FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

S3 Ep124: When so-called security apps go rogue [Audio + Text]

By: Paul Ducklin β€” March 2nd 2023 at 15:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

s3-ep124-auth--1200

☐ β˜† βœ‡ Naked Security

LastPass: Keylogger on home PC led to cracked corporate password vault

By: Paul Ducklin β€” February 28th 2023 at 02:23
Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.

☐ β˜† βœ‡ Naked Security

Dutch police arrest three cyberextortion suspects who allegedly earned millions

By: Naked Security writer β€” February 27th 2023 at 17:33
Ever paid hush money to crooks who broke into your network? Wondered how much you can trust them?

☐ β˜† βœ‡ Naked Security

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!

By: Paul Ducklin β€” February 27th 2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

☐ β˜† βœ‡ Naked Security

S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]

By: Paul Ducklin β€” February 23rd 2023 at 17:58
Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

☐ β˜† βœ‡ Naked Security

NPM JavaScript packages abused to create scambait links in bulk

By: Paul Ducklin β€” February 22nd 2023 at 18:59
Free spins? Bonus game points? Cheap social media followers? What harm could it possibly do if you just take a tiny little look?!

☐ β˜† βœ‡ Naked Security

Coinbase breached by social engineers, employee data stolen

By: Paul Ducklin β€” February 21st 2023 at 17:58
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

☐ β˜† βœ‡ Naked Security

Twitter tells users: Pay up if you want to keep using insecure 2FA

By: Paul Ducklin β€” February 20th 2023 at 17:58
Ironically, Twitter Blue users will be allowed to keep using the very 2FA process that's not considered secure enough for everyone else.

☐ β˜† βœ‡ Naked Security

GoDaddy admits: Crooks hit us with malware, poisoned customer websites

By: Paul Ducklin β€” February 20th 2023 at 01:36
New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.

☐ β˜† βœ‡ Naked Security

S3 Ep122: Stop calling every breach β€œsophisticated”! [Audio + Text]

By: Paul Ducklin β€” February 16th 2023 at 17:46
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Microsoft Patch Tuesday: 36 RCE bugs, 3 zero-days, 75 CVEs

By: Paul Ducklin β€” February 14th 2023 at 22:12
Lots of lovely patches for your Valentine's Day delight. Get 'em as soon as you can...

☐ β˜† βœ‡ Naked Security

Apple fixes zero-day spyware implant bug – patch now!

By: Paul Ducklin β€” February 14th 2023 at 13:08
Everyone update now! Except for those who don't need to! Or who need to but will only get updates later on, though Apple isn't saying yet!

☐ β˜† βœ‡ Naked Security

Serious Security: GnuTLS follows OpenSSL, fixes timing attack bug

By: Paul Ducklin β€” February 13th 2023 at 17:59
Conditional code considered cryptographically counterproductive.

☐ β˜† βœ‡ Naked Security

Reddit admits it was hacked and data stolen, says β€œDon’t panic”

By: Paul Ducklin β€” February 10th 2023 at 17:59
Reddit is suggesting three tips as a follow-up to this breach. We agree with two of them but not with the third...

☐ β˜† βœ‡ Naked Security

OpenSSL fixes High Severity data-stealing bug – patch now!

By: Paul Ducklin β€” February 8th 2023 at 02:58
7 memory mismanagements and a timing attack. We explain all the jargon bug terminology in plain English...

☐ β˜† βœ‡ Naked Security

VMWare user? Worried about β€œESXi ransomware”? Check your patches now!

By: Paul Ducklin β€” February 7th 2023 at 17:59
To borrow from HHGttG, please DON'T PANIC. But if you are two years out of date with patches, please do ACT NOW!

☐ β˜† βœ‡ Naked Security

Tracers in the Dark: The Global Hunt for the Crime Lords of Crypto

By: Paul Ducklin β€” February 6th 2023 at 17:53
Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...

☐ β˜† βœ‡ Naked Security

Finnish psychotherapy extortion suspect arrested in France

By: Naked Security writer β€” February 6th 2023 at 16:13
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

☐ β˜† βœ‡ Naked Security

OpenSSH fixes double-free memory bug that’s pokable over the network

By: Paul Ducklin β€” February 3rd 2023 at 17:59
It's a bug fix for a bug fix. A memory leak was turned into a double-free that has now been turned into correct code...

☐ β˜† βœ‡ Naked Security

S3 Ep120: When dud crypto simply won’t let go [Audio + Text]

By: Paul Ducklin β€” February 2nd 2023 at 17:50
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By: Paul Ducklin β€” February 1st 2023 at 18:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By: Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

Serious Security: The Samba logon bug caused by outdated crypto

By: Paul Ducklin β€” January 30th 2023 at 17:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

☐ β˜† βœ‡ Naked Security

Hive ransomware servers shut down at last, says FBI

By: Naked Security writer β€” January 27th 2023 at 17:58
Unfortunately, you've probably already heard the cliche that "cybercrime abhors a vacuum"...

☐ β˜† βœ‡ Naked Security

Dutch suspect locked up for alleged personal data megathefts

By: Paul Ducklin β€” January 26th 2023 at 22:02
Undercover Austrian "controlled data buy" leads to Amsterdam arrest and ongoing investigation. Suspect is said to steal and sell all sorts of data, including medical records.

☐ β˜† βœ‡ Naked Security

S3 Ep119: Breaches, patches, leaks and tweaks! [Audio + Text]

By: Paul Ducklin β€” January 26th 2023 at 15:57
Lastest episode - listen now! (Or read the transcript.)

☐ β˜† βœ‡ Naked Security

GoTo admits: Customer cloud backups stolen together with decryption key

By: Paul Ducklin β€” January 25th 2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

☐ β˜† βœ‡ Naked Security

Apple patches are out – old iPhones get an old zero-day fix at last!

By: Paul Ducklin β€” January 24th 2023 at 01:24
Don't delay, especially if you're still running an iOS 12 device... please do it today!

☐ β˜† βœ‡ Naked Security

Serious Security: How dEliBeRaTe tYpOs might imProVe DNS security

By: Paul Ducklin β€” January 23rd 2023 at 17:59
It's a really cool and super-simple trick. The question is, "Will it help?"

☐ β˜† βœ‡ Naked Security

T-Mobile admits to 37,000,000 customer records stolen by β€œbad actor”

By: Paul Ducklin β€” January 20th 2023 at 17:59
Once more, it's time for Shakespeare's words: Once more unto the breach...

☐ β˜† βœ‡ Naked Security

S3 Ep118: Guess your password? No need if it’s stolen already! [Audio + Text]

By: Paul Ducklin β€” January 19th 2023 at 15:53
As always: entertaining, informative and educational... and not bogged down with jargon! Listen (or read) now...

☐ β˜† βœ‡ Naked Security

Serious Security: Unravelling the LifeLock β€œhacked passwords” story

By: Paul Ducklin β€” January 17th 2023 at 17:59
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.

☐ β˜† βœ‡ Naked Security

Multi-million investment scammers busted in four-country Europol raid

By: Paul Ducklin β€” January 16th 2023 at 16:10
216 questioned, 15 arrested, 4 fake call centres searched, millions seized...

☐ β˜† βœ‡ Naked Security

S3 Ep117: The crypto crisis that wasn’t (and farewell forever to Win 7) [Audio + Text]

By: Paul Ducklin β€” January 12th 2023 at 17:59
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)

☐ β˜† βœ‡ Naked Security

Microsoft Patch Tuesday: One 0-day; Win 7 and 8.1 get last-ever patches

By: Paul Ducklin β€” January 11th 2023 at 00:22
Get 'em while they're hot. And get 'em for the very last time, if you still have Windows 7 or 8.1...

☐ β˜† βœ‡ Naked Security

Popular JWT cloud security library patches β€œremote” code execution hole

By: Paul Ducklin β€” January 10th 2023 at 17:59
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.

☐ β˜† βœ‡ Naked Security

CircleCI – code-building service suffers total credential compromise

By: Paul Ducklin β€” January 9th 2023 at 14:52
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

☐ β˜† βœ‡ Naked Security

RSA crypto cracked? Or perhaps not!

By: Paul Ducklin β€” January 6th 2023 at 17:59
Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?

☐ β˜† βœ‡ Naked Security

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]

By: Paul Ducklin β€” January 5th 2023 at 17:52
Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

By: Paul Ducklin β€” January 4th 2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

☐ β˜† βœ‡ Naked Security

Inside a scammers’ lair: Ukraine busts 40 in fake bank call-centre raid

By: Naked Security writer β€” January 3rd 2023 at 17:03
When someone calls you up to warn you that your bank account is under attack - it's true, because THAT VERY PERSON is the one attacking you!

☐ β˜† βœ‡ Naked Security

PyTorch: Machine Learning toolkit pwned from Christmas to New Year

By: Paul Ducklin β€” January 1st 2023 at 21:36
The bad news: the crooks have your SSH private keys. The good news: only users of the "nightly" build were affected.

