← Back to all episodes
March 16, 2026 — #3

An AI Agent Hacked McKinsey's AI Chatbot in Under 2 Hours

#3 · ~15 min · Curated by Asaf Nakash

Stories This Week

Curator's Corner

Built-in AI security is a sensor, not a solution. OpenAI buying Promptfoo raises the security floor — more model-layer testing, available by default. But the McKinsey breach didn't happen at the model layer. No jailbreak, no prompt injection. The vulnerabilities were unauthenticated APIs and SQL injection in the deployment infrastructure — things no model-layer testing tool would catch. Platform-native security raises the floor, but to truly protect AI, you need to understand the infrastructure underneath it — the tools, the memory, the integrations. That's where the real risk lives.

Never miss an episode

Spotify Substack RSS
📰 Subscribe to the newsletter on LinkedIn