OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway! – Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway! – Naked Security

We’ll begin with the vital stuff: the extensively awaited OpenSSL bugfixes introduced final week are out. OpenSSL 1.1.1 goes to model 1.1.1s, and patches one listed security-related bug, but this bug doesn’t have a safety score or an official CVE...
Zoom for Mac patches sneaky “spy-on-me” bug – update now! – Naked Security

Zoom for Mac patches sneaky “spy-on-me” bug – update now! – Naked Security

Popular and ubiquitous (software program isn’t at all times each of these issues!) cloud assembly firm Zoom not too long ago introduced an oops-that-wasn’t-supposed-to-happen bug within the Mac model of its software program. The safety bulletin is, forgivably, written within...
Poisoned Python and PHP packages purloin passwords for AWS access – Naked Security

Poisoned Python and PHP packages purloin passwords for AWS access – Naked Security

A keen-eyed researcher at SANS just lately wrote a few new and somewhat particular kind of supply chain attack in opposition to open-source software program modules in Python and PHP. Following on-line discussions a few suspicious public Python module, Yee...
Ransomware Survey 2022 – like the Curate’s Egg, “good in parts” – Naked Security

Ransomware Survey 2022 – like the Curate’s Egg, “good in parts” – Naked Security

Even when you’re not a local speaker of English, you’ve in all probability heard the curious saying, “It’s a little bit of a Curate’s Egg”, referring to one thing about which you’re decided to maintain a optimistic public angle, even...

Firefox update brings a whole new sort of security sandbox – Naked Security

Today’s a Firefox Tuesday, when the latest version of Mozilla’s browser comes out, full with all of the security updates which have been merged into the product for the reason that earlier launch. We used to name them Fortytwosdays, as...

ALPACA – the wacky TLS security vulnerability with a funky name – Naked Security

TLS, brief for Transport Layer Security, is a crucial a part of on-line cybersecurity today. TLS is the information safety protocol that places the padlock in your browser’s deal with bar, retains your e mail encrypted whereas it’s being despatched...

OpenSSL fixes two high-severity crypto bugs – Naked Security

We’re certain you’ve heard of OpenSSL, and even should you aren’t a coder your self, you’ve virtually definitely used it. OpenSSL is among the hottest open-source cryptography libraries on the market, and plenty of well-known merchandise depend on it, particularly...

World’s most popular email server praised as ‘near-impenetrable’ – Naked Security

It isn’t typically that excellent news makes headlines, particularly within the safety world. Dovecot bucked the development earlier this month, with a cybersecurity audit that praised the mail server as “near-impenetrable”. Commendations like which are rarer than hens’ tooth. What...

Satori IoT botnet author sentenced to 13 months in prison – Naked Security

The coder who created the huge Satori botnet of enslaved gadgets and a handful of different botnets can be spending 13 months behind bars, the US Attorney’s Office of Alaska (*13*) on Friday. Kenneth Currin Schuchman, 22, from Vancouver, Wash.,...