☐ β˜† βœ‡ Naked Security

Naked Security 33Β 1/3 – Cybersecurity predictions for 2023 and beyond

By: Paul Ducklin β€” December 30th 2022 at 17:59
The problem with anniversaries is that there's an almost infinite number of them every day...

hny-1200

☐ β˜† βœ‡ Naked Security

The horror! The horror! NOTEPAD gets tabbed editing (very briefly)

By: Paul Ducklin β€” December 29th 2022 at 17:59
Is there a special meaning of "don't" that means "go right ahead"?

☐ β˜† βœ‡ Naked Security

US passes the Quantum Computing Cybersecurity Preparedness Act – and why not?

By: Paul Ducklin β€” December 29th 2022 at 13:45
Cryptographic agility: the ability and the willingness to change quickly when needed.

sc-daa-1200

☐ β˜† βœ‡ Naked Security

S3 Ep115: True crime stories – A day in the life of a cybercrime fighter [Audio + Text]

By: Paul Ducklin β€” December 29th 2022 at 09:20
Listen now - you'll be alarmed, amused and educated, all in equal measure. (Full transcript in article.)

☐ β˜† βœ‡ Naked Security

Twitter data of β€œ+400 million unique users” up for sale – what to do?

By: Paul Ducklin β€” December 28th 2022 at 17:59
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?

☐ β˜† βœ‡ Naked Security

Critical β€œ10-out-of-10” Linux kernel SMB hole – should you worry?

By: Paul Ducklin β€” December 27th 2022 at 18:00
It's serious, it's critical, and you could call it severe... but in HHGttG terminology, it's probably "mostly harmless".

☐ β˜† βœ‡ Naked Security

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all…

By: Paul Ducklin β€” December 23rd 2022 at 17:58
The crooks now know who you are, where you live, which computers are yours, where you go online... and they got those password vaults, too.

☐ β˜† βœ‡ Naked Security

S3 Ep114: Preventing cyberthreats – stop them before they stop you! [Audio + Text]

By: Paul Ducklin β€” December 22nd 2022 at 17:56
Join world-renowned expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode on how to fight cybercrime.

☐ β˜† βœ‡ Naked Security

β€œSuspicious login” scammers up their game – take care at Christmas

By: Paul Ducklin β€” December 21st 2022 at 17:59
A picture is worth 1024 words - we clicked through so you don't have to.

☐ β˜† βœ‡ Naked Security

Microsoft dishes the dirt on Apple’s β€œAchilles heel” shortly after fixing similar Windows bug

By: Paul Ducklin β€” December 20th 2022 at 17:59
It happens to the best of us: Microsoft highlights a security bypass bug on Macs that is curiously similar to a recent Windows 0-day.

☐ β˜† βœ‡ Naked Security

OneCoin scammer Sebastian Greenwood pleads guilty, β€œCryptoqueen” still missing

By: Paul Ducklin β€” December 19th 2022 at 17:50
The Cryptoqueen herself is still missing, but her co-conspirator, who is said to have pocketed over $20m a month, has been convicted.

☐ β˜† βœ‡ Naked Security

S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text]

By: Paul Ducklin β€” December 15th 2022 at 17:10
Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!

☐ β˜† βœ‡ Naked Security

Apple patches everything, finally reveals mystery of iOS 16.1.2

By: Paul Ducklin β€” December 14th 2022 at 02:11
There's an update for everything this time, not just for iOS.

☐ β˜† βœ‡ Naked Security

Patch Tuesday: 0-days, RCE bugs, and a curious tale of signed malware

By: Paul Ducklin β€” December 14th 2022 at 01:13
Tales of derring-do in the cyberunderground! (And some zero-days.)

☐ β˜† βœ‡ Naked Security

COVID-bit: the wireless spyware trick with an unfortunate name

By: Paul Ducklin β€” December 13th 2022 at 17:58
It's not the switching that's the problem, it's the switching of the switching!

ind-1200

☐ β˜† βœ‡ Naked Security

Pwn2Own Toronto: 54 hacks, 63 new bugs, $1 million in bounties

By: Paul Ducklin β€” December 12th 2022 at 17:58
That's a mean average of $15,710 per bug... and 63 fewer bugs out there for crooks and rogues to find.

☐ β˜† βœ‡ Naked Security

S3 Ep112: Data breaches can haunt you more than once! [Audio + Text]

By: Paul Ducklin β€” December 9th 2022 at 16:46
Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

❌