Security Now (Audio)

SN 943: The Top 10 Cybersecurity Misconfigurations - MACE Act Passed, Brave Layoffs, 23andMe Breached


Listen Later

  • Steve announces the release of his new freeware utility ValiDrive for detecting fake drive capacities.
  • 23andMe claims a recent data breach exposed customer info due to credential stuffing attacks.
  • Key stats from Microsoft's 2023 Digital Defense Report on cyberattacks, including increased attacks on open source software, growth in business email compromise, and more password attacks.
  • Brave lays off 9% of its staff amid the tough economic climate, despite its efforts to diversify revenue with new search features.
  • Google Docs exports replace links with tracking redirects, enabling Google to monitor clicked links from exported documents.
  • The MOVEit breach impacted Sony, exposing employee and family data.
  • Firefox 118 now supports Encrypted ClientHello for hiding site requests from network surveillance.
  • Google will provide 7 years of updates for its new Pixel phones, up from 5 years previously.
  • The MACE Act passed overwhelmingly in Congress, allowing agencies more flexibility in cybersecurity hiring.
  • Median dwell time for ransomware dropped to less than 1 day, with human-driven attacks deploying it faster.
  • Steve digs into the top 10 cybersecurity misconfigurations outlined in the new NSA/CISA advisory.
  • Show notes: https://www.grc.com/sn/SN-943-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:

    • GO.ACILEARNING.COM/TWIT
    • drata.com/twit
    • lookout.com
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Security Now (Audio)By TWiT

      • 5
      • 5
      • 5
      • 5
      • 5

      5

      2 ratings


      More shows like Security Now (Audio)

      View all
      This Week in Tech (Audio) by TWiT

      This Week in Tech (Audio)

      3,003 Listeners

      Hands-On Tech (Audio) by TWiT

      Hands-On Tech (Audio)

      1,965 Listeners

      WSJ Tech News Briefing by The Wall Street Journal

      WSJ Tech News Briefing

      1,633 Listeners

      Security Now (Audio) by TWiT

      Security Now (Audio)

      1,962 Listeners

      MacBreak Weekly (Audio) by TWiT

      MacBreak Weekly (Audio)

      2,012 Listeners

      Windows Weekly (Audio) by TWiT

      Windows Weekly (Audio)

      854 Listeners

      Risky Business by Patrick Gray

      Risky Business

      362 Listeners

      No Agenda Show by Adam Curry & John C. Dvorak

      No Agenda Show

      5,927 Listeners

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

      632 Listeners

      Tech News Weekly (Audio) by TWiT

      Tech News Weekly (Audio)

      1,064 Listeners

      Accidental Tech Podcast by Marco Arment, Casey Liss, John Siracusa

      Accidental Tech Podcast

      2,092 Listeners

      Windows Weekly (Audio) by TWiT

      Windows Weekly (Audio)

      2 Listeners

      Cyber Security Headlines by CISO Series

      Cyber Security Headlines

      119 Listeners

      Human Events Daily with Jack Posobiec by Human Events with Jack Posobiec

      Human Events Daily with Jack Posobiec

      5,886 Listeners