FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Mom’s Meals issues β€œNotice of Data Event”: What to know and what to do

By Paul Ducklin β€” August 29th 2023 at 16:51
It took six months for notifications to start, and we still don't know exactly what went down... but here's our advice on what to do.

☐ β˜† βœ‡ Naked Security

S3 Ep149: How many cryptographers does it take to change a light bulb?

By Paul Ducklin β€” August 24th 2023 at 18:50
Latest episode - listen now! Full transcript inside...

☐ β˜† βœ‡ Naked Security

β€œSnakes in airplane mode” – what if your phone says it’s offline but isn’t?

By Paul Ducklin β€” August 21st 2023 at 17:45
WYSIWYG is short for "what you see is what you get". Except when it isn't...

☐ β˜† βœ‡ Naked Security

β€œGrab hold and give it a wiggle” – ATM card skimming is still a thing

By Paul Ducklin β€” August 14th 2023 at 23:18
The rise of tap-to-pay and chip-and-PIN hasn't rid the world of ATM card skimming criminals...

☐ β˜† βœ‡ Naked Security

S3 Ep147: What if you type in your password during a meeting?

By Paul Ducklin β€” August 10th 2023 at 13:34
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Serious Security: Why learning to touch-type could protect you from audio snooping

By Paul Ducklin β€” August 8th 2023 at 18:51
Fast, quiet, smooth, consistent and low impact... why true hacker-grade touch-typing might keep you more secure.

☐ β˜† βœ‡ Naked Security

S3 Ep146: Tell us about that breach! (If you want to.)

By Paul Ducklin β€” August 3rd 2023 at 17:56
Serious security stories explained clearly in plain English - listen now. (Full transcript available.)

☐ β˜† βœ‡ Naked Security

Performance and security clash yet again in β€œCollide+Power” attack

By Paul Ducklin β€” August 2nd 2023 at 23:36
It's a real vulnerability, but the data leakage rate can be as low as... let's just say that an IMAX-quality copy of the new "Oppenheimer" movie could take you 4 billion years to exfiltrate.

☐ β˜† βœ‡ Naked Security

SEC demands four-day disclosure limit for cybersecurity breaches

By Paul Ducklin β€” July 31st 2023 at 18:57
When is a ransomware attack a reportable matter? And how long have you got to decide?

☐ β˜† βœ‡ Naked Security

S3 Ep145: Bugs With Impressive Names!

By Paul Ducklin β€” July 27th 2023 at 18:47
Fascinating fun (with a serious and educational side) - listen now! Full transcript available inside.

☐ β˜† βœ‡ Naked Security

Zenbleed: How the quest for CPU performance could put your passwords at risk

By Paul Ducklin β€” July 26th 2023 at 19:01
You need to turn on a special setting to stop (the code you wrote to stop [the code you wrote to improve performance] from reducing performance) from reducing security.

☐ β˜† βœ‡ Naked Security

Google Virus Total leaks list of spooky email addresses

By Paul Ducklin β€” July 18th 2023 at 23:16
Careful with that file, Eugene!

☐ β˜† βœ‡ Naked Security

Microsoft hit by Storm season – a tale of two semi-zero days

By Paul Ducklin β€” July 18th 2023 at 20:59
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...

☐ β˜† βœ‡ Naked Security

Zimbra Collaboration Suite warning: Patch this 0-day right now (by hand)!

By Paul Ducklin β€” July 14th 2023 at 19:58
Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly request your cooperation to apply the fix manually."

☐ β˜† βœ‡ Naked Security

Serious Security: Rowhammer returns to gaslight your computer

By Paul Ducklin β€” July 10th 2023 at 21:22
Gaslights produce a telltale flicker when nearby lamps are lit; DRAM values do something similar when nearby memory cells are accessed.

☐ β˜† βœ‡ Naked Security

S3 Ep141: What was Steve Jobs’s first job?

By Paul Ducklin β€” June 29th 2023 at 16:58
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Interested in $10,000,000? Ready to turn in the Clop ransomware crew?

By Naked Security writer β€” June 28th 2023 at 18:59
Technically, it's "up to $10 million", but it's potentially a LOT of money, nevertheless...

☐ β˜† βœ‡ Naked Security

Aussie PM says, β€œShut down your phone every 24 hours for 5 mins” – but that’s not enough on its own

By Paul Ducklin β€” June 23rd 2023 at 16:10
Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.

☐ β˜† βœ‡ Naked Security

Gozi banking malware β€œIT chief” finally jailed after more than 10 years

By Paul Ducklin β€” June 13th 2023 at 18:43
Gozi threesome from way back in the late 2000s and early 2010s now all charged, convicted and sentenced. The DOJ got there in the end...

☐ β˜† βœ‡ Naked Security

More MOVEit mitigations: new patches published for further protection

By Paul Ducklin β€” June 9th 2023 at 21:54
Good news... more patches, this time available proactively

☐ β˜† βœ‡ Naked Security

MOVEit zero-day exploit used by data breach gangs: The how, the why, and what to do…

By Paul Ducklin β€” June 5th 2023 at 19:59
Little Bobby Tables is back!

mi-1200

☐ β˜† βœ‡ Naked Security

S3 Ep137: 16th century crypto skullduggery

By Paul Ducklin β€” June 1st 2023 at 16:45
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

s3-ep137-feat-1200

☐ β˜† βœ‡ Naked Security

Serious Security: That KeePass β€œmaster password crack”, and what we can learn from it

By Paul Ducklin β€” May 31st 2023 at 19:39
Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

☐ β˜† βœ‡ Naked Security

Serious Security: Verification is vital – examining an OAUTH login bug

By Paul Ducklin β€” May 30th 2023 at 16:59
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

☐ β˜† βœ‡ Naked Security

Phone scamming kingpin gets 13 years for running β€œiSpoof” service

By Naked Security writer β€” May 22nd 2023 at 16:58
Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

ispoof-1200

☐ β˜† βœ‡ Naked Security

Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France

By Paul Ducklin β€” May 15th 2023 at 16:36
We asked you once, we told you twice, now we're ordering you for the third time...

☐ β˜† βœ‡ Naked Security

Whodunnit? Cybercrook gets 6 years for ransoming his own employer

By Naked Security writer β€” May 12th 2023 at 16:15
Not just an active adversary, but a two-faced one, too.

☐ β˜† βœ‡ Naked Security

S3 Ep131: Can you really have fun with FORTRAN?

By Paul Ducklin β€” April 20th 2023 at 17:55
Loop-the-loop in this week's episode. Entertaining, educational and all in plain English. Transcript inside.

☐ β˜† βœ‡ Naked Security

Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security

By Paul Ducklin β€” April 18th 2023 at 16:56
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

☐ β˜† βœ‡ Naked Security

FBI and FCC warn about β€œJuicejacking” – but just how useful is their advice?

By Paul Ducklin β€” April 17th 2023 at 18:17
USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?

☐ β˜† βœ‡ Naked Security

Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert

By Paul Ducklin β€” April 11th 2023 at 18:58
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

☐ β˜† βœ‡ Naked Security

S3 Ep129: When spyware arrives from someone you trust

By Paul Ducklin β€” April 6th 2023 at 14:57
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

☐ β˜† βœ‡ Naked Security

Researchers claim they can bypass Wi-Fi encryption (briefly, at least)

By Paul Ducklin β€” April 3rd 2023 at 16:59
They can't read much of your data, but even a few stray network packets could tell them something they're not supposed to know.

☐ β˜† βœ‡ Naked Security

Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

By Paul Ducklin β€” March 27th 2023 at 19:59
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

☐ β˜† βœ‡ Naked Security

WooCommerce Payments plugin for WordPress has an admin-level hole – patch now!

By Paul Ducklin β€” March 24th 2023 at 19:48
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

woo-1200

☐ β˜† βœ‡ Naked Security

S3 Ep127: When you chop someone out of a photo, but there they are anyway…

By Paul Ducklin β€” March 23rd 2023 at 17:59
Listen now - latest episode. Full transcript inside.

☐ β˜† βœ‡ Naked Security

Windows 11 also vulnerable to β€œaCropalypse” image data leakage

By Paul Ducklin β€” March 22nd 2023 at 17:59
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

☐ β˜† βœ‡ Naked Security

Google Pixel phones had a serious data leakage bug – here’s what to do!

By Paul Ducklin β€” March 21st 2023 at 17:58
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

☐ β˜† βœ‡ Naked Security

Bitcoin ATM customers hacked by video upload that was actually an app

By Paul Ducklin β€” March 20th 2023 at 19:50
As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...

☐ β˜† βœ‡ Naked Security

S3 Ep 126: The price of fast fashion (and feature creep) [Audio + Text]

By Paul Ducklin β€” March 16th 2023 at 17:56
Worried about rogue apps? Unsure about the new Outlook zero-day? Clear advice in plain English... just like old times, with Duck and Chet!

☐ β˜† βœ‡ Naked Security

SHEIN shopping app goes rogue, grabs price and URL data from your clipboard

By Paul Ducklin β€” March 10th 2023 at 19:58
It's not exactly data theft, but it's worryingly close to "unintentional treachery" - apparently because it's great for marketing purposes

☐ β˜† βœ‡ Naked Security

Feds warn about right Royal ransomware rampage that runs the gamut of TTPs

By Paul Ducklin β€” March 3rd 2023 at 19:56
Wondering which cybercrime tools, techniques and procedures to focus on? How about any and all of them?

☐ β˜† βœ‡ Naked Security

S3 Ep124: When so-called security apps go rogue [Audio + Text]

By Paul Ducklin β€” March 2nd 2023 at 19:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

s3-ep124-auth--1200

☐ β˜† βœ‡ Naked Security

LastPass: Keylogger on home PC led to cracked corporate password vault

By Paul Ducklin β€” February 28th 2023 at 02:23
Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.

☐ β˜† βœ‡ Naked Security

Dutch police arrest three cyberextortion suspects who allegedly earned millions

By Naked Security writer β€” February 27th 2023 at 19:33
Ever paid hush money to crooks who broke into your network? Wondered how much you can trust them?

☐ β˜† βœ‡ Naked Security

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!

By Paul Ducklin β€” February 27th 2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

☐ β˜† βœ‡ Naked Security

S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]

By Paul Ducklin β€” February 23rd 2023 at 19:58
Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

☐ β˜† βœ‡ Naked Security

NPM JavaScript packages abused to create scambait links in bulk

By Paul Ducklin β€” February 22nd 2023 at 20:59
Free spins? Bonus game points? Cheap social media followers? What harm could it possibly do if you just take a tiny little look?!

☐ β˜† βœ‡ Naked Security

Coinbase breached by social engineers, employee data stolen

By Paul Ducklin β€” February 21st 2023 at 17:58
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

☐ β˜† βœ‡ Naked Security

GoDaddy admits: Crooks hit us with malware, poisoned customer websites

By Paul Ducklin β€” February 20th 2023 at 01:36
New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.

☐ β˜† βœ‡ Naked Security

Reddit admits it was hacked and data stolen, says β€œDon’t panic”

By Paul Ducklin β€” February 10th 2023 at 19:59
Reddit is suggesting three tips as a follow-up to this breach. We agree with two of them but not with the third...

☐ β˜† βœ‡ Naked Security

Finnish psychotherapy extortion suspect arrested in France

By Naked Security writer β€” February 6th 2023 at 19:13
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By Paul Ducklin β€” February 1st 2023 at 19:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

Dutch suspect locked up for alleged personal data megathefts

By Paul Ducklin β€” January 26th 2023 at 22:02
Undercover Austrian "controlled data buy" leads to Amsterdam arrest and ongoing investigation. Suspect is said to steal and sell all sorts of data, including medical records.

☐ β˜† βœ‡ Naked Security

S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text]

By Paul Ducklin β€” January 26th 2023 at 19:57
Lastest episode - listen now! (Or read the transcript.)

☐ β˜† βœ‡ Naked Security

GoTo admits: Customer cloud backups stolen together with decryption key

By Paul Ducklin β€” January 25th 2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

☐ β˜† βœ‡ Naked Security

T-Mobile admits to 37,000,000 customer records stolen by β€œbad actor”

By Paul Ducklin β€” January 20th 2023 at 17:59
Once more, it's time for Shakespeare's words: Once more unto the breach...

☐ β˜† βœ‡ Naked Security

S3 Ep118: Guess your password? No need if it’s stolen already! [Audio + Text]

By Paul Ducklin β€” January 19th 2023 at 15:53
As always: entertaining, informative and educational... and not bogged down with jargon! Listen (or read) now...

☐ β˜† βœ‡ Naked Security

CircleCI – code-building service suffers total credential compromise

By Paul Ducklin β€” January 9th 2023 at 14:52
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

❌