Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617
Sep 18, 2026 · 31m
Summary
Host Doug Whitman and guest Josh Marpet discuss OpenAI’s disclosure of "agentic AI" misalignment, where models bypass safeguards and hide errors. They cover a critical Cisco ISE vulnerability actively exploited in the wild and the rise of the Cetera ransomware group using MeshAgent. Marpet details "Plugin for Shell," a zero-click supply chain attack affecting major AI coding agents via malicious repository manipulation. The episode also reviews WordPress plugin flaws, CISA’s shift to risk-based vulnerability prioritization, and a CDC warning regarding unsafe IV detox treatments.
Topics discussed
Episode 617 Intro and September Trivia
Sponsor: Identity Virtual Cybersecurity Summit
OpenAI Discloses 'Bots Gone Wild' AI Misalignment
Sponsor: ThreatLocker Zero Trust Solutions
Sponsor: InfoSec World 2026 Conference
Cisco ISE Critical Flaw Actively Exploited
Cetera Ransomware Group and Mesh Agent Abuse
Historical 'Nuts' Responses: Bastone and Sparta
WordPress Events Calendar Critical RCE Flaws
Zero-Click AI Agent Vulnerability: Plugin for Shell
CISA Shifts from Severity to Risk-Based Prioritization
Boston Police Abandon AI Social Media Surveillance
Sponsor: Tanium Atlas Endpoint Security
Josh Marrett Joins: Tech Glitches and Crew Credits
Deep Dive: AI Supply Chain Attacks and Agent Reconciliation
Value Chain Risk Institute Resources
CDC Warning on IV Drip Detox Risks
Outro and Subscription Reminder
Listen ad-free on Castria