Menu

Gallery

Phishing tricks – the Top Ten Treacheries of 2020
Old and busted: Targeting servers and web bugs. New hotness: Pwning devs with targeted poisoned stacks
Facebook to blab bugs it finds if it thinks code owners aren’t fixing fast enough
Surprise! Voting app maker roasted by computer boffins for poor security now begs US courts to limit flaw finding
When classes are online, how do you get out of school? Florida teen cuffed, charged after crashing cyber-lessons
Sigh. Another day, another reason for WordPress users to get patching: Hackers abuse bug in popular plugin
Vishing scams use Amazon and Prime as lures – don’t get caught!
US court deems NSA bulk phone-call snooping illegal, possibly unconstitutional, and probably pointless anyway
Homeland Security demands a 911 for reporting security holes in federal networks: ‘Vulns in internet systems cause real-world impacts’
Phishing scam uses Sharepoint and One Note to go after passwords
Things are getting back to normal: Chinese hackers revert to bugging Tibetans after brief Euro campaign
Samsung supremo Lee Jae-yong indicted for fraud over role in 2015 merger deal that made him heir apparent
Someone’s getting a free trip to the US – well, not quite free. Brit bloke extradited to face $2m+ cyber-scam charges
Critical vuln that lets miscreants hijack computers via Slack? *Sucks in air* We’ll give you $1,750 for it
Microsoft reprieves SHA-1 deprecation in Edge 85 security baseline
The five best Kubernetes security practices
Before you head off for the weekend, you have patched your Pulse Secure VPNs, right? Wouldn’t want you to be pwned via a phishing link
Fake Android notifications – first Google, then Microsoft affected
Southern Water customers could view others’ personal data by tweaking URL parameters
BeagleBoyz: 2020’s hottest country-rap band, or N. Korea hackers stealing millions. Only one way to find out…
Russian cybercrime suspect arrested in $1m ransomware conspiracy
‘My wife tried to order some clothes tonight. When she logged in, she was in someone else’s account … Now someone’s charged her card’
DDoS downs New Zealand stock exchange for third consecutive day
Forget your space-age IT security systems. It might just take a $1m bribe and a willing employee to be pwned
Here’s a neat exploit to trick someone into inadvertently emailing their files to you from their Mac, iPhone via Safari
“Chrome considered harmful” – the Law of Unintended Consequences
Researchers shine light on hackers-for-hire op that hit estate agent with malicious plugin for Autodesk 3ds Max
US election 2020: The disinfo operations have evolved, but so have state governments
Impersonating users of ‘protest’ app Bridgefy was as simple as sniffing Bluetooth handshakes for identifiers
Be very afraid! British Army might scrap battle tanks for keyboard warriors – report
North Korean hackers pwned cryptocurrency sysadmin with GDPR-themed LinkedIn lure, says F-Secure
The Viking Snowden: Denmark spy chief ‘relieved of duty’ after whistleblower reveals illegal snooping on citizens
Canadian shipping company Canpar gets an unwanted delivery – ransomware
Bletchley Park Trust can’t crack COVID-caused revenue slump without losing staff
Utes gotta be kidding me… University of Utah handed $457K to ransomware creeps
Outlook “mail issues” phishing – don’t fall for this scam!
CREST exam cheat-sheet scandal: New temp chairman at UK infosec body as lawyers and ex-copper get involved
Using AI to fight hand-crafted Business Email Compromise
Shared memory vulnerability in IBM’s Db2 database could let nefarious insiders wreak havoc – so get patching
Physical locks are less hackable than digital locks, right? Maybe not: Boffins break in with a microphone
Ex-Uber chief security officer charged, accused of covering up theft of personal info from databases by hackers
Experian says it recovered and deleted data on 24 million South Africans after giving it to random ‘marketing’ person
Warehouse management software biz SnapFulfil hit by ransomware: It’s not just the big dogs getting KO’d
Sloppy string sanitization sabotages system security of millions of Java-powered 3G IoT kit: Patch me if you can
Thanks for the memories… now pay up or else: Maze ransomware crew claims to have hacked SK hynix, leaks ‘5% of stolen files’
Floating COVID incubation tank becomes data-leaking ransomware rustbucket: Carnival admits crims made off with personal data booty
Pretty wild that a malicious mailto: link might attach your secret keys and files from your PC to an outgoing message
US senators: WikiLeaks ‘likely knew it was assisting Russian intelligence influence effort’ in 2016 Dem email leak
US liquor giant hit by ransomware – what the rest of us can do to help
Cloudops tool integration is more important than the tools themselves
Please stop hard-wiring AWS credentials in your code. Looking at you, uni COVID-19 track-and-test app makers
CREST cancels UK infosec accreditation exams after fresh round of ‘cheat sheets’ are leaked online
Monday review – catch up on our latest articles and videos
Reply-All storm sparked by student smut sees school system shut down Google Classroom for up to a week
Feds seize ‘largest ever’ haul of crypto-dosh from terrorists – including coins from ‘fake’ pandemic mask web store
Microsoft Defender casts a jaundiced eye over Citrix, slams services in quarantine on suspicion of being malware
Oracle and Salesforce targeted in €10bn GDPR lawsuit backed by profit-making litigation fund
CREST: We are investigating NCC Group certification cheat sheet scandal – and not with NCC personnel
Australian government wants power to run cyber-response for businesses under attack
This NSA, FBI security advisory has four words you never want to see together: Fancy Bear Linux rootkit
Vivaldi composes sweet ad-blocking symphony for users of browser’s Android version
Tor and anonymous browsing – just how safe is it?
You weren’t hacked because you lacked space-age network defenses. Nor because cyber-gurus picked on you. It’s far simpler than that
Irony, thy name is SANS: 28k records nicked from infosec training org after staffer’s email account phished
If you haven’t yet patched this critical hole in SAP NetWeaver Application Server, today is not your day
This is node joke. Tor battles to fend off swarm of Bitcoin-stealing evil exit relays making up about 25% of outgoing capacity at its height
Citrix warns of patch-ASAP-grade bugs in its working-from-home products, just as we’re all working from home
We spent way too long on this Microsoft, Intel, Adobe, SAP, Red Hat Patch Tuesday article. Just click on it, pretend to read it, apply updates
Facial recognition – another setback for law enforcement
NCC Group admits its training data was leaked online after folders full of Crest pentest certification exam notes posted to Github
Police face-recog tech use in Welsh capital of Cardiff was unlawful – Court of Appeal
China now blocking ESNI-enabled TLS 1.3 connections, say Great-Firewall-watchers
Peer-to-peer takes on a whole new meaning when used to spy on 3.7 million or more cameras, other IoT gear
Brit bank Barclays probed amid claims bosses used high-tech to spy on staff, measure productivity
Pen Test Partners: Boeing 747s receive critical software updates over 3.5″ floppy disks
Pay ransomware crooks, or restore the network? Guess which way this city chose after weighing up the costs
Monday review – catch up with the latest articles
What happens when holes perfect for spyware are found in the engine room of millions of Qualcomm-based phones? Let’s find out
How did you spend your time at university? Pizza, booze, sleeping? This Oxford student is snooping on satellites
Business Email Compromise – fighting back with machine learning
Android user chucks potential $10bn+ sueball at Google over ‘spying’, ‘harvesting data’… this time to build supposed rival to TikTok called ‘Shorts’
So you’ve decided you want to write a Windows rootkit. Good thing this chap’s just demystified it in a talk
Chrome Web Store slammed again after 295 ad-injecting, spammy extensions downloaded 80 million times
Trump administration labels WeChat, TikTok ‘threats’ to national security, bans transactions with both
Capital One fined $80m for shoddy public cloud security. Yeah, same bank in that 106m customer-record hack
Foreshadow returns to the foreground: Secrets-spilling speculative-execution Intel flaw lives on, say boffins
When it comes to hacking societies, Russia remains the master at sowing discord and disinformation online
Intel NDA blueprints – 20GB of source code, schematics, specs, docs – spill onto web from partners-only vault
Think carefully about cyber insurance, says NCSC. But don’t worry about buying off ransomware crooks
Porn blast disrupts bail hearing of alleged Twitter hacker
National Crime Agency says Brit teen accused of Twitter hack has not been arrested
USA decides to cleanse local networks of anything Chinese under new five-point national data security plan
Canon not firing on all cylinders: Fledgling cloud loses people’s pics’n’vids, then ‘Maze ransomware’ hits
US voting hardware maker’s shock discovery: Security improves when you actually work with the community
Ever wonder how a pentest turns into felony charges? Coalfire duo explain Iowa courthouse arrest debacle
America was getting on top of its electronic voting machine security – then suddenly… A wild pandemic appears
UK data watchdog having a hard time making GDPR fines stick: Marriott scores another extension, BA prepares to pay 11% of original £183m penalty
OPA: A general-purpose policy engine for cloud-native
NSA warns that mobile device location services constantly compromise snoops and soldiers
China slams President Trump’s TikTok banned-or-be-bought plan in the US