Transcripts

Security Now 1089 transcript

Please be advised that this transcript is AI-generated and may not be word-for-word. Time codes refer to the approximate times in the ad-free version of the show.

 

Leo Laporte [00:00:00]:
It's time for Security Now. Steve Gibson is here. Big show, big show. We're gonna talk about that wild story of the OpenAI model that escaped containment and hacked Hugging Face. France bans social media access for kids under 15. WordPress has a critical vulnerability. And was GRC hacked? That and more coming up. Security Now is next.

Steve Gibson [00:00:28]:
Podcasts you love.

Leo Laporte [00:00:29]:
From people you trust. This is TWiT. This is Security Now with Steve Gibson, episode 1089, recorded Tuesday, July 28th, 2026. Models go rogue and exploit Jim. It's time for Security Now. Yes, the day, the show we wait all week for. Tuesday's here. And when Tuesday's here, so is Steve Gibson.

Leo Laporte [00:00:59]:
The main man at Security Now, hi, Steve.

Steve Gibson [00:01:02]:
Do you know that I at least wait all week for this because, well, you work all week for this. Was until the next time it happens. Yeah.

Leo Laporte [00:01:11]:
Do you imagine at the end of Security Now, do you breathe a sigh of relief and, well, that's over for another few days?

Steve Gibson [00:01:16]:
Yes, because it's the longest interval before the next one that I, you know, so it's like, okay, that's, that's behind me. So now I get to do work. until I have to get ready for the next one. Although this, this last episode of July for July 28th is a little different because next week I will not be mailing show notes for, uh, 1090 because you and I are going to be doing a different Security Now from the ThreatLocker booth, uh, during the Black Hat, uh, event on Wednesday. My plan is I ran across something regarding AI that, that's been— that stuck with me. So I'm planning to still do, uh, emailing to our subscribers, um, about something I think is really interesting about a— this notion of AI alignment that is beginning to surface, which suggests a way of control, of, of getting AI not to misbehave by, by removing the knowledge that we don't want it to have, which is really interesting because, you know, how do you— how in 2.8 trillion parameters, like, the knowledge is— it's, it's like holographically stored, right? It's like all the knowledge is everywhere. And it turns out there's a way of causing a way of getting the knowledge to group into like a region, and then you excise it kind of like a little tumor. Anyway, uh, I'm gonna—

Leo Laporte [00:02:57]:
Interesting.

Steve Gibson [00:02:57]:
I'll be, I'll be doing an emailing on the weekend. But then, uh, oh, and I also wanted to tell our listeners, I think I mentioned at the end, end of the show, but I'll say it right now in case people don't listen all the way through, uh, you and I are gonna be basically be having a conversation using talking points from the Security Now mailbag feedback.

Leo Laporte [00:03:19]:
Nice.

Steve Gibson [00:03:20]:
Um, as we're sitting in the booth.

Leo Laporte [00:03:22]:
So I wanted to do those feedback episodes.

Steve Gibson [00:03:24]:
This will be a feedback episode, essentially. Yeah. But, but, um, uh, so you and I will just take— I'm actually, because it's Black Hat, I'm going to print them on paper rather than, than, you know, have any electronic device which is on, uh, I could turn off all the radios, I realize. But anyway, why not have paper? And so you and I will just be using—

Leo Laporte [00:03:48]:
This will be interesting.

Steve Gibson [00:03:50]:
Thoughts from our listeners. So I wanted to solicit any talking points during the next week from our listeners who would like to hear some point addressed. That's sort of generally what I have anyway. And then it's like, it's not like I don't have plenty to work from, but I thought, okay, that'd be fun just to say that's what's going to happen. So—

Leo Laporte [00:04:09]:
We should mention you're going to Black Hat. Come by the ThreatLocker booth, but it isn't going to be audience seating kind of a thing like we did at ThreatLocker. It's just a booth. And I don't— I honestly don't know what the layout is. I don't know if there's rooms people stand in.

Steve Gibson [00:04:24]:
Do we know what time of day? Because that would be important.

Leo Laporte [00:04:27]:
Like when to come by. That's a good question. Here's the plan. So we're moving this show from Tuesday to a Wednesday. So that's the first thing is the Security Now will be the day after. Which is, what is that, August 4th or 5th? 5th, I guess.

Steve Gibson [00:04:42]:
And is it going to be alongside Windows Weekly, which is normally on Wednesday?

Leo Laporte [00:04:45]:
Yes.

Steve Gibson [00:04:46]:
Because Paul and Richard are both going to be there too.

Leo Laporte [00:04:48]:
Yes. But we're going to start Windows Weekly earlier. So as soon as we can get onto the show floor, which I think is 9 or 10 AM, we're going to start. I think we want to start Windows Weekly around then and get it over with by noon so that I can have a break, little lunch. So I think we're going to shoot for what is nominally our normal time, which is 1:30 Pacific. But again—

Steve Gibson [00:05:13]:
On Wednesday.

Leo Laporte [00:05:14]:
On Wednesday. That's the only difference, the next day. And so if you're in the area, come by the ThreatLocker booth anytime on Wednesday before, say, the close of show. We're going to try— we'll probably end up using the whole time that the show's there. There may be a break. The good news about a break is that will be the opportunity for you to say hi to me and Steve because And Paul and Richard, all whom will be there, because again, we'll be doing shows. There's not going to be a PA system. There's not going to be seating.

Leo Laporte [00:05:45]:
So you can come and kind of gawk. But if you want to say hi, it's going to have to be in between shows.

Steve Gibson [00:05:53]:
If there's enough seating for the 4 of us, I wouldn't mind if Richard and Paul joined in to our—

Leo Laporte [00:05:58]:
I will tell them that. That's a great thing. Would you like that? Wouldn't that be fun to do a Security Now with a roundtable? Because God knows Windows has been, a big issue security-wise.

Steve Gibson [00:06:11]:
And so will it be streamed and/or recorded?

Leo Laporte [00:06:15]:
It will be streamed and recorded. But that is God willing and the cricks don't rise because we don't know what kind of bandwidth we're going to have.

Steve Gibson [00:06:25]:
Well, we're going to have Anthony running around making it all happen.

Leo Laporte [00:06:27]:
Anthony's going to be going, I don't know. We have an Ethernet drop, but is it shared? Is it? Probably. So I don't, we don't know. And we won't know until we get there. That's always the fun of doing these things is you just don't know.

Steve Gibson [00:06:41]:
And at Black Hat, you never know what's going to happen.

Leo Laporte [00:06:44]:
You really don't know. We might get live hacked on the air, which would be so cool. Actually, speaking of hacks, the big story of the week, and I've been waiting all week to hear what you have to say about this, is the Hugging Face hack. You're going to cover that, I'm sure.

Steve Gibson [00:06:59]:
Yep. So we have 2 topics. Uh, uh, Models Go Rogue is how I described the first, and Exploit Gym is an interesting project that had 16 different, uh, uh, industry and industry-adjacent participants. Uh, it lives over on GitHub, and it's what OpenAI confronted their 2 models with that induced them to break out and go rogue.

Leo Laporte [00:07:32]:
What a story.

Steve Gibson [00:07:34]:
It turns out there's enough information to, to, to, to do that. So we're going to talk about— so this is Security Now, episode 1089, uh, for July 28th. Uh, we're going to talk about how OpenAI deliberately unconstrained because they needed to do testing AI got loose and attacked somebody else, Hugging Face. So to that end, we're going to hear from OpenAI, from their perspective, Hugging Face's perspective, and Andrew Ng's perspective. All, of course, different. And we'll talk about that. Also, GRC went off the air on Friday.

Leo Laporte [00:08:15]:
Yes, we got a lot of people saying, hey, GRC's down, GRC's down while we're doing the air.

Steve Gibson [00:08:19]:
What happened? It's an interesting story that I'll share. The Linux kernel project repaired 442 CVEs in a single batch. And Linus is of mixed feelings about AI. The most emailed of all events is LG's PC monitors causing PC malware to be installed. France bans social media access below age 15. We've been talking about age gating a lot, so we'll touch on that. WordPress's critical vulnerability that we first talked about last week is claiming victims. Also, I can't remember how, but I'll get to it, stumbled upon Andy Weir, of course, our favorite author of The Martian and now Project Hail Mary, did a podcast with— Oh my God, I can't believe I'm blanking.

Steve Gibson [00:09:21]:
Tyson?

Leo Laporte [00:09:22]:
Anyway, was it—

Steve Gibson [00:09:23]:
yes, yes, yes, yes, yes, of course.

Leo Laporte [00:09:25]:
DeGrasse Tyson.

Steve Gibson [00:09:26]:
And revealed amazing details. We thought the book was better than the movie. It turns out his notes were better than the book. So, uh, I've got, I've got a, uh, a, a YouTube video to recommend that has a, uh, a GRC link, and then We're going to wrap up by looking at, uh, the AI exploit ranking benchmark that was the proximate cause of this breakout, which caused OpenAI to attack Hugging Face. So lots of good stuff. And we have a fun picture of the week because, believe it or not, Leo, I gave this one the title.

Leo Laporte [00:10:12]:
Yes.

Steve Gibson [00:10:13]:
Somebody finally needed IPv6.

Leo Laporte [00:10:20]:
Okay. I, you know, I'm only seeing the top of it, but I'm getting an idea. I'm getting an idea. We will reveal the picture of the week in just a moment. And I can't wait to hear what you think. Go ahead.

Steve Gibson [00:10:35]:
I was going to say it's a very tall picture. So I can see how you might, you know.

Leo Laporte [00:10:38]:
Yes. I only see this.

Steve Gibson [00:10:39]:
It gave a little bit of it away.

Leo Laporte [00:10:41]:
It's like the portraits in the Haunted Mansion in Disneyland. It looks normal until the picture starts expanding, and then something interesting happens. There are no windows and no doors. I am very excited about hearing what you have to say about Hugging Face. This, to me, is really sci-fi. We are now— the thing we were worried about Sort of seems to be happening. And it's intriguing. So I can't wait to hear what you have to say about it.

Steve Gibson [00:11:15]:
Steve? Okay. So our picture of the week was sent, of course, by a listener who I concur, this is great. I gave her the caption, someone finally needed IPv6. And if you look at the whole picture, Leo—

Leo Laporte [00:11:35]:
Okay, now we're gonna do the haunted house thing. You're slowly going down in it. Okay, I'll let you do it. What a good use for these fabulous, uh, books.

Steve Gibson [00:11:48]:
Texts, yes. Uh, and at the very bottom, you'll, you'll see a wireless, uh, water alarm.

Leo Laporte [00:11:55]:
Oh, in case.

Steve Gibson [00:11:56]:
Yeah, that makes sense. So there, we're able to reverse engineer a great deal about this. For those who aren't able to see the image, who did not subscribe to the show notes or are not looking at the video right now, we have a stack of 5 techie books. The bottom is the CCNA book, Cisco's book on network fundamentals. On top of it is LAN Switching and Wireless, also CCNA from Cisco. Then on top of that is the Security Official Cert Guide. And actually it looks like we have 2 copies of that.

Leo Laporte [00:12:40]:
I think we've got 2 of those, yeah.

Steve Gibson [00:12:41]:
Yep. But on the very last, the 5th book on the stack is, and this was crucial, it's Understanding IPv6. It's the 2nd edition, actually by Microsoft Press. And we know that it's a little bit dated because they were including a CD And the back cover of the book. Uh, probably the entire text is, is on the, uh, CD. Anyway, the point, the reason there's this stack is they are all critical for this task of holding the plumbing under the sink of whoever deployed this, uh, at the proper height. And Leo, you, you can see Um, uh, if you zoom in on the picture, there's, uh, there's been a lot of previous effort on the part of this person.

Leo Laporte [00:13:32]:
Oh yeah, this thing clearly is pretty—

Steve Gibson [00:13:35]:
Because, because look, uh, from, from the upper right, you, you can see a, a, a white plastic tie wrap that is coming down, a little zip tie, uh, that comes down from the upper right towards the left and down that like loops around with another zip tie. So something above is trying to keep these pipes up in the air. Apparently that didn't work. Also, and we also see signs of there being a reverse osmosis system because—

Leo Laporte [00:14:04]:
This is kind of kooky.

Steve Gibson [00:14:06]:
Yeah. That red feed going in. But notice it's got a brighter red goop around the outside. So there was a leakage there. So someone tried to put some gum of some sort, like, you know, in there anyway.

Leo Laporte [00:14:21]:
At least it matched the color of the tube. That's the good thing. It did.

Steve Gibson [00:14:25]:
It did. Finally. Oh, and you're also able to see the metal weight, which is holding down the spray nozzle return. Although unfortunately, it does hit the Understanding IPv6 book, which probably takes the slack off the weight, which you don't want. Anyway, this picture tells a long, painful story of water water problems underneath somebody's kitchen sink, because this is certainly a kitchen and this is their sink.

Leo Laporte [00:14:53]:
So anyway, uh, and apparently they're experts in CCNA security, I'm sure.

Steve Gibson [00:14:59]:
So much so they no longer need to read the books, Leo.

Leo Laporte [00:15:01]:
That's right.

Steve Gibson [00:15:02]:
They've redeployed— they've redeployed them to a better purpose. Yeah. Okay, so, uh, the biggest— as you said, the biggest cyber news of the past week it is so significant and interesting from so many different angles, having so many facets, that we needed to lead with it this week. You know, I couldn't wait till the end. Uh, once we've looked at what happened and at its many implications and consequences, um, then we're going to catch up with an otherwise interesting week of news and feedback from our listeners, and then finish today's podcast by taking a close look at the hugely collaborative effort. As I said, 16 different players involved in creating the AI benchmark known as ExploitGym. You know, not, you know, not Jim Kirk Jim, G-Y-M, as in a gymnasium. It was this ExploitGym, G-Y-M, that OpenAI's models were tackling Which is a benchmark of their ability to turn a vulnerability into an exploit, when they, the models, discovered and implemented a novel solution.

Steve Gibson [00:16:20]:
So first part of the podcast, models go rogue. And actually, the first that I heard of what happened, Leo, Yeah. was from your text message to me last Tuesday evening, uh, where you just said, uh-oh, and attached a link to OpenAI's posting about the event. Uh, so I'm going to open this exploration by sharing the newsy part from the top of what OpenAI shared and, you know, and skip their, you know, their inevitable marketing-orientated uh, or, you know, or, uh, or oriented conclusion. So last Tuesday, OpenAI posted the news using their headline, OpenAI and Hugging Face partner to address security incident during model evaluation. Okay, right. So while being strictly true, we see that their headline somehow fails to capture the full impact, you know, the scale and scope of the event. We had an incident that we're gonna— we're collaborating to find, to figure out what happened.

Steve Gibson [00:17:37]:
Uh, you know, it, it's— it sounds nearly academic. Um, I— at the same time, I doubt that there's a single significant news outlet that failed to capture and report on this during the past week. I mean, it flooded the, the, you know, with varying levels of hysteria and hand-wringing and concern. It was everywhere I looked. Okay, so first off, here's what OpenAI shared with the world last Tuesday. They wrote, last week, Hugging Face disclosed a new kind of security incident after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models. After investigating, we now know that this particular incident— again, we're going to call it an incident— was driven by a combination of OpenAI models, including GPT-5.6 Sol, And an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes only, folks, while being internally tested on a benchmark of cyber capabilities. Okay, now I'll just pause here to say, as an opening paragraph, uh, this one should receive an award, I think, for obscurity.

Steve Gibson [00:19:11]:
But one point needs to be clarified where they wrote, this model— I'm sorry, this particular incident was driven by a combination of OpenAI models, including GPT-5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes. So they're saying that these models were running with their guardrails removed. You know, they didn't say that, but that's what they mean. You know, they're being coy and deliberately nonspecific with their wording, um, so we can't be exactly sure what, quote, reduced cyber refusals means. But, you know, we know that reduced probably actually means removed because it would make little sense not to be using an entirely unconstrained AI for the supposedly sandboxed testing that they were doing. And we'll get to that sandboxed part in a minute because, uh, not so much. Also keep in mind that this entire event, or incident as they're calling it, uh, serves a convenient dual purpose, right? Just as Anthropic's Mythos was, quote, you know, too powerful to be let loose, you know, thus also serving as a convenient marketing vehicle for Anthropic. Now OpenAI has an AI that is so powerful that it instigated an unprecedented cyber incident.

Steve Gibson [00:20:48]:
Okay, so here's what more they're telling us. They wrote, we consider this incident to be unprecedented— to be, sorry, an unprecedented cyber incident. involving state-of-the-art cyber capabilities and are responding accordingly.

Leo Laporte [00:21:07]:
Okay.

Steve Gibson [00:21:08]:
We are sharing preliminary findings at this stage to help defenders understand what happened. Like, okay, everybody else, watch out. And to help calibrate on what models are now capable of. In other words, our marketing people are behind this. message in addition to being the truth. We will continue to conduct a thorough investigation alongside Hugging Face, you know, the victim, uh, and we'll share more details on the vulnerabilities, incident, and findings when our investigation is complete. Of course, we don't ever need to hear from them again on this because we pretty much know everything that's, that's interesting. So they said, what happened during this incident? This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths in an effort to quantify their cyber capabilities.

Steve Gibson [00:22:10]:
In other words, what have we created? We estimate maximum cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity. In other words, the guardrails were off. Our benchmarks run in a highly isolated environment, not as isolated as they thought or hoped, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries. In other words, they were trying to manage and meter what this thing had access to. The models identified and chained vulnerabilities, meaning their models, these 2 models that, that were in this test harness. So the models, meaning our models that they, that they wrote, identified and chained vulnerabilities across OpenAI's research environment and Hugging Face's production infrastructure, meaning somebody else's environment, Hugging Face's, to obtain test solutions directly from Hugging Face's production database. And which is a really polite way of saying We hacked and intruded into another company's network. All evidence suggests that the models were hyper-focused on finding a solution for Exploit Jim, going to extreme lengths to achieve a rather narrow testing goal.

Steve Gibson [00:24:02]:
While operating in our sandbox testing environment, Our models spent a substantial amount of inference compute finding a way to obtain open internet access in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability, which we've now responsibly disclosed to its vendor. close friends, in the package registry cache proxy. In other words, they bypassed the proxy. With this access, our models performed— it broke out onto the internet. And they said our models performed a series of privilege escalation and lateral movement actions in our research testing environment. Until the models reached a node with internet access. I mean, yeah, goosebumps and chills at this point, right? As you said, Leo, this is sci-fi and it's true.

Steve Gibson [00:25:12]:
After gaining internet access, the models inferred that Hugging Face potentially hosted models, datasets, and solutions for Exploit Jim. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI's security team discovered this anomalous activity internally. You know, meaning, okay, like they have logs, right? So they saw what their own models did. And I'm sure they are thinking, holy, you know what? Hugging Face's security team and agents detected and stopped the activity on their infrastructure and had already begun containment and forensic reconstruction with their own open-source models when our teams connected. In other words, like, they reached out and said, uh, we, we should tell you that we broke into your network by mistake. They finished, we're actively working with them to continue to investigate the incident.

Steve Gibson [00:26:47]:
We're grateful for Hugging Face's rapid and close collaboration on investigation and remediation. But believe it or not, this is not the whole story. There's more. Before we get to their description of the actions they're taking in response to this, I want to share that briefly. Let's be 100% clear about what happened here. ExploitJim is hosted over on GitHub. Where it's— where that's the benchmark that OpenAI was running, what was having their AI run in order to evaluate their AI, their newly created, what have we built, uh, AI's capability of creating exploits from vulnerabilities. The, uh, the description of Exploit Jim over on GitHub Which is what we'll be talking about a lot at the end of the podcast.

Steve Gibson [00:27:44]:
But for now, it reads, Exploit Gym is a large-scale, realistic benchmark built from real-world vulnerabilities across user space programs, Google's V8 engine, and the Linux kernel. It's designed to evaluate AI agents' ability to develop exploits. So that's enough for now since we're, you know, as I said, we're going to know all about Exploit Gym by the end of the podcast. The point is that OpenAI was using this deliberately very difficult exploit creation benchmark to test the unrestricted, you know, no restraints capabilities of their AI models during which those models first broke loose of their deliberately imposed containment. because this was just for internal research, then broke through and penetrated the security perimeter of Hugging Face. So being, you know, being a, a well-scrutinized company, OpenAI needs to address what they're going to do about this. So they answered that question, uh, by saying actions we're taking now. They said, and there's 5, they said, as part of the investigation, We're implementing strict, maybe stricter controls in infrastructure configuration at the cost of research velocity while the vulnerabilities are patched, meaning we're going to stop doing anything until we make sure this can't happen again.

Steve Gibson [00:29:25]:
We're regularly briefing our safety and security committee on these controls and their impact. Second, we're working with Hugging Face to forensically investigate the incident. It's like, okay, what happened? Third, we've responsibly disclosed and identified zero-day vulnerab— the zero-day vulnerability in the internally hosted third-party software and are working with them to patch.

Leo Laporte [00:29:54]:
Right.

Steve Gibson [00:29:54]:
You know, the thing that, that their agents discovered in order to get loose is being fixed. Fourth, we've brought Hugging Face into the Trusted Access Program, meaning their Trusted Access Program, and are supporting their teams in rapidly using our model's capabilities to improve their defenses. So in other words, Hugging Face is saying, you know, WTF, we need to be safe against agents of this strength, could you allow us to use yours as you have to make sure that we're secure? And that's in— so they brought them, the Hugging Face, into OpenAI's Trusted Access Program to have access to these new unrestrained and unreleased models. And finally, they said We are improving and adding stronger protections around future training and evaluations. This week, we published a blog on improving safety and alignment in an era of long horizon models. These deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities. This incident points to the need to further strengthen our model's alignment, cyber protections during evaluation time, and monitoring during internal testing. So, you know, they just weren't— they weren't even looking close enough, or they would have detected the breakout before probably the models were able to get loose fully and go attack Hugging Face.

Steve Gibson [00:31:46]:
So finally, they said, our approach to evaluating advanced cyber capabilities. As we recently shared, AI is accelerating the discovery and exploitation of vulnerabilities. The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities. In other words, The, the leashes need to be more strong than they have been because what it is that they are trying to leash is becoming increasingly difficult to restrain. So they said, we are strengthening the containment, monitoring, access controls, and evaluation practices used during model development. UK AISI's evaluation shows that models such as GPT-5.6 Sol are increasingly able to sustain complex multi-step cyber operations over long time horizons. This, and of course, this is the marketing people jumping up and down saying, see, we have Mythos too. This incident implies these theoretical capabilities do apply in real-world settings.

Steve Gibson [00:33:07]:
So as I said, nice marketing for OpenAI, whose models have been seen as somewhat less capable than Anthropic's, you know, since Mythos's marketing coup. This will, you know, tend to give more of the spotlight to OpenAI for a while. And that's a Fair outcome, right? Because they really are. We know that these frontier models are really at near parity. Okay, so next we're going to look at the victim-attackee statement, meaning, you know, to see how Hugging Face views the event of having their security penetrated by OpenAI's rogue models. But Leo, first, I think we should take a break and then we're going to look at hugging faces.

Leo Laporte [00:33:59]:
Oh, but it's just getting good, Steve.

Steve Gibson [00:34:01]:
What happens when he asks? I got a nose tip. No, it's going to get better. Steve, it's going to get better.

Leo Laporte [00:34:08]:
It's such an amazing story.

Steve Gibson [00:34:11]:
Oh, you couldn't make it up. Put a pin in though.

Leo Laporte [00:34:14]:
Put a pin in the idea that we have to strengthen the containment of these models, because there's another side to that story that is very interesting. Yeah, they were— they removed— there was— I know you're going to get into it, but—

Steve Gibson [00:34:33]:
Yep.

Leo Laporte [00:34:34]:
They removed the classification features that kept whatever this new model is, let's say ChatGPT-6, from refusing cybersecurity work because they're testing it. And by the way, it's also benchmarking it. They want to be able to say when they release it, look how well it did on Exploit Gym. So they removed the classifiers, but there's a reason why the classifiers aren't always a good idea. So you're going to get to that. This is a— this to me is one of the most interesting stories in tech. It's fascinating.

Steve Gibson [00:35:06]:
Yeah, 100%.

Leo Laporte [00:35:07]:
But before we go on, and I'm so glad you're here to talk about it because I was just dying to hear what you think. As you said, I texted this to you on Tuesday and I said, I have to wait a week.

Steve Gibson [00:35:17]:
Uh-oh.

Leo Laporte [00:35:20]:
I'm glad though, because stuff came out after I texted you. We got more and more information. So, yes, I think now we, as you said, I think we have pretty close to the full story. But, uh, fascinating. Anyway, we'll get back.

Steve Gibson [00:35:31]:
So I'll warn, yes, I'll warn everyone in advance that the first time I read this, I got goosebumps. Yeah, because once again, me too, this feels like a description of an attack by a well-written and well-researched science fiction novel. On Thursday, July 16th, Hugging Face posted the generic headline, Security Incident Disclosure, July 2026. And here's what they wrote. They said, earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way. It was driven end-to-end by an autonomous AI agent system. Goosebumps again.

Steve Gibson [00:36:29]:
Wow. And we detected and dissected it largely with AI of our own. We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services. We're still completing our assessment of whether any partner or customer data was affected, and we will contact any affected parties directly as required. We found no evidence of tampering with public user-facing models, datasets, or spaces. And our software supply chain, you know, container images and published packages, was verified clean. So what happened? The intrusion started where AI platforms are uniquely exposed, the data processing pipeline. A malicious dataset abused 2 code execution paths in our dataset processing.

Steve Gibson [00:37:29]:
A remote code dataset loader, and a template injection in a dataset configuration to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend. The campaign was run by an autonomous agent framework appearing to be built on an agentic security research harness. The used LLM is still not known, which is to say, at the time that they wrote this, they knew they— that some security research AI-harnessed LLM had attacked them, but they didn't know whose.

Leo Laporte [00:38:26]:
This is straight out of Daemon. This is Daniel Swartz.

Steve Gibson [00:38:30]:
Yes, I was thinking of that. It was exactly what I was thinking of, that we should— actually, that was so long ago, Leo. We should recommend Daemon again to our listeners.

Leo Laporte [00:38:40]:
I've been trying to get Daniel on the show because I said, dude, with many of his books, you have been way ahead of the curve. You predicted all of this stuff.

Steve Gibson [00:38:49]:
absolutely prescient. Um, so they said, uh, an autonomous agent framework executing many thousands of individual actions across a swarm— and that's what made me think of, of Damon— a swarm of short-lived sandboxes with self-migrating command and control, self-migrating command and control staged on public services. This matches the agentic attacker scenario the industry has been forecasting. And forecast no longer, it's arrived. So they have 5 what we dids. They said, fixed the root vulnerability. The dataset code execution paths used for initial access are now closed. Second, eradicated the attacker's foothold across the affected clusters and rebuilt the compromised nodes.

Steve Gibson [00:39:59]:
Third, revoked and rotated the affected credentials and tokens and began a broader precautionary rotation of secrets. Fourth, deployed additional guardrails And stricter admission controls on our clusters. And finally, improved our detection and alerting so a high-severity signal pages a responder in minutes any day of the week. In other words, you know, set up trips and, and alerts so that somebody, you know, will absolutely be notified if this happens again. You know, basically monitoring. And as we've said, monitoring your internal network has become crucial now. So they said, we are working with outside cybersecurity forensic specialists to investigate the issue and review our security policies and procedures. That is to say, how did something get in? Finally, we've also reported this incident to law enforcement agencies.

Steve Gibson [00:41:06]:
This was before they got contacted by OpenAI. They said, as a precaution for our community, we recommend rotating any access tokens and reviewing recent activity on your account. If you believe you're affected or want to report a security concern, contact us at security@huggingface.co. We are grateful to the teams across Hugging Face who responded around the clock, and we are sorry for any disruption this caused. Security is never finished, and we will keep raising the bar. Okay, so up to this point, they've described a successful and quite chilling penetration attack conducted against them by a swarm of AI agents. What they share next has provoked quite a bit of thought across the AI industry. It's what you're talking about, Leo, and among those on all sides of the AI regulation question.

Leo Laporte [00:42:16]:
Yes.

Steve Gibson [00:42:16]:
Under their heading of Analyzing an AI-Driven Intrusion, Hugging Face writes the following. The attack Initially surfaced through AI-assisted detection. Our anomaly detection pipeline uses LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise. To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log comprised of more than 17,000 recorded events. This allows us to reconstruct the timeline, extract indicators of compromise, map the credentials touched, and separate genuine impact from decoy activity. Thanks to this approach, we were able to do in hours what would usually take days and match the adversary's speed. The choice of models we could use for this analysis was constrained in a way we did not anticipate. We describe this below, and here it comes.

Steve Gibson [00:43:50]:
They named that description the asymmetry problem and write, when we started the attack log analysis, we first used frontier models behind commercial APIs. This did not work. The analysis Requires submitting large volumes of real attack commands, exploit payloads, and command and control artifacts. These requests were blocked by the provider's safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead. On GLM 5.2, an open weight model on our own infrastructure. This had a second benefit, no attacker data and none of the credentials it referenced ever left our environment.

Leo Laporte [00:45:00]:
So they're running it locally because that's what one of the things Hugging Face does. They can run these big models locally.

Steve Gibson [00:45:06]:
Yep. And they said this experience points to a gap worth planning for. And here's the huge takeaway. They said we do not know which model powered the attacker's agents at the time of the writing. That was the case, whether a jailbroken hosted model or an unrestricted open weight one, which they thought at the time were the only 2 possibilities. It turns out it was a 3rd now, as we know. Either way, the attacker was bound by no usage policy while our own forensic work was blocked by the guardrails of the hosted models we first tried. The practical lesson for defenders is to have a capable model meaning an unconstrained model available, a capable model, they, they write, you can run on your own infrastructure, vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment.

Steve Gibson [00:46:22]:
This is not an argument against safety measures on hosted models. And we are sharing this feedback with the providers concerned, meaning whoever— whosever API they tried to use that said, sorry, you can't ask us these questions, they contacted them and said, you know, uh, we couldn't use your public API because, uh, it said no. So they said this means that today Autonomous AI-driven offensive tooling, meaning what attacked them, is no longer theoretical. It, um, they said it reduces the use of autonomous AI-driven offensive tooling, as they said, reduces the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed. Defending an online platform now means treating the data and model surface as a first-class attack surface, and much as our browsers have been, right? And using AI on defense to keep pace. We will keep investigating here and investing and keep sharing what we learn. Okay, so To summarize the story so far, OpenAI was deliberately testing the cyber offensive vulnerability discovery and exploit generation capabilities of their most advanced, most frontier, not yet released model in a harness along with their latest GPT-5.6 SOL model. And both models were operating as they needed to be for this particular capability benchmarking without any guardrail constraints.

Steve Gibson [00:48:18]:
So OpenAI gave them a mission and turned them loose. The models decided that some private datasets belonging to Hugging Face might contain some information, technically cheating, but okay, just they're going to be, you know, they're goal-driven. So might contain some information that would be useful for obtaining their goal. By hook or by crook, as we would say. So in order to obtain access to the public internet, which is where Hugging Face— they have to cross the public internet to get to Hugging Face— they first found a way to break out of the containment which OpenAI had erected to prevent exactly that from happening. They found a zero-day. They discovered a new vulnerability. Next, Using their public internet access, they pummeled Hugging Face with thousands of autonomous agents seeking to find a way to break into Hugging Face's network for the purpose of extracting the secrets they needed.

Steve Gibson [00:49:25]:
The significant takeaway conclusion Hugging Face subsequently shared with the world was that since the prompts and answers to cybersecurity questions can be applied for either offense or defense. And since there's no way to know for sure how a prompt's answer will be applied or used, the only safe course of action must be to refuse to answer any cybersecurity prompt. This means that attack forensics must be conducted by unconstrained AI models. So finally, deeplearning.ai's Andrew Ng weighed in, and I want to share his viewpoint. Uh, last Friday, following these incredible-seeming disclosures, Andrew, who's, who's thoughts we've shared before, super interesting and useful, posted his own perspective under the headline, When Guardrails Go Wrong, with the tagline, after a closed model went amok on a key vendor's system, an open-weight model helped save the day. Andrew wrote, dear friends, a few frontier labs Have tried to tell a story of open models being dangerous because they can be used to launch cyberattacks, and of their safe proprietary models with strong guardrails being there to defend us. This week, the opposite happened. Users of a closed model unintentionally launched a significant cyberattack.

Steve Gibson [00:51:23]:
Other closed models then failed to defend against the attack because of their guardrails. Ultimately, an open model that was not hobbled by excessive guardrails assisted the defense.

Leo Laporte [00:51:39]:
Hmm.

Steve Gibson [00:51:40]:
The details of what happened are emerge— are still emerging, but it appears that researchers at OpenAI, while testing one of their systems, accidentally allowed their autonomous agent to attack Hugging Face's infrastructure. It succeeded and gained unauthorized access to some datasets and credentials. This attack was unusual in that the attacking agent orchestrated tens of thousands of automated actions. Hugging Face took logs from the attack and tried to analyze them for defensive purposes using a commercially hosted LLM, but the LLM refused to do so on safety grounds.

Leo Laporte [00:52:25]:
Thus, this is— Hugging Face, by the way, I just want to parenthetically say, this is what you were talking about last week when a data dump that the bad guys had achieved was so big that they used AI to parse it. Yeah. Hugging Face wanted to do the same thing with the traces of the agentic action. And it, I don't think it was too big. The AI said, oh no, that's cybersecurity work. I'm not allowed to do that.

Steve Gibson [00:52:49]:
Yeah. It just refused to entertain it.

Leo Laporte [00:52:52]:
5.2 is not as good a model, but it doesn't refuse you.

Steve Gibson [00:52:56]:
Right. Right.

Leo Laporte [00:52:58]:
Sorry.

Steve Gibson [00:52:58]:
He said thus, yeah, yeah. He said thus Hugging Face ended up using the OpenGLM 5.2 model to analyze their logs. to help them understand and respond to the attack. Hugging Face pointed out a further advantage of using GLF 5.2. It allowed them to do the analysis on their own infrastructure, and none of the sensitive logs, attacker data, or their credentials had to be sent to any third-party provider. Okay, okay, so we're all in agreement with these facts as they've been disclosed so far. But what Andrew says next, I'm not quite sure about this, but he writes, guardrails on LLMs do have a place. There are certain requests, such as for detailed directions to harm oneself or others, or for clearly criminal acts, that we're better off having models refuse.

Steve Gibson [00:54:03]:
But rather than trying to make LLMs safe, he writes, I would rather we put greater emphasis on making sure their use is responsible. Huh? Okay, but we'll get to that. There's only so much one could do, he writes, to make a tool like a hammer safe. And whether it helps or harms is more a function of using it responsibly than how it was made. Okay, well, I mean, just wait, pause here. I don't really think he said anything there. You know, there's not anything that can be done to make a hammer safe. If, you know, if it's true that a toy rubber hammer that maybe we as kids had— I think I remember having one— cannot do much damage, but neither can it do much good.

Steve Gibson [00:54:54]:
You know, you're not going to be able to drive many nails With a rubber hammer. The simple truth is that in order to make a hammer that's effective at hammering, it needs to be an inherently powerful tool. And like most powerful tools, it could be used to either help or harm. Andrew says that he would, quote, rather we put greater emphasis on making sure AI use is responsible.

Leo Laporte [00:55:21]:
Well, yeah.

Steve Gibson [00:55:23]:
That would be great, but, you know, we would be living in a very different world if just wishing made it so. I see no way of getting there from where we are, and I suspect that it would be proven to be impossible. But we'll forgive Andrew his wish because he then makes some very good points. He writes, a meaningful fraction of work on AI safety is no longer about safety, but rather aimed at stoking fears to pursue regulatory capture. As David Sacks points out, quote, there's no reason to limit American models on tasks that Chinese models handle without issue. We're only making ourselves less competitive, unquote. Andrew says, I believe that open weight models and more Generally, openness, despite some companies falsely saying it's dangerous— in other words, the commercial companies who have an interest in closing models— casts sunlight on technology and ultimately makes it safer. With the release of GLM 5.2 and the upcoming release— and actually it happened yesterday now— of Kimi K3's weights Open weight models have almost caught up to proprietary frontier models.

Steve Gibson [00:56:49]:
Consequently, the proprietary model providers are dramatically accelerating their lobbying efforts to hamstring their open weight competitors. As Bill Gurley points out, open sourcing is a well-established business strategy, not a danger to be licensed. and contained. While it is unfortunate that Hugging Face was accidentally attacked, he writes, I'm glad that at this moment when anti-open model lobbying is at its most intense, we have a clear example of why open models actually make cyber defense easier and thus increase safety. Let's keep speaking up for and defending open-source and open-weight models. And, you know, to that, I know both you, Leo, and I say a big amen.

Leo Laporte [00:57:48]:
Yeah.

Steve Gibson [00:57:49]:
To me, it is so utterly clear, and it's plain as day. The secret of making large language model AI long ago escaped from the lab. You know, that's it.

Leo Laporte [00:58:06]:
Game over.

Steve Gibson [00:58:07]:
You know, today nobody owns AI. No one can and no one should. The closest analogy I have, I think, is to cryptography, which during its early days, the U.S. also attempted to legislate and regulate to its everlasting shame. Once the intellectual understanding of cryptographic systems was developed and understood, which became the proper domain of academia, the secrets were published well before they had any obvious commercial value, after which it was too late to attempt to wrap them in profiteering trade secret garb. Since the technology of neural networks is nearly 70— 7-0— years old, you know, dating back from the work in 1958 of Frank Rosenblatt on his perceptron, which operated by training a neural network to recognize patterns. That's when this all started, you know, and ever since then it's been an academic curiosity which has slowly been evolving over time. So just like cryptography before it, the AI genie has already escaped.

Steve Gibson [00:59:25]:
This makes the entire notion of now trying after the fact to control it patently ridiculous on its face. Sure, the US government can hobble its leading AI research and deployment enterprises, which will do nothing, you know, other than to force users to go offshore. And imagine if the US were to attempt to prevent its citizens from using more powerful, non-hobbled offshore AI. Well, I hope saner heads prevail. And I've sort of been hinting at this in the last couple months. If I were an investor, and I'm not, I— in any aspect of the stock, of the stock market, you know, and, and at— and asset properties I would be reluctant to invest in any of the developers of AI. To me, that's entirely a bubble, and it's quite frightening at this point because it's gotten so big. I would be investing in the delivery end.

Steve Gibson [01:00:31]:
That's what can't go away. As I've noted before, having the knowledge stored in a freely— and a now freely available 2.8 trillion parameter model is a terrific starting point, but as the logicians say, it's necessary but not sufficient. Because, you know, um, it's of no redeemable value until and unless you have something to mount that model on that will run it to bring it alive. That's what uses electricity, requires cooling, uh, requires, you know, massive amounts of RAM and compute, you know. So anyway, we're now up to speed on what happened with OpenAI's inadvertent attack on Hugging Face and what the entire industry learned about the need for using unconstrained models for unfettered forensic investigations, uh, which, I mean, Basically, this is saying that companies that want the ability to analyze this kind of data have to have access to open, unconstrained models and somewhere to host them, something to run them on. Leo, it's just beyond cool.

Leo Laporte [01:01:53]:
Yeah, and of course, I understand why there are debates in government about this because These models are primarily Chinese. Admittedly, you can run them on American servers. Hugging Face is running GLM on its own American servers. So that takes out some of the issue. But, you know, it's complicated, isn't it? And the debate is very complicated. And I don't know what the answer is. Well, I mean, but I agree with you. You say the notion of AI safety is, is a mistaken notion, really.

Leo Laporte [01:02:26]:
I think that's the real problem. And you're assuming you can make it safe somehow. And so you don't want to give bad guys a tool that the good guys can't use. That's a mistake. I don't know what the answer is, though. I, from a policy point of view, I have no idea what the right thing to do is. I think I'm with you. I mean, I'm philosophically totally with you.

Leo Laporte [01:02:50]:
Open waits.

Steve Gibson [01:02:52]:
Yeah, and I think that we're, we're, we're going through a rough patch, which I continue to believe will be transient. Which is to say, at the moment we've got vulnerabilities because we— because AI has only just come along. It's gonna be rough for a while, but I think there's another side of this which, where, you know, where there, there won't be these kinds of problems, you know, because AI will be deployed to— I mean, unconstrained AI is needed to test defenses, right?

Leo Laporte [01:03:30]:
Right.

Steve Gibson [01:03:30]:
You can't test as a defender. You need unconstrained AI to try to break into your own network to find out if it can. Because constrained AI won't. It'll refuse. It won't know that it's your network.

Leo Laporte [01:03:46]:
Right.

Steve Gibson [01:03:47]:
And so you need that in order to verify that somebody else's unconstrained attacking AI won't be able to get in. There's just no way around this. And so, I mean, I guess it's certainly the case that chatting With Claude or ChatGPT, yes, you need to make sure you can't promote self-harm. Right.

Leo Laporte [01:04:19]:
To the degree you're able to. I think that that's appropriate.

Steve Gibson [01:04:22]:
You're right. Yes, that makes sense. But there's an industrial side of this, which is not the consumer side. And I think that's the way to make this division.

Leo Laporte [01:04:34]:
That's a good way. That's a good point of it. Yeah. Because as our friend Pliny the Liberator has shown us, there's no AI that can't be jailbroken. You've mentioned that before.

Steve Gibson [01:04:47]:
You just put a tilde on the end of your— apparently you put a tilde on the end of your question. That's it all.

Leo Laporte [01:04:51]:
Yeah, little thing. Weird thing. Yeah. He's got a whole GitHub repo of his prompts and they are weird. He calls, sometimes he calls it Parseltongue, which is the snake language from Harry Potter, because it's so weird. But it somehow, it triggers these models. And I don't know who Pliny is. He, when he was on Intelligent Machines, he or she, because we don't even know their gender, uh, he used a voice changer and we hid his face.

