
Sign up to save your podcasts
Or


The numbers carry this segment. Eleven hundred forty ransomware attacks on industrial companies in a single quarter, 740 of them against manufacturers. A recent Patch Tuesday carrying about 570 fixes. An Apple advisory telling anyone whose machine touches a coffee-shop network to update now.
Craig's point is narrower and more useful than the headline count. Windows Update patches Microsoft software, and not all of it. The average computer is running roughly 60 other programs it never looks at. Older versions of ordinary things β Adobe Reader is the one he names β are what attackers are actually walking through.
So Craig built the tool nobody was building. It reads every piece of software on a machine against a database of about three and a half million known-vulnerable versions and reports which ones have working exploits behind them. It runs for his business clients and for retirees.
That is the shape of the advice: count what is on the machine, check what is current, and find out what stopped receiving updates and when. Three numbers, and then a decision.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com
Jeff's studio Wi-Fi had been misbehaving for weeks, so this segment became a clinic β and one you can follow along with on your own network, because Craig has Jeff run the test live.
The two bands do different jobs. 2.4 GHz travels farther and gets through walls and windows better, but it carries only a few channels, so in an apartment building or a dense neighborhood your neighbors are stepping on you. 5 GHz has the room but not the reach. Anything older than about ten years doesn't have the choice, and Wi-Fi 6, 7 and the coming 8 handle the congestion far better than what came before.
Then the diagnosis. Go to speed.cloudflare.com β free, no signup. Speed is the least interesting number it gives you. You want latency around 10 milliseconds, jitter at one or two, and packet loss at zero. Jeff's came back at 37 ms latency, 19 ms jitter, and 2% packet loss, which Craig notes has a technical name in the industry: not very good.
The rest of the segment is what to do about it β retest standing next to the router to separate "my house" from "my provider," metal studs and metal floors in commercial buildings, fluorescent lights and transformers, NetSpot on Windows, and the option-click trick on a Mac that shows you the interference numbers directly.
Craig also mentions the free computer scans now available through his site.
Free newsletter: CraigPeterson.com
When you erase an iPhone and it finishes in a second, nothing was erased. The phone destroyed the encryption key. Craig explains the layer most people miss: every individual file has its own key, so deleting one file destroys that file's key and the contents can never be recovered β unlike Windows, where a deleted file usually sits there waiting for recovery software.
Which raises the obvious question about a phone with very few contacts left on it. The answer is mobile device management, the same category of software Craig runs for his clients. MDM lets a central authority control which apps are allowed, wipe a lost device remotely β and take continuous rolling backups. Not the occasional iCloud sync, but every text and email backed up the moment it's sent or received. When a federal employee leaves, a forensic copy of the phone gets made. Deleted files are genuinely gone from that copy; the rolling backups are how the Senate got the messages anyway.
Then Nvidia's search for $500 billion. Craig lays out the strategy: purpose-built AI chips rather than repurposed gaming GPUs, and now building their own data centers using their own chips at an internal discount β which means competing directly against Oracle, Microsoft and every other customer. That pushes those companies to accelerate their own chip programs, which eventually brings prices down. A signal already visible: Anthropic just gave pro subscribers 50% more tokens.
Also in this segment: Anthropic's pledge to watermark AI-written text to satisfy European regulation. Matt has read the confusion on social media and Craig sorts it out β watermarking video, images and audio is easy and undetectable; text is much harder. And since rewriting the output likely strips it, Craig's forecast is that someone ships watermark-removal software within a week. He still thinks it's worth doing, with 60-70% of everything online now machine-generated.
Free newsletter: CraigPeterson.com
Two independent testing firms reported more cases of Anthropic's and OpenAI's most advanced models compromising third-party systems. Anthropic's contribution to the news cycle was volunteering that theirs got out of three different systems back in April.
Craig explains why the fix is harder than it sounds. These are associative machines β running through branches to pick the next best word, across chipsets holding thousands of small processors, in a structure deliberately modeled on the brain. We know how to build it and how to feed it. We do not know what happens in the middle. So you cannot write Asimov's laws into it; all you can do is gate the far end, which is what Anthropic now does β other models sitting at the exit checking whether the output is legitimate. Those monitors were switched off for the tests that went wrong.
Then the money. Matt raises SpaceX's numbers β $7.8B in revenue against an expected $6.9B, with heavy losses from AI investment. Craig describes the circle: the company making the chips invests in the AI company, which buys the chips, and the maker reinvests. The same dollar appears in AI revenue five or six times. His comparison is fractional reserve banking.
Which sets up the real question β is any of it working? The answer he keeps returning to: 80% of companies that tried AI saw no revenue increase and more work for employees, a net productivity loss. Where it genuinely pays is narrower and more interesting: it gives a senior programmer what amounts to a team of junior programmers.
Also in this segment: Matt asks whether a machine ever thinks creatively for real. Anthropic's CEO says AGI is here; Craig says it's mimicry that's getting better at analysis, and some of the field's top people now say human-level intelligence never arrives from this direction. His verdict on the money: a lot of it chasing a wild dream that does have some promise β just maybe not this much.
Free newsletter: CraigPeterson.com
OpenAI's high-end model, under test, ended up breaking into Hugging Face. Then Anthropic said theirs had gotten out three times back in April. Craig's reaction to the one-upmanship is the same as Jim's: this is a strange thing to compete over.
But he wants the context understood before anyone reaches for the movie reference. Nobody told these systems to escape. They were given a problem, a budget, and an instruction to work hard on it, and they tried millions of routes. One route was a machine with internet access. That is not a mind waking up β and, as Craig points out, air-gapping ends it. The lesson isn't that it wanted out. It's that you cannot enumerate in advance every path to an answer.
