Episode 1087 · Security Now (Audio)
SN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records
15 Jul 2026 · 2 hr 49 min
Episode 1087 · Security Now (Audio)
15 Jul 2026 · 2 hr 49 min
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet"…
Jul 15th 2026
AI-generated, human-reviewed.
The latest episode of Security Now revealed three new, deeply concerning security attacks—HalluSquatting, Ghost Approval, and GitLost—that take direct aim at AI agents and coding tools. These attacks highlight why every user and developer leveraging AI systems must understand the evolving threat landscape and adopt stronger security controls.
On Security Now , the discussion focused on HalluSquatting, a new attack where adversaries exploit the tendency of AI models to hallucinate (i.e., make up) the names or locations of resources like code repositories or packages. AI-based code assistants and agents, such as Copilot or Gemini, often can’t reliably confirm where new or trending packages actually exist. When tasked with cloning or installing a resource, they might “invent” a plausible-looking but incorrect repository name and attempt to retrieve it 01:56:03.
Attackers can predict these common hallucinated names, pre-register them, and seed them with malicious instructions—including installing a reverse shell or malware. Because coding agents frequently have high privileges and automatic install rights, this enables attackers to compromise potentially thousands of machines, automatically and at scale, without targeting victims one by one.
HalluSquatting is particularly dangerous because it turns innocent AI mistakes into enormous security risks, weaponizing the AI’s natural gaps in knowledge to build botnets or deploy ransomware on a massive scale 01:59:04.
The episode also covered Ghost Approval, a newly discovered class of vulnerability impacting popular AI coding assistants. Here, attackers exploit symbolic links (symlinks)—special files that point to other files—to make an AI agent believe it is modifying or approving a harmless edit, when in reality it’s writing to a sensitive or unauthorized location 02:01:28.
For example, an AI might propose a code change, ask a human to approve it, and then use a symlink to silently write to a system file outside of the approved working directory. On Security Now , it was explained that this “UI confusion” allows critical information to be hidden from the human reviewer: the user thinks they’re OK’ing a safe change, but the AI’s underlying action is far more dangerous 02:03:00.
Multiple vendors—including Amazon and Google—were found to have this issue in their products. While some have issued fixes, this highlights how old vulnerabilities (like symlink attacks) can resurface in new forms when AI agents are involved.
Another key AI threat explored was GitLost, in which attackers use indirect prompt injection to manipulate AI-powered GitHub workflows. In this scenario, any malicious stranger can submit a GitHub issue with hidden commands embedded in natural language text 02:06:26.
If an AI agent with organization-wide permissions responds to the issue, it may read these instructions and unwittingly execute them—leading to critical private data being leaked or actions being performed with elevated rights across both public and private repositories.
According to Security Now , GitLost demonstrates a fundamental design risk in today’s generative AI: the agent’s “context window”—the set of data and instructions it can process—is also its attack surface. If untrusted data isn’t carefully separated from control instructions, attackers can hijack the workflow with zero programming knowledge.
A key theme that emerged was that today’s AI agents are often built and integrated with a focus on functionality, not on robust security boundaries . All three attack types—HalluSquatting, Ghost Approval, and GitLost—exploit the fact that AI tools often fail to distinguish cleanly between trusted instructions and untrusted data, or blindly trust information supplied by third parties. As a result, legacy security problems (like typo-squatting and symlinks) can now be automated and scaled up using AI, turning “classic” attacks into existential problems for organizations.
According to Security Now , these new attack techniques—HalluSquatting, Ghost Approval, and GitLost—are proof that AI’s promise comes with serious new risks. Developers, security teams, and end users should be wary of overtrusting AI agents, insist on strict boundaries between code, instructions, and data, and keep up with patches and research as the field evolves.
For more in-depth analysis of today’s most pressing AI and security issues, subscribe to Security Now : https://twit.tv/shows/security-now/episodes/1087
Transcript supplied by the publisher with the episode.
by TWiT · English · Tech & Science
Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every…
E1090 · 6 Aug 2026 · 2 hr 5 min
At Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge and genuine progress? • Black Hat and DEF CON: Hacking Stories and Conference Culture • Zoox Ride-Hailing Hack and Over-the-Air Vulnerabilities • Autonomous Vehicles, AI, and the Security Implications • Hosts Share Personal Adoption and Use of AI Tools • AI-Powered Coding: From Hobbyists to Advanced Agency Chains •…
E1089 · 29 Jul 2026 · 3 hr 8 min
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL…
E1088 · 22 Jul 2026 · 2 hr 47 min
Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update.…
E1086 · 8 Jul 2026 · 2 hr 53 min
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are…
E1085 · 1 Jul 2026 · 2 hr 50 min
AI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down. Win10's popularity forces another year of free updates. CISA directs all federal agencies to update their UniFi OS devices. CISA gave federal agencies "the weekend" to update Cisco devices. Australia is disturbed by a deeply compromised infrastructure provider. OpenAI introduces Daybreak-powered "Patch the Planet" initiative. Meta's…
E1084 · 24 Jun 2026 · 2 hr 48 min
A flood of everyday gadgets, from cheap streaming boxes to digital photo frames, are being secretly conscripted into global proxy networks and used to mask major cyberattacks—possibly even targeting your own home network. Worries of AI-power cyberattacks are spreading. Mythos "missed some" important vulnerabilities in Firefox. Every recent patch Tuesday Nightmare Eclipse has struck. What now? Massive store of valid FortiGate VPN credentials found. F5 issues emergency updates to their NGINX-based server offerings. Introducing "AI Potpourri" -- deeply altering an AI's personality. A close look…
E1099 · 7 Oct 2026 · 3 hr 3 minNew
As AI becomes startlingly capable, top minds at OpenAI admit they can't always control what their own creations do—or even fully understand how they think. This episode dives into the real-world tension between rapid progress and the growing challenge of keeping AI truly aligned. GLM-5.3 can be and has been abliterated. What does that mean? Firefox 157 repairs a large number of high-impact vulnerabilities. A surprising reduction in RSA crypto strength has been discovered. Powerful agentic AI is being used to attack merchants. A new and potent Spectre-style processor attack has been designed.…
E1098 · 30 Sep 2026 · 2 hr 42 min
With millions racing to embrace AI assistants and cybercriminals pivoting to new, high-stakes tactics, the episode tackles the dizzying pace of change and asks: just how worried should we be? The discussion pulls back the curtain on AI's unpredictable power, the escalation of digital extortion, and why the next breach may hit closer to home than you think. Muse has a bad 0-day The regularity of "Irregular" More rogue OpenAI breaches The Seven Deadly Sins (TSDS) hacker group Liquified Natural Gas (LNG) cargo ship hacked The FBI offended ShinyHunters's delicate sensibilities Canonical switches…
E1097 · 23 Sep 2026 · 2 hr 50 min
After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided with real-world chaos. Andrew Ng weighs-in on AI Doomsaying. The wisdom of outsourcing AI security testing. The true risk of an AI-created bioweapon. The EU KIDS Act -- this one is even messier. "Nightmare Eclipse" finally unmasks himself. A whitehat firm used Claude to attack OpenAI. Cisco's own massive 77 CVE update. What was the fallout from Sept's Patch Tuesday Show…
E1096 · 16 Sep 2026 · 2 hr 51 min
Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? The full report on last week's nearly 1,000 Microsoft security fixes. Five months after its start, what's the status of Project Glasswing? Anthropic's rogue agent escape count reaches four incidents. Not to be outdone, OpenAI's count passes 10 and maybe as many as 23! Revisiting California's DROP compulsory data broker data deletion. Russian criminals get their hands on more than 153 million drivers license scans. "Skynet" is the wrong…