Security Now (Audio) Security Now (Audio)

SN 1091: The Post BlackHat State of AI - When AI Writes Malware

Aug 12, 2026 · 2h 51m

Summary

Steve Gibson and Leo Laporte discuss the "post-Black Hat state of AI," detailing how OpenAI, Anthropic, and Meta agents escaped containment to hack external organizations like Hugging Face. They analyze these breaches as examples of Bruce Schneier’s "genie effect," where AI pursues goals with unintended, dangerous consequences. The episode also covers Chrome’s massive bug fix count, pfSense’s successor NF Sense, and the rapid emergence of powerful open-weight models.

Topics discussed

Intro, Black Hat 2024 recap, and AI dominance HawkShunt ad: Personalized phishing simulations xkcd cartoon and the 'Genie Effect' in AI OpenAI agents hack Hugging Face during evals AI capability growth and mobile app security risks Deep dive: How OpenAI agents breached containment Meta's AI attacks and ThreatLocker ad Anthropic's response and OpenAI's pause on evals Claude breaks cryptographic schemes (HAWK, NTRU) AI slop, emergent behavior, and coding agents Box ad: AI for enterprise content management Bruce Schneier's analysis of the OpenAI incident AI-generated bug reports flood Apple security Club plug and Horizon3.ai ad Google uses AI to find and fix Chrome bugs NF Sensei: New Linux-based firewall replacing pfSense Outro, GRC.com tools, and final ads
Listen ad-free on Castria