# The cost of trusting the extension ecosystem. Page: https://stenobird.com/podcast/cyberwire-daily-454880/the-cost-of-trusting-the-extension-ecosystem Text version: https://stenobird.com/podcast/cyberwire-daily-454880/the-cost-of-trusting-the-extension-ecosystem.md Podcast: [CyberWire Daily](https://stenobird.com/podcast/cyberwire-daily-454880) Published: 2026-05-20T20:30:00+00:00 Episode link: https://www.thecyberwire.com/podcasts/daily-podcast/2556/notes Audio file: https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW7368792807.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/the-cost-of-trusting-the-extension-ecosystem Duration seconds: 1648 ## Resource GitHub confirms a breach tied to a malicious VS Code extension. Anthropic fights a Pentagon blacklist as the White House weighs new AI security rules. Drupal scrambles to patch a critical flaw. Cisco Talos tracks the evolution of BadIIS malware-for-hire. Signal adds anti-phishing safeguards, Microsoft cracks down on malware-signing services, and China says foreign spies hijacked domestic routers for phishing operations. Wireless carriers collaborate to kill dead zones. Our guest is Rob T. Lee, Chief AI Officer, Chief of Research, SANS Institute, discussing The Cloud Security Alliance’s “AI Vulnerability Storm” report. A book about misinformation contains helpful examples. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Rob T. Lee, Chief AI Officer, Chief of Research, SANS Institute, sharing Cloud Security Alliance’s The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program. Selected Reading GitHub confirms breach of 3,800 repos via malicious VSCode extension (Bleeping Computer) Trump AI executive order seeks early government access to frontier models (Axios) DC Circuit slams Pentagon blacklisting of Anthropic as overreach (Courthouse News Service) Drupal Issues Urgent Warning for Highly Critical Core Vulnerability (Beyond Machines) From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat (Cisco Talos) Signal adds security warnings for social engineering, phishing attacks (Bleeping Computer) Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomwa… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/the-cost-of-trusting-the-extension-ecosystem/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberwire-daily-454880/the-cost-of-trusting-the-extension-ecosystem.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.