
Hosted by TWiT
Cybersecurity guru Steve Gibson joins Leo Laporte every Tuesday. Steve and Leo break down the latest cybercrime and hacking stories, offering a deep understanding of what's happening and how to protect yourself and your business. Security Now is a must listen for security professionals every week.
10 episodes · publishes weekly · latest 2026-07-01 · ~166 min/episode
Rank
#5175
Substance
46.2
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#5175 of 6182
Substance
Top 84%
outscores 16% of the index
Security Now ranks #5175 on The B2B Podcast Index with a substance score of 46.2 out of 100, scored across 5 recent episodes. It scores highest on specificity & evidence and insight density. The Fortibleed and Patch the Planet sections are well-evidenced with precise figures: 86,644 compromised devices, 194 countries, 260 operational servers, specific CVE numbers with CVSS scores, 30 million lines of kernel code analyzed, 24 LPE exploits validated, a 23-year-old OpenBSD use-after-free, and 880,000 internet-facing HTTP/2 servers. This is the episode's strongest dimension.
Averaged across 5 recently scored episodes, with cited evidence.
Genuine substantive content on the Fortibleed campaign, AI loop engineering, and OpenAI's Patch the Planet initiative, but easily a third of the 170-minute runtime is consumed by filler: a cycling sign photo, Kevin Mitnick's car bequest, Leo's AI blog hobby, printer nostalgia, and coffee mug commentary. The density of actionable insight per minute is mediocre despite several individually strong segments.
“the campaign was far more complex and targeted many more things than just Fortinet devices”
“Everything we have known about the dynamics of vulnerabilities, exploitation, attacks and patching has been thrown up in the air”
The episode is primarily a compilation and narration of third-party reports from SOC Radar, Palo Alto Unit 42, OpenAI, and Andrew Ng's newsletter, with Steve synthesizing rather than originating. The pill-bottle analogy for neural-net noise injection is a genuinely novel explanatory device, but most commentary recycles industry consensus framing.
“I was reminded of trying to fill a bottle with too many pills. If you just fill the bottle to the top, no more pills will fit in. But if you then tap the bottle on the counter or shake it sideways a bit, sure enough the pills that are already in the bottle will further settle”
“someone said, hey, you know, if when I tell the AI it was wrong, it readily agrees. So how about if instead we just feed its first answer back in as in a loop”
There is no guest; the episode is a dual-host format with Steve Gibson as the sole technical voice. Gibson is a genuine independent security researcher and long-running podcaster (episode 1085), but he is fundamentally a solo developer and commentator rather than an enterprise practitioner who has operated security infrastructure at scale - closer to a career podcast personality than an operator.
“You know, I often will jot a note to make sure that I come back to it and, and, and, and talk about it”
“I'll be setting up a new system with Windows 10 because all the evidence I've seen on the Internet says that 10 watt runs on given the same hardware much more quickly than Windows 11”
The Fortibleed and Patch the Planet sections are well-evidenced with precise figures: 86,644 compromised devices, 194 countries, 260 operational servers, specific CVE numbers with CVSS scores, 30 million lines of kernel code analyzed, 24 LPE exploits validated, a 23-year-old OpenBSD use-after-free, and 880,000 internet-facing HTTP/2 servers. This is the episode's strongest dimension.
“SOC Radar researchers found a threat actor systematically compromising them at scale, building a verified database of working credentials across 194 countries”
“GPT 5.5 Cyber identified security relevant components across more than 30 million lines of code, flagged potential security issues and then validated them dynamically generated 8 kernel pointer information leak proof of concepts and 24 local privilege escalation exploits”
Leo occasionally provides genuine pushback - notably questioning whether kernel patching without a reboot is technically feasible, which produces a worthwhile micro-debate - but the format is predominantly Steve delivering prepared lecture notes with Leo playing appreciative foil. There are no probing follow-ups on the Fortibleed campaign's attribution claims, no challenge to Steve's Windows predictions, and large stretches of mutual affirmation.
“I'm still puzzled. I think you. If you're gonna modify the kernel code, I think you'd have to reboot. No. Would you do it without restarting the machine?”
“Man. It seems like seven days is too long to wait for Steve Gibson and the latest security news”
First period on the Index - history builds from here.
10 scored on substance.
SN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop Engineering
2026-07-01 · 2h 50m
SN 1084: The Residential Proxy Threat - Malicious Proxies in Your Living Room
2026-06-24 · 2h 48m
SN 1083: Patch Tuesday à la AI - Arch Linux Repo Under Siege
2026-06-17 · 2h 36m
SN 1082: The Malicious Use of AI - Anthropic's Red Team Report
2026-06-10 · 2h 37m
SN 1081: AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?
2026-06-03 · 3h 20m
SN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?
2026-05-27 · 2h 44m
SN 1079: Daybreak and Codename MDASH - Microsoft's Edge Password Blunder
2026-05-20 · 2h 52m
SN 1078: DigiCert does it right - Hugging Face Under Fire
2026-05-13 · 2h 41m
SN 1077: A Browser AI API? - End of Bug Bounties?
2026-05-06 · 2h 35m
SN 1076: FAST16.SYS - Unmasking the NSA's Most Diabolical Digital Sabotage
2026-04-29 · 2h 35m
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/security-now-audio" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/security-now-audio/badge.svg" alt="Ranked #266 on The B2B Podcast Index" width="360" height="136" />
</a>Track Security Now's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.
Cyber Sentries: AI Insight to Cloud Security
TruStory FM
AI Proving Ground Podcast
World Wide Technology: Artificial Intelligence Experts
Cyber Leaders
SANS Institute
Hidden Layers
KUNGFU.AI
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
ClearTech Research / Jo Peterson
The Scale Up Show
Ryan Staley