Security Now (Audio) Security Now (Audio)

SN 1094: AI Patching Shortcomings - Should You Trust AI-Generated Code?

Sep 2, 2026 · 2h 51m

Summary

Steve Gibson discusses a new research paper showing AI models are significantly worse at fixing vulnerabilities than finding them, while exploring a potential solution to prompt injection by having the dialog manager monitor the LLM's internal state in real-time. The episode also covers a critical security discovery of "Endless Doors," a backdoor implant found in white-labeled Chinese routers sold under various brands, and shares a listener's Spinrite graph demonstrating how rewriting data restores SSD performance.

Listen ad-free on Castria