Menu

Gallery

VMware flaw allows takeover of multiple private clouds
Amtrak breached, some customers’ logins and PII potentially exposed
Defending critical national infrastructure… hmm. Does Zoom count as critical now?
Tor soups up onion sites with bountiful browser bump: No more tears trying to find the secure sites you want
Office supplies biz owned by UK council snubs ransomware demand for 102 Bitcoin
The mystery of the expiring Sectigo web certificate
Hacker posts database stolen from Dark Net free hosting provider DH
Crime agency turns to Google ads to deter teen DDoS hackers
‘Beyond stupid’: Linus Torvalds trashes 5.8 Linux kernel patch over opt-in Intel CPU bug mitigation
Contact-tracer spoofing is already happening – and it’s dangerously simple to do
Had a bad weekend? Probably, if you’re a Sectigo customer, after root cert expires and online chaos ensues
Get rich quick! Work from home! Earn $100,000 easy – just find a critical flaw in Apple’s sign-in system
Cisco hacked: Six backend servers used by customer VIRL-PE deployments compromised via SaltStack
Remember when Republicans said Dems hacked voting systems to rig Georgia’s election? There were no hacks
REvil ransomware gang publishes ‘Elexon staff’s passports’ after UK electrical middleman shrugs off attack
No password required! “Sign in with Apple” account takeover flaw patched
Github uncovers malicious ‘Octopus Scanner’ targeting developers
Facebook to verify identities on accounts that churn out viral posts
UK.gov dangles £400k over makers of IoT Things: Go on, let’s see how you’d make a security cert scheme
The inevitable coronavirus-inspired cyber-attacks are stepping up. Are you ready?
Clearview AI facial recogition sued again – this time by ACLU
COVID-19 tests, PPE and antivirual drugs find a home on the dark web
Great news. Patch load drops 20% for the first time in 10 years. Bad news: Well, you’ve heard about coronavirus?
Windows 10 adds new security and privacy features in May update
Google sued by Arizona for tracking users’ locations in spite of settings
It’s not every day the NSA publicly warns of attacks by Kremlin hackers – so take this critical Exim flaw seriously
NTT warns its Singapore cloud was hacked, Japanese customer data compromised
Got $50k spare? Then you can crack SHA-1 – so OpenSSH is deprecating flawed hashing algo in a ‘near-future release’
Cybercrooks tend to prefer Google-branded phishing to Microsoft-flavoured lures
You, Apple Mac fan. Put down the homemade oat-milk latte, you need to patch a load of security bugs, too
Inside a ransomware gang’s attack toolbox
Pablo Escobar’s brother sues Apple for $2.6b over FaceTime flaw
Android ‘StrandHogg 2.0’ flaw lets malware assume identity of any app
Why zero trust security needs strong hardware foundations
26 million logins believed to be stolen from LiveJournal in 2017 pop up on hacker forum
Apple sends out 11 security alerts – get your fixes now!
Oh cool, tech service prices are plummeting. And by tech services, we mean botnet rentals and stolen credit cards
Open source libraries a big source of application security flaws
10 steps to automating security in Kubernetes pipelines
Google may soon add end-to-end encryption for RCS
Microsoft banishes Trend Micro code at center of driver ‘cheatware’ storm from Windows 10, rootkit detector product pulled from site
Mulled Chrome API shines light on long-neglected privacy gap: Sites can snoop on your find-in-page searches
Use of cloud collaboration tools surges and so do attacks
India said its coronavirus contact-tracing app is perfect… adds bug bounty and open-sources it anyway
US lawmakers get a second shot at forcing FBI agents to obtain a warrant before they leaf through web histories
If someone could stop hackers pwning medical systems right now, that would be cool, say Red Cross and friends
New iPhone jailbreak released
Airline-chasing lawyers leap on Easyjet for £18bn after 9m folks’ data, itineraries nicked
Internet giants unite to stop warrantless snooping on web histories
Docker Desktop danger discovered, patch now
Unmanned drones to slash NHS delivery times to one-fifth of road ‘n’ rail transport
eBay users spot the online auction house port-scanning their PCs. Um… is that OK?
