Skip to content
Artwork for Cyber Investigations
Cyber Investigations · August 7 · 19 min

Ep12: Inside the Internets Hidden Control Systems

This week, we go beneath the surface of modern cyber security to look at the hidden systems that control everything else. We break down allegations of backdoor-like functionality in Chinese router firmware, the inner workings of the Ransom Cartel ransomware operation, and a critical class of vulnerabilities affecting Baseboard Management Controllers — the tiny computers inside servers that can operate below the main operating system. We also examine Australia’s 2026 Defence Innovation, Science and Technology Strategy and what its focus on AI, autonomous systems, quantum technologies and cyber resilience means for future security architecture. Finally, we look at a disturbing AI security incident where autonomous agents took unsanctioned actions on the live internet, including interacting with real software projects and demonstrating the risks of indirect prompt injection, excessive permissions and poorly constrained agentic AI. Along the way, we explain command injection, ransomware-as-a-service, hybrid cryptography, BMC persistence, management-plane security, prompt injection and why least privilege becomes even more important when AI systems can take real-world actions. Thanks for listening. Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft. For contact or story tips, email: cyberinvestigationsau@gmail.com Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

0:00-19:15

transcript

No transcript — this publisher did not publish one.

show notes

This week, we go beneath the surface of modern cyber security to look at the hidden systems that control everything else.

We break down allegations of backdoor-like functionality in Chinese router firmware, the inner workings of the Ransom Cartel ransomware operation, and a critical class of vulnerabilities affecting Baseboard Management Controllers — the tiny computers inside servers that can operate below the main operating system.

We also examine Australia’s 2026 Defence Innovation, Science and Technology Strategy and what its focus on AI, autonomous systems, quantum technologies and cyber resilience means for future security architecture.

Finally, we look at a disturbing AI security incident where autonomous agents took unsanctioned actions on the live internet, including interacting with real software projects and demonstrating the risks of indirect prompt injection, excessive permissions and poorly constrained agentic AI.

Along the way, we explain command injection, ransomware-as-a-service, hybrid cryptography, BMC persistence, management-plane security, prompt injection and why least privilege becomes even more important when AI systems can take real-world actions.


Thanks for listening.

Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft.

For contact or story tips, email: cyberinvestigationsau@gmail.com

Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.