Routers on Trial, AI Found More Bugs - PSW #947
Oct 8, 2026 · 2h 1m
Summary
Paul's Security Weekly episode 947 features Paul, Lee, and Sam discussing why LLMs lack true reasoning, relying instead on prompt expansion and human feedback for accuracy. The hosts debate AI consciousness claims, open-weight model risks, and the necessity of uncensored tools for cybersecurity defenders. Additional topics include a Wired exposé on Israeli spyware vendors, a persistent WordPress malware strain, and various recent vulnerabilities affecting Cisco, Dell, and SonicWall.
Topics discussed
Episode 947 Security News Headlines
Show Intro and FinSec Virtual Summit Promo
InfoSec World Venue and Story Transition
Explaining AI Reasoning Models and Prompt Engineering
Using AI Skills to Improve Writing Style
ThreatLocker Zero Trust Ad Break
AI Model Selection and Content Generation Workflows
Debunking AI Consciousness Hype and FUD
The Future of Handwritten Code vs AI Assistance
Scrutinizing AI-Generated Code and Proof of Concepts
AI Hallucinations and Non-Technical Misuse Risks
Managing AI Context and Token Usage in Plans
AI Guardrails, Censorship, and Legal Risks
US Spyware Kings and Persistent Backdoors
Legacy Windows Worms and Clean Build Environments
AI-Driven Web App and Firmware Vulnerability Scanning
Legal Risks of Security Research and John Kiriakou
Challenges of Patching Network Edge Appliances
Cost and Complexity of Carrier-Grade Network Gear
Cisco NX API RCE Vulnerability and Mitigation
Building Relationships with Network Teams for Patching
Exchange Server Versions and Patch Adoption Challenges
Web Server Market Share: IIS vs Nginx vs Apache
Linux Desktop Use Cases and Photo Management
MFA Configuration and Hardware Token Requirements
SSH Compression Vulnerability and OpenSSH Updates
Linux Package Vulnerability Tracking with Fettle
AI Triage of Vulnerability Reports and ExploitDB
Impact of AI on Bug Bounties and Disclosure
Encouraging Vendors to Use AI for Self-Discovery
Listen ad-free on Castria