
16-Year-Old Hacks Microsoft + AI Tools Store Your Secrets + Your Car Shares Your Data
Show notes
A 16-year-old found a way into Microsoft's internal Titan analytics service, reported it responsibly and was paid five thousand dollars. Another 16-year-old is suspected of running a ransomware group that Eurojust links to almost a thousand attacks. Coding agents are storing API keys and credentials in plain text, and more than 543,000 credentials exposed in public GitHub repositories were still valid in July. And the app that comes with your car may be passing your data to advertising and tracking companies.
This week on Click Happens: episode two, with guest Oli joining while Ant records from a cybersecurity conference at sea in the Caribbean. We get into why convenience keeps beating security when it comes to AI tools, how "always approve" turns into a habit, and what organisations should do when a teenager shows them a hole in their systems.
00:00 Intro
03:42 AI coding agents are storing your secrets in plain text
07:37 Gemini desktop control and the "always approve" problem
11:18 Anthropic's voice data prompt and what AI knows about you
18:12 The 16-year-old who found a Microsoft Titan flaw
24:36 The 16-year-old suspected of running KillSec ransomware
28:14 543,000 valid credentials in public GitHub repos
36:40 Car apps sharing owners' data with advertisers
48:16 The Times Car breach, 6.6 million accounts
Subscribe for weekly cybersecurity news made simple, so even your mum gets it.
Click Happens is an independent podcast hosted by Ant Davis, with a different guest joining each week. This week's guest: Oli Inkley.
Instagram: @antdaviscyber
TikTok: @antdaviscyber
LinkedIn: @antdaviscyber
YouTube: @antdaviscyber
Website: www.antdavis.com