FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

Credit card skimming – the long and winding road of supply chain failure

By: Paul Ducklin β€” December 8th 2022 at 17:58
Don't keep calling home to a JavaScript server that closed its doors eight years ago!

☐ β˜† βœ‡ Naked Security

SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m

By: Naked Security writer β€” December 6th 2022 at 17:56
Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.

☐ β˜† βœ‡ Naked Security

Ping of death! FreeBSD fixes crashtastic bug in network tool

By: Paul Ducklin β€” December 5th 2022 at 17:59
It's a venerable program, and this version had a venerable bug in it.

☐ β˜† βœ‡ Naked Security

Number Nine! Chrome fixes another 2022 zero-day, Edge patched too

By: Paul Ducklin β€” December 5th 2022 at 00:58
Ninth more unto the breach, dear friends, ninth more.

☐ β˜† βœ‡ Naked Security

Apple pushes out iOS security update that’s more tight-lipped than ever

By: Paul Ducklin β€” December 2nd 2022 at 21:02
We grabbed the update, based on no information at all, just in case we came across a reason to advise you not to. So far, so good...

☐ β˜† βœ‡ Naked Security

LastPass admits to customer data breach caused by previous breach

By: Paul Ducklin β€” December 2nd 2022 at 01:10
Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.

☐ β˜† βœ‡ Naked Security

S3 Ep111: The business risk of a sleazy β€œnudity unfilter” [Audio + Text]

By: Paul Ducklin β€” December 1st 2022 at 17:58
Latest episode - listen now (or read if you prefer)...

☐ β˜† βœ‡ Naked Security

The CHRISTMA EXEC network worm – 35 years and counting!

By: Paul Ducklin β€” December 1st 2022 at 20:35
"Uh-oh, this viruses-and-worms scene could turn out quite troublesome." If only we'd been wrong...

xmas-1200-35-wide

☐ β˜† βœ‡ Naked Security

Serious Security: MD5 considered harmful – to the tune of $600,000

By: Paul Ducklin β€” November 30th 2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!

☐ β˜† βœ‡ Naked Security

TikTok β€œInvisible Challenge” porn malware puts us all at risk

By: Paul Ducklin β€” November 29th 2022 at 17:58
An injury to one is an injury to all. Especially if the other people are part of your social network.

☐ β˜† βœ‡ Naked Security

Chrome fixes 8th zero-day of 2022 – check your version now (Edge too!)

By: Paul Ducklin β€” November 28th 2022 at 19:42
There isn't a rhyme to remind you which months have browser zero-days... you just have to keep your eyes and ears open!

☐ β˜† βœ‡ Naked Security

Voice-scamming site β€œiSpoof” seized, 100s arrested in massive crackdown

By: Naked Security writer β€” November 25th 2022 at 17:17
Those numbers or names that pop up when a call comes up? They're OK as a hint of who's calling, but THEY PROVE NOTHING

☐ β˜† βœ‡ Naked Security

S3 Ep110: Spotlight on cyberthreats – an expert speaks [Audio + Text]

By: Paul Ducklin β€” November 24th 2022 at 16:52
Latest episode - security expert John Shier explains what the real-life cybercrime stories in the Sophos Threat Report can teach us

☐ β˜† βœ‡ Naked Security

Multimillion dollar CryptoRom scam sites seized, suspects arrested in US

By: Paul Ducklin β€” November 23rd 2022 at 19:58
Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...

cryptorom-1200

☐ β˜† βœ‡ Naked Security

How to hack an unpatched Exchange server with rogue PowerShell code

By: Paul Ducklin β€” November 22nd 2022 at 17:54
Review your servers, your patches and your authentication policies - there's a proof-of-concept out

☐ β˜† βœ‡ Naked Security

How social media scammers buy time to steal your 2FA codes

By: Paul Ducklin β€” November 21st 2022 at 17:02
The warning is hosted on a real Facebook page; the phishing uses HTTPS via a real Google server... but the content is all fake

ffs-2fa-1200

☐ β˜† βœ‡ Naked Security

S3 Ep109: How one leaked email password could drain your business [Audio + Transcript]

By: Paul Ducklin β€” November 17th 2022 at 17:52
Latest episode - listen now! Cybersecurity news plus loads of great advice...

☐ β˜† βœ‡ Naked Security

Black Friday and retail season – watch out for PayPal β€œmoney request” scams

By: Paul Ducklin β€” November 17th 2022 at 12:45
Don't let a keen eye for bargains lead you into risky online behaviour...

☐ β˜† βœ‡ Naked Security

Firefox fixes fullscreen fakery flaw – get the update now!

By: Paul Ducklin β€” November 16th 2022 at 17:51
What's so bad about a web page going fullscreen without warning you first?

