FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Black Friday and retail season – watch out for PayPal β€œmoney request” scams

By Paul Ducklin β€” November 17th 2022 at 12:45
Don't let a keen eye for bargains lead you into risky online behaviour...

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

S3 Ep106: Facial recognition without consent – should it be banned?

By Paul Ducklin β€” October 27th 2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!

☐ β˜† βœ‡ Naked Security

Online ticketing company β€œSee” pwned for 2.5 years by attackers

By Paul Ducklin β€” October 26th 2022 at 19:58
Don't be a cybersecurity slowcoach - you need to spot possible attacks as soon as you can.

☐ β˜† βœ‡ Naked Security

S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text]

By Paul Ducklin β€” October 20th 2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!

pic-1200

☐ β˜† βœ‡ Naked Security

Fashion brand SHEIN fined $1.9m for lying about data breach

By Naked Security writer β€” October 17th 2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

☐ β˜† βœ‡ Naked Security

Former Uber CSO convicted of covering up megabreach back in 2016

By Naked Security writer β€” October 6th 2022 at 01:04
Obstructed FTC proceedings, and concealed a crime, said the jury.

☐ β˜† βœ‡ Naked Security

Optus breach – Aussie telco told it will have to pay to replace IDs

By Paul Ducklin β€” September 28th 2022 at 13:55
Licence compromised? Passport number burned? Need a new one? Who's going to pay?

☐ β˜† βœ‡ Naked Security

Morgan Stanley fined millions for selling off devices full of customer PII

By Paul Ducklin β€” September 23rd 2022 at 18:07
Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...

☐ β˜† βœ‡ Naked Security

S3 Ep101: Uber and LastPass breaches – is 2FA all it’s cracked up to be? [Audio + Text]

By Paul Ducklin β€” September 22nd 2022 at 18:42
Latest episode - listen now! Learn why adopting 2FA isn't a reason to relax your other security precautions...

☐ β˜† βœ‡ Naked Security

LastPass source code breach – incident response report released

By Paul Ducklin β€” September 19th 2022 at 18:59
Wondering how you'd handle a data breach report if the worst happened to you? Here's a useful example.

☐ β˜† βœ‡ Naked Security

S3 Ep100.5: Uber breach – an expert speaks [Audio + Text]

By Paul Ducklin β€” September 17th 2022 at 20:57
Chester Wisniewski on what we can learn from Uber: "Just because a big company didn't have the security they should doesn't mean you can't."

☐ β˜† βœ‡ Naked Security

UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you

By Paul Ducklin β€” September 16th 2022 at 18:43
Uber is all over the news for a widely-publicised data breach. We help you answer the question, "How do I stop this happening to me?"

☐ β˜† βœ‡ Naked Security

Serious Security: Browser-in-the-browser attacks – watch out for windows that aren’t!

By Paul Ducklin β€” September 13th 2022 at 20:52
Simple but super-sneaky - use a picture of a browser, and convince people it's real...

pipe-light-not-1200

☐ β˜† βœ‡ Naked Security

S3 Ep98: The LastPass saga – should we stop using password managers? [Audio + Text]

By Paul Ducklin β€” September 1st 2022 at 16:55
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

LastPass source code breach – do we still recommend password managers?

By Paul Ducklin β€” August 29th 2022 at 16:59
What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?

☐ β˜† βœ‡ Naked Security

Breaching airgap security: using your phone’s gyroscope as a microphone

By Paul Ducklin β€” August 24th 2022 at 18:59
One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

S3 Ep93: Office security, breach costs, and leisurely patches [Audio + Text]

By Paul Ducklin β€” July 28th 2022 at 15:47
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

T-Mobile to cough up $500 million over 2021 data breach

By Paul Ducklin β€” July 25th 2022 at 16:20
Technically, it's not a fine, and the lawyers will get a big chunk of it. But it still adds up to a half-billion-dollar data breach.

☐ β˜† βœ‡ Naked Security

Office macro security: on-again-off-again feature now BACK ON AGAIN!

By Paul Ducklin β€” July 23rd 2022 at 01:10
20 years to turn it on, then 20 weeks to turn it off, then just 2 weeks to turn it back on again. That's progress!

☐ β˜† βœ‡ Naked Security

Facebook 2FA phish arrives just 28 minutes after scam domain created

By Paul Ducklin β€” July 1st 2022 at 20:01
The crooks hit us up with this phishing email less than half an hour after they activated their new scam domain.

☐ β˜† βœ‡ Naked Security

Harmony blockchain loses nearly $100M due to hacked private keys

By Paul Ducklin β€” June 27th 2022 at 18:14
The crooks needed at least two private keys, each stored in two parts... but they got them anyway.

☐ β˜† βœ‡ Naked Security

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]

By Paul Ducklin β€” June 23rd 2022 at 11:08
Latest epsiode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

GitHub issues final report on supply-chain source code intrusions

By Paul Ducklin β€” April 29th 2022 at 16:15
Learn how to find out which apps you've given access rights to, and how to revoke those rights immediately in an emergency.

☐ β˜† βœ‡ Naked Security

LAPSUS$ hacks continue despite two hacker suspects in court

By Paul Ducklin β€” April 4th 2022 at 21:36
Do you know where in your company to report security anomalies? If you receive such reports, do you have an efficient way to process them?

☐ β˜† βœ‡ Naked Security

World Backup Day: 5 data recovery tips for everyone!

By Paul Ducklin β€” March 30th 2022 at 15:10
The only backup you will ever regret is the one you didn't make

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Adafruit suffers GitHub data breach – don’t let this happen to you

By Paul Ducklin β€” March 7th 2022 at 12:47
Training data stashed in GitHub by mistake... unfortunately, it was *real* data

☐ β˜† βœ‡ Naked Security

Linux kernel patches β€œperformance can be harmful” bug in video driver

By Paul Ducklin β€” February 1st 2022 at 19:59
This bug is fiendishly hard to exploit - but if you patch, it won't be there to exploit at all.

☐ β˜† βœ‡ Naked Security

Serious Security: Apple Safari leaks private data via database API – what you need to know

By Paul Ducklin β€” January 18th 2022 at 19:23
There's a tiny data leakage bug in the WebKit browser engine... but it could act as a "supercookie" identifier for your browsing

☐ β˜† βœ‡ Naked Security

FTC threatens β€œlegal action” over unpatched Log4j and other vulns

By Paul Ducklin β€” January 5th 2022 at 19:37
Remember the Equifax breach? Remember the $700m penalty? In case you'd forgotten, here's the FTC to refresh your memory!

☐ β˜† βœ‡ Naked Security

US government securities watchdog spoofed by investment scammers – don’t fall for it!

By Paul Ducklin β€” November 24th 2021 at 19:57
Those numbers that show up on your phone to tell you who's calling? Treat them as SUGGESTIONS, never as PROOF.

☐ β˜† βœ‡ Naked Security

GoDaddy admits to password breach: check your Managed WordPress site!

By Paul Ducklin β€” November 23rd 2021 at 00:35
GoDaddy found crooks in its network, and kicked them out - but not before they'd been in there for six weeks.

☐ β˜† βœ‡ Naked Security

Github cookie leakage – thousands of Firefox cookie files uploaded by mistake

By Paul Ducklin β€” November 18th 2021 at 22:20
Be aware before you share! That's a good rule for developers and techies, just as much as it is for social media addicts.

❌