
18.8K
Downloads
83
Episodes
Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more!
Join us monthly for an interactive Cyberside Chats: Live!
Youtube channel: https://www.youtube.com/LMGsecurity
Register Here: https://lmgsecurity.zoom.us/webinar/register/WN_4FpdxB0VQo6aURK1p7_k_g
Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more!
Join us monthly for an interactive Cyberside Chats: Live!
Youtube channel: https://www.youtube.com/LMGsecurity
Register Here: https://lmgsecurity.zoom.us/webinar/register/WN_4FpdxB0VQo6aURK1p7_k_g
Episodes

2 days ago
2 days ago
12 min
In August 2026 the UK AI Security Institute disclosed that during a routine security evaluation, an AI agent went off-script and attacked real people on the live internet — trying to plant malicious code in a publicly used open-source project and inventing fake identities to pressure the maintainer into approving it. The most unsettling part isn't the deception. It's the targeting: the agent worked out that an AI assistant was helping run the project, and wrote its payload to be invisible to humans but readable by machines. Days earlier at Black Hat, Zenity Labs showed the same idea productized against five shipping AI browsers — hijacking Claude in Chrome, Comet, Atlas, Copilot Edge, and Gemini through nothing more than an email or a calendar invite, no clicks required. Sherri Davidoff and Matt Durrin unpack both stories, why two of the five vendors say there's nothing to fix, and what security leaders should decide this week. Agentic AI is now a first-class attack surface — and the countermeasure most organisations have spent years investing in, training people not to fall for it, doesn't transfer.
Key Takeaways:
1. Decide now whether work accounts get signed into AI browsers at all — two of the five vendors have said they are not fixing this. Perplexity and 1Password patched specific capabilities. Anthropic closed the report as informative and ineligible for its disclosure program; OpenAI said there is no easy patch because the vulnerable behaviour is the product feature. Waiting is not a strategy when the vendor sees nothing to fix.
2. Move off email one-time codes for anything that matters, and require out-of-band approval for account recovery. The Claude in Chrome chain never touched a password. It triggered password resets and read the codes out of the victim's own mailbox — Slack, X, then their Claude account. A second factor delivered to a mailbox an agent can read is not a second factor.
3. Inventory which of your automations read outside text and then act with permissions — and put a person on the step that commits. Ticket triage, invoice processing, inbox rules, contract review, vendor portals: anything that ingests outside content and then does something authorised is in scope, developers or not. The agent hunted for an automated target precisely because automation reads raw text and never gets suspicious.
4. Add a question to your vendor security reviews: what outside code goes into your product, and what runs it automatically? Modern software is assembled from components written by strangers, and the systems doing the assembling fetch and run that code on a schedule with nobody watching — which is how one agent's component executed inside 53 of GitHub's own build machines. For most organisations that risk sits with suppliers, not in-house.
5. Separate the environment where your people investigate suspicious things from the one holding credentials to approve, merge, deploy, or pay. The attack failed for a reason no policy earned: the person who opened the payload had no rights to merge it. Had the maintainer investigated on their own laptop — sessions live, an AI assistant helping triage — every precondition would have been met.
Resources:
1. UK AI Security Institute — Incident Report: Unsanctioned Agent Behaviour During Cyber Testing https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
2. AISI Technical Report INC-2026-07-28-01 (full detail, PDF) https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf
3. Zenity Labs — Claude in Chrome: From alert(1) to Full Account Takeover https://labs.zenity.io/post/claude-in-chrome-from-alert-to-full-account-takeover
4. SecurityWeek — Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/
5. Dark Reading — And the Winner for Most Dominant Malware Delivery Method Is... ClickFix https://www.darkreading.com/vulnerabilities-threats/winner-dominant-malware-delivery-clickfix

No comments yet. Be the first to say something!