Security Now (Audio)

SN 945: The Power of Privilege - New cURL vulnerabilities, CVSS 10.0 Cisco Nightmare, So long VBScript!


Listen Later

  • How fake drives continue to be sold on Amazon despite negative reviews
  • Microsoft is discontinuing support for the VBScript language
  • The 30-year old NTLM authentication protocol will eventually be removed from Windows
  • Two new vulnerabilities found in cURL
  • A new Cisco router vulnerability rated CVSS 10.0 was used to hack over 40,000 devices
  • Debate over whether "lib" should rhyme with "vibe" or "air"
  • Instructions for accessing the SpinRite 6.1 pre-release version
  • Feedback on passkey exportability and server IP address encryption
  • A listener asks if ransomware can encrypt already encrypted files
  • How Privacy Badger un-rewrites Google's search result links
  • The NSA and CISA warn about the power of privilege and the dangers of account misconfigurations like privilege creep, elevated service account permissions, and non-essential use of elevated accounts
  • Show Notes - https://www.grc.com/sn/SN-945-Notes.pdf

    Hosts: Steve Gibson and Leo Laporte

    Download or subscribe to this show at https://twit.tv/shows/security-now.

    Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

    You can submit a question to Security Now at the GRC Feedback Page.

    For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

    Sponsors:

    • drata.com/twit
    • joindeleteme.com/twit promo code TWIT
    • canary.tools/twit - use code: TWIT
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Security Now (Audio)By TWiT

      • 5
      • 5
      • 5
      • 5
      • 5

      5

      3 ratings


      More shows like Security Now (Audio)

      View all
      Global News Podcast by BBC World Service

      Global News Podcast

      7,770 Listeners

      No Agenda Show by Adam Curry & John C. Dvorak

      No Agenda Show

      5,974 Listeners

      Macworld Podcast by Foundry

      Macworld Podcast

      309 Listeners

      This Week in Tech (Audio) by TWiT

      This Week in Tech (Audio)

      3,060 Listeners

      Security Now (Audio) by TWiT

      Security Now (Audio)

      2,010 Listeners

      MacBreak Weekly (Audio) by TWiT

      MacBreak Weekly (Audio)

      2,012 Listeners

      Intelligent Machines (Audio) by TWiT

      Intelligent Machines (Audio)

      781 Listeners

      Accidental Tech Podcast by Marco Arment, Casey Liss, John Siracusa

      Accidental Tech Podcast

      2,141 Listeners

      LINUX Unplugged by Jupiter Broadcasting

      LINUX Unplugged

      275 Listeners

      The Amp Hour Electronics Podcast by The Amp Hour (Chris Gammell and David L Jones)

      The Amp Hour Electronics Podcast

      228 Listeners

      Smashing Security by Graham Cluley

      Smashing Security

      319 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      8,082 Listeners

      Tech Brew Ride Home by Morning Brew

      Tech Brew Ride Home

      970 Listeners

      This Week in Space (Audio) by TWiT

      This Week in Space (Audio)

      162 Listeners

      Risky Bulletin by Risky Business Media

      Risky Bulletin

      45 Listeners