FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayNaked Security

Microsoft hit by Storm season – a tale of two semi-zero days

By Paul Ducklin
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...

Zimbra Collaboration Suite warning: Patch this 0-day right now (by hand)!

By Paul Ducklin
Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly request your cooperation to apply the fix manually."

Interested in $10,000,000? Ready to turn in the Clop ransomware crew?

By Naked Security writer
Technically, it's "up to $10 million", but it's potentially a LOT of money, nevertheless...

Gozi banking malware β€œIT chief” finally jailed after more than 10 years

By Paul Ducklin
Gozi threesome from way back in the late 2000s and early 2010s now all charged, convicted and sentenced. The DOJ got there in the end...

S3 Ep137: 16th century crypto skullduggery

By Paul Ducklin
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

s3-ep137-feat-1200

Serious Security: Verification is vital – examining an OAUTH login bug

By Paul Ducklin
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

Phone scamming kingpin gets 13 years for running β€œiSpoof” service

By Naked Security writer
Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

ispoof-1200

Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security

By Paul Ducklin
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

FBI and FCC warn about β€œJuicejacking” – but just how useful is their advice?

By Paul Ducklin
USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?

S3 Ep129: When spyware arrives from someone you trust

By Paul Ducklin
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

Researchers claim they can bypass Wi-Fi encryption (briefly, at least)

By Paul Ducklin
They can't read much of your data, but even a few stray network packets could tell them something they're not supposed to know.

Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

By Paul Ducklin
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

WooCommerce Payments plugin for WordPress has an admin-level hole – patch now!

By Paul Ducklin
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

woo-1200

Windows 11 also vulnerable to β€œaCropalypse” image data leakage

By Paul Ducklin
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

Google Pixel phones had a serious data leakage bug – here’s what to do!

By Paul Ducklin
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

Bitcoin ATM customers hacked by video upload that was actually an app

By Paul Ducklin
As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...

S3 Ep 126: The price of fast fashion (and feature creep) [Audio + Text]

By Paul Ducklin
Worried about rogue apps? Unsure about the new Outlook zero-day? Clear advice in plain English... just like old times, with Duck and Chet!

SHEIN shopping app goes rogue, grabs price and URL data from your clipboard

By Paul Ducklin
It's not exactly data theft, but it's worryingly close to "unintentional treachery" - apparently because it's great for marketing purposes

Feds warn about right Royal ransomware rampage that runs the gamut of TTPs

By Paul Ducklin
Wondering which cybercrime tools, techniques and procedures to focus on? How about any and all of them?

S3 Ep124: When so-called security apps go rogue [Audio + Text]

By Paul Ducklin
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

s3-ep124-auth--1200

LastPass: Keylogger on home PC led to cracked corporate password vault

By Paul Ducklin
Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!

By Paul Ducklin
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

NPM JavaScript packages abused to create scambait links in bulk

By Paul Ducklin
Free spins? Bonus game points? Cheap social media followers? What harm could it possibly do if you just take a tiny little look?!

Coinbase breached by social engineers, employee data stolen

By Paul Ducklin
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

GoDaddy admits: Crooks hit us with malware, poisoned customer websites

By Paul Ducklin
New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.

Reddit admits it was hacked and data stolen, says β€œDon’t panic”

By Paul Ducklin
Reddit is suggesting three tips as a follow-up to this breach. We agree with two of them but not with the third...

Finnish psychotherapy extortion suspect arrested in France

By Naked Security writer
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By Paul Ducklin
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

GoTo admits: Customer cloud backups stolen together with decryption key

By Paul Ducklin
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

CircleCI – code-building service suffers total credential compromise

By Paul Ducklin
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

Inside a scammers’ lair: Ukraine busts 40 in fake bank call-centre raid

By Naked Security writer
When someone calls you up to warn you that your bank account is under attack - it's true, because THAT VERY PERSON is the one attacking you!

Twitter data of β€œ+400 million unique users” up for sale – what to do?

By Paul Ducklin
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all…

By Paul Ducklin
The crooks now know who you are, where you live, which computers are yours, where you go online... and they got those password vaults, too.

COVID-bit: the wireless spyware trick with an unfortunate name

By Paul Ducklin
It's not the switching that's the problem, it's the switching of the switching!

ind-1200

LastPass admits to customer data breach caused by previous breach

By Paul Ducklin
Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.

Online ticketing company β€œSee” pwned for 2.5 years by attackers

By Paul Ducklin
Don't be a cybersecurity slowcoach - you need to spot possible attacks as soon as you can.

Fashion brand SHEIN fined $1.9m for lying about data breach

By Naked Security writer
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

Former Uber CSO convicted of covering up megabreach back in 2016

By Naked Security writer
Obstructed FTC proceedings, and concealed a crime, said the jury.

Optus breach – Aussie telco told it will have to pay to replace IDs

By Paul Ducklin
Licence compromised? Passport number burned? Need a new one? Who's going to pay?

Morgan Stanley fined millions for selling off devices full of customer PII

By Paul Ducklin
Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...

❌