FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

S3 Ep72: AirTag stalking, web server coding woes and Instascams [Podcast + Transcript]

By Paul Ducklin β€” March 3rd 2022 at 14:04
Latest episode - listen now (or read it, if that's your preference)...

☐ β˜† βœ‡ Naked Security

Ransomware with a difference: β€œDerestrict your software, or else!”

By Paul Ducklin β€” March 2nd 2022 at 16:33
"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.

☐ β˜† βœ‡ Naked Security

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]

By Paul Ducklin β€” February 24th 2022 at 16:51
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

WordPress backup plugin maker Updraft says β€œYou should update”…

By Paul Ducklin β€” February 22nd 2022 at 17:26
A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

☐ β˜† βœ‡ Naked Security

French speakers blasted by sextortion scams with no text or links

By Paul Ducklin β€” February 21st 2022 at 17:59
You'd spot this one a mile away... but what about your friends or family?

☐ β˜† βœ‡ Naked Security

Irony alert! PHP fixes security flaw in input validation code

By Paul Ducklin β€” February 18th 2022 at 17:59
What's wrong with this sequence? 1. Step into the road 2. Check if it's safe 3. Keep on walki...

☐ β˜† βœ‡ Naked Security

S3 Ep70: Bitcoin, billing blunders, and 0-day after 0-day after 0-day [Podcast + Transcript]

By Paul Ducklin β€” February 17th 2022 at 17:12
Latest episode - listen and learn!

☐ β˜† βœ‡ Naked Security

VMware fixes holes that could allow virtual machine escapes

By Paul Ducklin β€” February 16th 2022 at 19:32
Hats off to VMware for not using weasel words: "When should you act?" Immediately...

☐ β˜† βœ‡ Naked Security

Google announces zero-day in Chrome browser – update now!

By Paul Ducklin β€” February 15th 2022 at 19:17
Zero-day buses: none for a while, then three at once. Here's Google joining Apple and Adobe in "zero-day week"

☐ β˜† βœ‡ Naked Security

Adobe fixes zero-day exploit in e-commerce code: update now!

By Paul Ducklin β€” February 14th 2022 at 22:38
There's a remote code execution hole in Adobe e-commerce products - and cybercrooks are already exploiting it.

☐ β˜† βœ‡ Naked Security

Power company pays out $3 trillion compensation to astonished customer

By Paul Ducklin β€” February 14th 2022 at 14:58
More money than the UK's economy produces in a year!

☐ β˜† βœ‡ Naked Security

Apple zero-day drama for Macs, iPhones and iPads – patch now!

By Paul Ducklin β€” February 11th 2022 at 14:25
Sudden update! Zero-day browser hole! Drive-by malware danger! Patch Apple laptops and phones now...

apple-1200

☐ β˜† βœ‡ Naked Security

S3 Ep69: WordPress woes, Wormhole holes, and a Microsoft change of heart [Podcast + Transcript]

By Paul Ducklin β€” February 10th 2022 at 01:15
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Self-styled β€œCrocodile of Wall Street” arrested with husband over Bitcoin megaheist

By Naked Security writer β€” February 9th 2022 at 14:44
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!

☐ β˜† βœ‡ Naked Security

At last! Office macros from the internet to be blocked by default

By Paul Ducklin β€” February 8th 2022 at 16:34
It's been a long time coming, and we're not there yet, but at least Microsoft Office will be a bit safer against macro malware...

☐ β˜† βœ‡ Naked Security

Microsoft blocks web installation of its own App Installer files

By Paul Ducklin β€” February 7th 2022 at 16:36
It's a big deal when a vendor decides to block one of its own "features" for security reasons. Here's why we think it's a good idea.

☐ β˜† βœ‡ Naked Security

S3 Ep68: Bugs, scams, privacy …and fonts?! [Podcast + Transcript]

By Paul Ducklin β€” February 3rd 2022 at 16:20
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Elementor WordPress plugin has a gaping security hole – update now

By Paul Ducklin β€” February 2nd 2022 at 17:11
We shouldn't need to say, "Check your inputs!" these days, but we're saying it anyway.

☐ β˜† βœ‡ Naked Security

Linux kernel patches β€œperformance can be harmful” bug in video driver

By Paul Ducklin β€” February 1st 2022 at 19:59
This bug is fiendishly hard to exploit - but if you patch, it won't be there to exploit at all.

☐ β˜† βœ‡ Naked Security

Coronavirus SMS scam offers home PCR testing devices – don’t fall for it!

By Paul Ducklin β€” January 28th 2022 at 23:58
Free home PCR devices would be technological marvels, and really useful, too. But there aren't any...

☐ β˜† βœ‡ Naked Security

Happy Data Privacy Day – and we really do mean β€œhappy” :-)

By Paul Ducklin β€” January 28th 2022 at 15:34
We give you some simple digital lifesytle tips that cost nothing.

☐ β˜† βœ‡ Naked Security

Apple fixes Safari data leak (and patches a zero-day!) – update now

By Paul Ducklin β€” January 27th 2022 at 21:09
That infamous "supercookie" bug in Safari has now been fixed. Oh, and there was a zero-day kernel hole as well.

apple-1200

☐ β˜† βœ‡ Naked Security

S3 Ep67: Tax scams, carder busts and crypto capers [Podcast + Transcript]

By Paul Ducklin β€” January 27th 2022 at 19:57
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

β€œPwnKit” security bug gets you root on most Linux distros – what to do

By Paul Ducklin β€” January 26th 2022 at 19:58
An elevation of privilege bug that could let a "mostly harmless" user give themselves a instant root shell

☐ β˜† βœ‡ Naked Security

Tax scam emails are alive and well as US tax season starts

By Paul Ducklin β€” January 25th 2022 at 17:19
If in doubt, don't give it out! (And don't forget that no reply is often a good reply.)

☐ β˜† βœ‡ Naked Security

Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft

By Paul Ducklin β€” January 21st 2022 at 16:25
The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.

☐ β˜† βœ‡ Naked Security

S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript]

By Paul Ducklin β€” January 20th 2022 at 17:28
Latest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Serious Security: Apple Safari leaks private data via database API – what you need to know

By Paul Ducklin β€” January 18th 2022 at 19:23
There's a tiny data leakage bug in the WebKit browser engine... but it could act as a "supercookie" identifier for your browsing

☐ β˜† βœ‡ Naked Security

S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]

By Paul Ducklin β€” January 13th 2022 at 15:26
Latest episode -listen to it or read it now!

☐ β˜† βœ‡ Naked Security

Wormable Windows HTTP hole – what you need to know

By Paul Ducklin β€” January 12th 2022 at 16:24
One bug in the January 2022 Patch Tuesday list is getting lots of attention: "HTTP Protocol Stack Remote Code Execution Vulnerability".

☐ β˜† βœ‡ Naked Security

Home routers with NetUSB support could have critical kernel hole

By Paul Ducklin β€” January 11th 2022 at 17:42
Got a router that supports USB access across the network? You might need a kernel update...

☐ β˜† βœ‡ Naked Security

Log4Shell-like security hole found in popular Java SQL database engine H2

By Paul Ducklin β€” January 7th 2022 at 19:32
"It's Log4Shell, Jim, but not as we know it." How to find and fix a JNDI-based vuln in the H2 Database Engine.

☐ β˜† βœ‡ Naked Security

S3 Ep64: Log4Shell again, scammers keeping busy, and Apple Home bug [Podcast + Transcript]

By Paul Ducklin β€” January 6th 2022 at 19:44
We're back for 2022 - listen now!

☐ β˜† βœ‡ Naked Security

FTC threatens β€œlegal action” over unpatched Log4j and other vulns

By Paul Ducklin β€” January 5th 2022 at 19:37
Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's the FTC to refresh your memory!

☐ β˜† βœ‡ Naked Security

Apple Home software bug could lock you out of your iPhone

By Paul Ducklin β€” January 4th 2022 at 17:23
The finder of this bug insists it "poses a serious risk". We're not so sure, but we recommend you take steps to avoid it anyway.

☐ β˜† βœ‡ Naked Security

Log4Shell vulnerability Number Four: β€œMuch ado about something”

By Paul Ducklin β€” December 29th 2021 at 19:12
It's a Log4j bug, and you ought to patch it. But we don't think it's a critical crisis like the last one.

☐ β˜† βœ‡ Naked Security

SFW! The Top N CyberΒ­security Stories of 2021 (for small positive integer values of N)

By Paul Ducklin β€” December 24th 2021 at 17:44
Happy Holidays! Our Top N stories, all totally SFW!

☐ β˜† βœ‡ Naked Security

The cool retro phone with a REAL DIAL… plus plenty of IoT problems

By Paul Ducklin β€” December 23rd 2021 at 17:58
You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.

☐ β˜† βœ‡ Naked Security

Plundered bitcoins recovered by FBI – all 3,879-and-one-sixth of them!

By Paul Ducklin β€” December 22nd 2021 at 17:57
Phew! An audacious crime... that didn't work out.

☐ β˜† βœ‡ Naked Security

Apache’s other product: Critical bugs in β€˜httpd’ web server, patch now!

