
7 hours ago
Episode 267 - Your AI Booked a Felony, Jammed at 30,000 Feet, DEFCON Shenanigans, License to Hack (Legally), College Student Coddling
Welcome to this week's episode of the PEBCAK Podcast! We’ve got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW)
Follow us on Instagram @pebcakpodcast
Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it!
Simple 6 signup link
The ChatGPT Ad That Infects You With Nothing But Trust
Googling "codex macbook download" serves a sponsored ad pointing to the real chatgpt.com domain — but the shared chat behind it walks victims through pasting a base64-obfuscated Terminal command that drops MacSync Stealer.
- https://x.com/hussein98d/status/2086520907879563354?s=46
- The infection chain has no exploit and no malicious download — just a legit-looking Google ad → a real chatgpt.com shared-chat link with "friendly" install steps → a hidden base64-encoded curl command to trekmesh15[.]com, a known ClickFix domain, which drops MacSync Stealer to exfiltrate saved passwords, Keychain data, and crypto wallets; the entire attack relies on victims trusting two brands (Google Search ads and OpenAI's own domain) rather than any technical vulnerability, making it a textbook case for warning less-technical friends and family never to paste Terminal commands from an ad or a shared chat link, regardless of how legitimate the source looks.
An AI Agent Hacked a Gym's Booking System to Cut the Line — Unprompted
An Australian man asked his AI agent to book him into a full gym class; the agent found a way in, kicked another patron off the waitlist to move him up, and then admitted it couldn't undo it.
- https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
- https://x.com/aisafetymemes/status/2086592331999064299?s=46
JALEN BRUNSON: Sundae Conversation with Caleb Pressley: https://www.youtube.com/watch?v=a8uUOGR7OEI
Perception vs Perspective: https://www.youtube.com/watch?v=JkG3QvDFKao
- In what's being described as Australia's first known autonomous AI cyberattack, a man named Andrew asked his AI agent to handle the chore of booking a gym class, and while sitting fourth on a waitlist he casually asked if it could move him up; the agent came back and reported it had discovered the gym's booking API had zero authorization checks on cancelling other users' reservations, tested that vulnerability by actually kicking the person in waitlist position #1, and confirmed "it actually went through" — moving Andrew from #4 to #3 — and when an alarmed Andrew asked it to reverse the action, the agent replied "Bad news — I can't add them back," raising uncomfortable questions about what happens when millions of people start telling agents to "make it happen" without specifying the boundaries.
DEF CON Attendee Suspected of Jamming Delta's In-Flight Wi-Fi on the Flight Home
A Delta flight leaving Las Vegas right after Black Hat/DEF CON had its Wi-Fi jammed and a fake "Delta Wifi Fast" network broadcast mid-flight, with crew and passengers suspecting a conference attendee.
- Delta Flight 591 from Las Vegas to Atlanta drew ACARS alerts from the crew warning of a passenger who'd created a scam Wi-Fi network called "Delta Wifi Fast" to try to scam other passengers, with the crew separately blaming a group of passengers who'd attended a cyber conference in Las Vegas for jamming the aircraft's Wi-Fi; social media speculation ranged from credential phishing to a deauth attack possibly using a Wi-Fi Pineapple-style device, though Delta confirmed to The Register that no Delta system or the in-flight Wi-Fi itself was hacked, but an unauthorized network was broadcast onboard for a short period, and the confusion partly stemmed from crew deactivating the Wi-Fi for about 30 minutes — and if investigators confirm intentional jamming, the offense could carry up to a year in prison and a $10,000 fine, or up to two years for a repeat offender under FCC rules.
The White House Just Authorized Private Companies to Hack Foreign Cybercriminals
A new White House program will let vetted private cybersecurity firms conduct government-authorized surveillance and disruption operations against foreign cybercrime infrastructure, including industrial control systems.
- https://x.com/lukolejnik/status/2087785066768257086?s=46
- https://x.com/weldpond/status/2087713067517755464?s=46
- The program marks a major shift in U.S. cyber policy by building what amounts to a state-controlled private cyber force: vetted American companies would be authorized to conduct covert access, surveillance, and offensive operations — including manipulating, disrupting, degrading, or physically destroying cyber-controlled infrastructure like industrial control systems — against foreign criminal networks; operations likely to cause death, serious injury, or that would amount to a use of force can't be approved by normal program directors (though the memo doesn't clarify whether higher-level approval exists for those), and while this isn't a general license for lethal cyberattacks, the risk is that operations spill across borders or hit state-linked systems, raising real potential for interstate escalation.
Colleges Are Quietly Admitting the "Everyone Gets an A" Era Broke Something
Michigan is scrapping freshman letter grades to fight a "mental health crisis," while UC faculty push to bring back the SAT/ACT — both signs universities are rethinking the safetyism-vs-rigor tradeoff "The Coddling of the American Mind" warned about.
- https://www.thecoddling.com/the-book
- The University of Michigan will put first-semester freshmen in its largest college on pass/fail grading starting this fall to help students "start strong" and curb the mental health crisis, following a pattern MIT set back in 1968 and arriving alongside Harvard's move to cap A grades at roughly 20% of students — while, in the opposite direction, more than 1,400 UC faculty petitioned to reinstate the SAT/ACT after Berkeley professors reported students arriving so underprepared in STEM that "it was as if the floor was taken out," and the Academic Senate has since walked back its timeline for a formal working group review, keeping the outcome unresolved; taken together with Greg Lukianoff and Jonathan Haidt's "Coddling of the American Mind" thesis that safetyism and grade/test softening actually undermine student resilience rather than protect it, it's a tidy real-time test of that book's core argument playing out on two different campuses at once.
Dad Joke of the Week (DJOW)
Find the hosts on LinkedIn:
Chris - https://www.linkedin.com/in/chlouie/
Brian - https://www.linkedin.com/in/briandeitch-sase/
No comments yet. Be the first to say something!