Security Now (Audio)

SN 1070: CISA's Free Internet Scanning - Malware Disguised as a VPN

43 snips
Mar 18, 2026
They dig into CISA's free internet scanning and one engineer’s hands-on experience getting actionable vulnerability reports. Big tech privacy rollbacks get attention, from Meta removing end-to-end chat encryption to WhatsApp parental controls. Malicious actors use fake VPN clients, SEO-poisoned AI installers, and a clever AV-evasion zip trick to steal credentials.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ADVICE

Use CISA Free External Scanning

  • Enroll your organization in CISA's free Cyber Hygiene vulnerability scanning to get weekly external scans and confidential PDF reports.
  • Steve emailed vulnerability@cisa.dhs, completed login.gov enrollment, and received actionable findings within days for GRC's 16 IPs.
INSIGHT

Residential IPs Are High Value For Attackers

  • Residential IPs are valuable to attackers as proxies because they hide malicious traffic behind innocuous consumer addresses.
  • Europol and FBI found a botnet renting infected home routers and modems to support ransomware, DDoS, and CSAM distribution.
ADVICE

Never Expose Router Management To The Internet

  • Avoid exposing router management to the WAN; do not enable remote web management on home/office routers.
  • Steve recommends outbound-only tools like TailScale rather than opening router ports that let attackers exploit firmware bugs.
Get the Snipd Podcast app to discover more snips from this episode
Get the app