Menu

Gallery

UK Computer Misuse Act convictions declined last year despite pandemic explosion in online criminal activity
Here’s how we got persistent shell access on a Boeing 747 – Pen Test Partners
Google’s ‘Ask me anything’ on Privacy Sandbox was more about questions than answers
In search of good cybersecurity
Doncaster insurance firm One Call hit by not-dead-at-all Darkside ransomware gang
Toyota rear-ended by twin cyber attacks that left ransomware-shaped dents
S3 Ep33: Eufy camera leak, Afterburner crisis, and AirTags (again) [Podcast]
UK data regulator fines American Express up to 0.021p per email after opted-out folk spammed 4.1 million times
Regulator fines COVID-19 tracker for turning contact data into sales leads
Miscreants started scanning for Exchange Hafnium vulns five minutes after Microsoft told world about zero-days
Uptime funk: Microsoft has lifted availability of Azure Key Vault to 99.99%
Australian Federal Police hiring digital evidence retrieval specialists: Being a very good boy and paws required
The Microsoft Authenticator extension in the Chrome store wasn’t actually made by Microsoft. Oops, Google
New Zealand hospitals infected by ransomware, cancel some surgeries
Us? Pwn SolarWinds? With our reputation? Russian spy chief makes laughable denial of supply chain attack
Business-intelligence-company-turned-Bitcoin-addict MicroStrategy grabs another $10m crypto-coin fix
The UK loves cybersecurity so much, it’s going to regulate managed service providers’ infosec practices in law
1Password unsheathes Rusty key, hopes to unlock Linux Desktop world
Latest phones are great at thwarting Wi-Fi tracking. Other devices, not so much – study
Eufycam Wi-Fi security cameras streamed video feeds from other people’s homes
Axa insurance offshoots pwned as Ireland reveals second ransomware hit
“Those aren’t my kids!” – Eufy camera owners report video mixups
We’d love to report on the outcome of the CREST exam cheatsheet probe, but UK infosec body won’t publish it
7 keys to selecting a low-code platform
Mammoth grab of GP patient data in the UK set to benefit private-sector market access as rules remain unchanged
Apple sent my data to the FBI, says boss of controversial research paper trove Sci-Hub
Singapore bolsters Bluetooth contact-tracing as new COVID wave sends students and workers home again
China signals dissatisfaction with gig economy impact on ride-share drivers
Apple AirTag hacked again – free internet with no mobile data plan!
Free SANS Cyber Security Summits: Sign up now, learn online, keep your network safe
Tor users, beware: ‘Scheme flooding’ technique may be used to deanonymize you
Hospitals cancel outpatient appointments as Irish health service struck by ransomware
NHS-backed org reacted to GitHub leak disclosure with legal threats and police call, complains IT pro
Don’t migrate your problems to the cloud
Cloudflare launches campaign to ‘end the madness’ of CAPTCHAs
Gamers beware! Crooks take advantage of MSI download outage…
Ransomware victim Colonial Pipeline paid $5m to get oil pumping again, restored from backups anyway – report
S3 Ep32: AirTag jailbreak, Dell vulns, and a never-ending scam [Podcast]
Colonial Pipeline was looking to hire cybersecurity manager before ransomware attack shut down operations
Oops, says Manchester City Council after thousands of number plates exposed in parking ticket spreadsheet
When it comes to cybersecurity, there’s always time for summer school or winter training
Apple’s Find My network can be abused to leak secrets to the outside world via passing devices
Happy to pay out to ransomware masterminds? Yup, we thought so
Tempted by cryptocoins? Fake trading apps get personal…
Britain to spend £22m influencing Indo-Pacific nations’ cybersecurity policies against ‘authoritarian regimes’
Blessed are the cryptographers, labelling them criminal enablers is just foolish
Beijing twirls ban-hammer at 84 more apps it says need to stop slurping excess data
South Korea orders urgent review of energy infrastructure cybersecurity
Tech industry quietly patches FragAttacks Wi-Fi flaws that leak data, weaken security
SolarWinds CEO describes overhauled Orion build system after that ‘very small, unique’ security breach
Microsoft emits more fixes for Exchange Server plus patches for remote-code exec holes in HTTP stack, Visual Studio
UK’s Computer Misuse Act to be reviewed, says Home Secretary as she condemns ransomware payoffs
NHS App gets go-ahead for vaccine passport use despite protest from privacy groups
App Tracking: Apps plead for users to press allow, but 85% of Apple iOS consumers are not opting in
Apple AirTag jailbroken already – hacked in rickroll attack
Compsci boffin publishes proof-of-concept code for 54-year-old zero-day in Universal Turing Machine
Train operator phlunks phishing test by teasing employees with non-existent COVID bonus
Tencent research team scores free powerups for electric cars with Raspberry Pi-powered X-in-the-middle attack
Indian government says 5G doesn’t cause COVID-19. Also points out India has no 5G networks
Trend Micro hosted email service is down, inboxes still stuck in cloudy limbo
Never say never! Warren Buffett caught up in integer overflow error…
Kubecon 2021: A largely dry and corporate affair where the best bits involved a spot of Kubernetes-hacking roleplay
Uncle Sam wants ‘ethical hackers’ to crack its planetary defenses, but don’t expect a pay-day from this bug bounty
Namecheap hosted 25%+ of fake UK govt phishing sites last year – NCSC report
US declares emergency after ransomware shuts oil pipeline that pumps 100 million gallons a day
Russian cyber-spies changed tactics after the UK and US outed their techniques – so here’s a list of those changes
Privacy activist Max Schrems on Microsoft’s EU data move: It won’t keep the NSA away
When not to use edge computing
Cisco HyperFlex web interface has critical flaw that lets attackers get root and execute arbitrary commands
Kids in Hong Kong and other highly surveilled states worry infosec careers are just asking for trouble
Google Play to require privacy labels on apps in 2022, almost two years after Apple
Google will make you use two-step verification to login
Vulnerability in Snapdragon 855 SoCs could pwn Android modems, allow baddies to snoop on conversations
S3 Ep31: Apple zero-days, Flubot scammers and PHP supply chain bug [Podcast]
Firefox for Android gets critical update to block cookie-stealing hole
Crane horror Reg reader uses his severed finger to unlock Samsung Galaxy phone
Chrome on Windows turns on Intel, AMD chip-level defenses against malicious websites
JET engine flaws can crash Microsoft’s IIS, SQL Server, say Palo Alto researchers
21 nails in Exim mail server: Vulnerabilities enable ‘full remote unauthenticated code execution’, millions of boxes at risk
East London council blurts thousands of residents’ email addresses in To field blunder
Dell fixes exploitable holes in its own firmware update driver – patch now!
Twilio’s private GitHub repositories cloned by Codecov attacker, cloud comms platform confirms
What not to expect when you’re expecting: Fertility apps may be selling intimate health secrets
‘Millions’ of Dell PCs will grant malware, rogue users admin-level access if asked nicely
Red Hat open-sources StackRox Kubernetes security product
Apple products hit by fourfecta of zero-day exploits – patch now!
Apple patches iOS, macOS, iPadOS, watchOS, kitchen-sinkOS bugs said to be exploited in the wild
Naked Security Live – Beware ‘Flubot’: the home delivery scam with a difference
Bill to protect UK against harmful foreign investment becomes law
PHP community sidesteps its third supply chain attack in three years
Happy Friday? Darktrace gets 40 per cent boost on London IPO debut
Australia proposes teaching cyber-security to five-year-old kids
Stealthy Linux backdoor malware spotted after three years of minding your business
BadAlloc: Microsoft looked at memory allocation code in tons of devices and found this one common security flaw
Vivaldi update unleashes the ‘Cookie Crumbler’ to simply block any services asking for consent (sites may break)
S3 Ep30: AirDrop worries, Linux pests and ransomware truths [Podcast]
Billions in data protection lawsuits rides on Google’s last-ditch UK Supreme Court defence for Safari Workaround sueball
48 ways you can avoid file-scrambling, data-stealing miscreants – or so says the Ransomware Task Force
When you’re building a cybersecurity pro, you need to get the foundations right
Digital Ocean springs a leak: Miscreant exploits hole to peep on unlucky customers’ billing details for two weeks