Mythos finds a curl vulnerability - 2026-05-18
This episode covers Mythos uncovering a vulnerability in cURL, a recent Google Threat Intelligence report on a zero-day exploit, and the growing impact of AI on capture-the-flag competitions and bug bounty programs. The hosts also discuss the economics of AI platforms like OpenAI, security research trends, and broader concerns around software vulnerabilities, automation, and defensive tooling.
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
Links
Story # 1: Mythos finds a curl vulnerability
Story # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
Story # 3: The down fall of bug bounties
Story # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat Robots
Story # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting Obliterated
Story # 5: Windows BitLocker zero-day gives access to protected drives, PoC released
Story # 6: Deal reached with hackers to delete data stolen from the Canvas educational platform
Story # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breach
Story # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible
Threat Hunting Summit Talk: Threat Hunting in the Dark: A Practical Approach
WEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek Banks
Click here to watch this episode on YouTube.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴live-chat
Chapters
- (00:00) - PreShow Banter™ — Token CTFs
- (03:18) - Story # 1: Mythos finds a curl vulnerability
- (06:36) - Story # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
- (14:47) - Story # 3: The down fall of bug bounties
- (15:34) - Story # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
- (40:52) - Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat Robots
- (43:51) - Story # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting Obliterated
- (49:35) - Story # 5: Windows BitLocker zero-day gives access to protected drives, PoC released
- (56:09) - Story # 6: Deal reached with hackers to delete data stolen from the Canvas educational platform
- (58:07) - Story # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breach
- (58:54) - Story # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible
- (01:00:29) - Threat Hunting Summit Talk: Threat Hunting in the Dark: A Practical Approach
- (01:04:47) - WEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek Banks
Links
Story # 1: Mythos finds a curl vulnerability
Story # 2: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
Story # 3: The down fall of bug bounties
Story # 3: Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Story # 4: Germany to Flood Ukraine’s Front Lines With Hundreds of New GEREON Combat Robots
Story # 4b: Wild Video Shows Delivery Robots Causing Havoc, Getting Obliterated
Story # 5: Windows BitLocker zero-day gives access to protected drives, PoC released
Story # 6: Deal reached with hackers to delete data stolen from the Canvas educational platform
Story # 7: Celebrities’ and influencers’ private communications exposed in stalkerware data breach
Story # 8: Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible
Threat Hunting Summit Talk: Threat Hunting in the Dark: A Practical Approach
WEBCAST: Looking at A.I. Wrong with John Strand, BB King and Derek Banks
Click here to watch this episode on YouTube.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Brought to you by:
Black Hills Information Security
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest
Episode Video
Creators and Guests
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Host
Hayden Covington
Hayden Covington joined Black Hills Information Security (BHIS) in the Summer of 2022 as a SOC Analyst. He chose BHIS after hearing many great things over the years and seeing the quality of work, as well as finding people who have the same passion for the field as he does. His favorite part of the job so far has been the community. Previously, Hayden worked in a SOC for a Naval contractor, where he also served as their SOAR project manager and SME, as well as insider threat lead. When he’s not working, Hayden can be found doing anything athletic (like triathlons!), as well as enjoying video gaming and Formula 1.
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Host
Wade Wells
Wade Wells has been working in cybersecurity for a decade, focusing on detection engineering, threat intelligence, and defensive operations. Wade currently works as a Lead Detection Engineer at 1Password, where he helps build and mature scalable detection programs. Outside of his day-to-day work, Wade is deeply involved in the security community through teaching, mentoring, podcasting, and running local events
Guest
Shane Hartman
Shane Hartman is a Principal Incident Response Consultant at TrustedSec, specializing in advanced threat hunting, forensic triage, and intrusion analysis. With over 30 years in IT and two decades in information security, Shane helps organizations detect, investigate, and contain targeted attacks against critical systems and intellectual property. His previous roles at FireEye, Fortinet, and RSA focused on malware reverse engineering, threat intelligence production, and adversary tradecraft analysis. He frequently presents and teaches at the University of South Florida on topics including Digital Forensics, Ethical Hacking, and Offensive Operations.