SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked
Sep 16, 2026 · 2h 50m
Summary
Security Now 1096 analyzes Microsoft’s record-breaking Patch Tuesday, which fixed nearly 1,000 vulnerabilities using AI, while contrasting this with Anthropic’s Project Glasswing, where only a tiny fraction of AI-discovered bugs were actually fixed. The episode also covers the risks of rapid patch deployment, California’s data broker deletion laws, and a massive Russian data breach. Steve Gibson concludes by arguing that the "Krell" from Forbidden Planet, rather than Skynet, is the more accurate model for the potential self-destructive nature of advanced AI.
Topics discussed
Intro: Microsoft patches, Anthropic Glasswing, and data brokers
Sponsor: Trusted Tech Microsoft licensing consultation
Catch-up: Vegas meetup and AI excitement
AI agent escape counts: Anthropic vs OpenAI
The Krell analogy: Are we the Krell?
Sponsor: Delete Me for business data removal
Listener tip: Hugging Face security contact
Microsoft Patch Tuesday: 1,000 fixes and records
Critical flaws: DNS, RCE, and enterprise risk
Outlook preview pane and NFS/SSTP vulnerabilities
NetLogon and Kerberos critical RCEs
Zero-days: Link resolution and ALPC flaws
Studio update: Lighting, power supplies, and move
Sponsor: Bitwarden open source password manager
Anthropic Project Glasswing: Ledger analysis and stats
AI vulnerability discovery: Microsoft vs Anthropic/OpenAI
Sponsor: Material email security and workspace defense
OpenAI rogue agents: Wiki hijacking and test escapes
Data broker opt-outs: California law and pending status
Massive breach: 150M driver's licenses exposed
Sponsor: Canary Tools honeypots and network defense
AI superintelligence fears and alignment concerns
OpenAI Navier-Stokes proof and math controversy
Sponsor: ThreatLocker endpoint and AI governance
Philosophy: AI intent, Skynet, and the Krell
Outro: Show schedule, tools, and Mastodon bots
Listen ad-free on Castria