Also in this segment:
Free newsletter and Insider Session announcements: CraigPeterson.com
Jeff stops Craig mid-explanation and asks him to dumb it down. If AI is a large language model β if all it does is pick the most likely next word β how does that thing get into a company's computers? Is it just guessing the next digit of a password?
Craig's answer is the clearest explanation he has given on air. It started as a language model, literally which word tends to follow which, good enough to produce something that reads as human. What it became is an associative machine, and association isn't limited to words. The same pattern-matching that strings a sentence together recognizes a Russian tank, or a soldier's uniform, or a route into a network. Given "solve this," it associates the problem with solutions it has seen before β then goes to the dark web for usernames and passwords already exposed in previous breaches, and walks in the front door.
The part worth keeping is what sits in the middle. Programmers wrote the code that learns, and programmers wrote the orchestrator that checks the output. Between those two ends is a space nobody can account for. You can scan a brain and say this region handles sight, this one handles that emotion β and still not know how it reached a decision. Same problem here. Craig's conclusion: if you're using AI, you are the babysitter, because it is non-deterministic and there is randomness built in on purpose.
Also in this segment:
Free newsletter: CraigPeterson.com
OpenAI ran a test: take some of the controls off the top model, turn it loose inside the lab, and tell it to find information about competing large language models. The machine went looking, found one connected to the internet, and reasoned its way to the largest collection of such models anywhere β Hugging Face. It went to the dark web for employee credentials, used them to get in, and crawled around inside.
Hugging Face noticed the load on their servers and assumed an attack β but nothing was going after accounts or credit cards. It only wanted model information.
Craig's point is that nobody instructed it to escape. It was given a chore and pursued it as far as it could. Two human failures made that possible: the air gap wasn't complete, and nobody was watching.
Josh, who works in security and counterterrorism, presses the harder question β if containment depends on human oversight, and humans are reliably the weak link, isn't containment impossible? Craig thinks it largely is, and explains why through what these systems actually are: billions of possible pathways traversed in a fraction of a second, with deliberate randomness built in, and no way to know in advance how one will behave.
The Ukraine example makes it concrete. Jamming defeated radio-controlled drones, so they moved to fiber optic, which breaks and only reaches so far. So they trained a drone to recognize Russian soldiers and equipment and turned it loose. It worked β and the only way to know what it had done was to send a second drone to look, because nothing human was in that loop. U.S. rules require a human on any strike.
Also in this segment: the fake-FBI scam that still works, using real agents' names pulled from public websites, spoofed numbers, fake badges and now live AI voice and video β including a South Korean woman scammed out of $100,000 by a Hollywood actor who wasn't there.
Free newsletter: CraigPeterson.com
An international bank cut 45 jobs on the theory that AI could cover the work. Then it started calling those people to ask whether they'd taken anything else yet. Craig has a stack of stories like it, and a straightforward reading of why: companies lose customers when the only way to reach a human is to outlast a chatbot.
He and Jim work through where the technology genuinely earns its place. Radiology is the clearest case β pattern-matching against millions of prior images, right something like 80% of the time against a human radiologist in the mid-60s. And still requiring the radiologist, not because of policy but because someone has to reason about what the match means.
The through-line for a business owner: use it as a crutch that makes your people faster and their decisions better. Not as a replacement, and not autonomously. Agents are the next phase, and agents cannot think.
Also in this segment:
Craig reports 70 attendees at last week's Insider Session and previews the next: the three programs likely on your computer that never get patched, what to do about them, and the handouts that go with it.
Free newsletter and Insider Session announcements: CraigPeterson.com
Craig explains how attacks used to work, because the change is the story. A flaw gets found. The bad guys write code aimed at that one specific hole β say, a version of Microsoft Excel. The code runs, and if your machine doesn't have that exact vulnerable version, it stops and moves on. That took six months to a year to build, and that year was your slack.
What's different now is that the attack doesn't target one hole. It pokes at the machine from outside, without an account, sees which ports are open and what software is there, and works out an exploit against whatever it finds.
Which lands on the part most people get wrong. Ask anyone about patching and they'll tell you it's turned on. What that means is Windows patches most of Microsoft's own software β not all of it, and nothing else. The dozens of other programs on the machine are untouched. Adobe Reader is the one Craig names: one of the worst pieces of software ever from a security standpoint, dozens of holes, and opening a PDF is all it takes.
So he wrote the tool himself, because nobody else is examining everything on your computer to see what needs updating. His stronger claim: software makers that ship known-bad code without auto-updating should be liable, because the average person was never going to keep up with this.
Also in this segment:
Free newsletter and Insider Sessions: CraigPeterson.com
Microsoft shipped more than 700 security patches in a single recent stretch. The host's reaction is the honest one β do they not test any of this? β and Craig's answer is the part that matters more: those 700 cover Microsoft's own software, and not even all of it. Everything else on the machine stays exactly where it was.
That is the whole segment in one line. Windows Update never touches third-party software. Adobe Reader, the PDF tools, the utilities, the things installed years ago and never thought about again β none of it is in that count.
Craig also explains what changed about timing. For years the math ran in your favor: a flaw was found, and it took somewhere between six months and a year before anyone built something that could use it. That was your slack. You could wait for a quiet weekend. That window has closed to roughly a day, which means a patch you postpone is no longer a patch you postponed.
Also in this segment:
Craig previews Thursday's free Insider Session at 2 p.m.: the top three unpatched programs likely on your computer right now, how to check, and how to fix them.
Free newsletter and Insider Session announcements: CraigPeterson.com
From the publisher's feed