Episódios

  • SN 1033: Going on the Offensive - The Digital Arms Race
    Jul 9 2025
    • Another Israeli spyware vendor surfaces.
    • Win11 to delete restore points more quickly.
    • The EU accelerates its plans to abandon Microsoft Azure.
    • The EU sets timelines for Post-Quantum crypto adoption.
    • Russia to create a massive IMEI database.
    • Canada and the UK create the "Common Good Cyber Fund".
    • U.S. states crack down on Bitcoin ATMs amid growing scams.
    • Congressional staffers cannot use WhatsApp on gov devices.
    • LibXML2 and the problems with commercial use of OSS.
    • A(nother) remote code execution vulnerability in WinRAR.
    • Have-I-Been-Pwned gets a cool data visualization site.
    • How is ransomware getting in?
    • Windows to offer "safe" non-kernel endpoint security?
    • Proactive age verification coming to porn sites. How?
    • Canada (also) says "bye bye" to Hikvision.
    • Germany will be banning DeekSeek. The whole EU may follow.
    • Cloudflare throttled in Russia?
    • What must the U.S. do to compete in global exploit acquisition?

    Show Notes - https://www.grc.com/sn/SN-1033-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • expressvpn.com/securitynow
    • Melissa.com/twit
    • 1password.com/securitynow
    • hoxhunt.com/securitynow
    • canary.tools/twit - use code: TWIT
    Exibir mais Exibir menos
    3 horas e 5 minutos
  • SN 1032: Pervasive Web Fingerprinting - How Websites Tracks You Despite Cookie Blocks
    Jul 2 2025

    • Let's Encrypt drops its long-running email notifications.
    • Microsoft's new "Unexpected Restart Experience".
    • Microsoft's response to last year's massive CrowdStrike outage.
    • Windows 10's extended service updates will sort of be free.
    • Russia-sold iPhones MUST include the RuStore app.
    • Lyon, in France, says bye-bye to Windows. Hello to Linux.
    • The US Gov gets more serious about memory-safe languages.
    • A new unbelievable AI malware scanner evaSion technique.
    • A new pair of Cisco 9.8 and 10.0 vulnerabilities.
    • The current state of post-Elon government cybersecurity.
    • PNGv3, Swift on Android, and the Samsung email purge.
    • Andy Weir's "Hail Mary" movie trailer.
    • And a close look at the pervasiveness of web browser tracking fingerprinting.

    Show Notes - https://www.grc.com/sn/sn-1032-notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • go.acronis.com/twit
    • bitwarden.com/twit
    • threatlocker.com/twit
    • joindeleteme.com/twit promo code TWIT
    Exibir mais Exibir menos
    2 horas e 58 minutos
  • SN 1031: How Salt Typhoon Gets In - What "AI" Really Means
    Jun 25 2025
    • China's Salt Typhoon claims another victim (or two).
    • State healthcare portals are tracking and leaking. No kidding.
    • Apple adopts FIDO's Passkeys and other credentials transport.
    • Facebook gets Passkey logon.
    • TikTok continues ticking for at least another 90 days.
    • Canadian telco admits they were infiltrated by Salt Typhoon.
    • Microsoft to remove unwanted (and hopefully unneeded) hardware drivers.
    • The Austrian government legislates court-warranted message decryption.
    • I (Steve) finally get full clarity on what today's "AI" means.
    • A deep dive into the Salt Typhoon's operation and how they got in

    Show Notes - https://www.grc.com/sn/SN-1031-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • 1password.com/securitynow
    • hoxhunt.com/securitynow
    • outsystems.com/twit
    • bigid.com/securitynow
    • zscaler.com/security
    Exibir mais Exibir menos
    3 horas e 1 minuto
  • SN 1030: Internet Foreground Radiation - The NPM Repository is Under Siege
    Jun 18 2025
    • An exploited iOS iMessage vulnerability Apple denies?
    • The NPM repository is under siege with no end in sight.
    • Were Comcast and Digital Realty compromised? Don't ask them.
    • Matthew Green agrees: XChat does not offer true security.
    • We may know how Russia is convicting Telegram users.
    • Microsoft finally decides to block two insane Outlook file types.
    • 40,000 openly available video camera are online. Who owns them?
    • Running SpinRite on encrypted drives.
    • An LLM describes Steve's (my) evolution on Microsoft security.
    • What do we know about the bots that are scanning the Internet?

    Show Notes - https://www.grc.com/sn/SN-1030-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • joindeleteme.com/twit promo code TWIT
    • bitwarden.com/twit
    • material.security
    • drata.com/securitynow
    • bigid.com/securitynow
    Exibir mais Exibir menos
    2 horas e 48 minutos
  • SN 1029: The Illusion of Thinking - Meta Apps and JavaScript Collusion
    Jun 11 2025
    • In memoriam: Bill Atkinson
    • Meta native apps & JavaScript collude for a localhost local mess.
    • The EU rolls out its own DNS4EU filtered DNS service.
    • Ukraine DDoS's Russia's Railway DNS ... and... so what?
    • The Linux Foundation creates an alternative Wordpress package manager.
    • Court tells OpenAI it must NOT delete ANYONE's chats. Period! :(
    • A CVSS 10.0 in Erlang/OTP's SSH library.
    • Can Russia intercept Telegram? Perhaps.
    • Spain's ISPs mistakenly block Google sites.
    • Reddit sues Anthropic.
    • Twitter's new encrypted DM's are as lame as the old ones.
    • The Login.gov site may not have any backups.
    • Apple explores the question of recent Large Reasoning Models "thinking"

    Show Notes - https://www.grc.com/sn/SN-1029-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • hoxhunt.com/securitynow
    • threatlocker.com for Security Now
    • uscloud.com
    • canary.tools/twit - use code: TWIT
    Exibir mais Exibir menos
    2 horas e 46 minutos
  • SN 1028: AI Vulnerability Hunting - The End of Jailbreaking
    Jun 4 2025
    • Pwn2Own 2025, Berlin results.
    • PayPal seeks a "newly registered domains" patent.
    • An expert iOS jailbreak developer gives up.
    • The rising abuse of SVG images, via JavaScript.
    • Interesting feedback from our listeners.
    • Four classic science fiction movies not to miss.
    • How OpenAI's o3 model discovered a 0-day in the Linux kernel

    Show Notes - https://www.grc.com/sn/SN-1028-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • material.security
    • outsystems.com/twit
    • bigid.com/securitynow
    • bitwarden.com/twit
    • joindeleteme.com/twit promo code TWIT
    Exibir mais Exibir menos
    3 horas e 8 minutos
  • SN 1027: Artificial Intelligence - The Status of Encrypted Client Hello
    May 28 2025
    • What the status of Encrypted Client Hello (ECH)?
    • What radio technology would be best for remote inverter shutdown?
    • Some DNS providers already block newly listed domains.
    • Knowing when not to click a link can take true understanding.
    • Why can losing a small portion of a power grid bring the rest down?
    • Where are we in the "AI Hype Cycle" and is this the first?
    • Speaking of hype: An AI system resorted to blackmail?
    • Why are we so quick to imbue AI with awareness?
    • ChatGPT's latest o3 model ignored the order to shutdown.
    • Copilot may not be making Windows core code any better.
    • Venice.AI is an unfiltered and unrestrained LLM

    Show Notes - https://www.grc.com/sn/SN-1027-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • outsystems.com/twit
    • threatlocker.com for Security Now
    • canary.tools/twit - use code: TWIT
    • hoxhunt.com/securitynow
    • 1password.com/securitynow
    Exibir mais Exibir menos
    2 horas e 54 minutos
  • SN 1026: Rogue Comms Tech Found in US Power Grid - Is AI Replicating Itself?
    May 21 2025
    • Chrome to actively refuse admin privileges.
    • Android Messenger is getting manual key verification.
    • Pwn2Own to add AI "pwning" as in-scope attack targets.
    • AI has already been found to be replicating.
    • Microsoft not killing off Office on Win10 after October.
    • 23andMe's asset purchaser revealed.
    • Many fun talking points thanks to our listeners.
    • Steve's review of "Andor", season 2.
    • What's been discovered inside the U.S. power grid

    Show Notes - https://www.grc.com/sn/SN-1026-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • bigid.com/securitynow
    • material.security
    • joindeleteme.com/twit promo code TWIT
    • bitwarden.com/twit
    • drata.com/securitynow
    Exibir mais Exibir menos
    2 horas e 47 minutos