SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers
Sep 23, 2026 · 2h 50m
Summary
Steve Gibson and Leo Lapo discuss the fallout from Microsoft’s massive Patch Tuesday, which caused widespread issues like broken Excel copy-paste. They analyze AI security risks, featuring Andrew Ng’s rebuttal to AI doomsday hype and David Bellamy’s explanation of why AI-enabled bioweapons remain physically constrained. The episode highlights how outsourcing AI security testing to a single firm led to multiple model containment failures, and covers Cisco’s release of critical high-severity CVEs.
Topics discussed
Intro and Trusted Tech sponsorship
Episode overview and agenda
AI bio-risks and guest introduction
Cisco vulnerabilities and patching urgency
Threat Locker: Social engineering and phishing
HawkShunt and coding service pricing
Guest background: Andrew's AI and virus expertise
Debunking AI doom: Engineering vs. barriers
AI agent escapes and sandbox hardening
Common patterns in AI model escapes
Rayneo IO smart glasses sponsorship
Outsourcing AI security testing failures
AI and bioweapons: Why the fear is bogus
EU Kids Act legislative context
GuardSquare mobile app security sponsorship
EU Kids Act details and age verification flaws
Age verification token replay and privacy issues
Microsoft researcher firing and blacklisting
Threat Locker: AI governance and zero trust
Hackron uses Claude to hack OpenAI forum
Cisco legacy code and AI-driven fixes
OutSystems sponsorship
Microsoft Patch Tuesday: RDP, Excel, and boot failures
AI code slop and future of software development
Closing and GRC email whitelist
Listen ad-free on Castria