Menu

Gallery

3D printing site Thingiverse suffers breach of 228,000 email addresses amid sluggish disclosure
S3 Ep54: Another 0-day, double Apache patch, and Fight The Phish [Podcast]
US invites friends to multilateral cybersecurity meetings – Russia and China strangely absent
Ad-blocking browser extension actually adds ads, say Imperva researchers
Romance scams with a cryptocurrency twist – new research from SophosLabs
Ex-camera biz Olympus investigating ‘suspicious’ network activity again a month after ransomware hit
Microsoft says Azure fended off what might just be the world’s biggest-ever DDoS attack
Microsoft Patch Tuesday bug harvest festival comes to town
User locked out of Microsoft account by MFA bug, complains of customer-hostile support
Apple patches ‘actively exploited’ iPhone zero-day with iOS 15.0.2 update
Schools email marketing company told us to go away when we told them of exposed database creds, say infoseccers
What’s missing from most ICS cybersecurity training? The ICS itself…
Apple quietly patches yet another iPhone 0-day – check you have 15.0.2
Zero-day hunters seek laws to prevent vendors suing them for helping out and doing their jobs
Russia-based criminals are still the UK’s number 1 cyber-foe, NSO Group’s wares a ‘red flag’ says NCSC chief
Cybersecurity awareness month: Fight the phish!
Brewdog might make an OK pint but its security sucks: Flaw opened door to free beers for anyone
When criminals go corporate: Ransomware-as-a-service, bulk discounts and more
Gripped by cybersec career indecision? Don’t give up. Level up
US nuke sub plans leaked on SD card hidden in peanut butter sandwich, claims FBI
Apache patch proves patchy – now you need to patch the patch
Never mind Russia: Turkey and Vietnam are Microsoft’s new state-backed hacker threats du jour
Air gaps have been ‘shattered’, says new Indian policy on power sector security
Russian spies reportedly used SolarWinds hack to steal US counterintelligence details
You know what ransomware attackers really, really like? Yes, your backups…
S3 Ep53: Apple Pay, giftcards, cybermonth, and ransomware busts [Podcast]
NSO Group’s Pegasus malware was used to spy on Dubai princess’s lawyers during child custody dispute
State-sponsored Chinese crims targeted India with tax and COVID phishing
Are you making good progress with Kubernetes? Cybercriminals are progressing faster
Apache web server zero-day bug is easy to exploit – patch now!
Running a recent Apache web server version? You probably need to patch it. Now
Things that are not PogChamp: Twitch has its source code, streamer payout data leaked
Element celebrates The Great Facebook Outage with a Signal bridge for Matrix
Google to auto-enroll 150m users, 2m YouTubers with two-factor authentication
Europol announces two more ransomware busts in Ukraine
Telegraph newspaper bares 10TB of subscriber data and server logs to world+dog
Lawsuit claims hospital ransomware infection cost baby her life
UK’s £5bn National Cyber Force HQ to be sited in Lancashire beside Defence Secretary’s constituency
Ukrainian cops cuff two over $150m ransomware gang allegations, seize $1.3m in cryptocurrency
Cybersecurity Awareness Month: #BeCyberSmart
Sir Tim Berners-Lee and the BBC stage a very British coup to rescue our data from Facebook and friends
Firewalls? Pfft – it’s no match for my mighty spares-bin PC
Internet Archive’s 2046 Wayforward Machine says Google will cease to exist
Sure, you can do Kubernetes at scale. But can you do it securely too?
That ‘anti-NSO Pegasus spyware’ download is actually a Trojan – so don’t touch it
Gift card fraud: four suspects hit with money laundering charges
IKEA: Cameras were hidden in the ceiling above warehouse toilets for ‘health and safety’
2FA? More like 2F-in-the-way: It seems no one wants me to pay for their services after all
Revealed: How to steal money from victims’ contactless Apple Pay wallets
Ransomware crim: Yeah, what I do is bad. No, I don’t care. Yes, infosec bods are all mouth and no trousers
How to steal money via Apple Pay using the “Express Transit” feature
S3 Ep52: Let’s Encrypt, Outlook leak, and VMware exploit [Podcast]
Which? survey finds people would actually pay the online giants not to take their data
UK MoD data strategy calls for social media surveillance on behalf of ‘local authorities’
How to prevent CSRF attacks in ASP.NET Core
Attacks against Remote Desktop Protocol endpoints have exploded this year, warns ESET’s latest Threat Report
Anonymous: We’ve leaked disk images stolen from far-right-friendly web host Epik
Don’t look a GriftHorse in the mouth: Trojan trampled 10 million Android devices
Unpatched flaw ‘weaponises’ Apple AirTags to turn them into the phisherman’s friend
Akamai beefs up cybersecurity portfolio with ransomware-tastic Guardicore acquisition
Kaspersky links new Tomiris malware to Nobelium group
Give put-upon infosec bods professional recognition to keep them working for you, says chartered institute
REvil customers complain ransomware gang uses backdoors to filch ransoms
ASUS patches ROG Armoury Crate app after researcher spots all-too-common flaw
Serious Security: Let’s Encrypt gets ready to go it alone (in a good way!)
Latest FinFisher spyware upgrades ‘particularly worrying,’ says Kaspersky
How to secure cloud infrastructure across the development lifecycle
UK umbrella payroll firm GiantPay confirms it was hit by ‘sophisticated’ cyber-attack
Microsoft warns: Active Directory FoggyWeb malware being actively used by Nobelium gang
Q2 2022 should see networking sales boom – when payouts to replace Huawei and ZTE kit start to flow
Emails, chat logs, more leaked online from far-right militia linked to US Capitol riot
Blockhead admits to helping North Korea mine crypto-bucks, faces 20 years jail
India, Japan flex cyber-defence muscles as China kicks the Quad
Story of the creds-leaking Exchange Autodiscover flaw – the one Microsoft wouldn’t fix even after 5 years
Move faster with continuous security scanning in the cloud
UK’s National Crime Agency WLTM Deputy Director of Digital Data & Technology
Fake ‘BT’ caller fleeces elderly victim of £30k in APP app scam
Cyber security in the public cloud
‘Quad’ group seeks to set security standards for global tech industry
Frustrated dev drops three zero-day vulns affecting Apple iOS 15 after six-month wait
S3 Ep51: OMIGOD a gaping hole, waybill scams, and Face ID hacked [Podcast]
The real value of continuous security scanning for cloud-based workloads
Stop worrying that crims could break the ‘net, say cyber-diplomats – only nations have tried
Apple warns of arbitrary code execution zero-day being actively exploited on Macs
STILL ALIVE! iOS 12 gets 3 zero-day security patches – update now
How Outlook “autodiscover” could leak your passwords – and how to stop it
UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan
Researchers finger new APT group, FamousSparrow, for hotel attacks
Zoom’s $15bn merger with Five9 probed by Uncle Sam for national security risks
Apple tried to patch this security hole in macOS Finder but didn’t consider upper and lowercase characters
Lithuania tells its citizens to throw Xiaomi mobile devices in the bin
Microsoft Exchange Autodiscover protocol found leaking hundreds of thousands of credentials
VMware patch bulletin warns: “This needs your immediate attention.”
Break out your emergency change process and patch this ransomware-friendly bug ASAP, says VMware
Database containing personal info on 106m people who traveled to Thailand found open to the internet – report
Suex to be you: Feds sanction cryptocurrency exchange for handling payments from 8+ ransomware variants
iOS 15 includes Face ID fix for security bypass using fake heads
Fix network printing or keep Windows secure? Admins would rather disable PrintNightmare patch
UK Ministry of Defence apologises after Afghan interpreters’ personal data exposed in email blunder
Mafia works remotely, too, it seems: 100+ people suspected of phishing, SIM swapping, email fraud cuffed