# AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers Page: https://stenobird.com/podcast/cybersecurity-today-65508/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers Text version: https://stenobird.com/podcast/cybersecurity-today-65508/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-08-10T01:50:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/ai-writes-patches-that-dont-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/AI_writes_patches_that_dont_work_WordPress_login_takeover_Researchers_hijack_36_million_kids_GPS_trackers.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers Duration seconds: 991 ## Resource AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile. A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 01:08 AI Patches Fail Often 03:19 WordPress Login XSS 05:40 Wipers Target Infrastructure 08:02 North Carolina Ports Hit 09:49 DEF CON Favorite Talks 10:15 GPS Trackers Takeover 11:28 Noreply Domain Email Leak 12:37 AI Finds HTTP Desyncs 13:47 Cliff Stoll Keynote 15:09 Wrap Up And Thanks 15:31 NordLayer Sponsor Close ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.