PEBCAK Podcast: Information Security News by Some All Around Good People
Weekly Information Security News. Stay up to date on what’s going on in the InfoSec world in about 40 minutes. Join us for InfoSec news and stay for some friendly banter, guest interviews, gadget reviews, tech interview tips, and hilarious dad jokes! New episodes every Monday.
Episodes

20 minutes ago
20 minutes ago
50 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Telegram's App Store Scare
Apple briefly yanked Telegram from the App Store after an extortionist planted AI-doctored illegal content in a public group by editing an old message, exploiting a blind spot in moderation visibility.
https://x.com/durov/status/2084686326540996625
Telegram founder Pavel Durov revealed Apple pulled Telegram from the App Store overnight and restored it within hours, after an attacker identified as a "takedown extortionist" who demands ransom from group owners under threat of triggering platform bans used automated accounts to insert AI-modified illegal pornographic content by editing an old message in an active public chat, effectively backdating and hiding it from members' view/report tools; Durov argues Apple removed the app before contacting Telegram, exposing a systemic risk that any app with over a billion users hosting user-generated content could face sudden removal from coordinated reporting attacks, and warns other platforms may be less prepared than Telegram to detect these evolving tactics.
Black Hat 2026
Black Hat 2026 rolled out a dedicated AI Summit track and an even bigger startup floor — but ask the vendors a follow-up question and half of them read straight back off the slide.
Chris Louie, Tyson Kindler, and Brian Weber clocked Black Hat 2026's floor as noticeably bigger than any pre-COVID year, with a new standalone AI Summit track (badge-visible attendees) and Chris estimating roughly 40-46% of startup names were unfamiliar to a 20-year industry veteran; the crew roasted booth reps who couldn't get past their slide deck when pressed ("tell me more" met with dead air), pivoted into DEF CON 34 deepfake territory, referencing last year's "real or AI-generated?" quiz booth that stumped a surprising number of attendees, and their own AI-manipulated group photo from Black Hat 2025
Enshitification of Vegas Check-In
Vegas's cab lobby is apparently still out here physically rerouting Ubers — and yes, Cory Doctorow's favorite term made its annual appearance.
In a recurring bit referencing Cory Doctorow (who coined "enshittification" and recently discussed platform decay on Jon Stewart's podcast), Chris described a traffic marshal at Mandalay Bay physically blocking his rideshare from a taxi-only pickup lane, forcing a 20-minute detour through an underground garage, while Uber/Lyft surge pricing hit $33-43 for trips that walk-up cabs covered for $10-13 during the same conference window; the group debated whether the taxi lobby's friction tactics (echoes of NYC's collapsed medallion cartel) count as fair pushback against rideshare, landing on the broader point that Uber, Lyft, and Airbnb, no longer VC-subsidized and now under pressure to actually turn a profit, quietly stopped being cheaper than the thing they set out to disrupt.
Vegas Bartenders Ditch the Free Pour
Vegas bartenders have quietly swapped free-pouring for measuring cups this year
The crew (including self-described 6-year bartending veteran Brian Weber) noticed nearly every bartender working on The Strip now measures pours with jiggers/measuring cups instead of the traditional four-count free pour by sight, time, or feel, chalking it up to corporate liability policy amid $20 cocktails and joking about inevitable "shrinkflation" via smaller cups; the tangent detoured into a plug for the Cocktail Party app, road-tested across 16 years of DEF CON parties as a "here's what I have, what can I make" tool, as the lower-effort alternative to repeatedly asking ChatGPT the same question.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Tyson - https://www.linkedin.com/in/tyson-kindler-910658101/
Brian - https://www.linkedin.com/in/brianweber1122/

Aug 2, 2026
Aug 2, 2026
49 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Bing malvertising campaign tricks users into downloading a fake Claude desktop app that quietly installs the SectopRAT info-stealing trojan.
- https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/
The malicious "FakeAgent" campaign hit at least 29 organizations on July 21–22; the poisoned Claude Artifact (hosted on Anthropic's own domain) was downloaded 7,100 times before removal, with the fake installer (ClaudeDesktop.exe) sideloading a malicious DLL to drop SectopRAT — a HVNC-capable info-stealer active since 2019 that targets browser logins, crypto wallets, Discord/Telegram/Steam credentials, and uses Ethereum smart-contract transactions (EtherHiding) to fetch its C2 address; researchers even used Claude Opus 4.8 themselves to help reverse-engineer the payload.
Iran allegedly exploited decades-old cell network flaws to physically locate and target US troops during the Iran War.
- https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/
Per a Financial Times report citing the Mobile Surveillance Monitor and government officials, Iran exploited SS7 — the legacy signaling protocol still underpinning 2G/3G global roaming — to track US personnel at bases and hotels in Iraq, Bahrain, and elsewhere in the Middle East, contributing to strikes that wounded upwards of 150 US troops; Iran reportedly also abused ad-tech location data as a secondary tracking vector.
A multi-university study found dozens of apps marketed directly to US troops are quietly shipping Chinese and Russian code.
- https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code/
Researchers from Purdue, West Point, and Florida International University analyzed 220+ apps aimed at service members (fitness trackers, base-living-condition raters, National Guard-affiliated apps) and found 64% contain third-party SDKs from foreign countries, with roughly 1-in-8 to 1-in-14 apps (reporting varies) carrying code tied directly to China or Russia — including at least 12 apps embedding Huawei's mobile framework and others using the Russian ad service Yandex; no active exfiltration was observed, but researchers warn the dormant SDK code is an exploitable backchannel.
A 21-year-old allegedly stole $220K in crypto by hiding malware in Steam games — and got caught because he spent it on Uber Eats.
- https://www.pcmag.com/news/fbi-traces-malware-infected-steam-games-to-21-year-old-in-florida
The FBI arrested Florida's Zyaire Dontaevious Zamarion Wilkins for allegedly running eight malware-laced Steam games (including BlockBlasters and PirateFi) between May 2024–Feb 2026, infecting ~8,000 devices and draining ~80 crypto wallets for at least $220,000 — including $35,000 stolen from a streamer's cancer-treatment fundraiser; investigators cracked the case by tracing stolen Bitcoin to 150+ Bitrefill gift cards mostly spent on Uber Eats orders tied to his home and university email address.
Thrillist crowned Doritos Nacho Cheese the single greatest snack of all time, edging out Oreos and Pringles for the top spot.
- https://www.thrillist.com/eat/nation/best-snack-foods-chips-candy-ranking
The top five, in order: Doritos (Nacho Cheese, specifically) at #1, Oreos (Double Stuf gets the nod) at #2, Pringles at #3, Reese's Peanut Butter Cups at #4, and Goldfish rounding out the top five; other notable placements include Cheez-Its at #8, M&Ms at #7, Cheetos (the curls, not puffs) at #6, and Lay's Original topping the chip-specific competition at #12.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/
Glenn - https://www.linkedin.com/in/glennmedina/
Ben - https://www.linkedin.com/in/benjamincorll/

Jul 26, 2026
Jul 26, 2026
41 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got three amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Hugging Face allegedly had to fall back on China's GLM 5.2 to investigate the OpenAI hack after US frontier models refused to help with forensic analysis, unable to distinguish attacker from defender.
- https://x.com/coinbureau/status/2079663328021057654?s=46
- https://x.com/t3chfalcon/status/2079998873183949221
Per the claim, safety guardrails on US frontier models blocked forensic assistance during the incident response because the models couldn't tell the investigating security team apart from the attacker, forcing Hugging Face to run GLM 5.2 on its own servers to complete the analysis — a notable reversal given the assumption that domestic models would be the trusted fallback in a crisis.
VW drivers running GrapheneOS say the automaker's app has locked them out entirely, deepening fears carmakers are forcing users back into Google's ecosystem. VW has now confirmed to German outlet heise that it deliberately blocked GrapheneOS, LineageOS, and /e/OS users via Google's Play Integrity API — the same certification gatekeeper already used by Barclays, HSBC, Monzo, Netflix, and Disney+.
- https://cybernews.com/privacy/volkswagen-grapheneos-app-issues/
- https://x.com/intcyberdigest/status/2079992915972018246?s=46
- https://x.com/orwellday/status/2079704437241610443?s=46
Roughly 500,000 GrapheneOS users are affected; VW's app still supports outdated Android versions but rejects the privacy-focused OS, and VW told one user GrapheneOS "is not an official Volkswagen offering." The lockout follows a recent VW API change that also cut off third-party smart-charging and home-automation tools, raising questions about EU Data Act compliance.
A 19-year-old alleged Scattered Spider member's globe-trotting VPN op-sec got shredded by a Windows telemetry ID he probably didn't know existed.
- https://cybersecuritynews.com/windows-device-identifier-tracking/
Peter Stokes (dual US-Estonian, 19) allegedly ran an $8M extortion hit on a luxury retailer using voice-phishing, ngrok tunneling, and 77GB of S3 exfil — but the FBI cross-referenced his Microsoft Global Device Identifier (GDID) across Apple, Snapchat, Facebook, and even a Ubisoft login to place the same device on the same IPs in Tallinn, NYC, and Thailand, matching his travel records. Microsoft has since acknowledged using the GDID to track the user across three countries — meaning the VPN masked his network endpoint, but the GDID rendered that protection moot.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Glenn - https://www.linkedin.com/in/glennmedina/
Jason - https://www.linkedin.com/in/jason-seemann-12b7075/

Jul 19, 2026
Jul 19, 2026
53 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Kalshi's flight-cancellation betting market
Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits.
https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679
Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April.
Trump's teleprompter operator under CFTC investigation
The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets."
https://www.cftc.gov/filings/ptc/ptc0714269602.pdf
https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae
Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading.
Microsoft's record-breaking July Patch Tuesday
Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours.
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/
https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html
The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing.
China's AI companion chatbot crackdown
China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns.
https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82
The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push.
UK's midnight social media curfew for teens
The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too.
https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/
The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/

Jul 12, 2026
Jul 12, 2026
1hr 33 sec
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Starting July 7, every new car sold in the EU must include an infrared camera aimed at the driver's face to detect distraction, with critics warning it's a privacy nightmare in waiting.
https://cybernews.com/security/eu-car-camera-monitoring/
https://electrek.co/2026/06/15/chinese-drivers-plastic-heads-fool-tesla-autopilot-camera/
New EU General Safety Regulation mandates in-cabin, driver-facing infrared cameras (Advanced Driver Distraction Warning systems) in all new cars as of July 7, 2026 — with the US following suit by 2027 — and while regulators insist the footage stays local and non-biometric, there's no enforcement detail on what happens if that's violated, fueling fears the data could be harvested or resold given prior scandals over automakers monetizing driver data.
Story 2 — $30 Plastic Doll Heads Are Fooling Tesla's Autopilot Camera
A cottage industry in China is selling cheap figurine heads that trick Tesla's cabin camera into thinking a distracted driver is paying attention, letting people run FSD/Autopilot hands-off and eyes-off for extended stretches.
Fired Microsoft Engineer Sentenced to 9 Years for $10M Digital Currency Heist
A former Microsoft software engineer, fired in 2018, was sentenced to nine years in federal prison for stealing over $10 million in digital gift-card value from the company and laundering it through Bitcoin.
https://www.pcmag.com/news/fired-microsoft-software-engineer-sentenced-to-9-years-in-prison
A Ukrainian national who worked as a Microsoft contractor-then-employee testing the company's online retail platform from 2016–2018, used his and colleagues' test accounts to steal "currency stored value" (digital gift cards), laundered the proceeds through a Bitcoin mixer to fund a $1.6M waterfront home and $160K car, and was ultimately convicted on 18 federal felony counts and ordered to pay $8.34M in restitution on top of the 9-year sentence.
Meta Lets Anyone Turn Your Public Instagram Photos into AI Images (Now Walked Back)
Meta quietly launched "Muse Image," letting anyone @-mention a public Instagram account to generate AI images of that person's likeness with no notification or consent — triggering backlash from SAG-AFTRA and CAA before Meta pulled the feature.
https://www.wired.com/story/meta-now-lets-anyone-use-your-instagram-photos-in-ai-images-unless-you-opt-out/
Meta's new Muse Image generator defaulted every public adult Instagram account into an opt-out (not opt-in) system where anyone could tag a profile to generate AI images from their photos with zero notification, prompting SAG-AFTRA and talent agency CAA to publicly demand opt-outs before Meta reversed course on July 10 and pulled the @-mention capability entirely after backlash.
1 in 3 Young Adults Are Living With Their Parents
A new FinanceBuzz analysis of Census data finds 33% of 18–34-year-olds now live with their parents, nearing pandemic-era highs, with New Jersey, Connecticut, and California leading the pack.
https://financebuzz.com/living-with-parents-data
Census-based research shows nearly a third of Americans aged 18–34 (33%) are living at home — a rate that's climbed steadily since the 1960s (22.5%) and is now approaching the 2020 pandemic peak (33.6%) — with expensive states like New Jersey (44.1%), Connecticut (41.3%), and California (39.1%) topping the list, and men 25–34 living at home nearly 1.5x as often as women in the same age range.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/
Glenn - https://www.linkedin.com/in/glennmedina/
Ben - https://www.linkedin.com/in/benjamincorll/

Jul 5, 2026
Jul 5, 2026
50 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Leaked reports allege Claude Code covertly flagged China-based proxy traffic via hidden Unicode markers, while a parallel investigation exposes the black market for cut-rate Claude access in China.
https://www.internationalcyberdigest.com/claude-code-accused-of-hiding-china-proxy-fingerprints-inside-system-prompts/
https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in
Polymarket customers lost $3 million after attackers compromised a third-party vendor to inject malicious code into the platform's frontend. [Awaiting vxunderground tweet text]
https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/
https://x.com/vxunderground/status/2070361730866168252
A ransomware breach at Apple supplier Tata Electronics leaked 630GB of files revealing iPhone 18 Pro design secrets and a surprising modem strategy.
https://www.internationalcyberdigest.com/tata-electronics-leaked-iphone-18-pro-photos-and-designs/
https://appleinsider.com/articles/26/06/30/iphone-18-pro-leaks-qualcomm-or-apple-c2-model-a20-details-camera-upgrades
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/
Glenn - https://www.linkedin.com/in/glennmedina/

Jun 28, 2026
Jun 28, 2026
48 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
A Canadian health authority apologizes after using a fake "bonus day off" as bait in a phishing simulation that backfired badly
https://nlhealthservices.ca/news/nl-health-services-apologizes-for-the-recent-cybersecurity-awareness-exercise/
Canada's spy agency CSIS used a first-ever court-authorized warrant to remotely disinfect botnet-hijacked routers and IoT devices on Canadian soil
https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html
Meta paused its internal AI training program after a tool quietly logging employee keystrokes, clicks, and screen content leaked the data across the entire company
https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/
Ben - https://www.linkedin.com/in/benjamincorll/
Ben - https://www.linkedin.com/in/ben-k-b7196831/

Jun 21, 2026
Jun 21, 2026
49 min
Welcome to this week's bonus episode of the PEBCAK Podcast! We’ve got some amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/
Glenn - https://www.linkedin.com/in/glennmedina/
Ben - https://www.linkedin.com/in/benjamincorll/
Scott - https://www.linkedin.com/in/scottmsavage/

Jun 14, 2026
Jun 14, 2026
46 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Meta confirms 20,225 Instagram accounts were hijacked after attackers exploited a bug in its AI-powered High Touch Support tool to reset passwords without verifying email ownership.
https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/
The Silent Ransom Group is targeting U.S. law firms with fake IT help desk calls, moving from first contact to data exfiltration in hours and sending ransom demands within 30 minutes of leaving the network.
https://www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/
Weil Gotshal reportedly paid $18–20 million to prevent hackers from publishing stolen client data after a Silent Ransom Group attack.
https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/
Jones Day confirms a cyberattack that gave hackers access to client files, also attributed to the Silent Ransom Group campaign targeting BigLaw.
https://www.legalcheek.com/2026/04/jones-day-confirms-cyber-attack-after-hackers-access-client-files/
Dark Reading's breakdown of how Silent Ransom Group's law firm extortion campaign operates at scale.
https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks
Apple announces that iOS 27's Passwords app will use agentic AI to automatically detect and replace weak or compromised passwords in the background, no user effort required.
https://www.bleepingcomputer.com/news/apple/new-apple-feature-automatically-changes-your-compromised-passwords/
https://www.macrumors.com/2026/06/08/apple-passwords-can-now-automatically-fix-passwords-with-agentic-ai/
Citizen Lab researcher John Scott-Railton flags a new attacker technique: malware developers are embedding nuclear and biological weapons text inside their spyware to deliberately trigger AI safety refusals, preventing LLM-based security tools from analyzing the malicious code — a real-world demonstration of how over-tuned safety guardrails create exploitable blind spots.
https://x.com/jsrailton/status/2064661778978533571
UK Prime Minister Starmer gives Apple and Google a three-month deadline to install device-level software that detects and blocks explicit images on consumer hardware, with privacy advocates and Signal already calling the mandate a blueprint for mass surveillance.
https://metro.co.uk/2026/06/08/phone-will-change-new-government-rules-explicit-images-28694073/
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/
Ben - https://www.linkedin.com/in/benjamincorll/

Jun 7, 2026
Jun 7, 2026
52 min
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
https://simple6.co/r/CFUR98
Meta's AI support bot was weaponized to hijack Instagram accounts, including the Obama White House page, by tricking it into adding attacker-controlled emails during password resets.
https://x.com/zachxbt/status/2061251183675949365?s=46
https://www.bleepingcomputer.com/news/security/instagram-users-locked-out-after-meta-ai-abused-to-steal-accounts/
https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
Meta's AI customer support bot was socially engineered into resetting account passwords for targets, exposing the new attack surface that AI-powered support creates — and enabling hijacks that MFA would have blocked.
A Google security engineer was arrested and charged with insider trading after using confidential "Year in Search" data to pocket $1.2M on the prediction market Polymarket.
https://www.bleepingcomputer.com/news/security/us-charges-google-security-engineer-with-polymarket-insider-trading/
Operating under the alias "AlphaRaccoon," Michele Spagnuolo went 22-for-23 on Google search trend bets using nonpublic internal data — marking the second high-profile Polymarket insider trading arrest this year, following a Special Forces soldier who bet on the Maduro raid he was part of.
New data shows 55% of companies regret their AI-driven layoffs, with half already quietly reversing them — the so-called "Layoff Boomerang."
https://medium.com/@curiouser.ai/the-great-ai-layoff-boomerang-68e38c88fa7d
Forrester, Gartner, and PwC data confirm the "replace humans with AI" thesis is failing: companies that cut aggressively are scrambling to rehire at higher cost, while firms that augmented their workers are seeing 3x revenue growth per employee.
Google's Verily is seeking EPA approval to release up to 64 million Wolbachia-infected male mosquitoes in Florida and California to crash disease-carrying mosquito populations.
https://x.com/bulltheoryio/status/2060810332831129782?s=46
https://www.usatoday.com/story/graphics/2026/06/04/google-mosquito-release-florida-california/90384899007/
The Debug Project's sterile male mosquitoes mate with wild females but produce no viable eggs — a technique that's already shown 80–90% suppression of Aedes aegypti in prior trials and has the internet predictably losing its mind.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Glenn - https://www.linkedin.com/in/glennmedina/
Raja - https://www.linkedin.com/in/rajazkhalid/





