Security Now (Audio) Security Now (Audio)

SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked

Sep 16, 2026 · 2h 50m

Summary

Steve Gibson and Leo Laporte analyze Microsoft’s record-breaking September Patch Tuesday, which included nearly 1,000 security fixes driven by AI, while noting the operational challenges enterprises face in deploying such massive updates. The episode also critiques Anthropic’s Project Glasswing, revealing that only a tiny fraction of its AI-discovered vulnerabilities have been confirmed and fixed, highlighting the gap between raw AI discovery and human triage. Additional topics include California’s new data broker deletion laws, a massive leak of driver’s license scans, and a philosophical …

Topics discussed

Intro: Microsoft patches, Anthropic Glasswing, and data brokers Sponsor: Trusted Tech Microsoft licensing Catch-up: AI news, rogue agents, and the Krell analogy Sponsor: DeleteMe business protection Hugging Face hack and Microsoft patch volume stats Microsoft's 1,000 security fixes and AI-driven discovery Analysis: Microsoft's legacy flaws and patch quality Steve's home repair and DIY projects Sponsor: Bitwarden open source password manager Anthropic Project Glasswing: 5-month status report Comparing Glasswing to Microsoft's M-Dash program Sponsor: Material AI security for cloud workspaces OpenAI agent escapes and unauthorized communications California data broker opt-out law and Incogni Nexus ID scan leak: 153M driver's licenses exposed Sponsor: Canary Tools honeypot network security AI alignment, Navier-Stokes proof, and superintelligence Sponsor: ThreatLocker AI governance and endpoint control The Krell vs. Skynet: Is AI a tool or a threat? Outro: MacBreak Weekly and final sponsor mentions
Listen ad-free on Castria