Security Now (Audio)

Security Now (Audio)

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week. Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 21:30 UTC.
  • All
  • security
  • technology
  • help & how to
SN 1068: The Call Is Coming From Inside the House - Live From Zero Trust World 2026
Security Now (Audio)March 05, 2026
1068
51:5547.64 MB

SN 1068: The Call Is Coming From Inside the House - Live From Zero Trust World 2026

Steve Gibson and Leo Laporte host a special episode of Security Now live from ThreatLocker's Zero Trust World 2026 in Orlando, Florida. The final frontier of security is internal. Today, we have the tools, techniques and technologies to thwart attacks originating from outside our perimeter. We're no...

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned
Security Now (Audio)March 03, 2026
1067
2:53:08158.62 MB

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned

A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting ...

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned
Security Now (Audio)March 03, 2026
1067
2:53:08158.62 MB

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned

A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting ...

SN 1066: Password Leakage - Zero Trust, Zero Knowledge
Security Now (Audio)February 25, 2026
1066
2:50:07155.99 MB

SN 1066: Password Leakage - Zero Trust, Zero Knowledge

ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us t...

SN 1066: Password Leakage - Zero Trust, Zero Knowledge
Security Now (Audio)February 25, 2026
1066
0:00155.99 MB

SN 1066: Password Leakage - Zero Trust, Zero Knowledge

ETH Zurich's deep-dive into the world's top password managers exposes how feature overload and legacy design obscure real security flaws, forcing a rethink of what "zero knowledge" actually means for your vault. Learn why recent fixes matter—and why open source may be your safest bet. CA's warn us t...

SN 1065: Attestation - Code Signing Gets Tough
Security Now (Audio)February 18, 2026
1065
2:40:42147.41 MB

SN 1065: Attestation - Code Signing Gets Tough

How secure are your Chrome extensions and certificate signings really? This episode pulls back the curtain on a massive spyware discovery and exposes the convoluted hoops developers must jump through to prove their identity in 2026. Websites can place high demands upon limited CPU resources. Microso...

SN 1064: Least Privilege - Cybercrime Goes Pro
Security Now (Audio)February 11, 2026
1064
2:36:39143.62 MB

SN 1064: Least Privilege - Cybercrime Goes Pro

From EU fines that never get paid to cyber warfare grounding missiles mid-battle, this week's episode uncovers the untold stories and real-world consequences shaping today's digital defenses. How is the EU's GDPR fine collection going. Western democracies are getting serious about offensive cybercri...

SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild
Security Now (Audio)February 04, 2026
1063
2:55:34160.96 MB

SN 1063: Mongo's Too Easy - AI Bug Bounties Gone Wild

When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's...

SN 1062: AI-Generated Malware - Ireland Legalizes Spyware
Security Now (Audio)January 28, 2026
1062
2:41:34148.09 MB

SN 1062: AI-Generated Malware - Ireland Legalizes Spyware

Can AI really write malware better than hackers ever could? This episode exposes the first real-world case of advanced, fully AI-generated malware and why it signals a seismic shift in cybersecurity risk. CISA's uncertain future remains quite worrisome. Worrisome is Ireland's new "lawful" intercepti...

SN 1061: More GhostPosting - RAM Crisis Hits Firewalls
Security Now (Audio)January 21, 2026
1061
2:44:10150.54 MB

SN 1061: More GhostPosting - RAM Crisis Hits Firewalls

Soaring RAM prices are about to hit your security gear where it hurts, and the fallout could change what's protecting your network. Find out who's about to pay and why the AI gold rush is reshaping more than just your server specs. RAM pricing to affect enterprise firewall equipment. Anthropic provi...

SN 1060: 3-Day Certificates - The Rise of AI Programming
Security Now (Audio)January 14, 2026
1060
2:49:13155.07 MB

SN 1060: 3-Day Certificates - The Rise of AI Programming

Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. Ca...

SN 1060: 3-Day Certificates - The Rise of AI Programming
Security Now (Audio)January 14, 2026
1060
2:38:52145.59 MB

SN 1060: 3-Day Certificates - The Rise of AI Programming

Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. Ca...

SN 1059: MongoBleed - Code Signing Under Siege
Security Now (Audio)January 07, 2026
1059
3:16:33180.12 MB

SN 1059: MongoBleed - Code Signing Under Siege

Why are code signing certificates suddenly getting shorter, pricier, and more restrictive? Steve Gibson and Leo Laporte expose the "cabal" rewriting the rules for everyone who builds software—and what it means for your security and your wallet. Code-signing certificate lifetimes shortened by two yea...

SN 1058: A Gift for the New Year - Vitamin D Revisited
Security Now (Audio)December 28, 2025
1058
1:26:0679.35 MB

SN 1058: A Gift for the New Year - Vitamin D Revisited

In this special holiday episode, Steve Gibson and Leo Laporte revisit their classic conversation about vitamin D—diving into the science, surprising updates, and practical tips for your health. Whether you've heard it before or are tuning in for the first time, this "blast from the past" is the perf...

SN 1057: GhostPoster - Free VPNs, Hidden Risks
Security Now (Audio)December 24, 2025
1057
2:20:19128.57 MB

SN 1057: GhostPoster - Free VPNs, Hidden Risks

What if your smart TV and Firefox extensions were secretly hijacking your security and privacy? This episode reveals the jaw-dropping discovery of a massive TV botnet and the surprisingly clever malware lurking behind innocent browser icons. North Korea's profitable fixation on cryptocurrency. Amazo...

SN 1056: Australia - AI Coding Blunders Exposed
Security Now (Audio)December 17, 2025
1056
2:56:38161.97 MB

SN 1056: Australia - AI Coding Blunders Exposed

Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOM...

SN 1055: React's Perfect 10 - RAM Is the New Lobster
Security Now (Audio)December 10, 2025
1055
2:45:50152.04 MB

SN 1055: React's Perfect 10 - RAM Is the New Lobster

A devastating new React vulnerability earned a "perfect 10" for risk, letting attackers remotely run code on a million-plus servers with a single HTTP request. Find out what happened, how fast attackers moved in, and why this bug changes everything for web security. France's VanityFair face a stiff ...

SN 1054: Bots in the Belfry - Cisco Promises Real Security Fixes!
Security Now (Audio)December 03, 2025
1054
3:04:04168.66 MB

SN 1054: Bots in the Belfry - Cisco Promises Real Security Fixes!

Cisco has finally admitted it's time for real change and is vowing to build "secure by default" gear after decades of criticism. Steve Gibson reacts to a rare moment when a tech giant actually gets security right—and what it means for everyone running critical infrastructure. • Scattered Lapsus$ Hun...

SN 1053: Banning VPNs - The Equals Coffee Hack
Security Now (Audio)November 26, 2025
1053
2:41:48148.31 MB

SN 1053: Banning VPNs - The Equals Coffee Hack

Could banning VPNs really become law in the US? This episode breaks down the jaw-dropping legislation in Wisconsin and Michigan that targets VPN access for everyone, not just kids—and what it means for your digital privacy. The EU finally comes to its "Chat Control" senses. Windows 11 to include Sys...

SN 1052: Global Cellphone Tracking - Checkout.com Fights Back
Security Now (Audio)November 19, 2025
1052
3:02:07166.95 MB

SN 1052: Global Cellphone Tracking - Checkout.com Fights Back

Think your cell phone is safe from tracking? Steve reveals how global networks let anyone pinpoint your location—no hacking required and no malware involved. Apple introduces a new Digital ID inside Wallet. Checkout.com refuses to pay a ransom demand. Google announces "Private AI Compute" in the clo...