FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Whodunnit? Cybercrook gets 6 years for ransoming his own employer

By Naked Security writer β€” May 12th 2023 at 16:15
Not just an active adversary, but a two-faced one, too.

☐ β˜† βœ‡ Naked Security

Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security

By Paul Ducklin β€” April 18th 2023 at 16:56
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

☐ β˜† βœ‡ Naked Security

FBI and FCC warn about β€œJuicejacking” – but just how useful is their advice?

By Paul Ducklin β€” April 17th 2023 at 18:17
USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?

☐ β˜† βœ‡ Naked Security

S3 Ep129: When spyware arrives from someone you trust

By Paul Ducklin β€” April 6th 2023 at 14:57
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

☐ β˜† βœ‡ Naked Security

Researchers claim they can bypass Wi-Fi encryption (briefly, at least)

By Paul Ducklin β€” April 3rd 2023 at 16:59
They can't read much of your data, but even a few stray network packets could tell them something they're not supposed to know.

☐ β˜† βœ‡ Naked Security

Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

By Paul Ducklin β€” March 27th 2023 at 19:59
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

☐ β˜† βœ‡ Naked Security

WooCommerce Payments plugin for WordPress has an admin-level hole – patch now!

By Paul Ducklin β€” March 24th 2023 at 19:48
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

woo-1200

☐ β˜† βœ‡ Naked Security

S3 Ep127: When you chop someone out of a photo, but there they are anyway…

By Paul Ducklin β€” March 23rd 2023 at 17:59
Listen now - latest episode. Full transcript inside.

☐ β˜† βœ‡ Naked Security

Windows 11 also vulnerable to β€œaCropalypse” image data leakage

By Paul Ducklin β€” March 22nd 2023 at 17:59
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

☐ β˜† βœ‡ Naked Security

Google Pixel phones had a serious data leakage bug – here’s what to do!

By Paul Ducklin β€” March 21st 2023 at 17:58
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

☐ β˜† βœ‡ Naked Security

Bitcoin ATM customers hacked by video upload that was actually an app

By Paul Ducklin β€” March 20th 2023 at 19:50
As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...

☐ β˜† βœ‡ Naked Security

S3 Ep 126: The price of fast fashion (and feature creep) [Audio + Text]

By Paul Ducklin β€” March 16th 2023 at 17:56
Worried about rogue apps? Unsure about the new Outlook zero-day? Clear advice in plain English... just like old times, with Duck and Chet!

☐ β˜† βœ‡ Naked Security

SHEIN shopping app goes rogue, grabs price and URL data from your clipboard

By Paul Ducklin β€” March 10th 2023 at 19:58
It's not exactly data theft, but it's worryingly close to "unintentional treachery" - apparently because it's great for marketing purposes

☐ β˜† βœ‡ Naked Security

Feds warn about right Royal ransomware rampage that runs the gamut of TTPs

By Paul Ducklin β€” March 3rd 2023 at 19:56
Wondering which cybercrime tools, techniques and procedures to focus on? How about any and all of them?

☐ β˜† βœ‡ Naked Security

S3 Ep124: When so-called security apps go rogue [Audio + Text]

By Paul Ducklin β€” March 2nd 2023 at 19:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

s3-ep124-auth--1200

☐ β˜† βœ‡ Naked Security

LastPass: Keylogger on home PC led to cracked corporate password vault

By Paul Ducklin β€” February 28th 2023 at 02:23
Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.

☐ β˜† βœ‡ Naked Security

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!

By Paul Ducklin β€” February 27th 2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

☐ β˜† βœ‡ Naked Security

S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]

By Paul Ducklin β€” February 23rd 2023 at 19:58
Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

☐ β˜† βœ‡ Naked Security

NPM JavaScript packages abused to create scambait links in bulk

By Paul Ducklin β€” February 22nd 2023 at 20:59
Free spins? Bonus game points? Cheap social media followers? What harm could it possibly do if you just take a tiny little look?!

☐ β˜† βœ‡ Naked Security

Coinbase breached by social engineers, employee data stolen

By Paul Ducklin β€” February 21st 2023 at 17:58
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

☐ β˜† βœ‡ Naked Security

GoDaddy admits: Crooks hit us with malware, poisoned customer websites

By Paul Ducklin β€” February 20th 2023 at 01:36
New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.

☐ β˜† βœ‡ Naked Security

Reddit admits it was hacked and data stolen, says β€œDon’t panic”

By Paul Ducklin β€” February 10th 2023 at 19:59
Reddit is suggesting three tips as a follow-up to this breach. We agree with two of them but not with the third...

☐ β˜† βœ‡ Naked Security

Finnish psychotherapy extortion suspect arrested in France

By Naked Security writer β€” February 6th 2023 at 19:13
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By Paul Ducklin β€” February 1st 2023 at 19:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text]

By Paul Ducklin β€” January 26th 2023 at 19:57
Lastest episode - listen now! (Or read the transcript.)

☐ β˜† βœ‡ Naked Security

GoTo admits: Customer cloud backups stolen together with decryption key

By Paul Ducklin β€” January 25th 2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

☐ β˜† βœ‡ Naked Security

T-Mobile admits to 37,000,000 customer records stolen by β€œbad actor”

By Paul Ducklin β€” January 20th 2023 at 17:59
Once more, it's time for Shakespeare's words: Once more unto the breach...

☐ β˜† βœ‡ Naked Security

CircleCI – code-building service suffers total credential compromise

By Paul Ducklin β€” January 9th 2023 at 14:52
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

☐ β˜† βœ‡ Naked Security

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

By Paul Ducklin β€” January 4th 2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

☐ β˜† βœ‡ Naked Security

Inside a scammers’ lair: Ukraine busts 40 in fake bank call-centre raid

By Naked Security writer β€” January 3rd 2023 at 17:03
When someone calls you up to warn you that your bank account is under attack - it's true, because THAT VERY PERSON is the one attacking you!

☐ β˜† βœ‡ Naked Security

S3 Ep115: True crime stories – A day in the life of a cybercrime fighter [Audio + Text]

By Paul Ducklin β€” December 29th 2022 at 09:20
Listen now - you'll be alarmed, amused and educated, all in equal measure. (Full transcript in article.)

☐ β˜† βœ‡ Naked Security

Twitter data of β€œ+400 million unique users” up for sale – what to do?

By Paul Ducklin β€” December 28th 2022 at 19:59
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?

☐ β˜† βœ‡ Naked Security

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all…

By Paul Ducklin β€” December 23rd 2022 at 19:58
The crooks now know who you are, where you live, which computers are yours, where you go online... and they got those password vaults, too.

☐ β˜† βœ‡ Naked Security

S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text]

By Paul Ducklin β€” December 15th 2022 at 17:10
Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!

☐ β˜† βœ‡ Naked Security

COVID-bit: the wireless spyware trick with an unfortunate name

By Paul Ducklin β€” December 13th 2022 at 19:58
It's not the switching that's the problem, it's the switching of the switching!

ind-1200

☐ β˜† βœ‡ Naked Security

Credit card skimming – the long and winding road of supply chain failure

By Paul Ducklin β€” December 8th 2022 at 19:58
Don't keep calling home to a JavaScript server that closed its doors eight years ago!

☐ β˜† βœ‡ Naked Security

LastPass admits to customer data breach caused by previous breach

By Paul Ducklin β€” December 2nd 2022 at 01:10
Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.

☐ β˜† βœ‡ Naked Security

Black Friday and retail season – watch out for PayPal β€œmoney request” scams

By Paul Ducklin β€” November 17th 2022 at 12:45
Don't let a keen eye for bargains lead you into risky online behaviour...

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

S3 Ep106: Facial recognition without consent – should it be banned?

By Paul Ducklin β€” October 27th 2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!

☐ β˜† βœ‡ Naked Security

Online ticketing company β€œSee” pwned for 2.5 years by attackers

By Paul Ducklin β€” October 26th 2022 at 19:58
Don't be a cybersecurity slowcoach - you need to spot possible attacks as soon as you can.

☐ β˜† βœ‡ Naked Security

S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text]

By Paul Ducklin β€” October 20th 2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!

pic-1200

☐ β˜† βœ‡ Naked Security

Fashion brand SHEIN fined $1.9m for lying about data breach

By Naked Security writer β€” October 17th 2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

☐ β˜† βœ‡ Naked Security

Former Uber CSO convicted of covering up megabreach back in 2016

By Naked Security writer β€” October 6th 2022 at 01:04
Obstructed FTC proceedings, and concealed a crime, said the jury.

☐ β˜† βœ‡ Naked Security

Optus breach – Aussie telco told it will have to pay to replace IDs

By Paul Ducklin β€” September 28th 2022 at 13:55
Licence compromised? Passport number burned? Need a new one? Who's going to pay?

☐ β˜† βœ‡ Naked Security

Morgan Stanley fined millions for selling off devices full of customer PII

By Paul Ducklin β€” September 23rd 2022 at 18:07
Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...

☐ β˜† βœ‡ Naked Security

S3 Ep101: Uber and LastPass breaches – is 2FA all it’s cracked up to be? [Audio + Text]

By Paul Ducklin β€” September 22nd 2022 at 18:42
Latest episode - listen now! Learn why adopting 2FA isn't a reason to relax your other security precautions...

☐ β˜† βœ‡ Naked Security

LastPass source code breach – incident response report released

By Paul Ducklin β€” September 19th 2022 at 18:59
Wondering how you'd handle a data breach report if the worst happened to you? Here's a useful example.

☐ β˜† βœ‡ Naked Security

S3 Ep100.5: Uber breach – an expert speaks [Audio + Text]

By Paul Ducklin β€” September 17th 2022 at 20:57
Chester Wisniewski on what we can learn from Uber: "Just because a big company didn't have the security they should doesn't mean you can't."

☐ β˜† βœ‡ Naked Security

UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you

By Paul Ducklin β€” September 16th 2022 at 18:43
Uber is all over the news for a widely-publicised data breach. We help you answer the question, "How do I stop this happening to me?"

☐ β˜† βœ‡ Naked Security

Serious Security: Browser-in-the-browser attacks – watch out for windows that aren’t!

By Paul Ducklin β€” September 13th 2022 at 20:52
Simple but super-sneaky - use a picture of a browser, and convince people it's real...

pipe-light-not-1200

☐ β˜† βœ‡ Naked Security

S3 Ep98: The LastPass saga – should we stop using password managers? [Audio + Text]

By Paul Ducklin β€” September 1st 2022 at 16:55
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

LastPass source code breach – do we still recommend password managers?

By Paul Ducklin β€” August 29th 2022 at 16:59
What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?

☐ β˜† βœ‡ Naked Security

Breaching airgap security: using your phone’s gyroscope as a microphone

By Paul Ducklin β€” August 24th 2022 at 18:59
One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

S3 Ep93: Office security, breach costs, and leisurely patches [Audio + Text]

By Paul Ducklin β€” July 28th 2022 at 15:47
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

T-Mobile to cough up $500 million over 2021 data breach

By Paul Ducklin β€” July 25th 2022 at 16:20
Technically, it's not a fine, and the lawyers will get a big chunk of it. But it still adds up to a half-billion-dollar data breach.

❌