0x696 - Actu - 18 janvier 2026

0x696 - Actu - 18 janvier 2026

🎙 PolySécure Podcast 👥 540 📅 January 19, 2026 ⏱ 45 min 👁 15 📄 news review 🧭 2026-08-16
Available in: English (current) Français

Keywords

AIprompt injectionprivacysovereigntycybersecurity

Summary

In this episode, the host covers a wide range of cybersecurity news from January 2026. He begins with a brief announcement about upcoming conferences and events. The main topics include the use of AI by attackers, highlighting that they are not fundamentally changing their strategies but using AI to accelerate and refine existing workflows. He discusses several prompt injection vulnerabilities in products like Anthropic’s Cowork and Microsoft Copilot, criticizing the lack of proper access controls in AI agents. The host also covers Signal’s new private AI model and warnings about agentic AI insecurity. He expresses concern about ChatGPT introducing ads, fearing manipulation. In the sovereignty section, he discusses Cloudflare’s threat to leave Italy over a fine, France ordering VPNs to block pirate sites, China banning US and Israeli cybersecurity software, and AWS launching a European cloud. He also touches on privacy issues, including complex US privacy laws, a data leak from Flock surveillance systems, and various other incidents. The host provides critical analysis and personal opinions throughout, emphasizing the need for better security practices and sovereignty considerations.

177 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into current cybersecurity trends, particularly the pragmatic use of AI by attackers and the security challenges of AI agents. The host argues that AI is not a game-changer for attackers but a tool to enhance existing methods, which is a nuanced perspective. He also raises important points about the lack of access controls in AI agents and the potential dangers of advertising in AI chatbots. The argumentation is generally solid, supported by references to recent news and personal expertise. However, some claims are based on opinion rather than evidence, and the host occasionally makes broad generalizations without deep technical detail.

Scientific Rigor, Source Quality, Title Accuracy

The host cites multiple sources from the description, including news articles and reports. He provides context for each topic and often links them to broader issues. The title accurately reflects the content as a news roundup. The sources appear credible, though the host does not always verify claims independently. The video is well-structured, with clear sections for different topics. The host’s analysis is thoughtful, but the lack of in-depth technical explanation may limit its usefulness for experts.

197 words

Title / Content Match

The title accurately reflects the content: a news roundup for January 18, 2026.

Quality & Reliability

7/10

The host provides a balanced overview of recent cybersecurity news, citing multiple sources and offering critical analysis. However, the video is a personal commentary with limited in-depth verification of claims, and some statements are subjective opinions.

