FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

Critical Samba bug could let anyone become Domain Admin – patch now!

By Paul Ducklin β€” July 27th 2022 at 21:15
It's a serious bug... but there's a fix for it, so you know exactly what to do!

☐ β˜† βœ‡ Naked Security

Facebook 2FA scammers return – this time in just 21 minutes

By Paul Ducklin β€” July 13th 2022 at 16:46
Last time they arrived 28 minutes after lighting up their fake domain... this time it was just 21 minutes

☐ β˜† βœ‡ Naked Security

Apache β€œCommons Configuration” patches Log4Shell-style bug – what you need to know

By Paul Ducklin β€” July 8th 2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.

☐ β˜† βœ‡ Naked Security

S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]

By Paul Ducklin β€” July 7th 2022 at 18:46
Listen now! Or read if you prefer...

☐ β˜† βœ‡ Naked Security

Google patches β€œin-the-wild” Chrome zero-day – update now!

By Paul Ducklin β€” July 5th 2022 at 15:55
Running Chrome? Do the "Help-About-Update" dance move right now, just to be sure...

☐ β˜† βœ‡ Naked Security

Facebook 2FA phish arrives just 28 minutes after scam domain created

By Paul Ducklin β€” July 1st 2022 at 20:01
The crooks hit us up with this phishing email less than half an hour after they activated their new scam domain.

☐ β˜† βœ‡ Naked Security

S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers [Podcast]

By Paul Ducklin β€” June 16th 2022 at 16:52
Lastest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Follina gets fixed – but it’s not listed in the Patch Tuesday patches!

By Paul Ducklin β€” June 15th 2022 at 01:20
We tried it out to make sure, so you don't have to.

☐ β˜† βœ‡ Naked Security

You’re invited! Join us for a live walkthrough of the β€œFollina” story…

By Paul Ducklin β€” June 13th 2022 at 16:28
Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

☐ β˜† βœ‡ Naked Security

Atlassian announces 0-day hole in Confluence Server – update now!

By Paul Ducklin β€” June 3rd 2022 at 18:59
Zero-day announced - here's what you need to know

☐ β˜† βœ‡ Naked Security

S3 Ep85: Now THAT’S what I call a Microsoft Office exploit! [Podcast]

By Paul Ducklin β€” June 2nd 2022 at 18:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Mysterious β€œFollina” zero-day hole in Office – here’s what to do!

By Paul Ducklin β€” May 30th 2022 at 23:01
News has emerged of a "feature" in Office that has been abused as a zero-day bug to run evil code. Turning off macros doesn't help!

☐ β˜† βœ‡ Naked Security

Mozilla patches Wednesday’s Pwn2Own double-exploit… on Friday!

By Paul Ducklin β€” May 20th 2022 at 23:47
That was quick! 48 hours from exploit report to published patch.

☐ β˜† βœ‡ Naked Security

US Government says: Patch VMware right now, or get off our network

By Paul Ducklin β€” May 20th 2022 at 14:03
Find and patch. Right now. If you can't patch, get it off the network. Right now! Oh, and show us what you did to comply.

☐ β˜† βœ‡ Naked Security

Pwn2Own hacking schedule released – Windows and Linux are top targets

By Paul Ducklin β€” May 18th 2022 at 13:04
What's better? Disclose early, patch fast? Or dig deep, disclose in full, patch more slowly?

☐ β˜† βœ‡ Naked Security

Firefox out-of-band update to 100.0.1 – just in time for Pwn2Own?

By Paul Ducklin β€” May 15th 2022 at 21:53
A new point-release of Firefox. Not unusual, but the timing of this one is interesting, with Pwn2Own coming up in a few days.

☐ β˜† βœ‡ Naked Security

RubyGems supply chain rip-and-replace bug fixed – check your logs!

By Paul Ducklin β€” May 9th 2022 at 15:41
Imagine if you could assume the identity of, say, Franklin Delano Roosevelt simply by showing up and calling yourself "Frank".

ruby-1200

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

Yet another Chrome zero-day emergency update – patch now!

By Paul Ducklin β€” April 16th 2022 at 00:33
The third emergency Chrome 0-day in three months - the first one was exploited by North Korea, so you might as well get this one ASAP.

☐ β˜† βœ‡ Naked Security

Two different β€œVMware Spring” bugs at large – we cut through the confusion

By Paul Ducklin β€” March 31st 2022 at 16:59
Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion

☐ β˜† βœ‡ Naked Security

β€œVMware Spring Cloud Function” Java bug gives instant remote code execution – update now!

