The Power of Privilege - New cURL vulnerabilities, CVSS 10.0 Cisco Nightmare, So long VBScript!
Security Now Security Now
63.2K subscribers
11,313 views
0

 Published On Oct 24, 2023

• How fake drives continue to be sold on Amazon despite negative reviews
• Microsoft is discontinuing support for the VBScript language
• The 30-year old NTLM authentication protocol will eventually be removed from Windows
• Two new vulnerabilities found in cURL
• A new Cisco router vulnerability rated CVSS 10.0 was used to hack over 40,000 devices
• Debate over whether "lib" should rhyme with "vibe" or "air"
• Instructions for accessing the SpinRite 6.1 pre-release version
• Feedback on passkey exportability and server IP address encryption
• A listener asks if ransomware can encrypt already encrypted files
• How Privacy Badger un-rewrites Google's search result links
• The NSA and CISA warn about the power of privilege and the dangers of account misconfigurations like privilege creep, elevated service account permissions, and non-essential use of elevated accounts

Show Notes - https://www.grc.com/sn/SN-945-Notes.pdf

Hosts: Steve Gibson and Leo Laporte
Security Now episode 945
More Info: https://twit.tv/shows/security-now/ep...

Sponsors:
• drata.com/twit
• joindeleteme.com/twit promo code TWIT
• canary.tools/twit - use code: TWIT

Download or subscribe to this show at https://twit.tv/shows/security-now

Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: https://grc.com/ also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Products we recommend: https://www.amazon.com/shop/twitnetca...
TWiT may earn commissions on certain products.

Join our TWiT Community on Discourse: https://www.twit.community/

Follow us:
https://twit.tv/
  / twit  
  / twitnetwork  
  / twit.tv  

About us:
TWiT.tv is a technology podcasting network located in the San Francisco Bay Area with the #1 ranked technology podcast This Week in Tech hosted by Leo Laporte. Every week we produce over 30 hours of content on a variety of programs including Tech News Weekly, MacBreak Weekly, This Week in Google, Windows Weekly, Security Now, All About Android, and more.

show more

Share/Embed