Naked Security Podcast: Recent Episodes

Sophos

Welcome to Series 3 of the Naked Security podcast.

Find out what happened in cybersecurity in the past week, how it happened, why it happened - and how to stop it happening to you!

New episode every Thursday.

View Details

Miss Manners confronts copy-and-paste. WinRAR patches bugs. When Airplane mode isn't. How many cryptographers to change a light bulb?

https://nakedsecurity.sophos.com/using-winrar-be-sure-to-patch https://nakedsecurity.sophos.com/snakes-in-airplane-mode https://nakedsecurity.sophos.com/smart-light-bulbs-could-give-away-your-password

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Email questions and suggestions to: tips@sophos.com

View Details

Navajo Code Talkers Day. Beta bogosities. Skimming shenanigans. Hooligan hosting. A cybercrime conundrum.

https://nakedsecurity.sophos.com/fbi-warns-about-scams-that-lure-you-in-as-a-mobile-beta-tester https://nakedsecurity.sophos.com/grab-hold-and-give-it-a-wiggle-atm-card-skimming https://nakedsecurity.sophos.com/crimeware-server-used-by-netwalker-ransomware-seized

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Email questions and suggestions to: tips@sophos.com

View Details

An amazing Art Deco computer. Yet more performance-versus-security trouble. Is sound alone enough to sniff out your password? A rap song (of sorts) with a cybersecurity connection.

https://nakedsecurity.sophos.com/2023/08/08/serious-security-why-learning-to-touch-type-could-protect-you-from-audio-snooping/ https://nakedsecurity.sophos.com/2023/08/04/crocodile-of-wall-street-and-her-husband-plead-guilty-to-giant-sized-cryptocrimes/

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Email questions and suggestions to: tips@sophos.com

View Details

Firefox fixes flaws. The exciting vulnerability that you don't need to be afraid of. Breach reporting rules with lots of leeway.

https://nakedsecurity.sophos.com/firefox-fixes-a-flurry-of-flaws https://nakedsecurity.sophos.com/performance-and-security-clash-yet-again https://nakedsecurity.sophos.com/sec-demands-four-day-disclosure-limit

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Email questions and suggestions to: tips@sophos.com

View Details

Apple patches two zero-days, one for a second time. How a 30-year-old cryptosystem got cracked. All your secret are belong to Zenbleed. Remembering those dodgy PC/Mac ads.

https://nakedsecurity.sophos.com/apple-ships-that-recent-rapid-response https://nakedsecurity.sophos.com/hacking-police-radios-30-year-old-crypto-flaws https://nakedsecurity.sophos.com/zenbleed-how-the-quest-for-cpu-performance

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Email questions and suggestions to: tips@sophos.com

View Details

Why your Mac's calendar app says it's JUL 17. One patch, one line, one file. Careful with that {axe,file}, Eugene. Storm season for Microsoft. When typos make you sing for joy.

https://nakedsecurity.sophos.com/zimbra-collaboration-suite-warning https://nakedsecurity.sophos.com/google-virus-total-leaks-list https://nakedsecurity.sophos.com/microsoft-hit-by-storm-season

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Remembering the slide rule. What you need to know about Patch Tuesday. Supercookie surveillance shenanigans. When bugs arrive in pairs. Apple's rapid patch that needed a rapid patch. User-Agent considered harmful.

https://nakedsecurity.sophos.com/microsoft-patches-four-zero-days-finally-takes-action https://nakedsecurity.sophos.com/serious-security-rowhammer-returns https://nakedsecurity.sophos.com/ghostscript-bug-could-allow-rogue-documents-to-run-system https://nakedsecurity.sophos.com/urgent-apple-fixes-critical-zero-day-hole https://nakedsecurity.sophos.com/apple-silently-pulls-its-latest-zero-day-update

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

First there was DevOps, then SecOps, then DevSecOps. Or should that be SecDevOps? Paul Ducklin talks to Sophos X-Ops insider Matt Holdcroft about how to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light.

With Paul Ducklin and Matt Holdcroft.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

PONG for one player. Apple pushes out anti-spyware patch. Beware bad passwords on Linux servers. "Twitter hacker" gets 5 years. When mobile phones and dental hygiene collide.

https://nakedsecurity.sophos.com/apple-patch-fixes-zero-day-kernel-hole https://nakedsecurity.sophos.com/beware-bad-passwords-as-attackers-co-opt-linux-servers https://nakedsecurity.sophos.com/uk-hacker-busted-in-spain-gets-5-years https://nakedsecurity.sophos.com/aussie-pm-says-shut-down-your-phone-every-24-hours

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Gee Whizz BASIC (probably). Think you know ransomware? Megaupload, 11 years on. ASUS warns of critical router bugs. MOVEit mayhem Part III.

https://nakedsecurity.sophos.com/the-ransomware-documentary-brand-new-video-series https://nakedsecurity.sophos.com/megaupload-duo-will-go-to-prison https://nakedsecurity.sophos.com/asus-warns-router-customers-patch-now https://nakedsecurity.sophos.com/moveit-mayhem-3

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Magnetic core memory. Patch Tuesday and SketchUp shenanigans. More MOVEit mitigations. Mt. Gox back in the news. Gozi malware criminal imprisoned at last. Are password rules like running through rain?

https://nakedsecurity.sophos.com/patch-tuesday-fixes-4-critical-rce-bugs https://nakedsecurity.sophos.com/more-moveit-mitigations-new-patches https://nakedsecurity.sophos.com/history-revisited-us-doj-unseals-mt-gox-cybercrime-charges https://nakedsecurity.sophos.com/gozi-banking-malware-it-chief-finally-jailed https://nakedsecurity.sophos.com/thoughts-on-scheduled-password-changes

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Calling all modems. KeePass gets an update. MOVEit gets pwned. Chromium zero-day. The backdoor that wasn't really. WPBT explained.

https://nakedsecurity.sophos.com/serious-security-that-keepass-master-password-crack https://nakedsecurity.sophos.com/moveit-zero-day-exploit-used-by-data-breach-gangs https://nakedsecurity.sophos.com/chrome-zero-day-this-exploit-is-in-the-wild https://nakedsecurity.sophos.com/researchers-claim-windows-backdoor

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

How to say "GIF". A Blackmailer-in-the-Middle attack. Knitting your own crypto. KeePass master password shenanigans. Binge listening.https://nakedsecurity.sophos.com/ransomware-tales-the-mitm-attackhttps://nakedsecurity.sophos.com/serious-security-verification-is-vitalhttps://nakedsecurity.sophos.com/serious-security-that-keepass-master-password-crackWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Luminiferous aether. A $10m cybercrime reward. Bank scam kingpin gets 13 years. Three Apple 0-days. A Python malware maelstrom.https://nakedsecurity.sophos.com/us-offers-10m-bounty-for-russian-ransomware-suspecthttps://nakedsecurity.sophos.com/phone-scamming-kingpin-gets-13-yearshttps://nakedsecurity.sophos.com/apples-secret-is-out-3-zero-days-fixedhttps://nakedsecurity.sophos.com/pypi-open-source-code-repository-deals-with-manic-malware-maelstromWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

An Apple product that flopped (and was not the Newton). Two-faced sysadmin jailed for 6 years. The smart plug with the unsmart security hole. Clearview AI again, once more, again.https://nakedsecurity.sophos.com/whodunnit-cybercrook-gets-6-yearshttps://nakedsecurity.sophos.com/belkin-wemo-smart-plug-v2-the-buffer-overflowhttps://nakedsecurity.sophos.com/zut-alors-raclage-crapuleux-clearview-aiWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The world-changing Visible Calculator. How not to get a job. Private keys - the hint is in the name. Microsoft's complicated bootkit patch. Taming Bluetooth trackers.https://nakedsecurity.sophos.com/php-packagist-supply-chain-poisoned-by-hackerhttps://nakedsecurity.sophos.com/low-level-motherboard-security-keys-leakedhttps://nakedsecurity.sophos.com/bootkit-zero-day-fix-is-this-microsofts-most-cautioushttps://nakedsecurity.sophos.com/tracked-by-hidden-tags-apple-and-google-uniteWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

New England gets BASIC. Google hits back at CryptBot crooks. Apple seals its lips on security. Mac malware-as-a-service. World Password Day. PaperCut: disclose or don't disclose?https://nakedsecurity.sophos.com/google-wins-court-order-to-force-isps-to-filterhttps://nakedsecurity.sophos.com/apple-delivers-first-ever-rapid-security-responsehttps://nakedsecurity.sophos.com/mac-malware-for-hire-steals-passwords-and-cryptocoinshttps://nakedsecurity.sophos.com/world-password-day-2-2-4https://nakedsecurity.sophos.com/papercut-security-vulnerabilities-under-active-attackWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The CIH or SpaceFiller virus revisited. Google's 2FA security shortcut. Server vulns under active attack. Two Chrome zero-days, but was it one attack?https://nakedsecurity.sophos.com/20-years-ago-today-what-we-can-learn-from-the-cih-virushttps://nakedsecurity.sophos.com/google-leaking-2fa-secretshttps://nakedsecurity.sophos.com/papercut-security-vulnerabilities-under-active-attackhttps://nakedsecurity.sophos.com/double-zero-day-in-chrome-and-edge-check-your-versionsWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Fun with FORTRAN?! An extreme data breach and its consequences. Rogue 2FA apps live in action. Juicejacking revisited.https://nakedsecurity.sophos.com/ex-ceo-of-breached-pyschotherapy-clinic-gets-prison-sentencehttps://nakedsecurity.sophos.com/beware-rogue-2fa-apps-in-app-store-and-google-playhttps://nakedsecurity.sophos.com/fbi-and-fcc-warn-about-juicejackingWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

A common business-oriented language. Patch Tuesday. Secure Boot (without the "Secure" part). Apple zero-days. World-readable garage doors. Motherboard malware threats.https://nakedsecurity.sophos.com/microsoft-fixes-a-zero-day-and-two-curious-bugshttps://nakedsecurity.sophos.com/apple-issues-emergency-patches-for-spywarehttps://nakedsecurity.sophos.com/apple-zero-day-spyware-patches-extendedhttps://nakedsecurity.sophos.com/us-government-warning-what-if-anyone-could-openhttps://nakedsecurity.sophos.com/attention-gamers-motherboard-maker-msi-admits-to-breachWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

A supply chain attack that foisted spyware on trusting users. Wi-Fi encryption bypass via left-over data. Surely there should be TWO World Backup Days?https://nakedsecurity.sophos.com/supply-chain-blunder-puts-3cx-telephone-app-users-at-riskhttps://nakedsecurity.sophos.com/researchers-claim-they-can-bypass-wi-fi-encryptionhttps://nakedsecurity.sophos.com/world-backup-day-is-here-again-5-tipsWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

