meta_pixel
Tapesearch Logo
Log in
Security Now (Audio)

SN 945: The Power of Privilege - New cURL vulnerabilities, CVSS 10.0 Cisco Nightmare, So long VBScript!

Security Now (Audio)

Leo Laporte

Cyber Crime, Malware, Technology, Encryption, Steve Gibson, Security, Hacking, Twit, Spyware, Leo Laporte

4.62.1K Ratings

🗓️ 24 October 2023

⏱️ 131 minutes

🧾️ Download transcript

Summary

  • How fake drives continue to be sold on Amazon despite negative reviews
  • Microsoft is discontinuing support for the VBScript language
  • The 30-year old NTLM authentication protocol will eventually be removed from Windows
  • Two new vulnerabilities found in cURL
  • A new Cisco router vulnerability rated CVSS 10.0 was used to hack over 40,000 devices
  • Debate over whether "lib" should rhyme with "vibe" or "air"
  • Instructions for accessing the SpinRite 6.1 pre-release version
  • Feedback on passkey exportability and server IP address encryption
  • A listener asks if ransomware can encrypt already encrypted files
  • How Privacy Badger un-rewrites Google's search result links
  • The NSA and CISA warn about the power of privilege and the dangers of account misconfigurations like privilege creep, elevated service account permissions, and non-essential use of elevated accounts

Show Notes - https://www.grc.com/sn/SN-945-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to this show at https://twit.tv/shows/security-now.

Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Sponsors:

Transcript

Click on a timestamp to play from that location

0:00.0

It's time for security now Steve Gibson is here coming up the end of the line for

0:04.5

VB script or is it another massive flaw in curl a CVSS of 10 for Cisco and the power of privilege and why it's not a good thing.

0:18.4

It's all coming up next on security now. Podcasts you love.

0:25.0

From people you trust.

0:27.0

This is Twit.

0:30.0

This is Security now with Steve Gibson episode 945 recorded Tuesday, October 24th,

0:41.0

2023. The power of privilege.

0:46.7

Security now is brought to you by Drata.

0:50.3

All too often security professionals

0:52.2

undergo the tedious and arduous task of manual

0:56.3

evidence collection for your compliance.

0:58.7

Withdrawal companies can complete audits, monitor controls, and expand security assurance efforts to scale.

1:05.0

Say goodbye to manual evidence collection.

1:07.0

Hello to automation, all done at draughta speed.

1:11.0

Visit draughta.com slash Twit to get a demo and 10% off implementation.

1:18.4

And by Delete Me.

1:20.1

Reclaim your privacy by removing personal data from online sources.

1:24.3

Protect yourself.

1:25.5

Reduce the risk of fraud, spam, cyber security threats and more

1:29.4

by going to join Delete Me.com slash Twit. Use the code Twit for 20% off. And by Thinksed Canary

1:39.2

Tocans are a quick painless way to help defenders discover they've been breached by having

1:44.9

attackers announce themselves.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Leo Laporte, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Leo Laporte and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.