Login
FreshRSS
Login
Secure Planet Training Courses Updated For 2019 - Click Here
Main stream
Favourites (0)
My labels
Security
/r/netsec - Information Security News & Discussion
Dark Reading:
ICS-CERT Alert Feed
InfoSec Resources
Infosec Island Latest Articles
Krebs on Security
McAfee Blogs
Naked Security
News β Packet Storm
Paul's Security Weekly
SANS Internet Storm Center, InfoCON: green
Security β Cisco Blog
SecurityFocus News
The Hacker News
The Register - Security
The first stop for security news | Threatpost
Threatpost | The first stop for security news
Troy Hunt
Verisign Blog
WIRED
WeLiveSecurity
ZDNet | security RSS
http://blog.trendmicro.com/feed
Tools
KitPloit - PenTest Tools!
Security Tool Files β Packet Storm
ToolsWatch.org β The Hackers Arsenal Tools Portal
Vulnerabilities
Advisory Files β Packet Storm
Exploit-DB Updates
Full Disclosure
SecurityFocus Vulnerabilities
There are new available articles, click to refresh the page.
Before yesterday
Naked Security
Naked Security
Ghostscript bug could allow rogue documents to run system commands
July 4
th
2023 at 17:57Β
Ghostscript bug could allow rogue documents to run system commands
By:
Paul Ducklin
Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.
π·οΈ
My labels
β
Article tags
β
Vulnerability
command injection
CVE-2023-36664
Ghostscript
pipe
rce
vulnerability
July 4
th
2023 at 17:57
Naked Security
S3 Ep140: So you think you know ransomware?
June 22
nd
2023 at 16:48Β
S3 Ep140: So you think you know ransomware?
By:
Paul Ducklin
Lots to learn this week - listen now! (Full transcript inside.)
π·οΈ
My labels
β
Article tags
β
Law & order
Podcast
Vulnerability
Asus
Kim Dotcom
megaupload
MOVEit
Naked Security Podcast
vulnerability
June 22
nd
2023 at 16:48
Naked Security
Megaupload duo will go to prison at last, but Kim Dotcom fights onβ¦
June 19
th
2023 at 16:59Β
Megaupload duo will go to prison at last, but Kim Dotcom fights onβ¦
By:
Paul Ducklin
One, sadly, has died, and two are heading to prison, but for Kim Dotcom, the saga goes on...
π·οΈ
My labels
β
Article tags
β
Law & order
dotcom
file locker
Kim Dotcom
megaupload
June 19
th
2023 at 16:59
Naked Security
Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France
May 15
th
2023 at 16:36Β
Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France
By:
Paul Ducklin
We asked you once, we told you twice, now we're ordering you for the third time...
π·οΈ
My labels
β
Article tags
β
GDPR compliance
Privacy
Clearview
Clearview AI
CNIL
Data Collection
May 15
th
2023 at 16:36
Naked Security
WooCommerce Payments plugin for WordPress has an admin-level hole β patch now!
March 24
th
2023 at 17:48Β
WooCommerce Payments plugin for WordPress has an admin-level hole β patch now!
By:
Paul Ducklin
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.
woo-1200
π·οΈ
My labels
β
Article tags
β
Data loss
Privacy
Vulnerability
vulnerability
WooCommerce
Wordpress
March 24
th
2023 at 17:48
Naked Security
GitHub code-signing certificates stolen (but will be revoked this week)
January 31
st
2023 at 11:35Β
GitHub code-signing certificates stolen (but will be revoked this week)
By:
Paul Ducklin
There was a breach, so the bad news isn't great, but the good news isn't too bad...
π·οΈ
My labels
β
Article tags
β
Data loss
Microsoft
Vulnerability
certificate breach
Code signing
compromise
github
January 31
st
2023 at 11:35
Naked Security
US passes the Quantum Computing Cybersecurity Preparedness Act β and why not?
December 29
th
2022 at 13:45Β
US passes the Quantum Computing Cybersecurity Preparedness Act β and why not?
By:
Paul Ducklin
Cryptographic agility: the ability and the willingness to change quickly when needed.
sc-daa-1200
π·οΈ
My labels
β
Article tags
β
Cryptography
Congress
Grover
PQC
quantum
quantum computing
Shor
December 29
th
2022 at 13:45
Naked Security
Credit card skimming β the long and winding road of supply chain failure
December 8
th
2022 at 17:58Β
Credit card skimming β the long and winding road of supply chain failure
By:
Paul Ducklin
Don't keep calling home to a JavaScript server that closed its doors eight years ago!
π·οΈ
My labels
β
Article tags
β
Data loss
Malware
Privacy
Cockpit
e-commerce
HTML injection
skimming
December 8
th
2022 at 17:58
Naked Security
βGucci Masterβ business email scammer Hushpuppi gets 11 years
November 14
th
2022 at 16:24Β
βGucci Masterβ business email scammer Hushpuppi gets 11 years
By:
Naked Security writer
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...
puppi-car-1200
π·οΈ
My labels
β
Article tags
β
BEC
Law & order
Abbas
business email compromise
Hushpuppi
November 14
th
2022 at 16:24
Naked Security
S3 Ep106: Facial recognition without consent β should it be banned?
October 27
th
2022 at 16:59Β
S3 Ep106: Facial recognition without consent β should it be banned?
By:
Paul Ducklin
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!
π·οΈ
My labels
β
Article tags
β
Cryptography
Data loss
GDPR compliance
Law & order
Podcast
Privacy
Ransomware
Clearview
Clearview AI
Deadbolt
Naked Security Podcast
randomness
October 27
th
2022 at 16:59
Naked Security
Dangerous hole in Apache Commons Text β like Log4Shell all over again
October 18
th
2022 at 16:26Β
Dangerous hole in Apache Commons Text β like Log4Shell all over again
By:
Paul Ducklin
Third time unlucky. Time to put your patching boots on again...
act-1200
π·οΈ
My labels
β
Article tags
β
Vulnerability
Apache
Apache Commons Text
CVE-2022-42889
Log4j
Log4Shell
string interpolation
October 18
th
2022 at 16:26
Naked Security
Fashion brand SHEIN fined $1.9m for lying about data breach
October 17
th
2022 at 16:50Β
Fashion brand SHEIN fined $1.9m for lying about data breach
By:
Naked Security writer
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?
π·οΈ
My labels
β
Article tags
β
Data loss
GDPR compliance
cover-up
data breach
New York
ROMWE
SHEIN
Zoetop
October 17
th
2022 at 16:50
Naked Security
Move over Patch Tuesday β itβs Ada Lovelace Day!
October 11
th
2022 at 15:22Β
Move over Patch Tuesday β itβs Ada Lovelace Day!
By:
Paul Ducklin
Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.
π·οΈ
My labels
β
Article tags
β
Machine Learning
ada
Ada Lovelace Day
Alan Turing
babbage
computer science
Lady Lovelace
October 11
th
2022 at 15:22
Naked Security
Former Uber CSO convicted of covering up megabreach back in 2016
October 6
th
2022 at 01:04Β
Former Uber CSO convicted of covering up megabreach back in 2016
By:
Naked Security writer
Obstructed FTC proceedings, and concealed a crime, said the jury.
π·οΈ
My labels
β
Article tags
β
Data loss
GDPR compliance
Privacy
Sullivan
Uber
October 6
th
2022 at 01:04
Naked Security
Morgan Stanley fined millions for selling off devices full of customer PII
September 23
rd
2022 at 14:07Β
Morgan Stanley fined millions for selling off devices full of customer PII
By:
Paul Ducklin
Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...
π·οΈ
My labels
β
Article tags
β
Data loss
GDPR compliance
data desctruction
data loss
Encryption
Morgan Stanley
September 23
rd
2022 at 14:07
Naked Security
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]
August 11
th
2022 at 14:34Β
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]
By:
Paul Ducklin
Latest episode - listen now! (Or read the transcript if you prefer.)
π·οΈ
My labels
β
Article tags
β
Cryptography
Data loss
Law & order
Malware
Microsoft
Podcast
Privacy
Cybercrime
github
hacking
malware
Naked Security Podcast
quantum computing
August 11
th
2022 at 14:34
Naked Security
Post-quantum cryptography β new algorithm βgone in 60 minutesβ
August 3
rd
2022 at 16:55Β
Post-quantum cryptography β new algorithm βgone in 60 minutesβ
By:
Paul Ducklin
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.
π·οΈ
My labels
β
Article tags
β
Cryptography
nist
PQC
quantum
quantum computing
SIKE
August 3
rd
2022 at 16:55
Naked Security
Paying ransomware crooks wonβt reduce your legal risk, warns regulator
July 12
th
2022 at 13:24Β
Paying ransomware crooks wonβt reduce your legal risk, warns regulator
By:
Paul Ducklin
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?
π·οΈ
My labels
β
Article tags
β
GDPR compliance
Law & order
Ransomware
Uncategorized
cyberextortion
GCHQ
ico
NCSC
ransomware
July 12
th
2022 at 13:24
Naked Security
Apache βCommons Configurationβ patches Log4Shell-style bug β what you need to know
July 8
th
2022 at 00:59Β
Apache βCommons Configurationβ patches Log4Shell-style bug β what you need to know
By:
Paul Ducklin
It's a bit like Log4J, but for configuration files, not for logging.
π·οΈ
My labels
β
Article tags
β
Vulnerability
Apache Commons
CVE-2022-33980
July 8
th
2022 at 00:59
Naked Security
OpenSSL issues a bugfix for the previous bugfix
June 24
th
2022 at 15:32Β
OpenSSL issues a bugfix for the previous bugfix
By:
Paul Ducklin
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.
π·οΈ
My labels
β
Article tags
β
Cryptography
Vulnerability
command injection
crypto
openssl
June 24
th
2022 at 15:32
Naked Security
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
April 14
th
2022 at 13:39Β
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
By:
Paul Ducklin
Latest episode - listen now!
π·οΈ
My labels
β
Article tags
β
Cryptocurrency
Cryptography
Podcast
Vulnerability
darkweb
Hydra
iot
Naked Security Podcast
PQC
quantum computing
robot
takedown
April 14
th
2022 at 13:39
Naked Security
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
April 11
th
2022 at 16:58Β
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
By:
Paul Ducklin
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?
cat-1200
π·οΈ
My labels
β
Article tags
β
Cryptography
NTRU Prime
openssh
quantum computing
April 11
th
2022 at 16:58
Naked Security
Web vendor CafePress fined $500,000 for giving cybersecurity a low value
March 21
st
2022 at 16:55Β
Web vendor CafePress fined $500,000 for giving cybersecurity a low value
By:
Paul Ducklin
Just because you're the victim of a cybercrime doesn't let you off your cybersecurity obligations
π·οΈ
My labels
β
Article tags
β
GDPR compliance
Privacy
compliance
fine
ftc
March 21
st
2022 at 16:55
Naked Security
Happy #PiDay β even if you arenβt in North America!
March 14
th
2022 at 23:59Β
Happy #PiDay β even if you arenβt in North America!
By:
Paul Ducklin
There is a cybersecurity angle here - but you will need to read right to the end to find it :-)
π·οΈ
My labels
β
Article tags
β
computation
mathematics
March 14
th
2022 at 23:59
Naked Security
Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft
January 21
st
2022 at 16:25Β
Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft
By:
Paul Ducklin
The company has put out a brief security report that summarises the 'what', but not yet the 'how' or 'why'.
π·οΈ
My labels
β
Article tags
β
Cryptocurrency
Vulnerability
2FA
Crypto.com
cryptocurrency
January 21
st
2022 at 16:25
Naked Security
S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]
December 2
nd
2021 at 20:50Β
S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]
By:
Paul Ducklin
Latest episode - listen now!
π·οΈ
My labels
β
Article tags
β
Law & order
Podcast
Privacy
Ada Lovelace
AI
computer ethics
Cybercrime
cybersecurity
facial recognition
Naked Security Podcast
December 2
nd
2021 at 20:50
There are no more articles
β
Mark all as read