FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayNaked Security

β€œDirty Pipe” Linux kernel bug lets anyone write to any file

By Paul Ducklin
Even read-only files can be written to, leading to a dangerously general purpose elevation-of-privilege attack.

pipe-1200

Adafruit suffers GitHub data breach – don’t let this happen to you

By Paul Ducklin
Training data stashed in GitHub by mistake... unfortunately, it was *real* data

Firefox patches two actively exploited 0-day holes: update now!

By Paul Ducklin
Firefox just published a double-zero-day patch - "remote code execution" combined with "sandbox escape". Update now!

Instagram scammers as busy as ever: passwords and 2FA codes at risk

By Paul Ducklin
Instagram scams don't seem to be dying out - we're seeing more variety and trickiness than ever...

Apple AirTag anti-stalking protection bypassed by researchers

By Paul Ducklin
Problems with Apple's Tracker Detect system, which warns you of likely stalking attempts using hidden AirTags.

WordPress backup plugin maker Updraft says β€œYou should update”…

By Paul Ducklin
A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

French speakers blasted by sextortion scams with no text or links

By Paul Ducklin
You'd spot this one a mile away... but what about your friends or family?

Irony alert! PHP fixes security flaw in input validation code

By Paul Ducklin
What's wrong with this sequence? 1. Step into the road 2. Check if it's safe 3. Keep on walki...

VMware fixes holes that could allow virtual machine escapes

By Paul Ducklin
Hats off to VMware for not using weasel words: "When should you act?" Immediately...

Google announces zero-day in Chrome browser – update now!

By Paul Ducklin
Zero-day buses: none for a while, then three at once. Here's Google joining Apple and Adobe in "zero-day week"

Adobe fixes zero-day exploit in e-commerce code: update now!

By Paul Ducklin
There's a remote code execution hole in Adobe e-commerce products - and cybercrooks are already exploiting it.

Apple zero-day drama for Macs, iPhones and iPads – patch now!

By Paul Ducklin
Sudden update! Zero-day browser hole! Drive-by malware danger! Patch Apple laptops and phones now...

apple-1200

Self-styled β€œCrocodile of Wall Street” arrested with husband over Bitcoin megaheist

By Naked Security writer
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!

At last! Office macros from the internet to be blocked by default

By Paul Ducklin
It's been a long time coming, and we're not there yet, but at least Microsoft Office will be a bit safer against macro malware...

Microsoft blocks web installation of its own App Installer files

By Paul Ducklin
It's a big deal when a vendor decides to block one of its own "features" for security reasons. Here's why we think it's a good idea.

Wormhole cryptotrading company turns over $340,000,000 to criminals

By Paul Ducklin
It was the best of blockchains, it was the worst of blockchains... as Charles Dickens might have said.

Elementor WordPress plugin has a gaping security hole – update now

By Paul Ducklin
We shouldn't need to say, "Check your inputs!" these days, but we're saying it anyway.

Linux kernel patches β€œperformance can be harmful” bug in video driver

By Paul Ducklin
This bug is fiendishly hard to exploit - but if you patch, it won't be there to exploit at all.

Website operator fined for using Google Fonts β€œthe cloudy way”

By Paul Ducklin
Google Fonts are OK, it seems, but only if everyone keeps their own copy of the fonts they use.

  • January 31st 2022 at 17:58

Coronavirus SMS scam offers home PCR testing devices – don’t fall for it!

By Paul Ducklin
Free home PCR devices would be technological marvels, and really useful, too. But there aren't any...

Apple fixes Safari data leak (and patches a zero-day!) – update now

By Paul Ducklin
That infamous "supercookie" bug in Safari has now been fixed. Oh, and there was a zero-day kernel hole as well.

apple-1200

β€œPwnKit” security bug gets you root on most Linux distros – what to do

By Paul Ducklin
An elevation of privilege bug that could let a "mostly harmless" user give themselves a instant root shell

Tax scam emails are alive and well as US tax season starts

By Paul Ducklin
If in doubt, don't give it out! (And don't forget that no reply is often a good reply.)

Alleged carder gang mastermind and three acolytes under arrest in Russia

By Naked Security writer
The motto of the gang was "In Fraud We Trust", and they went by a dizzying range of online nicknames.

Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft

By Paul Ducklin
The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.

Serious Security: Apple Safari leaks private data via database API – what you need to know

By Paul Ducklin
There's a tiny data leakage bug in the WebKit browser engine... but it could act as a "supercookie" identifier for your browsing

Romance scammer who targeted 670 women gets 28 months in jail

By Paul Ducklin
Found love online? Sending them money? Friends and family warning you it could be a scam? Don't be too quick to dismiss their concerns...

Serious Security: Linux full-disk encryption bug fixed – patch now!

By Paul Ducklin
Imagine if someone who didn't have your password could sneakily modify data that was encrypted with it.

REvil ransomware crew allegedly busted in Russia, says FSB

By Naked Security writer
The Russian Federal Security Bureau has just published a report about the investigation and arrest of the infamous "REvil" ransomware crew.

Wormable Windows HTTP hole – what you need to know

By Paul Ducklin
One bug in the January 2022 Patch Tuesday list is getting lots of attention: "HTTP Protocol Stack Remote Code Execution Vulnerability".

Home routers with NetUSB support could have critical kernel hole

By Paul Ducklin
Got a router that supports USB access across the network? You might need a kernel update...

JavaScript developer destroys own projects in supply chain β€œlesson”

By Paul Ducklin
Two popular open source JavaScript packages recently got "hacked" in a symbolic gesture by the original project creator.

Honda cars in flashback to 2002 – β€œCan’t Get You Out Of My Head”

By Paul Ducklin
Where were YOU on the night of 17 May 2002? And what about the day after that?

Log4Shell-like security hole found in popular Java SQL database engine H2

By Paul Ducklin
"It's Log4Shell, Jim, but not as we know it." How to find and fix a JNDI-based vuln in the H2 Database Engine.

FTC threatens β€œlegal action” over unpatched Log4j and other vulns

By Paul Ducklin
Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's the FTC to refresh your memory!

Apple Home software bug could lock you out of your iPhone

By Paul Ducklin
The finder of this bug insists it "poses a serious risk". We're not so sure, but we recommend you take steps to avoid it anyway.

Instagram copyright infringment scams – don’t get sucked in!

By Paul Ducklin
We deconstructed a copyright phish so you don't have to. Be warned: the crooks are getting better at these scams...

Log4Shell vulnerability Number Four: β€œMuch ado about something”

By Paul Ducklin
It's a Log4j bug, and you ought to patch it. But we don't think it's a critical crisis like the last one.

The cool retro phone with a REAL DIAL… plus plenty of IoT problems

By Paul Ducklin
You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.

Log4Shell: The Movie… a short, safe visual tour for work and home

By Paul Ducklin
Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!

S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]

By Paul Ducklin
Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)

Log4Shell explained – how it works, why you need to know, and how to fix it

By Paul Ducklin
Find out how to deal with the Log4Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!

❌