aspect. So, what's up, Shelby? >> I was going to say or the cost, since one is >> Yeah, well, if you're paying for it out of pocket, definitely do Codex, cuz like you're getting pretty much the same results. Um you know, and then if you get stuck, maybe switch over to Opus. That was actually my thought process right now is like it seems like Codex is better at like bug fixes and tiny features. Um and so, and it's like five times cheaper. So, I'm just been using Codex for pretty much everything. And then, I mean, this is last 24 hours, so take with a grain of salt. And then when I hit something that like it's not doing, I just switch over and tell Opus to do it, and that's typically like much larger features. Um >> [snorts] >> And I have some integrations set up in Opus that I that I don't in Claude code with Opus that I don't quite have set up yet. Um for um for Codex. So, it's not like a one-for-one. Like I have a I have some browser integrations so that like Claude code can automatically control my Chrome browser and do other weird stuff. Just so that like I don't have to like I don't want to take screenshots of like what's going on in the web GUI of a website that's not working. Like you can go do that, AI. That's that's fine, you know. >> Are those the browser extensions you wrote? >> Uh initially, but now they actually they they have they have they have official ones now, right? So, I'm using Claude and Anthropic, they have an extension now that's officially supported. Um and then Microsoft built a Playwright MCP server to control like a headless version of Chrome. Um and so, those are the two that I like primarily rely on for browser control right now. Um and I would say that the Playwright one's faster, like a lot faster. Um but there's some I just feels like sometimes like when I say like, "Okay, browse to it in Playwright and look at the errors in the browser's console." That like 80% of the time it works and then 20% of the time with Playwright it just is like, "I don't see any errors. Like, what are you talking about?" And so then I say like, "All right, go back and look at it again, but this time use like the Cod Code extension in Chrome." And it goes and browses and it's like, "Oh yeah, I see the errors now." I'm like, I don't understand what the difference is there. Maybe because like maybe Playwright doesn't do true like JavaScript rendering, so maybe there's some like bugs there. I don't know. I'm I'm not sure, but >> Interesting. >> That that is definitely uh My recommendation right now is try them both. See what you like the best. And if you don't have a strong opinion, I would just use Codax cuz it's a lot cheaper. And then when you get stuck, escalate to Opus. So, there's my recommendation. >> Excellent. Thank you for your personal research on that matter over the last 24 hours. >> Yeah, you'll get my you'll get my expert opinion, which will probably be different in another 28 hours. So, tune in for next week's episode so you can hear my update on which one I actually think is the best. >> There we go. >> So, what about you, Shelby? Anything else you've seen in the news? >> [snorts] >> Well, just a quick mention that um a cybersecurity company named Huntrix or sorry, Huntress. Huntrix, that would be >> Huntrix is like an anime, right? >> Yeah, HUNTRIX. >> YEAH, DEMON NURSE. >> HUNTRESS. >> You're such a fun mom. >> Huh? [laughter] >> You're such a fun person. >> When I get the wrong words out of my mouth. >> [laughter] >> All of a sudden we're just switching topics cuz I used the wrong word. >> [laughter] >> I think I think the audience would rather hear about anime. Let's be honest. So. >> [snorts] >> It's got great music. So, Huntress >> [laughter] >> recently found just um you know, more of the same shenanigans with a new attack vector. Basically, they found that if you did a Google search for how to clear disk space on your laptop or whatever. Um the top hit from Google would be a link to a reputable site. It was called chat GPT. Or as as as as you and I say, chat GPT. >> Chat GPT? >> Uh so you you click on this site because it's legit, it came from Google and chat GPT, and it will give you step-by-step instructions um including of how to accomplish your task of clearing disk space. Um so copy and paste these commands. Oh, by the way, that just installed malware. It's grabbed all your passwords. So, um AI is a great tool. However, the baddies also are trying to sneak their their shenanigans into it at all levels, right? And the I guess the key takeaway for us is just be skeptical. Don't trust that because AI is smart that it's got that it hasn't ever been fooled, right? Because it's always learning from the public. So, anytime AI or anyone else tells you, "Run this command," just give it another look before you copy paste it into your terminal. [laughter] So, that's my other story for you today. >> Yeah, I I once uh cuz I I did a lot of like pen testing red teaming. And so, I once had a client um he was like, "Yeah, yeah, your fishing attack worked. That's great." Cuz we were using something pretty sophisticated. He's like, "But he's like, you guys are like way too sophisticated." He's like, "Can you just come up with the dumbest fishing email ever and see if our employees will fall for it?" And I was like I was like, "Uh I've never heard anyone ask for that before, but sure. I'll come up with the dumbest fishing email I can create." And the dumbest email I could create was like, >> [snorts] >> "I am the IT department. The updates on your computer failed. I need you to copy and paste this command into the terminal and hit enter. And I got [laughter] ACTUALLY I ACTUALLY GOT USERS TO DO IT. LOOK, they actually literally like were like, "Oh, okay. I better update my computer." So, they copy and pasted the like malicious PowerShell script into the terminal and just hit enter and I got a callback of the boxes. I'm like, "It wasn't a lot, but I mean it wasn't as many as the like sophisticated fishing attack I got, but I think we got like on three people's computers like just from asking them to copy and paste commands, right? Like >> That's awesome. >> So, the fact that like attackers are doing this, I saw one this last week which was like uh imitating a Cloudflare CAPTCHA. It was like, "In order to solve this CAPTCHA, you have to press control C and then you have to like open a terminal and then press control V and then press enter." >> I see that. It's crazy. >> Yeah, I'm like, "Don't do it." If they're asking you ever to copy and paste a command, do not copy and paste something. Right? >> Yeah, your your spidey senses should be going off for sure. >> Yeah. Yeah. Yeah, I guess I guess that just brings up the point that like you know, you could have untrusted content on trusted websites, right? Like, you know, someone could get ChatGPT to create like some steps for you to follow and then post it on their website and then send you the link to that. So, so I almost like you need to treat some of these like content sharing features in the LLMs like ChatGPT as like social media posts. Like, people can get it to say arbitrary things. So, yeah, I guess yeah, just be cautious. Don't copy and paste things that especially if the website's telling you to do it. >> [laughter] >> I was like, "If you do it of your own volition, then maybe that's one thing. If the website's telling you to do it, probably don't do it." Right? Uh >> Seems sus. >> [snorts] >> Speaking of exploits, Shelby Anthropic Uh, they've got a they've got a pretty cool like offensive group over there and they took the latest model, so that 4.6 Opus model that I was talking about before. And guess how many high severity vulnerabilities they found in open source software. >> Lots. >> In the course of 1 week using the new model they found over 500 high severity vulnerabilities. >> And like existing open source software? >> Yep. Just open source software out there that everybody's importing and using as libraries. Sounds like some of the projects were things they were using in house that they just wanted to get more security validation around. And a lot of these projects have like had security researchers or you know, other bug bounty type programs looking at them for years, right? Um, and they've been unable to find things, so So you know, traditionally there's been two methods essentially for finding vulnerabilities kind of at scale. So, the first is you hire a bunch of humans, they reverse engineer the software, which is a very time intensive process and as part of that process they find vulnerabilities, right? So, that [snorts] was one end of the spectrum and that's kind of where a lot of these exploit developers came from. The other end of the spectrum, which was newer, maybe you know, 15 years ago this got really hot, is instead of spending all the time and effort of like understanding the software like let's just send a million inputs into the software and see what breaks. And that's essentially what fuzzing is. Like you're just trying every single input randomly and you watch the software crash and then you look at the crash and you say, "Okay, is this is this based on this crash and the input, do we think this is actually a security vulnerability or just like a bug in the software that's unrelated to a security thing. And so, using that, they were able to find a lot more vulnerabilities. But, now you have this weird cross-section in the middle where AI is able to do some of the same stuff a human does as far as like deep analysis, but it's also able to do some of the fuzzing um type activities where sending in random inputs. So, it's So, it's getting like a little bit more intelligent crossbreed between the two. And um so, it's uncovering like a set of bugs that previously like we just didn't have money to have humans manually do it um and that fuzzing wasn't smart enough to find. So, one was inside a Ghostscript, which is commonly used like anytime you go to a website and you're like, "Make a PDF." Like, 90% of the time on the background when you make a PDF, that's Ghostscript running on the server somewhere. Um and typically it's taking untrusted inputs from the user and converting it into a PDF. And a lot of vulnerabilities in this library over the years, like a lot a lot a lot of vulnerabilities. I've personally exploited several servers by taking advantage of Ghostscript uh vulnerabilities. So, it's long-standing, very hard to do that translation securely, is just what it comes down to. >> [snorts] >> Um and so, yeah, they were able to find some new Ghostscript 0-days uh that uh and they built proof-of-concept exploits for them. They also were able to find, and this breaks my heart, Shelby, right here. There is a library that almost everybody uses to create animated GIFs on the internet. You know, those little entertaining animated GIFs? >> Yes. >> They figured out a vulnerability in that process of building the animated GIFs that would allow the attacker to get code execution. Essentially, >> Oh, we can't have fun with anything anymore, huh? >> I know, you can't even build animated GIFs >> [laughter] >> like securely anymore. What is going on wrong with this world? I was