FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

S3 Ep136: Navigating a manic malware maelstrom

By: Paul Ducklin β€” May 25th 2023 at 16:50
Latest episode - listen now. Full transcript inside...

☐ β˜† βœ‡ Naked Security

Ransomware tales: The MitM attack that really had a Man in the Middle

By: Paul Ducklin β€” May 24th 2023 at 17:59
Another traitorous sysadmin story, this one busted by system logs that gave his game away...

☐ β˜† βœ‡ Naked Security

PyPI open-source code repository deals with manic malware maelstrom

By: Paul Ducklin β€” May 23rd 2023 at 16:45
Controlled outage used to keep malware marauders from gumming up the works. Learn what you can do to help in future...

☐ β˜† βœ‡ Naked Security

Phone scamming kingpin gets 13 years for running β€œiSpoof” service

By: Naked Security writer β€” May 22nd 2023 at 16:58
Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

ispoof-1200

☐ β˜† βœ‡ Naked Security

Apple’s secret is out: 3 zero-days fixed, so be sure to patch now!

By: Paul Ducklin β€” May 19th 2023 at 01:02
All Apple users have zero-days that need patching, though some have more zero-days than others.

☐ β˜† βœ‡ Naked Security

S3 Ep135: Sysadmin by day, extortionist by night

By: Paul Ducklin β€” May 18th 2023 at 16:48
Laugh (sufficiently), learn (efficiently), and then let us know what you think in our comments (anonymously, if you wish)...

☐ β˜† βœ‡ Naked Security

US offers $10m bounty for Russian ransomware suspect outed in indictment

By: Naked Security writer β€” May 17th 2023 at 16:40
"Up to $10 million for information that leads to the arrest and/or conviction of this defendant."

☐ β˜† βœ‡ Naked Security

Belkin Wemo Smart Plug V2 – the buffer overflow that won’t be patched

By: Paul Ducklin β€” May 16th 2023 at 17:59
Yes, it's a buffer overflow bug. No, it's not going get fixed.

☐ β˜† βœ‡ Naked Security

Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France

By: Paul Ducklin β€” May 15th 2023 at 16:36
We asked you once, we told you twice, now we're ordering you for the third time...

☐ β˜† βœ‡ Naked Security

Whodunnit? Cybercrook gets 6 years for ransoming his own employer

By: Naked Security writer β€” May 12th 2023 at 16:15
Not just an active adversary, but a two-faced one, too.

☐ β˜† βœ‡ Naked Security

S3 Ep134: It’s a PRIVATE key – the hint is in the name!

By: Paul Ducklin β€” May 11th 2023 at 14:54
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Bootkit zero-day fix – is this Microsoft’s most cautious patch ever?

By: Paul Ducklin β€” May 10th 2023 at 11:50
When blocking buggy bootup modules, you have to be really careful not to lock your keys inside the car...

☐ β˜† βœ‡ Naked Security

Low-level motherboard security keys leaked in MSI breach, claim researchers

By: Paul Ducklin β€” May 9th 2023 at 16:58
What can you do if someone steals your keys but you can't change the lock? We explain the dilemma in plain English.

☐ β˜† βœ‡ Naked Security

PHP Packagist supply chain poisoned by hacker β€œlooking for a job”

By: Paul Ducklin β€” May 5th 2023 at 16:59
I pwned you! Gizza job! You know it makes sense!

☐ β˜† βœ‡ Naked Security

S3 Ep133: Apple takes β€œtight-lipped” to a whole new level

By: Paul Ducklin β€” May 4th 2023 at 20:59
Entertaining, educational, and all in plain English πŸŽ§πŸ“–

☐ β˜† βœ‡ Naked Security

World Password Day: 2 + 2 = 4

By: Paul Ducklin β€” May 4th 2023 at 13:12
We've kept it short and simple, with no sermons, no judgmentalism, no tubthumping... and no BUY NOW buttons. Have a nice day!

☐ β˜† βœ‡ Naked Security

Tracked by hidden tags? Apple and Google unite to propose safety and security standards…

By: Paul Ducklin β€” May 3rd 2023 at 19:58
To bleat, or not to bleat, that is the question.

☐ β˜† βœ‡ Naked Security

Apple delivers first-ever Rapid Security Response β€œcyberattack” patch – leaves some users confused

By: Paul Ducklin β€” May 1st 2023 at 20:46
Just when we'd got used to three-numbered versions, such as "13.3.1", here comes an update suffix, bringing you "13.3.1 (a)"...

☐ β˜† βœ‡ Naked Security

Mac malware-for-hire steals passwords and cryptocoins, sends β€œcrime logs” via Telegram

By: Paul Ducklin β€” April 30th 2023 at 01:23
These malware peddlers are specifically going after Mac users. The hint's in the name: "Atomic macOS Stealer", or AMOS for short.

☐ β˜† βœ‡ Naked Security

Google wins court order to force ISPs to filter botnet traffic

By: Naked Security writer β€” April 28th 2023 at 19:59
CryptBot criminals are alleged to have plundered browser passwords, illicitly-snapped screenshots, cryptocurrency account data, and more.

☐ β˜† βœ‡ Naked Security

S3 Ep132: Proof-of-concept lets anyone hack at will

By: Paul Ducklin β€” April 27th 2023 at 16:55
When Doug says, "Happy Remote Code Execution Day, Duck"... it's irony. For the avoidance of all doubt :-)

☐ β˜† βœ‡ Naked Security

Google leaking 2FA secrets – researchers advise against new β€œaccount sync” feature for now

By: Paul Ducklin β€” April 26th 2023 at 17:59
You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...

☐ β˜† βœ‡ Naked Security

PaperCut security vulnerabilities under active attack – vendor urges customers to patch

By: Paul Ducklin β€” April 25th 2023 at 17:53
If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...

☐ β˜† βœ‡ Naked Security

Double zero-day in Chrome and Edge – check your versions now!

By: Paul Ducklin β€” April 24th 2023 at 16:59
Wouldn't it be handy if there were a single version number to check for in every Chromium-based browser, on every supported platform?

☐ β˜† βœ‡ Naked Security

VMware patches break-and-enter hole in logging tools: update now!

By: Paul Ducklin β€” April 21st 2023 at 17:58
You know jolly well/What we're going to say/And that's "Do not delay/Simply do it today."

☐ β˜† βœ‡ Naked Security

S3 Ep131: Can you really have fun with FORTRAN?

By: Paul Ducklin β€” April 20th 2023 at 17:55
Loop-the-loop in this week's episode. Entertaining, educational and all in plain English. Transcript inside.

☐ β˜† βœ‡ Naked Security

Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security

By: Paul Ducklin β€” April 18th 2023 at 16:56
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

☐ β˜† βœ‡ Naked Security

FBI and FCC warn about β€œJuicejacking” – but just how useful is their advice?

By: Paul Ducklin β€” April 17th 2023 at 14:17
USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?

☐ β˜† βœ‡ Naked Security

S3 Ep130: Open the garage bay doors, HAL [Audio + Text]

By: Paul Ducklin β€” April 13th 2023 at 16:54
I'm sorry, Dave. I'm afraid I can't... errr, no, hang on a minute, I can do that easily! Worldwide! Right now!

☐ β˜† βœ‡ Naked Security

Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert

By: Paul Ducklin β€” April 11th 2023 at 16:58
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

☐ β˜† βœ‡ Naked Security

Apple zero-day spyware patches extended to cover older Macs, iPhones and iPads

By: Paul Ducklin β€” April 10th 2023 at 20:20
That double-whammy Apple browser-to-kernel spyware bug combo we wrote up last week? Turns out it applies to all supported Macs and iDevices - patch now!

☐ β˜† βœ‡ Naked Security

Popular server-side JavaScript security sandbox β€œvm2” patches remote execution hole

By: Paul Ducklin β€” April 9th 2023 at 00:28
The security error was in the error handling system that was supposed to catch potential security errors...

vm2-1200

☐ β˜† βœ‡ Naked Security

Apple issues emergency patches for spyware-style 0-day exploits – update now!

By: Paul Ducklin β€” April 8th 2023 at 01:20
A bug to hack your browser, then a bug to pwn the kernel... reported from the wild by Amnesty International.

☐ β˜† βœ‡ Naked Security

S3 Ep129: When spyware arrives from someone you trust

By: Paul Ducklin β€” April 6th 2023 at 14:57
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

☐ β˜† βœ‡ Naked Security

Hack and enter! The β€œsecure” garage doors that anyone can open from anywhere – what you need to know

By: Paul Ducklin β€” April 5th 2023 at 18:49
Grab a message/Play it back/You've just performed/A big phat hack...

☐ β˜† βœ‡ Naked Security

Einstein tilings – the amazing β€œHat” shape that never repeats!

By: Paul Ducklin β€” April 4th 2023 at 16:59
Imagine tiling a whole football field using a single shape... yet not being able to produce a repeating pattern, even if you wanted to.

☐ β˜† βœ‡ Naked Security

Researchers claim they can bypass Wi-Fi encryption (briefly, at least)

By: Paul Ducklin β€” April 3rd 2023 at 16:59
They can't read much of your data, but even a few stray network packets could tell them something they're not supposed to know.

☐ β˜† βœ‡ Naked Security

World Backup Day is here again – 5 tips to keep your precious data safe

By: Paul Ducklin β€” March 31st 2023 at 01:14
The only backup you will ever regret is the one you didn't make...

