Security Now (Audio) Security Now (Audio)

SN 1083: Patch Tuesday à la AI - Arch Linux Repo Under Siege

Jun 17, 2026 · 2h 36m

Summary

Steve Gibson discusses AI-driven vulnerability discovery during June's Patch Tuesday and a massive supply chain attack compromising over 400 Arch Linux packages with info-stealing rootkits. The episode covers NPM’s shift to more secure install defaults and the U.S. government’s directive to suspend access to Anthropic’s advanced Fable and Mythos models due to alleged jailbreak risks. Gibson also shares a personal anecdote about using AI to troubleshoot a complex Linux boot failure, highlighting the technology's growing utility in system administration.

Topics discussed

Intro, AI in Patch Tuesday, and Meter ad Picture of the Week: Claude Opus 4.8 Linux fix NPM/Arch Linux supply chain attack analysis Anthropic Fable 5 ban and jailbreak controversy AI-driven attack acceleration and DeleteMe ad NPM v12 security changes and install scripts PHP security, eval functions, and Adaptive ad Listener feedback on cybersecurity careers and PHP Microsoft Patch Tuesday record and BitLocker flaws Windows Cloud Files RCE and show wrap-up
Listen ad-free on Castria