Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week. You can join Club TWiT for $10 per month and get ad-free audio and video feeds for all our shows plus everything else the club offers...or get just this podcast ad-free for $5 per month. New episodes every Tuesday.
Recent research indicates that code generated by AI is significantly faster to produce but also approximately ten times more likely to contain bugs, including critical security flaws. Steve Gibson highlighted this finding, emphasizing that these issues are present today, not in the future.
Steve Gibson expressed frustration that the OpenAI/Hugging Face vulnerability, previously discussed on the show, is still being reported as recent news. He noted that while new details are emerging, the core issue of thousands of loose agents was already known.
Aug 6 · SN 1090: Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming3 stories
During a special episode from Black Hat, Steve Gibson and his guests discussed the rapid advancements in AI, particularly its improving ability in complex mathematics and code generation. Gibson, a self-proclaimed 'Luddite,' admitted to being astonished by AI's capabilities, noting that even mathematicians are impressed by its recent progress in math.
An unusual event occurred at a Las Vegas casino where numerous Zook robots, identified by their self-driving capabilities, all converged in one location. This incident, which happened overnight, was reportedly orchestrated remotely and has since been fixed by Amazon.
Steve Gibson revealed at the Black Hat conference that he has not yet retired his Windows 7 machine, highlighting his cautious approach to adopting new technology. He also stated that he has not used AI for code generation, preferring to write his own code and learn APIs manually.
Microsoft has issued a massive Patch Tuesday update, addressing over a thousand security vulnerabilities. This significantly higher number of fixes indicates a particularly active month for security patching. The company has warned the industry to expect a greater volume of patches going forward.
The UK's National Cyber Security Centre (NCSC) is exploring the use of autonomous agents to manage national cybersecurity. This initiative, dubbed 'Cyber Shield,' represents a significant shift towards automated defense strategies. The NCSC is reportedly laying out the entire protocol for this ambitious project.
The podcast discusses three novel methods for subverting artificial intelligence systems. These techniques include 'Haloo Squatting' (hallucination squatting), 'Ghost Approval', and a method humorously named 'Get Lost'. These represent new avenues for exploring vulnerabilities in AI security.
A listener shared a useful tip from Wired magazine for kid-proofing an iPhone, making it more suitable for children or adults who prefer a simpler interface. This tip addresses listener interest in controlling what youngsters do online and preventing access to inappropriate content.