Menu

Gallery

Fujitsu admits it fluffed the fix for Japan’s flaky ID card scheme
Crook who stole $23m+ in YouTube song royalties gets five years behind bars
It’s 2023 and memory overwrite bugs are not just a thing, they’re still number one
Chinese balloon that US shot down was ‘crammed’ with American hardware
S3 Ep141: What was Steve Jobs’s first job?
Now Apple takes a bite out of encryption-bypassing ‘spy clause’ in UK internet law
Network security guy in extradition tug of war between US and Russia
Interested in $10,000,000? Ready to turn in the Clop ransomware crew?
Miscreants leak texts and info siphoned by Android stalkerware app LetMeSpy
Cops’ total pwnage of ‘secure’ EncroChat nets 6,500+ arrests, €740m in funds – so far
Warning: JavaScript registry npm vulnerable to ‘manifest confusion’ abuse
The unhappy reality of cloud security in 2023
Tackling the cyber skills gap with AI
Cloud security advice and expertise at your fingertips
UK hacker busted in Spain gets 5 years over Twitter hack and more
American and Southwest Airlines pilot candidate data exposed
Ex-FBI employee jailed for taking classified material home
JP Morgan accidentally deletes evidence in multi-million record retention screwup
The unlimited value of a strong defence
Google bug bounties inch closer to Microsoft’s payouts
Aussie PM says, “Shut down your phone every 24 hours for 5 mins” – but that’s not enough on its own
Millions of GitHub repositories vulnerable to RepoJacking: Report
UK cyberspies warn ransomware crews targeting law firms
Keep it schtum!
Chinese malware intended to infect USB drives accidentally infects networked storage too
US cyber ambassador says China knows how to steal its way to dominance of cloud and AI
To kill BlackLotus malware, patching is a good start, but…
Now BlackCat extortionists threaten to leak stolen plastic surgery pics
S3 Ep140: So you think you know ransomware?
The Log4j vulnerability – how can we all do better next time?
Japan’s digital ID card gets emergency review amid data leaks
A clash of titans
Apple patch fixes zero-day kernel hole reported by Kaspersky – update now!
A (cautionary) tale of two patched bugs, both exploited in the wild
Apple squashes kernel bug used by TriangleDB spyware
FTC accuses DNA testing company of lying about dumping samples
Beware bad passwords as attackers co-opt Linux servers into cybercrime
Training in Spanish for cyber security pros
“The Ransomware Documentary” – brand new video series from Sophos starting now!
Oreo cookie maker says crooks gobbled up staff info
Reddit confirms BlackCat gang pinched some data
ASUS warns router customers: Patch now, or block all inbound requests
Over 100,000 compromised ChatGPT accounts found for sale on dark web
Data leak at major law firm sets Australia’s government and elites scrambling
Megaupload duo will go to prison at last, but Kim Dotcom fights on…
Guess what happened to this US agency using outdated software?
Outsource to infill on cyber security
With dead-time dump, Microsoft revealed DDoS as cause of recent cloud outages
GitLab Dedicated offers single-tenant, SaaS-based devsecops
Third MOVEit bug fixed a day after PoC exploit made public
LockBit suspect’s arrest sheds more light on ‘trustworthy’ gang
Capita faces first legal Letter of Claim over mega breach
Microsoft: Russia sent its B team to wipe Ukrainian hard drives
EU boss Breton: There’s no Huawei that Chinese comms kit is safe to use in Europe
US government hit by Russia’s Clop in MOVEit mass attack
MOVEit mayhem 3: “Disable HTTP and HTTPS traffic immediately”
Chinese spies blamed for data-harvesting raids on Barracuda email gateways
S3 Ep139: Are password rules like running through rain?
North Korea created very phishy evil twin of Naver, South Korea’s top portal
Decision to hold women-in-cyber events in abortion-banning states sparks outcry
LockBit victims in the US alone paid over $90m in ransoms since 2020
Lethal weather
Capita wins £50M fraud reporting contract with City of London cops
Bringing security to account: why identity must be unified
Florida man insists he didn’t violate the law by keeping Top Secret docs
Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes
June Patch Tuesday: VMware vuln under attack by Chinese spies, Microsoft kinda meh
Last of the Gozi 3 sentenced over Windows info-stealing malware ops
Gozi banking malware “IT chief” finally jailed after more than 10 years
The commonality of criminal intrusion
These Microsoft Office security signatures are ‘practically worthless’
Malicious hackers are weaponizing generative AI
Russia-Ukraine war sending shockwaves into cyber-ecosystem
UK telco watchdog Ofcom, Minnesota Dept of Ed named as latest MOVEit victims
China’s cyber now aimed at infrastructure, warns CISA boss
India probes medical info ‘leak’ to Telegram
Unsealed: Charges against Russians blamed for Mt Gox crypto-exchange collapse
Fortinet squashes hijack-my-VPN bug in FortiOS gear
Posing as journalists, Pink Drainer pilfers $3.3M in crypto
Microsoft stole our stolen dark web data, says security outfit
History revisited: US DOJ unseals Mt. Gox cybercrime charges
Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors
Hold it – more vulnerabilities found in MOVEit file transfer software
Online muggers make serious moves on unpatched Microsoft bugs
More MOVEit mitigations: new patches published for further protection
FBI: FISA Section 702 ‘absolutely critical’ to spy on, err, protect Americans
Ransomware scum hit Japanese pharma giant Eisai Group
Thoughts on scheduled password changes (don’t call them rotations!)
Seven steps for using zero trust to protect your multicloud estate
Brit data watchdog fines sleazy sales ops £250K for ‘bombarding’ folk with calls
Darkweb credit card marts in decline across Asia, researchers claim
Google changes email authentication after spoof shows a bad delivery for UPS
Robot can rip the data out of RAM chips with chilling technology
North Korea’s Lazarus Group linked to Atomic Wallet heist
Barracuda tells its ESG owners to ‘immediately’ junk buggy kit
Firefox 114 is out: No 0-days, but one fascinating “teachable moment” bug
S3 Ep138: I like to MOVEit, MOVEit
Google puts $1M behind its promise to detect cryptomining malware
New York City latest to sue Hyundai and Kia claiming their cars are too easy to steal
On the frontline of cyber threats