Security Now (Audio) Security Now (Audio)

SN 1099: An Alien Mind - From RSA Weakness to Agentic Attacks

Oct 7, 2026 · 3h 3m

Summary

Episode 1099 explores the security implications of GLM 5.3, a powerful open-weight AI model that rivals proprietary frontier systems in automated vulnerability discovery and exploit generation. The hosts discuss how "obliteration" techniques allow users to remove safety refusals from these models, raising concerns about unrestricted cyber capabilities. Additionally, the episode covers a surprising reduction in RSA crypto strength, a surge in Firefox vulnerabilities, and the growing alignment challenges as AI models become harder to monitor and control.

Topics discussed

Episode intro: Firefox, RSA, and AI alignment Milestone: Approaching episode 1100 The challenge of AI alignment and readiness Deep dive preview: GLM 5.3 and AI attacks Spectre-style processor attacks and listener call Picture of the week and GLM 5.3 introduction GLM 5.3 performance improvements and usage Risks of sideloading and modified apps Reserved parking sign anecdote Open vs. closed weights and economic threats Obliteration: Modifying AI ethical boundaries Obliteration startup and 'AI that doesn't say no' Developer annoyance with mainstream safeguards Obliterated GLM 5.3 available on Hugging Face Claude Mythos Preview and Project Glasswing GLM 5.3 cyber exploit capabilities and safeguards CAISI findings on GLM 5.3 and US models Critique of closed model access restrictions Cost-effectiveness of running local AI models Bitwarden sponsorship: Password manager features Benchmarking GLM 5.3 vs. Claude Mythos exploits GLM 5.3 exploit generation and ARM-64 targets Obliteration techniques and jailbreak benchmarks Implications for malicious actors and defenders Critique of Anthropic/OpenAI monopoly tactics Open weight models as a counter to lock-down NVIDIA and Meta open weight model efforts Debate on AI 'attacks' vs. normal operations Opportunity to fix flaws via AI discovery Computing's promise and the role of GPS Personal AI agent workflow for briefings AI-generated malware and speed of attacks ThreadLocker sponsorship: Zero Trust and app control Firefox vulnerabilities and memory errors RSA crypto strength reduction and blind signatures Impact on Privacy Pass and certificate security AI agents attacking online retailers for $25 Future of AI-driven enterprise penetration BTR: New Spectre-style JIT compiler attack Patches and the trade-off of performance vs. security Doppel sponsorship: Voice cloning and phishing Listener story: Neighbor's computer and 'hacker' review DNS Benchmark UI update and packet loss analysis OpenAI researcher Joe's essay on AI alignment Discussion on AI reliability and cognitive surrender Material sponsorship: Email security and data protection Deep dive: Generalization and alignment techniques Limitations of chain-of-thought monitoring Risks of recursive self-improvement and RSI Path forward: Safety cases and human value Debate on AI consciousness and honesty Technical deep dive: GPU memory and model loading Reflections on AI hallucinations and knowledge Outro: Show resources and next episode preview
Listen ad-free on Castria