By Paul Ducklin β€” December 21st 2021 at 19:57
The Apache web server just got an update - this one is nothing to do with Log4j!

☐ β˜† βœ‡ Naked Security

Serious Security: OpenSSL fixes β€œerror conflation” bugs – how mixing up mistakes can lead to trouble

By Paul Ducklin β€” December 17th 2021 at 17:57
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!

☐ β˜† βœ‡ Naked Security

S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]

By Paul Ducklin β€” December 16th 2021 at 17:41
Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)

☐ β˜† βœ‡ Naked Security

Apple security updates are out – and not a Log4Shell mention in sight

By Paul Ducklin β€” December 14th 2021 at 12:55
Get 'em while they're hot!

☐ β˜† βœ‡ Naked Security

Log4Shell explained – how it works, why you need to know, and how to fix it

By Paul Ducklin β€” December 13th 2021 at 19:41
Find out how to deal with the Log4Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!

☐ β˜† βœ‡ Naked Security

β€œLog4Shell” Java vulnerability – how to safeguard your servers

By Paul Ducklin β€” December 10th 2021 at 19:22
Just when you thought it was safe to relax for the weekend... a critical bug showed up in Apache's Log4j product

☐ β˜† βœ‡ Naked Security

S3 Ep62: The S in IoT stands for security (and much more) [Podcast+Transcript]

By Paul Ducklin β€” December 9th 2021 at 17:40
Listen now or read as an article! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Firefox update brings a whole new sort of security sandbox

By Paul Ducklin β€” December 7th 2021 at 19:14
Firefox 95.0 is out, with the usual security fixes... plus some funky new ones.

☐ β˜† βœ‡ Naked Security

Cryptocurrency startup fails to subtract before adding, loses $31m

By Paul Ducklin β€” December 6th 2021 at 19:50
Think of a number, any number. Take away 42. Add 42 back in. Then pretend you didn't take away 42. How much is left?

☐ β˜† βœ‡ Naked Security

Mozilla patches critical β€œBigSig” cryptographic bug: Here’s how to track it down and fix it

By Paul Ducklin β€” December 3rd 2021 at 17:58
Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.

☐ β˜† βœ‡ Naked Security

S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]

By Paul Ducklin β€” December 2nd 2021 at 20:50
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

IoT devices must β€œprotect consumers from cyberharm”, says UK government

By Paul Ducklin β€” December 2nd 2021 at 19:10
"Must be at least THIS tall to go on ride" seems to be the starting point. Too little, too late? Or better than nothing?

☐ β˜† βœ‡ Naked Security

Clearview AI face-matching service set to be fined over $20m

By Paul Ducklin β€” November 30th 2021 at 19:13
Scraping data for a facial recognition service? "That's unlawful", concluded both the British and the Australians.

☐ β˜† βœ‡ Naked Security

Cloud Security: Don’t wait until your next bill to find out about an attack!

By Paul Ducklin β€” November 26th 2021 at 19:58
Cloud security is the best sort of altruism: you need to do it to protect yourself, but you help to protect everyone else at the same time.

☐ β˜† βœ‡ Naked Security

S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public [Podcast]

By Paul Ducklin β€” November 25th 2021 at 12:38
Latest episode - listen now! Solid cybersecurity advice in plain English.

☐ β˜† βœ‡ Naked Security

Check your patches – public exploit now out for critical Exchange bug

By Paul Ducklin β€” November 23rd 2021 at 14:36
It was a zero-day bug until Patch Tuesday, now there's an anyone-can-use-it exploit. Don't be the one who hasn't patched.

☐ β˜† βœ‡ Naked Security

GoDaddy admits to password breach: check your Managed WordPress site!

By Paul Ducklin β€” November 23rd 2021 at 00:35
GoDaddy found crooks in its network, and kicked them out - but not before they'd been in there for six weeks.

☐ β˜† βœ‡ Naked Security

Black Friday and Cyber Monday – here’s what you REALLY need to do!

By Paul Ducklin β€” November 22nd 2021 at 19:52
The world fills up with cybersecurity tips every year when Black Friday comes round. But what about the rest of the year?

☐ β˜† βœ‡ Naked Security

S3 Ep59: Emotet, an FBI hoax, Samba bugs, and a hijackable suitcase [Podcast]

By Paul Ducklin β€” November 18th 2021 at 15:00
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust [Podcast]

By Paul Ducklin β€” November 11th 2021 at 17:41
Latest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Patch Tuesday updates the Win 7 updater… for at most 1 more year of updates

By Paul Ducklin β€” November 10th 2021 at 19:45
The clock stopped long ago on Windows 7, except for those who paid for overtime. But there won't be any double overtime!

❌