‘Cable Haunt’ vulnerability exposes 200M cable modem users

A fortnight in to 2020 and we have the first security flaw to be given its own name: Cable Haunt – complete with eye-catching logo. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

NSA and GitHub ‘Rickrolled’ Using Windows CryptoAPI Bug

We said, “Assume that someone will find out how to do it pretty soon,” and that’s exactly what happened. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Powerful GPG collision attack spells the end for SHA-1

New research has heightened an already urgent call to abandon SHA-1, a cryptographic algorithm still used in many popular online services. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Plundervolt – stealing secrets by starving your computer of voltage

Turns out that if you drop your CPU voltage just enough, it makes mistakes that could let you sneak in where you shouldn’t. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Fake Android apps uploaded to Play store by notorious Sandworm hackers

The Russian ‘Sandworm’ hacking group has been caught repeatedly uploading fake and modified Android apps to Google’s Play Store. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Google plans to take Android back to 'mainline' Linux kernel

Android could be returning to its roots. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Scammers deepfake CEO’s voice to talk underling into $243,000 transfer

The voice had the hint of a German accent and the same “melody” that an employee recognized in his boss’s voice. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Vulnerability in content distribution networks found by researchers

Researchers have found a flaw that could lead to denial of service attacks on content distribution networks around the world. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Samsung Galaxy S10 fingerprint reader beaten by $3 gel protector

The fingerprint reader on Samsung’s flagship S10 and Note10 smartphones can be spoofed with a $3 screen protector. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Facebook flags thousands of kids as interested in gambling, booze

According to a new report, its algorithmic labelling may expose minors to age-inappropriate, targeted advertising. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Darknet hosting provider in underground NATO bunker busted

Police overcame not only digital defenses of the “bulletproof” provider CyberBunker but also barbed wire fences and surveillance cams. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Jira development and ticketing software hit by critical security flaws

Admins have a spot of patching work on their hands after the company released updates addressing two critical flaws. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Google fixes Chromebook 2FA flaw in ‘built-in security key’

Google has discovered a flaw in a Chromebook security feature which allows owners to press their device’s power button to initiate U2F 2FA. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Mozilla increases browser privacy with encrypted DNS

Mozilla is about to turn on-by-default an oft-overlooked privacy feature in Firefox. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

XKCD forums breached – 562k accounts

How did the Correct Horse Battery get Stapled? | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Google warns of system-controlling Chrome bug

Google is patching a serious bug in the desktop version of its Chrome browser that could let an attacker take over a computer simply by luring them to a website. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Web clickjacking fraud makes a comeback thanks to JavaScript tricks

More than a decade after hitting the headlines, clickjacking fraud remains an under-reported hazard on hundreds of popular websites. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

Multiple HTTP/2 DoS Flaws Found by Netflix

Netflix has identified several denial of service (DoS) flaws in HTTP/2, a popular network protocol that underpins large parts of the web. Exploiting them could bring servers grinding to a halt. | Continue reading


@nakedsecurity.sophos.com | 6 years ago

GitHub ‘encourages’ hacking, says lawsuit following Capital One breach

The class action charges Capital One and GitHub, charging it with being “friendly” (at least) toward hacking and for the hackers’ posts. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Listening in: Humans hear the private info Siri accidentally records

Apple Watch and HomePod have the highest rate of inadvertent recordings, a whistleblower says. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Programmer from hell plants logic bombs to guarantee future work

At some dark moment, have you ever wondered: what if the programmers are adding the bugs deliberately? | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Google Chrome is ditching its XSS detection tool

Google’s throwing in the towel on XSS Auditor and putting its trust in Trusted Types instead. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

iOS Walkie Talkie Offline for a Vulnerability

Apple disabled the app after somebody reported a bug – not exploited yet – that could allow an eavesdropper to listen in on another iPhone. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Apple aims privacy billboard at Google’s controversial smart-city

It’s outside of Sidewalk Labs HQ in Toronto, where Google’s sister company is working on stuffing the city with data-collecting sensors. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Facial recognition surveillance must be banned, says Fight for the Future

“We don’t need to regulate it, we need to ban it entirely.” | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Backdoor discovered in Ruby strong_password library

An eagle-eyed developer has discovered a backdoor recently sneaked into a library (or ‘gem’) used by Ruby on Rails (RoR) web apps to check password strength. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Privacy and Security Risks in Apple Open ID Protocol

An open letter from the OpenID Foundation says that Apple introduced potential risks when it diverged from the OpenID Connect protocol. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Scary Granny zombie game slurps credentials, spawns phishing attack

Halloween came a little early for some Android users this year after a horror-themed computer game was found stealing their account credentials and displaying potentially malicious ads. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

I’d like to add you to my professional network of people to spy on

A deepfake was reportedly spotted in the wild: LinkedIn’s well-connected, young, attractive Eurasia/Russia expert “Katie Jones.” | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Flipboard Data Breach

Hugely popular news aggregation site Flipboard – one billion app downloads from Google Play and counting – has become the latest internet company to admit it has suffered a breach. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Unpatched Docker bug allows read-write access to host OS – Naked Security

Suse developer Aleksa Sarai has uncovered a bug in the way that the container framework handles path names. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Hackers breach US license plate scanning company

One of the US’s most widely used vehicle license plate reader (LPR) companies, Perceptics, is reportedly investigating a data breach. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Linux Remote Exploit Found in Reliable Datagram Sockets

Unpatched Linux systems are vulnerable to remote compromise from the local network. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

UPDATE NOW! Critical, Remote, ‘Wormable’ Windows Vulnerability

Microsoft has fixed an RDP vulnerability that can be exploited remotely, without authentication and used to run arbitrary code. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Belgian programmer solves cryptographic puzzle 15 years too soon

Belgian coder Bernard Fabrot just finished a 3.5-year computational marathon, solving a fascinating cryptopuzzle set at MIT back in 1999. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

DNS over HTTPS is coming whether ISPs and governments like it or not

DNS over HTTPS (DoH), backed by Google, Mozilla and Cloudflare, is about to make web surveillance a lot more difficult. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Internet Explorer browser flaw threatens all Windows users

Nearly four years after it was replaced by Edge as Microsoft’s preferred Windows browser, researchers keep finding unpleasant security flaws in Internet Explorer (IE). | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Chrome and Safari Criticised for Removing Privacy Setting

Forthcoming versions of the Chrome, Apple Safari and Opera are in the process of removing the ability to disable a long-ignored tracking feature called hyperlink auditing pings. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Two teens charged with jamming school Wi-Fi to get out of exams

They’re facing charges of computer criminal activity after allegedly disrupting the network at the request of their friends. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

GPS week rollover and the other sort of “zero day”

Tomorrow night, the GPS “earth clock” has a Y2K event – but here’s why you should be OK. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Thousands of API and cryptographic keys leaked on GitHub every day

Researchers have found that one of the most popular source code repositories in the world is still housing thousands of publicly accessible user credentials. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Sacked IT guy annihilates 23 of his ex-employer’s AWS servers

He was fired after four weeks, ripped off the credentials of former colleague “Speedy”, and will be mulling it all over for two years in jail. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Sacked IT guy annihilates 23 of his ex-employer’s AWS servers

He was fired after four weeks, ripped off the credentials of former colleague “Speedy”, and will be mulling it all over for two years in jail. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

KeySteal could allow someone to steal your Apple Keychain passwords

The researcher says it works without root or administrator privileges and without password prompts. But he’s not revealing how it works to Apple because there’s no money for him in its … | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Privilege escalation vulnerability uncovered in Microsoft Exchange

A researcher has discovered an alarming way that an attacker controlling a Microsoft Exchange mailbox account could potentially elevate their privileges to become a Domain Administrator. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Microsoft Azure data deleted because of DNS outage

Users of Microsoft’s Azure system lost database records as part of a mass outage on Tuesday. A combination of DNS problems and automated scripts were to blame, said reports. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

Your Speakers Could Be Turned into Eavesdropping Microphones (2016)

A proof of concept attack uses malware to turn headphones into microphones that can eavesdrop from across a room. | Continue reading


@nakedsecurity.sophos.com | 7 years ago

BGP secure routing experiment ends in online row

An experiment to make the internet safer ended up breaking parts of it last week. | Continue reading


@nakedsecurity.sophos.com | 7 years ago