FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

S3 Ep144: When threat hunting goes down a rabbit hole

By Paul Ducklin β€” July 20th 2023 at 14:58
Latest episode - check it out now!

☐ β˜† βœ‡ Naked Security

Google Virus Total leaks list of spooky email addresses

By Paul Ducklin β€” July 18th 2023 at 23:16
Careful with that file, Eugene!

☐ β˜† βœ‡ Naked Security

Microsoft hit by Storm season – a tale of two semi-zero days

By Paul Ducklin β€” July 18th 2023 at 20:59
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...

☐ β˜† βœ‡ Naked Security

Zimbra Collaboration Suite warning: Patch this 0-day right now (by hand)!

By Paul Ducklin β€” July 14th 2023 at 19:58
Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly request your cooperation to apply the fix manually."

☐ β˜† βœ‡ Naked Security

S3 Ep143: Supercookie surveillance shenanigans

By Paul Ducklin β€” July 13th 2023 at 16:48
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Microsoft patches four zero-days, finally takes action against crimeware kernel drivers

By Paul Ducklin β€” July 12th 2023 at 18:57
Here's a brief reminder to do two things. The first is to patch. The second is to read up why it's a good idea to patch...

☐ β˜† βœ‡ Naked Security

Apple silently pulls its latest zero-day update – what now?

By Paul Ducklin β€” July 11th 2023 at 15:21
Previously, we said "do it today", but now we're forced back on: "Do not delay; do it as soon as Apple and your device will let you."

☐ β˜† βœ‡ Naked Security

Urgent! Apple fixes critical zero-day hole in iPhones, iPads and Macs

By Paul Ducklin β€” July 10th 2023 at 23:12
Don't delay, do it today. This is a code-implantation bug in WebKit that attackers already know how to exploit.

☐ β˜† βœ‡ Naked Security

Serious Security: Rowhammer returns to gaslight your computer

By Paul Ducklin β€” July 10th 2023 at 21:22
Gaslights produce a telltale flicker when nearby lamps are lit; DRAM values do something similar when nearby memory cells are accessed.

☐ β˜† βœ‡ Naked Security

S3 Ep142: Putting the X in X-Ops

By Paul Ducklin β€” July 6th 2023 at 19:58
How to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light.

s3-ep100-js-1200

☐ β˜† βœ‡ Naked Security

Firefox 115 is out, says farewell to users of older Windows and Mac versions

By Paul Ducklin β€” July 5th 2023 at 18:58
No zero-days this month, so you're patching to stay ahead, not merely to catch up!

☐ β˜† βœ‡ Naked Security

Ghostscript bug could allow rogue documents to run system commands

By Paul Ducklin β€” July 4th 2023 at 17:57
Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.

☐ β˜† βœ‡ Naked Security

WordPress plugin lets users become admins – Patch early, patch often!

By Paul Ducklin β€” July 3rd 2023 at 16:48
Ultimate Member plugin lets rogue users choose their own site capabilities, including becoming admins.

☐ β˜† βœ‡ Naked Security

S3 Ep141: What was Steve Jobs’s first job?

By Paul Ducklin β€” June 29th 2023 at 16:58
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Interested in $10,000,000? Ready to turn in the Clop ransomware crew?

By Naked Security writer β€” June 28th 2023 at 18:59
Technically, it's "up to $10 million", but it's potentially a LOT of money, nevertheless...

☐ β˜† βœ‡ Naked Security

UK hacker busted in Spain gets 5 years over Twitter hack and more

By Naked Security writer β€” June 26th 2023 at 18:35
Not just that infamous Twitter hack, but SIM-swapping, stalking and swatting too...

☐ β˜† βœ‡ Naked Security

Aussie PM says, β€œShut down your phone every 24 hours for 5 mins” – but that’s not enough on its own

By Paul Ducklin β€” June 23rd 2023 at 16:10
Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.

☐ β˜† βœ‡ Naked Security

S3 Ep140: So you think you know ransomware?

By Paul Ducklin β€” June 22nd 2023 at 16:48
Lots to learn this week - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Apple patch fixes zero-day kernel hole reported by Kaspersky – update now!

By Paul Ducklin β€” June 22nd 2023 at 00:36
Apple didn't use the words "Triangulation Trojan", but you probably will.

☐ β˜† βœ‡ Naked Security

Beware bad passwords as attackers co-opt Linux servers into cybercrime

By Paul Ducklin β€” June 21st 2023 at 19:50
Did you prevent password-only logins on your SSH servers? On ALL of them? Are you sure about that?

☐ β˜† βœ‡ Naked Security

β€œThe Ransomware Documentary” – brand new video series from Sophos starting now!

By Sally Adam β€” June 21st 2023 at 18:00
Get the full 360-degree view of ransomware

Ransomware Documentary Graphic Theme_780x480 NS

☐ β˜† βœ‡ Naked Security

ASUS warns router customers: Patch now, or block all inbound requests

By Paul Ducklin β€” June 20th 2023 at 18:14
"Do as we say, not as we do!" - The patches took ages to come out, but don't let that lure you into taking ages to install them.

☐ β˜† βœ‡ Naked Security

Megaupload duo will go to prison at last, but Kim Dotcom fights on…

By Paul Ducklin β€” June 19th 2023 at 18:59
One, sadly, has died, and two are heading to prison, but for Kim Dotcom, the saga goes on...

☐ β˜† βœ‡ Naked Security

MOVEit mayhem 3: β€œDisable HTTP and HTTPS traffic immediately”

By Paul Ducklin β€” June 15th 2023 at 22:10
Twice more unto the breach... third patch tested and released, shut down web access until you've applied it

mi-1200

☐ β˜† βœ‡ Naked Security

S3 Ep139: Are password rules like running through rain?

By Paul Ducklin β€” June 15th 2023 at 18:43
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes

By Paul Ducklin β€” June 13th 2023 at 23:32
No zero-days this month, if you ignore the Edge RCE hole patched last week

☐ β˜† βœ‡ Naked Security

Gozi banking malware β€œIT chief” finally jailed after more than 10 years

By Paul Ducklin β€” June 13th 2023 at 18:43
Gozi threesome from way back in the late 2000s and early 2010s now all charged, convicted and sentenced. The DOJ got there in the end...

☐ β˜† βœ‡ Naked Security

History revisited: US DOJ unseals Mt. Gox cybercrime charges

By Naked Security writer β€” June 12th 2023 at 16:58
Though the mills of the Law grind slowly/Yet they grind exceeding small/Though with patience they stand waiting/With exactness grind they all...

☐ β˜† βœ‡ Naked Security

More MOVEit mitigations: new patches published for further protection

By Paul Ducklin β€” June 9th 2023 at 21:54
Good news... more patches, this time available proactively

☐ β˜† βœ‡ Naked Security

Thoughts on scheduled password changes (don’t call them rotations!)

By Paul Ducklin β€” June 9th 2023 at 18:58
Does swapping your password regularly make it a better password?

☐ β˜† βœ‡ Naked Security

S3 Ep138: I like to MOVEit, MOVEit

By Paul Ducklin β€” June 8th 2023 at 16:56
Backdoors, exploits, and Little Bobby Tables. Listen now! (Full transcript available...)

s3-ep138-1200

☐ β˜† βœ‡ Naked Security

Firefox 114 is out: No 0-days, but one fascinating β€œteachable moment” bug

By Paul Ducklin β€” June 7th 2023 at 19:59
With the right (or wrong, if you're on the right side of the fence) timing...

☐ β˜† βœ‡ Naked Security

Chrome and Edge zero-day: β€œThis exploit is in the wild”, so check your versions now

By Paul Ducklin β€” June 6th 2023 at 18:28
Chrome and Edge 0-days patched.

☐ β˜† βœ‡ Naked Security

MOVEit zero-day exploit used by data breach gangs: The how, the why, and what to do…

By Paul Ducklin β€” June 5th 2023 at 19:59
Little Bobby Tables is back!

mi-1200

☐ β˜† βœ‡ Naked Security

Researchers claim Windows β€œbackdoor” affects hundreds of Gigabyte motherboards

By Paul Ducklin β€” June 2nd 2023 at 18:56
It's a backdoor, Jim, but not as we know it... here's a sober look at this issue.

☐ β˜† βœ‡ Naked Security

S3 Ep137: 16th century crypto skullduggery

By Paul Ducklin β€” June 1st 2023 at 16:45
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

s3-ep137-feat-1200

☐ β˜† βœ‡ Naked Security

Serious Security: That KeePass β€œmaster password crack”, and what we can learn from it

By Paul Ducklin β€” May 31st 2023 at 19:39
Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

☐ β˜† βœ‡ Naked Security

Serious Security: Verification is vital – examining an OAUTH login bug

By Paul Ducklin β€” May 30th 2023 at 16:59
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

☐ β˜† βœ‡ Naked Security

S3 Ep136: Navigating a manic malware maelstrom

By Paul Ducklin β€” May 25th 2023 at 16:50
Latest episode - listen now. Full transcript inside...

☐ β˜† βœ‡ Naked Security

Ransomware tales: The MitM attack that really had a Man in the Middle

By Paul Ducklin β€” May 24th 2023 at 17:59
Another traitorous sysadmin story, this one busted by system logs that gave his game away...

☐ β˜† βœ‡ Naked Security

PyPI open-source code repository deals with manic malware maelstrom

By Paul Ducklin β€” May 23rd 2023 at 18:45
Controlled outage used to keep malware marauders from gumming up the works. Learn what you can do to help in future...

☐ β˜† βœ‡ Naked Security

Phone scamming kingpin gets 13 years for running β€œiSpoof” service

By Naked Security writer β€” May 22nd 2023 at 16:58
Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

ispoof-1200

☐ β˜† βœ‡ Naked Security

Apple’s secret is out: 3 zero-days fixed, so be sure to patch now!

By Paul Ducklin β€” May 19th 2023 at 01:02
All Apple users have zero-days that need patching, though some have more zero-days than others.

☐ β˜† βœ‡ Naked Security

S3 Ep135: Sysadmin by day, extortionist by night

By Paul Ducklin β€” May 18th 2023 at 18:48
Laugh (sufficiently), learn (efficiently), and then let us know what you think in our comments (anonymously, if you wish)...

☐ β˜† βœ‡ Naked Security

US offers $10m bounty for Russian ransomware suspect outed in indictment

By Naked Security writer β€” May 17th 2023 at 18:40
"Up to $10 million for information that leads to the arrest and/or conviction of this defendant."

☐ β˜† βœ‡ Naked Security

Belkin Wemo Smart Plug V2 – the buffer overflow that won’t be patched

By Paul Ducklin β€” May 16th 2023 at 17:59
Yes, it's a buffer overflow bug. No, it's not going get fixed.

☐ β˜† βœ‡ Naked Security

Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France

By Paul Ducklin β€” May 15th 2023 at 16:36
We asked you once, we told you twice, now we're ordering you for the third time...

☐ β˜† βœ‡ Naked Security

Whodunnit? Cybercrook gets 6 years for ransoming his own employer

By Naked Security writer β€” May 12th 2023 at 16:15
Not just an active adversary, but a two-faced one, too.

☐ β˜† βœ‡ Naked Security

S3 Ep134: It’s a PRIVATE key – the hint is in the name!

By Paul Ducklin β€” May 11th 2023 at 14:54
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Bootkit zero-day fix – is this Microsoft’s most cautious patch ever?

By Paul Ducklin β€” May 10th 2023 at 11:50
When blocking buggy bootup modules, you have to be really careful not to lock your keys inside the car...

☐ β˜† βœ‡ Naked Security

Low-level motherboard security keys leaked in MSI breach, claim researchers

By Paul Ducklin β€” May 9th 2023 at 16:58
What can you do if someone steals your keys but you can't change the lock? We explain the dilemma in plain English.

☐ β˜† βœ‡ Naked Security

PHP Packagist supply chain poisoned by hacker β€œlooking for a job”

By Paul Ducklin β€” May 5th 2023 at 16:59
I pwned you! Gizza job! You know it makes sense!

☐ β˜† βœ‡ Naked Security

S3 Ep133: Apple takes β€œtight-lipped” to a whole new level

By Paul Ducklin β€” May 4th 2023 at 20:59
Entertaining, educational, and all in plain English πŸŽ§πŸ“–

☐ β˜† βœ‡ Naked Security

World Password Day: 2 + 2 = 4

By Paul Ducklin β€” May 4th 2023 at 13:12
We've kept it short and simple, with no sermons, no judgmentalism, no tubthumping... and no BUY NOW buttons. Have a nice day!

☐ β˜† βœ‡ Naked Security

Tracked by hidden tags? Apple and Google unite to propose safety and security standards…

By Paul Ducklin β€” May 3rd 2023 at 19:58
To bleat, or not to bleat, that is the question.

☐ β˜† βœ‡ Naked Security

Apple delivers first-ever Rapid Security Response β€œcyberattack” patch – leaves some users confused

By Paul Ducklin β€” May 1st 2023 at 20:46
Just when we'd got used to three-numbered versions, such as "13.3.1", here comes an update suffix, bringing you "13.3.1 (a)"...

☐ β˜† βœ‡ Naked Security

Mac malware-for-hire steals passwords and cryptocoins, sends β€œcrime logs” via Telegram

By Paul Ducklin β€” April 30th 2023 at 01:23
These malware peddlers are specifically going after Mac users. The hint's in the name: "Atomic macOS Stealer", or AMOS for short.

☐ β˜† βœ‡ Naked Security

Google wins court order to force ISPs to filter botnet traffic

By Naked Security writer β€” April 28th 2023 at 19:59
CryptBot criminals are alleged to have plundered browser passwords, illicitly-snapped screenshots, cryptocurrency account data, and more.

☐ β˜† βœ‡ Naked Security

S3 Ep132: Proof-of-concept lets anyone hack at will

By Paul Ducklin β€” April 27th 2023 at 16:55
When Doug says, "Happy Remote Code Execution Day, Duck"... it's irony. For the avoidance of all doubt :-)

☐ β˜† βœ‡ Naked Security

Google leaking 2FA secrets – researchers advise against new β€œaccount sync” feature for now

By Paul Ducklin β€” April 26th 2023 at 17:59
You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...

❌