SN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

SN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

Author: TWiT May 27, 2026 Duration: 2:44:00

Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage.

  • Cisco meets Mythos
  • Can the aging CVE system survive AI
  • Patch deployment latency in the AI age
  • MSFT's official YellowKey BitLocker bypass mitigation
  • Ubiquiti patches 5 serious vulnerabilities
  • Drupal attacked by a PostgreSQL injection
  • Microsoft terminates SMS as a second factor
  • GitHub hacked - all of its source code exfiltrated
  • Russia is using very old Western software
  • Why to get a no-charge AI chatbot account
  • New Sci-Fi on Netflix
  • What we learn from Mozilla's use of Mythos

Show Notes - https://www.grc.com/sn/SN-1080-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:


Every Tuesday, cybersecurity expert Steve Gibson sits down with Leo Laporte to dissect the week's most pressing digital threats. This isn't just a news recap; it's a detailed analysis where complex topics like emerging malware, data breaches, and software vulnerabilities are explained with clarity. The conversation in Security Now (Video) provides actionable insights, whether you're safeguarding a home network or responsible for enterprise infrastructure. As a production of TWiT, this video podcast delivers both visual aids and in-depth discussion, translating technical jargon into practical knowledge. Regular listeners gain a deeper understanding of the threat landscape and the evolving tools for defense. For those who want an enhanced experience, Club TWiT membership offers ad-free access to this and other shows. Tune in weekly to stay informed and build a more resilient digital life, as Steve and Leo unpack the stories that define our security reality.
Author: Language: en-us Episodes: 33

Security Now (Video)
Podcast Episodes
SN 1098: How worried should we be? - Unpredictable Agents [not-audio_url] [/not-audio_url]

Duration: 2:42:18
With millions racing to embrace AI assistants and cybercriminals pivoting to new, high-stakes tactics, the episode tackles the dizzying pace of change and asks: just how worried should we be? The discussion pulls back th…
SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers [not-audio_url] [/not-audio_url]

Duration: 2:50:02
After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided…
SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked [not-audio_url] [/not-audio_url]

Duration: 2:50:47
Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? The full report on last week's nearly 1,000 Microsoft security…
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails [not-audio_url] [/not-audio_url]

Duration: 2:49:05
From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI…
SN 1091: The Post BlackHat State of AI - When AI Writes Malware [not-audio_url] [/not-audio_url]

Duration: 2:51:12
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber…