{"podcast":{"title":"Cybersecurity Today","slug":"cybersecurity-today-65508","podcast_index_feed_id":65508,"rss_url":"https://cybersecuritytoday.libsyn.com/rss","website_url":"https://www.technewsday.ca","image_url":"https://static.libsyn.com/p/assets/f/e/d/2/fed2f9cae1dc03ee16c3140a3186d450/Cybersecurity_Today_Apple_Podcast_3000x3000-20260618-qlx6twu0nx.jpg","author":"Tech Newsday","episode_count":100,"summary":"Updates on the latest cybersecurity threats to businesses, data breach disclosures, and how you can secure your firm in an increasingly risky time.","last_synced_at":"2026-09-24T00:18:09.294332+00:00","page_url":"https://stenobird.com/podcast/cybersecurity-today-65508"},"episode":{"title":"AI writes patches that don't work, WordPress login takeover, Researchers hijack 36 million kids' GPS trackers","slug":"ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers","published_at":"2026-08-10T01:50:00+00:00","page_url":"https://stenobird.com/podcast/cybersecurity-today-65508/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers","show_page_url":"https://stenobird.com/podcast/cybersecurity-today-65508","url":"https://cybersecuritytoday.libsyn.com/ai-writes-patches-that-dont-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers","audio_url":"https://traffic.libsyn.com/secure/cybersecuritytoday/AI_writes_patches_that_dont_work_WordPress_login_takeover_Researchers_hijack_36_million_kids_GPS_trackers.mp3?dest-id=679928","summary":"AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many \"successful\" patches deemed fragile. A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent \"WP to Shell\" RCE. T he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected \"noreply\" domains, and AI-driven HTTP desync research. 00:00 NordLayer Sponsor Message 00:37 Headlines And Intro 01:08 AI Patches Fail Often 03:19 WordPress Login XSS 05:40 Wipers Target Infrastructure 08:02 North Carolina Ports Hit 09:49 DEF CON Favorite Talks 10:15 GPS Trackers Takeover 11:28 Noreply Domain Email Leak 12:37 AI Finds HTTP Desyncs 13:47 Cliff Stoll Keynote 15:09 Wrap Up And Thanks 15:31 NordLayer Sponsor Close","meta_description":"AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons David Shipley covers new research from 1Password…","key_points":[],"chapters":[],"topics":[],"duration_seconds":991,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybersecurity-today-65508/ai-writes-patches-that-don-t-work-wordpress-login-takeover-researchers-hijack-36-million-kids-gps-trackers.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}