SECURITY NOW

Ad-free audio episodes of Security Now

US$ 5.00/month or US$ 60.00/year

Security Now (Audio)

TWiT

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week. You can join Club TWiT for $10 per month and get ad-free audio and video feeds for all our shows plus everything else the club offers...or get just this podcast ad-free for $5 per month. New episodes every Tuesday.

  1. 20 HR AGO

    Bucketsquatting - Meta and TikTok's Tracking Pixels

    When convenience trumps caution, disaster waits in the wings. Join Steve Gibson and Mikah Sargent as they break down the jaw-dropping oversights lurking in mission-critical tax and cloud tools, and examine how a single unchecked decision can upend internet security for years. H&R Block's tax software does something SO WRONG. The Intoxalock breathalyzer calibration cyber attack. Firefox now offers a 100% free built-in VPN. TikTok and Meta's tracking pixels are so much more. Russians beg for the return of Telegram, WhatsApps and others. Never connect your crypto-wallet to an unknown service. What would a week be without a Cisco CVSS of 10.0. Ubiquiti patches a 10.0 critical flaw. Listener feedback and... What's "Bucketsquatting" and what can be done to prevent it Show Notes - https://www.grc.com/sn/SN-1071-Notes.pdf Hosts: Steve Gibson and Mikah Sargent Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: hoxhunt.com/securitynow guardsquare.com outsystems.com/twit zscaler.com/security

    2h 48m
  2. You Might Also Like: On Purpose with Jay Shetty

    20 HR AGO ·  BONUS

    You Might Also Like: On Purpose with Jay Shetty

    Introducing Nischa Shah: #1 Financial Mistake People Make in Their 20s & 30s (Fix It With This Simple System) from On Purpose with Jay Shetty. Follow the show: On Purpose with Jay Shetty Today, Jay sits down with his dear friend Nischa Shah, a former investment banker and accountant who walked away from a high-status corporate career to help people rethink their relationship with money, success, and freedom. Nischa reflects on the “dark phase” she experienced while climbing the corporate ladder, realizing that the prestige and polish of banking had created a deep disconnect from her true self. Nischa invites listeners to confront a powerful question many of us avoid: “Would I still be happy if I were living the same life five or ten years from now?” Jay and Nischa shift into practical strategies for navigating money anxiety. Nischa introduces the “ostrich effect,” which is the psychological tendency to avoid looking at our finances out of fear. She shares her simple but powerful “three-bucket” approach to personal finance, where income is intentionally divided between fundamentals, fun, and the “future you.” By reframing the goal from financial success to financial happiness, Nischa offers a clearer, more intentional way to manage money, one that prioritizes peace of mind over status or external validation. In this interview, you'll learn: How to Assess Your Career Alignment  How to Calculate a Financial Cushion  How to Manage Income Using the Three-Bucket Method  How to Audit Spending with Three Key Questions  How to Turn Financial Knowledge into Action  How to Strategize Paying Off Debt vs. Investing  How to Increase Your Value and Earning Potential  It is never too late to begin reclaiming your narrative, whether that starts with building a small financial safety net for peace of mind or finally turning knowledge into decisive action. With Love and Gratitude, Jay Shetty JAY’S DAILY WISDOM DELIVERED STRAIGHT TO YOUR INBOX Join 900,000+ readers discovering how small daily shifts create big life change with my free newsletter. Subscribe here: https://news.jayshetty.me/subscribe   Check out our Apple subscription to unlock bonus content of On Purpose! https://lnk.to/JayShettyPodcast  What We Discuss: 00:00 Intro 00:54 Questioning the Traditional Path  03:22 The Courage to Walk Away  06:14 Calculating Your Financial Runway  07:04 Separating Your Self-Worth from Your Title  10:49 What is the Ostrich Effect?  13:45 Fighting Instant Gratification  14:28 Ask Yourself These Three Questions Before Buying Anything  18:30 Micro-Habits That Build Real Wealth  21:29 Spending With Intention   23:33 Why More Money Doesn’t Always Fix Money Problems  28:49 Financial Success vs. Financial Happiness  31:03 Is there Such a Thing as Passive Income?  34:06 Mastering Long-Term Investing  36:42 Should You Buy a Home?  37:42 Breaking the Scarcity Mindset 42:01 Stop Spending to Impress People 44:31 The Problem With Constantly Upgrading  45:55 How Can You Be of Value To Others?  49:07 Focus on Earning More, Not Just Cutting Costs  53:40 Defining Your Personal Freedom  54:52 The Entrepreneurship vs. Employment Trap  56:37 Investing in Your Own Skills  58:47 Short-Term Joy vs. Long-Term Security  01:00:50 We All Make Financial Mistakes!  01:01:31 It’s Never Too Late 01:02:48 This or That: Money Edition 01:06:34 Nischa on Final Five Episode Resources: YouTube | https://www.youtube.com/@nischa  Facebook | https://www.facebook.com/profile.php?id=61567018784328  Instagram | https://www.instagram.com/nischa.me/  TikTok | https://www.tiktok.com/discover/nischa-shah See omnystudio.com/listener for privacy information. DISCLAIMER: Please note, this is an independent podcast episode not affiliated with, endorsed by, or produced in conjunction with the host podcast feed or any of its media entities. The views and opinions expressed in this episode are solely those of the creators and guests. For any concerns, please reach out to team@podroll.fm.

