SN 1078: DigiCert does it right - Hugging Face Under Fire

SN 1078: DigiCert does it right - Hugging Face Under Fire

Author: TWiT May 13, 2026 Duration: 2:40:32

DigiCert's latest security mishap triggered not just a scramble behind the scenes, but a cascading crisis that briefly wiped trust from millions of Windows systems. Find out how a single support slip, followed by Microsoft's heavy-handed response, left critical infrastructures exposed.

  • The FCC decides router firmware updates are useful.
  • Netgear applies for and gets a full FCC pass.
  • AI uncovers a 21-year old critical FreeBSD RCE.
  • What was behind that Let's Encrypt outage.
  • AI model repositories are overflowing with malware.
  • The CISA 2015 info-sharing act is being renewed.
  • Edge leaves ALL usernames and passwords in the clear.
  • An examination of DigiCert's breach and their response

Show Notes - https://www.grc.com/sn/SN-1078-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:


Every Tuesday, cybersecurity expert Steve Gibson sits down with Leo Laporte to dissect the week's most pressing digital threats. This isn't just a news recap; it's a detailed analysis where complex topics like emerging malware, data breaches, and software vulnerabilities are explained with clarity. The conversation in Security Now (Video) provides actionable insights, whether you're safeguarding a home network or responsible for enterprise infrastructure. As a production of TWiT, this video podcast delivers both visual aids and in-depth discussion, translating technical jargon into practical knowledge. Regular listeners gain a deeper understanding of the threat landscape and the evolving tools for defense. For those who want an enhanced experience, Club TWiT membership offers ad-free access to this and other shows. Tune in weekly to stay informed and build a more resilient digital life, as Steve and Leo unpack the stories that define our security reality.
Author: Language: en-us Episodes: 33

Security Now (Video)
Podcast Episodes
SN 1098: How worried should we be? - Unpredictable Agents [not-audio_url] [/not-audio_url]

Duration: 2:42:18
With millions racing to embrace AI assistants and cybercriminals pivoting to new, high-stakes tactics, the episode tackles the dizzying pace of change and asks: just how worried should we be? The discussion pulls back th…
SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers [not-audio_url] [/not-audio_url]

Duration: 2:50:02
After Microsoft's historic Mega Patch Tuesday, enterprise IT teams worldwide are scrambling as a wave of updates triggers system meltdowns, broken domains, and silent Excel failures. Find out how AI-driven speed collided…
SN 1096: Are we the Krell? - 153 Million Driver's Licenses Leaked [not-audio_url] [/not-audio_url]

Duration: 2:50:47
Are we charging toward a Krell-style catastrophe with AI, arming ourselves with incomprehensible power while missing the real risks lurking beneath the code? The full report on last week's nearly 1,000 Microsoft security…
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails [not-audio_url] [/not-audio_url]

Duration: 2:49:05
From autocorrect to full-fledged conversationalists, discover how a few tweaks transformed language models—and why understanding this shift exposes urgent questions about AI safety and control. Trusting an open source AI…
SN 1091: The Post BlackHat State of AI - When AI Writes Malware [not-audio_url] [/not-audio_url]

Duration: 2:51:12
AI agents are breaking free from their test environments, outsmarting their creators and breaching real-world networks in ways that no one predicted. Discover how these agentic models are changing the game for both cyber…