Menu

Gallery

Ransomware crooks who broke into Merseyrail used director’s email address to brag about it – report
Gamers update! Nvidia patches GPU driver kernel escalation bugs
Brit MPs and campaigners come together to oppose COVID status certificates as ‘divisive and discriminatory’
Here’s what Russia’s SVR spy agency does when it breaks into your network, says US CISA infosec agency
Ransomware: don’t expect a full recovery, however much you pay
Washington DC police force confirms data breach after ransomware upstart Babuk posts trophies to Tor blog
Patched Exchange to head off Hafnium? You might only be halfway to safety
HashiCorp reveals exposure of private code-signing key after Codecov compromise
Security vendor Proofpoint snapped up by private equity for $12.3bn but still in search of profit
Naked Security Live – Just how (un)safe is AirDrop?
Scam victims find same fraudulent ads lurking on Facebook and Google even after flagging them up
Ethics isn’t a county east of London, but it’s the only way to look at security
GCHQ boss warns China can rewrite ‘the global operating system’ in its own authoritarian image
Cloud security threats are growing – crucially, is your skills toolkit keeping pace?
India orders takedowns of social media posts it claims harm fight against raging COVID-19 outbreak
Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs
Homebrew fixes Cask repo GitHub Actions bug that would have let anyone sneak malicious code onto machines
Volunteer-run pirate Manga website attacked, loses hashed passwords, has ‘nobody’ to fix the mess
Computer security world in mourning over death of Dan Kaminsky, aged 42
Apple AirDrop has “significant privacy leak”, say German researchers
3 cloud architecture mistakes we all make, but shouldn’t
If you have a QNAP NAS, stop what you’re doing right now and install latest updates. Do it before Qlocker gets you
US aviation regulator warns of mid-air collision risk if Garmin TCAS boxes are not updated
Linux team in public bust-up over fake “patches” to introduce bugs
S3 Ep29: Anti-tracking, rowhammer problems and IoT vulns [Podcast]
MI5 wants to shed its cocktail-guzzling posho image – so it’s opened an Instagram account
Apple, you’ve AirDrop’d the ball: Academics detail ways to leak contact info of nearby iThings for spear-phishing
Asian buyers set for security spending spree to catch up on shabby strategies
Signal app’s Moxie says it’s possible to sabotage Cellebrite’s phone-probing tools with booby-trapped file
Do you expect me to talk? Yes, Mr Bond, I expect you to reply: 10k Brits targeted on LinkedIn by Chinese, Russian spies
Apple supplier Quanta Computer confirms it’s fallen victim to ransomware attack
UK.gov wants mobile makers to declare death dates for their new devices from launch
Half of Q1’s malware traffic observed by Sophos was TLS encrypted, hiding inside legit requests to legit services
When cryptography attacks – how TLS helps malware hide in plain sight
REvil ransomware gang claims it stole top-secret tech designs – including Apple lappies – from Quanta Computer
Your cloud security is static – and you’re open to more risk than you realize
Japan accuses Chinese military of cyber-attacks on its space agency
China broke into govt, defense, finance networks via zero-day in Pulse Secure VPN gateways? No way
Would be so cool if everyone normalized these pesky data leaks, says data-leaking Facebook in leaked memo
Firefox 88 patches bugs and kills off a sneaky JavaScript tracking trick
LinkedIn was vector for 10,000 hostile state recruiting efforts against Brits, warns MI5
We need to talk about criminal adversaries who want you to eat undercooked onion rings
Bank of England ponders minting ‘Britcoin’ to sit alongside the Pound
Who knew Uncle Sam had strike teams for SolarWinds, Exchange flaws? Well, anyway, they are disbanded
WordPress core contributor proposes treating Google FLoC as a security vulnerability
Won’t somebody please think of the children!!! UK to mount fresh assault on end-to-end encryption in Facebook
Codecov dev tool warns of stolen credentials from compromised script, undiscovered for two months
Sysadmin for FIN7 criminal cracking group gets 10 years in US prison for managing card slurping malware scam
Naked Security Live – To hack or not to hack?
Serious Security: Rowhammer is back, but now it’s called SMASH
Brit authorities could legally do an FBI and scrub malware from compromised boxen without your knowledge
Pakistan cut off Facebook, Twitter, WhatsApp, and Telegram – for just four hours
Russian infosec firm Positive Technologies trying to stay positive after US sanctions
Microsoft received almost 25,000 requests for consumer data from law enforcement over the last six months
S3 Ep28.5: Hacking back – is attack an acceptable form of defence? [Podcast]
Watchdog thinks Google tricked Australians into giving up data, sues. Judge semi-agrees
Mobile app security standard for IoT, VPNs proposed by group backed by Big Tech
It was Russia wot did it: SolarWinds hack was done by Kremlin’s APT29 crew, say UK and US
University of Hertfordshire pulls the plug on, well, everything after cyber attack
S3 Ep28: Pwn2Own hacks, dark web hitmen and COVID-19 privacy [Podcast]
Is it still possible to run malware in a browser using JavaScript and Rowhammer? Yes, yes it is (slowly)
Nigerian email scammer sent down for 40 months in the US, ordered to pay back $2.7m to victims
Report: Aussie biz Azimuth cracked San Bernardino shooter’s iPhone, ending Apple-FBI privacy standoff
What the FLoC? Browser makers queue up to decry Google’s latest ad-targeting initiative as invasive tracking
Chrome and Chromium updated after yet another exploit is found in browser’s V8 JavaScript engine
FBI hacks into hundreds of infected US servers (and disinfects them)
Spy agency GCHQ told me Gmail’s more secure than Microsoft 365, insists British MP as facepalming security bods tell him to zip it
FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins
Google Sites blight: Over 100,000 web pages for business form searches overrun with backdoor RATs
1Password targets developers with Secrets Automation, acquisition of SecretHub
NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches
IoT bug report claims “at least 100M devices” may be impacted
Cracked copies of Microsoft Office and Adobe Photoshop steal your session cookies, browser history, crypto-coins
Average convicted British computer criminal is young, male, not highly skilled, researcher finds
Want to turbo-charge your cybersec skills? It’s time to put yourself on the SPOT
Apple and Google block official UK COVID-19 app update
Mike Lynch-backed Darktrace to file for London IPO in aftermath of Deliveroo flop
Naked Security Live – How to spot “government” scammers
Stuxnet sibling theory surges after Iran says nuke facility shut down by electrical fault
United States’ plan to beat China includes dominating tech standards groups – especially for 5G
Texan’s alleged Amazon bombing effort fizzles: Militia man wanted to take out ‘about 70 per cent of the internet’
Pwn2Own 2021: Zoom, Teams, Exchange, Chrome and Edge “fully owned”
UK’s National Cyber Security Centre recommends password generation idea suggested by El Reg commenter
CyberBattleSim: Microsoft’s open-source Holodeck in which autonomous attackers, defenders battle it out
How do we stamp out the ransomware business model? Ban insurance payouts for one, says ex-GCHQ director
India uses controversial Aadhaar facial biometrics to identify COVID vaccination recipients
Italian charged with hiring “dark web hitman” to murder his ex-girlfriend
S3 Ep27: Census scammers, beg bounties and data breach fines [Podcast]
Belgian police seize 28 tons of cocaine after ‘cracking’ Sky ECC’s chat app encryption
What is unified policy as code, and why do you need it?
There’s a whole wide world of web application firewall options – so how do you choose the right one?
Indian defense chief admits China’s cyber-weapons would ‘disrupt large number of systems’ whenever Beijing presses the button
Another supply-chain attack? Android maker Gigaset injects malware into victims’ phones via poisoned update
Update on PHP source code compromise: User database leak suspected
Cybercrooks targeting UK organisations started 2020 strong only for attacks to wither away by Christmas
Atheists appeal to higher power for intercession over alleged sins against privacy
Too slow! Booking.com fined for not reporting data breach fast enough
SAP: It takes exploit devs about 72 hours to turn one of our security patches into a weapon against customers
Their ‘next job could be in cyber’: UK Cyber Security Council launches itself by pointing world+dog to domain it doesn’t own
What is operations-centric security?