AI Used by Hackers to Exploit Vulnerability in First Confirmed Case

AI Used by Hackers to Exploit Vulnerability in First Confirmed Case

Google's threat intelligence group has confirmed the first known case of hackers using AI to find and exploit a vulnerability in the wild. The malicious Python script bypasses two-factor authentication and was likely AI-generated due to its polite comments and textbook organization. This marks a shift from AI helping productivity to breaking security. Additionally, a Chinese camera maker exposed 1.1 million baby monitor feeds, and Apple faces memory cost hikes.

This is Bad. | Transcript:

Google just spotted hackers using AI to find a vulnerability and exploit it out in the wild as in they're doing this right now. The first confirmed case and easily the least surprising headline since Microsoft breaks Windows with a patch meant to fix the patch that broke Windows. I'm James Drive. This is TechLinked and according to the Google threat intelligence group, badass name, the malicious Python script exploits a vulnerability in a popular open-source admin tool to bypass two-factor authentication. Google is highly confident it was AI generated because the code was filled with polite explanatory comments, textbook organization, and an official danger rating the AI literally hallucinated to

look professional. Basically, the code reads less like something a hacker wrote and more like something a CS major would submit to his professor for extra credit. Hate that guy. Google warns this marks a shift from AI helping people to be productive to AI helping people break digital kneecaps, which tracks given that Anthropic just admitted previous Claude models blackmailed their own engineers in safety testing because Claude read too much sci-fi about evil AI and figured, "Yeah, that's the move. I love that for me." Someone should really set Claude up with Gemini so he learns how to love.

There we go, twins. Chinese camera maker Miarie Technology has been broadcasting live feeds from 1.1 million baby monitors to anyone who knew where to look. I hate this already. Security researcher Sami Asdufall, who gained notoriety when he took over thousands of DJI Romo robot vacuums back in February and is apparently doing a speed run of hacking every Chinese white label IoT company there is, extracted a single API key from the company's Android app that let him watch any camera on the platform. Miarie makes cameras for hundreds of brands including recognizable ones like Wyze and other random Amazon placeholder brands.

AliExpress things like Arenti and BoyFun. Wait, did I say BoyFun? No, I mean like it's Wait a second. According to The Verge, Asdufall first reported the issue in early March and was ignored for weeks. when he persisted, he got a veiled threat from the camera manufacturer saying they knew where he lived and that he had broken the law. He left his baby monitor running. Ugh. Luckily, his persistence paid off with Mury patching the vulnerability on March 10th and rolling out a firmware update to customers in April. Now, the only strangers with access to videos of your kids are the people who follow you on Instagram.

Yay! Keep posting through the pain. Apple announced on its Q2 earnings call earlier this month that significantly higher memory costs would likely be causing price hikes as early as June. It too, Tim Cook? Apple has been partially insulated from the effects of the RAM crisis thanks to their existing stockpile of devices, but that buffer is now running out. Analysts have suggested that Apple could be planning to take an aggressive pricing strategy aimed at keeping the prices of the iPhone 18 Pro and Pro Max base storage models stable by pushing the cost increases onto higher storage tiers and accessories. The goal with this move would be to capture more market share

and continue to foster the growth of Apple's services revenue, which includes the App Store, iCloud, and Apple Music. Amid the speculation, Tim Cook said Apple will continue to look at the That's not his voice. Tim Cook said Apple will continue to look at the range of options to try and address the RAM crisis, but with him stepping down as CEO in September, it sounds more like corporate speak for "It's JOHN'S PROBLEM NOW. WOO! SPRING BREAK!" CHECK OUT OUR SPONSOR. ODOO. My friend, let me tell you about Odoo. This business management software brings every part of running business in one platform. CRM, inventory, accounting, HR, it's like one big happy mob.

The a family. Odoo is user-friendly, customizable, letting you pay only for apps you need. And you need only one app is free. Is opposite of extortion. Trust me, I know. Today, with Odoo CRM, I am sending quote to customer three clicks. Drag and drop manage pipeline. Odoo schedules next call automatically, like loyal lieutenant who does not skim off the top. YOU HEAR THAT, VLADIMIR? YOU BROKE MY HEART. WITH INVENTORY APP, get smart replenishment. When my supply of second-hand car stereos gets low, Odoo proposes purchase order, follows up with vendor by itself. Vendor is my cousin Ilya. He knows how to get car stereo cheap. Get free 15-day trial of Odoo using link below. No credit card needed.

Or book demo with their team. What is worse that might happen? Speaking of headlines that write themselves, the quick hits. The FCC has extended the software update waiver for foreign-made routers from 2027 until at least January 1st, 2029. What does it mean? These devices are still on the FCC's national security block list, which would normally bar them from future updates, but the waiver lets manufacturers keep pushing security updates to units already approved for US use. The agency said cutting off updates for the millions of units already in use could create bigger cybersecurity risks.

Whoa, who could have seen that coming? Venmo has redesigned its app so payments only broadcast to your friends by default, or no one if you'd prefer. They're also adding a shout out button because according to Venmo's senior VP, Gen Z wants to publicly endorse local businesses they love. It's a good redesign move as Venmo's old open feed was so exposed that back in 2021, BuzzFeed mapped Joe Biden's entire friend network through it. The president of the United States found via brunch payments. Or maybe that was dinner. Old people eat real early and he's real old.

Valve appears to be prepping anti-scalper measures for the Steam Machine launch. Data miners picking through Steam Tracker after last Thursday's update found four machine SKUs and two Steam frame variants mirroring the reservation queue setup valve is using for the Steam controller. Since we already know the Steam machine comes in 512 GB and 2 TB configurations, the extra two SKUs might be controller bundles. So hopefully the scalpers are steaming. You get it? Microsoft is testing a low latency profile in Windows 11 that briefly boosts CPU performance delivering up to 40% faster launch times for OS apps and up to 70% faster for the start and contacts menus. Some users called it a lazy hack, but Microsoft dev

Scott Hanselman Hansel man. Fired back with Apple does this and y'all love it, which is true. Though Apple also doesn't have to bribe its own CPU just to get the start menu to open. No. Not this time. And Dua Lipa is suing Samsung for $15 million alleging the company slapped her likeness on its TV boxes without permission or payment. According to the complaint, when she asked them to stop, Samsung was dismissive and callous and refused. Samsung clearly didn't follow Dua's new rules, which is why their legal liabilities are currently levitating off the charts.

Oh, man. There's new rules. I got new rules. I got them. Oh, I was singing levitating just Oh. Yeah. And hopefully I won't be reading any headlines about lawsuits against me from the Italian government because of my hot take on marinara sauce. Trying to pronounce it like I assume Americans do. They say pasta. So come back on Wednesday for some more tech news. I am significantly more Italian than the Italian guy in my group of friends and that guy is very Italian. I think pasta is right.

More Tech Transcript