FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

β€œCrocodile of Wall Street” and her husband plead guilty to giant-sized cryptocrimes

By: Paul Ducklin β€” August 4th 2023 at 16:52
Sentences still to be decided, but she could get up to 10 years and he could get as many as 20.

☐ β˜† βœ‡ Naked Security

S3 Ep146: Tell us about that breach! (If you want to.)

By: Paul Ducklin β€” August 3rd 2023 at 17:56
Serious security stories explained clearly in plain English - listen now. (Full transcript available.)

☐ β˜† βœ‡ Naked Security

Firefox fixes a flurry of flaws in the first of two releases this month

By: Paul Ducklin β€” August 1st 2023 at 17:28
No zero-days, but some interesting patches with their very own "teachable moments".

Firefox

☐ β˜† βœ‡ Naked Security

Zenbleed: How the quest for CPU performance could put your passwords at risk

By: Paul Ducklin β€” July 26th 2023 at 19:01
You need to turn on a special setting to stop (the code you wrote to stop [the code you wrote to improve performance] from reducing performance) from reducing security.

☐ β˜† βœ‡ Naked Security

Apple ships that recent β€œRapid Response” spyware patch to everyone, fixes a second zero-day

By: Paul Ducklin β€” July 24th 2023 at 23:18
Another month, another patch for in-the-wild iPhone malware (and a whole lot more).

☐ β˜† βœ‡ Naked Security

S3 Ep144: When threat hunting goes down a rabbit hole

By: Paul Ducklin β€” July 20th 2023 at 14:58
Latest episode - check it out now!

☐ β˜† βœ‡ Naked Security

Zimbra Collaboration Suite warning: Patch this 0-day right now (by hand)!

By: Paul Ducklin β€” July 14th 2023 at 16:58
Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly request your cooperation to apply the fix manually."

☐ β˜† βœ‡ Naked Security

Apple silently pulls its latest zero-day update – what now?

By: Paul Ducklin β€” July 11th 2023 at 15:21
Previously, we said "do it today", but now we're forced back on: "Do not delay; do it as soon as Apple and your device will let you."

☐ β˜† βœ‡ Naked Security

Urgent! Apple fixes critical zero-day hole in iPhones, iPads and Macs

By: Paul Ducklin β€” July 10th 2023 at 23:12
Don't delay, do it today. This is a code-implantation bug in WebKit that attackers already know how to exploit.

☐ β˜† βœ‡ Naked Security

S3 Ep142: Putting the X in X-Ops

By: Paul Ducklin β€” July 6th 2023 at 17:58
How to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light.

s3-ep100-js-1200

☐ β˜† βœ‡ Naked Security

Firefox 115 is out, says farewell to users of older Windows and Mac versions

By: Paul Ducklin β€” July 5th 2023 at 18:58
No zero-days this month, so you're patching to stay ahead, not merely to catch up!

☐ β˜† βœ‡ Naked Security

Apple patch fixes zero-day kernel hole reported by Kaspersky – update now!

By: Paul Ducklin β€” June 22nd 2023 at 00:36
Apple didn't use the words "Triangulation Trojan", but you probably will.

☐ β˜† βœ‡ Naked Security

Beware bad passwords as attackers co-opt Linux servers into cybercrime

By: Paul Ducklin β€” June 21st 2023 at 17:50
Did you prevent password-only logins on your SSH servers? On ALL of them? Are you sure about that?

☐ β˜† βœ‡ Naked Security

History revisited: US DOJ unseals Mt. Gox cybercrime charges

By: Naked Security writer β€” June 12th 2023 at 16:58
Though the mills of the Law grind slowly/Yet they grind exceeding small/Though with patience they stand waiting/With exactness grind they all...

☐ β˜† βœ‡ Naked Security

Firefox 114 is out: No 0-days, but one fascinating β€œteachable moment” bug

By: Paul Ducklin β€” June 7th 2023 at 17:59
With the right (or wrong, if you're on the right side of the fence) timing...

☐ β˜† βœ‡ Naked Security

Serious Security: Verification is vital – examining an OAUTH login bug

By: Paul Ducklin β€” May 30th 2023 at 16:59
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

☐ β˜† βœ‡ Naked Security

Apple’s secret is out: 3 zero-days fixed, so be sure to patch now!

By: Paul Ducklin β€” May 19th 2023 at 01:02
All Apple users have zero-days that need patching, though some have more zero-days than others.

☐ β˜† βœ‡ Naked Security

Mac malware-for-hire steals passwords and cryptocoins, sends β€œcrime logs” via Telegram

By: Paul Ducklin β€” April 30th 2023 at 01:23
These malware peddlers are specifically going after Mac users. The hint's in the name: "Atomic macOS Stealer", or AMOS for short.

☐ β˜† βœ‡ Naked Security

PaperCut security vulnerabilities under active attack – vendor urges customers to patch

By: Paul Ducklin β€” April 25th 2023 at 17:53
If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...

