FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

OpenSSH fixes double-free memory bug that’s pokable over the network

By Paul Ducklin β€” February 3rd 2023 at 17:59
It's a bug fix for a bug fix. A memory leak was turned into a double-free that has now been turned into correct code...

☐ β˜† βœ‡ Naked Security

S3 Ep120: When dud crypto simply won’t let go [Audio + Text]

By Paul Ducklin β€” February 2nd 2023 at 17:50
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By Paul Ducklin β€” February 1st 2023 at 19:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

Serious Security: The Samba logon bug caused by outdated crypto

By Paul Ducklin β€” January 30th 2023 at 19:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

☐ β˜† βœ‡ Naked Security

S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text]

By Paul Ducklin β€” January 26th 2023 at 19:57
Lastest episode - listen now! (Or read the transcript.)

☐ β˜† βœ‡ Naked Security

Apple patches are out – old iPhones get an old zero-day fix at last!

By Paul Ducklin β€” January 24th 2023 at 01:24
Don't delay, especially if you're still running an iOS 12 device... please do it today!

☐ β˜† βœ‡ Naked Security

Serious Security: How dEliBeRaTe tYpOs might imProVe DNS security

By Paul Ducklin β€” January 23rd 2023 at 19:59
It's a really cool and super-simple trick. The question is, "Will it help?"

☐ β˜† βœ‡ Naked Security

S3 Ep117: The crypto crisis that wasn’t (and farewell forever to Win 7) [Audio + Text]

By Paul Ducklin β€” January 12th 2023 at 17:59
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)

☐ β˜† βœ‡ Naked Security

Microsoft Patch Tuesday: One 0-day; Win 7 and 8.1 get last-ever patches

By Paul Ducklin β€” January 11th 2023 at 00:22
Get 'em while they're hot. And get 'em for the very last time, if you still have Windows 7 or 8.1...

☐ β˜† βœ‡ Naked Security

Popular JWT cloud security library patches β€œremote” code execution hole

By Paul Ducklin β€” January 10th 2023 at 19:59
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.

☐ β˜† βœ‡ Naked Security

CircleCI – code-building service suffers total credential compromise

By Paul Ducklin β€” January 9th 2023 at 14:52
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

☐ β˜† βœ‡ Naked Security

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

By Paul Ducklin β€” January 4th 2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

☐ β˜† βœ‡ Naked Security

Naked Security 33Β 1/3 – Cybersecurity predictions for 2023 and beyond

By Paul Ducklin β€” December 30th 2022 at 19:59
The problem with anniversaries is that there's an almost infinite number of them every day...

hny-1200

☐ β˜† βœ‡ Naked Security

Microsoft dishes the dirt on Apple’s β€œAchilles heel” shortly after fixing similar Windows bug

By Paul Ducklin β€” December 20th 2022 at 17:59
It happens to the best of us: Microsoft highlights a security bypass bug on Macs that is curiously similar to a recent Windows 0-day.

☐ β˜† βœ‡ Naked Security

S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text]

By Paul Ducklin β€” December 15th 2022 at 17:10
Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!

☐ β˜† βœ‡ Naked Security

Apple patches everything, finally reveals mystery of iOS 16.1.2

By Paul Ducklin β€” December 14th 2022 at 02:11
There's an update for everything this time, not just for iOS.

☐ β˜† βœ‡ Naked Security

Patch Tuesday: 0-days, RCE bugs, and a curious tale of signed malware

By Paul Ducklin β€” December 14th 2022 at 01:13
Tales of derring-do in the cyberunderground! (And some zero-days.)

☐ β˜† βœ‡ Naked Security

Pwn2Own Toronto: 54 hacks, 63 new bugs, $1 million in bounties

By Paul Ducklin β€” December 12th 2022 at 19:58
That's a mean average of $15,710 per bug... and 63 fewer bugs out there for crooks and rogues to find.

☐ β˜† βœ‡ Naked Security

S3 Ep112: Data breaches can haunt you more than once! [Audio + Text]

By Paul Ducklin β€” December 9th 2022 at 16:46
Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

☐ β˜† βœ‡ Naked Security

Number Nine! Chrome fixes another 2022 zero-day, Edge patched too

By Paul Ducklin β€” December 5th 2022 at 20:58
Ninth more unto the breach, dear friends, ninth more.

