
Episode #3
Vulnerability Management in the Age of AI
<p>The security community has been sounding alarms about AI infrastructure for two years. BadHost, a critical authentication bypass discovered in May 2026 inside one of the most widely used Python frameworks on the internet, is what that alarm sounds like when it goes off. Dan Fernandez returns to AI Spy to talk about what actually happened, why the official severity rating understates the real risk, and what the broader pattern of 40-plus CVEs against MCP implementations in 2026 alone tells us about how AI infrastructure is being built. This is not a technical deep-dive. It is a practitioner briefing on the...






