POPULARITY
Categories
Anyone can build software with AI now, and millions of people are giving it a try. But when AI can spin up an app in minutes, are security risks slipping through the cracks?
Show Summary: Mudita Khurana — Tech Lead at Airbnb and the person who always says, “I got this” No Password Required Season 7: Episode 6 - Mudita Khurana Mudita Khurana is a Tech Lead for Automated Tooling and Vulnerability Management at Airbnb, where she focuses on building modular, scalable security systems in an era of rapidly evolving AI threats. Before Airbnb, she spent nearly a decade in security roles across Accenture, Meta, and PwC, making bold career pivots along the way, including turning down a PwC return offer to join Facebook's product security team. In this episode, Mudita shares her journey from a family of doctors in India to Carnegie Mellon and into the heart of Big Tech security. She discusses what it means to thrive as a non-traditional engineer in a deeply technical field, why she stepped back from management to get closer to the work, and how she thinks about building security tooling that won't be obsolete in three months. Jack Clabby and co-host Kayley Melton, recording live from Tampa B-Sides at the University of South Florida, talk with Mudita about imposter syndrome, AI's curveballs for security teams, leadership without a leadership title, and the importance of community in staying on top of a field that never stops moving. She also reflects on what great mentorship looks like early in a career and why clarity, ownership, and consistency are the leadership qualities she keeps coming back to. In the Lifestyle Polygraph, Mudita firmly plants her flag in the Harry Potter universe as Hermione, explains why Deadpool doesn't qualify as a superhero, debates gym vs. nature as a reset strategy, and reveals her dream remote work base: a high-altitude Buddhist mountain town in the Himalayas. Follow Mudita on LinkedIn: https://www.linkedin.com/in/muditakhurana/ In this episode: Mudita shares her unconventional path into cybersecurity, highlighting the importance of mentorship and curiosity (0:25 - 1:37) The significance of mentorship, especially Vandana Verma, in her career development (2:26 - 4:00) Transition from management to technical IC roles and why staying close to technical work matters (9:29 - 10:23) The influence of her education at Carnegie Mellon and how it broadened her problem-solving skills (6:23 - 7:41) Navigating imposter syndrome and embracing challenges as growth opportunities (3:26 - 5:29) How AI is changing cybersecurity strategies—building modular, layered systems for agility (15:31 - 16:26) The importance of community, trust, and consensus in cybersecurity decision-making (17:06 - 17:47) Mudita's favorite places for remote work and balancing planning with spontaneity in travel (23:01 - 24:13) Her personal approach to wellness, exercise, and resets during busy days (21:32 - 22:36) Her unique perspective on superhero characters, favorite places, and cultural roots (18:54 - 19:36, 25:19 - 26:21) Timestamp Highlights: (00:25) Mudita's 10-year journey into cybersecurity starting from India (02:26) Mentorship's critical role in her growth and her admiration for Vandana Verma (09:29) Transition from management back to technical roles and why staying close to the work matters (15:31) How AI fosters layered, modular security systems for faster adaptation (17:06) The importance of community and trusted information sources in security (21:32) Reset routines—gym versus nature hikes—and staying grounded during busy days (25:19) Leh, Ladakh: Mudita's ideal remote work location nestled in Himalayan beauty Resources & Links: Vandana Verma - Influential mentor in cybersecurity ThreatLocker - Supporter of this podcast Cyber Florida – The Mother Ship
In our World Password Day Special, we're digging into credentials, identity, and authentication — and where security is heading next.
So you've been hacked… Now what?!
Sharing information with AI has quickly become second nature. But what are you really giving away?
Supply chains, server crashes, and building break-ins. Our latest episode is a reminder that cybersecurity doesn't stop at the screen.
The Unsecurity Podcast returns with a truly joyful conversation with FRecure's own Jo Moldenhauer.Jo, an Associate Information Security Consultant, is famous around the FRSecure office for her weekly security news reviews, where she meticulously compiles articles and talking points for a company-wide discussion around industry trends and snapshots.And this couldn't have been easy to do. Jo's path to InfoSec is a recent and unique one—transitioning from dealing blackjack at casinos after most of them ceased operations during the COVID-19 pandemic. You can see how being tasked with leading a discussion to 75+ industry pros like this as a relative newcomer could be challenging—but Jo simply crushes it.In this episode, learn about:Non-traditional information security career pathsWhat makes "good" InfoSec newsWhy talking about industry news is important to FRSecure (and beyond)How vCISO engagements and risk assessments guide talking pointsThe Gaming (casino) and InfoSec industry Venn Diagram (and what they can learn from each other)User and security awareness training, culture, and incentive ideasLike, subscribe, and share with your network to stay informed about the latest in cyber and information security!We want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more:LinkedIn: https://www.linkedin.com/company/frsecure/Instagram: https://www.instagram.com/frsecureofficial/Facebook: https://www.facebook.com/frsecure/BlueSky: https://bsky.app/profile/frsecure.bsky.socialAbout FRSecure:https://frsecure.com/FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can't do it alone. Whether you're wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.
How can you help your loved ones navigate and securely adopt AI tools ? Will Gardner, CEO of Childnet joins the show for a vital conversation about helping families use AI safely. We talk about Childnet's latest research and the practical ways you can become a digital role model and start better AI conversations at home.
It's a brand new season of Random but Memorable — and we're kicking things off with practical security for the people you care about most.
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Why are code signing certificates suddenly so expensive, short-lived, and tangled in red tape? Leo Laporte and Steve Gibson dig into Microsoft's "three-day certificates," the hidden costs for developers, and the security tradeoffs no one saw coming. A look at Microsoft's Azure cloud code signing. California implements DROP, global data broker opt-out. Where's the town of "Whata Bod" Idaho. iOS built-in Mail app worked itself out of a job. A 30-minute tutorial for non-coders about AI coding. Claude Code appears to be winning over the AI coding world. Various listener musings on code signing. A bit of Magnesium feedback. What use are 3-day code signing certs? Show Notes - https://www.grc.com/sn/SN-1060-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: material.security zscaler.com/security hoxhunt.com/securitynow
Happy New Year!
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
Australia's nationwide social media ban has put tech's age verification tools under the spotlight, exposing the flaws and privacy risks in today's facial detection systems and sparking worldwide debate about what's coming for the rest of us. Home Depot's puzzling reluctance to close a bad hole. GNOME's shell extension manager is unhappy with AI. How attacks on open source repositories compares in 2025. China's researchers have taken aim at the US power grid. How bad has the React2Shell vulnerability turned out to be. More new React vulnerabilities. Apple moves to iOS 26.2. Let's Encrypt's crosses into one billion servers managed. A DNS Benchmark update. Some interesting listener feedback, then... How things going with Australia's social media ban and what we are learning https://www.grc.com/sn/SN-1056-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/securitynow threatlocker.com/twit joindeleteme.com/twit promo code TWIT veeam.com bitwarden.com/twit
This week in our technical segment, you will learn how to build a MITM proxy device using Kali Linux, some custom scripts, and a Raspberry PI! In the security news: Hacking Smart BBQ Probes China uses us as a proxy LOLPROX and living off the Hypervisor Are we overreating to React4Shell? Prolific Spyware vendors EDR evaluations and tin foil hats Compiling to Bash! How e-waste became a conference badge Overflows via underflows and reporting to CERT Users are using AI to complete mandatory infosec training! AI in your IDE is not a good idea Cybercrime is on the rise, and its the kids AI can replace humans in power plants Will AI prompt injection ever go away? To use a VPN or to not use a VPN, that is the question Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-904
This week in our technical segment, you will learn how to build a MITM proxy device using Kali Linux, some custom scripts, and a Raspberry PI! In the security news: Hacking Smart BBQ Probes China uses us as a proxy LOLPROX and living off the Hypervisor Are we overreating to React4Shell? Prolific Spyware vendors EDR evaluations and tin foil hats Compiling to Bash! How e-waste became a conference badge Overflows via underflows and reporting to CERT Users are using AI to complete mandatory infosec training! AI in your IDE is not a good idea Cybercrime is on the rise, and its the kids AI can replace humans in power plants Will AI prompt injection ever go away? To use a VPN or to not use a VPN, that is the question Show Notes: https://securityweekly.com/psw-904
This week in our technical segment, you will learn how to build a MITM proxy device using Kali Linux, some custom scripts, and a Raspberry PI! In the security news: Hacking Smart BBQ Probes China uses us as a proxy LOLPROX and living off the Hypervisor Are we overreating to React4Shell? Prolific Spyware vendors EDR evaluations and tin foil hats Compiling to Bash! How e-waste became a conference badge Overflows via underflows and reporting to CERT Users are using AI to complete mandatory infosec training! AI in your IDE is not a good idea Cybercrime is on the rise, and its the kids AI can replace humans in power plants Will AI prompt injection ever go away? To use a VPN or to not use a VPN, that is the question Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-904
This week in our technical segment, you will learn how to build a MITM proxy device using Kali Linux, some custom scripts, and a Raspberry PI! In the security news: Hacking Smart BBQ Probes China uses us as a proxy LOLPROX and living off the Hypervisor Are we overreating to React4Shell? Prolific Spyware vendors EDR evaluations and tin foil hats Compiling to Bash! How e-waste became a conference badge Overflows via underflows and reporting to CERT Users are using AI to complete mandatory infosec training! AI in your IDE is not a good idea Cybercrime is on the rise, and its the kids AI can replace humans in power plants Will AI prompt injection ever go away? To use a VPN or to not use a VPN, that is the question Show Notes: https://securityweekly.com/psw-904
Black Friday season is upon us!
Ever wondered what happens to your online accounts when you're gone?
Ever wondered how easy it is to hack a car?
How is the transition to passkeys going in 2025?
Identity theft affects millions of people every year — but do you really know how it works, or how to protect yourself? This week, we're joined by Eva Velasquez, CEO of the Identity Theft Resource Center, who shares the latest trends in identity crime and what steps you can take if it ever happens to you.
What does cyberwarfare really look like behind the headlines? This week, Roo sits down with Hayley Benedict, a cyber intelligence analyst at RANE, to explore the evolving world of digital conflict. From hacktivists to disinformation specialists, Hayley shares how nation states, criminals, and ideologically driven groups are blurring lines — and why data theft, disruption, and doubt remain the weapons of choice.
Want to work in cybersecurity but don't know where to begin? Or just curious what it takes to break into the field? This week, we're joined by the internet's very own Heath Adams, better known as The Cyber Mentor. He demystifies the application process and what it takes to build a career in cybersecurity – no matter your background.
Ken and Seth kickoff a podcast by reviewing current state of the OWASP Top 10 project, given recent requests and interactions on Absolute AppSec slack from various contributors. This is followed by an in-depth breakdown of the recent NX npm package compromise. This breakdown shows that even though AI is weaponized to exfiltrate data, the main exploit was the result of a command injection flaw. Crocs and Socks coming back to bit all of us. Finally, Ken and Seth provide a list of resources used to monitor the wider security community.
This episode is a family-friendly extravaganza as we unpack the secrets to secure digital parenting. We're joined by Alanna Powers, a research specialist from the renowned Family Online Safety Institute (FOSI).
Join Thane Riddle for another episode of Cloak & Dagger. He covers privacy/security news and tips in the first hour… And in the second hour, DeProgramming Coordinator Rayo2 joins to read and analyze the unpublished book of the gold medal winner in the libertarian special autism Olympics. [DONATE MONERO VIA… The post Cloak & Dagger with Thane Riddle, Episode 8: Privacy/Security News & Tips + “Fun At School” Mockiobook Reading appeared first on The Vonu Podcast.
Ethical hacker Rachel Tobac joins us to answer a juicy question: How would she hack someone reasonably security savvy like Matt?
We chat with Material Security about protecting G Suite and MS365. How else are you monitoring the most commonly used cloud environments and applications? In the security news: Google Sues Badbox operators Authenticated or Unauthenticated, big difference and my struggle to get LLMs to create exploits for me Ring cameras that were not hacked Malicous AURs Killing solar farms Weak passwords are all it takes Microsoft's UEFI keys are expiring Kali Linux and Raspberry PI Wifi updates Use lots of electricity, get a visit from law enforcement Sharepoint, vulnerabilities, nuclear weapons, and why you should use the cloud The time to next exploit is short Sonicwall devices are getting exploited How not to vibe code SMS blasters This segment is sponsored by Material Security. Visit https://securityweekly.com/materialsecurity to see purpose-built Google Workspace and Office 365 security in action! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-884
We're back with a brand-new season of Random but Memorable! ✨
It's Tuesday night at the studio and we've got plenty of things to react to in the news, including word on a 2026 lawsuit that may force the truth about TWA 800 into the public record.. After we are done with all of that and comments from the audience, we're checking in with James and Skip of https://patriot-protect.com/ with some Cyber Security news, plus some opinions on huge investments being made into AI Cities. Unleash Your Brain w/ Keto Brainz Nootropic Promo code FRANKLY: https://tinyurl.com/2cess6y7 Sponsor The Show and Get VIP Perks: https://www.quitefrankly.tv/sponsor One-Time Tip: http://www.paypal.me/QuiteFranklyLive Read July Newsletter: https://tinyurl.com/y4yvuxff Elevation Blend Coffee & Official QF Mugs: https://www.coffeerevolution.shop/category/quite-frankly Official QF Apparel: https://tinyurl.com/f3kbkr4s Send Holiday cards, Letters, and other small gifts, to the Quite Frankly P.O. Box! Quite Frankly 222 Purchase Street, #105 Rye, NY, 10580 Send Crypto: BTC: 1EafWUDPHY6y6HQNBjZ4kLWzQJFnE5k9PK Leave a Voice Mail: https://www.speakpipe.com/QuiteFrankly Quite Frankly Socials: Twitter/X: @QuiteFranklyTV Instagram: @QuiteFranklyOfficial Discord Chat: https://discord.gg/KCdh92Fn GUILDED Chat: https://tinyurl.com/kzrk6nxa Official Forum: https://tinyurl.com/k89p88s8 Telegram: https://t.me/quitefranklytv Truth: https://tinyurl.com/5n8x9s6f GETTR: https://tinyurl.com/2fprkyn4 MINDS: https://tinyurl.com/4p84d3cx Gab: https://tinyurl.com/mr42m2au Streaming Live On: QuiteFrankly.tv (Powered by Foxhole) Youtube: https://tinyurl.com/yc2cn395 BitChute: https://tinyurl.com/46dfca5c Rumble: https://tinyurl.com/yeytwwyz Kick: https://kick.com/quitefranklytv Audio On Demand: Spotify: https://spoti.fi/301gcES iTunes: http://apple.co/2dMURMq Amazon: https://amzn.to/3afgEXZ SoundCloud: https://tinyurl.com/yc44m474
WE NEED YOU! Our 2025 listener survey is now live, and we'd love to hear from you. Whether you've been with us from episode one or just joined the chaos, your feedback will make the show even better.
Random but Memorable turns 150! 1️⃣5️⃣0️⃣ (It's official, we're old.)