Menu

Gallery

Panasonic admits intruders were inside its servers for months
Wind turbine maker Vestas confirms recent security incident was ransomware
Australia will force social networks to identify trolls, so they can be sued for defamation
Cloud Security: Don’t wait until your next bill to find out about an attack!
EU needs more cybersecurity graduates, says ENISA infosec agency – pointing at growing list of master’s degree courses
Privacy Sandbox saga continues: UK watchdog extracts more commitments from Google over ad tech
Government-favoured child safety app warned it could violate the UK’s Investigatory Powers Act with message-scanning tech
If you want to see off next year’s cyber-threats, the time to prepare is … now
Microsoft Defender for Endpoint laid low. Not by malware, but by another buggy Windows patch
It’s about the survival of the fittest – CISOs must be brave enough to throw away their security playbook, or suffer the consequences
S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public [Podcast]
UK.gov emits draft IoT and smartphone security law for Parliamentary scrutiny
Google advises passwords are good, spear phishing is bad, and free clouds get attacked
Huawei’s AppGallery riddled with malware-infected games
US bans Chinese firms – including one linked to HPE’s China JV – for feeding tech to Beijing’s military
US government securities watchdog spoofed by investment scammers – don’t fall for it!
Max Schrems hits Irish Data Protection Commissioner with corruption complaint
How a malicious Android app could covertly turn the DSP in your MediaTek-powered phone into an eavesdropping bug
Yes, ransomware is your number one security nightmare. But here’s how to sleep easy
China trying to export its Great Firewall and governance model
Apple sues ‘amoral 21st century mercenaries’ NSO for infecting iPhones with Pegasus spyware
Zero-day proof-of-concept exploit lands for Windows make-me-admin vulnerability
Crypto for cryptographers! Infosec types revolt against use of ancient abbreviation by Bitcoin and NFT devotees
Check your patches – public exploit now out for critical Exchange bug
UK Ministry of Justice secures HVAC systems ‘protected’ by passwordless Wi-Fi after Register tipoff
Infosec bods: After more than a year, Sky gets round to squashing hijacking bug in 6m home broadband routers
Indian bank smacks down allegation it exposed 180 million customers’ accounts
GoDaddy admits to password breach: check your Managed WordPress site!
SSL keys, sFTP passwords and more exposed after someone broke into GoDaddy Managed WordPress using ‘compromised password’
Ecommerce platforms (cough, Magento) need patching before Black Friday, warns UK’s National Cyber Security Centre
Turbine maker Vestas Wind Systems admits to cyber incident, refuses to confirm if ransomware is at play
Black Friday and Cyber Monday – here’s what you REALLY need to do!
Nigeria’s central bank digital currency is ‘same Naira, more possibilities’ – if you count government snooping
GitHub will require 2FA for some NPM registry users
A tiny typo in an automated email to thousands of customers turns out to be a big problem for legal
After four bans, TikTok finally passes the Pakistan challenge
Amazon India execs charged after sellers allegedly use site to smuggle marijuana
Security is the Achilles’ heel of multicloud
Defending critical infrastructure: The status quo isn’t working
Web trust dies in darkness: Hidden Certificate Authorities undermine public crypto infrastructure
Canadian teen nabbed in $36.5M crypto heist – possibly the biggest haul yet by a single individual
Boffins find way to use a standard smartphone to find hidden spy cams
Github cookie leakage – thousands of Firefox cookie files uploaded by mistake
A quick guide to modern cryptography
Thousands of Firefox users accidentally commit login cookies on GitHub
S3 Ep59: Emotet, an FBI hoax, Samba bugs, and a hijackable suitcase [Podcast]
What’s the biggest threat to your best-laid plans? Events, dear boy. Events
Singaporean regulator punishes biggest-ever data breach: Almost 5.9 million hotel customers’ info exposed
Cybercriminals are looking forward to 2022, so you need to plan your response now
Apple’s Privacy Protection feature – watch out if you have a Watch!
UK government publishes guidance on security rules for tech takeovers
You wanna use GCHQ offshoot NCSC’s threat intel feeds? Why not, say bosses
The race to secure Kubernetes at run time
South Korean privacy watchdog apologises for violating privacy while mediating privacy lawsuit
The inside story of ransomware repeatedly masquerading as a popular JS library for Roblox gamers
Lock up your Office macros: Emotet botnet back from the dead with Trickbot links
GitHub fixes authorisation vulnerability in the NPM JavaScript package registry
The self-driving smart suitcase… that the person behind you can hijack!
Mozilla sprinkles Firefox Relay with Premium fairy dust
Not only MSPs: All cloudy firms are in line for UK security law crackdown
Emotet malware: “The report of my death was an exaggeration”
Intel’s recent Atom, Celeron, Pentium chips can be lulled into a debug mode, potentially revealing system secrets
If cybercriminals can’t see data because it’s encrypted, they have nothing to steal
China Telecom’s US arm sues in last-ditch bid to retain license
Chinese Communist Party official expelled for mining cryptocurrency
When the world ends, all that will be left are cockroaches and new Rowhammer attacks: RAM defenses broken again
America, when you’re done hitting us with the ban hammer, see these on-prem Zoom vulns, says Positive
Email encryption should be a no-brainer, not a brain melter
There’s something to be said for delayed gratification when Windows 11 is this full of bugs
3 reasons devops must integrate agile and ITSM tools
FBI spams thousands with fake infosec advice after ‘software misconfiguration’
DHS warning about hackers in your network? Don’t panic!
ChaosDB: Infosec bods could pull anyone’s plaintext Azure Cosmos DB keys at will from Microsoft admin tools
Samba update patches plaintext passwork plundering problem
AMD reveals an EPYC 50 flaws – 23 of them rated High severity. Intel has 25 problems, too
Philippines gov takes down passport application website amid privacy leak fears
Dutch newspaper accuses US spy agencies of orchestrating 2016 Booking.com breach
If even tech leaders struggle with email encryption, are we all doomed?
S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust [Podcast]
Palo Alto Networks patches 9.8 severity CVE in popular GlobalProtect product
Malicious Chrome extensions are bad. But what about nice ones that can be hijacked? This new tool spots them
Ransomware: The ones that got away (with it)
USA signs internet freedom and no-hack pact it’s ignored since 2018
New Zealand spooks say satellite snooping is obsolete – better intel is found elsewhere
Patch Tuesday updates the Win 7 updater… for at most 1 more year of updates
Boat biz breaches itself: Brittany Ferries ‘fesses up to leaks caused by routine website update
Stor-a-File hit by ransomware after crooks target SolarWinds Serv-U FTP software
Former Broadcom engineer accused of pinching chip tech to share with new Chinese employer
Let us give thanks that this November, Microsoft has given us just 55 security fixes, two of which are for actively exploited flaws
Shotgun targeting of malware attacks will be the defining infosec theme of 2022, reckons Sophos
Sophos 2022 Threat Report: Malware, Mobile, Machine learning and more!
The future of OT security in an IT-OT converged world
Indian securities depository exposed 44 million investors’ personal info – twice
Investment app Robinhood: Extortionist tricked our support desk and made off with customer information
NSO fails once again to claim foreign sovereign immunity in WhatsApp spying lawsuit
Kaseya ransomware suspect nabbed in Poland, $6m seized from absent colleague
Ukrainian cuffed, faces extradition to US for allegedly orchestrating Kaseya ransomware infection
Will they try it for 30 days first? McAfee goes private again in $14bn cash deal
You’ll never guess who’s been exploiting the ManageEngine service to steal passwords
Angling (re)Direct: Criminals net website of Brit fishing tackle retailer, send users straight to smut site