Security Now (Audio) SN 1067: KongTuke's CrashFix - Click, Paste, Pwned
29 snips
Mar 3, 2026 They unpack a new clipboard-based social engineering attack that tricks users into launching malware. They track the evolution from ClickFix to the more dangerous CrashFix campaign. Coverage also includes AI-driven low-skill attacks, mass VPN blocks in Russia, a critical Cisco zero-day, and troubling trends in AI-generated security noise.
AI Snips
Chapters
Transcript
Episode notes
AI Is Tooling Up Both Attackers And Defenders
- AI is a tool that amplifies both attackers and defenders rather than a magical cause of new threats.
- The Fortinet incidents used exposed management ports and weak passwords, not zero-days, with AI used to scale script writing and reconnaissance.
Close Management Ports And Require Strong MFA
- Harden exposed management interfaces by disabling public management ports and enforcing strong MFA.
- FortiGate breaches succeeded because devices had management ports open, weak passwords, and no multi-factor authentication.
FTC Temporarily Greenlights Limited Age Verification
- COPPA can block necessary age-verification flows, so the FTC will not enforce COPPA against operators that collect age solely to verify age under conditions.
- The FTC listed strict limits: purpose-limited use, minimal retention, and security safeguards for age data.
