FreshRSS

πŸ”’
☐ β˜† βœ‡ Naked Security

Crimeware server used by NetWalker ransomware seized and shut down

By Paul Ducklin β€” August 14th 2023 at 19:06
The site was running from 2014 and allegedly raked in more than $20m, which the DOJ is seeking to claw back...

☐ β˜† βœ‡ Naked Security

β€œCrocodile of Wall Street” and her husband plead guilty to giant-sized cryptocrimes

By Paul Ducklin β€” August 4th 2023 at 16:52
Sentences still to be decided, but she could get up to 10 years and he could get as many as 20.

☐ β˜† βœ‡ Naked Security

Phone scamming kingpin gets 13 years for running β€œiSpoof” service

By Naked Security writer β€” May 22nd 2023 at 16:58
Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

ispoof-1200

☐ β˜† βœ‡ Naked Security

PHP Packagist supply chain poisoned by hacker β€œlooking for a job”

By Paul Ducklin β€” May 5th 2023 at 16:59
I pwned you! Gizza job! You know it makes sense!

☐ β˜† βœ‡ Naked Security

Hack and enter! The β€œsecure” garage doors that anyone can open from anywhere – what you need to know

By Paul Ducklin β€” April 5th 2023 at 18:49
Grab a message/Play it back/You've just performed/A big phat hack...

☐ β˜† βœ‡ Naked Security

S3 Ep125: When security hardware has security holes [Audio + Text]

By Paul Ducklin β€” March 9th 2023 at 18:58
Lastest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Feds warn about right Royal ransomware rampage that runs the gamut of TTPs

By Paul Ducklin β€” March 3rd 2023 at 19:56
Wondering which cybercrime tools, techniques and procedures to focus on? How about any and all of them?

☐ β˜† βœ‡ Naked Security

OpenSSL fixes High Severity data-stealing bug – patch now!

By Paul Ducklin β€” February 8th 2023 at 02:58
7 memory mismanagements and a timing attack. We explain all the jargon bug terminology in plain English...

☐ β˜† βœ‡ Naked Security

S3 Ep120: When dud crypto simply won’t let go [Audio + Text]

By Paul Ducklin β€” February 2nd 2023 at 17:50
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

Serious Security: The Samba logon bug caused by outdated crypto

By Paul Ducklin β€” January 30th 2023 at 19:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

☐ β˜† βœ‡ Naked Security

T-Mobile admits to 37,000,000 customer records stolen by β€œbad actor”

By Paul Ducklin β€” January 20th 2023 at 17:59
Once more, it's time for Shakespeare's words: Once more unto the breach...

☐ β˜† βœ‡ Naked Security

Naked Security 33Β 1/3 – Cybersecurity predictions for 2023 and beyond

By Paul Ducklin β€” December 30th 2022 at 19:59
The problem with anniversaries is that there's an almost infinite number of them every day...

hny-1200

☐ β˜† βœ‡ Naked Security

β€œSuspicious login” scammers up their game – take care at Christmas

By Paul Ducklin β€” December 21st 2022 at 17:59
A picture is worth 1024 words - we clicked through so you don't have to.

☐ β˜† βœ‡ Naked Security

The CHRISTMA EXEC network worm – 35 years and counting!

By Paul Ducklin β€” December 1st 2022 at 20:35
"Uh-oh, this viruses-and-worms scene could turn out quite troublesome." If only we'd been wrong...

xmas-1200-35-wide

☐ β˜† βœ‡ Naked Security

S3 Ep111: The business risk of a sleazy β€œnudity unfilter” [Audio + Text]

By Paul Ducklin β€” December 1st 2022 at 19:58
Latest episode - listen now (or read if you prefer)...

☐ β˜† βœ‡ Naked Security

Voice-scamming site β€œiSpoof” seized, 100s arrested in massive crackdown

By Naked Security writer β€” November 25th 2022 at 19:17
Those numbers or names that pop up when a call comes up? They're OK as a hint of who's calling, but THEY PROVE NOTHING

☐ β˜† βœ‡ Naked Security

How social media scammers buy time to steal your 2FA codes

By Paul Ducklin β€” November 21st 2022 at 17:02
The warning is hosted on a real Facebook page; the phishing uses HTTPS via a real Google server... but the content is all fake

ffs-2fa-1200

☐ β˜† βœ‡ Naked Security

β€œGucci Master” business email scammer Hushpuppi gets 11 years

By Naked Security writer β€” November 14th 2022 at 19:24
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...

puppi-car-1200

☐ β˜† βœ‡ Naked Security

Silk Road drugs market hacker pleads guilty, faces 20 years inside

By Paul Ducklin β€” November 8th 2022 at 19:58
Jurisprudence isn't like arithmetic... two negatives never make a positive!

☐ β˜† βœ‡ Naked Security

Twitter Blue Badge email scams – Don’t fall for them!

By Naked Security writer β€” November 4th 2022 at 17:59
That was the week that was...

☐ β˜† βœ‡ Naked Security

Serious Security: How randomly (or not) can you shuffle cards?

By Paul Ducklin β€” October 24th 2022 at 18:57
What if you could guess the next card correctly twice as often as you should?

card-fan-1200

☐ β˜† βœ‡ Naked Security

S3 Ep102.5: β€œProxyNotShell” Exchange bugs – an expert speaks [Audio + Text]

By Paul Ducklin β€” October 1st 2022 at 14:05
Who's affected, what you can do while waiting for Microsoft's patches, and how to plan your threat hunting...

☐ β˜† βœ‡ Naked Security

Serious Security: Browser-in-the-browser attacks – watch out for windows that aren’t!

By Paul Ducklin β€” September 13th 2022 at 20:52
Simple but super-sneaky - use a picture of a browser, and convince people it's real...

pipe-light-not-1200

☐ β˜† βœ‡ Naked Security

Post-quantum cryptography – new algorithm β€œgone in 60 minutes”

By Paul Ducklin β€” August 3rd 2022 at 18:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.

☐ β˜† βœ‡ Naked Security

Facebook 2FA scammers return – this time in just 21 minutes

By Paul Ducklin β€” July 13th 2022 at 16:46
Last time they arrived 28 minutes after lighting up their fake domain... this time it was just 21 minutes

☐ β˜† βœ‡ Naked Security

That didn’t last! Microsoft turns off the Office security it just turned on

By Paul Ducklin β€” July 11th 2022 at 13:27
An Office anti-malware setting that took more than 20 years to arrive... and fewer than 20 weeks to vanish again.

☐ β˜† βœ‡ Naked Security

Facebook 2FA phish arrives just 28 minutes after scam domain created

By Paul Ducklin β€” July 1st 2022 at 20:01
The crooks hit us up with this phishing email less than half an hour after they activated their new scam domain.

☐ β˜† βœ‡ Naked Security

S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers [Podcast]

By Paul Ducklin β€” June 16th 2022 at 16:52
Lastest epsiode - listen now!

☐ β˜† βœ‡ Naked Security

Know your enemy! Learn how cybercrime adversaries get in…

By Paul Ducklin β€” June 7th 2022 at 15:49
Here's how 144 recent attacks actually went down in real life. Don't let this happen to you!

☐ β˜† βœ‡ Naked Security

S3 Ep85: Now THAT’S what I call a Microsoft Office exploit! [Podcast]

By Paul Ducklin β€” June 2nd 2022 at 18:37
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Beware the Smish! Home delivery scams with a professional feel…

By Paul Ducklin β€” May 30th 2022 at 17:59
Home delivery scams are getting leaner, and meaner, and more likely to "look about right". Here's an example to show you what we mean...

☐ β˜† βœ‡ Naked Security

Phishing goes KISS: Don’t let plain and simple messages catch you out!

By Paul Ducklin β€” April 25th 2022 at 16:58
Sometimes we receive phishing tricks that we grudgingly have to admit are better than average, just because they're uncomplicated.

☐ β˜† βœ‡ Naked Security

CISA warning: β€œRussian actors bypassed 2FA” – what happened and how to avoid it

By Paul Ducklin β€” March 16th 2022 at 01:22
Don't leave old accounts lying around where someone sketchy could reactivate them.

☐ β˜† βœ‡ Naked Security

S3 Ep72: AirTag stalking, web server coding woes and Instascams [Podcast + Transcript]

By Paul Ducklin β€” March 3rd 2022 at 14:04
Latest episode - listen now (or read it, if that's your preference)...

☐ β˜† βœ‡ Naked Security

Instagram scammers as busy as ever: passwords and 2FA codes at risk

By Paul Ducklin β€” February 28th 2022 at 17:56
Instagram scams don't seem to be dying out - we're seeing more variety and trickiness than ever...

☐ β˜† βœ‡ Naked Security

S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams [Podcast + Transcript]

By Paul Ducklin β€” February 24th 2022 at 16:51
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Self-styled β€œCrocodile of Wall Street” arrested with husband over Bitcoin megaheist

By Naked Security writer β€” February 9th 2022 at 14:44
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!

☐ β˜† βœ‡ Naked Security

At last! Office macros from the internet to be blocked by default

By Paul Ducklin β€” February 8th 2022 at 16:34
It's been a long time coming, and we're not there yet, but at least Microsoft Office will be a bit safer against macro malware...

☐ β˜† βœ‡ Naked Security

Microsoft blocks web installation of its own App Installer files

By Paul Ducklin β€” February 7th 2022 at 16:36
It's a big deal when a vendor decides to block one of its own "features" for security reasons. Here's why we think it's a good idea.

☐ β˜† βœ‡ Naked Security

Coronavirus SMS scam offers home PCR testing devices – don’t fall for it!

By Paul Ducklin β€” January 28th 2022 at 23:58
Free home PCR devices would be technological marvels, and really useful, too. But there aren't any...

☐ β˜† βœ‡ Naked Security

Wormable Windows HTTP hole – what you need to know

By Paul Ducklin β€” January 12th 2022 at 16:24
One bug in the January 2022 Patch Tuesday list is getting lots of attention: "HTTP Protocol Stack Remote Code Execution Vulnerability".

☐ β˜† βœ‡ Naked Security

Instagram copyright infringment scams – don’t get sucked in!

By Paul Ducklin β€” December 30th 2021 at 14:40
We deconstructed a copyright phish so you don't have to. Be warned: the crooks are getting better at these scams...

☐ β˜† βœ‡ Naked Security

Plundered bitcoins recovered by FBI – all 3,879-and-one-sixth of them!

By Paul Ducklin β€” December 22nd 2021 at 17:57
Phew! An audacious crime... that didn't work out.

☐ β˜† βœ‡ Naked Security

IoT devices must β€œprotect consumers from cyberharm”, says UK government

By Paul Ducklin β€” December 2nd 2021 at 19:10
"Must be at least THIS tall to go on ride" seems to be the starting point. Too little, too late? Or better than nothing?

☐ β˜† βœ‡ Naked Security

Black Friday and Cyber Monday – here’s what you REALLY need to do!

By Paul Ducklin β€” November 22nd 2021 at 19:52
The world fills up with cybersecurity tips every year when Black Friday comes round. But what about the rest of the year?

☐ β˜† βœ‡ Naked Security

β€œCustomer complaint” email scam preys on your fear of getting into trouble at work

By Paul Ducklin β€” November 5th 2021 at 19:49
Stop. Think. Connect. Don't let the crooks trick you into acting in haste.

☐ β˜† βœ‡ Naked Security

S3 Ep56: Cryptotrading rodent, ransomware hackback, and a Docusign phish [Podcast]

By Paul Ducklin β€” October 28th 2021 at 18:45
Latest episode - listen now! Serious security explained with personality in plain English.

ns-1200-logo-podcast-with-mic-and-rodent-emoji

☐ β˜† βœ‡ Naked Security

Banking scam uses Docusign phish to thieve 2FA codes

By Paul Ducklin β€” October 26th 2021 at 18:57
999 people in 1000 will know this is a phish straight off the bat. But for 1 in 1000 it will be plausible at first sight...

☐ β˜† βœ‡ Naked Security

Listen up 2 – CYBERSECURITY FIRST! How to protect yourself from supply chain attacks

By Paul Ducklin β€” October 25th 2021 at 16:38
Everyone remembers this year's big-news supply chain attacks on Kaseya and SolarWinds. Sophos expert Chester Wisniewski explains how to control the risk.

☐ β˜† βœ‡ Naked Security

S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish [Podcast]

By Paul Ducklin β€” October 14th 2021 at 18:33
Latest episode - listen now!

❌