Naked Security - Sophos: Recent Episodes

None

News, opinion, advice and research on computer security threats from Sophos

View Details

It took six months for notifications to start, and we still don't know exactly what went down... but here's our advice on what to do.

View Details

Latest episode - listen now! Full transcript inside...

View Details

Imagine if you clicked on a harmless-looking image, but an unknown application fired up instead...

View Details

Cryptography isn't just about secrecy. You need to take care of authenticity (no imposters!) and integrity (no tampering!) as well.

View Details

WYSIWYG is short for "what you see is what you get". Except when it isn't...

View Details

Celebrating the true crypto bros. Listen now (full transcript available).

View Details

Apps on your iPhone must come from the App Store. Except when they don't... we explain what to look out for.

View Details

The rise of tap-to-pay and chip-and-PIN hasn't rid the world of ATM card skimming criminals...

View Details

The site was running from 2014 and allegedly raked in more than $20m, which the DOJ is seeking to claw back...

View Details

Latest episode - listen now! (Full transcript inside.)

View Details

74 CVEs, and two "Exploitation Detected" advisories, which are nearly but not quite the same as 0-days. Also, two potential Teams treacheries that you really want to fix.

View Details

Fast, quiet, smooth, consistent and low impact... why true hacker-grade touch-typing might keep you more secure.

View Details

Sentences still to be decided, but she could get up to 10 years and he could get as many as 20.

View Details

Serious security stories explained clearly in plain English - listen now. (Full transcript available.)

View Details

It's a real vulnerability, but the data leakage rate can be as low as... let's just say that an IMAX-quality copy of the new "Oppenheimer" movie could take you 4 billion years to exfiltrate.

View Details

No zero-days, but some interesting patches with their very own "teachable moments".

View Details

When is a ransomware attack a reportable matter? And how long have you got to decide?

View Details

Fascinating fun (with a serious and educational side) - listen now! Full transcript available inside.

View Details

"You need to turn on a special setting to stop the code you wrote to stop the code you wrote to improve performance from reducing performance from reducing security."

View Details

Another month, another patch for in-the-wild iPhone malware (and a whole lot more).

View Details

"Three may keep a secret, if two of them are dead."

View Details

Latest episode - check it out now!

View Details

Careful with that file, Eugene!

View Details

The first compromise didn't get the crooks as far as they wanted, so they found a second one that did...

View Details

Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly request your cooperation to apply the fix manually."

View Details

Latest episode - listen now! (Full transcript inside.)

View Details

Here's a brief reminder to do two things. The first is to patch. The second is to read up why it's a good idea to patch...

View Details

Previously, we said "do it today", but now we're forced back on: "Do not delay; do it as soon as Apple and your device will let you."

View Details

Don't delay, do it today. This is a code-implantation bug in WebKit that attackers already know how to exploit.

View Details

Gaslights produce a telltale flicker when nearby lamps are lit; DRAM values do something similar when nearby memory cells are accessed.

View Details

How to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light.

View Details

No zero-days this month, so you're patching to stay ahead, not merely to catch up!

View Details

Even if you've never heard of the venerable Ghostscript project, you may have it installed without knowing.

View Details

Ultimate Member plugin lets rogue users choose their own site capabilities, including becoming admins.

View Details

Latest episode - listen now! (Full transcript inside.)

View Details

Technically, it's "up to $10 million", but it's potentially a LOT of money, nevertheless...

View Details

Not just that infamous Twitter hack, but SIM-swapping, stalking and swatting too...

View Details

Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.

View Details

Lots to learn this week - listen now! (Full transcript inside.)

View Details

Apple didn't use the words "Triangulation Trojan", but you probably will.

View Details

Did you prevent password-only logins on your SSH servers? On ALL of them? Are you sure about that?

View Details

Get the full 360-degree view of ransomware

View Details

"Do as we say, not as we do!" - The patches took ages to come out, but don't let that lure you into taking ages to install them.

View Details

One, sadly, has died, and two are heading to prison, but for Kim Dotcom, the saga goes on...

View Details

Twice more unto the breach... patch being tested, in the meantime, shut down web access.

View Details

Latest episode - listen now! (Full transcript inside.)

