Security Now with Steve Gibson and Leo Laporte

Feb 3rd 2026

Security Now 1063

Mongo's Too Easy

AI Bug Bounties Gone Wild

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 21:30 UTC.
Category: Help & How To

When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it’s clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update.

  • An anti-virus system infects its own users.
  • Apple's next iOS release "fuzzes" cellular locations.
  • cURL discontinues bug bounties under bogus AI flood.
  • AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL.
  • Ireland did NOT already pass their spying legislation.
  • AI irreversibly deletes all project files. Says it's sorry.
  • Windows has a serious global clipboard security problem.
  • ISPs have the ability to monetize their subscriber's identities.
  • MongoDB has lowered the hacking skill level bar to the floor

Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit