FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

Performance and security clash yet again in β€œCollide+Power” attack

By: Paul Ducklin β€” August 2nd 2023 at 23:36
It's a real vulnerability, but the data leakage rate can be as low as... let's just say that an IMAX-quality copy of the new "Oppenheimer" movie could take you 4 billion years to exfiltrate.

☐ β˜† βœ‡ Naked Security

Zenbleed: How the quest for CPU performance could put your passwords at risk

By: Paul Ducklin β€” July 26th 2023 at 19:01
You need to turn on a special setting to stop (the code you wrote to stop [the code you wrote to improve performance] from reducing performance) from reducing security.

☐ β˜† βœ‡ Naked Security

Urgent! Apple fixes critical zero-day hole in iPhones, iPads and Macs

By: Paul Ducklin β€” July 10th 2023 at 23:12
Don't delay, do it today. This is a code-implantation bug in WebKit that attackers already know how to exploit.

☐ β˜† βœ‡ Naked Security

Ghostscript bug could allow rogue documents to run system commands

By: Paul Ducklin β€” July 4th 2023 at 17:57
Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.

☐ β˜† βœ‡ Naked Security

WordPress plugin lets users become admins – Patch early, patch often!

By: Paul Ducklin β€” July 3rd 2023 at 16:48
Ultimate Member plugin lets rogue users choose their own site capabilities, including becoming admins.

☐ β˜† βœ‡ Naked Security

More MOVEit mitigations: new patches published for further protection

By: Paul Ducklin β€” June 9th 2023 at 21:54
Good news... more patches, this time available proactively

☐ β˜† βœ‡ Naked Security

Firefox 114 is out: No 0-days, but one fascinating β€œteachable moment” bug

By: Paul Ducklin β€” June 7th 2023 at 17:59
With the right (or wrong, if you're on the right side of the fence) timing...

☐ β˜† βœ‡ Naked Security

S3 Ep137: 16th century crypto skullduggery

By: Paul Ducklin β€” June 1st 2023 at 16:45
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

s3-ep137-feat-1200

☐ β˜† βœ‡ Naked Security

Serious Security: That KeePass β€œmaster password crack”, and what we can learn from it

By: Paul Ducklin β€” May 31st 2023 at 17:39
Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

☐ β˜† βœ‡ Naked Security

Serious Security: Verification is vital – examining an OAUTH login bug

By: Paul Ducklin β€” May 30th 2023 at 16:59
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

☐ β˜† βœ‡ Naked Security

PaperCut security vulnerabilities under active attack – vendor urges customers to patch

By: Paul Ducklin β€” April 25th 2023 at 17:53
If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...

☐ β˜† βœ‡ Naked Security

VMware patches break-and-enter hole in logging tools: update now!

By: Paul Ducklin β€” April 21st 2023 at 17:58
You know jolly well/What we're going to say/And that's "Do not delay/Simply do it today."

☐ β˜† βœ‡ Naked Security

Microsoft assigns CVE to Snipping Tool bug, pushes patch to Store

By: Paul Ducklin β€” March 27th 2023 at 16:59
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

☐ β˜† βœ‡ Naked Security

Windows 11 also vulnerable to β€œaCropalypse” image data leakage

By: Paul Ducklin β€” March 22nd 2023 at 17:59
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

☐ β˜† βœ‡ Naked Security

Google Pixel phones had a serious data leakage bug – here’s what to do!

By: Paul Ducklin β€” March 21st 2023 at 17:58
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

☐ β˜† βœ‡ Naked Security

Password-stealing β€œvulnerability” reported in KeePass – bug or feature?

By: Paul Ducklin β€” February 1st 2023 at 18:58
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

☐ β˜† βœ‡ Naked Security

Serious Security: The Samba logon bug caused by outdated crypto

By: Paul Ducklin β€” January 30th 2023 at 17:59
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

☐ β˜† βœ‡ Naked Security

Apple patches are out – old iPhones get an old zero-day fix at last!

By: Paul Ducklin β€” January 24th 2023 at 01:24
Don't delay, especially if you're still running an iOS 12 device... please do it today!

☐ β˜† βœ‡ Naked Security

Microsoft dishes the dirt on Apple’s β€œAchilles heel” shortly after fixing similar Windows bug

By: Paul Ducklin β€” December 20th 2022 at 17:59
It happens to the best of us: Microsoft highlights a security bypass bug on Macs that is curiously similar to a recent Windows 0-day.

☐ β˜† βœ‡ Naked Security

Apple patches everything, finally reveals mystery of iOS 16.1.2

By: Paul Ducklin β€” December 14th 2022 at 02:11
There's an update for everything this time, not just for iOS.

☐ β˜† βœ‡ Naked Security

Number Nine! Chrome fixes another 2022 zero-day, Edge patched too

By: Paul Ducklin β€” December 5th 2022 at 00:58
Ninth more unto the breach, dear friends, ninth more.

☐ β˜† βœ‡ Naked Security

How to hack an unpatched Exchange server with rogue PowerShell code

By: Paul Ducklin β€” November 22nd 2022 at 17:54
Review your servers, your patches and your authentication policies - there's a proof-of-concept out

☐ β˜† βœ‡ Naked Security

Log4Shell-like code execution hole in popular Backstage dev tool

By: Paul Ducklin β€” November 15th 2022 at 17:49
Good old "string templating", also known as "string interpolation", in the spotlight again...

bs-1200

☐ β˜† βœ‡ Naked Security

Dangerous SIM-swap lockscreen bypass – update Android now!

By: Paul Ducklin β€” November 11th 2022 at 17:59
A bit like leaving the front door keys under the doormat...

☐ β˜† βœ‡ Naked Security

Emergency code execution patch from Apple – but not an 0-day

By: Paul Ducklin β€” November 10th 2022 at 01:49
Not a zero-day, but important enough for a quick-fire patch to one system library...

☐ β˜† βœ‡ Naked Security

The OpenSSL security update story – how can you tell what needs fixing?

By: Paul Ducklin β€” November 3rd 2022 at 00:44
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...

ossl-code-1200

☐ β˜† βœ‡ Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

By: Paul Ducklin β€” November 1st 2022 at 17:24
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

☐ β˜† βœ‡ Naked Security

SHA-3 code execution bug patched in PHP – check your version!

By: Paul Ducklin β€” November 1st 2022 at 14:09
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

☐ β˜† βœ‡ Naked Security

Chrome issues urgent zero-day fix – update now!

By: Paul Ducklin β€” October 29th 2022 at 15:08
We've said it before/And we'll say it again/It's not *if* you should patch/It's a matter of *when*. (Hint: now!)

☐ β˜† βœ‡ Naked Security

Updates to Apple’s zero-day update story – iPhone and iPad users read this!

By: Paul Ducklin β€” October 28th 2022 at 12:04
Turns out that Tuesday's zero-day for iOS 16 is Friday's zero-day for iOS 15...

☐ β˜† βœ‡ Naked Security

Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!

By: Paul Ducklin β€” October 25th 2022 at 18:03
Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch...

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches sneaky β€œspy-on-me” bug – update now!

By: Paul Ducklin β€” October 18th 2022 at 15:58
Hey! That back door isn't supposed to be there at all, let alone propped open...

☐ β˜† βœ‡ Naked Security

Dangerous hole in Apache Commons Text – like Log4Shell all over again

By: Paul Ducklin β€” October 18th 2022 at 16:26
Third time unlucky. Time to put your patching boots on again...

act-1200

☐ β˜† βœ‡ Naked Security

Mystery iPhone update patches against iOS 16 mail crash-attack

By: Paul Ducklin β€” October 11th 2022 at 00:28
The problem with crashy messaging apps is that *other people* get to choose if and when to send you messages...

☐ β˜† βœ‡ Naked Security

S3 Ep102.5: β€œProxyNotShell” Exchange bugs – an expert speaks [Audio + Text]

By: Paul Ducklin β€” October 1st 2022 at 14:05
Who's affected, what you can do while waiting for Microsoft's patches, and how to plan your threat hunting...

☐ β˜† βœ‡ Naked Security

URGENT! Microsoft Exchange double zero-day – β€œlike ProxyShell, only different”

By: Paul Ducklin β€” September 30th 2022 at 13:25
Double-play 0-day in Exchange - what you need to know, and what you can do

☐ β˜† βœ‡ Naked Security

Chrome and Edge fix zero-day security hole – update now!

By: Paul Ducklin β€” September 5th 2022 at 15:12
This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.

☐ β˜† βœ‡ Naked Security

URGENT! Apple slips out zero-day update for older iPhones and iPads

By: Paul Ducklin β€” August 31st 2022 at 18:42
Patch as soon as you can - that recent WebKit zero-day affecting new iPhones and iPads is apparently being used against older models, too.

