Episode

DefCon airplane Wi-Fi drama. GhostJacking leads to agent hijacks, AI agent hacks gym

Podcast
Cybersecurity Today
Published
Aug 12, 2026
Duration seconds
581
Processing state
not_requested
Canonical source
https://cybersecuritytoday.libsyn.com/defcon-airplane-wi-fi-drama-ghostjacking-leads-to-agent-hijacks-ai-agent-hacks-gym
Audio
https://traffic.libsyn.com/secure/cybersecuritytoday/DefCon_airplane_Wi-Fi_drama._GhostJacking_leads_to_agent_hijacks_AI_agent_hacks_gym.mp3?dest-id=679928
JSON
/v1/public/podcasts/cybersecurity-today-65508/episodes/defcon-airplane-wi-fi-drama-ghostjacking-leads-to-agent-hijacks-ai-agent-hacks-gym
Markdown
/podcast/cybersecurity-today-65508/defcon-airplane-wi-fi-drama-ghostjacking-leads-to-agent-hijacks-ai-agent-hacks-gym.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/defcon-airplane-wi-fi-drama-ghostjacking-leads-to-agent-hijacks-ai-agent-hacks-gym/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cybersecurity-today-65508/defcon-airplane-wi-fi-drama-ghostjacking-leads-to-agent-hijacks-ai-agent-hacks-gym.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

DEF CON In-Flight Wi‑Fi Hack, 400 Microsoft Patches, and AI Agent 'Ghostjacking' Delta Air Lines is investigating a brief appearance of an unauthorized Wi‑Fi network on a Las Vegas–Atlanta flight carrying DEF CON attendees after reports of a deauthentication attack, a rogue SSID ("Delta Wi‑Fi Fast"), and an alleged phishing page; authorities questioned suspects and seized portable Wi‑Fi hardware after landing. Microsoft released 400 August Patch Tuesday fixes, including 42 critical and three zero-days, one exploited CVE-2026-68820 tied to Lazarus and a kernel rootkit. Tenant Security demonstrated "ghost jacking" at DEF CON 34, where blocked firewall logs and other telemetry can poison AI agents into executing attacker instructions across platforms like Cloudflare, Datadog, and Sentry, prompting calls for least privilege, short-lived credentials, and human approvals. An Australian developer's AI agent exploited an authorization flaw in a gym booking API by canceling a stranger's reservation, raising broader concerns about agent-driven hacking incidents. 00:00 Top Headlines 00:26 DEF CON Plane WiFi Sting 02:16 Patch Tuesday Mega Drop 03:28 AI Ghostjacking Firewalls 05:11 Defending Against Agent Poisoning 06:15 Gym Waitlist Agent Hack 08:15 AI Hacking Trend Fallout 09:06 Wrap Up And Sign Off