Key Moments

Cited Sources

  • What Should We Learn From How Attackers Leveraged AI in 2025? — Referenced in the AI section to discuss attacker use of AI.
  • LLMs are Accelerating the Ransomware Lifecycle to Gain Speed, Volume, and Multilingual Reach — Referenced in the AI section to highlight AI's role in ransomware.
  • Prompt injection — Referenced in the prompt injection section.
  • Anthropic’s Files API exfiltration risk resurfaces in Cowork — Referenced in the prompt injection section.
  • New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data — Referenced in the prompt injection section.
  • Claude Cowork – Quand l’IA d’Anthropic se fait exfiltrer vos fichiers — Referenced in the prompt injection section.
  • Signal creator Moxie Marlinspike wants to do for AI what he did for messaging — Referenced in the Signal section.
  • ‘Signal’ President and VP warn agentic AI is insecure, unreliable, and a surveillance nightmare — Referenced in the Signal section.
  • ‘Most Severe AI Vulnerability to Date’ Hits ServiceNow — Referenced in the AI agents section.
  • ChatGPT will get ads. Free and Go users first — Referenced in the ChatGPT ads section.
  • Cloudflare CEO threatens to pull out of Italy — Referenced in the sovereignty section.
  • Italy’s privacy watchdog, scourge of US big tech, hit by corruption probe — Referenced in the sovereignty section.
  • La France remet ça et ordonne aux VPNs de bloquer encore plus de sites pirates — Referenced in the sovereignty section.
  • China bans U.S. and Israeli cybersecurity software over security concerns — Referenced in the sovereignty section.
  • SéQCure 2021 - Splinternet par Franck Desert — Referenced in the sovereignty section.
  • AWS flips switch on Euro cloud as sovereignty fears mount — Referenced in the sovereignty section.
  • Dutch experts warn U.S. takeover of DigiD platform poses national security risks — Referenced in the sovereignty section.
  • Escaping the trap of US tech dependence — Referenced in the sovereignty section.
  • Privacy and Cybersecurity Laws in 2026 Pose Challenges — Referenced in the privacy section.
  • Police Unmask Millions of Surveillance Targets Because of Flock Redaction Error — Referenced in the privacy section.
  • UK backtracks on digital ID requirement for right to work — Referenced in the privacy section.
  • France fines telcos €42M for issues leading to 2024 breach — Referenced in the privacy section.
  • US regulator tells GM to hit the brakes on customer tracking — Referenced in the privacy section.
  • Foreigners’ data stolen in hack of French immigration agency — Referenced in the privacy section.
  • Facebook login thieves now using browser-in-browser trick — Referenced in the red team section.
  • More than 40 countries impacted by North Korea IT worker scams, crypto thefts — Referenced in the red team section.
  • Never-before-seen Linux malware is “far more advanced than typical” — Referenced in the red team section.
  • Predator spyware demonstrates troubleshooting, researcher-dodging capabilities — Referenced in the red team section.
  • OGhidra - Dopage à l’IA pour Ghidra en local — Referenced in the red team section.
  • China spies used Maduro capture as lure to phish US agencies — Referenced in the red team section.
  • A simple CodeBuild flaw put every AWS environment at risk — Referenced in the red team section.
  • Pourquoi votre vieux serveur Windows est une bombe à retardement, et comment la désamorcer — Referenced in the red team section.
  • Windows? Linux? Browser? Same Executable — Referenced in the red team section.
  • Selectively showing “act on your behalf” warning for GitHub Apps is in public preview — Referenced in the blue team section.
  • Python Software Foundation News: Anthropic invests $1.5 million in the Python Software Foundation and open source security — Referenced in the blue team section.
  • Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws — Referenced in the blue team section.
  • CISO Succession Crisis Highlights How Turnover Amplifies Risks — Referenced in the blue team section.
  • Internet monitoring experts say Iran blackout likely to continue — Referenced in the miscellaneous section.
  • Access to Elon Musk’s Starlink internet service is now free in Iran as regime continues brutal crackdown on protests — Referenced in the miscellaneous section.
  • Poland says it repelled major cyberattack on power grid, blames Russia — Referenced in the miscellaneous section.
  • Judge tosses CrowdStrike shareholder suit over 2024 outage — Referenced in the miscellaneous section.
  • 1980s Hacker Manifesto — Referenced in the miscellaneous section.

Concurring Sources

  • What Should We Learn From How Attackers Leveraged AI in 2025? — Supports the host's discussion on AI use by attackers.
  • LLMs are Accelerating the Ransomware Lifecycle to Gain Speed, Volume, and Multilingual Reach — Supports the host's point about AI accelerating ransomware.
  • ‘Most Severe AI Vulnerability to Date’ Hits ServiceNow — Supports the host's concern about AI agent vulnerabilities.
  • Cloudflare CEO threatens to pull out of Italy — Supports the host's discussion on the Cloudflare-Italy dispute.
  • AWS flips switch on Euro cloud as sovereignty fears mount — Supports the host's discussion on European cloud sovereignty.

Dissenting Sources

  • ChatGPT will get ads. Free and Go users first — The host expresses concern about ads in ChatGPT, but some may argue that ads are a common business model and not inherently harmful.

Contribution & Novelties

The video provides a comprehensive and critical overview of recent cybersecurity news, with a focus on AI security, sovereignty, and privacy. The host offers unique perspectives on the pragmatic use of AI by attackers and the dangers of AI agents lacking access controls. He also highlights the geopolitical tensions around digital sovereignty and the ethical implications of advertising in AI chatbots. The video serves as a valuable resource for professionals and enthusiasts to stay updated on current trends.

Pour aller plus loin :

  • Prompt injection — Wikipedia article explaining the concept and its implications.
  • Agentic AI — Wikipedia article on AI agents and their security challenges.
  • Digital sovereignty — Wikipedia article discussing the concept and its global relevance.
  • Cloudflare — Wikipedia article on Cloudflare, relevant to the Italy dispute.
  • Signal (messaging app) — Wikipedia article on Signal, relevant to the new AI model.

143 words

Radar Profile

The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-rounded news review that is informative and credible, though not extremely technical.

Reliability 7/10