FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Who’s watching your webcam? The Screencastify Chrome extension story…

By Paul Ducklin β€” May 26th 2022 at 12:41
When you really need to make exceptions in cybersecurity, specify them as explicitly as you can.

☐ β˜† βœ‡ Naked Security

Microsoft patches the Patch Tuesday patch that broke authentication

By Paul Ducklin β€” May 20th 2022 at 22:35
Remember the good old days when security patches rarely needed patches? Because security patches themlelves were rare enough anyway?

☐ β˜† βœ‡ Naked Security

He sold cracked passwords for a living – now he’s serving 4 years in prison

By Paul Ducklin β€” May 13th 2022 at 18:31
Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...

☐ β˜† βœ‡ Naked Security

S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]

By Paul Ducklin β€” April 21st 2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

Beanstalk cryptocurrency heist: scammer votes himself all the money

By Paul Ducklin β€” April 19th 2022 at 16:00
Voting safeguards based on commuity collateral don't work if one person can use a momentary loan to "become" 75% of the community.

☐ β˜† βœ‡ Naked Security

S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]

By Paul Ducklin β€” April 14th 2022 at 13:39
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

US cryptocurrency coder gets 5 years for North Korea sanctions busting

By Naked Security writer β€” April 13th 2022 at 15:52
Cryptocurrency expert didn't take "No" for an answer when the US authorities said he couldn't pursue cryptocoin opps in North Korea.

☐ β˜† βœ‡ Naked Security

OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default

By Paul Ducklin β€” April 11th 2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?

cat-1200

☐ β˜† βœ‡ Naked Security

Serious Security: Darkweb drugs market Hydra taken offline by German police

By Paul Ducklin β€” April 6th 2022 at 16:22
Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...

☐ β˜† βœ‡ Naked Security

LAPSUS$ hacks continue despite two hacker suspects in court

By Paul Ducklin β€” April 4th 2022 at 21:36
Do you know where in your company to report security anomalies? If you receive such reports, do you have an efficient way to process them?

☐ β˜† βœ‡ Naked Security

UK police arrest 7 hacking suspects – have they bust the LAPSUS$ gang?

By Naked Security writer β€” March 25th 2022 at 01:48
Seven alleged hackers have been arrested in the UK. But who are they, and which hacking crew are they from?

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

OpenSSL patches infinite-loop DoS bug in certificate verification

By Paul Ducklin β€” March 18th 2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!

☐ β˜† βœ‡ Naked Security

Beware bogus Betas – cryptocoin scammers abuse Apple’s TestFlight system

By Paul Ducklin β€” March 16th 2022 at 15:49
"Install this moneymaking app" - this one is so special that it isn't available on Google Play or the App Store!

☐ β˜† βœ‡ Naked Security

Cryptocoin ATMs ruled illegal – β€œShut down at once”, says regulator

By Paul Ducklin β€” March 14th 2022 at 17:51
If you live in the UK and hadn't yet heard of cryptocoin ATMs... it's too late now!

☐ β˜† βœ‡ Naked Security

Alleged Kaseya ransomware attacker arrives in Texas for trial

By Naked Security writer β€” March 11th 2022 at 14:59
The US Independence Day weekend of 2021 wasn't much of a holiday for cybersecurity staff. That was when the Kaseya attack unfolded...

☐ β˜† βœ‡ Naked Security

Ransomware with a difference: β€œDerestrict your software, or else!”

By Paul Ducklin β€” March 2nd 2022 at 16:33
"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.

☐ β˜† βœ‡ Naked Security

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]

By Paul Ducklin β€” February 24th 2022 at 16:51
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

French speakers blasted by sextortion scams with no text or links

By Paul Ducklin β€” February 21st 2022 at 17:59
You'd spot this one a mile away... but what about your friends or family?

☐ β˜† βœ‡ Naked Security

S3 Ep70: Bitcoin, billing blunders, and 0-day after 0-day after 0-day [Podcast + Transcript]

By Paul Ducklin β€” February 17th 2022 at 17:12
Latest episode - listen and learn!

☐ β˜† βœ‡ Naked Security

S3 Ep69: WordPress woes, Wormhole holes, and a Microsoft change of heart [Podcast + Transcript]

By Paul Ducklin β€” February 10th 2022 at 01:15
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Self-styled β€œCrocodile of Wall Street” arrested with husband over Bitcoin megaheist

By Naked Security writer β€” February 9th 2022 at 14:44
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!

☐ β˜† βœ‡ Naked Security

Wormhole cryptotrading company turns over $340,000,000 to criminals

By Paul Ducklin β€” February 4th 2022 at 17:38
It was the best of blockchains, it was the worst of blockchains... as Charles Dickens might have said.

☐ β˜† βœ‡ Naked Security

S3 Ep67: Tax scams, carder busts and crypto capers [Podcast + Transcript]

By Paul Ducklin β€” January 27th 2022 at 19:57
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft

By Paul Ducklin β€” January 21st 2022 at 16:25
The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.

☐ β˜† βœ‡ Naked Security

S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript]

By Paul Ducklin β€” January 20th 2022 at 17:28
Latest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Serious Security: Linux full-disk encryption bug fixed – patch now!

By Paul Ducklin β€” January 14th 2022 at 21:58
Imagine if someone who didn't have your password could sneakily modify data that was encrypted with it.

☐ β˜† βœ‡ Naked Security

SFW! The Top N CyberΒ­security Stories of 2021 (for small positive integer values of N)

By Paul Ducklin β€” December 24th 2021 at 17:44
Happy Holidays! Our Top N stories, all totally SFW!

☐ β˜† βœ‡ Naked Security

The cool retro phone with a REAL DIAL… plus plenty of IoT problems

By Paul Ducklin β€” December 23rd 2021 at 17:58
You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.

☐ β˜† βœ‡ Naked Security

Plundered bitcoins recovered by FBI – all 3,879-and-one-sixth of them!

By Paul Ducklin β€” December 22nd 2021 at 17:57
Phew! An audacious crime... that didn't work out.

☐ β˜† βœ‡ Naked Security

Serious Security: OpenSSL fixes β€œerror conflation” bugs – how mixing up mistakes can lead to trouble

By Paul Ducklin β€” December 17th 2021 at 17:57
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!

☐ β˜† βœ‡ Naked Security

Cryptocurrency startup fails to subtract before adding, loses $31m

By Paul Ducklin β€” December 6th 2021 at 19:50
Think of a number, any number. Take away 42. Add 42 back in. Then pretend you didn't take away 42. How much is left?

☐ β˜† βœ‡ Naked Security

Mozilla patches critical β€œBigSig” cryptographic bug: Here’s how to track it down and fix it

By Paul Ducklin β€” December 3rd 2021 at 17:58
Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.

☐ β˜† βœ‡ Naked Security

Cloud Security: Don’t wait until your next bill to find out about an attack!

By Paul Ducklin β€” November 26th 2021 at 19:58
Cloud security is the best sort of altruism: you need to do it to protect yourself, but you help to protect everyone else at the same time.

☐ β˜† βœ‡ Naked Security

Samba update patches plaintext password plundering problem

By Paul Ducklin β€” November 12th 2021 at 19:59
When Microsoft itself says STOP USING X, where X is one of its own protocols... we think you should listen.

☐ β˜† βœ‡ Naked Security

S3 Ep56: Cryptotrading rodent, ransomware hackback, and a Docusign phish [Podcast]

By Paul Ducklin β€” October 28th 2021 at 18:45
Latest episode - listen now! Serious security explained with personality in plain English.

ns-1200-logo-podcast-with-mic-and-rodent-emoji

☐ β˜† βœ‡ Naked Security

S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts]

By Paul Ducklin β€” October 21st 2021 at 18:13
Latest episode - listen now! (And sign up for our forthcoming Live Malware Demo at the same time.)

☐ β˜† βœ‡ Naked Security

β€œTo the moon!” Cryptocurrency hamster Mr Goxx trades online 24/7

By Paul Ducklin β€” October 20th 2021 at 18:07
Here's a happy cryptocurrency story for once, with not a cybercrook in sight.

❌