FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

β€œSnakes in airplane mode” – what if your phone says it’s offline but isn’t?

By: Paul Ducklin β€” August 21st 2023 at 17:45
WYSIWYG is short for "what you see is what you get". Except when it isn't...

☐ β˜† βœ‡ Naked Security

S3 Ep142: Putting the X in X-Ops

By: Paul Ducklin β€” July 6th 2023 at 17:58
How to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light.

s3-ep100-js-1200

☐ β˜† βœ‡ Naked Security

S3 Ep141: What was Steve Jobs’s first job?

By: Paul Ducklin β€” June 29th 2023 at 16:58
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Aussie PM says, β€œShut down your phone every 24 hours for 5 mins” – but that’s not enough on its own

By: Paul Ducklin β€” June 23rd 2023 at 16:10
Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.

☐ β˜† βœ‡ Naked Security

Beware bad passwords as attackers co-opt Linux servers into cybercrime

By: Paul Ducklin β€” June 21st 2023 at 17:50
Did you prevent password-only logins on your SSH servers? On ALL of them? Are you sure about that?

☐ β˜† βœ‡ Naked Security

S3 Ep139: Are password rules like running through rain?

By: Paul Ducklin β€” June 15th 2023 at 16:43
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

Gozi banking malware β€œIT chief” finally jailed after more than 10 years

By: Paul Ducklin β€” June 13th 2023 at 16:43
Gozi threesome from way back in the late 2000s and early 2010s now all charged, convicted and sentenced. The DOJ got there in the end...

☐ β˜† βœ‡ Naked Security

S3 Ep136: Navigating a manic malware maelstrom

By: Paul Ducklin β€” May 25th 2023 at 16:50
Latest episode - listen now. Full transcript inside...

☐ β˜† βœ‡ Naked Security

PyPI open-source code repository deals with manic malware maelstrom

By: Paul Ducklin β€” May 23rd 2023 at 16:45
Controlled outage used to keep malware marauders from gumming up the works. Learn what you can do to help in future...

☐ β˜† βœ‡ Naked Security

S3 Ep133: Apple takes β€œtight-lipped” to a whole new level

By: Paul Ducklin β€” May 4th 2023 at 20:59
Entertaining, educational, and all in plain English πŸŽ§πŸ“–

☐ β˜† βœ‡ Naked Security

Mac malware-for-hire steals passwords and cryptocoins, sends β€œcrime logs” via Telegram

By: Paul Ducklin β€” April 30th 2023 at 01:23
These malware peddlers are specifically going after Mac users. The hint's in the name: "Atomic macOS Stealer", or AMOS for short.

☐ β˜† βœ‡ Naked Security

Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert

By: Paul Ducklin β€” April 11th 2023 at 16:58
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

☐ β˜† βœ‡ Naked Security

S3 Ep129: When spyware arrives from someone you trust

By: Paul Ducklin β€” April 6th 2023 at 14:57
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

☐ β˜† βœ‡ Naked Security

Supply chain blunder puts 3CX telephone app users at risk

By: Paul Ducklin β€” March 30th 2023 at 17:36
Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

☐ β˜† βœ‡ Naked Security

LastPass: Keylogger on home PC led to cracked corporate password vault

By: Paul Ducklin β€” February 28th 2023 at 02:23
Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.

☐ β˜† βœ‡ Naked Security

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!

By: Paul Ducklin β€” February 27th 2023 at 02:10
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

☐ β˜† βœ‡ Naked Security

S3 Ep123: Crypto company compromise kerfuffle [Audio + Text]

By: Paul Ducklin β€” February 23rd 2023 at 17:58
Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

☐ β˜† βœ‡ Naked Security

GoDaddy admits: Crooks hit us with malware, poisoned customer websites

By: Paul Ducklin β€” February 20th 2023 at 01:36
New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.

☐ β˜† βœ‡ Naked Security

Microsoft Patch Tuesday: One 0-day; Win 7 and 8.1 get last-ever patches

By: Paul Ducklin β€” January 11th 2023 at 00:22
Get 'em while they're hot. And get 'em for the very last time, if you still have Windows 7 or 8.1...

☐ β˜† βœ‡ Naked Security

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

By: Paul Ducklin β€” January 4th 2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

☐ β˜† βœ‡ Naked Security

PyTorch: Machine Learning toolkit pwned from Christmas to New Year

By: Paul Ducklin β€” January 1st 2023 at 21:36
The bad news: the crooks have your SSH private keys. The good news: only users of the "nightly" build were affected.

☐ β˜† βœ‡ Naked Security

S3 Ep115: True crime stories – A day in the life of a cybercrime fighter [Audio + Text]

By: Paul Ducklin β€” December 29th 2022 at 09:20
Listen now - you'll be alarmed, amused and educated, all in equal measure. (Full transcript in article.)

☐ β˜† βœ‡ Naked Security

S3 Ep114: Preventing cyberthreats – stop them before they stop you! [Audio + Text]

By: Paul Ducklin β€” December 22nd 2022 at 17:56
Join world-renowned expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode on how to fight cybercrime.

☐ β˜† βœ‡ Naked Security

S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text]

By: Paul Ducklin β€” December 15th 2022 at 17:10
Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!

☐ β˜† βœ‡ Naked Security

S3 Ep112: Data breaches can haunt you more than once! [Audio + Text]

By: Paul Ducklin β€” December 9th 2022 at 16:46
Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

☐ β˜† βœ‡ Naked Security

Credit card skimming – the long and winding road of supply chain failure

By: Paul Ducklin β€” December 8th 2022 at 17:58
Don't keep calling home to a JavaScript server that closed its doors eight years ago!

☐ β˜† βœ‡ Naked Security

S3 Ep111: The business risk of a sleazy β€œnudity unfilter” [Audio + Text]

By: Paul Ducklin β€” December 1st 2022 at 17:58
Latest episode - listen now (or read if you prefer)...

☐ β˜† βœ‡ Naked Security

The CHRISTMA EXEC network worm – 35 years and counting!

By: Paul Ducklin β€” December 1st 2022 at 20:35
"Uh-oh, this viruses-and-worms scene could turn out quite troublesome." If only we'd been wrong...

xmas-1200-35-wide

☐ β˜† βœ‡ Naked Security

TikTok β€œInvisible Challenge” porn malware puts us all at risk

By: Paul Ducklin β€” November 29th 2022 at 17:58
An injury to one is an injury to all. Especially if the other people are part of your social network.

☐ β˜† βœ‡ Naked Security

Multimillion dollar CryptoRom scam sites seized, suspects arrested in US

By: Paul Ducklin β€” November 23rd 2022 at 19:58
Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...

cryptorom-1200

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By: Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

Online ticketing company β€œSee” pwned for 2.5 years by attackers

By: Paul Ducklin β€” October 26th 2022 at 16:58
Don't be a cybersecurity slowcoach - you need to spot possible attacks as soon as you can.

☐ β˜† βœ‡ Naked Security

WhatsApp goes after Chinese password scammers via US court

By: Paul Ducklin β€” October 7th 2022 at 16:14
If you can't beat 'em, sue 'em!

☐ β˜† βœ‡ Naked Security

Interested in cybersecurity? Join us for Security SOS Week 2022!

By: Paul Ducklin β€” September 21st 2022 at 14:24
Four one-on-one interviews with experts who are passionate about sharing their expertise with the community.

☐ β˜† βœ‡ Naked Security

S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, healthcare security [Audio + Text]

By: Paul Ducklin β€” August 18th 2022 at 14:38
Latest episode - listen now (or read if you prefer!)

☐ β˜† βœ‡ Naked Security

Apple patches double zero-day in browser and kernel – update now!

By: Paul Ducklin β€” August 17th 2022 at 23:33
Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By: Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

GitHub blighted by β€œresearcher” who created thousands of malicious projects

By: Paul Ducklin β€” August 3rd 2022 at 23:06
If you spew projects laced with hidden malware into an open source repository, don't waste your time telling us "no harm done" afterwards.

☐ β˜† βœ‡ Naked Security

Office macro security: on-again-off-again feature now BACK ON AGAIN!

By: Paul Ducklin β€” July 23rd 2022 at 01:10
20 years to turn it on, then 20 weeks to turn it off, then just 2 weeks to turn it back on again. That's progress!

☐ β˜† βœ‡ Naked Security

Last member of Gozi malware troika arrives in US for criminal trial

By: Paul Ducklin β€” July 20th 2022 at 14:56
His co-conspirators went into and got out of prison years ago, while he remained free. Now the tables have turned...

☐ β˜† βœ‡ Naked Security

8 months on, US says Log4Shell will be around for β€œa decade or longer”

By: Paul Ducklin β€” July 18th 2022 at 16:57
When it comes to cybersecurity, ask not what everyone else can do for you...

☐ β˜† βœ‡ Naked Security

S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]

By: Paul Ducklin β€” July 14th 2022 at 18:47
Latest episode - listen now! Great discussion, technical content, solid advice... all covered in plain English.

☐ β˜† βœ‡ Naked Security

That didn’t last! Microsoft turns off the Office security it just turned on

By: Paul Ducklin β€” July 11th 2022 at 13:27
An Office anti-malware setting that took more than 20 years to arrive... and fewer than 20 weeks to vanish again.

☐ β˜† βœ‡ Naked Security

Capital One identity theft hacker finally gets convicted

By: Paul Ducklin β€” June 21st 2022 at 15:24
It took three years, but the Capital One cracker was convicted in the end. Don't get caught out in a data breach of your own!

☐ β˜† βœ‡ Naked Security

You’re invited! Join us for a live walkthrough of the β€œFollina” story…

By: Paul Ducklin β€” June 13th 2022 at 16:28
Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

☐ β˜† βœ‡ Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access

By: Paul Ducklin β€” May 24th 2022 at 23:04
More supply chain trouble - this time with clear examples so you can learn how to spot this stuff yourself.

☐ β˜† βœ‡ Naked Security

S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]

By: Paul Ducklin β€” March 24th 2022 at 13:49
Latest episode - listen now!

☐ β˜† βœ‡ Naked Security

Beware bogus Betas – cryptocoin scammers abuse Apple’s TestFlight system

By: Paul Ducklin β€” March 16th 2022 at 15:49
"Install this moneymaking app" - this one is so special that it isn't available on Google Play or the App Store!

☐ β˜† βœ‡ Naked Security

At last! Office macros from the internet to be blocked by default

By: Paul Ducklin β€” February 8th 2022 at 16:34
It's been a long time coming, and we're not there yet, but at least Microsoft Office will be a bit safer against macro malware...

☐ β˜† βœ‡ Naked Security

Microsoft blocks web installation of its own App Installer files

By: Paul Ducklin β€” February 7th 2022 at 16:36
It's a big deal when a vendor decides to block one of its own "features" for security reasons. Here's why we think it's a good idea.

☐ β˜† βœ‡ Naked Security

Firefox update brings a whole new sort of security sandbox

By: Paul Ducklin β€” December 7th 2021 at 17:14
Firefox 95.0 is out, with the usual security fixes... plus some funky new ones.

☐ β˜† βœ‡ Naked Security

Black Friday and Cyber Monday – here’s what you REALLY need to do!

By: Paul Ducklin β€” November 22nd 2021 at 12:52
The world fills up with cybersecurity tips every year when Black Friday comes round. But what about the rest of the year?

☐ β˜† βœ‡ Naked Security

Emotet malware: β€œThe report of my death was an exaggeration”

By: Paul Ducklin β€” November 16th 2021 at 14:13
"Old malware rarely dies." The best way to predict the future is to look at the past... if it worked before, it will probably work again.

☐ β˜† βœ‡ Naked Security

Sophos 2022 Threat Report: Malware, Mobile, Machine learning and more!

By: Paul Ducklin β€” November 9th 2021 at 12:31
The crooks have shown that they're willing to learn and adapt their attacks, so we need to make sure we learn and adapt, too.

☐ β˜† βœ‡ Naked Security

β€œCustomer complaint” email scam preys on your fear of getting into trouble at work

By: Paul Ducklin β€” November 5th 2021 at 17:49
Stop. Think. Connect. Don't let the crooks trick you into acting in haste.

❌