Graham Cluley: Recent Episodes

None

Computer security news, advice, and opinion

View Details

The UK Government takes aim at IoT devices shipping with weak or default passwords, an identity thief spends two years in jail after being mistaken for the person who stole his name, and are you au fait with the latest scams?All this and much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin.

View Details

A wave of cheap, crude, amateurish ransomware has been spotted on the dark web - and although it may not make as many headlines as LockBit, Rhysida, and BlackSuit, it still presents a serious threat to organizations.Read more in my article on the Tripwire State of Security blog.

View Details

Czech news agency ČTK announced on Tuesday that a hacker had managed to break into its systems and published fake news reports of a plot to murder the president of a neighbouring country.Read more in my article on the Hot for Security blog.

View Details

Leicester City Council suffers a crippling ransomware attack, and a massive data breach, but is it out of the dark yet? And as election fever hits India we take a close eye at deepfakery.All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

The UK's Leicester City Council was thrown into chaos last month when a crippling cyber attack forced it to shut down its IT systems and phone lines.But the ransomware attack also had a more unusual impact...Read more in my article on the Hot for Security blog.

View Details

February's crippling ransomware attack against Change Healthcare, which saw prescription orders delayed across the United States, continues to have serious consequences.Read more in my article on the Hot for Security blog.

View Details

The international hotel chain Omni Hotels & Resorts has confirmed that a cyber attack last month saw it shut down its systems, with hackers stealing personal information about its customers.Read more in my article on the Exponential-E blog.

View Details

Police have successfully infiltrated and disrupted the fraud platform "LabHost", used by more than 2,000 criminals to defraud victims worldwide.Read more in my article on the Tripwire State of Security blog.

View Details

Take That's Gary Barlow chats up a pizza-slinging granny from Essex via Facebook, or does he? And a scam takes a sinister turn - for both the person being scammed and an innocent participant - in Ohio.All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

Law enforcement officers in Zambia have arrested 77 people at a call centre company they allege had employed local school-leavers to engage in scam internet users around the world.Read more in my article on the Hot for Security blog.

View Details

The East Central University (ECU) of Ada, Oklahoma, has revealed that a ransomware gang launched an attack against its systems that left some computers and servers encrypted and may have also seen sensitive information stolen.Read more in my article on the Hot for Security blog.

View Details

Learn more about the DragonForce ransomware - how it came to prominence, and some of the unusual tactics used by the hackers who extort money from companies with it.Read more in my article on the Tripwire State of Security blog.

View Details

If 25 documents stolen is "very serious," I'm not sure the words exist to describe the 1.3 terabytes of data that Leicester City Council now says it has had stolen by hackers.

View Details

MPs aren't just getting excited about an upcoming election, but also the fruity WhatsApp messages they're receiving, can we trust AI with our health, and who on earth is pretending to be a producer for the Drew Barrymore TV show?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by John Hawes.

View Details

Targus, the well-known laptop bag and case manufacturer, has been hit by a cyber attack that has interrupted its normal business operations.Read more in my article on the Hot for Security blog.

View Details

Two China-based Android app developers are being sued by Google for an alleged scam targeting 100,000 users worldwide through fake cryptocurrency and other investment apps.Read more in my article on the Hot for Security blog.

View Details

Google has issued a security advisory to owners of its Android Pixel smartphones, warning that it has discovered someone has been targeting some devices to bypass their built-in security.Read more in my article on the Tripwire State of Security blog.

View Details

New research has found that ransomware remediation costs can explode when backups have been compromised by malicious hackers - with overall recovery costs eight times higher than for those whose backups are not impacted.Read more in my article on th Exponential-e blog.

View Details

Google says it is deleting the your Google Chrome Incognito private-browsing data that it should never have collected anyway. Can a zero-risk millionaire-making bot be trusted? And what countries are banned from buying your sensitive data?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford.

View Details

Amazon failed to deliver an iPhone 15 to my home, but claims I am not eligible for a refund.Is there anybody at Amazon who still cares about looking after their legitimate honest customers?

View Details

The UK's Office for Nuclear Regulation (ONR) has started legal action against the controversial Sellafield nuclear waste facility due to years of alleged cybersecurity breaches.Read more in my article on the Hot for Security blog.

View Details

Deepfakes are being used for good (perhaps), common usernames could pose a security threat, and someone has paid a $500,000 fee... just to send $1,865.

Oh, and our guest mentions Mr Blobby (to the horror of the show's hosts...)

All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.

View Details

State-sponsored hackers, backed by the regime in North Korea, are believed to be using zero-day exploits to target cybersecurity researchers working in the field of vulnerability research and development.

Read more in my article on the Hot for Security blog.

View Details

A Texas court has heard how last month a gang of men used a Raspberry Pi device to steal thousands of dollars from ATMs.Read more in my article on the Tripwire State of Security blog.

View Details

AI news is bad news, an online service to catch your cheating partner, and an IoT-enabled dick cage fails to keep a grip on its own security.

All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.

Plus don't miss our featured interview with Alex Lawrence, principal security architect at Sysdig.

View Details

The ShinyHunters hacking group has claimed that in the last couple of months it has stolen more than 30 million customer order records from Pizza Hut Australia, alongside information on more than one million customers.Read more in my article on the Hot for Security blog.

View Details

An attack by the notorious LockBit ransomware gang stole 10 GB of data from a company that provides high-security fencing for military bases.

View Details

Graham Cluley Security News is sponsored this week by the folks at Deep Instinct. Thanks to the great team there for their support! Deep Instinct protects the data of the world’s largest brands by delivering on the promise of threat prevention with the only cybersecurity platform fully powered by Deep Learning.​ We have pioneered predictive … Continue reading "Deep Instinct takes a prevention-first approach to stopping ransomware and other malware using deep learning"

View Details

Freecycle, an online community that encourages sharing unwanted items with eachother than chucking them in the bin or taking them to landfill, has told users to change their passwords after it suffered a data breach.

View Details

Fashion chain Forever 21 has suffered what it has described as a "data security incident" that saw a hacker gain access to its systems for months, and exposed the personal details of 539,207 current and former employees.Read more in my article on the Hot for Security blog.

View Details

Seized cryptocurrency is stolen from the DEA, blue-ticks are being exploited, a bath full of dollar bills, the comfort offered by an ostrich’s head, and how Graham is refusing to call Twitter “X”.

All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC), the agency responsible for the nation's defences against cyber attacks, has itself been hacked.

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at PlexTrac. Thanks to the great team there for their support! If you are investing in solutions for continuous assessment and validation or breach and attack simulation, you know that managing the data and remediation efforts necessary to make real progress can be overwhelming. … Continue reading "Ready to enhance your continuous assessment efforts? Meet PlexTrac"

View Details

A London court has found two British teens responsible for a spree of high profile hacks, including one that saw the leaking of source code and videos of Rockstar Games's as-yet unreleased "Grand Theft Auto 6."

Read more in my article on the Hot for Security blog.

View Details

After a series of high-profile cryptocurrency hacks, the state-sponsored North Korean Lazarus Group is poised to cash out millions of dollars.

Read more in my article on the Tripwire State of Security blog.

View Details

Surely you should be able to order pizza without being pestered for sex? And Carole takes a look at the what and why of wearables...

All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

Surely you should be able to order pizza without being pestered for sex or a date?

So, how come so many young people are claiming that they are being hassled after ordering an online delivery?

Read more in my article on the Hot for Security blog.

View Details

The BlackCat ransomware gang has claimed credit for a cybersecurity attack against Japanese watchmaker Seiko.

BlackCat (also known as ALPHAV) posted on its dark web leak site what it claims are files stolen from Seiko's servers.

View Details

Security researchers have identified that a widespread LinkedIn hacking campaign has seen many users locked out of their accounts worldwide.

Read more in my article on the Tripwire State of Security blog.

View Details

Are you the kind of person who runs the beta-test versions of mobile apps before they are officially released? If so, the FBI is warning you to be on your guard.

Read more in my article on the Hot for Security blog.

View Details

AI chatbots are under fire in Las Vegas, the secrets of hackers’ passwords are put under the microscope, and Graham reveals (possibly) the greatest TV programme of all time.

All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

Someone clearly isn't very impressed with Vladimir Putin, as the Russian economy continues to tank in the wake of sanctions.

View Details

The LockBit ransomware gang may be having more than a few headaches right now.

According to a researcher who spent a year undercover gathering intelligence on the LockBit group, the ransomware gang is trying to cover up "the fact it often cannot consistently publish stolen data."

View Details

'Ello ello ello. What's all this then?

Just days after it was learned that the police had exposed the details of their 10,000 staff in Northern Ireland, another force has admitted to an embarrassing breach of sensitive data.

Read more in my article on the Hot for Security blog.

View Details

Security researchers have demonstrated how they were able to exploit a flaw which allowed them to hack the card-shuffling devices used in casinos and poker rooms.

Read more in my article on the Hot for Security blog.

View Details

I doubt there will be many people shedding tears at the news that a stalkerware company has announced it is permanently ceasing operations at the end of this month - after it suffered a devastating data breach.

Read more in my article on the Hot for Security blog.

View Details

Earlier this week, the details of all 10,000 staff at the Police Service of Northern Ireland (PSNI) were exposed after a spreadsheet containing the data was mistakenly published online.

View Details

Rhysida is a Windows-based ransomware operation that has come to prominence since May 2023, after being linked to a series of high profile cyber attacks in Western Europe, North and South America, and Australia.

Learn more in my article on the Tripwire State of Security blog.

View Details

Razzlekhan, the self-proclaimed Crocodile of Wall Street, pleads guilty to the biggest crypto laundering scheme in history, and just how safe are you typing while on a Zoom call?

Meanwhile, Graham rants about public EV chargers.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

Graham Cluley Security News is sponsored this week by the folks at Jotform. Thanks to the great team there for their support! What is form encryption, and why is it important? Whether you’re a pro with forms or just a newbie, it might be helpful to get an understanding of form encryption and why E2EE … Continue reading "Keep your sensitive data secure by using Encrypted Forms 2.0 from Jotform"

View Details

Newly-released research reveals the eye-watering costs that the manufacturing sector has suffered in recent years at the hands of ransomware.

Read more in my article on the Tripwire State of Security blog.

View Details

Carole takes us into the sinister side of Barbie, while Graham describes a stalkerware operation that has been spilling its secrets.

All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

Critical security vulnerabilities in a WordPress plugin used on around 900,000 websites, allow malicious hackers to steal sensitive information entered on forms.

Read more in my article on the Hot for Security blog.

View Details

After a ransomware attack which saw the personal information of 28,000 individuals stolen by hackers, Hawaii Community College has confirmed that it has paid a ransom.

View Details

CardioComm, a Canadian company which provides heart-monitoring technology to hospitals and consumers, has revealed that it has been forced to take its systems offline following a cyberattack.

Read more in my article on the Hot for Security blog.

View Details

New rules requiring publicly-listed firms to disclose serious cybersecurity incidents within four days have been adopted by the US Securities and Exchange Commission (SEC).

The tough new rules, although undoubtedly well-intentioned, are likely to leave some firms angry that they being "micromanaged" and - it is argued - could even assist attackers.

Read more in my article on the Tripwire State of Security blog.

View Details

Dr 90210 finds himself in a sticky situation after his patients' plastic surgery photos AND more end up in the hands of hackers, emails to the US military end up in the wrong hands, and script kiddies salivate at the thought of Business Email Compromise powered by generative AI.

All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by T-Minus Space Daily’s Maria Varmazis.

View Details

Yamaha Corporation, the world's largest producer of musical equipment, has confirmed that has suffered a "cybersecurity incident" during which hackers gained unauthorised access to its systems, and stole data.

Read more in my article on the Hot for Security blog.

View Details

Fake blockchain games, that are being actively promoted by cybercriminals on social media, are actually designed to infect the computers of unsuspecting Mac users with cryptocurrency-stealing malware.

View Details

Graham Cluley Security News is sponsored this week by the folks at PlexTrac. Thanks to the great team there for their support! Reports are the critical deliverables that make pentest results actionable, but do they have to be so painful to prepare? Not anymore. Check out our guide to writing a killer pentest report. And … Continue reading "How to write a killer pentest report"

View Details

Some employees at Google will have internet access from their desktop PCs significantly restricted, with only internal web-based tools and Google-owned sites such as Google Drive, Google Maps, and Gmail accessible.

But will such an approach protect the tech giant from attacks?

Read more in my article on the Hot for Security blog.

View Details

If you thought hackers might be causing your company a few headaches, pity the folks at Estée Lauder.

Two different ransomware groups have listed the cosmetics maker on their leak sites on the dark web, as a result of seemingly separate attacks.

Read more in my article on the Hot for Security blog.

View Details

The FBI warns that tech support scammers are increasingly telling their victims to send actual cash, concealed in newspaper or a magazine, rather than wiring funds.

But why?

Read more in my article on the Tripwire State of Security blog.

View Details

Former Prime Minister Boris Johnson wants to hand over his WhatsApp messages - or does he? And a couple of fun-loving girls from Aberdeen have come up with a sinister twist on sextortion scams.

All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley (from a mystery location) and Carole Theriault.

View Details

A federal grand jury has indicted a former employee of a contractor operating a California town's wastewater treatment facility, alleging that he remotely turned off critical systems and could have endangered public health and safety.

Read more in my article on the Tripwire State of Security blog.

View Details

A London court has heard that two British teens hacked and blackmailed a series of companies, causing millions of dollars worth of damage.

Read more in my article on the Hot for Security blog.

View Details

Going for a jog can be bad for your privacy (but even worse for your health), and Britain's consumer finance champion finds his face is being faked.

All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

A computer security engineer has been charged in connection with a multi-million dollar hack of a cryptocurrency exchange.

Read more in my article on the Hot for Security blog.

View Details

A British IT worker who exploited a ransomware attack against the company he worked for, in an attempt to extort money from them for himself, has been sentenced to jail for three years and seven months.

View Details

There's good news for any business that has fallen victim to the Akira ransomware.

Security researchers have developed a free decryption tool for files that have been encrypted since the Akira ransomware first emerged in March 2023.

Read more in my article on the Tripwire State of Security blog.

View Details

Just how much do porn websites know about your sexual peccadillos? How are Barbie dolls involved in identity scams? And would you trust a completely free telly?

Oh, and Graham has some opinions to share about "Indiana Jones and the Dial of Destiny".

All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Matt Davey from the "Random but Memorable" podcast.

View Details

Staff at Dublin Airport have been warned that their personal data has fallen into the hands of hackers, following a data breach at a third-party service provider.

Read more in my article on the Hot for Security blog.

View Details

Suncor, one of the largest energy companies in North America, has suffered a cyber attack that left Canadian motorists unable to make gas station purchases with payment cards, and even disabled car washes.

Read more in my article on the Hot for Security blog.

View Details

UPS delivers some smishing advice (but have they kept something under wraps?), we ask ChatGPT to take a long hard look at itself, and we debate what the penalty should be for taking national secrets home with you.

All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown’s sole founder Thom Langford.

View Details

Back in 2020, law enforcement agents across Europe had a major breakthrough in their fight against organised crime. They managed to crack into EncroChat - a secure encrypted messaging service which ran on modified Android phones, that promised "worry-free secure communications".

But investigators managed to gain full control of EncroChat's infrastructure, and could read users' supposedly-encrypted messages in real-time.

View Details

Graham Cluley Security News is sponsored this week by the folks at Infoblox. Thanks to the great team there for their support! At Infoblox, we know that the most important thing to prevent potential attacks against DNS is to understand it and get the right tools and techniques to defend DNS infrastructure. Assembled by the … Continue reading "DNS can speed up response to threats and make security operations more productive"

View Details

The city of Fort Worth in Texas announced on Saturday that it had suffered a security breach that saw hackers claim to have gained unauthorised access to data.

But it doesn't appear, for now at least, that the hackers are attempting to extort a ransom from the city...

Read more in my article on the Hot for Security blog.

View Details

It wasn't a great weekend for video game fans, as players of Diablo IV multiplayer role-playing game were greeted with an error message as it tried to connect to the servers of developer Blizzard.

View Details

The NSA has publsihed a guide about how to mitigate against attacks involving the BlackLotus bootkit malware, amid fears that system administrators may not be adequately protecting against the threat.

Read more in my article on the Tripwire State of Security blog.

View Details

If you have an Apple computer, watch, or smartphone you have hopefully already received a notification that you should install an update to your operating system.

And yes, you really should update your devices.

View Details

Fancy $10 million? Of course you do!

Well, all you have to do is provide information that helps identify or locate members of the notorious Cl0p ransomware gang.

View Details

Patients of a Beverly Hills plastic surgery clinic face the potential horror of having highly sensitive images of their bodies leaked onto the internet by hackers.

Read more in my article on the Hot for Security blog.

View Details

There's some funny business going on on Google, and Zuckerberg's $14 billion bet on the metaverse is beginning to look a little childish...

All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

View Details

Snack giant Mondelez is warning past and present employees that their personal information may now be in the hands of hackers following a data breach at a third-party firm.

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Uptycs. Thanks to the great team there for their support! Your developer’s laptop is just a hop away from cloud infrastructure. Attackers don’t think in silos, so why would you have siloed solutions protecting public cloud, private cloud, containers, laptops, and servers? Uptycs … Continue reading "Ensure the security and reliability of your applications at every stage, from development to production, with Uptycs"

View Details

In the 12 months running up to May 2023, the login credentials of over 100,000 hacked ChatGPT accounts found their way onto dark web marketplaces.

Read more in my article on the Hot for Security blog.

View Details

There are shocking revelations about a US Government data suck-up, historic security breaches at Windsor Castle, and the MOVEit hack causes consternation.

All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.

View Details

Earlier this year I was invited by Vodafone to appear on an episode of "Learning Curve", a series for founders, business leaders and - indeed - those who wish to be a business leader.

You won't be surprised to hear that the topic I was being asked about was cybersecurity

View Details

The UK's broadcasting regulator, Ofcom, has confirmed that it is amongst the organisations whose data has been stolen as a result of the massive MOVEit supply-chain cyber attack.

Read more in my article on the Hot for Security blog.

View Details

More than ten years after the hack of the now-defunct Mt. Gox cryptocurrency exchange, the US Department of Justice says it has identified and charged two men it alleges stole customers' funds and the exchange's private keys.

Read more in my article on the Tripwire State of Security blog.

View Details

UK law firm Knights certainly has an interesting way of keeping its staff happy.

View Details

Barracuda Networks is taking the unusual step of telling its customers to physically remove and decommission its hardware.

View Details

If you, or your kids, are fans of Minecraft - you might be wise to not download any new mods of plugins for a while.

Read more in my article on the Tripwire State of Security blog.

View Details

Australia's signal intelligence agency calls upon an Eighties popstar to fight terrorism, and a simple act of kindness leads to a woman being scammed for thousands.

All this and much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.

Plus don't miss our featured interview with Max Power of Bitwarden.

View Details

TikTok is making headlines again, and - as usual - it's not for a good reason.

Read more in my article on the Hot for Security blog.

View Details

The Russia-linked cybercrime gang thought to be behind a hack that has impacted companies around the world has posted a message to its corporate victims.

In short, firms affected by the MOVEit hack are being told to congtact the Cl0p ransomware group before June 14, or face the consequences.

View Details

North Korean state-sponsored hackers are targeting think tanks, research centres, media organisations, and academics in the United States and South Korea to gather intelligence.Read more in my article on the Hot for Security blog.

View Details

Staff at the BBC have been warned that their personal data may now be in the hands of cybercriminals, following the exploitation of a vulnerability in a software tool used by the company that manages their payroll.

View Details

Twitter awarded "gold checkmark" to unofficial Disney Twitter account which posted racial slurs.Is it any wonder that Twitter's ad sales in the United Sales have plunged 59% in the past year?

View Details

Jetpack. an extremely popular WordPress plugin that provides a variety of functions including security features for around five million websites, has received a critical security update following the discovery of a bug that has lurked unnoticed since 2012.Read more in my article on the Tripwire State of Security blog.

View Details

height="315" class="aligncenter size-full wp-image-292324" />ChatGPT hallucinations cause turbulence in court, a riot in Wales may have been ignited on social media, and do you think .MOV is a good top-level domain for "a website that moves you"?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Plus don't miss our featured interview with David Ahn of Centripetal.

View Details

RaidForums, the notorious hacking and data leak forum seized and shut down by the authorities back in April 2022, is - perhaps surprisingly - at the centre of another cybersecurity breach.

View Details

Scandinavian Airlines (SAS) has received a US $3 million ransom demand following a prolonged campaign of distributed denial-of-service (DDoS) attacks against its online services.Read more in my article on the Hot for Security blog.

View Details

The BBC reports that the Venezuelan government is paying people to tweet in support of it, in an attempt to drown out the noise of its critics.

View Details

I know this will come as a shock to many of you, but scammers have once again succeeded in stealing a lot of money from cryptocurrency investors.Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at PureDome. Thanks to the great team there for their support! PureDome offers a secure, quick, reliable solution that enhances and safeguards business network security. With seamless deployment, you can effortlessly expand your corporate network without sacrificing performance. By consolidating critical aspects of user … Continue reading "Protect your business network with PureDome"

View Details

Bad enough for your company to be held to ransom after a cyber attack.Worse still to then have one of your own employees exploit the attack in an attempt to steal the ransom for themselves.Read more in my article on the Tripwire State of Security blog.

View Details

Graham Cluley Security News is sponsored this week by the fab folks at Kolide. Thanks to the great team there for their support! Right now, “Zero Trust” is in serious danger of becoming an empty buzzword. The problem isn’t just that marketers have slapped the Zero Trust label on everything short of breakfast cereal–it’s that … Continue reading "Can zero trust be saved?"

View Details

I was surprised to receive an email this week telling me that I had renewed my annual subscription for McAfee virus protection.Would you, or a member of your family, have fallen for this scam?

View Details

13 years jail for spoofing scammer, a rogue IT security expert’s Bitcoin blackmail goes wrong, and Facebook’s eyewatering GDPR fine may be only the beginning of its problems.All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by the Imposter Syndrome Network podcast’s Zoë Rose.

View Details

The Indian manufacturing plant responsible for manufacturing Suzuki motorcycles has been forced to shut down following a cyber attack, with the loss of an estimated 20,000 vehicles.Read more in my article on the Hot for Security blog.

View Details

Since earlier this month some owners of HP OfficeJet printers have been reporting that they are faced with a blue screen error message, and a bricked device.Read more in my article on the Hot for Security blog.

View Details

Personal details of more than 100,000 pension holders may have been stolen by the hackers.And that's just the tip of the iceberg...

View Details

A joint alert has been issued by US government agencies, advising organisations of the steps they should take to mitigate the threat posed by BianLian ransomware attacks.Read more in my article on the Tripwire State of Security blog.

View Details

Personal information is going for a song, and the banks want social media sites to pay when their users get scammed.All this and much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

There's good news if you're plagued by shared Google Drive files from strangers. Google Drive is getting a spam folder.

View Details

Google has announced a new policy on dealing with inactive accounts - and it's an important read for anyone who doesn't regularly login.Read more in my article on the Hot for Security blog.

View Details

Twitter's new "encrypted DM" feature is a costly (and weaker) alternative to proper end-to-end encrypted messages.

View Details

Graham Cluley Security News is sponsored this week by the folks at Expel. Thanks to the great team there for their support! Expel wanted to find out what cybersecurity issues were most important to organisations in the United Kingdom, so it surveyed 500 IT decision-makers (ITDMs) to get a better sense for the state of … Continue reading "Expel’s UK cybersecurity landscape report sheds light on the challenges facing organisations"

View Details

Cybercriminals have developed a new malware threat which can steal highly sensitive data from the Mac computers it infects.

View Details

es, you should be worried about the threat posed by external hackers. But also consider the internal threat posed by insiders and rogue employees - the people you have entrusted to act responsibly with the data of your company and your customers.Read more in my article on the Hot for Security blog.

View Details

Akira is a new family of ransomware, first used in cybercrime attacks in March 2023.Read more about the threat in my article on the Tripwire State of Security blog.

View Details

After covering up a data breach that impacted the personal records of 57 million Uber passengers and drivers, the company's former Chief Security Officer has been found guilty and sentenced by a US federal judge.Read more in my article on the Hot for Security blog.

View Details

Millions of WordPress-powered websites are using the Advanced Custom Fields and Advanced Custom Fields Pro plugins, which security researchers say have been vulnerable to cross-site scripting (XSS) attacks.

View Details

Cinema chain Odeon may have shared more information than it intended in the release notes accompanying its latest iOS app update.

View Details

Businesses should patch their TP-Link routers as soon as possible, after the revelation that a legendary IoT botnet is targeting them for recruitment.Read more in my article on the Tripwire State of Security blog.

View Details

Apple and Google have announced that they are teaming up in order to combat the safety risks associated with AirTags and other tracking devices.Read more in my article on the Hot for Security blog.

View Details

Two unsavoury websites suffer from a worrying leak, scientists are going animal crackers over AI, and the BBC is intercepting scammers’ live phone calls with victims. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week … Continue reading "Smashing Security podcast #320: City Jerks, AI animals, and is the BBC hacking again?"

View Details

Graham Cluley Security News is sponsored this week by the folks at Intego. Thanks to the great team there for their support! Established in 1997, Intego is the leading company for Mac antivirus, providing powerful and reliable protection against malware, viruses, and other online threats. Intego offers a wide range of comprehensive security products designed … Continue reading "Fortify your Mac with Intego – the award-winning Mac antivirus"

View Details

Students and teachers at the Minneapolis Public School (MPS) District, which suffered a huge ransomware attack< at the end of February, have had highly sensitive information about themselves published on the web, including allegations of abuse by teachers and psychological reports.Read more in my article on the Hot for Security blog.

View Details

Boffins at McAfee have identified 38 Android apps in the Google Play store that unashamedly rip off the ever-popular gaming sensation Minecraft, but are actually designed to stealthily earn advertising revenue.

View Details

Is it possible ransomware gangs actually do have a heart?Read more in my article on the Hot for Security blog.

View Details

Wednesday was the official Independence Day of Israel, and the event was "celebrated" in typical style by malicious hackers.Read more in my article on the Hot for Security blog.

View Details

Iranian state-sponsored hacking group Charming Kitten has been named as the group responsible for a new wave of attacks targeting critical infrastructure in the United States and elsewhere.Read more in my article on the Tripwire State of Security blog.

View Details

A boss is bitten in the bottom after being struck by one of the worst crimes in Finnish history, Strava’s privacy isn’t so private, and a private investigator uncovers some TikTok tall tales. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham … Continue reading "Smashing Security podcast #319: The CEO who also ran IT, Strava strife, and TikTok tall tales"

View Details

Eurocontrol, the European air traffic control agency, has revealed that it has been under cyber attack for the last week, and says that pro-Russian hackers have claimed responsibility for the disruption.When you first see the headline in the likes of the Wall Street Journal, it's a scary thing to read. But dig a little deeper, and you realise that the err.. sky is not falling.Read more in my article on the Hot for Security blog.

View Details

Were you a US-based Facebook user between May 24 2007 and December 22 2022?If so, I've got some good news for you.Read more in my article on the Hot for Security blog.

View Details

Three Nigerian nationals face charges in a US federal court related to a business email compromise (BEC) scam that is said to have stolen more than US $6 million from victims.Read more in my article on the Tripwire State of Security blog.

View Details

In the last couple of days it has become clear that the notorious LockBit ransomware gang has been exploring creating what could become a big headache for users of Mac computers.

View Details

I'm still encountering people who, even after all these years, believe that their Apple Mac computers are somehow magically invulnerable to ever being infected by malware.Maybe details of this new Mac malware will change their mind...

View Details

A Finnish court has given the former CEO of a chain of psychotherapy clinics a suspended jail sentence after failing to adequately protect highly sensitive notes of patients' therapy sessions from falling into the hands of blackmailing hackers.Read more in my article on the Hot for Security blog.

View Details

Multinational payment processing firm Nexway has been rapped across the knuckles by the US authorities, who claim that the firm knowingly processed fraudulent credit card payments on behalf of tech support scammers.Read more in my article on the Tripwire State of Security blog.

View Details

Graham wonders what would happen if his bouncing buttocks were captured on camera by a Tesla employee, and we take a look at canny scams connected to China's Operation Fox Hunt.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

The emergency ditching of an Australian military helicopter in the water just off a beach in New South Wales, has been blamed on the failure to apply a software patch.Read more in my article on the Hot for Security blog.

View Details

Accountants are being warned to be on their guard from hackers, as cybercriminals exploit the rush to prepare tax returns for clients before the deadline of US Tax Day.Read more in my article on the Tripwire State of Security blog.

View Details

The US Department of Justice has arrested a member of the US Air Force National Guard in connection with a high profile leak of classified Pentagon documents.Here are my thoughts...

View Details

Everyone's talking juice-jacking - but has anyone ever been juice-jacked? Uber suffers yet another data breach, but it hasn't been hacked. And Carole hosts the "AI-a-go-go or a no-no?" quiz for Dave and Graham.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.

View Details

Travellers are being told to be wary when plugging their smartphones and laptops into USB chargers.But has anyone ever actually been juice-jacked in the real world?

View Details

A pro-Russian blogger who raised $25,000 for drones to assist Russian troops fighting in Ukraine, has received a huge delivery of sex toys instead.Read more in my article on the Hot for Security blog.

View Details

On Tuesday 11 April, I'll be joined by the CISOs of security firms Wiz, Rubrik, Noname, and Abnormal, for a friendly chat about how they protect their organisations from the huge number of threats targeting them.I hope to see some of you there!

View Details

Hacker can remotely open or close garage doors, seize control of alarms, and switch on (or switch off) customers' "smart" plugs due to vulnerabilities in Nexx products.

View Details

An Elon Musk-worshipping college principal gets schooled, and rapper Afroman turns the tables after armed police raid his house.All this and much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

My guess is that if you stumbled across a website that called itself "Hack the Pentagon" and was decorated with a grisly-looking skull, you would probably think that you might be somewhere less than legitimate.After all, normally if you hacked The Pentagon you would find yourself in heaps of trouble.Read more in my article on the Hot for Security blog.

View Details

Malware, disguised as copies of Tor, has stolen approximately US $400,000 worth of cryptocurrency from almost 16,000 users worldwide.

View Details

31-year-old Solomon Ekunke Okpe, of Lagos, was a member of a gang that devised and executed a variety of scams - including business email compromise (BEC), romance scams, working-from-home scams, and more - between December 2011 and January 2017.Read more in my article on the Hot for Security blog.

View Details

A cryptocurrency hack leads us down a mazze of twisty little passages, Joe Biden's commercial spyware bill, and Utah gets tough on social media sites.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson.

View Details

There's bad news if you're someone who is keen to launch a Distributed Denial-of-Service (DDoS) attack to boot a website off the internet, but don't have the know-how to do it yourself.Rather than hiring the help of cybercriminals to bombard a site with unwanted traffic or kick rivals out of a video game, you might be actually handing your details straight over to the police.Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Right now, “Zero Trust” is in serious danger of becoming an empty buzzword. The problem isn’t just that marketers have slapped the Zero Trust label on everything short of breakfast cereal–it’s that for … Continue reading "Can zero trust be saved?"

View Details

If you were sent a USB stick anonymously through the post, would you plug it into your computer?Perhaps you'll think twice when you hear what happened to these Ecuadorian journalists.Read more in my article on the Hot for Security blog.

View Details

A new report from ENISA, the European Union Agency for Cybersecurity, looking at cyberattacks targeting the European transport network over a period of almost two years, has identified that ransomware has become the prominent threat.Read more in my article on the Tripwire State of Security blog.

View Details

The world has gone ChatGPT bonkers.Which makes it an effective lure for cybercriminals who may want to break into accounts...

View Details

It could be a case of aCropalypse now for Google Pixel users, there’s a warning for house buyers, and just why is TikTok being singled out for privacy concerns?All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Thom Langford.

View Details

Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! What is one of the leading causes of breaches in the cloud? OMG, it’s still phishing! It’s no wonder CISOs push zero trust as a top priority. Identities are a top cloud target. … Continue reading "The hidden danger to zero trust: Excessive cloud permissions"

View Details

Have you ever shared a photograph where you've redacted some sensitive information?Perhaps you've cropped out part of the image you didn't want others to see?Well, users of Google's Pixel Android smartphone might be alarmed to learn that pictures they've shared in the past may have been less discreet than they imagined.Read more in my article on the Hot for Security blog.

View Details

Security researchers have released a new decryption tool which should come to the rescue of some victims of a modified version of the Conti ransomware, helping them to recover their encrypted data for free.Read more in my article on the Tripwire State of Security blog.

View Details

Well, this isn’t good.Google has issued a warning that some Android phones can be hacked remotely, without the intended victim having to click on anything.

View Details

The twisted tale of the two Teslas, and a deepfake sandwich.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

In its latest Patch Tuesday bundle of security fixes, Microsoft has patched a security flaw that was being used by the Magniber cybercrime gang to help them infect computers with ransomware.Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! Attacks targeting the software supply chain are on the rise and splashed across the news. SolarWinds raised awareness about the risk. More recent events, like the Federal Civilian Executive Branch (FCEB) agency breach, … Continue reading "Software supply chain attacks are on the rise — are you at risk?"

View Details

A Ukrainian video game developer has revealed that a hacker has leaked development material stolen from the company's systems, and is threatening to release tens of gigabytes more if their unorthodox ransom demands are not met.

View Details

The latest annual FBI report on the state of cybercrime has shown a massive increase in the amount of money stolen through investment scams.Read more in my article on the Hot for Security blog.

View Details

The boss of WhatsApp, the most popular messaging platform in the UK, says that it will not remove end-to-end encryption from the app to comply with requirements set out in the UK government's online safety bill.Learn more in my article on the Hot for Security blog.

View Details

Torrents on The Pirate Bay which claim to contain Final Cut Pro are instead being used to distribute cryptojacking malware to Macs.

View Details

The US Transportation and Security Administration (TSA) has issued new requirements for airport and aircraft operators who, they say, are facing a "persistent cybersecurity threat."Read more in my article on the Tripwire State of Security blog.

View Details

Scammers get pwned by a Canadian granny! Don't be seduced in a bar by an iPhone thief! And will the US Marshals be able to track down the villains who stole their data?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.Plus don’t miss our featured interview with Jason Meller of Kolide.

View Details

Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! This move to the cloud has made it easier to scale up applications when they need to grow. However, there is a corollary to this: Budgeting! Chances are, you’re probably overspending. Estimating how … Continue reading "Study reveals companies are wasting millions on unused Kubernetes resources"

View Details

A notorious ransomware gang has claimed responsibility for a cyber attack against Vesuvius, the London Stock Exchange-listed molten metal flow engineering company.

View Details

Willie Sutton, the criminal who became legendary for stealing from banks during a forty year career, was once asked, "Why do you keep robbing banks?"His answer? "Because that's where the money is."However, today there's a better target for robbers today than banks, which are typically well-defended against theft...Cryptocurrency wallets.Read more in my article on the Tripwire State of Security blog.

View Details

British high street giant WH Smith has revealed that it has suffered a "cybersecurity incident," which has seen hackers gain unauthorised access to its systems, and steal data including information related to current and former employees.

View Details

Following what it called a "cybersecurity incident" three weeks ago, Canadian bookstore chain Indigo has not only confirmed that it was hit by a ransomware attack, but also that data related to current and former employees was stolen by hackers.Read more in my article on the Hot for Security blog.

View Details

Who has been warning Italian criminals that their phones are wiretapped? Can you trust your voice to protect your bank account? And why is TikTok being singled out by investigators?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis.

View Details

Three men have been arrested by Dutch police in connection with ransomware attacks that blackmailed thousands of companies. Amongst them? An ethical hacker.Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! The unmanageable number of vulnerabilities in the cloud is the worst-kept secret. The Sysdig 2023 Cloud-Native Security and Usage report found that 87% of container images have high or critical vulnerabilities! Surely not … Continue reading "The cloud’s worst kept secret? Vulnerabilities"

View Details

Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Here’s an uncomfortable fact: at most companies, employees can download sensitive company data onto any device, keep it there forever, and never even know that they’re doing something wrong. Kolide’s new report, “The … Continue reading "That ticking noise is your end users’ laptops"

View Details

Malicious hackers are taking advantage of people searching the internet for free access to ChatGPT in order to direct them to malware and phishing sites.Read more in my article on the Hot for Security blog.

View Details

Earlier this month a cyber attack on food produce giant Dole caused the firm to shut down its production plants across North America for a period of time, and halt shipments to stores.Read more in my article on the Hot for Security blog.

View Details

Boyfriends who are bots, Facebook’s checkmark charge, Twitter Blue, and Will Ferrell’s taunt of football fans…All this and more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

Russian media has blamed hackers after commercial radio stations in the country broadcast bogus warnings about air raids and missile strikes, telling listeners to head to shelters.

View Details

A ransomware outfit is advising its victims to secretly tell them how much insurance they have, so their extortion demands will be met.Read more in my article on the Tripwire State of Security blog.

View Details

Many Twitter users have been presented with a message telling them that SMS-based two-factor authentication (2FA) will be removed next month.According to Twitter, only subscribers to its premium Twitter Blue service will be able to use text message-based 2FA to protect their accounts.Is that such a good idea?

View Details

A group calling itself "Anonymous Sudan" has claimed responsibility for a cyber attack which knocked the website of Scandinavian Airlines (SAS) offline earlier this week, and left customer data exposed.Read more in my article on the Hot for Security blog.

View Details

The owner of a Russian penetration-testing company has been found guilty of being part of an elaborate scheme that netted $90 million after stealing SEC earning reports.For nearly three years, 42-year-old Vladislav Klyushin - the owner of Moscow-based cybersecurity firm M-13 - and his co-conspirators had hacked into two US-based filing agents used by publicly-traded American companies to file earning reports to the Securities and Exchange Commission.Read more in my article on the Tripwire State of Security blog.

View Details

AI-generated voices are weaponised by online trolls, how ChatGPT reflects who we are as a society, and social media is in the firing line again. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by … Continue reading "Smashing Security podcast #309: Synthetic voices, ChatGPT reflections, and social skirmishes"

View Details

Towards the end of last year, malicious hackers broke into the systems of Pepsi Bottling Ventures, the largest privately-owned bottler of Pepsi-Cola beverages in the USA, and installed malware.For almost the month the malware secretly exfiltrated personally identifiable information (PII) from the company's network.Read more in my article on the Hot for Security blog.

View Details

A ransomware attack has again put the personal information of innocent parties at risk after it was revealed that a data breach has potentially exposed the medical records of more than three million people.Read more in my article on the Hot for Security blog.

View Details

A Dallas state agency has admitted to paying $170,000 to hackers after it suffered an attack from the Royal ransomware group.Read more in my article on the Hot for Security blog.

View Details

Want to sell some cocaine, ecstasy (MDMA), crystal meth, or magic mushrooms?Twitter could be the place for you. And the site isn't going to do anything to shut down your account.

View Details

Perhaps the biggest punishment of all will be Dennis Su's name being forever associated with an extraordinarily inept and cack-handed attempt to frighten people out of money.

View Details

When Ubiquiti suffered a hack the world assumed it was just a regular security breach, but the truth was much stranger... why are police happy that criminals keep using end-to-end encrypted messaging systems… and why is the Apple Watch being accused of crying wolf?All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Plus don't miss our featured interview with SecurEnvoy's Chris Martin.

View Details

Graham Cluley Security News is sponsored this week by the folks at Incogni. Thanks to the great team there for their support! Cybercrimes happen much more often than you might think and affect a growing amount of people. With crimes such as identity theft and various other scams, being mindful of your digital footprint is … Continue reading "How to remove yourself from the internet and from people search sites"

View Details

A former software engineer at Ubiquiti Networks has pleaded guilty to stealing gigabytes of data from the firm, attempting to extort millions of dollars, and damaging the company's reputation in the media.Read more in my article on the Hot for Security blog.

View Details

Vesuvius, the London Stock Exchange-listed molten metal flow engineering company, says it has shut down some of its IT systems after being hit by a cyber attack.

View Details

UK banking group TSB is calling on social networks and dating apps to better protect their users from fake profiles, following an alarming spike in romance fraud.Read more in my article on the Tripwire State of Security blog.

View Details

Could a senior Latvian politician really be responsible for scamming hundreds of "mothers-of-two" in the UK? (Probably not, despite Graham's theories...) And should we be getting worried about the AI wonder that is ChatGPT?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

Graham Cluley Security News is sponsored this week by the folks at Edgescan. Thanks to the great team there for their support! Edgescan simplifies Vulnerability Management (VM) by delivering a single full-stack SaaS solution integrated with world-class security professionals. Edgescan helps enterprise companies consolidate managing multiple point scanning tools for each layer of the attack … Continue reading "Take a tour of the Edgescan Cybersecurity Platform"

View Details

Planet Ice, which operates 14 ice rinks up and down the UK, has revealed that criminal hackers managed to break into its systems and steal the personal details of over 240,000 customers.Read more in my article on the Hot for Security blog.

View Details

The Kremlin-backed Gamaredon hacking group is being blamed for an attempted phishing attack against the Latvian Ministry of Defence.Read more in my article on the Hot for Security blog.

View Details

GoTo says that hackers stole its customers' "encrypted backups." But they also say the hackers stole the decryption keys.To say the backups were encrypted is a bit like trying to argue that a locked box is locked, if the key to the locked box is stolen at the same time as the box.

View Details

If you've purchased trainers from sports fashion retailer JD Sports in the past, your personal details could now be in the hands of hackers.Read more in my article on the Hot for Security blog.

View Details

Websites used by the Hive ransomware-as-a-service gang to extort ransoms and leak data stolen from corporate victims have been seized in a joint operation involving police around the world.

View Details

A 22-year-old suspected of being "Seyzo", a member of the ShinyHunters cybercrime gang, has been extradited from Morocco to the United States, where - if convicted - he could face up to 116 years in prison.The ShinyHunters gang became notorious in 2020, following a series of data breaches that impacted over 60 companies - including Microsoft. Read more in my article on the Tripwire State of Security blog.

View Details

What are prisoners getting up to with mobile phones? Why might ransomware no longer be generating as much revenue for cybercriminals? And how on earth did an airline leave the US government's "No Fly" list accessible for anyone in the world to download?All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.

View Details

Imagine you're an immigrant, who has fled your home country for the United States due to fear of being persecuted and tortured.What you definitely do not want is the agency handling your asylum request being careless with your personal information - and potentially putting your life and that of loved ones at risk.Read more in my article on the Hot for Security blog.

View Details

The important thing to realise about the most recently-reported data breach at email newsletter service Mailchimp is that it’s not just Mailchimp’s customer data that was put at risk.Even if you’re not personally a customer of Mailchimp, even if you’ve never even heard of Mailchimp, you may be affected.

View Details

Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! You know the old thought experiment about the AI designed to make paper clips, that quickly decides that in order to maximize paper clips, it will have to get rid of all the … Continue reading "Kolide – Endpoint security for people, not paper clips"

View Details

Anyone fancying a quick bite to eat in the UK may have found their choices more limited than usual on the high street.Nearly 300 fast food restaurants, including branches of KFC and Pizza Hut, were forced to close following a ransomware attack against parent company Yum! Brands.Read more in my article on the Hot for Security blog.

View Details

Wireless network operator T-Mobile has suffered yet another data breach.And we shouldn't be at all surprised if fraudsters use the information that they have stolen to send convincing phishing messages and scams.

View Details

It is the world's most active ransomware group - responsible for an estimated 40% of all ransomware infections worldwide.Find out what you need to know about LockBit in my article on the Tripwire State of Security blog.

View Details

For the second time in less than a year, email newsletter service Mailchimp has found itself in the embarrassing position of admitting it has suffered a data breach, putting its customers' subscribers at risk.

View Details

The Bitzlato cryptocurrency exchange has had its website seized by the authorities, after its Russian founder was charged with processing more than US $700m worth of "dirty money" on behalf of criminals.

View Details

Carole's in her sick bed, which leaves Graham in charge of the good ship "Smashing Security" as it navigates the choppy seas of credential stuffing and avoids the swirling waters of apps being sloppy with sensitive information.Find out more in this latest edition of the "Smashing Security" podcast, hosted by Graham Cluley with special guest BJ Mendelson.

View Details

Graham Cluley Security News is sponsored this week by the folks at SecurEnvoy. Thanks to the great team there for their support! We are often approached by organisations that depend on on-premise applications and data storage, who are looking for a multi-factor authentication solution, but are unable to move to a cloud-based solution for authentication. … Continue reading "Does your MFA solution secure access to your on-premise apps as well as those in the cloud?"

View Details

If you use Norton lifeLock as your password manager, your account may have been compromised.Learn more now.

View Details

A security breach may have cost current Formula 1 World Champion Max Verstappen an esports championship victory yesterday, and he's not happy.Read more in my article on the Hot for Security blog.

View Details

European law enforcement agencies have dealt a blow to scammers running call centres across the continent that stole millions of Euros from cryptocurrency investors.Crime-fighting authorities teamed up to tackle organised criminal groups who tricked unwary members of the public into investing in fake cryptocurrency schemes.Read more in my article on the Hot for Security blog.

View Details

It's time for you and your colleagues to become more skeptical about what you read.That's a takeaway from a series of experiments undertaken using GPT-3 AI text-generating interfaces to create malicious messages designed to spear-phish, scam, harrass, and spread fake news.Read more in my article on the Tripwire State of Security blog.

View Details

Someone called OxShagger thinks he has come up with the perfect Valentine’s surprise for Oxford students, but is the way he has gone about “bookworms with benefits” really a good idea? Robot security guards are trundling the streets of – you guessed it – America. And a writer of paranormal bully romances (no, we don’t know what that means either) returns from the grave...All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Andrew Agnês.

View Details

Three weeks after The Guardian newspaper was hit by a ransomware attack, it warns staff members that their personal data was accessed.

View Details

The experts at security firm Bitdefender have released a universal decryptor for victims of the MegaCortex family of ransomware, which is estimated to have caused more than 1800 infections - mostly of businesses.

View Details

Graham Cluley Security News is sponsored this week by the folks at Edgescan. Thanks to the great team there for their support! Edgescan simplifies Vulnerability Management (VM) by delivering a single full-stack SaaS solution integrated with world-class security professionals. Edgescan helps enterprise companies consolidate managing multiple point scanning tools for each layer of the attack … Continue reading "Does a hybrid model for vulnerability management make sense?"

View Details

Do ransomware gangs actually have a heart? Perhaps...Read more in my article on the Tripwire State of Security blog.

View Details

A security researcher has won a $107,500 bug bounty after discovering a way in which hackers could install a backdoor on Google Home devices to seize control of their microphones, and secretly spy upon their owners' conversations.Read more in my article on the Hot for Security blog.

View Details

Music-streaming service Deezer has owned up to a data breach, after hackers managed to steal the data of over 200 million of its users.

View Details

Do you use the LastPass password manager? Did you know they suffered a data breach, and that your passwords may be at risk?You do now. Here's what you need to know.

View Details

The FBI is warning US consumers that cybercriminals are placing ads in search engine results that impersonate well-known brands, in an attempt to spread ransomware and steal financial information.Read more in my article on the Tripwire State of Security blog.

View Details

Beware your Roomba's roving eye, the Finns warn of AI threats around the corner, and watch out when hailing a cab in Dublin...All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson.

View Details

Social media analytics service Social Blade has confirmed that it is investigating a security breach, after a hacker offered its user database for sale on an underground criminal website.Read more in my article on the Hot for Security blog.

View Details

Celebrated crime author Ann Cleeves turned to Twitter this week, desperate for help.The reason? The author, whose novels had been the inspiration for TV series like "Vera", had lost her HP laptop during a blizzard in Shetland.

View Details

Microsoft has warned that malicious hackers were able to get the software giant to digitally sign their code so it could be used in attacks, such as the deployment of ransomware.Read more in my article on the Hot for Security blog.

View Details

Law enforcement agencies in the United States, UK, Netherlands, Poland, and Germany have brought down the most popular DDoS-for-hire services on the internet, responsible for tens of millions of attacks against websites.Read more in my article on the Tripwire State of Security blog.

View Details

Drug dealers come unstuck while using the Encrochat encrypted-messaging app, and we put the Lensa AI’s avatar-generation tool under the microscope.All this and more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault.Plus – don’t miss our featured interview with Rico Acosta, IT manager at Bitwarden.

View Details

Sports retail giant Intersport, which boasts some 6000 stores worldwide in 57 countries, has fallen victim to a ransomware attack which disabled checkouts in France during what should have been one of the busiest times of the year.Read more in my article on the Hot for Security blog.

View Details

As ever, what matters most is not so much whether an organisation gets hit or not by a ransomware attack, but how well it handles the aftermath and recovery.Read more in my article on the Hot for Security blog.

View Details

Researchers at Sophos have investigated so-called "metaparasites" - the scammers who scam other scammers.

View Details

Malicious hackers, hell-bent on infiltrating an organisation, have no qualms about exploiting even the most tragic events.Read more in my article on the Tripwire State of Security blog.

View Details

Russian courts and government agencies have been hit by a previously-undocumented strain of data-wiping malware known as CryWiper.It poses as ransomware, but isn't interested in making money out of its victims...Read more in my article on the Hot for Security blog.

View Details

Your car's mobile app might have allowed hackers to remotely unlock your vehicle, turn on or off its engine, and even honk its horn.Read more in my article on the Hot for Security blog.

View Details

Researchers investigating a newly-discovered botnet have admitted that they "accidentally" broke Read more in my article on the Tripwire State of Security blog.

View Details

Why deleting your Twitter account may be a very bad idea, how the police unravelled the iSpoof fraud gang, and a trip into outer space (or at least interplanetary file systems).

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by original show co-host Vanja Švajcer.

View Details

As of September 2022, Twitter had challenged 11.72 million accounts, suspended 11,230 accounts, and removed over 97,674 pieces of misleading content related to COVID-19 worldwide. Today? It’s not doing anything. As an update on the company’s COVID-19 misinformation report webpage notes: Effective November 23, 2022, Twitter is no longer enforcing the COVID-19 misleading information policy. … Continue reading "Twitter isn’t going to stop people posting COVID-19 misinformation anymore"

View Details

A Canadian man has revealed that the company he chose to provide security for his home was carelessly exposing the private information for other customers, even after he warned them about the problem.

Read more in my article on the Hot for Security blog.

View Details

UK police are texting 70,000 people who they believe have fallen victim to a worldwide scam that saw fraudsters steal at least £50 million from bank accounts.

Read more in my article on the Tripwire State of Security blog.

View Details

Deepfake shenanigans strike users of troubled crypto firm FTX, the perils of charging your electric vehicle, and is Microsoft’s takeover of Activision good news for video game fanatics.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by John Hawes of AMTSO.

View Details

$100 million.

That's the amount of money that the Hive ransomware is thought to have extorted from over 1300 companies around the world, according to a joint report from the FBI, CISA, and HHS.

Read more in my article on the Hot for Security blog.

View Details

Researchers at cybersecurity firm Unit 221B have revealed that they have been secretly helping victims of the Zeppelin ransomware decrypt their computer systems since 2020.

View Details

The Daixin ransomware gang has given a humiliating slap in the face to Air Asia, which lost the personal data of five million passengers and all of its employees earlier this month.

View Details

A UK police force has apologised after it published the names and addresses of victims of sexual assault on its website.

Suffolk Police says that it has launched an investigation into how victims' names, addresses, dates of birth, and details of reportedly hundreds of alleged offences were left on public view.

Read more in my article on the Hot for Security blog.

View Details

Elon Musk is still causing chaos at Twitter (and it's beginning to impact users), are scammers selling your house without your permission, and Google gets stung with a record-breaking fine.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.

View Details

Twitter is in chaos. I'd rather delete my Direct Messages one-by-one than one day find that they are in the hands of a hacker or a disgruntled Twitter employee who goes rogue.

View Details

Healthcare organisations in the United States are being warned to be on their guard once again, this time against a family of ransomware known as Venus.

Read more in my article on the Tripwire State of Security blog.

View Details

A man with dual Russian and Canadian nationality has been arrested in connection with his alleged part in the LockBit ransomware conspiracy that has demanded more than $100 million from its victims.

Read more in my article on the Hot for Security blog.

View Details

PC manufacturer Lenovo has been forced to push out a security update to more than two dozen of its laptop models, following the discovery of high severity vulnerabilities that could be exploited by malicious hackers.

Security researchers at ESET discovered flaws in 25 of its laptop models - including IdeaPads, Slims, and ThinkBooks - that could be used to disable the UEFI Secure Boot process.

Read more in my article on the Tripwire State of Security blog.

View Details

Graham offers some security and privacy advice for those exodusing Twitter to Mastodon, and Carole slams the door shut on a notorious scammer with a huge Instagram following.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

A ransomware gang has begun to publish data on the dark web stolen from Australia's largest health insurer Medibank.

Curiously, the hackers have released details of insured customers, sorted into two files bearing the label "naughty-list" and "good-list."

Read more in my article on the Hot for Security blog.

View Details

Mastodon is hot right now. After some years of only being used by geeks (yes, I've had an account for a while now) it's at the tipping point of becoming mainstream. If you're part of the exodus of users leaving Twitter for Mastodon, what are the security and privacy issues that you need to be aware of?

View Details

Embattled Australian health insurer Medibank says that it will not pay a ransom to cyber extortionists who stolen the personal data of almost ten million customers.

Read more in my article on the Hot for Security blog.

View Details

The metaverse is evolving, and tech giants like Meta (the firm previously known as Facebook), Microsoft, and Google are betting big that you'll want to be a part of it.

You know who else might be keen? Criminals.

Read more in my article on the Hot for Security blog.

View Details

The world's richest man's plans for the news junkie's favourite social network inevitably get a great deal of attention. Not everyone will be aware of the details of what Elon Musk might be planning for Twitter, but they will certainly be aware that it's a hot topic.

And so if a Twitter user receives a message claiming to be about their verified account, they may very well believe it... and that makes them more susceptible to falling into a trap.

Read more in my article on the Tripwire State of Security blog.

View Details

Twitter has a new chief twit in the form of Elon Musk and he's causing problems, scientists say artificial intelligence may help us communicate with animals, and is the office of the future set in the metaverse?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.

View Details

Patients of Dutch mental health clinics are being warned that their personal records have fallen into the hands of hackers following a security breach at an online portal that "guaranteed" their privacy.

Read more in my article on the Hot for Security blog.

View Details

Cloud communications firm Twilio reveals that it fell victim to a voice phishing attack in June 2022, allowing hackers to access customer contact information.

Read more in my article on the Hot for Security blog.

View Details

The Murdoch-owned New York Post published a series of incendiary and offensive articles online earlier today, calling for the assassination of political figures like Joe Biden and Alexandria Ocasio-Cortez, and spreading racial slurs.

View Details

LinkedIn says it is beefing up its security in an attempt to better protect its userbase from fraudulent activity such as profiles that use AI-generated deepfake photos, and messages that may contain unwanted or harmful content.

Read more in my article on the Tripwire State of Security blog.

View Details

What is slushygate and how does it link to sextortion in the States? What is the most impersonated brand when it comes to delivering phishing emails? And what the flip is nano-targeting?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by fan favourite Maria Varmazis.

View Details

It was all going so well. At first.

Read more in my article on the Hot for Security blog.

View Details

Shouldn't affected users have been told sooner?

View Details

Pendragon - the car dealership group which owns Evans Halshaw, CarStore, and Stratstone, and operates around 160 showrooms across the UK - has confirmed that its IT servers have been hacked by cybercriminals who claim to have stolen five per cent of its data.

View Details

A former officer at Louisville Metro Police has admitted his part in a conspiracy that stalked and extorted young women online, breaking into their Snapchat accounts in order to steal their naked photos and videos.

Read more in my article on the Hot for Security blog.

View Details

Microsoft says that it accidentally exposed sensitive customer data after failing to configure a server securely. But it's far from happy with the security researchers who told them about the problem...

View Details

Someone's election-fiddling is uncovered with an Apple AirTag, a cyber scandal rocks Germany, and a swindler steals a fortune due to trains being delayed.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by runZero's Chris Kirsch.

Plus don't miss our featured interview with Akamai's Patrick Sullivan talking about bots in the retail sector.

View Details

The parent company of women's fashion site Shein has been fined $1.9 million after being accused of lying about the extent of data breach, and notifying "only a fraction" of affected customers.

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! In 2021, our company went through the SOC 2 Type 1 audit, and we found out just how challenging it can be to prove compliance to a third-party auditor. We also learned firsthand … Continue reading "Kolide, endpoint security for teams that want to meet SOC 2 compliance goals without sacrificing privacy"

View Details

Boffins at the University of Glasgow, in Scotland, have developed a system which they claim demonstrates a new type of cybersecurity threat: a "thermal attack."

According to the researchers, the falling price of heat-detecting thermal imaging cameras and advances in machine learning have made it more feasible to guess what passwords a target may have entered on a keyboard, up to a minute after typing them.

Read more in my article on the Hot for Security blog.

View Details

A couple unexpectedly find $10.5 million in their cryptocurrency account, and in Cambodia people are being forced to commit scams.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

Ukraine has seen internet outages this week following renewed missile attacks from Russian forces. With a combination of power cuts and DDoS attacks knocking out telecommunications systems, internet availibility suffered a 35% dip.

Read more in my article on the Hot for Security blog.

View Details

iOS 16.0.3 has been pushed out by Apple, and my advice is that you should install it.

View Details

At UKCyberWeek at the Business Design Centre in London, on 3 & 4 November 2022, I'll be offering practical insight on how computer systems are being targeted, shine some light on mysterious and elusive global crime rings that have made billions of dollars, and describe the lessons that today's organisations should learn about how to protect themselves from attack.

Grab your free ticket.

View Details

Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Device security is a lot like Mount Everest: it’s tough to scale. When you’re a small company dominated by engineers, you can keep up with fleet management with nothing more than trust and … Continue reading "Kolide gives you real-time fleet visibility across Mac, Windows, and Linux, answering questions MDMs can’t"

View Details

Has new UK prime minister Liz Truss been careless with her mobile phone, and hear the most extraordinary story of corporate cyberstalking.

All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by nobody for reasons that will become obvious.

View Details

A 74-year-old Manga artist received an unsolicited Facebook message from somebody claiming to be Incredible Hulk actor Mark Ruffalo.

You can probably guess where this is heading...

View Details

You always want to know what is attached to your network. And whether it could be vulnerable or not.

Read more in my article on the Tripwire State of Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Do you know the old thought experiment about the AI designed to make paper clips that quickly decides that it will have to eliminate all the humans to maximize paper clips? Many security … Continue reading "Kolide can help you nail audits and compliance goals with endpoint security for your entire fleet"

View Details

Hackers have leaked data stolen from the United States's second-largest school district, after the Los Angeles Unified School District (LAUSD) announced it would not be giving in to ransom demands.

Read more in my article on the Hot for Security blog.

View Details

Yay, Microsoft has told us how to mitigate against the recently-discovered zero-day attacks.

Boo, the mitigations can be bypassed...

View Details

Two men, who previously worked at eBay, have been sentenced to prison after admitting their role in a cyberstalking campaign that targeted the editor and publisher of a newsletter that criticised the company.

Read more in my article on the Hot for Security blog.

