Menu

Monthly Archives: December 2023

Attacks abuse Microsoft DHCP to spoof DNS records and steal secrets
US and EU infosec authorities pen intel-sharing pact
Navigating privacy: Should we put the brakes on car tracking?

Your car probably knows a lot more about you than it lets on – but is the trade-off of privacy for convenience truly justifiable?

BlackSuit ransomware – what you need to know
Finally! Facebook and Messenger are getting default end-to-end encryption. And not everyone is happy…
Smashing Security podcast #351: Nuclear cybersecurity, Marketplace scams, and face up to porn
See me talking about “Future-proofing enterprise cybersecurity for AI, vulnerabilities, and business risks”
Belgian man charged with smuggling sanctioned military tech to Russia and China
Australia building ‘top secret’ cloud to catch up and link with US, UK intel orgs
Apple and some Linux distros are open to Bluetooth attack
Locking down the edge
A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list
Shielding the data that drives AI
$10 million up for grabs in fight against North Korean hackers
Atlassian security advisory reveals four fresh critical flaws – in mail with dead links
Microsoft issues deadline for end of Windows 10 support – it’s pay to play for security
Cisco intros AI to find firewall flaws, warns this sort of thing can’t be free
Fancy Bear goes phishing in US, European high-value networks
3 security best practices for all DevSecOps teams
CISA details twin attacks on federal servers via unpatched ColdFusion flaw
DSPM deep dive: debunking data security myths
BlackCat ransomware crims threaten to directly extort victim’s customers
It’s ba-ack… UK watchdog publishes age verification proposals
Russian hacker pleads guilty to Trickbot malware conspiracy
UK government denies China/Russia nuke plant hack claim
US warns Iranian terrorist crew broke into ‘multiple’ US water facilities
Hershey phishes! Crooks snarf chocolate lovers’ creds
Supply-chain ransomware attack causes outages at over 60 credit unions
Two new versions of OpenZFS fix long-hidden corruption bug
Exposed Hugging Face API tokens offered full access to Meta’s Llama 2
EU lawmakers finalize cyber security rules that panicked open source devs
New Relic’s cyber-something revealed as attack on staging systems, some users

https://security-tracker.debian.org/tracker/DSA-5572-1

https://security-tracker.debian.org/tracker/DSA-5571-1

https://security-tracker.debian.org/tracker/DSA-5570-1

Teaching appropriate use of AI tech – Week in security with Tony Anscombe

Several cases of children creating indecent images of other children using AI software add to the worries about harmful uses of AI technology

Scores of US credit unions offline after ransomware infects backend cloud outfit
Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks
UEFI flaws allow bootkits to pwn potentially hundreds of devices using images
US readies prison cell for another Russian Trickbot developer
Regulator says stranger entered hospital, treated a patient, took a document … then vanished
Interpol makes first border arrest using Biometric Hub to ID suspect
Today’s ‘China is misbehaving online’ allegations come from Google, Meta