Security Now (Audio) Security Now (Audio)

SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Aug 26, 2026 · 2h 48m

Summary

Steve Gibson and Leo Laporte discuss a new research paper revealing that LLMs are inherently insecure due to "role confusion," which makes prompt injection attacks nearly impossible to prevent. The episode explores the controversy surrounding AI model distillation, where competitors allegedly train new models using outputs from proprietary frontier models, raising legal and ethical questions. Additionally, they cover Anthropic’s expansion of its powerful Mythos 5 model for cybersecurity defense and Bitwarden’s new Secrets Manager, which addresses the risk of AI agents accidentally exfiltrat…

Topics discussed

Intro: LLMs are inherently insecure Why understanding low-level mechanics matters AI agents and credential abuse risks Picture of the week and listener safety Sponsor: ThreatLocker AI governance controls Model distillation and data sourcing debates Anthropic expands Claude Mythos 5 access Sponsor: Box enterprise AI knowledge tools Sponsor: 1Password secrets for AI agents Sponsor: Hawk Hunt phishing simulations Guest intro: Lauren Kofelder and PKI Lauren's thesis: LLMs are untrustworthy Explaining the 'token soup' architecture Sponsor: GuardSquare mobile app security Research: Role confusion and prompt injection Deep dive: How tags fail to enforce roles Sponsor: Material workspace security Experiments: Proving implicit role assumption History of roles and the single-channel limit Outro: GRC.com and show details
Listen ad-free on Castria