meta_pixel
Tapesearch Logo
Log in
Security Now (Audio)

SN 947: Article 45 - Citrix Bleed update, Ace Hardware cyberattack, Bitwarden get Passkeys

Security Now (Audio)

Leo Laporte

Cyber Crime, Malware, Technology, Encryption, Steve Gibson, Security, Hacking, Twit, Spyware, Leo Laporte

4.62.1K Ratings

🗓️ 7 November 2023

⏱️ 134 minutes

🧾️ Download transcript

Summary

  • Microsoft announced storing their Azure keys in an HSM after previously losing control of a private signing key
  • A quartet of new 0-day vulnerabilities in Exchange Server that Microsoft declined to fix
  • Apache ActiveMQ servers under attack exploiting a 0-day, with over half of publicly exposed servers vulnerable
  • Update on the Citrix Bleed vulnerability with evidence of hackers gaining access and post-exploitation activity
  • CVSS version 4 released with new metrics for better granularity and clarity of vulnerability scores
  • Ace Hardware suffered a cyberattack impacting servers and systems
  • Google abandons controversial "Web DRM" proposal to let sites restrict browser extensions
  • Analysis of "BadCandy" malware infecting vulnerable Cisco routers
  • Bitwarden password manager adds support for FIDO2 passkeys in browser extension
  • Rescuing a severely degraded SSD and bringing it back to life with SpinRite
  • Feedback from listeners on IPv6 adoption, factors for choosing crypto primes, installing Windows 11, and more
  • The brewing battle in the EU over proposed eIDAS regulation Article 45 that could ban security checks on root certificates and undermine encrypted web traffic

Show Notes - https://www.grc.com/sn/SN-947-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to this show at https://twit.tv/shows/security-now.

Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Sponsors:

Transcript

Click on a timestamp to play from that location

0:00.0

It's time for security now.

0:01.2

Steve Gibson is here coming up lots to talk about.

0:04.4

Microsoft has some more flaws in exchange server.

0:07.9

This time they say, yeah, we're not going to fix it.

0:12.1

Well, maybe they ought to.

0:14.0

We'll also talk about an attack on our favorite hardware store.

0:18.0

Oh no, an update on Citrix Bleed.

0:21.0

And then, Steve's going to talk about something I hadn't heard anything

0:26.2

about but it's a real grab from the EU that will really destroy internet security.

0:33.5

What is section 45?

0:34.9

Stay tuned.

0:35.7

Security now is next.

0:37.2

Podcasts you love.

0:41.3

From people you trust.

0:43.0

This is Twit.

0:45.0

This is Twit.

0:46.0

This is Security now with Steve Gibson,

0:51.0

episode 947, recorded Tuesday, November 7th, 2023, Article 45.

1:00.7

This episode of Security Now is brought to you by Lookout, whether on a device or in the cloud your business data is always on the move.

1:09.0

Minimize risk, increase visibility, and ensure compliance with Lookout's unified platform.

1:15.0

Visit lookout.com today.

1:17.6

And by Thinks Canary.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Leo Laporte, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Leo Laporte and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.