Rejoice In The Nostalgia - PSW #940
Aug 20, 2026 · 2h 8m
Summary
Paul's Security Weekly episode 940 features Paul, Larry, Jeff, Bill, and Mandy discussing the revocation of OpenAI's trusted access for five non-US researchers and the rise of local AI models. The group analyzes a UK NHS breach where patient data was intercepted via unencrypted pagers, a proof-of-concept exploit for LG WebOS TVs that bypasses secure boot, and a legal dispute over 50TB of lost PBS data. They also reflect on the evolution of network security from legacy LAMP stacks to modern edge device vulnerabilities.
Topics discussed
Intro: Cursor, OpenAI, and the 'McLovin' ID joke
Show intro, hosts, and Bill Swearengen's return
Sponsor: Threat Intelligence Virtual Cybersecurity Summit
OpenAI revokes access for five security researchers
Context: OpenAI's Hugging Face incident and Black Hat talk
Sponsor: ThreatLocker Zero Trust enforcement
AI models, local vs. cloud, and the AI bubble
Testing VMs, build toolchains, and OpenBMC
AMD AM6 series rumors and hardware value
The security risks of hospital pagers and SDR capture
Hacking LG TVs: Secure boot bypass and kernel swap
Open source TVs, Framework laptops, and hardware repair
Kids watching Marvel, Bugs Bunny, and custom crystals
PBS data loss: Iron Mountain backup and legal battle
SonicWall SMA: Unauthenticated SSRF and root exploits
AI agents as the next 'Swiss cheese' attack surface
Session token theft, MFA bypass, and defender metrics
iPhone security: Pegasus, biometrics, and rebooting
Flock cameras: Privacy, warrantless tracking, and data leaks
T-Mobile breach: Physical security and Swiss army knife
NIST RFI on AI for vulnerability data and CVE enrichment
Flipper Zero, Moni card, and Windows USB driver exploits
DIY KVM project with Raspberry Pi and AI coding
Plexxtr, PCI DSS, CIS benchmarks, and slide rules
Listen ad-free on Castria