The UK Government takes aim at IoT devices shipping with weak or default passwords, an identity thief spends two years in jail after being mistaken for the person who stole his name, and are you au fait with the latest scams?All this and much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin.
A wave of cheap, crude, amateurish ransomware has been spotted on the dark web - and although it may not make as many headlines as LockBit, Rhysida, and BlackSuit, it still presents a serious threat to organizations.Read more in my article on the Tripwire State of Security blog.
Czech news agency ČTK announced on Tuesday that a hacker had managed to break into its systems and published fake news reports of a plot to murder the president of a neighbouring country.Read more in my article on the Hot for Security blog.
Leicester City Council suffers a crippling ransomware attack, and a massive data breach, but is it out of the dark yet? And as election fever hits India we take a close eye at deepfakery.All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
The UK's Leicester City Council was thrown into chaos last month when a crippling cyber attack forced it to shut down its IT systems and phone lines.But the ransomware attack also had a more unusual impact...Read more in my article on the Hot for Security blog.
February's crippling ransomware attack against Change Healthcare, which saw prescription orders delayed across the United States, continues to have serious consequences.Read more in my article on the Hot for Security blog.
The international hotel chain Omni Hotels & Resorts has confirmed that a cyber attack last month saw it shut down its systems, with hackers stealing personal information about its customers.Read more in my article on the Exponential-E blog.
Police have successfully infiltrated and disrupted the fraud platform "LabHost", used by more than 2,000 criminals to defraud victims worldwide.Read more in my article on the Tripwire State of Security blog.
Take That's Gary Barlow chats up a pizza-slinging granny from Essex via Facebook, or does he? And a scam takes a sinister turn - for both the person being scammed and an innocent participant - in Ohio.All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Law enforcement officers in Zambia have arrested 77 people at a call centre company they allege had employed local school-leavers to engage in scam internet users around the world.Read more in my article on the Hot for Security blog.
The East Central University (ECU) of Ada, Oklahoma, has revealed that a ransomware gang launched an attack against its systems that left some computers and servers encrypted and may have also seen sensitive information stolen.Read more in my article on the Hot for Security blog.
Learn more about the DragonForce ransomware - how it came to prominence, and some of the unusual tactics used by the hackers who extort money from companies with it.Read more in my article on the Tripwire State of Security blog.
If 25 documents stolen is "very serious," I'm not sure the words exist to describe the 1.3 terabytes of data that Leicester City Council now says it has had stolen by hackers.
MPs aren't just getting excited about an upcoming election, but also the fruity WhatsApp messages they're receiving, can we trust AI with our health, and who on earth is pretending to be a producer for the Drew Barrymore TV show?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by John Hawes.
Targus, the well-known laptop bag and case manufacturer, has been hit by a cyber attack that has interrupted its normal business operations.Read more in my article on the Hot for Security blog.
Two China-based Android app developers are being sued by Google for an alleged scam targeting 100,000 users worldwide through fake cryptocurrency and other investment apps.Read more in my article on the Hot for Security blog.
Google has issued a security advisory to owners of its Android Pixel smartphones, warning that it has discovered someone has been targeting some devices to bypass their built-in security.Read more in my article on the Tripwire State of Security blog.
New research has found that ransomware remediation costs can explode when backups have been compromised by malicious hackers - with overall recovery costs eight times higher than for those whose backups are not impacted.Read more in my article on th Exponential-e blog.
Google says it is deleting the your Google Chrome Incognito private-browsing data that it should never have collected anyway. Can a zero-risk millionaire-making bot be trusted? And what countries are banned from buying your sensitive data?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford.
Amazon failed to deliver an iPhone 15 to my home, but claims I am not eligible for a refund.Is there anybody at Amazon who still cares about looking after their legitimate honest customers?
The UK's Office for Nuclear Regulation (ONR) has started legal action against the controversial Sellafield nuclear waste facility due to years of alleged cybersecurity breaches.Read more in my article on the Hot for Security blog.
Deepfakes are being used for good (perhaps), common usernames could pose a security threat, and someone has paid a $500,000 fee... just to send $1,865.
Oh, and our guest mentions Mr Blobby (to the horror of the show's hosts...)
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.
State-sponsored hackers, backed by the regime in North Korea, are believed to be using zero-day exploits to target cybersecurity researchers working in the field of vulnerability research and development.
Read more in my article on the Hot for Security blog.
A Texas court has heard how last month a gang of men used a Raspberry Pi device to steal thousands of dollars from ATMs.Read more in my article on the Tripwire State of Security blog.
AI news is bad news, an online service to catch your cheating partner, and an IoT-enabled dick cage fails to keep a grip on its own security.
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.
Plus don't miss our featured interview with Alex Lawrence, principal security architect at Sysdig.
The ShinyHunters hacking group has claimed that in the last couple of months it has stolen more than 30 million customer order records from Pizza Hut Australia, alongside information on more than one million customers.Read more in my article on the Hot for Security blog.
An attack by the notorious LockBit ransomware gang stole 10 GB of data from a company that provides high-security fencing for military bases.
Graham Cluley Security News is sponsored this week by the folks at Deep Instinct. Thanks to the great team there for their support! Deep Instinct protects the data of the world’s largest brands by delivering on the promise of threat prevention with the only cybersecurity platform fully powered by Deep Learning. We have pioneered predictive … Continue reading "Deep Instinct takes a prevention-first approach to stopping ransomware and other malware using deep learning"
Freecycle, an online community that encourages sharing unwanted items with eachother than chucking them in the bin or taking them to landfill, has told users to change their passwords after it suffered a data breach.
Fashion chain Forever 21 has suffered what it has described as a "data security incident" that saw a hacker gain access to its systems for months, and exposed the personal details of 539,207 current and former employees.Read more in my article on the Hot for Security blog.
Seized cryptocurrency is stolen from the DEA, blue-ticks are being exploited, a bath full of dollar bills, the comfort offered by an ostrich’s head, and how Graham is refusing to call Twitter “X”.
All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC), the agency responsible for the nation's defences against cyber attacks, has itself been hacked.
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at PlexTrac. Thanks to the great team there for their support! If you are investing in solutions for continuous assessment and validation or breach and attack simulation, you know that managing the data and remediation efforts necessary to make real progress can be overwhelming. … Continue reading "Ready to enhance your continuous assessment efforts? Meet PlexTrac"
A London court has found two British teens responsible for a spree of high profile hacks, including one that saw the leaking of source code and videos of Rockstar Games's as-yet unreleased "Grand Theft Auto 6."
Read more in my article on the Hot for Security blog.
After a series of high-profile cryptocurrency hacks, the state-sponsored North Korean Lazarus Group is poised to cash out millions of dollars.
Read more in my article on the Tripwire State of Security blog.
Surely you should be able to order pizza without being pestered for sex? And Carole takes a look at the what and why of wearables...
All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Surely you should be able to order pizza without being pestered for sex or a date?
So, how come so many young people are claiming that they are being hassled after ordering an online delivery?
Read more in my article on the Hot for Security blog.
The BlackCat ransomware gang has claimed credit for a cybersecurity attack against Japanese watchmaker Seiko.
BlackCat (also known as ALPHAV) posted on its dark web leak site what it claims are files stolen from Seiko's servers.
Security researchers have identified that a widespread LinkedIn hacking campaign has seen many users locked out of their accounts worldwide.
Read more in my article on the Tripwire State of Security blog.
Are you the kind of person who runs the beta-test versions of mobile apps before they are officially released? If so, the FBI is warning you to be on your guard.
Read more in my article on the Hot for Security blog.
AI chatbots are under fire in Las Vegas, the secrets of hackers’ passwords are put under the microscope, and Graham reveals (possibly) the greatest TV programme of all time.
All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Someone clearly isn't very impressed with Vladimir Putin, as the Russian economy continues to tank in the wake of sanctions.
The LockBit ransomware gang may be having more than a few headaches right now.
According to a researcher who spent a year undercover gathering intelligence on the LockBit group, the ransomware gang is trying to cover up "the fact it often cannot consistently publish stolen data."
'Ello ello ello. What's all this then?
Just days after it was learned that the police had exposed the details of their 10,000 staff in Northern Ireland, another force has admitted to an embarrassing breach of sensitive data.
Read more in my article on the Hot for Security blog.
Security researchers have demonstrated how they were able to exploit a flaw which allowed them to hack the card-shuffling devices used in casinos and poker rooms.
Read more in my article on the Hot for Security blog.
I doubt there will be many people shedding tears at the news that a stalkerware company has announced it is permanently ceasing operations at the end of this month - after it suffered a devastating data breach.
Read more in my article on the Hot for Security blog.
Earlier this week, the details of all 10,000 staff at the Police Service of Northern Ireland (PSNI) were exposed after a spreadsheet containing the data was mistakenly published online.
Rhysida is a Windows-based ransomware operation that has come to prominence since May 2023, after being linked to a series of high profile cyber attacks in Western Europe, North and South America, and Australia.
Learn more in my article on the Tripwire State of Security blog.
Razzlekhan, the self-proclaimed Crocodile of Wall Street, pleads guilty to the biggest crypto laundering scheme in history, and just how safe are you typing while on a Zoom call?
Meanwhile, Graham rants about public EV chargers.
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Graham Cluley Security News is sponsored this week by the folks at Jotform. Thanks to the great team there for their support! What is form encryption, and why is it important? Whether you’re a pro with forms or just a newbie, it might be helpful to get an understanding of form encryption and why E2EE … Continue reading "Keep your sensitive data secure by using Encrypted Forms 2.0 from Jotform"
Newly-released research reveals the eye-watering costs that the manufacturing sector has suffered in recent years at the hands of ransomware.
Read more in my article on the Tripwire State of Security blog.
Carole takes us into the sinister side of Barbie, while Graham describes a stalkerware operation that has been spilling its secrets.
All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Critical security vulnerabilities in a WordPress plugin used on around 900,000 websites, allow malicious hackers to steal sensitive information entered on forms.
Read more in my article on the Hot for Security blog.
After a ransomware attack which saw the personal information of 28,000 individuals stolen by hackers, Hawaii Community College has confirmed that it has paid a ransom.
CardioComm, a Canadian company which provides heart-monitoring technology to hospitals and consumers, has revealed that it has been forced to take its systems offline following a cyberattack.
Read more in my article on the Hot for Security blog.
New rules requiring publicly-listed firms to disclose serious cybersecurity incidents within four days have been adopted by the US Securities and Exchange Commission (SEC).
The tough new rules, although undoubtedly well-intentioned, are likely to leave some firms angry that they being "micromanaged" and - it is argued - could even assist attackers.
Read more in my article on the Tripwire State of Security blog.
Dr 90210 finds himself in a sticky situation after his patients' plastic surgery photos AND more end up in the hands of hackers, emails to the US military end up in the wrong hands, and script kiddies salivate at the thought of Business Email Compromise powered by generative AI.
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by T-Minus Space Daily’s Maria Varmazis.
Yamaha Corporation, the world's largest producer of musical equipment, has confirmed that has suffered a "cybersecurity incident" during which hackers gained unauthorised access to its systems, and stole data.
Read more in my article on the Hot for Security blog.
Fake blockchain games, that are being actively promoted by cybercriminals on social media, are actually designed to infect the computers of unsuspecting Mac users with cryptocurrency-stealing malware.
Graham Cluley Security News is sponsored this week by the folks at PlexTrac. Thanks to the great team there for their support! Reports are the critical deliverables that make pentest results actionable, but do they have to be so painful to prepare? Not anymore. Check out our guide to writing a killer pentest report. And … Continue reading "How to write a killer pentest report"
Some employees at Google will have internet access from their desktop PCs significantly restricted, with only internal web-based tools and Google-owned sites such as Google Drive, Google Maps, and Gmail accessible.
