Menu

Gallery

Google launches FuzzBench service to benchmark fuzzing tools
Enable that MF-ing MFA: 1.2 million Azure Active Directory accounts compromised every month, reckons Microsoft
Zynga faces class action suit over massive Words With Friends hack
Sadly, the web has brought a whole new meaning to the phrase ‘nothing is true; everything is permitted’
Time to limber up in the battle against cybercriminals
Alleged Vault 7 leaker trial finale: Want to know the CIA’s password for its top-secret hacking tools? 123ABCdef
Download this update from mybrowser.microsoft.com. Oh, sorry, that was malware on a hijacked sub-domain. Oops
If Tesco was hacked, your data could be being flogged for just £2.70 – research
Why 3 million Let’s Encrypt certificates are being killed off today
It has been 15 years, and we’re still reporting homograph attacks – web domains that stealthily use non-Latin characters to appear legit
UK data watchdog slaps a £500,000 fine on Cathay Pacific for 2018 9.4m customer data leak
NCSC: Secure your webcams now
Google fixes MediaTek bug in Android March patches
Fancy that: Hacking airliner systems doesn’t make them magically fall out of the sky
Tech support scammers hacked back by vigilante
Facebook purges hundreds of fake accounts from state actors, marketers
Let’s Encrypt? Let’s revoke 3 million HTTPS certificates on Wednesday, more like: Check code loop blunder strikes
Why ‘free’ Wi-Fi isn’t really free
GCHQ’s infosec arm has 3 simple tips to secure those insecure smart home gadgets
Digital piggy bank sevice broken into by cybercrooks
Huge flaw found in how facial features are measured from images
GoodRx stops sharing personal medical data with Google, Facebook
Have I Been S0ld? No, trusted security website HIBP off the table, will remain independent
Nvidia patches severe flaws affecting GeForce, Quadro NVS and Tesla
Maersk prepares to lay off the Maidenhead staffers who rescued it from NotPetya super-pwnage
XSS plugin vulnerabilities plague WordPress users
Wi-Fi kit spilling data with bad crypto – Huawei, eh? No, it’s Cisco. US giant patches Krook spy-hole bug in network gear
Delicious irony: Credit rating builder Loqbox lets customer details and card numbers slip after ‘sophisticated attack’
Siri and Google Assistant hacked in new ultrasonic attack
Let’s Encrypt issues one billionth free certificate
Ironpie robot vacuum can suck up your privacy
Fresh phish! Stripe scam baked and delivered in under an hour
Facebook sues data analytics firm OneAudience over malicious SDK
Southern Water not such a phisherman’s phriend, hauls itself offline to tackle email lure
Clearview AI loses entire database of faceprint-buying clients to hackers
Ransomware wipes evidence, lets suspected drug dealers walk free
Firefox rolling out DNS-over-HTTPS privacy by default in the US
Google has right to censor conservative nonprofit on YouTube
Your phone wakes up. Its assistant starts reading out your text messages. To everyone around. You panic. How? Ultrasonic waves
Cyber-wrath of Iran for top general’s assassination hasn’t progressed beyond snooping and nicking logins… yet
How one man could have flooded your phone with Microsoft spam
Slickwraps data breach earns scorn for all
Sophos was gearing up for a private life – then someone remembered the bike scheme
Brave beats other browsers in privacy study
Chrome 80 encryption change blocks AZORult password stealer
Facebook bans coronavirus ‘miracle cure’ ads
If you’re serious about browser privacy, you should probably pass on Edge or Yandex, claims Dublin professor
Wi-Fi of more than a billion PCs, phones, gadgets can be snooped on. But you’re using HTTPS, SSH, VPNs… right?
After blowing $100m to snoop on Americans’ phone call logs for four years, what did the NSA get? Just one lead
Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now
Departing MI5 chief: Break chat app crypto for us, kthxbai
Apple’s iOS pasteboard leaks location data to spy apps
LTE vulnerability allows impersonation of other mobile devices
Rotherwood Healthcare AWS bucket security fail left elderly patients’ DNR choices freely readable online
Switch to Signal for encrypted messaging, EC tells staff
Taking a GPS tracker off your car isn’t ‘theft,’ court rules
Mind the gap: Google patches holes in Chrome – exploit already out there for one of them after duo spot code fix
Mystery zero-day in Chrome – update now!
Android 11 to clamp down on background location access
Apple tries to have VirnetX VPN patent ruling overturned again, US Supremes say no… again
Password killer FIDO2 comes bounding into Azure Active Directory hybrid environments
The “Cloud Snooper” malware that sneaks into your Linux servers
Microsoft uses its expertise in malware to help with fileless attack detection on Linux
Smart speakers mistakenly eavesdrop up to 19 times a day
Google denies illegally slurping data off free student Chromebooks
KidsGuard stalkerware leaks data on secretly surveilled victims
Samsung cops to data breach after unsolicited ‘1/1’ Find my Mobile push notification
Google purges 600 Android apps for “disruptive” pop-up ads
Apple chops Safari’s TLS certificate validity down to one year
Google rolls out Titan keys to Europe, Japan. Plus: Group Policy bug is a feature, not a flaw, says Microsoft
Duped into running bogus virus scans at Office Depot? Dry your eyes with a small check from $35m settlement
ISS World “malware attack” leaves employees offline
The Amazon Prime phishing attack that wasn’t…
Larry Tesler, of copy-and-paste fame, dies at 74
US and UK call out Russian hackers for Georgia attacks
Data of 10.6m MGM hotel guests posted for sale on Dark Web forum
Adobe fixes critical flaws in Media Encoder and After Effects
Washington state Senate passes bill to rein in facial recognition
‘Don’t tell anyone but I have a secret.’ There, that’s my security sorted
Google exiles 600 apps from Play Store for ‘disruptive advertising’ amid push to clean up Android souk’s image
Apple drops a bomb on long-life HTTPS certificates: Safari to snub new security certs valid for more than 13 months
Stuffing nonsense: Persistent cyberpunks are pummelling banks’ public APIs, warns Akamai
RSA Conference loses one more abbreviated tech giant after AT&T disconnects over Wuhan coronavirus fears
We know what you did last summer: MGM’s hotel spinoff lost 10.7m guest records and now they’re on hacker forums
GRU won’t believe it: UK and US call out Russia for cyber-attacks on Georgia last year
Ransomware attack forces 2-day shutdown of natural gas pipeline
Keen to check for ‘abnormal’ user behaviours? Microsoft talks insider risk, AWS imports and compliance at infosec shindig RSA
Nearly half of hospital Windows systems still vulnerable to RDP bugs
Firefox 73.0.1 fixes crashes, blank web pages and DRM niggles
Ring makes 2FA mandatory to keep hackers out of your doorbell account
Samsung will be Putin dreaded Kremlin-approved shovelware on its phones, claims Russia
Oi, Cisco! Who left the ‘high privilege’ login for Smart Software Manager just sitting out in the open?
Assange lawyer: Trump offered WikiLeaker a pardon in exchange for denying Russia hacked Democrats’ email
When the air gap is the space between the ears: A natural gas plant let ransomware spread from office IT to ops
Don’t use natwest.co.uk for online banking, Natwest bank tells baffled customer
Private photos leaked by PhotoSquared’s unsecured cloud storage
Facebook asks to be regulated kinda like a newspaper, kinda like telco
WordPress plugin hole could have allowed attackers to wipe websites
OpenSSH eases admin hassles with FIDO U2F token support
What do a Lenovo touch pad, an HP camera and Dell Wi-Fi have in common? They’ll swallow any old firmware, legit or saddled with malware