<?xml version="1.0" encoding="utf-8" ?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/" version="2.0">
	<channel>
		<title>Security Now (Audio)</title>
		<link>https://twit.tv/shows/security-now</link>
		<generator>TWiT Feed Generator v3.10.4</generator>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		<language>en-US</language>
		<copyright>This work is licensed under a Creative Commons License - Attribution-NonCommercial-NoDerivatives 4.0 International - http://creativecommons.org/licenses/by-nc-nd/4.0/</copyright>
		<creativeCommons:license>http://creativecommons.org/licenses/by-nc-nd/4.0/</creativeCommons:license>
		<managingEditor>distro@twit.tv (TWiT Editors)</managingEditor>
		<webMaster>distro@twit.tv (TWiT Engineering)</webMaster>
		<ttl>720</ttl>
		<sy:updatePeriod>weekly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
		<lastBuildDate>Tue, 09 Mar 2021 19:55:02 PST</lastBuildDate>
		<pubDate>Tue, 09 Mar 2021 19:55:02 PST</pubDate>
		<rawvoice:frequency>weekly</rawvoice:frequency>
		<rawvoice:location>Petaluma, CA</rawvoice:location>
		<itunes:type>episodic</itunes:type>
		<itunes:author>TWiT</itunes:author>
		<itunes:subtitle>Steve Gibson discusses the hot topics in security today with Leo Laporte.</itunes:subtitle>
		<itunes:summary>Steve Gibson, the man who coined the term spyware and created the first anti-spyware program, creator of Spinrite and ShieldsUP, discusses the hot topics in security today with Leo Laporte.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 21:30 UTC.</itunes:summary>
		<description>Steve Gibson, the man who coined the term spyware and created the first anti-spyware program, creator of Spinrite and ShieldsUP, discusses the hot topics in security today with Leo Laporte.

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 21:30 UTC.</description>
		<itunes:keywords>TWiT, Technology, Steve Gibson, Leo Laporte, security, spyware, malware, hacking, cyber crime, emcryption</itunes:keywords>
		<rawvoice:rating tv="tv-g">tv-g</rawvoice:rating>
		<itunes:explicit>false</itunes:explicit>
		<itunes:block>no</itunes:block>
		<itunes:owner>
			<itunes:name>Leo Laporte</itunes:name>
			<itunes:email>distro@twit.tv</itunes:email>
		</itunes:owner>
		<itunes:category text="News">
			<itunes:category text="Tech News"/>
</itunes:category>
		<itunes:category text="Technology" />
		<image>
			<title>Security Now (Audio)</title>
			<url>https://elroy.twit.tv/sites/default/files/styles/twit_album_art_144x144/public/images/shows/security_now/album_art/audio/sn_albumart_mask.jpg?itok=VEh3JGKV</url>
			<link>https://twit.tv/shows/security-now</link>
			<width>144</width>
			<height>144</height>
		</image>
		<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_album_art_2048x2048/public/images/shows/security_now/album_art/audio/sn_albumart_mask.jpg?itok=scC8c-TL" />
		<itunes:new-feed-url>https://feeds.twit.tv/sn.xml</itunes:new-feed-url>
		<rawvoice:subscribe feed="https://feeds.twit.tv/sn.xml" itunes="https://podcasts.apple.com/us/podcast/security-now-mp3/id79016499?uo=10" html="https://twit.tv/shows/security-now"></rawvoice:subscribe>
		<atom:link href="https://feeds.twit.tv/sn.xml" type="application/rss+xml" rel="self"/>
		<item>
			<title>SN 809: Hafnium - Dependency Confusion, Intel Side Channel Attacks, Crispy Subtitles From Lay's</title>
			<itunes:title>Hafnium - Dependency Confusion, Intel Side Channel Attacks, Crispy Subtitles From Lay's</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 09 Mar 2021 17:30:00 PST</pubDate>
			<itunes:episode>809</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/809</link>
			<comments>https://twit.tv/shows/security-now/episodes/809</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Dependency Confusion, Intel Side Channel Attacks, Crispy Subtitles From Lay's</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, intel, side channel attack, on-chip ring, WinAmp, llamas ass, winamp update, google linux, google open source, crispy subtitles lay's, lay's extension, potato chip software, chrome 89, chrome update</itunes:keywords>
			<description><![CDATA[
<p>Dependency confusion, Intel Side Channel Attacks, Crispy Subtitles from Lay's. </p>
<ul><li>Picture of the week.</li>
<li>47 fixes in Chrome 89.0.4389.72.</li>
<li>Crispy Subtitles from Lay's.</li>
<li>Google funds Linux kernel security developers.</li>
<li>WinAmp gets a huge update!</li>
<li>"Intel Side Channel Attacks on the CPU On-Chip Ring Interconnect Are Practical"</li>
<li>Dependency Confusion!</li>
<li>Listener feedback.</li>
<li>Hafnium.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-809-Notes.pdf">https://www.grc.com/sn/SN-809-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://thehelm.com/securitynow">thehelm.com/securitynow </a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Dependency confusion, Intel Side Channel Attacks, Crispy Subtitles from Lay's. </p>
<ul><li>Picture of the week.</li>
<li>47 fixes in Chrome 89.0.4389.72.</li>
<li>Crispy Subtitles from Lay's.</li>
<li>Google funds Linux kernel security developers.</li>
<li>WinAmp gets a huge update!</li>
<li>"Intel Side Channel Attacks on the CPU On-Chip Ring Interconnect Are Practical"</li>
<li>Dependency Confusion!</li>
<li>Listener feedback.</li>
<li>Hafnium.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-809-Notes.pdf">https://www.grc.com/sn/SN-809-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://thehelm.com/securitynow">thehelm.com/securitynow </a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Dependency confusion, Intel Side Channel Attacks, Crispy Subtitles from Lay's. </p>
<ul><li>Picture of the week.</li>
<li>47 fixes in Chrome 89.0.4389.72.</li>
<li>Crispy Subtitles from Lay's.</li>
<li>Google funds Linux kernel security developers.</li>
<li>WinAmp gets a huge update!</li>
<li>"Intel Side Channel Attacks on the CPU On-Chip Ring Interconnect Are Practical"</li>
<li>Dependency Confusion!</li>
<li>Listener feedback.</li>
<li>Hafnium.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-809-Notes.pdf">https://www.grc.com/sn/SN-809-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://thehelm.com/securitynow">thehelm.com/securitynow </a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/824628/hero/sn_0809.jpg?itok=g-H2Uz8C"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0809/sn0809.mp3</guid>
			<itunes:duration>1:52:41</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0809/sn0809.mp3" length="54215577" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0809/sn0809.mp3" fileSize="54215577" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 809: Hafnium - Dependency Confusion, Intel Side Channel Attacks, Crispy Subtitles From Lay's</media:title>
				<media:description type="plain">Dependency Confusion, Intel Side Channel Attacks, Crispy Subtitles From Lay's</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, intel, side channel attack, on-chip ring, WinAmp, llamas ass, winamp update, google linux, google open source, crispy subtitles lay's, lay's extension, potato chip software, chrome 89, chrome update</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/824628/hero/sn_0809.jpg?itok=lnWZBqd4" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 808: CNAME Collusion - Seven Exchange 0-Days, Firefox Enhanced Tracking Protection, SolarWinds Password</title>
			<itunes:title>CNAME Collusion - Seven Exchange 0-Days, Firefox Enhanced Tracking Protection, SolarWinds Password</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 02 Mar 2021 17:00:00 PST</pubDate>
			<itunes:episode>808</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/808</link>
			<comments>https://twit.tv/shows/security-now/episodes/808</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Seven Exchange 0-Days, Firefox Enhanced Tracking Protection, SolarWinds Password</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, HTTPS, firefox cookies, cookies privacy, enhanced tracking protection, tracking cookies, tracking firefox, solarwinds password, bad password, solarwinds123, rockwell automation, cve-2021-22681</itunes:keywords>
			<description><![CDATA[
<p>Seven Exchange 0-days, Firefox Enhanced Tracking Protection, SolarWinds Password. </p>
<ul><li>Chrome to default to trying HTTPS first when not specified.</li>
<li>Firefox's "Enhanced Tracking Protection" just neutered 3rd-party cookies!</li>
<li>As easy as "SolarWinds123".</li>
<li>Rockwell Automation's CVE-2021-22681 is a CRITICAL 10 out of 10.</li>
<li>VMware's vCenter troubles.</li>
<li>SpinRite update.</li>
<li>Microsoft issues emergency patches for 4 exploited 0-days in Exchange.</li>
<li>CNAME Collusion.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-808-Notes.pdf">https://www.grc.com/sn/SN-808-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://privacy.com/securitynow">privacy.com/securitynow</a></li>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Seven Exchange 0-days, Firefox Enhanced Tracking Protection, SolarWinds Password. </p>
<ul><li>Chrome to default to trying HTTPS first when not specified.</li>
<li>Firefox's "Enhanced Tracking Protection" just neutered 3rd-party cookies!</li>
<li>As easy as "SolarWinds123".</li>
<li>Rockwell Automation's CVE-2021-22681 is a CRITICAL 10 out of 10.</li>
<li>VMware's vCenter troubles.</li>
<li>SpinRite update.</li>
<li>Microsoft issues emergency patches for 4 exploited 0-days in Exchange.</li>
<li>CNAME Collusion.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-808-Notes.pdf">https://www.grc.com/sn/SN-808-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://privacy.com/securitynow">privacy.com/securitynow</a></li>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Seven Exchange 0-days, Firefox Enhanced Tracking Protection, SolarWinds Password. </p>
<ul><li>Chrome to default to trying HTTPS first when not specified.</li>
<li>Firefox's "Enhanced Tracking Protection" just neutered 3rd-party cookies!</li>
<li>As easy as "SolarWinds123".</li>
<li>Rockwell Automation's CVE-2021-22681 is a CRITICAL 10 out of 10.</li>
<li>VMware's vCenter troubles.</li>
<li>SpinRite update.</li>
<li>Microsoft issues emergency patches for 4 exploited 0-days in Exchange.</li>
<li>CNAME Collusion.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-808-Notes.pdf">https://www.grc.com/sn/SN-808-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://privacy.com/securitynow">privacy.com/securitynow</a></li>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/824490/hero/sn_0808.jpg?itok=JxakvMhU"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0808/sn0808.mp3</guid>
			<itunes:duration>2:06:08</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0808/sn0808.mp3" length="60661343" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0808/sn0808.mp3" fileSize="60661343" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 808: CNAME Collusion - Seven Exchange 0-Days, Firefox Enhanced Tracking Protection, SolarWinds Password</media:title>
				<media:description type="plain">Seven Exchange 0-Days, Firefox Enhanced Tracking Protection, SolarWinds Password</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, HTTPS, firefox cookies, cookies privacy, enhanced tracking protection, tracking cookies, tracking firefox, solarwinds password, bad password, solarwinds123, rockwell automation, cve-2021-22681</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/824490/hero/sn_0808.jpg?itok=1XRj6CII" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 807: Dependency Confusion - SHAREit's Security Update, Solorigate, Brave's "Private Window With Tor"</title>
			<itunes:title>Dependency Confusion - SHAREit's Security Update, Solorigate, Brave's "Private Window With Tor"</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 23 Feb 2021 15:30:00 PST</pubDate>
			<itunes:episode>807</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/807</link>
			<comments>https://twit.tv/shows/security-now/episodes/807</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>SHAREit's Security Update, Solorigate, Brave's "Private Window With Tor"</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, shareit vulnerability, shareit android, web browser tracking, browser tracking, email beacons, microsoft vulnerability, microsoft hack, SpinRite, Brave Browser, ssd spirit, solarwinds solorigate, solarwinds, </itunes:keywords>
			<description><![CDATA[
<p>SHAREit's security update, Solorigate, Brave's "Private Window with Tor". </p>
<ul><li>SHAREit Follow-up</li>
<li>This Week in Web Browser Tracking</li>
<li>Brave's "Private Window with Tor" was not so private</li>
<li>Tracking with eMail Beacons</li>
<li>Microsoft's final "Solorigate" update</li>
<li>"Good App goes Bad for Profit"</li>
<li>SpinRite: RS shows VERY obvious improvement after one pass of SR 6</li>
<li>Dependency Confusion</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-807-Notes.pdf">https://www.grc.com/sn/SN-807-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>SHAREit's security update, Solorigate, Brave's "Private Window with Tor". </p>
<ul><li>SHAREit Follow-up</li>
<li>This Week in Web Browser Tracking</li>
<li>Brave's "Private Window with Tor" was not so private</li>
<li>Tracking with eMail Beacons</li>
<li>Microsoft's final "Solorigate" update</li>
<li>"Good App goes Bad for Profit"</li>
<li>SpinRite: RS shows VERY obvious improvement after one pass of SR 6</li>
<li>Dependency Confusion</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-807-Notes.pdf">https://www.grc.com/sn/SN-807-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>SHAREit's security update, Solorigate, Brave's "Private Window with Tor". </p>
<ul><li>SHAREit Follow-up</li>
<li>This Week in Web Browser Tracking</li>
<li>Brave's "Private Window with Tor" was not so private</li>
<li>Tracking with eMail Beacons</li>
<li>Microsoft's final "Solorigate" update</li>
<li>"Good App goes Bad for Profit"</li>
<li>SpinRite: RS shows VERY obvious improvement after one pass of SR 6</li>
<li>Dependency Confusion</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-807-Notes.pdf">https://www.grc.com/sn/SN-807-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://Melissa.com/twit">Melissa.com/twit</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/824348/hero/sn_0807.jpg?itok=PfTteXh5"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0807/sn0807.mp3</guid>
			<itunes:duration>2:02:10</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0807/sn0807.mp3" length="58759211" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0807/sn0807.mp3" fileSize="58759211" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 807: Dependency Confusion - SHAREit's Security Update, Solorigate, Brave's "Private Window With Tor"</media:title>
				<media:description type="plain">SHAREit's Security Update, Solorigate, Brave's "Private Window With Tor"</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, shareit vulnerability, shareit android, web browser tracking, browser tracking, email beacons, microsoft vulnerability, microsoft hack, SpinRite, Brave Browser, ssd spirit, solarwinds solorigate, solarwinds, </media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/824348/hero/sn_0807.jpg?itok=1rN2Pn8a" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 806: C.O.M.B. - Florida Water Supply Hack Update, Major Patch Tuesday, Android SHAREit Vulnerability</title>
			<itunes:title>C.O.M.B. - Florida Water Supply Hack Update, Major Patch Tuesday, Android SHAREit Vulnerability</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 16 Feb 2021 17:30:00 PST</pubDate>
			<itunes:episode>806</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/806</link>
			<comments>https://twit.tv/shows/security-now/episodes/806</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Florida Water Supply Hack Update, Major Patch Tuesday, Android SHAREit Vulnerability</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, oldsmar florida, water supply hack, florida water hack, patch tuesday, microsoft patch, microsoft tuesday, adobe critical, Adobe update, adobe vulnerability, android shareit, shareit vulnerability, shareit</itunes:keywords>
			<description><![CDATA[
<p>Florida water supply hack update, Major patch Tuesday, Android SHAREit vulnerability. </p>
<ul><li>Pic of the week.</li>
<li>New info in the Oldsmar, Florida water supply attack.</li>
<li>Major Patch Tuesday update.</li>
<li>Adobe released critical updates to three versions each of its Acrobat and Reader.</li>
<li>Android SHAREit.</li>
<li>The Rise of The Web Shells.</li>
<li>This week's WordPress Mess: Responsive Menu plugin.</li>
<li>SpinRite drive discovery video.</li>
<li>What is C.O.M.B.?</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-806-Notes.pdf">https://www.grc.com/sn/SN-806-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Florida water supply hack update, Major patch Tuesday, Android SHAREit vulnerability. </p>
<ul><li>Pic of the week.</li>
<li>New info in the Oldsmar, Florida water supply attack.</li>
<li>Major Patch Tuesday update.</li>
<li>Adobe released critical updates to three versions each of its Acrobat and Reader.</li>
<li>Android SHAREit.</li>
<li>The Rise of The Web Shells.</li>
<li>This week's WordPress Mess: Responsive Menu plugin.</li>
<li>SpinRite drive discovery video.</li>
<li>What is C.O.M.B.?</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-806-Notes.pdf">https://www.grc.com/sn/SN-806-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Florida water supply hack update, Major patch Tuesday, Android SHAREit vulnerability. </p>
<ul><li>Pic of the week.</li>
<li>New info in the Oldsmar, Florida water supply attack.</li>
<li>Major Patch Tuesday update.</li>
<li>Adobe released critical updates to three versions each of its Acrobat and Reader.</li>
<li>Android SHAREit.</li>
<li>The Rise of The Web Shells.</li>
<li>This week's WordPress Mess: Responsive Menu plugin.</li>
<li>SpinRite drive discovery video.</li>
<li>What is C.O.M.B.?</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-806-Notes.pdf">https://www.grc.com/sn/SN-806-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/824207/hero/sn_0806.jpg?itok=fR06uxsK"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0806/sn0806.mp3</guid>
			<itunes:duration>2:01:23</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0806/sn0806.mp3" length="58383257" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0806/sn0806.mp3" fileSize="58383257" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 806: C.O.M.B. - Florida Water Supply Hack Update, Major Patch Tuesday, Android SHAREit Vulnerability</media:title>
				<media:description type="plain">Florida Water Supply Hack Update, Major Patch Tuesday, Android SHAREit Vulnerability</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, oldsmar florida, water supply hack, florida water hack, patch tuesday, microsoft patch, microsoft tuesday, adobe critical, Adobe update, adobe vulnerability, android shareit, shareit vulnerability, shareit</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/824207/hero/sn_0806.jpg?itok=AHQdDShR" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 805: SCADA Scandal - Defender Thinks Chrome is Malware, Plex Media Servers in DDoS Attacks</title>
			<itunes:title>SCADA Scandal - Defender Thinks Chrome is Malware, Plex Media Servers in DDoS Attacks</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 09 Feb 2021 17:30:00 PST</pubDate>
			<itunes:episode>805</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/805</link>
			<comments>https://twit.tv/shows/security-now/episodes/805</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Defender Thinks Chrome is Malware, Plex Media Servers in DDoS Attacks</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, chrome patch, chrome security, chrome heap buffer overflow, chrome vulnerability, chrome sync, command and control, data exfiltration, Microsoft, defender, defender chrome, defender malware</itunes:keywords>
			<description><![CDATA[
<p>Defender thinks Chrome is malware, Plex Media Servers in DDoS attacks. </p>
<ul><li>Picture of the Week.</li>
<li>Google has been busy with Chrome.</li>
<li>Google Chrome Heap Buffer Overflow Vulnerability Exploited.</li>
<li>A unique use of Chrome's "sync" feature for command &amp; control and data exfiltration.</li>
<li>Defender thinks Chrome is Malware.</li>
<li>More Critical WordPress Plug-in Problems.</li>
<li>Plex Media servers SSDP protocol being used in DDoS attacks.</li>
<li>Three more NEW vulnerabilities discovered in SolarWinds' software.</li>
<li>Closing the Loop.</li>
<li>SpinRite: "Discovering System's Mass Storage Devices..."</li>
<li>SCADA Scandal: Hacker's attempts to adjust chemicals in Oldsmar water supply.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-805-Notes.pdf">https://www.grc.com/sn/SN-805-Notes.pdf</a> <br />
 </p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://udacity.com/twit">udacity.com/twit coupon code TWiT</a></li>
<li><a href="http://Gabi.com/SECURITYNOW">Gabi.com/SECURITYNOW</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Defender thinks Chrome is malware, Plex Media Servers in DDoS attacks. </p>
<ul><li>Picture of the Week.</li>
<li>Google has been busy with Chrome.</li>
<li>Google Chrome Heap Buffer Overflow Vulnerability Exploited.</li>
<li>A unique use of Chrome's "sync" feature for command &amp; control and data exfiltration.</li>
<li>Defender thinks Chrome is Malware.</li>
<li>More Critical WordPress Plug-in Problems.</li>
<li>Plex Media servers SSDP protocol being used in DDoS attacks.</li>
<li>Three more NEW vulnerabilities discovered in SolarWinds' software.</li>
<li>Closing the Loop.</li>
<li>SpinRite: "Discovering System's Mass Storage Devices..."</li>
<li>SCADA Scandal: Hacker's attempts to adjust chemicals in Oldsmar water supply.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-805-Notes.pdf">https://www.grc.com/sn/SN-805-Notes.pdf</a> <br />
 </p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://udacity.com/twit">udacity.com/twit coupon code TWiT</a></li>
<li><a href="http://Gabi.com/SECURITYNOW">Gabi.com/SECURITYNOW</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Defender thinks Chrome is malware, Plex Media Servers in DDoS attacks. </p>
<ul><li>Picture of the Week.</li>
<li>Google has been busy with Chrome.</li>
<li>Google Chrome Heap Buffer Overflow Vulnerability Exploited.</li>
<li>A unique use of Chrome's "sync" feature for command &amp; control and data exfiltration.</li>
<li>Defender thinks Chrome is Malware.</li>
<li>More Critical WordPress Plug-in Problems.</li>
<li>Plex Media servers SSDP protocol being used in DDoS attacks.</li>
<li>Three more NEW vulnerabilities discovered in SolarWinds' software.</li>
<li>Closing the Loop.</li>
<li>SpinRite: "Discovering System's Mass Storage Devices..."</li>
<li>SCADA Scandal: Hacker's attempts to adjust chemicals in Oldsmar water supply.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-805-Notes.pdf">https://www.grc.com/sn/SN-805-Notes.pdf</a> <br />
 </p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://udacity.com/twit">udacity.com/twit coupon code TWiT</a></li>
<li><a href="http://Gabi.com/SECURITYNOW">Gabi.com/SECURITYNOW</a></li>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/824067/hero/sn_0805.jpg?itok=tESBdALK"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0805/sn0805.mp3</guid>
			<itunes:duration>2:23:08</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0805/sn0805.mp3" length="68821996" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0805/sn0805.mp3" fileSize="68821996" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 805: SCADA Scandal - Defender Thinks Chrome is Malware, Plex Media Servers in DDoS Attacks</media:title>
				<media:description type="plain">Defender Thinks Chrome is Malware, Plex Media Servers in DDoS Attacks</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, chrome patch, chrome security, chrome heap buffer overflow, chrome vulnerability, chrome sync, command and control, data exfiltration, Microsoft, defender, defender chrome, defender malware</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/824067/hero/sn_0805.jpg?itok=nLDdJ6yl" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 804: NAT Slipstreaming 2.0 - SUDO Was Pseudo Secure, BigNox Supply-Chain Attack, iMessage in a Sandbox</title>
			<itunes:title>NAT Slipstreaming 2.0 - SUDO Was Pseudo Secure, BigNox Supply-Chain Attack, iMessage in a Sandbox</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 02 Feb 2021 18:30:00 PST</pubDate>
			<itunes:episode>804</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/804</link>
			<comments>https://twit.tv/shows/security-now/episodes/804</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>SUDO Was Pseudo Secure, BigNox Supply-Chain Attack, iMessage in a Sandbox</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, ca root, root cert, bignox, Android, malware, bignox vulnerability, noxplayer malware, noxplayer android, ios 14 sandbox, apple ios 14, ios imessage security, SpinRite, NAT, GnuPG, Sudo, linux</itunes:keywords>
			<description><![CDATA[
<p>SUDO was pseudo secure, BigNox supply-chain attack, iMessage in a sandbox. </p>
<ul><li>Picture of the Week.</li>
<li>Chrome rescinding another CA's root cert.</li>
<li>An urgent update to the recently released GnuPG.</li>
<li>An interesting supply-chain attack "BigNox".</li>
<li>Apple quietly put iMessage in a sandbox in iOS 14.</li>
<li>For the past 10 years, "SUDO" was only pseudo secure.</li>
<li>SpinRite: February 1st Progress Report.</li>
<li>NAT Slipstreaming 2.0.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-804-Notes.pdf">https://www.grc.com/sn/SN-804-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>SUDO was pseudo secure, BigNox supply-chain attack, iMessage in a sandbox. </p>
<ul><li>Picture of the Week.</li>
<li>Chrome rescinding another CA's root cert.</li>
<li>An urgent update to the recently released GnuPG.</li>
<li>An interesting supply-chain attack "BigNox".</li>
<li>Apple quietly put iMessage in a sandbox in iOS 14.</li>
<li>For the past 10 years, "SUDO" was only pseudo secure.</li>
<li>SpinRite: February 1st Progress Report.</li>
<li>NAT Slipstreaming 2.0.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-804-Notes.pdf">https://www.grc.com/sn/SN-804-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>SUDO was pseudo secure, BigNox supply-chain attack, iMessage in a sandbox. </p>
<ul><li>Picture of the Week.</li>
<li>Chrome rescinding another CA's root cert.</li>
<li>An urgent update to the recently released GnuPG.</li>
<li>An interesting supply-chain attack "BigNox".</li>
<li>Apple quietly put iMessage in a sandbox in iOS 14.</li>
<li>For the past 10 years, "SUDO" was only pseudo secure.</li>
<li>SpinRite: February 1st Progress Report.</li>
<li>NAT Slipstreaming 2.0.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-804-Notes.pdf">https://www.grc.com/sn/SN-804-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
<li><a href="http://extrahop.com/SECURITYNOW">extrahop.com/SECURITYNOW</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823921/hero/sn_0804.jpg?itok=jOCdaxyq"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0804/sn0804.mp3</guid>
			<itunes:duration>2:11:32</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0804/sn0804.mp3" length="63257706" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0804/sn0804.mp3" fileSize="63257706" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 804: NAT Slipstreaming 2.0 - SUDO Was Pseudo Secure, BigNox Supply-Chain Attack, iMessage in a Sandbox</media:title>
				<media:description type="plain">SUDO Was Pseudo Secure, BigNox Supply-Chain Attack, iMessage in a Sandbox</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, ca root, root cert, bignox, Android, malware, bignox vulnerability, noxplayer malware, noxplayer android, ios 14 sandbox, apple ios 14, ios imessage security, SpinRite, NAT, GnuPG, Sudo, linux</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823921/hero/sn_0804.jpg?itok=NJD5Oelf" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 803: Comparative Smartphone Security - Browser Password Managers, Adobe Flash Repercussions, SolarWinds</title>
			<itunes:title>Comparative Smartphone Security - Browser Password Managers, Adobe Flash Repercussions, SolarWinds</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 26 Jan 2021 18:00:00 PST</pubDate>
			<itunes:episode>803</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/803</link>
			<comments>https://twit.tv/shows/security-now/episodes/803</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>Browser Password Managers, Adobe Flash Repercussions, SolarWinds</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, edge, chrome vs edge, chrome password manager, edge password manager, lastpass, adobe flash, flash dead, flash china railroad, flash south africa, solarwinds, solarwinds details, malwarebytes</itunes:keywords>
			<description><![CDATA[
<p>Browser password managers, Adobe Flash repercussions, SolarWinds. </p>
<ul><li>Chrome and Edge have beefed-up their built-in password managers.</li>
<li>The random repercussions associated with the end of Adobe Flash.</li>
<li>A new trend emerging with post-ransomware DDOS attacks.</li>
<li>SolarWinds attack details continue to emerge.</li>
<li>Malwarebytes was also attacked.</li>
<li>It seems that wherever we look, we find problems.</li>
<li>The Expanse is GOOD sci-fi.</li>
<li>Comparative Smartphone Security: Which mobile OS is better?</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-803-Notes.pdf">https://www.grc.com/sn/SN-803-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://udacity.com/twit">udacity.com/twit coupon code TWiT</a></li>
<li><a href="http://privacy.com/securitynow">privacy.com/securitynow</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>Browser password managers, Adobe Flash repercussions, SolarWinds. </p>
<ul><li>Chrome and Edge have beefed-up their built-in password managers.</li>
<li>The random repercussions associated with the end of Adobe Flash.</li>
<li>A new trend emerging with post-ransomware DDOS attacks.</li>
<li>SolarWinds attack details continue to emerge.</li>
<li>Malwarebytes was also attacked.</li>
<li>It seems that wherever we look, we find problems.</li>
<li>The Expanse is GOOD sci-fi.</li>
<li>Comparative Smartphone Security: Which mobile OS is better?</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-803-Notes.pdf">https://www.grc.com/sn/SN-803-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://udacity.com/twit">udacity.com/twit coupon code TWiT</a></li>
<li><a href="http://privacy.com/securitynow">privacy.com/securitynow</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>Browser password managers, Adobe Flash repercussions, SolarWinds. </p>
<ul><li>Chrome and Edge have beefed-up their built-in password managers.</li>
<li>The random repercussions associated with the end of Adobe Flash.</li>
<li>A new trend emerging with post-ransomware DDOS attacks.</li>
<li>SolarWinds attack details continue to emerge.</li>
<li>Malwarebytes was also attacked.</li>
<li>It seems that wherever we look, we find problems.</li>
<li>The Expanse is GOOD sci-fi.</li>
<li>Comparative Smartphone Security: Which mobile OS is better?</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-803-Notes.pdf">https://www.grc.com/sn/SN-803-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://udacity.com/twit">udacity.com/twit coupon code TWiT</a></li>
<li><a href="http://privacy.com/securitynow">privacy.com/securitynow</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823750/hero/sn_0803.jpg?itok=HOsMN_C3"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0803/sn0803.mp3</guid>
			<itunes:duration>2:11:20</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0803/sn0803.mp3" length="63160112" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0803/sn0803.mp3" fileSize="63160112" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 803: Comparative Smartphone Security - Browser Password Managers, Adobe Flash Repercussions, SolarWinds</media:title>
				<media:description type="plain">Browser Password Managers, Adobe Flash Repercussions, SolarWinds</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome, edge, chrome vs edge, chrome password manager, edge password manager, lastpass, adobe flash, flash dead, flash china railroad, flash south africa, solarwinds, solarwinds details, malwarebytes</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823750/hero/sn_0803.jpg?itok=JnfG9Bdm" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 802: Where the Plaintext Is - 2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</title>
			<itunes:title>Where the Plaintext Is - 2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 19 Jan 2021 17:30:00 PST</pubDate>
			<itunes:episode>802</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/802</link>
			<comments>https://twit.tv/shows/security-now/episodes/802</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, facebook whatsapp, plaintext security, encryption, at rest, in transit, e2ee, chrome, Chromium, duckduckgo, Google, project zero, google zero, patch tuesday microsoft, microsoft security, zerologon, nsa doh, </itunes:keywords>
			<description><![CDATA[
<p>2021's first Patch Tuesday, Titan Security Key side-channel attack, WhatsApp. </p>
<ul><li>When is Chrome not Chromium?</li>
<li>A major DuckDuckGo milestone.</li>
<li>Project Zero in the wild.</li>
<li>First Patch Tuesday of 2021.</li>
<li>ZeroLogon Drop Dead.</li>
<li>NSA warns against outsourcing DoH services.</li>
<li>A Side-Channel in Titan.</li>
<li>The "PayPal Football"</li>
<li>WhatsApp's decision to bring its data into Facebook.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-802-Notes.pdf">https://www.grc.com/sn/SN-802-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>2021's first Patch Tuesday, Titan Security Key side-channel attack, WhatsApp. </p>
<ul><li>When is Chrome not Chromium?</li>
<li>A major DuckDuckGo milestone.</li>
<li>Project Zero in the wild.</li>
<li>First Patch Tuesday of 2021.</li>
<li>ZeroLogon Drop Dead.</li>
<li>NSA warns against outsourcing DoH services.</li>
<li>A Side-Channel in Titan.</li>
<li>The "PayPal Football"</li>
<li>WhatsApp's decision to bring its data into Facebook.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-802-Notes.pdf">https://www.grc.com/sn/SN-802-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>2021's first Patch Tuesday, Titan Security Key side-channel attack, WhatsApp. </p>
<ul><li>When is Chrome not Chromium?</li>
<li>A major DuckDuckGo milestone.</li>
<li>Project Zero in the wild.</li>
<li>First Patch Tuesday of 2021.</li>
<li>ZeroLogon Drop Dead.</li>
<li>NSA warns against outsourcing DoH services.</li>
<li>A Side-Channel in Titan.</li>
<li>The "PayPal Football"</li>
<li>WhatsApp's decision to bring its data into Facebook.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-802-Notes.pdf">https://www.grc.com/sn/SN-802-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://business.eset.com/twit">business.eset.com/twit</a></li>
<li><a href="http://expressvpn.com/securitynow">expressvpn.com/securitynow</a></li>
