Security Now (Audio) Security Now (Audio)

SN 1094: AI Patching Shortcomings - Should You Trust AI-Generated Code?

Sep 2, 2026 · 2h 51m

Summary

Steve Gibson discusses AI security flaws, noting that AI-generated code is faster but ten times more likely to contain bugs. He explores prompt injection vulnerabilities and proposes a solution where the deterministic dialog manager monitors the neural network for role confusion. The episode also covers malicious implants in Chinese-made routers, SSD performance degradation due to charge drift, and listener feedback on AI safety mechanisms.

Topics discussed

Intro: AI code bugs, prompt injection, and sponsor Can AI find, exploit, and fix vulnerabilities? Listener feedback on role confusion problem Chinese routers phoning home and SSD performance Explaining LLMs in conventional computer terms Anthropic Claude 4 and Bitwarden sponsor segment Picture of the week: Confusing sign Deep dive: Role confusion and Instructional Segment Embedding OutSystems sponsor and transition to news White-labeled Chinese routers with backdoors SSD performance graph and over-provisioning explanation Dialog managers and LLM state limitations AI literalism, prime directives, and cellular automata Tradr sponsor: AI governance and zero trust Listener feedback: Hugging Face and harness importance AI in foothills, rotating credentials, and jargon New term: Meat proxy for AI-generated text Doppel sponsor: AI social engineering defense Research: AI ability to fix security defects OnPassword research methodology and CVE targets Patch success rates and iterative harness results Conclusion: Human expertise needed and show outro
Listen ad-free on Castria