SN 1067: KongTuke's CrashFix - Click, Paste, Pwned

SN 1067: KongTuke's CrashFix - Click, Paste, Pwned

Author: TWiT March 4, 2026 Duration: 2:40:04

A crafty new breed of social engineering attack is tricking users into launching malware straight from their clipboard, exposing a fresh vulnerability in Windows that even tech pros could fall for. Leo Laporte and Steve Gibson break down how the latest ClickFix and CrashFix exploits are outsmarting traditional defenses.

  • The lowdown on last week's "no turn" picture of the week.
  • Is an AI-driven hacking campaign a big deal now.
  • Clause used in multiple Mexican government attacks.
  • Apple continues to be confronted with age restrictions.
  • COPPA needs an exception to allow age collection.
  • Meta swamps law enforcement with AI-slop CSAM reports.
  • Roskomnadzor has been busy blocking VPNs. Guess how many.
  • The UK tries to report their self-scanning success.
  • Remember that hacker who extorted the psychotherapy patients.
  • Scattered Lapsus$ Hunters is actively recruiting women.
  • Cisco lands another breathtakingly rare 10.0 CVSS.
  • VulnCheck's report on 2025 vulnerabilities and exploits.
  • Steve discovers a fabulous $72 Hardware Security Module.
  • A listener shares an interesting AI service discovery.
  • The very potent "ClickFix" exploit evolves

Show Notes - https://www.grc.com/sn/SN-1067-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:


Every Tuesday, cybersecurity expert Steve Gibson sits down with Leo Laporte to dissect the week's most pressing digital threats. This isn't just a news recap; it's a detailed analysis where complex topics like emerging malware, data breaches, and software vulnerabilities are explained with clarity. The conversation in Security Now (Video) provides actionable insights, whether you're safeguarding a home network or responsible for enterprise infrastructure. As a production of TWiT, this video podcast delivers both visual aids and in-depth discussion, translating technical jargon into practical knowledge. Regular listeners gain a deeper understanding of the threat landscape and the evolving tools for defense. For those who want an enhanced experience, Club TWiT membership offers ad-free access to this and other shows. Tune in weekly to stay informed and build a more resilient digital life, as Steve and Leo unpack the stories that define our security reality.
Author: Language: en-us Episodes: 33

Security Now (Video)
Podcast Episodes
SN 1086: The Apex Agentic Adversary - Visual Prompt Injection Strikes [not-audio_url] [/not-audio_url]

Duration: 2:53:23
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's…
SN 1083: Patch Tuesday à la AI - Arch Linux Repo Under Siege [not-audio_url] [/not-audio_url]

Duration: 2:36:20
This episode unpacks the jaw-dropping surge in vulnerabilities unearthed by AI, revealing how Microsoft shattered its own patch records while adversaries and defenders race to outpace each other. The conversation gets re…
SN 1082: The Malicious Use of AI - Anthropic's Red Team Report [not-audio_url] [/not-audio_url]

Duration: 2:37:27
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm r…