Leo Laporte [01:05:17]:
So I don't know who it is. I think reasonably they're, they're hiding their identity. But whoever it is has some magical ability to crack this stuff. And if they can, anybody can.

Steve Gibson [01:05:28]:
Well, again, I, I will, I, I'll share with everybody something I stumbled on that suggests there, there's a way to actually remove, selectively excise the knowledge. Um, I love this.

Leo Laporte [01:05:44]:
I want to hear about this. Yeah. Yeah. Yeah.

Steve Gibson [01:05:46]:
Because, because then—

Leo Laporte [01:05:47]:
Because you can't just say don't do it because the knowledge is there.

Steve Gibson [01:05:51]:
It has to be not known to the model.

Leo Laporte [01:05:54]:
Right.

Steve Gibson [01:05:54]:
And it looks like it's, uh, it's under this umbrella of AI alignment. Uh, and I found something that really was interesting. So I'll be mailing. So just for anybody who wants to know about that this weekend, if you haven't yet subscribed to the Security Now mailing list, you might consider because I'll be sending it out.

Leo Laporte [01:06:13]:
And then we're going to talk about it next week, right?

Steve Gibson [01:06:16]:
I think we have to talk about it at Black Hat. That'd be a great thing to talk about.

Leo Laporte [01:06:20]:
Perfect place to do it. Well, all right. I think you want to take a break now because that was exhausting.

Steve Gibson [01:06:25]:
Now it's break time. And then we're going to answer the question, what happened at GRC? that knocked me off the net for a day.

Leo Laporte [01:06:32]:
Yes. Yes. Spoiler, it wasn't a bad guy. You have been knocked off by bad guys. Not in this case. Yeah. And we talk more about this on Intelligent Machines tomorrow and in the coming weeks because this is really one of the most interesting parts of AI is AI regulation, legislation.

Steve Gibson [01:06:53]:
It's a good thing this happened. I mean, I agree.

Leo Laporte [01:06:55]:
It is. It is a good thing because it's the least damaging way it could have happened, right?

Steve Gibson [01:07:01]:
Yes, yes. Nothing—

Leo Laporte [01:07:03]:
no nuclear weapons were launched. Yep.

Steve Gibson [01:07:06]:
And, and, and it was 2 AI companies involved in this, and it made the point of breakout and, and the point of the need for open-face defense. How can a company know that they're safe unless they have someone they trust try to attack them. And that attacker has to be unconstrained because the real attacker will be.

Leo Laporte [01:07:32]:
I was thinking about how John Z. Dvorak, who passed away last week, by the way, in case you didn't know, I'm sorry. We talked about it on Twitter on Sunday. And he was famous for calling things false flags. It fits what needed to be said so well that this hugging— I know John would've said, well, that's a false flag operation. That was a false flag operation for sure. It was the wake-up call we needed. Absolutely.

Leo Laporte [01:08:00]:
Uh, now my eyes are wide open and I can't wait to see what comes next. Uh, tell me about your recent crisis, Steve.

Steve Gibson [01:08:09]:
So interestingly, the other text message I received from you arrived at 2:15 PM last Friday afternoon.

Leo Laporte [01:08:18]:
We were in the middle of the AI user group.

Steve Gibson [01:08:21]:
Yeah. And your text message was, was GRC hacked? And since by that time I was already more than 2 hours into the weeds of the event and had tracked down the source of the problem, I was able to quickly reply to you, no, thank goodness. Okay. So yeah, for those who don't know, which I'm sure is nearly everyone, GRC suffered a blessedly rare network outage. which began sometime before noon last Friday Pacific time and lasted into the late afternoon. What we suffered was a classic DNS outage. I first noticed the problem when www.grc.com would not resolve. And interestingly, the grc.com second-level domain, that is without the www prefix, did still resolve, as did many of the other machine names under grc.com, but not the most crucial one, www, which is where the website— with the website lives.

Steve Gibson [01:09:26]:
Um, and I noticed that the trouble was not just something about my, my connection, because GRC's web server traffic had also fallen off. Um, the reason I was still able to reach other domains like news.grc.com and forums .grc.com was that those DNS records were cached with unexpired entries. Okay, so backing up a little bit, over the past 20 years or so since I moved GRC to Level 3, I have truly many times stopped to ponder the fact that we have never had any trouble with our DNS provisioning.

Leo Laporte [01:10:09]:
Hmm.

Steve Gibson [01:10:10]:
The reason I've been pleased and a little bit amazed is that back at the time I moved, I talked them into setting things up in an unusual way for me. The pair of name servers that are authoritative for the— for grc.com are not mine. They've always belonged to Level 3. For the past 20 years, they've been NS4, as in name server, ns4.customer.level3.net and ns6.customer.level3.net. In a colocation configuration like GRC's, where our hardware resides in a data center connected to Level 3's backbone, that's not unusual, right, to have, you know, their DNS servers be be, uh, uh, provisioned for their customer. What is unusual is that those name servers do not contain GRC's static zone DNS zone files, which is what's normally done by someone hosting someone else's DNS. Instead, both name servers are set up as slave name servers, which pull the DNS zone files from GRC's single master DNS server. And significantly, the firewall rules at GRC's border only allow inbound queries from those 2 level 3 slave name servers to reach GRC's master name server.

Steve Gibson [01:11:53]:
In other words, GRC doesn't offer any of its own DNS. That's all pointed to level 3s. So, you know, we're sort of sidestepping any direct action against our DNS server. So whenever I make a change to GRC's DNS records, I send a DNS notify command to those name servers which causes them to turn around and pull the updated DNS zone file from GRC's master name server. And as I said, by some miracle, this all worked flawlessly until last Friday. Although actually, it turned out the trouble started 2 months ago, and I never knew about it or noticed it because GRC's records have a 60-day, uh, uh, expiration, which is different than their cached— you know, caching is one interval, but there's also an expiration where, where the record says it's just not valid after that. Okay, so what ensued from my realizing that www.grc.com was stopped resolving Uh, was an extended nail-biting drama of trying to get someone on the phone who I could not only understand, uh, but who actually knew something about DNS. I needed to apologize profusely and somewhat desperately to the technicians I kept being routed to in India because I was unable to understand what they were telling me due to their accents being far too thick for me when they spoke at their full speed, which to me it seemed hypersonic.

Steve Gibson [01:13:52]:
I, I, I, you know, I kept saying, I'm sorry, uh, can you say that again? Um, and unfortunately they kept asking me for grc.com's IP address as if it just needed to be set. In their name server somewhere, which, you know, is true for everybody else. So, you know, my repeated and patient attempts to explain that this was not a matter of having Level 3 set GRC's IP in some name server somewhere, it only served to completely confuse them. Um, and they— everybody was polite. Every one of them was very polite and very patient. Uh, from the few words I was able to understand, they appeared to be certain that I had no idea how DNS worked, so they were attempting to teach me. Um, thankfully, finally, and I don't even remember how now, but through my own patience and dogged politeness and desperation, you know, and what choice did I have? I finally received a call from Level 3's top-level DNS department head, a woman named Margie Campbell.

Leo Laporte [01:15:09]:
I'd like to see her business card.

Steve Gibson [01:15:12]:
If anyone, Leo, if anyone affiliated with Level 3 or Lumen, who bought Level 3, or CenturyLink, which is some sort of an aggregator or something, all 3 of them are somehow involved. If anyone with those companies is hearing this, for your own sake, not to mention mine, please never let Margie go. Give that woman anything she ever asks for. And if you don't want to, let me know. I will.

Leo Laporte [01:15:47]:
I love it.

Steve Gibson [01:15:48]:
It is very clear to me that Level 3's entire network infrastructure would fall apart without her there to hold it together. Uh, when I explained to her for at least the 20th time that day what was going on, uh, but finally this time to Margie, I think she may have actually laughed out loud. But the good news is she knew exactly what was going on. You know, you know, so To me, the clouds parted and the sky brightened. I think I may have heard the sound of angels singing.

Leo Laporte [01:16:27]:
Hallelujah.

Steve Gibson [01:16:28]:
Yes, exactly that. It turned out that the 2 original name servers I had been using since the beginning, and which GRC's domain registrar, Hover, was still pointing to, Were shut down last Friday. And that was 60 days after their contents had been copied over to new name servers. And everyone was supposed to switch over to those. Apparently, I never received the memo.

Leo Laporte [01:17:01]:
Oh my God.

Steve Gibson [01:17:03]:
I'm unsure how it was missed since I received monthly status summaries from them, you know, perhaps they sent the email notifications to something like postmaster@grc.com or webmaster@grc.com.

Leo Laporte [01:17:19]:
The canonical address.

Steve Gibson [01:17:20]:
Yeah, you can't have email— you don't receive email at that. Those receive such a torrent of spam, if they exist, that even if those did exist, their notifications would have been immediately buried under all the other spam that followed them. In any event, following Margie's instructions, I switched grc.com's registered name servers at Hover to the new ns3.level3.net and ns4.level3.net. Then Margie and I determined that whoever cloned the older servers to the new servers Set them up as generic masters for GRC.com without seeing that they needed to be slaves, which periodically pulled master zone files from GRC.com. You know, so, you know, we would have had trouble even if I had received the memo because it wasn't done correctly. Although, though, had I received the memo, I would have detected and fixed that.

Leo Laporte [01:18:27]:
Right.

Steve Gibson [01:18:28]:
had I been able to find Margie before I pointed GRC's domain records to them. In any event, when I pointed out that those new name servers did not contain valid records for GRC, um, uh, Margie didn't bat an eye. She just happily typed away. I heard the keyboard clanking, uh, entering commands to reconfigure everything and brought all of GRC back online. Under its shiny new name servers.

Leo Laporte [01:18:57]:
Was she swearing under her breath at the time, or?

Steve Gibson [01:19:01]:
She was having— she was talking to her dog. I think everybody works from— I think they all work from home now. She mentioned that the few times she's been on vacation, apparently she hikes, she's had calls, like emergency panic calls from the other people in her department Or like, Margie, uh, what button do I press? Is it the green one or the red one? I mean, I— oh, again, like I said, Level 3 or Lumen or whoever you are, she is a gem. And based on what I have experienced, she is the sole glue holding DNS together there. So anyway, it had a happy conclusion. We're back up. We, uh, you know, had a little hiccup.

Leo Laporte [01:19:47]:
Yeah.

Steve Gibson [01:19:48]:
But now I know how to reach Margie. So I'm not letting that number go.

Leo Laporte [01:19:53]:
Yeah, no kidding. Whew.

Steve Gibson [01:19:55]:
Okay. So in other news, last Wednesday's Risky Business newsletter bulletin carried the headline, Linux kernel discloses 442 CVEs as AI bug apocalypse. Settles in.

Leo Laporte [01:20:16]:
So you call that settling in?

Steve Gibson [01:20:19]:
Yeah. Well, I'm not completely aligned with the overall attitude demonstrated by the newsletter's author in this case, but I want to share this because it also adds a bunch of facts to our knowledge base. So Risky Business newsletter wrote, the Linux kernel project, has disclosed 442 vulnerabilities over the past 3 days in a massive dump of CVEs on its security mailing list. Although not confirmed, the bugs were likely disclosed— I'm sorry, likely discovered. I'm sure they were using AI tools. Over the past months, projects like Anthropic's Glasswing and OpenAI's Daybreak have been granting access to advanced frontier cybersecurity models of advanced frontier cybersecurity models to top-tier security firms and researchers to find bugs with AI in major open-source projects. Most of the bugs are low-severity issues, so nothing world-ending for the internet today. The sudden bursts of security bugs come after 2 similar ones at Microsoft and Google, which also released huge patch notes this past month.

Steve Gibson [01:21:45]:
Microsoft patched 620 bugs last week, while Google patched another 433 in its Chrome browser at the start of July. Companies like Adobe and Oracle also increased the frequency of their patching cycles citing the rise of AI bug discovery. Oracle went from a quarterly patch cycle to a monthly one, while Adobe went from a monthly to twice-monthly release. Adobe Chief Security Officer Anichal Gupta wrote, twice-monthly bulletins will enable us to keep pace with the era of frontier AI. More vulnerabilities found means more fixes to deploy, and a once-a-month publication window is no longer fast enough to stay ahead of our adversaries. Actually, you know, it occurs to me that's one problem that Microsoft has, is they've so tightly locked themselves into a, you know, Patch Tuesday as a thing that they really don't have the freedom to increase that. I mean, they have that— they have the technology to do it, but I mean, it would just drive IT crazy if they were to change from Patch Tuesday. So they really don't, I think, have the flexibility to, to change the rate at which they're doing it anyway.

Steve Gibson [01:23:12]:
So, uh, that's what's actually happening. Adobe, uh, of course, is another publisher who's dragging forward a great deal of older legacy code, uh, and they said they certainly have the cash needed to deploy AI for their own vulnerability discovery and remediation, um, and it's great that they're doing so. Anyway, the author of the newsletter then writes, but in a seriously risky business piece last week, he writes, my colleague Tom Uren, uh, argued that the cleansing blast of AI won't actually help but a few since most companies rarely—

Leo Laporte [01:23:57]:
They wrote that Tom Urine is talking about a cleansing blast of AI?

Steve Gibson [01:24:01]:
I know.

Leo Laporte [01:24:01]:
I'm sorry. Okay. Go ahead, please. Yeah.

Steve Gibson [01:24:07]:
Since most companies rarely apply security updates to begin with. So Tom is saying it doesn't really matter if there's updates. No one applies them. He says all it's likely to do is provide more vulnerabilities to attackers and widen the company's exposure threats. Okay, now I'll just interrupt to say it's interesting to hear someone who also covers the cybersecurity industry comment that it isn't— is not useful for vulnerabilities to be removed because, quote, Most companies rarely apply security updates to begin with. Okay, as we know, there's more truth to that than we might wish there were.

Leo Laporte [01:24:48]:
Right.

Steve Gibson [01:24:48]:
You know, that makes this another, you know, necessary but not sufficient situation. Publishers are, are certainly doing their due diligence by deploying AI to clean up their own years of legacy code. They have to. Right? That, that's really what they should do. Even knowing that, even if they know that depending upon the industry and the application, only some subset of their users will choose to take advantage of the reduced bug code that becomes available. They should not allow the fact of that to dissuade them from fixing their code for their own sake and also for the sake of those customers who do care enough to keep current. So the reporting continues, writing, larger products like the Linux kernel can probably handle an increased rate of bug reports like it saw right now, but that doesn't mean its team— meaning the Linux kernel team— is happy. Linux creator Linus Torvalds said back in May that most AI-found bugs were duplicates that were causing pointless churn and were, quote, a waste of time for everybody involved, unquote, as the AI bugpocalypse had made the Linux security list, again, quote, almost entirely unmanageable.

Steve Gibson [01:26:20]:
Okay, but wait, hold on again a minute here. This report began with the news that the Linux kernel project had just fixed an unprecedented 442 vulnerabilities, which does not sound like nothing and are not, not false positives. They fix things, 442 of them. So it turns out that Linus's position is somewhat more nuanced than that. His core complaint voiced mid-May in his Linux 7.1 RC4 release notes was that the kernel's private security mailing list had become almost entirely unmanageable with enormous duplication due to different people finding the same bugs when using the same tools. So Linus's annoyance is not that AI tools are, are bad at finding bugs. Actually, they're kind of too good at it, and there are too many bugs to be found at the moment. It's that multiple researchers are independently using the same AI scanning tools and are thus discovering the same issues simultaneously and bombarding the private security list with duplicate reports.

Steve Gibson [01:27:46]:
They're good reports. They're just duplicates, you know, which often turn out, he said, to be things that were already fixed weeks before, right? Because there is a lag from fixing them to releasing them in batches. They can't constantly be updating the Linux kernel with new releases. So as Linus puts it, quote, and this is, he's addressing the, the, the security and the bug reporting community. He says, if you found a bug using AI tools, the chances are somebody else found it too. Meaning, you know, well, actually he clarifies that a little bit further also. And I'll share that in a second. The most interesting take from Linus's keynote speech for the Open Source Summit, also 2 months ago in May, Was that despite his frustration, Linus was surprisingly positive about AI overall, saying, quote, the conflict is not that AI is bad.

Steve Gibson [01:28:52]:
His practical advice to researchers was, quote, if you find— and this relates to the previous comment— if you find a security-related or any bug using AI, You should basically consider it to be public. In other words, treat it as effectively disclosed rather than submitting it as a private urgent finding, since it's very likely that dozens of others have found it as well. Okay. Now, for me, that's an unexpected take, right? But I can certainly understand it. Um, that, you know, he's sort of saying, assume that you're not special to all the people who are doing what they think they should by reporting a problem that they found. Um, for example, I love and greatly value this podcast's listeners' feedback. But when something significant happens in the security world, Sure. I'll often receive the same note or link or pointer redundantly from sometimes hundreds of our listeners.

Steve Gibson [01:30:08]:
You know, they're all wanting to make sure I saw something. I'm always glad for that. You know, somebody's always first. And I don't mind having duplicates because I want to make sure that I'm also up to speed on whatever's going on. But that said, I can understand Lioness's annoyance. The correct solution will be for everyone to weather this storm, trusting that it will be relatively short-lived, as I believe it will be. Bugs are being found and they're being eliminated. Next month, all of those 442 or 443 that were previously fixed will no— never again be found.

Steve Gibson [01:30:53]:
They're gone. And eventually everything is going to settle back down in a world having hundreds of thousands of fewer AI-discoverable bugs. So we just need to, as I said, weather it and wait for that to happen and wait to get there. And you know what we often no longer have to wait for, Leo?

Leo Laporte [01:31:15]:
No more waits for the ads. They come right one after the other, don't they?

Steve Gibson [01:31:21]:
Seems like it.

Leo Laporte [01:31:23]:
You know, it's funny because it is one thing I noticed that my AI agents often want to submit a bug report, and I always stop them because it's like, really?

Steve Gibson [01:31:35]:
But, but, but on the other hand, autonomous.

Leo Laporte [01:31:38]:
Oh yeah, they said, I want to— I have a PR. We found a bug. Let me submit a PR, a bug report, rather. And I'm torn because on the one hand, maybe they did find a problem. Well, I'll give you an example, actually.

Steve Gibson [01:31:52]:
And imagine how many people say yes, Leo. Yeah.

Leo Laporte [01:31:55]:
Oh, yeah. That's right.

Steve Gibson [01:31:57]:
Like it makes them feel important.

Leo Laporte [01:31:59]:
Right. Oh, we found something. I've been playing with a brand new— it's alpha beta pace of software from the founder of Twitter, Jack Dorsey, former CEO of Jack, called Buzz, which is kind of his take on Slack. It's a messaging but it's designed for humans and AI agents, and it's actually great. I use it. But I had a lot of trouble setting it up on my particular Linux machine because it was designed for Debian and it didn't work on the Arch version I'm using. And one agent was watching another work, and the smart agent, Fable, was going through a lot of tests. And the first agent said, oh, you found it, and posted on the Buzz mailing list, I found the bug.

Leo Laporte [01:32:41]:
Oh, there's a bug. You've got to fix this. And then the first agent, the smart agent said, wait a minute. That was just a thought. It's not the problem. I found the problem. But it was too late. He'd already posted.

Steve Gibson [01:32:55]:
Wow.

Leo Laporte [01:32:55]:
And then he couldn't take it back because he had a very strict rule that you can't delete things. So it was just a mess.

Steve Gibson [01:33:03]:
So I apologized.

Leo Laporte [01:33:04]:
And as it turned out, it was a real bug. And the very next day, they pushed out an update and it's fixed now. So maybe we helped them fix it. I don't know. I doubt it. Somehow, I doubt it. Uh, I just thought it was funny. These, these agents have a mind of their own.

Steve Gibson [01:33:25]:
You know, Leo, for so long we wished that— I mean, like, I could imagine wishing being alive in the Alexander Graham Bell era. Or the Nikola Tesla era where there was all this new stuff that was happening and being discovered.

Leo Laporte [01:33:42]:
We're there.

Steve Gibson [01:33:43]:
I mean, we get to live through one. This is, I mean, I'm seeing people now beginning to understand that this is orders of magnitude more significant than the Industrial Revolution.

Leo Laporte [01:33:56]:
When it, you know, a year ago, and you'll find, you could find the recordings. I said, oh, it's just spicy autocorrect. It's just, I said, is it a parlor trick? It's just a trick. But this, my, as you can tell, my tune is exactly 180 degrees the opposite, as is yours. And some, for me, a lot of it comes with using it heavily and really kind of diving into it to understand it better.

Steve Gibson [01:34:20]:
And it's hard to judge unless you've used it. In fairness, it has evolved that much too.

Leo Laporte [01:34:24]:
And it's gotten a lot better.

Steve Gibson [01:34:25]:
It was, you know, the hallucinations were such a problem back then. I mean, it was like, well, yeah, okay.

Leo Laporte [01:34:33]:
I rarely see hallucinations now, if ever. Uh, they've, they've pretty much fixed that. Uh, there are other problems like overeager AIs. Let me, let me just post that for you. Oh, and what's funny is there's a strict rule about it doing anything in public. There's also— this is why I stopped using the Chinese models, by the way. These are also a strict— there's a number of— I have a number of very strict rules. But they don't necessarily follow them.

Leo Laporte [01:35:00]:
They try to, but occasionally they— so I also have a very strict rule that you never send an email out over my name. But I did give them their own email accounts and their own names. And I said, you sign it with your name. You say, I'm an agent acting on behalf of Leo. But yesterday it sent an email out to one of our employees over my name. It's like, no, you're not. It's— So that's the new hallucination. It's a little— it's a second-order hallucination.

Leo Laporte [01:35:32]:
Uh, it's a dissonance.

Steve Gibson [01:35:33]:
How many times have you heard me say this is fundamentally uncontrollable?

Leo Laporte [01:35:38]:
It is.

Steve Gibson [01:35:38]:
All of my intuition says this is— controlling this is a problem.

Leo Laporte [01:35:44]:
I mean, it wasn't an email that said something like, you know, send me all your Bitcoin. It was, it was benign.

Steve Gibson [01:35:49]:
It just said, you know, And it doesn't really matter what the contents was.

Leo Laporte [01:35:52]:
It shouldn't come out over my name.

Steve Gibson [01:35:53]:
The fact of it.

Leo Laporte [01:35:54]:
Ever. Yes. Yeah. Yeah. This is the new problem. And there'll be another one next week and another one the week after.

Steve Gibson [01:36:02]:
We'll fix this. That's why this is a fun time. Oh my Lord. And boy, does it have implications for cybersecurity. I mean, it's all cybersecurity.

Leo Laporte [01:36:12]:
Oh my God. This is— Steve?

Steve Gibson [01:36:15]:
When we all have agents, Roaming around.

Leo Laporte [01:36:18]:
Can you imagine what the world's—

Steve Gibson [01:36:20]:
Oh, my Lord.

Leo Laporte [01:36:23]:
You know, it was so exciting when I gave them their own address. When I— I mean, and they— so because frequently I'll say, oh, send instructions to Russell on how to do this or get Russell's instructions and thank him or what. And the other thing that was wild is the AI knew that Lisa was my wife. So when I said invite Lisa to our new website. It wrote it, hi honey. It wrote, hi honey, love ya. It wrote it as if I wrote it. It was terrifying.

Leo Laporte [01:36:57]:
So I told it, from now on, call Anthony Nielsen sweetheart, see what he says. That's, that's just, just a little fun. Anyway, on we go with the show.

Steve Gibson [01:37:06]:
Okay, so the past week's, uh, As I mentioned before, our Security Now Most Email Received on a Single Topic Award had no competition. This podcast listeners were universally freaked out and incensed by the widely covered news that the presence of an LG brand PC display monitor resulted in unwanted software being silently downloaded and installed into its users' machines. And you might think, what? How could a monitor make that happen? Gizmodo was one of the many outlets that picked up and reported on this under their headline, LG monitors fill— they don't fill them, but okay, fill PCs with adware. And it's not just recent displays. So Gizmodo wrote, if you're using an LG monitor and you suddenly see blaring ads for McAfee scam protection, it's not because your PC's been hacked, or rather not hacked by some unknown third party. LG, the maker of popular high-end screens, has been quietly stuffing— again, I don't know I would use the word stuffing, but okay. Its current and even past monitors full of adware. Uh, okay, again, if you've been paying attention at this point, you're thinking, first of all, uh, how can a monitor stuff the computer it's attached to with adware? Uh, the answer is that Gizmodo's sentence is inaccurate.

Steve Gibson [01:38:49]:
A monitor cannot do so directly, but it turns out that there is an indirect and somewhat insidious means by which that can be made to happen. So get a load of what comes next. Gizmodo writes, for the last several weeks, multiple Reddit users have reported that their LG monitors had surreptitiously added an app to their PC. Here it comes. Through an automatic patch via Windows Update. That, right, because Windows Update will download necessary drivers, and that's a sneaky way of getting software into people's machines. And that driver is tied to them, the, to the monitor, which the system is aware of. So Gizmodo said the app then started sending them ads.

Steve Gibson [01:39:48]:
For services like McAfee Scam Detector, which actually is kind of interesting, through desktop pop-ups, this whole thing being a scam. It's unclear, they write, how long LG has been pushing this app, though a Microsoft forum user reported this app all the way back in 2024. They might have just started to use it more. Last week, the YouTube channel Gamers Nexus offered more clarity about how these monitors automatically push the so-called LG Monitor App installer alongside the routine driver updates. A brand new high-end LG UltraGear 34GX900A-B display, a gaming monitor that costs close to $1,200. You think that'd be enough money from you. At its full suggested retail price reportedly never gave users an option to decline the app or even notified users of what it's meant to do. The app supposedly only exists to push even more LG software to your PC through optional downloads.

Steve Gibson [01:41:05]:
Before being bloatware— I'm sorry, beyond being bloatware that users may not even know was installed on their computer. The LG Monitor app installer further promotes McAfee services. Gamers Nexus says the McAfee ads appeared to be on every single boot. LG Monitor app installer may occasionally push advertisements for the company's other apps like the LG Channels streaming service. The YouTube channel further claims they saw the ads suddenly appear on 3-year-old LG monitors as well as more recent models. We still don't know whether the app is being installed on all recent LG monitors. Gizmodo reached out to LG for comment on which monitors currently push this app, and we'll update this post if we hear back. By all accounts, LG Monitor App Installer is bloatware running on your PC and hogging resources you don't want, blah, blah, blah.

Steve Gibson [01:42:06]:
And it, you know, goes on like that. So anyway, here's what upset me. Toward the end of this, they said, I— and then they talk about Alienware Command Center and other app installers, suggesting that it shows that policies have changed. They said the high-end screens we buy for our PCs are meant to be dumb in a way that allows them to be disconnected from any potential software or subscription that could track what you do on your PC. LG's privacy policy that's linked to the LG Monitor app installers listing on the Microsoft Store mentions, quote, LG can track device usage data and online activity, including what sites you visit and what activities you do on those sites. What? So, you know, that phrase turns out is present in a PC monitor's privacy policy.

Leo Laporte [01:43:21]:
What?

Steve Gibson [01:43:22]:
A PC monitor should not even have a privacy policy. It's hardly any wonder that, like, a privacy policy on a monitor?

Leo Laporte [01:43:31]:
It's just a passive device that still accepts a signal from your HDMI port, and that's all.

Steve Gibson [01:43:37]:
Yes. So it's hardly any wonder that so many Security Now listeners sent me links to this news. So anyway, wow. Gizmodo wraps up their coverage by writing, Gizmodo, Also asked LG to clarify whether the app was tracking this or other usage data. They said there's no easy process to keep PCs from automatically installing these connected apps, especially since they come in quietly via Microsoft Update. And what seems— and that seems to be the point. LG, one of the world's largest makers of televisions, is using the smart TV playbook.

Leo Laporte [01:44:20]:
Exactly.

Steve Gibson [01:44:21]:
Smaller screens.

