Menu

Gallery

A real loch mess: Navy larks sunk by a truculent torpedo
Dutch spies helped Britain’s GCHQ break Argentine crypto during Falklands War
Cyber attack against UK power grid middleman Elexon sparks in-house IT recovery efforts
You can’t have it both ways: Anti-coronavirus masks may thwart our creepy face-recog cameras, London cops admit
How scammers abuse Google Search’s open redirect feature
Top 10 most exploited vulnerabilities list released by FBI, DHS CISA
Microsoft joins encrypted DNS club with Windows 10 option
Vint Cerf suggests GDPR could hurt coronavirus vaccine development
Brit defense contractor hacked, up to 100,000 past and present employees’ details siphoned off – report
PrintDemon – patch this ancient Windows printer bug!
Woman stalked by sandwich server via her COVID-19 contact tracing info
Multi-part Android spyware lurked on Google Play Store for 4 years, posing as a bunch of legit-looking apps
‘iOS security is f**ked’ says exploit broker Zerodium: Prices crash for taking a bite out of Apple’s core tech
Update now! Windows gets another bumper patch update
There’s Norway you’re going to believe this: Government investment fund conned out of $10m in cyber-attack
US-CERT lists the 10 most-exploited security bugs and, yeah, it’s mostly Microsoft holes people forgot to patch
Aussie money-manager MyBudget goes down for five days
Now there’s nothing stopping the PATRIOT Act allowing the FBI to slurp web-browsing histories without a warrant
Senator Wyden demands deep probe into spyware after hacking toolkit offered to American cops by NSO Group
Stop tracking me, Google: Austrian citizen files GDPR legal complaint over Android Advertising ID
Beware the DHL delivery message email – it could be a package scam
Danger zone! Brit research supercomputer ARCHER’s login nodes exploited in cyber-attack, admins reset passwords and SSH keys
TikTok’s handling of child privacy gets another watchdog’s attention
Criminal forum trading stolen data suffers ironic data breach
Sadly, 111 in this story isn’t binary. It’s decimal. It’s the number of security fixes emitted by Microsoft this week
Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases
Thunderspy – why turning your computer off is a cool idea!
Dating app user logins found on hacking forum
India releases data-use protocols for its contact-tracing app… after five weeks and 100 million downloads
Papa don’t breach: Contracts, personal info on Madonna, Lady Gaga, Elton John, others swiped in celeb law firm ‘hack’
Incredible how you can steal data via Thunderbolt once you’ve taken the PC apart, attached a flash programmer, rewritten the firmware…
Celebrity personal data taken in ransomware attack
Mama mia! Nintendo in need of a plumber after leak sprays N64, GameCube, Wii code
The Internet of Things in 2020: More vital than ever
Clearview AI won’t sell vast faceprint collection to private companies
Microsoft opens IoT bug bounty program
One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch
DEF CON is canceled… No, for real. The in-person event is canceled. We’re not joking. It’s canceled. We mean it
If you miss the happier times of the 2000s, just look up today’s SCADA gear which still have Stuxnet-style holes
More crypto-stealing Chrome extensions swatted by Google
Bored at home? Cisco has just the thing: A shed-load of security fixes to install, from a Kerberos bypass to crashes
FYI: Your browser can pick up ultrasonic signals you can’t hear, and that sounds like a privacy nightmare to some
More and more organizations are falling to ransomware – will you be next?
Vcrypt ransomware brings along a buddy to do the encryption
Senior MP tells UK Defence Committee on 5G security: Russia could become China’s cyber-attack dog
Fake news Facebook accounts used coronavirus to attract followers
Police nab InfinityBlack hackers
So you’ve set up MFA and solved the Elvish riddle, but some still think passwords alone are secure enough
California’s privacy warriors are back – and this time they want to take their fight all the way to the ballot box
Fake crypto-wallet extensions appear in Chrome Web Store once again, siphoning off victims’ passwords
GitHub blasts code-scanning tool into all open-source projects
Help us understand the shifting sands of network security: What’s working for you – and what’s not?
