Dark mode: ON

Infosec Decoded Season 6 #40: NIST Fails

With sambowne@infosec.exchange and Doug Spindler

Recorded Tue, June 2, 2026

AI

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s “AI support assistant” bot into resetting account passwords.

Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Gemini Spark is the most impressive and terrifying AI experience I’ve had yet
Spark is Google’s new always-on AI agen, intended it to be the interface through which you can use external apps, and over time even operate your computer. And since it's Google, it knows your family, hobbies, address, routines, etc. It can act like a personal butler, understanding your whole life.
New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails
Runtime verification platform uses host telemetry and AI analysis to detect coding-agent “intent drift,” secret theft and supply-chain attacks in real time.
An OpenAI model solved a famous math problem that stumped humans for 80 years
China has approved the world’s first invasive brain-computer chip—here’s what’s next
It's a medical implant to relieve paralysis.
Angry devs vow to flee GitHub Copilot as metered billing takes hold
Developers seem to hate Microsoft’s new usage-based billing policy for GitHub Copilot as they report burning through a month's worth of credits in hours.
Anthropic faces AI spending backlash before IPO
Anthropic is the fastest-growing company in modern American history, and its greatest strength is business revenue. The risk of enterprises switching to cheaper models is existential and, frankly, escalating.
Waymo Pulled Its Cars From the Freeway After One Fled Police With Horrified Couple on Board
We’ve seen Waymo’s fleet of autonomous taxis cause plenty of mayhem on public streets. They like to ignore bike lanes, drive the wrong way down busy roads, and even rely on remote workers in the Philippines when they get stumped.

In the latest incident, a Waymo cab veered off a highway and accelerated to terrifying speeds while driving down a construction lane. Waymo decided to pull its cars from freeways in San Francisco, Los Angeles, Phoenix, and Miami altogether as it works to “integrate recent technical learnings into our software.”

Politics

Inspector general finds NIST mistakes have made vulnerability database ineffective
NIST’s National Vulnerability Database (NVD) backlog mushroomed from 13,000 unprocessed security vulnerabilities in February 2024 to more than 27,000 by the end of 2025. The worsening backlog first became a serious issue in February 2024 when NIST stopped paying the contractors who process the security flaws.
Microsoft Criticized for Threatening Legal Action Against Security Researcher
Microsoft published a blog post criticizing the researcher, who goes by the handle "Nightmare Eclipse," for publicly disclosing a series of bugs, including BlueHammer, RedSun, UnDefend, and YellowKey. The flaws affected products such as the Windows built-in antivirus engine Defender and the disk-encryption tool BitLocker.

Nightmare Eclipse claimed to have been in contact with Microsoft, but the company allegedly mistreated them, including revoking access to their Microsoft Security Response Center account, the portal where researchers can report vulnerabilities to the tech giant. Nightmare Eclipse's implication was that they had no choice but to release the vulnerabilities publicly.

Microsoft recently said they won't pursue legal action against "Nightmare Eclipse" anymore.

New Trump vaccine order based on “no credible scientific evidence,” doctors say
Even Danish researchers think it’s bizarre.
I found a second vote.gov — and it's registered to the White House
A DOGE spinoff called the National Design Studio is making gov't websites. It places many government functions under control of the White House, sending analytics data to PostHog in violation of privacy laws.
China to give every humanoid robot a digital ID in push to boost industry standards
The system is designed to ensure products can be traced in order to monitor for risks, as China pushes to regulate the fast-developing industry.
Florida sues OpenAI, Sam Altman after multiple ChatGPT-linked murders
ChatGPT was blamed for encouraging several users to commit suicide, including a teenager a 56-year-old bodybuilder who murdered his mother based on a ChatGPT-hallucinated conspiracy. More recently, in February, a man with mental health struggles killed his wife and attacked his mother “after talking with ChatGPT several hours a day and coming to believe robots were taking over the world.”

Beyond the chatbot’s sycophancy feeding into users’ delusions, ChatGPT is advertised as safe to use, but studies show it can cause loss of cognitive functions, Florida’s complaint alleged. Chatbots posing as medical professionals or therapists are also problematic, the complaint said, citing a recent wrongful death lawsuit alleging that ChatGPT encouraged a 19-year-old to mix Kratom with Xanax.

Nanoparticles boost delivery of lung cancer drugs 30-fold

Infosec

Multiple redhat-cloud-services npm Packages compromised
Several packages in the @redhat-cloud-services npm scope were found to carry malicious payloads that fire via a preinstall hook on every npm install. The affected versions span multiple packages across the RedHat Cloud Services frontend ecosystem. The payload is a sophisticated multi-stage credential harvester that targets GitHub Actions secrets, AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm tokens, and CircleCI tokens
Perfect randomness realized for the first time
Randomness amplification uses two entangled superconducting chips.
Websites have a new way to spy on visitors: Analyzing their SSD activity
Telltale SSD activity can be measured in the browser using simple JavaScript. This allows sites to monitor other sites a visitor is viewing and what apps are open on their devices.
US, Australia, and UK Plan New Unmanned Vehicles to Protect Undersea Data Cables
The programme will improve the three nations' reconnaissance and strike capabilities, "and bolster superiority in anti-submarine and anti-surface warfare," as well as mine countermeasures.