AI Patch Development Fails, WordPress Login XSS Hits All Versions, and DEF CON's Biggest Security Lessons
David Shipley covers new research from 1Password's Off By One Labs showing AI-generated vulnerability patches often fail: across 6,080 scored patches for six CVEs, only 26% fixed issues without changing behavior, 20% fixed while changing behavior, and 53.9% failed or introduced new flaws, with many "successful" patches deemed fragile.
A critical WordPress login-page XSS (CVE-2026-64638, CVSS 8.9) affects every version ever shipped; fixes landed in 7.0.3 and were backported to 4.7, leaving older versions vulnerable, as CISA tracks active exploitation alongside the recent "WP to Shell" RCE. T
he episode also details warnings about destructive OT attacks, a cyber incident forcing North Carolina ports into manual operations, and DEF CON talks on hacking 36M GPS trackers, misdirected "noreply" domains, and AI-driven HTTP desync research.
00:00 NordLayer Sponsor Message
00:37 Headlines And Intro
01:08 AI Patches Fail Often
03:19 WordPress Login XSS
05:40 Wipers Target Infrastructure
08:02 North Carolina Ports Hit
09:49 DEF CON Favorite Talks
10:15 GPS Trackers Takeover
11:28 Noreply Domain Email Leak
12:37 AI Finds HTTP Desyncs
13:47 Cliff Stoll Keynote
15:09 Wrap Up And Thanks
15:31 NordLayer Sponsor Close
Read the original article: