FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

By Paul Ducklin β€” November 1st 2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

☐ β˜† βœ‡ Naked Security

SHA-3 code execution bug patched in PHP – check your version!

By Paul Ducklin β€” November 1st 2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

☐ β˜† βœ‡ Naked Security

Psychotherapy extortion suspect: arrest warrant issued

By Paul Ducklin β€” October 31st 2022 at 19:59
Wanted! Not only the extortionist who abused the data, but also the CEO who let it happen.

☐ β˜† βœ‡ Naked Security

S3 Ep106: Facial recognition without consent – should it be banned?

By Paul Ducklin β€” October 27th 2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!

☐ β˜† βœ‡ Naked Security

Clearview AI image-scraping face recognition service hit with €20m fine in France

By Paul Ducklin β€” October 26th 2022 at 00:50
"We told you to stop but you ignored us," said the French regulator, "so now we're coming after you again."

☐ β˜† βœ‡ Naked Security

Serious Security: How randomly (or not) can you shuffle cards?

By Paul Ducklin β€” October 24th 2022 at 18:57
What if you could guess the next card correctly twice as often as you should?

card-fan-1200

☐ β˜† βœ‡ Naked Security

When cops hack back: Dutch police fleece DEADBOLT criminals (legally!)

By Paul Ducklin β€” October 21st 2022 at 18:25
Crooks: Show us the money! Cops: How about you show us the decryption keys first?

☐ β˜† βœ‡ Naked Security

S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text]

By Paul Ducklin β€” October 20th 2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!

pic-1200

☐ β˜† βœ‡ Naked Security

Women in Cryptology – USPS celebrates WW2 codebreakers

By Paul Ducklin β€” October 19th 2022 at 16:58
What did you do in the war, Mom? Oh, y'know, a bit of this and that...

☐ β˜† βœ‡ Naked Security

Fashion brand SHEIN fined $1.9m for lying about data breach

By Naked Security writer β€” October 17th 2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

☐ β˜† βœ‡ Naked Security

Serious Security: Microsoft Office 365 attacked over feeble encryption

By Paul Ducklin β€” October 14th 2022 at 16:59
How 2022 is your encryption?

☐ β˜† βœ‡ Naked Security

Serious Security: OAuth 2 and why Microsoft is finally forcing you into it

By Paul Ducklin β€” October 10th 2022 at 18:02
Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.

☐ β˜† βœ‡ Naked Security

S3 Ep99: TikTok β€œattack” – was there a data breach, or not? [Audio + Text]

By Paul Ducklin β€” September 8th 2022 at 13:21
Latest episode - listen now! (Or read if you prefer - full transcript inside.)

☐ β˜† βœ‡ Naked Security

S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text]

By Paul Ducklin β€” August 25th 2022 at 15:37
Latest episode - listen now! (Or read the transcript if you prefer the text version.)

☐ β˜† βœ‡ Naked Security

Bitcoin ATMs leeched by attackers who created fake admin accounts

By Paul Ducklin β€” August 23rd 2022 at 18:35
The criminals didn't implant any malware. The attack was orchestrated via malevolent configuration changes.

☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By Paul Ducklin β€” August 18th 2022 at 18:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]

By Paul Ducklin β€” August 4th 2022 at 17:52
Latest episode - listen now! (Or read if that's what you prefer.)

☐ β˜† βœ‡ Naked Security

Post-quantum cryptography – new algorithm β€œgone in 60 minutes”

By Paul Ducklin β€” August 3rd 2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.

☐ β˜† βœ‡ Naked Security

Cryptocoin β€œtoken swapper” Nomad loses $200 million in coding blunder

By Paul Ducklin β€” August 2nd 2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.

☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]

By Paul Ducklin β€” July 14th 2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.

☐ β˜† βœ‡ Naked Security

Paying ransomware crooks won’t reduce your legal risk, warns regulator

By Paul Ducklin β€” July 12th 2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

☐ β˜† βœ‡ Naked Security

S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]

By Paul Ducklin β€” July 7th 2022 at 18:46
Listen now! Or read if you prefer...

☐ β˜† βœ‡ Naked Security

OpenSSL fixes two β€œone-liner” crypto bugs – what you need to know

By Paul Ducklin β€” July 6th 2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...

☐ β˜† βœ‡ Naked Security

Canadian cybercriminal pleads guilty to β€œNetWalker” attacks in US

By Paul Ducklin β€” July 4th 2022 at 14:09
Bust in Canada, now bust in the USA as well.

☐ β˜† βœ‡ Naked Security

β€œMissing Cryptoqueen” hits the FBI’s Ten Most Wanted list

By Paul Ducklin β€” July 1st 2022 at 16:49
The "Missing Cryptoqueen" makes the American Top Ten... but not in a good way.

☐ β˜† βœ‡ Naked Security

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

By Paul Ducklin β€” June 30th 2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!

☐ β˜† βœ‡ Naked Security

Harmony blockchain loses nearly $100M due to hacked private keys

By Paul Ducklin β€” June 27th 2022 at 18:14
The crooks needed at least two private keys, each stored in two parts... but they got them anyway.

☐ β˜† βœ‡ Naked Security

FTC warns of LGBTQ+ extortion scams – be aware before you share!

By Paul Ducklin β€” June 27th 2022 at 14:58
It's a simple jingle and it's solid advice: "If in doubt, don't give it out!"

☐ β˜† βœ‡ Naked Security

OpenSSL issues a bugfix for the previous bugfix

By Paul Ducklin β€” June 24th 2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

☐ β˜† βœ‡ Naked Security

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]

By Paul Ducklin β€” June 23rd 2022 at 11:08
Latest epsiode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

Murder suspect admits she tracked cheating partner with hidden AirTag

By Paul Ducklin β€” June 14th 2022 at 18:49
O! What a tangled web we weave, when first we practise to deceive.

☐ β˜† βœ‡ Naked Security

Who’s watching your webcam? The Screencastify Chrome extension story…

By Paul Ducklin β€” May 26th 2022 at 12:41
When you really need to make exceptions in cybersecurity, specify them as explicitly as you can.

☐ β˜† βœ‡ Naked Security

Microsoft patches the Patch Tuesday patch that broke authentication

By Paul Ducklin β€” May 20th 2022 at 22:35
Remember the good old days when security patches rarely needed patches? Because security patches themlelves were rare enough anyway?

☐ β˜† βœ‡ Naked Security

He sold cracked passwords for a living – now he’s serving 4 years in prison

By Paul Ducklin β€” May 13th 2022 at 18:31
Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...

☐ β˜† βœ‡ Naked Security

S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]

By Paul Ducklin β€” April 21st 2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

Beanstalk cryptocurrency heist: scammer votes himself all the money

By Paul Ducklin β€” April 19th 2022 at 16:00
Voting safeguards based on commuity collateral don't work if one person can use a momentary loan to "become" 75% of the community.

☐ β˜† βœ‡ Naked Security

S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]

By Paul Ducklin β€” April 14th 2022 at 13:39
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

US cryptocurrency coder gets 5 years for North Korea sanctions busting

By Naked Security writer β€” April 13th 2022 at 15:52
Cryptocurrency expert didn't take "No" for an answer when the US authorities said he couldn't pursue cryptocoin opps in North Korea.

☐ β˜† βœ‡ Naked Security

OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default

By Paul Ducklin β€” April 11th 2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?

cat-1200

☐ β˜† βœ‡ Naked Security

Serious Security: Darkweb drugs market Hydra taken offline by German police

By Paul Ducklin β€” April 6th 2022 at 16:22
Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...

☐ β˜† βœ‡ Naked Security

LAPSUS$ hacks continue despite two hacker suspects in court

By Paul Ducklin β€” April 4th 2022 at 21:36
Do you know where in your company to report security anomalies? If you receive such reports, do you have an efficient way to process them?

☐ β˜† βœ‡ Naked Security

UK police arrest 7 hacking suspects – have they bust the LAPSUS$ gang?

By Naked Security writer β€” March 25th 2022 at 01:48
Seven alleged hackers have been arrested in the UK. But who are they, and which hacking crew are they from?

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

OpenSSL patches infinite-loop DoS bug in certificate verification

By Paul Ducklin β€” March 18th 2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!

☐ β˜† βœ‡ Naked Security

Beware bogus Betas – cryptocoin scammers abuse Apple’s TestFlight system

By Paul Ducklin β€” March 16th 2022 at 15:49
"Install this moneymaking app" - this one is so special that it isn't available on Google Play or the App Store!

☐ β˜† βœ‡ Naked Security

Cryptocoin ATMs ruled illegal – β€œShut down at once”, says regulator

By Paul Ducklin β€” March 14th 2022 at 17:51
If you live in the UK and hadn't yet heard of cryptocoin ATMs... it's too late now!

☐ β˜† βœ‡ Naked Security

Alleged Kaseya ransomware attacker arrives in Texas for trial

By Naked Security writer β€” March 11th 2022 at 14:59
The US Independence Day weekend of 2021 wasn't much of a holiday for cybersecurity staff. That was when the Kaseya attack unfolded...

☐ β˜† βœ‡ Naked Security

Ransomware with a difference: β€œDerestrict your software, or else!”

By Paul Ducklin β€” March 2nd 2022 at 16:33
"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.

☐ β˜† βœ‡ Naked Security

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]

By Paul Ducklin β€” February 24th 2022 at 16:51
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

French speakers blasted by sextortion scams with no text or links

By Paul Ducklin β€” February 21st 2022 at 17:59
You'd spot this one a mile away... but what about your friends or family?

☐ β˜† βœ‡ Naked Security

S3 Ep70: Bitcoin, billing blunders, and 0-day after 0-day after 0-day [Podcast + Transcript]

By Paul Ducklin β€” February 17th 2022 at 17:12
Latest episode - listen and learn!

☐ β˜† βœ‡ Naked Security

S3 Ep69: WordPress woes, Wormhole holes, and a Microsoft change of heart [Podcast + Transcript]

By Paul Ducklin β€” February 10th 2022 at 01:15
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Self-styled β€œCrocodile of Wall Street” arrested with husband over Bitcoin megaheist

By Naked Security writer β€” February 9th 2022 at 14:44
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!

☐ β˜† βœ‡ Naked Security

Wormhole cryptotrading company turns over $340,000,000 to criminals

By Paul Ducklin β€” February 4th 2022 at 17:38
It was the best of blockchains, it was the worst of blockchains... as Charles Dickens might have said.

❌