AI Security Ops

AI News Stories | Episode 63

July 27, 2026·23 min
Episode Description from the Publisher

In this episode of BHIS Presents: AI Security Ops, the team follows a single trend that is changing the economics of cyberattacks:The machine-speed attacker is no longer theoretical.Across four stories from a single week, we watch AI move through every stage of the attack lifecycle. First it writes exploits from public patches. Then it discovers and weaponizes vulnerabilities. Next it helps attackers build phishing infrastructure like a software company. Finally, AI agents begin carrying out ransomware operations with minimal human intervention.Each story stands on its own. Together, they paint a much bigger picture.The window defenders have relied on for decades—the time between disclosure and exploitation—is rapidly disappearing.We dig into:• How Anthropic demonstrated AI-generated exploits in under an hour• Why “N-day” vulnerabilities are becoming “N-hour” attacks• The AI-discovered WordPress wp2shell exploit chain under active attack• The ServiceNow AI Platform vulnerability and rapid weaponization• Why patching alone is no longer enough• How attackers are using generative AI to build phishing campaigns at scale• What Rapid7 uncovered inside a live AI-assisted malware development lab• Why behavioral detection still catches many AI-assisted attacks• JadePuffer and EncForge’s AI-driven ransomware targeting AI infrastructure• The debate around fully autonomous cyberattacks• What security teams should prioritize as attackers move at machine speedThis episode explores a critical shift in cybersecurity: AI is not creating entirely new attack techniques. Instead, it is dramatically compressing the time required to discover vulnerabilities, build exploits, develop tooling, and execute attacks.For defenders, the question is no longer simply “Are we patched?”It is:Can an attacker reach us before we finish patching, and would our controls actually stop them?—Key Concepts & TopicsMachine-Speed Attacks• AI-generated exploit development• Shrinking disclosure-to-exploitation timelines• Why patch windows continue to collapseExploit Development• Reverse engineering security patches• AI-assisted vulnerability research• Practical impacts on defender response timesActive Exploitation• WordPress wp2shell attacks• ServiceNow AI Platform compromise• Post-exploitation persistence and huntingAI-Powered Malware Operations• AI-generated phishing infrastructure• Automated testing and documentation• Scaling attacker operations with LLMsAgentic Ransomware• JadePuffer and EncForge• AI targeting AI infrastructure• Autonomous attack capabilities• Protecting model weights and AI assetsDefensive Strategy• Exposure management• Behavioral detection• Adversarial exposure validation• Protecting AI infrastructure and secrets• Prioritizing reachable risk over severity scores(00:00) - Intro: The Machine-Speed Attacker (01:20) - Story 1: When N-Day Becomes N-Hour (09:13) - Story 2: AI-Discovered WordPress and ServiceNow Exploits (15:59) - Story 3: Inside the AI Malware Factory (17:29) - Story 4: Agentic Ransomware Targets AI Click here to watch this episode on YouTube. Creators & Guests Derek Banks - Host Bronwen Aker - Host Brian Fehrman - Host Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com🔗 Register for FREE Infosec Webcasts, Anti-casts & Summitshttps://poweredbybhis.com Click here

Podzilla Summary coming soon

Sign up to get notified when the full AI-powered summary is ready.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.

Listen to This Episode

Get summaries like this every morning.

Free AI-powered recaps of AI Security Ops and your other favorite podcasts, delivered to your inbox.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.