FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Performance and security clash yet again in β€œCollide+Power” attack

By Paul Ducklin β€” August 2nd 2023 at 23:36
It's a real vulnerability, but the data leakage rate can be as low as... let's just say that an IMAX-quality copy of the new "Oppenheimer" movie could take you 4 billion years to exfiltrate.

☐ β˜† βœ‡ Naked Security

Zenbleed: How the quest for CPU performance could put your passwords at risk

By Paul Ducklin β€” July 26th 2023 at 19:01
You need to turn on a special setting to stop (the code you wrote to stop [the code you wrote to improve performance] from reducing performance) from reducing security.

☐ β˜† βœ‡ Naked Security

Urgent! Apple fixes critical zero-day hole in iPhones, iPads and Macs

By Paul Ducklin β€” July 10th 2023 at 23:12
Don't delay, do it today. This is a code-implantation bug in WebKit that attackers already know how to exploit.

☐ β˜† βœ‡ Naked Security

Ghostscript bug could allow rogue documents to run system commands

By Paul Ducklin β€” July 4th 2023 at 17:57
Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.

☐ β˜† βœ‡ Naked Security

WordPress plugin lets users become admins – Patch early, patch often!

By Paul Ducklin β€” July 3rd 2023 at 16:48
Ultimate Member plugin lets rogue users choose their own site capabilities, including becoming admins.

☐ β˜† βœ‡ Naked Security

More MOVEit mitigations: new patches published for further protection

By Paul Ducklin β€” June 9th 2023 at 21:54
Good news... more patches, this time available proactively

☐ β˜† βœ‡ Naked Security

Firefox 114 is out: No 0-days, but one fascinating β€œteachable moment” bug

By Paul Ducklin β€” June 7th 2023 at 19:59
With the right (or wrong, if you're on the right side of the fence) timing...

☐ β˜† βœ‡ Naked Security

Chrome and Edge zero-day: β€œThis exploit is in the wild”, so check your versions now

By Paul Ducklin β€” June 6th 2023 at 18:28
Chrome and Edge 0-days patched.

☐ β˜† βœ‡ Naked Security

MOVEit zero-day exploit used by data breach gangs: The how, the why, and what to do…

By Paul Ducklin β€” June 5th 2023 at 19:59
Little Bobby Tables is back!

mi-1200

☐ β˜† βœ‡ Naked Security

S3 Ep137: 16th century crypto skullduggery

By Paul Ducklin β€” June 1st 2023 at 16:45
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

s3-ep137-feat-1200

☐ β˜† βœ‡ Naked Security

Serious Security: That KeePass β€œmaster password crack”, and what we can learn from it

By Paul Ducklin β€” May 31st 2023 at 19:39
Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

☐ β˜† βœ‡ Naked Security

Serious Security: Verification is vital – examining an OAUTH login bug

By Paul Ducklin β€” May 30th 2023 at 16:59
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

☐ β˜† βœ‡ Naked Security

Google leaking 2FA secrets – researchers advise against new β€œaccount sync” feature for now

By Paul Ducklin β€” April 26th 2023 at 17:59
You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...

☐ β˜† βœ‡ Naked Security

PaperCut security vulnerabilities under active attack – vendor urges customers to patch

By Paul Ducklin β€” April 25th 2023 at 17:53
If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...

☐ β˜† βœ‡ Naked Security

VMware patches break-and-enter hole in logging tools: update now!

By Paul Ducklin β€” April 21st 2023 at 17:58
You know jolly well/What we're going to say/And that's "Do not delay/Simply do it today."

☐ β˜† βœ‡ Naked Security

S3 Ep131: Can you really have fun with FORTRAN?

By Paul Ducklin β€” April 20th 2023 at 17:55
Loop-the-loop in this week's episode. Entertaining, educational and all in plain English. Transcript inside.

☐ β˜† βœ‡ Naked Security

Popular server-side JavaScript security sandbox β€œvm2” patches remote execution hole

By Paul Ducklin β€” April 9th 2023 at 00:28
The security error was in the error handling system that was supposed to catch potential security errors...

vm2-1200

☐ β˜† βœ‡ Naked Security

Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

By Paul Ducklin β€” March 27th 2023 at 19:59
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

☐ β˜† βœ‡ Naked Security

Windows 11 also vulnerable to β€œaCropalypse” image data leakage

By Paul Ducklin β€” March 22nd 2023 at 17:59
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

☐ β˜† βœ‡ Naked Security

Google Pixel phones had a serious data leakage bug – here’s what to do!

By Paul Ducklin β€” March 21st 2023 at 17:58
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

☐ β˜† βœ‡ Naked Security

Microsoft fixes two 0-days on Patch Tuesday – update now!

By Paul Ducklin β€” March 15th 2023 at 00:06
An email you haven't even looked at yet could be used to trick Outlook into helping crooks to logon as you.

☐ β˜† βœ‡ Naked Security

Serious Security: TPM 2.0 vulns – is your super-secure data at risk?

By Paul Ducklin β€” March 7th 2023 at 19:59
Security bugs in the very code you've been told you must have to improve the security of your computer...

☐ β˜† βœ‡ Naked Security

S3 Ep124: When so-called security apps go rogue [Audio + Text]

By Paul Ducklin β€” March 2nd 2023 at 19:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

s3-ep124-auth--1200

☐ β˜† βœ‡ Naked Security

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!

By Paul Ducklin β€” February 27th 2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

☐ β˜† βœ‡ Naked Security

S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]

By Paul Ducklin β€” February 23rd 2023 at 19:58
Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

☐ β˜† βœ‡ Naked Security

Twitter tells users: Pay up if you want to keep using insecure 2FA

By Paul Ducklin β€” February 20th 2023 at 17:58
Ironically, Twitter Blue users will be allowed to keep using the very 2FA process that's not considered secure enough for everyone else.

☐ β˜† βœ‡ Naked Security

Apple fixes zero-day spyware implant bug – patch now!

By Paul Ducklin β€” February 14th 2023 at 19:08
Everyone update now! Except for those who don't need to! Or who need to but will only get updates later on, though Apple isn't saying yet!

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By Paul Ducklin β€” February 1st 2023 at 19:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

Serious Security: The Samba logon bug caused by outdated crypto

By Paul Ducklin β€” January 30th 2023 at 19:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

☐ β˜† βœ‡ Naked Security

Apple patches are out – old iPhones get an old zero-day fix at last!

By Paul Ducklin β€” January 24th 2023 at 01:24
Don't delay, especially if you're still running an iOS 12 device... please do it today!

☐ β˜† βœ‡ Naked Security

Microsoft dishes the dirt on Apple’s β€œAchilles heel” shortly after fixing similar Windows bug

By Paul Ducklin β€” December 20th 2022 at 17:59
It happens to the best of us: Microsoft highlights a security bypass bug on Macs that is curiously similar to a recent Windows 0-day.

☐ β˜† βœ‡ Naked Security

Apple patches everything, finally reveals mystery of iOS 16.1.2

By Paul Ducklin β€” December 14th 2022 at 02:11
There's an update for everything this time, not just for iOS.

☐ β˜† βœ‡ Naked Security

Pwn2Own Toronto: 54 hacks, 63 new bugs, $1 million in bounties

By Paul Ducklin β€” December 12th 2022 at 19:58
That's a mean average of $15,710 per bug... and 63 fewer bugs out there for crooks and rogues to find.

☐ β˜† βœ‡ Naked Security

SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m

By Naked Security writer β€” December 6th 2022 at 17:56
Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.

☐ β˜† βœ‡ Naked Security

Number Nine! Chrome fixes another 2022 zero-day, Edge patched too

By Paul Ducklin β€” December 5th 2022 at 20:58
Ninth more unto the breach, dear friends, ninth more.

☐ β˜† βœ‡ Naked Security

The CHRISTMA EXEC network worm – 35 years and counting!

By Paul Ducklin β€” December 1st 2022 at 20:35
"Uh-oh, this viruses-and-worms scene could turn out quite troublesome." If only we'd been wrong...

xmas-1200-35-wide

☐ β˜† βœ‡ Naked Security

Serious Security: MD5 considered harmful – to the tune of $600,000

By Paul Ducklin β€” November 30th 2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!

☐ β˜† βœ‡ Naked Security

How to hack an unpatched Exchange server with rogue PowerShell code

By Paul Ducklin β€” November 22nd 2022 at 19:54
Review your servers, your patches and your authentication policies - there's a proof-of-concept out

☐ β˜† βœ‡ Naked Security

Log4Shell-like code execution hole in popular Backstage dev tool

By Paul Ducklin β€” November 15th 2022 at 17:49
Good old "string templating", also known as "string interpolation", in the spotlight again...

bs-1200

☐ β˜† βœ‡ Naked Security

Dangerous SIM-swap lockscreen bypass – update Android now!

By Paul Ducklin β€” November 11th 2022 at 19:59
A bit like leaving the front door keys under the doormat...

