Security Now (Audio) · TWiT

Least Privilege - Cybercrime Goes Pro

February 11, 2026·2 hr 37 min·5 clips
A U.S. cyber strike during Operation Midnight Hammer stopped Iran from launching surface-to-air missiles.
The hint lands dry. OpenClaw gets a short, technical verdict, and it is not exactly reassuring. AI coding is treated as a real security problem, not a shiny trick. A listener from corporate IT has noticed how often the show returns to AI, and the answer is straightforward: insecure code generation is now part of the job. The topic list moves quickly. GDPR fine collection, Midnight Hammer, cyber offense, and app coding security all come up before the episode settles into the machinery. Then the federal edge devices take over. Gibson works through a directive aimed at EOS hardware across federal networks, especially the boxes that keep running quietly enough to disappear into the dust. Inertia is the problem. Old devices stay because nothing looks broken, budgets are tight, and the next urgent fire keeps winning. The dust almost steals the scene. His point goes beyond unsupported hardware and unpatched risk, though the directive is clearly meant to push agencies to find and fix vulnerable gear. Replacement pays off in another way too. Newer devices are more likely to be configured under current security practices instead of old assumptions. Practices have improved. A modern device may reject a six character password, demand stronger minimums, and make casual setup harder to repeat. That is the useful security lesson underneath the directive. Defense improves through incident response, but also through ordinary replacement cycles that pull stale assumptions out of federal networks. Leo Laporte keeps the episode loose and conversational. He opens with familiar banter, gestures toward privacy and computer tech, and closes by sending live viewers to the usual streaming channels. Sponsor and network material stays at the edge. The center is Gibson's patient case that cyber defense often starts by dragging neglected systems back into the present.

As heard by us

A practical Security Now episode on AI coding risk, end-of-service edge devices, and the professionalization of cybercrime.

"Least Privilege" frames cybercrime as a more professional operation, but its sharper moments are grounded in the plain failures that let attackers in: AI-assisted coding with uncertain security judgment, unsupported edge devices, weak defaults, and old federal network gear left…

Read the full review in PlayNext →

Why you'd press play

Cybercrime went corporate. Your AI still thinks it is writing safe code. Interesting timing.

Read the full recommendation in PlayNext →
Listen to the show on