Image
Episode 32  •  Aug 28, 2026  •  35 Min

Audio Fingerprinting, AI-Assisted ICS Attacks & the Zombie Card Bypass

Three stories on the table this week. A developer's Bluetooth headphone glitch exposed a hidden audio-fingerprinting script running inside AliExpress's browser tab. US agencies warned that AI-generated exploit scripts are making it dramatically easier to find and abuse exposed Siemens S7 PLCs. And university researchers showed how rewriting one unsigned field revives an expired Visa card for contactless payment. We also sit down with Kraig Faulkner, Field CTO at InfoLock, in a Black Hat conversation about why all the AI hype is really forcing organizations to reckon with their own data. Here's what stood out from the operator chair.

We built tooling to audit cookies. Nobody's watching what's live in the audio graph. AliExpress was running a Web Audio API processing graph at zero volume in visitors' browsers, unconnected to anything actually playing, and using it to fingerprint devices by the tiny, hardware-specific way they handle that signal. Consumer privacy tooling assumes tracking lives in storage: cookies, local storage, things you can inspect and clear. A live audio pipeline running in memory sits outside that model entirely. That's exactly why this one went unnoticed until it broke something unrelated: a Bluetooth headset that wouldn't switch outputs while the tab held the audio channel open.

AI didn't create more exposed PLCs. It just taught more people how to talk to them. US agencies warned that attackers are using AI-generated Python scripts, riding libraries like python-snap7, to scan and exploit internet-facing Siemens S7 PLCs over the S7comm protocol. These devices have sat exposed for decades, built for uptime, not security. What's changed is the reverse-engineering tax: talking to a proprietary industrial protocol used to take real expertise, and now an LLM gets you something functional in an afternoon.

Your Visa card's expiration date was never part of what gets cryptographically verified. Researchers found they could revive an expired Visa card for contactless payment by rewriting the terminal-facing expiration date in transit. It never touches the card's signature or its issuer-verified cryptogram: the date the terminal reads simply isn't in the data both sides sign. It's a narrow bug (one specific card kernel, tested at three banks, one of which actually approved the modified transaction), but the underlying pattern is worth remembering. Payment systems assume a terminal's read of a field means that field was checked. It wasn't.

What is all the AI noise at Black Hat actually forcing us to confront? From the show floor, we sat down with Kraig Faulkner, Field CTO at InfoLock, for one of our favorite conversations from this year's Black Hat coverage. Kraig's take cuts against the hype: AI doesn't check your role-based access controls, it just looks at everything, which quietly breaks every legacy access model built to keep data compartmentalized. His argument is that securing AI starts with knowing what data you actually have and where it lives, not with a bigger toolset. If you've been buried in AI-security noise all summer, it's a grounding conversation on the fundamentals other tools assume you've already got handled.

Security Headlines:


Sean McMillan Headshot

Sean McMillan

Community Manager

Sean McMillan is Community Manager at Bishop Fox, focused on making complex security topics easier to understand and more interesting to follow. He holds a bachelor’s degree in Mass Communication and Media Studies from Arizona State University and brings over a decade of experience in podcasting, live hosting, and audience engagement. As host of Initial Access, he works with practitioners to explore how real-world attacks actually happen.


Ku image

Kendrick Urbaniak

Senior Operator

Kendrick Urbaniak is a Senior Operator at Bishop Fox, serving on the Threat Research Team with a focus on exploit development, vulnerability research, and offensive security innovation. He leverages extensive experience in exploit engineering, adversary tradecraft, and security research to uncover emerging threats and help organizations better understand and reduce real-world risk across modern software and infrastructure ecosystems.


Dillon Sparks Bio Photo

Dillon Sparks

Senior Operator

Dillon Sparks is a Senior Operator at Bishop Fox, serving on the Threat Enablement Team with a focus on Attack Surface Intelligence and Emerging Threat Analysis. He applies deep expertise in offensive security, network exploitation, and systems analysis to help organizations understand and mitigate real-world risk across complex software and infrastructure environments.


Bfx25 John Untz Author Bio 1

John Untz

Senior Security Engineer, Exploit Developer

John is a Senior Security Engineer, Exploit Developer, where he focuses on reverse engineering emerging threats and developing advanced capabilities to protect our customers' attack surfaces. Prior to joining Bishop Fox, John served in a number of selectively manned US Air Force teams, and is a graduate of the NSA's Computer Network Operations Development Program (CNODP).


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere