Security Now (Audio) Security Now (Audio)

SN 1094: AI Patching Shortcomings - Should You Trust AI-Generated Code?

Sep 2, 2026 · 2h 51m

Summary

Steve Gibson discusses a new research paper showing that AI models are poor at fixing the vulnerabilities they find, often introducing security flaws. He proposes a solution to prompt injection by having the deterministic "dialog manager" monitor the LLM’s internal state to detect role confusion and abort unsafe actions. The episode also covers a critical supply chain discovery where white-labeled Chinese routers were found to contain hidden backdoors phoning home to command-and-control servers. Additionally, Gibson shares a listener’s SSD performance graph demonstrating how Spinrite repair…

Listen ad-free on Castria