Menu

Gallery

Razer to fix Windows installer that grants admin powers if you plug in a mouse
38 million records exposed by misconfigured Microsoft Power Apps. Redmond’s advice? RTFM
Worried ransomware merchants know more about file storage than you do? You should be…
What’s *THAT* on my 3D printer? Cloud bug lets anyone print to everyone
Facebook sat on report that reveals most-shared post for months was questionable COVID story
Japanese cryptocoin exchange robbed of $100,000,000
Cloud load balancer snafu leads to 3D printer user printing on a stranger’s kit
UK’s Surveillance Camera Commissioner grills Hikvision on China human rights abuses
Buyout of British defence supplier Ultra Electronics paused by UK.gov over competition concerns
S3 Ep46: Copyright scams, video snooping and Grand Theft Crypto [Podcast]
How to use Auth0 with Node.js and Express
After reportedly dragging its feet, BlackBerry admits, yes, QNX in cars, equipment suffers from BadAlloc bug
OK, so you stole $600m-plus from us, how about you be our Chief Security Advisor, Poly Network asks thief
Researchers find high-severity command injection vuln in Fortinet’s web app firewall
Un-carrier? Definitely Unsecure: T-Mobile US admits 48m customers’ details stolen after downplaying reports
China orders annual security reviews for all critical information infrastructure operators
Apple says its CSAM scan code can be verified by researchers. Corellium starts throwing out dollar bills
Video surveillance network hacked by researchers to hijack footage
If you haven’t updated your ThroughTek DVR since 2018 do so now, warns Mandiant as critical vuln surfaces
The cloud changes the game for cybersecurity incident response – here’s how to master the new rules
British defence supplier Ultra Electronics to be sold for £2.6bn to US-controlled firm
Pakistan’s tax office services go dark after migration project goes awry
Remote code execution flaws lurk in countless routers, IoT gear, cameras using Realtek Wi-Fi module SDKs
T-Mobile US probes claims of 100m stolen customer records up for sale on dark web
Copyright scammers turn to phone numbers instead of web links
Dallas cops lost 8TB of criminal case data during bungled migration, says the DA… four months later
Apple’s iPhone computer vision has the potential to preserve privacy but also break it completely
I was offered $500k as a thank-you bounty for pilfering $600m from Poly Network, says crypto-thief
Fancy joining the SAS’s secret hacker squad in Hereford as an electronics engineer for £33k?
Before I agree to let your app track me everywhere, I want something ‘special’ in return (winks)…
United Nations calls for moratorium on sale of surveillance tech like NSO Group’s Pegasus
Re-volting: AMD Secure Encrypted Virtualization undone by electrical attack
China stops networked vehicle data going offshore under new infosec rules
FISMA’s a fizzer, says Cisco, and calls on Congress to get cyber security policy right – pronto
Huawei stole our tech and created a ‘backdoor’ to spy on Pakistan, claims IT biz
GitHub picks Friday 13th to kill off password-based Git authentication
US govt scores a point against Assange in run-up to extradition appeal showdown
Think your backups will protect you against ransomware? They’re top of the target list
Lockbit ransomware attack didn’t affect ops, claims Accenture amid lurid payoff rumours
S3 Ep45: Routers attacked, hacking tool hacked, and betrayers betrayed [Podcast]
COVID-19 cases surge as do sales of fake vaccination cards – around $100 for something you could get free
Singaporean telco leaked personal data of over 57,000 customers
Thief hands back at least a third of $600m in crypto-coins stolen from Poly Network
Hacker grabs $600m in cryptocash from blockchain company Poly Networks
Microsoft responds to PrintNightmare by making life that little bit harder for admins
Chinese espionage group targets Israel while suggesting the source could be Iran
Avast, ye takeover lawyers! Norton LifeLock to acquire security rival
Boffins propose Pretty Good Phone Privacy to end pretty invasive location data harvesting by telcos
$600m in cryptocurrencies swiped from Poly Network servers after security snafu
Microsoft Patch Tuesday bug drought: No, it’s not climate change or unexpected code quality improvements
Home and small business routers under attack – how to see if you are at risk
Solving authorization for software developers
We’ll drop SBOMs on UK.gov to solve Telecoms Security Bill’s technical demands, beams Cisco
Splunk spots malware targeting Windows Server on AWS to mine Monero
Apple responds to critics of CSAM scan plan with FAQs – says it’d block governments subverting its system
Black Hat security conference returns to Las Vegas – complete with hacks to quiet the hotel guest from hell
S3 Ep44: Unreported holes, retro computing, and tech support for malware [Podcast]
All your DNS were belong to us: AWS and Google Cloud shut down spying vulnerability
Conti ransomware affiliate goes rogue, leaks “gang data”
South Korea to test grenade-launching drones
Microsoft wonders if disabling just-in-time compilation of JavaScript improves browser security
America enlists Big Tech to help it develop and execute cyber security plans
US ‘dropped the ball’ on security by going it alone claims Huawei US CSO
Apple is about to start scanning iPhone users’ devices for banned content, warns professor
“Cobalt Strike” network attack tool patches crashtastic server bug
Got a cheap Cisco router in your home office? If it’s one of these, there’s an exposed RCE hole you need to plug
Das tut mir leid! Germany’s ruling party sorry for calling cops on researcher after she outed canvassing app flaws
Not all authentication is created equal – and that’s a good thing
Worried your data protection strategy is dated? Don’t let a ransomware infection prove you right
SolarWinds urges US judge to toss out crap infosec sueball: We got pwned by actual Russia, give us a break
Google: Linux kernel and its toolchains are underinvested by at least 100 engineers
UK data watchdog sees its approach to government health tech during COVID-19 outbreak as ‘pragmatic’
Legacy EDR. Yes, it’s a thing
Russia tells UN it wants vast expansion of cybercrime offenses, plus network backdoors, online censorship
Do you have a grip on the lifecycle security of your AWS-deployed applications?
BazarCaller – the malware gang that talks you into infecting yourself
UK’s Ministry of Defence coughs up bug bounties for crowdsourced pentesting
Shopping for execs: ID management biz Okta poaches Google’s veep of engineering to run product dev activities
Research finds cyber-snoops working for ‘Chinese state interests’ lurking in SE Asian telco networks since 2017
Credit-card-stealing, backdoored packages found in Python’s PyPI library hub
Nuisance call-blocking firm fined £170,000 for making almost 200,000 nuisance calls
PwnedPiper vulns have potential to turn Swisslog’s PTS hospital products into Swiss cheese, says Armis
Huawei to America: You’re not taking cyber-security seriously until you let China vouch for us
Zoom agrees to pay subscribers $25 to put its security SNAFUs behind it
Sysadmins: Why not simply verify there’s no backdoor in every program you install, and thus avoid any cyber-drama?
Here’s 30 servers Russian intelligence uses to fling malware at the West, beams RiskIQ
S3 Ep43: Apple 0-day, pygmy hippos, hive nightmares and Twitter hacker bust [Podcast]
Malware and Trojans, but there’s only one horse the boss man wants to hear about
We can’t believe people use browsers to manage their passwords, says maker of password management tools
Spam is Chipotle’s secret ingredient: Marketing email hijacked to dish up malware
Upcoming Android privacy changes include ability to blank advertising ID, and ‘safety section’ in Play store
Israeli authorities investigate NSO Group over Pegasus spyware abuse claims
Here’s a list of the flaws Russia, China, Iran and pals exploit most often, say Five Eyes infosec agencies
‘Woefully insufficient’: Biden administration’s assessment of critical infrastructure infosec protection
Over 100 Taiwanese political figures’ messages leaked outta LINE app
Microsoft researcher found Apple 0-day in March, didn’t report it
Security breaches where working from home is involved are costlier, claims IBM report
Iranian state-backed hackers posed as flirty Scouser called Marcy to target workers in defence and aerospace
UK’s National Cyber Security Centre needs its posh Westminster digs, says Cabinet Office, because of WannaCry
Google revamps bug bounty program