Security Now (Audio)

Security Now (Audio)

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week. You can join Club TWiT for $10 per month and get ad-free audio and video feeds for all our shows plus everything else the club offers...or get just this podcast ad-free for $5 per month. New episodes every Tuesday.
  • All
  • security
  • technology
  • help & how to
SN 1072: LiteLLM - Click Fix Attacks Surge
Security Now (Audio)April 01, 2026
1072
0:00154.93 MB

SN 1072: LiteLLM - Click Fix Attacks Surge

An explosive supply chain hack in Light LLM nearly unleashed catastrophic malware across millions of AI systems, and it took a coder's quick thinking to catch it before it snowballed into disaster. Will California require Linux to verify its user's age. • Apple's iOS 26.4 requires UK users to prove ...

SN 1071: Bucketsquatting - Meta and TikTok's Tracking Pixels
Security Now (Audio)March 25, 2026
1071
2:47:44153.65 MB

SN 1071: Bucketsquatting - Meta and TikTok's Tracking Pixels

When convenience trumps caution, disaster waits in the wings. Join Steve Gibson and Mikah Sargent as they break down the jaw-dropping oversights lurking in mission-critical tax and cloud tools, and examine how a single unchecked decision can upend internet security for years. H&R Block's tax sof...

SN 1070: CISA's Free Internet Scanning - Malware Disguised as a VPN
Security Now (Audio)March 18, 2026
1070
2:46:12152.41 MB

SN 1070: CISA's Free Internet Scanning - Malware Disguised as a VPN

Meta quietly ditches encryption for Instagram chats while TikTok also backpedals on privacy, shaking up assumptions about how much big tech really values your secrets. Meanwhile, Steve Gibson reveals why CISA's free government security scans are an absolute must for businesses—plus what he learned w...

SN 1069: You can't hide from LLMs - Was Your Smart TV a Stealth Proxy?
Security Now (Audio)March 11, 2026
1069
2:43:34149.97 MB

SN 1069: You can't hide from LLMs - Was Your Smart TV a Stealth Proxy?

Think your online alias keeps you safe? This episode reveals how advanced language models are making it trivial to de-anonymize users at scale, challenging everything we thought we knew about internet privacy. Anthropic & Mozilla improve Firefox's security. Apple & Google begin testing cross...

SN 1068: The Call Is Coming From Inside the House - Live From Zero Trust World 2026
Security Now (Audio)March 05, 2026
1068
51:5547.64 MB

SN 1068: The Call Is Coming From Inside the House - Live From Zero Trust World 2026

Steve Gibson and Leo Laporte host a special episode of Security Now live from ThreatLocker's Zero Trust World 2026 in Orlando, Florida. The final frontier of security is internal. Today, we have the tools, techniques and technologies to thwart attacks originating from outside our perimeter. We're no...

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned
Security Now (Audio)March 03, 2026
1067
2:53:08158.62 MB

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned

A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting ...

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned
Security Now (Audio)March 03, 2026
1067
2:53:08158.62 MB

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned

A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting ...

SN 1066: Password Leakage - Zero Trust, Zero Knowledge
Security Now (Audio)February 25, 2026
1066
2:50:07155.99 MB

SN 1066: Password Leakage - Zero Trust, Zero Knowledge

ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us t...

SN 1066: Password Leakage - Zero Trust, Zero Knowledge
Security Now (Audio)February 25, 2026
1066
0:00155.99 MB

SN 1066: Password Leakage - Zero Trust, Zero Knowledge

ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us t...

SN 1065: Attestation - Code Signing Gets Tough
Security Now (Audio)February 18, 2026
1065
2:40:42147.41 MB

SN 1065: Attestation - Code Signing Gets Tough

How secure are your Chrome extensions and certificate signings really? This episode pulls back the curtain on a massive spyware discovery and exposes the convoluted hoops developers must jump through to prove their identity in 2026. Websites can place high demands upon limited CPU resources. Microso...

SN 1064: Least Privilege - Cybercrime Goes Pro
Security Now (Audio)February 11, 2026
1064
2:36:39143.62 MB

SN 1064: Least Privilege - Cybercrime Goes Pro

From EU fines that never get paid to cyber warfare grounding missiles mid-battle, this week's episode uncovers the untold stories and real-world consequences shaping today's digital defenses. How is the EU's GDPR fine collection going. Western democracies are getting serious about offensive cybercri...

SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild
Security Now (Audio)February 04, 2026
1063
2:55:34160.96 MB

SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild

When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's...

SN 1062: AI-Generated Malware - Ireland Legalizes Spyware
Security Now (Audio)January 28, 2026
1062
2:41:34148.09 MB

SN 1062: AI-Generated Malware - Ireland Legalizes Spyware

Can AI really write malware better than hackers ever could? This episode exposes the first real-world case of advanced, fully AI-generated malware and why it signals a seismic shift in cybersecurity risk. CISA's uncertain future remains quite worrisome. Worrisome is Ireland's new "lawful" intercepti...

SN 1061: More GhostPosting - RAM Crisis Hits Firewalls
Security Now (Audio)January 21, 2026
1061
2:44:10150.54 MB

SN 1061: More GhostPosting - RAM Crisis Hits Firewalls

Soaring RAM prices are about to hit your security gear where it hurts, and the fallout could change what's protecting your network. Find out who's about to pay and why the AI gold rush is reshaping more than just your server specs. RAM pricing to affect enterprise firewall equipment. Anthropic provi...

SN 1060: 3-Day Certificates - The Rise of AI Programming
Security Now (Audio)January 14, 2026
1060
2:49:13155.07 MB

SN 1060: 3-Day Certificates - The Rise of AI Programming

Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. Ca...

SN 1060: 3-Day Certificates - The Rise of AI Programming
Security Now (Audio)January 14, 2026
1060
2:38:52145.59 MB

SN 1060: 3-Day Certificates - The Rise of AI Programming

Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. Ca...

SN 1059: MongoBleed - Code Signing Under Siege
Security Now (Audio)January 07, 2026
1059
3:16:33180.12 MB

SN 1059: MongoBleed - Code Signing Under Siege

Why are code signing certificates suddenly getting shorter, pricier, and more restrictive? Steve Gibson and Leo Laporte expose the "cabal" rewriting the rules for everyone who builds software—and what it means for your security and your wallet. Code-signing certificate lifetimes shortened by two yea...

SN 1058: A Gift for the New Year - Vitamin D Revisited
Security Now (Audio)December 28, 2025
1058
1:26:0679.35 MB

SN 1058: A Gift for the New Year - Vitamin D Revisited

In this special holiday episode, Steve Gibson and Leo Laporte revisit their classic conversation about vitamin D—diving into the science, surprising updates, and practical tips for your health. Whether you've heard it before or are tuning in for the first time, this "blast from the past" is the perf...

SN 1057: GhostPoster - Free VPNs, Hidden Risks
Security Now (Audio)December 24, 2025
1057
2:20:19128.57 MB

SN 1057: GhostPoster - Free VPNs, Hidden Risks

What if your smart TV and Firefox extensions were secretly hijacking your security and privacy? This episode reveals the jaw-dropping discovery of a massive TV botnet and the surprisingly clever malware lurking behind innocent browser icons. North Korea's profitable fixation on cryptocurrency. Amazo...

SN 1056: Australia - AI Coding Blunders Exposed
Security Now (Audio)December 17, 2025
1056
2:56:38161.97 MB

SN 1056: Australia - AI Coding Blunders Exposed

Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOM...