FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By Paul Ducklin β€” August 18th 2022 at 18:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

Apple patches double zero-day in browser and kernel – update now!

By Paul Ducklin β€” August 17th 2022 at 23:33
Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

☐ β˜† βœ‡ Naked Security

Chrome browser gets 11 security fixes with 1 zero-day – update now!

By Paul Ducklin β€” August 17th 2022 at 13:16
Don't delay - patch today.

☐ β˜† βœ‡ Naked Security

US offers reward β€œup to $10 million” for information about the Conti gang

By Naked Security writer β€” August 16th 2022 at 16:57
Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches critical bug – update now!

By Paul Ducklin β€” August 15th 2022 at 18:26
There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

Traffic Light Protocol for cybersecurity responders gets a revamp

By Paul Ducklin β€” August 5th 2022 at 18:57
Traffic lights make a handy global metaphor for denoting the sensitivity of cybersecurity threat data - three colours that everyone knows.

☐ β˜† βœ‡ Naked Security

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]

By Paul Ducklin β€” August 4th 2022 at 17:52
Latest episode - listen now! (Or read if that's what you prefer.)

☐ β˜† βœ‡ Naked Security

GitHub blighted by β€œresearcher” who created thousands of malicious projects

By Paul Ducklin β€” August 3rd 2022 at 23:06
If you spew projects laced with hidden malware into an open source repository, don't waste your time telling us "no harm done" afterwards.

☐ β˜† βœ‡ Naked Security

Post-quantum cryptography – new algorithm β€œgone in 60 minutes”

By Paul Ducklin β€” August 3rd 2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.

☐ β˜† βœ‡ Naked Security

Cryptocoin β€œtoken swapper” Nomad loses $200 million in coding blunder

By Paul Ducklin β€” August 2nd 2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.

☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

How to celebrate SysAdmin Day!

By Paul Ducklin β€” July 29th 2022 at 15:37
I've just popped in to wish you all/The best SysAdmin Day!

☐ β˜† βœ‡ Naked Security

S3 Ep93: Office security, breach costs, and leisurely patches [Audio + Text]

By Paul Ducklin β€” July 28th 2022 at 15:47
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Critical Samba bug could let anyone become Domain Admin – patch now!

By Paul Ducklin β€” July 27th 2022 at 21:15
It's a serious bug... but there's a fix for it, so you know exactly what to do!

☐ β˜† βœ‡ Naked Security

Mild monthly security update from Firefox – but update anyway

By Paul Ducklin β€” July 27th 2022 at 00:41
You're probably thinking we're going to say, "Don't delay/Do it today"... and that's exactly what we are saying!

☐ β˜† βœ‡ Naked Security

T-Mobile to cough up $500 million over 2021 data breach

By Paul Ducklin β€” July 25th 2022 at 16:20
Technically, it's not a fine, and the lawyers will get a big chunk of it. But it still adds up to a half-billion-dollar data breach.

☐ β˜† βœ‡ Naked Security

Office macro security: on-again-off-again feature now BACK ON AGAIN!

By Paul Ducklin β€” July 23rd 2022 at 01:10
20 years to turn it on, then 20 weeks to turn it off, then just 2 weeks to turn it back on again. That's progress!

☐ β˜† βœ‡ Naked Security

S3 Ep92: Log4Shell4Ever, travel tips, and scamminess [Audio + Text]

By Paul Ducklin β€” July 21st 2022 at 16:25
Latest episode - listen, read or both!

☐ β˜† βœ‡ Naked Security

Apple patches β€œ0-day” browser bug fixed 2 weeks ago in Chrome, Edge

By Paul Ducklin β€” July 21st 2022 at 12:38
One vendor's zero-day is another vendor's routine patch...

☐ β˜† βœ‡ Naked Security

Last member of Gozi malware troika arrives in US for criminal trial

By Paul Ducklin β€” July 20th 2022 at 14:56
His co-conspirators went into and got out of prison years ago, while he remained free. Now the tables have turned...

☐ β˜† βœ‡ Naked Security

8 months on, US says Log4Shell will be around for β€œa decade or longer”

By Paul Ducklin β€” July 18th 2022 at 16:57
When it comes to cybersecurity, ask not what everyone else can do for you...

☐ β˜† βœ‡ Naked Security

7 cybersecurity tips for your summer vacation!

By Paul Ducklin β€” July 15th 2022 at 18:23
Here you go - seven thoughtful cybersecurity tips to help you travel safely...

☐ β˜† βœ‡ Naked Security

S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]

By Paul Ducklin β€” July 14th 2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.

☐ β˜† βœ‡ Naked Security

Facebook 2FA scammers return – this time in just 21 minutes

By Paul Ducklin β€” July 13th 2022 at 16:46
Last time they arrived 28 minutes after lighting up their fake domain... this time it was just 21 minutes

☐ β˜† βœ‡ Naked Security

Paying ransomware crooks won’t reduce your legal risk, warns regulator

By Paul Ducklin β€” July 12th 2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

☐ β˜† βœ‡ Naked Security

That didn’t last! Microsoft turns off the Office security it just turned on

By Paul Ducklin β€” July 11th 2022 at 13:27
An Office anti-malware setting that took more than 20 years to arrive... and fewer than 20 weeks to vanish again.

☐ β˜† βœ‡ Naked Security

Apache β€œCommons Configuration” patches Log4Shell-style bug – what you need to know

By Paul Ducklin β€” July 8th 2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.

☐ β˜† βœ‡ Naked Security

S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]

By Paul Ducklin β€” July 7th 2022 at 18:46
Listen now! Or read if you prefer...

☐ β˜† βœ‡ Naked Security

OpenSSL fixes two β€œone-liner” crypto bugs – what you need to know

By Paul Ducklin β€” July 6th 2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...

☐ β˜† βœ‡ Naked Security

Google patches β€œin-the-wild” Chrome zero-day – update now!

By Paul Ducklin β€” July 5th 2022 at 15:55
Running Chrome? Do the "Help-About-Update" dance move right now, just to be sure...

☐ β˜† βœ‡ Naked Security

Canadian cybercriminal pleads guilty to β€œNetWalker” attacks in US

By Paul Ducklin β€” July 4th 2022 at 14:09
Bust in Canada, now bust in the USA as well.

☐ β˜† βœ‡ Naked Security

Facebook 2FA phish arrives just 28 minutes after scam domain created

By Paul Ducklin β€” July 1st 2022 at 20:01
The crooks hit us up with this phishing email less than half an hour after they activated their new scam domain.

☐ β˜† βœ‡ Naked Security

β€œMissing Cryptoqueen” hits the FBI’s Ten Most Wanted list

By Paul Ducklin β€” July 1st 2022 at 16:49
The "Missing Cryptoqueen" makes the American Top Ten... but not in a good way.

☐ β˜† βœ‡ Naked Security

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

By Paul Ducklin β€” June 30th 2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!

☐ β˜† βœ‡ Naked Security

Firefox 102 fixes address bar spoofing security hole (and helps with Follina!)

By Paul Ducklin β€” June 29th 2022 at 16:11
Firefox squashes a bug that helped phishers, and brings its own helping hand to Microsoft's "Follina" saga.

☐ β˜† βœ‡ Naked Security

Harmony blockchain loses nearly $100M due to hacked private keys

By Paul Ducklin β€” June 27th 2022 at 18:14
The crooks needed at least two private keys, each stored in two parts... but they got them anyway.

☐ β˜† βœ‡ Naked Security

FTC warns of LGBTQ+ extortion scams – be aware before you share!

By Paul Ducklin β€” June 27th 2022 at 14:58
It's a simple jingle and it's solid advice: "If in doubt, don't give it out!"

☐ β˜† βœ‡ Naked Security

OpenSSL issues a bugfix for the previous bugfix

By Paul Ducklin β€” June 24th 2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

☐ β˜† βœ‡ Naked Security

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]

By Paul Ducklin β€” June 23rd 2022 at 11:08
Latest epsiode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

Interpol busts 2000 suspects in phone scamming takedown

By Paul Ducklin β€” June 20th 2022 at 18:10
Friends don't let friends get scammed. Not everyone knows how typical scams unfold, so here are some real-world examples...

☐ β˜† βœ‡ Naked Security

S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers [Podcast]

By Paul Ducklin β€” June 16th 2022 at 16:52
Lastest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Follina gets fixed – but it’s not listed in the Patch Tuesday patches!

By Paul Ducklin β€” June 15th 2022 at 01:20
We tried it out to make sure, so you don't have to.

☐ β˜† βœ‡ Naked Security

Murder suspect admits she tracked cheating partner with hidden AirTag

By Paul Ducklin β€” June 14th 2022 at 18:49
O! What a tangled web we weave, when first we practise to deceive.

☐ β˜† βœ‡ Naked Security

You’re invited! Join us for a live walkthrough of the β€œFollina” story…

By Paul Ducklin β€” June 13th 2022 at 16:28
Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

☐ β˜† βœ‡ Naked Security

S3 Ep86: The crooks were in our network for HOW long?! [Podcast + Transcript]

By Paul Ducklin β€” June 9th 2022 at 13:07
Latest episode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

SSNDOB Market domains seized, identity theft β€œbrokerage” shut down

By Paul Ducklin β€” June 8th 2022 at 14:53
The online identity "brokerage" SSNDOB Market didn't want people to be in any doubt what it was selling.

☐ β˜† βœ‡ Naked Security

Know your enemy! Learn how cybercrime adversaries get in…

By Paul Ducklin β€” June 7th 2022 at 15:49
Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

☐ β˜† βœ‡ Naked Security

Atlassian announces 0-day hole in Confluence Server – update now!

By Paul Ducklin β€” June 3rd 2022 at 18:59
Zero-day announced - here's what you need to know

☐ β˜† βœ‡ Naked Security

Yet another zero-day (sort of) in Windows β€œsearch URL” handling

By Paul Ducklin β€” June 2nd 2022 at 19:39
More trouble with special-purpose URLs on Windows.

☐ β˜† βœ‡ Naked Security

S3 Ep85: Now THAT’S what I call a Microsoft Office exploit! [Podcast]

By Paul Ducklin β€” June 2nd 2022 at 18:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Firefox 101 is out, this time with no 0-day scares (but update anyway!)

By Paul Ducklin β€” June 1st 2022 at 14:31
After an intriguing month of Firefox releases, here's one with a bit less drama, probably to the collective relief of Mozilla's coders.

☐ β˜† βœ‡ Naked Security

Mysterious β€œFollina” zero-day hole in Office – here’s what to do!

By Paul Ducklin β€” May 30th 2022 at 23:01
News has emerged of a "feature" in Office that has been abused as a zero-day bug to run evil code. Turning off macros doesn't help!

☐ β˜† βœ‡ Naked Security

Beware the Smish! Home delivery scams with a professional feel…

By Paul Ducklin β€” May 30th 2022 at 17:59
Home delivery scams are getting leaner, and meaner, and more likely to "look about right". Here's an example to show you what we mean...

☐ β˜† βœ‡ Naked Security

S3 Ep84: Government demand, Mozilla velocity, and Clearview fine [Podcast]

By Paul Ducklin β€” May 27th 2022 at 11:17
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Who’s watching your webcam? The Screencastify Chrome extension story…

By Paul Ducklin β€” May 26th 2022 at 12:41
When you really need to make exceptions in cybersecurity, specify them as explicitly as you can.

☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

❌