FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Zoom for Mac patches sneaky β€œspy-on-me” bug – update now!

By Paul Ducklin β€” October 18th 2022 at 18:01
Hey! That back door isn't supposed to be there at all, let alone propped open...

☐ β˜† βœ‡ Naked Security

S3 Ep104: Should hospital ransomware attackers be locked up for life? [Audio + Text]

By Paul Ducklin β€” October 13th 2022 at 16:37
Have your say on three deep questions posed by this week's podcast. Read or listen as suits you best...

☐ β˜† βœ‡ Naked Security

WhatsApp goes after Chinese password scammers via US court

By Paul Ducklin β€” October 7th 2022 at 18:14
If you can't beat 'em, sue 'em!

☐ β˜† βœ‡ Naked Security

NetWalker ransomware affiliate sentenced to 20 years by Florida court

By Naked Security writer β€” October 5th 2022 at 18:55
Judge tells the accused that if he hadn't pleaded guilty, "I would have given you life."

☐ β˜† βœ‡ Naked Security

S3 Ep102: How to avoid a data breach [Audio + Transcript]

By Paul Ducklin β€” September 29th 2022 at 18:45
Latest episode - listen now! Tell fact from fiction in hyped-up cybersecurity news...

☐ β˜† βœ‡ Naked Security

Interested in cybersecurity? Join us for Security SOS Week 2022!

By Paul Ducklin β€” September 21st 2022 at 14:24
Four one-on-one interviews with experts who are passionate about sharing their expertise with the community.

☐ β˜† βœ‡ Naked Security

S3 Ep100: Browser-in-the-Browser – how to spot an attack [Audio + Text]

By Paul Ducklin β€” September 15th 2022 at 18:50
Latest episode - listen now! Cosmic rockets, zero-days, spotting cybercrooks, and unlocking the DEADBOLT...

s3-ep100-js-1200

☐ β˜† βœ‡ Naked Security

DEADBOLT ransomware rears its head again, attacks QNAP devices

By Paul Ducklin β€” September 7th 2022 at 16:57
NAS devices make it easy for anyone to add high-capacity file servers to their network. Guess why cybercrooks love NAS devices too...

☐ β˜† βœ‡ Naked Security

URGENT! Apple slips out zero-day update for older iPhones and iPads

By Paul Ducklin β€” August 31st 2022 at 18:42
Patch as soon as you can - that recent WebKit zero-day affecting new iPhones and iPads is apparently being used against older models, too.

☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By Paul Ducklin β€” August 18th 2022 at 18:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

Apple patches double zero-day in browser and kernel – update now!

By Paul Ducklin β€” August 17th 2022 at 23:33
Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

☐ β˜† βœ‡ Naked Security

US offers reward β€œup to $10 million” for information about the Conti gang

By Naked Security writer β€” August 16th 2022 at 16:57
Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches critical bug – update now!

By Paul Ducklin β€” August 15th 2022 at 18:26
There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

GitHub blighted by β€œresearcher” who created thousands of malicious projects

By Paul Ducklin β€” August 3rd 2022 at 23:06
If you spew projects laced with hidden malware into an open source repository, don't waste your time telling us "no harm done" afterwards.

☐ β˜† βœ‡ Naked Security

Office macro security: on-again-off-again feature now BACK ON AGAIN!

By Paul Ducklin β€” July 23rd 2022 at 01:10
20 years to turn it on, then 20 weeks to turn it off, then just 2 weeks to turn it back on again. That's progress!

☐ β˜† βœ‡ Naked Security

Last member of Gozi malware troika arrives in US for criminal trial

By Paul Ducklin β€” July 20th 2022 at 14:56
His co-conspirators went into and got out of prison years ago, while he remained free. Now the tables have turned...

☐ β˜† βœ‡ Naked Security

8 months on, US says Log4Shell will be around for β€œa decade or longer”

By Paul Ducklin β€” July 18th 2022 at 16:57
When it comes to cybersecurity, ask not what everyone else can do for you...

☐ β˜† βœ‡ Naked Security

S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]

By Paul Ducklin β€” July 14th 2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.

☐ β˜† βœ‡ Naked Security

Paying ransomware crooks won’t reduce your legal risk, warns regulator

By Paul Ducklin β€” July 12th 2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

☐ β˜† βœ‡ Naked Security

That didn’t last! Microsoft turns off the Office security it just turned on

By Paul Ducklin β€” July 11th 2022 at 13:27
An Office anti-malware setting that took more than 20 years to arrive... and fewer than 20 weeks to vanish again.

☐ β˜† βœ‡ Naked Security

Canadian cybercriminal pleads guilty to β€œNetWalker” attacks in US

By Paul Ducklin β€” July 4th 2022 at 14:09
Bust in Canada, now bust in the USA as well.

☐ β˜† βœ‡ Naked Security

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]

By Paul Ducklin β€” June 23rd 2022 at 11:08
Latest epsiode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

You’re invited! Join us for a live walkthrough of the β€œFollina” story…

By Paul Ducklin β€” June 13th 2022 at 16:28
Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

☐ β˜† βœ‡ Naked Security

Know your enemy! Learn how cybercrime adversaries get in…

By Paul Ducklin β€” June 7th 2022 at 15:49
Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

☐ β˜† βœ‡ Naked Security

S3 Ep84: Government demand, Mozilla velocity, and Clearview fine [Podcast]

By Paul Ducklin β€” May 27th 2022 at 11:17
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

☐ β˜† βœ‡ Naked Security

US Government says: Patch VMware right now, or get off our network

By Paul Ducklin β€” May 20th 2022 at 14:03
Find and patch. Right now. If you can't patch, get it off the network. Right now! Oh, and show us what you did to comply.

☐ β˜† βœ‡ Naked Security

Colonial Pipeline facing $1,000,000 fine for poor recovery plans

By Paul Ducklin β€” May 10th 2022 at 16:59
How good is your cybersecurity? Are you making the same mistakes as lots of other people? Here's some real-life advice...

☐ β˜† βœ‡ Naked Security

S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java [Podcast]

By Paul Ducklin β€” April 28th 2022 at 13:18
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Ransomware Survey 2022 – like the Curate’s Egg, β€œgood in parts”

By Paul Ducklin β€” April 27th 2022 at 15:22
You might not like the headline statistics in this year's ransomware report... but that makes it even more important to take a look!

☐ β˜† βœ‡ Naked Security

LAPSUS$ hacks continue despite two hacker suspects in court

By Paul Ducklin β€” April 4th 2022 at 21:36
Do you know where in your company to report security anomalies? If you receive such reports, do you have an efficient way to process them?

☐ β˜† βœ‡ Naked Security

Two different β€œVMware Spring” bugs at large – we cut through the confusion

By Paul Ducklin β€” March 31st 2022 at 16:59
Whoever came up with the name "Spring4Shell" didn't help at all... we cut through the Spring Bug confusion

☐ β˜† βœ‡ Naked Security

S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast]

By Paul Ducklin β€” March 31st 2022 at 13:38
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

World Backup Day: 5 data recovery tips for everyone!

By Paul Ducklin β€” March 30th 2022 at 15:10
The only backup you will ever regret is the one you didn't make

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Serious Security: DEADBOLT – the ransomware that goes straight for your backups

By Paul Ducklin β€” March 23rd 2022 at 19:58
Some tips on how to keep your network safe - even (or perhaps especially!) if you think you're safe already.

☐ β˜† βœ‡ Naked Security

Beware bogus Betas – cryptocoin scammers abuse Apple’s TestFlight system

By Paul Ducklin β€” March 16th 2022 at 15:49
"Install this moneymaking app" - this one is so special that it isn't available on Google Play or the App Store!

☐ β˜† βœ‡ Naked Security

Alleged Kaseya ransomware attacker arrives in Texas for trial

By Naked Security writer β€” March 11th 2022 at 14:59
The US Independence Day weekend of 2021 wasn't much of a holiday for cybersecurity staff. That was when the Kaseya attack unfolded...

☐ β˜† βœ‡ Naked Security

S3 Ep73: Ransomware with a difference, dirty Linux pipes, and much more [Podcast + Transcript]

By Paul Ducklin β€” March 10th 2022 at 19:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Ransomware with a difference: β€œDerestrict your software, or else!”

By Paul Ducklin β€” March 2nd 2022 at 16:33
"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.

