FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

S3 Ep102: How to avoid a data breach [Audio + Transcript]

By: Paul Ducklin β€” September 29th 2022 at 18:45
Latest episode - listen now! Tell fact from fiction in hyped-up cybersecurity news...

☐ β˜† βœ‡ Naked Security

Optus breach – Aussie telco told it will have to pay to replace IDs

By: Paul Ducklin β€” September 28th 2022 at 13:55
Licence compromised? Passport number burned? Need a new one? Who's going to pay?

☐ β˜† βœ‡ Naked Security

WhatsApp β€œzero-day exploit” news scare – what you need to know

By: Paul Ducklin β€” September 27th 2022 at 18:51
Is WhatsApp currently under active attack by cybercriminals? Is this a clear and current danger? How worried should WhatsApp users be?

☐ β˜† βœ‡ Naked Security

Uber and Rockstar – has a LAPSUS$ linchpin just been busted (again)?

By: Paul Ducklin β€” September 24th 2022 at 22:57
Is this the same suspect as before? Is he part of LAPSUS$? Is this the man who hacked Uber and Rockstar? And, if so, who else?

☐ β˜† βœ‡ Naked Security

Morgan Stanley fined millions for selling off devices full of customer PII

By: Paul Ducklin β€” September 23rd 2022 at 14:07
Critical data on old disks always seems inaccessible if you really need it. But when you DON''T want it back, guess what happens...

☐ β˜† βœ‡ Naked Security

S3 Ep101: Uber and LastPass breaches – is 2FA all it’s cracked up to be? [Audio + Text]

By: Paul Ducklin β€” September 22nd 2022 at 16:42
Latest episode - listen now! Learn why adopting 2FA isn't a reason to relax your other security precautions...

☐ β˜† βœ‡ Naked Security

Interested in cybersecurity? Join us for Security SOS Week 2022!

By: Paul Ducklin β€” September 21st 2022 at 14:24
Four one-on-one interviews with experts who are passionate about sharing their expertise with the community.

☐ β˜† βœ‡ Naked Security

LastPass source code breach – incident response report released

By: Paul Ducklin β€” September 19th 2022 at 16:59
Wondering how you'd handle a data breach report if the worst happened to you? Here's a useful example.

☐ β˜† βœ‡ Naked Security

S3 Ep100.5: Uber breach – an expert speaks [Audio + Text]

By: Paul Ducklin β€” September 17th 2022 at 20:57
Chester Wisniewski on what we can learn from Uber: "Just because a big company didn't have the security they should doesn't mean you can't."

☐ β˜† βœ‡ Naked Security

UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you

By: Paul Ducklin β€” September 16th 2022 at 15:43
Uber is all over the news for a widely-publicised data breach. We help you answer the question, "How do I stop this happening to me?"

☐ β˜† βœ‡ Naked Security

S3 Ep100: Browser-in-the-Browser – how to spot an attack [Audio + Text]

By: Paul Ducklin β€” September 15th 2022 at 18:50
Latest episode - listen now! Cosmic rockets, zero-days, spotting cybercrooks, and unlocking the DEADBOLT...

s3-ep100-js-1200

☐ β˜† βœ‡ Naked Security

Serious Security: Browser-in-the-browser attacks – watch out for windows that aren’t!

By: Paul Ducklin β€” September 13th 2022 at 20:52
Simple but super-sneaky - use a picture of a browser, and convince people it's real...

pipe-light-not-1200

☐ β˜† βœ‡ Naked Security

Apple patches zero-day holes – even in the brand new iOS 16

By: Paul Ducklin β€” September 12th 2022 at 21:25
Five updates, one upgrade, plus two zero-days. Patch your Macs, iPhones and iPads as soon as you can (again)...

apple-plus-16-1200

☐ β˜† βœ‡ Naked Security

How to deal with dates and times without any timezone tantrums…

By: Paul Ducklin β€” September 9th 2022 at 18:59
Heartfelt encouragement to embrace RFC 3339 - find out why!

☐ β˜† βœ‡ Naked Security

S3 Ep99: TikTok β€œattack” – was there a data breach, or not? [Audio + Text]

By: Paul Ducklin β€” September 8th 2022 at 13:21
Latest episode - listen now! (Or read if you prefer - full transcript inside.)

☐ β˜† βœ‡ Naked Security

DEADBOLT ransomware rears its head again, attacks QNAP devices

By: Paul Ducklin β€” September 7th 2022 at 16:57
NAS devices make it easy for anyone to add high-capacity file servers to their network. Guess why cybercrooks love NAS devices too...

☐ β˜† βœ‡ Naked Security

Chrome and Edge fix zero-day security hole – update now!

By: Paul Ducklin β€” September 5th 2022 at 15:12
This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.

☐ β˜† βœ‡ Naked Security

Peter Eckersley, co-creator of Let’s Encrypt, dies at just 43

By: Paul Ducklin β€” September 4th 2022 at 00:50
This site, like millions of others, has a certificate from Let's Encrypt. Farewell, Peter Eckersley, PhD, who helped make it all possible.

☐ β˜† βœ‡ Naked Security

URGENT! Apple slips out zero-day update for older iPhones and iPads

By: Paul Ducklin β€” August 31st 2022 at 18:42
Patch as soon as you can - that recent WebKit zero-day affecting new iPhones and iPads is apparently being used against older models, too.

☐ β˜† βœ‡ Naked Security

Chrome patches 24 security holes, enables β€œSanitizer” safety system

By: Paul Ducklin β€” August 31st 2022 at 11:48
24 existing bugs fixed. And, we hope, numerous potential future bugs prevented.

☐ β˜† βœ‡ Naked Security

JavaScript bugs aplenty in Node.js ecosystem – found automatically

By: Paul Ducklin β€” August 30th 2022 at 16:59
How to get the better of bugs in all the possible packages in your supply chain?

☐ β˜† βœ‡ Naked Security

LastPass source code breach – do we still recommend password managers?

By: Paul Ducklin β€” August 29th 2022 at 16:59
What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?

☐ β˜† βœ‡ Naked Security

Firefox 104 is out – no critical bugs, but update anyway

By: Paul Ducklin β€” August 26th 2022 at 16:27
Two trust-spoofing bugs were the main culprits this month - but neither one was a zero-day.

☐ β˜† βœ‡ Naked Security

S3 Ep97: Did your iPhone get pwned? How would you know? [Audio + Text]

By: Paul Ducklin β€” August 25th 2022 at 15:37
Latest episode - listen now! (Or read the transcript if you prefer the text version.)

☐ β˜† βœ‡ Naked Security

Breaching airgap security: using your phone’s gyroscope as a microphone

By: Paul Ducklin β€” August 24th 2022 at 18:59
One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...

☐ β˜† βœ‡ Naked Security

Bitcoin ATMs leeched by attackers who created fake admin accounts

By: Paul Ducklin β€” August 23rd 2022 at 15:35
The criminals didn't implant any malware. The attack was orchestrated via malevolent configuration changes.

☐ β˜† βœ‡ Naked Security

Laptop denial-of-service via music: the 1980s R&B song with a CVE!

By: Paul Ducklin β€” August 22nd 2022 at 16:03
We haven't validated this vuln ourselves... but the source of the story is impeccable. (Impeccably dressed, at least.)

☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By: Paul Ducklin β€” August 18th 2022 at 14:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

Apple patches double zero-day in browser and kernel – update now!

By: Paul Ducklin β€” August 17th 2022 at 23:33
Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

☐ β˜† βœ‡ Naked Security

US offers reward β€œup to $10 million” for information about the Conti gang

By: Naked Security writer β€” August 16th 2022 at 16:57
Wanted - Reward Offered - Five unknown individuals (plus a man with a weird hat)

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches critical bug – update now!

By: Paul Ducklin β€” August 15th 2022 at 18:26
There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By: Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By: Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

Slack admits to leaking hashed passwords for five years

By: Paul Ducklin β€” August 8th 2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."

☐ β˜† βœ‡ Naked Security

Traffic Light Protocol for cybersecurity responders gets a revamp

By: Paul Ducklin β€” August 5th 2022 at 16:57
Traffic lights make a handy global metaphor for denoting the sensitivity of cybersecurity threat data - three colours that everyone knows.

☐ β˜† βœ‡ Naked Security

S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]

By: Paul Ducklin β€” August 4th 2022 at 16:52
Latest episode - listen now! (Or read if that's what you prefer.)

☐ β˜† βœ‡ Naked Security

GitHub blighted by β€œresearcher” who created thousands of malicious projects

By: Paul Ducklin β€” August 3rd 2022 at 23:06
If you spew projects laced with hidden malware into an open source repository, don't waste your time telling us "no harm done" afterwards.

