FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Laptop denial-of-service via music: the 1980s R&B song with a CVE!

By Paul Ducklin β€” August 22nd 2022 at 16:03
We haven't validated this vuln ourselves... but the source of the story is impeccable. (Impeccably dressed, at least.)

☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By Paul Ducklin β€” August 18th 2022 at 18:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

US offers reward β€œup to $10 million” for information about the Conti gang

By Naked Security writer β€” August 16th 2022 at 16:57
Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

Apple patches β€œ0-day” browser bug fixed 2 weeks ago in Chrome, Edge

By Paul Ducklin β€” July 21st 2022 at 12:38
One vendor's zero-day is another vendor's routine patch...

☐ β˜† βœ‡ Naked Security

7 cybersecurity tips for your summer vacation!

By Paul Ducklin β€” July 15th 2022 at 18:23
Here you go - seven thoughtful cybersecurity tips to help you travel safely...

☐ β˜† βœ‡ Naked Security

Paying ransomware crooks won’t reduce your legal risk, warns regulator

By Paul Ducklin β€” July 12th 2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

☐ β˜† βœ‡ Naked Security

Apache β€œCommons Configuration” patches Log4Shell-style bug – what you need to know

By Paul Ducklin β€” July 8th 2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.

☐ β˜† βœ‡ Naked Security

S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]

By Paul Ducklin β€” July 7th 2022 at 18:46
Listen now! Or read if you prefer...

☐ β˜† βœ‡ Naked Security

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

By Paul Ducklin β€” June 30th 2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!

☐ β˜† βœ‡ Naked Security

Harmony blockchain loses nearly $100M due to hacked private keys

By Paul Ducklin β€” June 27th 2022 at 18:14
The crooks needed at least two private keys, each stored in two parts... but they got them anyway.

☐ β˜† βœ‡ Naked Security

FTC warns of LGBTQ+ extortion scams – be aware before you share!

By Paul Ducklin β€” June 27th 2022 at 14:58
It's a simple jingle and it's solid advice: "If in doubt, don't give it out!"

☐ β˜† βœ‡ Naked Security

OpenSSL issues a bugfix for the previous bugfix

By Paul Ducklin β€” June 24th 2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

☐ β˜† βœ‡ Naked Security

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]

By Paul Ducklin β€” June 23rd 2022 at 11:08
Latest epsiode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

Know your enemy! Learn how cybercrime adversaries get in…

By Paul Ducklin β€” June 7th 2022 at 15:49
Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

☐ β˜† βœ‡ Naked Security

Microsoft patches the Patch Tuesday patch that broke authentication

By Paul Ducklin β€” May 20th 2022 at 22:35
Remember the good old days when security patches rarely needed patches? Because security patches themlelves were rare enough anyway?

☐ β˜† βœ‡ Naked Security

Colonial Pipeline facing $1,000,000 fine for poor recovery plans

By Paul Ducklin β€” May 10th 2022 at 16:59
How good is your cybersecurity? Are you making the same mistakes as lots of other people? Here's some real-life advice...

☐ β˜† βœ‡ Naked Security

You didn’t leave enough space between ROSE and AND, and AND and CROWN

By Paul Ducklin β€” May 6th 2022 at 16:59
What weird Google Docs bug connects the words THEREFORE, AND, SECONDLY, WHY, BUT and BESIDES?

☐ β˜† βœ‡ Naked Security

Yet another Chrome zero-day emergency update – patch now!

By Paul Ducklin β€” April 16th 2022 at 00:33
The third emergency Chrome 0-day in three months - the first one was exploited by North Korea, so you might as well get this one ASAP.

☐ β˜† βœ‡ Naked Security

LAPSUS$ hacks continue despite two hacker suspects in court

By Paul Ducklin β€” April 4th 2022 at 21:36
Do you know where in your company to report security anomalies? If you receive such reports, do you have an efficient way to process them?

☐ β˜† βœ‡ Naked Security

Apple pushes out two emergency 0-day updates – get ’em now!

By Paul Ducklin β€” March 31st 2022 at 23:38
More Apple zero-days - mobile devices, laptops and desktops affected. Update now!

apple-1200

☐ β˜† βœ‡ Naked Security

β€œVMware Spring Cloud Function” Java bug gives instant remote code execution – update now!

By Paul Ducklin β€” March 30th 2022 at 20:38
Easy unauthenticated remote code execution - PoC code already out

☐ β˜† βœ‡ Naked Security

CISA warning: β€œRussian actors bypassed 2FA” – what happened and how to avoid it

By Paul Ducklin β€” March 16th 2022 at 01:22
Don't leave old accounts lying around where someone sketchy could reactivate them.

☐ β˜† βœ‡ Naked Security

Happy #PiDay – even if you aren’t in North America!

By Paul Ducklin β€” March 14th 2022 at 23:59
There is a cybersecurity angle here - but you will need to read right to the end to find it :-)

☐ β˜† βœ‡ Naked Security

Cryptocoin ATMs ruled illegal – β€œShut down at once”, says regulator

By Paul Ducklin β€” March 14th 2022 at 17:51
If you live in the UK and hadn't yet heard of cryptocoin ATMs... it's too late now!

☐ β˜† βœ‡ Naked Security

Ransomware with a difference: β€œDerestrict your software, or else!”

By Paul Ducklin β€” March 2nd 2022 at 16:33
"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.

☐ β˜† βœ‡ Naked Security

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]

By Paul Ducklin β€” February 24th 2022 at 16:51
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

French speakers blasted by sextortion scams with no text or links

By Paul Ducklin β€” February 21st 2022 at 17:59
You'd spot this one a mile away... but what about your friends or family?

☐ β˜† βœ‡ Naked Security

Apple zero-day drama for Macs, iPhones and iPads – patch now!

By Paul Ducklin β€” February 11th 2022 at 14:25
Sudden update! Zero-day browser hole! Drive-by malware danger! Patch Apple laptops and phones now...

apple-1200

☐ β˜† βœ‡ Naked Security

Wormhole cryptotrading company turns over $340,000,000 to criminals

By Paul Ducklin β€” February 4th 2022 at 17:38
It was the best of blockchains, it was the worst of blockchains... as Charles Dickens might have said.

☐ β˜† βœ‡ Naked Security

S3 Ep68: Bugs, scams, privacy …and fonts?! [Podcast + Transcript]

By Paul Ducklin β€” February 3rd 2022 at 16:20
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Coronavirus SMS scam offers home PCR testing devices – don’t fall for it!

By Paul Ducklin β€” January 28th 2022 at 23:58
Free home PCR devices would be technological marvels, and really useful, too. But there aren't any...

☐ β˜† βœ‡ Naked Security

Apple fixes Safari data leak (and patches a zero-day!) – update now

By Paul Ducklin β€” January 27th 2022 at 21:09
That infamous "supercookie" bug in Safari has now been fixed. Oh, and there was a zero-day kernel hole as well.

apple-1200

☐ β˜† βœ‡ Naked Security

S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]

By Paul Ducklin β€” January 13th 2022 at 15:26
Latest episode -listen to it or read it now!

☐ β˜† βœ‡ Naked Security

Honda cars in flashback to 2002 – β€œCan’t Get You Out Of My Head”

By Paul Ducklin β€” January 8th 2022 at 02:53
Where were YOU on the night of 17 May 2002? And what about the day after that?

☐ β˜† βœ‡ Naked Security

The cool retro phone with a REAL DIAL… plus plenty of IoT problems

By Paul Ducklin β€” December 23rd 2021 at 17:58
You know you want one, because this retro phone is NOT A TOY... except when it comes to cybersecurity.

☐ β˜† βœ‡ Naked Security

S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]

By Paul Ducklin β€” December 16th 2021 at 17:41
Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)

☐ β˜† βœ‡ Naked Security

Apple security updates are out – and not a Log4Shell mention in sight

By Paul Ducklin β€” December 14th 2021 at 12:55
Get 'em while they're hot!

☐ β˜† βœ‡ Naked Security

Cryptocurrency startup fails to subtract before adding, loses $31m

By Paul Ducklin β€” December 6th 2021 at 19:50
Think of a number, any number. Take away 42. Add 42 back in. Then pretend you didn't take away 42. How much is left?

☐ β˜† βœ‡ Naked Security

S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]

By Paul Ducklin β€” December 2nd 2021 at 20:50
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

IoT devices must β€œprotect consumers from cyberharm”, says UK government

By Paul Ducklin β€” December 2nd 2021 at 19:10
"Must be at least THIS tall to go on ride" seems to be the starting point. Too little, too late? Or better than nothing?

☐ β˜† βœ‡ Naked Security

Clearview AI face-matching service set to be fined over $20m

By Paul Ducklin β€” November 30th 2021 at 19:13
Scraping data for a facial recognition service? "That's unlawful", concluded both the British and the Australians.

☐ β˜† βœ‡ Naked Security

US government securities watchdog spoofed by investment scammers – don’t fall for it!

By Paul Ducklin β€” November 24th 2021 at 19:57
Those numbers that show up on your phone to tell you who's calling? Treat them as SUGGESTIONS, never as PROOF.

☐ β˜† βœ‡ Naked Security

GoDaddy admits to password breach: check your Managed WordPress site!

By Paul Ducklin β€” November 23rd 2021 at 00:35
GoDaddy found crooks in its network, and kicked them out - but not before they'd been in there for six weeks.

☐ β˜† βœ‡ Naked Security

Black Friday and Cyber Monday – here’s what you REALLY need to do!

By Paul Ducklin β€” November 22nd 2021 at 19:52
The world fills up with cybersecurity tips every year when Black Friday comes round. But what about the rest of the year?

☐ β˜† βœ‡ Naked Security

S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust [Podcast]

By Paul Ducklin β€” November 11th 2021 at 17:41
Latest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Facebook to throw out face recognition, delete all template data

By Paul Ducklin β€” November 3rd 2021 at 19:31
Publicity stunt? Or privacy progress?

☐ β˜† βœ‡ Naked Security

Europol announces β€œtargeting” of 12 suspects in ransomware attacks

By Naked Security writer β€” October 29th 2021 at 23:22
More anti-ransomware activity by law enforcement, this time in Switzerland and Ukraine.

☐ β˜† βœ‡ Naked Security

Listen up 2 – CYBERSECURITY FIRST! How to protect yourself from supply chain attacks

By Paul Ducklin β€” October 25th 2021 at 16:38
Everyone remembers this year's big-news supply chain attacks on Kaseya and SolarWinds. Sophos expert Chester Wisniewski explains how to control the risk.

☐ β˜† βœ‡ Naked Security

Listen up 3 – CYBERSECURITY FIRST! Cyberinsurance, help or hindrance?

By Paul Ducklin β€” October 25th 2021 at 16:37
Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance.

☐ β˜† βœ‡ Naked Security

Listen up 4 – CYBERSECURITY FIRST! Purple teaming – learning to think like your adversaries

By Paul Ducklin β€” October 25th 2021 at 16:36
Michelle Farenci knows her stuff, because she's a cybersecurity practitioner inside a cybersecurity company! Learn why thinking like an attacker makes you a better defender.

☐ β˜† βœ‡ Naked Security

Cybersecurity Awareness Month: Listen up – CYBERΒ­SECURITY FIRST!

By Paul Ducklin β€” October 25th 2021 at 16:39
Fraser Howard of SophosLabs is truly a world expert in fighting malware. Read now, and learn from the best!

☐ β˜† βœ‡ Naked Security

S3 Ep55: Live malware, global encryption, dating scams, and secret emanations [Podcasts]

By Paul Ducklin β€” October 21st 2021 at 18:13
Latest episode - listen now! (And sign up for our forthcoming Live Malware Demo at the same time.)

☐ β˜† βœ‡ Naked Security

Cybersecurity Awareness Month: Building your career

By Paul Ducklin β€” October 18th 2021 at 18:23
Explore. Experience. Share. How to get into cybersecurity...

☐ β˜† βœ‡ Naked Security

LANtenna hack spies on your data from across the room! (Sort of)

By Paul Ducklin β€” October 15th 2021 at 18:58
Are your network cables acting as undercover wireless transmitters? What can you do if they are?

☐ β˜† βœ‡ Naked Security

S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish [Podcast]

By Paul Ducklin β€” October 14th 2021 at 18:33
Latest episode - listen now!

❌