Menu

Gallery

China orders web operators to spring clean its entire internet
Alert: Let’s Encrypt to revoke about 2 million HTTPS certificates in two days
“PwnKit” security bug gets you root on most Linux distros – what to do
Infosec big dogs break out the bubbly over UK government’s latest cyber strategy emission
Infosec chap: I found a way to hijack your web accounts, turn on your webcam from Safari – and Apple gave me $100k
Linux distros haunted by Polkit-geist for 12+ years: Bug grants root access to any user
Tax scam emails are alive and well as US tax season starts
Sophos: Log4Shell would have been a catastrophe without the Y2K-esque mobilisation of engineers
UK government opens consultation on medic-style register for Brit infosec pros
Yes, your data is special. But do you know how special?
Twitter’s top security staff out after incoming CEO shakes things up
Hive View security camera customers left in the dark as some gear goes TITSUP*
Alleged carder gang mastermind and three acolytes under arrest in Russia
Of hacks and patches
Myanmar’s military junta seeks ban on VPNs and digital currency
Australian Prime Minister’s WeChat Shanghaied by Chinese patriots
Apple preps fix for Safari’s web-history-leaking IndexedDB privacy bug
Rust 1.58.1 fixes dangerous race condition
Arm rages against the insecure chip machine with new Morello architecture
Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft
Why should I pay for that security option? Hijacking only happens to planes
UK, Australia, to build ‘network of liberty that will deter cyber attacks before they happen’
Japan’s Supreme Court rules cryptojacking scripts are not malware
Russia’s Putin out the idea of a broad cryptocurrency ban
Crypto.com now says someone tried to drain $34m from hundreds of accounts
For those worried about Microsoft’s Pluton TPM chip: Lenovo won’t even switch it on by default in latest ThinkPads
Understand Diffie-Hellman key exchange
S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis [Podcast + Transcript]
UK mulls making MSPs subject to mandatory security standards where they provide critical infrastructure
Privacy is for paedophiles, UK government seems to be saying while spending £500k demonising online chat encryption
‘Now’ would be the right time to patch Ubuntu container hosts and ditch 21.04 thanks to heap buffer overflow bug
NortonLifeLock and Avast tie-up falls under UK competition regulator’s spotlight
Red Cross forced to shutter family reunion service following cyberattack and data leak
Being ‘Threat-Led’ is the answer. Your ISO certificate won’t save you from a breach!
McAfee and FireEye rename themselves ‘Trellix’
Singapore gives banks two-week deadline to fix SMS security
Need to prioritize security bug patches? Don’t forget to scan Twitter as well as use CVSS scores
Sniff those Ukrainian emails a little more carefully, advises Uncle Sam in wake of Belarusian digital vandalism
Faker NPM package back on track after malicious coding incident
Vulnerabilities and censorship tools among hot new features in Beijing’s Olympics app
US mergers doubled in 2021 so FTC and DoJ seek new guidelines to stop illegal ones
Crypto.com acknowledges ‘unauthorized activity’ on servers, maintains no funds have been lost
Suse open sources NeuVector container security platform
Serious Security: Apple Safari leaks private data via database API – what you need to know
International police shut down 15 server infrastructures as part of VPNLab.net’s takedown
More contractor pain: Parasol’s sister firms, SJD Accountancy and Nixon Williams, confirm cyberattack
Singapore monetary authority threatens action on bank over widespread phishing scam
Why global DDoS protection is essential for Anycast networks
Microsoft patches the patch that broke VPNs, Hyper-V, and left servers in boot loops
Bug in WebKit’s IndexedDB implementation makes Safari 15 leak Google account info… and more
Ukraine blames Belarus for PC-wiping ‘ransomware’ that has no recovery method and nukes target boxen
Romance scammer who targeted 670 women gets 28 months in jail
Umbrella company Parasol Group confirms cyber attack as ‘root cause’ of prolonged network outage
North Korea pulled in $400m in cryptocurrency heists last year – report
Russia starts playing by the rules: FSB busts 14 REvil ransomware suspects
Serious Security: Linux full-disk encryption bug fixed – patch now!
Multi-day IT systems outage whacks umbrella biz Parasol Group amid fears of a cyber attack
Ukraine shrugs off mass govt website defacement as world turns to stare at Russia
REvil ransomware crew allegedly busted in Russia, says FSB
Visibility, immutability, security … a revolutionary approach to fighting off ransomware
Federal Communications Commission proposed stricter rules on how telco carriers should report data breaches
Orca Security tells AWS fail tale with a happy ending
Continuous security and compliance for hybrid cloud, the Red Hat way
Ukrainian cops nab husband and wife suspected to be part of $1m ransomware operation
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle [Podcast + Transcript]
Austrian watchdog rules German company’s use of Google Analytics breached GDPR by sending data to US
Admins report Hyper-V and domain controller issues after first Patch Tuesday of 2022
Volunteer Dutch flaw finders bag $100k to forward national bug bounty goal
Ransomware puts New Mexico prison in lockdown: Cameras, doors go offline
Ransomware demands… a new approach to security
Wormable Windows HTTP hole – what you need to know
Info-saturated techie builds bug alert service that phones you to warn of new vulns
Microsoft starts 2022 with big bundle fixes for 96 security bugs in its software
Make sure you’re up-to-date with Sonicwall SMA 100 VPN box patches – security hole exploit info is now out
Home routers with NetUSB support could have critical kernel hole
EU data watchdog to Europol: You’ve helped yourself to too much data
Secure boot for UK electric car chargers isn’t mandatory until 2023 – but why the delay?
Four million outdated Log4j downloads were served from Apache Maven Central alone despite vuln publicity blitz
Signal CEO Moxie Marlinspike resigns, leaves WhatsApp co-founder to run things until a successor is named
JavaScript developer destroys own projects in supply chain “lesson”
Avira also mines imaginary internet money on customers’ PCs
China puts Walmart in the naughty corner, citing 19 alleged cybersecurity ‘violations’
GCHQ was rebuked for ignoring spy law safeguards as pandemic hit Britain
No defence for outdated defenders as consumer AV nears RIP
WebSpec, a formal framework for browser security analysis, reveals new cookie attack
Honda cars in flashback to 2002 – “Can’t Get You Out Of My Head”
Log4Shell-like security hole found in popular Java SQL database engine H2
Salesforce mandates MFA by default
Your backups can save you from ransomware. But how do you protect your backups?
S3 Ep64: Log4Shell again, scammers keeping busy, and Apple Home bug [Podcast + Transcript]
You better have patched those Log4j holes or we’ll see what a judge has to say – FTC
US Army journal’s top paper from 2021 says Taiwan should destroy TSMC if China invades
FTC threatens “legal action” over unpatched Log4j and other vulns
Remember Norton 360’s bundled cryptominer? Irritated folk realise Ethereum crafter is tricky to delete
Windows giant seeks Pluton-ic relationship with chip maker: AMD first out of the gates with Microsoft’s security processor
How ransomware gangs went pro
SlimPay fined €180k after 12 million customers’ bank data publicly accessible for 5 years
Apple Home software bug could lock you out of your iPhone
John Edwards takes the reins at the UK’s data protection watchdog
2022: The year of software supply chain security