☐ β˜† βœ‡ Naked Security

Emergency code execution patch from Apple – but not an 0-day

By Paul Ducklin β€” November 10th 2022 at 01:49
Not a zero-day, but important enough for a quick-fire patch to one system library...

☐ β˜† βœ‡ Naked Security

Twitter Blue Badge email scams – Don’t fall for them!

By Naked Security writer β€” November 4th 2022 at 17:59
That was the week that was...

☐ β˜† βœ‡ Naked Security

The OpenSSL security update story – how can you tell what needs fixing?

By Paul Ducklin β€” November 3rd 2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...

ossl-code-1200

☐ β˜† βœ‡ Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

By Paul Ducklin β€” November 1st 2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

☐ β˜† βœ‡ Naked Security

SHA-3 code execution bug patched in PHP – check your version!

By Paul Ducklin β€” November 1st 2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

☐ β˜† βœ‡ Naked Security

Chrome issues urgent zero-day fix – update now!

By Paul Ducklin β€” October 29th 2022 at 15:08
We've said it before/And we'll say it again/It's not *if* you should patch/It's a matter of *when*. (Hint: now!)

☐ β˜† βœ‡ Naked Security

Updates to Apple’s zero-day update story – iPhone and iPad users read this!

By Paul Ducklin β€” October 28th 2022 at 18:04
Turns out that Tuesday's zero-day for iOS 16 is Friday's zero-day for iOS 15...

☐ β˜† βœ‡ Naked Security

Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!

By Paul Ducklin β€” October 25th 2022 at 18:03
Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches sneaky β€œspy-on-me” bug – update now!

By Paul Ducklin β€” October 18th 2022 at 18:01
Hey! That back door isn't supposed to be there at all, let alone propped open...

☐ β˜† βœ‡ Naked Security

Dangerous hole in Apache Commons Text – like Log4Shell all over again

By Paul Ducklin β€” October 18th 2022 at 17:26
Third time unlucky. Time to put your patching boots on again...

act-1200

☐ β˜† βœ‡ Naked Security

Mystery iPhone update patches against iOS 16 mail crash-attack

By Paul Ducklin β€” October 11th 2022 at 00:28
The problem with crashy messaging apps is that *other people* get to choose if and when to send you messages...

☐ β˜† βœ‡ Naked Security

S3 Ep102.5: β€œProxyNotShell” Exchange bugs – an expert speaks [Audio + Text]

By Paul Ducklin β€” October 1st 2022 at 14:05
Who's affected, what you can do while waiting for Microsoft's patches, and how to plan your threat hunting...

☐ β˜† βœ‡ Naked Security

URGENT! Microsoft Exchange double zero-day – β€œlike ProxyShell, only different”

By Paul Ducklin β€” September 30th 2022 at 18:25
Double-play 0-day in Exchange - what you need to know, and what you can do

☐ β˜† βœ‡ Naked Security

Uber and Rockstar – has a LAPSUS$ linchpin just been busted (again)?

By Paul Ducklin β€” September 24th 2022 at 22:57
Is this the same suspect as before? Is he part of LAPSUS$? Is this the man who hacked Uber and Rockstar? And, if so, who else?

☐ β˜† βœ‡ Naked Security

S3 Ep101: Uber and LastPass breaches – is 2FA all it’s cracked up to be? [Audio + Text]

By Paul Ducklin β€” September 22nd 2022 at 18:42
Latest episode - listen now! Learn why adopting 2FA isn't a reason to relax your other security precautions...

☐ β˜† βœ‡ Naked Security

Chrome and Edge fix zero-day security hole – update now!

By Paul Ducklin β€” September 5th 2022 at 15:12
This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.

☐ β˜† βœ‡ Naked Security

URGENT! Apple slips out zero-day update for older iPhones and iPads

By Paul Ducklin β€” August 31st 2022 at 18:42
Patch as soon as you can - that recent WebKit zero-day affecting new iPhones and iPads is apparently being used against older models, too.

☐ β˜† βœ‡ Naked Security

Laptop denial-of-service via music: the 1980s R&B song with a CVE!

By Paul Ducklin β€” August 22nd 2022 at 16:03
We haven't validated this vuln ourselves... but the source of the story is impeccable. (Impeccably dressed, at least.)

☐ β˜† βœ‡ Naked Security

Apple patches double zero-day in browser and kernel – update now!

By Paul Ducklin β€” August 17th 2022 at 23:33
Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches critical bug – update now!

By Paul Ducklin β€” August 15th 2022 at 18:26
There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

❌