Episodios

  • SN 1045: News and Listener Views - 2.3 Million Cisco Devices Exposed
    Oct 1 2025

    Cisco's routers just exposed more than two million networks thanks to a "security optional" SNMP setup that's being actively exploited—Steve and Leo break down why this is a worst-case scenario for the industry and how easily it could have been avoided.

    • Gmail's spam filtering false-positive spree.
    • iOS 26's Safari randomizes its fingerprint by default.
    • Cisco's SNMP stands for "Security Not My Problem".
    • Windows' "stuck" Extended Security Updates (ESU).
    • Europe complains, gets 1-year of ESU with no strings.
    • Where to get $6 TLS certs (really) while they last.
    • The lessons to learn from Jaguar Land Rover's mess.
    • The NEON app: get paid to have your voice recorded.
    • Bluesky's age verification, now coming to Ohio.
    • What is "Kids Web Services" for age verification.
    • More than 10K Ollama instances publicly exposed.
    • GRC's DNS Benchmark reaches "release candidate"

    Show Notes - https://www.grc.com/sn/SN-1045-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • vanta.com/SECURITYNOW
    • 1password.com/securitynow
    • Melissa.com/twit
    • threatlocker.com/twit
    • zapier.com/twit
    Más Menos
    2 h y 50 m
  • SN 1044: The EU's Online Age Verification - Consumer Reports vs. Microsoft
    Sep 24 2025
    • Consumer Reports on Windows 10 updates.
    • Waste (not fraud or abuse) within DoD Cyberoperations.
    • China's DeepSeek produces deliberately flawed code.
    • WebAssembly v3.0 officially released.
    • Firefox v143 updates and new features.
    • Firefox for Android now offers DoH.
    • A nearly terminal flaw in Microsoft's Entra ID.
    • Chrome hits its 6th 0-day this year. Emergency update.
    • DRAM (now DDR5) still vulnerable to RowHammer.
    • SAMSUNG kitchen refrigerators begin showing ads.
    • China says no to NVIDIA.
    • 300 more (new) NPM maliciouspackages found and removed.
    • The EU is already testing proper online age verification.

    Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • bigid.com/securitynow
    • go.acronis.com/twit
    • zscaler.com/security
    • 1password.com/securitynow
    • hoxhunt.com/securitynow
    Más Menos
    3 h y 1 m
  • SN 1043: Memory Integrity Enforcement - Crypto ATM Scam Epidemic
    Sep 17 2025

    Apple just rewrote the rules of device security with a chip-level upgrade that could wipe out most iPhone vulnerabilities overnight. Find out how "memory integrity enforcement" aims to make exploits a thing of the past—and why it took half a decade to pull off.

    • Are Bitcoin ATMs anything more than scamming terminals.
    • Ransomware hits the Uvalde school district and Jaguar.
    • Did "Scattered LapSus Hunters" just throw in the towel.
    • Germany, for one, to vote "no" on Chat Control.
    • Russia's new MAX messenger has startup troubles.
    • Samsung follows Apple's WhatsApp patch chain.
    • Shocker: UK school hacks are mostly by students.
    • HackerOne was hacked.
    • Connected washing machines in Amsterdam hacked.
    • DDoS breaks another record.
    • Bluesky to implement conditional age verification.
    • Enforcement actions for Global Privacy Control.
    • Might Apple have finally beaten vulnerabilities

    Show Notes - https://www.grc.com/sn/SN-1043-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • joindeleteme.com/twit promo code TWIT
    • vanta.com/SECURITYNOW
    • threatlocker.com for Security Now
    • bitwarden.com/twit
    • Melissa.com/twit
    Más Menos
    2 h y 51 m
  • SN 1042: Letters of Marque - 1.1.1.1 Certificate Snafu
    Sep 10 2025

    Is the U.S. on the verge of legalizing "hack back" missions, turning private companies into sanctioned cyber warriors? Steve and Leo unpack Google's plan for a cyber disruption unit and why the lines between defense and digital retaliation are suddenly blurring.

    • My experience with 'X' vs email.
    • Google TIG blackmailed to fire two security researchers.
    • 1.1.1.1 DNS TLS certificate mis-issued.
    • Artists blackmailed with threats of training AI on their art.
    • Firefox extended end-of-life for Windows 7 to next March.
    • Is the renewal of cybersecurity info sharing coming soon.
    • Should security analysis be censored due to vibe-coding.
    • UK versus Apple may not be settled after all.
    • Another very serious supply chain attack.
    • Can the software supply-chain ever be trustworthy.
    • Why did BYTE Magazine die.
    • What happens if Google and others go on the attack

    Show Notes - https://www.grc.com/sn/SN-1042-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • uscloud.com
    • canary.tools/twit - use code: TWIT
    • bigid.com/securitynow
    • zscaler.com/security
    • expressvpn.com/securitynow
    Más Menos
    2 h y 56 m
  • SN 1041: Covering All the Bases - SHAKEN Networks, Uncontrollable AI, and Robocall Reckoning
    Sep 3 2025

    When even the Department of Defense can't properly vet its software dependencies, what chance do the rest of us have? Steve Gibson reveals how "fast-glob" became a case study in supply chain blindness, explores whether AI can ever truly be controlled after Meta's celebrity chatbot disaster, and celebrates BYTE Magazine's 50th anniversary with a look at how far we've come (and how vulnerable we still are).

