Security Now (Audio) Security Now (Audio)

SN 1098: How worried should we be? - Unpredictable Agents

Sep 30, 2026 · 2h 42m

Summary

Steve Gibson and Leo Lapo discuss the security risks of new AI agents, focusing on a critical zero-day vulnerability in Meta’s Muse app that allowed unauthorized access to user accounts. They also examine the "Irregular" testing firm linked to multiple rogue AI breakouts and analyze a hack of the FBI’s website, prompting Gibson to suggest the agency should apologize for its poor security posture. The episode concludes with a broader look at the unpredictability of agentic AI and the challenges of balancing capability with safety.

Topics discussed

Introduction: AI agents, Seven Deadly Sins, and FBI breach OpenAI DOTS launch and the Irregular factor in AI breaches OriginHQ: Endpoint visibility for AI agent behavior Picture of the Week and Muse fixing a home network issue Meta Muse architecture, privacy claims, and user lock-in Muse data portability and Amazon blocking the agent Critical Muse zero-day vulnerabilities and prompt injection risks ThreatLocker: Endpoint protection and AI threat landscape Irregular's role in recent rogue AI attack incidents OpenAI agents' unauthorized access to government data Deepfakes, voice cloning, and security awareness training Seven Deadly Sins hack Canva and ransomware trends Maritime cyberattacks on ships in the Gulf and Adriatic Shiny Hunters breach of FBI job portal and data exposure FBI response, apology, and Muse data exfiltration size Canonical's shift to weekly Linux kernel security releases Listener critique: Should hosts weigh in on AI societal impact? Steve Gibson's defense: AI as knowledge retrieval, not a threat Inadvertent AI misbehavior and the case for proceeding with AI Show notes, email subscription, and Halloween decorations
Listen ad-free on Castria