Episode 1086 · Security Now (Audio)
SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes
8 Jul 2026 · 2 hr 53 min
Episode 1086 · Security Now (Audio)
8 Jul 2026 · 2 hr 53 min
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are…
Jul 8th 2026
AI-generated, human-reviewed.
Artificial intelligence is rapidly changing the way we identify cybersecurity weaknesses. On Security Now , Steve Gibson highlighted how AI-driven analysis is exposing critical vulnerabilities in widely-used software—sometimes in code bases assumed to be safe for years. This shift has urgent implications for every user and organization relying on embedded devices, open-source libraries, and even the browsers that shape our digital experience.
AI-powered vulnerability hunting allows researchers to automate and scale up the process of finding software bugs. According to Steve Gibson, security teams are using AI assistants to audit legacy code bases, create custom fuzzing tools (which bombard software with random inputs to trigger errors), and validate whether issues are actually exploitable.
One striking example discussed was the recent discovery of seven severe vulnerabilities in the FATFS file system library . FATFS is a C-based implementation of the FAT file system, commonly used in everything from cameras to voting machines and IoT devices. Its widespread use, combined with minimal ongoing maintenance, made it a prime target for automated bug discovery using AI.
On the episode, Gibson emphasized the real-world impact of these findings. Security firm runZero, led by HD Moore (the creator of Metasploit), used AI to re-examine the FATFS code—uncovering vulnerabilities that went undetected during manual audits years ago.
These issues can be triggered simply by inserting a maliciously crafted SD card or USB stick into an embedded device. Since the FATFS code is often included unmodified in firmware and lacks memory protection, a successful attack could grant full control of millions of devices worldwide, from industrial controllers to smart appliances.
Researchers also warned that many vendors modify the library locally, slowing down the patching process. Combined with the lack of a central update channel or active maintainer, these widespread vulnerabilities may remain unpatched for years.
AI-assisted vulnerability discovery isn't just targeting obscure libraries. Mainstream products like Google Chrome are also seeing a spike in the number of security fixes per release. Gibson pointed to Chrome version 150, which included an unprecedented 433 security updates —many of which were serious vulnerabilities found through internal AI-powered code review tools.
Other vendors, including Synology and major operating system providers, appear to be using the same approach, issuing record numbers of patches as AI uncovers risks lying dormant for years. The net effect is an accelerated arms race between defenders and attackers—both empowered by powerful, accessible AI tools.
With AI lowering the barrier to discovering new bugs, organizations must update their devices and systems more frequently than ever . Relying on long-untouched firmware or unpatched third-party libraries is now riskier than ever, especially in internet-connected or physically accessible devices.
Gibson stressed the asymmetry in security: while defenders must patch every flaw, an attacker only needs one overlooked vulnerability to succeed. This urgency is multiplied in a world where AI can identify numerous issues in minutes rather than months.
AI-driven vulnerability discovery marks a seismic shift in cybersecurity. As highlighted on Security Now , the speed and scale at which software flaws are found is changing expectations for maintenance, patching, and overall digital safety. Whether you're a device manufacturer, IT administrator, or average user, the message is clear: stay vigilant, keep your systems updated, and recognize that every component—no matter how obscure—may now be re-examined and exploited at lightning speed.
Stay protected by staying informed—follow Security Now for more essential updates in cybersecurity.
Subscribe to Security Now : https://twit.tv/shows/security-now/episodes/1086
Transcript supplied by the publisher with the episode.
by TWiT · English · Tech & Science
Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every…
E1089 · 29 Jul 2026 · 3 hr 8 min
What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking. OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face. We hear from OpenAI, Hugging Face and Andrew Ng. GRC went off the air Friday. Was GRC hacked? What happened? The Linux kernel project repairs 442 CVEs in a single batch. LG's PC monitors cause PC adware installation. France bans all social media access below age 15. WordPress' recent CRITICAL…
E1088 · 22 Jul 2026 · 2 hr 47 min
Cybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't happen this month. Revisiting and inspecting July's Patch Tuesday. A widespread and worrisome flaw in OpenSSL. Claude can now access your 1Password credentials. Bitwarden is aware that we need whole new security. The day ends in "y" so a new prompt injection attack. A true (and rare) core Wordpress emergency update.…
E1087 · 15 Jul 2026 · 2 hr 49 min
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe warns their largest banks to prepare for AI attack. The EU launches an action plan for AI Cybersecurity. China considers keeping its budget AI to itself. The UK's NCSC & GCHQ announce their "Cyber Shield". CISA is using Mythos to audit U.S. government code. Microsoft warns of their upcoming patch flood. "RoguePlanet"…
E1085 · 1 Jul 2026 · 2 hr 50 min
AI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down. Win10's popularity forces another year of free updates. CISA directs all federal agencies to update their UniFi OS devices. CISA gave federal agencies "the weekend" to update Cisco devices. Australia is disturbed by a deeply compromised infrastructure provider. OpenAI introduces Daybreak-powered "Patch the Planet" initiative. Meta's…
E1084 · 24 Jun 2026 · 2 hr 48 min
A flood of everyday gadgets, from cheap streaming boxes to digital photo frames, are being secretly conscripted into global proxy networks and used to mask major cyberattacks—possibly even targeting your own home network. Worries of AI-power cyberattacks are spreading. Mythos "missed some" important vulnerabilities in Firefox. Every recent patch Tuesday Nightmare Eclipse has struck. What now? Massive store of valid FortiGate VPN credentials found. F5 issues emergency updates to their NGINX-based server offerings. Introducing "AI Potpourri" -- deeply altering an AI's personality. A close look…
E1083 · 17 Jun 2026 · 2 hr 36 min
This episode unpacks the jaw-dropping surge in vulnerabilities unearthed by AI, revealing how Microsoft shattered its own patch records while adversaries and defenders race to outpace each other. The conversation gets real about whether AI is fixing our broken software or just making attacks easier for everyone. Rootkits found in more than 400 ArchLinux User Repository packages. The US government requests Anthropic to remove Mythos and Fable. CISA responds to AI-driven attacks with new patching requirements. NPM to switch to more secure install defaults. Will it help. Our listeners react to…
E1099 · 7 Oct 2026 · 3 hr 3 min
As AI becomes startlingly capable, top minds at OpenAI admit they can't always control what their own creations do—or even fully understand how they think. This episode dives into the real-world tension between rapid progress and the growing challenge of keeping AI truly aligned. GLM-5.3 can be and has been abliterated. What does that mean? Firefox 157 repairs a large number of high-impact vulnerabilities. A surprising reduction in RSA crypto strength has been discovered. Powerful agentic AI is being used to attack merchants. A new and potent Spectre-style processor attack has been designed.…
E1098 · 30 Sep 2026 · 2 hr 42 min
With millions racing to embrace AI assistants and cybercriminals pivoting to new, high-stakes tactics, the episode tackles the dizzying pace of change and asks: just how worried should we be? The discussion pulls back the curtain on AI's unpredictable power, the escalation of digital extortion, and why the next breach may hit closer to home than you think. Muse has a bad 0-day The regularity of "Irregular" More rogue OpenAI breaches The Seven Deadly Sins (TSDS) hacker group Liquified Natural Gas (LNG) cargo ship hacked The FBI offended ShinyHunters's delicate sensibilities Canonical switches…
E1097 · 23 Sep 2026 · 2 hr 50 min
After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided with real-world chaos. Andrew Ng weighs-in on AI Doomsaying. The wisdom of outsourcing AI security testing. The true risk of an AI-created bioweapon. The EU KIDS Act -- this one is even messier. "Nightmare Eclipse" finally unmasks himself. A whitehat firm used Claude to attack OpenAI. Cisco's own massive 77 CVE update. What was the fallout from Sept's Patch Tuesday Show…
E1096 · 16 Sep 2026 · 2 hr 51 min
Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? The full report on last week's nearly 1,000 Microsoft security fixes. Five months after its start, what's the status of Project Glasswing? Anthropic's rogue agent escape count reaches four incidents. Not to be outdone, OpenAI's count passes 10 and maybe as many as 23! Revisiting California's DROP compulsory data broker data deletion. Russian criminals get their hands on more than 153 million drivers license scans. "Skynet" is the wrong…