meta_pixel
Tapesearch Logo
Log in
Security Now (Audio)

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned

Security Now (Audio)

Leo Laporte

Twit, Steve Gibson, Leo Laporte, Hacking, Technology, Cyber Crime, Malware, Security, Encryption, Spyware

4.62.3K Ratings

🗓️ 3 March 2026

⏱️ 173 minutes

🧾️ Download transcript

Summary

A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting traditional defenses.

  • The lowdown on last week's "no turn" picture of the week.
  • Is an AI-driven hacking campaign a big deal now.
  • Clause used in multiple Mexican government attacks.
  • Apple continues to be confronted with age restrictions.
  • COPPA needs an exception to allow age collection.
  • Meta swamps law enforcement with AI-slop CSAM reports.
  • Roskomnadzor has been busy blocking VPNs. Guess how many.
  • The UK tries to report their self-scanning success.
  • Remember that hacker who extorted the psychotherapy patients.
  • Scattered Lapsus$ Hunters is actively recruiting women.
  • Cisco lands another breathtakingly rare 10.0 CVSS.
  • VulnCheck's report on 2025 vulnerabilities and exploits.
  • Steve discovers a fabulous $72 Hardware Security Module.
  • A listener shares an interesting AI service discovery.
  • The very potent "ClickFix" exploit evolves

Show Notes - https://www.grc.com/sn/SN-1067-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Transcript

Click on a timestamp to play from that location

0:00.0

It's time for security now. Steve Gibson is here. A show we recorded a little bit early

0:04.2

because we're going to Zero Trust World in Florida. We have lots to talk about, though,

0:09.7

jam-packed programming. We're going to talk about scattered lapses hunters. They're looking for

0:14.6

female voices for their social engineering. AI hacking. Is it here? Yes, it is. And a very potent click-fix exploit.

0:26.8

When you see how this works, you might wonder how you didn't get bit by it. All of that coming

0:32.0

up next on security now.

0:36.4

Podcasts you love.

0:38.1

From people you trust.

0:40.6

This is Twitter.

0:45.9

This is Security Now with Steve Gibson.

0:48.6

Episode 1067 recorded Sunday, March 1st, 2026.

0:53.8

Kongtook's crash fix.

0:56.5

Security.

0:57.1

A weird Sunday edition.

0:59.5

A one-off.

1:01.7

Yes.

1:02.3

Let's never do it again.

1:03.7

Let's never do it.

1:06.1

When's your flight, Mr. G?

1:10.0

You muted us. I know. I'm sad. When's your flight, Mr. G? You muted us, Steve to say.

1:12.1

I'm setting.

1:13.4

When's your flight, Mr. G?

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Leo Laporte, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Leo Laporte and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.