SN 1098: How worried should we be? - Unpredictable Agents
Sep 30, 2026 · 2h 42m
Summary
Steve Gibson and Leo Lapo discuss the security risks of new AI agents, focusing on a critical zero-day vulnerability in Meta’s Muse app that allowed unauthorized access to user accounts. They also examine the "Irregular" testing firm linked to multiple rogue AI breakouts and analyze a hack of the FBI’s website, prompting Gibson to suggest the agency should apologize for its poor security posture. The episode concludes with a broader look at the unpredictability of agentic AI and the challenges of balancing capability with safety.
Topics discussed
Introduction: AI agents, Seven Deadly Sins, and FBI breach
OpenAI DOTS launch and the Irregular factor in AI breaches
OriginHQ: Endpoint visibility for AI agent behavior
Picture of the Week and Muse fixing a home network issue
Meta Muse architecture, privacy claims, and user lock-in
Muse data portability and Amazon blocking the agent
Critical Muse zero-day vulnerabilities and prompt injection risks
ThreatLocker: Endpoint protection and AI threat landscape
Irregular's role in recent rogue AI attack incidents
OpenAI agents' unauthorized access to government data
Deepfakes, voice cloning, and security awareness training
Seven Deadly Sins hack Canva and ransomware trends
Maritime cyberattacks on ships in the Gulf and Adriatic
Shiny Hunters breach of FBI job portal and data exposure
FBI response, apology, and Muse data exfiltration size
Canonical's shift to weekly Linux kernel security releases
Listener critique: Should hosts weigh in on AI societal impact?
Steve Gibson's defense: AI as knowledge retrieval, not a threat
Inadvertent AI misbehavior and the case for proceeding with AI
Show notes, email subscription, and Halloween decorations
Listen ad-free on Castria