☐ β˜† βœ‡ Naked Security

JavaScript bugs aplenty in Node.js ecosystem – found automatically

By: Paul Ducklin β€” August 30th 2022 at 16:59
How to get the better of bugs in all the possible packages in your supply chain?

☐ β˜† βœ‡ Naked Security

Laptop denial-of-service via music: the 1980s R&B song with a CVE!

By: Paul Ducklin β€” August 22nd 2022 at 16:03
We haven't validated this vuln ourselves... but the source of the story is impeccable. (Impeccably dressed, at least.)

☐ β˜† βœ‡ Naked Security

Apple patches double zero-day in browser and kernel – update now!

By: Paul Ducklin β€” August 17th 2022 at 23:33
Double 0-day exploits - one in WebKit (to break in) and the other in the kernel (to take over). Patch now!

☐ β˜† βœ‡ Naked Security

Zoom for Mac patches critical bug – update now!

By: Paul Ducklin β€” August 15th 2022 at 18:26
There's many a slip 'twixt the cup and the lip. Or at least between the TOC and the TOU...

☐ β˜† βœ‡ Naked Security

APIC/EPIC! Intel chips leak secrets even the kernel shouldn’t see…

By: Paul Ducklin β€” August 10th 2022 at 16:59
If you've ever written code that left stuff lying around in memory when you didn't need it any more... we bet you've regretted it!

☐ β˜† βœ‡ Naked Security

GnuTLS patches memory mismanagement bug – update now!

By: Paul Ducklin β€” August 1st 2022 at 16:55
GnuTLS may well be the most widespread cryptographic toolkit you've never heard of. Learn more...

☐ β˜† βœ‡ Naked Security

Critical Samba bug could let anyone become Domain Admin – patch now!

By: Paul Ducklin β€” July 27th 2022 at 21:15
It's a serious bug... but there's a fix for it, so you know exactly what to do!

☐ β˜† βœ‡ Naked Security

Apache β€œCommons Configuration” patches Log4Shell-style bug – what you need to know

By: Paul Ducklin β€” July 8th 2022 at 00:59
It's a bit like Log4J, but for configuration files, not for logging.

☐ β˜† βœ‡ Naked Security

Google patches β€œin-the-wild” Chrome zero-day – update now!

By: Paul Ducklin β€” July 5th 2022 at 15:55
Running Chrome? Do the "Help-About-Update" dance move right now, just to be sure...

☐ β˜† βœ‡ Naked Security

Follina gets fixed – but it’s not listed in the Patch Tuesday patches!

By: Paul Ducklin β€” June 15th 2022 at 01:20
We tried it out to make sure, so you don't have to.

☐ β˜† βœ‡ Naked Security

You’re invited! Join us for a live walkthrough of the β€œFollina” story…

By: Paul Ducklin β€” June 13th 2022 at 16:28
Live demo, plain English, no sales pitch, just a chance to watch an attack dissected in safety. Join us if you can!

☐ β˜† βœ‡ Naked Security

Atlassian announces 0-day hole in Confluence Server – update now!

By: Paul Ducklin β€” June 3rd 2022 at 18:59
Zero-day announced - here's what you need to know

☐ β˜† βœ‡ Naked Security

Mysterious β€œFollina” zero-day hole in Office – here’s what to do!

By: Paul Ducklin β€” May 30th 2022 at 23:01
News has emerged of a "feature" in Office that has been abused as a zero-day bug to run evil code. Turning off macros doesn't help!

☐ β˜† βœ‡ Naked Security

Mozilla patches Wednesday’s Pwn2Own double-exploit… on Friday!

By: Paul Ducklin β€” May 20th 2022 at 23:47
That was quick! 48 hours from exploit report to published patch.

☐ β˜† βœ‡ Naked Security

US Government says: Patch VMware right now, or get off our network

By: Paul Ducklin β€” May 20th 2022 at 14:03
Find and patch. Right now. If you can't patch, get it off the network. Right now! Oh, and show us what you did to comply.

☐ β˜† βœ‡ Naked Security

RubyGems supply chain rip-and-replace bug fixed – check your logs!

By: Paul Ducklin β€” May 9th 2022 at 15:41
Imagine if you could assume the identity of, say, Franklin Delano Roosevelt simply by showing up and calling yourself "Frank".

ruby-1200

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By: Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

Yet another Chrome zero-day emergency update – patch now!

By: Paul Ducklin β€” April 16th 2022 at 00:33
The third emergency Chrome 0-day in three months - the first one was exploited by North Korea, so you might as well get this one ASAP.

❌