Security Now with Steve Gibson and Leo Laporte

Jul 28th 2026

Security Now 1089

Models Go Rogue & ExploitGym

Regulators, Start Your Engines

New episodes every Tuesday.
Category: Help & How To

What happens when an unconstrained OpenAI model goes rogue and hacks into Hugging Face, breaching real-world security boundaries? This episode unpacks a watershed moment for AI safety that has everyone in cybersecurity talking.

  • OpenAI's unconstrained internal testing AI got loose, attacked Hugging Face.
  • We hear from OpenAI, Hugging Face and Andrew Ng.
  • GRC went off the air Friday. Was GRC hacked? What happened?
  • The Linux kernel project repairs 442 CVEs in a single batch.
  • LG's PC monitors cause PC adware installation.
  • France bans all social media access below age 15.
  • WordPress' recent CRITICAL vulnerability claims victims.
  • Amazing details about "Rocky" from Andy Weir.
  • The new AI exploit ranking benchmark that caused the breakout

Show Notes - https://www.grc.com/sn/SN-1089-Notes.pdf

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit