AI Agent Skills are a New Malware Supply Chain Risk | Tech Field Day News Rundown: February 4, 2026
This week’s Tech Field Day News Rundown dives into the biggest AI, security, and enterprise shakeups.
Tom Hollingsworth and Alastair Cooke deliver this week’s Tech Field Day News Rundown, starting with a global push by actors and musicians calling for a “permission-first” approach to AI training, as unions accuse AI companies of using copyrighted works without consent.
They also cover growing security concerns around agentic AI after researchers discovered serious vulnerabilities in MCP servers from Anthropic and Microsoft.
Snowflake and OpenAI’s $200 million partnership to bring governed, production-ready AI into the enterprise data cloud, mounting financial pressure on Oracle with potential mass layoffs and a possible sale of Cerner, high-severity vulnerabilities in the n8n AI automation platform that allow remote code execution.
They also discuss a critical Broadcom Wi-Fi chipset flaw capable of taking entire 5 GHz networks offline and new warnings from researcher Jason Meller about AI agent “skills” being weaponized as malware—highlighting how quickly AI ecosystems are evolving into both powerful business tools and major security risks.
This and more on the Tech Field Day News Rundown with Tom Hollingsworth and Alastair Cooke.
Time Stamps:
0:00 – Cold Open
0:25 – Welcome to the Tech Field Day News Rundown
1:26 – Creative Industry Launches Global Push Against AI Training Practices
5:17 – Anthropic and Microsoft MCP Server Flaws Expose Growing Security Risks in Agentic AI
9:27 – Snowflake and OpenAI Sign $200M Partnership to Bring Enterprise AI Closer to Data
12:48 – Oracle Weighs Massive Layoffs and Cerner Sale Amid AI Data Center Funding Crunch
17:03 – Critical n8n AI Automation Flaws Expose Systems to Remote Code Execution
21:21 – Broadcom Wi-Fi Flaw Highlights How One Wireless Bug Can Disrupt Entire Networks
25:24 – A Closer Look: AI Agent Skills Turn Into a New Malware Supply Chain Risk
35:36 – The Weeks Ahead: Upcoming Tech Field Day Events
37:51 – Thanks for Watching the Tech Field Day News Rundown
Transcript
Permitting AI work. MCP is still flawed. Snowflake partners with open ai, Oracle's uncertain on Cerner, automation flaws abound.
Wifi bugs are still out there. And we're gonna take a closer look at some molting claws in this episode of the Tech Field Day Rundown. Greetings everyone, welcome to the Tech Field Day rundown.
Hey, did you know that we're not quite 10% done with the year? Because it's February, it is February the fourth, as a matter of fact, and we are very happy to be here on the tech field Day rundown. It is national homemade soup day.
And, and I don't know about some of you, because I know it's cold in the country. It's like 60 degrees where I'm at a soup. I don't know, maybe I, I guess.
But, uh, one thing that I am certain about is that my co-host, Mr. Alistair Cook, is back from his sojourn to the Northern hemisphere. Al, it's good to see you.
It's a pleasure to be here. And I managed to stay in the warm parts of the Northern Hemisphere, despite it being the cold time of year. Uh, incidentally, it's a national day for New Zealand at the end of this week.
February 7th is our national day. Why Tan Day? And, um, it's an experience to look forward to.
Another experience to look forward to, of course, is all of the stories we have today. Exactly. And, uh, we we're gonna kick 'em off.
'cause I mean, there's some security stuff, it's kind of funny, uh, but of course there's some AI stuff that maybe is gonna help people be more funny. Uh, hundreds of top actors and musicians have launched a global campaign that is accusing ai companies of stealing copyrighted work to train generative models backed by major unions. The human Artistry campaign is calling for a permission first approach to ai warning that unauthorized training threatens jobs and the future of human creativity.
The fight comes as parts of the music industry begins. Striking licensing deals with AI firms and revealing a growing divide between confrontation and collaboration. Now, I was gonna put a really pithy joke at the end of this, but I couldn't get any of the AI agents to come up with a really good one.
So I guess I'll just turn it over to you. Is trying to create a collective amongst creators going to get the folks that run these AI algorithms to actually do what they're supposed to do in the first place? Maybe, but probably not.
Uh, the AI vendors build their large language models by harvesting everything they can see on the internet, whether they're supposed to or not. And that part's up for debate. We already covered this.
So a couple of times, I think on the rundown, talking about some of the court cases that are currently in play around fair use of content. And all of the AI providers say they're just fair use. We're just taking little segments and we're, uh, generating something that is a combination of multiple sources the way a human does when they read content.
Uh, the challenge, of course, is that the rate at which content is being then spewed back outta these large language models. It vastly exceeds the ability of human creators to actually create content. And, uh, a large number of content creators.
And this includes, um, in this case, cha Kahan, Kate Blanc and S Hanson are unhappy that the things they've been creating over their lifetime have been harvested and are now being used to generate AI slop. Um, I believe that was actually mentioned in the, in the quotes, uh, basically American sideline creators are being sidelined, not just American, but that's where this, the jurisdiction where this is being fought is about American, uh, creators. And, but essentially the whole spirit of human creation is being diluted by these large AI models that have stolen previous creation.
So, uh, it's a continuing story. This is definitely not one we've heard the end of. Even though organizations like Open AI have already struck deals with music publishers, they haven't yet struck deals with book, uh, creation or movie houses.
And so we probably will see this, we'll see a, a shift from the sort of confrontational, you can't do this to actually, we can be in business together and all be successful. You, you can compensate me for the things that I've, I've created that you're then reusing in the same way that, uh, libraries pay royalties, radio stations, pay royalties, AI companies will be continuing to pay royalties for more and more things. Um, leads us to some concerns about how things go when the, uh, recalculation of the AI market, the AI infrastructure market comes up.
Uh, it's also probably going to be yet another barrier to new entrant into creating large language models. I'm not sure that we need new entrants creating new large language models, but that's part of how, how industry works. So yes, this is a continuing battle.
This is another group of creators who have seen that there's been success by other collectives and are aiming to have more success. I think more likely the large AI companies will talk with the publishers rather than the creators. So it'll be the large organizations like the, uh, movie studios and the large book publication houses that actually do the negotiation with the AI vendors.
Uh, it's unlikely to be the, the smaller organizations that don't, just don't have the financial clout of these, uh, large publishing companies. Of course, our stories all revolve around AI all of the time at the moment. And, uh, we've noticed that, uh, security researchers have found some vulnerabilities and MCP servers, uh, those from Anthropic and from Microsoft.
And it highlights the growing risks around agent systems. And those, these particular flaws are ones that, uh, would allow, uh, sensitive data to be exfiltrated or, but have code execution, uh, running inside the environments where the, the data or originally resides. Uh, experts warn that the MCP adoption is growing, but as I've said earlier today, the s and MP stands for security.
And so you've gotta bolt security and controls all around this. Uh, and this needs to be done very, very rapidly because CP servers are proliferating in a being a headline thing. Uh, Tom, have we seen the last of these big security vulnerabilities and MCP servers, or is this gonna be a story for the agents?
I feel like we could probably do the story every week and it would still be relevant. And the reason why is the oldest problem in security. Well, it's that guy's job.
Uh, I don't know why you, you are getting onto me. I wrote the code. I didn't know I had to secure all the function calls.
What, what, what do you mean it's, it's in the server, right? I just hand it off to them and it works. And we never heard that before.
So one of the things that we've, we've been dealing with a lot is this idea that these AI agents can just pretty much do whatever they want. And that doesn't really work very well, right? Like, we can't just have 15 people, um, you know, requesting assets along the way.
And let, let's just assume for a moment that these AI agents are digital coworkers and not just scripts that are tools. Um, I want you to imagine in your office, let's just say for example, that there are 15 people running around and they all need resources and, and things from, uh, on high. Do you let them go talk to the CEO directly or call and, and buy things without that?
Or do you have a process for approving those things? And do you have a guardrails in place so that, for example, your employees don't go out and buy $4,800 worth of ballpoint pens? I, I'm guessing that you do, right?
That all gets funneled somewhere. And then there's a person who looks at things and makes these these judgment calls. Hey, guess what?
We have that in the AI world, and it's called MCP, but I'm gonna tell you a little secret folks. MCP does not have native security. It's not designed to do that.
MCP servers are checkpoints. It's checkpoint charlie, if you will. And if you're old enough to get that reference, you probably take ibuprofen before you go to bed tonight.
CP servers need to have security attached to them. That means we're all gonna have to get real smart real fast about where the security controls are. Because one of the things that was reported in this excellent article that I will come back to in a few minutes, so put a pin in that, is this idea that we are rapidly expanding the capabilities of these agent based tools without checking first to see what kind of security is in place to prevent them from doing things they're not supposed to.
In this particular case, one of the things that happened with the Microsoft flaw in particular is that a lot of the, uh, the tool sets that work on the back end were written in markdown. Markdown is fairly easy to understand. But if you don't put any kind of guardrails in place, people can inject just about anything into markdown and make it happen because it is, is a plain text language.
And so that's one of the things that you will see more about soon. We have to be very serious about this. We have to create structure that includes security as well as helping people understand that there's no inherent security in using MCP and MCP servers unless you put it there.
And if you didn't put it there, assume you don't have any at all. So I think that we're gonna be talking about this story for quite a bit to come, and I hope that I'm not talking about the same companies having the same problem over and over again. Snowflake and OpenAI have announced a $200 million multi-year deal to embed open AI's advanced AI models directly into snowflake's AI data cloud for enterprise use.
The partnership allows companies to run AI agents alongside their own governed data across major cloud platforms, reducing security and compliance risks, or so they say by focusing on deployment, governance, and real world business use, the deal signals a shift from AI experimentation towards scalable production ready enterprise ai. Al do you think snowflake's getting the better end of this deal, or do you think open AI is just trying to get another logo added to one of their slides? Oh, I think this is definitely a, a great deal for Snowflake.
Uh, snowflake has been progressively positioning themself as the place where you put all of your data that you wanna use in your AI applications, then something's gotta link those AI applications to that data. And when that's a cloud delivered AI model that's, uh, sitting in somebody else's cloud tenancy, in this case, open AI's, cloud tenancy, uh, there's some more security concerns around that. If we can push that AI service inside snowflake's tenancy, there's one less security boundary we're crossing as we're doing these AI things.
Uh, one of the fun things I saw in this is, of course, snowflake being available across all of the major, uh, public cloud platforms means that they're kind of a data standardization or they, they erode the differentiation between those clouds make it easier for companies to use the same snowflake data platform across multiple clouds wherever the data needs to be ingested. Now they're adding the open AI large language models and agents inside that same cross cloud platform where you're not nearly so tied to a single cloud or, uh, uh, essentially it's a, a meta service provider going on here with Snowflake. And now adding these features, our open AI likes this because it takes away some of the objection handling of taking your company sensitive data and pushing it across the internet to open AI's servers.
Uh, this place is the data governance alongside the execution of the AI models. So that seems to be a good thing, and I like that this isn't just a, we bundle the two things together. There's a commitment of the engineering teams to work together to particularly improve open AI's, SDKs, their software development kits and their agent kits to make it easier to create the agents on top.
I've gotta think that we'll be very helpful for putting a ring fence around Snowflake clients at making sure that nobody wants to exit the Snowflake service, but it will bring quite a lot of value to particularly the larger organizations who are wanting to use, uh, open AI and Snowflake together. Naturally, this is still pretty early on and as a rolling theme throughout AI tools and agentic ai, uh, security of data, security of execution, security of ai, um, we'll continue to see that need for, uh, security as we see AI being deployed at scale, particularly age AI at scale. It's gonna be an ongoing story.
Just you'll, you'll hear us talking about all lot. Another topic we're gonna talk about a lot is some of the consequences of spending a lot of money to build out for ai. And Oracle is currently reportedly considering layoffs of up to 30,000 of their staff as well as the sale over the entire Cerner healthcare unit that they only acquired four years ago.
This is coming about because Oracle is under increasing financial pressure and asset having higher costs to borrow money to build out the hundreds of millions of dollars worth of infrastructure. Um, despite for, for these AI projects, um, despite these challenges, Oracle says, uh, they remain committed to its long-term AI and cloud strategy. Thomas, is that a good strategy That remains to be seen?
Because all I've seen so far is that a lot of companies are going out there and buying up huge amounts of assets and then realizing they don't have a payoff strategy for this. Uh, I don't know if you guys have been following Nate Jones on, or Nate b Jones, I think is his actual, uh, name on, on YouTube. He also has a substack and a bunch of other things, and he's one of the people that kind of first brought this idea into my head a few months ago.
Um, these companies make money, right? Like we know that we, we've seen the quarterly reports because as soon as they release one, it's all we can talk about. And they make a lot of money, but they're spending a lot of money, right?
Like, this isn't a thing where they're creating value in a cloud somewhere. They are literally buying infrastructure in the hopes that down the road they're gonna be able to pay off when, well, according to what Sam Altman said at the Cisco AI Summit, you know, that, that, that there's some big huge breakthrough. There's a chat GPT moment, which I thought was kind of amusing coming from that guy.
Uh, but one of the things that happens though is that that money is owed to somebody else. This isn't like an Elon Musk thing where I can just trade money between a couple of companies that I own and it all works out in the end. Or that weird circular logic problem you have where like Nvidia buys a $2 billion worth of stuff from, uh, from a company that's then gonna turn around and buy $2 billion of stuff from Nvidia and like the money that does, that's not what's happening here.
What's happening is, is that a company is giving real money to another company and that money has to come from somewhere. Now I know where it should come from because I have a business degree and I took business accounting, oh God, uh, 30 years ago almost. Um, that money to buy that stuff comes outta your profits.
You know, the money that's left over after you've paid off everything. So like, if I paid all my salaries and I paid all of my bills and all that other stuff, and all the money that I have left over, I use that to buy things that I need. Like that's business 1 0 1, right?
But that's not how business 1 0 2 works in 2026 because the profits are what the shareholders deserve. And if they don't get their profits, they might sell their stock and that might cause the stock price to go down. And that might mean that Larry Ellison can't buy a TV network allegedly.
So what they do instead is the same thing that Amazon's doing. It's the same thing Oracle's doing. You gotta make the numbers work somehow.
Well, remember how I told you that you, the profit is what's left over after you pay your bills like your people's salaries, ahaha, haha, if I can reduce the number of salaries that I have to pay, that means I can cut the overhead and the money that I need to use to pay out all of this stuff is gonna come out of that instead of out of the profits. So, you know, why not lay off 30,000 people that make, uh, you know, a hundred thousand dollars a year? Uh, what is that?
That's still not as much as we're spending on ai, but the important thing is, is that it looks like we're trying to do this. Why not sell off Cerner? Well, great.
What are you gonna do with the money? We're gonna plow it right back into ai. And, and when you hear people talk about this, their, their thought process behind the whole thing is, well, if we can just build enough ai, if we can just build enough supply, then people will have to buy it to do what?
Exactly, because I think we tried that one time with tulips, and I seem to remember reading about that in business school, J Rog researchers have uncovered two high severity vulnerabilities in the innate n AI powered automation platform that could allow attackers to remotely execute malicious code. The flaws which affect both JavaScript and Python execution are considered very easy to exploit and highlight the growing security risks of, say It with me folks, AI driven automation tools. Organizations are using N eight N and they are being urged to update immediately and rethink patching strategies.
Because one of the things we're seeing is that AI is shortening the time between vulnerability disclosure and active exploitation. It's almost like people are able to get AI to actually jump out there and start doing this. So al my question to you is these two severities that were uncovered in N eight n, does that mean that people really should be thinking more carefully about how they're deploying these tools?
Or should they be rethinking their patching strategies to keep things up to date more quickly? Uh, and the answer of course is why not both? Yeah, 4K, no loss dose.
Yeah, I mean, these are pretty high vulnerability. 5. They're both remote code execution vulnerabilities.
5, little harder to achieve. Uh, but running that code inside whatever platform you're using in a and NA is a, a workflow automation tool, uh, that uses essentially AG agentic AI in the background. Uh, consequently this falls into our top theme of today, uh, security for your, uh, agents.
Uh, a couple of elements in this. One is that the NA TM platform can be run as a cloud service, in which case, uh, or consumed as a cloud service, in which case you should be consuming the latest released version at all times. That's what cloud services are about, right?
You, you rapidly release all of the latest versions. I hope the cloud providers that are delivering, or at least the the N 18 cloud service does this, but you can also deploy this on premises, and that will be a pretty common mode for more regulated, more controlled, uh, enterprise use. Of course, there's a whole lot of personal use of this as well as I've seen in my, uh, news feeds too.
Uh, fundamentally, if you're running it on premises, you, you have to keep it patched and updated. And there's nothing specific to NA 10 that is, is here a vulnerability due to, uh, the speed at which AI tools can scan and discover faults? Alright?
This is, this is not specific to NAN, it's absolutely across your entire IT estate AI tools can find and manipulate and, and, um, exploit these security vulnerabilities very rapidly, far faster than a highly skilled human being, and certainly faster than the script who used to be your biggest concern. Uh, this does then bring about some thoughts around, well, often the, the known vulnerabilities have a known resolution, a known patch resolution that we simply don't deploy fast enough. Now, if most vulnerable vulnerabilities were never exploited in the wild, this wasn't so much of a concern.
But if now it's conceivable that every vulnerability will be exploited within hours to days of it being known to somebody or discovered, that does then make us think about how quickly can I get patches out? How quickly can I safely get patches out? Can help with this there, help you with understanding which updates, which types of updates to which types of software are safe to deploy at great speed, and also to discover if a fault has occurred and roll those back.
These are the AI site reliability engineering tools that look at all changes, not just patching. And so like alcohol being the resolution to and source of all of life's problems, AI is going to be the source of and resolution to many of our problems in IT infrastructure over the coming years. Hey, this story doesn't have AI in it.
And newly discovered, uh, vulnerability in Broadcom wifi chip sets has allowed attackers to knock entire five gigahertz wireless networks offline with a single un authenticated signal forcing a manual reset of the affected servers. The floor was discovered through fuzz testing, uh, sending random signals into a, uh, system under test, and it affects widely used hardware and raises since serious concerns about business continuity, reliability, and trust in these always on always accessible wireless networks. Patches are available, but physical device firmware updating cycles means that this is gonna take a while to get out, particularly as wifi has become an in incre increasingly high criticality service within own organizations.
Uh, is this a reason to have some sort of diversity in the wifi hardware you have out or is there some other way of mitigating this risk? Well, It's kind of hard to do that because typically you don't buy Broadcom access points, do you? You buy from a company that buys from Broadcom and uses the wireless chip set as their underpinning.
So you may not actually know whether or not you're operating one of these chip sets that's, uh, problematic. Uh, that's why you really should be patching on a regular basis. And, and just so you know, because, uh, this is five gigahertz specific, a lot of people are like, oh, that must be bad.
4 gigahertz band offline with a single unauthenticated signal when I pop popcorn? 4 gigahertz, uh, spectrum completely offline. So the problem here is that you can send a malformed packet to one of these access points and, and it basically causes it to freeze and it needs to go into, uh, you know, you need to go bounce it.
And, and I get that, like that's a problem that a lot of people have pointed out. Why do we allow that to happen? Oh, I don't know.
Why do we allow these access points to scan for clients and offer wifi networks and all these other things while being unauthenticated? Why, why do we offer guest networks in, uh, restaurants and sporting events and things like that? The problem is not with the authentication mechanism that that's, that's not, uh, uh, up for debate.
Because if you have an authenticated network, that means you have to need to provide a password somewhere. It means you need to write it down, which means you need to restrict access to it. I applaud the researchers that found this for fuzzing it out enough to go, wow, nobody really thought about this, because it is, it's a fundamental 8 0 2 point 11 problem that's down, you know, at a protocol layer.
Nobody's gonna see this unless they're looking for it and unless they're trying to to do that. And bravo to Broadcom forgetting the patches out on time, but this is a good thing. So yeah, everybody stop puts keyboards down.
This is a good thing because we found it because we can patch it and because we can keep it from happening. Again, this is not something that was found by a security tool that was like doing millions of iterations on the 8 0 2 point 11, uh, standard document and found this one little weird thing. This was the kind of real security research that we should be doing more often to find these problems.
And, and I want more of that because if we can find these things before they hit prime time and become massive flaws across the entire system, then the patch lead time that we're talking about becomes a little bit longer because then that gives Broadcom a chance to issue a patch that then other organizations that use Broadcom hardware can implement. And I will tell you that wifi people are actually some of the best ones about pushing patches out pretty quickly because all of my wifi friends out there, you know how big of a pain in the neck it is to deal with drivers. And this is basically a driver update.
Alright, it's big time folks. Hope you guys have your little bibs and some drawn butter because we're gonna be roasting a particular crustacean security researcher, Jason Neller at One Password, who is a former Field day presenter, warns that AI agent platforms like open claw, nay molt, bot nay open clawed are creating a dangerous new attack surface. We're seemingly harmless skills written in, marked down.
Oh, hey, there's that thing I mentioned before. They can function as malware delivery mechanisms. His investigation uncovered highly downloaded skills that used fake prerequisites and set up instructions to trick users into executing info, stealing malware, exposing credentials, tokens, and sensitive data.
The incident highlights how agent ecosystems blur the line between documentation and execution, which turns skill registries into supply chains that attackers can then exploit, underscoring the urgent need for stronger trust layers, providence and permission controls and AI agent frameworks. Now, here's something that I think is kind of fascinating about this whole thing. This is all developed over the course of 10 days.
We went from open claw to mt bot to open claw to claw book, is it Claw book, whatever. Uh, and then one password. Jason Miller just comes out and basically has, if you go read the blog post that we we're gonna link here 'cause it is a thing of beauty.
Jason does not mince words. If you have deployed open claw on a, on a production machine and your business, assume all of your data is on the internet and you've been breached. So I'm gonna, I'm gonna let you start this al because I I gotta warm up my pincers here.
How do We feel about this? Um, shocked, stunned, horrified. Uh, well, um, so while I was at AI Infrastructure Field day last week, I was reading some of the early news of this is what Claude Bot, malt bot, whatever it's being renamed to does.
And the idea is you install the, the base software on a, on a computer and then you say, here's everything I know, work out how to help me do what I want to do. And by the way, here's everything I communicate with. Here's all of my data.
Here's, here's access to all of my emails, all of my texts, everything go work out for yourself, how to help me, and equally, how to help other people who communicate with me. Now, what claw bot, uh, mal bot, what this agent then does is says, right, I've, I've discovered you need to do something. I'm gonna go and install some software to help me do it.
And this is, uh, one of the attack vectors because there are wild West style registries where you can just pull down descriptions of how to help. They're called skills. And as, uh, Tom says, it's just a markdown text file that describes a set of actions.
If you are particularly reckless and who isn't, when you're deploying this stuff, you can say to your agent, just get everything you need. Don't bother asking me. Just download it, install it.
I don't care. Don't care what it's, so they get, your agent then goes out to, uh, these repositories says, I need a skill in order to do something basic. Uh, and it was a Twitter integration.
One was the one that, that Jason particularly called out, I need to integrate with Twitter or X. Uh, there's a prereq for that integration, which is to download some malware that is gonna steal every piece of information on the computer that you have just given access to everything. It is the most downloaded skill from that particular repository, and it's, particularly, its Mac malware, which, uh, affects me, wouldn't affect me if I was still using Windows.
But of course, there's plenty of Windows malware that you could download as a skill too. Uh, a huge number of the skills that are on these repositories contain malware. And it comes back to we need governance around this.
And the same way that we need governance and security around things like docker containers. When you download a docker container from Docker hub, there is governance around it, there is history of when was it released, who has released it. That's the very minimum we need as we're actually, as somebody's running these repositories.
And that's, again, something that's called out in this excellent article. If you run one of these repositories, you need to make sure you're not being a distributor of malware. Well, maybe that's not accidental.
Uh, yeah, this, this is a, an interesting train wreck happening. I sincerely hope nobody, uh, none of our listeners, none of our friends have deployed this anywhere but inside a very controlled sandbox and gave access to all a very limited amount of data. I suspect not, I suspect people have gotten quite excited about this amazing capability and I'm now wondering where they're gonna work next week.
Um, yeah. Yeah. I mean, it just feels painful, doesn't it, Tom?
It does. And like, look, the, they had all the right ideas at the beginning, right? It was on Mac stories for God's sakes.
Like, that's where I first saw it. I was like, oh, neat. I don't have a use for this right now, but I'll keep an eye on it.
And then we had all the renaming going on, which by the way, all the people squatting on those names to try to sell, you know, uh, crypto tokens. Bad, bad people don't do that. But like, the more you deal with this, and, and Jason did an amazing job on this, this, by the way, um, like, it, it is in the same problem that we have with the MCP server, right?
Well, whose job is security? Well, it's their job, not mine. I passed it off to the people who are supposed to secure things in, in general, this is the idea of what you want something to do.
If I have a, a thing that I wanna use to extend the capability of my device, then I give it a, uh, I give it a manifest and tell it to go get things that it needs, right? It's really, really straightforward, except nobody is checking to see what's going on. And that's the problem.
You cannot trust people. You can trust a person I trust Al I don't trust people. And these tools are written by people, not a person.
Yeah, Mt bought Claude. Claude bought Claude Molt, molt. Claude bought molt, whatever it was written by a guy.
We know who it was. And he has everybody's best intentions in heart. I'm not, I'm not telling, saying that the guy did anything wrong.
He, he actually, the fact that it got mentioned on stage at the Cisco AI Summit to Sam Altman as the hot new thing, and you could just, you could physically feel Sam Altman rolling his eyes. It's like, I am the most important human being on the planet. I'm gonna change the way the society works.
And you're talking to me about some guy who wrote something in his garage that I don't think is very important. Who cares? The fact that he's in the conversation should tell you the guy's got a, a huge future ahead of him.
The problem is, is that he did not think through the fact that people are idiots and some people are deceptive idiots. And that's exactly what happened, because all I have to do is upload the script and it says, go download this thing. That's not bad.
That downloaded thing says, well, you need to go fetch this package. That's not bad. But at no point along the way did anybody stop and do a sanity check and go, should I really be downloading things that I am not checking?
And if you follow the chain down far enough, what you're doing is you're pulling a binary that has no visibility whatsoever. And one of the first things that binary does is it restricts Mac OSS gatekeeper. Show of hands, and I'm not gonna count, but you, you know who you are.
Put a finger down if you have ever copied a command line from a webpage telling you to execute it in the terminal to make sure that a piece of software is able to install without triggering a warning message or failing to install properly. I hope every one of you people put your fingers down because we've all done it. We shouldn't, we know better.
If you don't know what a command does, don't run it. If you don't understand where a binary is coming from, don't install it. And if it's a piece of base 64 encoded code in a URL, you better not Jason uploaded this thing to virus total and it hit immediately.
It's like, I don't know what this thing is, but it's not good. This is the problem. We, okay, you know that I have a security podcast, you know that I do Security Field day and you know that a lot of my friends are security nerds.
We all say the same thing. You cannot pass the buck on security. And if you think you can please send me your social security number and your bank account passwords.
I mean, I'm a trustworthy person, right? What am I gonna do with them? If you're sitting there shaking your head saying, you wouldn't do that, then don't do it for anybody else.
Yeah, guess what? I I have all the hope in the world that Open Claw is going to change the way that we talk about agent workflows, because it's doing exactly what an AI agent should be doing. It's monitoring all of your communications channels, it's munging all of that data together, and it's giving you ideas and helping you do stuff.
In theory, open Claw is great in practice. People are untrustworthy idiots that are gonna try to compromise it to steal all of your data. Because guess what, at the heart of every brand new paradigm shifting thing that we've been talking a lot for the last 20 years are the same core group of criminal grifters that wanna make a quick buck from whatever's next.
And this is fundamentally, it's, this is a classic supply chain attack. You need to secure your supply chain. It, it really, it's security one.
Oh. It's, uh, we could rant and rave about this all day and, uh, we probably will, but you don't wanna listen to that all day. What you do wanna listen to though is Cloud Field Day Cloud Field Day will be back.
I'll be back in the United States surprisingly soon. It'll be March 11th and 12th. Uh, we'll be back with Cloud Field day number 25, as usual, great schedule of content, great schedule of delegates joining us.
I'm looking forward to another trip back to the United States. And of course, uh, Tom doesn't get to leave the United States. You have the end of March covered.
I do, because we're gonna be at RSAC this year. I bet you there's gonna be some talk about Open Claw and among other things that we talk about on the rundown every week. But we have exciting presentations from folks like Veeam.
Uh, we have, uh, great presentations from Commvault. Uh, we have, uh, a lot of presentations including Object First. Um, they're, they're, you know, recently now part of Veeam.
Uh, check out the website. Uh, we're gonna be listing our delegates there pretty soon. There are a lot of those same people that are out there telling you don't download software that you don't know what it does.
Uh, more importantly, the reason that we're excited to be there is because there's so many other great things going around on RSA, uh, Futurum Group and, uh, Techron TV have some cool stuff going on. There's gonna be a lot of content coming out of it, and we hope that you're tuned in for all of it. 'cause it really is, it's the biggest security show of the year.
Uh, so big in fact that we have to schedule our events away from it because nobody else wants to do anything when it's our SAC time. And, uh, it, it should be a lot of fun. And you're gonna hear a lot of familiar voices.
You're gonna hear a lot of familiar things that we've been telling you guys for the last 10 years, and hopefully this time, just like the year of VDI, I hope it's gonna stick. But you know, what does stick is that every week we're back here with more great news. Sometimes it feels like we're repeating ourselves, but you know what?
That's why you watch The Rundown every week because we put out new episodes every Wednesday. We put 'em up on YouTube. You can download us in your favorite podcast application of choice.
2 x whatever. I don't care. Uh, the rundown is also stream on text, on TV in a bunch of other places.
Do us a favor though. We want you to go down here and leave a comment. Um, you know, put your finger down if you did the thing that I told you that we all did.
Uh, tell me if you've run Claude Bot, uh, you can use an alias if you, if you wanna make sure that you're not gonna get in trouble. Uh, but we want to hear from you and we want to let you know that we're gonna be back next Wednesday to talk about all the IT news of the week. That was for myself, for my co-host, Alistair Cook, and for the Tank of Lobsters that I have over there currently fighting to see who's gonna be my new AI agent.
I wanna wish you all a happy week. And do me a favor, put some authentication in place, do it for the lobsters. We'll see you next week.