Security Now!

SN 831: Apple's CSAM Mistake - Flawed Random Number Generator, Super Duper Secure Mode, TCP Stack Error

Hinzugefügt: 11. August 2021

Picture of the week.
"You're Doing IoT RNG"
The Pulse Secure VPN remains in trouble.
And Cisco, too...
Flaws found in another popular embedded TCP/IP library.
Microsoft Edge gets "Super Duper...

SN 830: The BlackMatter Interview - Bad News for Firefox, DarkSide Returns, Tailscale, Google to Assume HTTPS

Hinzugefügt: 4. August 2021

Picture of the Week.
Mozilla's Firefox Monthly Active Users (MAU) slowly but steadily drops.
Google to finally assume HTTPS.
The evolution of "Initial Access Brokers".
DarkSide Returns.
"A...

SN 829: SeriousSAM & PetitPotam - Kaseya Universal Decryptor, Window's Process Hacker, Chrome 92

Hinzugefügt: 28. Juli 2021

Picture of the Week.
Faster and more efficient phishing detection in Chrome 92.
A Universal Decryptor for all Kaseya victims.
The printer driver used by millions of HP, Samsung and Xerox Printers...

SN 828: REvil Vanishes! - Chrome Zero-Day Vulnerability, iOS WiFi SSID Bug, Patch Tuesday Review

Hinzugefügt: 21. Juli 2021

Picture of the week
Browser NewsThe attacks on Google Chrome continue.
Firefox special-cases anti-tracking for "Login With" functions.

Security NewsiOS WiFi SSID bug
We still can't awaken from the...

SN 827: REvil's Clever Crypto - Microsoft Fails to Patch PrintNightmare & Sodinokibi Malware's Crypto Design

Hinzugefügt: 14. Juli 2021

Picture of the Week
The "PrintNightmare Continues"
Kaseya - Not nearly as bad as it could have been
Ransomwhere site
Microsoft Office Users: There's a new malware-protection bypass
Ransomware...

SN 826: The Kaseya Saga - Microsoft PrintNightmare, WD's MyCloud OS3 Troubles, SpinRite in a BMW

Hinzugefügt: 7. Juli 2021

Picture of the Week.
"PrintNightmare" is NOT CVE-2021-1675.
The Authentication Dilemma.
Western Digital steps up.
WD's MyCloud OS3 Troubles.
SpinRite.
Miscellany & Closing The Loop.
The Kaysea...

SN 825: Halfway Through 2021 - Google's FLoC, $600M Ransomware Attack, Where Will Windows 11 Run?

Hinzugefügt: 30. Juni 2021

Picture of the week
Google's FLoC has landed with a hard thud and is now-delayed
The high cost of Ireland's recovery from the Conti ransomware attack
Who is responsible for damage and data loss...

SN 824: Avaddon Ransonomics - Chrome 0-Day, Big Spinrite Update, iOS Wi-Fi Bug, Economics of Ransomware

Hinzugefügt: 23. Juni 2021

Picture of the Week.
Another day, another Chrome 0-day.
Ransomware perpetrators are increasingly purchasing access.
A weird bug in iOS Wi-Fi.
An Early Preview of Windows 11.
The Security Now!...

SN 823: TLS Confusion Attacks - TikTok Privacy, iOS 14.5 Tracking Permission, Industry-Wide Patch Tuesday

Hinzugefügt: 16. Juni 2021

Picture of the week.
Being #1 is a mixed blessing.
Industry wide patch Tuesday.
TikTok Quietly Updated Its Privacy Policy to Collect Users' Biometric Data.
iOS 14.5 requires apps to obtain explicit...

SN 822: Extrinsic Password Managers - Great CyberSecurity Awakening of 2021, NAT vs IPv6, Tavis Ormandy

Hinzugefügt: 9. Juni 2021

Picture of the week.
The Great CyberSecurity Awakening of 2021.
Firefox will soon auto-update on Windows even when it's not running.
Edge takes its own approach to HTTPS switching.
Three new...

SN 821: Epsilon Red - Chrome 91, Emsisoft's Ransomware Decryption Tool, Revisiting Amazon Sidewalk

Hinzugefügt: 2. Juni 2021

Photo of the Week.
Chrome advances to 91.
Emsisoft has created their own ransomware decryption tool.
Stepping off the Sidewalk.
Just another phishing attack.
The Great Encryption Struggle.
Hail...

SN 820: The Dark Escrow - Firefox Fission, Doom CAPTCHA, Conti and CNA Financial Ransomware

Hinzugefügt: 26. Mai 2021

Picture of the Week.
Firefox finally achieves sustained "Fission".
Conti ransomware.
CNA Financial pays up big.
When they say IoT do they mean us?
"Mean Time to Inventory"
The "Doom" CAPTCHA.
The...

SN 819: The WiFi Frag Attacks - DarkSide Follow-Up, DarkTracer, Patch Tuesday, The Frontiers Saga

Hinzugefügt: 19. Mai 2021

Picture of the week.
DarkSide Follow-Up.
Follow The Money.
Toshiba Attacked by DarkSide.
Ransomware topics off-limits here.
"DarkTracer: DarkWeb Criminal Intelligence"
Please Leak our Stolen...

SN 818: News From the Darkside - Exim Email Server, Tor's Exit Nodes, TsuNAME, Project Hail Mary

Hinzugefügt: 12. Mai 2021

Picture of the week.
TsuNAME - "DNS Configuration Flaw Lets Attackers Take Down DNS Servers"
Huh Google?
Tor's Exit Nodes.
21 Nails in Exim's coffin.
Project Hail Mary: A Novel.
Closing the...

SN 817: The Ransomware Task Force - Scripps Health, REvil Hacks Quanta Computer, Emotet Botnet, QNAP

Hinzugefügt: 5. Mai 2021

Picture of the Week.
REvil hacks Apple supplier Quanta Computer.
World-famous Scripps Health taken down.
The Big Emotet Botnet Takedown.
Emotet's 4,324,770 eMail addresses.
Have I Been Pwned...

SN 816: The Mystery of AS8003 - Remembering Dan Kaminski, Project Zero, Unethical Security Research

Hinzugefügt: 28. April 2021

Remembering Dan Kaminski.
Week before last was Patch Tuesday.
Google's Project Zero responds to today's patch latency reality.
Baking security into IoT
UNethical security research.
CloudFlare...

SN 815: Homogeneity Attacks - Is FLoC All That Bad?, Humble Bundle For Programmers, Chrome 90

Hinzugefügt: 21. April 2021

Club TWiT details.
Picture of the Week.
The Vivaldi Project's take on FLoC.
Chrome continues to be THE high-value target.
We're at Chrome v90.
Exchange Server Web Shells removed, with DOJ...

SN 814: PwnIt And OwnIt - Why Port 10080 is Blocked, FLoC Rollout, PHP GIT Hack Revisited, CISCO Router Problems

Hinzugefügt: 14. April 2021

Picture of the week.
The Slips keep Streaming.
Are You FLoC'ed?
The PHP GIT Hack, revisited.
CISCO abandons old routers having problems.
Failure to Patch.
PwnIt And OwnIt.
We invite you to read our...

SN 813: A Spy in Our Pocket - Ubiquity Coverup, Facebook Data Dump, Malicious Call of Duty Cheats

Hinzugefügt: 7. April 2021

Ubiquity coverup, Facebook data dump, malicious Call of Duty cheats.
The Ubiquiti Coverup.
Facebook's 533,313,128 Million User Whoopsie!
Don't mess with our water!
Android moves to limit inter-app...

SN 812: GIT Me Some PHP - Spectre Returns to Linux, API Security, OpenSSL Flaws, SolarWinds

Hinzugefügt: 31. März 2021

Spectre returns to Linux, API Security, OpenSSL flaws, SolarWinds.
Picture of the week.
ProxyLogon Update.
Spectre returns to Linux.
OpenSSL fixes several high-severity flaws.
SolarWinds keeps...