View Details

No zero-days this month, if you ignore the Edge RCE hole patched last week

View Details

Gozi threesome from way back in the late 2000s and early 2010s now all charged, convicted and sentenced. The DOJ got there in the end...

View Details

Though the mills of the Law grind slowly/Yet they grind exceeding small/Though with patience they stand waiting/With exactness grind they all...

View Details

Good news... more patches, this time available proactively

View Details

Does swapping your password regularly make it a better password?

View Details

Backdoors, exploits, and Little Bobby Tables. Listen now! (Full transcript available...)

View Details

With the right (or wrong, if you're on the right side of the fence) timing...

View Details

Chrome 0-day patched now, Edge patch coming soon.

View Details

Little Bobby Tables is back!

View Details

It's a backdoor, Jim, but not as we know it... here's a sober look at this issue.

View Details

Lots to learn, clearly explained in plain English... listen now! (Full transcript inside.)

View Details

Here, in an admittedly discursive nutshell, is the fascinating story of CVE-2023-32784. (Short version: Don't panic.)

View Details

What good is a popup asking for your approval if an attacker can bypass it simply by suppressing it?

View Details

Latest episode - listen now. Full transcript inside...

View Details

Another traitorous sysadmin story, this one busted by system logs that gave his game away...

View Details

Controlled outage used to keep malware marauders from gumming up the works. Learn what you can do to help in future...

View Details

Site marketing video promised total anonymity, but that was a lie. 170 arrested already. Potentially 1000s more to follow.

View Details

All Apple users have zero-days that need patching, though some have more zero-days than others.

View Details

Laugh (sufficiently), learn (efficiently), and then let us know what you think in our comments (anonymously, if you wish)...

View Details

"Up to $10 million for information that leads to the arrest and/or conviction of this defendant."

View Details

Yes, it's a buffer overflow bug. No, it's not going get fixed.

View Details

We asked you once, we told you twice, now we're ordering you for the third time...

View Details

Not just an active adversary, but a two-faced one, too.

View Details

I pwned you! Gizza job! You know it makes sense!

View Details

Entertaining, educational, and all in plain English 🎧📖

View Details

We've kept it short and simple, with no sermons, no judgmentalism, no tubthumping... and no BUY NOW buttons. Have a nice day!

View Details

To bleat, or not to bleat, that is the question.

View Details

Just when we'd got used to three-numbered versions, such as "13.3.1", here comes an update suffix, bringing you "13.3.1 (a)"...

View Details

These malware peddlers are specifically going after Mac users. The hint's in the name: "Atomic macOS Stealer", or AMOS for short.

View Details

CryptBot criminals are alleged to have plundered browser passwords, illicitly-snapped screenshots, cryptocurrency account data, and more.

View Details

When Doug says, "Happy Remote Code Execution Day, Duck"... it's irony. For the avoidance of all doubt :-)

View Details

You waited 13 years for this feature in Google Authenticator. Now researchers are advising you to wait a while longer, just in case...

View Details

If you have the product, but you haven't patched - well, the crooks have now landed, so please don't delay. Do it today...

View Details

Wouldn't it be handy if there were a single version number to check for in every Chromium-based browser, on every supported platform?

View Details

You know jolly well/What we're going to say/And that's "Do not delay/Simply do it today."

View Details

Loop-the-loop in this week's episode. Entertaining, educational and all in plain English. Transcript inside.

View Details

Did the sentence fit the crime? Read the backstory, and then have your say in our comments! (You may post anonymously.)

View Details

USB charging stations - can you trust them? What are the real risks, and how can you keep your data safe on the road?

View Details

I'm sorry, Dave. I'm afraid I can't... errr, no, hang on a minute, I can do that easily! Worldwide! Right now!

View Details

Is Secure Boot without the Secure just "Boot"?

View Details

Stealing private keys is like getting hold of a medieval monarch's personal signet ring... you get to put an official seal on treasonous material.

View Details

That double-whammy Apple browser-to-kernel spyware bug combo we wrote up last week? Turns out it applies to all supported Macs and iDevices - patch now!

View Details

The security error was in the error handling system that was supposed to catch potential security errors...

View Details

A bug to hack your browser, then a bug to pwn the kernel... reported from the wild by Amnesty International.