But will such an approach protect the tech giant from attacks?
Read more in my article on the Hot for Security blog.
If you thought hackers might be causing your company a few headaches, pity the folks at Estée Lauder.
Two different ransomware groups have listed the cosmetics maker on their leak sites on the dark web, as a result of seemingly separate attacks.
Read more in my article on the Hot for Security blog.
The FBI warns that tech support scammers are increasingly telling their victims to send actual cash, concealed in newspaper or a magazine, rather than wiring funds.
But why?
Read more in my article on the Tripwire State of Security blog.
Former Prime Minister Boris Johnson wants to hand over his WhatsApp messages - or does he? And a couple of fun-loving girls from Aberdeen have come up with a sinister twist on sextortion scams.
All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley (from a mystery location) and Carole Theriault.
A federal grand jury has indicted a former employee of a contractor operating a California town's wastewater treatment facility, alleging that he remotely turned off critical systems and could have endangered public health and safety.
Read more in my article on the Tripwire State of Security blog.
A London court has heard that two British teens hacked and blackmailed a series of companies, causing millions of dollars worth of damage.
Read more in my article on the Hot for Security blog.
Going for a jog can be bad for your privacy (but even worse for your health), and Britain's consumer finance champion finds his face is being faked.
All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
A computer security engineer has been charged in connection with a multi-million dollar hack of a cryptocurrency exchange.
Read more in my article on the Hot for Security blog.
A British IT worker who exploited a ransomware attack against the company he worked for, in an attempt to extort money from them for himself, has been sentenced to jail for three years and seven months.
There's good news for any business that has fallen victim to the Akira ransomware.
Security researchers have developed a free decryption tool for files that have been encrypted since the Akira ransomware first emerged in March 2023.
Read more in my article on the Tripwire State of Security blog.
Just how much do porn websites know about your sexual peccadillos? How are Barbie dolls involved in identity scams? And would you trust a completely free telly?
Oh, and Graham has some opinions to share about "Indiana Jones and the Dial of Destiny".
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Matt Davey from the "Random but Memorable" podcast.
Staff at Dublin Airport have been warned that their personal data has fallen into the hands of hackers, following a data breach at a third-party service provider.
Read more in my article on the Hot for Security blog.
Suncor, one of the largest energy companies in North America, has suffered a cyber attack that left Canadian motorists unable to make gas station purchases with payment cards, and even disabled car washes.
Read more in my article on the Hot for Security blog.
UPS delivers some smishing advice (but have they kept something under wraps?), we ask ChatGPT to take a long hard look at itself, and we debate what the penalty should be for taking national secrets home with you.
All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown’s sole founder Thom Langford.
Back in 2020, law enforcement agents across Europe had a major breakthrough in their fight against organised crime. They managed to crack into EncroChat - a secure encrypted messaging service which ran on modified Android phones, that promised "worry-free secure communications".
But investigators managed to gain full control of EncroChat's infrastructure, and could read users' supposedly-encrypted messages in real-time.
Graham Cluley Security News is sponsored this week by the folks at Infoblox. Thanks to the great team there for their support! At Infoblox, we know that the most important thing to prevent potential attacks against DNS is to understand it and get the right tools and techniques to defend DNS infrastructure. Assembled by the … Continue reading "DNS can speed up response to threats and make security operations more productive"
The city of Fort Worth in Texas announced on Saturday that it had suffered a security breach that saw hackers claim to have gained unauthorised access to data.
But it doesn't appear, for now at least, that the hackers are attempting to extort a ransom from the city...
Read more in my article on the Hot for Security blog.
It wasn't a great weekend for video game fans, as players of Diablo IV multiplayer role-playing game were greeted with an error message as it tried to connect to the servers of developer Blizzard.
The NSA has publsihed a guide about how to mitigate against attacks involving the BlackLotus bootkit malware, amid fears that system administrators may not be adequately protecting against the threat.
Read more in my article on the Tripwire State of Security blog.
If you have an Apple computer, watch, or smartphone you have hopefully already received a notification that you should install an update to your operating system.
And yes, you really should update your devices.
Fancy $10 million? Of course you do!
Well, all you have to do is provide information that helps identify or locate members of the notorious Cl0p ransomware gang.
Patients of a Beverly Hills plastic surgery clinic face the potential horror of having highly sensitive images of their bodies leaked onto the internet by hackers.
Read more in my article on the Hot for Security blog.
There's some funny business going on on Google, and Zuckerberg's $14 billion bet on the metaverse is beginning to look a little childish...
All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Snack giant Mondelez is warning past and present employees that their personal information may now be in the hands of hackers following a data breach at a third-party firm.
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Uptycs. Thanks to the great team there for their support! Your developer’s laptop is just a hop away from cloud infrastructure. Attackers don’t think in silos, so why would you have siloed solutions protecting public cloud, private cloud, containers, laptops, and servers? Uptycs … Continue reading "Ensure the security and reliability of your applications at every stage, from development to production, with Uptycs"
In the 12 months running up to May 2023, the login credentials of over 100,000 hacked ChatGPT accounts found their way onto dark web marketplaces.
Read more in my article on the Hot for Security blog.
There are shocking revelations about a US Government data suck-up, historic security breaches at Windsor Castle, and the MOVEit hack causes consternation.
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.
Earlier this year I was invited by Vodafone to appear on an episode of "Learning Curve", a series for founders, business leaders and - indeed - those who wish to be a business leader.
You won't be surprised to hear that the topic I was being asked about was cybersecurity
The UK's broadcasting regulator, Ofcom, has confirmed that it is amongst the organisations whose data has been stolen as a result of the massive MOVEit supply-chain cyber attack.
Read more in my article on the Hot for Security blog.
More than ten years after the hack of the now-defunct Mt. Gox cryptocurrency exchange, the US Department of Justice says it has identified and charged two men it alleges stole customers' funds and the exchange's private keys.
Read more in my article on the Tripwire State of Security blog.
Barracuda Networks is taking the unusual step of telling its customers to physically remove and decommission its hardware.
If you, or your kids, are fans of Minecraft - you might be wise to not download any new mods of plugins for a while.
Read more in my article on the Tripwire State of Security blog.
Australia's signal intelligence agency calls upon an Eighties popstar to fight terrorism, and a simple act of kindness leads to a woman being scammed for thousands.
All this and much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Plus don't miss our featured interview with Max Power of Bitwarden.
TikTok is making headlines again, and - as usual - it's not for a good reason.
Read more in my article on the Hot for Security blog.
The Russia-linked cybercrime gang thought to be behind a hack that has impacted companies around the world has posted a message to its corporate victims.
In short, firms affected by the MOVEit hack are being told to congtact the Cl0p ransomware group before June 14, or face the consequences.
North Korean state-sponsored hackers are targeting think tanks, research centres, media organisations, and academics in the United States and South Korea to gather intelligence.Read more in my article on the Hot for Security blog.
Staff at the BBC have been warned that their personal data may now be in the hands of cybercriminals, following the exploitation of a vulnerability in a software tool used by the company that manages their payroll.
Twitter awarded "gold checkmark" to unofficial Disney Twitter account which posted racial slurs.Is it any wonder that Twitter's ad sales in the United Sales have plunged 59% in the past year?
Jetpack. an extremely popular WordPress plugin that provides a variety of functions including security features for around five million websites, has received a critical security update following the discovery of a bug that has lurked unnoticed since 2012.Read more in my article on the Tripwire State of Security blog.
height="315" class="aligncenter size-full wp-image-292324" />ChatGPT hallucinations cause turbulence in court, a riot in Wales may have been ignited on social media, and do you think .MOV is a good top-level domain for "a website that moves you"?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Plus don't miss our featured interview with David Ahn of Centripetal.
RaidForums, the notorious hacking and data leak forum seized and shut down by the authorities back in April 2022, is - perhaps surprisingly - at the centre of another cybersecurity breach.
Scandinavian Airlines (SAS) has received a US $3 million ransom demand following a prolonged campaign of distributed denial-of-service (DDoS) attacks against its online services.Read more in my article on the Hot for Security blog.
The BBC reports that the Venezuelan government is paying people to tweet in support of it, in an attempt to drown out the noise of its critics.
I know this will come as a shock to many of you, but scammers have once again succeeded in stealing a lot of money from cryptocurrency investors.Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at PureDome. Thanks to the great team there for their support! PureDome offers a secure, quick, reliable solution that enhances and safeguards business network security. With seamless deployment, you can effortlessly expand your corporate network without sacrificing performance. By consolidating critical aspects of user … Continue reading "Protect your business network with PureDome"
Bad enough for your company to be held to ransom after a cyber attack.Worse still to then have one of your own employees exploit the attack in an attempt to steal the ransom for themselves.Read more in my article on the Tripwire State of Security blog.
Graham Cluley Security News is sponsored this week by the fab folks at Kolide. Thanks to the great team there for their support! Right now, “Zero Trust” is in serious danger of becoming an empty buzzword. The problem isn’t just that marketers have slapped the Zero Trust label on everything short of breakfast cereal–it’s that … Continue reading "Can zero trust be saved?"
I was surprised to receive an email this week telling me that I had renewed my annual subscription for McAfee virus protection.Would you, or a member of your family, have fallen for this scam?
13 years jail for spoofing scammer, a rogue IT security expert’s Bitcoin blackmail goes wrong, and Facebook’s eyewatering GDPR fine may be only the beginning of its problems.All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by the Imposter Syndrome Network podcast’s Zoë Rose.
The Indian manufacturing plant responsible for manufacturing Suzuki motorcycles has been forced to shut down following a cyber attack, with the loss of an estimated 20,000 vehicles.Read more in my article on the Hot for Security blog.
Since earlier this month some owners of HP OfficeJet printers have been reporting that they are faced with a blue screen error message, and a bricked device.Read more in my article on the Hot for Security blog.
Personal details of more than 100,000 pension holders may have been stolen by the hackers.And that's just the tip of the iceberg...
A joint alert has been issued by US government agencies, advising organisations of the steps they should take to mitigate the threat posed by BianLian ransomware attacks.Read more in my article on the Tripwire State of Security blog.
Personal information is going for a song, and the banks want social media sites to pay when their users get scammed.All this and much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
There's good news if you're plagued by shared Google Drive files from strangers. Google Drive is getting a spam folder.
Google has announced a new policy on dealing with inactive accounts - and it's an important read for anyone who doesn't regularly login.Read more in my article on the Hot for Security blog.
Twitter's new "encrypted DM" feature is a costly (and weaker) alternative to proper end-to-end encrypted messages.
Graham Cluley Security News is sponsored this week by the folks at Expel. Thanks to the great team there for their support! Expel wanted to find out what cybersecurity issues were most important to organisations in the United Kingdom, so it surveyed 500 IT decision-makers (ITDMs) to get a better sense for the state of … Continue reading "Expel’s UK cybersecurity landscape report sheds light on the challenges facing organisations"
Cybercriminals have developed a new malware threat which can steal highly sensitive data from the Mac computers it infects.
es, you should be worried about the threat posed by external hackers. But also consider the internal threat posed by insiders and rogue employees - the people you have entrusted to act responsibly with the data of your company and your customers.Read more in my article on the Hot for Security blog.
Akira is a new family of ransomware, first used in cybercrime attacks in March 2023.Read more about the threat in my article on the Tripwire State of Security blog.
After covering up a data breach that impacted the personal records of 57 million Uber passengers and drivers, the company's former Chief Security Officer has been found guilty and sentenced by a US federal judge.Read more in my article on the Hot for Security blog.
Millions of WordPress-powered websites are using the Advanced Custom Fields and Advanced Custom Fields Pro plugins, which security researchers say have been vulnerable to cross-site scripting (XSS) attacks.
Cinema chain Odeon may have shared more information than it intended in the release notes accompanying its latest iOS app update.
Businesses should patch their TP-Link routers as soon as possible, after the revelation that a legendary IoT botnet is targeting them for recruitment.Read more in my article on the Tripwire State of Security blog.
Apple and Google have announced that they are teaming up in order to combat the safety risks associated with AirTags and other tracking devices.Read more in my article on the Hot for Security blog.
Two unsavoury websites suffer from a worrying leak, scientists are going animal crackers over AI, and the BBC is intercepting scammers’ live phone calls with victims. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week … Continue reading "Smashing Security podcast #320: City Jerks, AI animals, and is the BBC hacking again?"
Graham Cluley Security News is sponsored this week by the folks at Intego. Thanks to the great team there for their support! Established in 1997, Intego is the leading company for Mac antivirus, providing powerful and reliable protection against malware, viruses, and other online threats. Intego offers a wide range of comprehensive security products designed … Continue reading "Fortify your Mac with Intego – the award-winning Mac antivirus"
Students and teachers at the Minneapolis Public School (MPS) District, which suffered a huge ransomware attack< at the end of February, have had highly sensitive information about themselves published on the web, including allegations of abuse by teachers and psychological reports.Read more in my article on the Hot for Security blog.
Boffins at McAfee have identified 38 Android apps in the Google Play store that unashamedly rip off the ever-popular gaming sensation Minecraft, but are actually designed to stealthily earn advertising revenue.
Is it possible ransomware gangs actually do have a heart?Read more in my article on the Hot for Security blog.
Wednesday was the official Independence Day of Israel, and the event was "celebrated" in typical style by malicious hackers.Read more in my article on the Hot for Security blog.
Iranian state-sponsored hacking group Charming Kitten has been named as the group responsible for a new wave of attacks targeting critical infrastructure in the United States and elsewhere.Read more in my article on the Tripwire State of Security blog.
A boss is bitten in the bottom after being struck by one of the worst crimes in Finnish history, Strava’s privacy isn’t so private, and a private investigator uncovers some TikTok tall tales. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham … Continue reading "Smashing Security podcast #319: The CEO who also ran IT, Strava strife, and TikTok tall tales"
Eurocontrol, the European air traffic control agency, has revealed that it has been under cyber attack for the last week, and says that pro-Russian hackers have claimed responsibility for the disruption.When you first see the headline in the likes of the Wall Street Journal, it's a scary thing to read. But dig a little deeper, and you realise that the err.. sky is not falling.Read more in my article on the Hot for Security blog.
Were you a US-based Facebook user between May 24 2007 and December 22 2022?If so, I've got some good news for you.Read more in my article on the Hot for Security blog.
Three Nigerian nationals face charges in a US federal court related to a business email compromise (BEC) scam that is said to have stolen more than US $6 million from victims.Read more in my article on the Tripwire State of Security blog.
In the last couple of days it has become clear that the notorious LockBit ransomware gang has been exploring creating what could become a big headache for users of Mac computers.
I'm still encountering people who, even after all these years, believe that their Apple Mac computers are somehow magically invulnerable to ever being infected by malware.Maybe details of this new Mac malware will change their mind...
A Finnish court has given the former CEO of a chain of psychotherapy clinics a suspended jail sentence after failing to adequately protect highly sensitive notes of patients' therapy sessions from falling into the hands of blackmailing hackers.Read more in my article on the Hot for Security blog.
Multinational payment processing firm Nexway has been rapped across the knuckles by the US authorities, who claim that the firm knowingly processed fraudulent credit card payments on behalf of tech support scammers.Read more in my article on the Tripwire State of Security blog.
Graham wonders what would happen if his bouncing buttocks were captured on camera by a Tesla employee, and we take a look at canny scams connected to China's Operation Fox Hunt.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
The emergency ditching of an Australian military helicopter in the water just off a beach in New South Wales, has been blamed on the failure to apply a software patch.Read more in my article on the Hot for Security blog.
Accountants are being warned to be on their guard from hackers, as cybercriminals exploit the rush to prepare tax returns for clients before the deadline of US Tax Day.Read more in my article on the Tripwire State of Security blog.
The US Department of Justice has arrested a member of the US Air Force National Guard in connection with a high profile leak of classified Pentagon documents.Here are my thoughts...
Everyone's talking juice-jacking - but has anyone ever been juice-jacked? Uber suffers yet another data breach, but it hasn't been hacked. And Carole hosts the "AI-a-go-go or a no-no?" quiz for Dave and Graham.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.
Travellers are being told to be wary when plugging their smartphones and laptops into USB chargers.But has anyone ever actually been juice-jacked in the real world?
A pro-Russian blogger who raised $25,000 for drones to assist Russian troops fighting in Ukraine, has received a huge delivery of sex toys instead.Read more in my article on the Hot for Security blog.
On Tuesday 11 April, I'll be joined by the CISOs of security firms Wiz, Rubrik, Noname, and Abnormal, for a friendly chat about how they protect their organisations from the huge number of threats targeting them.I hope to see some of you there!
Hacker can remotely open or close garage doors, seize control of alarms, and switch on (or switch off) customers' "smart" plugs due to vulnerabilities in Nexx products.
An Elon Musk-worshipping college principal gets schooled, and rapper Afroman turns the tables after armed police raid his house.All this and much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
My guess is that if you stumbled across a website that called itself "Hack the Pentagon" and was decorated with a grisly-looking skull, you would probably think that you might be somewhere less than legitimate.After all, normally if you hacked The Pentagon you would find yourself in heaps of trouble.Read more in my article on the Hot for Security blog.
Malware, disguised as copies of Tor, has stolen approximately US $400,000 worth of cryptocurrency from almost 16,000 users worldwide.
31-year-old Solomon Ekunke Okpe, of Lagos, was a member of a gang that devised and executed a variety of scams - including business email compromise (BEC), romance scams, working-from-home scams, and more - between December 2011 and January 2017.Read more in my article on the Hot for Security blog.
A cryptocurrency hack leads us down a mazze of twisty little passages, Joe Biden's commercial spyware bill, and Utah gets tough on social media sites.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson.
There's bad news if you're someone who is keen to launch a Distributed Denial-of-Service (DDoS) attack to boot a website off the internet, but don't have the know-how to do it yourself.Rather than hiring the help of cybercriminals to bombard a site with unwanted traffic or kick rivals out of a video game, you might be actually handing your details straight over to the police.Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Right now, “Zero Trust” is in serious danger of becoming an empty buzzword. The problem isn’t just that marketers have slapped the Zero Trust label on everything short of breakfast cereal–it’s that for … Continue reading "Can zero trust be saved?"
If you were sent a USB stick anonymously through the post, would you plug it into your computer?Perhaps you'll think twice when you hear what happened to these Ecuadorian journalists.Read more in my article on the Hot for Security blog.
A new report from ENISA, the European Union Agency for Cybersecurity, looking at cyberattacks targeting the European transport network over a period of almost two years, has identified that ransomware has become the prominent threat.Read more in my article on the Tripwire State of Security blog.
The world has gone ChatGPT bonkers.Which makes it an effective lure for cybercriminals who may want to break into accounts...
It could be a case of aCropalypse now for Google Pixel users, there’s a warning for house buyers, and just why is TikTok being singled out for privacy concerns?All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Thom Langford.
Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! What is one of the leading causes of breaches in the cloud? OMG, it’s still phishing! It’s no wonder CISOs push zero trust as a top priority. Identities are a top cloud target. … Continue reading "The hidden danger to zero trust: Excessive cloud permissions"
Have you ever shared a photograph where you've redacted some sensitive information?Perhaps you've cropped out part of the image you didn't want others to see?Well, users of Google's Pixel Android smartphone might be alarmed to learn that pictures they've shared in the past may have been less discreet than they imagined.Read more in my article on the Hot for Security blog.
Security researchers have released a new decryption tool which should come to the rescue of some victims of a modified version of the Conti ransomware, helping them to recover their encrypted data for free.Read more in my article on the Tripwire State of Security blog.
Well, this isn’t good.Google has issued a warning that some Android phones can be hacked remotely, without the intended victim having to click on anything.
The twisted tale of the two Teslas, and a deepfake sandwich.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
In its latest Patch Tuesday bundle of security fixes, Microsoft has patched a security flaw that was being used by the Magniber cybercrime gang to help them infect computers with ransomware.Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! Attacks targeting the software supply chain are on the rise and splashed across the news. SolarWinds raised awareness about the risk. More recent events, like the Federal Civilian Executive Branch (FCEB) agency breach, … Continue reading "Software supply chain attacks are on the rise — are you at risk?"
A Ukrainian video game developer has revealed that a hacker has leaked development material stolen from the company's systems, and is threatening to release tens of gigabytes more if their unorthodox ransom demands are not met.
The latest annual FBI report on the state of cybercrime has shown a massive increase in the amount of money stolen through investment scams.Read more in my article on the Hot for Security blog.
The boss of WhatsApp, the most popular messaging platform in the UK, says that it will not remove end-to-end encryption from the app to comply with requirements set out in the UK government's online safety bill.Learn more in my article on the Hot for Security blog.
Torrents on The Pirate Bay which claim to contain Final Cut Pro are instead being used to distribute cryptojacking malware to Macs.
The US Transportation and Security Administration (TSA) has issued new requirements for airport and aircraft operators who, they say, are facing a "persistent cybersecurity threat."Read more in my article on the Tripwire State of Security blog.
Scammers get pwned by a Canadian granny! Don't be seduced in a bar by an iPhone thief! And will the US Marshals be able to track down the villains who stole their data?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.Plus don’t miss our featured interview with Jason Meller of Kolide.
Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! This move to the cloud has made it easier to scale up applications when they need to grow. However, there is a corollary to this: Budgeting! Chances are, you’re probably overspending. Estimating how … Continue reading "Study reveals companies are wasting millions on unused Kubernetes resources"
A notorious ransomware gang has claimed responsibility for a cyber attack against Vesuvius, the London Stock Exchange-listed molten metal flow engineering company.
Willie Sutton, the criminal who became legendary for stealing from banks during a forty year career, was once asked, "Why do you keep robbing banks?"His answer? "Because that's where the money is."However, today there's a better target for robbers today than banks, which are typically well-defended against theft...Cryptocurrency wallets.Read more in my article on the Tripwire State of Security blog.
British high street giant WH Smith has revealed that it has suffered a "cybersecurity incident," which has seen hackers gain unauthorised access to its systems, and steal data including information related to current and former employees.
Following what it called a "cybersecurity incident" three weeks ago, Canadian bookstore chain Indigo has not only confirmed that it was hit by a ransomware attack, but also that data related to current and former employees was stolen by hackers.Read more in my article on the Hot for Security blog.
Who has been warning Italian criminals that their phones are wiretapped? Can you trust your voice to protect your bank account? And why is TikTok being singled out by investigators?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis.
Three men have been arrested by Dutch police in connection with ransomware attacks that blackmailed thousands of companies. Amongst them? An ethical hacker.Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Sysdig. Thanks to the great team there for their support! The unmanageable number of vulnerabilities in the cloud is the worst-kept secret. The Sysdig 2023 Cloud-Native Security and Usage report found that 87% of container images have high or critical vulnerabilities! Surely not … Continue reading "The cloud’s worst kept secret? Vulnerabilities"
Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Here’s an uncomfortable fact: at most companies, employees can download sensitive company data onto any device, keep it there forever, and never even know that they’re doing something wrong. Kolide’s new report, “The … Continue reading "That ticking noise is your end users’ laptops"
Malicious hackers are taking advantage of people searching the internet for free access to ChatGPT in order to direct them to malware and phishing sites.Read more in my article on the Hot for Security blog.
Earlier this month a cyber attack on food produce giant Dole caused the firm to shut down its production plants across North America for a period of time, and halt shipments to stores.Read more in my article on the Hot for Security blog.
Boyfriends who are bots, Facebook’s checkmark charge, Twitter Blue, and Will Ferrell’s taunt of football fans…All this and more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault.
Russian media has blamed hackers after commercial radio stations in the country broadcast bogus warnings about air raids and missile strikes, telling listeners to head to shelters.
A ransomware outfit is advising its victims to secretly tell them how much insurance they have, so their extortion demands will be met.Read more in my article on the Tripwire State of Security blog.
Many Twitter users have been presented with a message telling them that SMS-based two-factor authentication (2FA) will be removed next month.According to Twitter, only subscribers to its premium Twitter Blue service will be able to use text message-based 2FA to protect their accounts.Is that such a good idea?
A group calling itself "Anonymous Sudan" has claimed responsibility for a cyber attack which knocked the website of Scandinavian Airlines (SAS) offline earlier this week, and left customer data exposed.Read more in my article on the Hot for Security blog.
The owner of a Russian penetration-testing company has been found guilty of being part of an elaborate scheme that netted $90 million after stealing SEC earning reports.For nearly three years, 42-year-old Vladislav Klyushin - the owner of Moscow-based cybersecurity firm M-13 - and his co-conspirators had hacked into two US-based filing agents used by publicly-traded American companies to file earning reports to the Securities and Exchange Commission.Read more in my article on the Tripwire State of Security blog.
AI-generated voices are weaponised by online trolls, how ChatGPT reflects who we are as a society, and social media is in the firing line again. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by … Continue reading "Smashing Security podcast #309: Synthetic voices, ChatGPT reflections, and social skirmishes"
Towards the end of last year, malicious hackers broke into the systems of Pepsi Bottling Ventures, the largest privately-owned bottler of Pepsi-Cola beverages in the USA, and installed malware.For almost the month the malware secretly exfiltrated personally identifiable information (PII) from the company's network.Read more in my article on the Hot for Security blog.
A ransomware attack has again put the personal information of innocent parties at risk after it was revealed that a data breach has potentially exposed the medical records of more than three million people.Read more in my article on the Hot for Security blog.
A Dallas state agency has admitted to paying $170,000 to hackers after it suffered an attack from the Royal ransomware group.Read more in my article on the Hot for Security blog.
Want to sell some cocaine, ecstasy (MDMA), crystal meth, or magic mushrooms?Twitter could be the place for you. And the site isn't going to do anything to shut down your account.
Perhaps the biggest punishment of all will be Dennis Su's name being forever associated with an extraordinarily inept and cack-handed attempt to frighten people out of money.
When Ubiquiti suffered a hack the world assumed it was just a regular security breach, but the truth was much stranger... why are police happy that criminals keep using end-to-end encrypted messaging systems… and why is the Apple Watch being accused of crying wolf?All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Plus don't miss our featured interview with SecurEnvoy's Chris Martin.
Graham Cluley Security News is sponsored this week by the folks at Incogni. Thanks to the great team there for their support! Cybercrimes happen much more often than you might think and affect a growing amount of people. With crimes such as identity theft and various other scams, being mindful of your digital footprint is … Continue reading "How to remove yourself from the internet and from people search sites"
A former software engineer at Ubiquiti Networks has pleaded guilty to stealing gigabytes of data from the firm, attempting to extort millions of dollars, and damaging the company's reputation in the media.Read more in my article on the Hot for Security blog.
Vesuvius, the London Stock Exchange-listed molten metal flow engineering company, says it has shut down some of its IT systems after being hit by a cyber attack.
UK banking group TSB is calling on social networks and dating apps to better protect their users from fake profiles, following an alarming spike in romance fraud.Read more in my article on the Tripwire State of Security blog.
Could a senior Latvian politician really be responsible for scamming hundreds of "mothers-of-two" in the UK? (Probably not, despite Graham's theories...) And should we be getting worried about the AI wonder that is ChatGPT?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
Graham Cluley Security News is sponsored this week by the folks at Edgescan. Thanks to the great team there for their support! Edgescan simplifies Vulnerability Management (VM) by delivering a single full-stack SaaS solution integrated with world-class security professionals. Edgescan helps enterprise companies consolidate managing multiple point scanning tools for each layer of the attack … Continue reading "Take a tour of the Edgescan Cybersecurity Platform"
Planet Ice, which operates 14 ice rinks up and down the UK, has revealed that criminal hackers managed to break into its systems and steal the personal details of over 240,000 customers.Read more in my article on the Hot for Security blog.
The Kremlin-backed Gamaredon hacking group is being blamed for an attempted phishing attack against the Latvian Ministry of Defence.Read more in my article on the Hot for Security blog.
GoTo says that hackers stole its customers' "encrypted backups." But they also say the hackers stole the decryption keys.To say the backups were encrypted is a bit like trying to argue that a locked box is locked, if the key to the locked box is stolen at the same time as the box.
If you've purchased trainers from sports fashion retailer JD Sports in the past, your personal details could now be in the hands of hackers.Read more in my article on the Hot for Security blog.
Websites used by the Hive ransomware-as-a-service gang to extort ransoms and leak data stolen from corporate victims have been seized in a joint operation involving police around the world.
A 22-year-old suspected of being "Seyzo", a member of the ShinyHunters cybercrime gang, has been extradited from Morocco to the United States, where - if convicted - he could face up to 116 years in prison.The ShinyHunters gang became notorious in 2020, following a series of data breaches that impacted over 60 companies - including Microsoft. Read more in my article on the Tripwire State of Security blog.
What are prisoners getting up to with mobile phones? Why might ransomware no longer be generating as much revenue for cybercriminals? And how on earth did an airline leave the US government's "No Fly" list accessible for anyone in the world to download?All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.
Imagine you're an immigrant, who has fled your home country for the United States due to fear of being persecuted and tortured.What you definitely do not want is the agency handling your asylum request being careless with your personal information - and potentially putting your life and that of loved ones at risk.Read more in my article on the Hot for Security blog.
The important thing to realise about the most recently-reported data breach at email newsletter service Mailchimp is that it’s not just Mailchimp’s customer data that was put at risk.Even if you’re not personally a customer of Mailchimp, even if you’ve never even heard of Mailchimp, you may be affected.
Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! You know the old thought experiment about the AI designed to make paper clips, that quickly decides that in order to maximize paper clips, it will have to get rid of all the … Continue reading "Kolide – Endpoint security for people, not paper clips"
Anyone fancying a quick bite to eat in the UK may have found their choices more limited than usual on the high street.Nearly 300 fast food restaurants, including branches of KFC and Pizza Hut, were forced to close following a ransomware attack against parent company Yum! Brands.Read more in my article on the Hot for Security blog.
Wireless network operator T-Mobile has suffered yet another data breach.And we shouldn't be at all surprised if fraudsters use the information that they have stolen to send convincing phishing messages and scams.
It is the world's most active ransomware group - responsible for an estimated 40% of all ransomware infections worldwide.Find out what you need to know about LockBit in my article on the Tripwire State of Security blog.
For the second time in less than a year, email newsletter service Mailchimp has found itself in the embarrassing position of admitting it has suffered a data breach, putting its customers' subscribers at risk.
The Bitzlato cryptocurrency exchange has had its website seized by the authorities, after its Russian founder was charged with processing more than US $700m worth of "dirty money" on behalf of criminals.
Carole's in her sick bed, which leaves Graham in charge of the good ship "Smashing Security" as it navigates the choppy seas of credential stuffing and avoids the swirling waters of apps being sloppy with sensitive information.Find out more in this latest edition of the "Smashing Security" podcast, hosted by Graham Cluley with special guest BJ Mendelson.
Graham Cluley Security News is sponsored this week by the folks at SecurEnvoy. Thanks to the great team there for their support! We are often approached by organisations that depend on on-premise applications and data storage, who are looking for a multi-factor authentication solution, but are unable to move to a cloud-based solution for authentication. … Continue reading "Does your MFA solution secure access to your on-premise apps as well as those in the cloud?"
If you use Norton lifeLock as your password manager, your account may have been compromised.Learn more now.
A security breach may have cost current Formula 1 World Champion Max Verstappen an esports championship victory yesterday, and he's not happy.Read more in my article on the Hot for Security blog.
European law enforcement agencies have dealt a blow to scammers running call centres across the continent that stole millions of Euros from cryptocurrency investors.Crime-fighting authorities teamed up to tackle organised criminal groups who tricked unwary members of the public into investing in fake cryptocurrency schemes.Read more in my article on the Hot for Security blog.
It's time for you and your colleagues to become more skeptical about what you read.That's a takeaway from a series of experiments undertaken using GPT-3 AI text-generating interfaces to create malicious messages designed to spear-phish, scam, harrass, and spread fake news.Read more in my article on the Tripwire State of Security blog.
Someone called OxShagger thinks he has come up with the perfect Valentine’s surprise for Oxford students, but is the way he has gone about “bookworms with benefits” really a good idea? Robot security guards are trundling the streets of – you guessed it – America. And a writer of paranormal bully romances (no, we don’t know what that means either) returns from the grave...All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Andrew Agnês.
Three weeks after The Guardian newspaper was hit by a ransomware attack, it warns staff members that their personal data was accessed.
The experts at security firm Bitdefender have released a universal decryptor for victims of the MegaCortex family of ransomware, which is estimated to have caused more than 1800 infections - mostly of businesses.
Graham Cluley Security News is sponsored this week by the folks at Edgescan. Thanks to the great team there for their support! Edgescan simplifies Vulnerability Management (VM) by delivering a single full-stack SaaS solution integrated with world-class security professionals. Edgescan helps enterprise companies consolidate managing multiple point scanning tools for each layer of the attack … Continue reading "Does a hybrid model for vulnerability management make sense?"
Do ransomware gangs actually have a heart? Perhaps...Read more in my article on the Tripwire State of Security blog.
A security researcher has won a $107,500 bug bounty after discovering a way in which hackers could install a backdoor on Google Home devices to seize control of their microphones, and secretly spy upon their owners' conversations.Read more in my article on the Hot for Security blog.
Music-streaming service Deezer has owned up to a data breach, after hackers managed to steal the data of over 200 million of its users.
Do you use the LastPass password manager? Did you know they suffered a data breach, and that your passwords may be at risk?You do now. Here's what you need to know.
The FBI is warning US consumers that cybercriminals are placing ads in search engine results that impersonate well-known brands, in an attempt to spread ransomware and steal financial information.Read more in my article on the Tripwire State of Security blog.
Beware your Roomba's roving eye, the Finns warn of AI threats around the corner, and watch out when hailing a cab in Dublin...All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson.
Social media analytics service Social Blade has confirmed that it is investigating a security breach, after a hacker offered its user database for sale on an underground criminal website.Read more in my article on the Hot for Security blog.
Celebrated crime author Ann Cleeves turned to Twitter this week, desperate for help.The reason? The author, whose novels had been the inspiration for TV series like "Vera", had lost her HP laptop during a blizzard in Shetland.
Microsoft has warned that malicious hackers were able to get the software giant to digitally sign their code so it could be used in attacks, such as the deployment of ransomware.Read more in my article on the Hot for Security blog.
Law enforcement agencies in the United States, UK, Netherlands, Poland, and Germany have brought down the most popular DDoS-for-hire services on the internet, responsible for tens of millions of attacks against websites.Read more in my article on the Tripwire State of Security blog.
Drug dealers come unstuck while using the Encrochat encrypted-messaging app, and we put the Lensa AI’s avatar-generation tool under the microscope.All this and more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault.Plus – don’t miss our featured interview with Rico Acosta, IT manager at Bitwarden.
Sports retail giant Intersport, which boasts some 6000 stores worldwide in 57 countries, has fallen victim to a ransomware attack which disabled checkouts in France during what should have been one of the busiest times of the year.Read more in my article on the Hot for Security blog.
As ever, what matters most is not so much whether an organisation gets hit or not by a ransomware attack, but how well it handles the aftermath and recovery.Read more in my article on the Hot for Security blog.
Researchers at Sophos have investigated so-called "metaparasites" - the scammers who scam other scammers.
Malicious hackers, hell-bent on infiltrating an organisation, have no qualms about exploiting even the most tragic events.Read more in my article on the Tripwire State of Security blog.
Russian courts and government agencies have been hit by a previously-undocumented strain of data-wiping malware known as CryWiper.It poses as ransomware, but isn't interested in making money out of its victims...Read more in my article on the Hot for Security blog.
Your car's mobile app might have allowed hackers to remotely unlock your vehicle, turn on or off its engine, and even honk its horn.Read more in my article on the Hot for Security blog.
Researchers investigating a newly-discovered botnet have admitted that they "accidentally" broke Read more in my article on the Tripwire State of Security blog.
Why deleting your Twitter account may be a very bad idea, how the police unravelled the iSpoof fraud gang, and a trip into outer space (or at least interplanetary file systems).
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by original show co-host Vanja Švajcer.
As of September 2022, Twitter had challenged 11.72 million accounts, suspended 11,230 accounts, and removed over 97,674 pieces of misleading content related to COVID-19 worldwide. Today? It’s not doing anything. As an update on the company’s COVID-19 misinformation report webpage notes: Effective November 23, 2022, Twitter is no longer enforcing the COVID-19 misleading information policy. … Continue reading "Twitter isn’t going to stop people posting COVID-19 misinformation anymore"
A Canadian man has revealed that the company he chose to provide security for his home was carelessly exposing the private information for other customers, even after he warned them about the problem.
Read more in my article on the Hot for Security blog.
UK police are texting 70,000 people who they believe have fallen victim to a worldwide scam that saw fraudsters steal at least £50 million from bank accounts.
Read more in my article on the Tripwire State of Security blog.
Deepfake shenanigans strike users of troubled crypto firm FTX, the perils of charging your electric vehicle, and is Microsoft’s takeover of Activision good news for video game fanatics.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by John Hawes of AMTSO.
$100 million.
That's the amount of money that the Hive ransomware is thought to have extorted from over 1300 companies around the world, according to a joint report from the FBI, CISA, and HHS.
Read more in my article on the Hot for Security blog.
Researchers at cybersecurity firm Unit 221B have revealed that they have been secretly helping victims of the Zeppelin ransomware decrypt their computer systems since 2020.
The Daixin ransomware gang has given a humiliating slap in the face to Air Asia, which lost the personal data of five million passengers and all of its employees earlier this month.
A UK police force has apologised after it published the names and addresses of victims of sexual assault on its website.
Suffolk Police says that it has launched an investigation into how victims' names, addresses, dates of birth, and details of reportedly hundreds of alleged offences were left on public view.
Read more in my article on the Hot for Security blog.
Elon Musk is still causing chaos at Twitter (and it's beginning to impact users), are scammers selling your house without your permission, and Google gets stung with a record-breaking fine.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.
Twitter is in chaos. I'd rather delete my Direct Messages one-by-one than one day find that they are in the hands of a hacker or a disgruntled Twitter employee who goes rogue.
Healthcare organisations in the United States are being warned to be on their guard once again, this time against a family of ransomware known as Venus.
Read more in my article on the Tripwire State of Security blog.
A man with dual Russian and Canadian nationality has been arrested in connection with his alleged part in the LockBit ransomware conspiracy that has demanded more than $100 million from its victims.
Read more in my article on the Hot for Security blog.
PC manufacturer Lenovo has been forced to push out a security update to more than two dozen of its laptop models, following the discovery of high severity vulnerabilities that could be exploited by malicious hackers.
Security researchers at ESET discovered flaws in 25 of its laptop models - including IdeaPads, Slims, and ThinkBooks - that could be used to disable the UEFI Secure Boot process.
Read more in my article on the Tripwire State of Security blog.
Graham offers some security and privacy advice for those exodusing Twitter to Mastodon, and Carole slams the door shut on a notorious scammer with a huge Instagram following.
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
A ransomware gang has begun to publish data on the dark web stolen from Australia's largest health insurer Medibank.
Curiously, the hackers have released details of insured customers, sorted into two files bearing the label "naughty-list" and "good-list."
Read more in my article on the Hot for Security blog.
Mastodon is hot right now. After some years of only being used by geeks (yes, I've had an account for a while now) it's at the tipping point of becoming mainstream. If you're part of the exodus of users leaving Twitter for Mastodon, what are the security and privacy issues that you need to be aware of?
Embattled Australian health insurer Medibank says that it will not pay a ransom to cyber extortionists who stolen the personal data of almost ten million customers.
Read more in my article on the Hot for Security blog.
The metaverse is evolving, and tech giants like Meta (the firm previously known as Facebook), Microsoft, and Google are betting big that you'll want to be a part of it.
You know who else might be keen? Criminals.
Read more in my article on the Hot for Security blog.
The world's richest man's plans for the news junkie's favourite social network inevitably get a great deal of attention. Not everyone will be aware of the details of what Elon Musk might be planning for Twitter, but they will certainly be aware that it's a hot topic.
And so if a Twitter user receives a message claiming to be about their verified account, they may very well believe it... and that makes them more susceptible to falling into a trap.
Read more in my article on the Tripwire State of Security blog.
Twitter has a new chief twit in the form of Elon Musk and he's causing problems, scientists say artificial intelligence may help us communicate with animals, and is the office of the future set in the metaverse?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.
Patients of Dutch mental health clinics are being warned that their personal records have fallen into the hands of hackers following a security breach at an online portal that "guaranteed" their privacy.
Read more in my article on the Hot for Security blog.
Cloud communications firm Twilio reveals that it fell victim to a voice phishing attack in June 2022, allowing hackers to access customer contact information.
Read more in my article on the Hot for Security blog.
The Murdoch-owned New York Post published a series of incendiary and offensive articles online earlier today, calling for the assassination of political figures like Joe Biden and Alexandria Ocasio-Cortez, and spreading racial slurs.
LinkedIn says it is beefing up its security in an attempt to better protect its userbase from fraudulent activity such as profiles that use AI-generated deepfake photos, and messages that may contain unwanted or harmful content.
Read more in my article on the Tripwire State of Security blog.
What is slushygate and how does it link to sextortion in the States? What is the most impersonated brand when it comes to delivering phishing emails? And what the flip is nano-targeting?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by fan favourite Maria Varmazis.
It was all going so well. At first.
Read more in my article on the Hot for Security blog.
Pendragon - the car dealership group which owns Evans Halshaw, CarStore, and Stratstone, and operates around 160 showrooms across the UK - has confirmed that its IT servers have been hacked by cybercriminals who claim to have stolen five per cent of its data.
A former officer at Louisville Metro Police has admitted his part in a conspiracy that stalked and extorted young women online, breaking into their Snapchat accounts in order to steal their naked photos and videos.
Read more in my article on the Hot for Security blog.
Microsoft says that it accidentally exposed sensitive customer data after failing to configure a server securely. But it's far from happy with the security researchers who told them about the problem...
Someone's election-fiddling is uncovered with an Apple AirTag, a cyber scandal rocks Germany, and a swindler steals a fortune due to trains being delayed.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by runZero's Chris Kirsch.
Plus don't miss our featured interview with Akamai's Patrick Sullivan talking about bots in the retail sector.
The parent company of women's fashion site Shein has been fined $1.9 million after being accused of lying about the extent of data breach, and notifying "only a fraction" of affected customers.
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! In 2021, our company went through the SOC 2 Type 1 audit, and we found out just how challenging it can be to prove compliance to a third-party auditor. We also learned firsthand … Continue reading "Kolide, endpoint security for teams that want to meet SOC 2 compliance goals without sacrificing privacy"
Boffins at the University of Glasgow, in Scotland, have developed a system which they claim demonstrates a new type of cybersecurity threat: a "thermal attack."
According to the researchers, the falling price of heat-detecting thermal imaging cameras and advances in machine learning have made it more feasible to guess what passwords a target may have entered on a keyboard, up to a minute after typing them.
Read more in my article on the Hot for Security blog.
A couple unexpectedly find $10.5 million in their cryptocurrency account, and in Cambodia people are being forced to commit scams.
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
Ukraine has seen internet outages this week following renewed missile attacks from Russian forces. With a combination of power cuts and DDoS attacks knocking out telecommunications systems, internet availibility suffered a 35% dip.
Read more in my article on the Hot for Security blog.
At UKCyberWeek at the Business Design Centre in London, on 3 & 4 November 2022, I'll be offering practical insight on how computer systems are being targeted, shine some light on mysterious and elusive global crime rings that have made billions of dollars, and describe the lessons that today's organisations should learn about how to protect themselves from attack.
Grab your free ticket.
Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Device security is a lot like Mount Everest: it’s tough to scale. When you’re a small company dominated by engineers, you can keep up with fleet management with nothing more than trust and … Continue reading "Kolide gives you real-time fleet visibility across Mac, Windows, and Linux, answering questions MDMs can’t"
Has new UK prime minister Liz Truss been careless with her mobile phone, and hear the most extraordinary story of corporate cyberstalking.
All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by nobody for reasons that will become obvious.
A 74-year-old Manga artist received an unsolicited Facebook message from somebody claiming to be Incredible Hulk actor Mark Ruffalo.
You can probably guess where this is heading...
You always want to know what is attached to your network. And whether it could be vulnerable or not.
Read more in my article on the Tripwire State of Security blog.
Graham Cluley Security News is sponsored this week by the folks at Kolide. Thanks to the great team there for their support! Do you know the old thought experiment about the AI designed to make paper clips that quickly decides that it will have to eliminate all the humans to maximize paper clips? Many security … Continue reading "Kolide can help you nail audits and compliance goals with endpoint security for your entire fleet"
Hackers have leaked data stolen from the United States's second-largest school district, after the Los Angeles Unified School District (LAUSD) announced it would not be giving in to ransom demands.
Read more in my article on the Hot for Security blog.
Yay, Microsoft has told us how to mitigate against the recently-discovered zero-day attacks.
Boo, the mitigations can be bypassed...
Two men, who previously worked at eBay, have been sentenced to prison after admitting their role in a cyberstalking campaign that targeted the editor and publisher of a newsletter that criticised the company.
Read more in my article on the Hot for Security blog.
Luxury pre-owned watch website Watchfinder has warned its user base that their personal data has been accessed after an employee's account was broken into and a customer list accessed.
A 40-year-old man could face up to 10 years in prison, after admitting in a US District Court to sabotaging his former employer's computer systems.
Read more in my article on the Tripwire State of Security blog.
Anti-porn "shamware" apps take a privacy pounding, is your image already being used by AI, and deepfake danger continues to deepen.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford.
Politicians including Portugese president Marcelo Rebelo de Sousa are amongst those who have had their personal information leaked following an attack by the notorious Ragnar Locker gang against the country's national airline TAP.
Read more in my article on the Hot for Security blog.
Users of Revolut, the popular banking app, would be wise to be on their guard - as scammers are sending out barrages of SMS text messages, posing as official communications from the financial firm.
Could the 16-year-old arrested in Oxford in March now be the 17-year-old arrested in Oxfordshire and charged with breaching his bail conditions?
Graham Cluley Security News is sponsored this week by the folks at Pentera. Thanks to the great team there for their support! Leaked and stolen credentials continue to pose a critical risk to organizations globally. In fact, 65% of breaches involve leaked credentials taken from the dark web and other sources. While threat intelligence tools … Continue reading "See how Pentera identifies and mitigates the risk of your most exploitable exposed credentials"
The boy, who has not been named, was arrested as part of an investigation by the National Crime Agency (NCA). He remains in police custody.
Although at the time of writing no more details have been shared, there is speculation online that the arrest is in relation to the recent hacks of Uber and Rockstar Games.
A self-proclaimed cryptocurrency millionaire has been charged with multiple felonies for his alleged role in a scam that purported to sell a high-powered cryptomining machine called the "Bitex Blockbuster" that did not actually exist.
Read more in my article on the Hot for Security blog.
Between 5-7 October, I will be chairing the UK's National Information Security Conference (better known as NISC), at Carden Park in Cheshire. It's a great event - you should come along.
Oh, and we'll do the podcast "live" there as well...
The Financial Times has created an imaginative ransomware negotiation simulator which lets you imagine you’re in the hot seat at a hacked company, trying to stop cybercriminals from releasing sensitive data they have stolen from your systems.
Researchers reveal how your eyeglasses could be leaking secrets when you’re on video conferencing calls, we take a look at the recent data breaches involving Uber and Grand Theft Auto 6, and we cast an eye at what threats may be around the corner…
All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register’s Iain Thomson.
Plus – don’t miss our featured interview with Sal Aurigemma, the faculty director of the Master of Science in Cyber Security program at the University of Tulsa.
Bespectacled video conferencing participants have more to worry about than if their hair is uncombed or they have some spinach stuck between their teeth. According to newly-publicised research, they may also be unwittingly leaking sensitive information displayed on their computer screens.
Read more in my article on the Hot for Security blog.
Amid a wave of hacks which has cost investors billions of dollars worth of cryptocurrency, the FBI is calling on decentralised finance (DeFi) platforms to improve their security.
Read more in my article on the Tripwire State of Security blog.
Graham Cluley Security News is sponsored this week by the folks at Teleport. Thanks to the great team there for their support! Kubernetes is an amazing platform for managing containers at scale. However, a recent study found that over 900,000 Kubernetes clusters are vulnerable to attack because they are misconfigured! This means that your Kubernetes … Continue reading "Over 900K Kubernetes clusters are misconfigured! Is your cluster a target?"
We’re back from our summer break as we ask how did a cryptomining campaign stay unspotted for years, quiz special guest and infosec rockstar Mikko Hyppönen about his book, and ponder what spiders teach us about misinformation.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
I must admit I was delighted to receive an email today from UK high street pharmacy Boots telling me I should enable two-factor authentication on my account. Boots customers would have benefited from two-factor authentication a couple of years ago, when hackers attempted to gain access to customers’ Boots Advantage Card accounts, and temporarily stopped … Continue reading "Boots lets down its customers, by only offering SMS-based 2FA"
LastPass, the popular password manager trusted by millions of people around the world, has announced that it suffered a security breach two weeks ago that saw hackers break into its systems and steal information.
Read more in my article on the Tripwire State of Security blog.
Malicious hackers are demanding $10 million from a French hospital they hit with ransomware last weekend.
The Hospital Center Sud Francilien (CHSF) in Corbeil-Essonnes, south-east of Paris, was struck late on Saturday night, causing major disruption to health services.
Read more in my article on the Hot for Security blog.
Zoom users on macOS are being told once again to update their copy of the video-conferencing software after a security hole was found that could be exploited by hackers.
Read more in my article on the Hot for Security blog.
Ransomware is to blame for the closure of all 175 7-Eleven stores in Denmark on Monday.
The retailer closed all of its stores in Denmark after its cash registers and payment systems were brought down in the attack.
Read more in my article on the Tripwire State of Security blog.
Scammers are stealing money from children, with the alluring but bogus promise that China's tough restrictions on online gaming can be subverted.
Read more in my article on the Hot for Security blog.
This week Microsoft finally released a patch for a zero-day security flaw being exploited by hackers, that the company had claimed since 2019 was not actually a vulnerability.
Read more in my article on the Hot for Security blog.
Did Russian security Kaspersky really choose to send an email to its customers addressing them as "dear and lovely"? Had Kaspersky suffered a data breach? Had a hacker found a way to send messages to Kaspersky's customer base?
Pornhub has a problem, the UK's Co-op supermarket is accused of big brother tactics, and we take a look at how a security researcher is revealing the true identify of hackers.
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.
The official Instagram account of cricketing legend and former Pakistan Prime Minister Imran Khan was hacked yesterday in order to promote a cryptocurrency scam.
Read more in my article on the Hot for Security blog.
An Irish court has jailed three romance scammers who tricked a 66-year-old woman out of her life savings, and even tricked her into visiting Dubai at her own expense.
Read more in my article on the Hot for Security blog.
A $10 million reward is being offered for information leading to the identification or location of hackers working with North Korea to launch cyber attacks on US critical infrastructure.
Read more in my article on the Tripwire State of Security blog.
Uber may not face prosecution over its handling of a 2016 data breach - but its former chief security head does; how to defend your digital devices' data while on vacation, and how to change your accent with artificial intelligence.
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin.
Plus don't miss our featured interview with Ian Farquhar of Gigamon.
The former Chief Security Officer of Uber is facing wire fraud charges over allegations that he covered up a data breach that saw hackers steal the records of 57 million passengers and drivers.
Read more in my article on the Hot for Security blog.
An unauthorised party has seized control of the @avtestorg Twitter account, nuked its profile picture and banner, replaced its name and description with a full-stop, and set about retweeting numerous messages about NFTs.
Anti-virus testing organisation AV-Test appears to have done nothing wrong, so how was its account hacked?
In this special edition of the "Smashing Security" podcast, computer security veterans Graham Cluley and Carole Theriault welcome back author and journalist Jamie Bartlett - host of "The Missing CryptoQueen" podcast.
Jamie tells us about his new book, which shares more details about the disappearance of cryptocurrency scammer Dr Ruja Ignatova, and the subsequent hunt by law enforcement.
Three million Android users may have lost money and had their devices infected by spyware, after the discovery that the official Google Play store has been distributing apps infected by a new family of malware.
Read more in my article on the Tripwire State of Security blog.
Bexplus gave its users only 24 hours to withdraw their funds.
Can you imagine a traditional financial institution treating its customers in such a slipshod fashion?
Graham Cluley Security News is sponsored this week by the folks at Keeper Security. Thanks to the great team there for their support! IT and DevOps teams were presented with new challenges with the mass-migration to home working, and found themselves forced to perform infrastructure monitoring and management remotely. What is clearly needed is a … Continue reading "Keeper Connection Manager : Privileged access to remote infrastructure with zero-trust and zero-knowledge security"
An app which purported to launch distributed denial-of-service (DDoS) attacks against the internet infrastructure of Russia, was in reality secretly installing malware on to the devices of pro-Ukrainian activists.
Read more in my article on the Hot for Security blog.
I can't tell you not to seek ethical hacking certification from EC-Council. But I can suggest that if you are looking for an online university to boost your cybersecurity career, you don't settle for an outfit that has proven itself to be of questionable ethics and utterly clueless.
NFT artist DeeKay Kwon had his Twitter account hacked at the end of last week by scammers who managed to steal NFTs valued at $150,000 from his followers.
Read more in my article on the Hot for Security blog.
A self-proclaimed "super hacker" causes problems in the Magic Kingdom, criminals regret trusting Anom phones, and lawsuits are filed against TikTok.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.
Plus don't miss our featured interview with Scott McCrady, the CEO of SolCyber Managed Security Services.
Turn on a PC running Microsoft Windows 8.1 and you're likely to be greeted with a full-screen message warning that the operating system will no longer be supported after 10 January 2023, and - critically - will no longer be receiving any security updates.
Microsoft has shared details of a widespread phishing campaign that not only attempted to steal the passwords of targeted organisations, but was also capable of circumventing multi-factor authentication (MFA) defences.
Read more in my article on the Tripwire State of Security blog.
Even the Magic Kingdom isn't immune from hackers.
Late last week, millions of followers of Disneyland's Facebook and Instagram accounts were greeted by a series of offensive messages posted by a hacker.
Read more in my article on the Hot for Security blog.
Things haven't gone as smoothly as Microsoft (and, indeed, the rest of us) might have hoped...
Apple has previewed a new feature which aims to harden high-risk users from the serious threat of being spied upon by enemy states and intelligence agencies.
Read more in my article on the Tripwire State of Security blog.
A hacked university might have made a profit after paying a cryptocurrency ransom, China suffers possibly the biggest data breach in history, and Reuters investigates digital mercenaries. All this and much more is discussed in the latest edition of the award-winning “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this … Continue reading "Smashing Security podcast #282: Raising money through ransomware, China’s mega-leak, and hackers for hire"
Graham Cluley Security News is sponsored this week by the folks at Indusface. Thanks to the great team there for their support! It is hard to imagine an application without APIs (Application Programming Interface). For the past few years, APIs have become core foundational for the success of businesses. Hence, there is no surprise that … Continue reading "Comprehensive risk-based API protection with AppTrana"
Hundreds of thousands of people who follow the official social media accounts of the British Army may have been surprised to see that it had been hijacked by hackers on Sunday.
Read more in my article on the Hot for Security blog.
Members of the LGBTQ+ community have been warned to be on their guard against extortionists who may attempt to prey on them via online dating apps such as Grindr and Feeld.
Read more in my article on the Hot for Security blog.
Semiconductor giant AMD says that it is investigating what claims to be a major data breach of its network, that saw a group of online criminals steal 450GB of data from its systems.
Read more in my article on the Hot for Security blog.
Although only active for the past couple of months, the Black Basta ransomware is thought to have already hit almost 50 organisations.
Read more in my article on the Tripwire State of Security blog.
Graham Cluley Security News is sponsored this week by the folks at SolCyber. Thanks to the great team there for their support! If the bad guys don’t discriminate when it comes to who they are attacking, how can your business settle for anything less than the very best security? SolCyber has brought to market a … Continue reading "How to get Fortune 500 cybersecurity without the hefty price tag"
The FBI has warned that, in an attempt to gain access to sensitive data at organisations, crooks are using deepfake video when applying for remote working-at-home jobs.
Carnival Cruises, the world's largest travel leisure firm which operates over 100 ships for millions of vacationing customers, has been fined a total of $6.25 million following a series of security mishaps.
Read more in my article on the Hot for Security blog.
A Japanese worker, after a drunken night out, lost a flash drive containing the personal information of every single one of his city's residents.
Read more in my article on the Hot for Security blog.
Amazon has demonstrated an experimental feature that demonstrates how a child can choose to have a bedside story read to him by his Alexa... using his dead grandmother's voice.
The UK's National Health Service has warned the public about a spate of fake messages, sent out as SMS text messages, fraudulently telling recipients that they have been exposed to the Omicron variant of COVID-19.
Read more in my article on the Tripwire State of Security blog.
Internet-connected jacuzzis find themselves in hot water, and a Google engineer claims that their AI has developed feelings.
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
The Strava fitness-tracking app is being used to spy upon members of the Israeli military, tracking their movements at secret bases across the country and potentially even help observe their activities when they travel overseas.
Read more in my article on the Hot for Security blog.
Have you received an email notification that there is a voicemail waiting to be listened to by you?
Maybe you would be wise to think carefully before clicking on the attachment.
Graham Cluley Security News is sponsored this week by the folks at SolCyber. Thanks to the great team there for their support! If the bad guys aren’t discriminating who they are attacking, how can your business settle for anything less than Fortune 500 level security? SolCyber has brought to market a new way to consume … Continue reading "How to get Fortune 500 cybersecurity without the hefty price tag"
Owners of NAS drives manufactured by QNAP have been advised that the company is "thoroughly investigating" reports that a new variant of the DeadBolt ransomware is targeting devices, locking up data and demanding victims pay a fee to extortionists.
Read more in my article on the Hot for Security blog.
A critical vulnerability in a WordPress plugin used on over one million websites has been patched, after evidence emerged that malicious hackers were actively exploited in the wild.
With Father's Day falling this weekend in the United States and UK, more people might be more willing than normal to believe the latest scam to be spreading via WhatsApp is true. But I'm afraid it isn't.
Sorry dads, Heineken isn't giving away free coolers of beer.
Read more in my article on the Hot for Security blog.
Law enforcement agencies around the world appear to have scored a major victory in the fight against fraudsters, in an operation which has seized tens of millions of dollars and seen more than 2000 people arrested.
Read more in my article on the Tripwire State of Security blog.
Graham Cluley Security News is sponsored this week by the folks at Specops. Thanks to the great team there for their support! With the help of live attack data, Specops Software’s Breached Password Protection can detect over 2 billion known breached passwords in your Active Directory. Using the Specops database, you can block commonly used … Continue reading "Want to block two billion known breached passwords from being used at your company? It’s easy with Specops Password Policy tools"
How did a saxophonist sneak sensitive information in and out of the Soviet Union? How might an Apple AirTag have led to murder? And isn't the world of cryptocurrency and blockchain doing just great?
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
The US authorities have sentenced a man to 24 months in a federal prison after he was found to have run a DDoS-for-hire service that knocked websites off the internet.
Read more in my article on the Hot for Security blog.
Boffins at the University of California San Diego have found a way to track individuals via Bluetooth.
Researchers discovered that the Bluetooth signals emitted by mobile phones carry a unique fingerprint, caused by small imperfections accidentally created during the manufacturing process.
A Windows zero-day vulnerability dubbed "DogWalk" has not received an official patch yet from Microsoft, but that hasn't stopped others from offering free fixes to protect users.
Read more in my article on the Hot for Security blog.
Trouble brews with the Tim Hortons app, Mandiant gets in a tussle with a Russian ransomware gang, and should good faith security researchers be at risk of prosecution?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White.
An Iranian hacking gang called Bohrium has had its activities disrupted after Microsoft seized control of 41 domains used in spear-phishing attacks.
Read more in my article on the Hot for Security blog.
Apple says that it protected many millions of users from being defrauded to the tune of nearly $1.5 billion dollars in the last year, by policing its official App Store.
According to a newly published report by Apple, over 1.6 million risky and untrustworthy apps and app updates were stopped in their tracks due to the company’s fraud prevention analysis.
Read more in my article on the Tripwire State of Security blog.
Ransom acts of kindness are top of our mind, as we also explore how bad bots are hogging more and more of the internet's activity, and look at how deepfakes could be a good thing after all.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Ray [REDACTED].
A database of contact information for hundreds of Verizon employees is in the hands of cybercriminals, after a member of staff was duped into granting a hacker access to their work PC.
Read more in my article on the Hot for Security blog.
The world is waiting for a patch from Microsoft, after a zero-day vulnerability in Microsoft Office was found to be being exploited in boobytrapped Word documents to remotely execute code on victims' PCs.
The great thing about working in the world of cybersecurity is that there’s always something new. You may think you’ve seen it all, and then something comes along that completely surprises you.
And that’s certainly true of the GoodWill ransomware...
Read more in my article on the Tripwire State of Security blog.
Twitter has been fined $150 million for using phone numbers submitted by users to boost their security... for targeted advertising.
A browser extension bug let malicious websites spy on webcams, hackers threaten the global food supply chain, and Michael Fish (not that one...) hacked into his female classmates' online accounts, hunting for nude photos and videos.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.
An Indian airline says that an "attempted ransomware attack" against its IT infrastructure caused flights to be delayed or canceled, and left passengers stranded.
Read more in my article on the Hot for Security blog.
A man has been sentenced to over 9 years in jail after he was found guilty of breaking into the email accounts of his classmates, and stealing their private nude photographs and videos.
Read more in my article on the Hot for Security blog.
For the past week and a half, Greenland's health service has reportedly been struggling to recover from a cyber attack that has crippled its IT systems, causing long waiting times and forcing doctors to resort to using pen and paper instead of computers.
Read more in my article on the Hot for Security blog.
I'm not sure if it would be enough for me to switch bank accounts, but I have something of a sneaking respect for the Bank of Zambia...
Spanish police say that they have dismantled a phishing gang operating across the country, following the arrest of 13 people and the announcement that they are investigating a further seven suspects.
Read more in my article on the Tripwire State of Security blog.
It should be hard for malicious hackers to break into systems, but all too often it isn't.
Read more in my article on the Tripwire State of Security blog.
A man hacks his employer to prove its security sucks, Telegram provides a helping hand to the Eternity Project malware, and what the heck do mental health apps think they're up to?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dr Jessica Barker.
Plus don't miss our featured interview with Rumble's Chris Kirsch.
Central Bedfordshire Council failed to properly redact the details of 'dozens and dozens' of pupils with special educational needs when responding to a Freedom of Information request, publishing them on a public website.
If pro-Russian hackers had had their way, the Eurovision Song Contest could have been disrupted, potentially preventing the broadcast from being seen or meddling with the vote.
Read more in my article on the Hot for Security blog.
Clearview AI receives something of a slap in the face, and who is wrestling over an internet wormhole?
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
And don't miss our featured interview with Artur Kane of GoodAccess.
Graham Cluley Security News is sponsored this week by the folks at Keeper Security. Thanks to the great team there for their support! The mass migration to distributed work has given IT and DevOps teams the new challenge of performing infrastructure monitoring and management remotely. IT and DevOps personnel need a secure, reliable, and scalable … Continue reading "Keeper Connection Manager: Privileged access to remote infrastructure with zero-trust and zero-knowledge security"
A predominantly Black college, based in Illinois, USA, is closing its doors after 157 years - citing the challenges it faced due to the Coronavirus pandemic, and the aftermath of a ransomware attack.
Read more in my article on the Hot for Security blog.
The ransomware attack is likely to impact a number of agricultural machinery brands, including Challenger, Fendt, Ferguson, Massey, and Valtra, in the run-up to a crucial time of year for crop farmers.
As Russian state TV broadcast a military parade as part of Victory Day celebrations in Moscow, viewers of some channels were greeted by a message that certainly wasn't approved by Putin's propaganda machine...
Read more in my article on the Hot for Security blog.
The FBI's Internet Crime Complaint Center (IC3) has issued updated statistics on Business Email Compromise (BEC) attacks which use a variety of social engineering and phishing techniques to break into accounts and trick companies into transferring large amounts of money into the hands of criminals.
Read more in my article on the Tripwire State of Security blog.
In my keynote I'll be discussing whether cybercriminals really are evil geniuses (as the media and some security vendors would like us to believe), or not...
Save 50% off the ticket price using a discount code.
We find out why calls to Dublin airport's noise complaints line have soared, and Carole quizzes Graham to celebrate World Password Day.
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast, with computer security veterans Graham Cluley and Carole Theriault.
And don't miss our special featured interview with Clint Dovholuk of NetFoundry.
Graham Cluley Security News is sponsored this week by the folks at Keeper Security. Thanks to the great team there for their support! The mass migration to distributed work presented IT and DevOps teams with new challenges as they were forced to perform infrastructure monitoring and management remotely. IT and DevOps personnel needed a secure, … Continue reading "Keeper Connection Manager : Privileged access to remote infrastructure with zero-trust and zero-knowledge security"
One of the largest library services in Germany, EKZ Bibliotheksservice, has been impacted by a ransomware attack that has left book lovers unable to rent and borrow eBooks, audio books, and electronic magazines.
Read more in my article on the Hot for Security blog.
A police car's digital in-car video system uncovered that two Los Angeles officers ignored calls to provide assistance at a department store robbery because they were too enthralled in catching Pokémon.
If you are worried about the financial hit of paying a ransom to cybercriminals, wait until you find out the true cost of a ransomware attack.
Read more in my article on the Tripwire State of Security blog.
Elon Musk's takeover of the company might bring a swathe of changes to Twitter, including the introduction of end-to-end encryption for direct messages (DMs).
Read more in my article on the Hot for Security blog.
Members of The Bored Ape Yacht Club get that sinking feeling, a face unwittingly launches hundreds of romance scams, and is an as-yet unseen Kim Kardashian sex tape a load of old Roblox?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by BBC cyber correspondent Joe Tidy.
The United States has made it $10 million harder to keep your mouth shut, if you happen to have any information about the Russian military hackers who masterminded the notorious NotPetya cyber attack.
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Specops. Thanks to the great team there for their support! With the help of live attack data from our own honeypots, Specops Software’s Breached Password Protection can now detect over 2 billion known breached passwords in your Active Directory. Using our database, you … Continue reading "Block over two billion known breached passwords from your AD with Specops Password Policy tools"
Costa Rica's outgoing president, Carlos Alvarado Quesada, has said that a ransomware attack on the government's computer systems was an attempt to destabilise the country as it transitions to a new administration.
Read more in my article on the Hot for Security blog.
Someone isn't happy that Ukraine's post office has issued stamps mocking the sunken Russian navy flagship.
Researchers have spotted that the TOR address used by the notorious REvil ransomware gang is now redirecting to a new website, with information about seemingly new attacks.
Read more in my article on the Tripwire State of Security blog.
Security researchers at Kaspersky have released a free decryption tool that promises to recover files for organisations hit by the Yanlouwang ransomware, meaning they don't have to pay the ransom.
A man loses $650,000 from his cryptocurrency wallet after his Apple iCloud account is hacked, video conferencing apps may not be muting your mic quite the way you imagined, and Google has unblurred military bases in Russia... or has it?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.
Cryptocurrency wallet maker MetaMask has warned its 21 million monthly users to be wary of Apple iCloud backing up their app's data by default, after attackers successfully stole $650,000 of funds and NFTs.
Read more in my article on the Hot for Security blog.
Online greeting cards business Funky Pigeon was forced to close its doors temporarily last week after a "cybersecurity incident."
Visitors to the company's website were still being greeted as recently as Monday with a message saying that it could not accept new orders.
Graham Cluley Security News is sponsored this week by the folks at Indusface. Thanks to the great team there for their support! With APIs grown into a dominant mechanism of the modern web, protecting web applications and APIs becomes the default requirement of AppSec. This calls for a unified risk-based mitigation solution. Indusface WAAP, a … Continue reading "For cutting-edge web application and API protection – Trust Indusface WAAP"
Agencies of the US Government have issued a joint warning that hackers have revealed their capability to gain full system access to industrial control systems that might help enemy states sabotage critical infrastructure.
Read more in my article on the Tripwire State of Security blog.
Pulchritudinous women with glossy long hair are targeting Israeli officials via Facebook - but why? Scammers have found a new way to gain access to your most sensitive information - but how? And armchair detectives are helping investigating cold cases involving DNA - but should they?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.
One of the world’s largest hacker forums, which has been operating since 2015 helping cybercriminals sell and purchase the hacked personal data of millions of innocent people, has been taken down by the police.
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Perception Point. Thanks to the great team there for their support! The need to communicate, collaborate and do business on a global level has created a proliferation of cloud based applications and services: Email. Cloud Storage. Messaging platforms. CRM. Digital Apps and Services. … Continue reading "Security blind spots in the era of cloud communication & collaboration. Are you protected?"
Strange goings-on on LinkedIn, Ukraine publishes a list of alleged Russian FSB agents, and police in Pittsburgh investigate an odd report of an active shooter.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White.
Online photography printing service Shutterfly has disclosed that it has suffered a security breach at the hands of a ransomware gang that exposed the personal information of some employees.
Graham Cluley Security News is sponsored this week by the folks at Forcepoint. Thanks to the great team there for their support! Remember when you thought an antivirus was all you needed to keep safe from cybercriminals? Of course, cybersecurity has never truly been that simple. As threats and business operations have grown more complex, … Continue reading "Forcepoint ONE helps firms simplify their security"
After being linked to ransomware attacks that cost companies over US $53 million, an Estonian man has been sentenced to prison for five and a half years.
Read more in my article on the Hot for Security blog.
Compromise of safety systems could have resulted in the release of toxic gas or an explosion - causing physical damage to facilities and the loss of life.
Read more in my article on the Hot for Security blog.
British police arrested seven people earlier this week in relation to a wave of attacks launched by the LAPSUS$ hacking group, against firms such as Microsoft, NVIDIA, Ubisoft, Samsung, and Okta.
The hacking group's alleged mastermind? A 16-year-old boy from Oxford, UK.
A Russian bank tells its customers to stop installing security updates, an Apple employee ends up in hot water, and learn our tips to avoid being virtually kidnapped.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.
Graham Cluley Security News is sponsored this week by the folks at Forcepoint. Thanks to the great team there for their support! Remember the days when you thought an antivirus was all you needed to stay safe? Of course, cybersecurity has never truly been that simple. As cyberthreats and business operations have grown more complex, … Continue reading "Simplify your security with Forcepoint ONE"
AvosLocker is a ransomware-as-a-service (RaaS) gang which first appeared in mid-2021. It has since become notorious for its attacks targeting critical infrastructure in the United States, including the sectors of financial services, critical manufacturing, and government facilities.
Read more in my article on the Tripwire State of Security blog.
The RansomEXX ransomware gang has seen fit to publish on the dark web 12GB of data stolen from SAMH, including unredacted photographs of individuals' driving licences, passports, personal information such as volunteers' home addresses and phone numbers, and - in some cases - even passwords and credit card details.
Read more in my article on the Hot for Security blog.
International credit bureau TransUnion says that hackers managed to breach a server operated by its South African division, and gained access to the personal information of individuals.
Read more in my article on the Hot for Security blog.
With just a few weeks until the April 15 deadline for US individuals and businesses to file their tax returns, scammers are as busy as ever.
Read more in my article on the Tripwire State of Security blog.
A video clip shared on social media yesterday showed what appeared - to anyone who wasn't paying proper attention at least - to be Ukrainian President Volodymyr Zelensky calling on his country's citizens and army to lay down their weapons and surrender to invading Russian forces.
In the clip, the deepfake Zelensky is shown standing behind a podium, declaring that he has "decided to return Donbas" and that his army's efforts to fend off Russia's attack "has failed."
Read more in my article on the Hot for Security blog.
Germany tells consumers to stop using Kaspersky anti-virus products, OSINT reveals a secret government department (with help from an Apple AirTag), and the UK says it's taking a hard line on dick pics.
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Chris Kirsch.
The alleged ringleader of an international scam operation has been arrested by Nigerian authorities in Lagos, after being wanted by the FBI since 2016.
Read more in my article on the Hot for Security blog.
Last month, the LAPSUS$ hacking group stole up to one terabyte of internal data, including hashed passwords, from graphics card maker NVIDIA.
Of course, you would hope that any sensible NVIDIA employee would have chosen a sensible hard-to-crack password, and ensured that they weren’t using the same password anywhere else on the internet...
Many of us might need a helping hand to defeat our video game rivals, but you could end up shooting yourself in the foot.
Video game company Ubisoft, maker of hit titles like Assassin’s Creed and Just Dance says that it has “experienced a cyber security incident” - and as a consequence is changing its employees' passwords.
The FBI has warned that the Ragnar Locker gang has infected at least 52 critical infrastructure organisations across America with its ransomware.
Read more in my article on the Tripwire State of Security blog.
I would like to think that you're all smart enough to know better, but just in case...
No, there aren't women in Ukraine are keen to have a sexy webcam chat with you right now. But that doesn't mean spammers aren't trying to convince you otherwise...
The most famous policeman in Nigeria is in hot water over his links to Hushpuppi, has your Amazon Echo been talking to itself, and can an AI girlfriend save your marriage?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
Plus don't miss our featured interview with Jason Meller of Kolide.
Researchers have discovered a novel way of exploiting Amazon Echo smart speakers to perform commands.
They get the Amazon Echo speaker to say the commands to itself.
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Forcepoint. Thanks to the great team there for their support! Remember when you thought an antivirus was all you needed to keep safe from digital danger? Of course, cybersecurity has never truly been that simple. As cyberthreats and business operations have grown more … Continue reading "Forcepoint ONE simplifies your security"
Oh how embarrassing for the criminal gang who extorted millions from businesses by threatening to leak their data, that someone leaked some 160,000 messages between their members as well as their malware source code.
Yes, having access to Facebook would leave ordinary Russians open to crazy QAnon theories, anti-vax propaganda, and a myriad of narrow echo chambers. But it would also give them a chance to seek out independent reporting on the horrific invasion of Ukraine by Russia.
New legislation, unanimously passed by the US Senate could - amongst other things - require organisations working in critical industry sectors to alert the US Government about hacks and ransomware attacks.
Read more in my article on the Tripwire State of Security blog.
Why might Russian EV chargers be displaying an anti-Putin message? Why are Telegram groups sharing sharing explicit images of women without their consent? And who is watching you in the workplace?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Jessica Barker.
Graham Cluley Security News is sponsored this week by the folks at Teleport. Thanks to the great team there for their support! Imagine the scene – you’re woken up at 3 am, only to discover your worst nightmare. The new intern just accidentally deleted the production database during routine maintenance. You quickly restore from a … Continue reading "Who deleted the database? Find out with Teleport"
As widely anticipated, the conflict between Russia and Ukraine has heated up on cyberspace in the days since Vladimir Putin ordered his troops and tanks to invade.
This weekend saw the Kremlin's official website at kremlin.ru brought down, along with other Russian government sites, in what appears to have been a co-ordinated distributed denial-of-service (DDoS) attack.
Read more in my article on the Hot for Security blog.
A game, developed by the so-called IT Army of Ukraine, makes it easy for anyone around the world to contribute to the overloading of Russian websites while playing a version of the simple sliding puzzle "2048."
CERT-UA, the national Computer Emergency Response Team for Ukraine, has issued a warning of a major phishing campaign launched against military personnel.
The attack is being blamed on the UNC1151 hacking group , which is based in Minsk and whose members are said to be officers of the Ministry of Defence in Belarus.
Read more in my article on the Hot for Security blog.
A Manhattan couple in their 30s have been arrested in Manhattan in connection with the 2016 hack of cryptocurrency exchange Bitfinex.
Read more in my article on the Hot for Security blog.
'Tis the season for tax scams here in the UK, and it's no surprise to learn that scammers are spamming out fraudulent messages posing as HMRC.
Thankfully, at least some accountants are warning their clients about the danger of falling for a phish.
Bridge cryptocurrency hack follows bridge cryptocurrency hack follows bridge cryptocurrency hack.
Who's wearing the pyjamas while they take down North Korea's internet? Is it a case of cop or cosplay in Oregon? And what's to fear about the metaverse?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.
Last month, as North Korea's supreme leader Kim Jong-un oversaw a series of sabre-rattling hypersonic missile tests, cyber attacks disrupted the country's internet infrastructure. But who was responsible?
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at Teleport. Thanks to the great team there for their support! You’re woken up at 3 am, only to discover your worst nightmare. The new intern just deleted the production database during routine maintenance by accident. You quickly restore from a backup. During the … Continue reading "Who dropped the DB? Find out with Teleport Database Access"
Vodafone customers in the UK are spitting tacks after an "issue" has left them unable to use Twitter properly for days, after the display of images and movie files, and - in some cases - the entire website, was blocked.
BlackCat (also known as ALPHV) is a relatively new ransomware-as-a-service operation, which has been aggressively recruiting affiliates from other ransomware groups and targeting organisations worldwide.
Read more in my article on the Tripwire State of Security blog.
Graham Cluley Security News is sponsored this week by the folks at HYPR. Thanks to the great team there for their support! A new guide provides practical guidance for eliminating passwords to accelerate your Zero Trust strategy, and explains how Zero Trust can increase business agility. The free guide, by the analysts at The Cyber … Continue reading "Zero trust with zero passwords – free guide explains what you need to know"
Who's that new guy working at your company, and why don't you recognise him from the interview? How are hacktivists raising the heat in Belarus? And should you be fully vaxxed for your online date?
All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.
The IT systems of KP Snacks have been hit by ransomware. And it might well impact the British public's waistlines as well as the company's profits:
Facebook users are being warned of a phishing campaign that tries to break into accounts, disguised as a Facebook Messenger chat from a friend.
Read more in my article on the Hot for Security blog.
Qubit, a decentralized finance (DeFi) platform, has publicly offered $2,000,000 to a hacker who stole $80 million worth of cryptocurrency from it last week.
Read more in my article on the Hot for Security blog.
Andorra Telecom, the tiny microstate's only internet service provider, says that a barrage of distributed denial-of-service (DDoS) attacks impacted the country's internet and 4G service.
Read more in my article on the Hot for Security blog.
Graham Cluley Security News is sponsored this week by the folks at HYPR. Thanks to the great team there for their support! The analysts at The Cyber Hut have produced a new guide that explains how Zero Trust can increase business agility, and provides practical guidance for eliminating passwords to accelerate your Zero Trust strategy. … Continue reading "“A Journey to Zero Trust With Zero Passwords” – download the free guide now"
A Canadian man has been handed a three year prison sentence after being found guilty of buying and selling over 1700 stolen identies on a dark web marketplace, and collaborating with the notorious Dark Overlord extortion gang.
Read more in my article on the Tripwire State of Security blog.
An independent researcher has received a $100,500 bug bounty from Apple after discovering a security hole in the company's Safari browser for macOS that could allow a malicious website to hijack accounts and seize control of users' webcams.
Read more in my article on the Hot for Security blog.
Wordle - good or bad for the world? Whatever your opinion, at least someone wants to spoil players' fun. Meanwhile, we take a look at the threat mobile phones can pose to your mental health.
All this and more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.
Apple has released urgent security updates for its customers, following the discovery of zero-day vulnerabilities that can be used to hack into iPhones, iPads, and Macs.
Four US states have launched a law suit against Google, claiming that the technology giant continued to track users' location, even when they users had asked it not to.