☐ β˜† βœ‡ Naked Security

Ping of death! FreeBSD fixes crashtastic bug in network tool

By Paul Ducklin β€” December 5th 2022 at 19:59
It's a venerable program, and this version had a venerable bug in it.

☐ β˜† βœ‡ Naked Security

Chrome fixes 8th zero-day of 2022 – check your version now (Edge too!)

By Paul Ducklin β€” November 28th 2022 at 19:42
There isn't a rhyme to remind you which months have browser zero-days... you just have to keep your eyes and ears open!

☐ β˜† βœ‡ Naked Security

How to hack an unpatched Exchange server with rogue PowerShell code

By Paul Ducklin β€” November 22nd 2022 at 19:54
Review your servers, your patches and your authentication policies - there's a proof-of-concept out

☐ β˜† βœ‡ Naked Security

S3 Ep109: How one leaked email password could drain your business [Audio + Transcript]

By Paul Ducklin β€” November 17th 2022 at 17:52
Latest episode - listen now! Cybersecurity news plus loads of great advice...

☐ β˜† βœ‡ Naked Security

Firefox fixes fullscreen fakery flaw – get the update now!

By Paul Ducklin β€” November 16th 2022 at 19:51
What's so bad about a web page going fullscreen without warning you first?

☐ β˜† βœ‡ Naked Security

Log4Shell-like code execution hole in popular Backstage dev tool

By Paul Ducklin β€” November 15th 2022 at 17:49
Good old "string templating", also known as "string interpolation", in the spotlight again...

bs-1200

☐ β˜† βœ‡ Naked Security

S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?

By Paul Ducklin β€” November 10th 2022 at 17:26
Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!

☐ β˜† βœ‡ Naked Security

Emergency code execution patch from Apple – but not an 0-day

By Paul Ducklin β€” November 10th 2022 at 01:49
Not a zero-day, but important enough for a quick-fire patch to one system library...

☐ β˜† βœ‡ Naked Security

Exchange 0-days fixed (at last) – plus 4 brand new Patch Tuesday 0-days!

By Paul Ducklin β€” November 9th 2022 at 19:58
In all the excitement, we kind of lost track ourselves. Were there six 0-days, or only four?

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

The OpenSSL security update story – how can you tell what needs fixing?

By Paul Ducklin β€” November 3rd 2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...

ossl-code-1200

☐ β˜† βœ‡ Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

By Paul Ducklin β€” November 1st 2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

☐ β˜† βœ‡ Naked Security

SHA-3 code execution bug patched in PHP – check your version!

By Paul Ducklin β€” November 1st 2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

☐ β˜† βœ‡ Naked Security

Chrome issues urgent zero-day fix – update now!

By Paul Ducklin β€” October 29th 2022 at 15:08
We've said it before/And we'll say it again/It's not *if* you should patch/It's a matter of *when*. (Hint: now!)

☐ β˜† βœ‡ Naked Security

Updates to Apple’s zero-day update story – iPhone and iPad users read this!

By Paul Ducklin β€” October 28th 2022 at 18:04
Turns out that Tuesday's zero-day for iOS 16 is Friday's zero-day for iOS 15...

☐ β˜† βœ‡ Naked Security

Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!

By Paul Ducklin β€” October 25th 2022 at 18:03
Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

☐ β˜† βœ‡ Naked Security

Dangerous hole in Apache Commons Text – like Log4Shell all over again

By Paul Ducklin β€” October 18th 2022 at 17:26
Third time unlucky. Time to put your patching boots on again...

act-1200

☐ β˜† βœ‡ Naked Security

Patch Tuesday in brief – one 0-day fixed, but no patches for Exchange!

By Paul Ducklin β€” October 12th 2022 at 16:58
There's a zero-day patch, but it's not for the zero-day you thought.

☐ β˜† βœ‡ Naked Security

Mystery iPhone update patches against iOS 16 mail crash-attack

By Paul Ducklin β€” October 11th 2022 at 00:28
The problem with crashy messaging apps is that *other people* get to choose if and when to send you messages...

