Security Now (Audio) Security Now (Audio)

SN 1095: AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

Sep 9, 2026 · 3h 6m

Summary

Steve Gibson and Leo Laporte discuss a record-breaking Patch Tuesday with 973 Windows fixes and the upcoming mandatory enablement of memory integrity. The episode covers a legacy Dropbox hack, CISA’s scaling back of critical infrastructure assessments, and OpenAI’s release of GPT-6 Astra, which achieved a perfect score on exploit benchmarks. Gibson also clarifies misconceptions about AI "hidden chain of thought" and analyzes the security implications of NVIDIA acquiring Hugging Face. The show concludes with a discussion on AI-driven expertise loss, featuring insights from a nuclear reactor …

Topics discussed

Introduction and episode overview Patch Tuesday trends and CISA service cuts Record number of Microsoft security patches Discussion on social engineering threats Sponsor: Doppel social engineering platform Asimov's Three Laws and AI safety ordering Dropbox data breach via Lenovo ID abuse Windows Memory Integrity and performance impact Sponsor: Hawk Hunt phishing simulation Firefox updates and Google Gemini model routing CISA termination of cyber resilience reviews OpenAI Astra model capabilities and safeguards Local vs cloud AI models and supply chain risks Recurrent depth technique and AI safety debate Sponsor: ThreatLocker application control NVIDIA acquisition of Hugging Face Google Gemini 3.8 release and benchmarks Chinese cyber espionage using AI for stealth Matthew Green on AI bug drought and law enforcement UK/EU VPN regulations and legislative pressure Club Twit membership and show support Loss of engineering expertise due to AI automation Show notes, archives, and other Twit.tv shows
Listen ad-free on Castria