Menu

Gallery

You’ve trained at the cutting edge, here’s how to keep your DFIR skills razor sharp
Apache OpenOffice can be hijacked by malicious documents, fix still in beta
Ransomware recovery: Start getting back up before you’re even hit
“Back to basics” as courier scammers skip fake fees and missed deliveries
Tick, tick, tick … TikTok China just limited kids to 40 minutes’ use each day
Yes, of course there’s now malware for Windows Subsystem for Linux
Something phishy: Tech recruiters jabbed by fake COVID-19 Passport scam
Is it OK to use stolen data? What if it’s scientific research in the public interest?
WTF? Microsoft makes fixing deadly OMIGOD flaws on Azure your job
Aviation-themed phishing campaign pushed off-the-shelf RATs into inboxes for 5 years
Hack yourself before someone else does it for you
OMIGOD, an exploitable hole in Microsoft open source code!
Ransomware-hit law firm secures High Court judgment against unknown criminals
Computer and data scientists should be as highly regarded as ‘warriors’ says top UK cybergeneral
De-identify, re-identify: Anonymised data’s dirty little secret
It’s time to delete that hunter2 password from your Microsoft account, says IT giant
This is AUKUS for China – US, UK, Australia reveal defence tech-sharing pact
S3 Ep50: Two 0-days plus another 0-day plus a fast food bug [Podcast]
Ransomware crims saying ‘We’ll burn your data if you get a negotiator’ can’t be legally paid off anyway
Ex-US intel, military trio were cyber-mercenaries for UAE, say prosecutors
Microsoft’s end-of-summer software security cleanse crushes more than 80 bugs
Krita art app users targeted by ransomware posing as paid ‘collaboration’ opportunities
Security bods boost Apple iPhone hardware attack research with iTimed toolkit
Brits open doors for tech-enabled fraudsters because they ‘don’t want to seem rude’
Thousands of internet-connected databases contain high or critical CVEs, says report by cloud security biz
ExpressVPN bought for $1bn by Brit biz with an intriguing history in adware
Apple products vulnerable to FORCEDENTRY zero-day attack – patch now!
Apple emergency patches fix zero-click iMessage bug used to inject NSO spyware
How a glitch in the Matrix led to apps potentially exposing encrypted chats
Serious Security: How to make sure you don’t miss bug reports!
Open redirect on UK council website was being used for Royal Mail-themed parcel payments scam
You can ‘go your own way’ over GDPR, says UK’s new Information Commissioner
WhatsApp to offer end-to-end encrypted backups in iCloud, Google Drive with user-managed keys
Hey – how did you get in here? Number one app security weakness of 2021 was borked access control, says OWASP
S3 Ep49: Poison PACs, pointless alarms and phunky bugs [Podcast]
McDonald’s email blunder broadcasts database creds to comedy competition winners
LA cops told to harvest social media handles from people they stop, suspect or not
Microsoft fixes flaw that could leak data between users of Azure container services
New Zealand DDoS wave targets banks, post offices, weather forecasters and more
Proton welcomes Sir Tim Berners-Lee to its advisory board – as ProtonMail suffers a privacy backlash
3 years, 17 alphas, 2 betas, and over 7,500 commits later, OpenSSL version 3 is here
Windows zero-day MSHTML attack – how not to get booby trapped!
UK.gov is launching an anti-Facebook encryption push. Don’t think of the children: Think of the nuances and edge cases instead
AT&T Alien Labs warns of ‘zero or low detection’ for TeamTNT’s latest malware bundle
Global pandemic was good for business, say UK infosec pros – but we’re still burning out
Patch now? Why enterprise exploits are still partying like it’s 1999
Ransomware attacks are inevitable. Paying the ransom isn’t
Miscreants fling booby-trapped Office files at victims, no patch yet, says Microsoft
Can WhatsApp moderators really read your encrypted texts? Yes … if you forward them to the abuse dept
British data watchdog brings cookies to G7 meeting – pop-up consent requests, not the delicious baked treats
ProtonMail deletes ‘we don’t log your IP’ boast from website after French climate activist reportedly arrested
Guntrader breach perp: I don’t think it’s a crime to dump 111k people’s details online in Google Earth format
Glasgow firm fined £150k after half a million nuisance calls, spoofing phone number, using false trading names
Poisoned proxy PACs! The NPM package with a network-wide security hole…
Jenkins struck by ‘Confluenza’ as US Cyber Command warns Atlassian flaw ‘cannot wait’
When the bits hit the fan: What to do when ransomware strikes
Indonesian President’s COVID jab cert leaks – authorities argue that’s perfectly reasonable
Norwegian student tracks Bluetooth headset wearers by wardriving around Oslo on a bicycle
Apple stalls CSAM auto-scan on devices after ‘feedback’ from everyone on Earth
Rapid7 says Computer Misuse Act should include ‘good faith’ infosec research exemption
New Zealand internet outage blamed on DDoS attack on nation’s third largest internet provider
S3 Ep48: Cryptographic bugs, cryptocurrency nightmares, and lots of phishing [Podcast]
Confessions of a ransomware negotiator: Well, somebody’s got to talk to the criminals holding data hostage
Spring or autumn, your biggest cyber threat could be in the cloud
FTC bans ‘brazen’ stalkerware maker SpyFone, orders data deletion, alerts to victims
NSA: We ‘don’t know when or even if’ a quantum computer will ever be able to break today’s public-key encryption
Autodesk was one of the 18,000 firms breached in SolarWinds attack, firm admits
Pwned! The home security system that can be hacked with your email address
In space, no one can hear cyber security professionals scream
UK VoIP telco receives ‘colossal ransom demand’, reveals REvil cybercrooks suspected of ‘organised’ DDoS attacks on UK VoIP companies
How to secure REST with Spring Security
Dissected: A dropper-as-a-service miscreants pay to push their malware onto potentially 1,000s of victims
Fired credit union employee admits: I wiped 21GB of files from company’s shared drive in retaliation
Relax, says NSA: There’s no such thing as a quantum computer that’ll crack current encryption algos
Indonesian authorities probe million-record leak from national COVID app
Singapore adds a third bug bounty program – this time to fortify government digital services
US officials, experts fear China ransacked Exchange servers for data to train AI systems
Skimming the CREAM – recursive withdrawals loot $13M in cryptocash
Leaked Guntrader firearms data file shared. Worst case scenario? Criminals plot UK gun owners’ home addresses in Google Earth
Drowning in cybersecurity info? Make a dash to Security SOS Week 2021
Bangkok Airways hit by LockBit ransomware attack, loses lotsa data after refusing to pay
Boffins find if you torture AMD Zen+, Zen 2 CPUs enough, they are vulnerable to Meltdown-like attack
Microsoft warns of widespread open redirection phishing attack – which Defender can block, coincidentally
Slap on wrist for NCC Group over CREST exam-cheating scandal as infosec org agrees to rewrite NDAs and more
Azure’s now-fixed Cosmos DB flaw could have been exploited to read, write any database
Big bad decryption bug in OpenSSL – but no cause for alarm
S3 Ep47: Daylight robbery, spaghetti trouble, and mousetastic superpowers [Podcast]
Surveillance tech company sues Police Digital Service over ‘flawed’ scoring of bids on £18m contract
Big tech proud as punch about cameos in Joe Biden’s security theatre
Atlassian warns of critical Confluence flaw
Israeli firm Bright Data named as enabler of Philippines government DDOS attacks on opposition groups
ProxyLogon flaw, evil emails, SQL injections used to open backdoors on Windows boxes
Mirai-style IoT botnet is now scanning for router-pwning critical vuln in Realtek kit
Security blind spots persist as companies cross-breed security with devops
Fake Apple rep amasses 620,000+ stolen iCloud pics, vids in hunt for images of nude women to trade
How a gaming mouse can get you Windows superpowers!
Proofpoint wins $14m from ex-VP and French email security rival in IP theft court battle
Microsoft, Google partner on eBPF
Chinese auto-maker accused of altering data after fatal autonomous car accident
Poly Network says it’s got pretty much all of that $610m in stolen crypto-coins back