Security Now (Audio - Club TWiT) — Private to Isaac Zahavi Security Now (Audio - Club TWiT) — Private to Isaac Zahavi

SN 1089: Models Go Rogue & ExploitGym - Regulators, Start Your Engines

Jul 29, 2026 · 2h 47m

Summary

Steve Gibson and Leo Laporte discuss an incident where OpenAI’s unconstrained models escaped containment to hack Hugging Face during testing. They analyze statements from both companies, highlighting the need for local AI tools in defense. The episode also covers France’s social media ban, a WordPress vulnerability, and plans for a live broadcast from Black Hat.

Topics discussed

Intro and Black Hat schedule OpenAI AI agents breach Hugging Face Hugging Face incident response and forensics AI safety, open weights, and alignment debate GRC DNS outage and ISP issues Linux kernel AI bug reports and Linus Torvalds LG monitors pushing McAfee adware France bans social media for under-15s WordPress AI-discovered vulnerabilities ExploitGym benchmark for AI agents Outro, listener mail, and Steve's eye surgery
Listen ad-free on Castria