FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Tracers in the Dark: The Global Hunt for the Crime Lords of Crypto

By Paul Ducklin β€” February 6th 2023 at 21:53
Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...

☐ β˜† βœ‡ Naked Security

Finnish psychotherapy extortion suspect arrested in France

By Naked Security writer β€” February 6th 2023 at 19:13
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

☐ β˜† βœ‡ Naked Security

S3 Ep120: When dud crypto simply won’t let go [Audio + Text]

By Paul Ducklin β€” February 2nd 2023 at 17:50
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By Paul Ducklin β€” February 1st 2023 at 19:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

Serious Security: The Samba logon bug caused by outdated crypto

By Paul Ducklin β€” January 30th 2023 at 19:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

☐ β˜† βœ‡ Naked Security

S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text]

By Paul Ducklin β€” January 26th 2023 at 19:57
Lastest episode - listen now! (Or read the transcript.)

☐ β˜† βœ‡ Naked Security

GoTo admits: Customer cloud backups stolen together with decryption key

By Paul Ducklin β€” January 25th 2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

☐ β˜† βœ‡ Naked Security

S3 Ep118: Guess your password? No need if it’s stolen already! [Audio + Text]

By Paul Ducklin β€” January 19th 2023 at 15:53
As always: entertaining, informative and educational... and not bogged down with jargon! Listen (or read) now...

☐ β˜† βœ‡ Naked Security

Serious Security: Unravelling the LifeLock β€œhacked passwords” story

By Paul Ducklin β€” January 17th 2023 at 17:59
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.

☐ β˜† βœ‡ Naked Security

Multi-million investment scammers busted in four-country Europol raid

By Paul Ducklin β€” January 16th 2023 at 16:10
216 questioned, 15 arrested, 4 fake call centres searched, millions seized...

☐ β˜† βœ‡ Naked Security

S3 Ep117: The crypto crisis that wasn’t (and farewell forever to Win 7) [Audio + Text]

By Paul Ducklin β€” January 12th 2023 at 17:59
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)

☐ β˜† βœ‡ Naked Security

Popular JWT cloud security library patches β€œremote” code execution hole

By Paul Ducklin β€” January 10th 2023 at 19:59
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.

☐ β˜† βœ‡ Naked Security

RSA crypto cracked? Or perhaps not!

By Paul Ducklin β€” January 6th 2023 at 19:59
Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?

☐ β˜† βœ‡ Naked Security

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]

By Paul Ducklin β€” January 5th 2023 at 17:52
Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

By Paul Ducklin β€” January 4th 2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

☐ β˜† βœ‡ Naked Security

Inside a scammers’ lair: Ukraine busts 40 in fake bank call-centre raid

By Naked Security writer β€” January 3rd 2023 at 17:03
When someone calls you up to warn you that your bank account is under attack - it's true, because THAT VERY PERSON is the one attacking you!

☐ β˜† βœ‡ Naked Security

PyTorch: Machine Learning toolkit pwned from Christmas to New Year

By Paul Ducklin β€” January 1st 2023 at 21:36
The bad news: the crooks have your SSH private keys. The good news: only users of the "nightly" build were affected.

☐ β˜† βœ‡ Naked Security

US passes the Quantum Computing Cybersecurity Preparedness Act – and why not?

By Paul Ducklin β€” December 29th 2022 at 20:45
Cryptographic agility: the ability and the willingness to change quickly when needed.

sc-daa-1200

☐ β˜† βœ‡ Naked Security

Twitter data of β€œ+400 million unique users” up for sale – what to do?

By Paul Ducklin β€” December 28th 2022 at 19:59
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?

☐ β˜† βœ‡ Naked Security

OneCoin scammer Sebastian Greenwood pleads guilty, β€œCryptoqueen” still missing

By Paul Ducklin β€” December 19th 2022 at 19:50
The Cryptoqueen herself is still missing, but her co-conspirator, who is said to have pocketed over $20m a month, has been convicted.

☐ β˜† βœ‡ Naked Security

SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m

By Naked Security writer β€” December 6th 2022 at 17:56
Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.

☐ β˜† βœ‡ Naked Security

S3 Ep111: The business risk of a sleazy β€œnudity unfilter” [Audio + Text]

By Paul Ducklin β€” December 1st 2022 at 19:58
Latest episode - listen now (or read if you prefer)...

☐ β˜† βœ‡ Naked Security

Serious Security: MD5 considered harmful – to the tune of $600,000

By Paul Ducklin β€” November 30th 2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!

☐ β˜† βœ‡ Naked Security

TikTok β€œInvisible Challenge” porn malware puts us all at risk

By Paul Ducklin β€” November 29th 2022 at 19:58
An injury to one is an injury to all. Especially if the other people are part of your social network.

☐ β˜† βœ‡ Naked Security

Multimillion dollar CryptoRom scam sites seized, suspects arrested in US

By Paul Ducklin β€” November 23rd 2022 at 19:58
Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...

cryptorom-1200

☐ β˜† βœ‡ Naked Security

S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?

By Paul Ducklin β€” November 10th 2022 at 17:26
Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!

☐ β˜† βœ‡ Naked Security

Silk Road drugs market hacker pleads guilty, faces 20 years inside

By Paul Ducklin β€” November 8th 2022 at 19:58
Jurisprudence isn't like arithmetic... two negatives never make a positive!

☐ β˜† βœ‡ Naked Security

Twitter Blue Badge email scams – Don’t fall for them!

By Naked Security writer β€” November 4th 2022 at 17:59
That was the week that was...

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

The OpenSSL security update story – how can you tell what needs fixing?

By Paul Ducklin β€” November 3rd 2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...

ossl-code-1200

☐ β˜† βœ‡ Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

By Paul Ducklin β€” November 1st 2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

☐ β˜† βœ‡ Naked Security

SHA-3 code execution bug patched in PHP – check your version!

By Paul Ducklin β€” November 1st 2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

☐ β˜† βœ‡ Naked Security

Psychotherapy extortion suspect: arrest warrant issued

By Paul Ducklin β€” October 31st 2022 at 19:59
Wanted! Not only the extortionist who abused the data, but also the CEO who let it happen.

☐ β˜† βœ‡ Naked Security

S3 Ep106: Facial recognition without consent – should it be banned?

By Paul Ducklin β€” October 27th 2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!

☐ β˜† βœ‡ Naked Security

Clearview AI image-scraping face recognition service hit with €20m fine in France

By Paul Ducklin β€” October 26th 2022 at 00:50
"We told you to stop but you ignored us," said the French regulator, "so now we're coming after you again."

☐ β˜† βœ‡ Naked Security

Serious Security: How randomly (or not) can you shuffle cards?

By Paul Ducklin β€” October 24th 2022 at 18:57
What if you could guess the next card correctly twice as often as you should?

card-fan-1200

☐ β˜† βœ‡ Naked Security

When cops hack back: Dutch police fleece DEADBOLT criminals (legally!)

By Paul Ducklin β€” October 21st 2022 at 18:25
Crooks: Show us the money! Cops: How about you show us the decryption keys first?

☐ β˜† βœ‡ Naked Security

S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text]

By Paul Ducklin β€” October 20th 2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!

pic-1200

☐ β˜† βœ‡ Naked Security

Women in Cryptology – USPS celebrates WW2 codebreakers

By Paul Ducklin β€” October 19th 2022 at 16:58
What did you do in the war, Mom? Oh, y'know, a bit of this and that...

☐ β˜† βœ‡ Naked Security

Fashion brand SHEIN fined $1.9m for lying about data breach

By Naked Security writer β€” October 17th 2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

☐ β˜† βœ‡ Naked Security

Serious Security: Microsoft Office 365 attacked over feeble encryption

By Paul Ducklin β€” October 14th 2022 at 16:59
How 2022 is your encryption?

☐ β˜† βœ‡ Naked Security

Serious Security: OAuth 2 and why Microsoft is finally forcing you into it

By Paul Ducklin β€” October 10th 2022 at 18:02
Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.

☐ β˜† βœ‡ Naked Security

S3 Ep99: TikTok β€œattack” – was there a data breach, or not? [Audio + Text]

By Paul Ducklin β€” September 8th 2022 at 13:21
Latest episode - listen now! (Or read if you prefer - full transcript inside.)

☐ β˜† βœ‡ Naked Security

S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text]

By Paul Ducklin β€” August 25th 2022 at 15:37
Latest episode - listen now! (Or read the transcript if you prefer the text version.)

☐ β˜† βœ‡ Naked Security

Bitcoin ATMs leeched by attackers who created fake admin accounts

By Paul Ducklin β€” August 23rd 2022 at 18:35
The criminals didn't implant any malware. The attack was orchestrated via malevolent configuration changes.

☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By Paul Ducklin β€” August 18th 2022 at 18:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]

By Paul Ducklin β€” August 4th 2022 at 17:52
Latest episode - listen now! (Or read if that's what you prefer.)

☐ β˜† βœ‡ Naked Security

Post-quantum cryptography – new algorithm β€œgone in 60 minutes”

By Paul Ducklin β€” August 3rd 2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.

☐ β˜† βœ‡ Naked Security

Cryptocoin β€œtoken swapper” Nomad loses $200 million in coding blunder

By Paul Ducklin β€” August 2nd 2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.

☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]

By Paul Ducklin β€” July 14th 2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.

☐ β˜† βœ‡ Naked Security

Paying ransomware crooks won’t reduce your legal risk, warns regulator

By Paul Ducklin β€” July 12th 2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

☐ β˜† βœ‡ Naked Security

S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass [Podcast + Transcript]

By Paul Ducklin β€” July 7th 2022 at 18:46
Listen now! Or read if you prefer...

☐ β˜† βœ‡ Naked Security

OpenSSL fixes two β€œone-liner” crypto bugs – what you need to know

By Paul Ducklin β€” July 6th 2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...

☐ β˜† βœ‡ Naked Security

Canadian cybercriminal pleads guilty to β€œNetWalker” attacks in US

By Paul Ducklin β€” July 4th 2022 at 14:09
Bust in Canada, now bust in the USA as well.

☐ β˜† βœ‡ Naked Security

β€œMissing Cryptoqueen” hits the FBI’s Ten Most Wanted list

By Paul Ducklin β€” July 1st 2022 at 16:49
The "Missing Cryptoqueen" makes the American Top Ten... but not in a good way.

☐ β˜† βœ‡ Naked Security

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

By Paul Ducklin β€” June 30th 2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!

❌