Menu

Category Archives: Security

Articles about security

https://security-tracker.debian.org/tracker/DSA-5573-1

Competing Section 702 surveillance bills on collision path for US House floor
Meta releases open-source tools for AI safety
That call center tech scammer could be a human trafficking victim
UK and US expose Russian hacking plot intended to influence UK’s 2019 elections and spread disinformation
Zero trust security with a hardware root of trust
Polish train maker denies claims its software bricked rolling stock maintained by competitor
Five Eyes nations warn Moscow’s mates at the Star Blizzard gang have new phishing targets
Attacks abuse Microsoft DHCP to spoof DNS records and steal secrets
US and EU infosec authorities pen intel-sharing pact
Navigating privacy: Should we put the brakes on car tracking?

Your car probably knows a lot more about you than it lets on – but is the trade-off of privacy for convenience truly justifiable?

BlackSuit ransomware – what you need to know
Finally! Facebook and Messenger are getting default end-to-end encryption. And not everyone is happy…
Smashing Security podcast #351: Nuclear cybersecurity, Marketplace scams, and face up to porn
See me talking about “Future-proofing enterprise cybersecurity for AI, vulnerabilities, and business risks”
Belgian man charged with smuggling sanctioned military tech to Russia and China
Australia building ‘top secret’ cloud to catch up and link with US, UK intel orgs
Apple and some Linux distros are open to Bluetooth attack
Locking down the edge
A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list
Shielding the data that drives AI
$10 million up for grabs in fight against North Korean hackers
Atlassian security advisory reveals four fresh critical flaws – in mail with dead links
Microsoft issues deadline for end of Windows 10 support – it’s pay to play for security
Cisco intros AI to find firewall flaws, warns this sort of thing can’t be free
Fancy Bear goes phishing in US, European high-value networks
3 security best practices for all DevSecOps teams
CISA details twin attacks on federal servers via unpatched ColdFusion flaw
DSPM deep dive: debunking data security myths
BlackCat ransomware crims threaten to directly extort victim’s customers
It’s ba-ack… UK watchdog publishes age verification proposals
Russian hacker pleads guilty to Trickbot malware conspiracy
UK government denies China/Russia nuke plant hack claim
US warns Iranian terrorist crew broke into ‘multiple’ US water facilities
Hershey phishes! Crooks snarf chocolate lovers’ creds
Supply-chain ransomware attack causes outages at over 60 credit unions
Two new versions of OpenZFS fix long-hidden corruption bug
Exposed Hugging Face API tokens offered full access to Meta’s Llama 2
EU lawmakers finalize cyber security rules that panicked open source devs
New Relic’s cyber-something revealed as attack on staging systems, some users

https://security-tracker.debian.org/tracker/DSA-5572-1

https://security-tracker.debian.org/tracker/DSA-5571-1

https://security-tracker.debian.org/tracker/DSA-5570-1

Teaching appropriate use of AI tech – Week in security with Tony Anscombe

Several cases of children creating indecent images of other children using AI software add to the worries about harmful uses of AI technology

Scores of US credit unions offline after ransomware infects backend cloud outfit
Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks
UEFI flaws allow bootkits to pwn potentially hundreds of devices using images
US readies prison cell for another Russian Trickbot developer
Regulator says stranger entered hospital, treated a patient, took a document … then vanished
Interpol makes first border arrest using Biometric Hub to ID suspect
Today’s ‘China is misbehaving online’ allegations come from Google, Meta
Not all cybercriminals are evil geniuses
Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes
Admin of $19M marketplace that sold social security numbers gets 8 years in jail
Okta data breach dilemma dwarfs earlier estimates
Very precisely lost – GPS jamming

The technology is both widely available and well developed, hence it’s also poised to proliferate – especially in the hands of those wishing ill

Ex-Motorola worker phished former employer to illegally hack network and steal data
Black Basta ransomware operation nets over $100M from victims in less than two years
Smashing Security podcast #350: Think before you shrink! And our guest is faked
Locking down Industrial Control Systems
Weak session keys let snoops take a byte out of your Bluetooth traffic
US lawmakers have Chinese LiDAR on their threat-detection radar
Rogue ex-Motorola techie admits cyberattack on former employer, passport fraud

https://security-tracker.debian.org/tracker/DSA-5569-1

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew
British Library begins contacting customers as Rhysida leaks data dump
UK government rings the death knell for SIM farms
Brit borough council apologizes for telling website users to disable HTTPS
Japan’s space agency suffers cyber attack, points finger at Active Directory
Plex gives fans a privacy complex after sharing viewing habits with friends by default
Trio of major holes in ownCloud expose admin passwords, allow unauthenticated file mods
iOS 17 NameDrop privacy scare: What you need to know
Helping companies defend what attackers want most – their data
Europol shutters ransomware operation with kingpin arrests
Securing the software supply chain webinar
A bird’s eye view of your global attack surface
India’s CERT given exemption from Right To Information requests
‘Serial cybercriminal and scammer’ jailed for 8 years, told to pay back $1.2M
The crazy world of ransomware
Why IT teams should champion AI in the workplace, and deploy secure AI tools safely to their teams
Ethyrial: Echoes of Yore hacked! 17,000 game accounts “lost”
Leader of pro-Russia DDoS crew Killnet ‘unmasked’ by Russian state media
Education is the foundation of modern cyber defence
Ransomware-hit British Library: Too open for business, or not open enough?
Crypto crasher Do Kwon’s extradition approved, but destination is unclear
Beijing fosters foreign influencers to spread its propaganda

https://security-tracker.debian.org/tracker/DSA-5567-1

https://security-tracker.debian.org/tracker/DSA-5568-1

Telekopye’s tricks of the trade – Week in security with Tony Anscombe

ESET’s research team reveals details about the onboarding process of the Telekopye scam operation and the various methods that the fraudsters use to defraud people online

https://security-tracker.debian.org/tracker/DSA-5566-1

https://security-tracker.debian.org/tracker/DSA-5564-1

https://security-tracker.debian.org/tracker/DSA-5563-1

https://security-tracker.debian.org/tracker/DSA-5565-1

Telekopye: Chamber of Neanderthals’ secrets

Insight into groups operating Telekopye bots that scam people in online marketplaces

OpenCart owner turns air blue after researcher discloses serious vuln
Cloud security and devops have work to do
$9 million seized from “pig butchering” scammers who preyed on lonely hearts
BlackCat claims it is behind Fidelity National Financial ransomware shakedown
Your voice is my password

AI-driven voice cloning can make things far too easy for scammers – I know because I’ve tested it so that you don’t have to learn about the risks the hard way.

Industry piles in on North Korea for sustained rampage on software supply chains