Security Now
Hosted by Steve Gibson & Leo Laporte
Steve Gibson takes one security story apart every Tuesday, slowly, until you understand how it actually works.
- Level
- Practitioner, assumes you work in or study security
- Status
- Active, last episode
- Who's behind it
- Media outlet, TWiT sourceAd-supported; ad-free feeds through Club TWiT membership.
- Last verified
- Transcripts for every episode
Listed underThreat intel and newsAppSec
Editorial take
The longest-running security podcast still publishing, and the best at explaining mechanism rather than headline. Steve Gibson, the engineer behind SpinRite and GRC.com, works through the week's news with Leo Laporte, then spends the back half on one topic until the how and why are clear. Episodes run close to three hours, so this is a show you listen to at 1.5x across a few commutes. It is the rare show that serves both the curious enthusiast and the working practitioner who wants a slower explanation than a daily brief can give. The honest limitation is pace and tangents: listener mail, sci-fi asides, and long sponsor reads add up. In 2026 the episodes lean heavily on AI security.
Last hand-checked 2026-09-30, RSS feed carries only the latest 20 episodes; the full archive back to 2005 is on twit.tv.
Listen if you …
- want security news explained down to the protocol or code level, not just reported
- are studying for a certification and learn best from long worked explanations
- have a long weekly commute or workout and prefer one big episode to several short ones
Skip if you …
- you want a quick brief, episodes run close to three hours
- you dislike tangents and long sponsor reads, both are part of the format
Start with these 3 episodes
- 01
SN 1084: The Residential Proxy Threat - Malicious Proxies in Your Living Room
· 168 min · Beginner
A threat that lives on the listener's own TV box, a concrete way into the show's explain-the-mechanism style.
- 02
SN 1093: Tokens in the Stream - Why LLMs are inherently insecure and prompt injection will persist
· 168 min · Practitioner
Gibson at his best: one research paper on why prompt injection persists, explained from the token stream up.
- 03
SN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?
· 164 min · Practitioner
A contrarian argument that AI bug-finding is defenders paying down security debt, worth hearing whether or not you agree.
About the show
Security Now is a weekly show on the TWiT network, hosted by Steve Gibson of Gibson Research Corporation with Leo Laporte. It debuted on August 18, 2005, records every Tuesday, and passed episode 1,000 in 2024.
Each episode opens with a run through the week's security news and closes on a single featured topic, often a vulnerability, a research paper, or a protocol. Transcripts are published for every episode, and TWiT offers ad-free feeds through its Club TWiT membership.
Pairs with
If Security Now works for you, these likely will too.
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Five to eight minutes every weekday morning on what the SANS honeypots and handlers saw overnight.
Listen if you work in a SOC or run infrastructure and need to know what to patch today.
solodaily<30mRisky Business
PickPatrick Gray
Weekly news + analysis show for working security professionals.
Listen if you you work in security and need a weekly news synthesis.
panelweekly60m+CyberWire Daily
PickDave Bittner
Daily 25-minute briefing on the cybersecurity news that actually moved markets, regulators, or attackers.
Listen if you work in or sell to cybersecurity and need the daily news pulse.
narrativedaily<30m