Security Now!

SN 912: The NSA @ Home - LastPass hack details, Signal says no to UK, more PyPI troubles, QNAP bug bounty

Hinzugefügt: 1. März 2023

Picture of the Week.
Windows 11? ... anyone?
As Plain as Ever.
Edge's new built-in VPN?
LastPass Incident Update.
Signal says NO to the UK.
More PyPI troubles.
The QNAP bug bounty program....

SN 911: A Clever Regurgitator - GoneDaddy, Section 230, NPM malware, Hyundai Kia mess, Meta Verified

Hinzugefügt: 22. Februar 2023

GoneDaddy, Section 230, NPM malware, Hyundai Kia mess, Meta Verified
Picture of the Week.
GoneDaddy.
Section 230.
No Blue, No SMS-based 2FA.
Bitwarden gets Argon.
"Meta Verified".
Emsisoft...

SN 910: Ascon - Malicious ChatGPT Use, Google Security Key Giveaway, OTPAuth

Hinzugefügt: 15. Februar 2023

Picture of the Week
ESXiArgs follow-up
ChatGPT's Malicious Use
Google Security Key Giveaway
Brave goes HTTPS-by-default
1Password Makes Another Passkeys Move
Russian Patriotic Hackers
Amazon...

SN 909: How ESXi Fell - EU Internet Surveillance, QNAP returns, .DEV is always HTTPS

Hinzugefügt: 8. Februar 2023

Picture of the Week.
The European Union's Internet Surveillance Proposal.
30,000 patient records online?
.DEV is always HTTPS!
Google changes Chrome's release strategy.
Russia shoots the...

SN 908: Data Operand Independent Timing - Old Android apps, Kevin Rose, iOS 6.3 and FIDO, Hive hacked

Hinzugefügt: 1. Februar 2023

Android to start blocking old and unsafe apps.
Microsoft to block Internet sourced Excel add-ins.
An example of saying "no" even when it may hurt.
Hacked Wormhole funds on the move.
Kevin Rose...

SN 907: Credential Reuse - iOS 16.3, ChatGPT creates malware, Bitwarden acquires Passwordless.dev

Hinzugefügt: 25. Januar 2023

Picture of the Week.
PayPal Credential Stuffing.
iOS 16.3 : Cloud encryption for all.
InfoSecurity Magazine: "ChatGPT Creates Polymorphic Malware".
CheckPoint Research: OPWNAI : Cybercriminals...

SN 906: The Rule of Two - Norton Lifelock Data Breach, Chromium and Rust, LastPass

Hinzugefügt: 18. Januar 2023

Picture of the Week
About Password Iterations
EBC or CB
Norton Lifelock Troubles
Chrome Follows Microsoft and Firefox
Chromium is Beginning to Rust
BYOVD and Windows Defender Failures...

SN 905: 1 - LastPass Aftermath, LastPass vault de-obfuscator, LastPass iteration count folly

Hinzugefügt: 11. Januar 2023

Picture of the Week.
LastPass Aftermath.
LastPass Vault De-Obfuscator.
What more do we know this week regarding LastPass?
The most alarming discovery by listeners.
Understanding the scale of...

SN 904: Leaving LastPass - How LastPass failed, Steve's next password manager, how to protect yourself

Hinzugefügt: 4. Januar 2023

Picture of the Week.
SpinRite.
Leaving LastPass.
Is there reason for concern?
Well known password cracker Jeremi Gosney's LastPass rant.
Steve shares his plan regarding LastPass.
What is...

SN 903: Security Now Best of 2022 - The best moments from throughout the year

Hinzugefügt: 27. Dezember 2022

Anatomy of a Log4j Exploit.
Will Russia Disconnect?
FCC Says Kaspersky Labs is a National Security Threat.
Lenovo UEFI Firmware Troubles.
That ""Passkeys"" Thing.
Dis-CONTI-nued: The End of...

SN 902: A Generic WAF Bypass - Pwn2Own Toronto, URSNIF malware, Vivaldi Mastodon support, Bye Bye SHA-1

Hinzugefügt: 21. Dezember 2022

Picture of the Week.
A malware operation known as URSNIF.
Pwn2Own Toronto 2022.
Citrix and Fortinet recently released security updates to patch 0-day vulnerabilities.
Patch Tuesday.
Another...

SN 901: Apple Encrypts the Cloud - Chrome Passkeys, Telegram malware, SYNC.com outage, Rackspace lawsuits

Hinzugefügt: 14. Dezember 2022

Picture of the Week.
Chrome does Passkeys.
SYNC.COM suffered its first outage.
Medibank reboot.
Totally fake cryptocurrency trading platforms.
Malware on Telegram.
Texas gets in on the TikTok...

SN 900: LastPass Again - South Dakota bans TikTok, Anker Eufy Camera debacle, Mozilla yanks trusted root

Hinzugefügt: 7. Dezember 2022

Picture of the Week.
Don't mess with Australia.
Facebook / Meta fined by Ireland.
REvil's full Medibank dump.
Is nothing sacred?
Mozilla yanks a (no longer) trusted root.
Android Platform...

SN 899: Freebie Bots & Evil Cameras - iSpoofer no more, Boa server vulnerability, CISA on Mastodon

Hinzugefügt: 30. November 2022

Picture of the Week.
iSpoof you no more.
Here come the Freebie Bots!
Anatomy of the real-time Cryptocurrency heist.
Lookin' for something to do?
Boa server vulnerability.
The dilemma of...

SN 898: Wi-Peep - FBI purchased Pegasus, Passkey support directory, Quantum decryption deadline, Firefox 107

Hinzugefügt: 23. November 2022

Picture of the Week.
Firefox v107 was released last Tuesday.
Google settles for a cool $391.5 million.
Red Hat Signing its ZIP file Packages.
The FBI purchased Pegasus for "research and...

SN 897: Memory-Safe Languages - Shennina Framework, Shufflecake, The Helm, LightSpeed vulnerabilities

Hinzugefügt: 16. November 2022

Picture of the Week.
Patch Tuesday review.
Shennina Framework - Automating Host Exploitation with AI.
GitHub's welcome new feature.
Three LightSpeed vulnerabilities.
Shufflecake: Plausible...

SN 896: Something for Everyone - Dropbox breach, cyber bank heists, Russia goes Linux, OpenSSL flaw update

Hinzugefügt: 9. November 2022

Picture of the Week.
A minor Dropbox breach.
OpenSSL follow-up.
FTC sued and settled with a repeated offender.
$1.2 billion in reported ransomware payments during 2021.
Akamai's Q3 Threat...

SN 895: After 20 years in GCHQ - Stranger Strings, PayPal passkeys, new TCP/IP RCE in Windows

Hinzugefügt: 2. November 2022

Picture of the Week.
Windows driver blocklist to be updated next Tuesday.
More Microsoft shenanigans.
An upcoming OpenSSL CRITICAL vulnerability update -- get ready!
A new TCP/IP RCE in...

SN 894: Data Breach Responsibility - Firefo 106, KataOS and Sparrow, banking malware, CVSS 9.8 updateQ

Hinzugefügt: 26. Oktober 2022

Picture of the Week.
Firefox 106 is out.
Google's Open Source IoT KataOS and Sparrow.
This Week in CryptoCurrency Craziness.
New Windows 0-day bypasses executable security checks.
Apple's 9th...

SN 893: Password Change Automation - Windows Update RSS, malicious kernal drivers, Signal SMS/MMS, ZimaBoard

Hinzugefügt: 19. Oktober 2022

Picture of the Week.
Microsoft "Won't Fix".
Malicious Kernel Drivers.
Microsoft has finally added an RSS feed for Windows Updates!
Passkeys [dot] Dev.
Largest DDoS attack.
Signal will be...