Login
FreshRSS
Login
Secure Planet Training Courses Updated For 2019 - Click Here
Main stream
Favourites (0)
My labels
Security
/r/netsec - Information Security News & Discussion
Dark Reading:
ICS-CERT Alert Feed
InfoSec Resources
Infosec Island Latest Articles
Krebs on Security
McAfee Blogs
Naked Security
News β Packet Storm
Paul's Security Weekly
SANS Internet Storm Center, InfoCON: green
Security β Cisco Blog
SecurityFocus News
The Hacker News
The Register - Security
The first stop for security news | Threatpost
Threatpost | The first stop for security news
Troy Hunt
Verisign Blog
WIRED
WeLiveSecurity
ZDNet | security RSS
http://blog.trendmicro.com/feed
Tools
KitPloit - PenTest Tools!
Security Tool Files β Packet Storm
ToolsWatch.org β The Hackers Arsenal Tools Portal
Vulnerabilities
Advisory Files β Packet Storm
Exploit-DB Updates
Full Disclosure
SecurityFocus Vulnerabilities
There are new available articles, click to refresh the page.
Naked Security
Smart light bulbs could give away your password secrets
By:
Paul Ducklin
β August 22
nd
2023 at 17:56
Cryptography isn't just about secrecy. You need to take care of authenticity (no imposters!) and integrity (no tampering!) as well.
Naked Security
S3 Ep147: What if you type in your password during a meeting?
By:
Paul Ducklin
β August 10
th
2023 at 13:34
Latest episode - listen now! (Full transcript inside.)
Naked Security
S3 Ep145: Bugs With Impressive Names!
By:
Paul Ducklin
β July 27
th
2023 at 16:47
Fascinating fun (with a serious and educational side) - listen now! Full transcript available inside.
Naked Security
Hacking police radios: 30-year-old crypto flaws in the spotlight
By:
Paul Ducklin
β July 24
th
2023 at 16:59
"Three may keep a secret, if two of them are dead."
Naked Security
Microsoft hit by Storm season β a tale of two semi-zero days
By:
Paul Ducklin
β July 18
th
2023 at 16:59
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...
Naked Security
S3 Ep137: 16th century crypto skullduggery
By:
Paul Ducklin
β June 1
st
2023 at 16:45
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)
s3-ep137-feat-1200
Naked Security
S3 Ep125: When security hardware has security holes [Audio + Text]
By:
Paul Ducklin
β March 9
th
2023 at 18:58
Lastest episode - listen now! (Full transcript inside.)
Naked Security
Serious Security: TPM 2.0 vulns β is your super-secure data at risk?
By:
Paul Ducklin
β March 7
th
2023 at 17:59
Security bugs in the very code you've been told you must have to improve the security of your computer...
Naked Security
DoppelPaymer ransomware supsects arrested in Germany and Ukraine
By:
Naked Security writer
β March 6
th
2023 at 16:16
Devices seized, suspects interrogated and arrested, allegedly connected to devastating cyberattack on University Hospital in DΓΌsseldorf.
Naked Security
S3 Ep124: When so-called security apps go rogue [Audio + Text]
By:
Paul Ducklin
β March 2
nd
2023 at 15:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!
s3-ep124-auth--1200
Naked Security
Beware rogue 2FA apps in App Store and Google Play β donβt get hacked!
By:
Paul Ducklin
β February 27
th
2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)
Naked Security
Serious Security: GnuTLS follows OpenSSL, fixes timing attack bug
By:
Paul Ducklin
β February 13
th
2023 at 17:59
Conditional code considered cryptographically counterproductive.
Naked Security
OpenSSL fixes High Severity data-stealing bug β patch now!
By:
Paul Ducklin
β February 8
th
2023 at 02:58
7 memory mismanagements and a timing attack. We explain all the jargon bug terminology in plain English...
Naked Security
Tracers in the Dark: The Global Hunt for the Crime Lords of Crypto
By:
Paul Ducklin
β February 6
th
2023 at 17:53
Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...
Naked Security
S3 Ep120: When dud crypto simply wonβt let go [Audio + Text]
By:
Paul Ducklin
β February 2
nd
2023 at 17:50
Latest episode - listen now!
Naked Security
Password-stealing βvulnerabilityβ reported in KeePass β bug or feature?
By:
Paul Ducklin
β February 1
st
2023 at 18:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?
Naked Security
Serious Security: The Samba logon bug caused by outdated crypto
By:
Paul Ducklin
β January 30
th
2023 at 17:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!
Naked Security
GoTo admits: Customer cloud backups stolen together with decryption key
By:
Paul Ducklin
β January 25
th
2023 at 01:37
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.
Naked Security
Serious Security: Unravelling the LifeLock βhacked passwordsβ story
By:
Paul Ducklin
β January 17
th
2023 at 17:59
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.
Naked Security
S3 Ep117: The crypto crisis that wasnβt (and farewell forever to Win 7) [Audio + Text]
By:
Paul Ducklin
β January 12
th
2023 at 17:59
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)
Naked Security
Popular JWT cloud security library patches βremoteβ code execution hole
By:
Paul Ducklin
β January 10
th
2023 at 17:59
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.
Naked Security
RSA crypto cracked? Or perhaps not!
By:
Paul Ducklin
β January 6
th
2023 at 17:59
Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?
Naked Security
S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]
By:
Paul Ducklin
β January 5
th
2023 at 17:52
Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)
Naked Security
Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches
By:
Paul Ducklin
β January 4
th
2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.
Naked Security
US passes the Quantum Computing Cybersecurity Preparedness Act β and why not?
By:
Paul Ducklin
β December 29
th
2022 at 13:45
Cryptographic agility: the ability and the willingness to change quickly when needed.
sc-daa-1200
Naked Security
Serious Security: MD5 considered harmful β to the tune of $600,000
By:
Paul Ducklin
β November 30
th
2022 at 17:58
It's not just the hashing, by the way. It's the salting and the stretching, too!
Naked Security
The OpenSSL security update story β how can you tell what needs fixing?
By:
Paul Ducklin
β November 3
rd
2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...
ossl-code-1200
Naked Security
OpenSSL patches are outΒ β CRITICAL bug downgraded to HIGH, but patch anyway!
By:
Paul Ducklin
β November 1
st
2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...
Naked Security
SHA-3 code execution bug patched in PHP β check your version!
By:
Paul Ducklin
β November 1
st
2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!
Naked Security
S3 Ep106: Facial recognition without consent β should it be banned?
By:
Paul Ducklin
β October 27
th
2022 at 16:59
Latest episode - listen (or read) now. Teachable moments for X-Ops professionals!
Naked Security
Serious Security: How randomly (or not) can you shuffle cards?
By:
Paul Ducklin
β October 24
th
2022 at 18:57
What if you could guess the next card correctly twice as often as you should?
card-fan-1200
Naked Security
S3 Ep105: WONTFIX! The MS Office cryptofail that βisnβt a security flawβ [Audio + Text]
By:
Paul Ducklin
β October 20
th
2022 at 16:54
The coolest video game ever! And lots of solid cybersecurity advice - listen now!
pic-1200
Naked Security
Women in Cryptology β USPS celebrates WW2 codebreakers
By:
Paul Ducklin
β October 19
th
2022 at 16:58
What did you do in the war, Mom? Oh, y'know, a bit of this and that...
Naked Security
Serious Security: Microsoft Office 365 attacked over feeble encryption
By:
Paul Ducklin
β October 14
th
2022 at 16:59
How 2022 is your encryption?
Naked Security
Serious Security: OAuth 2 and why Microsoft is finally forcing you into it
By:
Paul Ducklin
β October 10
th
2022 at 14:02
Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.
Naked Security
S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]
By:
Paul Ducklin
β August 18
th
2022 at 14:38
Latest episode - listen now (or read if you prefer!)
Naked Security
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]
By:
Paul Ducklin
β August 11
th
2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)
Naked Security
APIC/EPIC! Intel chips leak secrets even the kernel shouldnβt seeβ¦
By:
Paul Ducklin
β August 10
th
2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!
Naked Security
Slack admits to leaking hashed passwords for five years
By:
Paul Ducklin
β August 8
th
2022 at 15:14
"When those invitations went out... somehow, your password hash went out with them."