  3. 18 MAR

    CISA's Free Internet Scanning - Malware Disguised as a VPN

    Meta quietly ditches encryption for Instagram chats while TikTok also backpedals on privacy, shaking up assumptions about how much big tech really values your secrets. Meanwhile, Steve Gibson reveals why CISA's free government security scans are an absolute must for businesses—plus what he learned when GRC took the plunge. The Security Now "Caption That Photo" contest. A mega social media company says "no" to strong encryption. WhatsApp to give parents more control, Consumer bandwidth proxying is becoming a big deal. Meta buys the Moltbook duo. The EU gives up and settles upon the status quo. When a ransomware negotiation is not what it seems. CISA compels federal agencies to submit their logs. Is that a VPN in your pocket or something more malicious. Be careful what you download, thinking it's AI. A super-clever and super-simple A/V scanner bypass. Will AI write code for me? Another listener discovers the Joy of AI. Steve's CISA Internet scanning experience Show Notes - https://www.grc.com/sn/SN-1070-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit joindeleteme.com/twit promo code TWIT material.security canary.tools/twit - use code: TWIT adaptivesecurity.com meter.com/securitynow

    2h 46m
  4. 5 MAR

    The Call Is Coming From Inside the House - Live From Zero Trust World 2026

    Steve Gibson and Leo Laporte host a special episode of Security Now live from ThreatLocker's Zero Trust World 2026 in Orlando, Florida. The final frontier of security is internal. Today, we have the tools, techniques and technologies to thwart attacks originating from outside our perimeter. We're now good at protecting our borders. But major high profile breaches occurring over the past several years have revealed that insufficient attention has been given to the security of our internal systems and networks. Today's greatest security weaknesses result from decades of system design, deployment and policy that have placed far too much trust on the conduct of those on the inside, behind our borders. Whether deliberate, inadvertent, or externally penetrating, the greatest challenge we now face is that of designing and deploying our internal security with strict adherence to the principles of least privilege and zero trust. Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsor: threatlocker.com/twit

    52 min
  5. 3 MAR

    KongTuke's CrashFix - Click, Paste, Pwned

    A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting traditional defenses. The lowdown on last week's "no turn" picture of the week. Is an AI-driven hacking campaign a big deal now. Clause used in multiple Mexican government attacks. Apple continues to be confronted with age restrictions. COPPA needs an exception to allow age collection. Meta swamps law enforcement with AI-slop CSAM reports. Roskomnadzor has been busy blocking VPNs. Guess how many. The UK tries to report their self-scanning success. Remember that hacker who extorted the psychotherapy patients. Scattered Lapsus$ Hunters is actively recruiting women. Cisco lands another breathtakingly rare 10.0 CVSS. VulnCheck's report on 2025 vulnerabilities and exploits. Steve discovers a fabulous $72 Hardware Security Module. A listener shares an interesting AI service discovery. The very potent "ClickFix" exploit evolves Show Notes - https://www.grc.com/sn/SN-1067-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: meter.com/securitynow guardsquare.com threatlocker.com/twit adaptivesecurity.com outsystems.com/twit

    2h 53m
  6. 25 FEB

    Password Leakage - Zero Trust, Zero Knowledge

    ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us to urgently prepare for the inevitable. Three U.S. states attempt to ban 3D printed firearms. Denied ransom, ShinyHunters leaks 967,000 personal details. "Billions" of U.S. social security numbers leaked. Is Apple planning to add cameras to three new gadgets. No more security fixes for Firefox on Windows 7 & 8. Russia blocks the official Linux kernel site they need. Will the U.S."freedom.gov" site post EU blocked content. LLM's will offer secure passwords. Do Not Use Them. As predicted, the "ClickFix" attack strategy takes over. A listener believes his computer is compromised. How could three popular password managers get things wrong. Show Notes - https://www.grc.com/sn/SN-1066-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com bitwarden.com/twit zscaler.com/security hoxhunt.com/securitynow material.security

    2h 50m
  7. 18 FEB

    Attestation - Code Signing Gets Tough

    How secure are your Chrome extensions and certificate signings really? This episode pulls back the curtain on a massive spyware discovery and exposes the convoluted hoops developers must jump through to prove their identity in 2026. Websites can place high demands upon limited CPU resources. Microsoft appears to back away from its security commitment. What's Windows 11 26H1 and where do I get it. Chrome 145 brings Device Bound Session Credentials. More countries are moving to ban underage social media use. The return of Roskomnadzor. Discord to require proof of adulthood for adult content. Might you still be using WinRAR 7.12 -- I was. Paragon's Graphite can definitely spy on all instant messaging. 30 malicious Chrome Extensions. 287 Chrome extensions from spying on 37.4 million users. The first malicious Outlook add-in steals 4000 user's credentials. Some AI "vibe" coding thoughts. What I just went through to obtain a new code signing certificate Show Notes - https://www.grc.com/sn/SN-1065-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT meter.com/securitynow zscaler.com/security hoxhunt.com/securitynow

    2h 41m

About

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week. You can join Club TWiT for $10 per month and get ad-free audio and video feeds for all our shows plus everything else the club offers...or get just this podcast ad-free for $5 per month. New episodes every Tuesday.

You Might Also Like