FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Irony alert! PHP fixes security flaw in input validation code

By Paul Ducklin β€” February 18th 2022 at 17:59
What's wrong with this sequence? 1. Step into the road 2. Check if it's safe 3. Keep on walki...

☐ β˜† βœ‡ Naked Security

Microsoft blocks web installation of its own App Installer files

By Paul Ducklin β€” February 7th 2022 at 16:36
It's a big deal when a vendor decides to block one of its own "features" for security reasons. Here's why we think it's a good idea.

☐ β˜† βœ‡ Naked Security

β€œPwnKit” security bug gets you root on most Linux distros – what to do

By Paul Ducklin β€” January 26th 2022 at 19:58
An elevation of privilege bug that could let a "mostly harmless" user give themselves a instant root shell

☐ β˜† βœ‡ Naked Security

Home routers with NetUSB support could have critical kernel hole

By Paul Ducklin β€” January 11th 2022 at 17:42
Got a router that supports USB access across the network? You might need a kernel update...

☐ β˜† βœ‡ Naked Security

Log4Shell-like security hole found in popular Java SQL database engine H2

By Paul Ducklin β€” January 7th 2022 at 19:32
"It's Log4Shell, Jim, but not as we know it." How to find and fix a JNDI-based vuln in the H2 Database Engine.

☐ β˜† βœ‡ Naked Security

Log4Shell vulnerability Number Four: β€œMuch ado about something”

By Paul Ducklin β€” December 29th 2021 at 19:12
It's a Log4j bug, and you ought to patch it. But we don't think it's a critical crisis like the last one.

☐ β˜† βœ‡ Naked Security

Apache’s other product: Critical bugs in β€˜httpd’ web server, patch now!

By Paul Ducklin β€” December 21st 2021 at 19:57
The Apache web server just got an update - this one is nothing to do with Log4j!

☐ β˜† βœ‡ Naked Security

Log4Shell: The Movie… a short, safe visual tour for work and home

By Paul Ducklin β€” December 20th 2021 at 13:20
Be happy that your sysadmins are taking one (three, actually!) for the team right now... here's why!

☐ β˜† βœ‡ Naked Security

Serious Security: OpenSSL fixes β€œerror conflation” bugs – how mixing up mistakes can lead to trouble

By Paul Ducklin β€” December 17th 2021 at 17:57
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!

☐ β˜† βœ‡ Naked Security

S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]

By Paul Ducklin β€” December 16th 2021 at 17:41
Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)

☐ β˜† βœ‡ Naked Security

Log4Shell explained – how it works, why you need to know, and how to fix it

By Paul Ducklin β€” December 13th 2021 at 19:41
Find out how to deal with the Log4Shell vulnerability right across your estate. Yes, you need to patch, but that helps everyone else along with you!

☐ β˜† βœ‡ Naked Security

β€œLog4Shell” Java vulnerability – how to safeguard your servers

By Paul Ducklin β€” December 10th 2021 at 19:22
Just when you thought it was safe to relax for the weekend... a critical bug showed up in Apache's Log4j product

☐ β˜† βœ‡ Naked Security

Check your patches – public exploit now out for critical Exchange bug

By Paul Ducklin β€” November 23rd 2021 at 14:36
It was a zero-day bug until Patch Tuesday, now there's an anyone-can-use-it exploit. Don't be the one who hasn't patched.

☐ β˜† βœ‡ Naked Security

Microsoft documents β€œSHROOTLESS” hack patched in latest Apple updates

By Paul Ducklin β€” October 29th 2021 at 13:38
We'd have called this bug "SHROOTMORE", but naming it wasn't our call.

☐ β˜† βœ‡ Naked Security

Listen up 2 – CYBERSECURITY FIRST! How to protect yourself from supply chain attacks

By Paul Ducklin β€” October 25th 2021 at 16:38
Everyone remembers this year's big-news supply chain attacks on Kaseya and SolarWinds. Sophos expert Chester Wisniewski explains how to control the risk.

☐ β˜† βœ‡ Naked Security

Listen up 3 – CYBERSECURITY FIRST! Cyberinsurance, help or hindrance?

By Paul Ducklin β€” October 25th 2021 at 16:37
Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance.

☐ β˜† βœ‡ Naked Security

Listen up 4 – CYBERSECURITY FIRST! Purple teaming – learning to think like your adversaries

By Paul Ducklin β€” October 25th 2021 at 16:36
Michelle Farenci knows her stuff, because she's a cybersecurity practitioner inside a cybersecurity company! Learn why thinking like an attacker makes you a better defender.

☐ β˜† βœ‡ Naked Security

Cybersecurity Awareness Month: Listen up – CYBERΒ­SECURITY FIRST!

By Paul Ducklin β€” October 25th 2021 at 16:39
Fraser Howard of SophosLabs is truly a world expert in fighting malware. Read now, and learn from the best!

☐ β˜† βœ‡ Naked Security

Cybersecurity Awareness Month: Building your career

By Paul Ducklin β€” October 18th 2021 at 18:23
Explore. Experience. Share. How to get into cybersecurity...

❌