DigiCert's latest security mishap triggered not just a scramble behind the scenes, but a cascading crisis that briefly wiped trust from millions of Windows systems. Find out how a single support slip, followed by Microsoft's heavy-handed response, left critical infrastructures exposed.
• The FCC decides router firmware updates are useful. • Netgear applies for and gets a full FCC pass. • AI uncovers a 21-year old critical FreeBSD RCE. • What was behind that Let's Encrypt outage. • AI model repositories are overflowing with malware. • The CISA 2015 info-sharing act is being renewed. • Edge leaves ALL usernames and passwords in the clear. • An examination of DigiCert's breach and their response
Show Notes - https://www.grc.com/sn/SN-1078-Notes.pdf
Hosts: Steve Gibson and Leo Laporte
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit
Sponsors:
cyberhoot.com/securitynow guardsquare.com doppel.com outsystems.com/twit threatlocker.com/twit