Menu

Latest articles

Pro-China campaign targeted YouTube with AI avatars
New iOS feature to thwart eavesdropping – Week in security with Tony Anscombe

Your iPhone has just received a new feature called iMessage Contact Key Verification that is designed to help protect your messages from prying eyes

https://security-tracker.debian.org/tracker/DSA-5576-2

https://security-tracker.debian.org/tracker/DSA-5578-1

Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned
Kraft Heinz suggests we simmer down about Snatch ransomware attack claims
Gang charged with running $80 million “pig butchering” cryptocurrency investment scam
NKabuse backdoor harnesses blockchain brawn to hit several architectures
InfoWorld’s 2023 Technology of the Year Award winners
To BCC or not to BCC – that is the question data watchdog wants answered
Microsoft seizes websites used to sell phony email accounts to Scattered Spider and other crims

https://security-tracker.debian.org/tracker/DSA-5577-1

Prison for man who wiped bank’s data after being fired for accessing porn in the office
Smashing Security podcast #352: For research purposes only
Hackers exploit Google Forms to trick users into falling for call-back phishing attack
Russia joins North Korea in sending state-sponsored cyber troops to pick on TeamCity users
Money-grubbing crooks abuse OAuth – and baffling absence of MFA – to do financial crimes
Fortifying confidential computing in Microsoft Azure
Surprise! Email from personal. information.reveal@gmail.com is not going to contain good news
The SANS Holiday Hack Challenge is back!
UK’s Ministry of Defence fined after Bcc email blinder that put the lives of Afghan citizens at risk
Black Hat Europe 2023: Should we regulate AI?

ChatGPT would probably say “Definitely not!”, but will we learn any lessons from the rush to regulate IoT in the past?

Learning the safety language of the cloud
Nearly a million non-profit donors’ details left exposed in unsecured database
Cyber security isn’t simple, but it could be
Think tank report labels NSO, Lazarus as ‘cyber mercenaries’
Final Patch Tuesday of 2023 goes out with a bang

https://security-tracker.debian.org/tracker/DSA-5576-1

https://security-tracker.debian.org/tracker/DSA-5575-1

https://security-tracker.debian.org/tracker/DSA-5574-1

Cloud engineer wreaks havoc on bank network after getting fired
Discord in the ranks: Lone Airman behind top-secret info leak on chat platform
Kelvin Security cybercrime gang suspect seized by Spanish police
Northern Ireland cops count human cost of August data breach
BlackBerry squashes plan to spin out its IoT biz
Interpol moves against human traffickers who enslave people to scam you online
Proposed US surveillance regime would enlist more businesses
2.5M patients infected with data loss in Norton Healthcare ransomware outbreak
Memory-safe languages so hot right now, agrees Lazarus Group as it slings DLang malware
Two years on, 1 in 4 apps still vulnerable to Log4Shell
Read the clouds, reduce the cyber risk
23andMe responds to breach with new suit-limiting user terms
VictoriaMetrics takes organic growth over investor pressure
Surge in deceptive loan apps – Week in security with Tony Anscombe

ESET Research reveals details about a growth in the number of deceptive loan apps on Android, their origins and modus operandi

Black Hat Europe 2023: The past could return to haunt you

Legacy protocols in the healthcare industry present dangers that can make hospitals extremely vulnerable to cyberattacks.

To tap or not to tap: Are NFC payments safer?

Contactless payments are quickly becoming ubiquitous – but are they more secure than traditional payment methods?

Hollywood plays unwitting Cameo in Kremlin plot to discredit Zelensky

https://security-tracker.debian.org/tracker/DSA-5573-1

Competing Section 702 surveillance bills on collision path for US House floor
Meta releases open-source tools for AI safety
That call center tech scammer could be a human trafficking victim
UK and US expose Russian hacking plot intended to influence UK’s 2019 elections and spread disinformation
Zero trust security with a hardware root of trust
Polish train maker denies claims its software bricked rolling stock maintained by competitor
Five Eyes nations warn Moscow’s mates at the Star Blizzard gang have new phishing targets
Attacks abuse Microsoft DHCP to spoof DNS records and steal secrets
US and EU infosec authorities pen intel-sharing pact
Navigating privacy: Should we put the brakes on car tracking?

Your car probably knows a lot more about you than it lets on – but is the trade-off of privacy for convenience truly justifiable?

BlackSuit ransomware – what you need to know
Finally! Facebook and Messenger are getting default end-to-end encryption. And not everyone is happy…
Smashing Security podcast #351: Nuclear cybersecurity, Marketplace scams, and face up to porn
See me talking about “Future-proofing enterprise cybersecurity for AI, vulnerabilities, and business risks”
Belgian man charged with smuggling sanctioned military tech to Russia and China
Australia building ‘top secret’ cloud to catch up and link with US, UK intel orgs
Apple and some Linux distros are open to Bluetooth attack
Locking down the edge
A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list
Shielding the data that drives AI
$10 million up for grabs in fight against North Korean hackers
Atlassian security advisory reveals four fresh critical flaws – in mail with dead links
Microsoft issues deadline for end of Windows 10 support – it’s pay to play for security
Cisco intros AI to find firewall flaws, warns this sort of thing can’t be free
Fancy Bear goes phishing in US, European high-value networks
3 security best practices for all DevSecOps teams
CISA details twin attacks on federal servers via unpatched ColdFusion flaw
DSPM deep dive: debunking data security myths
BlackCat ransomware crims threaten to directly extort victim’s customers
It’s ba-ack… UK watchdog publishes age verification proposals
Russian hacker pleads guilty to Trickbot malware conspiracy
UK government denies China/Russia nuke plant hack claim
US warns Iranian terrorist crew broke into ‘multiple’ US water facilities
Hershey phishes! Crooks snarf chocolate lovers’ creds
Supply-chain ransomware attack causes outages at over 60 credit unions
Two new versions of OpenZFS fix long-hidden corruption bug
Exposed Hugging Face API tokens offered full access to Meta’s Llama 2
EU lawmakers finalize cyber security rules that panicked open source devs
New Relic’s cyber-something revealed as attack on staging systems, some users

https://security-tracker.debian.org/tracker/DSA-5572-1

https://security-tracker.debian.org/tracker/DSA-5571-1

https://security-tracker.debian.org/tracker/DSA-5570-1

Teaching appropriate use of AI tech – Week in security with Tony Anscombe

Several cases of children creating indecent images of other children using AI software add to the worries about harmful uses of AI technology

Scores of US credit unions offline after ransomware infects backend cloud outfit
Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks
UEFI flaws allow bootkits to pwn potentially hundreds of devices using images
US readies prison cell for another Russian Trickbot developer
Regulator says stranger entered hospital, treated a patient, took a document … then vanished
Interpol makes first border arrest using Biometric Hub to ID suspect
Today’s ‘China is misbehaving online’ allegations come from Google, Meta
Not all cybercriminals are evil geniuses
Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes