Security Now (Audio)

TWiT

73 episodes listed below

Listen to the show on

Patient cybersecurity analysis with practical teeth.

The gist

Security Now tracks the week’s security, privacy, and software-supply-chain stories with Steve Gibson as the steady technical center. Recent episodes move from LinkedIn browser scanning and PyPI exploits to router bans, quantum risk, and least-privilege defenses.

PRESS PLAY

Find your next episode

All episodes

About Security Now (Audio)

Security Now is a weekly cybersecurity briefing for listeners who want the mechanism, not just the headline. The show’s center is Steve Gibson’s careful technical narration, usually framed by Leo Laporte’s conversational prompts and quick reality checks. It has a familiar rhythm. A story is introduced, the risk is named, and then the machinery is taken apart piece by piece. Recent episodes cover LinkedIn’s browser-scanning JavaScript, FCC action on consumer routers, LiteLLM’s PyPI exploit concerns, click-fix attacks, quantum factorization risk, OpenSSL vulnerability handling, AI bug bounty pressure, MongoDB exposure, and end-of-support edge devices in federal networks. The range is broad, but the sensibility is consistent. Security failures are treated as systems problems, not isolated surprises. Old routers matter because old defaults persist. Third-party libraries matter because responsibility does not disappear when code is borrowed. Authentication matters because the show keeps returning to what happens after it fails. That practical streak gives the show weight. It is willing to talk about North Korean hackers, Russian surveillance hardware, enterprise VPN exposure, and malware that evades traditional antivirus without turning the material into alarmism. The mood is dry and analytical, with flashes of humor when the field becomes absurd. Leo Laporte keeps the room human. Steve Gibson keeps the details intact. Together, they make space for long explanations of cryptography, network boundaries, browser behavior, supply-chain risk, and least-privilege design. The show is best for technically comfortable listeners: security professionals, systems administrators, software developers, and serious technology followers. It assumes intelligence and rewards patience. Its value is cumulative. Week by week, it builds a working model of how modern security actually fails, and why boring controls like filtering, patch tracking, replacement planning, and careful dependency review still matter.

Made for: Security Now is for security professionals, administrators, developers, and technically curious listeners who can follow detailed discussion of networks, software supply chains, cryptography, and privacy. It also suits careful generalists who prefer calm explanation over panic.

What sets it apart: The show stands out for its willingness to spend real time on the underlying mechanism behind each security story. It pairs deep technical exposition with a conversational counterweight, making dense topics like OpenSSL, PyPI exploits, router policy, and quantum risk feel traceable.

In their own words

Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week. You can join Club TWiT for $10 per month and get ad-free audio and video feeds for all our shows plus everything else the club offers...or get just this podcast ad-free for $5 per month. New episodes every Tuesday.

As heard by us

Based on 5 episodes we listened to · September 2026

Security Now connects fresh cyber incidents to the design assumptions, operational habits, and neglected dependencies that let failures spread.

Security Now turns current security incidents into patient, technically grounded conversations between Steve Gibson and Leo Laporte. The pair move from compromised software dependencies and invasive LinkedIn JavaScript to aging network equipment, authentication failures, and…

Read our full review in PlayNext →

Why you'd press play

A privacy scandal becomes a code audit before Steve Gibson lets you anywhere near the conclusion.

Press play if you want

  • Steve Gibson to trace a vulnerability past the headline and into the machinery
  • practical security thinking that survives failed authentication and neglected hardware
Read the full recommendation in PlayNext →
cybersecurity news analysisprivacy and browser trackingsoftware supply-chain attacksrouter and edge-device securityleast-privilege defensesquantum computing and cryptographyAI-assisted vulnerability discoveryenterprise VPN exposure

Talks about

Best episodes of Security Now (Audio)

Short reviews from the PlayNext desk, based on the episodes we processed.

The FCC Bans New Consumer Routers - LinkedIn's JavaScript BombshellApr 8, 2026

A pointed Security Now warning about LinkedIn's JavaScript tracking and the browser controls users still lack.

LinkedIn's browser-side data collection gives this Security Now episode its sharpest edge. Steve Gibson and Leo Laporte move from the old tracking pixel to a 2.7 MB JavaScript payload that, according to the discussion, checks visitors' local browser-extension traces across more…

LiteLLM - Click Fix Attacks SurgeApr 1, 2026

A sharp Security Now episode on LiteLLM, click-fix attacks, quantum risk, and the strange theater of wartime surveillance.

Security Now builds this episode around LiteLLM, framed as a PyPI nightmare for coders, then widens out to click-fix attacks, Apple's response, Linux age verification, and Google's newly aggressive 2029 quantum warning.

The Call Is Coming From Inside the House - Live From Zero Trust World 2026Mar 5, 2026

Steve Gibson argues for assuming authentication can fail, then tightening the network so attackers have less room to move.

The Call Is Coming From Inside the House is Security Now in conference mode: Steve Gibson and Leo Laporte are live at Zero Trust World in Orlando, working from one blunt premise. Assume authentication fails, then ask what an attacker can do next.

Least Privilege - Cybercrime Goes ProFeb 11, 2026

A practical Security Now episode on AI coding risk, end-of-service edge devices, and the professionalization of cybercrime.

"Least Privilege" frames cybercrime as a more professional operation, but its sharper moments are grounded in the plain failures that let attackers in: AI-assisted coding with uncertain security judgment, unsupported edge devices, weak defaults, and old federal network gear left…

Mongo's Too Easy - AI Bug Bounties Gone WildFeb 4, 2026

A practical Security Now episode on AI-found OpenSSL bugs, fragile dependencies, and the cost of treating third-party code as someone else's responsibility.

Security Now turns a packed security week into a pointed warning about misplaced trust. Steve Gibson tees up an antivirus that infects its own users, curl ending its bug bounties, and MongoDB lowering the skill bar for attackers, then settles into a sharper discussion of…

Podcasts like Security Now (Audio)

  • Malicious LifeMalicious Life

    Deeply researched narrative dives into hacking history and cyber-law cases, hosted by Ran Levi.

  • Click Here

    Reported narratives on hackers, spyware, and data crimes from Dina Temple-Raston.

  • Hacking HumansN2K Networks

    Dave, Joe, and Maria break down phishing kits, deepfakes, and social-engineering scams weekly.

  • The Privacy AdvisorJedidiah Bracy, IAPP Editorial Director

    IAPP's Jedidiah Bracy interviews the regulators and lawyers writing privacy and AI law.

  • The CyberWireAlan Geason

    A daily cybersecurity briefing hosted by Dave Bittner, pairing breaking incidents with a guest interview.

  • SANS Stormcast: Daily Cyber Security NewsJohannes Ullrich

    Daily signal for working defenders.

Episodes

  1. 1

    How worried should we be? - Unpredictable Agents

    Sep 30, 2026·2h 42m
  2. 2

    How worried should we be? - Unpredictable Agents

    Sep 30, 2026·2h 42m
  3. 3

    Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers

    Sep 23, 2026·2h 50m
  4. 4

    Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers

    Sep 23, 2026·2h 50m
  5. 5

    Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers

    Sep 23, 2026·2h 50m
  6. 6

    Are we the Krell? - 153 Million Driver's Licenses Leaked

    Sep 16, 2026·2h 51m
  7. 7

    Are we the Krell? - 153 Million Driver's Licenses Leaked

    Sep 16, 2026·2h 51m
  8. 8

    Are we the Krell? - 153 Million Driver's Licenses Leaked

    Sep 16, 2026·2h 51m
  9. 9

    AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

    Sep 9, 2026·3h 6m
  10. 10

    AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

    Sep 9, 2026·3h 6m
  11. 11

    AI-Driven Expertise Loss - Gemini, Hugging Face, and the AI Arms Race

    Sep 9, 2026·3h 6m
  12. 12

    AI Patching Shortcomings - Should You Trust AI-Generated Code?

    Sep 2, 2026·2h 52m
  13. 13

    AI Patching Shortcomings - Should You Trust AI-Generated Code?

    Sep 2, 2026·2h 52m
  14. 14

    AI Patching Shortcomings - Should You Trust AI-Generated Code?

