Login
FreshRSS
Login
Naked Security
SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m
By
Naked Security writer
β December 6
th
2022 at 17:56
Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.
Naked Security
S3 Ep111: The business risk of a sleazy βnudity unfilterβ [Audio + Text]
By
Paul Ducklin
β December 1
st
2022 at 19:58
Latest episode - listen now (or read if you prefer)...
Naked Security
Serious Security: MD5 considered harmful β to the tune of $600,000
By
Paul Ducklin
β November 30
th
2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!
Naked Security
TikTok βInvisible Challengeβ porn malware puts us all at risk
By
Paul Ducklin
β November 29
th
2022 at 19:58
An injury to one is an injury to all. Especially if the other people are part of your social network.
Naked Security
Multimillion dollar CryptoRom scam sites seized, suspects arrested in US
By
Paul Ducklin
β November 23
rd
2022 at 19:58
Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...
cryptorom-1200
Naked Security
S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?
By
Paul Ducklin
β November 10
th
2022 at 17:26
Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!
Naked Security
Silk Road drugs market hacker pleads guilty, faces 20 years inside
By
Paul Ducklin
β November 8
th
2022 at 19:58
Jurisprudence isn't like arithmetic... two negatives never make a positive!
Naked Security
Twitter Blue Badge email scams β Donβt fall for them!
By
Naked Security writer
β November 4
th
2022 at 17:59
That was the week that was...
Naked Security
S3 Ep107: Eight months to kick out the crooks and you think thatβs GOOD? [Audio + Text]
By
Paul Ducklin
β November 3
rd
2022 at 17:51
Listen now - latest episode - audio plus full transcript
Naked Security
The OpenSSL security update story β how can you tell what needs fixing?
By
Paul Ducklin
β November 3
rd
2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...
ossl-code-1200
Naked Security
OpenSSL patches are outΒ β CRITICAL bug downgraded to HIGH, but patch anyway!
By
Paul Ducklin
β November 1
st
2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...
Naked Security
SHA-3 code execution bug patched in PHP β check your version!
By
Paul Ducklin
β November 1
st
2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!
Naked Security
Psychotherapy extortion suspect: arrest warrant issued
By
Paul Ducklin
β October 31
st
2022 at 19:59
Wanted! Not only the extortionist who abused the data, but also the CEO who let it happen.
Naked Security
S3 Ep106: Facial recognition without consent β should it be banned?
By
Paul Ducklin
β October 27
th
2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!
Naked Security
Clearview AI image-scraping face recognition service hit with β¬20m fine in France
By
Paul Ducklin
β October 26
th
2022 at 00:50
"We told you to stop but you ignored us," said the French regulator, "so now we're coming after you again."
Naked Security
Serious Security: How randomly (or not) can you shuffle cards?
By
Paul Ducklin
β October 24
th
2022 at 18:57
What if you could guess the next card correctly twice as often as you should?
card-fan-1200
Naked Security
When cops hack back: Dutch police fleece DEADBOLT criminals (legally!)
By
Paul Ducklin
β October 21
st
2022 at 18:25
Crooks: Show us the money! Cops: How about you show us the decryption keys first?
Naked Security
S3 Ep105: WONTFIX! The MS Office cryptofail that βisnβt a security flawβ [Audio + Text]
By
Paul Ducklin
β October 20
th
2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!
pic-1200
Naked Security
Women in Cryptology β USPS celebrates WW2 codebreakers
By
Paul Ducklin
β October 19
th
2022 at 16:58
What did you do in the war, Mom? Oh, y'know, a bit of this and that...
Naked Security
Fashion brand SHEIN fined $1.9m for lying about data breach
By
Naked Security writer
β October 17
th
2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?
Naked Security
Serious Security: Microsoft Office 365 attacked over feeble encryption
By
Paul Ducklin
β October 14
th
2022 at 16:59
How 2022 is your encryption?
Naked Security
Serious Security: OAuth 2 and why Microsoft is finally forcing you into it
By
Paul Ducklin
β October 10
th
2022 at 18:02
Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.
Naked Security
S3 Ep99: TikTok βattackβ β was there a data breach, or not? [Audio + Text]
By
Paul Ducklin
β September 8
th
2022 at 13:21
Latest episode - listen now! (Or read if you prefer - full transcript inside.)
Naked Security
S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text]
By
Paul Ducklin
β August 25
th
2022 at 15:37
Latest episode - listen now! (Or read the transcript if you prefer the text version.)
Naked Security
Bitcoin ATMs leeched by attackers who created fake admin accounts
By
Paul Ducklin
β August 23
rd
2022 at 18:35
The criminals didn't implant any malware. The attack was orchestrated via malevolent configuration changes.
Naked Security
S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]
By
Paul Ducklin
β August 18
th
2022 at 18:38
Latest episode - listen now (or read if you prefer!)
Naked Security
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]
By
Paul Ducklin
β August 11
th
2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)
Naked Security
APIC/EPIC! Intel chips leak secrets even the kernel shouldnβt seeβ¦
By
Paul Ducklin
β August 10
th
2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!
Naked Security
Slack admits to leaking hashed passwords for five years
By
Paul Ducklin
β August 8
th
2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."
