Episodios

  • SN 1022: The Windows Sandbox - Short-life Certs, Ransomware Payout Stats
    Apr 23 2025
    • Enabling Firefox's Tab Grouping.
    • Recalled Recall Re-Rolls out.
    • The crucial CVE program nearly died. It's been given new life.
    • China confesses to hacking the US (blames our stance on Taiwan).
    • CISA says what Oracle still refuses to.
    • Brute force attacks on the (rapid) rise.
    • An AI/ML Python package rates a 9.8 (again!)
    • The CA/Browser forum passed short-life certs. :(
    • A wonderful crosswalk hack hits Silicon Valley.
    • Android to add force restarting ahead of schedule. Maybe.
    • The EFF is never happy. But especially now, about Florida.
    • Interesting research into ransomware payouts.
    • Windows Sandbox: The amazing gem hidden inside all Windows 10 & 11!

    Show Notesb - https://www.grc.com/sn/SN-1022-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • joindeleteme.com/twit promo code TWIT
    • drata.com/securitynow
    • bigid.com/securitynow
    • 1password.com/securitynow
    • material.security
    Más Menos
    2 h y 53 m
  • SN 1021: Device Bound Session Credentials - Hotpatching in Win 11, Apple vs. UK
    Apr 16 2025
    • Android to get "Lockdown Mode".
    • What's in the new editions of Chrome and Firefox?
    • Why did Apple silently re-enable automatic updates?
    • My new iPhone 16, Chinese tariffs and electronics.
    • Dynamic "hotpatching" coming to Win11 Enterprise & Edu.
    • Why is it so difficult for Oracle to fess up?
    • Another multi-year breach inside US Treasury.
    • An Apple -vs- the UK update.
    • "Thundermail" (Can't someone come up with a better name?)
    • The (in)Security of Programmable Logic Controllers.
    • When LLM's write code and hallucinate non-existent packages.
    • Wordpress core security and PHP gets an important audit.
    • Device-Bound Session Credentials update session cookie technology

    Show Notes - https://www.grc.com/sn/SN-1021-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • expressvpn.com/securitynow
    • vanta.com/SECURITYNOW
    • threatlocker.com for Security Now
    • legatosecurity.com
    • bitwarden.com/twit
    Más Menos
    3 h y 15 m
  • SN 1020: Multi-Perspective Issuance Corroboration - IoT Done Right, France Phishes, Gmails E2EE
    Apr 9 2025
    • Canon printer driver vulnerabilities enable Windows kernel exploitation.
    • Astonishing cyber-security awareness from a household appliance manufacturer.
    • France tries to hook 2.5 million school children with a Phishing test.
    • Wordpress added an abuse prone feature in 2022. Guess what happened?
    • Oracle? Is there something you'd like to tell us?
    • Utah's governor just signed the App Store Accountability Act. Now what?
    • AI bots hungry for new data are DDoSing FOSS projects.
    • No Microsoft Account? No Microsoft Windows 11.
    • Gmail claims it now offers E2EE. It kinda sorta does. Somewhat.
    • A dreaded CVSS 10.0 was discovered in Apache Parquet.
    • A bunch of terrific listener feedback.
    • What's Multi-Perspective Issuance Corroboration and why must all certificate authorities now do it?

    Show Notes - https://www.grc.com/sn/SN-1020-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • material.security
    • threatlocker.com for Security Now
    • canary.tools/twit - use code: TWIT
    • joindeleteme.com/twit promo code TWIT
    • bitwarden.com/twit
    Más Menos
    3 h y 8 m
  • SN 1019: EU OS - Troy Hunt Phished, Ransomware List, InControl
    Apr 2 2025
    • Kuala Lumpur International Airport says no to a ransom attack, switches to whiteboard.
    • A tired and jet-lagged Troy Hunt got Phished then listed himself on his own site.
    • Cloudflare completely pulls the plug on port 80 (HTTP) API access.
    • Malware is switching to obscure languages to avoid detection. FORTH, anyone?
    • Password reuse doesn't appear to be dropping. Cloudflare has numbers.
    • A listener shares his log of malicious Microsoft login attempts. Why no geofencing?
    • 23andMe down for the count (reminder).
    • A sobering Ransomware attack & victim listing website. Gulp!
    • "InControl" keeps VR planes aloft.
    • And the European Union gets serious about a switch to Linux

    Show Notes - https://www.grc.com/sn/SN-1019-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • drata.com/securitynow
    • outsystems.com/twit
    • bitwarden.com/twit
    • threatlocker.com for Security Now
    • legatosecurity.com
    Más Menos
    3 h y 5 m
  • SN 1018: The Quantum Threat - ESP32 Backdoor Update, RCS E2EE
    Mar 26 2025
    • The dangers of doing things you don't understand.
    • Espressif responds to the claims of an ESP32 backdoor.
    • A widely leveraged mistake Microsoft stubbornly refuses to correct.
    • A disturbingly simple remote takeover of Apache Tomcat servers.
    • A 10/10 vulnerability affecting some ASUS, ASRock and HPE motherboards.
    • Google snapped up another cloud security firm but paid a price!
    • RCS messaging to soon get full end-to-end encryption (done right!).
    • How did an AI Crypto Chatbot lose $105,000? ...and what is an AI Crypto Chatbot?
    • Looks like Oracle may take stewardship of TikTok to keep it in-country.
    • Whoops! 23andMe is sinking — don't let them take your genetics with them!
    • The White House says "the cyber guys should stay!"
    • AI project failure rates are on the rise. Anyone surprised?
    • Listener feedback, and a very interesting update on just how looming is the threat from quantum computing?

    Show Notes - https://www.grc.com/sn/SN-1018-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • zscaler.com/security
    • legatosecurity.com
    • joindeleteme.com/twit promo code TWIT
    Más Menos
    2 h y 53 m
  • SN 1017: Is YOUR System Vulnerable to RowHammer? - Telegram's Crypto, Twitter Outage, FBI Warning
    Mar 19 2025
    • An analysis of Telegram Messenger's crypto.
    • A beautiful statement of the goal of modern crypto design.
    • Who was behind Twitter's recent outage trouble?
    • An embedded Firefox root certificate expired. Who was surprised?
    • AI-generated Github repos, voice cloning, Patch Tuesday and an Apple 0-day.
    • The FBI warns of another novel attack vector that's seeing a lot of action.
    • Google weighs in on the Age Verification controversy.
    • In a vacuum, Kazakhstan comes up with their own solution.
    • Was Google also served an order from the UK? Can they say?
    • A serious PHP vulnerability you need to know you don't have.
    • A bunch of great listener feedback, some Sci-Fi content reviews and...
    • A new tool allows YOU to test YOUR PCs for their RowHammer susceptibility

    Show Notes - https://www.grc.com/sn/SN-1017-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • vanta.com/SECURITYNOW
    • bitwarden.com/twit
    • threatlocker.com for Security Now
    • veeam.com
    Más Menos
    2 h y 54 m
  • SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back
    Mar 12 2025
    • Utah passes age verification requirement for app stores.
    • The inside story on fake North Korean employees. Is that a Texas accent?
    • An update on the ongoing Bybit cryptoheist saga.
    • The industry may be making some changes in the wake of the Bybit attack.
    • Apple pushes back legally against the UK's secret order.
    • Did someone crack Passkeys?
    • The UK launches a legal salvo at an innocent security researcher.
    • The old data breach we witnessed that just keeps on giving.
    • A bit more Bybit postmortem forensic news.
    • A lesson to learn from a clever and effective ransomware attack.
    • And what about that Bluetooth Backdoor discovery everyone is talking about?

    Show Notes - https://www.grc.com/sn/SN-1016-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • 1password.com/securitynow
    • uscloud.com
    • joindeleteme.com/twit promo code TWIT
    • zscaler.com/security
    • canary.tools/twit - use code: TWIT
    Más Menos
    2 h y 57 m
  • SN 1015: Spatial-Domain Wireless Jamming - Firefox Privacy Policy, Signal Leaving Sweden?
    Mar 5 2025
    • Firefox amends their privacy policy -- the world melts down.
    • Signal threatens to leave Sweden.
    • Aftermath of the massive $1.5 billion Bybit ETH heist.
    • It turns out that it wasn't actually Bybit's fault.
    • "The Lazarus Bounty" monitoring and management site.
    • Mozilla's commitment to Manifest V2 (and the uBlock Origin).
    • What does the ACM's plea for memory-safe languages mean for developers?
    • What exactly are memory-safe languages?
    • Australia joins the Kaspersky ban.
    • Gmail plans to switch from SMS to QR code authentication.
    • A SpinRite success and some fun feedback.
    • An astonishing new technology for targeted radio jamming

    Show Notes - https://www.grc.com/sn/SN-1015-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • legatosecurity.com
    • bitwarden.com/twit
    • veeam.com
    • threatlocker.com for Security Now
    Más Menos
    2 h y 53 m
adbl_web_global_use_to_activate_webcro768_stickypopup