Security Now (Audio) Security Now (Audio)

SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

Aug 26, 2026 · 2h 48m

Summary

Steve Gibson and Leo Laport explore the mechanics of AI token streams, explaining how "role confusion" fundamentally causes prompt injection vulnerabilities. They discuss the controversy surrounding AI model distillation, where competitors train new models using outputs from mature systems, and analyze Anthropic’s strategy to safely deploy its powerful Mythos 5 cybersecurity model through restricted backend integrations. The episode also features Bitwarden, highlighting how their Secrets Manager protects credentials from agentic AI tools that might otherwise exfiltrate sensitive data via pr…

Topics discussed

Introduction and episode preview Discussion on role confusion and podcast context Episode title and proxy agent credentials Warning on multitasking and focus AI-driven malware and ThreatLocker security ThreatLocker awards and escalator joke LLM training data and post-training labor Model distillation and data contamination Web financing models and information freedom Anthropic's Claude Mythos 5 security expansion Sponsor segment: Box enterprise AI 1Password secrets management for AI agents Hawk Hunt phishing simulation tools Introduction of Lauren Cohnfelder and PKI LLM threat model and token stream analysis Mechanics of LLM context and token prediction Break and GuardSquare mobile security sponsor Role confusion and prompt injection mechanics Tag parsing failures and attack success rates Material security sponsor segment Research experiments on role perception Evolution of roles and inherent LLM limits Conclusion, GRC.com resources, and credits
Listen ad-free on Castria