☐ β˜† βœ‡ Naked Security

Supply chain blunder puts 3CX telephone app users at risk

By: Paul Ducklin β€” March 30th 2023 at 17:36
Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

☐ β˜† βœ‡ Naked Security

S3 Ep128: So you want to be a cyberΒ­criminal? [Audio + Text]

By: Paul Ducklin β€” March 30th 2023 at 14:43
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Cops use fake DDoS services to take aim at wannabe cybercriminals

By: Naked Security writer β€” March 28th 2023 at 16:58
Thinking of trying a bit of DDoSsing to get a feel for life at the fringes of the Dark Side? Don't do it!

☐ β˜† βœ‡ Naked Security

Apple patches everything, including a zero-day fix for iOS 15 users

By: Paul Ducklin β€” March 28th 2023 at 00:23
Got an older iPhone that can't run iOS 16? You've got a zero-day to deal with! That super-cool Studio Display monitor needs patching, too.

☐ β˜† βœ‡ Naked Security

Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

By: Paul Ducklin β€” March 27th 2023 at 16:59
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

☐ β˜† βœ‡ Naked Security

In Memoriam – Gordon Moore, who put the more in β€œMoore’s Law”

By: Paul Ducklin β€” March 27th 2023 at 00:05
His prediction was called a "Law", though it was an exhortation to engineering excellence as much it was an estimate.

gm-rip-1200

☐ β˜† βœ‡ Naked Security

WooCommerce Payments plugin for WordPress has an admin-level hole – patch now!

By: Paul Ducklin β€” March 24th 2023 at 17:48
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

woo-1200

☐ β˜† βœ‡ Naked Security

S3 Ep127: When you chop someone out of a photo, but there they are anyway…

By: Paul Ducklin β€” March 23rd 2023 at 17:59
Listen now - latest episode. Full transcript inside.

☐ β˜† βœ‡ Naked Security

Windows 11 also vulnerable to β€œaCropalypse” image data leakage

By: Paul Ducklin β€” March 22nd 2023 at 17:59
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

☐ β˜† βœ‡ Naked Security

Google Pixel phones had a serious data leakage bug – here’s what to do!

By: Paul Ducklin β€” March 21st 2023 at 17:58
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

☐ β˜† βœ‡ Naked Security

Bitcoin ATM customers hacked by video upload that was actually an app

By: Paul Ducklin β€” March 20th 2023 at 17:50
As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...

☐ β˜† βœ‡ Naked Security

Dangerous Android phone 0-day bugs revealed – patch or work around them now!

By: Paul Ducklin β€” March 17th 2023 at 17:56
Despite its usually inflexible 0-day disclosure policy, Google is keeping four mobile modem bugs semi-secret due to likely ease of exploitation.

☐ β˜† βœ‡ Naked Security

S3 Ep 126: The price of fast fashion (and feature creep) [Audio + Text]

By: Paul Ducklin β€” March 16th 2023 at 17:56
Worried about rogue apps? Unsure about the new Outlook zero-day? Clear advice in plain English... just like old times, with Duck and Chet!

☐ β˜† βœ‡ Naked Security

Microsoft fixes two 0-days on Patch Tuesday – update now!

By: Paul Ducklin β€” March 15th 2023 at 00:06
An email you haven't even looked at yet could be used to trick Outlook into helping crooks to logon as you.

☐ β˜† βœ‡ Naked Security

Firefox 111 patches 11 holes, but not 1 zero-day among them…

By: Paul Ducklin β€” March 14th 2023 at 17:16
In the game of cricket, 111 is an inauspicious number, but for Firefox, there doesn't seem to be much to worry about this month.

☐ β˜† βœ‡ Naked Security

Linux gets double-quick double-update to fix kernel Oops!

By: Paul Ducklin β€” March 13th 2023 at 17:59
Linux doesn't BSoD. It has oopses and panics instead. (We show you how to make a kernel module to explore further.)

☐ β˜† βœ‡ Naked Security

SHEIN shopping app goes rogue, grabs price and URL data from your clipboard

By: Paul Ducklin β€” March 10th 2023 at 17:58
It's not exactly data theft, but it's worryingly close to "unintentional treachery" - apparently because it's great for marketing purposes

☐ β˜† βœ‡ Naked Security

S3 Ep125: When security hardware has security holes [Audio + Text]

By: Paul Ducklin β€” March 9th 2023 at 18:58
Lastest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Serious Security: TPM 2.0 vulns – is your super-secure data at risk?

By: Paul Ducklin β€” March 7th 2023 at 17:59
Security bugs in the very code you've been told you must have to improve the security of your computer...

☐ β˜† βœ‡ Naked Security

DoppelPaymer ransomware supsects arrested in Germany and Ukraine

By: Naked Security writer β€” March 6th 2023 at 16:16
Devices seized, suspects interrogated and arrested, allegedly connected to devastating cyberattack on University Hospital in DΓΌsseldorf.

☐ β˜† βœ‡ Naked Security

Feds warn about right Royal ransomware rampage that runs the gamut of TTPs

By: Paul Ducklin β€” March 3rd 2023 at 17:56
Wondering which cybercrime tools, techniques and procedures to focus on? How about any and all of them?

❌