Feb 3rd 2026
Security Now 1063
Mongo's Too Easy
AI Bug Bounties Gone Wild
When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it’s clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update.
- An anti-virus system infects its own users.
- Apple's next iOS release "fuzzes" cellular locations.
- cURL discontinues bug bounties under bogus AI flood.
- AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL.
- Ireland did NOT already pass their spying legislation.
- AI irreversibly deletes all project files. Says it's sorry.
- Windows has a serious global clipboard security problem.
- ISPs have the ability to monetize their subscriber's identities.
- MongoDB has lowered the hacking skill level bar to the floor
Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf
Download or subscribe to Security Now at https://twit.tv/shows/security-now.
You can submit a question to Security Now at the GRC Feedback Page.
For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit