It took six months for notifications to start, and we still don't know exactly what went down... but here's our advice on what to do.
Imagine if you clicked on a harmless-looking image, but an unknown application fired up instead...
Cryptography isn't just about secrecy. You need to take care of authenticity (no imposters!) and integrity (no tampering!) as well.
Apps on your iPhone must come from the App Store. Except when they don't... we explain what to look out for.
The rise of tap-to-pay and chip-and-PIN hasn't rid the world of ATM card skimming criminals...
The site was running from 2014 and allegedly raked in more than $20m, which the DOJ is seeking to claw back...
74 CVEs, and two "Exploitation Detected" advisories, which are nearly but not quite the same as 0-days. Also, two potential Teams treacheries that you really want to fix.
Fast, quiet, smooth, consistent and low impact... why true hacker-grade touch-typing might keep you more secure.
Sentences still to be decided, but she could get up to 10 years and he could get as many as 20.
Serious security stories explained clearly in plain English - listen now. (Full transcript available.)
It's a real vulnerability, but the data leakage rate can be as low as... let's just say that an IMAX-quality copy of the new "Oppenheimer" movie could take you 4 billion years to exfiltrate.
Fascinating fun (with a serious and educational side) - listen now! Full transcript available inside.
"You need to turn on a special setting to stop the code you wrote to stop the code you wrote to improve performance from reducing performance from reducing security."
The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...
Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly request your cooperation to apply the fix manually."
Here's a brief reminder to do two things. The first is to patch. The second is to read up why it's a good idea to patch...
Previously, we said "do it today", but now we're forced back on: "Do not delay; do it as soon as Apple and your device will let you."
Don't delay, do it today. This is a code-implantation bug in WebKit that attackers already know how to exploit.
Gaslights produce a telltale flicker when nearby lamps are lit; DRAM values do something similar when nearby memory cells are accessed.
How to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light.
Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.
Ultimate Member plugin lets rogue users choose their own site capabilities, including becoming admins.
Technically, it's "up to $10 million", but it's potentially a LOT of money, nevertheless...
Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.
Did you prevent password-only logins on your SSH servers? On ALL of them? Are you sure about that?
"Do as we say, not as we do!" - The patches took ages to come out, but don't let that lure you into taking ages to install them.
One, sadly, has died, and two are heading to prison, but for Kim Dotcom, the saga goes on...
Twice more unto the breach... patch being tested, in the meantime, shut down web access.
Gozi threesome from way back in the late 2000s and early 2010s now all charged, convicted and sentenced. The DOJ got there in the end...
Though the mills of the Law grind slowly/Yet they grind exceeding small/Though with patience they stand waiting/With exactness grind they all...
Backdoors, exploits, and Little Bobby Tables. Listen now! (Full transcript available...)
Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)
Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)
What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?
Another traitorous sysadmin story, this one busted by system logs that gave his game away...
Controlled outage used to keep malware marauders from gumming up the works. Learn what you can do to help in future...
Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.
All Apple users have zero-days that need patching, though some have more zero-days than others.
Laugh (sufficiently), learn (efficiently), and then let us know what you think in our comments (anonymously, if you wish)...
"Up to $10 million for information that leads to the arrest and/or conviction of this defendant."
We've kept it short and simple, with no sermons, no judgmentalism, no tubthumping... and no BUY NOW buttons. Have a nice day!
Just when we'd got used to three-numbered versions, such as "13.3.1", here comes an update suffix, bringing you "13.3.1 (a)"...
These malware peddlers are specifically going after Mac users. The hint's in the name: "Atomic macOS Stealer", or AMOS for short.
CryptBot criminals are alleged to have plundered browser passwords, illicitly-snapped screenshots, cryptocurrency account data, and more.
When Doug says, "Happy Remote Code Execution Day, Duck"... it's irony. For the avoidance of all doubt :-)
You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...
If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...
Wouldn't it be handy if there were a single version number to check for in every Chromium-based browser, on every supported platform?
You know jolly well/What we're going to say/And that's "Do not delay/Simply do it today."
Loop-the-loop in this week's episode. Entertaining, educational and all in plain English. Transcript inside.
Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)
USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?
I'm sorry, Dave. I'm afraid I can't... errr, no, hang on a minute, I can do that easily! Worldwide! Right now!
Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.
That double-whammy Apple browser-to-kernel spyware bug combo we wrote up last week? Turns out it applies to all supported Macs and iDevices - patch now!
The security error was in the error handling system that was supposed to catch potential security errors...
A bug to hack your browser, then a bug to pwn the kernel... reported from the wild by Amnesty International.
Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!
Imagine tiling a whole football field using a single shape... yet not being able to produce a repeating pattern, even if you wanted to.
They can't read much of your data, but even a few stray network packets could tell them something they're not supposed to know.
Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.
Thinking of trying a bit of DDoSsing to get a feel for life at the fringes of the Dark Side? Don't do it!
Got an older iPhone that can't run iOS 16? You've got a zero-day to deal with! That super-cool Studio Display monitor needs patching, too.
Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.
His prediction was called a "Law", though it was an exhortation to engineering excellence as much it was an estimate.
Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.
Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...
What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?
As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...
Despite its usually inflexible 0-day disclosure policy, Google is keeping four mobile modem bugs semi-secret due to likely ease of exploitation.
Worried about rogue apps? Unsure about the new Outlook zero-day? Clear advice in plain English... just like old times, with Duck and Chet!
An email you haven't even looked at yet could be used to trick your mail server into helping crooks to logon as you.
In the game of cricket, 111 is an unauspicious number, but for Firefox, there doesn't seem to be much to worry about this month.
Linux doesn't BSoD. It has oopses and panics instead. (We show you how to make a kernel module to explore further.)
It's not exactly data theft, but it's worrying close to "unintentional treachery" - apparently because it's great for marketing purposes
Security bugs in the very code you've been told you must have to improve the security of your computer...
Devices seized, suspects interrogated and arrested, allegedly connected to devastating cyberattack on University Hospital in Düsseldorf.
Wondering which cybercrime tools, techniques and procedures to focus on? How about any and all of them?
Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!
Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.
Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)
Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.
Free spins? Bonus game points? Cheap social media followers? What harm could it possibly do if you just take a tiny little look?!
Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...
Ironically, Twitter Blue users will be allowed to keep using the very 2FA process that's not considered secure enough for everyone else.
New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.
Everyone update now! Except for those who don't need to! Or who need to but will only get updates later on, though Apple isn't saying yet!
Reddit is suggesting three tips as a follow-up to this breach. We agree with two of them but not with the third...
7 memory mismanagements and a timing attack. We explain all the jargon bug terminology in plain English...
To borrow from HHGttG, please DON'T PANIC. But if you are two years out of date with patches, please do ACT NOW!
Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...
Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.
It's a bug fix for a bug fix. A memory leak was turned into a double-free that has now been turned into correct code...
Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?
Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!
Unfortunately, you've probably already heard the cliche that "cybercrime abhors a vacuum"...
Undercover Austrian "controlled data buy" leads to Amsterdam arrest and ongoing investigation. Suspect is said to steal and sell all sorts of data, including medical records.
We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.
Don't delay, especially if you're still running an iOS 12 device... please do it today!
As always: entertaining, informative and educational... and not bogged down with jargon! Listen (or read) now...
Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.
Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)
Get 'em while they're hot. And get 'em for the very last time, if you still have Windows 7 or 8.1...
It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.
Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?
Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)
Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.
When someone calls you up to warn you that your bank account is under attack - it's true, because THAT VERY PERSON is the one attacking you!
The bad news: the crooks have your SSH private keys. The good news: only users of the "nightly" build were affected.
The problem with anniversaries is that there's an almost infinite number of them every day...
Listen now - you'll be alarmed, amused and educated, all in equal measure. (Full transcript in article.)
If the crooks have connected up your phone number and your Twitter handle... what could go wrong?
It's serious, it's critical, and you could call it severe... but in HHGttG terminology, it's probably "mostly harmless".
The crooks now know who you are, where you live, which computers are yours, where you go online... and they got those password vaults, too.
Join world-renowned expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode on how to fight cybercrime.
It happens to the best of us: Microsoft highlights a security bypass bug on Macs that is curiously similar to a recent Windows 0-day.
The Cryptoqueen herself is still missing, but her co-conspirator, who is said to have pocketed over $20m a month, has been convicted.
Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!
That's a mean average of $15,710 per bug... and 63 fewer bugs out there for crooks and rogues to find.
Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.
Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.
We grabbed the update, based on no information at all, just in case we came across a reason to advise you not to. So far, so good...
Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.
"Uh-oh, this viruses-and-worms scene could turn out quite troublesome." If only we'd been wrong...
An injury to one is an injury to all. Especially if the other people are part of your social network.
There isn't a rhyme to remind you which months have browser zero-days... you just have to keep your eyes and ears open!
Those numbers or names that pop up when a call comes up? They're OK as a hint of who's calling, but THEY PROVE NOTHING
Latest episode - security expert John Shier explains what the real-life cybercrime stories in the Sophos Threat Report can teach us
Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...
Review your servers, your patches and your authentication policies - there's a proof-of-concept out
The warning is hosted on a real Facebook page; the phishing uses HTTPS via a real Google server... but the content is all fake
Good old "string templating", also known as "string interpolation", in the spotlight again...
Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...
Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!
In all the excitement, we kind of lost track ourselves. Were there six 0-days, or only four?
How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...
That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...
As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!
Latest episode - listen and learn now (or read and revise, if the written word is your thing)...
Judge tells the accused that if he hadn't pleaded guilty, "I would have given you life."
Two years of scamming + $10 million leeched = 25 years in prison. Just in time for #Cybermonth.
Some thoughts for Cybersecurity Awareness Month: Is is worth reporting nuisance calls? Is it even worth reporting outright scams?
Who's affected, what you can do while waiting for Microsoft's patches, and how to plan your threat hunting...
This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.
This site, like millions of others, has a certificate from Let's Encrypt. Farewell, Peter Eckersley, PhD, who helped make it all possible.
Patch as soon as you can - that recent WebKit zero-day affecting new iPhones and iPads is apparently being used against older models, too.
What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?
Two trust-spoofing bugs were the main culprits this month - but neither one was a zero-day.
One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...