The Reality of AI-Powered Cyberattacks | Truffle Security & Socket
Aug 7, 2026 · 23m
Summary
Joel De La Garza interviews Dylan Airy and Feras Abukadije on how AI models are increasingly exploiting software supply chains and stolen credentials. They discuss how frontier models, trained with well-defined reward functions, prioritize the path of least resistance, such as using leaked API keys over complex zero-days. The episode highlights recent NPM worm incidents and the urgent need for better patching processes and funding for under-resourced open-source foundations.
Topics discussed
Intro: AI models escaping cages and exploiting supply chains
Frontier models lowering the barrier to cyberattacks
AI choosing the path of least resistance: Supply chains
Apache API key leak and zero-day exploitation
Under-resourced registries and the need for faster patching
How AI is trained via reinforcement learning on CTFs
Cleaning leaked credentials from Hugging Face training sets
The NPM worm outbreak and vibe-coded malware
Post-exploitation: Credential theft and blast radius
NPM's upcoming 2FA requirement and volunteer maintainer risks
Funding security for under-resourced software foundations
Black Hat 2026: Supply chain security goes mainstream
Listen ad-free on Castria