Security Now (Audio)

SN 1055: React's Perfect 10 - RAM Is the New Lobster


Listen Later

A devastating new React vulnerability earned a "perfect 10" for risk, letting attackers remotely run code on a million-plus servers with a single HTTP request. Find out what happened, how fast attackers moved in, and why this bug changes everything for web security.

  • France's VanityFair face a stiff fine over cookies.
  • GrapheneOS pulls out of France over coercion worries.
  • The EU adds to the pile-on over underage social media.
  • India mandates the tracking of all smartphones.
  • Apple says no.
  • India abandons its smartphone tracking mandate.
  • India requires all encrypted messaging to be SIM-tied.
  • Scattered Lapsus$ Hunters --becomes--> SLH.
  • AI demand has driven RAM pricing sky high.
  • GRC's DNS Benchmark is finished and available.
  • Cisco may talk a good game, but they're still Cisco.
  • Browsers to ask users for local network access permission.
  • React: The worst remote code exploit in a LONG time.
  • Show Notes - https://www.grc.com/sn/SN-1055-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to Security Now at https://twit.tv/shows/security-now.

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Join Club TWiT for Ad-Free Podcasts!

    Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

    Sponsors:

    • 1password.com/securitynow
    • veeam.com
    • bigid.com/securitynow
    • zscaler.com/security
    • hoxhunt.com/securitynow
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Security Now (Audio)By TWiT

      • 5
      • 5
      • 5
      • 5
      • 5

      5

      3 ratings


      More shows like Security Now (Audio)

      View all
      Global News Podcast by BBC World Service

      Global News Podcast

      7,608 Listeners

      No Agenda Show by Adam Curry & John C. Dvorak

      No Agenda Show

      5,948 Listeners

      Macworld Podcast by Foundry

      Macworld Podcast

      308 Listeners

      This Week in Tech (Audio) by TWiT

      This Week in Tech (Audio)

      3,060 Listeners

      Security Now (Audio) by TWiT

      Security Now (Audio)

      2,011 Listeners

      MacBreak Weekly (Audio) by TWiT

      MacBreak Weekly (Audio)

      2,012 Listeners

      Intelligent Machines (Audio) by TWiT

      Intelligent Machines (Audio)

      780 Listeners

      Accidental Tech Podcast by Marco Arment, Casey Liss, John Siracusa

      Accidental Tech Podcast

      2,139 Listeners

      LINUX Unplugged by Jupiter Broadcasting

      LINUX Unplugged

      268 Listeners

      The Amp Hour Electronics Podcast by The Amp Hour (Chris Gammell and David L Jones)

      The Amp Hour Electronics Podcast

      231 Listeners

      Smashing Security by Graham Cluley

      Smashing Security

      318 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      8,041 Listeners

      Tech Brew Ride Home by Morning Brew

      Tech Brew Ride Home

      961 Listeners

      This Week in Space (Audio) by TWiT

      This Week in Space (Audio)

      155 Listeners

      Risky Bulletin by risky.biz

      Risky Bulletin

      44 Listeners