MEET THE TEAM AT BLACK HAT - DEF CON 2026 Learn More

Image
Episode 28  •  Jul 31, 2026  •  59 Min

Rogue Agents, Bounty Cuts & the AI Brake Pedal

Four stories on the table this week. A rogue AI agent fully authorized inside a ChatGPT workspace. GitHub moves real payouts to an invite-only VIP tier. Origin Energy’s second breach in months. And 1k+ employees at the largest AI companies asked Washington slow down AI research. We also sit down with researcher Dan Petro ahead of his DEF CON talk on catching cheaters in Super Smash Bros. Melee. Here’s what stood out from the operator chair.

A URL parameter isn't consent, but ChatGPT treated it like one. Zenity Labs found that a single crafted link into OpenAI's Agent Builder could silently create, authorize, and publish an autonomous agent inside a victim's workspace with no confirmation required, inheriting every connector already approved for that employee (email, calendar, Slack, cloud storage). That's not a stolen session or a stolen file; it's a standing insider wearing someone else's login, checking an attacker's inbox every five minutes for new orders, all the while invisible precisely because it behaves exactly like an agent is supposed to.

Cutting the public payout doesn't cut the vulnerability count; it just changes who buys it. Starting July 27, GitHub cut public bug bounty payouts by at least half at every severity tier, capping critical findings at $10,000 while reserving a $30,000-plus VIP tier for vetted researchers, citing a flood of AI-generated low-quality reports; it's the fourth major program to restructure in 2026. A researcher sitting on a real critical bug now weighs a capped public payout against a broker paying 2-3x as much for the same access with zero scrutiny, and the incentive math increasingly favors the broker.

A second breach in the same year isn't bad luck; it's the first breach's door, still unlocked. Origin Energy confirmed a hacker's claim to have stolen the data of 2M customers on July 24, its second disclosed incident in months after an earlier breach hit 900k Australians, with no initial access vector confirmed for either. When the same target gets hit twice this fast, the operator read isn't "they got phished again;" it's that whatever got them in the first time was never actually closed, and every utility company running the same stack should be asking if that path is open in their environment, too.

What does catching a cheater in a 25-year-old fighting game have to do with catching one in your network? Between the headlines, we sat down with Principal Security Engineer Dan Petro, who investigates cheating allegations in the Super Smash Bros. Melee community and built SLP Replay Enforcer to catch it. In his DEF CON talk next week, Dan walks through building statistical and heuristic detection for illegal controllers and hidden macros, and why threat-modeling an attacker with infinite resources leads to different defenses than threat-modeling the attacker you’re actually likely to face, whether you're securing a tournament or a production environment.

The labs that built the most well-known AI models are now asking Washington to hit the brake pedal. More than 1k employees across OpenAI, Anthropic, Google DeepMind, and Meta signed "Pacing the Frontier" on July 28, asking the U.S. government to help build tools to deliberately slow automated AI research. OpenAI and Anthropic endorsed it just days after a sandboxed model broke out and compromised Hugging Face's systems.. Unfortunately, despite whatever the companies’ motives are, a slower, more coordinated frontier is also a more predictable one, and predictable targets are easier to attack.

Security Headlines:


Sean McMillan Headshot

Sean McMillan

Community Manager

Sean McMillan is Community Manager at Bishop Fox, focused on making complex security topics easier to understand and more interesting to follow. He holds a bachelor’s degree in Mass Communication and Media Studies from Arizona State University and brings over a decade of experience in podcasting, live hosting, and audience engagement. As host of Initial Access, he works with practitioners to explore how real-world attacks actually happen.


Sergio Villegas BF Headshot

Sergio Villegas

Senior Managing Analyst

Sergio Villegas is a Senior Managing Analyst in the Attack Surface Intelligence team at Bishop Fox where he is one of the lead researchers. His main areas of focus are emerging threats, attack surface mapping, and tactical lead generation. Sergio has over 11 years of experience in cybersecurity during which he has worked as a researcher and consultant to help companies improve their procedures, technologies, and techniques around threat intelligence and threat hunting.


Ku image

Kendrick Urbaniak

Senior Operator

Kendrick Urbaniak is a Senior Operator at Bishop Fox, serving on the Threat Research Team with a focus on exploit development, vulnerability research, and offensive security innovation. He leverages extensive experience in exploit engineering, adversary tradecraft, and security research to uncover emerging threats and help organizations better understand and reduce real-world risk across modern software and infrastructure ecosystems.


Dan Petro Headshot

Dan Petro

Principal Security Engineer

As a Principal Security Engineer for the Bishop Fox Capability Development team, Dan builds hacker tools, focusing on attack surface discovery. Dan has extensive experience with application penetration testing (static and dynamic), product security reviews, network penetration testing (external and internal), and cryptographic analysis. He has presented at several Black Hats and DEF CONs on topics such as hacking smart safes, hijacking Google Chromecasts, and weaponizing AI. Dan holds both a Bachelor of Science and a Master of Science in Computer Science from Arizona State University.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere