SN 1011: Jailbreaking AI – Deepseek, “ROUTERS” Act, Zyxel Vulnerability

SN 1011: Jailbreaking AI – Deepseek, “ROUTERS” Act, Zyxel Vulnerability

Why was DeepSeek banned by Italian authorities? What internal proprietary DeepSeek data was found online? What is “DeepSeek” anyway? Why do we care, and what does it mean? Did Microsoft just make OpenAI’s strong model available for free? Google explains how generative AI can be and is being misused. An actively exploited and unpatched Zyxel…

SN 1010: DNS over TLS – Record DDoS,  Hackers Get Hacked

SN 1010: DNS over TLS – Record DDoS, Hackers Get Hacked

eM Client CAN be purchased outright. An astonishing 5-year-old typo in MasterCard’s DNS. An unwelcome surprise received by 18,459 low-level hackers. DDoS attacks continue growing, seemingly without any end in sight. Let’s Encrypt clarifies their plans for 6-day “we barely knew you” certificates. SpinRite uncovers a bad brand new 8TB drive. Listener feedback about TOTP,…

SN 1009: Attacking TOTP – Force-Installed Outlook, DJI Firmware Update

SN 1009: Attacking TOTP – Force-Installed Outlook, DJI Firmware Update

What do we learn from January’s record breaking 0-day critical Patch Tuesday? Microsoft to “force-install” a new Outlook into all Windows 10 and 11 desktops? GoDaddy required to get much more serious about its hosting security. More age verification enforcement is coming, including globally. What another instance of a widely exposed management interface teaches us….

SN 1008: HOTP and TOTP – SyncThing, Auto-Updates, Sci-Fi Recs

SN 1008: HOTP and TOTP – SyncThing, Auto-Updates, Sci-Fi Recs

Meta winds down 3rd-party content filtering. Is encryption soon to follow? Taking over abandoned Command & Control server domains (strictly for research purposes only). IoT devices to get the “Cyber Trust Mark” — Will anyone notice or care? “SyncThing” receives a (blessedly infrequent) update. Government email is not using encryption? Really? Email relaying prevents point-to-point…

SN 1007: AI Training & Inference – Unencrypted Email, Doom Captcha
|

SN 1007: AI Training & Inference – Unencrypted Email, Doom Captcha

The consequences of Internet content restriction. The measured risks of 3rd-party browser extensions. The consequences of SonicWall’s unpatched 9.8 firewall severity. The incredible number of still-unencrypted email servers. SonicWall vulnerability patching Shadowserver Foundation & eMail Encryption Salt Typhoon Evicted HIPAA gets a long-needed cybersecurity upgrade. The EU standardizes on USB-C for power charging. What? Believe…

SN 1006: Best of 2024 – Apple’s Secret Backdoor, CrowdStrike Catastrophe, Recall’s Privacy Nightmare
| |

SN 1006: Best of 2024 – Apple’s Secret Backdoor, CrowdStrike Catastrophe, Recall’s Privacy Nightmare

Watch video here:https://twit.tv/shows/security-now/episodes/1006?autostart=false Leo revisits some of the year’s top Security Now segments of 2024. 956. Apple’s Hardware Backdoor: Steve reflects on the previous week’s ‘The Mystery of CVE-2023-38606’ deep-dive. Did Apple deliberately designed a secure backdoor? 960. Unforeseen Consequences of Google’s 3rd-party Cookie Cutoff: As Google moves to phase out third-party cookies, the advertising…

SN 1005: 6-Day Certificates? Why? – Android Anti-Tracking, MFA lLogin Bypass, BIMI
| | |

SN 1005: 6-Day Certificates? Why? – Android Anti-Tracking, MFA lLogin Bypass, BIMI

Watch video here:https://twit.tv/shows/security-now/episodes/1005?autostart=false Is AI the Wizard of Oz? Or is it more? Microsoft’s long standing effective MFA login bypass. Is TPM 2.0 not required after all for Windows 11? Meet 14 North Korean IT workers who made $88 million from the West. Android updates its Bluetooth tracking with anti-tracking. The NPM package manager repository…

SN 1004: A Chat with GPT – China’s Telecom Hack, Microsoft Activation Cracked, Coding with ChatGPT 4o
| | |

SN 1004: A Chat with GPT – China’s Telecom Hack, Microsoft Activation Cracked, Coding with ChatGPT 4o

Watch Video here:https://twit.tv/shows/security-now/episodes/1004?autostart=false This week, Steve and Leo discuss the recent ‘Salt Typhoon’ hack of U.S. telecom providers by China, TPM 2.0 requirement for Windows 11, Microsoft’s newly hacked Windows activation system, Apple patenting AI facial and body recognition, and much more. Steve also shares an intriguing conversation he had with the ChatGPT 4o AI…

SN 1003: A Light-Day Away – Digital Epileptic Seizures, Tor Needs You, Zello Password Panic, Wireguard’s Open Port Debate
| | |

SN 1003: A Light-Day Away – Digital Epileptic Seizures, Tor Needs You, Zello Password Panic, Wireguard’s Open Port Debate

Watch video here:https://twit.tv/shows/security-now/episodes/1003?autostart=false Steve Gibson and Leo Laporte discuss Microsoft’s clarification about AI training data usage, a fascinating breakthrough in understanding autonomous vehicle vulnerabilities, and an urgent call for help from the Tor Network. The show culminates in an in-depth exploration of NASA’s incredible Voyager 1 mission, which continues to communicate with Earth from nearly…

SN 1002: Disconnected Experiences – “Nearest Neighbor” Attack, Repo Swatting, the Return of Recall
| | |

SN 1002: Disconnected Experiences – “Nearest Neighbor” Attack, Repo Swatting, the Return of Recall

Watch video here:https://twit.tv/shows/security-now/episodes/1002?autostart=false What’s the new “nearest neighbor” attack and how do you defend against it? Let’s Encrypt just turned 10. What changes has it wrought? Now the Coast Guard is worried about Chinese built ship-to-shore cranes. Pakistan becomes the first country to block Bluesky. There’s a new way to get Git repos “swatted” and…