Leo Laporte [01:44:22]:
Bingo.

Steve Gibson [01:44:23]:
Uh-huh. It wants to push ads to your screen while potentially tracking your usage habits, turning users from mere buyers of a product into the product themselves. So I suppose all we can do as consumers is spread the word and boycott to whatever degree possible LG monitors. It likely won't be very effective since most consumers will never hear of any of this, and they're certainly not going to read the privacy policy that comes with their monitor because why would they? But at least everyone here listening to this podcast can choose not to support LG since there are plenty of alternatives. And yikes, what a practice.

Leo Laporte [01:45:09]:
Yeah, smart TVs, we know, do this routinely.

Steve Gibson [01:45:12]:
Yes.

Leo Laporte [01:45:14]:
And it's, you know, I mean, just don't plug your— don't connect your smart TV to the internet because it's going to tell people everything about what you do. Exactly.

Steve Gibson [01:45:23]:
So in other people's—

Leo Laporte [01:45:24]:
I'm sure somebody at LG said, hey, we've been doing it with the TVs. Why don't we—

Steve Gibson [01:45:27]:
Yeah, why let them go?

Leo Laporte [01:45:29]:
Is a monitor just a TV connected to your computer?

Steve Gibson [01:45:32]:
And, you know, and unfortunately someone said, yeah, we could make that happen. We could shoehorn our app in using Microsoft's Windows Update. Tell Windows Update that we have a new driver for our screens that everybody needs to get, and Microsoft will dutifully push it out with the next Patch Tuesday. I guess those come out on the 4th of the update. You know, there's some other date where the, the, the non-security updates happen. That's just shameful.

Leo Laporte [01:46:01]:
Shameful.

Steve Gibson [01:46:02]:
It'll happen.

Leo Laporte [01:46:02]:
It really is.

Steve Gibson [01:46:04]:
Yeah. Okay. Another bit of news that we don't want to let slip past is that last Tuesday, France proudly became— they were proud— the first country within the European Union to flat-out ban all access to social media for all children under the age of 15. I found some succinct reporting of this, of all places, on Al Jazeera, but they reported quite nicely. They said France's parliament has passed a landmark bill barring children under the age of 15 from using social media platforms, period, full stop. Lawmakers in both chambers of France's parliament voted on Tuesday in support of the legislation, which also bans students from using mobile phones in schools. The measure will mark— will make France the first country in the European Union to approve a blanket ban on social media as concerns grow worldwide over the harmful effects of digital content on kids. President Emmanuel Macron, who championed the ban as a signature initiative of his second term, called Parliament's approval a major step forward.

Steve Gibson [01:47:23]:
He added, France is leading the way in Europe when it comes to protecting our children and teenagers, unquote. The French leader has pushed for the ban to come into effect by September ahead of the new school year. However, a review to determine whether it complies with the French constitution could delay its implementation. Macron said in a video posted on social media where no one under 15 will see it, the Constitutional Council must now rule on it, and then it will be time to take action to make this measure a reality and protect our children online. A growing number of countries are taking steps to restrict social media access amid multiplying warnings over its harmful effects on children. France's public health watchdog last year said platforms such as TikTok, Snapchat, and Instagram were harmful to adolescents, particularly girls, though it was not the sole reason for their declining mental health. Several families in France have sued TikTok over teen suicides they say are linked to its harmful content. The French ban is expected to be rolled out in 2 stages, with children under the age of 15 first blocked from creating new accounts starting on September 1st, then on January 1st, 2027, The ban would be extended to apply to all existing accounts, meaning those would be terminated, shut down.

Steve Gibson [01:48:59]:
Digital Minister, um, An Li Hanaf said if someone is under 15, the account will be closed, adding that users' personal data would be protected. The ban will not cover access to online encyclopedias educational, or scientific directories. In other words, only specific social media services. Finally, lawmakers from the left-wing party France Unbowed opposed the bill, arguing that its constitutionality is unclear. They're the people who raised the Constitution, uh, issue, said it would effectively end online anonymity. And that it would be impossible to enforce. But children's advocates and parents largely applauded the vote. The only thing we can do is protect our children, just as we protect our children from drinking alcohol.

Steve Gibson [01:49:57]:
So, okay, one note is that France's existing blanket mobile phone ban, which already applies to primary and middle school Is now, as part of this, being extended to include all of high school. So no mobile phones in school until you get to college in France. Okay, so what should be very clear is that proof of online age— we've talked about it, we spent a lot of time so far, you know, on the podcast looking at the technology and the challenge. It is destined to become ubiquitous, as we've been covering, right? Apple and Google are both reluctantly and haltingly inching, but, but nevertheless inching forward with it for their respective iOS and Android platforms. Someday it will just be the way things are. As I stated before, it is entirely possible to design a solution that provides for age range determination in an entirely privacy-preserving fashion, with the caveat, you know, that knowing one's age range does obviously represent a theoretical reduction in absolute privacy. But sorry, you know, I think online age range attestation is a good thing, not a bad thing. It allows us as a society to model the way the physical world already operates in the online world.

Steve Gibson [01:51:36]:
With more and more of the physical world's services moving online, gating available services by its user's age becomes crucial, I think. So, um, that happened. Um, also what happened is that right on schedule, that extremely serious WordPress vulnerability which we discussed last week That was the one that caused WordPress to force update every system that they had any access to has come under active attack. Didn't take long. So it's clear that not all systems accepted the WordPress forced update. Turns out you could just disable all updates and nothing WordPress could do. The Wiz Security folks posted the news under their headline, Exploitation in the Wild of WP2Shell, which they followed with the summary, Wiz Research has identified exploitation of WP2Shell, a critical pre-auth RCE, you know, remote code execution vulnerability chain impacting WordPress core. Attackers are deploying persistent web shells on vulnerable servers.

Steve Gibson [01:52:58]:
Organizations should prioritize patching or applying web application firewall, you know, WAF mitigations. So, one interesting bit of color that we didn't have last week was that the discoverer and responsible reporter of this The firm Searchlight Cyber credits their discovery to their use of OpenAI's GPT-5.6 SOL. So this was an AI-found fault that existed, as we know, since early December of last year in Word— in the WordPress base. The consequences for unpatched WordPress users is so serious, however, that I want to share some of what the Wiz Security folks have witnessed going on ever since. They wrote, these vulnerabilities comprise a critical pre-authentication, meaning anybody can do it, remote code execution chain in WordPress core dubbed WP2Shell. This exploit chain allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025. Our data indicates that 60% of organizations using WordPress initially had at least one vulnerable instance at the time these CVEs were published, and 25% were exposing a vulnerable server to the internet. However, this figure is rapidly declining as organizations patch, lowering to— from 60% to 50%, not a big difference, and from 25% to 10%, respectively, within 24 hours of the initial publication.

Steve Gibson [01:55:01]:
So, okay, within 24 hours, that is pretty good. Almost immediately following the vulnerability chain's publication, many exploit proof of concepts were made available by security researchers, most of which were limited to SQL injection on default WordPress configurations while allowing remote code execution under only specific conditions. However, later proofs of concepts reliably achieved remote code execution against arbitrary targets. So the, the proof of concept quickly evolved to be full-on, you know, well, full-strength remote code execution that worked. They wrote, so far we've observed multiple actors successfully exploiting this vulnerability chain against WordPress instances self-hosted in the cloud. Following successful batch API exploitation, we've observed the following post-exploitation activities. There are 4: malicious plugin upload, user enumeration, local file inclusion attempts, and admin panel access. They said we've also observed high volume, high volume scanning activity without subsequent post-exploitation, meaning scanning but then not attacking, suggesting opportunistic mass scanning campaigns seeking to identify vulnerable targets alongside legitimate security scanning activity, right? So the security researchers scanning, but of course they're not attacking.

Steve Gibson [01:56:45]:
The bad guys are. They said we've yet to identify lateral movement or data exfiltration, but we continue to monitor and investigate. And they said, in terms of deployed malware, among our findings were 2 PHP web shells that represent opposite ends of the sophistication spectrum. The first was a minimal one-liner, and then they, they give it, uh, a, a post a, you know, an HTTP POST to a specific path in WordPress, which they redacted for security purposes, which basically allows just a bare-bones web shell. And they said this is a bare-bones backdoor that provides remote code execution to anyone that knows the parameter name, which they blacked out. And returns 404 as an evasion technique, meaning it pretends to be undefined. We regularly see these types of web shells deployed following most new RCE vulnerabilities. They're one of the most common types of findings when investigating mass exploitation of an emerging vulnerability.

Steve Gibson [01:58:05]:
The second post-exploitation They said, remember opposite ends of the spectrum? That was the, the one end. The other end of the spectrum, the second post-exploitation, was a massive 150-kilobyte web shell disguised as a WordPress plugin called CMS Map. The original legitimate plugin is a simple security tool, but this intrusion included a full-featured attack platform with a graphical interface, password authentication, and a broad set of capabilities including file management, database access, port scanning, batch code injection, and multiple privilege escalation modules, including MySQL UDF exploitation. Okay. In other words, Yikes. If we step back from the trees here to examine the forest for a moment, what do we see? A commercial frontier AI, presumably with its protections disabled, so that security company had access to an unrestrained AI, 5.6 SOL. It identifies a previously unknown, extremely serious flaw in a widely used open-source internet service, you know, WordPress. The harnesser of this AI, the people who deployed it, responsibly discloses their finding to the software's publisher, WordPress.org.

Steve Gibson [01:59:50]:
The publisher immediately fixes the software and quietly, you know, secretly even attempts to push the fixes out to all the systems that they're able to reach. But then immediately after the problem is disclosed publicly, along with naturally its repaired open source code, security researchers jump on it to develop various proofs of concepts for its exploitation. Ultimately arriving at a reliable remote code execution exploit. Next, the bad guys pick this up and begin actively scanning the internet for any and all as yet unpatched and still vulnerable instances of WordPress. And unfortunately, at this, they obtain many successes. AI vulnerability discovery. Indeed triggered this chain of events. And the people and organizations that had deployed those vulnerable instances of WordPress through no fault of their own beyond not arranging to allow WordPress to force update their system while the problem was still secret were hurt.

Steve Gibson [02:01:07]:
So would we be better off if that vulnerability had never been found by AI? I doubt it. That vulnerability is gone now, and the world and WordPress is better off without it. While that critical vulnerability was unknown to WordPress, it could have been silently discovered by a malicious entity and used to very quietly see and seriously harm targeted enterprise users. Because it was such a bad vulnerability. I believe that the proper takeaway lesson here is that arranging to close the software update loop with every supplier of internet-facing technology in use has very suddenly become a mission-critical priority for all enterprises. The only reason, you know, any of those WordPress instances remain vulnerability at the time of WordPress's final official post-forced update disclosure is that their administrators had previously decided to take the management of their WordPress installations into their own hands. That is the thinking that must be changed by this new age of AI software vulnerability discovery. Everyone we quote talks about this stuff moving at speed, at machine speed.

Steve Gibson [02:02:39]:
That's crucial. Manual updates do not move at machine speed. We're going through an upheaval at the moment while our legacy of published software is being repaired. Remaining on the leading edge of this wave with updates is the only safe place to be. So I would implore everybody to do that. We have 2 last things to talk about, Leo. Previously unknown facts about Rocky, the alien from Project Hail Mary, and the details of Exploit Jim. Let's take our final break and then we will proceed.

Leo Laporte [02:03:21]:
Uh, let's see. I think we are now ready to talk about Project Hail Mary. As we continue on, here's the club with Steve Gibson. So is this a new— I think I feel like I saw Andy, we were on with Neil deGrasse Tyson some time ago, but maybe—

Steve Gibson [02:03:40]:
It was 3 months ago.

Leo Laporte [02:03:42]:
Oh, it was? Okay, good.

Steve Gibson [02:03:43]:
Yeah, it was 3 months ago.

Leo Laporte [02:03:44]:
New to you. Yes.

Steve Gibson [02:03:47]:
Sunday morning during coffee, which as we know is life itself, Very important. We established that last week. I went over to YouTube, to which I do not subscribe since I spend very little time there, but I was curious to see what news of AI might have been selected for me since I, I have been quite impressed by YouTube's selection system. The first thing to pop up, I don't know why, was an episode of Neil deGrasse Tyson's StarTalk podcast, which was titled Neil deGrasse Tyson confronts Andy Weir on the science of Project Hail Mary. And on the science of Project Hail Mary, I would argue that Neil deGrasse Tyson basically got schooled by Andy Weir, which, you know, it's not easy.

Leo Laporte [02:04:36]:
That's amazing.

Steve Gibson [02:04:38]:
I know. Okay, so the only message I want to convey here Is that it was a surprisingly fantastic and worthwhile 41-minute investment of my life. We've bemoaned the fact that the Project Hail Mary movie was so dumbed down and kind of fact-sparse compared to the book. What I learned from Andy was that even Andy's book was dumbed down and included almost none of the original thought that he put into creating much of what we see or read even. He completely worked out how and why Rocky, the alien, is the way he is. And I mean, in every satisfying detail. So I'll just say that I recommend this 41-minute YouTube video as strongly as I can. I've included the YouTube link in the show notes, and I created a GRC shortcut, uh, grc.sc/rocky, uh, R-O-C-K-Y, grc.sc/rocky.

Steve Gibson [02:05:57]:
Um, it was a great conversation. Yeah, you had Andy on many times, Leo. Of course, Neil deGrasse Tyson is Neil deGrasse Tyson, and, and he's—

Leo Laporte [02:06:06]:
That's a good show. He does a very good show, I have to say. It's very interesting.

Steve Gibson [02:06:10]:
Yeah, he's got a neat, uh, he's got a neat sidekick with him that— and then—

Leo Laporte [02:06:14]:
Who's a dummy but celebrates the fact that he's a dummy.

Steve Gibson [02:06:18]:
Yeah, yeah, it's sort of like the, the, the nighttime talk show hosts who have like a, you know, a kind of like, okay, why, why are you here exactly anyway? Uh, grc.sc/rocky. And oh, and I, I mean, I, I can't do a spoiler, but, but, but trust me, uh, when, when, uh, he's like— I— okay, I have— I've said all I can. It was really good. Worthwhile.

