Menu

Gallery

Chinese debt collectors jailed for cyberbullying under ‘soft violence’ laws
Microsoft forked out $13.7m in bug bounties. The reward program’s architect thinks the money could be better spent
As the world descends into madness, it’s good to see some things never change: Monthly Android patches
They say the tooth will set you free… so Brit dentist trade union tells members: ‘Bad news; we’ve been hacked’
Uncle Sam blames best pal China as Taidoor crew’s dirty RAT takes aim at Western orgs, but others are less sure
GandCrab ransomware hacker arrested in Belgium
Doctor, doctor, got some sad news, there’s been a bad case of hacking you: UK govt investigates email fail
Leaky AWS S3 buckets are so common, they’re being found by the thousands now – with lots of buried secrets
Days after President Trump suggests pausing election over security, US House passes $500m for states to shore up election security
UK Defence Committee chair muses treating TikTok like Huawei: So eyeball its code then ban it from the country?
Linux Foundation rolls bunch of overlapping groups into one to tackle growing number of open-source security vulns
‘We stopped ransomware’ boasts Blackbaud CEO. And by ‘stopped’ he means ‘got insurance to pay off crooks’
Oh cool, more Cisco patches to apply. Happy Monday
Twitter hack – three suspects charged in the US
Who was behind that stunning Twitter hack? State spies? Probably this Florida kid, say US prosecutors
Travel company CWT avoids ransomware derailment by paying $4.5m blackmail demand
First rule of Ransomware Club is do not pay the ransom, but it looks like Carlson Wagonlit Travel didn’t get the memo
Burn baby burn, plastic inferno! Infosec researchers turn 3D printers into self-immolating suicide machines
In the market for a second-hand phone? Check it’s still supported by the vendor – almost a third sold are not
EU tries to get serious on cybercrime with first sanctions against Wannacry, NotPetya, CloudHopper crews
Fun fact: If you noticed a while ago Zoom’s web client going AWOL for a week, it’s because someone found a passcode-cracking hole
Twitter says spear-phishing attack hooked its staff and led to celebrity account hijack
Infosec bod: I’ve found zero-day flaws in Tor’s bridge relay defenses. Tor Project: Only the zero part is right
Servers at risk from “BootHole” bug – what you need to know
If you own one of these 45 Netgear devices, replace it: Gear maker won’t patch vulnerable gear despite live proof-of-concept code
DXC says ransomware attack disrupted customer operations at insurance services arm but barely left a scratch
YOU… SHA-1 NOT PASS! Microsoft magics away demonic hash algorithm from Windows updates, apps
GRUB2, you’re getting too bug for your boots: Config file buffer overflow is a boon for malware seeking to drill deeper into a system
US tax service says, “2FA is a must!”
Chinese ambassador to UK threatens to withdraw Huawei, £3bn investment if comms giant banned from building 5G
No wonder Brit universities report hacks so often: Half of staff have had zero infosec training, apparently
Japan starts work on global quantum crypto network
Reply-All storm flares as email announcing privacy policy puts 500 addresses in the ‘To’ field, not ‘BCC’
We’re suing Google for harvesting our personal info even though we opted out of Chrome sync – netizens
Firefox 79 is out – it’s a double-update month so patch now!
MI6 tried to intervene in independent court by stopping judge seeing legal papers – but they said sorry, so it’s OK
Find out this week: How to build a cyber threat intelligence program while cutting through the noise
Tune in this week to learn all about an identity-centric approach to zero-trust security
Data-stealing, password-harvesting, backdoor-opening QNAP NAS malware cruises along at 62,000 infections
Garmin staggers back to its feet: Aviation systems seem to be lagging, though. Here’s why
ProLock ransomware – new report reveals the evolution of a threat
Monday review – our recent stories revisited
UKIP blackmail, data breach sueball allegations were groundless, rules High Court
Psst.. You may want to patch this under-attack data-leaking Cisco bug – and these Ripple20 hijack flaws
It’s a Meow-nixed system, I know this: Purr-fect storm of 3,000+ insecure databases – and a data-wiping bot
Cabinet Office takes over control of UK government data: Mundane machinery or Machiavellian manoeuvrings?
ASUS routers could be reflashed with malware – patch now!
Brit unis hit in Blackbaud hack inform students that their data was nicked, which has gone as well as you might expect
UK’s NCSC reveals Premier League footie clubs to be ripe pickings for cybercrooks: One almost lost £1m to BEC attack
Raytheon techie who took home radar secrets gets 18 months in the clink in surprise time fraud probe twist
Congrats, First American Title Insurance, you’ve made technology history. For all the wrong reasons
Bridgecrew: Our mission is to set cloud security free
Sports team nearly paid a $1.25m transfer fee… to cybercrooks
Twitter hack latest: Up to 36 compromised accounts had their private messages read – including a Dutch politician’s
Ubiquiti, go write on the board 100 times, ‘I must validate input data before using it’… Update silently breaks IDS/IPS
UK surveillance laws tightened up as most spying demands to be subject to warrants
Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters
Stick that in your named pipe and smoke it: Flaw in Citrix Workspace app could let remote attacker pwn host
Capita’s bespoke British Army recruiting IT cost military 25k applicants after switch-on
Pakistan bans one Chinese app and gives TikTok a final warning to clean up its act
Twilio: Someone broke into our unsecured AWS S3 silo, added ‘non-malicious’ code to our JavaScript SDK
It’s July 2020, and your PC or Mac can be pwned by a dodgy Photoshop file – Adobe emits critical patch batch
Bad: US govt says Chinese duo hacked, stole blueprints from just about everyone. Also bad: They extorted cash
Stick that in your named pipe and smoke it: Flaw in Citrix Workspace could let remote attacker pwn host machine
UK intel committee on Russia: Social media firms should remove state disinformation. What was that, MI5? ████████?
Apple was the only Fortune 50 company to foresee COVID-19 pandemic risk and properly insure against it – Forrester
Computer misuse crimes down 9% on last year in England and Wales, says Office of National Statistics
7 VPNs that leaked their logs – the logs that “didn’t exist”
You’ve had your pandemic holiday, now Microsoft really is going to kill off TLS 1.0, 1.1
An axe age, a sword age, Privacy Shield is riven, but what might that mean for European businesses?
UK.gov admits it has not performed legally required data protection checks for COVID-19 tracing system
Is your Office 365 locked down in lockdown?
Hey there, want to break into computers like an Iranian hacker crew? IBM finds 40GB of videos that include how-tos
Twitter hackers busted 2FA to access accounts and then reset user passwords
Google Cloud adds security capabilities for sensitive workloads
Seven ‘no log’ VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet
Judge green-lights Facebook, WhatsApp hacking lawsuit against spyware biz NSO, unleashing Zuck’s lawyers
Cloud biz Blackbaud caved to ransomware gang’s demands – then neglected to inform customers for two months
Ew, that’s unsanitary: SEO plugin for WordPress would run arbitrary JavaScript inputs instead of scrubbing them
Apple’s latest updates are out for iPhones and Macs – get them now!
Twitter admits 130 A-lister accounts compromised to promote Bitcoin scam after ‘social engineering’ attack
This week of never-ending security updates continue. Now Apple emits dozens of fixes for iOS, macOS, etc
FYI Russia is totally hacking the West’s labs in search of COVID-19 vaccine files, say UK, US, Canada cyber-spies
Privacy Shield binned after EU court rules transatlantic data protection arrangements ‘inadequate’
Finally done with all those Patch Tuesday updates? Think again! Here’s 33 Cisco bug fixes, with five criticals
Twitter says hack of key staff led to celebrity, politician, biz account hijack mega-spree
Report: CIA runs secret cyberwar with little oversight after Trump gave the OK, say US government officials
Twitter limits tweeting as prominent accounts spam out cryptocoin scams
Twitter mass hacking: Bill Gates, Elon Musk, Jeff Bezos, Mike Bloomberg, Biden, Obama, more hijacked to peddle Bitcoin scam
If Microsoft 365 security is so great, why do its customers keep getting hacked?
Is it Patch Blues-day for Outlook? Microsoft’s email client breaks worldwide, leaves everyone stumped
Patch now! SIGRED – the wormable hole in your Windows servers
Cambridge student rebuilds Polish Enigma-code-breaking box that paved the way for Turing … and Victory!
Citrix denies dark web claim of network compromise and ransomware attack
Old-school security hole perfect for worms and remote hijackings found lurking in Windows Server DNS code
So kind of SAP NetWeaver to hand out admin accounts to anyone who can reach it. You’ll want to patch this
RATicate malware gang goes commercial
Burn baby burn, infosec inferno: Just 21% of security pros haven’t considered quitting their current job
Collabera hacked: IT staffing’n’services giant hit by ransomware, employee personal data stolen
Guilty: Russian miscreant who hacked LinkedIn, Dropbox, Formspring, stole 200-million-plus account records