Security Now

SN 1098: How worried should we be? - Unpredictable Agents

Security Now - Tue, 09/29/2026 - 9:55pm

With millions racing to embrace AI assistants and cybercriminals pivoting to new, high-stakes tactics, the episode tackles the dizzying pace of change and asks: just how worried should we be? The discussion pulls back the curtain on AI's unpredictable power, the escalation of digital extortion, and why the next breach may hit closer to home than you think.

  • Muse has a bad 0-day
  • The regularity of "Irregular"
  • More rogue OpenAI breaches
  • The Seven Deadly Sins (TSDS) hacker group
  • Liquified Natural Gas (LNG) cargo ship hacked
  • The FBI offended ShinyHunters's delicate sensibilities
  • Canonical switches to an every–2-weeks release cadence
  • Axios' AI 101: AI Explainer for normal people
  • How worried should we be?

Show Notes - https://www.grc.com/sn/SN-1098-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers

Security Now - Tue, 09/22/2026 - 10:57pm

After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided with real-world chaos.

  • Andrew Ng weighs-in on AI Doomsaying.
  • The wisdom of outsourcing AI security testing.
  • The true risk of an AI-created bioweapon.
  • The EU KIDS Act -- this one is even messier.
  • "Nightmare Eclipse" finally unmasks himself.
  • A whitehat firm used Claude to attack OpenAI.
  • Cisco's own massive 77 CVE update.
  • What was the fallout from Sept's Patch Tuesday

Show Notes - https://www.grc.com/sn/SN-1097-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked

Security Now - Tue, 09/15/2026 - 10:57pm

Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code?

  • The full report on last week's nearly 1,000 Microsoft security fixes.
  • Five months after its start, what's the status of Project Glasswing?
  • Anthropic's rogue agent escape count reaches four incidents.
  • Not to be outdone, OpenAI's count passes 10 and maybe as many as 23!
  • Revisiting California's DROP compulsory data broker data deletion.
  • Russian criminals get their hands on more than 153 million drivers license scans.
  • "Skynet" is the wrong model for the end of the world. The right model is The Krell

Show Notes - https://www.grc.com/sn/SN-1096-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked

Security Now - Tue, 09/15/2026 - 10:57pm

Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code?

  • Worried Anthropic researchers warn that AI 'could kill all humans'
  • Anthropic Researchers Raise Alarm Over A.I. Acceleration, Warning of Threat to Humanity
  • Countering misuse of AI: September 2026 / Anthropic
  • Pluralistic: LLMs are real, AI is fake (12 Sep 2026) – Pluralistic: Daily links from Cory Doctorow
  • New Apple Watches to get Siri AI 'Recaps' feature similar to AI wearables
  • Apple Unveils the iPhone Duo, a Foldable Phone That Costs $1,999
  • Key App Developers Have Yet to Embrace Apple's New Siri A.I.
  • Why this month's Microsoft patch release is a doozy
  • LG TV shown scanning LAN for third-party phones and other devices
  • LG's Response
  • The Flock backlash is coming for retail
  • Automobile Camouflage to Hide from Flock Cameras
  • A Secretive DHS 'Predictive Policing' Unit is Analyzing Americans' Financial Habits and Pulling Them Over
  • Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online
  • Some of Dyson's $500 toothbrushes are breaking
  • iRobot unveils the Roomba Duo
  • Husqvarna gets the first exception to the FCC's foreign robot ban for its mowers.

Show Notes - https://www.grc.com/sn/SN-1096-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Security Now - Tue, 09/08/2026 - 10:14pm

OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines.

  • We start out with a classic old school hack against Dropbox.
  • Next Patch Tuesday will be enabling "Memory Integrity" for many.
  • Firefox moved to 155 and obtained a dumb Smart Window.
  • CISA is terminating 6 most valuable cybersecurity services.
  • OpenAI advanced to topof the heap with GPT-6 Astra.
  • But... is it now hiding some of its thinking from monitoring?
  • Nvidia is acquiring Hugging Face. Who's that good for?
  • Google releases Gemini 3.8 Flash and Cyber. Is it good?
  • Chinese cyberespionage is using AI to become more slippery.
  • Matthew Green proposes a fascinating take on AI bug drought.
  • A lifelong safety engineer contemplates AI-driven loss of expertise.

Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now

SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Security Now - Tue, 09/08/2026 - 10:14pm

OpenAI's latest advances have the rumor mill buzzing about "hidden thoughts" and unsupervisable models, but are AI safety experts panicking over the wrong threat? Get the clear-headed take behind the headlines.

  • We start out with a classic old school hack against Dropbox.
  • Next Patch Tuesday will be enabling "Memory Integrity" for many.
  • Firefox moved to 155 and obtained a dumb Smart Window.
  • CISA is terminating 6 most valuable cybersecurity services.
  • OpenAI advanced to topof the heap with GPT-6 Astra.
  • But... is it now hiding some of its thinking from monitoring?
  • Nvidia is acquiring Hugging Face. Who's that good for?
  • Google releases Gemini 3.8 Flash and Cyber. Is it good?
  • Chinese cyberespionage is using AI to become more slippery.
  • Matthew Green proposes a fascinating take on AI bug drought.
  • A lifelong safety engineer contemplates AI-driven loss of expertise.

Show Notes - https://www.grc.com/sn/SN-1095-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Categories: Security Now