SN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

SN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

Author: TWiT May 27, 2026 Duration: 2:44:00

Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage.

  • Cisco meets Mythos
  • Can the aging CVE system survive AI
  • Patch deployment latency in the AI age
  • MSFT's official YellowKey BitLocker bypass mitigation
  • Ubiquiti patches 5 serious vulnerabilities
  • Drupal attacked by a PostgreSQL injection
  • Microsoft terminates SMS as a second factor
  • GitHub hacked - all of its source code exfiltrated
  • Russia is using very old Western software
  • Why to get a no-charge AI chatbot account
  • New Sci-Fi on Netflix
  • What we learn from Mozilla's use of Mythos

Show Notes - https://www.grc.com/sn/SN-1080-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:


Every Tuesday, cybersecurity expert Steve Gibson sits down with Leo Laporte to dissect the week's most pressing digital threats. This isn't just a news recap; it's a detailed analysis where complex topics like emerging malware, data breaches, and software vulnerabilities are explained with clarity. The conversation in Security Now (Video) provides actionable insights, whether you're safeguarding a home network or responsible for enterprise infrastructure. As a production of TWiT, this video podcast delivers both visual aids and in-depth discussion, translating technical jargon into practical knowledge. Regular listeners gain a deeper understanding of the threat landscape and the evolving tools for defense. For those who want an enhanced experience, Club TWiT membership offers ad-free access to this and other shows. Tune in weekly to stay informed and build a more resilient digital life, as Steve and Leo unpack the stories that define our security reality.
Author: Language: en-us Episodes: 33

Security Now (Video)
Podcast Episodes
SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes [not-audio_url] [/not-audio_url]

Duration: 2:53:23
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's…
SN 1083: Patch Tuesday à la AI - Arch Linux Repo Under Siege [not-audio_url] [/not-audio_url]

Duration: 2:36:20
This episode unpacks the jaw-dropping surge in vulnerabilities unearthed by AI, revealing how Microsoft shattered its own patch records while adversaries and defenders race to outpace each other. The conversation gets re…
SN 1082: The Malicious Use of AI - Anthropic's Red Team Report [not-audio_url] [/not-audio_url]

Duration: 2:37:27
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm r…
SN 1078: DigiCert does it right - Hugging Face Under Fire [not-audio_url] [/not-audio_url]

Duration: 2:40:32
DigiCert's latest security mishap triggered not just a scramble behind the scenes, but a cascading crisis that briefly wiped trust from millions of Windows systems. Find out how a single support slip, followed by Microso…