FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Ghostscript bug could allow rogue documents to run system commands

By Paul Ducklin β€” July 4th 2023 at 17:57
Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.

☐ β˜† βœ‡ Naked Security

S3 Ep140: So you think you know ransomware?

By Paul Ducklin β€” June 22nd 2023 at 16:48
Lots to learn this week - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Megaupload duo will go to prison at last, but Kim Dotcom fights on…

By Paul Ducklin β€” June 19th 2023 at 18:59
One, sadly, has died, and two are heading to prison, but for Kim Dotcom, the saga goes on...

☐ β˜† βœ‡ Naked Security

Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France

By Paul Ducklin β€” May 15th 2023 at 16:36
We asked you once, we told you twice, now we're ordering you for the third time...

☐ β˜† βœ‡ Naked Security

WooCommerce Payments plugin for WordPress has an admin-level hole – patch now!

By Paul Ducklin β€” March 24th 2023 at 19:48
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

woo-1200

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

US passes the Quantum Computing Cybersecurity Preparedness Act – and why not?

By Paul Ducklin β€” December 29th 2022 at 20:45
Cryptographic agility: the ability and the willingness to change quickly when needed.

sc-daa-1200

☐ β˜† βœ‡ Naked Security

Credit card skimming – the long and winding road of supply chain failure

By Paul Ducklin β€” December 8th 2022 at 19:58
Don't keep calling home to a JavaScript server that closed its doors eight years ago!

☐ β˜† βœ‡ Naked Security

β€œGucci Master” business email scammer Hushpuppi gets 11 years

By Naked Security writer β€” November 14th 2022 at 19:24
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...

puppi-car-1200

☐ β˜† βœ‡ Naked Security

S3 Ep106: Facial recognition without consent – should it be banned?

By Paul Ducklin β€” October 27th 2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!

☐ β˜† βœ‡ Naked Security

Dangerous hole in Apache Commons Text – like Log4Shell all over again

By Paul Ducklin β€” October 18th 2022 at 17:26
Third time unlucky. Time to put your patching boots on again...

act-1200

☐ β˜† βœ‡ Naked Security

Fashion brand SHEIN fined $1.9m for lying about data breach

By Naked Security writer β€” October 17th 2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

☐ β˜† βœ‡ Naked Security

Move over Patch Tuesday – it’s Ada Lovelace Day!

By Paul Ducklin β€” October 11th 2022 at 15:22
Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.

☐ β˜† βœ‡ Naked Security

Former Uber CSO convicted of covering up megabreach back in 2016

By Naked Security writer β€” October 6th 2022 at 01:04
Obstructed FTC proceedings, and concealed a crime, said the jury.

☐ β˜† βœ‡ Naked Security

Morgan Stanley fined millions for selling off devices full of customer PII

By Paul Ducklin β€” September 23rd 2022 at 18:07
Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

Post-quantum cryptography – new algorithm β€œgone in 60 minutes”

By Paul Ducklin β€” August 3rd 2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.

☐ β˜† βœ‡ Naked Security

Paying ransomware crooks won’t reduce your legal risk, warns regulator

By Paul Ducklin β€” July 12th 2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

☐ β˜† βœ‡ Naked Security

Apache β€œCommons Configuration” patches Log4Shell-style bug – what you need to know

By Paul Ducklin β€” July 8th 2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.

☐ β˜† βœ‡ Naked Security

OpenSSL issues a bugfix for the previous bugfix

By Paul Ducklin β€” June 24th 2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.

☐ β˜† βœ‡ Naked Security

S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]

By Paul Ducklin β€” April 14th 2022 at 13:39
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default

By Paul Ducklin β€” April 11th 2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?

cat-1200

☐ β˜† βœ‡ Naked Security

Web vendor CafePress fined $500,000 for giving cybersecurity a low value

By Paul Ducklin β€” March 21st 2022 at 16:55
Just because you're the victim of a cybercrime doesn't let you off your cybersecurity obligations

☐ β˜† βœ‡ Naked Security

Happy #PiDay – even if you aren’t in North America!

By Paul Ducklin β€” March 14th 2022 at 23:59
There is a cybersecurity angle here - but you will need to read right to the end to find it :-)

☐ β˜† βœ‡ Naked Security

Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft

By Paul Ducklin β€” January 21st 2022 at 16:25
The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.

☐ β˜† βœ‡ Naked Security

S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]

By Paul Ducklin β€” December 2nd 2021 at 20:50
Latest episode - listen now!

❌