WhatsApp goes after Chinese password scammers via US court

If you can’t beat ’em, sue ’em! | Continue reading


@nakedsecurity.sophos.com | 1 year ago

Peter Eckersley, co-creator of Let’s Encrypt, dies at just 43

This site, like millions of others, has a certificate from Let’s Encrypt. Farewell, Peter Eckersley, PhD, who helped make it all possible. | Continue reading


@nakedsecurity.sophos.com | 1 year ago

GitHub blighted by malicious code by a researcher

If you spew projects laced with hidden malware into an open source repository, don’t waste your time telling us “no harm done” afterwards. | Continue reading


@nakedsecurity.sophos.com | 1 year ago

Slack admits to leaking hashed passwords for five years

“When those invitations went out… somehow, your password hash went out with them.” | Continue reading


@nakedsecurity.sophos.com | 1 year ago

SIKE algo cracked [Post-quantum cryptography–new algorithm “gone in 60 minutes”]

And THIS is why you don’t knit your own home-made encryption algorithms and hope no one looks at them. | Continue reading


@nakedsecurity.sophos.com | 1 year ago

Poisoned Python and PHP packages purloin passwords (for AWS access)

More supply chain trouble – this time with clear examples so you can learn how to spot this stuff yourself. | Continue reading


@nakedsecurity.sophos.com | 1 year ago

You can’t trust things you copy and paste from web pages

Just when you thought it was safe to delve into your clipboard. | Continue reading


@nakedsecurity.sophos.com | 1 year ago

Zlib data compressor fixes 17-year-old security bug – patch, errrm, now

This code is venerable! Surely all the bugs must be out by now? | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Google announces zero-day in Chrome browser

Zero-day buses: none for a while, then three at once. Here’s Google joining Apple and Adobe in “zero-day week” | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Facebook paid for a 0-day to help FBI unmask child predator

A third-party cybersecurity firm were paid to drill a hole in a Tor-reliant operating system to uncover a man who spent years sextorting young girls. | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Apple zero-day drama for Macs, iPhones and iPads – patch now

Sudden update! Zero-day browser hole! Drive-by malware danger! Patch Apple laptops and phones now… | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Conti ransomware goes rogue, leaks “gang” data

Once more unto the breach, dear friends, once more… | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Bit-squatting – DNS hijacking without exploitation (2011)

Researcher Artem Dinaburg presented his paper about memory errors leading to mistaken DNS lookups at last week’s Black Hat conference in Las Vegas, Nevada. He showed how attackers could use t… | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Microsoft researcher found Apple 0-day in March, didn’t report it

Ut tensio, sic uis! Does twice the bug pile on twice the pressure to fix it? | Continue reading


@nakedsecurity.sophos.com | 2 years ago

PrintNightmare, the zero-day hole in Windows

All bugs are equal. But some bugs are more equal than others. | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Windows Hello face recognition spoofed with photographs

You are the password (and so is a photograph of you) | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Can *YOU* blow a PC speaker using only a Linux kernel driver?

Can you help? There’s a hidden meaning here, and it’s time to find it! | Continue reading


@nakedsecurity.sophos.com | 2 years ago

“Unpatchable” vulnerability in Apple’s M1 chip

It’s all over the news! The bug you can’t fix! Fortunately, you don’t need to. We explain why. | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Apple patches dangerous security holes, one in active use – update now

It’s three weeks since last time. Now it’s this time, so patch now! | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Apple AirTag hacked again – free internet with no mobile data plan

More phun with Apple AirTags! Free internet, no data plan required… but it’s s-l-o-o-o-w. | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Apple AirTag jailbroken already – hacked in rickroll attack

Ooooh, look! A shiny button-like object! | Continue reading


@nakedsecurity.sophos.com | 2 years ago

Search crimes – How the Gootkit gang poisons Google searches

When a search result looks too good to be true – it IS too good to be true! | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Poison packages: Supply Chain Risks user hits Python's PyPI with 4k fake modules

To this “researcher”, even a job not worth doing was worth overdoing. Here’s what you can learn from the incident… | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Another Chrome zero-day exploit – so get that update done

It’s déjà vu all over again! New month, new Chrome zero-day bug being exploited in the wild. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Beware of technical “experts” bombarding you with bug reports

Beware pseudo-geeks bearing ‘gifts’. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Emotet takedown – Europol attacks “most dangerous malware”

Great news from Europol – if you’ve heard of Emotet, you’ll have a good idea how badly things often end for its victims. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Ghost hack – criminals use deceased employee's account to wreak havoc

Most companies are quick to remove ex-staff from the payroll, but often not so quick to shut down their network access. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

German divers find Enigma crypto machine on seabed

What looked at first glance underwater like an “old typewriter” turned out to be an historic cipher machine. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

How to steal photos off someone’s iPhone from across the street

The bug at the heart of this is already patched – but there’s a lot to learn from this story anyway. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Adobe Flash – it’s the end of the end of the end of the road at last

The journey to the end of Flash. Are we there yet? | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Buer Loader “malware-as-a-service” joins Emotet for ransomware delivery

A relative newcomer in the “malware-as-a-service” scene is starting to attract the big-money ransomware criminals. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Fake Android notifications – first Google, then Microsoft affected

Were you woken up by a bogus Android notification from Google or Microsoft this week? | Continue reading


@nakedsecurity.sophos.com | 3 years ago

United States wants HTTPS for all government sites, all the time

Making .GOV domains secure – it’ll take “a few years” yet | Continue reading


@nakedsecurity.sophos.com | 3 years ago

GitHub uncovers malicious 'Octopus Scanner' targeting developers

GitHub has uncovered a form of malware that spreads via infected repositories on its system. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Google sued by Arizona for tracking users’ locations in spite of settings

Maps, weather, searches et al. suck up location data in the background, even if Tracking is turned off. Arizona says it’s consumer fraud. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Woman stalked by sandwich server via her Covid-19 contact tracing info

She wanted a sub, not Facebook, Instagram and SMS come-ons from the guy who served her and intercepted her contact-tracing details. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

GoDaddy – “unauthorized individual” had access to login info

Web hosting behemoth GoDaddy just filed a data breach notification with the US state of California. | Continue reading


@nakedsecurity.sophos.com | 3 years ago

Fan vibrations can be used to transmit data from air-gapped machines

Scientists known for finding ways to transmit software from non-networked computers have figured out a way to do it with computer fan vibrations. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

The Big Bad Wolves haven’t blown the house down but did come up with a way to “hold the three little pigs responsible for being delicious,” Signal said. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Hackers’ forum hacked, OGUsers database dumped

A rival hacking forum has yet again hacked OGUsers and doxxed its database for one and all to grab. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Firefox 76 will have option to enforce HTTPS-only connections

The aim is to block the browser from reaching the small number of sites that cling to HTTP, closing security risks. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Data of millions of eBay and Amazon shoppers exposed

Eight million customer records belonging to companies including Amazon, eBay, Shopify, PayPal, and Stripe were collected. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Earn IT Act threatens end-to-end encryption

The bill, which would undercut Section 230 protections for online publishing, presents itself as a way to stop online child abuse. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Brave browser to block fingerprinting with randomization

Brave is testing a new defence against fingerprinting: confusing algorithms by randomising some of the data they collect. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Why 3M Let’s Encrypt certificates are being killed off today

If your certificate gets revoked and you don’t renew it, visitors won’t be able to get to your site… | Continue reading


@nakedsecurity.sophos.com | 4 years ago

SSL/TLS certificate validity chopped down to one year by Apple’s Safari

From 1 September 2020, Safari will no longer trust SSL/TLS certificates with more than a year on the clock. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Ransomware attack forces 2-day shutdown of natural gas pipeline

The attacker(s) infected both IT and operational networks with an unspecified ransomware strain, though the facility never lost control. | Continue reading


@nakedsecurity.sophos.com | 4 years ago

Malware and HTTPS – A growing love affair

HTTPS web encryption – blessing or curse? A new SophosLabs report looks at how much the crooks love TLS. | Continue reading


@nakedsecurity.sophos.com | 4 years ago