Security Now (Audio) SN 1054: Bots in the Belfry - Cisco Promises Real Security Fixes!
17 snips
Dec 3, 2025 Cisco finally acknowledges the need for serious security improvements, vowing to implement 'secure by default' devices. A major cybersecurity incident strikes Salesforce, leading to discussions about supply-chain breaches and the risks of outsourcing. Australia introduces a ban on underage social media use, and the EU considers replacing US tech with local alternatives. Best practices for passwords versus passkeys are explored, alongside an intriguing analysis of SSD data retention. Plus, exciting news about a new Stargate series!
AI Snips
Chapters
Books
Transcript
Episode notes
Supply-Chain Breach Hits Salesforce Customers
- Steve recounts the recent Gainsight-related Salesforce incident affecting over 200 customers via third-party app tokens.
- He highlights attackers chaining through SaaS integrations and the resulting customer data exposures.
Outsourcing Expands Blast Radius
- Outsourcing common services reduces operational cost but multiplies systemic risk and blast radius.
- Repeated supply-chain-like breaches show current API/outsourcing models lack adequate containment.
Cisco's Past Defaults Hurt Security
- Steve Gibson recounts Cisco's long history of running unnecessary services on routers and poor defaults.
- He contrasts past optional hardening guides with Cisco's new promise to make security the default.


