S3 Ep149: How many cryptographers does it take to change a light bulb?

Published: 08/23/2023 20:06:08
S3 Ep149: How many cryptographers does it take to change a light bulb? Episode Details
Miss Manners confronts copy-and-paste. WinRAR patches bugs. When Airplane mode isn't. How many cryptographers to change a light bulb? Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep148: Remembering crypto heroes

Published: 08/17/2023 07:20:22
S3 Ep148: Remembering crypto heroes Episode Details
Navajo Code Talkers Day. Beta bogosities. Skimming shenanigans. Hooligan hosting. A cybercrime conundrum. Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep147: What if you type in your password during a meeting?

Published: 08/09/2023 18:43:44
S3 Ep147: What if you type in your password during a meeting? Episode Details
An amazing Art Deco computer. Yet more performance-versus-security trouble. Is sound alone enough to sniff out your password? A rap song (of sorts) with a cybersecurity connection. Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep146: Tell us about that breach! (If you want to.)

Published: 08/03/2023 11:32:00
S3 Ep146: Tell us about that breach! (If you want to.) Episode Details
Firefox fixes flaws. The exciting vulnerability that you don't need to be afraid of. Breach reporting rules with lots of leeway. Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep145: Bugs With Impressive Names!

Published: 07/27/2023 09:38:32
S3 Ep145: Bugs With Impressive Names! Episode Details
Apple patches two zero-days, one for a second time. How a 30-year-old cryptosystem got cracked. All your secret are belong to Zenbleed. Remembering those dodgy PC/Mac ads. Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep144: When threat hunting goes down a rabbit hole

Published: 07/20/2023 08:05:24
S3 Ep144: When threat hunting goes down a rabbit hole Episode Details
Why your Mac's calendar app says it's JUL 17. One patch, one line, one file. Careful with that {axe,file}, Eugene. Storm season for Microsoft. When typos make you sing for joy. Twitter: @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep143: Supercookie surveillance shenanigans

Published: 07/13/2023 09:16:07
S3 Ep143: Supercookie surveillance shenanigans Episode Details
Remembering the slide rule. What you need to know about Patch Tuesday. Supercookie surveillance shenanigans. When bugs arrive in pairs. Apple's rapid patch that needed a rapid patch. User-Agent considered harmful. Twitter: @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep142: Putting the X in X-Ops

Published: 07/06/2023 10:28:07
S3 Ep142: Putting the X in X-Ops Episode Details
First there was DevOps, then SecOps, then DevSecOps. Or should that be SecDevOps? Paul Ducklin talks to Sophos X-Ops insider Matt Holdcroft about how to get all your corporate "Ops" teams working together, with cybersecurity correctness as a guiding light. Twitter: @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep141: What was Steve Jobs's first job?

Published: 06/29/2023 09:29:25
S3 Ep141: What was Steve Jobs's first job? Episode Details
PONG for one player. Apple pushes out anti-spyware patch. Beware bad passwords on Linux servers. "Twitter hacker" gets 5 years. When mobile phones and dental hygiene collide. Twitter: @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep140: So you think you know ransomware?

Published: 06/22/2023 08:56:38
S3 Ep140: So you think you know ransomware? Episode Details
Gee Whizz BASIC (probably). Think you know ransomware? Megaupload, 11 years on. ASUS warns of critical router bugs. MOVEit mayhem Part III. Twitter: @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep139: Are password rules like running through rain?

Published: 06/15/2023 08:41:59
S3 Ep139: Are password rules like running through rain? Episode Details
Magnetic core memory. Patch Tuesday and SketchUp shenanigans. More MOVEit mitigations. Mt. Gox back in the news. Gozi malware criminal imprisoned at last. Are password rules like running through rain? Twitter @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep138: I like to MOVEit, MOVEit

Published: 06/08/2023 07:58:34
S3 Ep138: I like to MOVEit, MOVEit Episode Details
Calling all modems. KeePass gets an update. MOVEit gets pwned. Chromium zero-day. The backdoor that wasn't really. WPBT explained. Twitter @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep137: 16th century crypto skullduggery

Published: 06/01/2023 06:39:06
S3 Ep137: 16th century crypto skullduggery Episode Details
How to say "GIF". A Blackmailer-in-the-Middle attack. Knitting your own crypto. KeePass master password shenanigans. Binge listening. Email tips@sophos.com Twitter @NakedSecurity Intro and outro music by Edith Mudge (www.edithmudge.com)
S3 Ep136: Navigating a manic malware maelstrom

Published: 05/25/2023 06:15:19
S3 Ep136: Navigating a manic malware maelstrom Episode Details
Luminiferous aether. A $10m cybercrime reward. Bank scam kingpin gets 13 years. Three Apple 0-days. A Python malware maelstrom. Email tips@sophos.com Twitter @NakedSecurity
S3 Ep135: Sysadmin by day, extortionist by night

Published: 05/18/2023 07:51:12
S3 Ep135: Sysadmin by day, extortionist by night Episode Details
An Apple product that flopped (and was not the Newton). Two-faced sysadmin jailed for 6 years. The smart plug with the unsmart security hole. Clearview AI again, once more, again. Intro and outro music by Edith Mudge (https://www.edithmudge.com). Hit us up on Twitter: @NakedSecurity
S3 Ep134: It's a PRIVATE key - the hint is in the name!

Published: 05/11/2023 07:21:20
S3 Ep134: It's a PRIVATE key - the hint is in the name! Episode Details
The world-changing Visible Calculator. How not to get a job. Private keys - the hint is in the name. Microsoft's complicated bootkit patch. Taming Bluetooth trackers. Email: tips@sophos.com Twitter: https://twitter.com/nakedsecurity Original music by Edith Mudge (www.edithmudge.com)
S3 Ep133: Apple takes "tight-lipped" to a whole new level

Published: 05/04/2023 08:59:32
S3 Ep133: Apple takes "tight-lipped" to a whole new level Episode Details
New England gets BASIC. Google hits back at CryptBot crooks. Apple seals its lips on security. Mac malware-as-a-service. World Password Day. PaperCut: disclose or don't disclose? Original music by Edith Mudge (https://www.edithmudge.com).
S3 Ep132: Proof-of-concept lets anyone hack at will

Published: 04/27/2023 09:27:39
S3 Ep132: Proof-of-concept lets anyone hack at will Episode Details
The CIH or SpaceFiller virus revisited. Google's 2FA security shortcut. Server vulns under active attack. Two Chrome zero-days, but was it one attack? Email: tips@sophos.com Twitter: @NakedSecurity
S3 Ep131: Can you really have fun with FORTRAN?

Published: 04/20/2023 09:35:04
S3 Ep131: Can you really have fun with FORTRAN? Episode Details
Fun with FORTRAN?! An extreme data breach and its consequences. Rogue 2FA apps live in action. Juicejacking revisited. With Doug Aamoth and Paul Ducklin. Original music by Edith Mudge.
S3 Ep130: Open the garage bay doors, HAL

Published: 04/13/2023 09:15:15
S3 Ep130: Open the garage bay doors, HAL Episode Details
A common business-oriented language. Patch Tuesday. Secure Boot (without the "Secure" part). Apple zero-days. World-readable garage doors. Motherboard malware threats. Original music by Edith Mudge (https://www.edithmudge.com) Email tips@sophos.com Twitter @NakedSecurity
S3 Ep129: When spyware arrives from someone you trust

Published: 04/06/2023 07:53:14
S3 Ep129: When spyware arrives from someone you trust Episode Details
A supply chain attack that foisted spyware on trusting users. Wi-Fi encryption bypass via left-over data. Surely there should be TWO World Backup Days? Email tips@sophos.com Original music by Edith Mudge (https://www.edithmudge.com) Twitter @NakedSecurity
S3 Ep128: So you want to be a cybercriminal?

Published: 03/30/2023 08:45:49
S3 Ep128: So you want to be a cybercriminal? Episode Details
RIP Gordon Moore, the more in Moore's Law. Photo cropping bugfix. DDoS honeypot. E-commerce patches. Apple 0-day and lots more. Email tips@sophos.com Twitter @NakedSecurity
S3 Ep127: When you chop someone out of a photo, but there they are anyway...

Published: 03/23/2023 11:05:16
S3 Ep127: When you chop someone out of a photo, but there they are anyway... Episode Details
The mobile phone bugs that Google kept quiet, just in case. The mysterious case of ATM video uploads. When redacted data springs back to life. Email tips@sophos.com Twitter @NakedSecurity
S3 Ep126: The price of fast fashion (and feature creep)

Published: 03/16/2023 12:36:57
S3 Ep126: The price of fast fashion (and feature creep) Episode Details
The price of fast fashion. Firefox fixes. Feature creep fail curtailed in Patch Tuesday updates. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep125: When security hardware has security holes

Published: 03/09/2023 11:25:17
S3 Ep125: When security hardware has security holes Episode Details
Memories of Michelangelo (the virus, not the artist). Data leakage bugs in TPM 2.0. Ransomware bust, ransomware warning, and anti-ransomware advice. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep124: When so-called security apps go rogue

Published: 03/01/2023 18:49:06
S3 Ep124: When so-called security apps go rogue Episode Details
How Woz nearly gave away the Apple I. Rogue software packages. Rogue network "administrators". Rogue keyloggers. Rogue authenticators. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep123: Crypto company compromise kerfuffle

Published: 02/23/2023 10:59:13
S3 Ep123: Crypto company compromise kerfuffle Episode Details
The first search warrant for computer storage. GoDaddy breach. Twitter surprise. Coinbase kerfuffle. The cost of success. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep122: Stop calling every breach "sophisticated"!

Published: 02/16/2023 06:45:58
S3 Ep122: Stop calling every breach "sophisticated"! Episode Details
The birth of ENIAC. A "sophisticated attack" (someone got phished). A cryptographic hack enabled by a security warning. Valentine's Day Patch Tuesday. Apple closes spyware-sized 0-day hole. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep121: When cybercrime victims are culprits, too

Published: 02/08/2023 19:07:38
S3 Ep121: When cybercrime victims are culprits, too Episode Details
Cryptocurrency crimelords. Security patches for VMware, OpenSSH and OpenSSL. Medical breacher busted. Is that a bug or a feature? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Special: Tracers in the Dark with Andy Greenberg

Published: 02/06/2023 11:31:28
S3 Special: Tracers in the Dark with Andy Greenberg Episode Details
Do we really need a "war against cryptography" - codes and ciphers that the government can easily crack if it thinks there's an emergency - to cement our collective online security? Hear renowned cybersecurity author Andy Greenberg's thoughtful commentary on this and many other vital issues, including anonymity and privacy, as we talk to him about his tremendous new book, Tracers in the Dark. Original music by Edith Mudge.
S3 Ep120: When dud crypto simply won't let go

Published: 02/02/2023 09:52:12
S3 Ep120: When dud crypto simply won't let go Episode Details
The mighty CPU that wasn't. Hive ransomware takedown. Dutch data crime suspect busted. Samba finally gets rid of MD5. GitHub admits to an intrusion. Storing passwords securely. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep119: Breaches, patches, leaks and tweaks!

Published: 01/26/2023 06:19:03
S3 Ep119: Breaches, patches, leaks and tweaks! Episode Details
The programming language almost called Oak. GoTo admits to more breach woes. T-Mobile spills 37 million records. Apple patches everything, even iOS 12. And Google mAkES tYpOs for sECurity.Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep118: Guess your password? No need if it's stolen already!

Published: 01/18/2023 19:46:33
S3 Ep118: Guess your password? No need if it's stolen already! Episode Details
The HAPPY99 virus reminds us that less is more. Trouble with JSON Web Tokens. Investment scammers busted in Europe. The LifeLock "breach" that wasn't. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep117: The crypto crisis that wasn't (and farewell forever to Win 7)

Published: 01/12/2023 10:27:31
S3 Ep117: The crypto crisis that wasn't (and farewell forever to Win 7) Episode Details
Two stories from the underground. Bank scammers busted. The crypto-crack that wasn't. And the end of two Windows eras at the same time. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep116: Last straw for LastPass? Is crypto doomed?

Published: 01/05/2023 07:46:45
S3 Ep116: Last straw for LastPass? Is crypto doomed? Episode Details
The ground-breaking HP-35 digital calculator. Last straw for LastPass? Congress takes on quantum computing. 33 1/3-year-old cybersecurity lessons. Machine learning supply chain attack. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep115: True crime stories - A day in the life of a cybercrime fighter

Published: 12/28/2022 18:27:26
S3 Ep115: True crime stories - A day in the life of a cybercrime fighter Episode Details
Once more unto the breach, dear friends, once more! Paul Ducklin talks to Peter Mackenzie, Director of Incident Response at Sophos, in a cybersecurity session that will alarm, amuse and educate you, all in equal measure. Original music by Edith Mudge Got questions/suggestions/stories to share? Email: tips@sophos.com Twitter: @NakedSecurity
S3 Ep114: Preventing cyberthreats - stop them before they stop you!

Published: 12/22/2022 09:26:11
S3 Ep114: Preventing cyberthreats - stop them before they stop you! Episode Details
Join world-renowned Sophos expert Fraser Howard, Director of Research at SophosLabs, for this fascinating episode, recorded during our recent Security SOS Week 2022. When it comes to fighting cybercrime, Fraser truly is a "specialist in everything", and he also has the knack of explaining this tricky and treacherous subject in plain English. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep113: Pwning the Windows kernel: the crooks who hoodwinked Microsoft

Published: 12/15/2022 08:51:13
S3 Ep113: Pwning the Windows kernel: the crooks who hoodwinked Microsoft Episode Details
The irony of the CAN-SPAM law. When genuine kernel drivers go rogue. Apple patches everything. Stealing data via secret radio waves. E-commerce supply chain drama. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep112: Beware! Data breaches can haunt you more than once...

Published: 12/08/2022 08:58:43
S3 Ep112: Beware! Data breaches can haunt you more than once... Episode Details
The worm that wasn't a Goner. LastPass suffers a sting in the data breach tail. Apple's secretive update. The Ping o' Death. SIM swapping explained. A Beatles-esque 0-day in Chrome and Edge. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep111: The business risk of a sleazy "nudity unfilter"

Published: 12/01/2022 08:19:45
S3 Ep111: The business risk of a sleazy "nudity unfilter" Episode Details
Christmas-themed wormage. Prurient malware. Cryptorom busts. Voice call spoofing. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep110: Spotlight on cyberthreats - an expert speaks

Published: 11/24/2022 07:37:52
S3 Ep110: Spotlight on cyberthreats - an expert speaks Episode Details
Security specialist John Shier tells you the "news you can really use" - how to boost your cybersecurity based on real-world advice from the 2023 Sophos Threat Report. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep109: How one leaked email password could drain your business

Published: 11/17/2022 11:01:28
S3 Ep109: How one leaked email password could drain your business Episode Details
Microsoft's tilt at the MP3 marketplace. Apple's not-a-zero-day emergency. Cracking the lock on Android phones. Browser-in-the-Browser revisited. The Emmenthal cheese attack. Business Email Compromise and how to prevent it. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep108: What would YOU do if you found $3 billion in a popcorn tin?

Published: 11/10/2022 09:38:31
S3 Ep108: What would YOU do if you found $3 billion in a popcorn tin? Episode Details
Radio waves so mysterious they're known only as X-Rays. Were there six 0-days or only four? The cops that found $3 billion in a popcorn tin. Blue badge confusion. When URL scanning goes wrong. Tracking down every last unpatched file. Why even unlikely exploits can earn "high" severity levels. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep107: Eight months to kick out the crooks and you think that's GOOD?

Published: 11/03/2022 10:51:17
S3 Ep107: Eight months to kick out the crooks and you think that's GOOD? Episode Details
The man who put Boole in Boolean. OpenSSL's bated-breath update. Apple's zero-day finally settled. New Chrome zero-day. SHA-3 code gets a patch. Extreme extortion via stolen medical data. Data breach response the nonchalant way. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep106: Facial recognition without consent - should it be banned?

Published: 10/27/2022 06:44:46
S3 Ep106: Facial recognition without consent - should it be banned? Episode Details
Windows XP (fondly?!) remembered. Clearview AI courts controversy again. DEADBOLT ransomware crooks get counterhacked. Women cryptologists commemorated in US. How to measure randomness. Deconstructing Apple's latest security bulletins. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep105: WONTFIX! The MS Office cryptofail that "isn't a security flaw"

Published: 10/20/2022 08:49:15
S3 Ep105: WONTFIX! The MS Office cryptofail that "isn't a security flaw" Episode Details
Coolest videogame ever. Zoom thinks everyone's a developer. The Patch Tuesday that wasn't. A data breach coverup. Log4Shell all over again. And the Office cryptofail that Microsoft won't fix. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep104: Should hospital ransomware attackers be locked up for life?

Published: 10/13/2022 08:20:54
S3 Ep104: Should hospital ransomware attackers be locked up for life? Episode Details
What goes up... must come down. Ransomware criminal avoids a life sentence. Former CSO convicted over Uber megabreach coverup. WhatsApp fights rip-off rogue apps. The Countess of Computer Science. Could a weird email brick your iPhone? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep103.5: OAuth 2 and why Microsoft is forcing you into it

Published: 10/09/2022 14:52:54
S3 Ep103.5: OAuth 2 and why Microsoft is forcing you into it Episode Details
Naked Security meets Sophos X-Ops! Duck and Chet dig into OAuth 2.0, a well-known protocol for authorization. Microsoft calls it "Modern Auth", though it's a decade old, and is finally forcing Exchange Online customers to switch to it. Original music by Edith Mudge
S3 Ep103: Scammers in the Slammer (and other stories)

Published: 10/06/2022 07:07:20
S3 Ep103: Scammers in the Slammer (and other stories) Episode Details
A fridge-sized calculator made with transistors (really). ProxyNotShell situation reviewed. Romance and BEC scammer gets 25 years in the slammer. Is there an answer to nuisance callers? Is the answer voicemail? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep102.5: "ProxyNotShell" Exchange bugs - an expert speaks

Published: 10/01/2022 07:27:32
S3 Ep102.5: "ProxyNotShell" Exchange bugs - an expert speaks Episode Details
Chester Wisniewski gives you actionable advice on how to deal with two actively exploited Exchange zero-days that suddenly burst into the news. Learn who's affected and how, find out what you can do while waiting for Microsoft's patches, and plan your threat hunting in case the worst happens to you. Original music by Edith Mudge
S3 Ep102: Cutting through cybersecurity news hype

Published: 09/29/2022 06:16:26
S3 Ep102: Cutting through cybersecurity news hype Episode Details
What's the real deal with LAPSUS$? How did Optus get hacked? Was there really a WhatsApp 0-day? What if "deleted" data comes back from the dead to haunt you? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep101: Uber and LastPass - is 2FA all it's cracked up to be?

Published: 09/22/2022 09:33:43
S3 Ep101: Uber and LastPass - is 2FA all it's cracked up to be? Episode Details
Security SOS Week 2022 - check it out! The very first Android. Firefox 105 is out. Uber hacked... by LAPSUS$? LastPass talks about its breach. Are two disks better than one? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep100.5: Uber breach - an expert speaks

Published: 09/17/2022 15:02:10
S3 Ep100.5: Uber breach - an expert speaks Episode Details
Chester Wisniewski explains what we can learn from Uber's latest cybsecurity crisis: "Just because a big company didn't have the security they should doesn't mean you can't." Original music by Edith Mudge
S3 Ep100: Browser-in-the-Browser hacking – how to spot an attack

Published: 09/14/2022 16:24:27
S3 Ep100: Browser-in-the-Browser hacking - how to spot an attack Episode Details
Second Cosmic Rocket (not a band!) Microsoft 0-day. Apple 0-days. Good logging habits. Browser-in-the-browser trickery. DEADBOLT ransomware. Again. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity
S3 Ep99: TikTok "attack" - was there a data breach, or not?

Published: 09/08/2022 06:18:33
S3 Ep99: TikTok "attack" - was there a data breach, or not? Episode Details
The bug that was a moth. Was there really a TikTok breach? Peter Eckersley: Code In Peace. Chrome and Edge fix a zero-day. Apple updates iOS 12 for the first time in a year. App icons: the difference between sprockets and cogs. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep98: The LastPass saga - should we stop using password managers?

Published: 08/31/2022 19:48:11
S3 Ep98: The LastPass saga - should we stop using password managers? Episode Details
The Computer Misuse Act, back in 1990. JavaScript supply-chain bug hunting. Jumping airgaps. "The Sanitizer" comes to Chrome. LastPass breach provokes password manager puzzlement. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep97: A musical crash, ATM skimming, and was your iPhone pwned?

Published: 08/24/2022 19:11:14
S3 Ep97: A musical crash, ATM skimming, and was your iPhone pwned? Episode Details
Start me up. The R&B dance classic that crashed computers. Bitcoin ATM skimming (no malware required). Multiple browser zero-days. Was your iPhone pwned? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, heathcare security

Published: 08/17/2022 19:03:39
S3 Ep96: Zoom 0-day, AEPIC leak, Conti reward, heathcare security Episode Details
Chester attends DEF CON from afar. Zoom fixes an 0-day. An APIC leak that isn't EPIC. $10m for dobbing in Conti criminals. Cybersecurity in hospitals. Ransomware in triplicate. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto

Published: 08/10/2022 18:57:01
S3 Ep95: Slack leak, Github onslaught, and post-quantum crypto Episode Details
Memories of the Blaster worm. Slack leaked password hashes for FIVE YEARS. Github showered with malware. Traffic lights and cybersecurity. Post-quantum cryptography. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!)

Published: 08/04/2022 10:01:35
S3 Ep94: This sort of crypto (graphy), and the other sort of crypto (currency!) Episode Details
Queen Victoria goes online. A nasty bug in Samba. Smiles for SysAdmins. A crypto-as-in-cryptography bug. A crypto-as-in-currency disaster. And is $200 million just chump change these days? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep93: Office security, data breach costs, and leisurely patches

Published: 07/27/2022 20:00:32
S3 Ep93: Office security, data breach costs, and leisurely patches Episode Details
Geosynchronicity. Office security (on-off-on). A half-billion-dollar data breach cost. And patch that browser! Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep92: Log4Shell4Ever, summer tips, and scammer timing

Published: 07/20/2022 19:49:30
S3 Ep92: Log4Shell4Ever, summer tips, and scammer timing Episode Details
Integrated circuits and Nobel prizes. Log4Shell - forever? Cybersecurity tips for summmer. Scams and coincidence. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep91: Code Red, OpenSSL, Java bugs and Office macros

Published: 07/14/2022 06:39:31
S3 Ep91: Code Red, OpenSSL, Java bugs and Office macros Episode Details
Memories of the Code Red worm. OpenSSL fixes two tiny but troublesome bugs. More trouble in Java-land. Office macros off and back on again. Potential perils of paying ransomware demands. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass

Published: 07/06/2022 19:07:33
S3 Ep90: Chrome 0-day again, True Cybercrime, and a 2FA bypass Episode Details
Chrome quashes another zero-day browser bug. Two big-time cybercrime stories. A 2FA phishing scam that arrived PDQ. Chester swarmed by bots on Twitter. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix

Published: 06/29/2022 19:10:26
S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix Episode Details
Memories of the iPhone 1. Sextortion scams target LGBTQ+ daters. Yet another blockchain blunder. OpenSSL fixes the bug missed in the last bugfix. And what became of Little Bobby Tables? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep88: Phone scammers, hacking bust, and data breach fines

Published: 06/23/2022 05:50:49
S3 Ep88: Phone scammers, hacking bust, and data breach fines Episode Details
Duck gets behind the Ducks. 2000 phone scammers arrested in Interpol action. A three-year-old hacking case ends in conviction. And a Canadian financial company picks up an enormous data breach fine. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers

Published: 06/15/2022 08:09:40
S3 Ep87: Follina, AirTags, ID theft and the Law of Big Numbers Episode Details
Computer Science in the 1800s. Fixing Follina. AirTag stalking. ID theft site seizure. And the Law of Big Numbers versus SMS scams. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep86: The crooks were in our network for HOW long?!

Published: 06/08/2022 15:44:54
S3 Ep86: The crooks were in our network for HOW long?! Episode Details
The dawn of the x86 era. The Active Adversary Playbook. A sort-of zero day in Windows. A real-life zero-day in Atlassian Confluence. And the registry settings that could keep you in your job. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep85: Now THAT'S what I call a Microsoft Office exploit!

Published: 06/01/2022 19:18:58
S3 Ep85: Now THAT'S what I call a Microsoft Office exploit! Episode Details
Why calling a computer after a famous scientist doesn't always help. The wacky but dangerous 0-day hole in Windows. Supply chain attacks and the crooks who orchestrate them. Smishing revisited. And why saying what you really mean makes you better at cybersecurity. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep84: Government demand, Mozilla velocity, and Clearview fine

Published: 05/26/2022 15:44:17
S3 Ep84: Government demand, Mozilla velocity, and Clearview fine Episode Details
How network comms caught a murderer back in in 1845. Why the US government said, "Patch, or else!" How Mozilla got a double code-execution bug fixed in 48 hours. And why controversial face-matching company Clearview AI got fined $10m. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns

Published: 05/18/2022 18:33:36
S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns Episode Details
What does the word "non-commensurate" mean? When is cracking passwords legal? Why did Firefox get patched? Which computer needed dropping onto the desk? Why wasn't this 0-day listed in every Apple update? Did Duck get spammed, or was it actually a troll? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again)

Published: 05/11/2022 18:38:49
S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) Episode Details
Where does the word "radio" come from? RubyGems supply chain rip-and-replace bug. A weird, weird, weird, weird, weird GoogleDocs bug. Colonial Pipeline back in the cybersecurity news. What about built-in password managers? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms

Published: 05/05/2022 08:49:25
S3 Ep81: Passwords (still with us!), Github, Firefox at 100, and network worms Episode Details
World Password Day (we still need it), Github authentication tokens, Firefox hits a ton, and a look back at network worms. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java

Published: 04/27/2022 17:43:38
S3 Ep80: Ransomware news, phishing woes, NAS bugs, and a giant hole in Java Episode Details
The biggest mountain in tne solar system. New ransomware statistics. Trouble with phishing. Bugs in NAS boxes. A giant security hole in Java. And how to get an industrial grade firewall at home for free. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep79: Chrome hole, a bad-choice holiday, and cryptododginess

Published: 04/20/2022 18:24:48
S3 Ep79: Chrome hole, a bad-choice holiday, and cryptododginess Episode Details
Adam Osborne or John Osbourne? Another 0-day in Chrome. How not to choose a cybersecurity holiday destination. The Osbo[u]rne Effect. Cryptododginess that might actually be legal. And the Zilog Z80 versus the Mostech 6502. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution

Published: 04/14/2022 08:06:38
S3 Ep78: Darkweb hydra, Ruby, quantum computing, and a robot revolution Episode Details
Hydra darkweb market decapitated. Ruby module supply chain hole. Quantum computing sidestepped. A robot revolution that could result in ransomware. And the Zuckerberg scam that just won't die. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep77: Bugs, busts and old-school PDP-11 hacking

Published: 04/06/2022 18:17:11
S3 Ep77: Bugs, busts and old-school PDP-11 hacking Episode Details
Hacking 2022-style. Some Apple bugs. Some Android bugs. Some Firefox bugs. The SATAN network scanner. Some VMware Spring bugs. And hacking PDP-11 style. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep76: Deadbolt, LAPSUS$, Zlib and a Chrome 0-day

Published: 03/30/2022 19:58:00
S3 Ep76: Deadbolt, LAPSUS$, Zlib and a Chrome 0-day Episode Details
The DEADBOLT ransomware. LAPSUS$ members bust - or were they? Zlib patches a 17-year-old bug. Chrome experiences another weird 0-day. And Clippy. Yes, THAT Clippy. No, we're not sure why. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep75: Okta, CryptoRom, OpenSSL and CafePress

Published: 03/23/2022 19:07:05
S3 Ep75: Okta, CryptoRom, OpenSSL and CafePress Episode Details
LAPSUS$ hackers break into Okta. The CryptoRom money-scamming malware is back on phones. OpenSSL gets into an infinite loop. CafePress fined for covering up a data breach. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep74: Cybercrime busts, Apple patches, Pi Day, and disconnect effects

Published: 03/17/2022 08:25:12
S3 Ep74: Cybercrime busts, Apple patches, Pi Day, and disconnect effects Episode Details
Two ransomware suspects extradited for trial. Apple patches 87 known security holes. Happy Pi Day. What happens if a whole country exits the global internet? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep73: Ransomware with a difference, dirty Linux pipes, and more

Published: 03/09/2022 19:57:38
S3 Ep73: Ransomware with a difference, dirty Linux pipes, and more Episode Details
What do ransomware blackmailers ask for when they don't want money? Why did Firefox get two updates in three days? How did Adafruit get hoist by the petard of shadow IT? And what's with those dirty Linux pipes? REGISTER FOR OUR CYBERINSURANCE EVENT: https://events.sophos.com/cyberinsurance Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep72: AirTag stalking, web server coding woes and Instascams

Published: 03/02/2022 18:51:04
S3 Ep72: AirTag stalking, web server coding woes and Instascams Episode Details
How good is Apple's AirTag stalker detection? Why are web coders still making Y2K-like blunders? And how many Instagram scams can you get in one weekend? Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams

Published: 02/24/2022 10:41:36
S3 Ep71: VMware escapes, PHP holes, WP plugin woes, and scary scams Episode Details
VM escapes could put your host servers at risk. PHP fixes an input validation bug in input validation code. A WordPress plugin maker shows you how to write a decent security report. And French scammers remind us that sextortion is sadly still a thing. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep70: Bitcoin, billing blunders, and 0-day after 0-day after 0-day

Published: 02/16/2022 18:58:52
S3 Ep70: Bitcoin, billing blunders, and 0-day after 0-day after 0-day Episode Details
Alleged Bitcoin fraudsters busted, power company in trillion-dollar payout blunder, how a blizzard led to a telecomms revolution, and 0-day after 0-day after 0-day. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep69: Wordpress woes, Wormhole holes, and a Microsoft change of heart

Published: 02/09/2022 18:52:01
S3 Ep69: Wordpress woes, Wormhole holes, and a Microsoft change of heart Episode Details
Problems with plugins. A Wormhole wormhole. Can machines think? Microsoft has a change of heart. And then another one. Why screen cleaning cloths are cool. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep68: Bugs, scams, privacy... and fonts?!

Published: 02/02/2022 18:38:26
S3 Ep68: Bugs, scams, privacy... and fonts?! Episode Details
Stealing root on Linux. Snooping on RAM with a video driver bug. Apple patches a zero-day hole. SMS scams promise home PCR machines. German court freaks out over fonts. How to be private. And a paint robot that went wild. https://nakedsecurity.sophos.com/pwnkit-security-bug-gets-you-root https://nakedsecurity.sophos.com/linux-kernel-patches-performance-can-be-harmful-bug https://nakedsecurity.sophos.com/apple-patches-safari-data-leak https://nakedsecurity.sophos.com/coronavirus-sms-scam-offers-home-pcr https://nakedsecurity.sophos.com/website-operator-fined-for-using-google-fonts https://nakedsecurity.sophos.com/happy-data-privacy-day Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep67: Tax scams, carder busts and crypto capers

