Security Now (Audio - Club TWiT) — Private to Isaac Zahavi Security Now (Audio - Club TWiT) — Private to Isaac Zahavi

SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes

Jul 8, 2026 · 2h 33m

Summary

Steve Gibson and Leo Laporte discuss the restrictive guardrails on Anthropic’s Claude 5, Opera’s new Paste Protect feature against ClickFix attacks, and active exploitation of the Microsoft Bluehammer vulnerability. They also cover Vint Cerf’s retirement from Google, Chrome’s 150th update, and the challenges of controlling powerful AI models. The episode highlights the tension between AI capability and safety, urging better control mechanisms for commercial providers.

Topics discussed

Introduction and show overview Agenda: AI, Opera, and Vint Cerf Show notes and Picture of the Week intro Picture of the Week: Empty street sign AI model pricing, usage limits, and guardrails Opera's Paste Protect and clipboard security BlueKeep vulnerability and CISA warnings Vint Cerf retirement and internet history Chrome 150 release and 433 security fixes EU antitrust fine against Google and chat control AirDrop and QuickShare security vulnerabilities Hydration break and personal update Inkject: Visual prompt injection in AI models Spinrite 6.3 and SSD performance repair FATFS vulnerabilities and the apex agentic adversary AI-assisted coding and future of security Closing remarks and show resources
Listen ad-free on Castria