View Details

Scanning tools, supply-chain malware, Wi-Fi hacking, and why there should be TWO World Backup Days... listen now!

View Details

Grab a message/Play it back/You've just performed/A big phat hack...

View Details

Imagine tiling a whole football field using a single shape... yet not being able to produce a repeating pattern, even if you wanted to.

View Details

They can't read much of your data, but even a few stray network packets could tell them something they're not supposed to know.

View Details

The only backup you will ever regret is the one you didn't make...

View Details

Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

View Details

Latest episode - listen now!

View Details

Thinking of trying a bit of DDoSsing to get a feel for life at the fringes of the Dark Side? Don't do it!

View Details

Got an older iPhone that can't run iOS 16? You've got a zero-day to deal with! That super-cool Studio Display monitor needs patching, too.

View Details

Microsoft says "successful exploitation requires uncommon user interaction", but it's the innocent and accidental leakage of private data you should be concerned about.

View Details

His prediction was called a "Law", though it was an exhortation to engineering excellence as much it was an estimate.

View Details

Admin-level holes in websites are always a bad thing... and for "bad", read "worse" if it's an e-commerce site.

View Details

Listen now - latest episode. Full transcript inside.

View Details

Turns out that the Windows 11 Snipping Tool has the same "aCropalypse" data leakage bug as Pixel phones. Here's how to work around the problem...

View Details

What if the "safe" images you shared after carefully cropping them... had some or all of the "unsafe" pixels left behind anyway?

View Details

As the misquote goes, "Once is misfortune..." This is the second time, and you know what Lady Bracknell had to say about that...

View Details

Despite its usually inflexible 0-day disclosure policy, Google is keeping four mobile modem bugs semi-secret due to likely ease of exploitation.

View Details

Worried about rogue apps? Unsure about the new Outlook zero-day? Clear advice in plain English... just like old times, with Duck and Chet!

View Details

An email you haven't even looked at yet could be used to trick your mail server into helping crooks to logon as you.

View Details

In the game of cricket, 111 is an unauspicious number, but for Firefox, there doesn't seem to be much to worry about this month.

View Details

Linux doesn't BSoD. It has oopses and panics instead. (We show you how to make a kernel module to explore further.)

View Details

It's not exactly data theft, but it's worrying close to "unintentional treachery" - apparently because it's great for marketing purposes

View Details

Lastest episode - listen now! (Full transcript inside.)

View Details

Security bugs in the very code you've been told you must have to improve the security of your computer...

View Details

Devices seized, suspects interrogated and arrested, allegedly connected to devastating cyberattack on University Hospital in Düsseldorf.

View Details

Wondering which cybercrime tools, techniques and procedures to focus on? How about any and all of them?

View Details

Rogue software packages. Rogue "sysadmins". Rogue keyloggers. Rogue authenticators. Rogue ROGUES!

View Details

Seems the crooks implanted a keylogger via a vulnerable media app (LastPass politely didn't say which one!) on a developer's home computer.

View Details

Even in Apple's and Google's "walled gardens", there are plenty of 2FA apps that are either dangerously incompetent, or unrepentantly malicious. (Or perhaps both.)

View Details

Latest episode - listen now! Top-notch advice for cybersecurity, both at work and at home.

View Details

Free spins? Bonus game points? Cheap social media followers? What harm could it possibly do if you just take a tiny little look?!

View Details

Another day, another "sophisticated" attack. This time, the company has handily included some useful advice along with its mea culpa...

View Details

Ironically, Twitter Blue users will be allowed to keep using the very 2FA process that's not considered secure enough for everyone else.

View Details

New report admits that attackers were detected in the network about three months ago, and may have been attacking for about three years.

View Details

Latest episode - listen now! (Full transcript inside.)

View Details

Lots of lovely patches for your Valentine's Day delight. Get 'em as soon as you can...

View Details

Everyone update now! Except for those who don't need to! Or who need to but will only get updates later on, though Apple isn't saying yet!

View Details

Conditional code considered cryptographically counterproductive.

View Details

Reddit is suggesting three tips as a follow-up to this breach. We agree with two of them but not with the third...

View Details

Latest epsiode. Listen now!