☐ β˜† βœ‡ Naked Security

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]

By Paul Ducklin β€” February 24th 2022 at 16:51
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

VMware fixes holes that could allow virtual machine escapes

By Paul Ducklin β€” February 16th 2022 at 19:32
Hats off to VMware for not using weasel words: "When should you act?" Immediately...

☐ β˜† βœ‡ Naked Security

At last! Office macros from the internet to be blocked by default

By Paul Ducklin β€” February 8th 2022 at 16:34
It's been a long time coming, and we're not there yet, but at least Microsoft Office will be a bit safer against macro malware...

☐ β˜† βœ‡ Naked Security

Microsoft blocks web installation of its own App Installer files

By Paul Ducklin β€” February 7th 2022 at 16:36
It's a big deal when a vendor decides to block one of its own "features" for security reasons. Here's why we think it's a good idea.

☐ β˜† βœ‡ Naked Security

REvil ransomware crew allegedly busted in Russia, says FSB

By Naked Security writer β€” January 14th 2022 at 19:48
The Russian Federal Security Bureau has just published a report about the investigation and arrest of the infamous "REvil" ransomware crew.

☐ β˜† βœ‡ Naked Security

Firefox update brings a whole new sort of security sandbox

By Paul Ducklin β€” December 7th 2021 at 19:14
Firefox 95.0 is out, with the usual security fixes... plus some funky new ones.

☐ β˜† βœ‡ Naked Security

Black Friday and Cyber Monday – here’s what you REALLY need to do!

By Paul Ducklin β€” November 22nd 2021 at 19:52
The world fills up with cybersecurity tips every year when Black Friday comes round. But what about the rest of the year?

☐ β˜† βœ‡ Naked Security

S3 Ep59: Emotet, an FBI hoax, Samba bugs, and a hijackable suitcase [Podcast]

By Paul Ducklin β€” November 18th 2021 at 15:00
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Emotet malware: β€œThe report of my death was an exaggeration”

By Paul Ducklin β€” November 16th 2021 at 14:13
"Old malware rarely dies." The best way to predict the future is to look at the past... if it worked before, it will probably work again.

☐ β˜† βœ‡ Naked Security

S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust [Podcast]

By Paul Ducklin β€” November 11th 2021 at 17:41
Latest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Sophos 2022 Threat Report: Malware, Mobile, Machine learning and more!

By Paul Ducklin β€” November 9th 2021 at 19:31
The crooks have shown that they're willing to learn and adapt their attacks, so we need to make sure we learn and adapt, too.

☐ β˜† βœ‡ Naked Security

Kaseya ransomware suspect nabbed in Poland, $6m seized from absent colleague

By Naked Security writer β€” November 8th 2021 at 22:37
Suspects nabbed, millions seized, in ransomware busts across the globe.

☐ β˜† βœ‡ Naked Security

β€œCustomer complaint” email scam preys on your fear of getting into trouble at work

By Paul Ducklin β€” November 5th 2021 at 19:49
Stop. Think. Connect. Don't let the crooks trick you into acting in haste.

☐ β˜† βœ‡ Naked Security

S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars [Podcast]

By Paul Ducklin β€” November 4th 2021 at 17:46
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Europol announces β€œtargeting” of 12 suspects in ransomware attacks

By Naked Security writer β€” October 29th 2021 at 23:22
More anti-ransomware activity by law enforcement, this time in Switzerland and Ukraine.

☐ β˜† βœ‡ Naked Security

S3 Ep56: Cryptotrading rodent, ransomware hackback, and a Docusign phish [Podcast]

By Paul Ducklin β€” October 28th 2021 at 18:45
Latest episode - listen now! Serious security explained with personality in plain English.

ns-1200-logo-podcast-with-mic-and-rodent-emoji

☐ β˜† βœ‡ Naked Security

Listen up 2 – CYBERSECURITY FIRST! How to protect yourself from supply chain attacks

By Paul Ducklin β€” October 25th 2021 at 16:38
Everyone remembers this year's big-news supply chain attacks on Kaseya and SolarWinds. Sophos expert Chester Wisniewski explains how to control the risk.

☐ β˜† βœ‡ Naked Security

Listen up 3 – CYBERSECURITY FIRST! Cyberinsurance, help or hindrance?

By Paul Ducklin β€” October 25th 2021 at 16:37
Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance.

❌