FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

SEC demands four-day disclosure limit for cybersecurity breaches

By Paul Ducklin β€” July 31st 2023 at 18:57
When is a ransomware attack a reportable matter? And how long have you got to decide?

☐ β˜† βœ‡ Naked Security

S3 Ep131: Can you really have fun with FORTRAN?

By Paul Ducklin β€” April 20th 2023 at 17:55
Loop-the-loop in this week's episode. Entertaining, educational and all in plain English. Transcript inside.

☐ β˜† βœ‡ Naked Security

Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security

By Paul Ducklin β€” April 18th 2023 at 16:56
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

☐ β˜† βœ‡ Naked Security

Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert

By Paul Ducklin β€” April 11th 2023 at 18:58
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

☐ β˜† βœ‡ Naked Security

Bitcoin ATM customers hacked by video upload that was actually an app

By Paul Ducklin β€” March 20th 2023 at 19:50
As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...

☐ β˜† βœ‡ Naked Security

LastPass: Keylogger on home PC led to cracked corporate password vault

By Paul Ducklin β€” February 28th 2023 at 02:23
Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.

☐ β˜† βœ‡ Naked Security

Dutch police arrest three cyberextortion suspects who allegedly earned millions

By Naked Security writer β€” February 27th 2023 at 19:33
Ever paid hush money to crooks who broke into your network? Wondered how much you can trust them?

☐ β˜† βœ‡ Naked Security

Coinbase breached by social engineers, employee data stolen

By Paul Ducklin β€” February 21st 2023 at 17:58
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

☐ β˜† βœ‡ Naked Security

GoDaddy admits: Crooks hit us with malware, poisoned customer websites

By Paul Ducklin β€” February 20th 2023 at 01:36
New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.

☐ β˜† βœ‡ Naked Security

Reddit admits it was hacked and data stolen, says β€œDon’t panic”

By Paul Ducklin β€” February 10th 2023 at 19:59
Reddit is suggesting three tips as a follow-up to this breach. We agree with two of them but not with the third...

☐ β˜† βœ‡ Naked Security

Finnish psychotherapy extortion suspect arrested in France

By Naked Security writer β€” February 6th 2023 at 19:13
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

Dutch suspect locked up for alleged personal data megathefts

By Paul Ducklin β€” January 26th 2023 at 22:02
Undercover Austrian "controlled data buy" leads to Amsterdam arrest and ongoing investigation. Suspect is said to steal and sell all sorts of data, including medical records.

☐ β˜† βœ‡ Naked Security

GoTo admits: Customer cloud backups stolen together with decryption key

By Paul Ducklin β€” January 25th 2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

☐ β˜† βœ‡ Naked Security

T-Mobile admits to 37,000,000 customer records stolen by β€œbad actor”

By Paul Ducklin β€” January 20th 2023 at 17:59
Once more, it's time for Shakespeare's words: Once more unto the breach...

☐ β˜† βœ‡ Naked Security

S3 Ep118: Guess your password? No need if it’s stolen already! [Audio + Text]

By Paul Ducklin β€” January 19th 2023 at 15:53
As always: entertaining, informative and educational... and not bogged down with jargon! Listen (or read) now...

☐ β˜† βœ‡ Naked Security

CircleCI – code-building service suffers total credential compromise

By Paul Ducklin β€” January 9th 2023 at 14:52
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

☐ β˜† βœ‡ Naked Security

Twitter data of β€œ+400 million unique users” up for sale – what to do?

By Paul Ducklin β€” December 28th 2022 at 19:59
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?

☐ β˜† βœ‡ Naked Security

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all…

By Paul Ducklin β€” December 23rd 2022 at 19:58
The crooks now know who you are, where you live, which computers are yours, where you go online... and they got those password vaults, too.

☐ β˜† βœ‡ Naked Security

LastPass admits to customer data breach caused by previous breach

By Paul Ducklin β€” December 2nd 2022 at 01:10
Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

Online ticketing company β€œSee” pwned for 2.5 years by attackers

By Paul Ducklin β€” October 26th 2022 at 19:58
Don't be a cybersecurity slowcoach - you need to spot possible attacks as soon as you can.

☐ β˜† βœ‡ Naked Security

S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text]

By Paul Ducklin β€” October 20th 2022 at 18:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!

pic-1200

☐ β˜† βœ‡ Naked Security

Fashion brand SHEIN fined $1.9m for lying about data breach

By Naked Security writer β€” October 17th 2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

☐ β˜† βœ‡ Naked Security

S3 Ep102: How to avoid a data breach [Audio + Transcript]

By Paul Ducklin β€” September 29th 2022 at 18:45
Latest episode - listen now! Tell fact from fiction in hyped-up cybersecurity news...

☐ β˜† βœ‡ Naked Security

Optus breach – Aussie telco told it will have to pay to replace IDs

By Paul Ducklin β€” September 28th 2022 at 13:55
Licence compromised? Passport number burned? Need a new one? Who's going to pay?

☐ β˜† βœ‡ Naked Security

S3 Ep101: Uber and LastPass breaches – is 2FA all it’s cracked up to be? [Audio + Text]

By Paul Ducklin β€” September 22nd 2022 at 18:42
Latest episode - listen now! Learn why adopting 2FA isn't a reason to relax your other security precautions...

☐ β˜† βœ‡ Naked Security

LastPass source code breach – incident response report released

By Paul Ducklin β€” September 19th 2022 at 18:59
Wondering how you'd handle a data breach report if the worst happened to you? Here's a useful example.

☐ β˜† βœ‡ Naked Security

UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you

By Paul Ducklin β€” September 16th 2022 at 18:43
Uber is all over the news for a widely-publicised data breach. We help you answer the question, "How do I stop this happening to me?"

☐ β˜† βœ‡ Naked Security

LastPass source code breach – do we still recommend password managers?

By Paul Ducklin β€” August 29th 2022 at 16:59
What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?

☐ β˜† βœ‡ Naked Security

T-Mobile to cough up $500 million over 2021 data breach

By Paul Ducklin β€” July 25th 2022 at 16:20
Technically, it's not a fine, and the lawyers will get a big chunk of it. But it still adds up to a half-billion-dollar data breach.

☐ β˜† βœ‡ Naked Security

S3 Ep88: Phone scammers, hacking bust, and data breach fines [Podcast + Transcript]

By Paul Ducklin β€” June 23rd 2022 at 11:08
Latest epsiode - listen (or read) now!

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]

By Paul Ducklin β€” April 7th 2022 at 12:24
Latest episode - listen now! Cybersecurity news and advice in plain English.

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Adafruit suffers GitHub data breach – don’t let this happen to you

By Paul Ducklin β€” March 7th 2022 at 12:47
Training data stashed in GitHub by mistake... unfortunately, it was *real* data

☐ β˜† βœ‡ Naked Security

Ransomware with a difference: β€œDerestrict your software, or else!”

By Paul Ducklin β€” March 2nd 2022 at 16:33
"Change your code to improve cryptomining"... or we'll dump 1TB of stolen secrets.

☐ β˜† βœ‡ Naked Security

S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public [Podcast]

By Paul Ducklin β€” November 25th 2021 at 12:38
Latest episode - listen now! Solid cybersecurity advice in plain English.

☐ β˜† βœ‡ Naked Security

GoDaddy admits to password breach: check your Managed WordPress site!

By Paul Ducklin β€” November 23rd 2021 at 00:35
GoDaddy found crooks in its network, and kicked them out - but not before they'd been in there for six weeks.

❌