☐ β˜† βœ‡ Naked Security

Log4Shell-like code execution hole in popular Backstage dev tool

By: Paul Ducklin β€” November 15th 2022 at 17:49
Good old "string templating", also known as "string interpolation", in the spotlight again...

bs-1200

☐ β˜† βœ‡ Naked Security

β€œGucci Master” business email scammer Hushpuppi gets 11 years

By: Naked Security writer β€” November 14th 2022 at 16:24
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...

puppi-car-1200

☐ β˜† βœ‡ Naked Security

Dangerous SIM-swap lockscreen bypass – update Android now!

By: Paul Ducklin β€” November 11th 2022 at 17:59
A bit like leaving the front door keys under the doormat...

☐ β˜† βœ‡ Naked Security

S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?

By: Paul Ducklin β€” November 10th 2022 at 17:26
Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!

☐ β˜† βœ‡ Naked Security

Emergency code execution patch from Apple – but not an 0-day

By: Paul Ducklin β€” November 10th 2022 at 01:49
Not a zero-day, but important enough for a quick-fire patch to one system library...

☐ β˜† βœ‡ Naked Security

Exchange 0-days fixed (at last) – plus 4 brand new Patch Tuesday 0-days!

By: Paul Ducklin β€” November 9th 2022 at 17:58
In all the excitement, we kind of lost track ourselves. Were there six 0-days, or only four?

☐ β˜† βœ‡ Naked Security

Silk Road drugs market hacker pleads guilty, faces 20 years inside

By: Paul Ducklin β€” November 8th 2022 at 17:58
Jurisprudence isn't like arithmetic... two negatives never make a positive!

☐ β˜† βœ‡ Naked Security

Public URL scanning tools – when security leads to insecurity

By: Paul Ducklin β€” November 7th 2022 at 17:59
Never make your users cry/By how you use an API

☐ β˜† βœ‡ Naked Security

Twitter Blue Badge email scams – Don’t fall for them!

By: Naked Security writer β€” November 4th 2022 at 17:59
That was the week that was...

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By: Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

The OpenSSL security update story – how can you tell what needs fixing?

By: Paul Ducklin β€” November 3rd 2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...

ossl-code-1200

☐ β˜† βœ‡ Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

By: Paul Ducklin β€” November 1st 2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

☐ β˜† βœ‡ Naked Security

SHA-3 code execution bug patched in PHP – check your version!

By: Paul Ducklin β€” November 1st 2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

☐ β˜† βœ‡ Naked Security

Psychotherapy extortion suspect: arrest warrant issued

By: Paul Ducklin β€” October 31st 2022 at 17:59
Wanted! Not only the extortionist who abused the data, but also the CEO who let it happen.

☐ β˜† βœ‡ Naked Security

Chrome issues urgent zero-day fix – update now!

By: Paul Ducklin β€” October 29th 2022 at 15:08
We've said it before/And we'll say it again/It's not *if* you should patch/It's a matter of *when*. (Hint: now!)

☐ β˜† βœ‡ Naked Security

Updates to Apple’s zero-day update story – iPhone and iPad users read this!

By: Paul Ducklin β€” October 28th 2022 at 12:04
Turns out that Tuesday's zero-day for iOS 16 is Friday's zero-day for iOS 15...

☐ β˜† βœ‡ Naked Security

S3 Ep106: Facial recognition without consent – should it be banned?

By: Paul Ducklin β€” October 27th 2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!

☐ β˜† βœ‡ Naked Security

Online ticketing company β€œSee” pwned for 2.5 years by attackers

By: Paul Ducklin β€” October 26th 2022 at 16:58
Don't be a cybersecurity slowcoach - you need to spot possible attacks as soon as you can.

☐ β˜† βœ‡ Naked Security

Clearview AI image-scraping face recognition service hit with €20m fine in France

By: Paul Ducklin β€” October 26th 2022 at 00:50
"We told you to stop but you ignored us," said the French regulator, "so now we're coming after you again."

☐ β˜† βœ‡ Naked Security

Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!

By: Paul Ducklin β€” October 25th 2022 at 18:03
Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

☐ β˜† βœ‡ Naked Security

Serious Security: How randomly (or not) can you shuffle cards?

By: Paul Ducklin β€” October 24th 2022 at 18:57
What if you could guess the next card correctly twice as often as you should?

card-fan-1200

☐ β˜† βœ‡ Naked Security

When cops hack back: Dutch police fleece DEADBOLT criminals (legally!)

By: Paul Ducklin β€” October 21st 2022 at 16:25
Crooks: Show us the money! Cops: How about you show us the decryption keys first?

☐ β˜† βœ‡ Naked Security

S3 Ep105: WONTFIX! The MS Office cryptofail that β€œisn’t a security flaw” [Audio + Text]

By: Paul Ducklin β€” October 20th 2022 at 16:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!

pic-1200

☐ β˜† βœ‡ Naked Security

Women in Cryptology – USPS celebrates WW2 codebreakers

By: Paul Ducklin β€” October 19th 2022 at 16:58
What did you do in the war, Mom? Oh, y'know, a bit of this and that...

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches sneaky β€œspy-on-me” bug – update now!

By: Paul Ducklin β€” October 18th 2022 at 15:58
Hey! That back door isn't supposed to be there at all, let alone propped open...

☐ β˜† βœ‡ Naked Security

Dangerous hole in Apache Commons Text – like Log4Shell all over again

By: Paul Ducklin β€” October 18th 2022 at 16:26
Third time unlucky. Time to put your patching boots on again...

act-1200

☐ β˜† βœ‡ Naked Security

Fashion brand SHEIN fined $1.9m for lying about data breach

By: Naked Security writer β€” October 17th 2022 at 16:50
Is "pay a small fine and keep on trading" a sufficient penalty for letting a breach happen, impeding an investigation, and hiding the truth?

☐ β˜† βœ‡ Naked Security

Serious Security: Microsoft Office 365 attacked over feeble encryption

By: Paul Ducklin β€” October 14th 2022 at 16:59
How 2022 is your encryption?

☐ β˜† βœ‡ Naked Security

S3 Ep104: Should hospital ransomware attackers be locked up for life? [Audio + Text]

By: Paul Ducklin β€” October 13th 2022 at 16:37
Have your say on three deep questions posed by this week's podcast. Read or listen as suits you best...

☐ β˜† βœ‡ Naked Security

Patch Tuesday in brief – one 0-day fixed, but no patches for Exchange!

By: Paul Ducklin β€” October 12th 2022 at 16:58
There's a zero-day patch, but it's not for the zero-day you thought.

☐ β˜† βœ‡ Naked Security

Move over Patch Tuesday – it’s Ada Lovelace Day!

By: Paul Ducklin β€” October 11th 2022 at 15:22
Hacking on actual computers is one thing, but hacking purposefully on imaginary computers is, these days, something we can only imagine.

☐ β˜† βœ‡ Naked Security

Mystery iPhone update patches against iOS 16 mail crash-attack

By: Paul Ducklin β€” October 11th 2022 at 00:28
The problem with crashy messaging apps is that *other people* get to choose if and when to send you messages...

☐ β˜† βœ‡ Naked Security

Serious Security: OAuth 2 and why Microsoft is finally forcing you into it

By: Paul Ducklin β€” October 10th 2022 at 14:02
Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.

☐ β˜† βœ‡ Naked Security

WhatsApp goes after Chinese password scammers via US court

By: Paul Ducklin β€” October 7th 2022 at 16:14
If you can't beat 'em, sue 'em!

☐ β˜† βœ‡ Naked Security

S3 Ep103: Scammers in the Slammer (and other stories) [Audio + Text]

By: Paul Ducklin β€” October 6th 2022 at 14:43
Latest episode - listen and learn now (or read and revise, if the written word is your thing)...

☐ β˜† βœ‡ Naked Security

Former Uber CSO convicted of covering up megabreach back in 2016

By: Naked Security writer β€” October 6th 2022 at 01:04
Obstructed FTC proceedings, and concealed a crime, said the jury.

☐ β˜† βœ‡ Naked Security

NetWalker ransomware affiliate sentenced to 20 years by Florida court

By: Naked Security writer β€” October 5th 2022 at 16:55
Judge tells the accused that if he hadn't pleaded guilty, "I would have given you life."

☐ β˜† βœ‡ Naked Security

BEC fraudster and romance scammer sent to prison for 25 years

By: Paul Ducklin β€” October 4th 2022 at 19:12
Two years of scamming + $10 million leeched = 25 years in prison. Just in time for #Cybermonth.

rs-1200

☐ β˜† βœ‡ Naked Security

Scammers and rogue callers – can anything ever stop them?

By: Paul Ducklin β€” October 4th 2022 at 00:06
Some thoughts for Cybersecurity Awareness Month: Is is worth reporting nuisance calls? Is it even worth reporting outright scams?

☐ β˜† βœ‡ Naked Security

S3 Ep102.5: β€œProxyNotShell” Exchange bugs – an expert speaks [Audio + Text]

By: Paul Ducklin β€” October 1st 2022 at 14:05
Who's affected, what you can do while waiting for Microsoft's patches, and how to plan your threat hunting...

☐ β˜† βœ‡ Naked Security

URGENT! Microsoft Exchange double zero-day – β€œlike ProxyShell, only different”

By: Paul Ducklin β€” September 30th 2022 at 13:25
Double-play 0-day in Exchange - what you need to know, and what you can do

❌