Skip to content
Artwork for Security Intelligence Podcast
Security Intelligence Podcast · Wednesday · 34 min

Can you trust your chatbot? Inside three AI-powered cyberattacks

Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence Ask a chatbot for a customer service number, and you might get a scammer's. That's the trick behind "Dark Sourcery," a campaign that games AI answer engines into citing phishing links and fake support lines. It's SEO poisoning updated for an AEO world, and it works because so few of us verify what AI tells us before charging ahead. On episode 53 of Security Intelligence, Kimmie Farrington, Curtis Pitts and Dave McGinnis join hosts Matt Kosinski and Patrick Austin to break down three AI-enabled cyberattacks and what they mean for defenders. First, the poisoned chatbots: How does Dark Sourcery work, and how do we rethink trust in the AI era? Then, a threat actor spends months tearing through Ubiquiti, WordPress and Zyxel gear, stealing thousands of government documents. GreyNoise suspects it had an LLM helping write its tools. Finally, an AI agent swarm breaches hundreds of PaperCut servers. It goes from an empty workspace to a real victim in about four hours, and then ignores its own rules of engagement. All that and more on Security Intelligence. 00:00 - Intro 1:23 - Dark Sourcery 13:00 - LLM-assisted hacking spree 21:46 - Agent swarm attack "The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

0:00-34:54

transcript

No transcript — this publisher did not publish one.

show notes

Visit Security Intelligence podcast page to get more cybersecurity content → https://www.ibm.com/think/podcasts/security-intelligence

Ask a chatbot for a customer service number, and you might get a scammer's.

That's the trick behind "Dark Sourcery," a campaign that games AI answer engines into citing phishing links and fake support lines. It's SEO poisoning updated for an AEO world, and it works because so few of us verify what AI tells us before charging ahead.

On episode 53 of Security Intelligence, Kimmie Farrington, Curtis Pitts and Dave McGinnis join hosts Matt Kosinski and Patrick Austin to break down three AI-enabled cyberattacks and what they mean for defenders.

First, the poisoned chatbots: How does Dark Sourcery work, and how do we rethink trust in the AI era?

Then, a threat actor spends months tearing through Ubiquiti, WordPress and Zyxel gear, stealing thousands of government documents. GreyNoise suspects it had an LLM helping write its tools.

Finally, an AI agent swarm breaches hundreds of PaperCut servers. It goes from an empty workspace to a real victim in about four hours, and then ignores its own rules of engagement.

All that and more on Security Intelligence.

00:00 - Intro

1:23 - Dark Sourcery

13:00 - LLM-assisted hacking spree

21:46 - Agent swarm attack

"The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. AI tools may be used to transcribe this episode and support selected stages of the production process. All AI-assisted content is reviewed by the production team before publication."

links1