meta_pixel
Tapesearch Logo
Log in
Security Now (Audio)

SN 943: The Top 10 Cybersecurity Misconfigurations - MACE Act Passed, Brave Layoffs, 23andMe Breached

Security Now (Audio)

Leo Laporte

Cyber Crime, Malware, Technology, Encryption, Steve Gibson, Security, Hacking, Twit, Spyware, Leo Laporte

4.62.1K Ratings

🗓️ 10 October 2023

⏱️ 132 minutes

🧾️ Download transcript

Summary

  • Steve announces the release of his new freeware utility ValiDrive for detecting fake drive capacities.
  • 23andMe claims a recent data breach exposed customer info due to credential stuffing attacks.
  • Key stats from Microsoft's 2023 Digital Defense Report on cyberattacks, including increased attacks on open source software, growth in business email compromise, and more password attacks.
  • Brave lays off 9% of its staff amid the tough economic climate, despite its efforts to diversify revenue with new search features.
  • Google Docs exports replace links with tracking redirects, enabling Google to monitor clicked links from exported documents.
  • The MOVEit breach impacted Sony, exposing employee and family data.
  • Firefox 118 now supports Encrypted ClientHello for hiding site requests from network surveillance.
  • Google will provide 7 years of updates for its new Pixel phones, up from 5 years previously.
  • The MACE Act passed overwhelmingly in Congress, allowing agencies more flexibility in cybersecurity hiring.
  • Median dwell time for ransomware dropped to less than 1 day, with human-driven attacks deploying it faster.
  • Steve digs into the top 10 cybersecurity misconfigurations outlined in the new NSA/CISA advisory.

Show notes: https://www.grc.com/sn/SN-943-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to this show at https://twit.tv/shows/security-now.

Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Sponsors:

Transcript

Click on a timestamp to play from that location

0:00.0

it's time for security now Steve Gibson is here more victims of the move it

0:04.4

vulnerability would you believe it will also talk about the future of the

0:08.8

brave browser seems like things have gotten a little rocky Steve is very

0:12.7

suspicious of 23 and me's explanation about their breach and then we're

0:17.4

going to talk about sissa and their top 10 misconfiguration settings maybe

0:25.1

something you want to think about going forward it's all coming up next

0:28.4

on security now podcasts you love from people you trust

0:36.0

this is twit

0:41.6

this is security now with Steve Gibson episode 943 recorded Tuesday October 10th

0:48.8

2023 the top 10 cyber security misconfigurations

0:55.4

security now is brought to you by our friends at it pro TV now called ACI

1:00.5

learning ACI's new cyber skills is training that's for

1:04.5

everyone not just the pros visit go dot ACI learning dot com slash twit as a

1:10.2

twit listener you'll get up to 65 percent off an IT pro enterprise

1:13.6

solution plan just complete the form and you'll get a quote based on your

1:17.5

team's size that's go dot ACI learning dot com slash twit

1:23.2

and by drata all too often security professionals

1:27.3

undergo the tedious and arduous task of manually collecting evidence

1:32.7

with drata companies can complete audits monitor controls and expand

1:36.9

security assurance efforts to scale say goodbye to manual evidence collection

1:41.3

say hello to automation done at drata speed visit drata dot com slash twit

1:47.2

to get a demo and 10 percent off implementation

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Leo Laporte, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Leo Laporte and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.