112 episodes

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 20:30 UTC.

Security Now (Audio‪)‬ Security Now

    • Technology
    • 4.6 • 1.9K Ratings

Listen on Apple Podcasts
Requires subscription and macOS 11.4 or higher

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 20:30 UTC.

Listen on Apple Podcasts
Requires subscription and macOS 11.4 or higher

    The Polyfill.io Attack - Entrust Responds, Passkey Redaction Attacks

    The Polyfill.io Attack - Entrust Responds, Passkey Redaction Attacks

    Entrust Responds
    Other major Certificate Authorities respond
    Passkey Redaction Attacks
    Syncing passkeys
    Port Knocking
    Fail2Ban
    The Polyfill.io Attack
    Show Notes - https://www.grc.com/sn/SN-982-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    lookout.com
    vanta.com/SECURITYNOW
    bitwarden.com/twit
    panoptica.app

    • 1 hr 57 min
    The End of Entrust Trust - Open SSH Vulnerability, SyncThing, Endtrust

    The End of Entrust Trust - Open SSH Vulnerability, SyncThing, Endtrust

    The regreSSHion Bug
    50BTC moved
    Voyager 1 Update
    Email @ GRC
    SyncThing
    DNS queries
    Recall
    The End of Entrust Trust
    Show Notes - https://www.grc.com/sn/SN-981-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    bigid.com/securitynow
    joindeleteme.com/twit promo code TWIT
    panoptica.app
    lookout.com

    • 2 hr 27 min
    The Mixed Blessing of Lousy PRNG - Kaspersky Ban, EU vs. Google's Privacy Sandbox

    The Mixed Blessing of Lousy PRNG - Kaspersky Ban, EU vs. Google's Privacy Sandbox

    Expected follow-up on CVE-2024-30078
    From Russia with Love
    An EU privacy agency complains about Google's Privacy Sandbox?
    Email @ GRC
    Security Now SPAM?
    Orange Tsai needs help!
    Recall and 3rd Party Leakage
    Errata
    The Mixed Blessing of a Crappy PRNG
    Show Notes - https://www.grc.com/sn/SN-980-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    joindeleteme.com/twit promo code TWIT
    1password.com/securitynow
    mylio.com/twit
    canary.tools/twit - use code: TWIT

    • 2 hr 3 min
    The Angle of the Dangle - "Recall" Recall, IT at the NYT, Private Cloud Compute

    The Angle of the Dangle - "Recall" Recall, IT at the NYT, Private Cloud Compute

    CVE-2024-30078
    "Recall" has been recalled
    Matthew Green on Apple's Private Cloud Compute
    A WGET flaw with a CVSS of 10.0?
    Thou shall not Resolve!
    Email @ GRC
    Downloading email with MailStore Home
    IT at The New York Times
    ReMarkable
    The Angle of the Dangle
    Show Notes - https://www.grc.com/sn/SN-979-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    bitwarden.com/twit
    1bigthink.com
    kolide.com/securitynow
    GO.ACILEARNING.COM/TWIT - code TWIT100

    • 2 hr 14 min
    The Rise and Fall of code.microsoft.com - Apple Password Manager, AI Coding

    The Rise and Fall of code.microsoft.com - Apple Password Manager, AI Coding

    MS on Recall changes
    Thanks for the "Memory"
    New York Times (and Wordle) leak
    Apple's own password manager app
    DJI drones on the defensive
    SlashData reveals some interesting developer statistics
    Are we going to turn programming over to AIs?
    The Linux Kernel Project goes CVE crazy
    Email @ GRC
    Pizza in 2024
    Microsoft Recall at work
    Google Domains to Squarespace DNS migration
    T2F2-NFC-Dual keys
    The rise and fall of code.microsoft.com
    Show Notes - https://www.grc.com/sn/SN-978-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    mylio.com/twit
    joindeleteme.com/twit promo code TWIT
    1bigthink.com
    kolide.com/securitynow

    • 2 hr 20 min
    A Large Language Model in Every Pot - Problems With Recall, End of ICQ, Email @ GRC

    A Large Language Model in Every Pot - Problems With Recall, End of ICQ, Email @ GRC

    "Tornado Notes"
    Email @ GRC
    Have I Been Pwned?
    A new "supply chain" attack vector
    Another CA in the DogHouse
    ICQ to shutter its service
    Steve reviews "Déjà vu"
    Hide my email
    Security in Windows
    SpinRite update
    A Large Language Model in Every Pot
    Show Notes - https://www.grc.com/sn/SN-977-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:
    GO.ACILEARNING.COM/TWIT - code TWIT100
    kolide.com/securitynow
    zscaler.com/zerotrustAI
    Melissa.com/twit

    • 1 hr 55 min

Customer Reviews

4.6 out of 5
1.9K Ratings

1.9K Ratings

JD000000000000000 ,

Can’t Get Enough

I am a security professional and have been listening to Security Now for years. I learn new things every episode. Steve and Leo have a way of breaking down complex issues to a language that anyone can understand. Keep up the great work!

SecEnthused ,

Best security podcast

I’m a security professional and this is the only podcast I never miss. I’ve learned a lot and I’ve been in the field 20 years.

Alex6464 ,

The last TWIT podcast I enjoy.

I used to listen to/ subscribe to 5-6 TWIT shows. I’m down to two, and MBW is on the chopping block.

But Security Now remains stellar. Steve Gibson is a treasure.

Top Podcasts In Technology

Acquired
Ben Gilbert and David Rosenthal
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Lex Fridman Podcast
Lex Fridman
Search Engine
PJ Vogt, Audacy, Jigsaw
Hard Fork
The New York Times
TED Radio Hour
NPR

You Might Also Like

Windows Weekly (Audio)
TWiT
This Week in Tech (Audio)
TWiT
MacBreak Weekly (Audio)
TWiT
Tech News Weekly (Audio)
TWiT
CyberWire Daily
N2K Networks
Smashing Security
Graham Cluley & Carole Theriault

More by TWiT TV

This Week in Tech (Audio)
TWiT
MacBreak Weekly (Audio)
TWiT
Ask The Tech Guys (Audio)
TWiT
Windows Weekly (Audio)
TWiT
MacBreak Weekly (Video)
TWiT
iOS Today (Audio)
TWiT