<li><a href="http://canary.tools/twit">canary.tools/twit - use code: TWIT</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823537/hero/sn_0802.jpg?itok=vIJoKIRF"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0802/sn0802.mp3</guid>
			<itunes:duration>1:45:55</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0802/sn0802.mp3" length="50959257" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0802/sn0802.mp3" fileSize="50959257" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 802: Where the Plaintext Is - 2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</media:title>
				<media:description type="plain">2021's First Patch Tuesday, Titan Security Key Side-Channel Attack, WhatsApp</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, facebook whatsapp, plaintext security, encryption, at rest, in transit, e2ee, chrome, Chromium, duckduckgo, Google, project zero, google zero, patch tuesday microsoft, microsoft security, zerologon, nsa doh, </media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823537/hero/sn_0802.jpg?itok=kH-jMiHf" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 801: Out With The Old - SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</title>
			<itunes:title>Out With The Old - SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 12 Jan 2021 18:00:00 PST</pubDate>
			<itunes:episode>801</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/801</link>
			<comments>https://twit.tv/shows/security-now/episodes/801</comments>
			<itunes:author>TWiT</itunes:author>
			<category>Technology</category>
			<category>Security</category>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, firefox, Chromium, tenable, critical, firefox backspace, ryuk malware, ryuk crypto, intel marketing, intel ces, intel ransomware, male chastity cage, sex toy security, solarwinds sunburts, krebs stamos group,</itunes:keywords>
			<description><![CDATA[
<p>SolarWinds smoking gun, Signal influx of WhatsApp users, male chastity cage. </p>
<ul><li>Firefox and Chromium updates address remote system take over bugs.</li>
<li>Tenable researchers reported a critical Chromium bug.</li>
<li>What Firefox's backspace key does and should do.</li>
<li>How Ryuk malware operations netted $150 million via cryptocurrency exchange.</li>
<li>Intel: A triumph of marketing over technology.</li>
<li>The strange case of the Male Chastity Cage.</li>
<li>A SolarWinds smoking gun? "Sunburst backdoor."</li>
<li>A class action lawsuit filed by shareholders of SolarWinds stock.</li>
<li>The "Krebs Stamos Group"</li>
<li>Zyxel security endpoints under attack.</li>
<li>WhatsApp revises their privacy policy.</li>
<li>Signal sees a mass influx of WhatsApp users.</li>
<li>Out with the old: A look at the history of SpinRite code.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-801-Notes.pdf">https://www.grc.com/sn/SN-801-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>SolarWinds smoking gun, Signal influx of WhatsApp users, male chastity cage. </p>
<ul><li>Firefox and Chromium updates address remote system take over bugs.</li>
<li>Tenable researchers reported a critical Chromium bug.</li>
<li>What Firefox's backspace key does and should do.</li>
<li>How Ryuk malware operations netted $150 million via cryptocurrency exchange.</li>
<li>Intel: A triumph of marketing over technology.</li>
<li>The strange case of the Male Chastity Cage.</li>
<li>A SolarWinds smoking gun? "Sunburst backdoor."</li>
<li>A class action lawsuit filed by shareholders of SolarWinds stock.</li>
<li>The "Krebs Stamos Group"</li>
<li>Zyxel security endpoints under attack.</li>
<li>WhatsApp revises their privacy policy.</li>
<li>Signal sees a mass influx of WhatsApp users.</li>
<li>Out with the old: A look at the history of SpinRite code.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-801-Notes.pdf">https://www.grc.com/sn/SN-801-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>SolarWinds smoking gun, Signal influx of WhatsApp users, male chastity cage. </p>
<ul><li>Firefox and Chromium updates address remote system take over bugs.</li>
<li>Tenable researchers reported a critical Chromium bug.</li>
<li>What Firefox's backspace key does and should do.</li>
<li>How Ryuk malware operations netted $150 million via cryptocurrency exchange.</li>
<li>Intel: A triumph of marketing over technology.</li>
<li>The strange case of the Male Chastity Cage.</li>
<li>A SolarWinds smoking gun? "Sunburst backdoor."</li>
<li>A class action lawsuit filed by shareholders of SolarWinds stock.</li>
<li>The "Krebs Stamos Group"</li>
<li>Zyxel security endpoints under attack.</li>
<li>WhatsApp revises their privacy policy.</li>
<li>Signal sees a mass influx of WhatsApp users.</li>
<li>Out with the old: A look at the history of SpinRite code.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-801-Notes.pdf">https://www.grc.com/sn/SN-801-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsors:</strong><ul>
<li><a href="http://WWT.COM/TWIT">WWT.COM/TWIT</a></li>
<li><a href="http://barracuda.com/securitynow">barracuda.com/securitynow</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823390/hero/sn_0801.jpg?itok=-EFlbI4g"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0801/sn0801.mp3</guid>
			<itunes:duration>2:00:15</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0801/sn0801.mp3" length="57837402" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0801/sn0801.mp3" fileSize="57837402" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 801: Out With The Old - SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</media:title>
				<media:description type="plain">SolarWinds Smoking Gun, Signal Influx of WhatsApp Users, Male Chastity Cage</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, firefox, Chromium, tenable, critical, firefox backspace, ryuk malware, ryuk crypto, intel marketing, intel ces, intel ransomware, male chastity cage, sex toy security, solarwinds sunburts, krebs stamos group,</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823390/hero/sn_0801.jpg?itok=8QSlFMo7" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
		<item>
			<title>SN 800: SolarBlizzard - SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</title>
			<itunes:title>SolarBlizzard - SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</itunes:title>
			<itunes:episodeType>full</itunes:episodeType>
			<pubDate>Tue, 05 Jan 2021 18:00:00 PST</pubDate>
			<itunes:episode>800</itunes:episode>
			<link>https://twit.tv/shows/security-now/episodes/800</link>
			<comments>https://twit.tv/shows/security-now/episodes/800</comments>
			<itunes:author>TWiT</itunes:author>
			<itunes:explicit>clean</itunes:explicit>
			<itunes:subtitle>SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</itunes:subtitle>
			<itunes:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome antivirus, chrome prescan, av chrome, zyxel password, zyfwp / PrOw!aN_fXp, redundant password, swatter iot, swatting iot, internet of things swat, wordpress zend vulnerability</itunes:keywords>
			<description><![CDATA[
<p>SolarWinds' Orion software, swatting goes IoT, PHP Zend Framework vulnerability. </p>
<ul><li>Chrome struggles with A/V pre-scan file locking.</li>
<li>Zyxel security products protected by a single redundant password.</li>
<li>How Swatters are using IoT devices to increase the terror.</li>
<li>A new serious problem in the PHP Zend Framework on WordPress.</li>
<li>Bitcoin woes as value reaches new peaks.</li>
<li>ReadSpeed, SSD's, and SpinRite.</li>
<li>A new flaw discovered in SolarWinds' Orion software.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-800-Notes.pdf">https://www.grc.com/sn/SN-800-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsor:</strong><ul>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></description>
			<itunes:summary><![CDATA[
<p>SolarWinds' Orion software, swatting goes IoT, PHP Zend Framework vulnerability. </p>
<ul><li>Chrome struggles with A/V pre-scan file locking.</li>
<li>Zyxel security products protected by a single redundant password.</li>
<li>How Swatters are using IoT devices to increase the terror.</li>
<li>A new serious problem in the PHP Zend Framework on WordPress.</li>
<li>Bitcoin woes as value reaches new peaks.</li>
<li>ReadSpeed, SSD's, and SpinRite.</li>
<li>A new flaw discovered in SolarWinds' Orion software.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-800-Notes.pdf">https://www.grc.com/sn/SN-800-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsor:</strong><ul>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></itunes:summary>
			<content:encoded><![CDATA[
<p>SolarWinds' Orion software, swatting goes IoT, PHP Zend Framework vulnerability. </p>
<ul><li>Chrome struggles with A/V pre-scan file locking.</li>
<li>Zyxel security products protected by a single redundant password.</li>
<li>How Swatters are using IoT devices to increase the terror.</li>
<li>A new serious problem in the PHP Zend Framework on WordPress.</li>
<li>Bitcoin woes as value reaches new peaks.</li>
<li>ReadSpeed, SSD's, and SpinRite.</li>
<li>A new flaw discovered in SolarWinds' Orion software.</li>
</ul><p>We invite you to read our show notes at <a href="https://www.grc.com/sn/SN-800-Notes.pdf">https://www.grc.com/sn/SN-800-Notes.pdf</a></p> 
<p><strong>Hosts:</strong> <a href="https://twit.tv/people/steve-gibson">Steve Gibson</a> and <a href="https://twit.tv/people/leo-laporte">Leo Laporte</a> </p>
<p>Download or subscribe to this show at <a href="https://twit.tv/shows/security-now">https://twit.tv/shows/security-now</a>. </p>
<p>You can submit a question to Security Now! at the <a href="https://www.grc.com/feedback.htm" target="_blank">GRC Feedback Page</a>. </p>
<p>For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: <a href="https://www.grc.com/securitynow.htm" target="_blank">grc.com</a>, also the home of the best disk maintenance and recovery utility ever written <a href="https://www.grc.com/sr/spinrite.htm" target="_blank">Spinrite 6</a>.</p>
<p><strong>Sponsor:</strong><ul>
<li><a href="http://itpro.tv/securitynow">itpro.tv/securitynow  promo code SN30</a></li>
</ul></p>
]]></content:encoded>
				<itunes:image href="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_600x450/public/images/episodes/823174/hero/sn_0800.jpg?itok=L0sYe7gE"/>
			<guid isPermaLink="false">https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0800/sn0800.mp3</guid>
			<itunes:duration>1:50:21</itunes:duration>
			<enclosure url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0800/sn0800.mp3" length="53092729" type="audio/mpeg"/>
			<media:content url="https://pdst.fm/e/chtbl.com/track/E91833/cdn.twit.tv/audio/sn/sn0800/sn0800.mp3" fileSize="53092729" type="audio/mpeg" medium="audio">
				<media:title type="plain">SN 800: SolarBlizzard - SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</media:title>
				<media:description type="plain">SolarWinds' Orion Software, Swatting Goes IoT, PHP Zend Framework Vulnerability</media:description>
				<media:keywords>Security Now, TWiT, steve gibson, Leo Laporte, chrome antivirus, chrome prescan, av chrome, zyxel password, zyfwp / PrOw!aN_fXp, redundant password, swatter iot, swatting iot, internet of things swat, wordpress zend vulnerability</media:keywords>
				<media:thumbnail url="https://elroy.twit.tv/sites/default/files/styles/twit_slideshow_400x300/public/images/episodes/823174/hero/sn_0800.jpg?itok=a6kUlS2-" width="400" height="225" />
				<media:rating scheme="urn:simple">nonadult</media:rating>
				<media:rating scheme="urn:v-chip">tv-g</media:rating>
				<media:category scheme="urn:iab:categories" label="Technology &amp; Computing">IAB19</media:category>		<media:credit role="anchor person">Steve Gibson</media:credit>
		<media:credit role="anchor person">Leo Laporte</media:credit>
			</media:content>
		</item>
	</channel>
</rss>
