Skip to main content
Security Now
CPE Certificates
Light
Verify Certificate
Episode
Select...
#1092 - Restraint Abliteration
#1091 - The Post BlackHat State of AI
#1089 - Models Go Rogue & ExploitGym
#1088 - A nefarious novel use for AI
#1087 - HalluSquatting, GhostApproval & GitLost
#1086 - The Apex Agentic Adversary
#1085 - A SOTA State-Sponsored Campaign
#1084 - The Residential Proxy Threat
#1083 - Patch Tuesday à la AI
#1082 - The Malicious Use of AI
#1081 - AI Captures the Flag
#1080 - Vulnerability Debt Repayment
#1079 - Daybreak and Codename MDASH
#1078 - DigiCert Does It Right
#1077 - A Browser AI API?
#1076 - FAST16.SYS
#1075 - Yes. Exactly.
#1074 - What Mythos Means
#1073 - The FCC Bans New Consumer Routers
#1072 - LiteLLM
#1071 - Bucketsquatting
#1070 - CISA's Free Internet Scanning
#1069 - You can't hide from LLMs
#1067 - KongTuke's CrashFix
#1066 - Password Leakage
#1065 - Attestation
#1064 - Least Privilege
#1063 - Mongo's Too Easy
#1062 - VoidLink: AI-Generated Malware
#1061 - More GhostPoster
#1060 - 3-Day Certificates
#1059 - MongoBleed
#1057 - GhostPoster
#1056 - Australia
#1055 - React's Perfect 10
#1054 - Bots in the Belfry
#1053 - Banning VPNs
#1052 - Global Cell Phone Tracking
#1051 - Amazon Sues Perplexity
#1050 - Here Come the AI Browsers
#1049 - DNS Cache Poisoning Returns
#1048 - Mic-E-Mouse
#1047 - RediShell's CVSS 10.0
#1046 - Google's Developer Registration Decree
#1045 - News and Listener Views
#1044 - The EU's Online Age Verification
#1043 - Memory Integrity Enforcement
#1042 - Letters of Marque
#1041 - Covering All the Bases
#1040 - Clickjacking "Whac-A-Mole"
#1039 - The Sad Case of Scriptcase
#1038 - Perplexity's Duplicity
#1037 - Chinese Participation in MAPP
#1036 - Inside the SharePoint 0-day RCE
#1035 - Cloudflare's 1.1.1.1 Outage
#1034 - Introduction to Zero-Knowledge Proofs
#1033 - Going on the Offensive
#1032 - Pervasive Web Fingerprinting
#1031 - How Salt Typhoon Gets In
#1030 - Internet Foreground Radiation
#1029 - The Illusion of Thinking
#1028 - AI Vulnerability Hunting
#1027 - Artificial Intelligence
#1026 - Rogue Comms Tech Found in U.S. Power Grid
#1025 - Secure Conversation Records Retention
#1024 - Don't Blame Signal
#1023 - Preventing Windows Sandbox Abuse
#1022 - Windows Sandbox
#1021 - Device Bound Session Credentials
#1020 - Multi-Perspective Issuance Corroboration
#1019 - EU OS
#1018 - THE QUANTUM THREAT
#1017 - Is YOUR System Vulnerable to Rowhammer?
#1016 - The Bluetooth Backdoor
#1015 - Spatial-Domain Wireless Jamming
#1014 - FREEDOM Administration Login
#1013 - Chrome Web Store Is a Mess
#1012 - Hiding School Cyberattacks
#1011 - Jailbreaking AI
#1010 - DNS Over TLS
#1009 - Attacking TOTP
#1008 - HOTP & TOTP
#1007 - AI Training & Inference
#1005 - Six-Day Certificates? Why?
#1004 - A Chat with GPT
#1003 - A Light-Day Away
#1002 - Disconnected Experiences
#1001 - Artificial General Intelligence (AGI)
#1000 - One Thousand!
#999 - AI Vulnerability Discovery
#998 - The Endless Journey to IPv6
#997 - Credential Exchange Protocol
#996 - BIMI (Up Scotty)
#995 - uBlock Origin & Manifest V3
#994 - Recall's Re-Rollout
#989 - Cascading Bloom Filters
#988 - National Public Data
#987 - Rethinking Revocation
#986 - How Revoking!
#980 - The Mixed Blessing of a Crappy PRNG
#979 - THE ANGLE OF THE DANGLE
#978 - The rise and fall of code.microsoft.com
#977 - A Large Language Model in Every Pot
#976 - The 50 Gigabyte Privacy Bomb
#975 - 312 SCIENTISTS & RESEARCHERS RESPOND
#974 - Microsoft's Head in the Clouds
#973 - Not So Fast
#972 - Passkeys: A Shattered Dream?
#971 - Chat (out of) Control
#970 - GhostRace
#969 - Minimum Viable Secure Product
#968 - A Cautionary Tale
#967 - GoFetch
#966 - Morris the Second
#965 - Passkeys vs 2FA
#964 - PQ3
#963 - Web portal? Yes, please!
#962 - The Internet Dodged a Bullet
#961 - BitLocker: Chipped or Cracked?
#960 - UNFORESEEN CONSEQUENCES
#959 - Stamos on "Microsoft Security"
#958 - A Week of News and Listener Views
#957 - The Protected Audience API
#956 - The Inside Tracks
#955 - The Mystery of CVE-2023-38606
#953 - Active Listening
#952 - Quantum Computing Breakthrough
#951 - Revisiting Browser Trust
#950 - Leo Turns 67
#949 - Ethernet Turned 50
#948 - What if a Bit Flipped?
#947 - Article 45
#946 - Citrix Bleed
#945 - The Power of Privilege
#944 - Abusing HTTP/2 Rapid Reset
#943 - The Top 10 Cybersecurity Misconfigurations
#942 - Encrypting Client Hello
#941 - We Told You So!
#940 - When Hashes Collide
#939 - LastMess
#938 - Apple Says No
#937 - The Man in the Middle
#936 - When Heuristics Backfire
#935 - "Topics" Arrives
#934 - Revisiting Global Privacy Control
#933 - TETRA:BURST
#932 - Satellite Insecurity, Part 2
#931 - SATELLITE INSECURITY, PART 1
#930 - Rowhammer Indelible Fingerprinting
#929 - Operation Triangle
#928 - The Massive MOVEit Maelstrom
#927 - Scanning the Internet
#926 - Windows Platform Binary Table
#925 - Brave's Brilliant Off the Record Request
#924 - VCaaS - Voice Cloning as a Service
#923 - Location Tracker Behavior
#922 - Detecting Unwanted Location Trackers
#921 - OSB OMG and Other News!
#920 - An End-to-End Encryption Proposal
#919 - Forced Entry
#918 - A Dangerous Interpretation
#917 - Zombie Software
#916 - Microsoft's Email Extortion
#915 - Flying Trojan Horses
#914 - Sony Sues Quad9
#913 - A Fowl Incident
#912 - The NSA @ Home
#911 - A Clever Regurgitator
#910 - Ascon
#909 - How ESXi Fell
#908 - Data Operand Independent Timing
#907 - Credential Reuse
#906 - The Rule of Two
#905 - 1
#904 - Leaving LastPass
#902 - A Generic WAF Bypass
#901 - Apple Encrypts the Cloud
#900 - LastPass Again
#899 - Freebie Bots & Evil Cameras
#898 - Wi-Peep
#897 - Memory-Safe Languages
#896 - Something for Everyone
#895 - After 20 Years in GCHQ
#894 - Data Breach Responsibility
#893 - Password Change Automation
#892 - Source Port Randomization
#891 - Poisoning Akamai
#890 - DarkNet Politics
#889 - Spell-Jacking
#888 - The EvilProxy Service
#887 - Embedding AWS Credentials
#886 - Wacky Data Exfiltration
#885 - THE BUMBLEBEE LOADER
#884 - TLS PRIVATE KEY LEAKAGE
#883 - The Maker's Schedule
#882 - Rowhammer's Nine Lives
#881 - The MV720
#880 - RetBleed
#879 - The Rolling Pwn
#878 - The ZuoRAT
#877 - The Hertzbleed Attack
#876 - Microsoft's Patchy Patches
#875 - The PACMAN Attack
#874 - Passkeys, Take 2
#873 - DuckDuckGone?
#872 - Dis-CONTI-nued: The End of Conti?
#871 - The New EU Surveillance State
#870 - THAT "PASSKEYS" THING
#869 - Global Privacy Control
#868 - The Zero-Day Explosion
#867 - A Critical Windows RPC RCE
#866 - Spring4Shell
#865 - Port Knocking
#864 - Targeted Exploitation
#863 - Use After Free
#862 - QWACs On? or QWACs Off?
#861 - Rogue Nation Cyber Consequences
#860 - Trust Dies in Darkness
#859 - A BGP Routing Attack
#858 - InControl
#857 - The Inept Panda
#856 - The "Topics" API
#855 - Inside the NetUSB Hack
#854 - Anatomy of a Log4j Exploit
#853 - URL Parsing Vulnerabilities
#852 - December 33rd
#850 - It's a Log4j Christmas
#849 - Log4j & Log4Shell
#848 - XSinator
#847 - Bogons Begone!
#846 - HTTP REQUEST SMUGGLING
#845 - Blacksmith
#844 - Bluetooth Fingerprinting
#843 - Trojan Source
#842 - The More Things Change...
#841 - Minh Duong's Epic Rickroll
#840 - 0-Day Angst
#839 - Something Went Wrong
#838 - Autodiscover.fiasco
#837 - Cobalt Strike
#836 - The Meris Botnet
#835 - TPM v1.2 vs 2.0
#834 - Life: Hanging by a PIN
#833 - Microsoft's Reasoned Neglect
#832 - Microsoft's Culpable Negligence
#831 - Apple's CSAM Mistake
#830 - The BlackMatter Interview
#829 - SeriousSAM & PetitPotam
#828 - REvil Vanishes!
#827 - REvil's Clever Crypto
#826 - The Kaseya Saga
#825 - Halfway Through 2021
#824 - Avaddon Ransonomics
#823 - TLS Confusion Attacks
#822 - Extrinsic Password Managers
#821 - Epsilon Red
#820 - The Dark Escrow
#819 - The WiFi Frag Attacks
#818 - News from the DarkSide
#816 - The Mystery of AS8003
#815 - Homogeneity Attacks
#814 - PwnIt and OwnIt
#813 - A Spy in Our Pocket
#812 - GIT Me Some PHP
#811 - What the FLoC?
#810 - ProxyLogon
#809 - Hafnium
#808 - CNAME Collusion
#807 - Dependency Confusion: The Build Chain Hack
#806 - C.O.M.B.
#805 - SCADA Scandal
#804 - NAT Slipstreaming 2.0
#803 - Comparative Smartphone Security
#802 - Where the Plaintext Is
#801 - Out With the Old
#800 - SolarBlizzard
Full Name
Email
Hash
Verify
Back