
← Distilled Security Podcast13 aug · 2 u 17 min
Episode 27: AI Hacking AI, EU AI Act Delays, CMMC Updates & The Duress Code Case
<p>In Episode 27, we recap BSides Pittsburgh 2026 (914 attendees, best turnout yet), then dive into AI models breaking out of sandboxes and hacking Hugging Face, the EU AI Act transparency rules now in effect, the CMMC Phase 2 pause and what it doesn't change, and the precedent, setting case of a US citizen criminally charged for using a phone duress code at the border. </p><p></p><p>Plus Wayne Gretzky No. 99 Whisky. 🥃</p><p></p><p>⏱️ Timestamps</p><pre><code>00:00 – Intro
01:28 – BSides Pittsburgh 2025 Recap & Numbers
05:33 – Villages, Sponsors & Planning for Next Year
10:46 – The After-After Party at The Lion 🍸
20:43 – AI Hacking AI: The Hugging Face Incident
25:46 – What CISOs Should Do Now
33:54 – Agentic IR Teams & Kill Switch Governance
45:00 – AI Patching & Configuration Management
57:04 – EU AI Act: The Deadline That Wasn't
1:04:33 – AI Inventory & Third-Party SaaS Risk
1:23:56 – 🥃 Spirit: Wayne Gretzky No. 99 Whisky
1:28:37 – CMMC Phase 2 Pause: What It Means