    • A look back at issue #1 of BYTE magazine exactly 50 years ago
    • The enforcement of the SHAKEN & STIR Telecom protocols
    • Breaking: Judge rules against forced Google divestitures in monopoly case
    • The inherent danger of consolidating authentication
    • Can AI be controlled?
    • Vivaldi says a big "no" to AI-enhanced web browsers
    • How WhatsApp figured into Apple's recent 0-day attacks
    • Leveraging AI as an attack aid
    • The latest TransUnion data breach
    • Two scummy websites sue the UK over age requirements
    • OpenSSH reminds its users to adopt post-quantum crypto
    • The DOD uses open source maintained by a Russian national
    • Much great feedback from our terrific listeners
    • Sci-Fi news from "The Frontiers Saga" Ryk Brown

    Show Notes - https://www.grc.com/sn/sn-1041-notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • go.acronis.com/twit
    • threatlocker.com/twit
    • bitwarden.com/twit
    • bigid.com/securitynow
    • joindeleteme.com/twit promo code TWIT
    Más Menos
    3 h y 3 m
  • SN 1040: Clickjacking "Whac-A-Mole" - Inside the Password Manager Clickjacking Frenzy and What It Means
    Aug 27 2025

    Alarm bells are ringing over a supposed browser zero-day, but is the threat as bad as it sounds? Steve reveals why "clickjacking" might be more whac-a-mole than breaking news, and what that really means for your passwords.

    • Germany may soon outlaw ad blockers
    • What's happening in the courts over AI
    • The U.K. drops its demands of Apple
    • New Microsoft 365 tenants being throttled
    • Is Russia preparing to block Google Meet?
    • Bluesky suspends its service in Mississippi
    • How to throttle AI
    • A tricky SSH-busting Go library
    • Here comes the Linux desktop malware
    • Apple just patched a doozy of a vulnerability
    • A trivial Docker escape was found and fixed
    • Why the recent browser 0-day clickjacking is really just whac-a-mole

    Show Notes - https://www.grc.com/sn/sn-1040-notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • 1password.com/securitynow
    • zscaler.com/security
    • bigid.com/securitynow
    • uscloud.com
    Más Menos
    2 h y 51 m
  • SN 1039: The Sad Case of ScriptCase - Data Brokers Dodge Deletion
    Aug 20 2025
    • What AI website summaries mean for Internet economics.
    • Time to urgently update Plex Servers (again).
    • Allianz Life stolen data gets leaked.
    • Chrome test Incognito-mode fingerprint script blocking.
    • Chrome 140 additions coming in 2 weeks.
    • Data brokers hide opt-out pages from search engines.
    • Secure messaging changes in Russia.
    • NIST rolls-out lightweight IoT crypto.
    • SyncThing moves to v2.0 and beyond.
    • Alien:Earth -- first take.
    • What can we learn from another critical vulnerability?

    Show Notes - https://www.grc.com/sn/SN-1039-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • threatlocker.com/twit
    • bitwarden.com/twit
    • go.acronis.com/twit
    • joindeleteme.com/twit promo code TWIT
    • vanta.com/SECURITYNOW
    Más Menos
    2 h y 52 m
  • SN 1038: Perplexity's Duplicity - Malicious Repository Libraries
    Aug 13 2025
    • CISA's Emergency Directive to ALL Federal agencies re: SharePoint.
    • NVIDIA firmly says "no" to any embedded chip gimmicks.
    • Dashlane is terminating its (totally unusable) free tier.
    • Malicious repository libraries are becoming even more hostile.
    • The best web filter (uBlock Origin) comes to Safari.
    • The very popular SonicWall firewall is being compromised.
    • >100 models of Dell Latitude and Precision laptops are in danger.
    • The significant challenge of patching SharePoint (for example).
    • A quick look at my DNS Benchmark progress.
    • Does InControl prevent an important update.
    • An venerable Sci-Fi franchise may be getting a great new series.
    • What to do about the problem of AI "website sucking"

    Show Notes - https://www.grc.com/sn/SN-1038-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • zscaler.com/security
    • canary.tools/twit - use code: TWIT
    • uscloud.com
    • go.acronis.com/twit
    Más Menos
    3 h y 4 m