Summary of "Security Now 1065"

Summary — Security Now (episode covering “Attestation” and related security news)

Overview

This episode covered changes to code‑signing attestation, TLS/code‑signing certificate lifetime reductions, password‑manager server‑side research, web‑scale/AI bot traffic effects, Chrome 145 device‑bound sessions, extension ecosystem abuses, an Outlook add‑in supply‑chain attack, active WinRAR exploitation, mobile spyware leaks, age‑verification policy debates, and risks/benefits of AI code generation. The hosts discussed practical guidance and real‑world examples throughout.


Key technical topics, findings, and analysis

Attestation & code‑signing changes (main focus)

Personal account of obtaining a code‑signing cert

Password manager server‑side research (preview)

Web scale, dynamic sites, and bot/AI traffic

Chrome 145 — device‑bound session credentials

Browser extension ecosystem abuses

Outlook add‑in supply chain attack

WinRAR active exploitation

Mobile spyware & IM interception

Age verification and social platforms

AI/code generation (“vibe coding”) discussion


Product mentions, features & sponsor tools


Other items / anecdotes


Actionable takeaways


Main speakers / primary sources

Category ?

Technology


Share this summary


Is the summary off?

If you think the summary is inaccurate, you can reprocess it with the latest model.

Video