Security Now is a weekly cybersecurity briefing for listeners who want the mechanism, not just the headline. The show’s center is Steve Gibson’s careful technical narration, usually framed by Leo Laporte’s conversational prompts and quick reality checks. It has a familiar rhythm. A story is introduced, the risk is named, and then the machinery is taken apart piece by piece. Recent episodes cover LinkedIn’s browser-scanning JavaScript, FCC action on consumer routers, LiteLLM’s PyPI exploit concerns, click-fix attacks, quantum factorization risk, OpenSSL vulnerability handling, AI bug bounty pressure, MongoDB exposure, and end-of-support edge devices in federal networks. The range is broad, but the sensibility is consistent. Security failures are treated as systems problems, not isolated surprises. Old routers matter because old defaults persist. Third-party libraries matter because responsibility does not disappear when code is borrowed. Authentication matters because the show keeps returning to what happens after it fails. That practical streak gives the show weight. It is willing to talk about North Korean hackers, Russian surveillance hardware, enterprise VPN exposure, and malware that evades traditional antivirus without turning the material into alarmism. The mood is dry and analytical, with flashes of humor when the field becomes absurd. Leo Laporte keeps the room human. Steve Gibson keeps the details intact. Together, they make space for long explanations of cryptography, network boundaries, browser behavior, supply-chain risk, and least-privilege design. The show is best for technically comfortable listeners: security professionals, systems administrators, software developers, and serious technology followers. It assumes intelligence and rewards patience. Its value is cumulative. Week by week, it builds a working model of how modern security actually fails, and why boring controls like filtering, patch tracking, replacement planning, and careful dependency review still matter.