Menu

Gallery

Digicert revokes a raft of web security certificates
Sueball locked, loaded and pointed at LinkedIn over iOS privacy naughtiness
Better get Grandpa off Windows 7 because zero-day bug in Zoom allows remote code execution on vintage OS
Monday review – the hot stories of the week
Trump reveals US cyber-attack on Russian election-misdirection troll farms
How to make your IT security go beyond your network – and make people your perimeter
An email banning our staff from using TikTok? Haha, funny story about that, we didn’t mean it – Amazon
Tony Blair tells Russian infosec conference that cross-border infosec policies need more gov intervention
TomTom bill bomb: Why am I being charged for infotainment? I sold my car last year, rages Reg reader
Digicert will shovel some 50,000 EV HTTPS certificates into the furnace this Saturday after audit bungle
FYI: Someone’s scanning gateways, looking for those security holes Citrix told you not to worry too much about
How to build a cyber threat intelligence program while cutting through the noise
If you haven’t potentially exposed 1000s of customers once again with networking vulns, step forward… Not so fast, Palo Alto Networks
Social engineering hacks weaken cybersecurity during the pandemic
Microsoft sues coronavirus phishing spammers to seize their domains amid web app attacks against Office 354.5
One surefire way to get the boss’s attention on network security is to get hacked. But there must be a better way?
Criminals auction off stolen domain admin credentials for up to £95k. Your bank account details? Barely get £50
Mozilla turns off “Firefox Send” following malware abuse reports
Citrix tells everyone not to worry too much over its latest security patches. NSA’s former top hacker disagrees
Kinda sorta weakened version of EARN IT Act creeps closer
Shopped recently in a small online store? Check this list to see if it was one of 570 websites infected with card-skimming Magecart
Fret not, Linux fans, Microsoft’s Project Freta is here to peer deep into your memory… to spot malware
Company web names hijacked via outdated cloud DNS records
Social media giants move to defy Hong Kong’s new national security law
Flashy Nigerian Instagram star extradited to US to face BEC charges
Hundreds of forgotten corners of mega-corp websites fall into the hands of spammers and malware slingers
Want to kill all the weak passwords? This may be the tool for you
Your 2.3m Instagram fans won’t stop the FBI… Web star accused of plotting to launder millions from cyber-crime
You may be distracted by the pandemic but FYI: US Senate panel OK’s backdoors-by-the-backdoor EARN IT Act
Think of a number: A tale of iffy discount codes, supermarket loyalty cards and Hotels.com
Three UK: We’re sending you this SMS to warn you not to pay attention to unsolicited texts
Boston bans government use of facial recognition
Make sure you’ve patched your F5 BIG-IP gear. Exploit code for scary bug pair is so trivial, it fits in a tweet
Barclays Bank appeared to be using the Wayback Machine as a ‘CDN’ for some Javascript
Facebook hoaxes back in the spotlight – what to tell your friends
Google buys AR smart-glasses company North
Fighting BEC and EAC: Why whack-a-mole won’t work
F5 emits fixes for critical flaws in BIG-IP gear: Hopefully yours aren’t internet-facing while you ready a patch
Holy Guacamole! Researchers find Apache remote desktop software was silently pwnable for snooping on sessions
Euro police forces infiltrated encrypted phone biz – and now ‘criminal’ EncroChat users are being rounded up
Hold off that rush into the July 4 weekend – you may need this: Microsoft patches pwn-by-picture pitfalls in Win 10
Users who don’t understand how to encrypt their emails won’t do it
MongoDB ransom threats step up from blackmail to full-on wiping
Cisco SMB kit harbors cross-site scripting bug: One wrong link click… and that’s your router pwned remotely
133m records for sale as fruits of data breach spree keep raining down
Microsoft issues critical fixes for booby-trapped images – update now!
Google stops pushing scam ads on Americans searching for how to vote
Details of Beijing’s new Hong Kong security law revealed: Signals end to more than two decades of autonomy
Firefox 78 is out – with a mysteriously empty list of security fixes
Tune in and watch live right here this week – it’s your email encryption wake-up call
Things that happen every four years: Olympic Games, Presidential elections, and now new Mac ransomware
After six months of stonewalling by Apple, app dev goes public with macOS privacy protection bypass
It’s happened again: AT&T sued for allegedly transferring victim’s number to thieves in $1.9m cryptocoin heist
Living on a prayer? Netgear not quite halfway there with patches for 28 out of 79 vulnerable router models
Google joins Apple in limiting web certificates to one year
NEC insists its face-recog training dataset isn’t biased, but refuses to share details of Neoface system with UK court
DDoS and dingoes: Australia to bolster cyber-defences with 500 hackers amid China spat
iOS 14 flags TikTok, 53 other apps spying on iPhone clipboards
Remember when we warned in February Apple will crack down on long-life HTTPS certs? It’s happening: Chrome, Firefox ready to join in, too
University of California San Francisco pays ransomware gang $1.14m as BBC publishes ‘dark web negotiations’
Beware “secure DNS” scam targeting website owners and bloggers
Yes, Prime Minister, rewrite the Computer Misuse Act: Brit infosec outfits urge reform
Satori IoT botnet author sentenced to 13 months in prison
Monday review – the hot 10 stories of the week
CyberX, CyberX, does whatever a CyberX does. Locks IoT, machines too, Microsoft got it, so will you
Macs, iPhones, iPads to get encrypted DNS – how’d you like them Apples?
Let’s roll the 3d6 dice on today’s security drama: Ah, 15, that’s LG allegedly hacked, source code stolen by Maze ransomware gang
Tune in and watch live: Email encryption doesn’t have to be an all-or-nothing deal
Brit plod’s use of facial-recognition tech is lawful, no need to question us, cops’ lawyer tells Court of Appeal
Fancy hacking a PlayStation? Sony announces its bug bounty program
When one open-source package riddled with vulns pulls in dozens of others, what’s a dev to do?
REvil gang threaten to auction celebrity data from Mariah Carey, Lebron James, MTV and more
Talk about the fox guarding the hen house. Comcast to handle DNS-over-HTTPS for Firefox-using subscribers
US govt: Julian Assange tried to recruit hacker to steal hush-hush dirt and we should know – the hacker was an informant
Honeypot behind sold-off IP subnet shows Cyberbunker biz hosted all kinds of filth, says SANS Institute
Patch time! NVIDIA fixes kernel driver holes on Windows and Linux
Twitter apologizes for leaking businesses’ financial data
There are DDoS attacks, then there’s this 809 million packet-per-second tsunami Akamai says it just caught
After huffing and puffing for years, US senators unveil law to blow the encryption house down with police backdoors
Ransomware crims to sell off ‘scandalous’ files swiped from Mariah Carey, Nicki Minaj, Puff Daddy’s legal eagles
Laws on police facial recognition aren’t tough enough, UK data watchdog barrister tells Court of Appeal
Glupteba – the malware that gets secret messages from the Bitcoin blockchain
Former UK Labour deputy leader wants to know how the NHS’s contact-tracing app will ensure user privacy
Maze ransomware gang threatens to publish sensitive stolen data after US aerospace biz sensibly refuses to pay
Carbon-based vuln hunters will always be better at infosec than AI, insist puny humans
iOS 14, macOS Big Sur, Safari to give us ‘No, thanks!’ option for ad tracking
Three words you do not want to hear regarding a ‘secure browser’ called SafePay… Remote. Code. Execution
The state of OpenPGP key servers: Kristian, can you renew my certificate? A month later: Kristian? Ten days later: Too late, it’s expired
Here’s a headline we never thought we’d write 20 years ago: Microsoft readies antivirus for Linux, Android
None shall pass: Yet another layer to protect hapless users, employers from dodgy docs added to Microsoft 365
UK police’s face recognition tech breaks human rights laws. Outlaw it, civil rights group urges Court of Appeal
United States wants HTTPS for all government sites, all the time
‘BlueLeaks’ exposes sensitive files from hundreds of police departments
What did it take for stubborn IBM to fix flaws in its Data Risk Manager security software? Someone dropping zero-days
Step on it, I’ve got the police on my hack: Anon swipes, leaks online 269GB of crime intel docs from cops, Feds
We were already secure enough for mass remote working before COVID-19, boast IT pros
Anatomy of a survey scam – how innocent questions can rip you off
Hacker indicted for stealing 65K employees’ PII in medical center hack
VMware and Office for Mac need patching, Microsoft can scan your firmware, and Anonymous takes credit for Atlanta police hacks
Hey NYPD, when you’re done tear-gassing and running over protesters, can you tell us about your spy gear?