We take an expert look at the latest cybersecurity incidents, how they happened, and why. Tune in weekly to learn what you can do to stop bad things from happening to you!
Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity Instagram: @NakedSecurity
Miss Manners confronts copy-and-paste. WinRAR patches bugs. When Airplane mode isn't. How many cryptographers to change a light bulb?
Intro and outro music by Edith Mudge (www.edithmudge.com)
Navajo Code Talkers Day. Beta bogosities. Skimming shenanigans. Hooligan hosting. A cybercrime conundrum.
Intro and outro music by Edith Mudge (www.edithmudge.com)
An amazing Art Deco computer. Yet more performance-versus-security trouble. Is sound alone enough to sniff out your password? A rap song (of sorts) with a cybersecurity connection.
Intro and outro music by Edith Mudge (www.edithmudge.com)
Firefox fixes flaws. The exciting vulnerability that you don't need to be afraid of. Breach reporting rules with lots of leeway.
Intro and outro music by Edith Mudge (www.edithmudge.com)
Apple patches two zero-days, one for a second time. How a 30-year-old cryptosystem got cracked. All your secret are belong to Zenbleed. Remembering those dodgy PC/Mac ads.
Intro and outro music by Edith Mudge (www.edithmudge.com)
Why your Mac's calendar app says it's JUL 17. One patch, one line, one file. Careful with that {axe,file}, Eugene. Storm season for Microsoft. When typos make you sing for joy.
Twitter: @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
Remembering the slide rule. What you need to know about Patch Tuesday. Supercookie surveillance shenanigans. When bugs arrive in pairs. Apple's rapid patch that needed a rapid patch. User-Agent considered harmful.
Twitter: @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
First there was DevOps, then SecOps, then DevSecOps. Or should that be SecDevOps? Paul Ducklin talks to Sophos X-Ops insider Matt Holdcroft about how to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light.
Twitter: @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
PONG for one player. Apple pushes out anti-spyware patch. Beware bad passwords on Linux servers. "Twitter hacker" gets 5 years. When mobile phones and dental hygiene collide.
Twitter: @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
Gee Whizz BASIC (probably). Think you know ransomware? Megaupload, 11 years on. ASUS warns of critical router bugs. MOVEit mayhem Part III.
Twitter: @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
Magnetic core memory. Patch Tuesday and SketchUp shenanigans. More MOVEit mitigations. Mt. Gox back in the news. Gozi malware criminal imprisoned at last. Are password rules like running through rain?
Twitter @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
Calling all modems. KeePass gets an update. MOVEit gets pwned. Chromium zero-day. The backdoor that wasn't really. WPBT explained.
Twitter @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
How to say "GIF". A Blackmailer-in-the-Middle attack. Knitting your own crypto. KeePass master password shenanigans. Binge listening.
Email tips@sophos.com
Twitter @NakedSecurity
Intro and outro music by Edith Mudge (www.edithmudge.com)
Luminiferous aether. A $10m cybercrime reward. Bank scam kingpin gets 13 years. Three Apple 0-days. A Python malware maelstrom.
Email tips@sophos.com
Twitter @NakedSecurity
An Apple product that flopped (and was not the Newton). Two-faced sysadmin jailed for 6 years. The smart plug with the unsmart security hole. Clearview AI again, once more, again.
Intro and outro music by Edith Mudge (https://www.edithmudge.com).
Hit us up on Twitter: @NakedSecurity
The world-changing Visible Calculator. How not to get a job. Private keys - the hint is in the name. Microsoft's complicated bootkit patch. Taming Bluetooth trackers.
Email: tips@sophos.com
Twitter: https://twitter.com/nakedsecurity
Original music by Edith Mudge (www.edithmudge.com)
New England gets BASIC. Google hits back at CryptBot crooks. Apple seals its lips on security. Mac malware-as-a-service. World Password Day. PaperCut: disclose or don't disclose?
Original music by Edith Mudge (https://www.edithmudge.com).
The CIH or SpaceFiller virus revisited. Google's 2FA security shortcut. Server vulns under active attack. Two Chrome zero-days, but was it one attack?
Email: tips@sophos.com
Twitter: @NakedSecurity
Fun with FORTRAN?! An extreme data breach and its consequences. Rogue 2FA apps live in action. Juicejacking revisited.
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge.
A common business-oriented language. Patch Tuesday. Secure Boot (without the "Secure" part). Apple zero-days. World-readable garage doors. Motherboard malware threats.
Original music by Edith Mudge (https://www.edithmudge.com)
Email tips@sophos.com
Twitter @NakedSecurity
A supply chain attack that foisted spyware on trusting users. Wi-Fi encryption bypass via left-over data. Surely there should be TWO World Backup Days?
Email tips@sophos.com
Original music by Edith Mudge (https://www.edithmudge.com)
Twitter @NakedSecurity
RIP Gordon Moore, the more in Moore's Law. Photo cropping bugfix. DDoS honeypot. E-commerce patches. Apple 0-day and lots more.
Email tips@sophos.com
Twitter @NakedSecurity
The mobile phone bugs that Google kept quiet, just in case. The mysterious case of ATM video uploads. When redacted data springs back to life.
Email tips@sophos.com
Twitter @NakedSecurity
The price of fast fashion. Firefox fixes. Feature creep fail curtailed in Patch Tuesday updates.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Memories of Michelangelo (the virus, not the artist). Data leakage bugs in TPM 2.0. Ransomware bust, ransomware warning, and anti-ransomware advice.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
How Woz nearly gave away the Apple I. Rogue software packages. Rogue network "administrators". Rogue keyloggers. Rogue authenticators.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The first search warrant for computer storage. GoDaddy breach. Twitter surprise. Coinbase kerfuffle. The cost of success.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The birth of ENIAC. A "sophisticated attack" (someone got phished). A cryptographic hack enabled by a security warning. Valentine's Day Patch Tuesday. Apple closes spyware-sized 0-day hole.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Cryptocurrency crimelords. Security patches for VMware, OpenSSH and OpenSSL. Medical breacher busted. Is that a bug or a feature?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Do we really need a "war against cryptography" - codes and ciphers that the government can easily crack if it thinks there's an emergency - to cement our collective online security?
Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary on this and many other vital issues, including anonymity and privacy, as we talk to him about his tremendous new book, Tracers in the Dark.
Original music by Edith Mudge.
The mighty CPU that wasn't. Hive ransomware takedown. Dutch data crime suspect busted. Samba finally gets rid of MD5. GitHub admits to an intrusion. Storing passwords securely.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The programming language almost called Oak. GoTo admits to more breach woes. T-Mobile spills 37 million records. Apple patches everything, even iOS 12. And Google mAkES tYpOs for sECurity.Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The HAPPY99 virus reminds us that less is more. Trouble with JSON Web Tokens. Investment scammers busted in Europe. The LifeLock "breach" that wasn't.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Two stories from the underground. Bank scammers busted. The crypto-crack that wasn't. And the end of two Windows eras at the same time.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The ground-breaking HP-35 digital calculator. Last straw for LastPass? Congress takes on quantum computing. 33 1/3-year-old cybersecurity lessons. Machine learning supply chain attack.Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Once more unto the breach, dear friends, once more!
Paul Ducklin talks to Peter Mackenzie, Director of Incident Response at Sophos, in a cybersecurity session that will alarm, amuse and educate you, all in equal measure.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email: tips@sophos.com
Twitter: @NakedSecurity
Join world-renowned Sophos expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode, recorded during our recent Security SOS Week 2022. When it comes to fighting cybercrime, Fraser truly is a "specialist in everything", and he also has the knack of explaining this tricky and treacherous subject in plain English.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The irony of the CAN-SPAM law. When genuine kernel drivers go rogue. Apple patches everything. Stealing data via secret radio waves. E-commerce supply chain drama.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The worm that wasn't a Goner. LastPass suffers a sting in the data breach tail. Apple's secretive update. The Ping o' Death. SIM swapping explained. A Beatles-esque 0-day in Chrome and Edge.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Christmas-themed wormage. Prurient malware. Cryptorom busts. Voice call spoofing.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Security specialist John Shier tells you the "news you can really use" - how to boost your cybersecurity based on real-world advice from the 2023 Sophos Threat Report.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Microsoft's tilt at the MP3 marketplace. Apple's not-a-zero-day emergency. Cracking the lock on Android phones. Browser-in-the-Browser revisited. The Emmenthal cheese attack. Business Email Compromise and how to prevent it.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Radio waves so mysterious they're known only as X-Rays. Were there six 0-days or only four? The cops that found $3 billion in a popcorn tin. Blue badge confusion. When URL scanning goes wrong. Tracking down every last unpatched file. Why even unlikely exploits can earn "high" severity levels.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The man who put Boole in Boolean. OpenSSL's bated-breath update. Apple's zero-day finally settled. New Chrome zero-day. SHA-3 code gets a patch. Extreme extortion via stolen medical data. Data breach response the nonchalant way.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Windows XP (fondly?!) remembered. Clearview AI courts controversy again. DEADBOLT ransomware crooks get counterhacked. Women cryptologists commemorated in US. How to measure randomness. Deconstructing Apple's latest security bulletins.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Coolest videogame ever. Zoom thinks everyone's a developer. The Patch Tuesday that wasn't. A data breach coverup. Log4Shell all over again. And the Office cryptofail that Microsoft won't fix.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
What goes up... must come down. Ransomware criminal avoids a life sentence. Former CSO convicted over Uber megabreach coverup. WhatsApp fights rip-off rogue apps. The Countess of Computer Science. Could a weird email brick your iPhone?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Naked Security meets Sophos X-Ops! Duck and Chet dig into OAuth 2.0, a well-known protocol for authorization. Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it.
Original music by Edith Mudge
A fridge-sized calculator made with transistors (really). ProxyNotShell situation reviewed. Romance and BEC scammer gets 25 years in the slammer. Is there an answer to nuisance callers? Is the answer voicemail?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Chester Wisniewski gives you actionable advice on how to deal with two actively exploited Exchange zero-days that suddenly burst into the news. Learn who's affected and how, find out what you can do while waiting for Microsoft's patches, and plan your threat hunting in case the worst happens to you.
Original music by Edith Mudge
What's the real deal with LAPSUS$? How did Optus get hacked? Was there really a WhatsApp 0-day? What if "deleted" data comes back from the dead to haunt you?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Security SOS Week 2022 - check it out! The very first Android. Firefox 105 is out. Uber hacked... by LAPSUS$? LastPass talks about its breach. Are two disks better than one?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Chester Wisniewski explains what we can learn from Uber's latest cybsecurity crisis: "Just because a big company didn't have the security they should doesn't mean you can't."
Original music by Edith Mudge
Second Cosmic Rocket (not a band!) Microsoft 0-day. Apple 0-days. Good logging habits. Browser-in-the-browser trickery. DEADBOLT ransomware. Again.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
The bug that was a moth. Was there really a TikTok breach? Peter Eckersley: Code In Peace. Chrome and Edge fix a zero-day. Apple updates iOS 12 for the first time in a year. App icons: the difference between sprockets and cogs.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The Computer Misuse Act, back in 1990. JavaScript supply-chain bug hunting. Jumping airgaps. "The Sanitizer" comes to Chrome. LastPass breach provokes password manager puzzlement.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Start me up. The R&B dance classic that crashed computers. Bitcoin ATM skimming (no malware required). Multiple browser zero-days. Was your iPhone pwned?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Chester attends DEF CON from afar. Zoom fixes an 0-day. An APIC leak that isn't EPIC. $10m for dobbing in Conti criminals. Cybersecurity in hospitals. Ransomware in triplicate.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Memories of the Blaster worm. Slack leaked password hashes for FIVE YEARS. Github showered with malware. Traffic lights and cybersecurity. Post-quantum cryptography.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Queen Victoria goes online. A nasty bug in Samba. Smiles for SysAdmins. A crypto-as-in-cryptography bug. A crypto-as-in-currency disaster. And is $200 million just chump change these days?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Geosynchronicity. Office security (on-off-on). A half-billion-dollar data breach cost. And patch that browser!
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Integrated circuits and Nobel prizes. Log4Shell - forever? Cybersecurity tips for summmer. Scams and coincidence.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Memories of the Code Red worm. OpenSSL fixes two tiny but troublesome bugs. More trouble in Java-land. Office macros off and back on again. Potential perils of paying ransomware demands.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Chrome quashes another zero-day browser bug. Two big-time cybercrime stories. A 2FA phishing scam that arrived PDQ. Chester swarmed by bots on Twitter.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Memories of the iPhone 1. Sextortion scams target LGBTQ+ daters. Yet another blockchain blunder. OpenSSL fixes the bug missed in the last bugfix. And what became of Little Bobby Tables?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Duck gets behind the Ducks. 2000 phone scammers arrested in Interpol action. A three-year-old hacking case ends in conviction. And a Canadian financial company picks up an enormous data breach fine.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Computer Science in the 1800s. Fixing Follina. AirTag stalking. ID theft site seizure. And the Law of Big Numbers versus SMS scams.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The dawn of the x86 era. The Active Adversary Playbook. A sort-of zero day in Windows. A real-life zero-day in Atlassian Confluence. And the registry settings that could keep you in your job.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Why calling a computer after a famous scientist doesn't always help. The wacky but dangerous 0-day hole in Windows. Supply chain attacks and the crooks who orchestrate them. Smishing revisited. And why saying what you really mean makes you better at cybersecurity.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How network comms caught a murderer back in in 1845. Why the US government said, "Patch, or else!" How Mozilla got a double code-execution bug fixed in 48 hours. And why controversial face-matching company Clearview AI got fined $10m.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
What does the word "non-commensurate" mean? When is cracking passwords legal? Why did Firefox get patched? Which computer needed dropping onto the desk? Why wasn't this 0-day listed in every Apple update? Did Duck get spammed, or was it actually a troll?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Where does the word "radio" come from? RubyGems supply chain rip-and-replace bug. A weird, weird, weird, weird, weird GoogleDocs bug. Colonial Pipeline back in the cybersecurity news. What about built-in password managers?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
World Password Day (we still need it), Github authentication tokens, Firefox hits a ton, and a look back at network worms.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The biggest mountain in tne solar system. New ransomware statistics. Trouble with phishing. Bugs in NAS boxes. A giant security hole in Java. And how to get an industrial grade firewall at home for free.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Adam Osborne or John Osbourne? Another 0-day in Chrome. How not to choose a cybersecurity holiday destination. The Osbo[u]rne Effect. Cryptododginess that might actually be legal. And the Zilog Z80 versus the Mostech 6502.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Hydra darkweb market decapitated. Ruby module supply chain hole. Quantum computing sidestepped. A robot revolution that could result in ransomware. And the Zuckerberg scam that just won't die.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Hacking 2022-style. Some Apple bugs. Some Android bugs. Some Firefox bugs. The SATAN network scanner. Some VMware Spring bugs. And hacking PDP-11 style.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The DEADBOLT ransomware. LAPSUS$ members bust - or were they? Zlib patches a 17-year-old bug. Chrome experiences another weird 0-day. And Clippy. Yes, THAT Clippy. No, we're not sure why.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
LAPSUS$ hackers break into Okta. The CryptoRom money-scamming malware is back on phones. OpenSSL gets into an infinite loop. CafePress fined for covering up a data breach.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Two ransomware suspects extradited for trial. Apple patches 87 known security holes. Happy Pi Day. What happens if a whole country exits the global internet?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
What do ransomware blackmailers ask for when they don't want money? Why did Firefox get two updates in three days? How did Adafruit get hoist by the petard of shadow IT? And what's with those dirty Linux pipes?
REGISTER FOR OUR CYBERINSURANCE EVENT: https://events.sophos.com/cyberinsurance
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How good is Apple's AirTag stalker detection? Why are web coders still making Y2K-like blunders? And how many Instagram scams can you get in one weekend?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
VM escapes could put your host servers at risk. PHP fixes an input validation bug in input validation code. A WordPress plugin maker shows you how to write a decent security report. And French scammers remind us that sextortion is sadly still a thing.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Alleged Bitcoin fraudsters busted, power company in trillion-dollar payout blunder, how a blizzard led to a telecomms revolution, and 0-day after 0-day after 0-day.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Problems with plugins. A Wormhole wormhole. Can machines think? Microsoft has a change of heart. And then another one. Why screen cleaning cloths are cool.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Stealing root on Linux. Snooping on RAM with a video driver bug. Apple patches a zero-day hole. SMS scams promise home PCR machines. German court freaks out over fonts. How to be private. And a paint robot that went wild.
https://nakedsecurity.sophos.com/pwnkit-security-bug-gets-you-root
https://nakedsecurity.sophos.com/linux-kernel-patches-performance-can-be-harmful-bug
https://nakedsecurity.sophos.com/apple-patches-safari-data-leak
https://nakedsecurity.sophos.com/coronavirus-sms-scam-offers-home-pcr
https://nakedsecurity.sophos.com/website-operator-fined-for-using-google-fonts
https://nakedsecurity.sophos.com/happy-data-privacy-day
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Watch out for tax scams. Crooks with the motto "In Fraud We Trust". How not to write a data breach notification. Where to find the "10" key on your telephone.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Russia busts Revil. Romance scammer sent to prison. Wormable Windows hole patched. Memories of the HAPPY99 virus. Linux disk encryption trouble. Apple browsers leak personal data. And how (not) to paint a computer.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
A JavaScript coder sabotages his own projects. Routers with critical holes. Honda cars party like it's 2002. The FTC warns everyone to patch. And a Log4Shell-like bug in another Java library.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Log4Shell - the gift that keeps on taking. Scammers threatening your social media accounts. Apple Home has a pecuu[...]uuliar bug. And why 2FA is easier than you think.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Understanding Log4Shell. Fixing Log4Shell. What criminals are up to with Log4Shell. Apple's latest security fixes. And what (not to) do when your mouse gets stuck.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Mozilla's "BigSig" buffer overflow hole. UK to put IoT vendors on notice. The Mother of All Demos. Cryptocurrency company catastrophe. Firefox gets an extra sandbox. And an access point from outer space (OK, from home).
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Call scammers and cryptocoin treachery. Cloud insecurity and yet more cryptocoin treachery. Facial recognition creepiness. And the wannabe wizard that went to school with a trainee Sith.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Cybersecurity tips for the holiday season and beyond. Exchange at risk from public exploit. GoDaddy loses passwords for 1.2m users. Longest-lived Windows version ever. Don't make your cookies public. And the day that umbrellas became an anti-DDoS tool.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The infamous Emotet malware makes a comeback. Crooks smirk at the world with a fake FBI warning. Why tubes are also valves. Samba fixes an intriguing bug. The suitcase that needs no handle. And a virtual-versus-real monitor mixup.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We enjoy the Sophos 2022 Threat Report. The world's {oldest, coolest} continously maintained browser. Facebook folds up its Face Recognition feature. Crooks combine a new social engineering scam with a new way of packaging malware. Kaseya ransomware suspect busted in Poland. Oh! No! How to block radio communications in a land with no hills.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Norbert (huzzah for Norbert!) does tech support. Europol digs into the ransomware scene. Microsoft finds a wacky bug in Apple's shell. The Morris worm turns 33. Edge on Linux phans the phlames. Ola! Gibberish peculiarity textual solvage.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Bliss is a hill in wine country. Lessons from a cryptotrading hamster. Ransomware gang hacked back. Docusign phishers go after 2FA codes. Sleep mode considered harmful.
Original music by Edith Mudge
Got something to share? Email tips@sophos.com
Special minisode! Michelle Farenci knows her stuff, because she's a cybersecurity practitioner inside a cybersecurity company. Learn why thinking like an attacker makes you a better defender.
Full transcript: https://nakedsecurity.sophos.com/listen-up-4-cybersecurity-first-purple-teaming
Special minisode! Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance.
Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-cyberinsurance
Special minisode! Chester Wisniewski, Principal Research Scientist at Sophos, gives you useful and actionable advice to reduce the risk of supply chain attacks.
Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-supply-chain-attacks
Special Minisode for #Cybermonth! Fraser Howard, Director of Threat Research at Sophos, talks about malware and how to fight it. Fraser's breadth and depth of knowledge in the threat-fighting field is second to none.
Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-week4
Hook up with our forthcoming Live Malware Demo presentation. Why we think you should celebrate Global Encryption Day. A whole new twist on bogus online "friendships". How to stop your network cables giving you away. And why superglue is NOT a cybersecurity tool!
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Apple (you guessed it!) fixes yet another iPhone 0-day. Apache patches an embarrassing bug and then has to patch the patch. It's Fight The Phish week. The user who got punched right in the nose by a recalcitrant computer.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Apple Pay gets hacked (sort of). DOJ busts four gift card scamming suspects. We give you our top tips for #Cybermonth. Ukrainian Cyberpolice take on ransomware crooks. Oh! No! The user that volunteered to RTFM!?
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Let's Encrypt brings HTTPS to everyone. Researchers rediscover an Outlook data leakage issue. VMware keeps it real. And when the mouse is away, the cat will play.
With Paul Ducklin and Doug Aamoth.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
A scarily exploitable hole in Microsoft open source code. A simpler take on delivery scams. A Face ID bypass hack, patched for the initial release of iOS 15. And how not to get locked in a cabling closet.
Coder? Use Sophos Intelix yourself for free: https://sophos.com/intelix
With Paul Ducklin and Doug Aamoth.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Apple patches two zero-day bugs. Microsoft patches one zero-day bug. A security researcher finds a fast-food bug (non-insect sort). And a touchpad user turns right into left, and vice versa.
(See also: Big Office bug squashed for September 2021 Patch Tuesday)
With Paul Ducklin and Doug Aamoth.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Overlooked security flaw leaves web code vulnerable. A home alarm system that almost anyone can turn off. Some fascinating Firefox bugs fixed. And when you grab your laptop... but it's not yours.
With Paul Ducklin and Doug Aamoth.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Security code flushes out security bugs. Recursion: see recursion. Phishing (and lots of it). And the Windows desktop that got so big it imploded.
With Paul Ducklin and Doug Aamoth.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
More money troubles in cryptotown. Trouble with plastic spaghetti. The mouse that conquered Windows. And the embarrassment when you report one of your very own emails as a phish.
With Paul Ducklin and Doug Aamoth.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Copyright infringement scams that beg you to call. An IoT bug that could be exploited for video snooping and more. A hacker steals $600m and then makes a song and dance out of giving it back. And how Doug's PS5 issues could be solved at last.
With Paul Ducklin and Chester Wisniewski.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Home and small business routers under attack. A hacking tool favoured by crooks gets hacked. The Navajo Nation's selfless cryptographic contribution to America. A cybercrook gets aggrieved at being ripped off by cybercrooks.
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The latent 0-day that didn't get reported until it was too late. Retro computing: reliving the TRS-80. Crooks that help you install their malware. And a 5-minute billionaire (who ended up with $400).
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Apple's emergency 0-day fix. Two sorts of Windows nightmare, neither involving printers. Twitter hacker busted. And our very own Doug ruins a brand new TV.
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Learning from computer virus history. The PrintNightmare saga continues. Apple puts out a patch, but doesn't say why. Snitch on a crook and earn $10 million. Scammers do grammar. And the Business Email Compromise that wasn't.
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We explain how a format string bug could lock your iPhone out of your own network. We revisit the PrintNightmare saga, which is sort-of fixed but not really. We look back at the 20-year-old Code Red virus. We look at what cybercriminals spend money on (hint: more cybercrime). And in this week's "Oh! No!", we learn how farm animals can disrupt your network.
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The "Independence Day Weekend" ransomware drama. The PrintNightmare nightmare continues. An email hacker gets his conviction overturned. In this week's Oh! No! story, a server room fills with toxic fumes...
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
In this special splintersode, Kimberly Truong talks to Eva Galperin, Director of Security at the Electronic Frontier Foundation.
Eva's TED talk mentioned in the podcast: What you need to know about Stalkerware.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
When you spend tens of pounds but get billed thousands because the system mistook the date for the amount. Our tips to make #SocialMediaDay your safest day on social media yet. And a clip from a great new privacy splintersode we'll be airing next week.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Ukrainian cops bring out the BFG (Big Fearsome Grinder) and cut open some doors. A repeated request for destructive Linux code enters its 15th year. Peloton exercise bicycles found to be rootable.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Will quantum cryptography mean the end of encryption? How was the FBI able to get bitcoins back in the Colonial Pipeline ransomware case? What is the ALPACA attack, and does it make your browsing less secure?
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Alleged malware coder from the Trickbot gang arrested. 5500 passwords cracked and salaries stolen by "credential stuffing" crook. And we answer a listener's question about just how tough to be when judging a company that's had a breach.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The fascinating tale of a bug that's baked into Apple's latest chip. Why the Aussie data breach warning site HIBP is partnering with the FBI. And a coronavirus tracking toolkit that fell foul of privacy rules.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Apple patches a raft of serious security holes. Police arrest eight suspects in an online scamming ring. We explain how WhatsApp messages from hacked accounts are helping cybercrooks bypass 2FA.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We look into an unnerving case of mixed-up video feeds. We warn you against "going rogue" when you can't get the download you want from the regular place. We explain how Apple's new AirTag product got hacked (again).
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Apple's brand new AirTag product got hacked already. Things you can learn from Colonial Pipeline's ransomware misfortune. Why Dell patched a bunch of driver bugs going back more than a decade. And the "Is it you in the video?" scam just keeps on coming back.
Additional links you will find useful:
https://news.sophos.com/en-us/using-sophos-edr-to-identify-endpoints-impacted-by-dell
https://nakedsecurity.sophos.com/ransomware-dont-expect-a-full-recovery
https://www.sophos.com/ransomware
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We look into Apple's recent emergency updates that closed off four in-the-wild browser bugs. We explain how the infamous "Flubot" home delivery scam works and how to stop it. We investigate a recent security bug that threatened the PHP ecosystem.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We investigate whether AirDrop is really as dangerous as researchers claimed. We discuss the pestiferous problem of fake Linux bugs submitted as an academic exercise. We review the latest Sophos Ransomware Report and uncover uncomfortable truths about paying up.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How Firefox showed the hand to a widely abused online tracking trick. Why reading from one part of your computer's memory can paradoxically (and sneakily) let you write to another part. And yet more IoT bugs, this time a whole slew of them that go by the moniker "name:wreck".
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Sophos cybersecurity expert Chester Wisniewski provides excellent, topical and timely commentary on the FBI’s recent use of a malware-like method to forcibly clean up hundreds of servers still infected in the Hafnium aftermath.
With Paul Ducklin and Chester Wisniewski
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We look at the big-money hacks from the 2021 Pwn2Own competition. We investigate the difficulties of hiring an assassin via the dark web. We wrestle with some of the privacy issues relating to COVID-19 infection tracking apps.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How scammers copied a government website almost to perfection. What to do about those fake "bug" hunters who ask for payment for finding "vulnerabilities" that aren't. Why the Dutch data protection authority fined Booking.com for not sending in a data breach disclosure fast enough.
Useful podcasts and videos mentioned in this episode:
https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac
https://nakedsecurity.sophos.com/s3-ep8-a-conversation-with-katie-moussouris
https://nakedsecurity.sophos.com/what-should-you-say-if-you-have-a-data-breach
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Why Apple had to rush out a security update for iDevices. Two cryptographic security holes patched in OpenSSL. How PHP nearly got backdoored by crooks.
With Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How a social engineer ripped off a victim lured in by one of those "small outstanding fee to pay" home delivery scams. The ransomware crooks targeting networks that still haven’t done their Hafnium patches. And the Linux kernel security holes that lay there undiscovered for 15 years.
Related articles that we refer to in the show:
https://nakedsecurity.sophos.com/beware-the-dhl-delivery-message
https://nakedsecurity.sophos.com/watch-out-scummy-scammers
https://nakedsecurity.sophos.com/s3-ep12-a-chat-with-social-engineering-hacker-rachel-tobac
https://nakedsecurity.sophos.com/blackkingdom-ransomware
https://nakedsecurity.sophos.com/serious-security-webshells-explained
https://nakedsecurity.sophos.com/naked-security-live-hafnium-explained
https://nakedsecurity.sophos.com/serious-security-the-linux-kernel-bugs
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We discuss an iPhone app that allowed anyone to snoop on anyone's calls - but not in the way you might expect. We investigate a data breach where 150,000 surveillance cameras protecting hundreds or thousands of customers were apparently "secured" by a single password... that got leaked onto the internet. And we urge you as keenly as we can: "Don't spread hoaxes, folkses."
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
John Noble was Director of Incident Management at the UK's National Cyber Security Centre (NCSC) until his retirement in 2018. During his 40 years of Government service, John specialised in operational delivery and strategic business change. For his work in creating effective partnerships in the run up to the London Olympics, he was made a Commander of the British Empire (CBE) in 2012.
John helped to establish the NCSC and led the response to nearly 800 significant cyberincidents. This work has given him unrivalled experience in dealing with and understanding the causes of cyberattacks.
John is currently a non-executive director at NHS Digital, where he chairs the Information Assurance and Cyber Security Committee. NHS Digital is the national information and technology partner to the health and social care system in England.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Getting to grips with the HAFNIUM gang/vulnerabilities/exploits/webshells/attacks. Why it's important to think before you share those home-based selfies. What you need to know about social engineering. How (not!) to prove a point when you're a programmer.
With Kimberly Truong and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How to stop security-conscious apps from allowing unencrypted data to escape, and how scammers put social network users under pressure in order to steal their passwords.
With Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
The graphics card that wants you to stick to playing games, the man that didn't weigh 100 tons after all, and the marketing gang that used a browser bug to bombard iPhone users with scammy online surveys.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How a bug hunter snuck into the internal networks of 35 megacorporations. Why romance scams are going stronger than ever (and how to avoid them). What to do about those tempting but treacherous "tax refund" messages. And a listener tells us how he got a bit carried away while he was gardening...
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
In this special mini-episode, Paul Ducklin talks to Sophos cybersecurity expert Chester Wisniewski about bug bounty hunting.
How does bug bounty hunting work? What should you do if you get a bug report that doesn't follow established protocol? Chester tells you how to deal with so-called "beg bounties", where self-styled "experts" beg you for money or even threaten you with ill-defined "problems" they claim to have found.
https://news.sophos.com/en-us/have-a-domain-name-beg-bounty-hunters-may-be-on-their-way
https://nakedsecurity.sophos.com/beware-of-technical-experts-bombarding-you-with-bug-reports
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We delve into Google's tight-lipped Chrome bugfix, explain how a Belgian researcher awarded himself 111,848 cups of coffee, and discuss the audacious but thankfully temporary theft of the Perl.com domain.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Apple pushed out an iOS update in a hurry to shut down a serious 0-day bug. The GnuPG team scrambled to fix an ironic vulnerability that could be exploited during the very process of checking if the data you just received could be trusted. And Europol reported on a successful takedown operation against the notorious Emotet malware.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
What's the connection between coronavirus facemasks and fingerprint biometrics? Who would have expected funky job ads on the White House website? And what would you do if you ran into a deceased former colleague on your network?
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Anonymous and private, yet busted! We explain how darkweb sites sometimes keep your secrets... and sometimes don't. We help you improve your cybersecurity at home. And we tell you the tale of a company with the coolest name but allegedly with the creepiest habits coded into its browser extensions.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Thanks to coronavirus lockdown rules in the UK, and the temporary closure of all schools, Sally Adam suddenly found herself responsible for cybersecurity where it mattered more than ever: on a home network that jointly served for home, work and school.
Paul Ducklin talks to Sally about how she did it, and how to keep your own family’s digital life safe.
https://nakedsecurity.sophos.com/home-schooling-how-to-stay-secure
https://nakedsecurity.sophos.com/home-wi-fi-security-tips
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We explain how two French researchers hacked a Google Titan security key (but why you don't need to panic), and dig into the Mimecast certificate compromise story to see what we can all learn from it.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We advise you how to react when a friend suddenly asks for money, explain why Chromium is finally aiming for HTTPS by default, and warn you why you should never, ever hardcode passwords into your software.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How did the movie "Hackers" inspire a girl to grow up to become a hacker herself? Find out from security analyst, friendly hacker and TED Talk speaker Keren Elazari. Hear about Keren’s incredible journey, why hackers should be welcomed with open arms, and the inspiration that guided her career.
With Kimberly Truong and special guest Keren Elazari (@k3r3n3 on Twitter), cybersecurity analyst and researcher.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How do you go from neuroscientist to DEFCON Social Engineering Capture the Flag champ? Find out from hacker and social engineering expert Rachel Tobac. Join us for a fascinating interview with Rachel about her journey, why you should always be “politely paranoid”, and the people who inspired her along the way.
With Kimberly Truong and special guest Rachel Tobac (@RachelTobac on Twitter), hacker and CEO of SocialProof Security.
Book mentioned by Rachel: The 6 principles of persuasion by Robert Cialdini.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We look at phishing tricks that really work, investigate a bizarre scam involving Subway sandwiches, and ask whether cybercriminals have lost their interest in the rest of us now they have coronavirus-related targets to go after.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
https://nakedsecurity.sophos.com/phishing-tricks-that-really-work
https://nakedsecurity.sophos.com/subway-sandwich-scam-mystifies
https://nakedsecurity.sophos.com/was-there-a-covid-19-vaccine-hack
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Naked Security's Paul Ducklin interviews Sophos expert John Shier about his recently published paper, "20 years of cyberthreats that shaped information security."
Join John on a dizzying journey all the way from legendary viruses such as ILOVEYOU and Code Red, which flooded the internet in 2000, to present-day ransomware gangs like Ryuk and REvil, who are extorting millions of dollars in blackmail money per attack.
https://news.sophos.com/20-years-of-cyberthreats
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We dig into research that figured out a way to steal data from iPhones wirelessly, we tell the fascinating story of how environmentalist divers in Germany came across an old Enigma cipher machine at the bottom of the Baltic sea, and we give you advice on how to talk to phone scammers.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
https://nakedsecurity.sophos.com/how-to-steal-photos-off-someones-iphone
https://nakedsecurity.sophos.com/german-divers-find-enigma-crypto-machine
https://nakedsecurity.sophos.com/vishing-criminals-let-rip-with-two-scams
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
We look at a network intrusion where the crooks tried to take over dozens of different online accounts from every user, we discuss the potential dangers of digital doorbells, and we give you some handy hints for improving your wireless security at home.
With Kimberly Truong, Doug Aamoth and Paul Ducklin.
https://nakedsecurity.sophos.com/gift-card-hack-exposed-you-pay-they-play
https://nakedsecurity.sophos.com/bzzzzzzt-how-safe-is-that-keenly-priced-digital-doorbell
https://nakedsecurity.sophos.com/home-wi-fi-security-tips-5-things-to-check
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
How do you go from pentester to creator of Microsoft’s bug bounty program? Find out from hacker and vulnerability disclosure pioneer, Katie Moussouris. Join us for a fascinating interview with Katie about her journey, the bugs in bug bounty programs, and the people who inspired her along the way.
With Kimberly Truong and special guest Katie Moussouris (@k8em0 on Twitter), Founder and CEO of Luta Security.
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
In this episode: we say thanks to companies that refuse to pay ransomware hush money, dig into the new Sophos 2021 Threat Report, and take a quick look inside a malicious Linux kernel driver. Also, a sneak preview of our upcoming podcast interview with bug bounty pioneer Katie Moussouris.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Cult videogame company Capcom pays a big round $0.00 to ransomware crooks https://nakedsecurity.sophos.com/cult-videogame-company-capcom-pays-a-big-round-0
The Sophos Threat Report 2021 https://nakedsecurity.sophos.com/sophos-threat-report-2021
The Cloud Snooper Malware https://nakedsecurity.sophos.com/the-cloud-snooper-malware
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
In this episode: When payments go astray, why "just in case" cybersecurity warnings do more harm than good, how to shop safely on Black Friday and beyond, and (oh no!) what to do when all your emails disappear.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
To register for the Sophos Evolve event: https://sophos.com/evolve
Smishing attack tells you “mobile payment problem” – don’t fall for it https://nakedsecurity.sophos.com/smishing-attack-tells-you-mobile-payment-problem
“Instant bank fraud” hoax is back – don’t spread fake news https://nakedsecurity.sophos.com/instant-bank-fraud-hoax-is-back-dont-spread-fake-news
Black Friday – stay safe before, during and after peak retail season https://nakedsecurity.sophos.com/black-friday-stay-safe-before-during-and-after
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
In this episode: a zero-day bug in Chrome for Android, the imminent death of Adobe Flash, the evolution of "malware-as-a-service", and the malware risks from image search. Also (oh! no!), why you should take care before you pair.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
https://nakedsecurity.sophos.com/another-chrome-zero-day-this-time-on-android
https://nakedsecurity.sophos.com/adobe-flash-its-the-end-of-the-end-of-the-end
https://nakedsecurity.sophos.com/buer-loader-malware-as-a-service-joins-emotet
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
On Wednesday, the FBI, CISA and HHS released an unprecedented warning against "an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers." In this quick mini-sode, Chester Wisniewski (Principal Research Scientist at Sophos) discusses what the threat is, what this advisory means, and why this warning is a warning for everyone.
With Kimberly Truong and special guest, Chester Wisniewski @chetwisniewski
RESOURCES:
Read the article from Naked Security https://nakedsecurity.sophos.com/2020/10/29/fbi-ransomware-warning-for-healthcare-is-a-warning-for-everyone/
Get tools and guidance to protect your organization https://www.sophos.com/en-us/content/healthcare-targeted-ransomware.aspx
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
This week: Facebook scammers trick you with fake copyright notices, voice scammers automate their attacks on the vulnerable, how to tune up your mobile privacy, and (oh! no!) the best/worst IT helpdesk call ever.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Facebook “copyright violation” tries to get past 2FA – don’t fall for it https://nakedsecurity.sophos.com/facebook-copyright-violation-tries-to-get-past-2fa
Phone scamming – friends don’t let friends get vished https://nakedsecurity.sophos.com/phone-scamming-friends-dont-let-friends-get-vished
Time for a mobile privacy reset? https://nakedsecurity.sophos.com/time-for-a-mobile-privacy-reset
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
This week: the DOJ's attempt to reignite the Battle to Break Encryption; the story of the Russian hackers behind the Sandworm Team; a zero-day bug just patched in Chrome; and (oh no!) why your vocabulary needs the word "restore" even more than it needs "backup".
With Kimberly Truong, Doug Aamoth and Paul Ducklin
US Department of Justice reignites the Battle to Break Encryption https://nakedsecurity.sophos.com/us-department-of-justice-reignites
Russian “government hackers” charged with cybercrimes by the US https://nakedsecurity.sophos.com/russian-government-hackers-charged
Chrome zero-day in the wild – patch now! https://nakedsecurity.sophos.com/chrome-zero-day-in-the-wild
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
In this episode: we investigate a smartwatch for kids with a creepy set of functions, discuss Microsoft's short-lived takedown of Trickbot, explain how to avoid the Windows "Ping of Death" bug, and (oh no!) find the source of mysterious beeping from every computer in the office.
With Kimberly Truong, Doug Aamoth and Paul Ducklin
Creepy covert camera “feature” found in popular smartwatch for kids https://nakedsecurity.sophos.com/creepy-covert-camera-feature-found
Microsoft on the counterattack! Trickbot malware network takes a hit https://nakedsecurity.sophos.com/microsoft-on-the-counterattack-trickbot
Windows' "Ping of Death" bug revealed https://nakedsecurity.sophos.com/windows-ping-of-death-bug
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
Join us for the first episode in our brand new Series 3! This week we wonder whether Cybersecurity Awareness Month is a waste of time, explain the concept of "linkless phishing", ask if it's ever OK to pay a ransomware demand, and advise what to do when the CEO won't stop looking at naughty sites.
With Paul Ducklin, Kimberly Truong and Doug Aamoth
Tips for National Cybersecurity Awareness Month https://nakedsecurity.sophos.com/if-you-connect-it-protect-it
Phishing without links https://nakedsecurity.sophos.com/serious-security-phishing-without-links
REvil ransomware crew dangles $1M cybercrime carrot https://nakedsecurity.sophos.com/revil-ransomware-crew-dangles-1000000-cybercrime-carrot
Original music by Edith Mudge
Got questions/suggestions/stories to share?
Email tips@sophos.com
Twitter @NakedSecurity
Instagram @NakedSecurity
END OF SERIES SPECIAL: This week Mark shares why Pablo Escobar’s brother is suing Apple for $2.6b, Greg talks about a malicious ‘Octopus Scanner’ targeting developers on Github and Duck discusses the “Sign in with Apple” account takeover flaw.
Host Anna Brading is joined by Sophos experts Paul Ducklin, Mark Stockley and Greg Iddon.
Related articles: Github uncovers malicious ‘Octopus Scanner’ targeting developers https://nakedsecurity.sophos.com/2020/06/01/github-uncovers-malicious-scanner-targeting-developers/ No password required! “Sign in with Apple” account takeover flaw patched https://nakedsecurity.sophos.com/2020/06/01/no-password-required-sign-in-with-apple-account-takeover-flaw-patched/ Pablo Escobar’s brother sues Apple for $2.6b over FaceTime flaw https://nakedsecurity.sophos.com/2020/05/28/pablo-escobars-brother-sues-apple-for-2-6b-over-facetime-flaw/
This week Peter shares how Ragnar Locker ransomware deploys a virtual machine to dodge security, Mark discusses the latest in the Apple v FBI saga and Duck talks "MagicPairing."
Producer Alice Duckett is joined by Sophos experts Mark Stockley, Paul Ducklin and Peter Mackenzie.
Listen now!
Related articles: Signal secure messaging can now identify you without a phone number https://nakedsecurity.sophos.com/2020/05/22/signal-secure-messaging-can-now-identify-you-without-a-phone-number/ Apple and Google launch COVID-19 contact tracing API https://nakedsecurity.sophos.com/2020/05/22/apple-and-google-launch-covid-19-contact-tracing-api/ VIDEO: What is the dark web? https://www.youtube.com/watch?v=9F3rz7GfPys&t=52s Ragnar Locker ransomware deploys virtual machine to dodge security https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/ FBI finally unlock shooter’s iPhones, Apple berated for not helping https://nakedsecurity.sophos.com/2020/05/20/fbi-finally-unlock-shooters-iphones-berate-apple-for-not-helping/ Apple “MagicPairing” for AirPods – the magic isn’t perfect yet https://nakedsecurity.sophos.com/2020/05/19/apple-magicpairing-for-airpods-the-magic-isnt-perfect-yet/
This week we discuss a customer who went to Subway for a sandwich and left with a stalker, demon printers and the things you should patch now.
Producer Alice Duckett is joined by Sophos experts Mark Stockley, Paul Ducklin and Greg Iddon.
Related articles: Beware the DHL delivery message email – it could be a package scam https://nakedsecurity.sophos.com/2020/05/13/beware-the-dhl-delivery-message-email-it-could-be-a-package-scam/ Microsoft joins encrypted DNS club with Windows 10 option https://nakedsecurity.sophos.com/2020/05/15/microsoft-joins-encrypted-dns-club-with-windows-10-option/ Criminal forum trading stolen data suffers ironic data breach https://nakedsecurity.sophos.com/2020/05/13/criminal-forum-trading-stolen-data-suffers-ironic-data-breach/ Woman stalked by sandwich server via her COVID-19 contact tracing info https://nakedsecurity.sophos.com/2020/05/14/woman-stalked-by-sandwich-server-via-her-covid-19-contact-tracing-info/ PrintDemon – patch this ancient Windows printer bug! https://nakedsecurity.sophos.com/2020/05/14/printdemon-patch-this-ancient-windows-printer-bug/ Top 10 most exploited vulnerabilities list released by FBI, DHS CISA https://nakedsecurity.sophos.com/2020/05/15/top-10-most-exploited-vulnerabilities-list-released-by-fbi-dhs-cisa/
In this episode Mark discusses government encryption, Duck tells us why turning your computer off is a cool idea and Greg regales us with his reply all woes.
Host Anna Brading is joined by Sophos experts Mark Stockley, Paul Ducklin, Greg Iddon and Producer Alice Duckett.
Related articles:
Clearview AI won’t sell vast faceprint collection to private companies https://nakedsecurity.sophos.com/2020/05/11/clearview-ai-wont-sell-vast-faceprint-collection-to-private-companies/ Celebrity personal data taken in ransomware attack https://nakedsecurity.sophos.com/2020/05/11/celebrity-personal-data-taken-in-ransomware-attack/ Reveal the identities of alleged pirates, court tells ISP https://nakedsecurity.sophos.com/2020/05/05/reveal-the-identities-of-alleged-pirates-court-tells-isp/ Maze ransomware: extorting victims for 1 year and counting https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/ Thunderspy – why turning your computer off is a cool idea! https://nakedsecurity.sophos.com/2020/05/12/thunderspy-why-turning-your-computer-off-is-a-cool-idea/
In this episode Duck discusses the iPhone "word of death", Peter shares a shocking ransomware story and Alice talks about a chatbot that shows empathy. Or so it says.
Host Anna Brading is joined by Naked Security regular Paul Ducklin, Threat Response expert Peter Mackenzie and Producer Alice Duckett.
Related articles: https://nakedsecurity.sophos.com/godaddy-unauthorized-individual-had-access-to-login-info https://nakedsecurity.sophos.com/adult-live-streaming-site-cam4-leaks-millions-of-emails-private-chats https://nakedsecurity.sophos.com/coronavirus-pandemic-coincides-with-spike-in-online-puppy-scams https://nakedsecurity.sophos.com/iphone-word-of-death-could-crash-your-phone-what-you-need-to-know
This week we talk ransomware apologies, whether companies should be pushing 2FA and good vibrations, kind of...
We're proud to be nominated for Best Cybersecurity Podcast in the European Cybersecurity Blogger Awards. If you enjoy our show, please vote for us: https://docs.google.com/forms/d/e/1FAIpQLSe8AkYMfAAwJ4JZzYRm8GfsJCDON8q83C9_wu5u10sNAt_CcA/viewform?fbzx=1378805297375984251
Host Anna Brading is joined by Sophos experts Mark Stockley, Paul Ducklin and Producer Alice Duckett.
Listen now!
Further reading: https://nakedsecurity.sophos.com/evil-gif-account-takeover-flaw-patched-in-teams https://nakedsecurity.sophos.com/warning-fake-zoom-hr-meeting-emails-phish-for-your-password https://nakedsecurity.sophos.com/patch-now-microsoft-issues-unexpected-office-fix https://nakedsecurity.sophos.com/fan-vibrations-can-be-used-transmit-data-from-air-gapped-machines
This week we discuss 49 rogue Chrome extensions, Signal fears over the EARN IT Act and how Darth Vader sent someone viral for all the wrong reasons.
Host Anna Brading is joined by Sophos experts Paul Ducklin, Mark Stockley and Producer Alice Duckett.
Listen now!
First three stories: https://nakedsecurity.sophos.com/critical-bug-in-google-chrome-get-your-update-now https://nakedsecurity.sophos.com/new-sextortion-scam-high-level-of-risk-your-account-has-been-hacked https://nakedsecurity.sophos.com/tiktok-announces-family-pairing-bust-your-moves-but-cap-the-risk
Main topics: https://nakedsecurity.sophos.com/49-malicious-chrome-extensions-caught-pickpocketing-crypto-wallets https://nakedsecurity.sophos.com/signal-well-be-eaten-alive-by-earn-it-acts-anti-encryption-wolves https://nakedsecurity.sophos.com/creep-shamed-on-facebook-was-actually-man-taking-selfie-with-darth-vader
Mentioned in the episode: https://nakedsecurity.sophos.com/the-talking-angela-witch-hunt-what-on-earth-is-going-on https://nakedsecurity.sophos.com/no-houseparty-hasnt-hacked-your-phone-and-stolen-your-bank-details
This week we discuss a TikTok flaw, why sextortion scammers are rearing their heads again and whether single sign-on is better than having loads of different passwords.
Host Anna Brading is joined by Sophos experts Mark Stockey, Paul Ducklin and Producer Alice Duckett.
Listen now!
Related articles:
https://nakedsecurity.sophos.com/tiktok-users-beware-hackers-could-swap-your-videos-with-their-own https://nakedsecurity.sophos.com/sextortion-emails-and-porn-scams-are-back-dont-let-them-scare-you
Find out Mark's new method of authentication by listening to last week's episode: https://soundcloud.com/sophossecurity/s2-ep34-can-you-trust-hackers-on-how-not-to-get-hacked
Duck's anti-sextortion video to share with your friends and family: https://www.youtube.com/watch?v=veY0WzoubQw
This week we discuss the hackers' forum that got hacked (lol), how the coronavirus pandemic has deferred a security update, and why jumping to conclusions is always a bad idea.
Oh, and we came across plans for a toilet that identifies you by scanning your, errrm... you'll have to listen to find out.
Listen now!
Related stories: https://nakedsecurity.sophos.com/hackers-forum-hacked-ogusers-database-dumped-again https://nakedsecurity.sophos.com/covid-19-forces-browser-makers-to-continue-supporting-tls-1-0 https://nakedsecurity.sophos.com/no-houseparty-hasnt-hacked-your-phone-and-stolen-your-bank-details https://nakedsecurity.sophos.com/as-if-the-world-couldnt-get-any-weirder-this-ai-toilet-scans-your-anus-to-identify-you/
This week we bring you the podcast from our makeshift home studios (pillow forts). We discuss Dharma ransomware, the tour guide who turned out to be a Chinese spy, and why thousands of dark web sites have disappeared.
Host Anna Brading is joined by Sophos experts Mark Stockley, Greg Iddon, Peter Mackenzie and Producer Alice Duckett.
Listen now!
Related articles: https://nakedsecurity.sophos.com/dharma-ransomware-source-code-on-sale-for-2000 https://nakedsecurity.sophos.com/tour-guide-chinese-spy-gets-four-years-for-sd-card-dead-drops https://nakedsecurity.sophos.com/thousands-of-dark-web-sites-deleted-in-attack-on-free-hosting-service
In this episode, Greg looks at why the WhatsApp Martinelli hoax has come back in a big way, Duck decompiles some coronavirus-themed Android malware, and Anna tells you what ZoomBombing is and why you really, really need to get the security settings right on your Zoom meetings.
Join host Anna Brading with Sophos experts Paul Ducklin and Greg Iddon.
Listen now!
Related articles: https://nakedsecurity.sophos.com/whatsapp-martinelli-hoax-is-back-warning-about-dance-of-the-pope https://nakedsecurity.sophos.com/android-malware-uses-coronavirus-for-sextortion-ransomware-combo https://nakedsecurity.sophos.com/trolls-zoombomb-work-from-home-videocall-with-filth
This week, Duck advises how to keep your company safe while working remotely, Peter discusses a malwareless ransomware attack, and Mark shares the latest in the EARN IT saga.
Host Anna Brading is joined by Sophos experts Paul Ducklin, Peter Mackenzie and Mark Stockley.
Listen now!
Links for you: https://nakedsecurity.sophos.com/earn-it-act-threatens-end-to-end-encryption https://nakedsecurity.sophos.com/5-tips-for-working-safely-from-home
This week we talk about why Let's Encrypt might have to celebrate its billionth certificate twice, wonder if James Bond could hack Siri with ultrasound and make backups surprisingly interesting.
Host Mark Stockley is joined by Sophos experts Greg 'Fido' Iddon and Peter Mackenzie.
Related articles: Let's Encrypt: https://nakedsecurity.sophos.com/2020/03/02/lets-encrypt-issues-one-billionth-free-certificate/ https://nakedsecurity.sophos.com/2020/03/04/why-3-million-lets-encrypt-certificates-are-being-killed-off-today/
SurfingAttack: https://nakedsecurity.sophos.com/2020/03/02/siri-and-google-assistant-hacked-in-new-ultrasonic-attack/
Ransomware in your backups https://www.bleepingcomputer.com/news/security/ransomware-attackers-use-your-cloud-backups-against-you/
To celebrate International Women's Day we invite you to this all-female splinter episode. We discuss privacy, biometrics, machine learning, social media, getting into cybersecurity and of course, what it's like to be a woman in tech.
Host Anna Brading is joined by Sophos experts Hillary Sanders, Michelle Farenci and Alice Duckett.
Listen now!
You can get Hillary's book here: https://www.amazon.com/Malware-Data-Science-Detection-Attribution/dp/1593278594 Malware Data Science: Attack Detection and Attribution
This week we discuss the latest in the Clearview AI debacle, get more tales from the ransomware swamp and discover how often our smart speakers are listening to us.
Host Anna Brading is joined by Sophos experts Alice Duckett, Paul Ducklin and Peter Mackenzie.
Related articles: Facial recognition and Clearview: https://nakedsecurity.sophos.com/clearview-ai-loses-entire-database-of-faceprint-buying-clients-to-hackers https://nakedsecurity.sophos.com/facebook-google-youtube-order-clearview-to-stop-scraping-faceprints
Malware madness: https://nakedsecurity.sophos.com/revil-ransomware-exploiting-vpn-flaws-made-public-last-april https://nakedsecurity.sophos.com/gandcrab-ransomware-revisited-is-it-back-under-a-revil-new-guise
Smart speakers: https://nakedsecurity.sophos.com/smart-speakers-mistakenly-eavesdrop-up-to-19-times-a-day
This week we discuss the stalkerware app that spilled bucketloads of ultrapersonal data, a double-whammy ransomware attack on a homeless charity, and an Amazon Prime phishing attack with a skull-and-crossbones twist.
Producer Alice Duckett hosts the show with Sophos experts Paul Ducklin, Greg Iddon and Peter Mackenzie.
Related articles: https://nakedsecurity.sophos.com/2020/02/24/kidsguard-stalkerware-leaks-data-on-secretly-surveilled-victims/ https://nakedsecurity.sophos.com/2020/02/21/the-amazon-prime-phishing-attack-that-wasnt/
This week we discuss why Google abruptly pulled over 500 Chrome extensions from its Web Store, the case of a man held in custody for refusing to decrypt two hard drives and research detailing a number of security holes in Bluetooth chips from several different vendors.
Greg Iddon plays host and Producer this week and is joined by fellow Sophos experts Paul Ducklin and Peter Mackenzie.
Listen now!
Related articles:
Google pulls 500 malicious Chrome extensions after researcher tip-off: https://nakedsecurity.sophos.com/2020/02/17/google-pulls-500-malicious-chrome-extensions-after-researcher-tip-off/
Suspect who refused to decrypt hard drives released after four years: https://nakedsecurity.sophos.com/2020/02/17/google-pulls-500-malicious-chrome-extensions-after-researcher-tip-off/
Bluetooth bugs – researchers find 10 “Sweyntooth” security holes: https://nakedsecurity.sophos.com/2020/02/14/bluetooth-bugs-researchers-find-10-sweyntooth-security-holes/
This week we welcome back Peter who discusses RobbinHood - the ransomware that brings its own bug. Greg explains how a student's Twitter account was handed over to their college and Duck talks SMS 2FA.
Host Anna Brading is joined by Sophos experts Peter Mackenzie, Paul Ducklin and Greg Iddon.
Listen now!
Related articles: RobbinHood – the ransomware that brings its own bug: https://nakedsecurity.sophos.com/2020/02/07/robbin-hood-the-ransomware-that-brings-its-own-bug/ Living off another land: Ransomware borrows vulnerable driver to remove security software: https://news.sophos.com/en-us/2020/02/06/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software/ Apple proposes simple security upgrade for SMS 2FA codes: https://nakedsecurity.sophos.com/2020/02/03/apple-proposes-simple-security-upgrade-for-sms-2fa-codes/ Twitter hands over student’s account to his college: https://nakedsecurity.sophos.com/2020/02/04/twitter-gave-access-to-students-account-to-his-college/ Peter's ransomware list (tweet): https://twitter.com/AltShiftPrtScn/status/1225715096124567557 Joshua Saxe AI malware detector (tweet): https://twitter.com/joshua_saxe/status/1225521199800864769 Security ML models encoded as Yara rules: https://github.com/sophos-ai/yaraml_rules
Over the past couple of years, Sophos' Director of Security Craig Jones has discovered a worrying amount of personal data on public Trello boards. Mark says companies shouldn’t microchip their employees and Duck discusses a bug that could have blown a hole in OpenSMTPD.
Host Anna Brading is joined by Sophos experts Paul Ducklin, Mark Stockley and special guest Craig Jones.
Listen now!
Related articles:
Trello exposed! Search turns up huge trove of private data: https://nakedsecurity.sophos.com/2020/01/30/trello-exposed-search-turns-up-huge-trove-of-private-data/ Employers can’t force you to get microchipped, Indiana reps say https://nakedsecurity.sophos.com/2020/01/30/employers-cant-force-you-to-get-microchipped-indiana-reps-say/ Serious Security – How ‘special case’ code blew a hole in OpenSMTPD https://nakedsecurity.sophos.com/2020/01/31/serious-security-how-special-case-code-blew-a-hole-in-opensmtpd/
This week we discuss 70,000 images being stolen from Tinder, the weleakinfo.com FBI bust and how Sonos annoyed its longstanding customers.
Host Anna Brading is joined by Sophos experts Mark Stockley, Greg Iddon and producer Alice Duckett.
Listen now!
Related articles: Sonos’s tone-deaf legacy product policy angers customers: https://nakedsecurity.sophos.com/2020/01/23/sonoss-tone-deaf-legacy-product-policy-angers-customers/ FBI seizes credentials-for-sale site: https://nakedsecurity.sophos.com/2020/01/20/fbi-seizes-credentials-for-sale-site-weleakinfo-com/ What do online file sharers want with 70,000 Tinder images? https://nakedsecurity.sophos.com/2020/01/21/what-do-online-file-sharers-want-with-70000-tinder-images/
This week we cover Snake ransomware, VPN vulnerabilities and decide whether our phones are spying on us.
Mark also revisits his growing list of pet peeves and Anna tests whether getting deep fake feet to your phone via SMS is real.
Host Anna Brading is joined by Sophos experts Mark Stockley, Greg Iddon and Producer Alice Duckett.
Listen now!
Related articles: Snake alert! This ransomware is not a game… https://nakedsecurity.sophos.com/2020/01/13/snake-alert-this-ransomware-is-not-a-game/ Browser zero day: Update your Firefox right now! https://nakedsecurity.sophos.com/2020/01/09/browser-zero-day-update-your-firefox-right-now/ REvil ransomware exploiting VPN flaws made public last April: https://nakedsecurity.sophos.com/2020/01/08/revil-ransomware-exploiting-vpn-flaws-made-public-last-april/ Windows 7 computers will no longer be patched after today: https://nakedsecurity.sophos.com/2020/01/14/windows-7-computers-will-no-longer-be-patched-after-today/
This week we discuss the IT exec who scammed his employer out of $6m with fake invoices and the death of Python 2. Peter also shares two of his latest investigations from the ransomware swamp.
Producer Alice Duckett is joined by Mark Stockley, Greg Iddon and Peter Mackenzie in this week's episode.
Thank you to everyone who gives us feedback on the podcast and helps us promote it on social media, it really helps us reach more people.
Listen now!
Related articles: IT exec sets up fake biz to scam his employer out of $6m: https://nakedsecurity.sophos.com/2020/01/07/it-exec-sets-up-fake-biz-to-scam-his-employer-out-of-6m/ Python is dead. Long live Python! https://nakedsecurity.sophos.com/2020/01/03/python-is-dead-long-live-python/
Here are the week's top stories - we explain the Plundervolt attack, look into a gunfight over a domain name, and explore the encryption drama that's unfolding between Facebook and Congress.
Host Anna Brading is joined by Sophos experts Mark Stockley, Paul Ducklin and Greg Iddon.
Listen and share!
Related articles: https://nakedsecurity.sophos.com/doitforstate-domain-name-thief-gets-14-years-for-pistol-whipping-plot https://nakedsecurity.sophos.com/plundervolt-stealing-secrets-by-starving-your-computer-of-voltage https://nakedsecurity.sophos.com/facebook-refuses-to-break-end-to-end-encryption
As always, we pick the top three cybersecurity stories of the week to discuss. This week we talk about open-source supply chain madness, Snatch ransomware and iPhone 11 tracking concerns.
Host Anna Brading is joined by Sophos experts Mark Stockley, Peter Mackenzie and Paul Ducklin.
Listen and share!
Related articles: Will the new iPhone 11 track you even if you tell it not to? https://nakedsecurity.sophos.com/2019/12/09/will-the-new-iphone-11-track-you-even-if-you-tell-it-not-to/ Snatch ransomware pwns security using sneaky ‘safe mode’ reboot https://nakedsecurity.sophos.com/2019/12/10/snatch-ransomware-pwns-security-using-sneaky-safe-mode-reboot/ Machine-raiding Python libraries squashed by community https://nakedsecurity.sophos.com/2019/12/05/machine-raiding-python-libraries-squashed-by-community/
Peter Mackenzie saved a casino from a ransomware attack, a children's smartwatch leaks location data and HPE warns of impending SSD disk doom.
Host Anna Brading is joined by Peter Mackenzie, Paul Ducklin and Mark Stockley.
Related articles: Children's smartwatch: https://nakedsecurity.sophos.com/2019/11/28/kids-smartwatch-security-tracker-can-be-hacked-by-anyone/
SSD disk impending doom: https://nakedsecurity.sophos.com/2019/11/28/hpe-warns-of-impending-ssd-disk-doom/
This week we discuss the large scale crypto-scam which tricked people into investing $400m, Tim Berners-Lee's proposed principles to save the web from a 'digital dystopia' and how to stay safe online during the festive season.
Producer Alice Duckett hosts the show with Sophos experts Paul Ducklin and Peter Mackenzie.
Listen now!
Related articles:
Crypto-scam: https://nakedsecurity.sophos.com/2019/11/25/onecoin-crypto-scam-lawyer-found-guilty-of-worldwide-400m-fraud/ Web principles: https://nakedsecurity.sophos.com/2019/11/26/sir-tim-berners-lee-publishes-plan-to-save-the-web-from-digital-dystopia/ Festive scams: https://nakedsecurity.sophos.com/2019/11/19/ho-ho-ouch-there-are-4x-more-fake-retailer-sites-than-real-ones/
A huge Airbnb scam ends with promises to verify every host and listing, Mozilla says ISPs are lying to Congress about encrypted DNS and we discuss the Sophos Threat Report 2020.
Host Anna Brading is joined by Sophos experts Peter Mackenzie and Greg Iddon on this week's episode of the podcast.
Listen now!
Related articles:
Airbnb: https://nakedsecurity.sophos.com/2019/11/11/huge-airbnb-scam-leads-to-promise-to-vet-every-host-every-listing/ Mozilla: https://nakedsecurity.sophos.com/2019/11/06/mozilla-says-isps-are-lying-to-congress-about-encrypted-dns/ 2020 threat report: https://www.sophos.com/en-us/labs/security-threat-report.aspx
Mass ransomware hit Spain earlier this week, BlueKeep's back and there's yet another twist in the sextortion saga.
Sophos experts Mark Stockley, Peter Mackenzie and Paul Ducklin join Producer Alice Duckett this week to discuss.
We also have a brand new Naked Security YouTube channel subscribe here: https://www.youtube.com/channel/UCuTRp4eg7vwZFYMzHP4KDlA?view_as=subscriber
Listen now!
Related articles:
RDP BlueKeep exploit shows why you really, really need to patch: https://nakedsecurity.sophos.com/rdp-bluekeep-exploit-shows-why-you-really-really-need-to-patch/
Ransomware attacks in Spain leave radio station in “hysteria”: https://nakedsecurity.sophos.com/spanish-ransomware-hits-two-companies/
Sextortion scammers are hijacking blogs – and victims are paying up: https://nakedsecurity.sophos.com/sextortion-scammers-are-hijacking-blog-sites/
This week we discuss the cyberattack with a difference on the city Johannesburg, how a hacker accessed company web servers via NordVPN and why the US nuclear weapons command finally ditched 8-inch floppies.
Host Anna Brading is joined by Mark Stockley, Greg Iddon and Peter Mackenzie.
Listen now!
Related articles:
Ransomware with a difference as hackers threaten to release city data: https://nakedsecurity.sophos.com/2019/10/28/johannesburg-hit-by-second-malware-attack/
Hacker breached servers used by NordVPN: https://nakedsecurity.sophos.com/2019/10/23/hacker-breached-servers-used-by-nordvpn/
US nuclear weapons command finally ditches 8-inch floppies: https://nakedsecurity.sophos.com/2019/10/22/us-nuclear-weapons-command-finally-ditches-8-inch-floppies/
This week we discuss the screen protector which bypasses fingerprint readers on Samsung’s flagship smartphones, icon-hiding Android adware and a mystery black box.
Host Anna Brading is joined by Sophos experts Mark Stockley and - for his final appearance - Matt Boddy.
Read our related articles here: Samsung fingerprint reader spoofed: https://nakedsecurity.sophos.com/2019/10/21/samsung-galaxy-s10-fingerprint-reader-beaten-by-3-gel-protector/ Icon-hiding Android adware returns to the Play Market: https://news.sophos.com/en-us/2019/10/08/icon-hiding-android-adware-returns-to-the-play-market/ Pen testers find mystery black box connected to ship’s engines: https://nakedsecurity.sophos.com/2019/10/17/pen-testers-find-mystery-black-box-connected-to-ships-engines/
In light of National Cybersecurity Awareness Month, we're giving you a special splinter episode all about social media.
Harry McMullin shares insights into what it was like growing up with social media from as early as ten, Mark Stockley gives the perspective of a parent with two children currently under ten and Alice Duckett discusses cancel culture and social media shaming.
If you're new here, we share episodes every week discussing the biggest cybersecurity news stories from data breaches to company faux pas. Did you like this episode centered around one topic? Let us know, and also tell us if there's another topic you want us to explore.
Listen now!
This week producer Alice Duckett steps in to host the show with Sophos experts Mark Stockley and Greg Iddon.
They discuss Twitter's two-factor authentication faux pas, the risks of copy and pasting code from Stack Overflow and an Android zero-day with a difference.
If you're interested in learning more, read our related articles:
Twitter fail: https://nakedsecurity.sophos.com/2019/10/10/twitter-used-2fa-phone-numbers-for-targeted-advertising/
Stack Overflow: https://nakedsecurity.sophos.com/2019/10/09/copy-and-paste-sharing-on-stack-overflow-spreads-insecure-code/
Android Zero Day: https://nakedsecurity.sophos.com/2019/10/07/android-devices-hit-by-zero-day-exploit-google-thought-it-had-patched/
This week host Anna Brading is joined by Sophos experts Mark Stockley and Greg Iddon.
They discuss the bust of CyberBunker, a malicious lightning cable that's about to hit the mass market and how to secure your laptop.
Related articles:
Darknet: https://nakedsecurity.sophos.com/2019/10/01/darknet-hosting-provider-busted-in-underground-nato-bunker/
O.MG lightning cable: https://nakedsecurity.sophos.com/2019/10/02/omg-evil-lightning-cable-hits-prime-time/
Secure your new laptop: https://nakedsecurity.sophos.com/2019/10/04/buying-a-new-laptop-heres-how-to-secure-it/
This week host Anna Brading is joined by Sophos experts Mark Stockley and Greg Iddon.
They discuss National Cyber Security Awareness Month, the latest chrome bug, 'Fleeceware' and why people are still falling for emails claiming they've recorded you through your webcam.
Related articles: Greg talks about SophosLabs’ latest research into ‘Fleeceware’: https://nakedsecurity.sophos.com/2019/09/27/fleeceware-play-store-apps-quietly-charging-up-to-250/ Source article: https://news.sophos.com/en-us/2019/09/25/fleeceware-apps-overcharge-users-for-basic-app-functionality/ Mark discusses how Chrome brought Hollywood to a standstill: https://nakedsecurity.sophos.com/2019/09/27/chrome-cripples-movie-studio-mac-pros/ Chrome Update Google thread: https://support.google.com/chrome/thread/15235262 Anna covers the sextortion emails that just won’t die. Here’s the original sextortion article from July 2018: https://nakedsecurity.sophos.com/2018/07/13/sextortion-scam-knows-your-password-but-dont-fall-for-it/ Another article that focused on email address spoofing (including Duck’s video that Anna mentions): https://nakedsecurity.sophos.com/2018/10/15/beware-sextortionists-spoofing-your-own-email-address/ And the “FINAL WARNING” sextortion email article from March: https://nakedsecurity.sophos.com/2019/03/13/final-warning-email-have-they-really-hacked-your-webcam/
This week host Anna Brading is joined by Sophos experts Mark Stockley, Ben Jones and Peter Mackenzie.
Ben explains why emotet is back, Peter shares his latest research into WannaCry and Mark shares the latest social media phish.
Related articles: Emotet: https://nakedsecurity.sophos.com/2019/01/25/fighting-emotet-lessons-from-the-front-line/ WannaCry: https://nakedsecurity.sophos.com/2019/09/18/wannacry-the-worm-that-just-wont-die/ https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/WannaCry-Aftershock.pdf Instagram phish: https://nakedsecurity.sophos.com/2019/09/24/instagram-phish-poses-as-copyright-infringement-warning-dont-click/
This week, Producer Alice Duckett steps in to host the show with Paul Ducklin, Mark Stockley and Greg Iddon.
Greg discusses the most disruptive Distributed Denial of Service (DDoS) attack in recent memory affecting Wikipedia, Mark shares another privacy boost for Firefox users and Duck explains why SSH-stealing NetCAT is not really a problem.
Related articles Wikipedia DDos: https://nakedsecurity.sophos.com/2019/09/11/wikipedia-fights-off-huge-ddos-attack/ Firefox Private Network: https://nakedsecurity.sophos.com/2019/09/13/mozilla-private-network-vpn-gives-firefox-another-privacy-boost/ NetCat: https://nakedsecurity.sophos.com/2019/09/13/intel-ssh-stealing-netcat-bug-not-really-a-problem/
This week, Producer Alice Duckett steps in to host the show with Paul Ducklin, Ben Jones and special guest Peter Mackenzie.
Peter shares the latest ransomware trends, Ben discusses a Facebook data leak which led to the exposure of 419 million phone numbers and Duck explains why not everyone is happy about Mozilla's move towards DNS over HTTPS.
Related articles Mozilla: https://nakedsecurity.sophos.com/2019/09/10/mozilla-increases-browser-privacy-with-encrypted-dns/ Facebook: https://nakedsecurity.sophos.com/2019/09/06/database-exposed-133-million-us-facebook-users-phone-numbers/ Ransomware: https://nakedsecurity.sophos.com/2019/09/09/us-city-balks-at-paying-5-3-million-ransomware-demand/ RDP research: https://sophos.com/rdp
This week on the Naked Security podcast host Anna Brading is joined by Mark Stockley, Paul Ducklin and Matt Boddy.
They discuss iPhone zero days, android botnets and how the founder and CEO of Twitter had his account hijacked.
Do you have a question? Let us know and we’ll answer them next week.
Related Naked Security articles: iPhone hacking: https://nakedsecurity.sophos.com/2019/08/30/sophisticated-iphone-hacking-went-unnoticed-for-over-two-years/ Twitter takeover: https://nakedsecurity.sophos.com/2019/08/30/jacks-twitter-attacked-phone-number-hacked/ Iphone Botnet targets set-top boxes: https://nakedsecurity.sophos.com/2019/08/30/botnet-targets-set-top-boxes-using-android-os/ Read our rdp research: https://sophos.com/rdp
This week on the Naked Security podcast host Anna Brading is joined by Mark Stockley and Paul Ducklin.
They discuss sophisticated Instagram phishing attacks, jailbreaking iPhones and the latest social media hoax.
Do you have a question? Let us know and we’ll answer them next week.
Related Naked Security articles: Jailbreaking: https://nakedsecurity.sophos.com/apple-ios-update-ends-in-jailbroken-iphones https://nakedsecurity.sophos.com/emergency-ios-patch-fixes-jailbreaking-flaw Social media hoaxes: https://nakedsecurity.sophos.com/privacy-policy-change-hoax-infects-instagram https://nakedsecurity.sophos.com/hoax-alert-facebook-deadline https://nakedsecurity.sophos.com/please-dont-spread-the-facebook-giraffe-picture-hoax https://nakedsecurity.sophos.com/the-momo-challenge-urban-legend https://nakedsecurity.sophos.com/the-talking-angela-witch-hunt Phishing: https://nakedsecurity.sophos.com/instagram-phishing-uses-2fa-as-a-lure https://www.sophos.com/en-us/products/phish-threat.aspx
This week on the Naked Security podcast we discuss whether big tech companies are spying on you and the latest phishing scams.
Do you have a question? Let us know and we’ll answer them next week.
With Anna Brading, Ben Jones and Matt Boddy.
Humans are listening to your voice recordings – Our articles are below: Microsoft: https://nakedsecurity.sophos.com/2019/08/09/your-skype-translator-calls-may-be-heard-by-humans/ And then updating its policy: https://nakedsecurity.sophos.com/2019/08/16/microsoft-wont-shift-on-ai-recordings-policy/ Facebook: https://nakedsecurity.sophos.com/2019/08/15/facebook-got-humans-to-listen-in-on-some-messenger-voice-chats/ Google and Apple: https://nakedsecurity.sophos.com/2019/08/05/google-and-apple-suspend-contractor-access-to-voice-recordings/ Apple saying no to backdoor the San Bernadino terrorist’s iPhone: https://nakedsecurity.sophos.com/2016/02/17/apple-says-no-to-iphone-backdoor-in-terror-case/ Sophos says No Backdoors: https://sophos.com/nobackdoors/ Phishing article Matt mentions: https://nakedsecurity.sophos.com/2019/08/20/serious-security-phishing-in-the-cloud-the-freemium-way/ Matt, Ben and Mark did some RDP research: https://sophos.com/rdp
The Naked Security podcast tells you how to keep crooks out of your home network, discusses whether the government should be able to read our private messages or not, and digs into the crooks behind the Baldr malware.
With Anna Brading, Paul Ducklin, Mark Stockley and Ben Jones.
This week's links: https://nakedsecurity.sophos.com/nas-vendors-hit-by-brute-force https://nakedsecurity.sophos.com/ep-025-business-email-compromise https://sophos.com/rdp https://nakedsecurity.sophos.com/five-eyes-nations-demand-access
This week we discuss EvilGnome, leaky browser add ons and the latest on BlueKeep.
With Anna Brading, Paul Ducklin, Mark Stockley and Matt Boddy.
What we talked about this week: https://nakedsecurity.sophos.com/2019/07/26/happy-sysadminday-2019/ https://nakedsecurity.sophos.com/happy-sysadminday-2019 https://nakedsecurity.sophos.com/evilgnome-linux-malware https://nakedsecurity.sophos.com/rdp-bluekeep-exploit-shows-why https://nakedsecurity.sophos.com/browser-plug-ins-peddled-personal-data
The Naked Security podcast - now in Series 2! This week we investigate whether FaceApp is as dangerous as they say, how to keep logic bombs out of your software, and how to help youngsters stay safe online.
With Anna Brading, Paul Ducklin, Mark Stockley and Matt Boddy.
What we talked about this week: https://nakedsecurity.sophos.com/faceapp-panic-sets-internet-alight https://nakedsecurity.sophos.com/the-momo-challenge-urban-legend-what-on-earth-is-going-on/ https://nakedsecurity.sophos.com/how-my-instagram-account-got-hacked/ https://nakedsecurity.sophos.com/programmer-from-hell-plants-logic-bombs-to-guarantee-future-work/ https://www.youtube.com/watch?v=QEkoetCHVRY https://twitter.com/NakedSecurity/status/1153627392965042176 https://twitter.com/NakedSecurity/status/1152171399001366528
The Naked Security podcast is back - in our brand new studio! We present our latest research into RDP security and just how quickly crooks can find you online.
Anna Brading talks to Matt Boddy, Ben Jones and Mark Stockley. https://sophos.com/rdp
The Naked Security podcast tells you how to make your web signup forms safer, explains how Android phones can be used as security tokens, and looks into a Facebook "hidden message" that escaped into the wild..
With Anna Brading. Paul Ducklin and Matthew Boddy.
This week's links: https://nakedsecurity.sophos.com/serious-security-how-web-forms-can-steal https://nakedsecurity.sophos.com/android-phones-transformed-into-anti-phishing https://nakedsecurity.sophos.com/facebook-admits-supply-chain-data-leak
Music by: https://purple-planet.com/
The Naked Security podcast reveals how long you can expect to go unnoticed online, explains why we still have applications where every bit matters, and comes up with a new vocabulary for "data loss" on the scale of MySpace's music file implosion.
With Anna Brading, Paul Ducklin, Matthew Boddy and Benedict Jones.
This week's links: https://nakedsecurity.sophos.com/knock-and-dont-run https://nakedsecurity.sophos.com/ep-025 https://nakedsecurity.sophos.com/serious-security-gps-week-rollover https://nakedsecurity.sophos.com/myspace-songs-come-back
Music by: https://purple-planet.com/
The Naked Security podcast looks into the annoying problem of bloatware on Android phones, explains a zero-day bug in a TP-Link router and how it turned into bad PR, and gives you advice on how to keep crooks out of your web server.
With Anna Brading, Paul Ducklin, Matthew Boddy and Benedict Jones.
This week's links: https://nakedsecurity.sophos.com/preinstalled-android-software https://nakedsecurity.sophos.com/tp-link-router-zero-day https://nakedsecurity.sophos.com/supermarket-patches-its-web
Music by: https://purple-planet.com/
The Naked Security podcast explains how to avoid losing money to the cybercrime known as BEC, or Business Email Compromise, and gives you tips on what to look out for when you plug new devices into your network.
With Paul Ducklin, Matthew Boddy and Benedict Jones.
This week's links: https://nakedsecurity.sophos.com/fbi-arrests-74-in-global-business-email-compromise-takedown https://nakedsecurity.sophos.com/why-you-should-be-cautious-of-emails-from-friends-or-colleagues https://nakedsecurity.sophos.com/7-tips-for-securing-the-internet-of-things https://nakedsecurity.sophos.com/what-if-your-security-camera-were-an-insecurity-camera https://nakedsecurity.sophos.com/upnp-flaws-turn-millions-of-firewalls-into-doorstops
To get Sophos XG Firewall Home Edition (100% free): https://www.sophos.com/en-us/products/free-tools/sophos-xg-firewall-home-edition.aspx
Music by: https://purple-planet.com/
In this Naked Security podcast, we explain how to handle sextortion, look at techniques for getting rid of malvertising, and discuss the things that make randomness hard.
With Anna Brading, Paul Ducklin, Mark Stockley and Matthew Boddy.
This week's stories: https://nakedsecurity.sophos.com/final-warning-email https://nakedsecurity.sophos.com/cia-bribery-scam https://nakedsecurity.sophos.com/sextortion-whats-new https://nakedsecurity.sophos.com/chrome-will-soon-block-drive-by https://nakedsecurity.sophos.com/serious-security-when-randomness-isnt
How to report cybercrime online: https://nakedsecurity.sophos.com/beware-sextortionists/#comment-5621990
Music by: https://purple-planet.com/
This week, the Naked Security Podcast tries to figure out where Mark Zuckerberg's new "Facebook Privacy Promise" is going, and digs into both the technical and community aspects of a recent Chrome zero-day bug.
With Anna Brading, Mark Stockley and Matthew Boddy.
This week's stories: https://nakedsecurity.sophos.com/study-throws-security-shade-on-freelance https://nakedsecurity.sophos.com/zuck-says-facebook-is-becoming-more-privacy-focused https://nakedsecurity.sophos.com/serious-chrome-zero-day-google-says-update
Music by: https://purple-planet.com/
The Naked Security podcast explains why storing plaintext passwords is an unnecessary evil, investigates a cryptocurrency spat between a software maker and a disgruntled user, and tells you some earnest but unpopular truths about how to keep your children safe online.
With Anna Brading, Paul Ducklin, Mark Stockley and Matthew Boddy.
This week's stories: https://nakedsecurity.sophos.com/millions-of-utilities-customers-passwords-stored-in-plain-text https://nakedsecurity.sophos.com/disgruntled-dev-blames-crypto-wallet-for-losing-cryptocoins https://nakedsecurity.sophos.com/the-momo-challenge-urban-legend https://nakedsecurity.sophos.com/the-momo-challenge-why-its-time-to-stop-the-hype
Related links: https://nakedsecurity.sophos.com/serious-security-how-to-store-your-users-passwords-safely https://nakedsecurity.sophos.com/the-passwordless-web-explained
Music by: https://purple-planet.com/
The Naked Security podcast investigates a massive medical data blunder, tells you how NOT to do vulnerability disclosure, and asked whether password managers do more harm than good.
With Anna Brading, Paul Ducklin, Mark Stockley and Matt Boddy.
This week's stories: https://nakedsecurity.sophos.com/milions-of-private-medical-calls-exposed https://nakedsecurity.sophos.com/virus-attack-hackers-unleash https://nakedsecurity.sophos.com/password-managers-leaking-data
Music by: https://purple-planet.com/
The Naked Security podcast explains the recent security hole in Linux products such as Docker and Kubernetes, ponders whether Apple's insistence on 2FA for developers will bring rogue apps under control, and tells you whether to worry about booby-trapped USB cables.
With Anna Brading, Paul Ducklin and Greg Iddon.
This week's stories: https://nakedsecurity.sophos.com/linux-container-bug-could-eat-your-server https://nakedsecurity.sophos.com//apple-fighting-pirate-app-developers https://nakedsecurity.sophos.com/evil-usb-o-mg-cable
Music by: https://purple-planet.com/
The Naked Security podcast pokes a stick into the latest critical security bugs in Android, investigates the dubious art of iOS screenshots you didn't take yourself, and marvels at the USB drive that survived a seal's digestive tract.
With Anna Brading, Paul Ducklin, Mark Stockley and Matthew Boddy.
This week's stories: https://nakedsecurity.sophos.com/android-vulnerabilities-open-pie https://nakedsecurity.sophos.com/iphone-apps-record-your-screen https://nakedsecurity.sophos.com/anyone-want-to-lay-claim-to-the-usb
Music by: https://purple-planet.com/
The Naked Security podcast looks at who was at fault in a network home invasion, investigates how both Google and Facebook fell foul of Apple's developer rules, and answers the vital question, "Which is better, Android or iPhone?"
With Anna Brading, Paul Ducklin and Matthew Boddy.
This week's stories: https://nakedsecurity.sophos.com/hacker-talks-to-baby https://nakedsecurity.sophos.com/apple-kicks-facebook https://nakedsecurity.sophos.com/google-says-sorry https://twitter.com/NakedSecurity/status/1090960185441562624
Music by: https://purple-planet.com/
The Naked Security Podcast digs into a US Emergency Directive to stop government sites getting hijacked, examines a data breach with a difference, and hears a cybersecurity expert's confession of how his Instagram got hacked.
With Anna Brading, Paul Ducklin, Mark Stockley and Matthew Boddy.
This week's stories: https://nakedsecurity.sophos.com/us-gov-declares-emergency https://nakedsecurity.sophos.com/bqs-dodgy-database-divulges-data https://nakedsecurity.sophos.com/how-my-instagram-account-got-hacked
Social network advice: https://nakedsecurity.sophos.com/how-to-secure-your-instagram-account-using-2fa https://nakedsecurity.sophos.com/how-to-secure-your-twitter-account https://nakedsecurity.sophos.com/how-to-protect-your-facebook- https://nakedsecurity.sophos.com/facebook-fallout-what-are-your-options
Music by: https://purple-planet.com/
The Naked Security podcast looks at high-value email crime, Google's latest attempt to clean up the Play Store, how you can buy a billion email addresses for just $45, and the conspiracy theories that say the "10 year challenge" is a dangerous trap! With Anna Brading, Paul Ducklin, Mark Stockley and Matthew Boddy.
https://nakedsecurity.sophos.com/email-crooks-swindle-woman https://nakedsecurity.sophos.com/google-locks-down-access https://nakedsecurity.sophos.com/vast-data-berg-washes-up https://nakedsecurity.sophos.com/is-the-ten-year-challenge
Music by: https://purple-planet.com/
Naked Security looks at whether the latest USB hardware proposals will be used for security or for anti-piracy, investigates an open-source toolkit for bypassing 2FA, and explains how the US government shutdown is affecting online security. With Anna Brading, Paul Ducklin, Mark Stockley and Matthew Boddy.
https://nakedsecurity.sophos.com/usb-c-authentication-sounds-great https://nakedsecurity.sophos.com/2fa-codes-can-be-phished https://nakedsecurity.sophos.com/shutdown-hits-government-web
Music by: https://purple-planet.com/
The Naked Security Podcast investigates the ethics of remote rickrolling, whether Acrobat is the new Flash, and how to fool biometrics with a zombie hand. With Anna Brading. Paul Ducklin, Mark Stockley and Matthew Boddy.
https://nakedsecurity.sophos.com/dont-fall-victim-to-the-chromecast https://nakedsecurity.sophos.com/update-now-adobe-acrobat https://nakedsecurity.sophos.com/vein-authentication-beaten
Music by https://purple-planet.com/
The Naked Security Podcast rings out 2018 with a look at the big issues of the past year. With Anna Brading, Paul Ducklin and Matthew Boddy.
https://nakedsecurity.sophos.com/huge-marriott-breach https://nakedsecurity.sophos.com/big-facebook-breach https://nakedsecurity.sophos.com/cambridge-analyticas-secret https://nakedsecurity.sophos.com/iranian-hackers-charged https://nakedsecurity.sophos.com/after-samsam-ryuk https://nakedsecurity.sophos.com/how-to-pick-a-proper-password https://nakedsecurity.sophos.com/two-factor-authentication-2fa
Music by https://purple-planet.com/
In this Naked Security podcast, Anna Brading, Paul Ducklin and Mark Stockley confront the latest cybersecurity threats affecting WordPress, Android and Flash.
https://nakedsecurity.sophos.com/massive-botnet-chews-through https://nakedsecurity.sophos.com/android-click-fraud-apps https://nakedsecurity.sophos.com/flash-zero-day-exploit-spotted
Music by https://purple-planet.com/
On the Naked Security podcast this week: Marriott's huge and scary data breach, a bug in software management software could be a data thief's goldmine, and a self-righteous "hacker" prints out an advert on 50,000 internet printers. With Anna Brading, Mark Stockley, Matthew Boddy and Paul Ducklin. (Music: purple-planet.com)
In the Naked Security Podcast this week: hacking phones at Pwn2Own, the brand new SophosLabs Threat report, and squeezing Shakespeare into one tweet. With Anna Brading, Paul Ducklin and Mark Stockley. (Music: purple-planet.com)
Hyperthreading considered harmful, how to avoid lock screen hacks, and what happens when cryptocurrency exchanges implode. With Naked Security Editor-in-Chief Anna Brading, Paul Ducklin, Mark Stockley and Matthew Boddy. (Music: purple-planet.com)
Naked Security editor-in-chief Anna Brading is back in the presenter's seat, talking to Mark Stockley, Matthew Boddy and Paul Ducklin about the lessons we can learn from the latest cybersecurity news.
This week, Naked Security editor-in-chief Anna Brading talks to Sophos experts Paul Ducklin, Mark Stockley and Matthew Boddy about: a security flaw in the WhatsApp app, a shopping site compromise using rogue JavaScript, and the in-your-face cybercrime known as sextortion. (Music: purple-planet.com)
Naked Security experts Paul Ducklin, Matt Boddy and Mark Stockley teach you what to do about the recent Facebook breach, and discuss how to make mobile security more than just "some annoying thing on my phone that gets in the way." (Music: purple-planet.com)
Join us as we talk to Sophos security expert Matt Boddy about how you can embrace the "bring your own" world of 21st century IT while staying safe and secure at the same time.
Should we have more privacy to protect us from cybercriminals, or less privacy so those selfsame cybercrooks can't hide so easily?
Join Sophos security experts Paul Ducklin and James Burchell for a lively discussion that is informative, entertaining – and just a touch controversial!
When it comes to learning about the latest trends in malware, there's no one we'd rather talk to than SophosLabs Principal Researcher Fraser Howard. Join us as Fraser explains how to "know your enemies" so you can fight them more effectively.
No website is too small, and no website too big, that it is out of the reach of hacktivists, online vandals, bad actors and unreconstructed cybercrooks. So web security is vital - but how to get it right?
Join us as we talk to Sophos Naked Security's very own website guru, Mark Stockley, an expert who not only understands web security but also has a special gift for making this treacherous topic both clear and interesting.
GDPR enforcement started in May 2018. Where next?
Join Sophos Naked Security's Paul Ducklin and Vincent Vanbiervliet, Product Manager of Data Protection at Sophos, as they talk about how to turn security into a business asset - a value to be embraced, not just a cost to be minimised.
A cybersecurity scare about ransomware called "WannaCrypt" has been widely spammed out. This one, fortunately, is a scam - there isn't any malware - but the attack that the crooks describe could, in theory, be pulled off. Matt Boddy and Paul Ducklin investigate, and explain what to do.
This week's podcast finds Chet and John both enjoying some well deserved time in their respective homes. Topics include an overview of InfoSec Europe and BSides London, the dangers of not providing password management tools, how small mistakes lead to bigger vulnerabilities, the state of cryptojacking and the latest FBI cybercrime bust.
Chester and Ben talk about the week's security news including the latest Flash and Internet Explorer zero-day vulnerabilities, insecure toys being yanked from major retailers, Naked Security's award winning performance at InfoSec Europe 2018, the debate of a public postmortem at the City of Atlanta and the conviction of Yahoo! hacker Karim Baratov.
The FBI just issued a VPNFilter malware warning saying, "Reboot your routers now!" But why? And will it help? Kimberly Truong and Paul Ducklin of Sophos investigate.
Charlotte Williams from Naked Security talks to Sophos experts Matt Boddy and Paul Ducklin about the EFAIL in email, a gift-horse bug in Red Hat Linux, and what happens when sniffer dogs join your cybersecurity team. (Music: purple-planet.com and codices.bandcamp.com)
This week's podcast finds Chet hosting from Hong Kong with guest Ben Verschaeren. Topics covered include the eFail disclosure, Adobe Reader vulns, Chili's credit card theft, LocationSmart leaking cell locations and Android requirements to stay up to date.
Chester Wisniewski is joined by Greg Iddon from London in this week's Chet Chat. They discuss the latest Drupal attacks, patch urgency, the IC3 report on cybercrime and the cost of cryptomining.
Charlotte Williams from the award-winning computer security website Naked Security talks to Sophos experts Matt Boddy and Paul Ducklin about old-school malware, how to judge Patch Tuesday, and what to do about Facebook. (Music: purple-planet.com and codices.bandcamp.com)
Paul Ducklin from the award-winning computer security website Naked Security talks to Sophos experts Matt Boddy and Fraser Howard about password cracking and HTTPS. (Music: purple-planet.com and thespacelords1.bandcamp.com)
Paul Ducklin from the award-winning computer security website Naked Security talks to SophosLabs researcher Fraser Howard about a growing trend in cybercrime: cryptojacking, where the crooks mine cryptocurrency and keep the loot, but you pay for the electricity. (Music: purple-planet.com)
John Shier interviews Claudio Stahnke from Canalys Channel Forums about the view of security from the channel partner's perspective. John and Claudio touch on GDPR, security as a service, IoT and more.
This week's Chet Chat comes to you live from BSides Perth in West Australia. Chester and John share their thoughts on Coinbase forking over data to the IRS, Apple's non-fixy-fix for OS X, FBI not notifying victims of Fancy Bear and Firefox warning about password thefts.
This week's Chet Chat is live from the Tom's Guide offices in New York City after the O'reilly Security event. Chester has a chat with journalist Paul Wagenseil about the O'reilly event, another lost thumbdrive with sensitive unencrypted data, KRACK patch availability, malicious Chrome extensions and the seemingly lax governance at some social media companies.
This week's Chet Chat was recorded live from BSides Calgary with Michael Argast from Sky Northern. Chester and Michael shared their opinions on the KRACK vulnerabilities, Infineon RSA crypto bug, Mastercard ditching receipt signing, IRS saying your ID is compromised and Australia's new data breach notification legislation.
This week's Chet Chat comes to you from Madrid, Spain thanks to it being the host city for Virus Bulletin 2017. Chester interviews the Editor for VB, Martijn Grooten, about the conference while mispronouncing his name at least 3 ways. John Shier joins Chet to discuss their favourite talks and takeaways from this years event.
John Shier hosts the Chet Chat this week with special guest Ben Verschaeren from Sophos Australia. John and Ben share their insights on this year's BSides Las Vegas, Black Hat and DEF CON conferences. Topics covered include IoThacking, information sharing, machine learning, responsible disclosure and more.
Is ransomware really the worst sort of cyberattack you can experience? Or is it more of a “worst among equals,” given all the other sorts of malware out there too?
Sophos security expert James Burchell explains what to do when faced with a multitude of cyberthreats.
https://sophos.com/securitysos
Botnet malware quietly downloads instructions from cybercriminals on what to do next, such as grabbing passwords, stealing files, sending spam, and delivering malware.
Learn from Fraser Howard, one of the world’s leading anti-malware researchers, how to dezombify your world.
https://sophos.com/securitysos
Here's the third episode of our June 2017 "Sophos Security SOS" series - a week of topical podcasts, originally recorded and broadcast live.
Sophos cybersecurity specialist Luke Groves talks to Paul Ducklin about how to take charge of security inside your organisation without creating an uncomfortable culture of snooping and surveillance.
https://sophos.com/securitysos
Here's the second episode of our June 2017 "Sophos Security SOS" series - a week of topical podcasts, originally recorded and broadcast live.
In this episode, Paul Ducklin interviews Sophos malware specialist Peter Mackenzie about the evolution of phishing. Join us to learn how to keep your own users safe.
https://sophos.com/securitysos
This is the first in our June 2017 "Sophos Security SOS" series - a week of topical podcasts, originally recorded and broadcast live. In this episode, Paul Ducklin interviews Sophos expert John Shaw about the new European data protection laws (GDPR), how they affect organizations in Europe, North America and beyond, and how to turn them into an opportunity rather than merely shouldering them as a burden.
https://sophos.com/securitysos
In this week's Chet Chat, Sophos researchers Chester Wisniewski and John Shier share their opinions on the leaked NSA election hacking docs, Judy Android ad fraud, the OneLogin breach, Crisis authors throwing in the towel and Google's latest privacy SNAFU in Chrome.
The Chet Chat is back! Join Sophos experts Chester Wisniewski and Paul Ducklin for their keen commentary on the latest security news. In this episode: WannaCry revisited, a wormable hole in Samba, security changes in the Android world, and a bunch of cybercrime busts.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our regular security podcast.
The duo turn the latest news into purposeful advice as they discuss swastikas on Twitter, the recent Apache Struts zero-day exploit, the CIA's funkily-named "Fine Dining" project, and why four of Google's biggest competitors have decided to stand up for Mountain View in court.
Live from BSides Vancouver 2017 Chester Wisniewski of Sophos interviews Derek Hanson from Yubico about U2F, FIDO and the future of mutlifactor authentication.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest edition of our regular security podcast.
In this episode: trouble at the SHA-1 mill; the (not so) imaginary world of Mac ransomware; wiretapping your children with furry toys; and Google goes one step forward/one step back in Chrome's new TLS security dialog.
Chester Wisniewski and John Shier share their thoughts from the floor of this year's RSA Conference in San Francisco.
Join Paul Ducklin and Bill Brenner for our third and final roving report from RSA Conference 2017.
Bill Brenner of Sophos is at the RSA Conference 2017 in San Franscisco. He talks to Paul Ducklin about the lessons learned so far...
Bill Brenner from Sophos is our "roving reporter" at the RSA 2017 conference in San Francisco. Paul Ducklin gets Bill's take on the hot topics from the first day of the event.
In this week's Chet Chat, Paul and Chester discuss the vulnerabilities reported in Cisco's WebEx plugin, the ease of breaking into Android phones which use the lock pattern, a recent security audit of the Dovecot project, animals attacking infrastructure and Data Privacy Day.
Chester Wisniewski is back from his December vacation, and this week he's talking to fellow Sophos expert Paul Ducklin about the world of computer security.
It's not all bad news following the many big breaches and security blunders of 2016: Chet and Duck find reasons to be upbeat for 2017, so join them to find put why!
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our security podcast.
This week: the BlackNurse "attack", booby-trapped network cards, a Linux bug to make you smile, how Wi-Fi can leak your phone PIN, and Facebook's announcement that it is buying up stolen passwords.
Chet and John bring you this week's Chet Chat live from the Virus Bulletin conference in Denver, Colorado USA. They summarize some of their favourite talks covering IoT vulnerabilities, malvertising, banking malware, building your own open source lab and whether Microsoft Defender is ever enough.
Chester and John pack a lot into a busy week attending a conference and bringing you this week's security news. They discuss the recent mass DDoS attack on Brian Krebs, more horrifically vulnerable routers, changes to protect the SWIFT banking system, certificate authorities demonstrating their untrustworthiness and the Lock Down Your Login campaign to kick off National Cyber Security Awareness Month.
In this week's Chet Chat, John Shier joins Chet to discuss the Yahoo! breach, the US FTC's new website for identity theft victims, how to break into an iPhone, credit card best practices and how the US DOT is working with car manufacturers on privacy concerns.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our entertaining and informative computer security podcast.
From a breach in Opera's cloud to handy back-to-school advice for kids (and their parents), " here's this week's "security news you can use."
Join Sophos experts Chester Wisniewski and Paul Ducklin for our latest security podcast.
In this week's episode: new tricks in ransomware, DARPA's grand bug-finding challenge, carder crook busted, and why your email password could be worth millions.
Chet and John record live from DEF CON and summarize all the great content they experienced at this year's Black Hat, DEF CON and BSides Las Vegas hacking conferences. Topics covered this week include Bluetooth man in the middle attacks, password standards, testing binaries for the liklihood of vulnerabilities, using DNS as a botnet detection scheme, hooking the kernel gone wrong and the overall state of hacking conferences in 2016.
John Shier joins Chester Wisniewski this week to complete the last podcast before the Black Hat and DEF CON conferences in Las Vegas next week. They try to explain the scoop behind the LastPass vulnerability, a dead man's fingerprints, strange behaviours on Tor and Ed Snowden's plan to tell you if your phone is spying on you.
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our weekly security podcast.
This time: how to get paid for using two-factor authentication; the weirdly-named "HTTPoxy" bug; and ATM jackpotting in the spotlight.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our computer security podcast.
This week: Pokémon GO, "boneidleware", Patch Tuesday, Mac malware, free (yes!) tools, and a 15-country cyberbust.
Sophos Security researchers Chester Wisniewski and John Shier dive into what's behind this week's security news. In this episode they discuss the latest ransomware, Zepto, safe usage of the dark web, how a criminal could take over your Facebook account and how crooks are after your information just as much as they are after celebrities.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our regular security podcast.
This week: just in time for Canada Day, some Google Play malware with a Canuckian theme; how pen testers turn bugs into breaches; and Chet puts on his fireproof trousers to come out in favour of Windows 10.
Join Sophos experts Chester Wisniewski and Paul Ducklin for our latest security podcast.
In this episode: hardening Tor, the ransomware with a Pirate Name, and not one but two stories about Apple and crpyto. Enjoy!
Join Sophos security experts John Shier and Paul Ducklin for the latest episode of our security podcast.
This time: hardware random numbers; the death (we hope) of the Angler exploit kit; the Spam King goes to prison at long last; and Github reminds us all, "Don't re-use passwords!"
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our security podcast.
This week: TeslaCrypt gives up its master key; iOS researcher fights with Apple; iPad Pro users complain of "bricked devices"; Bing gets tough on fake support; Mr Robot website has Mr-Robot-style security hole; and... please vote for the Chet Chat in the 2016 European Security Blogger awards.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our regular Chet Chat podcast.
This week: Friday 13th viruses remembered; US regulators ask tough questions about mobile updates; how software you might never have heard of could put your website at risk; and 3 zero-days in 3 months for Flash.
Join Sophos experts Chester Wisniewski and Paul Ducklin for another entertaining and well-informed episode of our computer security poccast.
This week: the test server that wasn't; the text file that isn't; the VPN that might not be; and a cool new concept for bug bounties... the "Occam's Razor Bonus."
Chester Wisniewski and John Shier interview Mark Loman about the growing threat of Ransomware and the tool his team developed, CryptoGuard.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our computer security podcast.
This week, Chester reports from BSides Austin, where he's been presenting a talk on the security (or otherwise) of the IoT. Other topics this week: Apple and FBI (what now?), a password strength meter that wasn't, and how to save your friends and family from the "jury duty" scam.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest edition of our weekly computer security podcast.
In this episode: Tor and backdoors, an overdue kernel patch for Android, Apple's iMessage security hole, and an FBI warning about "car hacking."
Join Sophos experts John Shier and Mario Winter, who recorded this episode live at the CeBIT computer show in Hanover, Germany.
From ransomware to the collection of personal data, Mario talks to John about the latest IT security challenges in the German-speaking world.
Join Sophos Senior Technologists Chester Wisniewski and Paul Ducklin for the latest episode of our weekly security podcast.
Our experts take an amusing but very informative look at the latest security stories: Android "security lag", OS X ransomware, hacking Facebook, and making fake fingerprints.
Chester and John podcast from San Francisco at the RSA Conference USA 2016 in front of a live studio audience this week. Find out about what you may have missed at this year's conference and a brief discussion of the DROWN openssl vulnerability.
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our award-winning security podcast.
This week: why we think there should be #nobackdoors; how "mousejacking" works; the security system that anyone can login to; a mysterious spike in the Dark Web; and malware in the world's favourite Linux distro.
This week's Chet Chat comes to you live from HackCon XI in Oslo, Norway. Kristian Samstad from Infinigate is Chester's guest and they discuss the talks at the conference, SMS phishing, Locky ransomware, the glibc bug and Ringo Starr's Twitter account hack.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our computer security podcast.
This week: President Obama endorses 2FA for everyone; the IRS and 2FA that wasn't; the NSA versus the Internet of Things; and Wired magazine goes up against adblockers.
Join Sophos experts Chester Wisniewski and Paul Ducklin for our weekly security podcast.
In this episode: the bug-fixing bot from MIT; no more Java in your browser; why Tor is a technology for all of us, not just for crooks; and how a US text spammer ended up in prison.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our computer security podcast.
This week, our duo turn their wit and expertise on: PrivacyCon and the Internet of Things; Shodan and public webcams; a vulnerability brouhaha on Android; Data Privacy Day; and more.
Join Sophos security experts John Shier and Paul Ducklin for the latest episode of our regular security podcast.
This week: the "crypto debate", malicious web ads, exploit kits and ransomware, a tricky bug patched in iOS...and the very, very worst passwords of 2015. (Star Wars is back. Whoever would have thought?)
Michael Argast joined Chet this week to talk a bit about the retirement of IE 8, IE 9 and IE 10, a bit of IoT security and lots of crypto chat.
In our first episode of 2016 Chester and John explore the week's news including the Ukrainian power hack, Android fixes, insecure security systems, jailbreaking the PS4 and Sophos Home.
In this episode, we look back over the past year to tell you what we think we've learned, and what we can do differently to improve our collective security and privacy in 2016.
If you're expecting bad news, then there's plenty of it - but we made sure to look at the bright side, too!
Join Sophos experts Chester Wisniewski and John Shier for the latest episode in our weekly security podcast.
This week: daily December tips on Naked Security, a big breach at VTech, insecurity-by design in the IoT, Geekweek, a cybercrime bust...and Sophos Home as a present for the festive season!
Join Sophos security experts John Shier and Paul Ducklin for their witty but insightful review of the week's security news.
In this episode: email security, malicious barcodes, whether to trust a search engine, and how to avoid online crooks during your seasonal shopping.
Join Sophos security experts John Shier and Paul Ducklin as they dissect the week's computer security news with their usual mix of insight and wit.
In this episode: we reach our "double nelson"; busts in the JPMorgan hack; malware on iOS, Android and OS X; get Sophos Home for free; and how BadBIOS is back...this time, on your TV.
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our quarter-hour computer security podcast.
This week, our amusing-yet-serious experts take on ransomware, Linux security, the Dark Web...and the thorny issue of what smartphone to choose for Commander James Bond.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our weekly computer security podcast.
From data breaches to encryption denial, and from the latest #sophospuzzle to Yahoo's "crypto witch," we cover the week's news in a way that's fun, informative and educational - all in a tight, quarter-hour format.
Join Sophos experts Chester Wisniewski and Paul Ducklin as they dissect the latest computer security news in their witty but informative way.
This week: encrypting everything, clown computing (yes, you read that correctly!), the Internet O' Things, thwarting state-sponsored attacks, and how to take down a botnet. (One byte at a time.)
Join Sophos security experts Chester Wisniewski and Paul Ducklin for our latest weekly security podcast.
In this episode: encryption backdoors, Patch Tuesday, weak ciphers, leaked crypto keys, the ups and downs of adblocking, a "randomness" scammer jailed, and what you sound like after a data breach...
Chester Wisniewski and Paul Ducklin of Sophos get together for the latest episode of our computer security podcast.
This week, our two experts look into anti-hacker insurance, social engineering, cyberdétente, cyberirony, and cybersecurity awareness. Oh, and a topic close to both their hearts: Why you should never, EVER knit your own cryptography.
Paul Ducklin crosses live to Sophos security expert Chester Wisniewski, who is attending this year's Virus Bulletin conference in the Czech Republic.
Find out what the world's top threat protection experts talk about when you cloister them in a Prague hotel for three days!
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our security podcast.
This week: Shark attacks and selfies, selfies and you, yet more lock screen insecurity, and why malware in Word files is making a comeback...
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our weekly computer security podcast.
Listen and learn from the latest stories including: the release of iOS 9, malware in the App Store, a lock screen bypass on Android, Facebook's decision to sell yet more data to advertisers, and why the crooks are loving the social network's new "Dislike" button.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our weekly security podcast.
Informative, educational and amusing, we spend a tight quarter-hour helping you turn last week's news into next week's good advice.
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our security podcast - a fun and fascinating quarter-hour of "news you can use".
This week: the cop who stole $800k in Bitcoin, WH Smith's leaky web form, Mozilla finds an intruder right inside its Firefox bug database, and the Dead Parrot sketch. No, that's not right...the even weirder Dead Pigeon code.
Chester Wisniewski is back from Down Under to resume our podcast series, the Chet Chat.
In this episode, Chester talks to Paul Ducklin about: Ashley Madison, salting-and-hashing, the FTC, the future of Flash, and the criminal conviction - at last! - of the "Spam King", Sanford Wallace. Oh, and about fraud-fighting ferrets...
Join Sophos security experts Chester Wisniewski and Paul Ducklin as they tackle the latest security news in our weekly podcast.
This time: a password-stealing zero-day in Firefox; a "grab root privilege" hole in Android; a firmware worm for Macs...and prison for IRS scammers in the US.
Sophos expert Chester Wisnieski is in Las Vegas this week, at the Black Hat 2015 conference.
Paul Ducklin caught up with Chester on the Sophos booth to get his impressions. Oh, and Duck asked Chet how many Apple Watches he'd spotted...listen at 8'35" to find the answer!
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our award-winning security podcast.
This week: Windows 10 updating, Tor's trustworthiness, Xen bugfix, BIND server problems, and get free stuff at booth 452 at #BHUSA.
Join security experts Chester Wisniewski and John Shier as they discuss and explain the week's computer security news.
This week Chet and John talk about Pakistan banning Blackberry servers, Linux's role in the malware ecosystem, Windows 10 privacy SNAFUs, the latest zero-day vulnerability in Android (Stagefright) and the sentencing of those behind the DNS Changer malware.
Join Sophos experts John Shier and Paul Ducklin in the latest episode of our thought-provoking security podcast.
In this week's quarter-hour: cybercrime (and punishment), crimeware, the infamous Angler exploit kit, and how the Fourth Amendment applies to social networks.
Join Sophos security experts John Shier and Paul Ducklin for the latest episode of the Chet Chat.
Enjoy a tight quarter-hour podcast where we turn the latest security news into advice you can use - and have fun at the same time.
Join Sophos security experts John Shier and Paul Ducklin in the latest episode of our weekly podcast.
From Windows 10 Wi-Fi Sense to the Mr Robot TV show, here's 15 minutes of news turned into educational fun!
Sophos security expert Chester Wisniewski took a week's worth of known-bad website data from SophosLabs and worked backwards to investigate some important questions: Which platform hosts the most malware? How does it get there? And what can we do about it?
Paul Ducklin dug into the research data with Chester, and the result was this fascinating and educational podcast, revealingly subtitled, "When Penguins Attack."
Join Sophos experts John Shier and Paul Ducklin for the latest episode of our weekly security podcast, the Chet Chat.
News you can use!
Join Sophos security experts Chester Wisniewski and Paul Ducklin in the latest episode of our Chet Chat security podcast.
This week: US Navy keeps XP alive, Apple gets CORED, Android starts bug bounties, Drupal needs a patch, and alleged megacarder Ercan Findikoglu will be extradited from Germany to the US after all.
Join Sophos security experts John Shier and Paul Ducklin as they dig into the latest security news in our weekly "Chet Chat" podcast.
In this episode: the LastPass breach, Facebook and its new-look photo privacy, our readers react to Windows 10's rolling update model, and the Samsung phones where an update could make your security worse!
Join Sophos security experts Chester Wisniewski and Paul Ducklin in this week's episode of our security podcast.
Apple, Microsoft, patching, hacking - and 49 arrests in a Europol action against bank fraudsters.
We took to the exhibition floor at Infosec 2015 to ask ten visitors: "What concerns you the most in computer security?"
We got 11 answers...and here they are.
https://nakedsecurity.sophos.com/infosec-2015-what-concerns-you-the-most
Join Sophos experts Chester Wisniewski and Paul Ducklin for another episode of our weekly computer security podcast.
This week, they're both at the Infosec Europe conference in London, England...join them straight from the trade show floor.
Join Sophos experts Chester Wisniewski and Paul Ducklin as they dissect the latest security news in our weekly podcast.
It's entertaining and educational - news you can use.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our weekly security podcast.
A quarter-hour of "news you can use" - entertaining to listen to and educational to hear.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our no-nonsense computer security podcast.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our weekly computer security podcast.
From the future, where Microsoft's Update Tuesday is no more, to 15 years in the past, when we were awash in virus-infected emails that claimed, "ILOVEYOU." News and discussion with plenty of good advice.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of the weekly Chet Chat podcast.
From bugs to busts, here's the computer security news you can use.
Sophos experts Paul Ducklin and John Shier take a quick look at what's happening at the RSA Conference 2015.
From "joined up security" to the suggestion that Google proclaimed the end of malware on Android, find out what's happening at RSA...
This week, Chester Wisniewski is at RSA 2015 in San Francisco.
He talks to fellow Sophos security expert Paul Ducklin straight from Sophos's booth at the trade show.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our weekly security podcast.
From the very latest Update Tuesday to how we get rid of 10-year-old security holes, here's the security news you can use.
Join Sophos experts Chester Wisniewski and Paul Ducklin as they dissect the latest computer security stories in their inimitable style.
Turn news into advice with the Sophos Security Chet Chat!
Join Sophos experts Chester Wisniewski and Paul Ducklin as they dissect the latest news in our weekly computer security podcast.
From the G20 leaders' "passport leak" to World Backup Day, we turn news into useful advice!
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of our computer security podcast.
This week's Chet Chat comes to you from an al fresco café in downtown Ljubljana, as Chester gets ready to present at a conference in Slovenia. Topics include: Pwn2Own, FREAK, Facebook, and just how to decide whether to trust those mobile apps.
Join Sophos security experts Chester Wisniewski and Paul Ducklin for the latest episode of our weekly podcast.
This week's edition comes to you straight from the Sophos exhibition booth at the CeBIT show in Hannover Germany!
Join Sophos experts Chester Wisniewski and Paul Ducklin for our weekly security podcast.
In this episode: FREAK, Update Tuesday, hypervisor escape, spammers, hackers, foistware...and the Chet Chat's 5th birthday!
Join Sophos experts Chester Wisniewski and Paul Ducklin as they dissect the week's security stories.
Listen to the latest episode of the Chet Chat, our weekly educate-and-entertain podcast for anyone interested in computer security.
Sophos expert John Shier sits in for regular presenter Chester Wisniewski in this episode.
John and Paul Ducklin dissect the latest security issues, which were dominated this week by some thorny matters of cryptography.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest "Chet Chat" podcast.
A quarter-hour of focused and well-informed discussion to help you make the best of the week's security news.
Our weekly "Chet Chat" podcast is carefully prepared to fit into a quarter-hour, so it is clear and concise as well as being witty and amusing.
Join Sophos experts Chester Wisniewski and Paul Ducklin as they dig into the latest computer security news...
Join Sophos experts Chester Wisniewski and Paul Ducklin in our weekly podcast that dissects the latest security news so that it's educational and entertaining at the same time.
In this episode: Flash flaws again, again; the lifetime of GHOSTs; hotels versus Wi-Fi; and a fascinating new research paper from SophosLabs called "Exploit This."
Join Sophos experts Chester Wisniewski and Paul Ducklin in our weekly podcast as they turn their insight on the latest security news.
From Apple's latest OS X and iOS updates to Data Privacy Day - listen, learn and enjoy!
Join Sophos experts Chester Wisniewski and Paul Ducklin as they dig into the latest news in our weekly security podcast.
In a crisp and serious yet amusing quarter-hour", "they'll take you all the way from the Internet of Things to a Young Pirate's Wi-Fi privacy stunt...enjoy!
Join Sophos experts Chester Wisniewski and Paul Ducklin as they take on the week's news in our regular security podcast.
In this epsiode: the new-look Update Tuesday; the "bug reports at 15 paces" duel between Microsoft and Google; Google drops the security ball for 61% of Android users; CENTCOM hacked (sort of); Apple Spotlight privacy leakage; and why attacks only ever get smarter.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the first Chet Chat security podcast of 2015.
In this episode: zero-day politics, leaky security features, Bitcoin news, and a shout out to our New Year #sophospuzzle winners!
Regular host Chester Wisniewski is taking a well-earned vacation, so Sophos security experts Paul Ducklin and Mark Stockley bring you this episode of the Chet Chat.
This week: phishing, spamming, zombification, SCADA and the Internet of Things, and the curiously named cybervandals that go by "Lizard Squad."
Chester Wisnieski and John Shier are both on vacation this week, so regular guest Paul Ducklin takes the presenter's side of the microphone to talk to Sophos Naked Security's Mark Stockley.
Topics in this episode of our security podcast include: learning from Sony, embracing 2FA, rising above old-school attacks, and...what does 2015 have in store?
Join Sophos experts John Shier and Paul Ducklin as they dig into the latest security news in our weekly podcast.
In this episode: Sony (twice!), Android, holiday scams, online safety and looking after your passwords properly.
Sophos experts Chester Wisniewski and Paul Ducklin dissect the week's security news and turn it into advice you can use.
In this episode of the Chet Chat: Sony's breach, a spyware bust, Android Lollipop "pinning", e-cigarette malware, and how to win cool T-shirts in the "12 Days of Christmas" Naked Security quiz.
Sophos experts Chester Wisniewski and Paul Ducklin take on the latest security news in our weekly podcast.
In this episode: Cyber Monday and online scams; the true cost of data breaches; the good and bad of auto-updating your servers; and the FTC takes on 120 million dollars' worth of fake support calls.
Sophos security experts Paul Ducklin and Chester Wisniewski tell you what you need to know about the what, the why and the how of ransomware.
What is ransomware? Why has it become such a problem? And how do you protect yourself from it?
Sophos experts Chester Wisniewski and Paul Ducklin dissect the latest security news in this episode of the weekly Chet Chat podcast.
From a carder ring that got busted to a spamming system that ran amuck, let yourself be amused and educated at the same time.
Sophos security experts Chester Wisniewski and Paul Ducklin aim their insights at the latest security news in our weekly Chet Chat podcast.
Recorded on Patch Tuesday, which was also Remembrance Day (Veterans' Day), this episode covers topics that are interesting, important - and intriguing!
Sophos experts Chester Wisniewski and Paul Ducklin turn the week's security news into actionable advice.
In this episode: the Sophos SPAMPIONSHIP; understanding bots and zombies; keeping your web servers safe; and why ransomware isn't dead, even if CryptoLocker is.
Sophos experts Chester Wisniewski and Paul Ducklin look at the week's security news and turn it into entertaining and informative advice.
In this episode: Sandworm, Death by Powerpoint, password security, FIDO and two-factor authentication...and (huzzah!) some scammers get busted by the FTC.
Sophos expert Chester Wisniewski digs into the week's security news with John Shier and Paul Ducklin.
In this episode: the POODLE problem; the effect of data breaches on consumer confidence; South Korea's identify crisis; Get Safe Online week; and Advance Fee Fraud.
With Chester Wisniewski on the road, Sophos security expert John Shier steps up to the microphone to discuss the week's security news with Paul Ducklin.
In this episode: October's Patch Tuesday, the problem of "breach fatigue", some thorny questions about metadata, and how to stay safe on Android.
Sophos experts Chester Wisniewski and Paul Ducklin take apart the latest computer security stories to turn them into news you can use.
From BadUSB to breaches to Bugzilla, this week's podcast looks at exploits, breaches, zero-days, responsible disclosure and more.
Join Sophos security experts Chester Wisniewski and Paul Ducklin as they dissect the week's news.
Shellshock leads the list, of course, but Snapchat, cybersecurity awareness and the iPhone 6 all get a look in too...
Sophos Security expert Chester Wisniewski was at the Virus Bulletin 2014 conference in Seattle.
In this special edition of the Chet Chat, Paul Ducklin puts Chet on the other side of the mic to find out more about both the technology and the ethics of anti-malware research.
Sophos experts Chester Wisniewski and Paul Ducklin entertain, inform and explain in their regular computer security podcast.
In this week's episode: Home Depot and security, Apple and iOS 8, eBay and JavaScript, the battle for passwords, and cybersecurity awareness.
Sophos experts Chester Wisniewski and Paul Ducklin get to grips with the big computer security issues of the past week.
In this episode: the Android "Browser" privacy-busting bug, and what to do about it; real-world risks of password sharing; U2 or not U2; Firefox fixes; and advice from the Year's Most Epic Privacy Fails.
Sophos experts Chester Wisniewski and Paul Ducklin dig into the week's computer security news.
In this episode of the Chet Chat: Patch Tuesday (and what it teaches us about security holes); Apple Pay; Home Depot's breach; and Google's "search page time warp" that's supposed to put some light-hearted pressure on those who refuse to upgrade their browsers.
Sophos security experts Chester Wisniewski and Paul Ducklin take you to Mars to explain how flash memory works (and why you can't erase it very reliably).
Also in this episode: Wi-fi security, data breaches, randomness and mobile app permissions...
Chester Wisniewski and Paul Ducklin take a special look at a conference Chester just attended in Queensland, Australia.
Sophos has supported this event, run by the Queensland Police, for many years, because it brings together security experts from law enforcement, online merchants, software companies and community groups to make a collective committment to deal with the question, "What is each of us actually going to do to help fight cybercrime in the next twelve months?"
Join Sophos experts Chester Wisniewski and Paul Ducklin for this week's Chet Chat podcast, and turn computer security news into computer security advice.
In this episode: Microsoft's blue screen of death woes; the future of Apple security patches; the risks of remote access; and a Russian MP's son arrested for online cybercrime.
Join Sophos experts Chester Wisniewski and Paul Ducklin in the weekly Chet Chat security podcast.
In this episode: Patch Tuesday; combining exploits; an Android virus attack; Foursquare opts out of opt-in; Facebook under fire; and Chester relives his favorite talks of Black Hat and DEFCON.
Listen to this "Black Hat Special" episode of the Chet Chat.
Paul Ducklin puts Chester Wisniewski on the other side of the microphone to tell us about the real security lessons from Black Hat USA 2014...
Sophos expert Chester Wisniewski takes time out of the Nevada heat to delve into the latest security news with Paul Ducklin. (Chet's in fabulous Las Vegas this week, attending the B-Sides, Black Hat and DEFCON conferences.)
There's something for everyone in this epsiode, including: spam, malware, hacking, encryption, backup and more.
Chester Wisniewski and Paul Ducklin of Sophos dissect the week's security news to see what we can learn from other people's mistakes. ("Those who cannot remember the past are condemned to repeat it," as George Santayana famously said.)
And Chester has an invitation: "If you're going to be in Las Vegas for BlackHat 2014, be sure to drop by at the Sophos booth and say G'day!"
Sophos experts Chester Wisniewski and Paul Ducklin look for lessons in the latest computer security news.
In this week's podcast: how to make SoHo routers more secure; how to decide if you can trust your browser; UK law enforcement takes aim at a banking botnet; and, boy-oh-boy, do we have a prize for you.
Join Sophos experts Paul Ducklin and Chester Wisniewski as they take a clear but entertaining trip through the components you'll find in a modern network firewall, helping you to understand the what, how and why of each part.
Whether you're an IT professional responsible for implementing a network security policy, the CFO who has to pay for it, or just a concerned user keen to learn more about defense in depth, this podcast will tell you what you need to know...
Sophos experts Chester Wisniewski and Paul Ducklin are back with this week's Chet Chat security podcast, turning plain old news into advice you can use.
In this episode: Warbiking in Manhattan; buffer overflow hubris for Google; why you don't/do/don't/do need anti-virus for Android; what we can do to stop botnets like Gameover recovering after takedowns; and how LibreSSL shows that less can be more when it comes to security.
In this episode, Sophos experts John Shier and Paul Ducklin tackle the week's interesting security stories.
John keeps Duck to 60 seconds (OK, 75") in a TL;DR version of Patch Tuesday, and then the pair get stuck into: the high-profile cybercrime arrest of a Russian MP's son; how mainstream brands inadvertently help phishers; and why macro malware is coming back from the brink of extinction.
Join Sophos experts Chester Wisniewski and Paul Ducklin for the latest episode of the weekly Chet Chat podcast.
In this episode: Were does your country sit on the fraud list, and what can you do about it? Just how much can you trust SMSes on Android, even if they come from a friend? Is Apple serious enough about security on the iOS mobile platform? And will Google's End-To-End email encryption plugin save the world from surveillance?
Chester Wisniewski and Paul Ducklin present Sophos's regular weekly security podcast, the "Chet Chat."
This week the enthusiatic experts look at: yet more in the TrueCrypt saga; the Towelroot software for rooting locked-down Androids; the ongoing problem of ransomware even after the CryptoLocker takedown; and Canada's long, long, long-awaited anti-spam law.
Sophos security experts Chester Wisniewski and Paul Ducklin turn their attention on the week's security news.
As usual, they extract plenty of useful lessons during their insightful dissection of the issues, including: PF Chang's data breach, which the company has as good as admitted but not yet tracked down; the ongoing saga of vanishing encryption software TrueCrypt; the ethics of creating computer worms; and how much online scammers are actually costing us.
Chester Wisniewski and Paul Ducklin dig into the latest security news for lessons we can all learn.
In this episode of our weekly quarter-hour podcast: Patch Tuesday, and why simply counting vulnerabilities isn't a good measure of danger; file-encrypting ransomware comes to Android; Apple announces Wi-Fi MAC scrambling as a privacy measure; and mysterious iPhone-locking cybercrook "Oleg Pliss" has been arrested...perhaps.
Chester Wisniewski and Paul Ducklin take on the latest security news with their usual mix of enthusiasm, expertise and entertainment.
This week, they dig into the bafflement of the disappearing TrueCrypt encryption software: did it jump, or was it pushed? They also look at the takedown of the Gameover and CryptoLocker malware by law enforcement, and Chet sends Duck down memory lane to tell us what we can learn from ten years of mobile malware.
John Shier interviews security expert Chester Wisniewski about the sudden demise of the freeware TrueCrypt project. They discuss what happened and what users should consider when moving on to greener pastures.
Chester Wisnieski and Paul Ducklin dig into the important security stories of the past week, and pull out some lessons we can all learn.
Take an entertaining and informative journey through the case of Apple iDevices held to ransom in Australia; the calamity of eBay's super-sized data breach; a carefully-coordinated cybercrime bust in Bulgaria; and Sourceforge's "in a good cause" password reset.
The Chet Chat comes to you this week from Hanoi, Vietnam with special guest Sean Richmond from Sophos Australia.
Chet and Sean continue the tradition of working through the details to paint you a clearer picture. This week they tackle the FBI's crackdown on the Blackshades malware, new research showing more flaws in Chip & PIN technology, the latest Apple updates and an analysis of the EFF's "Who has got your back" report.
Road trips again prove no barrier to the Chet Chat, with Chester Wisniewski calling home to the studio from the exotic wilderness of the Air Canada lounge at Toronto Airport.
As usual, Chester and Paul Ducklin turn their insightful and entertaining gaze on the security lessons we can learn from the past few days.
There's the difference between "Important" and "Critical" on Patch Tuesday; Apple's possible return from the security wildnerness; Bitly's underwhelming breach notification; and Snapchat, who settled with the FTC by admitting some rather unflattering stuff about the company...
Sophos security experts Chester Wisniewski and Paul Ducklin look at what we can learn from the week's security news.
Target, Dropbox, Microsoft, the mysterious Webdriver Torso and Sophos Naked Security itself feature in this episode of our weekly podcast.
A zero-day in IE to contend with, followed by a zero-day in Flash; two approaches to fixing OpenSSL after the Heartbleed bug; how to get a free pass to the Infosec Europe 2014 event in London; and why security happens by design and not by accident!
Chet and Duck turn their attention on the lessons we can learn from the latest security news.
Computer security experts Chester Wisnieski and Paul Ducklin of Sophos turn their attention on the week's news.
Mixing wit, insight and advice, the duo look at: the risk from iOS malware, the state of play in fingerprint security, whether to trust mobile apps, why it's a bad idea to hack the taxman, and what to do if Brian Krebs calls to warn you've been pwned.
From the latest Heartbleed revelations to various successes by law enforcement, Sophos experts Chester Wisniewski and Paul Ducklin take you through the big computer security stories of the week.
Be entertained as you learn from the news, all in our regular quarter-hour podcast format.
Sophos experts Chester Wisniewski and Paul Ducklin help you to understand - and explain what you can do about - the big ticket security news items of the past week.
The epic "Heartbleed" bug in OpenSSL, the last patches ever for XP and Office 2003, and Apple's attitude to updates and support all come under the microscope.
Chet and Duck get together once again to look at the week's news with their usual blend of humor, insight and informed intensity.
There's Adobe's password breach revisited (in poetic form, no less), why there are 42 days left in Windows XP, how Snapchat dissed the US legislature, and what World Backup Day really ought to mean to you...
On 01 April 2014, we decided not to do an April Fool's but to have some April Fun instead!
So we turned three recent computer security stories into poems. OK, rhyming verse. Doggerel, in fact.
Here, then, with apologies to Mr Robert William Service, are the stories of Mt Gox, Snapchat and the End of XP, as you've never heard them before.
How bad is the latest Microsoft Word 0-day? Does OS X really need patching less often than Windows? What does Gmail's move to HTTPS-only really mean? And if WhatsApp has privacy coded into its DNA, is it coded into its app, too?
Chet and Duck add their opinion and advice to the good and the bad in the past weeks' news.
Is a browser less secure if more people like to hack it? Is it OK to ignore alerts simply because you get too many? Do you back yourself to spot every single phish? And just how smart is the Google Play Store?
Chester and Duck dissect these issues in their entertaining and informative style in this week's Sophos Security Chet Chat podcast...
Chet and Duck turn the week's news into useful lessons once again.
There's Patch Tuesday, the impending end of XP, Advanced Persistent Threatitis, and some astonishing statistics about just how many people have been hit by the CryptoLocker ransomware.
Join the dynamic duo for another entertaining quarter-hour on computer security.
What about support for OS X Lion and Mountain Lion? Are they, or aren't they? Why can't Apple just say? Could the addition of a rootkit to the Gameover malware be a blessing in disguise? If you want to hack your way to better results at University, is jumping from an F to an A a wise maneouvre? And will proposed federal data breach laws in the US make things better or worse?
Chester and Duck once again aim their entertaining expertise at the security news of the week...
Paul Ducklin hooks up "live at RSA" with Naked Security writers Chester Wisniewski and John Shier for a Conference Special podcast.
This half-length Chet Chat packs in one-quarter humour, five-eighths news and two-thirds insight - find out what was good, weird, interesting, or all of the above, at this year's RSA 2014 event!
Chester ducks out of booth duties at the RSA 2014 conference in San Francisco to bring you this week's Chet Chat.
From Apple's SSL bug to Adobe's second-in-a-month emergency Flash update, Chet and Duck once again help you to learn from others' mistakes.
Chet and Duck again turn the week's security news into advice you can use and share with your friends.
What happened to Flappy Bird? Why was Talking Angela so talked about? Is internet access at the Winter Olympics in Sochi really a "special danger" situation? What can we learn from the database breaches at Kickstarter and Forbes?
Chet and Duck cast their expert eyes over the week's security news.
The pair bring some infectious enthusiam to Sophos's recently-announced acquisition of Cyberoam; they look at Patch Tuesday plus Adobe's out-of-band update to Flash; urge aginst the trend for big brands to bundle "foistware downloads" of complete new applications into what are supposed to be security updates; and plenty more besides.
Join this dynamic duo as they turn the latest news into a quarter-hour podcast that is informative, entertaining and educational.
Chet and Duck review the week's news in their informed and entertainingly serious style, discussing the prizes on offer at this year's PWN2OWN competition, talking about a new twist in Android malware, and reviewing the latest attack reports from Yahoo and Target.
Oh, and Sophos Naked Security is up for "Blog that Best Represents the Security Industry" in the forthcoming Security Bloggers Awards 2014, so...please vote for us if you are elgibile to do so.
This week's Chet Chat starts out with credit card breaches, as yet more big PII leaks hit the news; then covers the issue of whether you really need good passwords everywhere; before going into an upbeat and encouraging conclusion - we like to finish on a positive note! - discussing Data Privacy Day.
You did know it was Data Privacy Day, didn't you? (You do now.)
Chet and Duck turn a week's worth of lost data, malware attacks, misleading apologies and shabby security into actions you can take to steer a safer course inside your own organisation.
From digitally signed Mac malware, through plaintext password storage, all the way to the South Korean credit agency that lost personal information on close to half of the country's population, here's our weekly "podcast with a purpose."
In early 2014, a contractor at credit-scoring company Korea Credit Bureau was arrested for loading up a USB key with personally identifiable information for some 20,000,000 people, about 40% of South Korea's population.
Shades of the Bradley/Chelsea Manning "Wikileaks" saga of three years earlier, in which decades of confidential US State Department cables were siphoned off.
Here's a sadly-still-relevant podcast from the Wikileaks incident, looking at the question, "How could this have happened?"
Chester Wisniweski and Paul Ducklin dig into the lessons we can learn from the security issues of the past week.
What's the best way to deal with bots and botnets? If you use your financial institution's official mobile banking app, are you more or less secure that just using your browser? What's going on with data security in the US retail sector? What are the must-have and must-do patches from this Patch Tuesday? And do you really have to update your Mac to Mavericks if you want security fixes?
Botnets, short for "robot networks", are more than just malware: they're the money making machinery of modern cybercriminals.
Paul Ducklin and James Wyke help you to understand the What, How and Why of this troublesome topic.
The result is an entertaining and educational podcast that's suitable for everyone from sysadmins to home surfers.
Chet and Duck look at the security stories that made the headlines over New Year 2013/2014 - from the OpenSSL "hypervisor hack" that wasn't, to the Skype Twitter breach that shouldn't have happened - and explain how we can learn from these mistakes to have a safer and more secure 2014.
From Cryptolocker, through PRISM, Target and Adobe, to tainted randomness: Chet and Duck review the security lessons of 2013, and advise how to make 2014 safer and more secure!
Chet and Duck analyse the latest security news to help you keep ahead of the bad guys. Find out about the recent and massive Target breach; get to grips with Microsoft's and Apple's latest updates; and learn how to respond to Google's recent changes to image rendering for Gmail users.
Chet and Duck tell you what you need to know about the latest security stories. Turn bad news into good with "what you can do better" advice on the back of an XP zero-day, a spate of Bitcoin "bank robberies," the outcome of a European user security survey, and yet another cryptographic blunder, this time from Drupal.
Chet and Duck dig into the good and bad of the week's computer security news, from the amusing "Happy Hour Virus", through Twitter's implementation of "forward secrecy" to discourage government-type surveillance, to LG's data-grabbing TVs and the company's unamusingly casual attitude to what amounts to business-type surveillance.
Chester and John Shier take time out of the IANS Information Security Forum in Atlanta, Georgia, to talk about the key issues of the past week. There's the US police department that paid the CryptoLocker ransom; the company Loyaltybuild that took two weeks to tell its loyal customers that it hadn't even bothered to encrypt their PII that was stolen; and, to finish with some good news, high praise for Microsoft's public push for cryptographic progress.
Paul Ducklin and Chester Wisniewski investigate the what, the why and the how of dealing with the impending end of support for Windows XP in 2014.
Don't worry: even if you have computers that you simply won't be able to update in time, for example because they run bespoke industrial control software, or a legacy financial application, Duck and Chet have some healthy suggestions for you.
They also share some insights into why Microsoft hasn't simply packed all the improved security components from Windows 7 and 8 into the aging XP, leading to the 08 April 2014 deadline.
Chet and Duck deal with: November's Patch Tuesday, whether or not hacking attacks are getting worse, whether Anonymous defacements count as "hacking", an esoteric bug in OpenSSH, and the lessons to learn from Adobe's megabreach.
Chet and Duck discuss the latest Microsoft zero-day, the latest code verification flaw in Android (the third bug of the same sort in the same part of the code!), and whether version numbers are becoming an irrelevancy as products "just update" anyway.
Chet and Duck discuss WordPress autoupdating; OS X's giant new wave, Mavericks; iCloud and 2FA; smartphone tracking by retailers; and security in pacemakers and other medical devices.
Chet and Duck discuss Oracle's monster Java patch, Joel's backdoor in D-Link routers, Cryptolocker and WhatsApp's demonstration of why you shouldn't roll your own crypto.
Chet interviews Robert Slade a well known anti-virus expert for National Cyber Security Awareness Month #NCSAM. Rob shares his thoughts on how average folks can stay safer online.
Chet and Duck are back on the regular schedule and talked about the 10th anniversary of Patch Tuesday, Adobe going "open source" and the alleged demise of the Dread Pirate Roberts.
In the last third of Sophos Security Chet Chat 118 Chet interviews Vanja Svajcer from SophosLabs about his presentation on potentially unwanted Android apps. Many users are being inundated with advertising pop-ups and other pesky behaviours, leading security vendors toward providing tools to block these apps.
As a reminder to everyone that it is National Cyber Security Awareness Month #NCSAM, Chet and Duck remind our listeners to do the three things to help themselves and others stay safer online.
Chester interviews James Wyke of SophosLabs UK about his presentation on the Zero Access Trojan at this year's Virus Bulletin conference in Berlin, Germany.
This week Chet and Duck talk about Apple, Apple, iOS, Apple, OS X, lots of patches, browser trust and Facebook privacy.
Make sense of vulnerability jargon by listening to this 15 minute podcast... With recent updates from Microsoft (three times), Adobe, Oracle, Apple and Firefox, the timing could scarcely be better.
In this episode of SSCC Chet and Duck talk about Google Authenticator temporarily forgetting its seeds, Apple bugs, Facebook data probes and an increase in WordPress phishing.
Chet and Duck discuss XP "as a giant 0-day", password practices in light of LastPass's recent vulnerability and the next generation of the HTTP protocol.
Chet welcomes series regular Paul 'Duck' Ducklin to discuss the latest security news: Android random number flaw implicated in Bitcoin thefts, OpenX ad servers "pre-compromised", Lavabit and Silent Circle suspend operation, winners of Black Hat 2013 #sophospuzzle.
Chet and Duck talk about the stolen "master Android keys", Tumblr security flaws, Club Nintendo password woes and the new Sophos puzzle for BlackHat 2013.
In this podcast Chester and Duck tackle 'Keyjacking', obfuscated data breach notification letters and Apple's iOS WPA2 passphrases being a little too easy.
Security experts Chester 'Chet' Wisniewski and Paul 'Duck' Ducklin discuss the latest security news: the leak behind PRISM, Swedish against Google's cloud, and BlackBerry ships Flash on its latest smartphones.
Chet welcomes series regular Paul 'Duck' Ducklin to discuss the latest security news: Microsoft reading Skype messages, the IP Commission Report, small business cybersecurity, and AusCERT 2013 #SophosPuzzle.
Chet welcomes series regular Paul 'Duck' Ducklin to discuss the latest security news: Name.com breach (and others), laptop theft, casher crews, LulzSec busts, Patch Tuesday.
In this podcast Chester interviews Parmy Olson author of "We are Anonymous" about her thoughts on LulzSec, their sentencing and the Anonymous movement. Parmy also shares some of her thoughts on Firefox OS and other developments from Mobile World Congress 2013.
Chester calls home from Interop in Las Vegas to record the latest episode of the Sophos Security Chet Chat. Duck explains a WWII steganography technique and introduces a contest. Chester and Duck then discuss internet camera vulnerabilities, game software rigged to mint Bitcoins and more password database breaches.
Chet welcomes series regular Paul 'Duck' Ducklin to discuss the latest: Boston marathon bombing scams, Hostgator's hack, Safari's Java safety update, pwning planes with an Android app, and Facebook Home and "Cover Feed".
To some of us, two-factor authentication (2FA) is a welcome aspect of online security; to others, token or SMS-based login codes are just extra online hassle we'd rather do without. Duck and Chet help you evaluate the risks and rewards of 2FA in this enjoyable quarter-hour podcast.
This week's Chet Chat has Duck and Chet discuss the DOD BYOD policy, malware posing as multi-function printers, WordPress adopting 2FA and two new browser rendering engines competing on both performance and security.
Chet and Duck discuss debuggy HP printer firmware, ad-supported phone apps, scans of the whole internet, Apple introducing 2 step authentication, link morphing and Internet Explorer 11.
Chet inteviews the writer and director of hacker film "Code 2600" and Austin BSides organizers/consultants Michael Gough and Ian Robertson. We also introduce the new kickstarter "Hackers in Uganda".
Guest Paul Ducklin and host Chester Wisniewski talk about RSA Conference 2013, CanSecWest 2013, Vancouver's first Security BSides, PWN2OWN, the cPanel break-in and cloud security.
This week Chet and Duck discuss Mandiant's APT1 report, the alleged watering hole attack against iOS developers and Twitter hacks.
Chet and Duck tackle the weeks news including UPnP, the Balmital botnet take down, Flash patches for Windows and OS X and the Lucky Thirteen SSL/TLS weakness.
This podcast outlines what to expect if you attend one of our Anatomy of an Attack seminars. Chester Wisniewski and John Shier explain the content presented and what attendees should expect to take away.
Chester talks to Paul Ducklin about HP Printers on the open internet, Java, precision versus accuracy and PWN2OWN and Pwnium 3 contests.
In this 100th episode of the Chet Chat, Duck and Chester discuss the bizarre story of John McAfee, OS X malware, Switzerland losing intelligence data, NASA laptops and Romanian carders.
Michael Argast rejoined Chet this Halloween to catch up on the week's news including new DMCA exceptions, Hurricane Sandy scams, Yahoo! ignoring do not track, Barnes and Noble credit cards skimming and Facebook's donation to spam research.
This week Paul Ducklin is in the guest seat as he and Chester discuss Patch Tuesday, weak RSA certificates, losing $250,000 worth of bitcoins, Do Not Track, Blackhole exploit kit and the Nitol botnet takedown.
Peter Szabo from SophosLabs joins Chet to chat about 4 more talks from this year's Black Hat and DEF CON conferences. Topics include MSCHAPv2, Frack, smart meters and hacking public transit.
Java brings with it some significant risks, yet for many people, it's "just there on my computer." In this episode, Duck and Chet tell you All about Java, and help you to make an informed decision in balancing its risks and rewards at work and at home.
Peter Szabo, a senior threat researcher with SophosLabs, joins Chet this week to to share what they learned at this year's Black Hat and DEF CON conferences. They discuss NFC, a file disinfection framework, steganography and the dangers of IPv6 and DNSSEC.
To many of us, SSL isn't much more than "the padlock in the browser." But how does it work? Who verifies SSL certificates? How do we know we can trust them? What happens if we realize we can't? Duck and Chet discuss all this, and more, in this episode of the Techknow podcast.
Paul Ducklin joins Chet this week to discuss the quarterly Oracle patches, the theft of a USB stick belonging to Elections Ontario, the bypass of in-app purchases from the App Store and how WiFi hackers stole $3 million.
Do you really need seven committee meetings and a 90 day waiting period before you update your computers with the latest patches? Duck and Chet take on the challenges of security patches in this episode of the TechKnow podcast.
Paul Ducklin joins Chet once again to discuss the latest security news. This week's topics include DNS Changer, Patch Tuesday, Find and Call, San Diego's fireworks fiasco and password breaches.
Michael Argast joins Chet once again to discuss Flame, LinkedIn, warrantless wiretapping, Patch Tuesday, border patrol spying and Microsoft's BlueHat prize.
Michael Argast from Telus joined Chet once again to discuss the week's news. Topics covered include Flame malware, Do Not Track, TACK, Conficker and Sophos Mobile Security for Android.
This week's Chet Chat returns to our usual news format this week with guest Gary Korhonen (@hundredaire). Gary and Chet discuss the Utah data breach, Facebook hacker's prison term, OS X Leopard's FlashBack removal tool, Pentagon data sharing and Operation Phish Phry sentencing.
This week's Chet Chat comes to you live from the show floor at Interop 2012. John Shier and Chet Wisniewski have some fun and share highlights from the expo hall.
Chester Wisniewski and Chris Pace walk around the exhibition hall at this year's InfoSec Europe and share their insights on trends and some fantastic giveaways some vendors thought might grab your attention.
Chester Wisniewski and Paul Ducklin chat about the security issues surrounding Apple's new iTunes security, knowledge-based authentication, Mac malware and Google's fine from the FCC.
David Schwartzberg is this week's guest on the Chet Chat to talk about the data breach at Global Payments, a new Mac botnet and Flash Player updating. David also explained the new AES-NI encryption acceleration in Intel chips and a new way to safely store files in the cloud.
Paul Ducklin is this week's guest on the Chet Chat. Chet and Paul discuss an attempted DDoS of an election in Canada, the knock-on effects of the DNS Changer malware, Facebook's new Data Usage Policy and the risks of outsourcing.
In this week's episode John Shier joins Chet to discuss the review of electronic device usage on airplanes by the FAA, the arrests of the Carberp malware authors, the worm danger from the MS12-020 RDP vulnerability and whether the time has come for encrypting more than just laptops and USB drives.
In this new podcast series Paul Ducklin and Chester Wisniewski take a more in-depth look at a single topic, exploring the ins and outs to help listeners understand complex topics. In this episode - Busting Password Myths, Paul and Chester take a look at the thorny issue of password rules and regulations.
Chet and Duck say goodbye to San Francisco, thank their fellow bloggers for Naked Security winning the Best Corporate Security Blog, discuss their favorite stand and talk a bit about how "big data" plays with security.
RSA special Chet Chat sharing Chester's and Duck's first impressions of the first day of the RSA 2012 conference in San Francisco.
Paul Ducklin hosts this week's Chet Chat with the tables turned... Chet is the guest. They discussed the recent Google cookie-gate incident, House Intelligence Committee advice on using laptops while travelling and the malicious emails sent to leaked Stratfor subscriber email addresses.
This week's Chet Chat finds Paul Ducklin and Chester Wisniewski discussing the vulnerabilities patched this Tuesday in Microsoft, Adobe and Oracle products, mobile phone application privacy issues and upcoming events RSA and Anatomy of an Attack in Portland, OR and Wellington, NZ.
Paul Baccas is interviewed by Chester Wisniewski on his paper A time-based analysis of Rich Text Format manipulations. Paul explains how the focus is often on zero-day exploits even though flaws like CVE 2010-3333 have been patched for over a year and are still resulting in successful compromise.
This week, Paul Ducklin joins Chet to talk about the Sophos Security Threat Report 2012, the new anti-phishing proposal known as DMARC and mobile phone numbers being leaked through HTTP headers at O2.
Chet sits down with Michael Kaiser, Executive Director at the National Cyber Security Alliance (NCSA) to discuss Data Privacy Day. Michael explains the origin of Data Privacy Day, some of the activities related to it and how people can participate in raising awareness about privacy and data security.
In this week's podcast, Vanja Svajcer joins Chet to talk about the mobile security landscape. Topics discussed include mobile malware, theft, application markets and advice on securing your smartphone.
Paul Ducklin joins Chet for the first Chet Chat of 2012. This week they discuss the privacy implications of smart meters, the recent research showing how WiFi routers are vulnerable due to an easy setup feature and password hashes.
Gary Korhonen joins Chet for this week's podcast discussing the automatic upgrade of Internet Explorer, Android Market malware, Carrier IQ and an infection that shut down a hospital in Georgia.
Paul Ducklin joins Chet to talk about this week's news including giving your friends and family a hand at Thanksgiving, Android security, SCADA hacking and Google's WiFi mapping opt-out scheme.
Chester interviews Michael Kaiser from the National Cyber Security Alliance and Rob Strayer from the Bipartisan Policy Center about National Cyber Security Awareness Month and our upcoming State of Cyber Security event.
John Shier joined Chet this week as they discussed the death of UNIX and C co-creator Dennis Ritchie, the Virus Bulletin 2011 conference, Apple's release of iOS 5 and OS X 10.7.2, Microsoft Patch Tuesday, and the German R2D2 Trojan.
Brad Arkin joined Chester Wisniewski to discuss the launch of Flash Player 11 and the improvements in security and privacy in this new version. Brad also shares some insights into the success of Reader X in blocking malicious code.
This week Paul Ducklin joins Chester Wisniewski to discuss cooperating to fight hi-tech crime, the Kelihos botnet shutdown, the US government proposal to have ISPs notify infected customers and the impact of BEAST on SSL connections.
Paul Ducklin joined Chet this week from a real life denial of service situation at the Sydney, Australia airport. Topics discussed include Patch Tuesday, UBS losing $3bn, SpyEye on Android, Twit.tv hacked and Windows 8 including anti-virus.
Mike Wood a Senior Threat Researcher with SophosLabs is Chet's guest. They discuss the upcoming Patch Tuesday, the new Firesheep and go in depth on the recent troubles at certificate authority DigiNotar.
Chester Wisniewski welcomes back Paul Ducklin to summarize the week's security news. This week they talk about ATM skimming and recent related research, Juicejacking, the latest Anonymous attacks and the digital bread crumbs we all leave behind on the internet.
Vanja Svajcer joins Chester Wisniewski to discuss the papers and demos they attended at last week's Black Hat and DEFCON conferences. Topics covered include Android patch cycles, Fixing the SSL CA problem, insulin pump hacking, Google ChromeOS flaws and archiving our digital past.
David Schwartzberg joined Chet for this week's Chet Chat. David is a specialist in data protection and shared his thoughts on the new File Vault 2 feature in Mac OS X Lion. Dave and Chet also discussed Google+ privacy, Facebook's compromise on facial recognition and the critical vulnerability in Apple's iOS.
In this week's Chet Chat Kris Braun SophosLabs Threat Operations Manager joins Chet to discuss the week's news. Topics include OS X Lion, Oracle patches, Zeus for Android and Secunia's mid-year threat report.
Richard Baldry is Chet's guest on this week's Chet Chat. Chet and Richard talk about Google blocking the .co.cc domain, Patch Tuesday, Apple's JailBreakMe.com patch and the "phone hacking" and malware related to the News of the World scandal.
In this week's Chet Chat Paul Ducklin is Chet's guest as they cover the latest security news. Topics covered include a paper on the Popureb rootkit, the vulnerabilities in Apple's iOS exploited by jailbreakme.com, WordPress 3.2 and the latest Twitter account hacks.
Paul Ducklin joins Chester this week for Chet Chat episode 65. Chet and Paul discuss the impact of the recent FBI arrests of scareware purveyors, the arrest of Ryan Cleary and LulzSec's latest stunts, Trojanized WordPress plugins and the imaginary world of Bitcoin digital currency.
In SSCC episode 64 Chet's guest is the North American Threat Operations Manager for SophosLabs. They discuss the LulzSec DDoS last week, the attack against the IMF, Nissan's Leaf leaking location data and the latest Adobe fixes. Kris also provided advise from SophosLabs on defending against targeted attacks.
In this week's Chet Chat Rich Baldry joins Chet to discuss the future of Mac OS X security. They also discuss the week's news including RSA, Sony, software patches and Facebook's introduction of facial recognition software
Chester Wisniewski and Paul Ducklin discuss this week's news including the latest attacks against Sony, Apple's new malware problem and cloud security.
Chester Wisniewski sits down with one of the most experienced Sophos technical support experts to discuss best practices and how we can use the tools we have to do a better job defending against modern malware.
Chester Wisniewski and Ben Jupp discuss the hype and the truth behind the recent Mac rogue security attacks and discuss Obama's proposed changes to RICO, Square Enix and Sony.
Chet interviews the Manager of SophosLabs US Richard Wang this week. They discuss Sony, bin Laden, LastPass, the upcoming Patch Tuesday and the latest Mac malware scams.
Sophos Security Chet Chat 58 features Paul Ducklin and Chester Wisniewski discussing the week's most pertinent security topics. This week: the Coreflood take-down; password loss at DSLReports; Sony's big data breach; Iran claims a "Stars" virus attack; and Facebook shuts down Ars Technica.
Chester Wisniewski and Paul Ducklin, Head of Technology, Asia Pacific discuss the open letter Naked Security published to Facebook and all the latest from Infosec Europe 2011.
Chester Wisniewski and Michael Argast talk about this week's Patch Tuesday, the Albert Gonzalez appeal and the state of Texas data breach.
Tony Ross joins Chester Wisniewski this week to discuss the latest news on SSL Certificate Authorities ignoring signing guidelines. They also talk about the RSA breach, email best practices, Chrome adding malicious download filtering and more.
Michael Argast joins Chet for a HUGE Chet Chat this week. They primarily cover Facebook's new SSL/anti-likejacking, Comodo SSL hack, Firefox 4 and the SQL injection attacks against MySQL and Sun/Oracle. Extra: Don't miss the blooper of Chet mistakenly calling this Chet Chat 55... That's next week.
Chester Wisniewski and guest Michael Argast discuss this week's security news. They give advice to users of RSA's SecureID tokens post-breach, talk about RIM's advice to disable JavaScript on BlackBerry devices and Google patching Adobe Flash in Chrome before even Adobe has patched it.
Chester Wisniewski and Michael Argast talk about the latest security news related to Twitter's use of HTTPS, Congress killing net neutrality, car hacking, tsunami scams,the Adobe Reader zero day and more.
Michael Argast talks with Chet about Apple's new test release of OS X, codenamed Lion. They also chat about Microsoft begging people to stop using IE6, providing social media access to your employer, the rise in Facebook scams and the recent spat of malware on the Android Market.
Tony Ross joins Chet this week to discuss erasing SSDs, a new banking Trojan and HIPAA - how to protect medical records
Michael Argast and Chet talk about Westboro Church vs. Anonymous, the Canadian Government getting hacked, the latest MS and Java vulnerabilities and more
This week Chet Wisniewski and Paul Ducklin discuss the new Android Trojan Horse and RSA Conference 2011 happenings.
Michael Argast and Chester Wisniewski discuss the weeks security news, including RBS WorldPay hacker pleads guilty, HBGary hack, Patch Tuesday and CanSecWest's Pwn2Own contest.
Chester Wisniewski and Michael Argast discuss the internet situation in Egypt, Anonymous and the arrests by the FBI, the new Microsoft zero day MHTML vulnerability and the standard set of Facebook stories