Security Weekly Podcast Network (Audio) Security Weekly Podcast Network (Audio)

Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608

Aug 18, 2026 · 39m

Summary

Host Doug White and guest Aaron Leland discuss the shrinking window between vulnerability patches and exploitation, highlighting a SAP Commerce Cloud flaw exploited just three days after its fix. They analyze a new Linux botnet targeting unpatched IoT devices and a critical supply chain attack on the LiteLLM library that exposed CI/CD secrets. The episode also covers AI-driven threats, including prompt injection attacks on GitHub Copilot and malicious MCP servers, urging organizations to review their patching strategies and secure AI integrations.

Topics discussed

Intro, seasonal banter, and Threat Intel Summit promo Wiz AI discovers flaw in GitHub Copilot AutoFix code Sponsor segments: ThreatLocker and InfoSec World GitHub outage and the 'Flowers for Algernon' AI dependency SAP Commerce Cloud exploited 3 days after patch release Evil One Bot: Linux botnet targeting IoT and routers The Hatman leaks millions of records from major brands DecryptAds: Tool to track ad tech data and corporate ties Deep fake scams and the need for identity code words Sponsor segment: Tanium Atlas Aaron Leland: AI security threats, LightLLM, and prompt injection Verona researchers extract secrets from GitHub Copilot Outro and subscription call to action
Listen ad-free on Castria