SN 1067: KongTuke's CrashFix - Click, Paste, Pwned
Security Now (Audio)
Leo Laporte
4.6 • 2.3K Ratings
🗓️ 3 March 2026
⏱️ 160 minutes
🧾️ Download transcript
Summary
A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting traditional defenses.
- The lowdown on last week's "no turn" picture of the week.
- Is an AI-driven hacking campaign a big deal now.
- Clause used in multiple Mexican government attacks.
- Apple continues to be confronted with age restrictions.
- COPPA needs an exception to allow age collection.
- Meta swamps law enforcement with AI-slop CSAM reports.
- Roskomnadzor has been busy blocking VPNs. Guess how many.
- The UK tries to report their self-scanning success.
- Remember that hacker who extorted the psychotherapy patients.
- Scattered Lapsus$ Hunters is actively recruiting women.
- Cisco lands another breathtakingly rare 10.0 CVSS.
- VulnCheck's report on 2025 vulnerabilities and exploits.
- Steve discovers a fabulous $72 Hardware Security Module.
- A listener shares an interesting AI service discovery.
- The very potent "ClickFix" exploit evolves
Show Notes - https://www.grc.com/sn/SN-1067-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit
Sponsors:
Transcript
Click on a timestamp to play from that location
| 0:00.0 | It's time for security now. Steve Gibson is here. A show we recorded a little bit early because we're going to Zero Trust World in Florida. |
| 0:07.4 | We have lots to talk about, though, jam-packed programming. We're going to talk about scattered lapses hunters. |
| 0:14.0 | They're looking for female voices for their social engineering. AI hacking. Is it here? Yes, it is. And a very potent click-fix exploit. |
| 0:26.8 | When you see how this works, you might wonder how you didn't get bit by it. All of that coming |
| 0:32.0 | up next on security now. |
| 0:36.4 | Podcasts you love. |
| 0:38.1 | From people you trust. |
| 0:40.6 | This is Twitter. |
| 0:45.9 | This is Security Now with Steve Gibson. |
| 0:48.6 | Episode 1067 recorded Sunday, March 1st, 2026. |
| 0:53.8 | Kongtook's Crash Fix. |
| 0:56.7 | It's time for security now. |
| 0:59.0 | Hello, everybody. |
| 1:00.4 | Normally, I would say you wait all week for Tuesday, but if you're watching live, it's Sunday. |
| 1:08.0 | March 1st, Steve and I are headed off to Orlando, Florida tomorrow for the incredible |
| 1:13.0 | Zero Trust World Conference put on by Threadlocker. So we thought we'd do secure now a little early. |
| 1:17.6 | Those of you who listen after the fact will get the show at the same time. So you're going, |
| 1:22.8 | what are they talking about? But, you know, the only reason I mentioned this, Steve, |
| 1:27.4 | you probably want to |
| 1:28.1 | mention it too is that if anything happens on monday monday it won't be in the show till next |
| 1:34.6 | week well and this has been actually a problem i've been conscious of because i've now got in the |
| 1:40.7 | habit of preparing tuesday's show on the previous weekend, Saturday and Sunday. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from Leo Laporte, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of Leo Laporte and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

