Security Now (Audio - Club TWiT) — Private to Isaac Zahavi Security Now (Audio - Club TWiT) — Private to Isaac Zahavi

SN 1088: A Nefarious Novel Use for AI - Ransomware Negotiations Go High-Tech

Jul 22, 2026 · 2h 28m

Summary

Steve Gibson and Leo Laporte discuss a critical OpenSSL denial-of-service flaw, the "Legacy Hive" Windows zero-day from hacker Nightmare Eclipse, and 1Password’s new integration allowing AI agents like Claude to access credentials securely. They also cover a severe WordPress core vulnerability and the emerging security challenges of agentic AI.

Topics discussed

Introduction and Picture of the Week: Coffee Menu Nightmare Eclipse and Microsoft Patch Tuesday Analysis OpenSSL Memory Corruption Vulnerability (CVE-2024-5535) 1Password Agentic Mode for AI Credential Security Bitwarden's Approach to Securing AI Agents Indirect Prompt Injection Attacks on AI Agents WordPress WP2Shell Remote Code Execution Vulnerability Listener Feedback: AI Personas and Local LLMs Wiz Security's AI-Powered Cyber Agents Listener Feedback: Bureaucracy, GM Email, and AI Coding AI-Enhanced Ransomware: FulcrumSec and Novo Nordisk Outro, Show Notes, and Sponsor Information
Listen ad-free on Castria