Menu

Gallery

Instagram copyright infringment scams – don’t get sucked in!
Log4Shell vulnerability Number Four: “Much ado about something”
What most cloud-using CIOs want in 2022
What app developers need to do now to fight Log4j exploits
SFW! The Top N Cyber­security Stories of 2021 (for small positive integer values of N)
Four years: that’s how long Azure’s App Service had a source code leak bug
The cool retro phone with a REAL DIAL… plus plenty of IoT problems
Fisher Price’s Bluetooth reboot of pre-school play phone has adult privacy flaw
Alibaba Cloud slapped by Chinese ministry for mishandling Log4j
Plundered bitcoins recovered by FBI – all 3,879-and-one-sixth of them!
Of course a Bluetooth-using home COVID test was cracked to fake results
How to tackle hybrid cloud security and DevSecOps
Why SBOM management is no longer optional
Apache’s other product: Critical bugs in ‘httpd’ web server, patch now!
Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability
UK National Crime Agency finds 225 million previously unexposed passwords
US bags Russian accused of stealing millions after stealing pre-release financial filings
Police National Computer not pwned by Clop ransomware crims, insists Home Office
Log4Shell: The Movie… a short, safe visual tour for work and home
How to keep on top of cloud security best practices
VMware 2FA flaw can divulge that vital second credential to malicious actors
Bad things come in threes: Apache reveals another Log4J bug
US distrust of Huawei linked in part to malicious software update in 2012
CISA issues emergency directive to fix Log4j vulnerability
Serious Security: OpenSSL fixes “error conflation” bugs – how mixing up mistakes can lead to trouble
RAF shoots down ‘terrorist drone’ over US-owned special ops base in Syria
Over Log4j? VMware has another critical flaw for you to patch
Facebook locks out 1,500 fake accounts used by cyber-spy firms to snoop on people, alerts 50k potential targets
Why ransomware attacks happen out of hours or during the holidays
S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]
East Londoners nicked under Computer Misuse Act after NHS vaccine passport app sprouted clump of fake entries
How developers scrambled to secure the Log4j vulnerability
Move fast, break security: Why CISOs must push back against Agile IT
National Cyber Strategy will lead to BritChip for mobile devices by 2025, claims UK.gov
Japan draws a LINE: web giants must reveal where they store user data
Facebook expands bug bounty program to include scraping attacks, two years after it was scraped – hard
As CISA tells US govt agencies to squash Log4j bug by Dec 24, fingers start pointing at China, Iran, others
US lawmakers want to put NSO Group, 3 other spyware makers out of business with fresh severe sanctions
Pen Test Partners: Anyone could view Gumtree users’ GPS location by pressing F12
Securing the Kubernetes software supply chain
Microsoft closes installer hole abused by Emotet malware, Google splats Chrome bug exploited in the wild
Apache takes off, nukes insecure feature at the heart of Log4j from orbit with v2.16
You may have cracked serverless development, but it’s almost certain you haven’t solved serverless security
Popular password manager LastPass to be spun out from LogMeIn
MPs charged with analysing Online Safety Bill say end-to-end encryption should be called out as ‘specific risk factor’
Apple security updates are out – and not a Log4Shell mention in sight
Log4j RCE latest: In case you hadn’t noticed, this is Really Very Bad, exploited in the wild, needs urgent patching
When disaster strikes, data recovery really is a race against time
Is VPOTUS Bluetooth-phobic or sensible? The answer’s pretty clear
Timekeeping biz Kronos hit by ransomware and warns customers to engage biz continuity plans
Ooh, an update. Let’s install it. What could possibly go wro-
Log4Shell explained – how it works, why you need to know, and how to fix it
How to detect the Log4j vulnerability in your applications
Irish Health Service ransomware attack happened after one staffer opened malware-ridden email
“Log4Shell” Java vulnerability – how to safeguard your servers
Log4j RCE: Emergency patch issued to plug critical auth-free code execution hole in widely-used logging utility
Revealed: Remember the Sony rootkit rumpus? It was almost oh so much worse
Ransomwared payroll provider leaks data on 38,000 Australian government workers
A third of you slackers out there still aren’t using HTTPS by default
S3 Ep62: The S in IoT stands for security (and much more) [Podcast+Transcript]
Resistance is … cheap? Cloudflare, Mandiant, and pals form incident response ‘n’ cyber insurance borg
Ransomware giving you sleepless nights? Here’s how to insure a good night’s sleep
Oz Feds reveal distribution model behind backdoored ‘An0m’ chat app spread by crims
Canadian charged with running ransomware attack on US state of Alaska
Not all tech disasters are ‘all hands’ events. But how do you tell which is which?
Virgin Media fined £50,000 after spamming 451,000 who didn’t want marketing emails
What’s the right amount of trust to build into your network? Less than Zero
Microsoft extends Secured-core concept to servers
Firefox update brings a whole new sort of security sandbox
Cryptominers aren’t just a headache – they’re a big neon sign that Bad Things are on your network
Foreign Office IT chaos: Shocking testimony reveals poor tech support hindered Afghan evac attempts
Integrate security into CI/CD with the Trivy scanner
Microsoft wins court approval to take over sites run by Chinese crime gang
LINE Pay leaks around 133,000 users’ data to GitHub, of all places
Spar shops across northern UK shut after cyber attack hits payment processing abilities
Miscreants make off with $150m of digital assets in BitMart security breach
Cryptocurrency startup fails to subtract before adding, loses $31m
Cuba ransomware gang scores almost $44m in ransom payments across 49 orgs, say Feds
American diplomats’ iPhones reportedly compromised by NSO Group intrusion software
Utility biz Delta-Montrose Electric Association loses billing capability and two decades of records after cyber attack
Feds charge two men with claiming ownership of others’ songs to steal YouTube royalty payments
Protecting your critical infrastructure is one thing…protecting your backups is the same thing
Mozilla patches critical “BigSig” cryptographic bug: Here’s how to track it down and fix it
Netgear router flaws exploitable with authentication … like the default creds on Netgear’s website
BadgerDAO DeFi defunded as hackers apparently nab millions in crypto tokens
S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast]
IoT devices must “protect consumers from cyberharm”, says UK government
New UK product security law won’t be undercut by rogue traders upping and vanishing, government boasts
European Cybercrime Centre confident it’s kicked credit card crims – again
Three key ransomware actors changed jobs on October 18 – the same day REvil went dark
Rewriting your disaster recovery plan might just save your company…and could transform it
Singapore and UK ink digital trade agreements at Future Tech Forum in London
UK watchdog’s punishment for Blackbaud, Easyjet, other big privacy lawbreakers was slap on the wrist in private
UK intel chief says MI6 must outsource innovation – and James Bond’s in-house ‘Q’ is nonsense
It’s the flu season – FluBot, that is: Surge of info-stealing Android malware detected
Visiting a booby-trapped webpage could give attackers code execution privileges on HP network printers
Controversial face matchers Clearview set to be fined over $20m
Leaked footage shows British F-35B falling off HMS Queen Elizabeth and pilot’s death-defying ejection
Lloyd’s of London suggests insurers should not cover ‘retaliatory cyber operations’ between nation states
Winter is coming … with a blizzard of live and virtual SANS Institute events