Menu

Gallery

Londoner who tried to blackmail Apple with 300m+ iCloud account resets was reusing stale old creds
What a decade! Our baddest stories and biggest lessons, year by year…
To protect data and code in the age of hybrid cloud, you can always turn to Intel SGX
Serious Security: The decade-ending “Y2K bug” that wasn’t
Patch now: Published Citrix applications leave networks of ‘potentially 80,000’ firms at risk from attackers
Emirati ‘surveillance app’ ToTok promoted by Huawei as Apple punts it from store
Smartphone location data can be used to identify and track anyone
Congress passes anti-robocall bill
Facebook will stop mining contacts with your 2FA number
Say GDP-aaaR: UK’s Information Commissioner pours £275k fine into London pharmacy’s teaspoon
Tracking President Trump with cellphone location data, Greta-Thunberg-themed malware, SharePoint patch, and more
It’s cool for Brit snoops to break the law, says secretive spy court. Just hold on while we pull off some legal jujitsu to let MI5 off the hook…
What’s that? Encryption’s OK now? UK politicos Brexit from Whatsapp to Signal
Five years for the man who scammed Facebook and Google out of $120m by cunning use of email
Twitter trolls attack epileptics with seizure-inducing images
Facebook’s location tracking policy still worries US Senators
What’s behind Putin’s old-school operating system?
Hello ‘123456,’ my old friend, I’ve come to talk with you again
Want to ‘live long and prosper’? Then avoid pirated, malware-laden Star Wars streams and pay to watch
Email blackmail brouhaha tears UKIP apart as High Court refuses computer seizure attempt
Chrome 79 patched after Android WebView app chaos
Get in line! 38,000 students and staff forced to queue for new passwords
Proposed standard would make warrant canaries machine-readable
Instagram hides ‘false’ content, unless it’s from a politician
British bloke accused of extorting victims for ‘Dark Overlord’ hacker crew finally gets his free trip* to America
Das Reboot: Uni forces 38,000 students, staff to queue, show their papers for password reset following ‘cyber attack’
FYI: FBI raiding NSA’s global wiretap database to probe US peeps is probably illegal, unconstitutional, court says
Medical biz LifeLabs fesses up: Hackers slurped 15 million customer records – and we paid them to hand it all back
You leak our secrets? We’ll leak your book sales, speech fees – into our coffers: Uncle Sam wins royalties fight against Edward Snowden
Jet2 hacker who deleted every account on UK company’s domain cops 5 months in jail
BlackBerry tells UK High Court that security outfit SentinelOne is its direct rival
Doxed credit card data has two hours max before it’s nabbed
Mozilla adds NextDNS to list of DNS-over-HTTPS providers
Log us out: Private equity snaffles Lastpass owner LogMeIn
Alleged bank vault robber posed with cash on Instagram, Facebook
Google to choke off ‘less secure applications’
Don’t fall for this porn scam – even if your password’s in the subject!
Half a billion here, half a billion there – pretty soon you’re talking real money: US Congress earmarks $425m for 2020 election security
Ransomware-seized New Orleans declares state of emergency
Researchers discover weakness in IoT digital certificates
Destroyed: A method of destroying Whatsapp group chats forever, say infosec bods of vuln patch
Mozilla mandates 2FA security for Firefox developers
Facebook employees’ payroll data nabbed in car smash-and-grab
London’s Met Police splash the cash on e-learning ‘cyber’ training for 4k staffers
It’s 2019 so, of course, this Wells Fargo employee accused of stealing customer cash posed with wads of dosh on Instagram, Facebook
“Dig up his body,” say creditors of deceased cryptocurrency player
Your workmates might still be reading that ‘unshared’ Slack document
Chinese e-commerce site LightInTheBox.com bared 1.3TB of server logs, user data and more
Plundervolt – stealing secrets by starving your computer of voltage
Police get “unprecedented” data haul from Google with geofence warrants
Npm patches two serious bugs
Google adds Verified SMS and anti-spam feature to Messages app
Emotion-detection in AI should be regulated, AI Now says
VMware warning, OpenBSD gimme-root hole again, telco hit with GDPR fine, Ring camera hijackings, and more
Valuable personal info leaks from Facebook – not Zuck selling it, unencrypted hard drives of staff data stolen
Facebook will target ads based on your Oculus VR data
YouTube bans malicious insults, veiled threats, harassment
Jack Dorsey wants a decentralised Twitter
Weak account checks earn company $10.5 million privacy fine
Ever wonder how hackers could possibly pwn power plants? Here are 54 Siemens bugs that could explain things
NPM swats path traversal bug that lets evil packages modify, steal files. That’s bad for JavaScript crypto-wallets
Iran says it staved off cyber attack but doesn’t blame US
Facebook refuses to break end-to-end encryption
Chrome 79 includes anti-phishing and hacked password protection
Brexit – even cybercriminals want to have their say…
S2 Ep20: Why don’t they send ransomware on floppies anymore?
Disgrace of Base: Scammy hordes force Keybase to end cryptocoin giveaway
It’s time you were T0RTT a lesson: Here’s how you could build a better Tor, say boffins
December Patch Tuesday blunts WizardOpium attack chain
Apple iOS 13.3 is here, bringing support for keyfobby authentication
Microsoft movie tried to Azure Ignite attendees about CPU side-channel flaws, but biz wouldn’t be drawn on details
LightAnchors array: LEDs in routers, power strips, and more, can sneakily ship data to this smartphone app
You had one job, Cupertino: Apple’s Intelligent Tracking Protection actually gets tracking protection
Bad news: KeyWe Smart Lock is easily bypassed and can’t be fixed
Google Chrome will check for breached credentials every time you sign in anywhere
Windows 10 Mobile receives its last security patches
DoItForState domain name thief gets 14 years for pistol-whipping plot
FTC warns Christmas buyers that smart toys are a security risk
Beware of bad Santas this Xmas: Piles of insecure smart toys fill retailers’ shelves
Ad industry groups ask that the CCPA keep its mitts off their cookies
Alleged Nigerian social engineer wins free flight to the US for business email fraud and love scams
It’s the end of the 20-teens, and your Windows PC can still be pwned by nothing more than a simple bad font
Americans should have strong privacy-protecting encryption …that the Feds and cops can break, say senators
Intel might want to reconsider the G part of SGX – because it’s been plunderstruck
Don’t pay off Ryuk ransomware, warn infoseccers: Its creators borked the decryptor
Snatch ransomware pwns security using sneaky ‘safe mode’ reboot
EU releases its 5G conclusions
SIEMs like a stretch: Elastic searches for cash from IT pros with security budgets
Facebook users were duped by Cambridge Analytica, FTC rules
TikTok settles class action over child privacy one day after it’s filed
Advertisers want exemption from web privacy rules that, you know, enforce privacy
Serious Security: Understanding how computers count
Will the new iPhone 11 track you even if you tell it not to?
Ad network ransomware crook to flog £5k Rolex after court confiscates £270k in ill-gotten gains
Metasploit for drones? Best of luck with that, muses veteran tinkerer
Networking attack gives hijackers VPN access
HackerOne pays $20,000 bounty after breach of own systems
Facebook suing ILikeAd for hijacking users’ ad accounts
$5m bounty set on the alleged head of Evil Corp banking Trojan group
OpenBSD bugs, Microsoft’s bad update, a new Nork hacking crew, and more