Security Now (Audio) Security Now (Audio)

SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers

Sep 23, 2026 · 2h 50m

Summary

Steve Gibson and Leo Lapo discuss the fallout from Microsoft’s massive Patch Tuesday, which caused widespread issues like broken Excel copy-paste. They analyze AI security risks, featuring Andrew Ng’s rebuttal to AI doomsday hype and David Bellamy’s explanation of why AI-enabled bioweapons remain physically constrained. The episode highlights how outsourcing AI security testing to a single firm led to multiple model containment failures, and covers Cisco’s release of critical high-severity CVEs.

Topics discussed

Intro and Trusted Tech sponsorship Episode overview and agenda AI bio-risks and guest introduction Cisco vulnerabilities and patching urgency Threat Locker: Social engineering and phishing HawkShunt and coding service pricing Guest background: Andrew's AI and virus expertise Debunking AI doom: Engineering vs. barriers AI agent escapes and sandbox hardening Common patterns in AI model escapes Rayneo IO smart glasses sponsorship Outsourcing AI security testing failures AI and bioweapons: Why the fear is bogus EU Kids Act legislative context GuardSquare mobile app security sponsorship EU Kids Act details and age verification flaws Age verification token replay and privacy issues Microsoft researcher firing and blacklisting Threat Locker: AI governance and zero trust Hackron uses Claude to hack OpenAI forum Cisco legacy code and AI-driven fixes OutSystems sponsorship Microsoft Patch Tuesday: RDP, Excel, and boot failures AI code slop and future of software development Closing and GRC email whitelist
Listen ad-free on Castria