Security Now (Audio) Security Now (Audio)

SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked

Sep 16, 2026 · 2h 50m

Summary

Security Now 1096 analyzes Microsoft’s record-breaking Patch Tuesday, which fixed nearly 1,000 vulnerabilities using AI, while contrasting this with Anthropic’s Project Glasswing, where only a tiny fraction of AI-discovered bugs were actually fixed. The episode also covers the risks of rapid patch deployment, California’s data broker deletion laws, and a massive Russian data breach. Steve Gibson concludes by arguing that the "Krell" from Forbidden Planet, rather than Skynet, is the more accurate model for the potential self-destructive nature of advanced AI.

Topics discussed

Intro: Microsoft patches, Anthropic Glasswing, and data brokers Sponsor: Trusted Tech Microsoft licensing consultation Catch-up: Vegas meetup and AI excitement AI agent escape counts: Anthropic vs OpenAI The Krell analogy: Are we the Krell? Sponsor: Delete Me for business data removal Listener tip: Hugging Face security contact Microsoft Patch Tuesday: 1,000 fixes and records Critical flaws: DNS, RCE, and enterprise risk Outlook preview pane and NFS/SSTP vulnerabilities NetLogon and Kerberos critical RCEs Zero-days: Link resolution and ALPC flaws Studio update: Lighting, power supplies, and move Sponsor: Bitwarden open source password manager Anthropic Project Glasswing: Ledger analysis and stats AI vulnerability discovery: Microsoft vs Anthropic/OpenAI Sponsor: Material email security and workspace defense OpenAI rogue agents: Wiki hijacking and test escapes Data broker opt-outs: California law and pending status Massive breach: 150M driver's licenses exposed Sponsor: Canary Tools honeypots and network defense AI superintelligence fears and alignment concerns OpenAI Navier-Stokes proof and math controversy Sponsor: ThreatLocker endpoint and AI governance Philosophy: AI intent, Skynet, and the Krell Outro: Show schedule, tools, and Mastodon bots
Listen ad-free on Castria