Firefox 76.0 released with critical security patches – update now
Air gap security beaten by turning PC capacitors into speakers
Now we know what the P really stands for in PwC: X-rated ads plastered over derelict corner of accountants’ website
Transport biz Toll Group suffers second ransomware infection in just three months
India acknowledges, but brushes aside, features-not-bugs in Aarogya Setyu virus contact-tracing app
Surprise surprise! Hostile states are hacking coronavirus vaccine research, warn UK and USA intelligence
GoDaddy hack: Miscreant goes AWOL with 28,000 users’ SSH login creds after vandalizing server-side file
GoDaddy – “unauthorized individual” had access to login info
We beg, implore and beseech thee. Stop reusing the same damn password everywhere
It has been 20 years since cybercrims woke up to social engineering with an intriguing little email titled ‘ILOVEYOU’
Firefox’s Private Relay service tests anonymous email alias feature
Reveal the identities of alleged pirates, court tells ISP
More Salt in their wounds: DigiCert hit as hackers wriggle through (patched) holes in buggy config tool
UK finds itself almost alone with centralized virus contact-tracing app that probably won’t work well, asks for your location, may be illegal
Apple-Google COVID-19 virus contact-tracing API to bar location-tracking access
OK, so you’ve air-gapped that PC. Cut the speakers. Covered the LEDs. Disconnected the monitor. Now, about the data-leaking power supply unit…
Sweet TCAS! We can make airliners go up-diddly-up whenever we want, say infosec researchers
UK COVID-19 contact tracing app data may be kept for ‘research’ after crisis ends, MPs told
ILOVEYOU: The Love Bug virus 20 years on – could it happen again?
AsSalt-ed at the weekend: Miscreants roast Ghost, LineageOS totters as Salt bug bites
Coronavirus pandemic coincides with spike in online puppy scams
Uncle Sam to agencies: No encrypted DNS for you!
Monday review – the hot 11 stories of the week
Xiaomi emits phone browser updates after almighty row over web activity harvested even in incognito mode
India makes contact-tracing app compulsory in viral hot zones despite most local phones not being smart
Singapore to require smartphone check-ins at all businesses and will log visitors’ national identity numbers
Spyware slinger NSO to Facebook: Pretty funny you’re suing us in California when we have no US presence and use no American IT services…
Google fights spammy extensions with new Chrome Web Store policy
COVID-19 prompts DHS warning to review Office 365 security
Android trojan EventBot abuses accessibility services to clear out bank accounts – fortunately, it’s ‘in preview’
What’s worse than an annoying internet filter? How about one with a pre-auth remote-command execution hole and there’s no patch?
Quibi, JetBlue, Wish, others accused of leaking millions of email addresses to ad orgs via HTTP referer headers
“Zero-click” mobile phone attacks – and how to avoid them
Bumper Adobe update fixes flaws in Magento, Bridge and Illustrator
Coronavirus delays trial of alleged Russian hacker a third time
Salt peppered with holes? Automation tool vulnerable to auth bypass: Patch now
In trying times like these, it’s reassuring to know you can still get pwned five different ways by Adobe Illustrator files
Academics demand answers from NHS over potential data timebomb ticking inside new UK contact-tracing app
Flaw in defunct WordPress plugin exploited to create backdoor
Twitter turns off SMS-based tweeting in most countries
ProtonMail-run website boasting ‘complete guide’ to GDPR left credential-baring .git repo exposed online
San Francisco trial of Russian bloke extradited and accused of hacking LinkedIn, Dropbox, Formspring stalls again amid pandemic lockdown
iPhone “word of death” could crash your phone – what you need to know
Nine million logs of Brits’ road journeys spill onto the internet from password-less number-plate camera dashboard
Coronavirus tracking tool from Apple and Google embraced by Germany
‘Evil GIF’ account takeover flaw patched in Teams
Warning! Fake Zoom “HR meeting” emails phish for your password
We’re going on a vuln hunt. We’re going catch a big one: Researchers find Windows bugs dominate – but fixes are fast