Security Now (Audio) · TWiT

Mongo's Too Easy - AI Bug Bounties Gone Wild

February 4, 2026·2 hr 56 min·5 clips
E-scan antivirus was breached again, infecting users via its update server and using obfuscated malware to block fixes.
Episode 1063 starts with a run of bad-news teasers. The cold open points to an antivirus infecting its own users, Curl discontinuing bug bounties, and MongoDB making hacking feel almost too easy. The mood is dry and a little grim, the usual Security Now rhythm of looking at security messes and asking what could possibly go wrong. Then the OpenSSL excerpt gets more practical. A listener explains that his company tracks new OpenSSL releases because its products rely on OpenSSL cryptographic primitives. Steve slows down for that. He is less interested in the raw count than in the habit behind it: checking whether 12 newly disclosed vulnerabilities matter to your own software. That gets real approval. His phrase is non-finger-pointing security, meaning you do not get to import a library and then import an excuse. Plenty of organizations link and forget. Steve's point is that the breach still lands on your systems when a third party component fails under your care. The AI piece gives the story some bite. According to the listener, all 12 OpenSSL zero-days were found by AISLE, an AI based cybersecurity company. That makes AI bug hunting feel real inside the disclosure pipeline. Curl's bounty retreat sits right next to it, since the excerpt says AISLE's work led Curl to cancel its bug bounty program. MongoDB stays the title's blunt example. If the hacking skill bar really drops to the floor, exposure becomes routine hygiene, not just specialist defense. The segment does not sell doom. It keeps coming back to mechanism, responsibility, and knowing what code your product depends on.

As heard by us

A practical Security Now episode on AI-found OpenSSL bugs, fragile dependencies, and the cost of treating third-party code as someone else's responsibility.

Security Now turns a packed security week into a pointed warning about misplaced trust. Steve Gibson tees up an antivirus that infects its own users, curl ending its bug bounties, and MongoDB lowering the skill bar for attackers, then settles into a sharper discussion of…

Read the full review in PlayNext →

Why you'd press play

An AI just found twelve OpenSSL zero-days at once, and MongoDB has apparently made hacking embarrassingly easy.

Read the full recommendation in PlayNext →
Listen to the show on