☐ β˜† βœ‡ Naked Security

Ex-CEO of breached pyschotherapy clinic gets prison sentence for bad data security

By: Paul Ducklin β€” April 18th 2023 at 16:56
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

☐ β˜† βœ‡ Naked Security

S3 Ep130: Open the garage bay doors, HAL [Audio + Text]

By: Paul Ducklin β€” April 13th 2023 at 16:54
I'm sorry, Dave. I'm afraid I can't... errr, no, hang on a minute, I can do that easily! Worldwide! Right now!

☐ β˜† βœ‡ Naked Security

Attention gamers! Motherboard maker MSI admits to breach, issues β€œrogue firmware” alert

By: Paul Ducklin β€” April 11th 2023 at 16:58
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

☐ β˜† βœ‡ Naked Security

Apple zero-day spyware patches extended to cover older Macs, iPhones and iPads

By: Paul Ducklin β€” April 10th 2023 at 20:20
That double-whammy Apple browser-to-kernel spyware bug combo we wrote up last week? Turns out it applies to all supported Macs and iDevices - patch now!

☐ β˜† βœ‡ Naked Security

Popular server-side JavaScript security sandbox β€œvm2” patches remote execution hole

By: Paul Ducklin β€” April 9th 2023 at 00:28
The security error was in the error handling system that was supposed to catch potential security errors...

vm2-1200

☐ β˜† βœ‡ Naked Security

Apple issues emergency patches for spyware-style 0-day exploits – update now!

By: Paul Ducklin β€” April 8th 2023 at 01:20
A bug to hack your browser, then a bug to pwn the kernel... reported from the wild by Amnesty International.

☐ β˜† βœ‡ Naked Security

S3 Ep129: When spyware arrives from someone you trust

By: Paul Ducklin β€” April 6th 2023 at 14:57
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

☐ β˜† βœ‡ Naked Security

Hack and enter! The β€œsecure” garage doors that anyone can open from anywhere – what you need to know

By: Paul Ducklin β€” April 5th 2023 at 18:49
Grab a message/Play it back/You've just performed/A big phat hack...

☐ β˜† βœ‡ Naked Security

Supply chain blunder puts 3CX telephone app users at risk

By: Paul Ducklin β€” March 30th 2023 at 17:36
Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

☐ β˜† βœ‡ Naked Security

Apple patches everything, including a zero-day fix for iOS 15 users

By: Paul Ducklin β€” March 28th 2023 at 00:23
Got an older iPhone that can't run iOS 16? You've got a zero-day to deal with! That super-cool Studio Display monitor needs patching, too.

☐ β˜† βœ‡ Naked Security

Google Pixel phones had a serious data leakage bug – here’s what to do!

By: Paul Ducklin β€” March 21st 2023 at 17:58
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

☐ β˜† βœ‡ Naked Security

S3 Ep 126: The price of fast fashion (and feature creep) [Audio + Text]

By: Paul Ducklin β€” March 16th 2023 at 17:56
Worried about rogue apps? Unsure about the new Outlook zero-day? Clear advice in plain English... just like old times, with Duck and Chet!

☐ β˜† βœ‡ Naked Security

Microsoft fixes two 0-days on Patch Tuesday – update now!

By: Paul Ducklin β€” March 15th 2023 at 00:06
An email you haven't even looked at yet could be used to trick Outlook into helping crooks to logon as you.

☐ β˜† βœ‡ Naked Security

Firefox 111 patches 11 holes, but not 1 zero-day among them…

By: Paul Ducklin β€” March 14th 2023 at 17:16
In the game of cricket, 111 is an inauspicious number, but for Firefox, there doesn't seem to be much to worry about this month.

☐ β˜† βœ‡ Naked Security

Linux gets double-quick double-update to fix kernel Oops!

By: Paul Ducklin β€” March 13th 2023 at 17:59
Linux doesn't BSoD. It has oopses and panics instead. (We show you how to make a kernel module to explore further.)

☐ β˜† βœ‡ Naked Security

S3 Ep124: When so-called security apps go rogue [Audio + Text]

By: Paul Ducklin β€” March 2nd 2023 at 15:40
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

s3-ep124-auth--1200

☐ β˜† βœ‡ Naked Security

Coinbase breached by social engineers, employee data stolen

By: Paul Ducklin β€” February 21st 2023 at 17:58
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

☐ β˜† βœ‡ Naked Security

S3 Ep122: Stop calling every breach β€œsophisticated”! [Audio + Text]

By: Paul Ducklin β€” February 16th 2023 at 17:46
Latest episode - listen now! (Full transcript inside.)

☐ β˜† βœ‡ Naked Security

VMWare user? Worried about β€œESXi ransomware”? Check your patches now!

By: Paul Ducklin β€” February 7th 2023 at 17:59
To borrow from HHGttG, please DON'T PANIC. But if you are two years out of date with patches, please do ACT NOW!

