FreshRSS

🔒
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayNaked Security

Mom’s Meals issues “Notice of Data Event”: What to know and what to do

By Paul Ducklin
It took six months for notifications to start, and we still don't know exactly what went down... but here's our advice on what to do.

Using WinRAR? Be sure to patch against these code execution bugs…

By Paul Ducklin
Imagine if you clicked on a harmless-looking image, but an unknown application fired up instead...

“Grab hold and give it a wiggle” – ATM card skimming is still a thing

By Paul Ducklin
The rise of tap-to-pay and chip-and-PIN hasn't rid the world of ATM card skimming criminals...

Microsoft Patch Tuesday: 74 CVEs plus 2 “Exploit Detected” advisories

By Paul Ducklin
74 CVEs, and two "Exploitation Detected" advisories, which are nearly but not quite the same as 0-days. Also, two potential Teams treacheries that you really want to fix.

Serious Security: Why learning to touch-type could protect you from audio snooping

By Paul Ducklin
Fast, quiet, smooth, consistent and low impact... why true hacker-grade touch-typing might keep you more secure.

S3 Ep146: Tell us about that breach! (If you want to.)

By Paul Ducklin
Serious security stories explained clearly in plain English - listen now. (Full transcript available.)

Performance and security clash yet again in “Collide+Power” attack

By Paul Ducklin
It's a real vulnerability, but the data leakage rate can be as low as... let's just say that an IMAX-quality copy of the new "Oppenheimer" movie could take you 4 billion years to exfiltrate.

SEC demands four-day disclosure limit for cybersecurity breaches

By Paul Ducklin
When is a ransomware attack a reportable matter? And how long have you got to decide?

S3 Ep145: Bugs With Impressive Names!

By Paul Ducklin
Fascinating fun (with a serious and educational side) - listen now! Full transcript available inside.

Zenbleed: How the quest for CPU performance could put your passwords at risk

By Paul Ducklin
You need to turn on a special setting to stop (the code you wrote to stop [the code you wrote to improve performance] from reducing performance) from reducing security.

Microsoft hit by Storm season – a tale of two semi-zero days

By Paul Ducklin
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...

Zimbra Collaboration Suite warning: Patch this 0-day right now (by hand)!

By Paul Ducklin
Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly request your cooperation to apply the fix manually."

Microsoft patches four zero-days, finally takes action against crimeware kernel drivers

By Paul Ducklin
Here's a brief reminder to do two things. The first is to patch. The second is to read up why it's a good idea to patch...

Urgent! Apple fixes critical zero-day hole in iPhones, iPads and Macs

By Paul Ducklin
Don't delay, do it today. This is a code-implantation bug in WebKit that attackers already know how to exploit.

Serious Security: Rowhammer returns to gaslight your computer

By Paul Ducklin
Gaslights produce a telltale flicker when nearby lamps are lit; DRAM values do something similar when nearby memory cells are accessed.

Firefox 115 is out, says farewell to users of older Windows and Mac versions

By Paul Ducklin
No zero-days this month, so you're patching to stay ahead, not merely to catch up!

WordPress plugin lets users become admins – Patch early, patch often!

By Paul Ducklin
Ultimate Member plugin lets rogue users choose their own site capabilities, including becoming admins.

Interested in $10,000,000? Ready to turn in the Clop ransomware crew?

By Naked Security writer
Technically, it's "up to $10 million", but it's potentially a LOT of money, nevertheless...

Aussie PM says, “Shut down your phone every 24 hours for 5 mins” – but that’s not enough on its own

By Paul Ducklin
Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.

ASUS warns router customers: Patch now, or block all inbound requests

By Paul Ducklin
"Do as we say, not as we do!" - The patches took ages to come out, but don't let that lure you into taking ages to install them.

Gozi banking malware “IT chief” finally jailed after more than 10 years

By Paul Ducklin
Gozi threesome from way back in the late 2000s and early 2010s now all charged, convicted and sentenced. The DOJ got there in the end...

S3 Ep137: 16th century crypto skullduggery

By Paul Ducklin
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

s3-ep137-feat-1200

Serious Security: That KeePass “master password crack”, and what we can learn from it

By Paul Ducklin
Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

Serious Security: Verification is vital – examining an OAUTH login bug

By Paul Ducklin
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

Ransomware tales: The MitM attack that really had a Man in the Middle

By Paul Ducklin
Another traitorous sysadmin story, this one busted by system logs that gave his game away...

Phone scamming kingpin gets 13 years for running “iSpoof” service

By Naked Security writer
Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

ispoof-1200

Bootkit zero-day fix – is this Microsoft’s most cautious patch ever?

By Paul Ducklin
When blocking buggy bootup modules, you have to be really careful not to lock your keys inside the car...

Apple delivers first-ever Rapid Security Response “cyberattack” patch – leaves some users confused

By Paul Ducklin
Just when we'd got used to three-numbered versions, such as "13.3.1", here comes an update suffix, bringing you "13.3.1 (a)"...

Google leaking 2FA secrets – researchers advise against new “account sync” feature for now

By Paul Ducklin
You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...

Double zero-day in Chrome and Edge – check your versions now!

By Paul Ducklin
Wouldn't it be handy if there were a single version number to check for in every Chromium-based browser, on every supported platform?

S3 Ep131: Can you really have fun with FORTRAN?

By Paul Ducklin
Loop-the-loop in this week's episode. Entertaining, educational and all in plain English. Transcript inside.

Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security

By Paul Ducklin
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

FBI and FCC warn about “Juicejacking” – but just how useful is their advice?

By Paul Ducklin
USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?

Attention gamers! Motherboard maker MSI admits to breach, issues “rogue firmware” alert

By Paul Ducklin
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

Apple issues emergency patches for spyware-style 0-day exploits – update now!

By Paul Ducklin
A bug to hack your browser, then a bug to pwn the kernel... reported from the wild by Amnesty International.

S3 Ep129: When spyware arrives from someone you trust

By Paul Ducklin
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

Einstein tilings – the amazing “Hat” shape that never repeats!

By Paul Ducklin
Imagine tiling a whole football field using a single shape... yet not being able to produce a repeating pattern, even if you wanted to.

Researchers claim they can bypass Wi-Fi encryption (briefly, at least)

By Paul Ducklin
They can't read much of your data, but even a few stray network packets could tell them something they're not supposed to know.

Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

By Paul Ducklin
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

WooCommerce Payments plugin for WordPress has an admin-level hole – patch now!

By Paul Ducklin
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

woo-1200

Windows 11 also vulnerable to “aCropalypse” image data leakage

By Paul Ducklin
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

❌