SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist
Aug 26, 2026 · 2h 48m
Summary
Steve Gibson and Leo Laporte explore the inherent insecurity of LLMs, focusing on "role confusion" as the root cause of prompt injection vulnerabilities. They discuss the controversy surrounding AI model distillation and Anthropic’s new measures to safely deploy its Mythos 5 cybersecurity model. The episode also highlights Bitwarden Secrets Manager as a critical tool for protecting credentials from agentic AI abuse.
Topics discussed
Introduction and episode overview
ThreatLocker security features and AI risks
Humorous interlude and training data discussion
Model distillation and open source ethics
Anthropic's Mythos model and security initiatives
Box AI agents and Bitwarden secrets management
Agentic security challenges and Lauren Kohnfelder intro
Prompt injection as role confusion explained
LLM token stream mechanics and security flaws
How LLMs misinterpret roles and tool outputs
Experiments on role tags and model behavior
Conclusion on AI security and show wrap-up
Listen ad-free on Castria