Menu

Gallery

45 million medical scans from hospitals all over the world left exposed online for anyone to view – some servers were laced with malware
SolarWinds: Hey, only as many as 18,000 customers installed backdoored software linked to US govt hacks
Ransomware masterminds claim to have nabbed 53GB of data from Intel’s Habana Labs
SolarWinds’ ‘breached by nation state spies’ software is in wide use throughout the British public sector
Ad blocking made Google throw its toys out of the pram – and now even more control is being taken from us
US Treasury, Dept of Commerce hacks linked to SolarWinds IT monitoring software supply-chain attack
Rogue ex-Cisco employee who crippled WebEx conferences and cost Cisco millions gets two years in US prison
Subway sandwich scam mystifies loyalty card users
British voyeur escapes US extradition over 770 cases of webcam malware
Subway email weirdness: Suspicion grows over apparent Trickbot trojan delivery campaign
Was there a “COVID-19 vaccine hack” against the European Medicines Agency?
Ad-scamming, login-stealing Windows malware is hitting Chrome, Edge, Firefox, Yandex browsers, says Microsoft
‘Malwareless’ ransomware campaign operators pwned 83k victims’ MySQL servers, 250k databases up for sale
The patch that wasn’t: Cisco emits fresh fixes for NTLM hash-spilling vuln and XSS-RCE combo in Jabber app
UK union pens letter to data watchdog on icky workplace monitoring systems like Microsoft’s Productivity Score
UK Ministry of Defence: We won’t prosecute bug bounty hunters – oh btw, we now have one of those
Google Chrome’s crackdown on ad blockers and browser extensions, Manifest v3, is now available in beta
South Korea kills ActiveX-based government digital certificate service
EU Medicines Agency hacked, BioNTech-Pfizer coronavirus vaccine paperwork stolen, probe launched
Using OPA for multicloud policy and process portability
Bitter war of words erupts between UK cops and web security expert over alleged flaws in Cyberalarm monitoring tool
Cybersecurity giant FireEye says it was hacked by govt-backed spies who stole its crown-jewels hacking tools
Patch Tuesday brings bug fixes for OpenSSL, IBM, SAP, Kubernetes, Adobe, and Red Hat. And Microsoft, of course
Court orders encrypted email biz Tutanota to build a backdoor in user’s mailbox, founder says ‘this is absurd’
Oblivious DoH, OPAQUE passwords, Encrypted Client Hello: Cloudflare’s protocol proposals to protect privacy
Vishing criminals let rip with two scams at once
Pure frustration: What happens when someone uses your email address to sign up for PayPal, car hire, doctors, security systems and more
Iran to issue license for national bug bounty program to clean up its code base
Cops raid home of ousted data scientist who created her own Florida COVID-19 dashboard
Kremlin hackers are right now exploiting security hole in VMware software to hijack systems, NSA warns
When is a remote-code-execution bug in Teams not an RCE? When Microsoft says it isn’t, flaw finder discovers
Channel Isles cop sacked after abusing police database to track down women drivers for Instagram ‘comic’ page
It’s not just the economy and bad management messing with Kmart – ransomware crews are there too
German divers find Enigma crypto machine on seabed
Travel agent leaked customer data by – this is embarrassing – giving it away in a hackathon
What if you could call on SANS experts for training that fits your schedule?
Protect your business from DDoS attacks: Join this webinar to find out more
It’s dark out there, and if you want to keep the lights on, you need to update your cyber-security skills with SANS
Crooks posing as COVID-19 ‘cold chain’ company phished EU for vaccine intel, says IBM
Android devs: If you’re using the Google Play Core Library, update it against this remote file inclusion CVE. Pronto
ACLU sues US govt, demands to know if agents are buying their way around warrants to track suspects’ smartphones
How a nightmare wormable, wireless, automatic hijack-a-nearby-iPhone security flaw was found and fixed
Hacker given three years for stealing secret Nintendo Switch blueprints, collecting child sex abuse vids
How to steal photos off someone’s iPhone from across the street
Ever had a bogus call from someone claiming to be the IRS? A tax scam ringleader just got sent down for 20 years
How the human immune system inspired a new approach to email security
As if Productivity Score wasn’t creepy enough, Microsoft has patented tech for ‘meeting quality monitoring devices’
Supreme Court mulls whether a cop looking up a license plate for cash is equivalent to watching Instagram at work
Cayman Islands investment fund left entire filestore viewable by world+dog in unsecured Azure blob
Yes, we’re all going to be at home for the foreseeable future. Does that leave you feeling insecure?
New study: DNS spoofing doubles in six years … albeit from the point of naff all
Forget Snow Day: Baltimore’s 115,000+ public school kids get Ransomware Day, must check Win PCs for infection
The CEO’s chuckling at their email… you better check your security defenses
Home Wi-Fi security tips – 5 things to check
Manchester United email servers remain offline amid what is being called a ‘ransomware’ attack
UK infoseccer launches petition asking government not to backdoor encryption
Bzzzzzzt! How safe is that keenly priced digital doorbell?
Privacy campaigner flags concerns about Microsoft’s creepy Productivity Score
Ticketmaster: We’re not liable for credit card badness because the hack straddled GDPR day
Google binned two apps by China’s Baidu, which says researchers got it wrong by linking it to personal info leaks
VMware urges sysadmins to apply workarounds after critical Workspace command execution vuln found
Gift card hack exposed – you pay, they play
Imagine things are bad enough that you need a payday loan. Then imagine flaws in systems of loan lead generators leave your records in the open… for years
Marketers for an Open Web ask UK competition watchdog to block launch of Google’s anti-tracking Privacy Sandbox
Crooks social-engineer GoDaddy staff into handing over control of crypto-biz domain names
Apple’s global security boss accused of bribing cops with 200 free iPads in exchange for concealed gun permits
Penetration testing isn’t enough, you need to activate full offensive operations
US Air Force deploys robot security dogs to guard base
No Xmas office party? Missing infosec pals and colleagues? Want to listen to DJs who also happen to be cyber warriors?
Head thumping, heart racing? Here’s how not to panic when you’re under cyber attack
Manchester United working with infosec experts to ‘minimize ongoing IT disruption’ caused by ‘cyber attack’
IBM Power9 processors beset by Cardiac Osprey data-leaking flaw as Spectre still haunts speculative chips
End to end encryption? In Android’s default messaging app? Don’t worry, nobody else noticed either
Facebook patches Messenger audio snooping bug – update now!
NCSC’s London HQ was chosen because GCHQ spies panicked at the prospect of grubby Shoreditch offices
UK reveals new ‘National Cyber Force’, announces Space Command and mysterious AI agency
You can protect the company from hackers, but can you protect the company from the CEO?
VMware reveals critical hypervisor bugs found at Chinese white hat hacking comp. One lets guests run code on hosts
In 2016 Australia’s online census failed. Preparations for the 2021 edition have been rated ‘partly effective’
US Senate approves deepfake bill to defend against manipulated media
AWS includes open-source Suricata for stateful inspection with Network Firewall service
Cyberup campaign: 80% of infosec pros fear they might fall foul of UK’s outdated Computer Misuse Act
Anti-adversarial machine learning defenses start to take root
Compsci guru wants ‘right to be forgotten’ for old email, urges Google and friends to expire, reveal crypto-keys
China-linked hacking gang ‘APT10’ named as probable actor behind extended attacks on Japanese companies
Heads up: A new strain of card-skimming Grelos malware is on the loose
How AI Is powering a new generation of cyber-attacks
The ones who brought you Let’s Encrypt, bring you: Tools for gathering anonymized app usage metrics from netizens
Test and Trace chief Dido Harding prompted to self-isolate by NHS COVID-19 app
No, the creator of cURL didn’t morph into Elon Musk and give away Bitcoins. But his hijacked Twitter page tried to
Trump fires cybersecurity boss Chris Krebs for doing his job: Securing the election and telling the truth about it
Israeli spyware maker NSO channels Hollywood spy thrillers in appeal for legal immunity in WhatsApp battle
Microsoft brings Trusted Platform Module functionality directly to CPUs under securo-silicon architecture Pluton
A visit to a crafted webpage would have been enough for a bad guy to munch all your Firefox for Android cookies
Legendary hacker and L0pht member Peiter Zatko joins Twitter as security chief
Apple’s privacy pledges: We sent dev checks over plain HTTP, logged IP addresses. We bypass firewall apps
End the year as you mean to go on… with world-class cyber-security training
Micropayments company Coil distributes new privacy policy with email that puts users’ addresses in the ‘To:’ field
Cult videogame company Capcom pays a big round $0.00 to ransomware crooks
Street Fighter maker says soz after ransomware hadoukens servers leaving 350,000 folks’ data at risk of compromise