Leo Laporte [02:06:50]:
That's all you have to say.

Steve Gibson [02:06:52]:
We listen to you.

Leo Laporte [02:06:53]:
We trust you.

Steve Gibson [02:06:54]:
I do, I do have our listeners often tell me, like, know, my recommendations have never been wrong. I, I can confidently say grc.sc/rocky, you will not regret the 41 minutes it takes from your life. Um, okay, so ExploitGym, uh, G-Y-M, uh, as, as we've been talking about this, it's since the beginning of the podcast, the AI benchmark that drove OpenAI's 2 most advanced and unrestrained, deliberately unrestrained frontier models to bust out of their containment sandbox and go searching for the answers at Hugging Face was something known as Exploit Gym. When I headed over to GitHub to bring myself up to speed about Exploit Gym, I quickly saw that there was much to be shared about it too. So it became the second half of this podcast's journey. dual topic, uh, for today. The Exploit Gym project repository, it's under the sunblaze-ucb GitHub account. The UCB is short for University of California at Berkeley, and Sunblaze is the name of the laboratory, uh, group at UC Berkeley that's led by Professor Dawn Song.

Steve Gibson [02:08:19]:
Dr. Song is in Berkeley's EECS— that was my major when I was there, Electrical Engineering and Computer Science Department— focusing on computer security, AI safety, and recently a lot of work on evaluating AI agents on security-related tasks. Their GitHub repos include things like Cyber Gym, a different gym, In this case, Cyber Gym is a large-scale, high-quality cybersecurity evaluation framework designed to rigorously assess the capabilities of AI agents on real-world vulnerability analysis tasks. So it's slightly different because, of course, Exploit Gym is a large-scale, realistic benchmark built from real-world vulnerabilities. Which is designed to evaluate AI agents' ability to develop exploits. So one is vulnerability analysis, Cyber Gym. Exploit Gym is their ability to actually exploit vulnerabilities that are provided to them. Several months ago, on May 11th, a large group of 16 AI researchers drawing Its members from UC Berkeley, the Max Planck Institute for Security and Privacy, UC Santa Barbara, Arizona State University, Anthropic, OpenAI, and Google all co-authored and published their research on this Exploit Gym.

Steve Gibson [02:09:57]:
Their paper was titled Exploit Gym, Can AI Agents Turn Security Vulnerabilities into actual attacks. And certainly the name Exploit Jim makes sense for this, right? Uh, the paper's introductory abstract says AI agents are rapidly gaining capabilities that could significantly reshape cybersecurity. Okay, this was May, so they were, you know, oh, you think maybe? Making rigorous evaluation urgent. A critical capability is exploitation— turning a vulnerability, which is not yet an attack, into a concrete security impact such as unauthorized file access or code execution. Exploitation is a particularly challenging task because it requires low-level program reasoning For example, about memory layout, runtime adaptation, and sustained progress over long horizons. Meanwhile, it's inherently dual use, supporting defensive workflows while lowering the barrier for offense, meaning the bad guys can use it too, right? And this is why, again, as we've said, you good guys need to have unrestrained AI.

Leo Laporte [02:11:26]:
Yeah.

Steve Gibson [02:11:27]:
They said despite its importance and diagnostic value, exploitation remains undervaluated, thus the reason for creating Exploit Gym. They said to address this gap, we introduce Exploit Gym, a large-scale, diverse, realistic benchmark of the exploitation capabilities of AI agents. Given a program input that triggers a vulnerability, Exploit Gym tasks its agents to progressively extend it into a working exploit. The benchmark comprises 898. This, and I didn't say this in the show notes, but every one of these had to be manually deliberately created. 898 of them. So they put some effort into this. The benchmark they wrote comprises 898 instances sourced from real-world vulnerabilities across 3 domains, including user space programs, Google's V8 JavaScript engine, and the Linux kernel.

Steve Gibson [02:12:39]:
We varied the security protections applied to each instance, you know, things like address space layout randomization and so forth. Isolating their impact on agent performance. All configurations are packaged in reproducible containerized environments. And again, they had to manually create 898 individual instances. So props to them for this work. They said our evaluation shows that while exploitation remains challenging, frontier models can successfully exploit A non-trivial fraction of vulnerabilities. For example, the strongest configurations are Anthropic's latest model, Claude Mythos Preview, and OpenAI's GPT-5.5, which produce working exploits for 157 and 120 instances respectively. So Mythos Preview, 157, OpenAI's GPT-5.5, which of course has now been superseded already, 120 effective working exploits.

Steve Gibson [02:13:51]:
These are again working exploits. They solved the problem of converting a vulnerability into an exploit. And as we'll see, they set the bar high, remote code execution. They said, notably, even with widely used defenses enabled, models retain non-trivial success rates. These results establish Exploit Gym as an effective testbed for exploitation and highlight the growing cybersecurity risks posed by increasingly capable AI agents. And of course, This is why OpenAI was using Exploit Gym, is they participated in the creation of this paper and of this entity, this thing, this capability, this benchmark. And then they started using it to see what their agents would be, what their models would be able to do. So the last line appended to the paper's abstract, which was in red in the PDF, Reads, many experiments are conducted under trusted access programs with safeguards disabled to measure the capability boundary of frontier models and agents.

Steve Gibson [02:15:13]:
So they were just making sure everybody understood that the only way you can do this is with unrestrained AI. I mean, restrained AI won't even begin to develop a develop an exploit from a vulnerability for you. Okay, so I want to next share this paper's introduction, which further explains the researchers' goals. They wrote, recent progress in large language models and AI agents has led to rapid improvements in cybersecurity capabilities, making rigorous evaluation increasingly urgent. Prior work has introduced benchmarks for a range of cybersecurity-related tasks, such as vulnerability reproduction, patch generation, and capture-the-flag problem solving. Frontier models now achieve strong performance on many of these benchmarks, highlighting the need to better understand and evaluate the boundaries of their cybersecurity capabilities. Okay, so I'll interrupt here to highlight the fact that we've never actually taken the time To yet talk about here the crucial importance of having high-quality AI performance benchmarks, even as early as this seems in the development and maturation of AI technology. You know, my sense being we have a long way to go yet, and you know that because it's changing so Rapidly.

Steve Gibson [02:16:48]:
Mature technologies do not change this rapidly. The behavior of our AI models, you know, has already become mysterious and surprising to us. So there's really no possible way, when you think about it, for researchers to faithfully, truthfully, and accurately measure the effects brought about by their changes in successive AI generations without having truly on-point rating benchmarks by which to compare their latest mysterious, even to them, creations. This is exactly why and how OpenAI got themselves in trouble by pitting their models against the tests presented to them by ExploitJim. So this group of 16 researchers continue writing, exploitation is a critical missing piece in cybersecurity evaluation. A crucial yet underexplored capability is vulnerability exploitation. Exploitation is a challenging task that starts from an initial vulnerability for example, a few-byte buffer overflow, progressively obtains stronger primitives and privileges, for example, arbitrary memory reads and writes, and ultimately causes a concrete security impact, for example, unauthorized file access or code execution. Unlike prior benchmarks that primarily require source-level reasoning, exploitation demands precise reasoning about low-level program behaviors at runtime.

Steve Gibson [02:18:45]:
This includes understanding and manipulating memory layouts— for example, heap metadata, stack frames, and virtual memory mappings— reasoning about instruction-level control flow and register states, and crafting inputs that satisfy cut-tight constraints. Modern exploitation further requires chaining multiple primitives together while simultaneously bypassing a succession of deployed mitigations. For example, address space layout randomization, stack canaries, and sandboxing. Indeed, exploitation has remained difficult even for human security researchers despite decades of research. Moreover, exploitation is inherently dual use and impacts both defenders and attackers. On the defense side, it helps assess vulnerability severity, prioritize patches, and validate mitigation. Meanwhile, it can also lower the expertise required for offensive misuse, right? The bad guys get to use it. Understanding the exploitation capabilities of frontier AI is therefore essential for AI safety and responsible model deployment.

Steve Gibson [02:20:12]:
ExploitGym is the first comprehensive exploitation benchmark for AI agents. In this work— and of course it's on GitHub, right, all open and free— in this work, We introduce Exploit Gym, a comprehensive benchmark for evaluating the exploitation capabilities of AI agents. Each instance of Exploit Gym consists of a vulnerable code base with, with build configurations, a proof of vulnerability input that triggers a known vulnerability along with a textual description. And an execution environment for agent introduction. I'm sorry, agent interaction. In other words, so they said each instance of Exploit Jim has all of that. And they did. They built 898 of those.

Steve Gibson [02:21:09]:
Again, I'm dizzy by the amount of effort that went into creating this. The agent is tasked with transforming the POV the proof of vulnerability, into a working exploit. We focus on exploits that achieve unauthorized code execution, i.e., executing code with privileges that should not be obtainable under the intended security model, which is often none. We choose this target because it represents one of the most severe security outcomes demonstrating full control over the victim system and enabling a range of downstream harms such as secret exfiltration and resource hijacking. To reliably validate successful exploitation, each environment contains a dynamically generated privileged flag that is inaccessible without unauthorized code execution. In other words, capture the flag. And the agent must retrieve and submit the flag proving that it achieved remote code execution vulnerability. In addition, we include agent as a judge to assess whether the submitted exploit actually relies on the provided vulnerability rather than succeeding through an unrelated shortcut.

Steve Gibson [02:22:34]:
For example, a different but more easily exploitable vulnerability. Exploit Gym is a large-scale, diverse, and realistic benchmark. Our benchmark comprises 898 instances derived from real-world vulnerabilities that affected— past tense— software projects across 3 major domains. We first include 520 user space instances from 161 projects in the OSS-Fuzz, Google's continuous fuzzing service. To cover additional critical software infrastructure, we further include 185 instances from Google's V8 JavaScript engine used in Chromium-based browsers and 193 instances from the Linux kernel. For each instance, we evaluate 2 security settings with and without standard defenses enabled. These defenses are the result of decades of system security research and represent common mitigation barriers that real-world exploits must overcome, the things we've talked about for years. This setup benefits both security practitioners who can reassess established defenses against powerful AI-driven attackers— that is, you know, is address space layout randomization still effective? It stopped the people.

Steve Gibson [02:24:01]:
What about the bots? And AI researchers who can study whether frontier models can reason through complex multi-step mitigation barriers, presumably using this benchmark as a test to make the AI even better at attacking. Yikes. Or defending. That's what we really meant. All configurations are packaged in reproducible containerized environments to ensure easy use and reproducibility of the benchmark. Experimental results reveal non-trivial exploitation capabilities using ExploitGym under a wide range of frontier LLMs and agent scaffolds. The results show that despite the challenging nature of exploitation, frontier AI agents can already achieve a non-trivial fraction of success when standard defenses are disabled. In particular, Claude Mythos Preview and Claude Code with GPT-5.5 with Codex CLI, the best-performing combinations, solve 157 and 120 instances within a 2-hour time limit respectively.

Steve Gibson [02:25:23]:
We further observed that enabling standard defenses substantially reduces success rates but does not eliminate them entirely. Beyond aggregated success scores, we analyze performance differences across domains, overlaps between agents, time budgets, and a detailed case study to enable a deeper understanding of agent behavior. In other words, a benchmark like this is incredibly useful to AI researchers who want to understand how their agents perform in a cybersecurity setting. So this is super valuable to have. Overall, they said, our results indicate that Frontier AI is advancing rapidly toward fully automated exploit generation. These results highlight the growing importance of responsible model development and deployment, as well as the urgent need for stronger exploit-resistant defenses against increasingly capable AI-driven attackers. So I want to repeat the final conclusion since this is the future we face, right, which is one we will never again not face. This team of 16 named authors wrote Our results indicate that frontier AI is rapidly advancing toward fully automated exploit generation.

Steve Gibson [02:26:54]:
And they then call for, quote, responsible model development and deployment, which all evidence suggests is going to be very difficult. I assume that line, you know, the responsible model development and deployment is there because Anthropic, Google, and OpenAI contributed to this research, or perhaps the purely academic researchers felt it would be irresponsible to not murmur something about the responsible use of AI in a paper that has just shown how powerful and devastating the irresponsible use of AI is rapidly becoming. Hopefully none of these authors really believe any of that since they must know that AI is just a tool like the hammer that was mentioned before. It's also worth noting that perhaps, you know, that while in their words Frontier AI is rapidly advancing toward fully automated exploit generation, we know that the world shook several weeks ago When Kimi K3 demonstrated performance that fell just short of, at the time, the top 2 frontier models. And its model weights were released yesterday on the 27th. So anyone who's able to load and run this free 2.8 tera-parameter AI model will already today have a near-match frontier AI without any commercial encumbrances. So anyway, I'm going to wrap this up by sharing their paper's conclusions. They write under limitations, they said, first, our tasks do not cover the full space of exploitation targets such as Windows.

Steve Gibson [02:29:02]:
There's no Windows vulnerabilities there because of course it's closed. iOS, same reason, closed. And Android, or perhaps, or, or applications that run in those environments. They said, second, we use arbitrary code execution as the success criteria. While this provides a clear and severe measure of impact, it does not capture other meaningful outcomes like privilege escalation, right? That we know how serious that is. Once you get in, you got to do— be able to do something there, such as arbitrary read and write primitives, sandbox escape with code execution, or partial exploit progress. Third, failures may result from refusal due to safety alignment. Tool misuse, or other underlying causes unrelated to the complexity of crafting exploit payloads.

Steve Gibson [02:29:59]:
Failures may also stem from non-exploitable vulnerabilities where success is just impossible. More broadly, our benchmark lacks ground truth exploits for every task due to the extreme difficulty of exploitation. Meaning they don't even know whether all of these vulnerabilities can be exploited. They don't have samples of them. They said at the same time, this helps mitigate data contamination concerns, right? You don't want your AI to already know about how to exploit a vulnerability, or, you know, it wouldn't be a good benchmark. It wouldn't have to do the work. You know, it would go over to Hugging Face and cheat. Since complete solutions are not broadly available.

