FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

S3 Ep93: Office security, breach costs, and leisurely patches [Audio + Text]

By Paul Ducklin β€” July 28th 2022 at 15:47
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Critical Samba bug could let anyone become Domain Admin – patch now!

By Paul Ducklin β€” July 27th 2022 at 21:15
It's a serious bug... but there's a fix for it, so you know exactly what to do!

☐ β˜† βœ‡ Naked Security

Mild monthly security update from Firefox – but update anyway

By Paul Ducklin β€” July 27th 2022 at 00:41
You're probably thinking we're going to say, "Don't delay/Do it today"... and that's exactly what we are saying!

☐ β˜† βœ‡ Naked Security

Apple patches β€œ0-day” browser bug fixed 2 weeks ago in Chrome, Edge

By Paul Ducklin β€” July 21st 2022 at 12:38
One vendor's zero-day is another vendor's routine patch...

☐ β˜† βœ‡ Naked Security

8 months on, US says Log4Shell will be around for β€œa decade or longer”

By Paul Ducklin β€” July 18th 2022 at 16:57
When it comes to cybersecurity, ask not what everyone else can do for you...

☐ β˜† βœ‡ Naked Security

Apache β€œCommons Configuration” patches Log4Shell-style bug – what you need to know

By Paul Ducklin β€” July 8th 2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.

☐ β˜† βœ‡ Naked Security

S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]

By Paul Ducklin β€” July 7th 2022 at 18:46
Listen now! Or read if you prefer...

☐ β˜† βœ‡ Naked Security

OpenSSL fixes two β€œone-liner” crypto bugs – what you need to know

By Paul Ducklin β€” July 6th 2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...

☐ β˜† βœ‡ Naked Security

Google patches β€œin-the-wild” Chrome zero-day – update now!

By Paul Ducklin β€” July 5th 2022 at 15:55
Running Chrome? Do the "Help-About-Update" dance move right now, just to be sure...

☐ β˜† βœ‡ Naked Security

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

By Paul Ducklin β€” June 30th 2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!

☐ β˜† βœ‡ Naked Security

Firefox 102 fixes address bar spoofing security hole (and helps with Follina!)

By Paul Ducklin β€” June 29th 2022 at 16:11
Firefox squashes a bug that helped phishers, and brings its own helping hand to Microsoft's "Follina" saga.

☐ β˜† βœ‡ Naked Security

OpenSSL issues a bugfix for the previous bugfix

By Paul Ducklin β€” June 24th 2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

☐ β˜† βœ‡ Naked Security

S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers [Podcast]

By Paul Ducklin β€” June 16th 2022 at 16:52
Lastest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Follina gets fixed – but it’s not listed in the Patch Tuesday patches!

By Paul Ducklin β€” June 15th 2022 at 01:20
We tried it out to make sure, so you don't have to.

☐ β˜† βœ‡ Naked Security

You’re invited! Join us for a live walkthrough of the β€œFollina” story…

By Paul Ducklin β€” June 13th 2022 at 16:28
Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

☐ β˜† βœ‡ Naked Security

S3 Ep86: The crooks were in our network for HOW long?! [Podcast + Transcript]

By Paul Ducklin β€” June 9th 2022 at 13:07
Latest episode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Know your enemy! Learn how cybercrime adversaries get in…

By Paul Ducklin β€” June 7th 2022 at 15:49
Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

☐ β˜† βœ‡ Naked Security

Atlassian announces 0-day hole in Confluence Server – update now!

By Paul Ducklin β€” June 3rd 2022 at 18:59
Zero-day announced - here's what you need to know

☐ β˜† βœ‡ Naked Security

Yet another zero-day (sort of) in Windows β€œsearch URL” handling

By Paul Ducklin β€” June 2nd 2022 at 19:39
More trouble with special-purpose URLs on Windows.

☐ β˜† βœ‡ Naked Security

S3 Ep85: Now THAT’S what I call a Microsoft Office exploit! [Podcast]

By Paul Ducklin β€” June 2nd 2022 at 18:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Firefox 101 is out, this time with no 0-day scares (but update anyway!)

By Paul Ducklin β€” June 1st 2022 at 14:31
After an intriguing month of Firefox releases, here's one with a bit less drama, probably to the collective relief of Mozilla's coders.

☐ β˜† βœ‡ Naked Security

Mysterious β€œFollina” zero-day hole in Office – here’s what to do!

By Paul Ducklin β€” May 30th 2022 at 23:01
News has emerged of a "feature" in Office that has been abused as a zero-day bug to run evil code. Turning off macros doesn't help!

☐ β˜† βœ‡ Naked Security

S3 Ep84: Government demand, Mozilla velocity, and Clearview fine [Podcast]

By Paul Ducklin β€” May 27th 2022 at 11:17
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

☐ β˜† βœ‡ Naked Security

Mozilla patches Wednesday’s Pwn2Own double-exploit… on Friday!

By Paul Ducklin β€” May 20th 2022 at 23:47
That was quick! 48 hours from exploit report to published patch.

☐ β˜† βœ‡ Naked Security

Microsoft patches the Patch Tuesday patch that broke authentication

By Paul Ducklin β€” May 20th 2022 at 22:35
Remember the good old days when security patches rarely needed patches? Because security patches themlelves were rare enough anyway?

☐ β˜† βœ‡ Naked Security

US Government says: Patch VMware right now, or get off our network

By Paul Ducklin β€” May 20th 2022 at 14:03
Find and patch. Right now. If you can't patch, get it off the network. Right now! Oh, and show us what you did to comply.

☐ β˜† βœ‡ Naked Security

S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns [Podcast]

By Paul Ducklin β€” May 19th 2022 at 13:56
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Pwn2Own hacking schedule released – Windows and Linux are top targets

By Paul Ducklin β€” May 18th 2022 at 13:04
What's better? Disclose early, patch fast? Or dig deep, disclose in full, patch more slowly?

☐ β˜† βœ‡ Naked Security

Apple patches zero-day kernel hole and much more – update now!

By Paul Ducklin β€” May 17th 2022 at 09:30
You'll find fixes for numerous kernel-level code execution holes, including an 0-day vulnerability in many (though not all) versions.

☐ β˜† βœ‡ Naked Security

Serious Security: Learning from curl’s latest bug update

By Paul Ducklin β€” May 12th 2022 at 15:08
Learn how to write plain-speaking and purposeful security advisories from one of the most widely-used open source tools in the world.

☐ β˜† βœ‡ Naked Security

RubyGems supply chain rip-and-replace bug fixed – check your logs!

By Paul Ducklin β€” May 9th 2022 at 15:41
Imagine if you could assume the identity of, say, Franklin Delano Roosevelt simply by showing up and calling yourself "Frank".

ruby-1200

☐ β˜† βœ‡ Naked Security

You didn’t leave enough space between ROSE and AND, and AND and CROWN

By Paul Ducklin β€” May 6th 2022 at 16:59
What weird Google Docs bug connects the words THEREFORE, AND, SECONDLY, WHY, BUT and BESIDES?

☐ β˜† βœ‡ Naked Security

Android monthly updates are out – critical bugs found in critical places!

By Paul Ducklin β€” May 4th 2022 at 15:54
Android May 2022 updates are out - with some critical fixes in some critical places. Learn more...

☐ β˜† βœ‡ Naked Security

Firefox hits 100*, fixes bugs… but no new zero-days this month

By Paul Ducklin β€” May 3rd 2022 at 16:42
Despite concerns that some websites might break when Chromium and then Firefox reached version 100, the web still seems to be intact.

☐ β˜† βœ‡ Naked Security

QNAP warns of new bugs in its Network Attached Storage devices

By Paul Ducklin β€” April 22nd 2022 at 15:15
Here's what you need to know - plus some sensible advice for all the devices on your home or small biz network!

nas-1200

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

Beanstalk cryptocurrency heist: scammer votes himself all the money

By Paul Ducklin β€” April 19th 2022 at 16:00
Voting safeguards based on commuity collateral don't work if one person can use a momentary loan to "become" 75% of the community.

☐ β˜† βœ‡ Naked Security

Yet another Chrome zero-day emergency update – patch now!

By Paul Ducklin β€” April 16th 2022 at 00:33
The third emergency Chrome 0-day in three months - the first one was exploited by North Korea, so you might as well get this one ASAP.

☐ β˜† βœ‡ Naked Security

S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]

By Paul Ducklin β€” April 14th 2022 at 13:39
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Hospital robot system gets five critical security holes patched

By Paul Ducklin β€” April 12th 2022 at 18:58
Fortunately, we're not talking about a robot revolution, or about hospital AI run amuck. But these bugs could lead to ransomware, or worse...

☐ β˜† βœ‡ Naked Security

Popular Ruby Asciidoc toolkit patched against critical vuln – get the update now!

By Paul Ducklin β€” April 8th 2022 at 15:38
A rogue line-continuation character can trick the code into validating just the second half of the line, but executing all of it.

ruby-1200

☐ β˜† βœ‡ Naked Security

S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]

By Paul Ducklin β€” April 7th 2022 at 12:24
Latest episode - listen now! Cybersecurity news and advice in plain English.

☐ β˜† βœ‡ Naked Security

Firefox 99 is out – no major bugs, but update anyway!

By Paul Ducklin β€” April 5th 2022 at 16:21
Firefox's four-weekly updates just dropped - here's what you need to know.

☐ β˜† βœ‡ Naked Security

Google’s monthly Android updates patch numerous β€œget root” holes

By Paul Ducklin β€” April 5th 2022 at 14:44
Get the update now... if it's available for your phone. Here's how to check.

android-1200

☐ β˜† βœ‡ Naked Security

Apple pushes out two emergency 0-day updates – get ’em now!

By Paul Ducklin β€” March 31st 2022 at 23:38
More Apple zero-days - mobile devices, laptops and desktops affected. Update now!

apple-1200

☐ β˜† βœ‡ Naked Security

S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast]

By Paul Ducklin β€” March 31st 2022 at 13:38
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Zlib data compressor fixes 17-year-old security bug – patch, errrm, now

By Paul Ducklin β€” March 29th 2022 at 16:37
This code is venerable! Surely all the bugs must be out by now?

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Serious Security: DEADBOLT – the ransomware that goes straight for your backups

By Paul Ducklin β€” March 23rd 2022 at 19:58
Some tips on how to keep your network safe - even (or perhaps especially!) if you think you're safe already.

☐ β˜† βœ‡ Naked Security

OpenSSL patches infinite-loop DoS bug in certificate verification

By Paul Ducklin β€” March 18th 2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!

☐ β˜† βœ‡ Naked Security

S3 Ep74: Cybercrime busts, Apple patches, Pi Day, and disconnect effects [Podcast]

By Paul Ducklin β€” March 17th 2022 at 13:32
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

CISA warning: β€œRussian actors bypassed 2FA” – what happened and how to avoid it

By Paul Ducklin β€” March 16th 2022 at 01:22
Don't leave old accounts lying around where someone sketchy could reactivate them.

☐ β˜† βœ‡ Naked Security

Apple patches 87 security holes – from iPhones and Macs to Windows

By Paul Ducklin β€” March 15th 2022 at 16:36
Lots of fixes, with data leakage flaws and code execution bugs patched on iPhones, Macs and even Windows.

apple-1200

☐ β˜† βœ‡ Naked Security

β€œDirty Pipe” Linux kernel bug lets anyone write to any file

By Paul Ducklin β€” March 8th 2022 at 19:37
Even read-only files can be written to, leading to a dangerously general purpose elevation-of-privilege attack.

pipe-1200

☐ β˜† βœ‡ Naked Security

Firefox patches two actively exploited 0-day holes: update now!

By Paul Ducklin β€” March 5th 2022 at 19:06
Firefox just published a double-zero-day patch - "remote code execution" combined with "sandbox escape". Update now!

☐ β˜† βœ‡ Naked Security

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]

By Paul Ducklin β€” February 24th 2022 at 16:51
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

WordPress backup plugin maker Updraft says β€œYou should update”…

By Paul Ducklin β€” February 22nd 2022 at 17:26
A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

☐ β˜† βœ‡ Naked Security

Irony alert! PHP fixes security flaw in input validation code

By Paul Ducklin β€” February 18th 2022 at 17:59
What's wrong with this sequence? 1. Step into the road 2. Check if it's safe 3. Keep on walki...

❌