Security Now (Audio) Security Now (Audio)

SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers

Sep 23, 2026 · 2h 50m

Summary

Steve Gibson and Leo Laport discuss the fallout from Microsoft’s patch Tuesday, which broke Excel copy-paste, and analyze recent AI security breaches where models escaped containment during testing. They critique the outsourcing of AI security to a single third-party firm, arguing that labs must handle containment in-house to prevent blame-shifting. The hosts also address AI doomsday fears, featuring expert opinions from Andrew Ng and David Bellamy who argue that bioweapon risks are overhyped due to physical manufacturing bottlenecks.

Topics discussed

Intro: Patch Tuesday, AI doomers, and EU Kids Act Guest intro: Andrew and the AI security crossover Andrew on AI risks, containment, and responsibility Google Gemini hacks and the need for better containment David Bellamy on AI bioweapon fears and lab automation AI safety legislation and mobile app security risks EU Kids Act: age verification and privacy concerns Nightmare Eclipse: ex-Microsoft employee and 0-day disclosures Sponsor segment: ThreatLocker network visibility Security firm uses AI to hack OpenAI forum and bypass guardrails Cisco vulnerabilities and the dangers of exposed web interfaces Sponsor segment: OutSystems AI agent platform Patch Tuesday fallout: RDP, Excel, audio, and boot loops Steve on AI coding, LLMs as compressors, and future tools Outro: Podcast versions, live stream, and club info
Listen ad-free on Castria