Menu

Gallery

UK snubs Apple-Google coronavirus app API, insists on British control of data, promises to protect privacy
Australian contact-tracing app leaks telling info and increases chances of third-party tracking, say security folks
5 common mistakes that lead to ransomware
Web shell warning issued by US and Australia
We could have pwned Microsoft Teams with a GIF, claims Israeli infosec outfit
Apple and Google tweak key bits of contact-tracing privacy plan
Rabobank security cert expires and gives its Australian Android app a case of internet-blindness
Australia’s contact-tracing app regulation avoids ‘woolly’ principles in comparable cyber-laws, say lawyers
Sophos XG firewalls hacked, hotfix ready. Texts wreck Apple iThings. Yup, business as usual in infosec world
Spyware maker NSO can’t claim immunity, Facebook lawyers insist – it’s time to face the music
Patch now! Microsoft issues unexpected Office fix
Shadow Broker leaked NSA files point to unknown APT group
AI helps experts find thousands of child sexual abuse imagery keywords
Canada’s .ca overlord rolls out free privacy-protecting DNS-over-HTTPS service for folks in Great White North
iPhone zero day – don’t panic! Here’s what you need to know
Trove of RubyGems malware highlights software supply chain issues
Password-free database of exercise app Kinomap leaks 42m user records
GCC 10 gets security bug trap. And look what just fell into it: OpenSSL and a prod-of-death flaw in servers and apps
Why should the UK pensions watchdog be able to spy on your internet activities? Same reason as the Environment Agency and many more
Get your free work-from-home IT security awareness training kit, courtesy of SANS
Vietnam alleged to have hacked Chinese organisations in charge of COVID-19 response
Zero-click, zero-day flaws in iOS Mail ‘exploited to hijack’ VIP smartphones. Apple rushes out beta patch
Stripe is absolutely logging your mouse movements on websites’ payment pages – for your own good, says CEO
After intense scrutiny, Zoom tightens up security with version 5. New features include not, er, spilling video calls to network snoops
Attention, lockdown DIY fans: UK hardware flinger Robert Dyas had credit card data and more skimmed from website
Porn scammers making $100,000 a month from sextortion emails
Attack of the clones: If you were relying on older Xilinx FPGAs to keep your product’s hardware code encrypted and secret, here’s some bad news
309 million Facebook users’ phone numbers found online
Yes, there’s lots of COVID-19-themed scuminess around – but otherwise the level of cybercrime is the same
Gaming company targeted by Chinese Winnti hackers
Free ebook for every reader: Unleash the power of your Apple fleet with Jamf
Netflix says subscriptions just boomed but tells investors it’s no money heist and they should expect stranger things
IBM == Insecure Business Machines: No-auth remote root exec exploit in Data Risk Manager drops after Big Blue snubs bug report
At last – a use for all those phishing emails you’ve been getting!
Frippin’ heck: Watch out, chin-stroking prog rock fans. King Crimson distributor Burning Shed says it’s been hacked
Something a bit phishy in your inbox? You can now email suspected frauds straight to Blighty’s web takedown cops
Facebook to alert us if we’ve been exposed to fake coronavirus news
Typosquatting RubyGems laced with Bitcoin-nabbing malware have been downloaded thousands of times
Weeks before US oil contract prices went negative, a spear-phishing crew went after oil firms. What did they get?
Google productises its own not-a-VPN secure remote access tool
Bad news: Cognizant hit by ransomware gang. Worse: It’s Maze, which leaks victims’ data online after non-payment
CFAA latest: Supremes to tackle old chestnut of what ‘authorized use’ of a computer really means in America
Maze ransomware hits US giant Cognizant
Fan vibrations can be used to transmit data from air-gapped machines
New sextortion scam: “High level of risk. Your account has been hacked.”