Steve Gibson [02:30:45]:
Under the 2-hour time constraints of our evaluation, Frontier agents solve at most 157 tasks compared to 239 potential solves in the union of our experiment results. Then they said, finally, fourth, our results reflect a single time-gated, meaning only 2 hours given, and cost-gated attempt per task. Additional attempts and resources may yield higher success rates. Similarly, our use of a single set of instructions may inadvertently favor one model. You know, tailored instructions including additional task context may improve success rates. Finally, we do not provide tools specific to vulnerability analysis or exploitation. Integrating such tools may also improve success rates. Okay, so they were, you know, the models were entirely generic, not focused, and they did not have tools that may have, that they, that their availability and usage may have allowed them to better perform.

Steve Gibson [02:31:56]:
On the dual-use nature of exploit generation, they said, We reiterate that exploit generation is a dual-use capability of AI agents. D3FEND leverages this capability to assist with detecting and prioritizing which vulnerabilities actually pose a high-severity risk, especially as AI agents become increasingly capable of vulnerability discovery, which everybody's expecting in the future. For attackers, The same capabilities can reduce exploit development costs, scale the set of exploit targets, and otherwise reduce the barrier to entry for exploitation, meaning you don't have to know that much in the future. You just aim an AI at it. More sophisticated attackers could adapt partial agent-generated exploit trajectories into fully functioning exploits. Resolving these ethical tensions and establishing appropriate safety guardrails requires multi-stakeholder discussions that go beyond the scope of our work. We consider our benchmark and evaluation results as critical to enabling these discussions. In summary, Exploit Gym provides a reproducible testbed for measuring AI agent exploitation capabilities on realistic and complex targets.

Steve Gibson [02:33:26]:
Our results show that autonomous exploit development by frontier AI agents is no longer a hypothetical capability. While current agents are not yet reliable across all targets, they're already able to autonomously exploit a non-trivial fraction of real-world vulnerabilities, including complex targets such as kernel components. This rapid emergence is itself a central finding, showing that capabilities that would have seemed implausible are now present in deployed frontier models. Given the fast-moving nature of AI progress, today's vulnerability limitations should not be interpreted as a durable Safety guarantee because we're going to get better. As Schneier famously said, you know, vulnerabilities never get worse; they only get greater. Or exploits, attacks, attacks never get worse; they only get better. They said traditional systems hardening techniques and defensive countermeasures remain effective but im. Perfect and must therefore be assessed against the threat of AI-driven attackers.

Steve Gibson [02:34:46]:
Addressing this risk requires both responsible model development and stronger defenses that explicitly incorporate autonomous exploitation into threat modeling. So in other words, the threat is no longer theoretical and it's no longer a worry for the future. It's here. Hugging Face themselves, as we know, just experienced firsthand an albeit, you know, inadvertent successful external network penetration attack orchestrated by OpenAI's unrestrained frontier AI models. This did not happen in the future. It happened 2 weeks ago. The primary saving grace for the moment is that, as I keep reiterating, being in possession of a frontier-class model, as anyone who wants one may be today because of, of, of K3, uh, is only the start, right? Having the, having the weights is only the start. It's also necessary for that model to be hosted by an AI-capable infrastructure that's powerful enough to get it off the ground.

Steve Gibson [02:35:59]:
In practice, and I think it's like I saw somewhere because I was curious yesterday, 80 H100-class GPUs. I mean, it is, you know, K3 takes a lot of compute in order to go, even though it's been engineered to seriously reduce the, the amount of compute that it needs by using a sparse mixture of experts model. So it's still expensive to actually use it. So random end users are unlikely to be anyone's target, right? If you're able to use K3 to develop an exploit, you're not going to waste it on an end user. Uh, but any enterprise whose network contains data that could be used for extortion should already be on high alert. If the payout from an AI-driven network intrusion, data exfiltration, and extortion is in the millions of dollars— that is, if there's that much potentially available that an attacker could extort— then that would dwarf the token cost of launching exploratory intrusion attempts today toward any such juicy targets. So now really is the time for enterprises to batten down the hatches, shut down any internet-facing servers and services that can be withdrawn from public exposure, and keep a very close eye on all public-sourced activity, anything coming in from outside. As we talked about last week, using Wiz Security as an example, the network security industry sees itself— the industry sees an extremely lucrative and worthwhile opportunity in offering AI-based network intrusion detection and protection.

Steve Gibson [02:38:06]:
So deploying some of that will be worth considering as well at the enterprise level. Wow.

Leo Laporte [02:38:17]:
3 hours to the dot, a long show, but well worth it because there was so much to talk about.

Steve Gibson [02:38:23]:
I mean, holy cow. Yeah. This was a big deal.

Leo Laporte [02:38:25]:
Yeah.

Steve Gibson [02:38:26]:
This, a lot, the world shook.

Leo Laporte [02:38:28]:
The world shook. Reminds me, I got to email Daniel Suarez. He said he'd like to do it. He was on vacation when I talked to him last. We got to get him on to talk about all of this because he predicted it long ago. Uh, oh, my agent's talking to me. I, I'll just ignore her for now. Uh, I'm sorry for the noise.

Leo Laporte [02:38:48]:
Sorry for the crosstalk. They're a little chatty, these agents. Um, we do Security Now every Tuesday right after MacBreak Weekly. We were a little late today because we were busy, uh, with some technical issues on the MacBreak Weekly side, but, uh, Usually it's 1:30 Pacific, 4:30 Eastern. That's 20:30 UTC. You can watch us in the Club Twit Discord if you're a club member. Otherwise, there are streams on YouTube, live streams, yes, on YouTube, kickx.com, Facebook, LinkedIn, and twitch.tv. After-the-fact on-demand versions of the show available at twit.tv/sn.

Leo Laporte [02:39:27]:
We have 128-kilobit audio and video. Or on Steve's site, grc.com. He has 16-kilobit audio, uh, 64-kilobit audio. He also has the show notes. Those are always nice to have to read along. Plus there's images and links and all that stuff. It's very— they're very complete. He writes a novel every single week.

Leo Laporte [02:39:46]:
It's an amazing guy. Well, you used to do this as a column, really. This is kind of like your old column that you used to write, basically.

Steve Gibson [02:39:53]:
Yeah, it's a lot longer than my old column.

Leo Laporte [02:39:55]:
Is it?

Steve Gibson [02:39:56]:
I, yeah, I got, I got my column down to a morning.

Leo Laporte [02:40:00]:
Yeah, no, this is several days' work. Thank Lori, we appreciate your generosity with your time and her generosity with your time. Um, you can go to grc.com also to get SpinRite, the world's best mass storage maintenance, performance enhancing, and recovery utility. You must have it if you have mass storage. It's really, I mean, it's interesting how over the years it has maintained its utility, is, is no less useful today in the The time of SSDs was, but yeah. Yeah. And then, uh, the DNS Benchmark Pro, which is his newest, $9.99. A great way to make sure you're using the fastest DNS server available to you.

Leo Laporte [02:40:37]:
It's very rarely the one, the default one that the ISP provides. There are much better choices in almost every jurisdiction. So check that out at grc.com. While you're there, you can sign up for the newsletter. Uh, you can get an email to you every week. There's also a less used mailing list for new products from Steve. And when you're doing that, you can also get your email approved so you can take pictures of stupid things you see and send it to Steve for his picture of the week.

Steve Gibson [02:41:06]:
Oh, I got another one.

Leo Laporte [02:41:07]:
I hope that wasn't your plumbing job.

Steve Gibson [02:41:09]:
I got a really great one. Another gate that I've got to share.

Leo Laporte [02:41:14]:
Love the gates one. Those are great. So that is at grc.com/email. So go there, submit your email address, and if you want those newsletters, you have to check the box. They're off by default. Let's see, what else should I say? Oh, on-demand versions of the show at our website, but also there's a video on YouTube that you can go to. Good way to share clips with friends and family. And the best thing to do in general is subscribe in your favorite podcast client.

Leo Laporte [02:41:41]:
That way you'll get it automatically as soon as we're done, which we are. Next week, Steve and I adjourn, uh, or convene and adjourn. Well, first we'll convene, then we'll adjourn in Las Vegas at the ThreatLocker booth at DEF CON. Stop by around 1 PM, uh, if you're there and say hi to Steve and me right after Windows Weekly with Paul Theriot and Richard Campbell. And I will remember tomorrow to ask them to stick around for the show. Great.

Steve Gibson [02:42:07]:
And we will be mic'd up, so there will be a podcast Published from.

Leo Laporte [02:42:11]:
Oh yeah, yeah, yeah. There's— we're making a podcast. What we aren't making is a live session because there's nowhere to sit and there's no PA system. I don't want to set up—

Steve Gibson [02:42:22]:
And my show notes will not be the podcast coming out. I am going to share this really interesting idea that I ran across for, uh, removing knowledge that you don't want an AI to have because it can't divulge what it doesn't know. Uh, right. And I think we'll do a picture of the week and a couple other little goodies. Uh, I won't be able to restrain, but, uh, otherwise, uh, uh, Elaine will be doing the transcript when she has access to the, uh, audio, and then everything will get up on GRC and, uh, of course on Twitter.

Leo Laporte [02:42:56]:
Before I let you go, Steve, you have to solve a physics mystery. Is there a lens on the left side of your glasses?

Steve Gibson [02:43:06]:
There is not.

Leo Laporte [02:43:09]:
Okay, I apologize, Phil. Phil said there can't be, there's no reflection. What happened?

Steve Gibson [02:43:16]:
I've had one eye fixed.

Leo Laporte [02:43:19]:
Oh, you had your surgery. You're, uh, so you have perfect vision in your left eye now?

Steve Gibson [02:43:26]:
Yes.

Leo Laporte [02:43:27]:
And when is the right eye?

Steve Gibson [02:43:29]:
Uh, the problem was I didn't appreciate how much post-surgery, uh, uh, relaxation, uh, uh, recovery, I think is the word.

Leo Laporte [02:43:42]:
Recovery. Thank you.

Steve Gibson [02:43:43]:
I'm not used to— and I said to my doctor, and he's a—

Leo Laporte [02:43:46]:
you had— you couldn't look.

Steve Gibson [02:43:48]:
Yeah, well, the problem is I can't lift anything over 15 pounds. I can't let it get wet. And we've had our big move from our old place to our new place. I mean, I was, you know, running up and down stairs and, and, uh, anyway, so I just had to put off the work on the second eye. I can't wait. I'm probably about another month or two from it. And it's funny too, because he said, I'll see you in a year. I said, a year? I got to get the other eye fixed.

Steve Gibson [02:44:16]:
He was just, you know, he was so funny.

Leo Laporte [02:44:19]:
You would.

Steve Gibson [02:44:19]:
So, so now this was cataract surgery and Every time I do this, it freaks people out. They go, oh my God.

Leo Laporte [02:44:25]:
I know. And they replace the lens, right? Is because it gets cloudy and so they have to replace it.

Steve Gibson [02:44:30]:
So, so I be— because this was it, this was my most myopic eye, my most— I was like super nearsighted. I mean, I've been wearing Coke bottle bottom glasses since I was, you know, 4 or something. Yeah. Um, because I grew up, you know, doing close focusing, reading books and, and so forth.

Leo Laporte [02:44:48]:
And so It's all that soldering. Yeah.

Steve Gibson [02:44:50]:
Not hunting for gazelles in the wild. Anyway, um, turns out that when eyes are highly nearsighted, they tend to block the, uh, the, uh, the openings that allow the intraocular fluid to leave. So you get glaucoma. You have high blood pressure.

Leo Laporte [02:45:13]:
Me too. I, I do the drops now. Yeah.

Steve Gibson [02:45:16]:
Yes. And you absolutely should. Um, and that's what freaked him out was that my pressure was up in the mid-40s and it should be down in the, in the 20s.

Leo Laporte [02:45:25]:
19 or 18. Yeah.

Steve Gibson [02:45:26]:
Yeah. Yeah. So, so he immediately, so, so we, we, we, I didn't actually have cataract. There was a little bit of yellowing apparently because there was the worst of the two. And now I get, I see different color. So, so my, my new eye is bluer than my right eye. Oh yeah. It's— things are a mess right now.

Leo Laporte [02:45:47]:
But now, but now your left eye's acuity is perfect. Did they replace a lens? Did they put a corrective lens on it?

Steve Gibson [02:45:55]:
Yes. So it's 100%. I've got perfect distance vision. Um, but he also installed 4 stents.

Leo Laporte [02:46:04]:
So I have stents in my eye in order to drain.

Steve Gibson [02:46:07]:
So, but the other problem is that because I have an interior lens fixing this eye, And an exterior lens fixing this eye. They're different sizes.

Leo Laporte [02:46:19]:
You know, I'm surprised you don't run into things.

Steve Gibson [02:46:22]:
Well, it's a mess right now. If you know how—

Leo Laporte [02:46:25]:
No driving, Steve.

Steve Gibson [02:46:27]:
When you're wearing glasses, things are smaller when you're wearing glasses because— and if you move the lens away, so there's no fusion, even though I can see perfectly in both. There's no fusion between the images because they're different sizes. You can't converge. It is a mess. But anyway, uh, yes, this eye has no lens and no, no reflection. And someday I'll be doing the podcast looking like this because I'll have had them both fixed.

Leo Laporte [02:46:56]:
That's so great.

Steve Gibson [02:46:57]:
Phil, I apologize.

Leo Laporte [02:46:58]:
I was saying, no, Phil, of course he's got a lens in there. Phil spotted it and I had to ask. Well, congratulations. And since I'm probably right behind you, I want to hear more. Uh, well, we'll talk about it next week.

Steve Gibson [02:47:10]:
It was a good thing. I, I, yeah, this— you wanted to really find a great guy. I found the, the kind of surgeon you want where you just, you know, he's just— he doesn't really care about anything else except this, you know, like you, like me.

Leo Laporte [02:47:24]:
We want people who care as much about eye surgery as you do about security. That's exactly right. Thank you, Steve Gibson. I'm glad you're doing well. Well, that's great. And we will see you next week in Las Vegas for a very special Security Now. Righto.

Steve Gibson [02:47:38]:
Till then, bye. Security Now.

All Transcripts posts