Technology
Autonomous Autopsy
Every week, two hosts break down the security failures, close calls, and attack patterns hitting autonomous AI agents in the wild.
Listen on

Episodes
The archive
8 episodes, newest first.
- MCP's By-Design RCE Heads to VegasDerek and Max open with the still-unpatched MCP supply chain flaw that Anthropic called expected behavior, then map out which Black Hat and DEF CON 34 sessions actually matter if you're shipping agents into production.
- GLM-5.2 Ate the Export Controls for BreakfastSix days after Five Eyes warned that frontier cyber-AI attacks were months away, Z.ai dropped GLM-5.2 under an MIT license with no API governor, no rate limiter, and no off switch. Derek and Max autopsy what happens to every defensive assumption when the attack model is free, local, and already on Russian hacker forums.
- Five Eyes Named Your Agent Stack a National Security RiskOn June 22, 2026, the heads of NSA, CISA, and their four allied counterparts signed a joint statement naming frontier AI models Fable 5 and Daybreak as threats that will transform offensive cyber within months. Derek and Max autopsy what the advisory actually says, what it left out, and what you should fix before Monday.
- IronWorm Ate Your AI KeysA Rust-built self-replicating worm hit 36 npm packages with an eBPF kernel rootkit, Tor C2, and a shopping list of 86 environment variables that reads like a who's who of AI developer credentials. Derek and Max do the full kill-chain autopsy.
Show moreShow less
- Your AI Assistant Is Now the Attack SurfaceDerek and Max do a full autopsy of TeamPCP's May 2026 supply chain blitz: the Mini Shai-Hulud worm that hit TanStack, Mistral AI, and Guardrails AI, plus the TrapDoor campaign that weaponized .cursorrules and CLAUDE.md files to turn AI coding assistants into credential exfiltrators.
- Trivy Was the Key the Whole TimeOn March 24, 2026, TeamPCP backdoored LiteLLM on PyPI by poisoning the very security scanner LiteLLM used to protect itself. Derek and Max do a full kill-chain autopsy of the most consequential AI supply chain attack of 2026.
- Anthropic Called the RCE a FeatureOX Security found an architectural flaw baked into every Anthropic MCP SDK that enables arbitrary command execution across 200,000 servers, and Anthropic declined to patch it. Derek and Max dissect the kill chain, the CVE graveyard at vulnerablemcp.info, and what it means that banks like Grasshopper are already running this protocol in production.
- Shadow Agents at Scale82% of organizations are finding AI agents they never approved, and 95% of CISOs say they couldn't detect or contain a compromised one. Derek and Max break down the shadow agent kill chain, the no-code automation environments where these agents breed, and the concrete hunting steps your team can run before Black Hat season.
Talent
Talents in this show
Each one has a profile of their own.
About
What the show is
From prompt injection exploits and MCP vulnerabilities to rogue agent incidents and shadow AI breaches, Autonomous Autopsy treats each case like a crime scene: what happened, how it happened, and what the defenders missed. Built for security engineers, infrastructure leads, and anyone shipping AI agents into production who'd rather learn from someone else's disaster than create their own. If your agents have credentials, API access, or the ability to take action without a human in the loop, this show is your weekly briefing on what's going wrong and how to stop it.
More shows
Elsewhere in the directory
Every one of them is made with Mato.