Bot creates millions of fake eyeballs to rip off smart-TV advertisers
Tor Project loses a third of staff in coronavirus cuts: Unlucky 13 out as nonprofit hacks back to core ops
Monday review – the hot 13 stories of the week
Ministry of Defence lowers supplier infosec standards thanks to COVID-19 outbreak
Contact-tracing or contact sport? Defections and accusations emerge among European COVID-chasing app efforts
Critical bug in Google Chrome – get your update now
That critical VMware vuln allowed anyone on your network to create new admin users, no creds needed
Google: We’ve blocked 126 million COVID-19 phishing scams in the last week
US offers up to $5m reward for information on North Korean hackers
GitHub users targeted by Sawfish phishing campaign
Europe publishes draft rules for coronavirus contact-tracing app development, on a relaxed schedule
India says ‘Zoom is a not a safe platform’ and bans government users
You’re a botnet, you’ve got a zero-day, so where do you go? After fiber, because that’s where the bandwidth is
TikTok announces “Family Pairing” – bust your moves but cap the risk
Bad news: So much of your personal data has been hacked that lesson manuals on how to use it are the latest hot property
49 malicious Chrome extensions caught pickpocketing crypto wallets
Update now! Windows zero-day flaws fixed in Patch Tuesday
United Nations reportedly tears up Tencent’s invite to its big 75th birthday bash
Stuck inside with time on your hands? The US govt would like to remind you it’s paying $5m for Nork hacking scalps
Linksys forces password reset for Smart Wi-Fi accounts after router DNS hack pointed users at COVID-19 malware
Zoom passwords for sale on the Dark Web – “ten-a-penny” by all accounts
Think before filling in that convenient flight refund form with all your delicious details – there’s a scam going about
Signal: We’ll be eaten alive by EARN IT Act’s anti-encryption wolves
WordPress WooCommerce sites targeted by card swiper attacks
Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store
Apple: We respect your privacy so much we’ve revealed a little about what we can track when you use Maps
At least someone’s making out like a bandit: Scammers have pocketed $13m in Coronavirus fraud from the US this year
April 2020 and – rest assured – your Windows PC can still be pwned by something so innocuous as an unruly font
Let’s authenticate: Beyond Identity pitches app-wrapped certificate authority
TikTok users beware: Hackers could swap your videos with their own
ICANN asks registrars to crack down on scam coronavirus websites
Microsoft and Google delay online authentication change
Zoom adds Choose Your Own Routing Adventure to keep chats out of China
So how do the coronavirus smartphone tracking apps actually work and should you download one to help?
How to make a stranger’s insecure 3D printer halt-and-catch-fire – plus more alerts from infosec world
Sextortion emails and porn scams are back – don’t let them scare you!
The pains – and pleasures? – of network security: Tell us exactly what you think about this corner of business IT
Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay
Signal sends smoke, er, signal: If Congress cripples anonymous speech with EARN IT Act, we’ll shut US ops
Fleeceware on your iPhone? Don’t get caught out while penned up at home
Consumer reviewer Which? finds CAN bus ports on Ford and VW, starts yelling ‘Security! We have a problem…’
Google removes Android VPN with ‘critical vulnerability’ from Play Store
Low-orbit internet banking fraud claim alleged to be a load of space junk
Cloudflare dumps Google’s reCAPTCHA, moves to hCaptcha as free ride ends (and something about privacy)
Slack in the security spotlight – lessons for collaboration servers
Update Firefox again – more RCEs and an Android “takeover” bug too
Microsoft prevents Domain of Danger from falling into miscreants’ paws by forking out cash for corp.com
Microsoft project proposed to aid Linux IoT code integrity
As if the world couldn’t get any weirder, this AI toilet scans your anus to identify you
Please, just stop downloading apps from unofficial stores: Android users hit with ‘unkillable malware’
China and Taiwan aren’t great friends. Zoom sends chats through China. So Taiwan has banned Zoom
Visual Studio Code extension flags NPM vulnerabilities
New year, old threats: Malware peddlers went into overdrive in Q1, says Trend Micro
Flaw hunter bags $75,000 off Apple after duping Safari into spying through iPhone, Mac cameras without permission
Twitter warns users – Firefox might hold on to private messages