Security Now
SN 1013: Chrome Web Store is a mess - Apple Encryption in the UK, Texas Vs. DeepSeek
- US lawmakers respond to the UK's outrageous demand about Apple's encryption.
- What, exactly, is a "backdoor", and can a "backdoor" NOT be secret?
- Highlights from last week's Windows' Patch Tuesday.
- A look into RansomHub: The latest king of the Ransomware hill.
- "TOAD": Telephone-Oriented Attack Delivery.
- The state of Texas -versus- DeepSeek.
- Disabling Apple's "Restricted Mode".
- Where did I put that $800 million in Bitcoin?
- A Sci-Fi author update.
- And a deep dive into the misoperation of Chrome's critically important Web Extension Store
Show Notes - https://www.grc.com/sn/SN-1013-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
Sponsors:
SN 1012: Hiding School Cyberattacks - SparkCat, Decrypting ADP, AI Fuzzing
- New "SparkCat" secret-stealing AI image scanner discovered in App and Play stores.
- The UK demands that Apple does the impossible: decrypting ADP cloud data.
- France moves forward on legislation to require backdoors to encryption.
- Firefox moves to 135 with a bunch of useful new features.
- The Five Eyes alliance publishes edge-device security guidance.
- Six NetGear routers contain CVSS 9.6 and 9.8 vulnerabilities.
- Sysinternals utilities allow malicious Windows DLL injection.
- Google removes restrictive do-gooder language from AI application policies.
- "AI Fuzzing" successfully jailbreaks the most powerful ChatGPT o3 model.
- Examining the well and deliberately hidden truth behind ransomware cyberattacks on U.S. K-12 schools
Show Notes - https://www.grc.com/sn/SN-1012-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
Sponsors:
SN 1011: Jailbreaking AI - Deepseek, "ROUTERS" Act, Zyxel Vulnerability
- Why was DeepSeek banned by Italian authorities?
- What internal proprietary DeepSeek data was found online?
- What is "DeepSeek" anyway? Why do we care, and what does it mean?
- Did Microsoft just make OpenAI's strong model available for free?
- Google explains how generative AI can be and is being misused.
- An actively exploited and unpatched Zyxel router vulnerability.
- The new US "ROUTERS" Act.
- Is pirate-site blocking legislation justified or is it censorship?
- Russia's blocked website count tops 400,000.
- Microsoft adds "scareware" warnings to Edge.
- Bitwarden improves account security.
- What's still my favorite disk imaging tool?
- And let's take a close look into the extraction of proscribed knowledge from today's AI
Show Notes - https://www.grc.com/sn/SN-1011-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit
Sponsors:
SN 1010: DNS Over TLS - Record DDoS, Hackers Get Hacked
- eM Client CAN be purchased outright.
- An astonishing 5-year-old typo in MasterCard's DNS.
- An unwelcome surprise received by 18,459 low-level hackers.
- DDoS attacks continue growing, seemingly without any end in sight.
- Let's Encrypt clarifies their plans for 6-day "we barely knew you" certificates.
- SpinRite uncovers a bad brand new 8TB drive.
- Listener feedback about TOTP, Syncthing and UDP hole punching, email spam, ValiDrive speed, AI neural nets, DJI geofencing, and advertising in the "New" Outlook.
- A look into the tradeoffs required to obtain privacy for our DNS lookups
Show Notes - https://www.grc.com/sn/SN-1010-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Sponsors: