<?xml version="1.0" encoding="utf-8" ?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/" version="2.0">
	<channel>
		<title>Security Now (Audio)</title>
		<link>https://twit.tv/shows/security-now</link>
		<generator>TWiT Feed Generator v3.10.3</generator>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		<language>en-US</language>
		<copyright>This work is licensed under a Creative Commons License - Attribution-NonCommercial-NoDerivatives 4.0 International - http://creativecommons.org/licenses/by-nc-nd/4.0/</copyright>
		<creativeCommons:license>http://creativecommons.org/licenses/by-nc-nd/4.0/</creativeCommons:license>
		<managingEditor>distro@twit.tv (TWiT Editors)</managingEditor>
		<webMaster>distro@twit.tv (TWiT Engineering)</webMaster>
		<ttl>720</ttl>
		<sy:updatePeriod>weekly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
		<lastBuildDate>Tue, 19 Jan 2021 19:55:02 PST</lastBuildDate>
		<pubDate>Tue, 19 Jan 2021 19:55:02 PST</pubDate>
		<rawvoice:frequency>weekly</rawvoice:frequency>
		<rawvoice:location>Petaluma, CA</rawvoice:location>
		<itunes:type>episodic</itunes:type>
		<itunes:author>TWiT</itunes:author>
		<itunes:subtitle>Steve Gibson discusses the hot topics in security today with Leo Laporte.</itunes:subtitle>
		<itunes:summary>Steve Gibson, the man who coined the term spyware and created the first anti-spyware program, creator of Spinrite and ShieldsUP, discusses the hot topics in security today with Leo Laporte.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 21:30 UTC.</itunes:summary>
		<description>Steve Gibson, the man who coined the term spyware and created the first anti-spyware program, creator of Spinrite and ShieldsUP, discusses the hot topics in security today with Leo Laporte.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 21:30 UTC.</description>
		<itunes:keywords>TWiT, Technology, Steve Gibson, Leo Laporte, security, spyware, malware, hacking, cyber crime, emcryption</itunes:keywords>
		<rawvoice:rating tv="tv-g">tv-g</rawvoice:rating>
		<itunes:explicit>false</itunes:explicit>
		<itunes:block>no</itunes:block>
		<itunes:owner>
			<itunes:name>Leo Laporte</itunes:name>
			<itunes:email>distro@twit.tv</itunes:email>
		</itunes:owner>
		<itunes:category text="News">
			<itunes:category text="Tech News"/>
</itunes:category>
		<itunes:category text="Technology" />
		<image>
			<title>Security Now (Audio)</title>
			<url>https://elroy.twit.tv/sites/default/files/styles/twit_album_art_144x144/public/images/shows/security_now/album_art/audio/sn_albumart_mask.jpg?itok=VEh3JGKV</url>
			<link>https://twit.tv/shows/security-now</link>
			<width>144</width>
			<height>144</height>
		</image>
		<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_album_art_2048x2048/public/images/shows/security_now/album_art/audio/sn_albumart_mask.jpg?itok=scC8c-TL" />
		<itunes:new-feed-url>https://feeds.twit.tv/sn.xml</itunes:new-feed-url>
		<rawvoice:subscribe feed="https://feeds.twit.tv/sn.xml" itunes="https://podcasts.apple.com/us/podcast/security-now-mp3/id79016499?uo=10" html="https://twit.tv/shows/security-now"></rawvoice:subscribe>
		<atom:link href="https://feeds.twit.tv/sn.xml" type="application/rss+xml" rel="self"/>
		<item>
			<title>SN 802: Where the Plaintext Is - 2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</title>
			<itunes:title>Where the Plaintext Is - 2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 19 Jan 2021 17:30:00 PST</pubDate>
			<itunes:episode>802</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/802</link>
			<comments>https://twit.tv/shows/security-now/episodes/802</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, facebook whatsapp, plaintext security, encryption, at rest, in transit, e2ee, chrome, Chromium, duckduckgo, Google, project zero, google zero, patch tuesday microsoft, microsoft security, zerologon, nsa doh, </itunes:keywords>
			<description><![CDATA[
<p>2021's first Patch Tuesday, Titan Security Key side-channel attack, WhatsApp. </p>
<ul><li>When is Chrome not Chromium?</li>
<li>A major DuckDuckGo milestone.</li>
<li>Project Zero in the wild.</li>
<li>First Patch Tuesday of 2021.</li>
<li>ZeroLogon Drop Dead.</li>
<li>NSA warns against outsourcing DoH services.</li>
<li>A Side-Channel in Titan.</li>
<li>The "PayPal Football"</li>
<li>WhatsApp's decision to bring its data into Facebook.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-802-Notes.pdf">https://www.grc.com/sn/SN-802-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>2021's first Patch Tuesday, Titan Security Key side-channel attack, WhatsApp. </p>
<ul><li>When is Chrome not Chromium?</li>
<li>A major DuckDuckGo milestone.</li>
<li>Project Zero in the wild.</li>
<li>First Patch Tuesday of 2021.</li>
<li>ZeroLogon Drop Dead.</li>
<li>NSA warns against outsourcing DoH services.</li>
<li>A Side-Channel in Titan.</li>
<li>The "PayPal Football"</li>
<li>WhatsApp's decision to bring its data into Facebook.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-802-Notes.pdf">https://www.grc.com/sn/SN-802-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>2021's first Patch Tuesday, Titan Security Key side-channel attack, WhatsApp. </p>
<ul><li>When is Chrome not Chromium?</li>
<li>A major DuckDuckGo milestone.</li>
<li>Project Zero in the wild.</li>
<li>First Patch Tuesday of 2021.</li>
<li>ZeroLogon Drop Dead.</li>
<li>NSA warns against outsourcing DoH services.</li>
<li>A Side-Channel in Titan.</li>
<li>The "PayPal Football"</li>
<li>WhatsApp's decision to bring its data into Facebook.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-802-Notes.pdf">https://www.grc.com/sn/SN-802-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823537/hero/sn_0802.jpg?itok=vIJoKIRF"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0802/sn0802.mp3</guid>
			<itunes:duration>1:45:54</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0802/sn0802.mp3" length="50959257" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0802/sn0802.mp3" fileSize="50959257" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 802: Where the Plaintext Is - 2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</media:title>
				<media:description type="plain">2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, facebook whatsapp, plaintext security, encryption, at rest, in transit, e2ee, chrome, Chromium, duckduckgo, Google, project zero, google zero, patch tuesday microsoft, microsoft security, zerologon, nsa doh, </media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823537/hero/sn_0802.jpg?itok=kH-jMiHf" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 801: Out With The Old - SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</title>
			<itunes:title>Out With The Old - SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 12 Jan 2021 18:00:00 PST</pubDate>
			<itunes:episode>801</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/801</link>
			<comments>https://twit.tv/shows/security-now/episodes/801</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, firefox, Chromium, tenable, critical, firefox backspace, ryuk malware, ryuk crypto, intel marketing, intel ces, intel ransomware, male chastity cage, sex toy security, solarwinds sunburts, krebs stamos group,</itunes:keywords>
			<description><![CDATA[
<p>SolarWinds smoking gun, Signal influx of WhatsApp users, male chastity cage. </p>
<ul><li>Firefox and Chromium updates address remote system take over bugs.</li>
<li>Tenable researchers reported a critical Chromium bug.</li>
<li>What Firefox's backspace key does and should do.</li>
<li>How Ryuk malware operations netted $150 million via cryptocurrency exchange.</li>
<li>Intel: A triumph of marketing over technology.</li>
<li>The strange case of the Male Chastity Cage.</li>
<li>A SolarWinds smoking gun? "Sunburst backdoor."</li>
<li>A class action lawsuit filed by shareholders of SolarWinds stock.</li>
<li>The "Krebs Stamos Group"</li>
<li>Zyxel security endpoints under attack.</li>
<li>WhatsApp revises their privacy policy.</li>
<li>Signal sees a mass influx of WhatsApp users.</li>
<li>Out with the old: A look at the history of SpinRite code.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-801-Notes.pdf">https://www.grc.com/sn/SN-801-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>SolarWinds smoking gun, Signal influx of WhatsApp users, male chastity cage. </p>
<ul><li>Firefox and Chromium updates address remote system take over bugs.</li>
<li>Tenable researchers reported a critical Chromium bug.</li>
<li>What Firefox's backspace key does and should do.</li>
<li>How Ryuk malware operations netted $150 million via cryptocurrency exchange.</li>
<li>Intel: A triumph of marketing over technology.</li>
<li>The strange case of the Male Chastity Cage.</li>
<li>A SolarWinds smoking gun? "Sunburst backdoor."</li>
<li>A class action lawsuit filed by shareholders of SolarWinds stock.</li>
<li>The "Krebs Stamos Group"</li>
<li>Zyxel security endpoints under attack.</li>
<li>WhatsApp revises their privacy policy.</li>
<li>Signal sees a mass influx of WhatsApp users.</li>
<li>Out with the old: A look at the history of SpinRite code.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-801-Notes.pdf">https://www.grc.com/sn/SN-801-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>SolarWinds smoking gun, Signal influx of WhatsApp users, male chastity cage. </p>
<ul><li>Firefox and Chromium updates address remote system take over bugs.</li>
<li>Tenable researchers reported a critical Chromium bug.</li>
<li>What Firefox's backspace key does and should do.</li>
<li>How Ryuk malware operations netted $150 million via cryptocurrency exchange.</li>
<li>Intel: A triumph of marketing over technology.</li>
<li>The strange case of the Male Chastity Cage.</li>
<li>A SolarWinds smoking gun? "Sunburst backdoor."</li>
<li>A class action lawsuit filed by shareholders of SolarWinds stock.</li>
<li>The "Krebs Stamos Group"</li>
<li>Zyxel security endpoints under attack.</li>
<li>WhatsApp revises their privacy policy.</li>
<li>Signal sees a mass influx of WhatsApp users.</li>
<li>Out with the old: A look at the history of SpinRite code.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-801-Notes.pdf">https://www.grc.com/sn/SN-801-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823390/hero/sn_0801.jpg?itok=-EFlbI4g"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0801/sn0801.mp3</guid>
			<itunes:duration>2:00:15</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0801/sn0801.mp3" length="57837402" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0801/sn0801.mp3" fileSize="57837402" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 801: Out With The Old - SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</media:title>
				<media:description type="plain">SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, firefox, Chromium, tenable, critical, firefox backspace, ryuk malware, ryuk crypto, intel marketing, intel ces, intel ransomware, male chastity cage, sex toy security, solarwinds sunburts, krebs stamos group,</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823390/hero/sn_0801.jpg?itok=8QSlFMo7" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 800: SolarBlizzard - SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</title>
			<itunes:title>SolarBlizzard - SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 05 Jan 2021 18:00:00 PST</pubDate>
			<itunes:episode>800</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/800</link>
			<comments>https://twit.tv/shows/security-now/episodes/800</comments>
			<itunes:author>TWiT</itunes:author>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome antivirus, chrome prescan, av chrome, zyxel password, zyfwp / PrOw!aN_fXp, redundant password, swatter iot, swatting iot, internet of things swat, wordpress zend vulnerability</itunes:keywords>
			<description><![CDATA[
<p>SolarWinds' Orion software, swatting goes IoT, PHP Zend Framework vulnerability. </p>
<ul><li>Chrome struggles with A/V pre-scan file locking.</li>
<li>Zyxel security products protected by a single redundant password.</li>
<li>How Swatters are using IoT devices to increase the terror.</li>
<li>A new serious problem in the PHP Zend Framework on WordPress.</li>
<li>Bitcoin woes as value reaches new peaks.</li>
<li>ReadSpeed, SSD's, and SpinRite.</li>
<li>A new flaw discovered in SolarWinds' Orion software.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-800-Notes.pdf">https://www.grc.com/sn/SN-800-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsor:</strong><ul>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>SolarWinds' Orion software, swatting goes IoT, PHP Zend Framework vulnerability. </p>
<ul><li>Chrome struggles with A/V pre-scan file locking.</li>
<li>Zyxel security products protected by a single redundant password.</li>
<li>How Swatters are using IoT devices to increase the terror.</li>
<li>A new serious problem in the PHP Zend Framework on WordPress.</li>
<li>Bitcoin woes as value reaches new peaks.</li>
<li>ReadSpeed, SSD's, and SpinRite.</li>
<li>A new flaw discovered in SolarWinds' Orion software.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-800-Notes.pdf">https://www.grc.com/sn/SN-800-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsor:</strong><ul>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>SolarWinds' Orion software, swatting goes IoT, PHP Zend Framework vulnerability. </p>
<ul><li>Chrome struggles with A/V pre-scan file locking.</li>
<li>Zyxel security products protected by a single redundant password.</li>
<li>How Swatters are using IoT devices to increase the terror.</li>
<li>A new serious problem in the PHP Zend Framework on WordPress.</li>
<li>Bitcoin woes as value reaches new peaks.</li>
<li>ReadSpeed, SSD's, and SpinRite.</li>
<li>A new flaw discovered in SolarWinds' Orion software.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-800-Notes.pdf">https://www.grc.com/sn/SN-800-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsor:</strong><ul>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823174/hero/sn_0800.jpg?itok=L0sYe7gE"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0800/sn0800.mp3</guid>
			<itunes:duration>1:50:21</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0800/sn0800.mp3" length="53092729" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0800/sn0800.mp3" fileSize="53092729" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 800: SolarBlizzard - SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</media:title>
				<media:description type="plain">SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome antivirus, chrome prescan, av chrome, zyxel password, zyfwp / PrOw!aN_fXp, redundant password, swatter iot, swatting iot, internet of things swat, wordpress zend vulnerability</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823174/hero/sn_0800.jpg?itok=a6kUlS2-" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 799: Sunburst &amp; Supernova - Ransomware Task Force, Chrome 87, Firefox Caches, Preserving Flash Video</title>
			<itunes:title>Sunburst &amp; Supernova - Ransomware Task Force, Chrome 87, Firefox Caches, Preserving Flash Video</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 29 Dec 2020 17:30:00 PST</pubDate>
			<itunes:episode>799</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/799</link>
			<comments>https://twit.tv/shows/security-now/episodes/799</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Ransomware Task Force, Chrome 87, Firefox Caches, Preserving Flash Video</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome 87, insecure form warning, insecure form, chrome form, firefox cache, firefox partition, kazakhstan browser, rtf, ransomware task force, wordpress insecure, wordpress critical, wordpress plugin</itunes:keywords>
			<description><![CDATA[
<p>Ransomware Task Force, Chrome 87, Firefox caches, preserving Flash video. </p>
<ul><li>Chrome 87 backs away from Insecure Form Warnings.</li>
<li>Firefox to begin partitioning its caches.</li>
<li>Browsers say no to Kazakhstan again.</li>
<li>Announcing the RTF - The Ransomware Task Force.</li>
<li>5 million WordPress sites in critical danger.</li>
<li>Treck's TCP/IO stack strikes again!</li>
<li>Preserving Flash content online.</li>
<li>SpinRite: ReadSpeed is ready!</li>
<li>InitDisk is at release 5.</li>
<li>Numerous updates on SolarWind, Sunburst, and Supernova.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-799-Notes.pdf">https://www.grc.com/sn/SN-799-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
]]></description>
			<itunes:summary><![CDATA[
<p>Ransomware Task Force, Chrome 87, Firefox caches, preserving Flash video. </p>
<ul><li>Chrome 87 backs away from Insecure Form Warnings.</li>
<li>Firefox to begin partitioning its caches.</li>
<li>Browsers say no to Kazakhstan again.</li>
<li>Announcing the RTF - The Ransomware Task Force.</li>
<li>5 million WordPress sites in critical danger.</li>
<li>Treck's TCP/IO stack strikes again!</li>
<li>Preserving Flash content online.</li>
<li>SpinRite: ReadSpeed is ready!</li>
<li>InitDisk is at release 5.</li>
<li>Numerous updates on SolarWind, Sunburst, and Supernova.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-799-Notes.pdf">https://www.grc.com/sn/SN-799-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Ransomware Task Force, Chrome 87, Firefox caches, preserving Flash video. </p>
<ul><li>Chrome 87 backs away from Insecure Form Warnings.</li>
<li>Firefox to begin partitioning its caches.</li>
<li>Browsers say no to Kazakhstan again.</li>
<li>Announcing the RTF - The Ransomware Task Force.</li>
<li>5 million WordPress sites in critical danger.</li>
<li>Treck's TCP/IO stack strikes again!</li>
<li>Preserving Flash content online.</li>
<li>SpinRite: ReadSpeed is ready!</li>
<li>InitDisk is at release 5.</li>
<li>Numerous updates on SolarWind, Sunburst, and Supernova.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-799-Notes.pdf">https://www.grc.com/sn/SN-799-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823077/hero/sn_0799.jpg?itok=_quBvFWz"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0799/sn0799.mp3</guid>
			<itunes:duration>1:36:11</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0799/sn0799.mp3" length="46287727" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0799/sn0799.mp3" fileSize="46287727" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 799: Sunburst &amp; Supernova - Ransomware Task Force, Chrome 87, Firefox Caches, Preserving Flash Video</media:title>
				<media:description type="plain">Ransomware Task Force, Chrome 87, Firefox Caches, Preserving Flash Video</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome 87, insecure form warning, insecure form, chrome form, firefox cache, firefox partition, kazakhstan browser, rtf, ransomware task force, wordpress insecure, wordpress critical, wordpress plugin</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823077/hero/sn_0799.jpg?itok=FE-eU8QT" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 798: Best of 2020 - The Year's Best Stories on Security Now</title>
			<itunes:title>Best of 2020 - The Year's Best Stories on Security Now</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 22 Dec 2020 11:00:00 PST</pubDate>
			<itunes:episode>798</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/798</link>
			<comments>https://twit.tv/shows/security-now/episodes/798</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>The Year's Best Stories on Security Now</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, bestof 2020, security 2020, Clearview AI, EARN IT Act, Contact Tracing, covid tech, covid security, twitter hack, zoom security, zoombomb</itunes:keywords>
			<description><![CDATA[
<p>Leo Laporte walks through some of the highlights of the show and most impactful stories of 2020. Stories include: </p>
<ul><li>Clearview AI face scanning.</li>
<li>The "EARN IT" act.</li>
<li>Zoom security issues.</li>
<li>Why contact tracing apps won't work.</li>
<li>How to prevent the next Twitter hack</li>
<li>Ring's autonomous flying home security webcam.</li>
</ul> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
]]></description>
			<itunes:summary><![CDATA[
<p>Leo Laporte walks through some of the highlights of the show and most impactful stories of 2020. Stories include: </p>
<ul><li>Clearview AI face scanning.</li>
<li>The "EARN IT" act.</li>
<li>Zoom security issues.</li>
<li>Why contact tracing apps won't work.</li>
<li>How to prevent the next Twitter hack</li>
<li>Ring's autonomous flying home security webcam.</li>
</ul> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Leo Laporte walks through some of the highlights of the show and most impactful stories of 2020. Stories include: </p>
<ul><li>Clearview AI face scanning.</li>
<li>The "EARN IT" act.</li>
<li>Zoom security issues.</li>
<li>Why contact tracing apps won't work.</li>
<li>How to prevent the next Twitter hack</li>
<li>Ring's autonomous flying home security webcam.</li>
</ul> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/822987/hero/sn_0798_bestof.jpg?itok=bBrspC0T"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0798/sn0798.mp3</guid>
			<itunes:duration>1:13:01</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0798/sn0798.mp3" length="35169386" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0798/sn0798.mp3" fileSize="35169386" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 798: Best of 2020 - The Year's Best Stories on Security Now</media:title>
				<media:description type="plain">The Year's Best Stories on Security Now</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, bestof 2020, security 2020, Clearview AI, EARN IT Act, Contact Tracing, covid tech, covid security, twitter hack, zoom security, zoombomb</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/822987/hero/sn_0798_bestof.jpg?itok=9Qy1gCqh" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 797: SolarWinds - Chrome Throttling Ads, Google Outage, 2020 Pwnie Awards, JavaScript's 25th Birthday</title>
			<itunes:title>SolarWinds - Chrome Throttling Ads, Google Outage, 2020 Pwnie Awards, JavaScript's 25th Birthday</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 15 Dec 2020 19:00:00 PST</pubDate>
			<itunes:episode>797</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/797</link>
			<comments>https://twit.tv/shows/security-now/episodes/797</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Chrome Throttling Ads, Google Outage, 2020 Pwnie Awards, JavaScript's 25th Birthday</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, solarwinds, flash dead, end of flash, amnesia:33, d-link vulnerabiity, vpn vulnerability, patch tuesday, double extortion, chrome heavy ad, adrozek, pwnie award, pwnie 2020, initdisk 4, solarwinds hack</itunes:keywords>
			<description><![CDATA[
<p>Chrome throttling ads, Google outage, 2020 Pwnie Awards, JavaScript's 25th birthday. </p>
<ul><li>Chrome's heavy ad intervention.</li>
<li>Adrozek.</li>
<li>Ransomware: "Double Extortion."</li>
<li>A 0-click wormable vulnerability in D-Link VPN servers.</li>
<li>Google suffered an outage.</li>
<li>Amnesia:33.</li>
<li>Zero-day in WordPress SMTP plugin.</li>
<li>The 2020 Pwnie Awards.</li>
<li>The end of Flash.</li>
<li>JavaScript is celebrating its 25th birthday.</li>
<li>InitDisk release 4 published.</li>
<li>A deep look at the SolarWinds hack.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-797-Notes.pdf">https://www.grc.com/sn/SN-797-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Chrome throttling ads, Google outage, 2020 Pwnie Awards, JavaScript's 25th birthday. </p>
<ul><li>Chrome's heavy ad intervention.</li>
<li>Adrozek.</li>
<li>Ransomware: "Double Extortion."</li>
<li>A 0-click wormable vulnerability in D-Link VPN servers.</li>
<li>Google suffered an outage.</li>
<li>Amnesia:33.</li>
<li>Zero-day in WordPress SMTP plugin.</li>
<li>The 2020 Pwnie Awards.</li>
<li>The end of Flash.</li>
<li>JavaScript is celebrating its 25th birthday.</li>
<li>InitDisk release 4 published.</li>
<li>A deep look at the SolarWinds hack.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-797-Notes.pdf">https://www.grc.com/sn/SN-797-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Chrome throttling ads, Google outage, 2020 Pwnie Awards, JavaScript's 25th birthday. </p>
<ul><li>Chrome's heavy ad intervention.</li>
<li>Adrozek.</li>
<li>Ransomware: "Double Extortion."</li>
<li>A 0-click wormable vulnerability in D-Link VPN servers.</li>
<li>Google suffered an outage.</li>
<li>Amnesia:33.</li>
<li>Zero-day in WordPress SMTP plugin.</li>
<li>The 2020 Pwnie Awards.</li>
<li>The end of Flash.</li>
<li>JavaScript is celebrating its 25th birthday.</li>
<li>InitDisk release 4 published.</li>
<li>A deep look at the SolarWinds hack.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-797-Notes.pdf">https://www.grc.com/sn/SN-797-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/822855/hero/sn_0797.jpg?itok=Q-5dZI2W"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0797/sn0797.mp3</guid>
			<itunes:duration>2:11:23</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0797/sn0797.mp3" length="63182055" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0797/sn0797.mp3" fileSize="63182055" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 797: SolarWinds - Chrome Throttling Ads, Google Outage, 2020 Pwnie Awards, JavaScript's 25th Birthday</media:title>
				<media:description type="plain">Chrome Throttling Ads, Google Outage, 2020 Pwnie Awards, JavaScript's 25th Birthday</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, solarwinds, flash dead, end of flash, amnesia:33, d-link vulnerabiity, vpn vulnerability, patch tuesday, double extortion, chrome heavy ad, adrozek, pwnie award, pwnie 2020, initdisk 4, solarwinds hack</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/822855/hero/sn_0797.jpg?itok=V05hihre" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 796: Amazon Sidewalk - Google Play Core Library, iOS Zero-Click Radio Proximity Exploit, Apple M1 Chip</title>
			<itunes:title>Amazon Sidewalk - Google Play Core Library, iOS Zero-Click Radio Proximity Exploit, Apple M1 Chip</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 08 Dec 2020 18:00:00 PST</pubDate>
			<itunes:episode>796</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/796</link>
			<comments>https://twit.tv/shows/security-now/episodes/796</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Google Play Core Library, iOS Zero-Click Radio Proximity Exploit, Apple M1 Chip</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, Amazon Sidewalk, sidewalk security, sidewalk privacy, ransomware foxconn, ransomware egregor, ransomware k12, iphone wormable hack, iphone zero-click hack, ios wormable hack, ios radio hack, odoh</itunes:keywords>
			<description><![CDATA[
<p>Google Play Core Library, iOS zero-click radio proximity exploit, Apple M1 chip. </p>
<ul><li>Ransomware news regarding Foxconn, Egregor, and K12 Inc.</li>
<li>The Apple iPhone zero-click radio proximity vulnerability.</li>
<li>Oblivious DoH (ODoH).</li>
<li>Google Play Core Library problems.</li>
<li>The mysterious power of Apple's M1 Arm processor chip.</li>
<li>InitDisk release 2 published.</li>
<li>SpinRite update.</li>
<li>Amazon Sidewalk.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-796-Notes.pdf">https://www.grc.com/sn/SN-796-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://Wasabi.com">Wasabi.com  offer code SECURITYNOW</a></li>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Google Play Core Library, iOS zero-click radio proximity exploit, Apple M1 chip. </p>
<ul><li>Ransomware news regarding Foxconn, Egregor, and K12 Inc.</li>
<li>The Apple iPhone zero-click radio proximity vulnerability.</li>
<li>Oblivious DoH (ODoH).</li>
<li>Google Play Core Library problems.</li>
<li>The mysterious power of Apple's M1 Arm processor chip.</li>
<li>InitDisk release 2 published.</li>
<li>SpinRite update.</li>
<li>Amazon Sidewalk.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-796-Notes.pdf">https://www.grc.com/sn/SN-796-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://Wasabi.com">Wasabi.com  offer code SECURITYNOW</a></li>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Google Play Core Library, iOS zero-click radio proximity exploit, Apple M1 chip. </p>
<ul><li>Ransomware news regarding Foxconn, Egregor, and K12 Inc.</li>
<li>The Apple iPhone zero-click radio proximity vulnerability.</li>
<li>Oblivious DoH (ODoH).</li>
<li>Google Play Core Library problems.</li>
<li>The mysterious power of Apple's M1 Arm processor chip.</li>
<li>InitDisk release 2 published.</li>
<li>SpinRite update.</li>
<li>Amazon Sidewalk.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-796-Notes.pdf">https://www.grc.com/sn/SN-796-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://Wasabi.com">Wasabi.com  offer code SECURITYNOW</a></li>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/822682/hero/sn_0796.jpg?itok=5YCqd9ZX"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0796/sn0796.mp3</guid>
			<itunes:duration>2:10:22</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0796/sn0796.mp3" length="62698685" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0796/sn0796.mp3" fileSize="62698685" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 796: Amazon Sidewalk - Google Play Core Library, iOS Zero-Click Radio Proximity Exploit, Apple M1 Chip</media:title>
				<media:description type="plain">Google Play Core Library, iOS Zero-Click Radio Proximity Exploit, Apple M1 Chip</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, Amazon Sidewalk, sidewalk security, sidewalk privacy, ransomware foxconn, ransomware egregor, ransomware k12, iphone wormable hack, iphone zero-click hack, ios wormable hack, ios radio hack, odoh</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/822682/hero/sn_0796.jpg?itok=QJVGfvsD" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 795: DNS Consolidation - Generic Smart Doorbells, Tesla Model X Key Fobs, Critical Drupal Flaw, Spotify</title>
			<itunes:title>DNS Consolidation - Generic Smart Doorbells, Tesla Model X Key Fobs, Critical Drupal Flaw, Spotify</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 01 Dec 2020 19:00:00 PST</pubDate>
			<itunes:episode>795</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/795</link>
			<comments>https://twit.tv/shows/security-now/episodes/795</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Generic Smart Doorbells, Tesla Model X Key Fobs, Critical Drupal Flaw, Spotify</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, ransomware, Canon, us fertility, banijay, drupal core, php code execution, tesla, tesla fob hack, tesla x hack, smart doorbells, hack doorbells, chrome open tab search, chrome omnibox, fortinet VPN leak</itunes:keywords>
			<description><![CDATA[
<p>Generic smart doorbells, Tesla Model X key fobs, critical Drupal flaw, Spotify. </p>
<ul><li>Chrome Omnibox becomes more Omni.</li>
<li>Chrome's open tabs search.</li>
<li>Ransomware news involving Delaware County, Canon, US Fertility, Ritzau, Baltimore County Public Schools, and Banijay group SAS.</li>
<li>Drupal's security advisory titled "Drupal core - Critical - Arbitrary PHP code execution."</li>
<li>The revenge of cheap smart doorbells.</li>
<li>Tesla Key Fob Hack #3.</li>
<li>CA's adapt to single-year certs.</li>
<li>Nearly 50,000 Fortinet VPN credentials posted online.</li>
<li>More than 300,000 Spotify accounts hacked.</li>
<li>MobileIron MDM CVSS 9.8 RCE.</li>
<li>The Salvation Trilogy.</li>
<li>Spinrite update.</li>
<li>DNS Consolidation.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-795-Notes.pdf">https://www.grc.com/sn/SN-795-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://LastPass.com/twit">LastPass.com/twit</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Generic smart doorbells, Tesla Model X key fobs, critical Drupal flaw, Spotify. </p>
<ul><li>Chrome Omnibox becomes more Omni.</li>
<li>Chrome's open tabs search.</li>
<li>Ransomware news involving Delaware County, Canon, US Fertility, Ritzau, Baltimore County Public Schools, and Banijay group SAS.</li>
<li>Drupal's security advisory titled "Drupal core - Critical - Arbitrary PHP code execution."</li>
<li>The revenge of cheap smart doorbells.</li>
<li>Tesla Key Fob Hack #3.</li>
<li>CA's adapt to single-year certs.</li>
<li>Nearly 50,000 Fortinet VPN credentials posted online.</li>
<li>More than 300,000 Spotify accounts hacked.</li>
<li>MobileIron MDM CVSS 9.8 RCE.</li>
<li>The Salvation Trilogy.</li>
<li>Spinrite update.</li>
<li>DNS Consolidation.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-795-Notes.pdf">https://www.grc.com/sn/SN-795-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://LastPass.com/twit">LastPass.com/twit</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Generic smart doorbells, Tesla Model X key fobs, critical Drupal flaw, Spotify. </p>
<ul><li>Chrome Omnibox becomes more Omni.</li>
<li>Chrome's open tabs search.</li>
<li>Ransomware news involving Delaware County, Canon, US Fertility, Ritzau, Baltimore County Public Schools, and Banijay group SAS.</li>
<li>Drupal's security advisory titled "Drupal core - Critical - Arbitrary PHP code execution."</li>
<li>The revenge of cheap smart doorbells.</li>
<li>Tesla Key Fob Hack #3.</li>
<li>CA's adapt to single-year certs.</li>
<li>Nearly 50,000 Fortinet VPN credentials posted online.</li>
<li>More than 300,000 Spotify accounts hacked.</li>
<li>MobileIron MDM CVSS 9.8 RCE.</li>
<li>The Salvation Trilogy.</li>
<li>Spinrite update.</li>
<li>DNS Consolidation.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-795-Notes.pdf">https://www.grc.com/sn/SN-795-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://LastPass.com/twit">LastPass.com/twit</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/822503/hero/sn_0795.jpg?itok=h-lpchld"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0795/sn0795.mp3</guid>
			<itunes:duration>2:03:46</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0795/sn0795.mp3" length="59524076" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0795/sn0795.mp3" fileSize="59524076" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 795: DNS Consolidation - Generic Smart Doorbells, Tesla Model X Key Fobs, Critical Drupal Flaw, Spotify</media:title>
				<media:description type="plain">Generic Smart Doorbells, Tesla Model X Key Fobs, Critical Drupal Flaw, Spotify</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, ransomware, Canon, us fertility, banijay, drupal core, php code execution, tesla, tesla fob hack, tesla x hack, smart doorbells, hack doorbells, chrome open tab search, chrome omnibox, fortinet VPN leak</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/822503/hero/sn_0795.jpg?itok=YnUvlUh9" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 794: Cicada - Ongoing WordPress Attack, RCS Gets End-to-End Encryption</title>
			<itunes:title>Cicada - Ongoing WordPress Attack, RCS Gets End-to-End Encryption</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 24 Nov 2020 17:30:00 PST</pubDate>
			<itunes:episode>794</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/794</link>
			<comments>https://twit.tv/shows/security-now/episodes/794</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Ongoing WordPress Attack, RCS Gets End-to-End Encryption</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, cicada china, cicada cyber espionage, rcs e2e, rcs encryption, rcs signal, bluekeep rdp, bluekeep bug, wordpress epsilon hack, wordpress hack, wordpress security, wordpress theme vulnerability</itunes:keywords>
			<description><![CDATA[
<p>Ongoing WordPress attack, RCS gets End-to-end encryption. </p>
<ul><li>Chrome moves to release 87.</li>
<li>Explicit Publication of Privacy Practices.</li>
<li>Firefox 83 gets HTTPS-only Mode.</li>
<li>Mozilla seeks consultation on implementing DNS-over-HTTPS.</li>
<li>The comical announcement strategy of the Egregor Ransomware.</li>
<li>Large-scale attacks targeting Epsilon Framework Themes in WordPress.</li>
<li>Cybercrime gang installs hidden e-commerce stores on WordPress sites.</li>
<li>245,000 Windows systems still vulnerable to BlueKeep RDP bug.</li>
<li>Google's Rich Communication Services is getting E2EE via Signal.</li>
<li>Cicada, a Chinese state-sponsored advanced persistent threat group.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-794-Notes.pdf">https://www.grc.com/sn/SN-794-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/jason-howell">Jason Howell</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://manscaped.com/twit">manscaped.com/twit</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Ongoing WordPress attack, RCS gets End-to-end encryption. </p>
<ul><li>Chrome moves to release 87.</li>
<li>Explicit Publication of Privacy Practices.</li>
<li>Firefox 83 gets HTTPS-only Mode.</li>
<li>Mozilla seeks consultation on implementing DNS-over-HTTPS.</li>
<li>The comical announcement strategy of the Egregor Ransomware.</li>
<li>Large-scale attacks targeting Epsilon Framework Themes in WordPress.</li>
<li>Cybercrime gang installs hidden e-commerce stores on WordPress sites.</li>
<li>245,000 Windows systems still vulnerable to BlueKeep RDP bug.</li>
<li>Google's Rich Communication Services is getting E2EE via Signal.</li>
<li>Cicada, a Chinese state-sponsored advanced persistent threat group.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-794-Notes.pdf">https://www.grc.com/sn/SN-794-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/jason-howell">Jason Howell</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://manscaped.com/twit">manscaped.com/twit</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Ongoing WordPress attack, RCS gets End-to-end encryption. </p>
<ul><li>Chrome moves to release 87.</li>
<li>Explicit Publication of Privacy Practices.</li>
<li>Firefox 83 gets HTTPS-only Mode.</li>
<li>Mozilla seeks consultation on implementing DNS-over-HTTPS.</li>
<li>The comical announcement strategy of the Egregor Ransomware.</li>
<li>Large-scale attacks targeting Epsilon Framework Themes in WordPress.</li>
<li>Cybercrime gang installs hidden e-commerce stores on WordPress sites.</li>
<li>245,000 Windows systems still vulnerable to BlueKeep RDP bug.</li>
<li>Google's Rich Communication Services is getting E2EE via Signal.</li>
<li>Cicada, a Chinese state-sponsored advanced persistent threat group.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-794-Notes.pdf">https://www.grc.com/sn/SN-794-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/jason-howell">Jason Howell</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://manscaped.com/twit">manscaped.com/twit</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/822346/hero/sn_0794.jpg?itok=IQzgSumz"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0794/sn0794.mp3</guid>
			<itunes:duration>1:44:03</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0794/sn0794.mp3" length="50064615" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0794/sn0794.mp3" fileSize="50064615" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 794: Cicada - Ongoing WordPress Attack, RCS Gets End-to-End Encryption</media:title>
				<media:description type="plain">Ongoing WordPress Attack, RCS Gets End-to-End Encryption</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, cicada china, cicada cyber espionage, rcs e2e, rcs encryption, rcs signal, bluekeep rdp, bluekeep bug, wordpress epsilon hack, wordpress hack, wordpress security, wordpress theme vulnerability</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/822346/hero/sn_0794.jpg?itok=wj1er_oT" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Jason Howell</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 793: SAD DNS - Malicious Android Apps, Ransomware-as-a-Service</title>
			<itunes:title>SAD DNS - Malicious Android Apps, Ransomware-as-a-Service</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 17 Nov 2020 19:29:25 PST</pubDate>
			<itunes:episode>793</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/793</link>
			<comments>https://twit.tv/shows/security-now/episodes/793</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Malicious Android Apps, Ransomware-as-a-Service</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, android malware, malicious apps, malicious android apps, ransomware as a service, ragnar locker, ryuk, chrome 0-days, patch tuesday, sad dns</itunes:keywords>
			<description><![CDATA[
<p>Malicious Android apps, ransomware-as-a-service. </p>
<ul><li>Where do most malicious Android apps come from?</li>
<li>SAD DNS is a revival of the classic DNS cache poisoning attack</li>
<li>How many Ransomware-as-a-Service (RaaS) operations are there?</li>
<li>Ragnar Locker ransomware gang takes out a Facebook ad</li>
<li>Two more new 0-days revealed in Chrome</li>
<li>Last Tuesday, Microsoft fixed 112 known vulnerabilities in Microsoft products</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-793-Notes.pdf">https://www.grc.com/sn/SN-793-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Malicious Android apps, ransomware-as-a-service. </p>
<ul><li>Where do most malicious Android apps come from?</li>
<li>SAD DNS is a revival of the classic DNS cache poisoning attack</li>
<li>How many Ransomware-as-a-Service (RaaS) operations are there?</li>
<li>Ragnar Locker ransomware gang takes out a Facebook ad</li>
<li>Two more new 0-days revealed in Chrome</li>
<li>Last Tuesday, Microsoft fixed 112 known vulnerabilities in Microsoft products</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-793-Notes.pdf">https://www.grc.com/sn/SN-793-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Malicious Android apps, ransomware-as-a-service. </p>
<ul><li>Where do most malicious Android apps come from?</li>
<li>SAD DNS is a revival of the classic DNS cache poisoning attack</li>
<li>How many Ransomware-as-a-Service (RaaS) operations are there?</li>
<li>Ragnar Locker ransomware gang takes out a Facebook ad</li>
<li>Two more new 0-days revealed in Chrome</li>
<li>Last Tuesday, Microsoft fixed 112 known vulnerabilities in Microsoft products</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-793-Notes.pdf">https://www.grc.com/sn/SN-793-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/822182/hero/sn_0793.jpg?itok=MjOsAQPz"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0793/sn0793.mp3</guid>
			<itunes:duration>1:59:10</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0793/sn0793.mp3" length="57320386" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0793/sn0793.mp3" fileSize="57320386" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 793: SAD DNS - Malicious Android Apps, Ransomware-as-a-Service</media:title>
				<media:description type="plain">Malicious Android Apps, Ransomware-as-a-Service</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, android malware, malicious apps, malicious android apps, ransomware as a service, ragnar locker, ryuk, chrome 0-days, patch tuesday, sad dns</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/822182/hero/sn_0793.jpg?itok=je2cGsID" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
	</channel>
</rss>
