Security Now (Audio) Security Now (Audio)

SN 1088: A Nefarious Novel Use for AI - Ransomware Negotiations Go High-Tech

Jul 22, 2026 · 2h 47m

Summary

Steve Gibson and Leo Laporte discuss a critical OpenSSL denial-of-service flaw, the "Legacy Hive" Windows zero-day from hacker Nightmare Eclipse, and July’s record-breaking Patch Tuesday. They examine 1Password’s new integration with Anthropic’s Claude, which allows AI agents to access credentials without exposing secrets, and Bitwarden’s similar efforts. The episode also covers new prompt injection attacks and novel malicious uses of AI by attackers already inside networks.

Topics discussed

Introduction and overview of upcoming topics Microsoft Patch Tuesday and the LegacyHive vulnerability OpenSSL denial-of-service vulnerability and silent patch AI agent security and 1Password's new credential model Sponsors, AI prompt injection attacks, and WordPress vulnerabilities Listener feedback on AI, bureaucracy, and 2FA changes Ransomware groups using AI for data analysis and extortion
Listen ad-free on Castria