Galaxy S20 security is already old hat as Samsung launches new safety silicon
Contact-tracing app may become a permanent fixture in major Chinese city
What is the dark web? Your questions answered, in plain English
Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs
It wasn’t just a few credit cards: Entire travel itineraries were stolen by hackers, Easyjet now tells victims
The ransomware that attacks you from inside a virtual machine
Forget BYOD, this is BYOVM: Ransomware tries to evade antivirus by hiding in a virtual machine on infected systems
Signal secure messaging can now identify you without a phone number
Apple and Google launch COVID-19 contact tracing API
To test its security mid-pandemic, GitLab tried phishing its own work-from-home staff. 1 in 5 fell for it
Amid the pandemic, using trust to fight shadow IT
Campaign groups warn GCHQ can re-identify UK’s phones from COVID-19 contact-tracing app data
Far-right leader walks free from court after conviction for refusing to hand his phone passcode over to police
Adobe “out of band” critical patch – get your update now!
Scammers target COVID-19 CARES Act relief scheme
Chrome 83 adds DNS-over-HTTPS support and privacy tweaks
DNS this week stands for Drowning Needed Services: Design flaw in name server system can be exploited to flood machines offline
Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook
Remember when Securus was sued for recording 14,000 calls between prison inmates and lawyers? It just settled
UK’s Ministry of Defence: We’ll harvest and anonymise private COVID-19 apps’ tracing data by handing it to ‘behavioural science’ arm
Beware of emails with “horrible charts” about Covid-19
Ransomware has gone nuclear: To avoid any fallout yourself, tune in online this month to hear from KnowBe4
Houseparty denied it had been hacked… while miscreants were abusing its dot-com domain name infrastructure
Office 365 exposed some internal search results to other companies
FBI finally unlock shooter’s iPhones, Apple berated for not helping
Tech’s Volkswagen moment? Trend Micro accused of cheating Microsoft driver QA by detecting test suite
Former Labour deputy leader Harriet Harman calls on UK govt to legally protect data from contact-tracing apps
You know this Land of the Free thing, yeah? Well then, why allow the FBI to trawl through America’s browsing history without a warrant?
Rogue ADT tech spied on hundreds of customers in their homes via CCTV – including me, says teen girl
6 ways to be more secure in the cloud
Beer rating app reveals homes and identities of spies and military bods, warns Bellingcat
Apple “MagicPairing” for AirPods – the magic isn’t perfect yet
Cash-flashing rapper charged with money laundering for BTC-e
Firefox to tell you if sites are shortening your passwords
Easyjet hacked: 9 million people’s data accessed plus 2,200 folks’ credit card details grabbed
Open letter from digital rights groups to UK health secretary questions big tech’s role in NHS COVID-19 data store
AT&T tracked its own sales bods using GPS, secretly charged them $135 a month to do so, lawsuit claims
Magecart malware merrily sipped card details, evaded security scans on UK e-tailer Páramo for almost 8 months
Get your live, GIAC-certified, online cybersecurity training from SANS – available now
Insider threat? Pffft. Hackers on the outside are the ones mostly making off with your private biz data, says Verizon
With millions upon millions out of work in the US, here come the scammers claiming victims’ unemployment money using stolen info
Attorney General: We didn’t need Apple to crack terrorist’s iPhones – tho we still want iGiant to do it in future
Apple’s MagicPairing for Bluetooth fails to enchant after mischief-making bugs found hiding in the stack
Microsoft gives Office 365 admins the heads-up: Some internal queries over weekend might have returned results from completely different orgs
The RATicate gang – implanting malware in an industry near you
Senate renews warrantless collection of web histories
Shiny new Azure login attracts shiny new phishing attacks
I know what you leased last summer: Asset database leak hits Capita, Rolls-Royce, Tesco (every little helps, eh?)