View Details

Luxury pre-owned watch website Watchfinder has warned its user base that their personal data has been accessed after an employee's account was broken into and a customer list accessed.

View Details

A 40-year-old man could face up to 10 years in prison, after admitting in a US District Court to sabotaging his former employer's computer systems.

Read more in my article on the Tripwire State of Security blog.

View Details

Anti-porn "shamware" apps take a privacy pounding, is your image already being used by AI, and deepfake danger continues to deepen.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford.

View Details

Politicians including Portugese president Marcelo Rebelo de Sousa are amongst those who have had their personal information leaked following an attack by the notorious Ragnar Locker gang against the country's national airline TAP.

Read more in my article on the Hot for Security blog.

View Details

Users of Revolut, the popular banking app, would be wise to be on their guard - as scammers are sending out barrages of SMS text messages, posing as official communications from the financial firm.

View Details

Could the 16-year-old arrested in Oxford in March now be the 17-year-old arrested in Oxfordshire and charged with breaching his bail conditions?

View Details

Graham Cluley Security News is sponsored this week by the folks at Pentera. Thanks to the great team there for their support! Leaked and stolen credentials continue to pose a critical risk to organizations globally. In fact, 65% of breaches involve leaked credentials taken from the dark web and other sources. While threat intelligence tools … Continue reading "See how Pentera identifies and mitigates the risk of your most exploitable exposed credentials"

View Details

The boy, who has not been named, was arrested as part of an investigation by the National Crime Agency (NCA). He remains in police custody.

Although at the time of writing no more details have been shared, there is speculation online that the arrest is in relation to the recent hacks of Uber and Rockstar Games.

View Details

A self-proclaimed cryptocurrency millionaire has been charged with multiple felonies for his alleged role in a scam that purported to sell a high-powered cryptomining machine called the "Bitex Blockbuster" that did not actually exist.

Read more in my article on the Hot for Security blog.

View Details

Between 5-7 October, I will be chairing the UK's National Information Security Conference (better known as NISC), at Carden Park in Cheshire. It's a great event - you should come along.

Oh, and we'll do the podcast "live" there as well...

View Details

The Financial Times has created an imaginative ransomware negotiation simulator which lets you imagine you’re in the hot seat at a hacked company, trying to stop cybercriminals from releasing sensitive data they have stolen from your systems.

View Details

Researchers reveal how your eyeglasses could be leaking secrets when you’re on video conferencing calls, we take a look at the recent data breaches involving Uber and Grand Theft Auto 6, and we cast an eye at what threats may be around the corner…

All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register’s Iain Thomson.

Plus – don’t miss our featured interview with Sal Aurigemma, the faculty director of the Master of Science in Cyber Security program at the University of Tulsa.

View Details

Bespectacled video conferencing participants have more to worry about than if their hair is uncombed or they have some spinach stuck between their teeth. According to newly-publicised research, they may also be unwittingly leaking sensitive information displayed on their computer screens.

Read more in my article on the Hot for Security blog.

View Details

Amid a wave of hacks which has cost investors billions of dollars worth of cryptocurrency, the FBI is calling on decentralised finance (DeFi) platforms to improve their security.

Read more in my article on the Tripwire State of Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Teleport. Thanks to the great team there for their support! Kubernetes is an amazing platform for managing containers at scale. However, a recent study found that over 900,000 Kubernetes clusters are vulnerable to attack because they are misconfigured! This means that your Kubernetes … Continue reading "Over 900K Kubernetes clusters are misconfigured! Is your cluster a target?"

View Details

We’re back from our summer break as we ask how did a cryptomining campaign stay unspotted for years, quiz special guest and infosec rockstar Mikko Hyppönen about his book, and ponder what spiders teach us about misinformation.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

I must admit I was delighted to receive an email today from UK high street pharmacy Boots telling me I should enable two-factor authentication on my account. Boots customers would have benefited from two-factor authentication a couple of years ago, when hackers attempted to gain access to customers’ Boots Advantage Card accounts, and temporarily stopped … Continue reading "Boots lets down its customers, by only offering SMS-based 2FA"

View Details

LastPass, the popular password manager trusted by millions of people around the world, has announced that it suffered a security breach two weeks ago that saw hackers break into its systems and steal information.

Read more in my article on the Tripwire State of Security blog.

View Details

Malicious hackers are demanding $10 million from a French hospital they hit with ransomware last weekend.

The Hospital Center Sud Francilien (CHSF) in Corbeil-Essonnes, south-east of Paris, was struck late on Saturday night, causing major disruption to health services.

Read more in my article on the Hot for Security blog.

View Details

Zoom users on macOS are being told once again to update their copy of the video-conferencing software after a security hole was found that could be exploited by hackers.

Read more in my article on the Hot for Security blog.

View Details

Ransomware is to blame for the closure of all 175 7-Eleven stores in Denmark on Monday.

The retailer closed all of its stores in Denmark after its cash registers and payment systems were brought down in the attack.

Read more in my article on the Tripwire State of Security blog.

View Details

Scammers are stealing money from children, with the alluring but bogus promise that China's tough restrictions on online gaming can be subverted.

Read more in my article on the Hot for Security blog.

View Details

This week Microsoft finally released a patch for a zero-day security flaw being exploited by hackers, that the company had claimed since 2019 was not actually a vulnerability.

Read more in my article on the Hot for Security blog.

View Details

Did Russian security Kaspersky really choose to send an email to its customers addressing them as "dear and lovely"? Had Kaspersky suffered a data breach? Had a hacker found a way to send messages to Kaspersky's customer base?

View Details

Pornhub has a problem, the UK's Co-op supermarket is accused of big brother tactics, and we take a look at how a security researcher is revealing the true identify of hackers.

All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.

View Details

The official Instagram account of cricketing legend and former Pakistan Prime Minister Imran Khan was hacked yesterday in order to promote a cryptocurrency scam.

Read more in my article on the Hot for Security blog.

View Details

An Irish court has jailed three romance scammers who tricked a 66-year-old woman out of her life savings, and even tricked her into visiting Dubai at her own expense.

Read more in my article on the Hot for Security blog.

View Details

A $10 million reward is being offered for information leading to the identification or location of hackers working with North Korea to launch cyber attacks on US critical infrastructure.

Read more in my article on the Tripwire State of Security blog.

View Details

Uber may not face prosecution over its handling of a 2016 data breach - but its former chief security head does; how to defend your digital devices' data while on vacation, and how to change your accent with artificial intelligence.

All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin.

Plus don't miss our featured interview with Ian Farquhar of Gigamon.

View Details

The former Chief Security Officer of Uber is facing wire fraud charges over allegations that he covered up a data breach that saw hackers steal the records of 57 million passengers and drivers.

Read more in my article on the Hot for Security blog.

View Details

An unauthorised party has seized control of the @avtestorg Twitter account, nuked its profile picture and banner, replaced its name and description with a full-stop, and set about retweeting numerous messages about NFTs.

Anti-virus testing organisation AV-Test appears to have done nothing wrong, so how was its account hacked?

View Details

In this special edition of the "Smashing Security" podcast, computer security veterans Graham Cluley and Carole Theriault welcome back author and journalist Jamie Bartlett - host of "The Missing CryptoQueen" podcast.

Jamie tells us about his new book, which shares more details about the disappearance of cryptocurrency scammer Dr Ruja Ignatova, and the subsequent hunt by law enforcement.

View Details

Three million Android users may have lost money and had their devices infected by spyware, after the discovery that the official Google Play store has been distributing apps infected by a new family of malware.

Read more in my article on the Tripwire State of Security blog.

View Details

Bexplus gave its users only 24 hours to withdraw their funds.

Can you imagine a traditional financial institution treating its customers in such a slipshod fashion?

View Details

Graham Cluley Security News is sponsored this week by the folks at Keeper Security. Thanks to the great team there for their support! IT and DevOps teams were presented with new challenges with the mass-migration to home working, and found themselves forced to perform infrastructure monitoring and management remotely. What is clearly needed is a … Continue reading "Keeper Connection Manager : Privileged access to remote infrastructure with zero-trust and zero-knowledge security"

View Details

An app which purported to launch distributed denial-of-service (DDoS) attacks against the internet infrastructure of Russia, was in reality secretly installing malware on to the devices of pro-Ukrainian activists.

Read more in my article on the Hot for Security blog.

View Details

I can't tell you not to seek ethical hacking certification from EC-Council. But I can suggest that if you are looking for an online university to boost your cybersecurity career, you don't settle for an outfit that has proven itself to be of questionable ethics and utterly clueless.

View Details

NFT artist DeeKay Kwon had his Twitter account hacked at the end of last week by scammers who managed to steal NFTs valued at $150,000 from his followers.

Read more in my article on the Hot for Security blog.

View Details

A self-proclaimed "super hacker" causes problems in the Magic Kingdom, criminals regret trusting Anom phones, and lawsuits are filed against TikTok.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.

Plus don't miss our featured interview with Scott McCrady, the CEO of SolCyber Managed Security Services.

View Details

Turn on a PC running Microsoft Windows 8.1 and you're likely to be greeted with a full-screen message warning that the operating system will no longer be supported after 10 January 2023, and - critically - will no longer be receiving any security updates.

View Details

Microsoft has shared details of a widespread phishing campaign that not only attempted to steal the passwords of targeted organisations, but was also capable of circumventing multi-factor authentication (MFA) defences.

Read more in my article on the Tripwire State of Security blog.

View Details

Even the Magic Kingdom isn't immune from hackers.

Late last week, millions of followers of Disneyland's Facebook and Instagram accounts were greeted by a series of offensive messages posted by a hacker.

Read more in my article on the Hot for Security blog.

View Details

Things haven't gone as smoothly as Microsoft (and, indeed, the rest of us) might have hoped...

View Details

Apple has previewed a new feature which aims to harden high-risk users from the serious threat of being spied upon by enemy states and intelligence agencies.

Read more in my article on the Tripwire State of Security blog.

View Details

A hacked university might have made a profit after paying a cryptocurrency ransom, China suffers possibly the biggest data breach in history, and Reuters investigates digital mercenaries. All this and much more is discussed in the latest edition of the award-winning “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this … Continue reading "Smashing Security podcast #282: Raising money through ransomware, China’s mega-leak, and hackers for hire"

View Details

Graham Cluley Security News is sponsored this week by the folks at Indusface. Thanks to the great team there for their support! It is hard to imagine an application without APIs (Application Programming Interface). For the past few years, APIs have become core foundational for the success of businesses. Hence, there is no surprise that … Continue reading "Comprehensive risk-based API protection with AppTrana"

View Details

Hundreds of thousands of people who follow the official social media accounts of the British Army may have been surprised to see that it had been hijacked by hackers on Sunday.

Read more in my article on the Hot for Security blog.

View Details

Members of the LGBTQ+ community have been warned to be on their guard against extortionists who may attempt to prey on them via online dating apps such as Grindr and Feeld.

Read more in my article on the Hot for Security blog.

View Details

Semiconductor giant AMD says that it is investigating what claims to be a major data breach of its network, that saw a group of online criminals steal 450GB of data from its systems.

Read more in my article on the Hot for Security blog.

View Details

Although only active for the past couple of months, the Black Basta ransomware is thought to have already hit almost 50 organisations.

Read more in my article on the Tripwire State of Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at SolCyber. Thanks to the great team there for their support! If the bad guys don’t discriminate when it comes to who they are attacking, how can your business settle for anything less than the very best security? SolCyber has brought to market a … Continue reading "How to get Fortune 500 cybersecurity without the hefty price tag"

View Details

The FBI has warned that, in an attempt to gain access to sensitive data at organisations, crooks are using deepfake video when applying for remote working-at-home jobs.

View Details

Carnival Cruises, the world's largest travel leisure firm which operates over 100 ships for millions of vacationing customers, has been fined a total of $6.25 million following a series of security mishaps.

Read more in my article on the Hot for Security blog.

View Details

A Japanese worker, after a drunken night out, lost a flash drive containing the personal information of every single one of his city's residents.

Read more in my article on the Hot for Security blog.

View Details

Amazon has demonstrated an experimental feature that demonstrates how a child can choose to have a bedside story read to him by his Alexa... using his dead grandmother's voice.

View Details

The UK's National Health Service has warned the public about a spate of fake messages, sent out as SMS text messages, fraudulently telling recipients that they have been exposed to the Omicron variant of COVID-19.

Read more in my article on the Tripwire State of Security blog.

View Details

Internet-connected jacuzzis find themselves in hot water, and a Google engineer claims that their AI has developed feelings.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

The Strava fitness-tracking app is being used to spy upon members of the Israeli military, tracking their movements at secret bases across the country and potentially even help observe their activities when they travel overseas.

Read more in my article on the Hot for Security blog.

View Details

Have you received an email notification that there is a voicemail waiting to be listened to by you?

Maybe you would be wise to think carefully before clicking on the attachment.

View Details

Graham Cluley Security News is sponsored this week by the folks at SolCyber. Thanks to the great team there for their support! If the bad guys aren’t discriminating who they are attacking, how can your business settle for anything less than Fortune 500 level security? SolCyber has brought to market a new way to consume … Continue reading "How to get Fortune 500 cybersecurity without the hefty price tag"

View Details

Owners of NAS drives manufactured by QNAP have been advised that the company is "thoroughly investigating" reports that a new variant of the DeadBolt ransomware is targeting devices, locking up data and demanding victims pay a fee to extortionists.

Read more in my article on the Hot for Security blog.

View Details

A critical vulnerability in a WordPress plugin used on over one million websites has been patched, after evidence emerged that malicious hackers were actively exploited in the wild.

View Details

With Father's Day falling this weekend in the United States and UK, more people might be more willing than normal to believe the latest scam to be spreading via WhatsApp is true. But I'm afraid it isn't.

Sorry dads, Heineken isn't giving away free coolers of beer.

Read more in my article on the Hot for Security blog.

View Details

Law enforcement agencies around the world appear to have scored a major victory in the fight against fraudsters, in an operation which has seized tens of millions of dollars and seen more than 2000 people arrested.

Read more in my article on the Tripwire State of Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Specops. Thanks to the great team there for their support! With the help of live attack data, Specops Software’s Breached Password Protection can detect over 2 billion known breached passwords in your Active Directory. Using the Specops database, you can block commonly used … Continue reading "Want to block two billion known breached passwords from being used at your company? It’s easy with Specops Password Policy tools"

View Details

How did a saxophonist sneak sensitive information in and out of the Soviet Union? How might an Apple AirTag have led to murder? And isn't the world of cryptocurrency and blockchain doing just great?

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

The US authorities have sentenced a man to 24 months in a federal prison after he was found to have run a DDoS-for-hire service that knocked websites off the internet.

Read more in my article on the Hot for Security blog.

View Details

Boffins at the University of California San Diego have found a way to track individuals via Bluetooth.

Researchers discovered that the Bluetooth signals emitted by mobile phones carry a unique fingerprint, caused by small imperfections accidentally created during the manufacturing process.

View Details

A Windows zero-day vulnerability dubbed "DogWalk" has not received an official patch yet from Microsoft, but that hasn't stopped others from offering free fixes to protect users.

Read more in my article on the Hot for Security blog.

View Details

Trouble brews with the Tim Hortons app, Mandiant gets in a tussle with a Russian ransomware gang, and should good faith security researchers be at risk of prosecution?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White.

View Details

An Iranian hacking gang called Bohrium has had its activities disrupted after Microsoft seized control of 41 domains used in spear-phishing attacks.

Read more in my article on the Hot for Security blog.

View Details

Apple says that it protected many millions of users from being defrauded to the tune of nearly $1.5 billion dollars in the last year, by policing its official App Store.

According to a newly published report by Apple, over 1.6 million risky and untrustworthy apps and app updates were stopped in their tracks due to the company’s fraud prevention analysis.

Read more in my article on the Tripwire State of Security blog.

View Details

Ransom acts of kindness are top of our mind, as we also explore how bad bots are hogging more and more of the internet's activity, and look at how deepfakes could be a good thing after all.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Ray [REDACTED].

View Details

A database of contact information for hundreds of Verizon employees is in the hands of cybercriminals, after a member of staff was duped into granting a hacker access to their work PC.

Read more in my article on the Hot for Security blog.

View Details

The world is waiting for a patch from Microsoft, after a zero-day vulnerability in Microsoft Office was found to be being exploited in boobytrapped Word documents to remotely execute code on victims' PCs.

View Details

The great thing about working in the world of cybersecurity is that there’s always something new. You may think you’ve seen it all, and then something comes along that completely surprises you.

And that’s certainly true of the GoodWill ransomware...

Read more in my article on the Tripwire State of Security blog.

View Details

Twitter has been fined $150 million for using phone numbers submitted by users to boost their security... for targeted advertising.

View Details

A browser extension bug let malicious websites spy on webcams, hackers threaten the global food supply chain, and Michael Fish (not that one...) hacked into his female classmates' online accounts, hunting for nude photos and videos.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.

View Details

An Indian airline says that an "attempted ransomware attack" against its IT infrastructure caused flights to be delayed or canceled, and left passengers stranded.

Read more in my article on the Hot for Security blog.

View Details

A man has been sentenced to over 9 years in jail after he was found guilty of breaking into the email accounts of his classmates, and stealing their private nude photographs and videos.

Read more in my article on the Hot for Security blog.

View Details

For the past week and a half, Greenland's health service has reportedly been struggling to recover from a cyber attack that has crippled its IT systems, causing long waiting times and forcing doctors to resort to using pen and paper instead of computers.

Read more in my article on the Hot for Security blog.

View Details

I'm not sure if it would be enough for me to switch bank accounts, but I have something of a sneaking respect for the Bank of Zambia...

View Details

Spanish police say that they have dismantled a phishing gang operating across the country, following the arrest of 13 people and the announcement that they are investigating a further seven suspects.

Read more in my article on the Tripwire State of Security blog.

View Details

It should be hard for malicious hackers to break into systems, but all too often it isn't.

Read more in my article on the Tripwire State of Security blog.

View Details

A man hacks his employer to prove its security sucks, Telegram provides a helping hand to the Eternity Project malware, and what the heck do mental health apps think they're up to?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dr Jessica Barker.

Plus don't miss our featured interview with Rumble's Chris Kirsch.

View Details

Central Bedfordshire Council failed to properly redact the details of 'dozens and dozens' of pupils with special educational needs when responding to a Freedom of Information request, publishing them on a public website.

View Details

If pro-Russian hackers had had their way, the Eurovision Song Contest could have been disrupted, potentially preventing the broadcast from being seen or meddling with the vote.

Read more in my article on the Hot for Security blog.

View Details

Clearview AI receives something of a slap in the face, and who is wrestling over an internet wormhole?

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

And don't miss our featured interview with Artur Kane of GoodAccess.

View Details

Graham Cluley Security News is sponsored this week by the folks at Keeper Security. Thanks to the great team there for their support! The mass migration to distributed work has given IT and DevOps teams the new challenge of performing infrastructure monitoring and management remotely. IT and DevOps personnel need a secure, reliable, and scalable … Continue reading "Keeper Connection Manager: Privileged access to remote infrastructure with zero-trust and zero-knowledge security"

View Details

A predominantly Black college, based in Illinois, USA, is closing its doors after 157 years - citing the challenges it faced due to the Coronavirus pandemic, and the aftermath of a ransomware attack.

Read more in my article on the Hot for Security blog.

View Details

The ransomware attack is likely to impact a number of agricultural machinery brands, including Challenger, Fendt, Ferguson, Massey, and Valtra, in the run-up to a crucial time of year for crop farmers.

View Details

As Russian state TV broadcast a military parade as part of Victory Day celebrations in Moscow, viewers of some channels were greeted by a message that certainly wasn't approved by Putin's propaganda machine...

Read more in my article on the Hot for Security blog.

View Details

The FBI's Internet Crime Complaint Center (IC3) has issued updated statistics on Business Email Compromise (BEC) attacks which use a variety of social engineering and phishing techniques to break into accounts and trick companies into transferring large amounts of money into the hands of criminals.

Read more in my article on the Tripwire State of Security blog.

View Details

In my keynote I'll be discussing whether cybercriminals really are evil geniuses (as the media and some security vendors would like us to believe), or not...

Save 50% off the ticket price using a discount code.

View Details

We find out why calls to Dublin airport's noise complaints line have soared, and Carole quizzes Graham to celebrate World Password Day.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast, with computer security veterans Graham Cluley and Carole Theriault.

And don't miss our special featured interview with Clint Dovholuk of NetFoundry.

View Details

Graham Cluley Security News is sponsored this week by the folks at Keeper Security. Thanks to the great team there for their support! The mass migration to distributed work presented IT and DevOps teams with new challenges as they were forced to perform infrastructure monitoring and management remotely. IT and DevOps personnel needed a secure, … Continue reading "Keeper Connection Manager : Privileged access to remote infrastructure with zero-trust and zero-knowledge security"

View Details

One of the largest library services in Germany, EKZ Bibliotheksservice, has been impacted by a ransomware attack that has left book lovers unable to rent and borrow eBooks, audio books, and electronic magazines.

Read more in my article on the Hot for Security blog.

View Details

A police car's digital in-car video system uncovered that two Los Angeles officers ignored calls to provide assistance at a department store robbery because they were too enthralled in catching Pokémon.

View Details

If you are worried about the financial hit of paying a ransom to cybercriminals, wait until you find out the true cost of a ransomware attack.

Read more in my article on the Tripwire State of Security blog.

View Details

Elon Musk's takeover of the company might bring a swathe of changes to Twitter, including the introduction of end-to-end encryption for direct messages (DMs).

Read more in my article on the Hot for Security blog.

View Details

Members of The Bored Ape Yacht Club get that sinking feeling, a face unwittingly launches hundreds of romance scams, and is an as-yet unseen Kim Kardashian sex tape a load of old Roblox?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by BBC cyber correspondent Joe Tidy.

View Details

The United States has made it $10 million harder to keep your mouth shut, if you happen to have any information about the Russian military hackers who masterminded the notorious NotPetya cyber attack.

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Specops. Thanks to the great team there for their support! With the help of live attack data from our own honeypots, Specops Software’s Breached Password Protection can now detect over 2 billion known breached passwords in your Active Directory. Using our database, you … Continue reading "Block over two billion known breached passwords from your AD with Specops Password Policy tools"

View Details

Costa Rica's outgoing president, Carlos Alvarado Quesada, has said that a ransomware attack on the government's computer systems was an attempt to destabilise the country as it transitions to a new administration.

Read more in my article on the Hot for Security blog.

View Details

Someone isn't happy that Ukraine's post office has issued stamps mocking the sunken Russian navy flagship.

View Details

Researchers have spotted that the TOR address used by the notorious REvil ransomware gang is now redirecting to a new website, with information about seemingly new attacks.

Read more in my article on the Tripwire State of Security blog.

View Details

Security researchers at Kaspersky have released a free decryption tool that promises to recover files for organisations hit by the Yanlouwang ransomware, meaning they don't have to pay the ransom.

View Details

A man loses $650,000 from his cryptocurrency wallet after his Apple iCloud account is hacked, video conferencing apps may not be muting your mic quite the way you imagined, and Google has unblurred military bases in Russia... or has it?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.

View Details

Cryptocurrency wallet maker MetaMask has warned its 21 million monthly users to be wary of Apple iCloud backing up their app's data by default, after attackers successfully stole $650,000 of funds and NFTs.

Read more in my article on the Hot for Security blog.

View Details

Online greeting cards business Funky Pigeon was forced to close its doors temporarily last week after a "cybersecurity incident."

Visitors to the company's website were still being greeted as recently as Monday with a message saying that it could not accept new orders.

View Details

Graham Cluley Security News is sponsored this week by the folks at Indusface. Thanks to the great team there for their support! With APIs grown into a dominant mechanism of the modern web, protecting web applications and APIs becomes the default requirement of AppSec. This calls for a unified risk-based mitigation solution. Indusface WAAP, a … Continue reading "For cutting-edge web application and API protection – Trust Indusface WAAP"

View Details

Agencies of the US Government have issued a joint warning that hackers have revealed their capability to gain full system access to industrial control systems that might help enemy states sabotage critical infrastructure.

