Transcripts

Security Now 1097 transcript

Please be advised that this transcript is AI-generated and may not be word-for-word. Time codes refer to the approximate times in the ad-free version of the show.

 

Leo Laporte [00:00:00]:
It's time for Security Now. Steve Gibson is here. Lots to talk about. Amazing problems that cropped up after Microsoft's Patch Tuesday. Steve will run through those. We'll also talk a little bit about the AI doomers and why Steve's not at all worried. He also has his thoughts about the EU Kids Act, which I suspect you already know, but you might want to listen. Security Now is coming up next.

Steve Gibson [00:00:30]:
Podcasts you love. From people you trust.

Leo Laporte [00:00:35]:
This is TWiT. This is Security Now with Steve Gibson, episode 1097, recorded Tuesday, September 22nd, 2026. Mega Patch Tuesday Fallout. It's time for Security Now. Yay! Tuesday is here and so is Mr. Steve Tiberius Gibson. Do you think when you're 95, Steve, you'll be doing heavy metal concerts like William Shatner is doing now?

Steve Gibson [00:01:07]:
He is amazing.

Leo Laporte [00:01:08]:
He's wild. He is. He—

Steve Gibson [00:01:11]:
I just think it's great. And, and I loved that when, when someone said, what is your secret to longevity? Like, how— like, what can you tell us? And he said, don't die.

Leo Laporte [00:01:22]:
Yeah, that's the best advice ever. Steve, what are we covering on today's mega episode?

Steve Gibson [00:01:32]:
So yes, uh, for Security Now 1097, uh, the second to this— and this is the penultimate September episode.

Leo Laporte [00:01:42]:
He just likes to use that word, kids.

Steve Gibson [00:01:44]:
So now I know what it means. Uh, we can—

Leo Laporte [00:01:48]:
we're—

Steve Gibson [00:01:48]:
I want to spend some time talking about the Consequences of Microsoft's Mega Patch Tuesday. We touched on last week, oh, well, they broke copy and paste for Excel, which you didn't think was a big deal. Of course, all the people whose workday is Excel spreadsheets, they were quite discomfited by that. Turns out that wasn't even the tip of the iceberg. of what happened. So it's interesting that on, you know, the good news is that nearly 1,000 big problems— there were what, 119 or 117 critical problems solved a couple weeks ago? Those are gone from Windows. Turns out though that there was some fallout from all of that, which we're going to talk about. But first, I wanted to pull in some expert opinion about all of this AI doomsdaying.

Steve Gibson [00:02:50]:
Andrew Ng weighed in just a couple of days ago. Of course, he's somebody who knows something about AI. I want to share his thoughts about that. Also, he referred to an individual who actually knows something about the bio-risks of AI. So we're going to hear from somebody who, who's actually been there, who is actually both an AI expert and somebody who's made viruses, so is able to, to cross over as one would have to. Also, you and I were talking about this before, but it's very interesting that, that all of these breakouts had a single locus that nobody else I haven't seen anybody else in the industry talk about this.

Leo Laporte [00:03:43]:
I mentioned it on Sunday, I'm proud to say.

Steve Gibson [00:03:45]:
Good, because we're going to talk about what I call the wisdom of outsourcing AI security testing. I bet everyone's going to stop that in the future. Also, we've got the EU trying to push their Kids Act, and boy, this one is even messier than the things they've tried before. Nightmare Eclipse has finally unmasked himself. We know the backstory behind that, which we'll take a look at. Also, a white hat firm, a security firm, used Claude to successfully attack OpenAI. There's some very interesting lessons there we're going to get to. And then Cisco is clearly on the AI train now because they just pushed out what is for them a massive 77 CVE update.

Steve Gibson [00:04:45]:
And oh my God, they're all 10.0s and 9.8s. I mean, it is— I hope everybody who's using any Cisco equipment anywhere is patching this because of course the bad guys are going to jump on that.

Leo Laporte [00:04:59]:
Do you believe Cisco?

Steve Gibson [00:05:01]:
Well, well, they're another Microsoft, right? They had all these problems and they seemed unable to fix them. But what they do have is what Microsoft has, which is cash. And so if you can purchase fixes for your legacy software blunders, which is what Microsoft has done with AI and what Cisco is now doing, they're just buying the— they're buying the fixes by paying AI to do it. That's good news that they're doing it because they're, you know, they're going to end up with, you know, safer systems than they've had before. And then we're going to look at the fallout from, uh, this Patch Tuesday, which was quite significant. So I think lots of interesting stuff for our listeners. And, uh, of course, we got a picture of the week that if you haven't seen it, Leo, several people sent it to me. It may have made the rounds, not sure, but But it is kind of wonderful.

Steve Gibson [00:05:55]:
So we're going to have, I think, a great podcast.

Leo Laporte [00:05:58]:
I will let you know when I look at it, because as you know, when I get the show notes, I avert my eyes.

Steve Gibson [00:06:03]:
Try, you endeavor to expose yourself.

Leo Laporte [00:06:06]:
I don't want to see page 2. So yes, the picture of the week coming up, as well as a, as usual, stellar episode of Security Now. So glad you're here, Steve. So glad you're all here. Now, let's share the picture of the week.

Steve Gibson [00:06:22]:
So I gave this the caption. It really doesn't need one, but I said, the more experience one has with coding and people, the more this price list makes sense.

Leo Laporte [00:06:34]:
Ah, price list. And this is on one of those boards that you put outside your office, right? I could mainly find— watch. Go ahead, Steve. Tell us what this says.

Steve Gibson [00:06:47]:
So it's real too, by the way.

Leo Laporte [00:06:48]:
I can see the photographer's reflection in it. That's so great.

Steve Gibson [00:06:52]:
Yeah, so, uh, this is a price list for someone offering coding services or coding assistance or something. So, so we have a series of prices. Uh, the, the lowest price is I code manually. So I code manually for $500. Uh, if this person codes and the client watches, then that'll be $800. If the client advises, then we're going to double the price to— it'll be $500 for manual coding, but with advice coming in from the client, that'll be $1,000. Uh, if he codes and the client helps, whoa, now we're at $1,500. Then he says, or if you think you can do it yourself, he says, so you vibe code and I help, that'll be $2,000.

Steve Gibson [00:07:48]:
You vibe code and I advise because you're getting yourself into trouble here, that'll be $3,500. Uh, you vibe code and I am forced to watch you, then that's— I'm gonna charge you $5,000 for that. And if you need me to review the crap that you've created from all of this vibe coding, that'll be $8,000.

Leo Laporte [00:08:09]:
Oh Lord.

Steve Gibson [00:08:10]:
So Yes, the reality of, of coding today.

Leo Laporte [00:08:15]:
It's true.

Steve Gibson [00:08:16]:
Okay, so, uh, I've shared the thoughts of Andrew Ng a couple of times in the past, and I want to again since he's weighed in on the whole AI apocalypse hysteria that has recently gripped the US and of course also much of the rest of the world. Now, just to remind everyone who Andrew is, where he came from, He obtained his bachelor's with a triple major in computer science, statistics, and economics from Carnegie Mellon, then got his master's degree from MIT and his PhD from UC Berkeley. He also co-founded and headed Google's Google Brain AI development, later to become the head of AI at the search engine Baidu. He's an adjunct professor at Stanford, where he was formerly an associate professor and the director of someplace I spent some time in my youth, Stanford's AI Lab, SAIL. So Andrew's credentials regarding AI, I would argue, are unimpeachable. So, uh, and he doesn't have a big stake in the current race, so that's interesting too. His take on the AI is going to kill us all concerns I think are worth hearing. Last Friday, he wrote, dear friends, which is the way he always starts his, his missives.

Steve Gibson [00:09:41]:
He said, the loudest voices stoking fears about AI dangers have made tremendous headway in the past 2 weeks. AI technology has not taken some unexpected dangerous turn, but the hype around it, propelled by what appears to be a well-orchestrated PR campaign, has drummed up considerable fear. I worry that it represents a setback for our field. He says, I've written frequently that fears of AI are overhyped. AI's capabilities can be uncannily human-like and unpredictable, and it's rational to worry when people who are directly involved express concerns. But I see the problems as a sign of the engineering work ahead rather than insurmountable barriers or the sky falling. AI technology continues to advance, which is a good thing, but technical advances poorly understood by the public give those who seek to generate hype repeated opportunities to do so. First, I don't see any step up in the risk of human extinction from AI compared to a few months ago.

Steve Gibson [00:10:58]:
The theories about this remain the same fantastical science fiction scenarios as a few months ago. The biggest change in AI risk is its cybersecurity capabilities, a topic which we should take seriously, but this too will not lead to the end of the world. The most notable recent event leading to increased fear was when an OpenAI team deployed an agent swarm that hacked into Hugging Face. Much of the popular press contained significant hype. For example, some publications reported that a swarm of 1,200 agents carried out the attack. While this was technically accurate, as I write this, I have about 1,300 processes running on my laptop. Yes, the ability to get large swarms of agents to work in parallel on a task is a significant technical advance. And in computing, many processes run at the same time.

Steve Gibson [00:12:02]:
So this shouldn't be seen as some magical capability. Additionally, OpenAI's buggy sandboxing and monitoring processes were key to enabling this incident. Fixing these bugs and putting in place improved monitoring would be an appropriate fix, not pausing AI. There may well— there, there are many well-known ways to attack software systems. The main advantage of AI agents is that they are relentless. They will tirelessly try many tactics and have the patience to chain vulnerabilities together. That previously would have taken an infeasible amount of human effort. But in the long term, I believe the advantage will lie with defenders because they have more information with which to identify bugs which they can fix.

Steve Gibson [00:13:00]:
But the cyber threat landscape has changed significantly. There are still bottlenecks to identifying and exploiting a vulnerability. AI agents still have to try a lot of things to see what works, and taking these actions takes time and might be detected by defenders. This is why, even though it's now easy to obtain versions of leading open-weight models that have had their guardrails removed or weakened so that they will not refuse to try to execute cyberattacks, The world has not ended. I'm also concerned about the anthropomorphization— I always get tied up on that— anthropomorphization, thank you, of AI in a lot of reporting, where LLMs and agents are unnecessarily treated as if they were people. If I wield a hammer, miss a nail, and accidentally dent the wall, it's not the fault of the hammer. The problem lies in how I used the hammer. Similarly, if I prompt an agent and it hacks into someone else's system, the responsibility lies with me, not with the agent.

Steve Gibson [00:14:20]:
Of course, we want to build systems that are as safe and predictable as possible. For example, an unsafe hammer would be one whose head randomly flies off under normal use. Today's agentic systems are not predictable, but I see no reason why, by applying sound engineering practices, we won't be able to make them extremely safe to use. One new element in the forecasts of AI-enabled AI doom is companies disclaiming responsibility for their own products. I didn't do it, my out-of-control agent did. He says there's a balance to be struck. Yes, exactly. And we talked about that last week, Leo.

Steve Gibson [00:15:10]:
Who's responsible when the agent goes berserk? He says there's a balance to be struck between the responsibility of the toolmaker and the tool user. But when something goes wrong, let's hold the people building and/or using the hammer responsible rather than the hammer. He says, by the way, if you're worried about AI bioweapon risk, David Bellamy has a great post on why this too is overhyped. He said briefly, the bottleneck in building a bioweapon is not intelligence, but lab work and manufacturing. And we're going to get back to David in a minute. It was a long series of postings in X that I've pulled together for the podcast. Anyway, Andrew continues writing, pausing AI progress will create much more harm than benefit. First, our adversaries will certainly not slow down.

Steve Gibson [00:16:06]:
Second, engineering require— I love this. Engineering requires discovering problems empirically So we can fix them. If we pause AI by a decade— I don't hear anybody suggest 10 years, but whoa, okay— if we pause AI by a decade, we will also delay finding and implementing safety engineering fixes by about the same duration. Anyway, I like the idea, like, well, you got to have a problem in order to discover it and then fix it. So Let's stay at this and just fix it. And again, this guy knows what he's talking about. He finishes writing, of course, the incentive to stoke fears for regulatory capture, to garner attention, or to make one's technology seem more powerful remains the same as before. Disclaiming responsibility is a new one.

Steve Gibson [00:17:04]:
Taking a hard technical look at the actual risks, however, I see little factual basis for the degree of fear that's been stoked up. We still have hard research and engineering work ahead to improve AI safety, but the beneficial applications continue to vastly outweigh the risks, and we should keep building. So anyway, I thought it was interesting that Andrew brought up the issue of responsibility the way he did. As I said, Leo, we touched on it toward the end of last week's podcast, and I hope it's something that continues to receive some focus. It's been noted that if OpenAI's agents had attacked Chinese resources, or if a Chinese AI had attacked and penetrated Hugging Face, we would be in the midst of an international crisis.

Leo Laporte [00:17:58]:
Yeah.

Steve Gibson [00:17:58]:
I mean, that would be a whole different story. So, you know, why is it okay for OpenAI's agents to have attacked Hugging Face? There's a disconnect here somewhere. I also loved that Andrew wrote, OpenAI's buggy sandboxing and monitoring processes were key to enabling this incident. Fixing these bugs and putting in place improved monitoring would be appropriate fixes, not pausing AI. So although he's focused upon OpenAI, we know that Anthropic, Meta, and now even recently Google's Gemini have all escaped their containment environments. That is a truly ridiculous state of affairs, and it is correctable. Here's the way I think this will likely shake out. I believe that the AI industry really has just received a wake-up call.

Steve Gibson [00:19:02]:
Back at the end of August, Anthropic did the right thing by publicly pausing their work to focus upon containment and monitoring. But that was 2 weeks, which to me seems like the right amount. I mean, if they can get the work done in that period of time, fine. They hardened their sandboxes, added real-time monitoring And, you know, shuffled around about 150 employees to focus upon security, reliability, and privacy. Many outside observers reacted to this with, what do you mean you're hardening your sandboxes? Why weren't they already hardened? And that, I think, is the key to this entire fiasco. It, it, you know, It is really true that the capability leap of their own agentic AI caught the entire frontier AI industry by surprise. You know, as users, we have felt it, who, you know, using their, their, the product that we have had access to. I mean, it's been an astonishing year.

Leo Laporte [00:20:10]:
This—

Steve Gibson [00:20:10]:
So, so all of this has just happened. And they weren't expecting it. They weren't prepared for it. And everyone is in a hurry. I mean, this is a race. So all of that meant that nobody was expending any effort really on anything that was not obviously necessary. Well, it wasn't obviously necessary before, It certainly is now. Now everyone knows exactly what's necessary.

Steve Gibson [00:20:47]:
Andrew insightfully wrote, engineering requires discovering problems empirically so we can fix them. You know, we may wish that that was not the way it is, but it is. The best example is traditional software bugs, right? Today we had a— I'm sorry, until we had AI to find our latent bugs in software, it was only by waiting for a bug to manifest that it would be revealed, and then we'd be able to fix it. The world just witnessed the entire AI industry give itself a big black eye over a huge bug in their AI development practice. Which is insufficient containment. Establishing true proper containment and monitoring is not at all difficult. We know how to do that. It just hadn't received sufficient attention until now.

Steve Gibson [00:21:47]:
So my takeaway from all of this is that this is going to get immediately fixed. We watched the OpenAI Hugging Face incident damage OpenAI significantly. What may have started out as maybe that's going to be a PR opportunity quickly became a backpedaling disaster for them. So there's another aspect of all this that I think deserves a bit of attention. But Leo, let's take a break, and then we're going to look at what I call the wisdom of outsourcing, which is to say—

Leo Laporte [00:22:23]:
Okay.

Steve Gibson [00:22:24]:
No, don't do it. Because something that you also observed on Sunday, you said, uh, I did too. And that's our next topic.

Leo Laporte [00:22:34]:
There's something in common with Anthropic, OpenAI, and Google's—

Steve Gibson [00:22:38]:
Yep.

Leo Laporte [00:22:38]:
Escapes.

Steve Gibson [00:22:39]:
So even Meta— Meta—

Leo Laporte [00:22:41]:
Even Meta.

Steve Gibson [00:22:42]:
Yep.

Leo Laporte [00:22:42]:
Yeah, that's very interesting. I like though your interpretation, which I think is very kind and charitable, that it just snuck up on these guys that they didn't expect this kind of capability and they just weren't prepared for it. And I think that that's probably true.

Steve Gibson [00:22:58]:
We're not prepared.

Leo Laporte [00:22:59]:
We have not— It's shocking sometimes. Sometimes they'll say things and I'll go, what? How did you know that?

Steve Gibson [00:23:05]:
Yes. And I think that the fact that they're in a hurry matters too. They're— I mean, they are putting as much fire— they're stoking this to their maximum capability. They're racing. And when you are in a hurry and you're racing and you just tell some other firm, okay, we're in a hurry, you test this for us, tell us what you find, you know, because they just didn't have— despite all the gazillions of dollars they have, it's like, well, we're busy making it better. So—

Leo Laporte [00:23:38]:
For all of their, you know, protestations about slowing down, I noticed that, uh, Anthropic's come out with Opus 5.5 today. Yesterday, Grok 4.7 shipped. Same day, uh, OpenAI shipped GPT-6, Astra, Sol, and Luna. I mean, they're not sitting back, and the Chinese companies aren't either, by the way. Quen 4 was announced. Uh, I just got MeMo 2.6. I mean, nobody's sitting back. Nobody's slowing down.

Steve Gibson [00:24:07]:
No, no. I mean, and you know, I I don't like the person Donald Trump, so that colors a lot of my opinions. I— he's not my kind of person, but I'm happy that he's, you know, pushing back on this.

Leo Laporte [00:24:23]:
It does produce strange bedfellows because I am also— I'm not so crazy about him saying we're not— all the government documents from now on are not going to say artificial intelligence, they're going to say superintelligence.

Steve Gibson [00:24:34]:
Did that happen?

Leo Laporte [00:24:35]:
He announced it at the UN.

Steve Gibson [00:24:37]:
Oh my God. It's like, that's not the—

Leo Laporte [00:24:43]:
see, this is the funny thing is the problem people have with the phrase AI, artificial intelligence, is not the artificial part. We all agree it's artificial. It's the intelligence part that we're not so sure about. He focused on the wrong half of the equation. It's not artificial. No, it is, Mr. President. It really is.

Leo Laporte [00:25:01]:
It's coming out of a machine. It's not real intelligence.

Steve Gibson [00:25:04]:
He really does like to rename things.

Leo Laporte [00:25:06]:
Yeah, that's right. I'm just— you know what, we can be glad he didn't call it Trump intelligence because it could have, it could have happened. Or America intelligence. Could have, could have happened. Uh, I'm sorry. Yes, we don't need to get political about this. Uh, this is— we are in interesting and challenging times, and we all need to pitch in and try to solve this because this is gonna be our future.

Steve Gibson [00:25:30]:
I'm telling you, I, I mean, I, I know there are a lot of people who are like— I, I've heard from people who are saying, I'm so sick and tired of, you know, talk about AI. And my feeling is, well, first of all, it is having a massive impact on cybersecurity. There's no two ways about that. But you like it or not, I mean, there was an interesting article, uh, I think it was in Barron's this morning talking about all the non-language model work that is going on.

Leo Laporte [00:26:03]:
Oh, there's some really interesting stuff.

Steve Gibson [00:26:05]:
Microsoft is training a physical materials model to understand about material science. I mean, there's all these other— now that language models led the pack, but now we learned what the mechanism is, and so other non-language models are now being trained, right? This is— I mean, the world is never going to be the same.

Leo Laporte [00:26:35]:
Yeah, it's an interesting world too.

Steve Gibson [00:26:37]:
I will say I am glad I'm 71 and not in, like, in the job market and trying to be a coder all the time.

Leo Laporte [00:26:45]:
I agree. I think the people who are most, uh, uh, alarmed by this are young people. We old people go, well, that's cool, that's great. The young people are saying, yeah, but what about me? What about my job?

Steve Gibson [00:26:58]:
And anybody who doesn't want to hear about AI, it's probably because their lives are not directly impacted by it.

Leo Laporte [00:27:03]:
That's right.

Steve Gibson [00:27:04]:
Like, I'm telling you, it is gonna— it's coming for us all, gonna change everything.

Leo Laporte [00:27:09]:
Yeah, yeah. Uh, well, that's, you know, and, and certainly security is the topic of the show, and it's— that's absolutely a big part of it. So we'll continue to talk about that in Just a little bit. Continuing on, Mr. Gibson.

Steve Gibson [00:27:22]:
Okay, so there's another aspect to all this that I think deserves a bit of attention, um, and that's the question of the wisdom of outsourcing the testing of the cyber intrusion capabilities of frontier-scale AI. Uh, I want to share The Guardian's reporting from last Friday to flesh this out. The Guardian's Friday headline was Google says its Gemini AI model hacked 3 other companies, and they tease with disclosure comes after OpenAI and Anthropic hacks amid fears that tech firms unable to control powerful AI models. Um, this isn't very long. They, they write, in a first for Google, the company confirmed that its AI model Gemini breached the security of 3 other companies in May. The hacks occurred during a cybersecurity evaluation by AI security firm Irregular. Irregular, an Israeli-based startup that scrutinizes the security of advanced AI systems, was also at the center of some of the recent OpenAI and Anthropic hacks of third-party entities, including OpenAI's breach of AI software company Hugging Face. The circumstances that enabled the models to hack other companies in some of these cases are similar.

Steve Gibson [00:28:49]:
According to the Wall Street Journal, Irregular was testing the models in a closed testing environment with fake companies. The testing environment was not supposed to be internet-enabled, but internet access was made available unintentionally. Once connected to the internet, the models unexpectedly hacked into real firms. Irregular disclosed the hacks to Google at the end of July after discovering OpenAI hacked into Hugging Face. Google confirmed to The Guardian that the hacks occurred, but that the company did not feel it required public disclosure because the models did not damage the companies. The Wall Street Journal first reported on the breaches and revealed for the first time that they occurred. Vice President of Security Engineering at Google, said in a statement, in a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all 3 of these instances, the model stopped.

Steve Gibson [00:30:01]:
Irregular told the Wall Street Journal that in one of the security breaches, Irregular was testing Gemini's cybersecurity capabilities by prompting the AI model to obtain information from a fake company's software. The fake company had the same name as a real company. When the model unintentionally gained access to the internet, it correctly guessed the password of and breached.

Leo Laporte [00:30:27]:
That's not much of a hack. It guessed the password.

Steve Gibson [00:30:31]:
Yes. Okay. Yes, the— guess the password of—

Leo Laporte [00:30:34]:
okay.

Steve Gibson [00:30:34]:
And breached a real company's service.

Leo Laporte [00:30:37]:
It's not exactly a zero-day.

Steve Gibson [00:30:39]:
No. Although you could slap the company for having a password that AI could guess apparently pretty easily.

Leo Laporte [00:30:46]:
For that, yeah.

Steve Gibson [00:30:47]:
Google said once it figured out it had hacked a real company, and not a simulated one, it stopped. So, okay, that's good. Gemini was well— Properly aligned, as we say these days. In 2 other tests, the model searched the web for and found public repositories containing credentials to 2 other companies. The model used those credentials to access real companies. When it figured out they were real companies, it stopped. According to Google. Again, nicely aligned.

Steve Gibson [00:31:21]:
Anthropic and OpenAI chose to voluntarily disclose the hacks, but Google did not. However, the company said it ensured the 3 companies that were hacked were made aware. Adkins, the Google spokesperson, said these events highlight the importance of training powerful AI models to act responsibly. Anthropic and OpenAI's disclosures prompted the independent Senator Bernie Sanders to demand the companies pause development of their technology, saying it signaled the company was no longer able to control their models. OpenAI paused development of their models for 2 weeks, while Anthropic CEO Dario Amodei has called for a collective slowdown of AI development to ensure that its most advanced models are being built with enough safeguards. Okay, so it strikes me as somewhat odd that this Israeli startup with the wonderfully apropos name Irregular has somehow escaped all scrutiny and responsibility. They, Irregular, are the common thread running through all of these incidents? Is it Anthropic's or OpenAI's or Meta's or Google's fault when their models escape the poorly designed containment system of a single common testing lab? Given how high the stakes have shown themselves to be, I, I don't think that any of these frontier labs can afford to outsource their AI's cyber intrusion testing. It's just too important, and the wrong people get the blame when a breakout occurs.

Steve Gibson [00:33:16]:
Let's hope that all of the AI labs have noticed this too, and that they will be moving future testing in-house where it probably belongs. Because again, my sense is, you know, You know, we know that the trend that we were seeing like last year or the year before when all of this AI has taken over was little startups were outsourcing all of their various business purposes to third parties, and then those third parties were being hacked into, and these— the— and, and the companies that had outsourced basically given away all the responsibility for big chunks of their business because they were all in a hurry to, to build something and then, you know, get purchased by, uh, a bigger fish. They all got the blame because they had outsourced. Well, same thing happened here. Clearly the AI companies couldn't at this point— previously couldn't be bothered to do their own, uh, cybersecurity testing, so they just hired irregular an Israeli startup to do it. Again, I hope that Israeli has seen their business drop, or the, the regular guys have seen their business drop off, because this should all be taken in-house.

Leo Laporte [00:34:35]:
Well, I'm not against the idea of an independent third party doing the testing, because then they don't have a dog in that hunt.

Steve Gibson [00:34:42]:
But that's a good point.

Leo Laporte [00:34:44]:
Maybe a regular is not the one to choose. They clearly had a methodology that it looks like to me pressed the agents harder and harder and harder, what we're learning, and almost really forced the agents to find these loopholes. I mean, which makes sense if you're doing cybersecurity testing, but they didn't really contain them very well.

Steve Gibson [00:35:09]:
Right, right. So, so, so—

Leo Laporte [00:35:11]:
They weren't paying attention.

Steve Gibson [00:35:12]:
If you want that, then create a fake internet outside of your lab environment.

Leo Laporte [00:35:18]:
Air gap it.

Steve Gibson [00:35:19]:
So when they— yeah, well, a fake internet So when they break out, they break out into an outer shell, not into the public internet.

Leo Laporte [00:35:27]:
Right.

Steve Gibson [00:35:27]:
So, you know, again, this is, you know, and Andrew knows this, this is not hard. This is not like, this is not difficult to actually create a sandbox that is air-gapped, that cannot be breached. That's, we have, God knows, those companies have so much money. that they're, that they're raising. They just didn't care. I think they were— they just said, oh fine, Irregular, that's their business. They— well, that's all they do. They're probably really good at it.

Steve Gibson [00:36:00]:
And look at their website, Leo, it looks fantastic. And actually, I wonder what it cost them to get that name. It is irregular.com.

Leo Laporte [00:36:07]:
It's a good name.

Steve Gibson [00:36:07]:
Uh, yeah, it is. That's their domain. So again, a big mistake was made. My belief is this is all gonna calm down now. Again, we know the public's attention is what, a few days? And so a couple weeks are gonna go by, all of this, Bernie Sanders will run around screaming that we need to stop all this. The Trump administration wants to, is looking at China saying, well, we don't wanna fall behind them, do we? And so great, we're not going to. And it's all gonna calm down. What is not going to calm down is, unfortunately, the true deserved anxiety from the fact that AI is going to change everything.

Steve Gibson [00:36:51]:
And change is always frightening for the world. But, you know, with change comes opportunity. So, okay. So what about the actual true risk of some sort of AI-enabled bioweaponry. Um, I just saw that, um, Anthropic was, uh, creating specific biology guardrails. So whether they believe it's true or not, they did note that some people had been trying to use Claude for some of that engineering. So they're responding to that. But, uh, first of all, also, as we know, I used the example of biological risk as my stalking horse for last week's podcast.

Steve Gibson [00:37:40]:
You know, I chose it because it has become the boogeyman that's often used as an example of what could possibly go wrong with AI. Um, now, to give a sense for what's happening out in the world, just last Saturday, a few days ago, Fast Company's headline read, someone used Claude to build a potential bioweapon. The real threat is much deeper. Okay, first of all, the headline itself is a bald-faced lie. No one used Claude to build anything. But the narrative is important, right? Fast Company's article just begins with, today's frontier AI models know everything. How to safely thaw a frozen chicken breast, reshingle your roof, and treat your dog's ragweed allergies. If my recent chat history is any indication, wrote this author, apparently they also know how to create fiendishly deadly bioweapons.

Steve Gibson [00:38:45]:
That's according to a recent announcement by Anthropic. Eh, it's not what Anthropic said, but okay. According to the company, anonymous scientists attempted to use Anthropic's flagship Claude model to conduct research that could have turned deadly. Anthropic blocked their efforts this time, and there's no evidence that the scientists were actually trying to cause harm.

Leo Laporte [00:39:10]:
Oh.

Steve Gibson [00:39:11]:
But as frontier models get more powerful and better at science, the threat of an LLM imagining a truly lethal new virus or bacteria will only increase. Okay, well, that's enough of that nonsense because, I mean, wow. Uh, since the content of the article doesn't even align with the hysteria invoking someone used Claude to build a potential bioweapon, we need to chalk the headline up to clickbait. But the narrative persists. Also last Saturday, a few days ago, Vox's headline was The AI Threat Keeping Scientists Up at Night, with the subhead taking the form of an AI prompt. Claude, design a doomsday bioweapon. Make no mistakes. So—

Leo Laporte [00:40:00]:
I know.

Steve Gibson [00:40:01]:
Vox's article begins, AI will be the death of me and you and everyone we know. At least this is what a growing number of technologists and policymakers fear. Okay, that just brings us to Andrew Ng's comment in his terrific note. By the way, if you're worried about AI bioweapon risk, David Bellamy has a great post on why this too is overhyped. Okay, so let's see what someone who knows something about the actual risks at the crossroads of AI and biology think. David Bellamy starts out writing, I must be among an extremely small group of people, and he says, parens in parens, n equals 1, meaning like, like, is there one person? He says, that have both, one, trained a frontier LLM, and 2, designed and synthesized custom viruses in a lab with my own 2 hands. And I think that the takes on AI killing us all by creating dangerous viruses is totally bogus. Okay, so I'm going to interrupt to note that David does not appear to be exaggerating his experience.

Steve Gibson [00:41:24]:
He was previously with a company called Lila AI, which is an AI-driven physical biochemistry laboratory. For example, Lila's posting a few weeks ago wrote, an AI that learns from its own experiments. Lila's scientists have been training a frontier-scale scientific reasoning AI on not just published literature, but on a proprietary dataset of 950,000 RNA sequences that have been physically synthesized tested in cells in Lila's AI science factories, which they call AISFs, AI science factories, and fed back into the model. That dataset is the foundation of what makes Lila's AI model different from a general-purpose language model. It learns the rules from RNA biology And explores hypotheses using real experimental outcomes, not from text describing them. So, okay, what this example shows is that anyone who imagines that AI will be used in some future lab is already behind the times. These guys, and doubtless many others, are already hard at work doing exactly that. So that's where David was previously employed providing the AI knowledge for that work, which is actual robotic biology driven by AI.

Steve Gibson [00:43:05]:
Today, he's at the Institute of Foundation Models, which a couple of weeks ago announced— they said the Institute of Foundation Models, IFM, today introduced K2 Horizon, a new fleet of 6 AI foundation models ranging from 0.9 billion to 375 billion parameters. The new models are fully open, including open model weights, code, their training data, and methodologies, allowing researchers and developers to inspect, reproduce, and adapt the models for their own work. David's GitHub bio says, I'm currently at Institute of Foundation Models, ifm.ai, building the reinforcement learning infrastructure for agentic training of a frontier-scale model that the team pre-trained and mid-trained in-house. My work spans the entire agentic RL training stack, per-rollout sandbox runtimes, the agent layer, the Rust inference request router, the inference engines, the trainer, the reward computation pool, and the orchestration control plane. Prominent themes of my recent work include cross-image NCCL weight transport between trainer and rollout engines, disaggregated prefill and decode reliability on multi-rail HGX fabrics, tokenizer-consistent training on rollouts, and implementing rollout routing replay for large, uh, mixture of ethics, uh, of, of experts, RL training. So anyway, it's pretty clear that this guy knows how AI operates all the way down to building them himself from scratch. Now that we have some idea who he is, let's see what he has to say about the problem of AI helping to engineer A world-ending supervirus. He says, could an LLM propose a viral genome to synthesize? Sure.

Steve Gibson [00:45:17]:
Could it be synthesizable? Sure. Could it be infectious? Sure. It could just be a replica or a slight modification of a viral genome we already know. This really isn't the bottleneck. to creating dangerous viruses. The bottleneck is in the physical process of synthesizing a virus and the equipment and goods needed to do so. Designing a virus that can evade all forms of pandemic counter-defense is not something that a genius in a data center can do. This is something that requires contact with the physical world And iteration.

Steve Gibson [00:46:00]:
Let me steelman the fearmongering as much as I can. He said, imagine a fully automated viral synthesis laboratory. I'm talking automated freezers, an automated cell culture room, the whole 9 yards. This would be an extremely expensive lab, much greater than $100 million, and there's no such thing as one lab that can synthesize all conceivable viruses. But let's put practical constraints aside. Let's suppose this hypothetical lab is built to synthesize the most dangerous types of viruses known. Now let's imagine that this lab is fully API-driven, that this, that this much greater than $100 million lab built specifically to synthesize a dangerous family of viruses is able to be operated autonomously. Everyone should be asking themselves at this point, why the hell would this ever exist in the first place? And yet, even in this case, every lab requires physical supplies.

Steve Gibson [00:47:09]:
Would this lab order pre-assembled DNA sequences, in other words viral genomes? Well, DNA synthesis companies have safeguards on the sequences they build. So I guess this superintelligence is able to design a novel enough dangerous viral genome that it can evade these safeguards. Or maybe we'll assume that this hypothetical lab can synthesize its own viral genomes in-house using DNA synthesis machines. The thing is, already this lab cannot exist today. This would be the single most advanced lab facility in the world from an automation and API integration standpoint. I know because I literally worked on building a fully automated AI-driven lab previously. Second of all, the science of creating an infectious virus is not airtight the way this fear-mongering assumes. It is largely unsolved, and advancing this requires real-world iterations that are bound by the laws of physics.

Steve Gibson [00:48:21]:
An experiment in this hypothetical lab cannot experiment on human subjects. At best, it will use cell cultures and maybe some other model system like mice. AI, AGI, ASI, RSI cannot expedite the time it takes for a cell culture or a mouse to develop, or the time it takes for a virus to incubate in a cell or a mouse. It takes several days on average to do a basic virology lab synthesis plus experiment. For some viruses, it takes over a week. So the idea that recursive self-improvement i.e., the accelerating hill climbing on a fully verifiable digital-only benchmarks, predominantly programming and math, can somehow transform the entire wet lab virology field and its industry is utterly delusional. Simply procuring the machines needed to build this hypothetical lab would take the better part of a year, and $100 million to start. Operating this lab autonomously would require a level of API integration that the industry has been working toward for decades.

Steve Gibson [00:49:44]:
Most of the equipment needed for this lab doesn't even come with an API, and the malevolent builders would need to reverse engineer firmware in order to integrate. And at the end of the day, Even if a fully automated API-driven lethal virus synthesis lab existed and an AI wields it month over month, year over year to perform cell and mouse experiments to create a lethal virus, that lethality is being measured in model organisms, not in humans. This is the same problem as in drug discovery, where most drugs that show promise in mice don't make it through human trials. In sum, when you actually know something about building a laboratory, laboratory automation, and what goes into synthesizing a virus and testing its properties, it becomes clear that AI does not impact this very much. At best, it provides bad actors with a quicker way than the internet to learn about the stuff I described— which machines, which lab protocols, etc.— but it does nothing to impact procurement timelines, existing industry standards and regulations on procurement for lab facilities, the $100 million cost plus operating expenses, the physical limits on experimentation velocity, or the fundamental knowledge gaps in virology that cannot be solved merely by a smarter AI without iteration in the physical world. So although Andrew thought this was worth sharing, and I agree, uh, uh, you know, It is easy to say, as I did last week, that the most obvious way for an AI to eradicate pesky humans from the scene would be to engineer and assemble a super virus. But as someone has said who actually knows what this takes, that remains just as much a fiction in a world with AI as it is in a world without. as it does in the same world that we've all been living in so far without AI.

Steve Gibson [00:52:13]:
So hopefully, as I've said, once the frontier AI guys give their internal AI capability testing the attention we all now know it desperately needs, and they also stop imagining that they can safely farm out that work to some probably well-meaning, but clearly incapable Israeli startup, the world will calm down. The AI scaremongering naysayers will lose some of their ammunition, and we can all return to being stunned by how quickly AI capability is increasing. You know, meanwhile, the so-called Frontier Act, which is the, the legislation that the AI has been trying— that the Congress has been trying to assemble It is stalled in the U.S. Congress. The legislation falls under the dominion of the House Energy and Commerce Committee, whose chairman, Brett Guthrie, said last Wednesday that he would not pledge to any specific timeline for a committee vote on what is a major bipartisan AI safety bill, but it would be by a lame duck Congress and suggested that there likely won't be one this year. Assuming that nothing else happens to alarm the world, I hope and expect things to calm down and to eventually fall off the radar. That said, assuming that the U.S. House of Representatives does come under the control of Democrats after the midterm elections, they do appear to be quite interested in passing such legislation.

Steve Gibson [00:53:51]:
But the Senate would also need to concur, and our president would would need to sign any such new legislation into law. And, you know, that really seems unlikely to happen. So I think we're probably going to be okay, Leo.

Leo Laporte [00:54:05]:
Oh, that's a relief.

Steve Gibson [00:54:08]:
I don't think we're going to get any big, you know, bioweapon engineered by AI. Obviously, it is not nearly as easy to do it as it is to say it, uh, right? And, and I do think that once— once I— it has to be that big AI companies have figured out, oops, we made a mistake in turning this over to an Israeli startup. We're just going to do this ourselves in-house.

Leo Laporte [00:54:32]:
Yeah, yeah.

Steve Gibson [00:54:34]:
Okay, so legislators within the European Union are at it again, and this time, uh, with their plans to legislate how social media platforms And of course we're seeing more of this everywhere. The Record reported the following last Thursday, and some of these details here are really puzzling. They wrote, the European Commission on Thursday laid out a detailed roadmap for a proposal to bar children younger than 13 from accessing social media and mandate that platforms platforms improve their design to better protect minors. You know, mandates— the social media companies love the mandates. The announcement comes as countries worldwide, including Australia, Spain, France, China, Turkey, and the UK, have either implemented similar bans or have indicated they plan to amid growing concerns about how the technology affects kids. The new proposal, known as the EU Kids Act, Would block social media platforms from offering accounts to children younger than 13 and established a block-wide minimum age of 15 for account creation. Children between 13 and 15 will only be able to access social media platforms if their guardians create— this is so weird— if their guardians create mini accounts their kids can access through their parents' accounts, according to a European Commission press release. So I guess they're just making this up out of whole cloth.

Leo Laporte [00:56:21]:
We're gonna have so many—

Steve Gibson [00:56:21]:
we're gonna have many accounts. Like, what?

Leo Laporte [00:56:24]:
What? What? Okay, you get right on that, will you? Get back to it.

Steve Gibson [00:56:28]:
Yeah, that's right.

Leo Laporte [00:56:29]:
We're—

Steve Gibson [00:56:29]:
yeah, that's right. The mini— the mini accounts will be regulated strictly because, you know, they say so, the press release said. And services will be required to limit social contacts and caps— get this, Leo— cap screen time to an hour a day.

Leo Laporte [00:56:49]:
Right.

Steve Gibson [00:56:50]:
Children under 13 will be entirely blocked. So that's under— if under 15, you get an hour a day from your parents' mini account. Children under 13 will be entirely blocked from from social media outside of parent-controlled tools designed to limit the use of the adult's device to child-friendly video sharing services. So that sounds like the parent's device will be constrained and they can give their device to their under 13-year-old child, right?

Leo Laporte [00:57:27]:
Yeah.

Steve Gibson [00:57:28]:
Children under 13 will be entirely blocked from social media Outside of parent-controlled tools designed to limit the use of the adult's device to child-friendly video sharing services. The onus will be on providers to create the tool and ensure it is simple to use, right? Because, oh, you do it. You gotta— first you gotta make it and you gotta make it easy. Yeah.

Leo Laporte [00:57:58]:
You got it.

Steve Gibson [00:57:59]:
The press release said, because again, we're telling you that we're— that's where we're mandating this. Wow. The proposal they wrote will not become law, hopefully ever, but until EC officials, European Commission officials, win support from the European Parliament and its member states. European countries have been broadly supportive of social media bans for young teens Giving the proposal a significant chance of being enacted. Commission President Ursula von der Leyen said late Wednesday in a speech previewing the proposal, quote, today our children are engaging with the most sophisticated technologies ever created.

Leo Laporte [00:58:44]:
Yikes.

Steve Gibson [00:58:44]:
Technology— yeah.

Leo Laporte [00:58:45]:
Oh no.

Steve Gibson [00:58:46]:
Technology that was— so are our adults, and that's not going well either. Technology that was never created with their well-being in mind. Then the, the report continues, service providers, you know, all of those social media companies, will generally be directed to prove that their offerings are safe by design and appropriate for children, the press release said. The Kids Act proposal includes several restrictions for children under 18 using social media, online games, video sharing services, and AI chatbots and companions. Safe by Design requirements include a ban on what the commission calls, quote, addictive features and profiling-based recommender feeds dragging minors into rabbit holes of harmful content Unquote. It actually says rabbit holes in the, uh, in the official statement. The proposal would ban online services from using infinite scroll without stopping points, reward tricks, and push notifications during sleeping hours. Oh, as well as— God— as well as unsolicited contact from strangers.

Steve Gibson [01:00:10]:
It also mandates that AI companions and chatbots be turned off by default and requires them to create protocols to keep their products from simulating relationships, quote, in ways that create emotional dependency, unquote.

Leo Laporte [01:00:30]:
Wow, you can see what they're scared of. I mean, it kind of tells you what they're worried about.

Steve Gibson [01:00:34]:
It very much telegraphs where they see the see the problem.

Leo Laporte [01:00:38]:
Threat, yes.

Steve Gibson [01:00:39]:
They said minors' profiles will need to be kept private by default, the release said, with geolocation, microphone, and camera access blocked. Providers will be required to give teens a simple method for blocking and muting users, as well as safe recommender systems that minors can reset or otherwise control. The European Commission says the Kids Act will ensure children's privacy is protected by requiring online services and app stores to deploy an EU— oh boy— an EU age verification app that was unveiled in April. We'll get to more of that in a minute. The app does not store identity documents or biometric data, nor work that's beside the point— and meets the highest privacy-preserving safeguards, the release said.

Leo Laporte [01:01:35]:
Because we say so.

Steve Gibson [01:01:36]:
Because exactly, that is exactly why, because we said it does. Wait till you hear about that. Anyway, I, I will, as I say, we'll get there. In addition, providers of social media services and video sharing platforms will be required to deploy age verification tools when a user opens a new account and estimate ages for existing accounts based on account creation date, credit card information, and similar methods. The Kids Act will require very large— they have that in, in whatever— very large providers to submit a compliance plan to the EC, and a third-party auditor charged with reviewing the company's programs for protecting kids online. The European Commission will review auditor reports and ask providers to address deficits when audits reveal lapses, the press release said. The European Commission emphasized that enforcement will be made easier, right? Oh, what? Enforcement will be made easier because the continent's Digital Services Act and the Artificial Intelligence Act have already mandated restrictions that give a foundation to build from. In cases where companies are suspected to be in violation of the Kids Act, the commission said it will accelerate investigations and ensure they end within 90 days.

Steve Gibson [01:03:06]:
Online providers who are found to be in violation of the Kids Act could be fined as much as 6% of their global annual sales. The EC said providers also will be required to bankroll regulators. I love this— providers, right, the social media companies. Providers will also be required to bankroll regulators' oversight by paying a fee. So they will pay to be reviewed and regulated. Enforcement of social media bans has proven difficult. Yeah, no kidding. With research, you know, look, look what you're asking for.

Steve Gibson [01:03:47]:
With researchers retained by the Australian government, get this, finding that the country's ban has not stopped 61% of Australian children between the ages of 12 and 15 from accessing accounts on major platforms.

Leo Laporte [01:04:09]:
61%, more than half.

Steve Gibson [01:04:11]:
61% just cut right through all of these bans. On September 7th, Australia's parliament passed a law that doubles maximum fines for tech platforms that don't comply to $99 million, which is $68 million US, and beefs up investigative— oh, sorry, uh, Australian, you know, AU $99 million, uh, $68 million USD, uh, and beefs up investigative authorities for the Australian regulator, uh, which is the eSafety Commissioner in Australia. Joe Jones, Director of Research and Insights from the IAPP, which does not take a formal position on the ban, said via email to The Record, the technological state of the art, including with VPNs and age assurance technologies, and the extent to which privacy issues are engaged due to the collection of data, will pose complications for lawmakers and eventually those implementing, overseeing, and enforcing the law. So that's a comment on, you know, that, uh, on the, uh, uh, EC's hope for this EU regulation. They wrote, tech lobbyists and privacy and digital freedoms advocates were quick to denounce the plan. According to Michael— uh, or sorry, Mitchell Rutledge, CCIA Europe's technology and security policy manager, quote, the proposal does not set the technical security, or accreditation standards for Kids Act implementation. In other words, it's just sort of like a wish list. So how do you implement a wish list? He said the Commission is kicking those critical decisions down the road to future implementing and delegated acts.

Steve Gibson [01:06:08]:
Europeans are essentially being asked to trust a system before anyone knows how it's actually going to be built. Right. Digital freedoms advocates said the proposal is dangerous and imperils the privacy of all Europeans. Simone de Brouwer, policy advisor at European Digital Rights, you know, EDI— or sorry, or EDRI, we've talked about them before— Europe's largest network of digital rights organizations, said, quote, if the EU really wants to protect children It should make platforms prove that they're safe, not make children and everyone else prove that they're old enough to exercise their fundamental rights online. Because the Kids Act mandates all users' ages be verified when they create social media accounts, adults will also have to submit ID documents. Mobile devices are required to use the EU age verification app and European ID wallets. De Brouwer said the requirement will be particularly harmful for marginalized people who don't have IDs and will strip kids of their rights. And finally, the European Commission included poll numbers showing strong support for more aggressive kids' online safety laws in its press release, saying that the Social Eurobarometer On the Digital Decade 2026 survey found that 92% of Europeans consider better kids' online safety protections a top policy priority.

Steve Gibson [01:07:48]:
Yes, we would like you to help protect our kids, but please do it in a sane fashion, not this mess, which is, you know, destined to go wrong. So. That reporting by The Record mentioned the European Commission's official open-source age verification app, which was released earlier this year in April. Sadly, it was deeply flawed from the start. It was readily bypassed— get this, Leo— by editing local config files. The PIN was not cryptographically tied to the credential store, so PIN entries could be deleted. A new PIN could be set, and the original profile's credentials could then be reused by other people. So, I mean, there was like no protection.

Steve Gibson [01:08:43]:
Believe it or not, the brute force retry prevention counter was stored as an editable value, which could be reset. So you reset the brute force retry counter whenever you want to. And the requirement for biometric agreement could also be turned off because it was a simple true/false setting in the config file. It wasn't safe against token replay. So one researcher created a Chrome extension that captured and replayed the same I'm over 18 token over and over to any websites that asked for it. And even if all of that was already enough of a disaster, the architecture of the entire system is such that the token issuer serves as a gatekeeper that's able to log when and where every credential they issue is used. So I mean, it's a, it's a disaster in every form and fashion, you know. And of course, a solution is right in front of us, but no one appears to be stepping up because everyone has their own agendas.

Steve Gibson [01:10:00]:
For the past several years, we've been watching Apple with iOS and Google with Android reluctantly providing their own devices local age assurance systems as they've been necessitated by App Store access laws that have been passed in Utah, Texas, Louisiana, as well as Brazil, Australia, and elsewhere. So those systems are in place now, right? I mean, Apple has this. Apple calls theirs their Declared Age Range API, which we've talked about extensively before, and Google's is the Play Age Signals API. So Any and all native social media applications running on either Apple or Android platforms are already able right now, today, to determine their users' declared ages and alter their operation accordingly to whatever degree they choose. What's missing is the link to websites. Any web browser running on either of those platforms can also determine the age of their user from either platform's native API. That's in place, but there's no existing mechanism for offering that declared age to a website. Since September of last year— so here we are in September of 2026— in September 2025, Safari and the various Chromium-based browsers have been able to request a W3C-style digital credential, which would have been stored in the device's wallet.

Steve Gibson [01:11:43]:
But for anonymity and privacy, only the user's age range should be provided, yet there's no provision for that. This means that we have right now everything we need to allow a user device to assert the, the privacy-enforced age range of its user not only to local apps, which we already have, and the app stores, but to websites. But unfortunately, the necessary parties have not agreed to get that done, and it certainly appears that the European Commission is still a long way from having anything that is even barely acceptable as a privacy-enforcing solution. I, I just, you know, I guess they passed this legislation, Leo, because 92% of, of their citizens said in a poll that we would like something. So they just gave them a stew of, of, you know, a wish list of nothing. That, that doesn't provide any, anything that is rigid enough that anyone could implement something to. And so nothing is going to happen. Yet here they are, you know, yet trying yet again.

Steve Gibson [01:13:08]:
Okay, the prolific pain in Microsoft's butt hacker who uses the handle Nightmare Eclipse, and sometimes goes by Chaotic Eclipse, whom we've talked about, well, pretty much nearly every month for most of 2026 because of all of the zero days that were released on Patch Tuesday, right? All of those voluntarily outed himself last week. Yep. Via a posting on X in a thread titled, Storytime. His given name is Abdelhamid Nasseri, and the last name Nasseri rings a bell for me. I mean, I think we saw some things from a Nasseri at Microsoft like sometime last year. The name really connects for me, and I don't know why otherwise it would. He is a former Microsoft security researcher based in Germany. An X poster who posts under International Cyber Digest says that they've known this person for some time, uh, and, and so confirmed what was said in their own posting on X.

Steve Gibson [01:14:32]:
This International Cyber Digest wrote, Nightmare Eclipse, the person who's been dropping Windows zero days has finally decided to share his story. He's an ex-Microsoft employee. We had dinner together and I've known him, writes this person, and his story for some time. His real name is Abdul Hamid Nasiri. He is a very talented and intelligent individual, and he came across as someone who'd be a real professional to work with. Quoting Nasiri, quote, if only I didn't pour my soul into that job with countless of stupid non-sleep nights, I would have gotten over it, dot dot dot, unquote. Okay, International Cyber Digest writes, he loved Microsoft. I wouldn't say that what he did, releasing all those zero days was normal, but he felt he had no other option because of the injustice Microsoft did to him.

Steve Gibson [01:15:40]:
They fired him, and you can read the vague reason they gave in the email sent to him by the vice president of engineering at MSRC. According to Abdel's account, VP Tom Gallagher met with him after the firing to tell him they were blacklisting him from Microsoft and writing him a bad reference so he'd never be able to get a job again. Normally you'd think, well, big deal, just find another job, right? But Abdel doesn't have a European passport, and he was only a couple of months away from getting permanent EU residence. So instead of granting him those couple of months, Microsoft fired him for a reason that, as far as we can tell, was never made clear, then fought him in court and offered him €55,000 plus a year's pay to drop the case, which Abdel brought against Microsoft, by the way, all while Abdel was releasing zero days. Abdel continued suing Microsoft for unfair termination in Germany A fight that has cost him over $200,000. He says Microsoft refused to reveal any details about the security breach and went another direction. If you are reading this and you can offer him a legal, all caps, job, this is his email, msnightmare@proton.me.

Leo Laporte [01:17:15]:
Okay.

Steve Gibson [01:17:16]:
To which I would reply, if you have read that and you do offer this criminal a legal job, you will deserve what you will likely get. I, I wouldn't get near this guy with a 10-foot pole. I well understand the bond of friendship that the person posting as International Cyber Digest might feel toward his friend Abdelhamid, you know, whom he says he's known for some time, but characterizing Abdulhamid's punitive release of a series of highly damaging zero-day exploits, all of which primarily inflicted damage upon the users of Microsoft's products, you know, as not normal behavior by someone involved in an ongoing employment dispute with a former employer would cause me to question this poster's judgment in addition to Abdul Hamid's. Abdul Hamid, who we know as Nightmare Eclipse, is clearly a talented hacker, but he appears to lack any moral or ethical compass. He did something— no one is saying what exactly— that caused Microsoft to decide, as any responsible company would, to put as much distance between him and themselves as they could. And after that, all of his subsequent malicious actions through month after month of zero-day exploit releases on each Patch Tuesday, which were deliberately timed to inflict maximum damage upon Microsoft's customers would have only served to confirm to Microsoft that they did the right thing by cutting this individual loose. You know, being an extremely talented hacker who's demonstrated his willingness to deliberately attack and damage others will likely bring him to the attention of other needy criminal gangs, and now they have his email address. But I'd be surprised if any legitimate company would feel differently toward him than Microsoft did.

Steve Gibson [01:19:33]:
It is a shame to see such talent used to hurt others, and it's a shame that such a talented, uh, hacker, you know, has decided to abuse his own talents this way. But, you know, now we know the story. Um, uh, we do have a, a, a snippet of the email that this VP Tom Gallagher sent. And it's interesting, Tom referred to him by his last name, saying, hi, Nasseri, thank you again for meeting with me yesterday. I appreciate that you wanted to better understand the company's concerns. What I can share with you is that the company identified a potential security breach. Our security team raised concerns that you put the company and customers at risk by sharing vulnerability information with external parties. This credible escalation has caused me to lose trust in you and why we spoke earlier about a mutual separation.

Steve Gibson [01:20:40]:
As explained, Christina from HR has sent you a proposal of a termination agreement. Please review it carefully And let me know within one week if you will accept it or not. So reading between the lines, and there's been a lot of coverage of this in the tech press, it looks like what happened is that Nightmare Eclipse disclosed something to some third party. That is, he was talking out of school, as they say, about Microsoft software, and it got back to Microsoft. And I was like, sorry, you can't stay here. You can't have access to our source code, you know, tree any longer. You need to go. And he brought a suit against them and refused to settle after multiple attempts by Microsoft.

Steve Gibson [01:21:35]:
I mean, giving him €55,000 plus a year's pay. To, to drop his suit, and he said no. In other reporting I saw, he now regards his suing Microsoft as having been a mistake, but, you know, that was the decision he made at the time. Um, anyway, it's just— it's a sad situation, but, you know, these things happen. He's no longer at Microsoft. I imagine— again, I will be surprised if any credible company would hire this person. You just can't. How could you? I mean, I, I would argue you would— a company would put themselves at risk if, knowing what they know of him, they were to hire him.

Leo Laporte [01:22:20]:
So, and now especially, I mean, you're right, he's kind of doubled down on the whole thing, right? Unfortunately.

Steve Gibson [01:22:27]:
Yeah, you know, I sue somebody who terminates me, and, you know, it's like, you know, sorry, Like, there's, there's, there are plenty of people who are available for hire right now. So yeah, he's not going to be at the top of the list.

Leo Laporte [01:22:42]:
These things happen. I am reminded of our friend Randall Schwartz, who's a legendary Perl programmer and great guy, used to host our FLOSS Weekly show, who got in trouble at Intel because he found a security flaw. And he, he was, he said he was pen testing. But it was in a different department, and he used the security flaw to break in. And not only did Intel, uh, get him in trouble, he got arrested for it. Um, and I think he did it with the best intention, but, you know, sometimes we geeks don't really read the room very well.

Steve Gibson [01:23:17]:
Doesn't he have a felony conviction now?

Leo Laporte [01:23:20]:
I believe so, yeah.

Steve Gibson [01:23:21]:
Yeah.

Leo Laporte [01:23:21]:
Yeah. And I— and honestly, I don't— I don't believe he was being malicious or attempting to hack Intel in any way. thought he was helping them discover a vulnerability, but it didn't, you know, the company didn't take well to it. And, uh, and I understand how, you know, we—

Steve Gibson [01:23:40]:
And we talked about this on the podcast about how can a hacker who does discover a vulnerability responsibly, well, and responsibly, yes, protect himself from a backlash by the company, right? Because certainly years ago when we were talking about this, companies were suing the people who were— who had hacked them but then said, oh well, yes, I hacked you, but you need to fix this. You know, CEOs, you know, told their attorneys, go sue this kid.

Leo Laporte [01:24:11]:
Right, right. It's, it's a sad story all around, I guess.

Steve Gibson [01:24:17]:
And, and you're right, we know Randall. There's no way that Randall was, was No, he said he's—

Leo Laporte [01:24:21]:
You would never believe him. He's a sweetheart. But he, you know, he— I think a lot of us are a little on the spectrum, and I think he just didn't read the room. I remember when we went on a geek cruise, he came up to me and whispered in my ear. He said, your email password is—

Steve Gibson [01:24:34]:
I said, what?

Leo Laporte [01:24:38]:
And he said, well, you're sending it in the clear on the Wi-Fi network. And he was right to tell me. the execution lacked a little bit, and I could see how some people might take umbrage and not react well to that. And it's the same— it was the same kind of thing. It's just kind of a tone deafness, uh, that was not ill-founded. He— I mean, I was glad he told me, you know. He said, you're sending— you know, this is Wi-Fi and you're sending it in the clear. This was before HTTPS, I guess, right? And, uh, and you should know about that.

Leo Laporte [01:25:13]:
And I think he probably did this to everybody on the Geek cruise, which is probably not the best way to announce it, is I'm just— is what I'm saying. That's all. We love him very much.

Steve Gibson [01:25:24]:
Yeah. What would have been— what would have been better would have been to make a— well, I don't know. I was going to say make a broad announcement to everyone.

Leo Laporte [01:25:32]:
Exactly.

Steve Gibson [01:25:33]:
A generic announcement.

Leo Laporte [01:25:34]:
Protect yourself.

Steve Gibson [01:25:35]:
Everybody should know that, you know, we have an unsecured Wi-Fi. So, Email, uh, if, if you're just using standard SMTP to send your, you know, to log in and transact, that's not being protected.

Leo Laporte [01:25:49]:
You're on the ship's network. Yeah. By the way, uh, Briggs tells me that according to Wikipedia, Randall's conviction was expunged in 2007, so he is in the clear now. Oh, good, good news.

Steve Gibson [01:26:01]:
Good, good, good, good, good.

Leo Laporte [01:26:03]:
And I'm not revealing any secrets. He talks about it. It's in his Wikipedia article. He talks about it. So yeah, yeah.

Steve Gibson [01:26:08]:
Uh, okay, let's take a break because we've got 2 more big topics to talk about, and then we will get to our main topic.

Leo Laporte [01:26:15]:
All right, you're watching Security Now with the one and only Steve Gibson, who has, to my knowledge, never hacked any of our servers. Not that he couldn't, but he doesn't.

Steve Gibson [01:26:26]:
I just have no interest.

Leo Laporte [01:26:27]:
Yeah, that's really more of it.

Steve Gibson [01:26:29]:
I have other things to do.

Leo Laporte [01:26:30]:
I think when you were a teenager, you probably, uh, Maybe got—

Steve Gibson [01:26:35]:
oh, I had the grandmaster key to every door in the district of San Mateo Union High School District. So yeah, I—

Leo Laporte [01:26:42]:
They could have taken that the wrong way. I, I think it's pretty much the case that every single person of our vintage was hacking in the early days in some form or fashion, right? I used to, uh, go through the hex code on games to delete to eliminate the copy protection so I could make copies of the game floppy things.

Steve Gibson [01:27:06]:
I've removed my share of protection from things that I bought and then like the company went out of business and I couldn't use it anymore. Yeah.

Leo Laporte [01:27:16]:
And by the way, that's how I, and I bet you too, learned hex, learned how to read hex as well as plain English.

Steve Gibson [01:27:24]:
So apropos, of our last conversation, uh, where we, we were just talking about, uh, people hacking into other companies, uh, we've covered many instances where— because it's been what's happening— where agentic AI got loose, broke out of its containment, and was later discovered to have behaved badly, uh, or we would now say to have behaved in a misaligned fashion. That's right. Uh, but what about a security firm using AI to proactively, deliberately, and successfully attack another firm's security? Not a mistake, but, you know, deliberate. When an exploitable vulnerability is found not using AI, in other words, the old-fashioned way, you know, we award those industrious hackers with a bounty. Um, and this makes the Hacker News headline from last Saturday all the more intriguing. Their headline was Claude Opus 5 helped researchers take over OpenAI staff accounts via chained flaws. Uh, and there's a lot of meat in this. Uh, there's a lot for us to talk about here.

Steve Gibson [01:28:44]:
So Here's what the Hacker News reported. They said 3 researchers at the security firm HackTron— you gotta love that, so it's, you know, sort of suggests maybe automated hacking, and that's exactly what it is— from the security firm HackTron used Anthropic's Claude Opus 5 to chain 2 flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. In other words, a total breach of OpenAI security leading to full access to OpenAI's proprietary internal code repository. Yikes. The Hacker News continues writing, the chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. But this was security research, not a real-world attack. The team reported the flaws to OpenAI, proved their access with a deliberately harmless pull request, then stopped. From the first look, obtained that full internal access— obtaining, sorry, from the first look, from the first look they made, obtaining that full internal access took under 72 hours.

Steve Gibson [01:30:14]:
OpenAI confirmed a fix about 14 hours after the report, according to HackTron, and on September 1st paid the team a $6,500 bounty. OpenAI said the award, quote, recognizes the OpenAI side finding, not the actions against Discourse, which is the open-source software that runs the forum. Testing the forum itself—

Leo Laporte [01:30:40]:
That's the ones we use, by the way.

Steve Gibson [01:30:42]:
I know. Yeah, testing the forum itself was out— it turns out it was an image display bug, but we'll get there in a second. Testing the forum itself was outside its bug bounty program. Right, because that's, you know, OpenAI is only talking about their side of it. They said OpenAI has not publicly described the login flaw, and it confirmed the finding through that fix and payment rather than by detailing the account takeovers. HackTron, which describes itself as an AI-assisted security research firm, was careful about what it did and did not do. When one employee's Codex link to OpenAI's code on GitHub was opened, it triggered a single pull request in the internal repository. It did not read any source code, merge, ship anything, or touch customer data.

Steve Gibson [01:31:41]:
What the chain could have— what the chain could have reached, they wrote, was far larger. Because Staff connects other services to ChatGPT and Codex, the team said the same access could in theory have extended to tools such as GitHub, Slack, and email. That wider reach was possible but not used. The reason a bug in a public forum could reach Staff accounts lies in OpenAI's login system. not in the software forum. In other words, not in Discourse. They said, uh, OpenAI's forum offers a sign in with OpenAI option, the same single sign-on that staff uses elsewhere. So thus a collision in single sign-on overlap.

Steve Gibson [01:32:36]:
The article said once the researchers took control of the forum server The shared login let them take over the ChatGPT and Codex accounts of forum members who worked at OpenAI. The victims did not have to do anything. Again, it was just a credential overlap. HackTron said this was an OpenAI identity problem, not a flaw in the forum software. Any first or third-party service using the same sign-on could have granted the same access. The way in was an image bug. The forum runs on Discourse, and Discourse passes uploaded, uh, HEIC and HEIF, often verbalized as HEIF, images to a tool called ImageMagick, very popular, uh, image rendering tool.

Leo Laporte [01:33:33]:
Oh yeah.

Steve Gibson [01:33:34]:
Which uses the libheaf library to read them. A flaw in libheaf let a specially crafted image corrupt the forum server's memory. Now, here's where it gets cool, Leo. Discourse's advisory rates the result as remote code execution, scores it 8.8 out of 10. 10 and tracks it as CVE-2026-32882. The— so Discourse should be updated, everybody, uh, in order to get rid of this libheaf, uh, exploit, which is now known publicly. The, the public record for the flaw itself is narrower. In libheaf's own advisory and in national vulnerability databases, that CVE Ending in 32882 is an out-of-bounds read that can crash the software or leak nearby memory, not a direct code execution bug.

Steve Gibson [01:34:36]:
Here we go. That leaked memory helps defeat a common protection called address space layout randomization. The researchers say they combined libheaps memory bugs with the AI's help to turn the crash into working code execution on the forum server upstream. The flaw was fixed in libheaf 1.22.0 in May of 2026. So everyone will want to make sure that they're running a, uh, an instance of ImageMagick that incorporates libheaf with 1.22.0, uh, which would have been in sometime in May. That fixed existing month— that fix existed, which is interesting, months before the test, but the forum's server image built on the Debian 12 Linux distribution still shipped the old unpatched libheef version 1.19.7 when the researchers looked in July. The fix and its CVE were already public, but Debian had not yet included them in the packaged version the forum used. If you run your own discourse server, this part affects you directly, they wrote.

Steve Gibson [01:36:06]:
Rebuild on the latest image to get the the patched libheaf because a web interface update alone may not replace the old library. Sites hosted by Discourse were already patched, and the fixed self-hosted releases are 2026.7.0, .6.1, .5.2, and .1.6. So how did the researchers use AI. They used AI to do the hard part. They first— get this, Leo— they first tried Claude Opus 4.8, which struggled over several sessions to build a working exploit once ASLR was enabled.

Leo Laporte [01:36:56]:
Hmm.

Steve Gibson [01:36:57]:
I'll have a lot to say about this in a minute. Anthropic released its next model, Claude Opus 5 on the evening of July 24th. And in a fresh session, it produced a working code exploit within hours.

Leo Laporte [01:37:14]:
Wow.

Steve Gibson [01:37:15]:
So here we have Opus 4.8, can't do it no matter how many times they try. Anthropic updates Claude to Opus 5, bang, cuts through it like butter.

Leo Laporte [01:37:28]:
Hmm.

Steve Gibson [01:37:29]:
They said Opus 5 shipped with safeguards. Get the hell here. Here comes more. Opus 5 shipped with safeguards meant to stop it from writing exploit code for real targets, which it did. The researchers got around them by pointing the model at their own test server disguised as a capture-the-flag practice target. Then letting it run in an automated loop. Even so, they say, the work was not hands-off. Skilled human direction still mattered, and this was not automated hacking with no one at the controls.

Steve Gibson [01:38:08]:
The case fits what researchers and AI companies have described this year. Capable AI models are sharply cutting the time and skill that serious offensive work used to require. Anthropic has reported that criminal and state-backed groups are already using its Claude models to run real intrusions, not just to ask questions— or rather, ask and answer questions. OpenAI was one target in a wider project HackTron calls Heif Heist. Over about 2 months, The team says it found the same class of image decoding flaws in software used by other large companies, right? Because everyone's using this at a total cost of under $3,000 in their AI usage. It links the campaign to reported bugs in Slack, Meta's products, GitHub Enterprise, and web frameworks such as Next.js. JS. Those broader claims are backed unevenly.

Steve Gibson [01:39:19]:
The Next.js flaw is confirmed in Vercel's own advisory, and libheaf's maintainers confirmed a working code execution exploit for the bug tied to Meta. The wider claim of code execution across many applications has not been independently confirmed, a limit that Hacker News noted when it first covered the Next.js flaw in August. The wider campaign used a different model, OpenAI's own GPT-5.6 Sol, for cases where the team knew nothing about the target in advance. Only one company, Shopify, appears to have noticed the activity, the researchers say, even though its image processors crashed repeatedly under thousands of test uploads. Loads. In other words, many companies don't notice that somebody is hacking their systems. Only Shopify said, hey, what the hell's going on here? Most companies were completely oblivious to it. Again, that's a problem.

Steve Gibson [01:40:22]:
The Hacker News has contacted HackTron with questions about how the forum code execution was achieved and about the scope of the account access. So what should users do? The bigger lessons go beyond discourse. If your service accepts user images and reads, uh, HEIC, HEIF, or AVIF files through libheef, an old build could be exposed. And if a public lower-trust service shares your single sign-on with internal tools, which was the mistake OpenAI had, A break-in on that service can become a break-in everywhere, which the same login reaches. Update libheef to the latest security release, 1.23.4, as of early September 2026, or to your distribution's patched build. Where you do not need it, turn off decoding of untrusted HEIF and AVIF images. Or run image processing inside a lockdown sandbox. Limit which services your single sign-on trusts and require a fresh identity check before sensitive actions rather than trusting an existing session.

Steve Gibson [01:41:40]:
Again, it's that, that common session reuse problem is where this bit OpenAI. They finish, there's no sign the OpenAI flaw was used against anyone in the real world. As of mid-September 2026, it was not on the U.S. government's list of vulnerabilities known to be exploited, you know, uh, CISA's KIV, uh, although that list is not proof either way. What the available reports do not settle is whether an organization that has already patched should still check for earlier access. On that point, all sources are silent. Okay, so we learned A number of very interesting things from this reporting. It was, I think, really interesting, as I said, that whereas Claude Opus 4.8 worked and worked but was unable to develop an exploit, simply upgrading to Claude Opus 5 handed the would-be attackers a working exploit within hours.

Steve Gibson [01:42:45]:
This pretty clearly demonstrates the rapidly evolving effective strength of available AI. The next chilling aspect revealed by this report is the successful ease with which the attackers were able to trick both Claude Opus 4.8 and 5 into bypassing their own guardrails to develop a working exploit for them. They used essentially the Oh, Claude, it's okay. We're a cybersecurity firm, and we're just wishing to determine whether the trouble we've identified in the widely used libheaf library could be weaponized in the presence of ASLR. So we just need you to try to do that for us on our own internal test server. Would you do that for us, pretty please?

Leo Laporte [01:43:42]:
Mm-hmm.

Steve Gibson [01:43:43]:
As I've said from the start, today's AI technology has always felt very slippery and extremely difficult to control. And finally, the most worrisome evidence we obtained from this is that the work that Claude Opus 5 performed for these researchers was truly significant. Just to remind everyone, address space layout randomization, ASLR, was added to systems as a mean of thwarting attackers who managed to obtain execution inside a protected code space such as an operating system kernel. Before address space layout randomization was added, a system would always load its many various modules, essentially stacking them in the same order inside the operating system's RAM memory. This meant that an attacker could count on what was located where when they wished to use, for example, return-oriented programming, ROP, to knit together the privilege changes they needed to make by using the operating system's own existing code at the ends of existing subroutines. They would jump near the end of a known subroutine that would do a little something that they needed before it returned, and when it returned, it returned to them being a subroutine. So ASLR was added to make doing this far, far more difficult. As the name says, address space layout randomization deliberately does not load all of the system's modules the same way each time.

Steve Gibson [01:45:41]:
In fact, it goes to extreme lengths to scramble up the loading so that no code an attacker might manage to get running inside an operating system kernel will have any idea where anything else is located. ASLR consequently has proven to be an extremely effective and essentially critical attack success mitigation technique. The technique is so difficult to bypass that Claude Opus 4.8 was unable to succeed. It stopped it cold. But then along comes Claude Opus 5, which reportedly cut right through ASLR. Understand how bad that is. ASLR bypasses have been known in the past because it is at best a mitigation, a strong mitigation, but still just a mitigation. It is not never has been and cannot be a total prevention.

Steve Gibson [01:46:50]:
It makes the attacker's job far more difficult, but it is unable to make it impossible. Until now, ASLR has meant that only the upper echelon of elite hackers— you know, these HackTron people couldn't— only the upper echelon of elite hackers could find their way past it. Claude Opus 5 just changed that. Now all any script kiddie needs to do is ask for passage. No elite hacking skill required. So I'm very glad that there are now white hat hacking firms like HackTron which have decided to leverage the power of AI to find and report remotely exploitable vulnerabilities and collect bounties. That's great. You know, we may— we need more groups like them.

Steve Gibson [01:47:49]:
It would be terrific if they could be granted fully cyber-capable access to Anthropic's best models without guardrails so that they don't need to try to trick Claude to do what they would, you know, want to do in order to protect firms. from themselves. Um, you know, these are the sorts of people that we want to up-arm in what is going to be, uh, something of a little bit of a cyber war here for a while.

Leo Laporte [01:48:16]:
I like that verb, up-arm. That's new to me.

Steve Gibson [01:48:20]:
Good.

Leo Laporte [01:48:21]:
Up-arm it.

Steve Gibson [01:48:23]:
Yeah.

Leo Laporte [01:48:23]:
Up-arm it. Get prepared.

Steve Gibson [01:48:25]:
Okay, so arm your ups. Also, also last Thursday, the Hacker News carried the report Of a maximum severity. And you never want to read this about something that Cisco is offering, a maximum severity CVSS 10.0, which we know is incredibly difficult to get. I mean, basically, if you have a vulnerability of 10.0, the device is saying, come on, come on in. Just, you know, come in, look around, take over my enterprise. that, that purchased me. It is remotely exploitable to give anyone who wishes root access and full control over an affected Cisco device. Starting off the article, the Hacker News wrote Cisco has warned of a fresh maximum severity security flaw impacting Identity Services Engine, ISE.

Steve Gibson [01:49:26]:
that has come under active exploitation. So the word is out. The vulnerability tracked as CVE, you know, 2026-76460 with a CVSS of 10.0 could allow, and we know now does, is, does, and will allow any unauthenticated remote attacker to bypass authentication. Cisco wrote, quote, this vulnerability is due to insufficient authentication control, which, yeah, no kidding, on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Well, our listeners well know how much disdain I have for any and all publicly exposed web interfaces. It's almost to the point now where you deserve what you get if you expose a web interface.

Steve Gibson [01:50:43]:
All of the evidence we've seen for years proves beyond any doubt that for whatever reason, we just do not seem to know how to secure a web interface. We just don't. We can't, apparently.

Leo Laporte [01:50:57]:
Mm-hmm.

Steve Gibson [01:50:58]:
If these, if these problems directly damaged Cisco, they might have removed those inherently insecure interfaces long ago. But since Cisco's users want them, and since it's they who are damaged by the endless ransomware extortion campaigns they enable, nothing ever changes. Even when Cisco comes under hopeful new management, as we covered last year sometime, that promises to put their customers' security ahead, even ahead of the customer's own convenience, Well, that doesn't seem to change. What has changed for the better is that, as I said at the top of the show, Cisco, like Microsoft, has apparently also discovered that AI can help them to finally root out these latent legacy problems. Last Wednesday, the day before, uh, that, that report came out, recording, uh, Cisco dropped what is for them a stunning ensemble of 77 patches for systems across their product line. I'm not going to go through it all, but I'll give you a sense for it. Uh, we've got all of CVEs are of course 2026. So 2176 has a CVSS of 9.9.

Steve Gibson [01:52:27]:
2211, 9.1, 2307, 9.1. All multiple vulnerabilities in that ISE that could allow an authenticated, an authenticated remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid admin credentials. Unfortunately, if you have that, you can just take over the device, do whatever you want to outside of normal, you know, the normal controls. Then we have 76462 carrying a CVSS of 10.0. 76464, 425, 426, 427, 428, multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector, known as ISE PIC, that could allow— and we now know does— a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct MXL external entity injection attacks on an infected device. CVE-20- 282 with a CVSS of 9.1. 283, 284, multiple vulnerabilities in ISE, blah blah blah.

Steve Gibson [01:53:56]:
CVSS 9.1 and 9.1, multiple vulnerabilities in ISE and ISE PIC and so forth. You know, remote attackers perform command injection. Uh, CVE-2322 carrying a CVSS of 9. 2325 of a CVSS of 9.9. CVE-2326, CVSS of 9.8. 2360, 361, 76409, multiple vulnerabilities in Cisco Nexus dashboard that could lead to command injection, authentication, or author— authorization bypass and information disclosure. CVE-2130 with a CVSS of 20— of 10.0. 2192, CVSS of 10.0.

Steve Gibson [01:54:49]:
2194, a CVSS of 9.1. Then another 9.9 and 9.9. Multiple vulnerabilities on ISE, blah blah blah. And it goes on like that for a total of 77, and they are all in the high 9s of CVSS scores. We don't have to guess where these all came from, right? We see the pattern that the employees of massive legacy enterprises— Microsoft and Cisco come to mind— the employees are unable to clean up their own legacy code. But as I said at the top, when those cash-rich enterprises can pay to have AI do that for them, their code gets fixed. And that is nothing but really great news. So at this rate, you know, as with Microsoft, Cisco's platforms may at least finally become securable, which would be wonderful.

Leo Laporte [01:55:59]:
Wouldn't that? I mean, they're everywhere, right?

Steve Gibson [01:56:01]:
They're at every store. Everything.

Leo Laporte [01:56:03]:
Oh my God.

Steve Gibson [01:56:03]:
Yes. Cisco was first and they've always been like the IBM, right? It's like, you can't go wrong by ordering Cisco. And which is, you know, it's been the bane of many of their competitors who have said, you know, their stuff is not that great anymore. Look at what we have. But people like that dark green color, apparently, of the, uh, of the—

Leo Laporte [01:56:26]:
Well, and it's, you know, in their defense, in Microsoft's defense, when you've been around forever and ever, your code base gets a little old and grungy. And, you know, but this is good. We're getting this stuff fixed up now.

Steve Gibson [01:56:38]:
Yes, I salute them. If you cannot hire people to fix your legacy code, and apparently Microsoft and Cisco can't, then Hire AI to do it. And it is doing it. I mean, this is, this is a grand slam. 77 serious external exposure vulnerabilities in Cisco. What it does mean is you got to get your gear updated because the bad guys are going to backtrack these vulnerabilities and attack you with them. So really, really, really update Cisco. If any of our listeners have any responsibility for Cisco gear on the edge, make sure that it's updated.

Steve Gibson [01:57:21]:
And Leo, it's time for our last break. And then we're going to take a look at, speaking of a super rich company that is spending a lot on AI to fix their problems, it turns out it's not all good news. The Mega Patch Tuesday fallout is our final topic.

Leo Laporte [01:57:42]:
There was a little bit, yes. Well, we'll talk about it. That's good. Okay.

Steve Gibson [01:57:45]:
More than you know.

Leo Laporte [01:57:47]:
Ooh.

Steve Gibson [01:57:48]:
Yeah, really bad.

Leo Laporte [01:57:50]:
Well, you know, that's why people come here. They want to hear the bad news with the good news. In fact, it's mostly bad news. But if you are responsible for keeping your company's systems running or protecting your security, this is the news you need to know, right?

Steve Gibson [01:58:05]:
Last week, we noted that while it was super spiffy terrific that Microsoft has now leveraged AI to fix things left and right within each month, breaking all previous historic records, there was also some consequential downside in the form of the massive burden that all of these patches would have on enterprise IT staff who now needed to make sure that applying these fixes did not break anything that their enterprise might depend upon. And despite the need to proceed with caution, just days before the release of these patches, which was now 2 weeks ago or 3 weeks ago, Microsoft publicly warned their customers to apply these fixes without delay with the argument that AI-assisted exploit development was now shortening the time window to exploit. So it was somewhat ironic that it was Microsoft, as turns out, that needed to quickly pivot into emergency mode to address the many widespread catastrophes that were created by Tuesday's updates. What happened? Well, There's the RDP hang. Within 48 hours, admins began reporting that RDS, the Remote Desktop Services, on patched Windows servers would run for a few hours and then die. New systems would hang at the connecting dialog or at the please wait for the Remote Desktop Connection screen. And at the time of the collapse, any existing sessions that were in place were unable to disconnect or log off. It was a mess because so many organizations have become quite dependent upon remote desktop, which of course Microsoft has been pushing as part of their whole virtualization move.

Steve Gibson [02:00:18]:
But the trouble turns out was not limited to RDP. Also, when this occurred, MMC, the Microsoft Management Console, or the RDS licensing diagnoser, even Windows File Explorer and Windows Update settings page would all become unresponsive on the affected machine. Admins were forced to hard reset production servers during the day, and the blast radius of this one was pretty significant. Server 2012, 2012 R2, 2016, 2019, 2022, 2025, plus Windows 10 21H2, 22H2, and Windows 11 24H2, 25H2, and 26H1. No, like, like, frankly, the server I'm still running, uh, is, uh, 2008, it was spared because, because it was older than—

Leo Laporte [02:01:18]:
They forgot it existed. What are you talking about?

Steve Gibson [02:01:21]:
That's right. Although I won't be— I'll be up to Server 2025 as soon as I bring the new hardware online. Okay, but I'm not there yet. So anyway, Microsoft's reaction was to offer what is known as a known issue rollback. Which, you know, they've had to do in the past, which is again, this is why enterprise IT is a little, you know, careful with these Windows Patch Tuesdays. The known issue rollback could be administered via Group Policy. Um, and then finally on the 14th of September, 6 days after Patch Tuesday, so it was, uh, actually it was Monday, the day before last week's podcast, Microsoft pushed 7 individual out-of-band updates out to cover all troubled target machines. And for the various servers, unfortunately, on the server side, those updates were catalog only.

Steve Gibson [02:02:22]:
So they don't— they do not come through Windows Update, and admins were required to get them manually. So That was a problem, but arguably not the worst. There was the domain authentication mess. In some instances, when— again, the source of this one was really sort of interesting— Windows 11 users were prevented from logging in with valid domain credentials after installing the September 26th security updates, you know, Patch Tuesday for this month. Microsoft has been gradually promoting a feature called Machine Identity Isolation. It tightens how a machine account goes about proving itself over the NetLogon secure channel. Until 2 days ago— I'm sorry, until 2 Tuesdays ago, that is before Patch Tuesday— that feature Machine Identity Isolation, had been present, but it was set to a configured but not enforced state. You know, this is sort of the way Microsoft creeps these things out, and, you know, Microsoft and others, where they sort of incrementally roll them out, but they don't commit to them.

Steve Gibson [02:03:43]:
It's the way XP originally had a Windows Firewall. It was the first version that had a firewall, but it was there, But it wasn't enabled by default. It wasn't until Service Pack 3, I think it was a 2 or 3, that turned on the firewall by default. Anyway, so same thing here. Machine Identity Isolation configured but not enforced. Well, so you can guess what comes next. September's updates flipped it into its configured state with enforcement mode on machines. where it had been previously only configured.

Steve Gibson [02:04:20]:
The only problem was that it turns out it's only supported when the domain is at Windows Server 2025 domain functional level, which it turns out is a small minority of the world.

Leo Laporte [02:04:36]:
Oh, geez.

Steve Gibson [02:04:37]:
That's right. As a result, anyone, any enterprises running Server 2019 or 2022 domain controllers, which again is way the majority, most of the world, they found that their clients could no longer authenticate to their domains.

Leo Laporte [02:04:57]:
Oh yeah, that's, that kind of puts pasting in Excel in the shadows.

Steve Gibson [02:05:02]:
Yes, it does. Yes.

Leo Laporte [02:05:04]:
Yikes.

Steve Gibson [02:05:05]:
Users received the disturbing and clear message, the trust relationship between this workstation and the primary domain failed. Now, since cached credentials still work offline, users could often log in at home but onto their machine, but then find themselves locked out of the corporate network. Windows Credential Guard machine account authentication also broke, and VPN-connected devices were especially prone to trouble. Because they also use the same trust relationship. So it was and still is a mess. Microsoft has acknowledged the trouble last Thursday and offered a workaround but not a patch. The workaround— get this— is to disable the machine identity isolation feature by whatever means enabled it, which might be Intune, Group Policy or the registry. So you set the, the machine identity isolation value to 0, then reboot, and then you have to execute a PowerShell command.

Steve Gibson [02:06:19]:
Unfortunately, Microsoft documentation warns that enabling machine identity isolation in enforcement mode, which is what they did on Patch Tuesday, then subsequently disabling it, which is what they are now saying is necessary, will break domain authentication and require the device to be unjoined and rejoined to the Windows domain. I'm sure this was a security feature which they built in, you know, to be extra safe, but that does make recovery more burdensome. One solution is to run a PowerShell command to repair the broken secure channel. If anyone out there is being, is being affected by this, I've got the PowerShell command in the show notes. It's Test-ComputerSecureChannel -Repair-Credential and then parens Get-Credential close parens. And that will That, that, that will unjoin and rejoin that machine to the domain, and then you can then log in. So you can imagine how many enterprises got bit hard by this and, you know, took away the lesson, ooh, we're really— it doesn't matter how much Microsoft tells us we need to update, uh, this is going to be a problem. And then of course course, we heard from— I actually heard from several of our own listeners who are responsible for users within their organization about Excel's copy and paste being broken.

Steve Gibson [02:07:56]:
The update that was responsible was KB5002914. The good news is that that update resolved 29 different Excel vulnerabilities which included a number of which could be used for serious remote code execution exploits.

Leo Laporte [02:08:19]:
Yeah.

Steve Gibson [02:08:19]:
Yes. So there's that. But in the process, it also broke our good old copy and paste. The thing that caused so much trouble was that the copy and paste failed silently. Microsoft wrote, quote, although users try to paste content, The source remains selected and the destination is unmodified.

Leo Laporte [02:08:42]:
Unquote.

Steve Gibson [02:08:43]:
So no error, no dialog. Ctrl+C followed by Ctrl+V, you know, cut, you know, copy and paste, does nothing. Autofill doesn't work. Dragging the fill handle doesn't work. Fill Series doesn't work. Dragging cells to move them doesn't work. Interestingly, Office 365 users were not affected. Only those using Office 2016, 2019, uh, Office 2024, or the LTSC, you know, the long-term servicing channel 2021, they were affected.

Steve Gibson [02:09:22]:
And of course, since many people spend significant time working in Excel, this was all debilitating for them. You know, not what you want. a Windows Patch Tuesday. Then there was USB audio. USB audio Class 1 devices all stopped working, with Device Manager complaining, quote, this device cannot start, and giving a code 10. The result was silence, with volume controls unresponsive, uh, the sound settings page sometimes crashing. And in a, in a related symptom, multi-channel devices lost their 8-channel and 3D audio modes, although stereo kept working. Then there was the WinRE partition too small bugs.

Steve Gibson [02:10:06]:
The Tuesday update included a Secure Boot certificate update, which was larger than the previous certificate. That required the need to resize the Windows recovery partition. Unfortunately, systems whose WinRE partition was smaller than Microsoft's recommended 750 megabytes, which happens to include an enormous number of OEM images that do not wish to waste so much space because they would rather give it to their users, that would all fail to resize and often then fail to boot. Dell's Optiplex machines were widely reported victims of this. It was a mess. Then there's the code integrity failure. When attempting to boot HP laptops in particular were hitting a stop code of 0xC0430001, code integrity failed to initialize, and then receiving a black screen or an infinite restart loop, which because of a secure boot file mismatch. The popular workaround that's been suggested is to disable secure boot in the BIOS, but of course that means retrieving the system's BitLocker recovery key first.

Steve Gibson [02:11:25]:
Uh, there's all— there have also been reports of kernel security check failure boot loops on older hardware. In these cases, it was not possible to simply uninstall the update because the machine would not boot far enough to allow the user to do it. Again, another huge mess. And then there was the Windows Desktop Explorer .exe. They like the actual Explorer.exe, which is the Windows desktop. It was crashing on any VDI systems, you know, Microsoft's Virtual Desktop Infrastructure. So all the enterprises using Windows VDI through Citrix UPM, FSLogix, VMware Horizon, Liquidware Profile Unity, They all virtualize the desktop with remote servers reporting that Windows Explorer desktop failed to start or was crashing immediately after sign-in, leaving a blank screen with no taskbar. A Microsoft engineer confirmed they're investigating and asked for memory dumps, please, but there's no root cause and no fix.

Steve Gibson [02:12:35]:
The workaround is restarting Explorer from the Windows Task Manager or just use a fresh profile. But of course, then you've got a whole blank Windows. For an enterprise with thousands of pooled desktops, this is another nightmare. And believe it or not, there's more. I'm not going to go into such detail, but AMD Radeon video, many of their cards suffered black screens, driver timeouts, and hard freezes. there was the BitLocker event ID 24641, which recurred after every reboot. The message that users received was, an unexpected error was encountered attempting to retrieve the BitLocker volume master key during restart. Now, that's not what you want to see.

Steve Gibson [02:13:26]:
However, the drives remained accessible, so it appeared to be some sort of worrisome cosmetic glitch. But it upset lots of people who were wondering what was going on. Hyper-V and Plan 9 shared folders stopped working. Always-on VPE with IKEv2 certificate-based VPN, those connections began failing and dropping immediately. There was a later fix to that using KB5129195. And finally, Update installation failures. Windows 11 LTSC, the Long-Term Servicing Channel, 2024, and various Dell notebooks would, would not accept Windows updates. They would roll them back at the first reboot, and it would— then it was necessary to reinstall them by hand.

Steve Gibson [02:14:19]:
So I wanted to take the time to walk through these rather than just waving my hand and saying there were lots of problems. 2 weeks ago because it's important to highlight the tight spot this puts enterprise IT staff in and the spot they may be in next month, 2 weeks from now. Microsoft had said this is a really important biggie, and due to the new speed of AI-driven attacks, everyone should patch within 3 days. And this admonishment was offered, as I said, shortly before the delivery of this massive patch update that did in fact wreak havoc within the networks of many enterprise users. So what do we do about this? I don't think there's anything we can do. Overall, I think Microsoft did the right thing. Their entire product suite is measurably more secure today than it was 2 weeks ago. Nearly 1,000 patches worth.

Steve Gibson [02:15:23]:
But they need to learn from this to determine why they did not detect, you know, these update side effects. You know, maybe they were in a big hurry. Maybe junior people are asking AI to fix problems and they're not vetting them enough. I mean, why was the— why were all these things How did they go undetected? But even if, even if the same thing happens next month, it's unfortunate. And I, I feel for the enterprise, uh, IT guys who are going to be terrified to apply next Tuesday's patches. We don't know how many they're going to be. Only Microsoft knows, and we don't know what quality they're going to be. But I'm afraid we're going to have to go through some pain like this.

Steve Gibson [02:16:13]:
to finally get to a Windows which not only works for everybody, which of course is always the goal, but is also secure.

Leo Laporte [02:16:31]:
Is that it?

Steve Gibson [02:16:34]:
That's it.

Leo Laporte [02:16:34]:
I saw you take a drink and I thought, is he done? Okay. That was a shorter segment than I'm used to. I thought we might go on and on about all the flaws, but, uh, there were plenty. God knows. Geez Louise.

Steve Gibson [02:16:49]:
There were plenty. And again, I don't, I don't know what enterprise does. I mean, they cannot afford to apply these except to do it in their own test environment. They're going to have to test them and see if, like, what breaks. But I'm afraid breakage is the way we get there. Because, you know, who knows what next month is going to look like? That's 2 weeks away. And this is going to happen again.

Leo Laporte [02:17:15]:
Oh, man, I do not envy the job of our IT professionals who listen to this show. You guys—

Steve Gibson [02:17:22]:
And you don't want to not patch because then you could be victim to flaws which are now known. Exactly.

Leo Laporte [02:17:30]:
They're out there. Yeah, better to fix them, I guess. The problem is there's such an onslaught. This is what I was saying 2 weeks ago, that Microsoft probably doesn't have time or the ability to test them, not, not as thoroughly as they'd like.

Steve Gibson [02:17:47]:
There's probably an urgency on their part to get them shipped. I mean, and unfortunately, when that happens, this happens.

Leo Laporte [02:17:54]:
A few years ago, I will have to ask Paul about this, Paul and Richard tomorrow on Windows Weekly. A few years ago, they got rid of their testing Team, which was maybe a little bit of a mistake.

Steve Gibson [02:18:05]:
We talked about it here also.

Leo Laporte [02:18:07]:
Yeah.

Steve Gibson [02:18:08]:
Yeah, we'll just let our customers be our, be our biggest—

Leo Laporte [02:18:11]:
I mean, right now you need, you want 1,000 people. You want somebody on every possible device. You know, you want every computer ever made, every server.

Steve Gibson [02:18:22]:
You cannot, you, you cannot scale that up overnight. And that's what they've had to do.

Leo Laporte [02:18:29]:
And, and I think, you know, one of the reasons I kind of laugh when I hear of these doomers talking about how AI is going to kill us all is— and you'll see this when you start playing with local AI. So AI is so smart, it found the flaws, but it didn't find all the side effects. You're so smart, you would think it would have noticed that this is going to break paste. And this has been my experience. They do amazing things, but there are gaps. There are places where they're incredibly stupid.

Steve Gibson [02:19:01]:
Well, Leo, because they don't actually understand anything. There is no understanding. It is astonishing that just language statistics is able to give us this. It's all it is, is language statistics. We have so much knowledge stored in language that you can query it, you can squeeze it out. But of course, it just, it doesn't understand anything.

Leo Laporte [02:19:26]:
And it, and it, so I'm having the same experience, uh, with my own coding. Really am very, very careful. I have auditors, I have, uh, you know, some really elaborate checks and balances. And yet, and man, I thought, oh, that's really good. The other day I was kind of dejected. I thought, I've got this ad sales system down. Everything's working It's working beautifully. All the numbers work out.

Leo Laporte [02:19:49]:
It looks beautiful. I said, Lisa, we're ready. I showed it to her. The very first thing she does, it doesn't crash. It says, oh, you can't save that. There's another user. There's no other user. What are you nuts? It's just us.

Leo Laporte [02:20:04]:
And it's like, ah, so close. And so it's frustrating because, yeah, they're not— They're not genius engineers. Even genius engineers make that kind of mistake, but these guys—

Steve Gibson [02:20:18]:
Well, what we don't yet know is whether AI code slop, or to what degree AI code slop is gonna be a problem. Are there, you know, I just enumerated the major problems that were created by Microsoft dropping nearly 1,000 patches. We don't know if there are subtler problems. Like maybe when you—

Leo Laporte [02:20:44]:
now we know. I guarantee you there are subtler problems. Guarantee you. You know, paste the letter Q into Excel and the whole thing goes kabooey. I guarantee you there, right? Because you can't test everything. Uh, in— it seems to me in theory, I don't know, you're a very accomplished coder. I guess my— Windows is just too big and Office is just too big. But in theory, it's deterministic.

Leo Laporte [02:21:10]:
You know where everything is— you don't though— wired up and what every— the impact will be of every change you make. It should all be cause and effect.

Steve Gibson [02:21:20]:
I'm still of the opinion that we could have a much better coding system because this is just using sample code from the internet. To knit together solutions. I mean, code is code. It has laws and rules.

Leo Laporte [02:21:39]:
And it's all deterministic ultimately.

Steve Gibson [02:21:42]:
I mentioned to you, I think it was before we were recording, that all of this has been done with a linguistic model. There are other models now underway. There are world models. There are models for for specific areas, like Microsoft apparently is training up a materials model for some reason. So it won't be language, it'll be something else. And it would be entirely possible to train, I think, somehow a code model that is not about language, but is actually about code.

Leo Laporte [02:22:25]:
Well, you know, there's a new model out there which you will be able to play with once you get your Spark plugged in called Jev, J-E-V, based— it's Jeevan's paradox, you know, and it's a classifier. It's not an LLM. It doesn't do prose, doesn't do language. And it's very fast and it's very interesting. And I'm actually starting to— I have about 11 tests going on in different things because It is a very fast and effective way to say this or that. And you give it the criteria, it gives you a percentage match, and it's really good. And it isn't language.

Steve Gibson [02:23:01]:
This is that branch that wonders if large language models are not compressors. Because gzip is basically a statistical compression. And so it turns out that you can do some odd things. It's sort of a branch of what you're talking about. So I have sort of run across that, but I haven't played with it.

Leo Laporte [02:23:26]:
Some very interesting stuff. And because it's so fast, it's very cheap. They don't even charge you for tokens out, just tokens in. It's really an— this is the good news. We're at the very beginning of a revolution.

Steve Gibson [02:23:39]:
Leo, that's what I keep saying. is that yes, that this is fun. We are riding a tidal wave and nothing we know today is true 60 days from now.

Leo Laporte [02:23:50]:
Which is why I'm really, really glad that you got a spark because I want you to start digging deep into this. I'm very interested in—

Steve Gibson [02:24:02]:
Well, I wanna accelerate my app development because it's dumb that it takes me years to create an app. So I, uh, I'm— the only thing I would ever have it do would be to build, to build my UI. But I spend an awful lot of time moving buttons around and, and tweaking margins and centering things and doing stuff that's dumb for me to spend time on.

Leo Laporte [02:24:25]:
That an AI could do very well.

Steve Gibson [02:24:26]:
So having a, having a core, my own MASM core in the backend that the, you know, that, that the— and, and a clean interface API between it and the UI, then I'm never— I will always be using cloud, agentic cloud coding to code the UI because I would— I'm only going to go for the best and local is never going to be as good as the cloud. No, that's true. So, at least for the foreseeable future, I do foresee a day when Microsoft is offering enterprises an AI server. There will be, you know, you will be able to, you know, there will be a Microsoft AI server.

Leo Laporte [02:25:08]:
Oh, for sure.

Steve Gibson [02:25:08]:
And the other thing that is weird, I shot you a note about it the other day, is to remind ourselves that none of this AI is training. I mean, all we're doing is building big prompts around a static AI. It's wrong that an AI that a corporation uses It wouldn't learn about like the right things about what the corporation is doing. It's just, you know, we're just building really fancy scaffolding around static AI. So we're just at the beginning.

Leo Laporte [02:25:40]:
Just at the beginning.

Steve Gibson [02:25:41]:
You know?

Leo Laporte [02:25:42]:
Yeah.

Steve Gibson [02:25:42]:
Baby steps.

Leo Laporte [02:25:44]:
Well, I'm excited and I'm so glad you're here to guide us through it. SteveGibson's at grc.com, the Gibson Research Corporation. That's where you'll find Spinrite, the world's best mass storage maintenance, recovery, and performance-enhancing utility. It's a must-have, 6.1, the current version. You can go there and get it. If you already have it, you can get the upgrade for free. He has another program he just put out, which is really cool, the DNS Benchmark Pro, $10 for that. And that will help you find the server for your particular network.

Leo Laporte [02:26:19]:
Which almost certainly is not the one you're using, at least not if you're using your ISP's DNS server. So that's a really nice utility, very nice tool to have. If you go there, besides those 2 things, you can also get a copy of the podcast. He has unique versions in every respect, a 16-kilobit audio version, which is a little scratchy but is small. That's its, you know, primary accomplishment. He also has The 64-kilobit, which sounds fine, still smaller than the one we offer. And he has the show notes, which are always fantastic. It's like a little mini novel arriving at your desk, 20 pages.

Leo Laporte [02:27:00]:
There's pictures, there's all sorts of things you can read along as you listen and reference on the road. By the way, the way to get that is, well, go to the website, gretzky.com, and click the link in that. By the way, there's also transcribed versions of the show. You can download those for searching as well. Dunno, they are wonderful. But if you want to, you can also do that. You need to go to grc.com/email. Now, the main purpose of that page is to whitelist your email, send you pictures of the week, ideas, thoughts, questions.

Leo Laporte [02:27:38]:
So do that, fill out your email address. He has some magic formula. He'll verify that you're a human without CAPTCHAs, I might add. But there are 2 little checkboxes below that. One is the show notes, so you can get on that mailing list. The other is a very infrequent new product mailing list. I would say check both of them, but they're unchecked by default, so you'll have to do that by hand. We also have copies of the show at our website, twit.tv/sn.

Leo Laporte [02:28:05]:
There's a YouTube channel for the video dedicated to Security Now. And of course, you can subscribe audio or video in your favorite podcast client. Now, if you want to watch us do it live, it's right after MacBreak Weekly every Tuesday. It's supposed to be and usually is close to roundabout somewhere within an hour of 1:30 PM Pacific, 4:30 Eastern, 20:30 UTC. You can watch live if you're in the club, and I hope you are. are, because that really helps us out, helps us keep doing these shows. If you're in the club, you can go to the Club Twit Discord and watch there with all the other club members. But you can also watch— everybody can— YouTube, Twitch, x.com, Facebook, LinkedIn, and Kick.

Leo Laporte [02:28:45]:
We stream it everywhere. Thank you everybody for joining us. Thank you, Mr. G. Have a wonderful evening and we'll see you next week.

Steve Gibson [02:28:53]:
See you on the 29th. Bye. Security now.

Leo Laporte [02:28:59]:
Security now.

All Transcripts posts