Login
FreshRSS
Login
Naked Security
Ghostscript bug could allow rogue documents to run system commands
By
Paul Ducklin
β July 4
th
2023 at 17:57
Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.
Naked Security
S3 Ep140: So you think you know ransomware?
By
Paul Ducklin
β June 22
nd
2023 at 16:48
Lots to learn this week - listen now! (Full transcript inside.)
Naked Security
Megaupload duo will go to prison at last, but Kim Dotcom fights onβ¦
By
Paul Ducklin
β June 19
th
2023 at 18:59
One, sadly, has died, and two are heading to prison, but for Kim Dotcom, the saga goes on...
Naked Security
Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France
By
Paul Ducklin
β May 15
th
2023 at 16:36
We asked you once, we told you twice, now we're ordering you for the third time...
Naked Security
WooCommerce Payments plugin for WordPress has an admin-level hole β patch now!
By
Paul Ducklin
β March 24
th
2023 at 19:48
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.
woo-1200
Naked Security
GitHub code-signing certificates stolen (but will be revoked this week)
By
Paul Ducklin
β January 31
st
2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...
Naked Security
US passes the Quantum Computing Cybersecurity Preparedness Act β and why not?
By
Paul Ducklin
β December 29
th
2022 at 20:45
Cryptographic agility: the ability and the willingness to change quickly when needed.
sc-daa-1200
Naked Security
Credit card skimming β the long and winding road of supply chain failure
By
Paul Ducklin
β December 8
th
2022 at 19:58
Don't keep calling home to a JavaScript server that closed its doors eight years ago!
Naked Security
βGucci Masterβ business email scammer Hushpuppi gets 11 years
By
Naked Security writer
β November 14
th
2022 at 19:24
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...
puppi-car-1200
Naked Security
S3 Ep106: Facial recognition without consent β should it be banned?
By
Paul Ducklin
β October 27
th
2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!
Naked Security
Dangerous hole in Apache Commons Text β like Log4Shell all over again
By
Paul Ducklin
β October 18
th
2022 at 17:26
Third time unlucky. Time to put your patching boots on again...
act-1200
Naked Security
Fashion brand SHEIN fined $1.9m for lying about data breach
By
Naked Security writer
β October 17
th
2022 at 18:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?
Naked Security
Move over Patch Tuesday β itβs Ada Lovelace Day!
By
Paul Ducklin
β October 11
th
2022 at 15:22
Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.
Naked Security
Former Uber CSO convicted of covering up megabreach back in 2016
By
Naked Security writer
β October 6
th
2022 at 01:04
Obstructed FTC proceedings, and concealed a crime, said the jury.
Naked Security
Morgan Stanley fined millions for selling off devices full of customer PII
By
Paul Ducklin
β September 23
rd
2022 at 18:07
Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...
Naked Security
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]
By
Paul Ducklin
β August 11
th
2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)
Naked Security
Post-quantum cryptography β new algorithm βgone in 60 minutesβ
By
Paul Ducklin
β August 3
rd
2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.
Naked Security
Paying ransomware crooks wonβt reduce your legal risk, warns regulator
By
Paul Ducklin
β July 12
th
2022 at 18:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?
Naked Security
Apache βCommons Configurationβ patches Log4Shell-style bug β what you need to know
By
Paul Ducklin
β July 8
th
2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.
Naked Security
OpenSSL issues a bugfix for the previous bugfix
By
Paul Ducklin
β June 24
th
2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.
Naked Security
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
By
Paul Ducklin
β April 14
th
2022 at 13:39
Latest episode - listen now!
Naked Security
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
By
Paul Ducklin
β April 11
th
2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?
cat-1200
Naked Security
Web vendor CafePress fined $500,000 for giving cybersecurity a low value
By
Paul Ducklin
β March 21
st
2022 at 16:55
Just because you're the victim of a cybercrime doesn't let you off your cybersecurity obligations
Naked Security
Happy #PiDay β even if you arenβt in North America!
By
Paul Ducklin
β March 14
th
2022 at 23:59
There is a cybersecurity angle here - but you will need to read right to the end to find it :-)
Naked Security
Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft
By
Paul Ducklin
β January 21
st
2022 at 16:25
The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.
Naked Security
S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]
By
Paul Ducklin
β December 2
nd
2021 at 20:50
Latest episode - listen now!
There are no more articles
β
Mark all as read