Naked Security
S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) [Audio + Text]
By:
Paul Ducklin
β August 4
th
2022 at 16:52
Latest episode - listen now! (Or read if that's what you prefer.)
Naked Security
Post-quantum cryptography β new algorithm βgone in 60 minutesβ
By:
Paul Ducklin
β August 3
rd
2022 at 16:55
And THIS is why you don't knit your own home-made encryption algorithms and hope no one looks at them.
Naked Security
Cryptocoin βtoken swapperβ Nomad loses $200 million in coding blunder
By:
Paul Ducklin
β August 2
nd
2022 at 16:12
Transactions were only approved, it seems, if they were initiated by... errrrr, by anyone.
Naked Security
GnuTLS patches memory mismanagement bug β update now!
By:
Paul Ducklin
β August 1
st
2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...
Naked Security
S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]
By:
Paul Ducklin
β July 14
th
2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.
Naked Security
OpenSSL fixes two βone-linerβ crypto bugs β what you need to know
By:
Paul Ducklin
β July 6
th
2022 at 16:52
"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...
Naked Security
S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]
By:
Paul Ducklin
β June 30
th
2022 at 12:57
Latest episode - listen and read now! Use our advice to advise your own friends and family... let's all do our bit to stand up to scammers!
Naked Security
OpenSSL issues a bugfix for the previous bugfix
By:
Paul Ducklin
β June 24
th
2022 at 15:32
Fortunately, it's not a major bugfix, which means it's easy to patch and can teach us all some useful lessons.
Naked Security
He sold cracked passwords for a living β now heβs serving 4 years in prison
By:
Paul Ducklin
β May 13
th
2022 at 15:31
Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough...
Naked Security
S3 Ep79: Chrome hole, a bad place for a cybersecurity holiday, and crypto-dodginess [Podcast]
By:
Paul Ducklin
β April 21
st
2022 at 13:41
Do you know your Adam Osborne from your John Osbourne? Your Z80 from your 6502? Latest episode - listen now!
Naked Security
Critical cryptographic Java security blunder patched β update now!
By:
Paul Ducklin
β April 20
th
2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.
Naked Security
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution [Podcast]
By:
Paul Ducklin
β April 14
th
2022 at 13:39
Latest episode - listen now!
Naked Security
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
By:
Paul Ducklin
β April 11
th
2022 at 16:58
Useful quantum computers might not actually be possible. But what if they are? And what if they arrive, say, tomorrow?
cat-1200
Naked Security
S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]
By:
Paul Ducklin
β March 24
th
2022 at 13:49
Latest episode - listen now!
Naked Security
OpenSSL patches infinite-loop DoS bug in certificate verification
By:
Paul Ducklin
β March 18
th
2022 at 17:59
When it comes to writing loops in your code... never sit on the fence!
Naked Security
Self-styled βCrocodile of Wall Streetβ arrested with husband over Bitcoin megaheist
By:
Naked Security writer
β February 9
th
2022 at 14:44
The cops say they've recovered 80% of a $72 million cryptocoin heist... but the recovered funds alone are now worth over $4 billion!
Naked Security
S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript]
By:
Paul Ducklin
β January 20
th
2022 at 17:28
Latest epsiode - listen now!
Naked Security
Serious Security: Linux full-disk encryption bug fixed β patch now!
By:
Paul Ducklin
β January 14
th
2022 at 17:58
Imagine if someone who didn't have your password could sneakily modify data that was encrypted with it.
Naked Security
Serious Security: OpenSSL fixes βerror conflationβ bugs β how mixing up mistakes can lead to trouble
By:
Paul Ducklin
β December 17
th
2021 at 17:57
Have you ever seen the message "An error occurred"? Even worse, the message "This error cannot occur"? Facts matter!
Naked Security
Mozilla patches critical βBigSigβ cryptographic bug: Hereβs how to track it down and fix it
By:
Paul Ducklin
β December 3
rd
2021 at 17:58
Mozilla's cryptographic code had a critical bug. Problem is that numerous apps are affected and may need patching individually.
Naked Security
Samba update patches plaintext password plundering problem
By:
Paul Ducklin
β November 12
th
2021 at 17:59
When Microsoft itself says STOP USING X, where X is one of its own protocols... we think you should listen.
There are no more articles
β
Mark all as read