Episode 1083 · Security Now (Audio)
SN 1083: Patch Tuesday à la AI - Arch Linux Repo Under Siege
17 Jun 2026 · 2 hr 36 min
Episode 1083 · Security Now (Audio)
17 Jun 2026 · 2 hr 36 min
This episode unpacks the jaw-dropping surge in vulnerabilities unearthed by AI, revealing how Microsoft shattered its own patch records while adversaries and defenders race to outpace each other. The conversation gets real about whether AI is fixing our broken software or just making attacks easier for everyone. Rootkits found in more than 400 ArchLinux User Repository packages. The US government requests Anthropic to remove Mythos and Fable. CISA responds to AI-driven attacks with new patching requirements. NPM to switch to more secure install defaults. Will it help. Our listeners react to…
Jun 17th 2026
AI-generated, human-reviewed.
Microsoft shattered previous records with the June 2026 Patch Tuesday, issuing over 200 security updates for Windows and its ecosystem. This surge in vulnerability fixes marks the dawn of an AI-driven era in software security—and brings major changes for every Windows user and system administrator.
According to Steve Gibson and Leo Laporte on Security Now , Microsoft leveraged advanced artificial intelligence to uncover and fix vulnerabilities across its platforms. Code-reviewing AIs—like Microsoft’s internal “M Dash”—now analyze vast amounts of source code, revealing security flaws undetected by traditional methods.
This process resulted in more than 200 Windows vulnerabilities being fixed in a single update cycle—a number that far exceeds previous Patch Tuesday totals. Notably, over 30 of these were labeled “critical,” including at least 28 remote code execution flaws that could let attackers run malicious code on unpatched systems.
The volume and severity of bugs patched this month underscore the risks of delaying updates. Among the critical flaws fixed, six were “zero-days”—meaning they were publicly known or actively exploited before Microsoft issued a fix. Vulnerabilities touched key Windows components like BitLocker encryption, Windows network services, and remote desktop features.
Failing to apply these updates leaves systems exposed to both automated malware and targeted attacks. With AI increasingly available to both defenders and adversaries, the window for attackers to exploit unpatched systems is shrinking.
On Security Now , Steve Gibson explained that AI is now “front and center” in vulnerability discovery and mitigation. AI models can audit mountains of legacy code, spot subtle coding errors, and even design proof-of-concept exploits—tasks previously reserved for elite hackers or months-long manual code audits.
This transformation means that not only are more bugs found and fixed, but the rate at which vulnerabilities are discovered has skyrocketed. The immediate challenge: companies and IT managers must adapt to more frequent, larger, and faster patch cycles.
The massive increase in patched vulnerabilities means improved security for those who stay current with updates. However, it also brings operational strain. The U.S. government now requires some agencies to patch within three days of a critical vulnerability disclosure—a policy that many private organizations may soon have to emulate. Automation and robust patch management processes will become essential to keep up.
As more bugs get patched quickly, the overall security baseline for Windows users should improve. But for the next several months, expect elevated patch volumes—and ongoing waves of critical fixes as AI tools continue to dig deep into legacy codebases.
Microsoft’s record-breaking Patch Tuesday in June 2026 demonstrates how artificial intelligence is transforming software security. By harnessing powerful code-analyzing AIs, Microsoft is closing old gaps in Windows security at an unprecedented rate—but it also means users and IT pros must be more vigilant and respond to updates faster than ever. Adopting automated patch management is quickly becoming a necessity, not a luxury.
Stay up to date and get expert analysis every week—subscribe to Security Now : https://twit.tv/shows/security-now/episodes/1083
Transcript supplied by the publisher with the episode.
by TWiT · English · Tech & Science
Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every…
E1086 · 8 Jul 2026 · 2 hr 53 min
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are…
E1085 · 1 Jul 2026 · 2 hr 50 min
AI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down. Win10's popularity forces another year of free updates. CISA directs all federal agencies to update their UniFi OS devices. CISA gave federal agencies "the weekend" to update Cisco devices. Australia is disturbed by a deeply compromised infrastructure provider. OpenAI introduces Daybreak-powered "Patch the Planet" initiative. Meta's…
E1084 · 24 Jun 2026 · 2 hr 48 min
A flood of everyday gadgets, from cheap streaming boxes to digital photo frames, are being secretly conscripted into global proxy networks and used to mask major cyberattacks—possibly even targeting your own home network. Worries of AI-power cyberattacks are spreading. Mythos "missed some" important vulnerabilities in Firefox. Every recent patch Tuesday Nightmare Eclipse has struck. What now? Massive store of valid FortiGate VPN credentials found. F5 issues emergency updates to their NGINX-based server offerings. Introducing "AI Potpourri" -- deeply altering an AI's personality. A close look…
E1082 · 10 Jun 2026 · 2 hr 37 min
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns…
E1081 · 3 Jun 2026 · 3 hr 20 min
AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to…
E1080 · 27 May 2026 · 2 hr 44 min
Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage. Cisco meets Mythos Can the aging CVE system survive AI Patch deployment latency in the AI age MSFT's official YellowKey BitLocker bypass mitigation Ubiquiti patches 5 serious vulnerabilities Drupal attacked by a PostgreSQL injection Microsoft terminates SMS as a second factor GitHub hacked - all of its…
E1099 · 7 Oct 2026 · 3 hr 3 min
As AI becomes startlingly capable, top minds at OpenAI admit they can't always control what their own creations do—or even fully understand how they think. This episode dives into the real-world tension between rapid progress and the growing challenge of keeping AI truly aligned. GLM-5.3 can be and has been abliterated. What does that mean? Firefox 157 repairs a large number of high-impact vulnerabilities. A surprising reduction in RSA crypto strength has been discovered. Powerful agentic AI is being used to attack merchants. A new and potent Spectre-style processor attack has been designed.…
E1098 · 30 Sep 2026 · 2 hr 42 min
With millions racing to embrace AI assistants and cybercriminals pivoting to new, high-stakes tactics, the episode tackles the dizzying pace of change and asks: just how worried should we be? The discussion pulls back the curtain on AI's unpredictable power, the escalation of digital extortion, and why the next breach may hit closer to home than you think. Muse has a bad 0-day The regularity of "Irregular" More rogue OpenAI breaches The Seven Deadly Sins (TSDS) hacker group Liquified Natural Gas (LNG) cargo ship hacked The FBI offended ShinyHunters's delicate sensibilities Canonical switches…
E1097 · 23 Sep 2026 · 2 hr 50 min
After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided with real-world chaos. Andrew Ng weighs-in on AI Doomsaying. The wisdom of outsourcing AI security testing. The true risk of an AI-created bioweapon. The EU KIDS Act -- this one is even messier. "Nightmare Eclipse" finally unmasks himself. A whitehat firm used Claude to attack OpenAI. Cisco's own massive 77 CVE update. What was the fallout from Sept's Patch Tuesday Show…
E1096 · 16 Sep 2026 · 2 hr 51 min
Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? The full report on last week's nearly 1,000 Microsoft security fixes. Five months after its start, what's the status of Project Glasswing? Anthropic's rogue agent escape count reaches four incidents. Not to be outdone, OpenAI's count passes 10 and maybe as many as 23! Revisiting California's DROP compulsory data broker data deletion. Russian criminals get their hands on more than 153 million drivers license scans. "Skynet" is the wrong…