Smashing Security Smashing Security

AI gets hacked, and BitLocker gets bypassed

Jun 17, 2026 · 1h 12m

Summary

Graham Cluley and Paul Ducklin discuss how AI coding agents can be hijacked via fake Sentry error reports to execute malicious code, bypassing traditional security. They also cover Nightmare Eclipse’s full disclosure of zero-day exploits that bypass Microsoft Defender and BitLocker, sparking a debate on responsible disclosure. The episode concludes with a look at the FBI’s kinetic cyber range, a simulated town used for training law enforcement in cyber investigations.

Topics discussed

Intro: AI hacks, fake breaches, and episode overview Sponsor: ProtonPass password manager features AI Coding Agents: The Sentry error injection attack Analysis: Why the Sentry attack works and vendor response Sponsor: Vanta compliance automation Nightmare Eclipse: Microsoft bugs and BitLocker flaws Sponsor: CoreView Microsoft 365 security checks Pick of the Week: FBI cyber range and Linux hotspot Guest: Sun on AI agent security risks and permissions Outro: ProtonPass trial, credits, and ZipRecruiter ad
Listen ad-free on Castria