Security Now (Audio) SN 1070: CISA's Free Internet Scanning - Malware Disguised as a VPN
43 snips
Mar 18, 2026 They dig into CISA's free internet scanning and one engineer’s hands-on experience getting actionable vulnerability reports. Big tech privacy rollbacks get attention, from Meta removing end-to-end chat encryption to WhatsApp parental controls. Malicious actors use fake VPN clients, SEO-poisoned AI installers, and a clever AV-evasion zip trick to steal credentials.
AI Snips
Chapters
Books
Transcript
Episode notes
Use CISA Free External Scanning
- Enroll your organization in CISA's free Cyber Hygiene vulnerability scanning to get weekly external scans and confidential PDF reports.
- Steve emailed vulnerability@cisa.dhs, completed login.gov enrollment, and received actionable findings within days for GRC's 16 IPs.
Residential IPs Are High Value For Attackers
- Residential IPs are valuable to attackers as proxies because they hide malicious traffic behind innocuous consumer addresses.
- Europol and FBI found a botnet renting infected home routers and modems to support ransomware, DDoS, and CSAM distribution.
Never Expose Router Management To The Internet
- Avoid exposing router management to the WAN; do not enable remote web management on home/office routers.
- Steve recommends outbound-only tools like TailScale rather than opening router ports that let attackers exploit firmware bugs.