RIP Gordon Moore, the more in Moore's Law. Photo cropping bugfix. DDoS honeypot. E-commerce patches. Apple 0-day and lots more.https://nakedsecurity.sophos.com/in-memoriam-gordon-moorehttps://nakedsecurity.sophos.com/microsoft-assigns-cve-to-snipping-tool-bughttps://nakedsecurity.sophos.com/cops-use-fake-ddos-serviceshttps://nakedsecurity.sophos.com/woocommerce-payments-pluginhttps://nakedsecurity.sophos.com/apple-patches-everything-including-a-zero-dayWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The mobile phone bugs that Google kept quiet, just in case. The mysterious case of ATM video uploads. When redacted data springs back to life.https://nakedsecurity.sophos.com/dangerous-android-phone-0-day-bugs-revealedhttps://nakedsecurity.sophos.com/bitcoin-atm-customers-hacked-by-video-uploadhttps://nakedsecurity.sophos.com/google-pixel-phones-had-a-serious-data-leakage-bughttps://nakedsecurity.sophos.com/windows-11-also-vulnerable-to-acropalypseWith Paul Ducklin and Chester WisniewskiOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The price of fast fashion. Firefox fixes. Feature creep fail curtailed in Patch Tuesday updates.https://nakedsecurity.sophos.com/shein-shopping-app-goes-roguehttps://nakedsecurity.sophos.com/firefox-111-patches-11-holeshttps://nakedsecurity.sophos.com/microsoft-fixes-two-0-daysWith Paul Ducklin and Chester WisniewskiOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Memories of Michelangelo (the virus, not the artist). Data leakage bugs in TPM 2.0. Ransomware bust, ransomware warning, and anti-ransomware advice.https://nakedsecurity.sophos.com/serious-security-tpm-2-0-vulnshttps://nakedsecurity.sophos.com/doppelpaymer-ransomware-supsects-arrestedhttps://nakedsecurity.sophos.com/feds-warn-about-right-royal-ransomwareWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

How Woz nearly gave away the Apple I. Rogue software packages. Rogue network "administrators". Rogue keyloggers. Rogue authenticators.https://nakedsecurity.sophos.com/npm-javascript-packages-abused-to-create-scambaithttps://nakedsecurity.sophos.com/dutch-police-arrest-three-cyberextortion-suspectshttps://nakedsecurity.sophos.com/lastpass-the-crooks-used-a-keyloggerhttps://nakedsecurity.sophos.com/beware-rogue-2fa-apps-in-app-store-and-google-playWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The first search warrant for computer storage. GoDaddy breach. Twitter surprise. Coinbase kerfuffle. The hidden cost of success.https://nakedsecurity.sophos.com/godaddy-admits-crooks-hit-us-with-malwarehttps://nakedsecurity.sophos.com/twitter-tells-users-pay-uphttps://nakedsecurity.sophos.com/coinbase-breached-by-social-engineersWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The birth of ENIAC. A "sophisticated attack" (someone got phished). A cryptographic hack enabled by a security warning. Valentine's Day Patch Tuesday. Apple closes spyware-sized 0-day hole. https://nakedsecurity.sophos.com/reddit-admits-it-was-hacked-https://nakedsecurity.sophos.com/serious-security-gnutls-follows-opensslhttps://nakedsecurity.sophos.com/microsoft-patch-tuesday-36-rce-bugshttps://nakedsecurity.sophos.com/apple-fixes-zero-day-spyware-implant-bugWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Cryptocurrency crimelords. Security patches for VMware, OpenSSH and OpenSSL. Medical breacher busted. Is that a bug or a feature?https://nakedsecurity.sophos.com/tracers-in-the-darkhttps://nakedsecurity.sophos.com/using-vmware-worried-about-esxi-ransomwarehttps://nakedsecurity.sophos.com/openssh-fixes-double-free-memory-bughttps://nakedsecurity.sophos.com/openssl-fixes-high-severity-data-stealing-bughttps://nakedsecurity.sophos.com/finnish-psychotherapy-extortion-suspect-arrestedhttps://nakedsecurity.sophos.com/password-stealing-vulnerability-reported-in-keypassWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Do we really need a "war against cryptography" - codes and ciphers that the government can easily crack if it thinks there's an emergency - to cement our collective online security?Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary on this and many other vital issues, including anonymity and privacy, as we talk to him about his tremendous new book, Tracers in the Dark.https://andygreenberg.nethttps://nakedsecurity.sophos.comhttps://sophos.com/nobackdoorsOriginal music by Edith Mudge (https://www.edithmudge.com)

View Details

The mighty CPU that wasn't. Hive ransomware takedown. Dutch data crime suspect busted. Samba finally gets rid of MD5. GitHub admits to an intrusion. Storing passwords securely.https://nakedsecurity.sophos.com/hive-ransomware-servers-shut-downhttps://nakedsecurity.sophos.com/dutch-suspect-locked-uphttps://nakedsecurity.sophos.com/serious-security-the-samba-logon-bughttps://nakedsecurity.sophos.com/github-code-signing-certificates-stolenWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The programming language almost called Oak. GoTo admits to more breach woes. T-Mobile spills 37 million records. Apple patches everything, even iOS 12. And Google mAkES tYpOs for sECurity.https://nakedsecurity.sophos.com/goto-admits-customer-cloud-backups-stolenhttps://nakedsecurity.sophos.com/t-mobile-admits-to-37000000-customer-records-stolenhttps://nakedsecurity.sophos.com/apple-patches-are-out-old-iphoneshttps://nakedsecurity.sophos.com/serious-security-how-deliberate-typos-might-improve-dnsWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The HAPPY99 virus reminds us that less is more. Trouble with JSON Web Tokens. Investment scammers busted in Europe. The LifeLock "breach" that wasn't.https://nakedsecurity.sophos.com/popular-jwt-cloud-security-library-patcheshttps://nakedsecurity.sophos.com/multi-million-investment-scammers-bustedhttps://nakedsecurity.sophos.com/serious-security-unravelling-the-nortonlifelock-hackWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Two stories from the underground. Bank scammers busted. The crypto-crack that wasn't. And the end of two Windows eras at the same time.https://nakedsecurity.sophos.com/inside-a-scammers-lair-ukraine-busts-40https://nakedsecurity.sophos.com/rsa-crypto-cracked-or-perhaps-nothttps://nakedsecurity.sophos.com/microsoft-patch-tuesday-one-0-dayWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The ground-breaking HP-35 digital calculator. Last straw for LastPass? Congress takes on quantum computing. 33 1/3-year-old cybersecurity lessons. Machine learning supply chain attack.https://www.hpmuseum.org/hp35.htmhttps://nakedsecurity.sophos.com/lastpass-finally-admits-they-did-steal-your-password-vaultshttps://nakedsecurity.sophos.com/us-passes-the-quantum-computing-cybersecurity-preparedness-acthttps://nakedsecurity.sophos.com/naked-security-33-1-3-cybersecurity-predictions-for-2023https://nakedsecurity.sophos.com/pytorch-machine-learning-toolkit-pwnedWith Doug Aamoth and Paul DucklinOriginal music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Once more unto the breach, dear friends, once more! Paul Ducklin talks to Peter Mackenzie, Director of Incident Response at Sophos, in a cybersecurity session that will alarm, amuse and educate you, all in equal measure.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Join world-renowned Sophos expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode, recorded during our recent Security SOS Week 2022. When it comes to fighting cybercrime, Fraser truly is a "specialist in everything", and he also has the knack of explaining this tricky and treacherous subject in plain English.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The irony of the CAN-SPAM law. When genuine kernel drivers go rogue. Apple patches everything. Stealing data via secret radio waves. E-commerce supply chain drama. https://nakedsecurity.sophos.com/patch-tuesday-0-days-rce-bugs-and-a-curious-talehttps://nakedsecurity.sophos.com/apple-patches-everything-finally-reveals-mysteryhttps://nakedsecurity.sophos.com/covid-bit-the-wireless-spyware-trick-https://nakedsecurity.sophos.com/credit-card-skimming-the-long-and-winding-roadWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The worm that wasn't a Goner. LastPass suffers a sting in the data breach tail. Apple's secretive update. Ping o' Death. SIM swapping explained. A Beatles-esque 0-day in Chrome and Edge.https://nakedsecurity.sophos.com/lastpass-admits-to-customer-data-breachhttps://nakedsecurity.sophos.com/apple-pushes-out-ios-security-updatehttps://nakedsecurity.sophos.com/ping-of-death-freebsd-fixes-crashtastic-bughttps://nakedsecurity.sophos.com/sim-swapper-sent-to-prison-for-2fa-cryptocurrency-heisthttps://nakedsecurity.sophos.com/number-nine-chrome-fixes-another-2022-zero-dayWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Christmas wormage. Prurient malware. Cryptorom busts. Voice call spoofing.https://nakedsecurity.sophos.com/cryptorom-pig-butchering-scam-sites-seizedhttps://nakedsecurity.sophos.com/tiktok-invisible-challenge-porn-malwarehttps://nakedsecurity.sophos.com/voice-scamming-site-ispoof-seized-100s-arrestedWith Doug Aamoth and Paul Ducklin.Original music by Edith Mudge (https://www.edithmudge.com)Got questions/suggestions/stories to share?Email: tips@sophos.comTwitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Security specialist John Shier tells you the "news you can really use" - how to boost your cybersecurity based on real-world advice from the 2023 Sophos Threat Report.

https://sophos.com/threatreport

With Paul Ducklin and John Shier.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Microsoft's tilt at the MP3 marketplace. Apple's not-a-zero-day emergency. Cracking the lock on Android phones. Browser-in-the-Browser revisited. The Emmenthal cheese attack. Business Email Compromise and how to prevent it.

https://nakedsecurity.sophos.com/emergency-code-execution-patch-from-apple https://nakedsecurity.sophos.com/dangerous-sim-swap-lockscreen-bypass https://nakedsecurity.sophos.com/firefox-fixes-fullscreen-fakery-flaw https://nakedsecurity.sophos.com/log4shell-like-code-execution-hole https://nakedsecurity.sophos.com/gucci-master-business-email-scammer

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Radio waves so mysterious they're known only as X-Rays. Were there six 0-days or only four? The cops that found $3 billion in a popcorn tin. Blue badge confusion. When URL scanning goes wrong. Tracking down every last unpatched file. Why even unlikely exploits can earn "high" severity levels.

https://nakedsecurity.sophos.com/exchange-0-days-fixed-at-last-plus-4-brand-new https://nakedsecurity.sophos.com/silk-road-drugs-market-hacker-pleads-guilty https://nakedsecurity.sophos.com/twitter-blue-badge-email-scams- https://nakedsecurity.sophos.com/public-url-scanning-tools-when-security-leads-to-insecurity https://nakedsecurity.sophos.com/the-openssl-security-update-story-how-can-you-tell

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

The man who put Boole in Boolean. OpenSSL's bated-breath update. Apple's zero-day finally settled. New Chrome zero-day. SHA-3 code gets a patch. Extreme extortion via stolen medical data. Data breach response the nonchalant way.

https://nakedsecurity.sophos.com/openssl-patches-are-out-critical-bug-downgraded-to-high https://nakedsecurity.sophos.com/the-openssl-security-update-story-how-can-you-tell https://nakedsecurity.sophos.com/updates-to-apples-zero-day-update-story-iphone-and-ipad https://nakedsecurity.sophos.com/chrome-issues-urgent-zero-day-fix-update-now https://nakedsecurity.sophos.com/sha-3-code-execution-bug-patched-in-php https://nakedsecurity.sophos.com/psychotherapy-extortion-suspect-arrest-warrant https://nakedsecurity.sophos.com/online-ticketing-company-see-pwned-for-2-5-years

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Windows XP (fondly?!) remembered. Clearview AI courts controversy again. DEADBOLT ransomware crooks get counterhacked. Women cryptologists commemorated in US. How to measure randomness. Deconstructing Apple's latest security bulletins.

https://nakedsecurity.sophos.com/clearview-ai-image-scraping-face-recognition-service-hit-with-e20m-fine https://nakedsecurity.sophos.com/when-cops-hack-back-dutch-police-fleece-deadbolt-criminals https://nakedsecurity.sophos.com/women-in-cryptology-usps-celebrates-ww2-codebreakers https://nakedsecurity.sophos.com/serious-security-you-cant-beat-the-house-at-blackjack https://nakedsecurity.sophos.com/apple-megaupdate-ventura-out-ios-and-ipad-kernel-zero-day

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Coolest videogame ever. Zoom thinks everyone's a developer. The Patch Tuesday that wasn't. A data breach coverup. Log4Shell all over again. And the Office cryptofail that Microsoft won't fix.

https://nakedsecurity.sophos.com/zoom-for-mac-patches-sneaky-spy-on-me-bug https://nakedsecurity.sophos.com/patch-tuesday-in-brief-one-0-day-fixed https://nakedsecurity.sophos.com/fashion-brand-shein-fined-1-9m-for-lying https://nakedsecurity.sophos.com/dangerous-hole-in-apache-commons-text https://nakedsecurity.sophos.com/serious-security-microsoft-office-365

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

What goes up... must come down. Ransomware criminal avoids a life sentence. Former CSO convicted over Uber megabreach coverup. WhatsApp fights rip-off rogue apps. The Countess of Computer Science. Could a weird email brick your iPhone?

https://nakedsecurity.sophos.com/netwalker-ransomware-affiliate-sentenced https://nakedsecurity.sophos.com/former-uber-cso-convicted https://nakedsecurity.sophos.com/whatsapp-goes-after-chinese-password-scammers https://nakedsecurity.sophos.com/move-over-patch-tuesday-its-ada-lovelace https://nakedsecurity.sophos.com/mystery-iphone-update

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Naked Security meets Sophos X-Ops! Duck and Chet dig into OAuth 2.0, a well-known protocol for authorization. Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

https://nakedsecurity.sophos.com/ https://twitter.com/nakedsecurity https://twitter.com/sophosxops

View Details

S3 Ep103: Scammers in the Slammer (and other stories)

A fridge-sized calculator made with transistors (really). ProxyNotShell situation reviewed. Romance and BEC scammer gets 25 in the slammer. Is there an answer to nuisance callers? Is the answer voicemail?

https://nakedsecurity.sophos.com/urgent-microsoft-exchange-double-zero-day https://nakedsecurity.sophos.com/s3-ep102-5-proxynotshell-exchange-bugs https://nakedsecurity.sophos.com/romance-scammer-and-bec-fraudster-sent-to-prison https://nakedsecurity.sophos.com/scammers-and-rogue-callers-can-anything-ever-stop-them

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Chester Wisniewski gives you actionable advice on how to deal with two actively exploited Exchange zero-days that suddenly burst into the news. Learn who's affected and how, find out what you can do while waiting for Microsoft's patches, and plan your threat hunting in case the worst happens to you.

https://nakedsecurity.sophos.com/urgent-microsoft-exchange-double-zero-day https://twitter.com/sophosxops

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

View Details

Chester Wisniewski gives you actionable advice on how to deal with two actively exploited Exchange zero-days that suddenly burst into the news. Learn who's affected and how, find out what you can do while waiting for Microsoft's patches, and plan your threat hunting in case the worst happens to you.

https://nakedsecurity.sophos.com/urgent-microsoft-exchange-double-zero-day https://twitter.com/sophosxops

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

View Details

What's the real deal with LAPSUS$? How did Optus get hacked? Was there really a WhatsApp 0-day? What if "deleted" data comes back from the dead to haunt you?

https://nakedsecurity.sophos.com/uber-and-rockstar-has-a-lapsus-linchpin https://news.sophos.com/uber-rockstar-fall-to-social-engineering-attacks https://nakedsecurity.sophos.com/optus-breach-aussie-telco-told-it-will-have-to-pay https://nakedsecurity.sophos.com/whatsapp-zero-day-exploit-news-scare https://nakedsecurity.sophos.com/morgan-stanley-fined-millions-for-selling-off-devices

With Paul Ducklin and Chester Wisniewski

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

What's the real deal with LAPSUS$? How did Optus get hacked? Was there really a WhatsApp 0-day? What if "deleted" data comes back from the dead to haunt you?

https://nakedsecurity.sophos.com/uber-and-rockstar-has-a-lapsus-linchpin https://news.sophos.com/uber-rockstar-fall-to-social-engineering-attacks https://nakedsecurity.sophos.com/optus-breach-aussie-telco-told-it-will-have-to-pay https://nakedsecurity.sophos.com/whatsapp-zero-day-exploit-news-scare https://nakedsecurity.sophos.com/morgan-stanley-fined-millions-for-selling-off-devices

With Paul Ducklin and Chester Wisniewski

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity)

View Details

Security SOS Week 2022 - check it out! The very first Android. Firefox 105 is out. Uber hacked... by LAPSUS$? LastPass talks about its breach. Are two disks better than one?

https://nakedsecurity.sophos.com/interested-in-cybersecurity-join-us-for-security-sos-week https://nakedsecurity.sophos.com/s3-ep100-5-uber-breach-an-expert-speaks https://nakedsecurity.sophos.com/uber-has-been-hacked-boasts-hacker https://nakedsecurity.sophos.com/lastpass-source-code-breach-incident-response

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Security SOS Week 2022 - check it out! The very first Android. Firefox 105 is out. Uber hacked... by LAPSUS$? LastPass talks about its breach. Are two disks better than one?

https://nakedsecurity.sophos.com/interested-in-cybersecurity-join-us-for-security-sos-week https://nakedsecurity.sophos.com/s3-ep100-5-uber-breach-an-expert-speaks https://nakedsecurity.sophos.com/uber-has-been-hacked-boasts-hacker https://nakedsecurity.sophos.com/lastpass-source-code-breach-incident-response

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

S3 Ep100.5: Uber breach - an expert speaks

Chester Wisniewski explains what we can learn from Uber's latest cybsecurity crisis: "Just because a big company didn't have the security they should doesn't mean you can't."

https://nakedsecurity.sophos.com/uber-has-been-hacked-boasts-hacker

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

View Details

S3 Ep100.5: Uber breach - an expert speaks

Chester Wisniewski explains what we can learn from Uber's latest cybsecurity crisis: "Just because a big company didn't have the security they should doesn't mean you can't."

https://nakedsecurity.sophos.com/uber-has-been-hacked-boasts-hacker

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

View Details

Second Cosmic Rocket (not a band!) Microsoft 0-day. Apple 0-days. Good logging habits. Browser-in-the-browser trickery. DEADBOLT ransomware. Again.

https://news.sophos.com/en-us/2022/09/13/a-lighter-patch-tuesday https://nakedsecurity.sophos.com/2022/09/12/apple-patches-a-zero-day https://nakedsecurity.sophos.com/hoe-to-deal-with-dates-and-times https://nakedsecurity.sophos.com/serious-security-browser-in-the-browser-attacks https://nakedsecurity.sophos.com/deadbolt-ransomware-rears-its-head-again

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Second Cosmic Rocket (not a band!) Microsoft 0-day. Apple 0-days. Good logging habits. Browser-in-the-browser trickery. DEADBOLT ransomware. Again.

https://news.sophos.com/en-us/2022/09/13/a-lighter-patch-tuesday https://nakedsecurity.sophos.com/2022/09/12/apple-patches-a-zero-day https://nakedsecurity.sophos.com/hoe-to-deal-with-dates-and-times https://nakedsecurity.sophos.com/serious-security-browser-in-the-browser-attacks https://nakedsecurity.sophos.com/deadbolt-ransomware-rears-its-head-again

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The bug that was a moth. Was there really a TikTok breach? Peter Eckersley: Code In Peace. Chrome and Edge fix a zero-day. Apple updates iOS 12 for the first time in a year. App icons: the difference between sprockets and cogs.

https://nakedsecurity.sophos.com/peter-eckersley-co-creator-of-lets-encrypt-dies https://nakedsecurity.sophos.com/chrome-fixes-zero-day-security-hole https://nakedsecurity.sophos.com/urgent-apple-quietly-slips-out-zero-day-update

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The bug that was a moth. Was there really a TikTok breach? Peter Eckersley: Code In Peace. Chrome and Edge fix a zero-day. Apple updates iOS 12 for the first time in a year. App icons: the difference between sprockets and cogs.

https://nakedsecurity.sophos.com/peter-eckersley-co-creator-of-lets-encrypt-dies https://nakedsecurity.sophos.com/chrome-fixes-zero-day-security-hole https://nakedsecurity.sophos.com/urgent-apple-quietly-slips-out-zero-day-update

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The Computer Misuse Act, back in 1990. JavaScript supply-chain bug hunting. Jumping airgaps. "The Sanitizer" comes to Chrome. LastPass breach provokes password manager puzzlement.

https://nakedsecurity.sophos.com/javascript-bugs-aplenty-in-node-js-ecosystem https://nakedsecurity.sophos.com/breaching-airgap-security-using-your-phone https://nakedsecurity.sophos.com/chrome-patches-24-security-holes https://nakedsecurity.sophos.com/lastpass-source-code-breach

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Start me up. The R&B dance classic that crashed computers. Bitcoin ATM skimming (no malware required). Multiple browser zero-days. Was your iPhone pwned?

https://nakedsecurity.sophos.com/laptop-denial-of-service-via-music https://nakedsecurity.sophos.com/bitcoin-atms-leeched-by-attackers https://nakedsecurity.sophos.com/chrome-browser-gets-11-security-fixes https://nakedsecurity.sophos.com/apple-patches-double-zero-day

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Chester attends DEF CON from afar. Zoom fixes an 0-day. An APIC leak that isn't EPIC. $10m for dobbing in Conti criminals. Cybersecurity in hospitals. Ransomware in triplicate.

https://nakedsecurity.sophos.com/zoom-for-mac-patches-get-root-bug https://nakedsecurity.sophos.com/apic-epic-intel-chips-leak-secrets https://nakedsecurity.sophos.com/us-offers-reward-up-to-10-million https://pubmed.ncbi.nlm.nih.gov/31506956/ https://news.sophos.com/en-us/multiple-attackers-increase-pressure

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Memories of the Blaster worm. Slack leaked password hashes for FIVE YEARS. Github showered with malware. Traffic lights and cybersecurity. Post-quantum cryptography.

https://nakedsecurity.sophos.com/slack-admits-to-leaking-hashed-passwords https://nakedsecurity.sophos.com/github-blighted-by-researcher https://nakedsecurity.sophos.com/traffic-light-protocol-for-cybersecurity https://nakedsecurity.sophos.com/post-quantum-cryptography-new-algorithm-gone

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Queen Victoria goes online. A nasty bug in Samba. Smiles for SysAdmins. A crypto-as-in-cryptography bug. A crypto-as-in-currency disaster. And is $200 million just chump change these days?

https://nakedsecurity.sophos.com/critical-samba-bug https://nakedsecurity.sophos.com/how-to-celebrate-sysadmin-day https://nakedsecurity.sophos.com/gnutls-patches-memory-mismanagement https://nakedsecurity.sophos.com/cryptocoin-token-swapper-nomad

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Geosynchronicity. Office security (on-off-on). A half-billion-dollar data breach cost. And patch that browser!

https://nakedsecurity.sophos.com/office-macro-security-on-again-off-again https://nakedsecurity.sophos.com/t-mobile-to-cough-up-500-million https://nakedsecurity.sophos.com/apple-patches-0-day-browser-bug https://nakedsecurity.sophos.com/mild-monthly-security-update-from-firefox

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Integrated circuits and Nobel prizes. Log4Shell - forever? Cybersecurity tips for summmer. Scams and coincidence.

https://nakedsecurity.sophos.com/8-months-on-us-says-log4shell-will-be-around-for-a-decade https://nakedsecurity.sophos.com/serious-security-how-to-make-sure-you-dont-miss-bug-reports https://nakedsecurity.sophos.com/7-cybersecurity-tips-for-your-summer-vacation https://nakedsecurity.sophos.com/facebook-2fa-scammers-return-this-time-in-just-21-minutes

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Memories of the Code Red worm. OpenSSL fixes two tiny but troublesome bugs. More trouble in Java-land. Office macros off and back on again. Potential perils of paying ransomware demands.

https://nakedsecurity.sophos.com/openssl-fixes-two-one-liner-crypto-bugs https://nakedsecurity.sophos.com/apache-commons-configuration-toolkit-patches https://nakedsecurity.sophos.com/that-didnt-last-microsoft-turns-off-the-office-security https://nakedsecurity.sophos.com/paying-ransomware-crooks-wont-reduce-your-legal-risk

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Chrome quashes another zero-day browser bug. Two big-time cybercrime stories. A 2FA phishing scam that arrived PDQ. Chester swarmed by bots on Twitter.

https://nakedsecurity.sophos.com/google-patches-in-the-wild-chrome-zero-day https://nakedsecurity.sophos.com/missing-cryptoqueen-hits-the-fbis-ten-most-wanted https://nakedsecurity.sophos.com/canadian-cybercriminal-pleads-guilty https://nakedsecurity.sophos.com/facebook-2fa-phish-arrives-just-28-minutes

With Paul Ducklin and Chester Wisniewski

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Memories of the iPhone 1. Sextortion scams target LGBTQ+ daters. Yet another blockchain blunder. OpenSSL fixes the bug missed in the last bugfix. And what became of Little Bobby Tables?

https://nakedsecurity.sophos.com/ftc-warns-of-lgbtq-extortion-scams https://nakedsecurity.sophos.com/harmony-blockchain-loses-nearly-100m https://nakedsecurity.sophos.com/openssl-issues-a-bugfix-for-the-previous-bugfix https://xkcd.com/327/

With Doug Aamoth and Paul Ducklin

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Duck gets behind the Ducks. 2000 phone scammers arrested in Interpol action. A three-year-old hacking case ends in conviction. And a Canadian financial company picks up an enormous data breach fine.

https://nakedsecurity.sophos.com/interpol-busts-2000-suspects https://nakedsecurity.sophos.com/capital-one-identity-theft-hacker

With Paul Ducklin and Chester Wisniewski

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Computer Science in the 1800s. Fixing Follina. AirTag stalking. ID theft site seizure. And the Law of Big Numbers versus SMS scams.

https://nakedsecurity.sophos.com/youre-invited-join-us-for-a-live-walkthrough https://nakedsecurity.sophos.com/murder-suspect-admits-she-tracked-cheating-partner https://nakedsecurity.sophos.com/ssndob-market-servers-seized https://nakedsecurity.sophos.com/beware-the-smish-home-delivery-scams

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The dawn of the x86 era. The Active Adversary Playbook. A sort-of zero day in Windows. A real-life zero-day in Atlassian Confluence. And the registry settings that could keep you in your job.

https://nakedsecurity.sophos.com/know-your-enemy-learn-how-cybercrime-adversaries-get-in https://nakedsecurity.sophos.com/yet-another-zero-day-sort-of-in-windows https://nakedsecurity.sophos.com/atlassian-announces-0-day-hole-in-confluence

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Why calling a computer after a famous scientist doesn't always help. The wacky but dangerous 0-day hole in Windows. Supply chain attacks and the crooks who orchestrate them. Smishing revisited. And why saying what you really mean makes you better at cybersecurity.

https://nakedsecurity.sophos.com/mysterious-follina-zero-day-hole https://nakedsecurity.sophos.com/poisoned-python-and-php-packages https://nakedsecurity.sophos.com/beware-the-smish-home-delivery-scams https://nakedsecurity.sophos.com/whos-watching-your-webcam

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How network comms caught a murderer back in in 1845. Why the US government said, "Patch, or else!" How Mozilla got a double code-execution bug fixed in 48 hours. And why controversial face-matching company Clearview AI got fined $10m.

https://nakedsecurity.sophos.com/us-government-says-patch-vmware-right-now https://nakedsecurity.sophos.com/mozilla-patches-wednesdays-pwn2own-double-exploit https://nakedsecurity.sophos.com/clearview-ai-face-matching-service-fined

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

What does the word "non-commensurate" mean? When is cracking passwords legal? Why did Firefox get patched? Which computer needed dropping onto the desk? Why wasn't this 0-day listed in every Apple update? Did Duck get spammed, or was it actually a troll?

https://nakedsecurity.sophos.com/he-cracked-passwords-for-a-living https://nakedsecurity.sophos.com/firefox-out-of-band-update-to-100-0-1 https://nakedsecurity.sophos.com/apple-patches-zero-day-kernel-hole

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Where does the word "radio" come from? RubyGems supply chain rip-and-replace bug. A weird, weird, weird, weird, weird GoogleDocs bug. Colonial Pipeline back in the cybersecurity news. What about built-in password managers?

https://nakedsecurity.sophos.com/rubygems-supply-chain-rip-and-replace-bug https://nakedsecurity.sophos.com/you-didnt-leave-enough-space https://nakedsecurity.sophos.com/colonial-pipeline-facing-1000000-fine https://www.sophos.com/en-us/products/managed-threat-response https://www.sophos.com/en-us/products/managed-threat-response/rapid-response

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms

World Password Day (we still need it), Github authentication tokens, Firefox hits a ton, and a look back at network worms.

https://nakedsecurity.sophos.com/world-password-day-2022 https://nakedsecurity.sophos.com/firefox-hits-100 https://nakedsecurity.sophos.com/github-issues-final-report

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The biggest mountain in tne solar system. New ransomware statistics. Trouble with phishing. Bugs in NAS boxes. A giant security hole in Java. And how to get an industrial grade firewall at home for free.

https://mars.nasa.gov/gallery/atlas/olympus-mons.html https://nakedsecurity.sophos.com/ransomware-survey-2022 https://nakedsecurity.sophos.com/phishing-goes-kiss https://nakedsecurity.sophos.com/qnap-warns-of-new-bugs https://nakedsecurity.sophos.com/critical-cryptographic-java-security-blunder https://www.sophos.com/en-us/products/free-tools/sophos-xg-firewall-home-edition.aspx

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Adam Osborne or John Osbourne? Another 0-day in Chrome. How not to choose a cybersecurity holiday destination. The Osbo[u]rne Effect. Cryptododginess that might actually be legal. And the Zilog Z80 versus the Mostech 6502.

https://nakedsecurity.sophos.com/yet-another-chrome-zero-day-emergency https://nakedsecurity.sophos.com/us-cryptocurrency-coder-gets-5-years https://nakedsecurity.sophos.com/beanstalk-cryptocurrency-heist

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Hydra darkweb market decapitated. Ruby module supply chain hole. Quantum computing sidestepped. A robot revolution that could result in ransomware. And the Zuckerberg scam that just won't die.

https://nakedsecurity.sophos.com/serious-security-darkweb-drugs-market-hydra https://nakedsecurity.sophos.com/popular-ruby-asciidoc-toolkit-patched https://nakedsecurity.sophos.com/openssh-goes-post-quantum https://nakedsecurity.sophos.com/five-critical-bugs-fixed-in-automatic-hospital-robot

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Hacking 2022-style. Some Apple bugs. Some Android bugs. Some Firefox bugs. The SATAN network scanner. Some VMware Spring bugs. And hacking PDP-11 style.

https://nakedsecurity.sophos.com/lapsus-hacks-continue-despite-two-uk-hacker-suspects https://nakedsecurity.sophos.com/apple-pushes-out-two-emergency-0-day-updates https://nakedsecurity.sophos.com/googles-monthly-android-updates-patch-numerous-get-root-holes https://nakedsecurity.sophos.com/firefox-99-is-out-no-major-bugs-but-update-anyway https://nakedsecurity.sophos.com/two-different-vmware-spring-bugs-at-large

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The DEADBOLT ransomware. LAPSUS$ members bust - or were they? Zlib patches a 17-year-old bug. Chrome experiences another weird 0-day. And Clippy. Yes, THAT Clippy. No, we're not sure why.

https://nakedsecurity.sophos.com/serious-security-deadbolt-the-ransomware https://nakedsecurity.sophos.com/uk-police-arrest-7-hacking-suspects https://nakedsecurity.sophos.com/zlib-data-compressor-fixes-17-year-old-security-bug https://nakedsecurity.sophos.com/google-chrome-patches-mysterious-new-zero-day

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

LAPSUS$ hackers break into Okta. The CryptoRom money-scamming malware is back on phones. OpenSSL gets into an infinite loop. CafePress fined for covering up a data breach.

https://nakedsecurity.sophos.com/beware-bogus-betas-cryptocoin-scammers https://nakedsecurity.sophos.com/openssl-patches-infinite-loop-dos-bug https://nakedsecurity.sophos.com/web-vendor-cafepress-fined-500000 https://nakedsecurity.sophos.com/serious-security-how-to-store-your-users-passwords

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Two ransomware suspects extradited for trial. Apple patches 87 known security holes. Happy Pi Day. What happens if a whole country exits the global internet?

https://nakedsecurity.sophos.com/alleged-kaseya-ransomware-attacker-arrives-in-texas https://nakedsecurity.sophos.com/apple-patches-87-security-holes https://nakedsecurity.sophos.com/happy-piday-even-if-you-arent-in-north-america https://news.sophos.com/en-us/will-russias-war-on-ukraine-result-in-less-online-crime

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

What do ransomware blackmailers ask for when they don't want money? Why did Firefox get two updates in three days? How did Adafruit get hoist by the petard of shadow IT? And what's with those dirty Linux pipes?

https://nakedsecurity.sophos.com/ransomware-with-a-difference https://nakedsecurity.sophos.com/firefox-patches-two-in-the-wild-exploits https://nakedsecurity.sophos.com/adafruit-suffers-github-data-breach https://nakedsecurity.sophos.com/dirty-pipe-linux-kernel-bug https://events.sophos.com/cyberinsurance

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How good is Apple's AirTag stalker detection? Why are web coders still making Y2K-like blunders? And how many Instagram scams can you get in one weekend?

https://nakedsecurity.sophos.com/apple-airtag-anti-stalking https://nakedsecurity.sophos.com/did-we-learn-nothing-from-y2k https://nakedsecurity.sophos.com/instagram-scammers-as-busy-as-ever

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

VM escapes could put your host servers at risk. PHP fixes an input validation bug in input validation code. A WordPress plugin maker shows you how to write a decent security report. And French scammers remind us that sextortion is sadly still a thing.

https://nakedsecurity.sophos.com/vmware-fixes-holes https://nakedsecurity.sophos.com/irony-alert-php-fixes-security-flaw https://nakedsecurity.sophos.com/wordpress-backup-plugin-maker-updraft-says-you-should-update https://nakedsecurity.sophos.com/french-cybercriminals-using-sextortion-scams

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Alleged Bitcoin fraudsters busted, power company in trillion-dollar payout blunder, how a blizzard led to a telecomms revolution, and 0-day after 0-day after 0-day.

https://nakedsecurity.sophos.com/self-styled-crocodile-of-wall-street-arrested https://nakedsecurity.sophos.com/power-company-pays-out-3-trillion-compensation https://nakedsecurity.sophos.com/apple-zero-day-drama-for-macs-iphones-and-ipads https://nakedsecurity.sophos.com/adobe-fixes-zero-day-exploit-in-e-commerce-code https://nakedsecurity.sophos.com/google-announces-zero-day-in-chrome-browser

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Problems with plugins. A Wormhole wormhole. Can machines think? Microsoft has a change of heart. And then another one. Why screen cleaning cloths are cool.

https://nakedsecurity.sophos.com/elementor-wordpress-plugin-has-a-gaping-security-hole https://nakedsecurity.sophos.com/wormhole-cryptotrading-company-turns-over-340000000-to-criminals https://nakedsecurity.sophos.com/microsoft-blocks-web-installation-of-its-own-app-installer-files https://nakedsecurity.sophos.com/at-last-office-macros-from-the-internet-to-be-blocked-by-default

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Stealing root on Linux. Snooping on RAM with a video driver bug. Apple patches a zero-day hole. SMS scams promise home PCR machines. German court freaks out over fonts. How to be private. And a paint robot that went wild.

https://nakedsecurity.sophos.com/pwnkit-security-bug-gets-you-root https://nakedsecurity.sophos.com/linux-kernel-patches-performance-can-be-harmful-bug https://nakedsecurity.sophos.com/apple-patches-safari-data-leak https://nakedsecurity.sophos.com/coronavirus-sms-scam-offers-home-pcr https://nakedsecurity.sophos.com/website-operator-fined-for-using-google-fonts https://nakedsecurity.sophos.com/happy-data-privacy-day

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Watch out for tax scams. Crooks with the motto "In Fraud We Trust". How not to write a data breach notification. Where to find the "10" key on your telephone.

https://nakedsecurity.sophos.com/tax-scam-emails-are-alive-and-well-as-us-tax-season-starts https://nakedsecurity.sophos.com/alleged-carder-gang-mastermind-and-three-acolytes-under-arrest-in-russia https://nakedsecurity.sophos.com/cryptocoin-broker-crypto-com-says-2fa-bypass-led-to-35m-theft

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Russia busts Revil. Romance scammer sent to prison. Wormable Windows hole patched. Memories of the HAPPY99 virus. Linux disk encryption trouble. Apple browsers leak personal data. And how (not) to paint a computer.

https://nakedsecurity.sophos.com/revil-ransomware-crew-allegedly-busted https://nakedsecurity.sophos.com/romance-scammer-who-targeted-670-women https://nakedsecurity.sophos.com/wormable-windows-http-hole https://nakedsecurity.sophos.com/serious-security-linux-full-disk-encryption-bug https://nakedsecurity.sophos.com/serious-security-apple-safari-leaks-private-data

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

A JavaScript coder sabotages his own projects. Routers with critical holes. Honda cars party like it's 2002. The FTC warns everyone to patch. And a Log4Shell-like bug in another Java library.

https://nakedsecurity.sophos.com/javascript-developer-destroys-own-projects https://nakedsecurity.sophos.com/home-routers-with-netusb-support https://nakedsecurity.sophos.com/honda-cars-in-flashback-to-2002 https://nakedsecurity.sophos.com/ftc-threatens-legal-action https://nakedsecurity.sophos.com/log4shell-like-security-hole

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Log4Shell - the gift that keeps on taking. Scammers threatening your social media accounts. Apple Home has a pecuu[...]uuliar bug. And why 2FA is easier than you think.

https://nakedsecurity.sophos.com/sfw-the-top-n-cybersecurity-stories https://nakedsecurity.sophos.com/log4shell-vulnerability-number-four https://nakedsecurity.sophos.com/log4shell-the-movie https://nakedsecurity.sophos.com/instagram-copyright-infringment-scams https://nakedsecurity.sophos.com/apple-home-software-bug

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Understanding Log4Shell. Fixing Log4Shell. What criminals are up to with Log4Shell. Apple's latest security fixes. And what (not to) do when your mouse gets stuck.

https://nakedsecurity.sophos.com/log4shell-explained https://nakedsecurity.sophos.com/log4shell-java-vulnerability https://news.sophos.com/log4shell-hell-anatomy-of-an-exploit https://nakedsecurity.sophos.com/apple-security-updates-are-out

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Mozilla's "BigSig" buffer overflow hole. UK to put IoT vendors on notice. The Mother of All Demos. Cryptocurrency company catastrophe. Firefox gets an extra sandbox. And an access point from outer space (OK, from home).

https://nakedsecurity.sophos.com/mozilla-patches-exploitable-bigsig https://nakedsecurity.sophos.com/iot-devices-must-protect-consumers https://nakedsecurity.sophos.com/cryptocurrency-startup-fails-to-subtract https://nakedsecurity.sophos.com/firefox-update-brings-a-whole-new

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Call scammers and cryptocoin treachery. Cloud insecurity and yet more cryptocoin treachery. Facial recognition creepiness. And the wannabe wizard that went to school with a trainee Sith.

https://nakedsecurity.sophos.com/us-government-securities-watchdog-spoofed https://nakedsecurity.sophos.com/cloud-security-dont-wait-until-your-next-bill https://nakedsecurity.sophos.com/controversial-face-matchers-clearview-set-to-be-fined

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Cybersecurity tips for the holiday season and beyond. Exchange at risk from public exploit. GoDaddy loses passwords for 1.2m users. Longest-lived Windows version ever. Don't make your cookies public. And the day that umbrellas became an anti-DDoS tool.

https://nakedsecurity.sophos.com/black-friday-and-cyber-monday-heres-what https://nakedsecurity.sophos.com/check-your-patches-public-exploit-now-out https://nakedsecurity.sophos.com/godaddy-admits-to-password-breach-check https://nakedsecurity.sophos.com/github-cookie-leakage-thousands-of-firefox-cookie-files

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The infamous Emotet malware makes a comeback. Crooks smirk at the world with a fake FBI warning. Why tubes are also valves. Samba fixes an intriguing bug. The suitcase that needs no handle. And a virtual-versus-real monitor mixup.

https://nakedsecurity.sophos.com/emotet-malware-the-report-of-my-death https://nakedsecurity.sophos.com/dhs-warning-about-hackers-in-your-network https://nakedsecurity.sophos.com/samba-update-patches-plaintext-passwork-plundering https://nakedsecurity.sophos.com/the-self-driving-smart-suitcase

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We enjoy the Sophos 2022 Threat Report. The world's {oldest, coolest} continously maintained browser. Facebook folds up its Face Recognition feature. Crooks combine a new social engineering scam with a new way of packaging malware. Kaseya ransomware suspect busted. And how to block radio communications in a land with no hills.

https://nakedsecurity.sophos.com/2022-threat-report https://nakedsecurity.sophos.com/customer-complaint-email-scam https://nakedsecurity.sophos.com/kaseya-ransomware-suspect-nabbed-in-poland https://nakedsecurity.sophos.com/facebook-to-throw-out-face-recognition

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Norbert (huzzah for Norbert!) does tech support. Europol digs into the ransomware scene. Microsoft finds a wacky bug in Apple's shell. The Morris worm turns 33. Edge on Linux phans the phlames. Ola! Gibberish peculiarity textual solvage.

https://nakedsecurity.sophos.com/europol-announce-targeting-of-12-suspects https://nakedsecurity.sophos.com/microsoft-documents-shrootless-hack https://nakedsecurity.sophos.com/memories-of-the-internet-worm https://nakedsecurity.sophos.com/microsoft-edge-finally-arrives-on-linux

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Bliss is a hill in wine country. Lessons from a cryptotrading hamster. Ransomware gang hacked back. Docusign phishers go after 2FA codes. Sleep mode considered harmful.

https://nakedsecurity.sophos.com/revil-ransomware-gang-allegedly-forced-offline https://nakedsecurity.sophos.com/banking-scam-uses-docusign-phish https://nakedsecurity.sophos.com/to-the-moon-cryptocurrency-hamster-mr-goxx

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got something to share? Email tips@sophos.com

View Details

Special minisode! Michelle Farenci knows her stuff, because she's a cybersecurity practitioner inside a cybersecurity company. Learn why thinking like an attacker makes you a better defender.

Full transcript: https://nakedsecurity.sophos.com/listen-up-4-cybersecurity-first-purple-teaming

View Details

Special minisode! Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance.

Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-cyberinsurance

View Details

Special minisode! Chester Wisniewski, Principal Research Scientist at Sophos, gives you useful and actionable advice to reduce the risk of supply chain attacks.

Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-supply-chain-attacks

View Details

Special Minisode! Fraser Howard, Director of Threat Research at Sophos, talks about malware and how to fight it. Fraser's breadth and depth of knowledge in the threat-fighting field is second to none.

Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-week4

View Details

Hook up with our forthcoming Live Malware Demo presentation. Why we think you should celebrate Global Encryption Day. A whole new twist on bogus online "friendships". How to stop your network cables giving you away. And why superglue is NOT a cybersecurity tool!

Register for the Live Malware Demo: https://jaarbeurs.swoogo.com/tbx2021/registersocially?ref=Sophos

Further reading: https://nakedsecurity.sophos.com/becybersmart-2021-week3 https://nakedsecurity.sophos.com/romance-scams-with-a-cryptocurrency-twist https://nakedsecurity.sophos.com/lantenna-hack-spies-on-your-data

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Apple (you guessed it!) fixes yet another iPhone 0-day. Apache patches an embarrassing bug and then has to patch the patch. It's Fight The Phish week. And the user who got punched right in the nose by a recalcitrant computer.

https://nakedsecurity.sophos.com/apple-quietly-patches-yet-another-iphone-0-day https://nakedsecurity.sophos.com/apache-patch-proves-patchy https://nakedsecurity.sophos.com/becybersmart-2021-week2

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Apple Pay gets hacked (sort of). DOJ busts four gift card scamming suspects. We give you our top tips for #Cybermonth. Ukrainian Cyberpolice take on ransomware crooks. And, believe it or not, the user that volunteered to RTFM!?

https://nakedsecurity.sophos.com/how-to-steal-money-via-apple-pay https://nakedsecurity.sophos.com/gift-card-fraud-four-suspects-hit https://nakedsecurity.sophos.com/gift-card-hack-exposed https://nakedsecurity.sophos.com/becybersmart-2021-week1 https://nakedsecurity.sophos.com/europol-announces-two-more-ransomware-busts

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Let's Encrypt brings HTTPS to everyone. Researchers rediscover an Outlook data leakage issue. VMware keeps it real. And when the mouse is away, the cat will play.

https://nakedsecurity.sophos.com/serious-security-lets-encrypt-gets-ready-to-go-it-alone https://nakedsecurity.sophos.com/how-outlook-autodiscover-could-leak-your-passwords https://nakedsecurity.sophos.com/vmware-patch-bulletin-warns-this-needs-your-immediate-attention

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

A scarily exploitable hole in Microsoft open source code. A simpler take on delivery scams. A Face ID bypass hack, patched for the initial release of iOS 15. And how not to get locked in a cabling closet.

https://nakedsecurity.sophos.com/omigod-an-exploitable-hole https://sophos.com/intelix https://nakedsecurity.sophos.com/back-to-basics-as-courier-scammers-skip-fake-fees https://nakedsecurity.sophos.com/ios-15-includes-face-id-fix

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Apple patches two zero-day bugs. Microsoft patches one zero-day bug. A security researcher finds a fast-food bug (non-insect sort). And a touchpad user turns right into left, and vice versa.

https://nakedsecurity.sophos.com/apple-products-vulnerable-to-forcedentry https://nakedsecurity.sophos.com/windows-zero-day-mshtml-attack https://news.sophos.com/big-office-bug-squashed-for-september-2021 https://nakedsecurity.sophos.com/serious-security-how-to-make-sure-you-dont-miss-bug-reports

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Overlooked security flaw leaves web code vulnerable. A home alarm system that almost anyone can turn off. Some fascinating Firefox bugs fixed. And when you grab your laptop... but it's not yours.

https://events.sophos.com/sosweek2021 https://nakedsecurity.sophos.com/poisoned-proxy-pacs https://nakedsecurity.sophos.com/pwned-the-home-security-system

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Security code flushes out security bugs. Recursion: see recursion. Phishing (and lots of it). And the Windows desktop that got so big it imploded.

https://nakedsecurity.sophos.com/big-bad-decryption-bug-in-openssl https://nakedsecurity.sophos.com/skimming-the-cream-recursive-withdrawals https://news.sophos.com/phishing-insights-2021

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

More money troubles in cryptotown. Trouble with plastic spaghetti. The mouse that conquered Windows. And the embarrassment when you report one of your very own emails as a phish.

https://nakedsecurity.sophos.com/japanese-cryptocoin-exchange-robbed https://nakedsecurity.sophos.com/whats-that-on-my-3d-printer-cloud-bug https://nakedsecurity.sophos.com/how-a-gaming-mouse-can-get-you-windows-superpowers

With Paul Ducklin and Doug Aamoth.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Copyright infringement scams that beg you to call. An IoT bug that could be exploited for video snooping and more. A hacker steals $600m and then makes a song and dance out of giving it back. And how Doug's PS5 issues could be solved at last.

https://nakedsecurity.sophos.com/copyright-scammers-turn-to-phone https://nakedsecurity.sophos.com/video-surveillance-network-hacked https://nakedsecurity.sophos.com/hacker-grabs-600m-in-cryptocash

With Paul Ducklin and Chester Wisniewski.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Home and small business routers under attack. A hacking tool favoured by crooks gets hacked. The Navajo Nation's selfless cryptographic contribution to America. A cybercrook gets aggrieved at being ripped off by cybercrooks.

https://nakedsecurity.sophos.com/home-and-small-business-routers-under-attack https://nakedsecurity.sophos.com/cobalt-strike-network-attack-tool-patches https://www.reaganlibrary.gov/archives/speech/proclamation-4954-national-navaho-code-talkers-day https://nakedsecurity.sophos.com/conti-ransomware-affiliate-goes-rogue

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The latent 0-day that didn't get reported until it was too late. Retro computing: reliving the TRS-80. Crooks that help you install their malware. And a 5-minute billionaire (who ended up with $400).

https://nakedsecurity.sophos.com/microsoft-researcher-found-apple-0-day https://nakedsecurity.sophos.com/bazarcaller-the-malware-gang

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Apple's emergency 0-day fix. Two sorts of Windows nightmare, neither involving printers. Twitter hacker busted. And our very own Doug ruins a brand new TV.

https://nakedsecurity.sophos.com/apple-emergency-zero-day-fix https://nakedsecurity.sophos.com/windows-petitpotam-network-attack https://nakedsecurity.sophos.com/windows-hivenightmare-bug https://nakedsecurity.sophos.com/us-court-gets-uk-twitter-hack-suspect-arrested https://nakedsecurity.sophos.com/porn-blast-disrupts-bail-hearing https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Learning from computer virus history. The PrintNightmare saga continues. Apple puts out a patch, but doesn't say why. Snitch on a crook and earn $10 million. Scammers do grammar. And the Business Email Compromise that wasn't.

https://nakedsecurity.sophos.com/the-code-red-worm-20-years-on https://nakedsecurity.sophos.com/more-printnightmare https://nakedsecurity.sophos.com/apple-iphone-patches-are-out-no-news https://nakedsecurity.sophos.com/want-to-earn-10-million-snitch https://nakedsecurity.sophos.com/home-delivery-scams-get-smarter

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We explain how a format string bug could lock your iPhone out of your own network. We revisit the PrintNightmare saga, which is sort-of fixed but not really. We look back at the 20-year-old Code Red virus. We look at what cybercriminals spend money on (hint: more cybercrime). And in this week's "Oh! No!", we learn how farm animals can disrupt your network.

https://nakedsecurity.sophos.com/take-care-dont-get-tricked https://nakedsecurity.sophos.com/printnightmare-official-patch-is-out https://nakedsecurity.sophos.com/where-do-all-those-cybercrime-payments-go

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

The "Independence Day Weekend" ransomware drama. The PrintNightmare nightmare continues. An email hacker gets his conviction overturned. In this week's Oh! No! story, a server room fills with toxic fumes...

This week's articles: https://nakedsecurity.sophos.com/kaseya-ransomware-attackers-say-pay-70-m https://nakedsecurity.sophos.com/printnightmare-the-zero-day-hole https://nakedsecurity.sophos.com/printnightmare-official-patch-is-out https://nakedsecurity.sophos.com/us-email-hacker-gets-his-computer-trespass

The IBM 3270 "retrofont" that Duck loves: https://github.com/rbanffy/3270font

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

In this special splintersode, Kimberly Truong talks to Eva Galperin, Director of Security at the Electronic Frontier Foundation.

Follow Eva on Twitter: https://twitter.com/evacide TED talk mentioned in podcast: https://www.ted.com/talks/eva_galperin_what_you_need_to_know_about_stalkerware

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

When you spend tens of pounds but get billed thousands because the system mistook the date for the amount. Our tips to make #SocialMediaDay your safest day on social media yet. And a clip from a great new privacy splintersode we'll be airing next week.

https://nakedsecurity.sophos.com/british-tourists-charged-1000s https://nakedsecurity.sophos.com/police-warn-of-whatsapp-scams

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

S3 Ep38: Clop busts, destructive Linux hacking, and rooted bicycles

Ukrainian cops bring out the BFG (Big Fearsome Grinder) and cut open some doors. A repeated request for destructive Linux code enters its 15th year. Peloton exercise bicycles found to be rootable.

https://nakedsecurity.sophos.com/clop-ransomware-suspects-busted-in-ukraine https://nakedsecurity.sophos.com/can-you-blow-a-pc-speaker https://nakedsecurity.sophos.com/how-to-hack-a-bicycle-peloton-bike-rooting

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

S3 Ep37: Quantum crypto, refunding Bitcoins, and Alpaca problems

Will quantum cryptography mean the end of encryption? How was the FBI able to get bitcoins back in the Colonial Pipeline ransomware case? What is the ALPACA attack, and does it make your browsing less secure?

https://nakedsecurity.sophos.com/serious-security-post-quantum-cryptography https://nakedsecurity.sophos.com/how-could-the-fbi-recover-btc https://nakedsecurity.sophos.com/alpaca-the-wacky-tls-security-vulnerability

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

S3 Ep36: Trickbot coder busted, passwords cracked, and breaches judged

Alleged malware coder from the Trickbot gang arrested. 5500 passwords cracked and salaries stolen by "credential stuffing" crook. And we answer a listener's question about just how tough to be when judging a company that's had a breach.

https://nakedsecurity.sophos.com/latvian-woman-charged-with-writing-malware https://nakedsecurity.sophos.com/how-to-hack-into-5500-accounts

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

S3 Ep35: Apple chip flaw, Have I Been Pwned, and Covid tracker trouble

The fascinating tale of a bug that's baked into Apple's latest chip. Why the Aussie data breach warning site HIBP is partnering with the FBI. And a coronavirus tracking toolkit that fell foul of privacy rules.

https://nakedsecurity.sophos.com/unpatchable-vuln-in-apples-new-mac-chip https://nakedsecurity.sophos.com/have-i-been-pwned-breach-site-partners-with-the-fbi https://nakedsecurity.sophos.com/regulator-fines-covid-19-tracker

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Apple patches a raft of serious security holes. Police arrest eight suspects in an online scamming ring. We explain how WhatsApp messages from hacked accounts are helping cybercrooks bypass 2FA.

https://nakedsecurity.sophos.com/apple-patches-dangerous-security-holes-one-in-active-use-update-now https://nakedsecurity.sophos.com/eight-suspects-busted-in-raid-on-home-delivery-scamming-operation https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac-podcast

And if you are after the product recommended by our up-and-coming haircare expert Duck, it's spelled Tangle Teezer. (That may look like a typo, but it's not. That's really how they write it.)

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We look into an unnerving case of mixed-up video feeds. We warn you against "going rogue" when you can't get the download you want from the regular place. We explain how Apple's new AirTag product got hacked (again).

Stories discussed: https://nakedsecurity.sophos.com/apple-airtags-hacked-again-free-internet https://nakedsecurity.sophos.com/gamers-beware-crooks-take-advantage https://nakedsecurity.sophos.com/those-arent-my-kids-eufy-camera-owners

Related stories from the podcast: https://nakedsecurity.sophos.com/omg-i-just-received-someone-elses-security-cam https://nakedsecurity.sophos.com/150000-security-cameras-allegedly-breached https://nakedsecurity.sophos.com/apple-airtag-jailbroken-already

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Apple's brand new AirTag product got hacked already. Things you can learn from Colonial Pipeline's ransomware misfortune. Why Dell patched a bunch of driver bugs going back more than a decade. And the "Is it you in the video?" scam just keeps on coming back.

Stories discussed: https://nakedsecurity.sophos.com/apple-airtag-jailbroken-already https://nakedsecurity.sophos.com/dell-fixes-exploitable-holes https://nakedsecurity.sophos.com/is-it-you-in-the-video-dont-fall-for-this

Additional links you will find useful: https://news.sophos.com/en-us/using-sophos-edr-to-identify-endpoints-impacted-by-dell https://nakedsecurity.sophos.com/ransomware-dont-expect-a-full-recovery https://news.sophos.com/a-defenders-view-inside-a-darkside-ransomware-attack https://www.sophos.com/ransomware

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We look into Apple's recent emergency updates that closed off four in-the-wild browser bugs. We explain how the infamous "Flubot" home delivery scam works and how to stop it. We investigate a recent security bug that threatened the PHP ecosystem.

https://nakedsecurity.sophos.com/apple-products-hit-by-fourfecta-of-zero-day-exploits https://nakedsecurity.sophos.com/naked-security-live-beware-flubot-the-home-delivery-scam https://nakedsecurity.sophos.com/php-community-sidesteps-its-third-supply-chain-attack

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We investigate whether AirDrop is really as dangerous as researchers claimed. We discuss the pestiferous problem of fake Linux bugs submitted as an academic exercise. We review the latest Sophos Ransomware Report and uncover uncomfortable truths about paying up.

https://nakedsecurity.sophos.com/apple-airdrop-has-significant-privacy-leak https://nakedsecurity.sophos.com/linux-team-in-public-bust-up-over-fake-patches https://nakedsecurity.sophos.com/ransomware-dont-expect-a-full-recovery

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How Firefox showed the hand to a widely abused online tracking trick. Why reading from one part of your computer's memory can paradoxically (and sneakily) let you write to another part. And yet more IoT bugs, this time a whole slew of them that go by the moniker "name:wreck".

https://nakedsecurity.sophos.com/firefox-88-patches-bugs https://nakedsecurity.sophos.com/serious-security-rowhammer-is-back https://nakedsecurity.sophos.com/iot-bug-report-claims-at-least-100m

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Sophos cybersecurity expert Chester Wisniewski provides excellent, topical and timely commentary on the FBI’s recent use of a malware-like method to forcibly clean up hundreds of servers still infected in the Hafnium aftermath.

With Paul Ducklin and Chester Wisniewski

https://nakedsecurity.sophos.com/fbi-hacks-into-hundreds-of-infected-us-servers https://nakedsecurity.sophos.com/naked-security-live-hafnium-explained-in-plain-english

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We look at the big-money hacks from the 2021 Pwn2Own competition. We investigate the difficulties of hiring an assassin via the dark web. We wrestle with some of the privacy issues relating to COVID-19 infection tracking apps.

https://nakedsecurity.sophos.com/pwn2own-2021-zoom-teams-exchange-chrome-and-edge https://nakedsecurity.sophos.com/italian-charged-with-hiring-dark-web-hitman https://nakedsecurity.sophos.com/apple-and-google-block-official-uk-covid-19-app

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How scammers copied a government website almost to perfection. What to do about those fake "bug" hunters who ask for payment for finding "vulnerabilities" that aren't. Why the Dutch data protection authority fined Booking.com for not sending in a data breach disclosure fast enough.

https://nakedsecurity.sophos.com/criminals-send-out-fake-census https://news.sophos.com/have-a-domain-name-beg-bounty-hunters https://news.sophos.com/beg-bounty-hunting-why-do-people-do-it https://news.sophos.com/the-unintended-consequences-of-rewarding-beg-bounty-hunters https://nakedsecurity.sophos.com/s3-ep8-a-conversation-with-katie-moussouris https://nakedsecurity.sophos.com/too-slow-booking-com-fined https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac https://nakedsecurity.sophos.com/what-should-you-say-if-you-have-a-data-breach

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Why Apple had to rush out a security update for iDevices. Two cryptographic security holes patched in OpenSSL. How PHP nearly got backdoored by crooks.

https://nakedsecurity.sophos.com/apple-devices-get-urgent-patch-for-zero-day-exploit https://nakedsecurity.sophos.com/serious-security-openssl-fixes-two-high-severity-crypto-bugs https://nakedsecurity.sophos.com/php-web-language-narrowly-avoids-dangerous-supply-chain-attack

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How a social engineer ripped off a victim lured in by one of those "small outstanding fee to pay" home delivery scams. The ransomware crooks targeting networks that still haven’t done their Hafnium patches. And the Linux kernel security holes that lay there undiscovered for 15 years.

Related articles that we refer to in the show: https://nakedsecurity.sophos.com/beware-the-dhl-delivery-message https://nakedsecurity.sophos.com/watch-out-scummy-scammers-target-home-deliveries https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac https://nakedsecurity.sophos.com/blackkingdom-ransomware https://nakedsecurity.sophos.com/serious-security-webshells-explained https://nakedsecurity.sophos.com/naked-security-live-hafnium-explained-in-plain-english https://nakedsecurity.sophos.com/serious-security-the-linux-kernel-bugs-that-surfaced

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We discuss an iPhone app that allowed anyone to snoop on anyone's calls - but not in the way you might expect. We investigate a data breach where 150,000 surveillance cameras protecting hundreds or thousands of customers were apparently "secured" by a single password... that got leaked onto the internet. And we urge you as keenly as we can: "Don't spread hoaxes, folkses."

https://nakedsecurity.sophos.com/how-confidential-are-your-calls https://nakedsecurity.sophos.com/150000-security-cameras-allegedly-breached https://nakedsecurity.sophos.com/facebook-hoaxes-harmless-fun-or-security-risk

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

John Noble was Director of Incident Management at the UK's National Cyber Security Centre (NCSC) until his retirement in 2018. During his 40 years of Government service, John specialised in operational delivery and strategic business change. For his work in creating effective partnerships in the run up to the London Olympics, he was made a Commander of the British Empire (CBE) in 2012.

John helped to establish the NCSC and led the response to nearly 800 significant cyberincidents. This work has given him unrivalled experience in dealing with and understanding the causes of cyberattacks.

John is currently a non-executive director at NHS Digital, where he chairs the Information Assurance and Cyber Security Committee. NHS Digital is the national information and technology partner to the health and social care system in England.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Getting to grips with the HAFNIUM cybercrooks/vulnerabilities/exploits/webshells/attacks. Why it's important to think before you share those home-based selfies. What you need to know about social engineering. How (not!) to prove a point when you're a programmer.

https://nakedsecurity.sophos.com/serious-security-webshells-explained-in-the-aftermath-of-hafnium https://nakedsecurity.sophos.com/i-see-you-your-home-working-photos-reveal-more-than-you-think https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac https://nakedsecurity.sophos.com/poison-packages-supply-chain-risks-user-hits-python-community

With Kimberly Truong and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How to stop security-conscious apps from allowing unencrypted data to escape, and how scammers put social network users under pressure in order to steal their passwords.

https://nakedsecurity.sophos.com/keybase-secure-messaging-fixes-photo-leaking-bug https://nakedsecurity.sophos.com/naked-security-live-beware-copyright-scams

With Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

S3 Ep21: Cryptomining clampdown, the 100-ton man, and ScamClub ads

The graphics card that wants you to stick to playing games, the man that didn't weigh 100 tons after all, and the marketing gang that used a browser bug to bombard iPhone users with scammy online surveys.

https://nakedsecurity.sophos.com/nvidia-announces-official-anti-cryptomining https://nakedsecurity.sophos.com/the-massive-coronavirus-pandemic-it-blunder https://nakedsecurity.sophos.com/scamclub-gang-outed-for-exploiting-iphone-browser

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How a bug hunter snuck into the internal networks of 35 megacorporations. Why romance scams are going stronger than ever (and how to avoid them). What to do about those tempting but treacherous "tax refund" messages. And a listener tells us how he got a bit carried away while he was gardening...

https://nakedsecurity.sophos.com/how-one-man-silently-infiltrated https://nakedsecurity.sophos.com/romance-scams-at-all-time https://nakedsecurity.sophos.com/sms-tax-scam-unmasked

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

In this special mini-episode, Paul Ducklin talks to Sophos cybersecurity expert Chester Wisniewski about bug bounty hunting.

How does bug bounty hunting work? What should you do if you get a bug report that doesn't follow established protocol? Chester tells you how to deal with so-called "beg bounties", where self-styled "experts" beg you for money or even threaten you with ill-defined "problems" they claim to have found.

https://news.sophos.com/have-a-domain-name-beg-bounty-hunters-may-be-on-their-way https://nakedsecurity.sophos.com/beware-of-technical-experts-bombarding-you-with-bug-reports

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We delve into Google's tight-lipped Chrome bugfix, explain how a Belgian researcher awarded himself 111,848 cups of coffee, and discuss the audacious but thankfully temporary theft of the Perl.com domain.

https://nakedsecurity.sophos.com/chrome-zero-day-browser-bug https://nakedsecurity.sophos.com/free-coffee-dutch-researcher https://nakedsecurity.sophos.com/perl-com-gets-its-domain-back

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Apple pushed out an iOS update in a hurry to shut down a serious 0-day bug. The GnuPG team scrambled to fix an ironic vulnerability that could be exploited during the very process of checking if the data you just received could be trusted. And Europol reported on a successful takedown operation against the notorious Emotet malware.

https://nakedsecurity.sophos.com/apple-critical-patches-fix-in-the-wild-iphone-exploits https://nakedsecurity.sophos.com/gnupg-crypto-library-can-be-pwned-during-decryption https://nakedsecurity.sophos.com/emotet-takedown-europol-attacks-worlds-most-dangerous-malware

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

What's the connection between coronavirus facemasks and fingerprint biometrics? Who would have expected funky job ads on the White House website? And what would you do if you spotted a deceased former colleague hanging out on your network?

https://nakedsecurity.sophos.com/has-the-coronavirus-pandemic-affected-apples-hardware https://nakedsecurity.sophos.com/us-administration-adds-subliminal-ad https://nakedsecurity.sophos.com/ghost-hack-criminals-use-deceased-employees-account

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Anonymous and private, yet busted! We explain how darkweb sites sometimes keep your secrets... and sometimes don't. We help you improve your cybersecurity at home. And we tell you the tale of a company with the coolest name but allegedly with the creepiest habits coded into its browser extensions.

https://nakedsecurity.sophos.com/europol-announces-bust-of-worlds-biggest-dark-web-market https://nakedsecurity.sophos.com/home-schooling-how-to-stay-secure

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Thanks to coronavirus lockdown rules in the UK, and the temporary closure of all schools, Sally Adam suddenly found herself responsible for cybersecurity where it mattered more than ever: on a home network that jointly served for home, work and school.

Paul Ducklin talks to Sally about how she did it, and how to keep your own family’s digital life safe.

https://nakedsecurity.sophos.com/home-schooling-how-to-stay-secure https://nakedsecurity.sophos.com/home-wi-fi-security-tips

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We explain how two French researchers hacked the Google Titan security key product (but why you don't need to panic), and dig into the Mimecast certificate compromise story to see what we can all learn from it.

https://nakedsecurity.sophos.com/google-titan-security-keys-hacked

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We advise you how to react when a friend suddenly asks for money, explain why Chromium is finally aiming for HTTPS by default, and warn you why you should never, ever hardcode passwords into your software.

https://nakedsecurity.sophos.com/does-a-friend-need-money-urgently https://nakedsecurity.sophos.com/chrome-browser-has-a-new-years-resolution https://nakedsecurity.sophos.com/zyxel-hardcoded-admin-password

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How did the movie "Hackers" inspire a girl to grow up to become a hacker herself? Find out from security analyst, friendly hacker and TED Talk speaker Keren Elazari. Hear about Keren’s incredible journey, why hackers should be welcomed with open arms, and the inspiration that guided her career.

With Kimberly Truong and special guest Keren Elazari (@k3r3n3 on Twitter), cybersecurity analyst and researcher.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How do you go from neuroscientist to DEFCON Social Engineering Capture the Flag champ? Find out from hacker and social engineering expert Rachel Tobac. Join us for a fascinating interview with Rachel about her journey, why you should always be “politely paranoid”, and the people who inspired her along the way.

With Kimberly Truong and special guest Rachel Tobac (@RachelTobac on Twitter), hacker and CEO of SocialProof Security.

Book mentioned by Rachel: "The 6 principles of persuasion" by Robert Cialdini.

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We look at phishing tricks that really work, investigate a bizarre scam involving Subway sandwiches, and ask whether cybercriminals have lost their interest in the rest of us now they have coronavirus-related targets to go after.

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/phishing-tricks-that-really-work https://nakedsecurity.sophos.com/subway-sandwich-scam-mystifies https://nakedsecurity.sophos.com/was-there-a-covid-19-vaccine-hack

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Naked Security's Paul Ducklin interviews Sophos expert John Shier about his recently published paper, "20 years of cyberthreats that shaped information security."

Join John on a dizzying journey all the way from legendary viruses such as ILOVEYOU and Code Red, which flooded the internet in 2000, to present-day ransomware gangs like Ryuk and REvil, who are extorting millions of dollars in blackmail money per attack.

https://news.sophos.com/20-years-of-cyberthreats

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We dig into research that figured out a way to steal data from iPhones wirelessly, we tell the fascinating story of how environmentalist divers in Germany came across an old Enigma cipher machine at the bottom of the Baltic sea, and we give you advice on how to talk to phone scammers.

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/how-to-steal-photos-off-someones-iphone https://nakedsecurity.sophos.com/german-divers-find-enigma-crypto-machine https://nakedsecurity.sophos.com/vishing-criminals-let-rip-with-two-scams

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

We look at a network intrusion where the crooks tried to take over dozens of different online accounts from every user, we discuss the potential dangers of digital doorbells, and we give you some handy hints for improving your wireless security at home.

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/gift-card-hack-exposed-you-pay-they-play https://nakedsecurity.sophos.com/bzzzzzzt-how-safe-is-that-keenly-priced-digital-doorbell https://nakedsecurity.sophos.com/home-wi-fi-security-tips-5-things-to-check

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

How do you go from pentester to creator of Microsoft’s bug bounty program? Find out from hacker and vulnerability disclosure pioneer, Katie Moussouris. Join us for a fascinating interview with Katie about her journey, the bugs in bug bounty programs, and the people who inspired her along the way.

With Kimberly Truong and special guest Katie Moussouris (https://twitter.com/k8em0), Founder and CEO of Luta Security (https://www.lutasecurity.com).

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

In this episode: we say thanks to companies that refuse to pay ransomware hush money, dig into the new Sophos 2021 Threat Report, and take a quick look inside a malicious Linux kernel driver. Also, a sneak preview of our upcoming podcast interview with bug bounty pioneer Katie Moussouris.

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/cult-videogame-company-capcom-pays-a-big-round-0 https://nakedsecurity.sophos.com/sophos-threat-report-2021 https://nakedsecurity.sophos.com/the-cloud-snooper-malware

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

In this episode: When payments go astray, why "just in case" cybersecurity warnings do more harm than good, how to shop safely on Black Friday and beyond, and (oh no!) what to do when all your emails disappear.

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/smishing-attack-tells-you-mobile-payment-problem https://nakedsecurity.sophos.com/instant-bank-fraud-hoax-is-back-dont-spread-fake-news https://nakedsecurity.sophos.com/black-friday-stay-safe-before-during-and-after

To register for the Sophos Evolve event: https://sophos.com/evolve

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

In this episode: a zero-day bug in Chrome for Android, the imminent death of Adobe Flash, the evolution of "malware-as-a-service", and the malware risks from image search. Also (oh! no!), why you should take care before you pair.

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/another-chrome-zero-day-this-time-on-android https://nakedsecurity.sophos.com/adobe-flash-its-the-end-of-the-end-of-the-end https://nakedsecurity.sophos.com/buer-loader-malware-as-a-service-joins-emotet

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

On Wednesday, the FBI, CISA and HHS released an unprecedented warning against "an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers." In this quick mini-sode, Chester Wisniewski (Principal Research Scientist at Sophos) discusses what the threat is, what this advisory means, and why this warning is a warning for everyone.

With Kimberly Truong and special guest, Chester Wisniewski, Principal Research Scientist at Sophos @chetwisniewski

RESOURCES:

Read the article from Naked Security https://nakedsecurity.sophos.com/2020/10/29/fbi-ransomware-warning-for-healthcare-is-a-warning-for-everyone/

Get tools and guidance to protect your organization https://www.sophos.com/en-us/content/healthcare-targeted-ransomware.aspx


Original music by Edith Mudge www.edithmudge.com

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity twitter.com/nakedsecurity Instagram: NakedSecurity instagram.com/nakedsecurity

View Details

S3 Ep4: Now THAT'S what I call a fire alarm!

This week: Facebook scammers trick you with fake copyright notices, voice scammers automate their attacks on the vulnerable, how to tune up your mobile privacy, and (oh! no!) the best/worst IT helpdesk call ever.

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/facebook-copyright-violation-tries-to-get-past-2fa https://nakedsecurity.sophos.com/phone-scamming-friends-dont-let-friends-get-vished https://nakedsecurity.sophos.com/time-for-a-mobile-privacy-reset

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

This week: the DOJ's attempt to reignite the Battle to Break Encryption; the story of the Russian hackers behind the Sandworm Team; a zero-day bug just patched in Chrome; and (oh no!) why your vocabulary needs the word "restore" even more than it needs "backup".

With Kimberly Truong, Doug Aamoth and Paul Ducklin.

https://nakedsecurity.sophos.com/us-department-of-justice-reignites https://nakedsecurity.sophos.com/russian-government-hackers-charged https://nakedsecurity.sophos.com/chrome-zero-day-in-the-wild

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

This week we investigate a creepy smartwatch for kids, discuss Microsoft's short-lived takedown of Trickbot, explain how to avoid the Windows "Ping of Death" bug, and (oh no!) find the source of mysterious beeping from every computer in the office.

With Kimberly Truong, Doug Aamoth and Paul Ducklin

https://nakedsecurity.sophos.com/creepy-covert-camera-feature-found https://nakedsecurity.sophos.com/microsoft-on-the-counterattack-trickbot https://nakedsecurity.sophos.com/windows-ping-of-death-bug

Original music by Edith Mudge (https://www.edithmudge.com)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)

View Details

Join us for the first episode in our brand new Series 3! This week we wonder whether Cybersecurity Awareness Month is a waste of time, explain the concept of "linkless phishing", ask if it's ever OK to pay a ransomware demand, and advise what to do when the CEO won't stop looking at naughty sites.

With Paul Ducklin, Kimberly Truong and Doug Aamoth

https://nakedsecurity.sophos.com/if-you-connect-it-protect-it https://nakedsecurity.sophos.com/serious-security-phishing-without-links https://nakedsecurity.sophos.com/revil-ransomware-crew-dangles-1000000-cybercrime-carrot

Original music by Edith Mudge (https://www.edithmudge.com/)

Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: NakedSecurity (https://twitter.com/nakedsecurity) Instagram: NakedSecurity (https://instagram.com/nakedsecurity)