Three stories on the table this week. A developer's Bluetooth headphone glitch exposed a hidden audio-fingerprinting script running inside AliExpress's browser tab. US agencies warned that AI-generated exploit scripts are making it dramatically easier to find and abuse exposed Siemens S7 PLCs. And university researchers showed how rewriting one unsigned field revives an expired Visa card for contactless payment. We also sit down with Kraig Faulkner, Field CTO at InfoLock, in a Black Hat conversation about why all the AI hype is really forcing organizations to reckon with their own data. Here's what stood out from the operator chair.
We built tooling to audit cookies. Nobody's watching what's live in the audio graph. AliExpress was running a Web Audio API processing graph at zero volume in visitors' browsers, unconnected to anything actually playing, and using it to fingerprint devices by the tiny, hardware-specific way they handle that signal. Consumer privacy tooling assumes tracking lives in storage: cookies, local storage, things you can inspect and clear. A live audio pipeline running in memory sits outside that model entirely. That's exactly why this one went unnoticed until it broke something unrelated: a Bluetooth headset that wouldn't switch outputs while the tab held the audio channel open.
AI didn't create more exposed PLCs. It just taught more people how to talk to them. US agencies warned that attackers are using AI-generated Python scripts, riding libraries like python-snap7, to scan and exploit internet-facing Siemens S7 PLCs over the S7comm protocol. These devices have sat exposed for decades, built for uptime, not security. What's changed is the reverse-engineering tax: talking to a proprietary industrial protocol used to take real expertise, and now an LLM gets you something functional in an afternoon.
Your Visa card's expiration date was never part of what gets cryptographically verified. Researchers found they could revive an expired Visa card for contactless payment by rewriting the terminal-facing expiration date in transit. It never touches the card's signature or its issuer-verified cryptogram: the date the terminal reads simply isn't in the data both sides sign. It's a narrow bug (one specific card kernel, tested at three banks, one of which actually approved the modified transaction), but the underlying pattern is worth remembering. Payment systems assume a terminal's read of a field means that field was checked. It wasn't.
What is all the AI noise at Black Hat actually forcing us to confront? From the show floor, we sat down with Kraig Faulkner, Field CTO at InfoLock, for one of our favorite conversations from this year's Black Hat coverage. Kraig's take cuts against the hype: AI doesn't check your role-based access controls, it just looks at everything, which quietly breaks every legacy access model built to keep data compartmentalized. His argument is that securing AI starts with knowing what data you actually have and where it lives, not with a bigger toolset. If you've been buried in AI-security noise all summer, it's a grounding conversation on the fundamentals other tools assume you've already got handled.
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources
AI Can See More of Your Data Than You Think, with Kraig Faulkner, Infolock
No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452
A GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console
Download
Your download is starting in a new tab. If it does not start automatically, use the button below.