☐ β˜† βœ‡ Naked Security

Post-quantum cryptography – new algorithm β€œgone in 60 minutes”

By: Paul Ducklin β€” August 3rd 2022 at 16:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.

☐ β˜† βœ‡ Naked Security

Cryptocoin β€œtoken swapper” Nomad loses $200 million in coding blunder

By: Paul Ducklin β€” August 2nd 2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.

☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By: Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

How to celebrate SysAdmin Day!

By: Paul Ducklin β€” July 29th 2022 at 15:37
I've just popped in to wish you all/The best SysAdmin Day!

☐ β˜† βœ‡ Naked Security

Critical Samba bug could let anyone become Domain Admin – patch now!

By: Paul Ducklin β€” July 27th 2022 at 21:15
It's a serious bug... but there's a fix for it, so you know exactly what to do!

☐ β˜† βœ‡ Naked Security

Mild monthly security update from Firefox – but update anyway

By: Paul Ducklin β€” July 27th 2022 at 00:41
You're probably thinking we're going to say, "Don't delay/Do it today"... and that's exactly what we are saying!

☐ β˜† βœ‡ Naked Security

T-Mobile to cough up $500 million over 2021 data breach

By: Paul Ducklin β€” July 25th 2022 at 16:20
Technically, it's not a fine, and the lawyers will get a big chunk of it. But it still adds up to a half-billion-dollar data breach.

☐ β˜† βœ‡ Naked Security

Office macro security: on-again-off-again feature now BACK ON AGAIN!

By: Paul Ducklin β€” July 23rd 2022 at 01:10
20 years to turn it on, then 20 weeks to turn it off, then just 2 weeks to turn it back on again. That's progress!

☐ β˜† βœ‡ Naked Security

S3 Ep92: Log4Shell4Ever, travel tips, and scamminess [Audio + Text]

By: Paul Ducklin β€” July 21st 2022 at 16:25
Latest episode - listen, read or both!

☐ β˜† βœ‡ Naked Security

Apple patches β€œ0-day” browser bug fixed 2 weeks ago in Chrome, Edge

By: Paul Ducklin β€” July 21st 2022 at 12:38
One vendor's zero-day is another vendor's routine patch...

☐ β˜† βœ‡ Naked Security

Last member of Gozi malware troika arrives in US for criminal trial

By: Paul Ducklin β€” July 20th 2022 at 14:56
His co-conspirators went into and got out of prison years ago, while he remained free. Now the tables have turned...

☐ β˜† βœ‡ Naked Security

8 months on, US says Log4Shell will be around for β€œa decade or longer”

By: Paul Ducklin β€” July 18th 2022 at 16:57
When it comes to cybersecurity, ask not what everyone else can do for you...

☐ β˜† βœ‡ Naked Security

7 cybersecurity tips for your summer vacation!

By: Paul Ducklin β€” July 15th 2022 at 16:23
Here you go - seven thoughtful cybersecurity tips to help you travel safely...

☐ β˜† βœ‡ Naked Security

S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]

By: Paul Ducklin β€” July 14th 2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.

☐ β˜† βœ‡ Naked Security

Facebook 2FA scammers return – this time in just 21 minutes

By: Paul Ducklin β€” July 13th 2022 at 16:46
Last time they arrived 28 minutes after lighting up their fake domain... this time it was just 21 minutes

☐ β˜† βœ‡ Naked Security

Paying ransomware crooks won’t reduce your legal risk, warns regulator

By: Paul Ducklin β€” July 12th 2022 at 13:24
"We paid the crooks to keep things under control and make a bad thing better"... isn't a valid excuse. Who knew?

☐ β˜† βœ‡ Naked Security

That didn’t last! Microsoft turns off the Office security it just turned on

By: Paul Ducklin β€” July 11th 2022 at 13:27
An Office anti-malware setting that took more than 20 years to arrive... and fewer than 20 weeks to vanish again.

☐ β˜† βœ‡ Naked Security

Apache β€œCommons Configuration” patches Log4Shell-style bug – what you need to know

By: Paul Ducklin β€” July 8th 2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.

☐ β˜† βœ‡ Naked Security

OpenSSL fixes two β€œone-liner” crypto bugs – what you need to know

By: Paul Ducklin β€” July 6th 2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...

❌