FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Naked Security

Supply chain blunder puts 3CX telephone app users at risk

By: Paul Ducklin β€” March 30th 2023 at 17:36
Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

☐ β˜† βœ‡ Naked Security

GitHub code-signing certificates stolen (but will be revoked this week)

By: Paul Ducklin β€” January 31st 2023 at 11:35
There was a breach, so the bad news isn't great, but the good news isn't too bad...

☐ β˜† βœ‡ Naked Security

TikTok β€œInvisible Challenge” porn malware puts us all at risk

By: Paul Ducklin β€” November 29th 2022 at 17:58
An injury to one is an injury to all. Especially if the other people are part of your social network.

☐ β˜† βœ‡ Naked Security

S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto [Audio + Text]

By: Paul Ducklin β€” August 11th 2022 at 14:34
Latest episode - listen now! (Or read the transcript if you prefer.)

☐ β˜† βœ‡ Naked Security

GitHub blighted by β€œresearcher” who created thousands of malicious projects

By: Paul Ducklin β€” August 3rd 2022 at 23:06
If you spew projects laced with hidden malware into an open source repository, don't waste your time telling us "no harm done" afterwards.

☐ β˜† βœ‡ Naked Security

GitHub issues final report on supply-chain source code intrusions

By: Paul Ducklin β€” April 29th 2022 at 16:15
Learn how to find out which apps you've given access rights to, and how to revoke those rights immediately in an emergency.

☐ β˜† βœ‡ Naked Security

Critical cryptographic Java security blunder patched – update now!

By: Paul Ducklin β€” April 20th 2022 at 16:43
Either know the private key and use it scrupulously in your digital signature calculation.... or just send a bunch of zeros instead.

☐ β˜† βœ‡ Naked Security

Adafruit suffers GitHub data breach – don’t let this happen to you

By: Paul Ducklin β€” March 7th 2022 at 12:47
Training data stashed in GitHub by mistake... unfortunately, it was *real* data

❌