EinloggenRegistrieren

Security Now!

SN 1021: Device Bound Session Credentials - Hotpatching in Win 11, Apple vs. UK

Hinzugefügt: 16. April 2025

Android to get "Lockdown Mode".
What's in the new editions of Chrome and Firefox?
Why did Apple silently re-enable automatic updates?
My new iPhone 16, Chinese tariffs and electronics.
Dynamic...

SN 1020: Multi-Perspective Issuance Corroboration - IoT Done Right, France Phishes, Gmails E2EE

Hinzugefügt: 9. April 2025

Canon printer driver vulnerabilities enable Windows kernel exploitation.
Astonishing cyber-security awareness from a household appliance manufacturer.
France tries to hook 2.5 million school...

SN 1019: EU OS - Troy Hunt Phished, Ransomware List, InControl

Hinzugefügt: 2. April 2025

Kuala Lumpur International Airport says no to a ransom attack, switches to whiteboard.
A tired and jet-lagged Troy Hunt got Phished then listed himself on his own site.
Cloudflare completely...

SN 1018: The Quantum Threat - ESP32 Backdoor Update, RCS E2EE

Hinzugefügt: 26. März 2025

The dangers of doing things you don't understand.
Espressif responds to the claims of an ESP32 backdoor.
A widely leveraged mistake Microsoft stubbornly refuses to correct.
A disturbingly simple...

SN 1017: Is YOUR System Vulnerable to RowHammer? - Telegram's Crypto, Twitter Outage, FBI Warning

Hinzugefügt: 19. März 2025

An analysis of Telegram Messenger's crypto.
A beautiful statement of the goal of modern crypto design.
Who was behind Twitter's recent outage trouble?
An embedded Firefox root certificate...

SN 1016: The Bluetooth Backdoor - North Korean Texans, Apple Pushes Back

Hinzugefügt: 12. März 2025

Utah passes age verification requirement for app stores.
The inside story on fake North Korean employees. Is that a Texas accent?
An update on the ongoing Bybit cryptoheist saga.
The industry...

SN 1015: Spatial-Domain Wireless Jamming - Firefox Privacy Policy, Signal Leaving Sweden?

Hinzugefügt: 5. März 2025

Firefox amends their privacy policy -- the world melts down.
Signal threatens to leave Sweden.
Aftermath of the massive $1.5 billion Bybit ETH heist.
It turns out that it wasn't actually Bybit's...

SN 1013: Chrome Web Store is a mess - Apple Encryption in the UK, Texas Vs. DeepSeek

Hinzugefügt: 19. Februar 2025

US lawmakers respond to the UK's outrageous demand about Apple's encryption.
What, exactly, is a "backdoor", and can a "backdoor" NOT be secret?
Highlights from last week's Windows' Patch...

SN 1011: Jailbreaking AI - Deepseek, "ROUTERS" Act, Zyxel Vulnerability

Hinzugefügt: 5. Februar 2025

Why was DeepSeek banned by Italian authorities?
What internal proprietary DeepSeek data was found online?
What is "DeepSeek" anyway? Why do we care, and what does it mean?
Did Microsoft just...

SN 1010: DNS Over TLS - Record DDoS, Hackers Get Hacked

Hinzugefügt: 29. Januar 2025

eM Client CAN be purchased outright.
An astonishing 5-year-old typo in MasterCard's DNS.
An unwelcome surprise received by 18,459 low-level hackers.
DDoS attacks continue growing, seemingly...

SN 1009: Attacking TOTP - Force-Installed Outlook, DJI Firmware Update

Hinzugefügt: 22. Januar 2025

What do we learn from January's record breaking 0-day critical Patch Tuesday?
Microsoft to "force-install" a new Outlook into all Windows 10 and 11 desktops?
GoDaddy required to get much more...

SN 1008: HOTP and TOTP - SyncThing, Auto-Updates, Sci-Fi Recs

Hinzugefügt: 15. Januar 2025

Meta winds down 3rd-party content filtering. Is encryption soon to follow?
Taking over abandoned Command & Control server domains (strictly for research purposes only).
IoT devices to get the...

SN 1007: AI Training & Inference - Unencrypted Email, Doom Captcha

Hinzugefügt: 8. Januar 2025

The consequences of Internet content restriction.
The measured risks of 3rd-party browser extensions.
The consequences of SonicWall's unpatched 9.8 firewall severity.
The incredible number of...

SN 1006: Best of 2024 - Apple's Secret Backdoor, CrowdStrike Catastrophe, Recall's Privacy Nightmare

Hinzugefügt: 23. Dezember 2024

Leo revisits some of the year's top Security Now segments of 2024.
956. Apple's Hardware Backdoor: Steve reflects on the previous week's 'The Mystery of CVE-2023-38606' deep-dive. Did Apple...

SN 1005: 6-Day Certificates? Why? - Android Anti-Tracking, MFA lLogin Bypass, BIMI

Hinzugefügt: 18. Dezember 2024

Is AI the Wizard of Oz? Or is it more?
Microsoft's long standing effective MFA login bypass.
Is TPM 2.0 not required after all for Windows 11?
Meet 14 North Korean IT workers who made $88...

SN 1004: A Chat with GPT - China's Telecom Hack, Microsoft Activation Cracked, Coding with ChatGPT 4o

Hinzugefügt: 11. Dezember 2024

This week, Steve and Leo discuss the recent 'Salt Typhoon' hack of U.S. telecom providers by China, TPM 2.0 requirement for Windows 11, Microsoft's newly hacked Windows activation system, Apple...

SN 1003: A Light-Day Away - Digital Epileptic Seizures, Tor Needs You, Zello Password Panic, Wireguard's Open Port Debate

Hinzugefügt: 4. Dezember 2024

Steve Gibson and Leo Laporte discuss Microsoft's clarification about AI training data usage, a fascinating breakthrough in understanding autonomous vehicle vulnerabilities, and an urgent call for...

SN 1002: Disconnected Experiences - 'Nearest Neighbor' Attack, Repo Swatting, the Return of Recall

Hinzugefügt: 27. November 2024

What's the new "nearest neighbor" attack and how do you defend against it?
Let's Encrypt just turned 10. What changes has it wrought?
Now the Coast Guard is worried about Chinese built...

SN 1001: Artificial General Intelligence (AGI) - Gmail Temp Addresses, Russia's Internet Off Switch

Hinzugefügt: 20. November 2024

How Microsoft lured the US Government into a far deeper and expensive dependency upon its cybersecurity solutions.
Gmail to offer native throwaway email aliases like Apple and Mozilla.
Russia to...

SN 1001: Artificial General Intelligence (AGI) - Gmail Temp Addresses, Russia's Internet Off Switch

Hinzugefügt: 20. November 2024

How Microsoft lured the US Government into a far deeper and expensive dependency upon its cybersecurity solutions.
Gmail to offer native throwaway email aliases like Apple and Mozilla.
Russia to...