View Details

7 memory mismanagements and a timing attack. We explain all the jargon bug terminology in plain English...

View Details

To borrow from HHGttG, please DON'T PANIC. But if you are two years out of date with patches, please do ACT NOW!

View Details

Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary about the "war on crypto" as we talk to him about his new book...

View Details

Company transcribed ultra-personal conversations, didn't secure them. Criminal stole them, then extorted thousands of vulnerable patients.

View Details

It's a bug fix for a bug fix. A memory leak was turned into a double-free that has now been turned into correct code...

View Details

Latest episode - listen now!

View Details

Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

View Details

There was a breach, so the bad news isn't great, but the good news isn't too bad...

View Details

Enjoy our Serious Security deep dive into this real-world example of why cryptographic agility is important!

View Details

Unfortunately, you've probably already heard the cliche that "cybercrime abhors a vacuum"...

View Details

Undercover Austrian "controlled data buy" leads to Amsterdam arrest and ongoing investigation. Suspect is said to steal and sell all sorts of data, including medical records.

View Details

Lastest episode - listen now! (Or read the transcript.)

View Details

We were going to write, "Once more unto the breach, dear friends, once more"... but it seems to go without saying these days.

View Details

Don't delay, especially if you're still running an iOS 12 device... please do it today!

View Details

It's a really cool and super-simple trick. The question is, "Will it help?"

View Details

Once more, it's time for Shakespeare's words: Once more unto the breach...

View Details

As always: entertaining, informative and educational... and not bogged down with jargon! Listen (or read) now...

View Details

Four straight-talking tips to improve your online security, whether you're a LifeLock customer or not.

View Details

216 questioned, 15 arrested, 4 fake call centres searched, millions seized...

View Details

Tell us in the comments... What's the REAL reason there was no Windows 9? (No theory too far-fetched!)

View Details

Get 'em while they're hot. And get 'em for the very last time, if you still have Windows 7 or 8.1...

View Details

It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.

View Details

They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

View Details

Stand down from blue alert, it seems... but why not plan your cryptographic agility anyway?

View Details

Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)

View Details

Lessons for us all: improve cryptography, fight cybercrime, own your supply chain... and don't steal my data and then pretend you're sorry.

View Details

When someone calls you up to warn you that your bank account is under attack - it's true, because THAT VERY PERSON is the one attacking you!

View Details

The bad news: the crooks have your SSH private keys. The good news: only users of the "nightly" build were affected.

View Details

The problem with anniversaries is that there's an almost infinite number of them every day...

View Details

Is there a special meaning of "don't" that means "go right ahead"?

View Details

Cryptographic agility: the ability and the willingness to change quickly when needed.

View Details

Listen now - you'll be alarmed, amused and educated, all in equal measure. (Full transcript in article.)

View Details

If the crooks have connected up your phone number and your Twitter handle... what could go wrong?

View Details

It's serious, it's critical, and you could call it severe... but in HHGttG terminology, it's probably "mostly harmless".

View Details

The crooks now know who you are, where you live, which computers are yours, where you go online... and they got those password vaults, too.

View Details

Join world-renowned expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode on how to fight cybercrime.

View Details

A picture is worth 1024 words - we clicked through so you don't have to.

View Details

It happens to the best of us: Microsoft highlights a security bypass bug on Macs that is curiously similar to a recent Windows 0-day.

View Details

The Cryptoqueen herself is still missing, but her co-conspirator, who is said to have pocketed over $20m a month, has been convicted.

View Details

Return o' the rookit, super-sneaky wireless spyware, credit card skimming, and patches galore. Listen and learn!

View Details

There's an update for everything this time, not just for iOS.

View Details

Tales of derring-do in the cyberunderground! (And some zero-days.)

View Details

It's not the switching that's the problem, it's the switching of the switching!

View Details

That's a mean average of $15,710 per bug... and 63 fewer bugs out there for crooks and rogues to find.

View Details

Breaches, exploits, busts, buffer overflows and bug hunting - entertaining and educational in equal measure.

View Details

Don't keep calling home to a JavaScript server that closed its doors eight years ago!

View Details

Guilty party got 18 months, also has to pay back $20m he probably hasn't got, which could land him in more hot water.

View Details

It's a venerable program, and this version had a venerable bug in it.

View Details

Ninth more unto the breach, dear friends, ninth more.

View Details

We grabbed the update, based on no information at all, just in case we came across a reason to advise you not to. So far, so good...

View Details

Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.

View Details

"Uh-oh, this viruses-and-worms scene could turn out quite troublesome." If only we'd been wrong...

View Details

Latest episode - listen now (or read if you prefer)...

View Details

It's not just the hashing, by the way. It's the salting and the stretching, too!

View Details

An injury to one is an injury to all. Especially if the other people are part of your social network.

View Details

There isn't a rhyme to remind you which months have browser zero-days... you just have to keep your eyes and ears open!

View Details

Those numbers or names that pop up when a call comes up? They're OK as a hint of who's calling, but THEY PROVE NOTHING

View Details

Latest episode - security expert John Shier explains what the real-life cybercrime stories in the Sophos Threat Report can teach us

View Details

Five tips to keep yourself, and your friends and family, out of the clutches of "chopping block" scammers...

View Details

Review your servers, your patches and your authentication policies - there's a proof-of-concept out

View Details

The warning is hosted on a real Facebook page; the phishing uses HTTPS via a real Google server... but the content is all fake

View Details

Latest episode - listen now! Cybersecurity news plus loads of great advice...

View Details

Don't let a keen eye for bargains lead you into risky online behaviour...

View Details

What's so bad about a web page going fullscreen without warning you first?

View Details

Good old "string templating", also known as "string interpolation", in the spotlight again...

View Details

Learn how to protect yourself from big-money tricksters like the Hushpuppis of the world...

View Details

A bit like leaving the front door keys under the doormat...

View Details

Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks - listen now!

View Details

Not a zero-day, but important enough for a quick-fire patch to one system library...

View Details

In all the excitement, we kind of lost track ourselves. Were there six 0-days, or only four?

View Details

Jurisprudence isn't like arithmetic... two negatives never make a positive!

View Details

Never make your users cry/By how you use an API

View Details

That was the week that was...

View Details

How to Hack! Finding OpenSSL library files and accurately identifying their version numbers...

View Details

Listen now - latest episode - audio plus full transcript

View Details

That bated-breath OpenSSL update is out! It's no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here's why...

View Details

As everyone waits for news of a bug in OpenSSL, here's a reminder that other cryptographic code in your life may also need patching!

View Details

If you can't beat 'em, sue 'em!

View Details

Latest episode - listen and learn now (or read and revise, if the written word is your thing)...

View Details

Obstructed FTC proceedings, and concealed a crime, said the jury.

View Details

Judge tells the accused that if he hadn't pleaded guilty, "I would have given you life."

View Details

Two years of scamming + $10 million leeched = 25 years in prison. Just in time for #Cybermonth.

View Details

Some thoughts for Cybersecurity Awareness Month: Is is worth reporting nuisance calls? Is it even worth reporting outright scams?

View Details

Who's affected, what you can do while waiting for Microsoft's patches, and how to plan your threat hunting...

View Details

Double-play 0-day in Exchange - what you need to know, and what you can do

View Details

Latest episode - listen now! Tell fact from fiction in hyped-up cybersecurity news...

View Details

Licence compromised? Passport number burned? Need a new one? Who's going to pay?

View Details

This time, the crooks got there first - only 1 security hole patched, but it's a zero-day.

View Details

This site, like millions of others, has a certificate from Let's Encrypt. Farewell, Peter Eckersley, PhD, who helped make it all possible.

View Details

Latest episode - listen now!

View Details

Patch as soon as you can - that recent WebKit zero-day affecting new iPhones and iPads is apparently being used against older models, too.

View Details

24 existing bugs fixed. And, we hope, numerous potential future bugs prevented.

View Details

How to get the better of bugs in all the possible packages in your supply chain?

View Details

What does the recent LastPass breach mean for password managers? Just a bump in the road, or a reason to ditch them entirely?

View Details

Two trust-spoofing bugs were the main culprits this month - but neither one was a zero-day.

View Details

Latest episode - listen now! (Or read the transcript if you prefer the text version.)

View Details

One bit per second makes the Voyager probe data rate seem blindingly fast. But it's enough to break your security assumptions...