FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

By Paul Ducklin β€” June 30th 2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!

☐ β˜† βœ‡ Naked Security

Firefox 102 fixes address bar spoofing security hole (and helps with Follina!)

By Paul Ducklin β€” June 29th 2022 at 16:11
Firefox squashes a bug that helped phishers, and brings its own helping hand to Microsoft's "Follina" saga.

☐ β˜† βœ‡ Naked Security

OpenSSL issues a bugfix for the previous bugfix

By Paul Ducklin β€” June 24th 2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

☐ β˜† βœ‡ Naked Security

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]

By Paul Ducklin β€” June 23rd 2022 at 11:08
Latest epsiode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers [Podcast]

By Paul Ducklin β€” June 16th 2022 at 16:52
Lastest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Follina gets fixed – but it’s not listed in the Patch Tuesday patches!

By Paul Ducklin β€” June 15th 2022 at 01:20
We tried it out to make sure, so you don't have to.

☐ β˜† βœ‡ Naked Security

You’re invited! Join us for a live walkthrough of the β€œFollina” story…

By Paul Ducklin β€” June 13th 2022 at 16:28
Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

☐ β˜† βœ‡ Naked Security

S3 Ep86: The crooks were in our network for HOW long?! [Podcast + Transcript]

By Paul Ducklin β€” June 9th 2022 at 13:07
Latest episode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

SSNDOB Market domains seized, identity theft β€œbrokerage” shut down

By Paul Ducklin β€” June 8th 2022 at 14:53
The online identity "brokerage" SSNDOB Market didn't want people to be in any doubt what it was selling.

☐ β˜† βœ‡ Naked Security

Know your enemy! Learn how cybercrime adversaries get in…

By Paul Ducklin β€” June 7th 2022 at 15:49
Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

☐ β˜† βœ‡ Naked Security

Atlassian announces 0-day hole in Confluence Server – update now!

By Paul Ducklin β€” June 3rd 2022 at 18:59
Zero-day announced - here's what you need to know

☐ β˜† βœ‡ Naked Security

Yet another zero-day (sort of) in Windows β€œsearch URL” handling

By Paul Ducklin β€” June 2nd 2022 at 19:39
More trouble with special-purpose URLs on Windows.

☐ β˜† βœ‡ Naked Security

S3 Ep85: Now THAT’S what I call a Microsoft Office exploit! [Podcast]

By Paul Ducklin β€” June 2nd 2022 at 18:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Firefox 101 is out, this time with no 0-day scares (but update anyway!)

By Paul Ducklin β€” June 1st 2022 at 14:31
After an intriguing month of Firefox releases, here's one with a bit less drama, probably to the collective relief of Mozilla's coders.

☐ β˜† βœ‡ Naked Security

Mysterious β€œFollina” zero-day hole in Office – here’s what to do!

By Paul Ducklin β€” May 30th 2022 at 23:01
News has emerged of a "feature" in Office that has been abused as a zero-day bug to run evil code. Turning off macros doesn't help!

☐ β˜† βœ‡ Naked Security

S3 Ep84: Government demand, Mozilla velocity, and Clearview fine [Podcast]

By Paul Ducklin β€” May 27th 2022 at 11:17
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

☐ β˜† βœ‡ Naked Security

Mozilla patches Wednesday’s Pwn2Own double-exploit… on Friday!

By Paul Ducklin β€” May 20th 2022 at 23:47
That was quick! 48 hours from exploit report to published patch.

☐ β˜† βœ‡ Naked Security

Microsoft patches the Patch Tuesday patch that broke authentication

By Paul Ducklin β€” May 20th 2022 at 22:35
Remember the good old days when security patches rarely needed patches? Because security patches themlelves were rare enough anyway?

☐ β˜† βœ‡ Naked Security

US Government says: Patch VMware right now, or get off our network

By Paul Ducklin β€” May 20th 2022 at 14:03
Find and patch. Right now. If you can't patch, get it off the network. Right now! Oh, and show us what you did to comply.

☐ β˜† βœ‡ Naked Security

S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns [Podcast]

By Paul Ducklin β€” May 19th 2022 at 13:56
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Pwn2Own hacking schedule released – Windows and Linux are top targets

By Paul Ducklin β€” May 18th 2022 at 13:04
What's better? Disclose early, patch fast? Or dig deep, disclose in full, patch more slowly?

☐ β˜† βœ‡ Naked Security

Apple patches zero-day kernel hole and much more – update now!

By Paul Ducklin β€” May 17th 2022 at 09:30
You'll find fixes for numerous kernel-level code execution holes, including an 0-day vulnerability in many (though not all) versions.

☐ β˜† βœ‡ Naked Security

S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) [Podcast]

By Paul Ducklin β€” May 12th 2022 at 15:46
Latest episode - lots to learn - plain English - fun with a serious side - listen now!

☐ β˜† βœ‡ Naked Security

Serious Security: Learning from curl’s latest bug update

By Paul Ducklin β€” May 12th 2022 at 15:08
Learn how to write plain-speaking and purposeful security advisories from one of the most widely-used open source tools in the world.

☐ β˜† βœ‡ Naked Security

RubyGems supply chain rip-and-replace bug fixed – check your logs!

By Paul Ducklin β€” May 9th 2022 at 15:41
Imagine if you could assume the identity of, say, Franklin Delano Roosevelt simply by showing up and calling yourself "Frank".

ruby-1200

☐ β˜† βœ‡ Naked Security

You didn’t leave enough space between ROSE and AND, and AND and CROWN

By Paul Ducklin β€” May 6th 2022 at 16:59
What weird Google Docs bug connects the words THEREFORE, AND, SECONDLY, WHY, BUT and BESIDES?

☐ β˜† βœ‡ Naked Security

S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms [Podcast]

By Paul Ducklin β€” May 5th 2022 at 14:16
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

World Password Day – the 1960s just called and gave you your passwords back

By Paul Ducklin β€” May 5th 2022 at 01:06
Yes, passwords are going away. No, it won't happen tomorrow. So it's still worth knowing the basics of picking proper passwords.

☐ β˜† βœ‡ Naked Security

Android monthly updates are out – critical bugs found in critical places!

By Paul Ducklin β€” May 4th 2022 at 15:54
Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

☐ β˜† βœ‡ Naked Security

Firefox hits 100*, fixes bugs… but no new zero-days this month

By Paul Ducklin β€” May 3rd 2022 at 16:42
Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.

☐ β˜† βœ‡ Naked Security

GitHub issues final report on supply-chain source code intrusions

By Paul Ducklin β€” April 29th 2022 at 16:15
Learn how to find out which apps you've given access rights to, and how to revoke those rights immediately in an emergency.

☐ β˜† βœ‡ Naked Security

S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java [Podcast]

By Paul Ducklin β€” April 28th 2022 at 13:18
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Ransomware Survey 2022 – like the Curate’s Egg, β€œgood in parts”

By Paul Ducklin β€” April 27th 2022 at 15:22
You might not like the headline statistics in this year's ransomware report... but that makes it even more important to take a look!

☐ β˜† βœ‡ Naked Security

QNAP warns of new bugs in its Network Attached Storage devices

By Paul Ducklin β€” April 22nd 2022 at 15:15
Here's what you need to know - plus some sensible advice for all the devices on your home or small biz network!

nas-1200

☐ β˜† βœ‡ Naked Security

S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]

By Paul Ducklin β€” April 21st 2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

Beanstalk cryptocurrency heist: scammer votes himself all the money

By Paul Ducklin β€” April 19th 2022 at 16:00
Voting safeguards based on commuity collateral don't work if one person can use a momentary loan to "become" 75% of the community.

☐ β˜† βœ‡ Naked Security

Yet another Chrome zero-day emergency update – patch now!

By Paul Ducklin β€” April 16th 2022 at 00:33
The third emergency Chrome 0-day in three months - the first one was exploited by North Korea, so you might as well get this one ASAP.

☐ β˜† βœ‡ Naked Security

S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]

By Paul Ducklin β€” April 14th 2022 at 13:39
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Hospital robot system gets five critical security holes patched

By Paul Ducklin β€” April 12th 2022 at 18:58
Fortunately, we're not talking about a robot revolution, or about hospital AI run amuck. But these bugs could lead to ransomware, or worse...

☐ β˜† βœ‡ Naked Security

Popular Ruby Asciidoc toolkit patched against critical vuln – get the update now!

By Paul Ducklin β€” April 8th 2022 at 15:38
A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.

ruby-1200

☐ β˜† βœ‡ Naked Security

S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]

By Paul Ducklin β€” April 7th 2022 at 12:24
Latest episode - listen now! Cybersecurity news and advice in plain English.

☐ β˜† βœ‡ Naked Security

Firefox 99 is out – no major bugs, but update anyway!

By Paul Ducklin β€” April 5th 2022 at 16:21
Firefox's four-weekly updates just dropped - here's what you need to know.

☐ β˜† βœ‡ Naked Security

Google’s monthly Android updates patch numerous β€œget root” holes

By Paul Ducklin β€” April 5th 2022 at 14:44
Get the update now... if it's available for your phone. Here's how to check.

android-1200

☐ β˜† βœ‡ Naked Security

Apple pushes out two emergency 0-day updates – get ’em now!

By Paul Ducklin β€” March 31st 2022 at 23:38
More Apple zero-days - mobile devices, laptops and desktops affected. Update now!

apple-1200

☐ β˜† βœ‡ Naked Security

S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast]

By Paul Ducklin β€” March 31st 2022 at 13:38
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Zlib data compressor fixes 17-year-old security bug – patch, errrm, now

By Paul Ducklin β€” March 29th 2022 at 16:37
This code is venerable! Surely all the bugs must be out by now?

☐ β˜† βœ‡ Naked Security

Google Chrome patches mysterious new zero-day bug – update now

By Paul Ducklin β€” March 28th 2022 at 14:18
CVE-2022-1096 - another mystery in-the-wild 0-day in Chrome... check your version now!

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Serious Security: DEADBOLT – the ransomware that goes straight for your backups

By Paul Ducklin β€” March 23rd 2022 at 19:58
Some tips on how to keep your network safe - even (or perhaps especially!) if you think you're safe already.

☐ β˜† βœ‡ Naked Security

OpenSSL patches infinite-loop DoS bug in certificate verification

By Paul Ducklin β€” March 18th 2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!

☐ β˜† βœ‡ Naked Security

S3 Ep74: Cybercrime busts, Apple patches, Pi Day, and disconnect effects [Podcast]

By Paul Ducklin β€” March 17th 2022 at 13:32
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

CISA warning: β€œRussian actors bypassed 2FA” – what happened and how to avoid it

By Paul Ducklin β€” March 16th 2022 at 01:22
Don't leave old accounts lying around where someone sketchy could reactivate them.

☐ β˜† βœ‡ Naked Security

Apple patches 87 security holes – from iPhones and Macs to Windows

By Paul Ducklin β€” March 15th 2022 at 16:36
Lots of fixes, with data leakage flaws and code execution bugs patched on iPhones, Macs and even Windows.

apple-1200

☐ β˜† βœ‡ Naked Security

S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast + Transcript]

By Paul Ducklin β€” March 10th 2022 at 19:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

β€œDirty Pipe” Linux kernel bug lets anyone write to any file

By Paul Ducklin β€” March 8th 2022 at 19:37
Even read-only files can be written to, leading to a dangerously general purpose elevation-of-privilege attack.

pipe-1200

☐ β˜† βœ‡ Naked Security

Adafruit suffers GitHub data breach – don’t let this happen to you

By Paul Ducklin β€” March 7th 2022 at 12:47
Training data stashed in GitHub by mistake... unfortunately, it was *real* data

☐ β˜† βœ‡ Naked Security

Firefox patches two actively exploited 0-day holes: update now!

By Paul Ducklin β€” March 5th 2022 at 19:06
Firefox just published a double-zero-day patch - "remote code execution" combined with "sandbox escape". Update now!

❌