Login
FreshRSS
Login
Naked Security
S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns [Podcast]
By
Paul Ducklin
β May 19
th
2022 at 13:56
Latest episode - listen now!
Naked Security
Pwn2Own hacking schedule released β Windows and Linux are top targets
By
Paul Ducklin
β May 18
th
2022 at 13:04
What's better? Disclose early, patch fast? Or dig deep, disclose in full, patch more slowly?
Naked Security
Apple patches zero-day kernel hole and much more β update now!
By
Paul Ducklin
β May 17
th
2022 at 09:30
You'll find fixes for numerous kernel-level code execution holes, including an 0-day vulnerability in many (though not all) versions.
Naked Security
Firefox out-of-band update to 100.0.1 β just in time for Pwn2Own?
By
Paul Ducklin
β May 15
th
2022 at 21:53
A new point-release of Firefox. Not unusual, but the timing of this one is interesting, with Pwn2Own coming up in a few days.
Naked Security
He sold cracked passwords for a living β now heβs serving 4 years in prison
By
Paul Ducklin
β May 13
th
2022 at 18:31
Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...
Naked Security
S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) [Podcast]
By
Paul Ducklin
β May 12
th
2022 at 15:46
Latest episode - lots to learn - plain English - fun with a serious side - listen now!
Naked Security
Serious Security: Learning from curlβs latest bug update
By
Paul Ducklin
β May 12
th
2022 at 15:08
Learn how to write plain-speaking and purposeful security advisories from one of the most widely-used open source tools in the world.
Naked Security
Colonial Pipeline facing $1,000,000 fine for poor recovery plans
By
Paul Ducklin
β May 10
th
2022 at 16:59
How good is your cybersecurity? Are you making the same mistakes as lots of other people? Here's some real-life advice...
Naked Security
RubyGems supply chain rip-and-replace bug fixed β check your logs!
By
Paul Ducklin
β May 9
th
2022 at 15:41
Imagine if you could assume the identity of, say, Franklin Delano Roosevelt simply by showing up and calling yourself "Frank".
ruby-1200
Naked Security
You didnβt leave enough space between ROSE and AND, and AND and CROWN
By
Paul Ducklin
β May 6
th
2022 at 16:59
What weird Google Docs bug connects the words THEREFORE, AND, SECONDLY, WHY, BUT and BESIDES?
Naked Security
S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms [Podcast]
By
Paul Ducklin
β May 5
th
2022 at 14:16
Latest episode - listen now!
Naked Security
World Password Day β the 1960s just called and gave you your passwords back
By
Paul Ducklin
β May 5
th
2022 at 01:06
Yes, passwords are going away. No, it won't happen tomorrow. So it's still worth knowing the basics of picking proper passwords.
Naked Security
Android monthly updates are out β critical bugs found in critical places!
By
Paul Ducklin
β May 4
th
2022 at 15:54
Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...
Naked Security
Firefox hits 100*, fixes bugs⦠but no new zero-days this month
By
Paul Ducklin
β May 3
rd
2022 at 16:42
Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.
Naked Security
GitHub issues final report on supply-chain source code intrusions
By
Paul Ducklin
β April 29
th
2022 at 16:15
Learn how to find out which apps you've given access rights to, and how to revoke those rights immediately in an emergency.
Naked Security
S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java [Podcast]
By
Paul Ducklin
β April 28
th
2022 at 13:18
Latest episode - listen now!
Naked Security
Ransomware Survey 2022 β like the Curateβs Egg, βgood in partsβ
By
Paul Ducklin
β April 27
th
2022 at 15:22
You might not like the headline statistics in this year's ransomware report... but that makes it even more important to take a look!
Naked Security
Phishing goes KISS: Donβt let plain and simple messages catch you out!
By
Paul Ducklin
β April 25
th
2022 at 16:58
Sometimes we receive phishing tricks that we grudgingly have to admit are better than average, just because they're uncomplicated.
Naked Security
QNAP warns of new bugs in its Network Attached Storage devices
By
Paul Ducklin
β April 22
nd
2022 at 15:15
Here's what you need to know - plus some sensible advice for all the devices on your home or small biz network!
nas-1200
Naked Security
S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]
By
Paul Ducklin
β April 21
st
2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!
Naked Security
Critical cryptographic Java security blunder patched β update now!
By
Paul Ducklin
β April 20
th
2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.
Naked Security
Beanstalk cryptocurrency heist: scammer votes himself all the money
By
Paul Ducklin
β April 19
th
2022 at 16:00
Voting safeguards based on commuity collateral don't work if one person can use a momentary loan to "become" 75% of the community.
Naked Security
Yet another Chrome zero-day emergency update β patch now!
By
Paul Ducklin
β April 16
th
2022 at 00:33
The third emergency Chrome 0-day in three months - the first one was exploited by North Korea, so you might as well get this one ASAP.
Naked Security
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
By
Paul Ducklin
β April 14
th
2022 at 13:39
Latest episode - listen now!
Naked Security
US cryptocurrency coder gets 5 years for North Korea sanctions busting
By
Naked Security writer
β April 13
th
2022 at 15:52
Cryptocurrency expert didn't take "No" for an answer when the US authorities said he couldn't pursue cryptocoin opps in North Korea.
Naked Security
Hospital robot system gets five critical security holes patched
By
Paul Ducklin
β April 12
th
2022 at 18:58
Fortunately, we're not talking about a robot revolution, or about hospital AI run amuck. But these bugs could lead to ransomware, or worse...
Naked Security
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
By
Paul Ducklin
β April 11
th
2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?
cat-1200
Naked Security
Popular Ruby Asciidoc toolkit patched against critical vuln β get the update now!
By
Paul Ducklin
β April 8
th
2022 at 15:38
A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.
ruby-1200
Naked Security
S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]
By
Paul Ducklin
β April 7
th
2022 at 12:24
Latest episode - listen now! Cybersecurity news and advice in plain English.
Naked Security
Serious Security: Darkweb drugs market Hydra taken offline by German police
By
Paul Ducklin
β April 6
th
2022 at 16:22
Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...
Naked Security
Firefox 99 is out β no major bugs, but update anyway!
By
Paul Ducklin
β April 5
th
2022 at 16:21
Firefox's four-weekly updates just dropped - here's what you need to know.
Naked Security
Googleβs monthly Android updates patch numerous βget rootβ holes
By
Paul Ducklin
β April 5
th
2022 at 14:44
Get the update now... if it's available for your phone. Here's how to check.
android-1200
Naked Security
LAPSUS$ hacks continue despite two hacker suspects in court
By
Paul Ducklin
β April 4
th
2022 at 21:36
Do you know where in your company to report security anomalies? If you receive such reports, do you have an efficient way to process them?
Naked Security
Apple pushes out two emergency 0-day updates β get βem now!
By
Paul Ducklin
β March 31
st
2022 at 23:38
More Apple zero-days - mobile devices, laptops and desktops affected. Update now!
apple-1200
Naked Security
Two different βVMware Springβ bugs at large β we cut through the confusion
By
Paul Ducklin
β March 31
st
2022 at 16:59
Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion
Naked Security
S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast]
By
Paul Ducklin
β March 31
st
2022 at 13:38
Latest episode - listen now!
Naked Security
βVMware Spring Cloud Functionβ Java bug gives instant remote code execution β update now!
By
Paul Ducklin
β March 30
th
2022 at 20:38
Easy unauthenticated remote code execution - PoC code already out
Naked Security
World Backup Day: 5 data recovery tips for everyone!
By
Paul Ducklin
β March 30
th
2022 at 15:10
The only backup you will ever regret is the one you didn't make
Naked Security
Zlib data compressor fixes 17-year-old security bug β patch, errrm, now
By
Paul Ducklin
β March 29
th
2022 at 16:37
This code is venerable! Surely all the bugs must be out by now?
Naked Security
Google Chrome patches mysterious new zero-day bug β update now
By
Paul Ducklin
β March 28
th
2022 at 14:18
CVE-2022-1096 - another mystery in-the-wild 0-day in Chrome... check your version now!
Naked Security
UK police arrest 7 hacking suspects β have they bust the LAPSUS$ gang?
By
Naked Security writer
β March 25
th
2022 at 01:48
Seven alleged hackers have been arrested in the UK. But who are they, and which hacking crew are they from?
Naked Security
S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]
By
Paul Ducklin
β March 24
th
2022 at 13:49
Latest episode - listen now!
Naked Security
Serious Security: DEADBOLT β the ransomware that goes straight for your backups
By
Paul Ducklin
β March 23
rd
2022 at 19:58
Some tips on how to keep your network safe - even (or perhaps especially!) if you think you're safe already.
Naked Security
Web vendor CafePress fined $500,000 for giving cybersecurity a low value
By
Paul Ducklin
β March 21
st
2022 at 16:55
Just because you're the victim of a cybercrime doesn't let you off your cybersecurity obligations
Naked Security
OpenSSL patches infinite-loop DoS bug in certificate verification
By
Paul Ducklin
β March 18
th
2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!
Naked Security
S3 Ep74: Cybercrime busts, Apple patches, Pi Day, and disconnect effects [Podcast]
By
Paul Ducklin
β March 17
th
2022 at 13:32
Latest episode - listen now!
Naked Security
Beware bogus Betas β cryptocoin scammers abuse Appleβs TestFlight system
By
Paul Ducklin
β March 16
th
2022 at 15:49
"Install this moneymaking app" - this one is so special that it isn't available on Google Play or the App Store!
Naked Security
CISA warning: βRussian actors bypassed 2FAβ β what happened and how to avoid it
By
Paul Ducklin
β March 16
th
2022 at 01:22
Don't leave old accounts lying around where someone sketchy could reactivate them.
Naked Security
Apple patches 87 security holes β from iPhones and Macs to Windows
By
Paul Ducklin
β March 15
th
2022 at 16:36
Lots of fixes, with data leakage flaws and code execution bugs patched on iPhones, Macs and even Windows.
apple-1200
Naked Security
Happy #PiDay β even if you arenβt in North America!
By
Paul Ducklin
β March 14
th
2022 at 23:59
There is a cybersecurity angle here - but you will need to read right to the end to find it :-)
Naked Security
Cryptocoin ATMs ruled illegal β βShut down at onceβ, says regulator
By
Paul Ducklin
β March 14
th
2022 at 17:51
If you live in the UK and hadn't yet heard of cryptocoin ATMs... it's too late now!
Naked Security
Alleged Kaseya ransomware attacker arrives in Texas for trial
By
Naked Security writer
β March 11
th
2022 at 14:59
The US Independence Day weekend of 2021 wasn't much of a holiday for cybersecurity staff. That was when the Kaseya attack unfolded...
Naked Security
S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast + Transcript]
By
Paul Ducklin
β March 10
th
2022 at 19:37
Latest episode - listen now!
Naked Security
βDirty Pipeβ Linux kernel bug lets anyone write to any file
By
Paul Ducklin
β March 8
th
2022 at 19:37
Even read-only files can be written to, leading to a dangerously general purpose elevation-of-privilege attack.
pipe-1200
Naked Security
Adafruit suffers GitHub data breach β donβt let this happen to you
By
Paul Ducklin
β March 7
th
2022 at 12:47
Training data stashed in GitHub by mistake... unfortunately, it was *real* data
Naked Security
Firefox patches two actively exploited 0-day holes: update now!
By
Paul Ducklin
β March 5
th
2022 at 19:06
Firefox just published a double-zero-day patch - "remote code execution" combined with "sandbox escape". Update now!
Naked Security
S3 Ep72: AirTag stalking, web server coding woes and Instascams [Podcast + Transcript]
By
Paul Ducklin
β March 3
rd
2022 at 14:04
Latest episode - listen now (or read it, if that's your preference)...
Naked Security
Ransomware with a difference: βDerestrict your software, or else!β
By
Paul Ducklin
β March 2
nd
2022 at 16:33
"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.
Naked Security
Instagram scammers as busy as ever: passwords and 2FA codes at risk
By
Paul Ducklin
β February 28
th
2022 at 17:56
Instagram scams don't seem to be dying out - we're seeing more variety and trickiness than ever...
Naked Security
Did we learn nothing from Y2K? Why are some coders still stuck on two digit numbers?
By
Paul Ducklin
β February 25
th
2022 at 17:59
Calling all website coders: Y2K was then. V1H is now!
Load more articles