Read more in my article on the Tripwire State of Security blog.

View Details

Pulchritudinous women with glossy long hair are targeting Israeli officials via Facebook - but why? Scammers have found a new way to gain access to your most sensitive information - but how? And armchair detectives are helping investigating cold cases involving DNA - but should they?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.

View Details

One of the world’s largest hacker forums, which has been operating since 2015 helping cybercriminals sell and purchase the hacked personal data of millions of innocent people, has been taken down by the police.

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Perception Point. Thanks to the great team there for their support! The need to communicate, collaborate and do business on a global level has created a proliferation of cloud based applications and services: Email. Cloud Storage. Messaging platforms. CRM. Digital Apps and Services. … Continue reading "Security blind spots in the era of cloud communication & collaboration. Are you protected?"

View Details

Strange goings-on on LinkedIn, Ukraine publishes a list of alleged Russian FSB agents, and police in Pittsburgh investigate an odd report of an active shooter.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White.

View Details

Online photography printing service Shutterfly has disclosed that it has suffered a security breach at the hands of a ransomware gang that exposed the personal information of some employees.

View Details

Graham Cluley Security News is sponsored this week by the folks at Forcepoint. Thanks to the great team there for their support! Remember when you thought an antivirus was all you needed to keep safe from cybercriminals? Of course, cybersecurity has never truly been that simple. As threats and business operations have grown more complex, … Continue reading "Forcepoint ONE helps firms simplify their security"

View Details

After being linked to ransomware attacks that cost companies over US $53 million, an Estonian man has been sentenced to prison for five and a half years.

Read more in my article on the Hot for Security blog.

View Details

Compromise of safety systems could have resulted in the release of toxic gas or an explosion - causing physical damage to facilities and the loss of life.

Read more in my article on the Hot for Security blog.

View Details

British police arrested seven people earlier this week in relation to a wave of attacks launched by the LAPSUS$ hacking group, against firms such as Microsoft, NVIDIA, Ubisoft, Samsung, and Okta.

The hacking group's alleged mastermind? A 16-year-old boy from Oxford, UK.

View Details

A Russian bank tells its customers to stop installing security updates, an Apple employee ends up in hot water, and learn our tips to avoid being virtually kidnapped.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.

View Details

Graham Cluley Security News is sponsored this week by the folks at Forcepoint. Thanks to the great team there for their support! Remember the days when you thought an antivirus was all you needed to stay safe? Of course, cybersecurity has never truly been that simple. As cyberthreats and business operations have grown more complex, … Continue reading "Simplify your security with Forcepoint ONE"

View Details

AvosLocker is a ransomware-as-a-service (RaaS) gang which first appeared in mid-2021. It has since become notorious for its attacks targeting critical infrastructure in the United States, including the sectors of financial services, critical manufacturing, and government facilities.

Read more in my article on the Tripwire State of Security blog.

View Details

The RansomEXX ransomware gang has seen fit to publish on the dark web 12GB of data stolen from SAMH, including unredacted photographs of individuals' driving licences, passports, personal information such as volunteers' home addresses and phone numbers, and - in some cases - even passwords and credit card details.

Read more in my article on the Hot for Security blog.

View Details

International credit bureau TransUnion says that hackers managed to breach a server operated by its South African division, and gained access to the personal information of individuals.

Read more in my article on the Hot for Security blog.

View Details

With just a few weeks until the April 15 deadline for US individuals and businesses to file their tax returns, scammers are as busy as ever.

Read more in my article on the Tripwire State of Security blog.

View Details

A video clip shared on social media yesterday showed what appeared - to anyone who wasn't paying proper attention at least - to be Ukrainian President Volodymyr Zelensky calling on his country's citizens and army to lay down their weapons and surrender to invading Russian forces.

In the clip, the deepfake Zelensky is shown standing behind a podium, declaring that he has "decided to return Donbas" and that his army's efforts to fend off Russia's attack "has failed."

Read more in my article on the Hot for Security blog.

View Details

Germany tells consumers to stop using Kaspersky anti-virus products, OSINT reveals a secret government department (with help from an Apple AirTag), and the UK says it's taking a hard line on dick pics.

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Chris Kirsch.

View Details

The alleged ringleader of an international scam operation has been arrested by Nigerian authorities in Lagos, after being wanted by the FBI since 2016.

Read more in my article on the Hot for Security blog.

View Details

Last month, the LAPSUS$ hacking group stole up to one terabyte of internal data, including hashed passwords, from graphics card maker NVIDIA.

Of course, you would hope that any sensible NVIDIA employee would have chosen a sensible hard-to-crack password, and ensured that they weren’t using the same password anywhere else on the internet...

View Details

Many of us might need a helping hand to defeat our video game rivals, but you could end up shooting yourself in the foot.

View Details

Video game company Ubisoft, maker of hit titles like Assassin’s Creed and Just Dance says that it has “experienced a cyber security incident” - and as a consequence is changing its employees' passwords.

View Details

The FBI has warned that the Ragnar Locker gang has infected at least 52 critical infrastructure organisations across America with its ransomware.

Read more in my article on the Tripwire State of Security blog.

View Details

I would like to think that you're all smart enough to know better, but just in case...

No, there aren't women in Ukraine are keen to have a sexy webcam chat with you right now. But that doesn't mean spammers aren't trying to convince you otherwise...

View Details

The most famous policeman in Nigeria is in hot water over his links to Hushpuppi, has your Amazon Echo been talking to itself, and can an AI girlfriend save your marriage?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

Plus don't miss our featured interview with Jason Meller of Kolide.

View Details

Researchers have discovered a novel way of exploiting Amazon Echo smart speakers to perform commands.

They get the Amazon Echo speaker to say the commands to itself.

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Forcepoint. Thanks to the great team there for their support! Remember when you thought an antivirus was all you needed to keep safe from digital danger? Of course, cybersecurity has never truly been that simple. As cyberthreats and business operations have grown more … Continue reading "Forcepoint ONE simplifies your security"

View Details

Oh how embarrassing for the criminal gang who extorted millions from businesses by threatening to leak their data, that someone leaked some 160,000 messages between their members as well as their malware source code.

View Details

Yes, having access to Facebook would leave ordinary Russians open to crazy QAnon theories, anti-vax propaganda, and a myriad of narrow echo chambers. But it would also give them a chance to seek out independent reporting on the horrific invasion of Ukraine by Russia.

View Details

New legislation, unanimously passed by the US Senate could - amongst other things - require organisations working in critical industry sectors to alert the US Government about hacks and ransomware attacks.

Read more in my article on the Tripwire State of Security blog.

View Details

Why might Russian EV chargers be displaying an anti-Putin message? Why are Telegram groups sharing sharing explicit images of women without their consent? And who is watching you in the workplace?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Jessica Barker.

View Details

Graham Cluley Security News is sponsored this week by the folks at Teleport. Thanks to the great team there for their support! Imagine the scene – you’re woken up at 3 am, only to discover your worst nightmare. The new intern just accidentally deleted the production database during routine maintenance. You quickly restore from a … Continue reading "Who deleted the database? Find out with Teleport"

View Details

As widely anticipated, the conflict between Russia and Ukraine has heated up on cyberspace in the days since Vladimir Putin ordered his troops and tanks to invade.

This weekend saw the Kremlin's official website at kremlin.ru brought down, along with other Russian government sites, in what appears to have been a co-ordinated distributed denial-of-service (DDoS) attack.

Read more in my article on the Hot for Security blog.

View Details

A game, developed by the so-called IT Army of Ukraine, makes it easy for anyone around the world to contribute to the overloading of Russian websites while playing a version of the simple sliding puzzle "2048."

View Details

CERT-UA, the national Computer Emergency Response Team for Ukraine, has issued a warning of a major phishing campaign launched against military personnel.

The attack is being blamed on the UNC1151 hacking group , which is based in Minsk and whose members are said to be officers of the Ministry of Defence in Belarus.

Read more in my article on the Hot for Security blog.

View Details

A Manhattan couple in their 30s have been arrested in Manhattan in connection with the 2016 hack of cryptocurrency exchange Bitfinex.

Read more in my article on the Hot for Security blog.

View Details

'Tis the season for tax scams here in the UK, and it's no surprise to learn that scammers are spamming out fraudulent messages posing as HMRC.

Thankfully, at least some accountants are warning their clients about the danger of falling for a phish.

View Details

Bridge cryptocurrency hack follows bridge cryptocurrency hack follows bridge cryptocurrency hack.

View Details

Who's wearing the pyjamas while they take down North Korea's internet? Is it a case of cop or cosplay in Oregon? And what's to fear about the metaverse?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.

View Details

Last month, as North Korea's supreme leader Kim Jong-un oversaw a series of sabre-rattling hypersonic missile tests, cyber attacks disrupted the country's internet infrastructure. But who was responsible?

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at Teleport. Thanks to the great team there for their support! You’re woken up at 3 am, only to discover your worst nightmare. The new intern just deleted the production database during routine maintenance by accident. You quickly restore from a backup. During the … Continue reading "Who dropped the DB? Find out with Teleport Database Access"

View Details

Vodafone customers in the UK are spitting tacks after an "issue" has left them unable to use Twitter properly for days, after the display of images and movie files, and - in some cases - the entire website, was blocked.

View Details

BlackCat (also known as ALPHV) is a relatively new ransomware-as-a-service operation, which has been aggressively recruiting affiliates from other ransomware groups and targeting organisations worldwide.

Read more in my article on the Tripwire State of Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at HYPR. Thanks to the great team there for their support! A new guide provides practical guidance for eliminating passwords to accelerate your Zero Trust strategy, and explains how Zero Trust can increase business agility. The free guide, by the analysts at The Cyber … Continue reading "Zero trust with zero passwords – free guide explains what you need to know"

View Details

Who's that new guy working at your company, and why don't you recognise him from the interview? How are hacktivists raising the heat in Belarus? And should you be fully vaxxed for your online date?

All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.

View Details

The IT systems of KP Snacks have been hit by ransomware. And it might well impact the British public's waistlines as well as the company's profits:

View Details

Facebook users are being warned of a phishing campaign that tries to break into accounts, disguised as a Facebook Messenger chat from a friend.

Read more in my article on the Hot for Security blog.

View Details

Qubit, a decentralized finance (DeFi) platform, has publicly offered $2,000,000 to a hacker who stole $80 million worth of cryptocurrency from it last week.

Read more in my article on the Hot for Security blog.

View Details

Andorra Telecom, the tiny microstate's only internet service provider, says that a barrage of distributed denial-of-service (DDoS) attacks impacted the country's internet and 4G service.

Read more in my article on the Hot for Security blog.

View Details

Graham Cluley Security News is sponsored this week by the folks at HYPR. Thanks to the great team there for their support! The analysts at The Cyber Hut have produced a new guide that explains how Zero Trust can increase business agility, and provides practical guidance for eliminating passwords to accelerate your Zero Trust strategy. … Continue reading "“A Journey to Zero Trust With Zero Passwords” – download the free guide now"

View Details

A Canadian man has been handed a three year prison sentence after being found guilty of buying and selling over 1700 stolen identies on a dark web marketplace, and collaborating with the notorious Dark Overlord extortion gang.

Read more in my article on the Tripwire State of Security blog.

View Details

An independent researcher has received a $100,500 bug bounty from Apple after discovering a security hole in the company's Safari browser for macOS that could allow a malicious website to hijack accounts and seize control of users' webcams.

Read more in my article on the Hot for Security blog.

View Details

Wordle - good or bad for the world? Whatever your opinion, at least someone wants to spoil players' fun. Meanwhile, we take a look at the threat mobile phones can pose to your mental health.

All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.

View Details

Apple has released urgent security updates for its customers, following the discovery of zero-day vulnerabilities that can be used to hack into iPhones, iPads, and Macs.

View Details

Four US states have launched a law suit against Google, claiming that the technology giant continued to track users' location, even when they users had asked it not to.