Naked Security
S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]
By
Paul Ducklin
β August 4
th
2022 at 17:52
Latest episode - listen now! (Or read if that's what you prefer.)
Naked Security
Post-quantum cryptography β new algorithm βgone in 60 minutesβ
By
Paul Ducklin
β August 3
rd
2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.
Naked Security
Cryptocoin βtoken swapperβ Nomad loses $200 million in coding blunder
By
Paul Ducklin
β August 2
nd
2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.
Naked Security
GnuTLS patches memory mismanagement bug β update now!
By
Paul Ducklin
β August 1
st
2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...
Naked Security
S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]
By
Paul Ducklin
β July 14
th
2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.
Naked Security
Paying ransomware crooks wonβt reduce your legal risk, warns regulator
By
Paul Ducklin
β July 12
th
2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?
Naked Security
S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]
By
Paul Ducklin
β July 7
th
2022 at 18:46
Listen now! Or read if you prefer...
Naked Security
OpenSSL fixes two βone-linerβ crypto bugs β what you need to know
By
Paul Ducklin
β July 6
th
2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...
Naked Security
Canadian cybercriminal pleads guilty to βNetWalkerβ attacks in US
By
Paul Ducklin
β July 4
th
2022 at 14:09
Bust in Canada, now bust in the USA as well.
Naked Security
βMissing Cryptoqueenβ hits the FBIβs Ten Most Wanted list
By
Paul Ducklin
β July 1
st
2022 at 16:49
The "Missing Cryptoqueen" makes the American Top Ten... but not in a good way.
Naked Security
S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]
By
Paul Ducklin
β June 30
th
2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!
Naked Security
Harmony blockchain loses nearly $100M due to hacked private keys
By
Paul Ducklin
β June 27
th
2022 at 18:14
The crooks needed at least two private keys, each stored in two parts... but they got them anyway.
Naked Security
FTC warns of LGBTQ+ extortion scams β be aware before you share!
By
Paul Ducklin
β June 27
th
2022 at 14:58
It's a simple jingle and it's solid advice: "If in doubt, don't give it out!"
Naked Security
OpenSSL issues a bugfix for the previous bugfix
By
Paul Ducklin
β June 24
th
2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.
Naked Security
S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]
By
Paul Ducklin
β June 23
rd
2022 at 11:08
Latest epsiode - listen (or read) now!
Naked Security
Capital One identity theft hacker finally gets convicted
By
Paul Ducklin
β June 21
st
2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!
Naked Security
Murder suspect admits she tracked cheating partner with hidden AirTag
By
Paul Ducklin
β June 14
th
2022 at 18:49
O! What a tangled web we weave, when first we practise to deceive.
Naked Security
Whoβs watching your webcam? The Screencastify Chrome extension storyβ¦
By
Paul Ducklin
β May 26
th
2022 at 12:41
When you really need to make exceptions in cybersecurity, specify them as explicitly as you can.
Naked Security
Microsoft patches the Patch Tuesday patch that broke authentication
By
Paul Ducklin
β May 20
th
2022 at 22:35
Remember the good old days when security patches rarely needed patches? Because security patches themlelves were rare enough anyway?
Naked Security
He sold cracked passwords for a living β now heβs serving 4 years in prison
By
Paul Ducklin
β May 13
th
2022 at 18:31
Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...
Naked Security
S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]
By
Paul Ducklin
β April 21
st
2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!
Naked Security
Critical cryptographic Java security blunder patched β update now!
By
Paul Ducklin
β April 20
th
2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.
Naked Security
Beanstalk cryptocurrency heist: scammer votes himself all the money
By
Paul Ducklin
β April 19
th
2022 at 16:00
Voting safeguards based on commuity collateral don't work if one person can use a momentary loan to "become" 75% of the community.
Naked Security
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
By
Paul Ducklin
β April 14
th
2022 at 13:39
Latest episode - listen now!
Naked Security
US cryptocurrency coder gets 5 years for North Korea sanctions busting
By
Naked Security writer
β April 13
th
2022 at 15:52
Cryptocurrency expert didn't take "No" for an answer when the US authorities said he couldn't pursue cryptocoin opps in North Korea.
Naked Security
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
By
Paul Ducklin
β April 11
th
2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?
cat-1200
Naked Security
Serious Security: Darkweb drugs market Hydra taken offline by German police
By
Paul Ducklin
β April 6
th
2022 at 16:22
Why are Tor sites hard to locate and therefore difficult to take down? We explain in plain English...
Naked Security
LAPSUS$ hacks continue despite two hacker suspects in court
By
Paul Ducklin
β April 4
th
2022 at 21:36
Do you know where in your company to report security anomalies? If you receive such reports, do you have an efficient way to process them?
Naked Security
UK police arrest 7 hacking suspects β have they bust the LAPSUS$ gang?
By
Naked Security writer
β March 25
th
2022 at 01:48
Seven alleged hackers have been arrested in the UK. But who are they, and which hacking crew are they from?
Naked Security
S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]
By
Paul Ducklin
β March 24
th
2022 at 13:49
Latest episode - listen now!
Naked Security
OpenSSL patches infinite-loop DoS bug in certificate verification
By
Paul Ducklin
β March 18
th
2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!
Load more articles