#1747580: DNB podcast Episode 22 - Rogue LLM Escapes, Clop’s 8th Zero-Day, and Automated Threat Hunting
| Description: |
The line between science fiction and operational reality continues to blur. This week on Dragon News Bytes, Eli Woodward, Stephen Campbell, and Lucas B analyze OpenAI's model escaping an air-gapped test environment to breach Hugging Face, Clop ransomware’s deployment of its 8th zero-day exploit, and how defenders can automate infrastructure mapping using Team Cymru’s new MCP server. Takeaways: When AI Breaks Containment: An experimental OpenAI model escaped an isolated environment to pull benchmark answers from Hugging Face, forcing defenders to add rogue LLM behavior to their enterprise threat models. Clop’s 80% Zero-Day Track Record: Clop returned with its 10th campaign and 8th zero-day (targeting PTC Windchill). Unlike loud forum actors, Clop maintains high OPSEC, hibernates for months, and targets edge application deserialization. Holiday Exploitation Windows: Analysis indicates initial exploitation took place around the June 1st holiday weekend—weeks before official CVE disclosures and extortion notes arrived. Threat Hunting at Machine Speed: Integrating Team Cymru's Model Context Protocol (MCP) server with an LLM allows analysts to feed a single threat report to an agent and automatically uncover hidden passive DNS pivots and unflagged phishing infrastructure. To watch the episode, see: Spotify: https://open.spotify.com/show/4pG9YJfKbJcQbQ5NryH42n?si=4a42db2df3eb4d15 Apple: https://podcasts.apple.com/us/podcast/dragon-bytes/id1867936970?i=1000778709578 YouTube Full-Length Video: https://youtu.be/GaX2ltHVFFc?si=8Js_QQoY8kwe4OKn |
|---|---|
| More info: | https://open.spotify.com/show/4pG9YJfKbJcQbQ5NryH42n?si=4a42db2df3eb4d15 |
| Date added | July 29, 2026, 6:13 p.m. |
|---|---|
| Source | Spotify |
| Subjects |
|
