Menu

Gallery

Fraudsters posed as art dealer, bilked museum for millions
Cover for ‘cyber’ attacks is risky, complex and people don’t trust us, moan insurers
Google launches open-source security key project, OpenSK
WannaCry ransomware attack on NHS could have triggered NATO reaction, says German cybergeneral
Flaws punched holes in Azure cloud, Apple patches pretty much everything, Eurocops cuff Maltese hackers, etc
Remember those infosec fellas who were cuffed while testing the physical security of a courthouse? The burglary charges have been dropped
Serious Security – How ‘special case’ code blew a hole in OpenSMTPD
UN hacked via unpatched SharePoint server
China’s Winnti hackers (apparently): Forget the money, let’s get political and start targeting Hong Kong students for protest info
US Interior Dept extends drone grounding over foreign hacking fears
Financial tech firms disagree on ban of customer data screen-scraping
A year after Bank of Valletta ‘cyber heist’, cuffs applied as cash-cleansing case continues
Attempts to define international infosec rules of the road bogged down by endless talkshops, warn diplomats
Facebook to pay $550m to settle face-tagging suit
Trello exposed! Search turns up huge trove of private data
Facebook knows a lot about your online habits – here’s how to stop it
Difficult season: Antivirus-flinger Avast decides to ‘wind down’ Jumpshot
Employers can’t force you to get microchipped, Indiana reps say
Government spyware company spied on hundreds of innocent people
If only 3 in 100,000 cyber-crimes are prosecuted, why not train cops to bring these crooks to justice once and for all, suggests think-tank veep
Anatomy of OpenBSD’s OpenSMTPD hijack hole: How a malicious sender address can lead to remote pwnage
UN didn’t patch SharePoint, got mega-hacked, covered it up, kept most staff in the dark, finally forced to admit it
Apple patches critical bugs on iPhone and Mac – update now!
Canadian insurer paid for ransomware decryptor. Now it’s hunting the scum down
Intel promises fix after researchers reveal ‘CacheOut’ CPU flaws
Anatomy of a “free” gift – how online surveys can harm your digital health
Only 6 ransomware attacks on the UK’s NHS since WannaCry worm hit in 2017 – report
Let’s make ransomware MORE illegal, says Maryland
Fraud spike prompts Chrome developer lock-out
15 NFL teams’ Twitter hijacked in lead-up to the Super Bowl
How AI will improve API security
Dear friends in DevSecOps: Don’t forget, security is your responsibility, too – now learn how to do it right
Cache flow problems continue for Intel: Yet more data-leaking processor design blunders discovered, patches due soon
Coronavirus claims new victim: ‘DEF CON cancelled’ joke cancelled after DEF CON China actually cancelled
5 ways to be a bit safer this Data Privacy Day
IoT security? We’ve heard of it, says UK.gov waving new regs
The duke of URL: Zoom meetups’ info leaked out through eavesdrop hole
States sue over rules that allow release of 3D-printed gun blueprints
Facial recognition firm sued for scraping 3 billion faceprints
Cisco patches bugs in security admin center and Webex
Mozilla bans Firefox extensions for executing remote code
NetWars! Let the SANS Tournaments commence: Compete and learn all about forensics, incident response, red teaming – and much more
Remember the Clipper chip? NSA’s botched backdoor-for-Feds from 1993 still influences today’s encryption debates
Google halts paid-for Chrome extension updates amid fraud surge: Web Store in lockdown ‘due to the scale of abuse’
Maryland: Make malware possession a crime! Yes, yes, researchers get a free pass
Cisco Webex bug allowed anyone to join a password-protected meeting
Cardplanet mastermind pleads guilty to credit card fraud
Tinder to get panic button, catfish-fighting facial recognition
Instagram CEO’s homes were targetted by SWATters
New York wants to ban taxpayer-funded ransomware payments
Teenagers today. Can’t take them anywhere, eh? 18-year-old kid accused of $50m SIM-swap cryptocurrency heist
2015-member database floats off through breach in Royal Yachting Association’s hull
Google finds privacy holes in Safari’s ITP anti-tracking system
Protestors petition equity firm over .org buyout
9th Methbot suspect arrested in massive clickfraud ring
Privacy watchdog throws wider net to protect children online
Russian super-crook behind $20m internet fraud den Cardplanet and malware-exchange forum pleads guilty
We need to make it even easier for UK terror cops to rummage about in folks’ phones, says govt lawyer
Looking for silver linings in the CVE-2020-0601 crypto vulnerability
Ooh, watch out Google. You’ve got competition. Verizon has a new ‘privacy-focused’ search engine
UN report alleges that Saudi crown prince hacked Jeff Bezos’s phone
Apple allegedly made nice with FBI by dropping iCloud encryption plan
Sonos’s tone-deaf legacy product policy angers customers
FBI issues warning about lucrative fake job scams
Still losing sleep over that awful Citrix bug? This scanner is here to help… you realize you’ve already been pwned
Who honestly has a crown prince in their threat model? UN report officially fingers Saudi royal as Bezos hacker
Safari’s Intelligent Tracking Protection is misspelled, says Google: It should be Dumb Browser Stalking Enabler
Big Microsoft data breach – 250 million records exposed
Academics call for UK’s Computer Misuse Act 1990 to be reformed
WindiLeaks: Microsoft exposes 250 million customer support records dating back to 2005 (Not on purpose though)
Ubisoft sues DDoS-for-hire operators for ruining game play
NIST’s new privacy rules – what you need to know
Regus spills data of 900 staff on Trello board set to ‘public’
Nobody boogies quite like you
Capita Education Services accidentally spaffs email addresses in Helpdesk snafu
Crown Prince of Saudi Arabia accused of hacking Jeff Bezos’ phone with malware-laden WhatsApp message
No backdoors needed: Apple ditched plans to fully encrypt iCloud backups after heavy pressure from FBI – claim
WTF, EFS? Experts warn Windows encryption could spawn nasty new ransomware
Citrix ships patches as vulnerable servers come under attack
China and US top user data requests in Apple transparency report
What do online file sharers want with 70,000 Tinder images?
Leave your admin interface’s TLS cert and private key in your router firmware in 2020? Just Netgear things
Citrix emits patches to stop RCE-holes fiddling with Gateway and ADC
Ubisoft sues handful of gamers for DDoSing Rainbow Six: Siege
LastPass stores passwords so securely, not even its users can access them
FBI seizes credentials-for-sale site WeLeakInfo.com
FBI to inform election officials about hacking attempts
Teen entered ‘dark rabbit hole of suicidal content’ online
Hospital hacker spared prison after plod find almost 9,000 cardiac images at his home
Facebook and Instagram ban alleged ‘brainwashing’ service
To catch a thief, go to Google with a geofence warrant – and it will give you all the details
It’s Friday, the weekend has landed… and Microsoft warns of an Internet Explorer zero day exploited in the wild
‘Friendly’ hackers are seemingly fixing the Citrix server hole – and leaving a nasty present behind
5 tips to avoid spear-phishing attacks
Stolen creds site WeLeakInfo busted by multinational cop op for data reselling
Oracle’s January 2020 update patches 334 security flaws
Google will now accept your iPhone as an authentication key
Facial recognition is real-life ‘Black Mirror’ stuff, Ocasio-Cortez says
EDRi’s guidelines call for more ethical websites
Unlocking news: We decrypt those cryptic headlines about Scottish cops bypassing smartphone encryption