Episode 1099 · Security Now (Audio)
SN 1099: An Alien Mind - From RSA Weakness to Agentic Attacks
7 Oct 2026 · 3 hr 3 min
Episode 1099 · Security Now (Audio)
7 Oct 2026 · 3 hr 3 min
As AI becomes startlingly capable, top minds at OpenAI admit they can't always control what their own creations do—or even fully understand how they think. This episode dives into the real-world tension between rapid progress and the growing challenge of keeping AI truly aligned. GLM-5.3 can be and has been abliterated. What does that mean? Firefox 157 repairs a large number of high-impact vulnerabilities. A surprising reduction in RSA crypto strength has been discovered. Powerful agentic AI is being used to attack merchants. A new and potent Spectre-style processor attack has been designed.…
by TWiT · English · Tech & Science
Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every…
E1098 · 30 Sep 2026 · 2 hr 42 min
With millions racing to embrace AI assistants and cybercriminals pivoting to new, high-stakes tactics, the episode tackles the dizzying pace of change and asks: just how worried should we be? The discussion pulls back the curtain on AI's unpredictable power, the escalation of digital extortion, and why the next breach may hit closer to home than you think. Muse has a bad 0-day The regularity of "Irregular" More rogue OpenAI breaches The Seven Deadly Sins (TSDS) hacker group Liquified Natural Gas (LNG) cargo ship hacked The FBI offended ShinyHunters's delicate sensibilities Canonical switches…
E1097 · 23 Sep 2026 · 2 hr 50 min
After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided with real-world chaos. Andrew Ng weighs-in on AI Doomsaying. The wisdom of outsourcing AI security testing. The true risk of an AI-created bioweapon. The EU KIDS Act -- this one is even messier. "Nightmare Eclipse" finally unmasks himself. A whitehat firm used Claude to attack OpenAI. Cisco's own massive 77 CVE update. What was the fallout from Sept's Patch Tuesday Show…
E1096 · 16 Sep 2026 · 2 hr 51 min
Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? The full report on last week's nearly 1,000 Microsoft security fixes. Five months after its start, what's the status of Project Glasswing? Anthropic's rogue agent escape count reaches four incidents. Not to be outdone, OpenAI's count passes 10 and maybe as many as 23! Revisiting California's DROP compulsory data broker data deletion. Russian criminals get their hands on more than 153 million drivers license scans. "Skynet" is the wrong…
E1095 · 9 Sep 2026 · 3 hr 6 min
OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines. We start out with a classic old school hack against Dropbox. Next Patch Tuesday will be enabling "Memory Integrity" for many. Firefox moved to 155 and obtained a dumb Smart Window. CISA is terminating 6 most valuable cybersecurity services. OpenAI advanced to topof the heap with GPT-6 Astra. But... is it now hiding some of its thinking from monitoring? Nvidia is acquiring Hugging…
E1094 · 2 Sep 2026 · 2 hr 52 min
AI-generated code is flooding the industry, but researchers reveal that almost half of it contains critical vulnerabilities. This week, we unpack what happens when the race for automation outpaces security best practices. A possible means for preventing prompt injection abuse. Clear evidence of Chinese-made router malicious intent. A cool before and after SpinRite graph of SSD performance. How about adding unpredictable hashes to role tags? What did Claude make of last week's podcast? Could much better harnesses prevent prompt injection? A listener wants us to stop saying AI "thinks". AI…
E1093 · 26 Aug 2026 · 2 hr 48 min
Turns out, every chatbot conversation runs on a messy hack at the heart of language models, making prompt injection an unsolved—and possibly unsolvable—security threat. Steve and Leo unravel the research that explains why "roles" in AI aren't what you think they are. Understanding the controversy surrounding "AI Model Distillation" Anthropic moves to make their most powerful Mythos 5 model more widely available. Bitwarden's "Secrets Manager" offering prevents agentic and prompt injection abuse. The astounding and disturbing truth about the way conversation AI actually works Show Notes -…
E1092 · 19 Aug 2026 · 2 hr 49 min
From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI proxy might bite you. France's under-15 social media ban hits its constitution. A bit of AI prompting found a serious bug in Zoom. AI-based network defenders see a stock price jump. A (very) deep dive into the operation of AI chatbots Show Notes - https://www.grc.com/sn/SN-1092-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at…
E1091 · 12 Aug 2026 · 2 hr 51 min
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber offense and defense. Anthropic's agentic AI also broke free and hacked others. We know much (much!) more about the OpenAI breakout. OpenAI posts that they're pausing "Astra" - even internally. What was that about AI recently cracking (or denting) cryptography. Bruce Schneier brilliantly equates AI agents to capricious genies. Apple doesn't react so well to the new deluge of…
E1090 · 6 Aug 2026 · 2 hr 5 min
At Black Hat Las Vegas, the Security Now crew digs into how AI is not just finding hidden software bugs but also fueling both groundbreaking innovation and alarming new exploits. When open models can launch surprise Bitcoin heists, who draws the line between forbidden knowledge and genuine progress? • Black Hat and DEF CON: Hacking Stories and Conference Culture • Zoox Ride-Hailing Hack and Over-the-Air Vulnerabilities • Autonomous Vehicles, AI, and the Security Implications • Hosts Share Personal Adoption and Use of AI Tools • AI-Powered Coding: From Hobbyists to Advanced Agency Chains •…
E1089 · 29 Jul 2026 · 3 hr 8 min
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL…