SN 1088: A Nefarious Novel Use for AI - Ransomware Negotiations Go High-Tech
Jul 22, 2026 · 2h 28m
Summary
Steve Gibson and Leo Laporte discuss a critical OpenSSL denial-of-service flaw, the "Legacy Hive" Windows zero-day from hacker Nightmare Eclipse, and 1Password’s new integration allowing AI agents like Claude to access credentials securely. They also cover a severe WordPress core vulnerability and the emerging security challenges of agentic AI.
Topics discussed
Introduction and Picture of the Week: Coffee Menu
Nightmare Eclipse and Microsoft Patch Tuesday Analysis
OpenSSL Memory Corruption Vulnerability (CVE-2024-5535)
1Password Agentic Mode for AI Credential Security
Bitwarden's Approach to Securing AI Agents
Indirect Prompt Injection Attacks on AI Agents
WordPress WP2Shell Remote Code Execution Vulnerability
Listener Feedback: AI Personas and Local LLMs
Wiz Security's AI-Powered Cyber Agents
Listener Feedback: Bureaucracy, GM Email, and AI Coding
AI-Enhanced Ransomware: FulcrumSec and Novo Nordisk
Outro, Show Notes, and Sponsor Information
Listen ad-free on Castria