☐ β˜† βœ‡ Naked Security

Finnish psychotherapy extortion suspect arrested in France

By: Naked Security writer β€” February 6th 2023 at 16:13
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

☐ β˜† βœ‡ Naked Security

Apple patches are out – old iPhones get an old zero-day fix at last!

By: Paul Ducklin β€” January 24th 2023 at 01:24
Don't delay, especially if you're still running an iOS 12 device... please do it today!

☐ β˜† βœ‡ Naked Security

Microsoft Patch Tuesday: One 0-day; Win 7 and 8.1 get last-ever patches

By: Paul Ducklin β€” January 11th 2023 at 00:22
Get 'em while they're hot. And get 'em for the very last time, if you still have Windows 7 or 8.1...

☐ β˜† βœ‡ Naked Security

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

By: Paul Ducklin β€” January 4th 2023 at 19:50
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

☐ β˜† βœ‡ Naked Security

PyTorch: Machine Learning toolkit pwned from Christmas to New Year

By: Paul Ducklin β€” January 1st 2023 at 21:36
The bad news: the crooks have your SSH private keys. The good news: only users of the "nightly" build were affected.

☐ β˜† βœ‡ Naked Security

Twitter data of β€œ+400 million unique users” up for sale – what to do?

By: Paul Ducklin β€” December 28th 2022 at 17:59
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?

☐ β˜† βœ‡ Naked Security

Patch Tuesday: 0-days, RCE bugs, and a curious tale of signed malware

By: Paul Ducklin β€” December 14th 2022 at 01:13
Tales of derring-do in the cyberunderground! (And some zero-days.)

☐ β˜† βœ‡ Naked Security

COVID-bit: the wireless spyware trick with an unfortunate name

By: Paul Ducklin β€” December 13th 2022 at 17:58
It's not the switching that's the problem, it's the switching of the switching!

ind-1200

☐ β˜† βœ‡ Naked Security

Pwn2Own Toronto: 54 hacks, 63 new bugs, $1 million in bounties

By: Paul Ducklin β€” December 12th 2022 at 17:58
That's a mean average of $15,710 per bug... and 63 fewer bugs out there for crooks and rogues to find.

☐ β˜† βœ‡ Naked Security

S3 Ep112: Data breaches can haunt you more than once! [Audio + Text]

By: Paul Ducklin β€” December 9th 2022 at 16:46
Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

☐ β˜† βœ‡ Naked Security

S3 Ep110: Spotlight on cyberthreats – an expert speaks [Audio + Text]

By: Paul Ducklin β€” November 24th 2022 at 16:52
Latest episode - security expert John Shier explains what the real-life cybercrime stories in the Sophos Threat Report can teach us

☐ β˜† βœ‡ Naked Security

How to hack an unpatched Exchange server with rogue PowerShell code

By: Paul Ducklin β€” November 22nd 2022 at 17:54
Review your servers, your patches and your authentication policies - there's a proof-of-concept out

☐ β˜† βœ‡ Naked Security

Firefox fixes fullscreen fakery flaw – get the update now!

By: Paul Ducklin β€” November 16th 2022 at 17:51
What's so bad about a web page going fullscreen without warning you first?

☐ β˜† βœ‡ Naked Security

S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?

By: Paul Ducklin β€” November 10th 2022 at 17:26
Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!

☐ β˜† βœ‡ Naked Security

Emergency code execution patch from Apple – but not an 0-day

By: Paul Ducklin β€” November 10th 2022 at 01:49
Not a zero-day, but important enough for a quick-fire patch to one system library...

☐ β˜† βœ‡ Naked Security

Exchange 0-days fixed (at last) – plus 4 brand new Patch Tuesday 0-days!

By: Paul Ducklin β€” November 9th 2022 at 17:58
In all the excitement, we kind of lost track ourselves. Were there six 0-days, or only four?

☐ β˜† βœ‡ Naked Security

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]

By: Paul Ducklin β€” November 3rd 2022 at 17:51
Listen now - latest episode - audio plus full transcript

☐ β˜† βœ‡ Naked Security

Psychotherapy extortion suspect: arrest warrant issued

By: Paul Ducklin β€” October 31st 2022 at 17:59
Wanted! Not only the extortionist who abused the data, but also the CEO who let it happen.

☐ β˜† βœ‡ Naked Security

Chrome issues urgent zero-day fix – update now!

By: Paul Ducklin β€” October 29th 2022 at 15:08
We've said it before/And we'll say it again/It's not *if* you should patch/It's a matter of *when*. (Hint: now!)

☐ β˜† βœ‡ Naked Security

Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!

By: Paul Ducklin β€” October 25th 2022 at 18:03
Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

☐ β˜† βœ‡ Naked Security

Dangerous hole in Apache Commons Text – like Log4Shell all over again

By: Paul Ducklin β€” October 18th 2022 at 16:26
Third time unlucky. Time to put your patching boots on again...

act-1200

❌