MYTHOS FINDS A CURL VULNERABILITY – BHIS - Talkin' Bout [infosec] News 2026-05-18

MYTHOS FINDS A CURL VULNERABILITY – BHIS - Talkin' Bout [infosec] News 2026-05-18

Source: YouTube · Black Hills Information Security · published May 18, 2026 · 1:06:35

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The cybersecurity community is observing a significant decline in the viability of Capture The Flag (CTF) competitions and bug bounty programs due to the rapid advancement of AI capabilities 0:12-0:15.

Key Takeaways:
• Recent CTF events in San Diego were reportedly solved entirely by AI participants, highlighting the shifting landscape of competitive hacking 0:20-0:27.
• One notable exception required competitors to call a physical phone number, a task AI could not perform, proving that physical world interactions remain a current limitation for automated agents 0:29-0:37.
• There was an incident where an AI agent was allowed to succeed while a human sat in the room, raising questions about transparency and the fairness of such competitions 0:39-0:46.

As AI tools become more sophisticated, traditional security challenges must evolve to test human-specific skills and physical-world interactions.

Sources:

  • 0:12 Discussion on the decline of CTFs and bug bounty programs.
  • 0:20 Mention of San Diego CTFs being won by AI.
  • 0:29 Explanation of the one challenge requiring a phone call.
  • 0:39 Anecdote about an AI being allowed to win while observed.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Talk about John's nudes till like 20 minutes in, so this is >> [laughter] >> We're ahead of schedule. No, we have a capture the flag, which is how fast can we get demonetized every show? [laughter] By the way, did you see that article about CTFs and bug bounty programs but how they're [ __ ] cratering everywhere? Uh I can the the besides San Diego CTF one and two were both one by by AI. Yeah. Oh, yeah. And the only one they didn't get was where you won you had to call a phone number. Yeah. And nobody told us No no one told us that that literally the dude was just sitting in the middle of the room letting the AI do everything. He didn't even And they were watching him. And I'm like, why did no one come tell us or like say anything? Like you guys let him win. I don't know what to tell you. I…