Security Now (Audio) Security Now (Audio)

SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Sep 9, 2026 · 3h 6m

Summary

Steve Gibson and Leo Laport discuss a record-breaking Patch Tuesday with 973 Windows security fixes and the upcoming mandatory enablement of memory integrity for all qualifying Windows 11 systems. The episode covers a legacy Dropbox hack, CISA’s scaling back of critical infrastructure assessments, and the release of OpenAI’s GPT-6 Astra, which achieved a perfect score on exploit benchmarks. Gibson also debunks rumors regarding hidden AI reasoning chains and shares a humorous XKCD comic about Asimov’s laws of robotics.

Topics discussed

Introduction and episode overview Patch Tuesday trends and CISA service cuts Microsoft September patch statistics Discussion on social engineering and AI flaws Sponsor: Doppel security platform Asimov's Three Laws and AI safety ordering Dropbox data breach via Lenovo ID abuse Windows Memory Integrity and hardware changes Sponsor: Hawk Hunt phishing training Firefox bug fixes and Google Gemini models CISA termination of cyber resilience reviews OpenAI Astra model capabilities and safeguards AI efficiency: Tokens per second vs useful work Sponsor: GuardSquare mobile app security Debunking 'opaque recurrence' and chain of thought Chinese state-sponsored AI cyber espionage Sponsor: ThreatLocker application control NVIDIA acquisition of Hugging Face Google Gemini 3.8 Flash pricing and performance Bitdefender report on Silk Parasite AI attacks Matthew Green on AI bug drought and security Law enforcement going dark and encryption debates Privacy rights vs government surveillance needs Predicting the future of AI and security Club TW membership promotion AI efficiency risks and loss of human expertise Discussion on AI-coded software and quality GRC newsletter and show sign-off
Listen ad-free on Castria