
 Security Now (Audio)
 Security Now (Audio) SN 1047: RediShell's CVSS 10.0 - The Rise of Mega Botnets
 20 snips 
 Oct 15, 2025  Texas may require Apple and Google to enforce strict age verification for app downloads, sparking privacy concerns. The EU has postponed a controversial chat control vote, while Salesforce refuses to pay a ransomware demand, leading to a data leak. A Discord breach exposes 70,000 government IDs, and Microsoft prepares to move GitHub to Azure. Plus, a massive botnet targets U.S. RDP services, and experts critique the usability of iOS 26's new interface. Finally, a critical vulnerability in Redis servers demands urgent attention. 
 AI Snips 
 Chapters 
 Books 
 Transcript 
 Episode notes 
Refuse Ransom Payments
- Do not pay ransomware extortion demands as a matter of policy; Salesforce refused to pay.
- Expect data to be leaked after public extortion, so prepare incident response and notify affected customers.
Third-Party Support Risk
- Attackers used a compromised BPO support account to access Discord's support platform and exfiltrate 1.6 TB of tickets.
- API integrations magnified the breach by enabling mass queries into Discord's internal systems.
Turn On Global Privacy Control
- Enable Global Privacy Control (GPC) or use a browser that emits it to signal opt-out preferences.
- Expect enforcement to follow legal adoption, so browsers should implement GPC support proactively.