    Sep 2, 2026·2h 52m
  15. 15

    Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

    Aug 26, 2026·2h 48m
  16. 16

    Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

    Aug 26, 2026·2h 48m
  17. 17

    Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist

    Aug 26, 2026·2h 48m
  18. 18

    Restraint Abliteration - Rotating Keys, Broken Guardrails

    Aug 19, 2026·2h 49m
  19. 19

    Restraint Abliteration - Rotating Keys, Broken Guardrails

    Aug 19, 2026·2h 49m
  20. 20

    Restraint Abliteration - Rotating Keys, Broken Guardrails

    Aug 19, 2026·2h 49m
  21. 21

    The Post BlackHat State of AI - When AI Writes Malware

    Aug 12, 2026·2h 51m
  22. 22

    The Post BlackHat State of AI - When AI Writes Malware

    Aug 12, 2026·2h 51m
  23. 23

    The Post BlackHat State of AI - When AI Writes Malware

    Aug 12, 2026·2h 51m
  24. 24

    Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

    Aug 6, 2026·2h 5m
  25. 25

    Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

    Aug 6, 2026·2h 5m
  26. 26

    Black Hat - The Hidden Flaws in AI Security Nobody Saw Coming

    Aug 6, 2026·2h 5m
  27. 27

    Models Go Rogue & ExploitGym - Regulators, Start Your Engines

    Jul 29, 2026·3h 8m
  28. 28

    Models Go Rogue & ExploitGym - Regulators, Start Your Engines

    Jul 29, 2026·3h 8m
  29. 29

    Models Go Rogue & ExploitGym - Regulators, Start Your Engines

    Jul 29, 2026·3h 8m
  30. 30

    A Nefarious Novel Use for AI - Ransomware Negotiations Go High-Tech

    Jul 22, 2026·2h 47m
  31. 31

    A Nefarious Novel Use for AI - Ransomware Negotiations Go High-Tech

    Jul 22, 2026·2h 47m
  32. 32

    A Nefarious Novel Use for AI - Ransomware Negotiations Go High-Tech

    Jul 22, 2026·2h 47m
  33. 33

    HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records

    Jul 15, 2026·2h 49m
  34. 34

    HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records

    Jul 15, 2026·2h 49m
  35. 35

    HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks Records

    Jul 15, 2026·2h 49m
  36. 36

    The Apex Agentic Adversary - Visual Prompt Injection Strikes

    Jul 8, 2026·2h 53m
  37. 37

    The Apex Agentic Adversary - Visual Prompt Injection Strikes

    Jul 8, 2026·2h 53m
  38. 38

    The Apex Agentic Adversary - Visual Prompt Injection Strikes

    Jul 8, 2026·2h 53m
  39. 39

    A SOTA State-Sponsored Campaign - AI's New Superpower: Loop Engineering

    Jul 1, 2026·2h 50m
  40. 40

    A SOTA State-Sponsored Campaign - AI's New Superpower: Loop Engineering

    Jul 1, 2026·2h 50m
  41. 41

    A SOTA State-Sponsored Campaign - AI's New Superpower: Loop Engineering

    Jul 1, 2026·2h 50m
  42. 42

    The Residential Proxy Threat - Malicious Proxies in Your Living Room

    Jun 24, 2026·2h 48m
  43. 43

    The Residential Proxy Threat - Malicious Proxies in Your Living Room

    Jun 24, 2026·2h 48m
  44. 44

    The Residential Proxy Threat - Malicious Proxies in Your Living Room

    Jun 24, 2026·2h 48m
  45. 45

    Patch Tuesday à la AI - Arch Linux Repo Under Siege

    Jun 17, 2026·2h 36m
  46. 46

    Patch Tuesday à la AI - Arch Linux Repo Under Siege

    Jun 17, 2026·2h 36m
  47. 47

    Patch Tuesday à la AI - Arch Linux Repo Under Siege

    Jun 17, 2026·2h 36m
  48. 48

    The Malicious Use of AI - Anthropic's Red Team Report

    Jun 10, 2026·2h 37m
  49. 49

    The Malicious Use of AI - Anthropic's Red Team Report

    Jun 10, 2026·2h 37m
  50. 50

    The Malicious Use of AI - Anthropic's Red Team Report

    Jun 10, 2026·2h 37m
  51. 51

    AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?

    Jun 3, 2026·3h 20m
  52. 52

    AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?

    Jun 3, 2026·3h 20m
  53. 53

    AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?

    Jun 3, 2026·3h 20m
  54. 54

    Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

    May 27, 2026·2h 44m
  55. 55

    Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

    May 27, 2026·2h 44m
  56. 56

    Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?

    May 27, 2026·2h 44m
  57. 57

    Daybreak and Codename MDASH - Microsoft's Edge Password Blunder

    May 20, 2026·2h 52m
  58. 58

    Daybreak and Codename MDASH - Microsoft's Edge Password Blunder

    May 20, 2026·2h 52m
  59. 59

    Daybreak and Codename MDASH - Microsoft's Edge Password Blunder

    May 20, 2026·2h 52m
  60. 60

    DigiCert does it right - Hugging Face Under Fire

    May 13, 2026·2h 41m
  61. 61

    The FCC Bans New Consumer Routers - LinkedIn's JavaScript Bombshell

    Episode 1073 is recorded on Tuesday, April 7, 2026.

    Apr 8, 2026·2h 52m·5 clips
  62. 62

    LiteLLM - Click Fix Attacks Surge

    LiteLLM is the calm thread running through this one.

    Apr 1, 2026·2h 49m·5 clips
  63. 63

    Bucketsquatting - Meta and TikTok's Tracking Pixels

    Mar 25, 2026·2h 48m
  64. 64

    CISA's Free Internet Scanning - Malware Disguised as a VPN

    Mar 18, 2026·2h 46m
  65. 65

    You can't hide from LLMs - Was Your Smart TV a Stealth Proxy?

    Mar 11, 2026·2h 44m
  66. 66

    The Call Is Coming From Inside the House - Live From Zero Trust World 2026

    Live in Orlando, the show feels a little looser.

    Mar 5, 2026·52m·4 clips
  67. 67

    KongTuke's CrashFix - Click, Paste, Pwned

    Mar 3, 2026·2h 53m
  68. 68

    KongTuke's CrashFix - Click, Paste, Pwned

    Mar 3, 2026·2h 53m
  69. 69

    Password Leakage - Zero Trust, Zero Knowledge

    Feb 25, 2026·2h 50m
  70. 70

    Password Leakage - Zero Trust, Zero Knowledge

    Feb 25, 2026·2h 50m
  71. 71

    Attestation - Code Signing Gets Tough

    Feb 18, 2026·2h 41m
  72. 72

    Least Privilege - Cybercrime Goes Pro

    OpenClaw does not get a comforting answer.

    Feb 11, 2026·2h 37m·5 clips
  73. 73

    Mongo's Too Easy - AI Bug Bounties Gone Wild

    MongoDB gets the blunt headline.

    Feb 4, 2026·2h 56m·5 clips