Security Now (Audio) Security Now (Audio)

SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes

Jul 8, 2026 · 2h 53m

Summary

Steve Gibson and Leo Laporte discuss the strict new safety guardrails on Anthropic’s Claude 5, which hinder security research, and Opera’s new Paste Protect feature against clickfix attacks. They also cover the active exploitation of the Blue Hammer Windows vulnerability, Vint Cerf’s retirement from Google, and the ongoing debate over AI control versus capability.

Topics discussed

Intro and preview of topics Listener picture of the week and sponsor intro Anthropic's Claude 3.5 Sonnet controversy and fallbacks Opera browser introduces Paste Protect feature Bitwarden password manager and digital legacy Microsoft Blue Hammer vulnerability and CISA response Vint Cerf's retirement and legacy of TCP/IP Sponsor: Exbow agentic pen testing Chrome 130 update with 433 security fixes EU fines Google and Apple over antitrust and encryption Vulnerabilities in AirDrop and Quick Share protocols Inkject: Visual prompt injection attacks on VLMs Spinrite 6.1 SSD repair and optimization Sponsor: Adaptive AI security Critical vulnerabilities in FATFS file system library Outro, GRC.com resources, and Club Twit
Listen ad-free on Castria