about We all know what's going on in the news these days, and animated GIFs is is the worst of it. So, um >> Really top priority. >> [laughter] >> Really top priority. Of all the world concerns, animated GIF security We've got to get people on this. >> It's all people are talking about these days. >> Yeah, well, it's what they should be talking about. Let's be honest. Okay, so anyways, so there's like a mismatch in the It had like a deep understanding of the way the compression algorithm worked. So, like, in order to make those animated GIFs easy to share, they have to do like a compression. And then there's like reading of the files that are of the data that's compressed. And in that reading of the data that's compressed, there was a buffer overflow, which could be exploited to get code execution. So, imagine you just think you're going to look at a cute animated GIF of cats or whatever you look at GIFs of, and then an attacker's on your device. So, >> And this is regardless of what app you're using to send these? >> As long as the app uses this library underneath it to process and display you the animated GIF, which a lot of apps out there use this library. It's called the C GIF library. Uh the letter C, and then GIF. Um Yeah, a lot a lot of things use it under the hood. So, >> Well, I'll just go sit over there and pout. You let me know when it's safe to start looking at these again. >> [laughter] >> Well, luckily for you, the LLM, the AIs, they also wrote the patches for these vulnerabilities, and they submitted the pull requests back to those uh the projects. And the ones that we talked about right here have been patched. So, um it will I mean it's a library, so it requires that like the people that include that library update their software to include the new library version that is not vulnerable anymore. So, which can sometimes take some time to get like through the whole ecosystem of software, but >> thing we know that people always patch really quickly. [laughter] >> But they never wait for 7 years to go by before they patch it. >> Yeah, they never ever just forget about dependencies and be like, "Uh, who's going to know that isn't up to date?" >> [laughter] >> They like They're like, "We'll update that rapidly right before the acquisition." >> But like an RCE [laughter] from that, yeah, that's that's non-trivial. >> Yeah, yeah, it's kind of a >> everyone should be patching. All right, all you see GIF users, see GIF users, owners, >> If you're an engineer out there and you're trying to delight your user by giving them animated GIFs, update that library now. Update it now, man. That's [snorts] my advice. >> Please and thank you. >> Um So, big picture, I mean, we're hearing about the wins that the AI labs are giving us on the cybersecurity side. We're not necessarily hearing about the wins that the attackers are having by leveraging the same technology to find volns cuz they're not disclosing those back to the public, right? So, Bryce prediction, right? You know, we're going to see a uh uptick in 0-days, you know, 12 to 24 months from now. That's because it takes typically about at least 6 months for like an 0-day to burn. Like before researchers figure out that like people are using like a a vulnerability in the GIF processing library to get code execution on people's systems. So, anyways, I you know, I I think by the end of the year we'll definitely be seeing that upswing. Um I think the challenge of cybersecurity professionals is really like, how can we apply these technologies to one, you know, shift left and get the bugs out of the software before the attackers can get there. And then two, like come up with countermeasures to figure out things have gone wrong on our devices before you know, having to like typically the way things get caught in the real world is like you exploit a bunch of stuff as an attacker and then that causes some small percentage of availability issues, like crashes somebody's server. And then when they go to investigate why the server crashed, they're like, oh, because somebody hacked into it, basically. So so um and that's, you know, a process that gets kind of drawn out. So So yeah, anyways, it's it's going to be a fun ride, so stick around. I'm sure we'll have more updates on this. All right, well the one thing that I got to ask you is and I'm talking to you, the listener, what do you think the biggest cybersecurity threat that people are ignoring today is? And let us know in the comments below because then we'll talk about it more next week. So um Shelby, you got anything fun for us that you've seen in the last week? >> Well, yesterday in Japan, they opened the Poké Park, Kanto region. >> Ooh, that's cool. >> is like the first, I think, like permanent um location where it's a theme park all about the Pokémon games. So you walk into this theme park and you feel like you've stepped into the games. There are like herds of Pikachu running around. They all have like um like unique faces and stuff and Psyducks and there's a really tall Onix that you can walk by and discover. So, you kind of just walk through this park and discover them. I'm sure they have activities and stuff, too. Um But, yeah, just yesterday it officially opened. And so, you know what this means? I need to go to Japan. >> Yeah, my my kids really want to go to Japan, as well. And they don't even know about this Pokémon park. So, this is like a This looks incredible. This looks cool. I want to go. >> Yeah, I'm not sure how hard it is to get tickets right now, because it's probably really It's all the hotness, but um >> I'm sure