Épisodes

  • SN 1040: Clickjacking "Whac-A-Mole" - Inside the Password Manager Clickjacking Frenzy and What It Means
    Aug 27 2025

    Alarm bells are ringing over a supposed browser zero-day, but is the threat as bad as it sounds? Steve reveals why "clickjacking" might be more whac-a-mole than breaking news, and what that really means for your passwords.

    • Germany may soon outlaw ad blockers
    • What's happening in the courts over AI
    • The U.K. drops its demands of Apple
    • New Microsoft 365 tenants being throttled
    • Is Russia preparing to block Google Meet?
    • Bluesky suspends its service in Mississippi
    • How to throttle AI
    • A tricky SSH-busting Go library
    • Here comes the Linux desktop malware
    • Apple just patched a doozy of a vulnerability
    • A trivial Docker escape was found and fixed
    • Why the recent browser 0-day clickjacking is really just whac-a-mole

    Show Notes - https://www.grc.com/sn/sn-1040-notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • 1password.com/securitynow
    • zscaler.com/security
    • bigid.com/securitynow
    • uscloud.com
    Voir plus Voir moins
    Moins d'une minute
  • SN 1039: The Sad Case of ScriptCase - Data Brokers Dodge Deletion
    Aug 20 2025
    • What AI website summaries mean for Internet economics.
    • Time to urgently update Plex Servers (again).
    • Allianz Life stolen data gets leaked.
    • Chrome test Incognito-mode fingerprint script blocking.
    • Chrome 140 additions coming in 2 weeks.
    • Data brokers hide opt-out pages from search engines.
    • Secure messaging changes in Russia.
    • NIST rolls-out lightweight IoT crypto.
    • SyncThing moves to v2.0 and beyond.
    • Alien:Earth -- first take.
    • What can we learn from another critical vulnerability?

    Show Notes - https://www.grc.com/sn/SN-1039-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • threatlocker.com for Security Now
    • bitwarden.com/twit
    • go.acronis.com/twit
    • joindeleteme.com/twit promo code TWIT
    • vanta.com/SECURITYNOW
    Voir plus Voir moins
    2 h et 52 min
  • SN 1038: Perplexity's Duplicity - Malicious Repository Libraries
    Aug 13 2025
    • CISA's Emergency Directive to ALL Federal agencies re: SharePoint.
    • NVIDIA firmly says "no" to any embedded chip gimmicks.
    • Dashlane is terminating its (totally unusable) free tier.
    • Malicious repository libraries are becoming even more hostile.
    • The best web filter (uBlock Origin) comes to Safari.
    • The very popular SonicWall firewall is being compromised.
    • >100 models of Dell Latitude and Precision laptops are in danger.
    • The significant challenge of patching SharePoint (for example).
    • A quick look at my DNS Benchmark progress.
    • Does InControl prevent an important update.
    • An venerable Sci-Fi franchise may be getting a great new series.
    • What to do about the problem of AI "website sucking"

    Show Notes - https://www.grc.com/sn/SN-1038-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • zscaler.com/security
    • canary.tools/twit - use code: TWIT
    • uscloud.com
    • go.acronis.com/twit
    Voir plus Voir moins
    3 h et 4 min
  • SN 1037: Chinese Participation in MAPP - Why Signal is Leaving Australia
    Aug 6 2025
    • A follow-up to the SharePoint server patch mess.
    • How Russia arranges to spy on other country's local embassies.
    • "Dropbox Passwords" manager app is ending in October.
    • Signal will leave Australia rather than help spy.
    • YouTube deploys viewing history age-estimation heuristics.
    • Chrome adds clever lightweight extension signing to prevent abuse.
    • A domain registrar is coming close to losing its rights.
    • A TP-Link router that doesn't encrypt its configuration.
    • What is "TruAge" and might it be useful for age verification.
    • An update on "Artemis".
    • With U.S.-China tensions on the rise, should Chinese security companies receive weeks of advance notice of forthcoming Microsoft flaw patches?

    Show Notes - https://www.grc.com/sn/SN-1037-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • bitwarden.com/twit
    • bigid.com/securitynow
    • joindeleteme.com/twit promo code TWIT
    • Melissa.com/twit
    • threatlocker.com for Security Now
    Voir plus Voir moins
    2 h et 47 min
  • SN 1036: Inside the SharePoint 0-day - Is Our Data Safe Anywhere?
    Jul 30 2025
    • Brave randomizes its fingerprints.
    • The next Brave will block Microsoft Recall by default.
    • Clorox sues its IT provider for $380 million in damages.
    • 6-month Win10 ESU offers are beginning to appear.
    • Warfare has significantly become cyber.
    • Allianz Life loses control of 125 million customers' data.
    • The CIA's Acquisition Research Center website was hacked.
    • The Pentagon says the SharePoint RCE didn't get them.
    • A look at a DPRK "laptop farm" to impersonate Americans.
    • FIDO's passkey was NOT bypassed by a MITM after all.
    • Is our data safe anywhere?
    • The UK is trying to back-pedal out of the Apple ADP mess.
    • Meanwhile, the EU resumes its push for "Chat Control".
    • Microsoft fumbled the patch of a powerful Pwn2Own exploit

    Show Notes - https://www.grc.com/sn/SN-1036-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • canary.tools/twit - use code: TWIT
    • threatlocker.com for Security Now
    • bitwarden.com/twit
    • uscloud.com
    Voir plus Voir moins
    2 h et 58 min
  • SN 1035: Cloudflare's 1.1.1.1 Outage - Bypassing Passkey Protections
    Jul 23 2025
    • Bypassing all passkey protections.
    • The ransomware attacks just keep on coming.
    • Cloudflare capitulates to the MPA and starts blocking.
    • The need for online age verification is exploding.
    • Microsoft really wants Exchange Servers to subscribe.
    • Russia (further) clamps down on Internet usage.
    • The global trend toward more Internet restrictions.
    • China can inspect locked Android phones. Use a burner.
    • Web shells are the new buffer overflow.
    • An age verification protocol sketch.
    • What Cloudflare did to create an outage of 1.1.1.1

    Show Notes - https://www.grc.com/sn/SN-1035-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • zscaler.com/security
    • 1password.com/securitynow
    • go.acronis.com/twit
    Voir plus Voir moins
    2 h et 48 min
  • SN 1034: Introduction to Zero-Knowledge Proofs - Taking Down Quantum Factorization
    Jul 16 2025
    • A glorious takedown of quantum factorization.
    • Notepad++ signs its own code signing certificate.
    • Dennis Taylor has Bobiverse Book 6 on his lap.
    • Crypto/ATM machines flat out outlawed.
    • Signal vs WhatsApp: Encryption in flight and at rest.
    • A close look at browser fingerprinting metrics.
    • Rewriting interpreters in memory-safe languages.
    • An introduction to zero-knowledge proofs

    Show Notes - https://www.grc.com/sn/SN-1034-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • bitwarden.com/twit
    • joindeleteme.com/twit promo code TWIT
    • bigid.com/securitynow
    • threatlocker.com for Security Now
    • uscloud.com
    Voir plus Voir moins
    2 h et 56 min
  • SN 1033: Going on the Offensive - The Digital Arms Race
    Jul 9 2025
    • Another Israeli spyware vendor surfaces.
    • Win11 to delete restore points more quickly.
    • The EU accelerates its plans to abandon Microsoft Azure.
    • The EU sets timelines for Post-Quantum crypto adoption.
    • Russia to create a massive IMEI database.
    • Canada and the UK create the "Common Good Cyber Fund".
    • U.S. states crack down on Bitcoin ATMs amid growing scams.
    • Congressional staffers cannot use WhatsApp on gov devices.
    • LibXML2 and the problems with commercial use of OSS.
    • A(nother) remote code execution vulnerability in WinRAR.
    • Have-I-Been-Pwned gets a cool data visualization site.
    • How is ransomware getting in?
    • Windows to offer "safe" non-kernel endpoint security?
    • Proactive age verification coming to porn sites. How?
    • Canada (also) says "bye bye" to Hikvision.
    • Germany will be banning DeekSeek. The whole EU may follow.
    • Cloudflare throttled in Russia?
    • What must the U.S. do to compete in global exploit acquisition?

    Show Notes - https://www.grc.com/sn/SN-1033-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!
    Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit

    Sponsors:

    • expressvpn.com/securitynow
    • Melissa.com/twit
    • 1password.com/securitynow
    • hoxhunt.com/securitynow
    • canary.tools/twit - use code: TWIT
    Voir plus Voir moins
    3 h et 5 min