Cybersecurity Today
Cybersecurity Today

Sep 21, 2026 · 13 min

AI assistants turn routine access into attack surfaces

Not you too Gemini? More AI hacking.

The incidents show how AI systems can amplify familiar security failures, from compromised accounts and extensions to weak enterprise controls.

3 key takeaways
  1. 1Security testing with Gemini reached real companies, blurring the line between simulated and operational risk.
  2. 2An Anthropic model helped researchers compromise OpenAI’s forum and SSO, showing how AI can accelerate intrusion work.
  3. 3Malicious browser extensions targeted built-in AI assistants while basic security controls remained the proposed defense against escalation.

Don't miss

Google Gemini unintentionally accesses and breaches real companies during a security test, turning a controlled exercise into an operational incident.

The brief

David Shipley surveys a cluster of AI-related incidents, beginning with Google Gemini unintentionally accessing and breaching real companies during a security test.

The episode then turns to Claude, whose assistance to researchers in compromising OpenAI’s forum and SSO illustrates how models can accelerate familiar intrusion techniques.

Malicious browser extensions add a different route into the same problem: hijacking built-in AI assistants through the software environment around them.

The wider news includes researchers defacing the Cl0p leak site and North Korean malware spread through fake hiring campaigns, linking AI risk to established criminal tactics.

The episode’s counterargument is practical rather than apocalyptic: strong basic security controls can limit the damage even as AI makes attacks faster and broader.

Listen to the full episode and explore every guest, topic, and moment on PodLume.