it's impossible. >> Worth the >> the time I make it over there >> [laughter] >> Might as well be you. Might as well try. >> Yeah, I I still want to go out to the Orlando parks, the the new Universal one. What's that called? Universal something, universe or something. >> Studios? Universal Studios? Or is it something different? >> different, new. Well, they have like a new land or a new park that has like the Mario land in it, and it's got the >> Oh, yes. I've been to that park. >> How to train the Dragon land and all that. Have you seen >> I haven't I haven't been to that park. So, I've been to the the park that was um like the Mario world. >> You did? That's cool. >> in Japan. >> Oh, in Japan. Okay. All right. >> Just so perfect. It was great. And it was really cute. As a fan, I loved it. You get to ride like little Yoshis around the top, and >> Ooh. >> punch the the little question mark boxes. Yeah. >> That's cool. >> mind going back there. What about you? What's new? What's What's good? >> Well, I found out through a reliable source that the Super Bowl is coming up this Sunday. And this is how I found out, Shelby. There was like a bunch of news press coverage about new commercials that are coming out that are talking about It was like basically Anthropic was throwing shade at OpenAI for OpenAI's plans to put ads into ChatGPT responses later this year. So they had a bunch of like commercials they made ripping on them. And then I somehow put together I was like, why are they making commercials about ripping on their competitor? I was like, why randomly are they just doing that now? And then I read one of the articles and it's like, and these will be first launched on Super Bowl weekend or whatever and I was like, okay, it's the Super Bowl. It's commercial time. Let's just be honest, man. The commercials are better than the the game. So I am sorry if you're a sports man, but uh but uh so these commercials are pretty entertaining. Uh so it's like a guy is talking to his grandma and then all of a sudden his grandma responds with like an ad like in the middle of the conversation, you know? So it's like very unexpected and kind of jarring. >> Do you know that? Do you know that? >> Yeah, apparently somebody got a cut I don't know if like Anthropic released them or who, but these commercials are definitely out there and I I mean I guess, you know, like they got to give the commercials to the networks that are going to air them as part of the event, so I don't know when they did that, but I mean they're they're up on YouTube right now, so I watched two of them last night over when I was hanging out with a friend. And then I saw a third one this morning referenced on social media somewhere that I haven't seen yet, so the [snorts] two I watched last night were pretty hilarious, so anyways, if you're looking for a good laugh >> know that they would like release before I guess unofficially leak >> I don't know if they were leaked or like officially released. I don't know. It seems weird to me too. Typically you don't see the commercials until the day of the game, but >> [snorts] >> but apparently >> even have to tune into the at all cuz you already saw the best part. >> Exactly. I saw AI commercials throwing shade at each other. Apparently Sam Altman at OpenAI was not happy about the commercials. He did a big reply on Twitter {slash} X and X post reply saying, "That's not what we meant when we said ads are going to be coming. >> [snorts] >> This is categorically false." >> [laughter] >> He's like, "Oh, looks like there's some negative backlash. Uh never mind, that's not what we meant." >> Yeah, I I mean on the Sam Altman side like I do think the commercials are portraying the ads that experience that they were going to insert into ChatGPT um differently than what Sam Altman was saying the ads are going to be like. Like like the commercials are portraying them as like injecting into the conversation, right? Um almost in like an abrupt way where >> [snorts] >> OpenAI said like they're going to be like additional data tacked to the bottom of the reply that's clear it's an ad, right? >> That's important. >> But with that being said I mean ads are a slippery slope. Let's just be honest, right? And so foreseeably you know, once you have to increase revenue you're probably going to do what advertisers want and eventually you're probably going to end up in a scenario that's similar to these commercials where you know, maybe that's not a 2026, but you know, by 2030 I mean you could definitely see things similar to what this commercial's like and everyone being so normal like everyone being so used to it. They're just like, "Oh yeah, that's the way the internet works now, you know? There's just random ads that get injected when I'm trying to figure out stuff for research, you know?" So I'm not looking forward to that future and I think uh >> Yeah. Not a big fan. I will I'm excited to see the the ads that mock it [clears throat] then. >> [snorts] >> Okay, I'll send you some links. >> I'll send you some [laughter] links. >> Thanks. Oh, yeah, early preview. That's right. >> Yeah. >> Cool. >> All right. Well, thanks thanks for hanging out today, Shelby, and everybody on listening on the line. Uh, you know, [snorts] what do you guys think? What do you What do you think is going to be the new hotness? Do you like the new OpenAI model or the new Anthropic model better? Do you Which one's better at coding? Do you think Shelby should go to the new Pokémon park in Japan? Leave it in the comments below. >> [laughter] >> And we'll see you next time. Thanks. >> Bye.