By Paul Ducklin β€” March 30th 2022 at 20:38
Easy unauthenticated remote code execution - PoC code already out

☐ β˜† βœ‡ Naked Security

Zlib data compressor fixes 17-year-old security bug – patch, errrm, now

By Paul Ducklin β€” March 29th 2022 at 16:37
This code is venerable! Surely all the bugs must be out by now?

☐ β˜† βœ‡ Naked Security

Google Chrome patches mysterious new zero-day bug – update now

By Paul Ducklin β€” March 28th 2022 at 14:18
CVE-2022-1096 - another mystery in-the-wild 0-day in Chrome... check your version now!

☐ β˜† βœ‡ Naked Security

OpenSSL patches infinite-loop DoS bug in certificate verification

By Paul Ducklin β€” March 18th 2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!

☐ β˜† βœ‡ Naked Security

CISA warning: β€œRussian actors bypassed 2FA” – what happened and how to avoid it

By Paul Ducklin β€” March 16th 2022 at 01:22
Don't leave old accounts lying around where someone sketchy could reactivate them.

☐ β˜† βœ‡ Naked Security

S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast + Transcript]

By Paul Ducklin β€” March 10th 2022 at 19:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

β€œDirty Pipe” Linux kernel bug lets anyone write to any file

By Paul Ducklin β€” March 8th 2022 at 19:37
Even read-only files can be written to, leading to a dangerously general purpose elevation-of-privilege attack.

pipe-1200

☐ β˜† βœ‡ Naked Security

WordPress backup plugin maker Updraft says β€œYou should update”…

By Paul Ducklin β€” February 22nd 2022 at 17:26
A straight-talking bug report written in plain English by an actual expert - there's a teachable moment in this cybersecurity story!

☐ β˜† βœ‡ Naked Security

Irony alert! PHP fixes security flaw in input validation code

By Paul Ducklin β€” February 18th 2022 at 17:59
What's wrong with this sequence? 1. Step into the road 2. Check if it's safe 3. Keep on walki...

☐ β˜† βœ‡ Naked Security

Google announces zero-day in Chrome browser – update now!

By Paul Ducklin β€” February 15th 2022 at 19:17
Zero-day buses: none for a while, then three at once. Here's Google joining Apple and Adobe in "zero-day week"

☐ β˜† βœ‡ Naked Security

Adobe fixes zero-day exploit in e-commerce code: update now!

By Paul Ducklin β€” February 14th 2022 at 22:38
There's a remote code execution hole in Adobe e-commerce products - and cybercrooks are already exploiting it.

☐ β˜† βœ‡ Naked Security

Apple zero-day drama for Macs, iPhones and iPads – patch now!

By Paul Ducklin β€” February 11th 2022 at 14:25
Sudden update! Zero-day browser hole! Drive-by malware danger! Patch Apple laptops and phones now...

apple-1200

☐ β˜† βœ‡ Naked Security

Microsoft blocks web installation of its own App Installer files

By Paul Ducklin β€” February 7th 2022 at 16:36
It's a big deal when a vendor decides to block one of its own "features" for security reasons. Here's why we think it's a good idea.

☐ β˜† βœ‡ Naked Security

Linux kernel patches β€œperformance can be harmful” bug in video driver

By Paul Ducklin β€” February 1st 2022 at 19:59
This bug is fiendishly hard to exploit - but if you patch, it won't be there to exploit at all.

☐ β˜† βœ‡ Naked Security

S3 Ep67: Tax scams, carder busts and crypto capers [Podcast + Transcript]

By Paul Ducklin β€” January 27th 2022 at 19:57
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

β€œPwnKit” security bug gets you root on most Linux distros – what to do

By Paul Ducklin β€” January 26th 2022 at 19:58
An elevation of privilege bug that could let a "mostly harmless" user give themselves a instant root shell

☐ β˜† βœ‡ Naked Security

Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft

By Paul Ducklin β€” January 21st 2022 at 16:25
The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.

☐ β˜† βœ‡ Naked Security

Wormable Windows HTTP hole – what you need to know

By Paul Ducklin β€” January 12th 2022 at 16:24
One bug in the January 2022 Patch Tuesday list is getting lots of attention: "HTTP Protocol Stack Remote Code Execution Vulnerability".

☐ β˜† βœ‡ Naked Security

Home routers with NetUSB support could have critical kernel hole

By Paul Ducklin β€” January 11th 2022 at 17:42
Got a router that supports USB access across the network? You might need a kernel update...

☐ β˜† βœ‡ Naked Security

Log4Shell-like security hole found in popular Java SQL database engine H2

By Paul Ducklin β€” January 7th 2022 at 19:32
"It's Log4Shell, Jim, but not as we know it." How to find and fix a JNDI-based vuln in the H2 Database Engine.

☐ β˜† βœ‡ Naked Security

Log4Shell vulnerability Number Four: β€œMuch ado about something”

By Paul Ducklin β€” December 29th 2021 at 19:12
It's a Log4j bug, and you ought to patch it. But we don't think it's a critical crisis like the last one.

☐ β˜† βœ‡ Naked Security

SFW! The Top N CyberΒ­security Stories of 2021 (for small positive integer values of N)

By Paul Ducklin β€” December 24th 2021 at 17:44
Happy Holidays! Our Top N stories, all totally SFW!

☐ β˜† βœ‡ Naked Security

Apache’s other product: Critical bugs in β€˜httpd’ web server, patch now!

By Paul Ducklin β€” December 21st 2021 at 19:57
The Apache web server just got an update - this one is nothing to do with Log4j!

☐ β˜† βœ‡ Naked Security

Log4Shell: The Movie… a short, safe visual tour for work and home

By Paul Ducklin β€” December 20th 2021 at 13:20
Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!

☐ β˜† βœ‡ Naked Security

Serious Security: OpenSSL fixes β€œerror conflation” bugs – how mixing up mistakes can lead to trouble

By Paul Ducklin β€” December 17th 2021 at 17:57
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!

☐ β˜† βœ‡ Naked Security

S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]

By Paul Ducklin β€” December 16th 2021 at 17:41
Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)

☐ β˜† βœ‡ Naked Security

Log4Shell explained – how it works, why you need to know, and how to fix it

By Paul Ducklin β€” December 13th 2021 at 19:41
Find out how to deal with the Log4Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!

☐ β˜† βœ‡ Naked Security

β€œLog4Shell” Java vulnerability – how to safeguard your servers

By Paul Ducklin β€” December 10th 2021 at 19:22
Just when you thought it was safe to relax for the weekend... a critical bug showed up in Apache's Log4j product

☐ β˜† βœ‡ Naked Security

Check your patches – public exploit now out for critical Exchange bug

By Paul Ducklin β€” November 23rd 2021 at 14:36
It was a zero-day bug until Patch Tuesday, now there's an anyone-can-use-it exploit. Don't be the one who hasn't patched.

☐ β˜† βœ‡ Naked Security

Microsoft documents β€œSHROOTLESS” hack patched in latest Apple updates

By Paul Ducklin β€” October 29th 2021 at 13:38
We'd have called this bug "SHROOTMORE", but naming it wasn't our call.

☐ β˜† βœ‡ Naked Security

Listen up 2 – CYBERSECURITY FIRST! How to protect yourself from supply chain attacks

By Paul Ducklin β€” October 25th 2021 at 16:38
Everyone remembers this year's big-news supply chain attacks on Kaseya and SolarWinds. Sophos expert Chester Wisniewski explains how to control the risk.

☐ β˜† βœ‡ Naked Security

Listen up 3 – CYBERSECURITY FIRST! Cyberinsurance, help or hindrance?

By Paul Ducklin β€” October 25th 2021 at 16:37
Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance.

☐ β˜† βœ‡ Naked Security

Listen up 4 – CYBERSECURITY FIRST! Purple teaming – learning to think like your adversaries

By Paul Ducklin β€” October 25th 2021 at 16:36
Michelle Farenci knows her stuff, because she's a cybersecurity practitioner inside a cybersecurity company! Learn why thinking like an attacker makes you a better defender.

☐ β˜† βœ‡ Naked Security

Cybersecurity Awareness Month: Listen up – CYBERΒ­SECURITY FIRST!

By Paul Ducklin β€” October 25th 2021 at 16:39
Fraser Howard of SophosLabs is truly a world expert in fighting malware. Read now, and learn from the best!

☐ β˜† βœ‡ Naked Security

Cybersecurity Awareness Month: Building your career

By Paul Ducklin β€” October 18th 2021 at 18:23
Explore. Experience. Share. How to get into cybersecurity...

❌