☐ β˜† βœ‡ Naked Security

S3 Ep103: Scammers in the Slammer (and other stories) [Audio + Text]

By Paul Ducklin β€” October 6th 2022 at 14:43
Latest episode - listen and learn now (or read and revise, if the written word is your thing)...

☐ β˜† βœ‡ Naked Security

S3 Ep102.5: β€œProxyNotShell” Exchange bugs – an expert speaks [Audio + Text]

By Paul Ducklin β€” October 1st 2022 at 14:05
Who's affected, what you can do while waiting for Microsoft's patches, and how to plan your threat hunting...

☐ β˜† βœ‡ Naked Security

URGENT! Microsoft Exchange double zero-day – β€œlike ProxyShell, only different”

By Paul Ducklin β€” September 30th 2022 at 18:25
Double-play 0-day in Exchange - what you need to know, and what you can do

☐ β˜† βœ‡ Naked Security

WhatsApp β€œzero-day exploit” news scare – what you need to know

By Paul Ducklin β€” September 27th 2022 at 18:51
Is WhatsApp currently under active attack by cybercriminals? Is this a clear and current danger? How worried should WhatsApp users be?

☐ β˜† βœ‡ Naked Security

Apple patches zero-day holes – even in the brand new iOS 16

By Paul Ducklin β€” September 12th 2022 at 21:25
Five updates, one upgrade, plus two zero-days. Patch your Macs, iPhones and iPads as soon as you can (again)...

apple-plus-16-1200

☐ β˜† βœ‡ Naked Security

Chrome and Edge fix zero-day security hole – update now!

By Paul Ducklin β€” September 5th 2022 at 15:12
This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.

☐ β˜† βœ‡ Naked Security

S3 Ep98: The LastPass saga – should we stop using password managers? [Audio + Text]

By Paul Ducklin β€” September 1st 2022 at 16:55
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Chrome patches 24 security holes, enables β€œSanitizer” safety system

By Paul Ducklin β€” August 31st 2022 at 11:48
24 existing bugs fixed. And, we hope, numerous potential future bugs prevented.

☐ β˜† βœ‡ Naked Security

JavaScript bugs aplenty in Node.js ecosystem – found automatically

By Paul Ducklin β€” August 30th 2022 at 16:59
How to get the better of bugs in all the possible packages in your supply chain?

☐ β˜† βœ‡ Naked Security

Firefox 104 is out – no critical bugs, but update anyway

By Paul Ducklin β€” August 26th 2022 at 16:27
Two trust-spoofing bugs were the main culprits this month - but neither one was a zero-day.

☐ β˜† βœ‡ Naked Security

S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text]

By Paul Ducklin β€” August 25th 2022 at 15:37
Latest episode - listen now! (Or read the transcript if you prefer the text version.)

☐ β˜† βœ‡ Naked Security

Breaching airgap security: using your phone’s gyroscope as a microphone

By Paul Ducklin β€” August 24th 2022 at 18:59
One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...

☐ β˜† βœ‡ Naked Security

Bitcoin ATMs leeched by attackers who created fake admin accounts

By Paul Ducklin β€” August 23rd 2022 at 18:35
The criminals didn't implant any malware. The attack was orchestrated via malevolent configuration changes.

☐ β˜† βœ‡ Naked Security

Laptop denial-of-service via music: the 1980s R&B song with a CVE!

By Paul Ducklin β€” August 22nd 2022 at 16:03
We haven't validated this vuln ourselves... but the source of the story is impeccable. (Impeccably dressed, at least.)

☐ β˜† βœ‡ Naked Security

Apple patches double zero-day in browser and kernel – update now!

By Paul Ducklin β€” August 17th 2022 at 23:33
Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

☐ β˜† βœ‡ Naked Security

Chrome browser gets 11 security fixes with 1 zero-day – update now!

By Paul Ducklin β€” August 17th 2022 at 13:16
Don't delay - patch today.

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches critical bug – update now!

By Paul Ducklin β€” August 15th 2022 at 18:26
There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]

By Paul Ducklin β€” August 4th 2022 at 17:52
Latest episode - listen now! (Or read if that's what you prefer.)

☐ β˜† βœ‡ Naked Security

Cryptocoin β€œtoken swapper” Nomad loses $200 million in coding blunder

By Paul Ducklin β€” August 2nd 2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.

❌