Published: 01/27/2022 06:05:28
S3 Ep67: Tax scams, carder busts and crypto capers Episode Details
Watch out for tax scams. Crooks with the motto "In Fraud We Trust". How not to write a data breach notification. Where to find the "10" key on your telephone. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis

Published: 01/20/2022 08:39:14
S3 Ep66: Cybercrime busts, wormable Windows, and the crisis of featuritis Episode Details
Russia busts Revil. Romance scammer sent to prison. Wormable Windows hole patched. Memories of the HAPPY99 virus. Linux disk encryption trouble. Apple browsers leak personal data. And how (not) to paint a computer. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle

Published: 01/13/2022 06:40:12
S3 Ep65: Supply chain conniption, NetUSB hole, Honda flashback, FTC muscle Episode Details
A JavaScript coder sabotages his own projects. Routers with critical holes. Honda cars party like it's 2002. The FTC warns everyone to patch. And a Log4Shell-like bug in another Java library. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep64: Log4Shell again, scammers keeping busy, and Apple Home bug

Published: 01/05/2022 18:13:04
S3 Ep64: Log4Shell again, scammers keeping busy, and Apple Home bug Episode Details
Log4Shell - the gift that keeps on taking. Scammers threatening your social media accounts. Apple Home has a pecuu[...]uuliar bug. And why 2FA is easier than you think. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep63: Log4Shell (what else?) and Apple kernel bugs

Published: 12/16/2021 09:47:22
S3 Ep63: Log4Shell (what else?) and Apple kernel bugs Episode Details
Understanding Log4Shell. Fixing Log4Shell. What criminals are up to with Log4Shell. Apple's latest security fixes. And what (not to) do when your mouse gets stuck. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep62: The S in IoT stands for security (and much more)

Published: 12/09/2021 11:33:06
S3 Ep62: The S in IoT stands for security (and much more) Episode Details
Mozilla's "BigSig" buffer overflow hole. UK to put IoT vendors on notice. The Mother of All Demos. Cryptocurrency company catastrophe. Firefox gets an extra sandbox. And an access point from outer space (OK, from home). Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness

Published: 12/02/2021 11:34:15
S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness Episode Details
Call scammers and cryptocoin treachery. Cloud insecurity and yet more cryptocoin treachery. Facial recognition creepiness. And the wannabe wizard that went to school with a trainee Sith. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public

Published: 11/24/2021 19:35:34
S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public Episode Details
Cybersecurity tips for the holiday season and beyond. Exchange at risk from public exploit. GoDaddy loses passwords for 1.2m users. Longest-lived Windows version ever. Don't make your cookies public. And the day that umbrellas became an anti-DDoS tool. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep59: Emotet, an FBI hoax, Samba bugs, and a hijackable suitcase

Published: 11/18/2021 08:35:09
S3 Ep59: Emotet, an FBI hoax, Samba bugs, and a hijackable suitcase Episode Details
The infamous Emotet malware makes a comeback. Crooks smirk at the world with a fake FBI warning. Why tubes are also valves. Samba fixes an intriguing bug. The suitcase that needs no handle. And a virtual-versus-real monitor mixup. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust

Published: 11/11/2021 11:50:15
S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust Episode Details
We enjoy the Sophos 2022 Threat Report. The world's {oldest, coolest} continously maintained browser. Facebook folds up its Face Recognition feature. Crooks combine a new social engineering scam with a new way of packaging malware. Kaseya ransomware suspect busted in Poland. Oh! No! How to block radio communications in a land with no hills. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars

Published: 11/04/2021 12:41:25
S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars Episode Details
Norbert (huzzah for Norbert!) does tech support. Europol digs into the ransomware scene. Microsoft finds a wacky bug in Apple's shell. The Morris worm turns 33. Edge on Linux phans the phlames. Ola! Gibberish peculiarity textual solvage. Original music by Edith Mudge Got questions/suggestions/stories to share? Email tips@sophos.com Twitter @NakedSecurity Instagram @NakedSecurity
S3 Ep56: Cryptotrading rodent, ransomware hackback, and a Docusign phish

Published: 10/28/2021 06:56:50
S3 Ep56: Cryptotrading rodent, ransomware hackback, and a Docusign phish Episode Details
Bliss is a hill in wine country. Lessons from a cryptotrading hamster. Ransomware gang hacked back. Docusign phishers go after 2FA codes. Sleep mode considered harmful. Original music by Edith Mudge Got something to share? Email tips@sophos.com
S3 Ep55.8: Purple teaming - learning to think like your adversaries

Published: 10/25/2021 11:39:12
S3 Ep55.8: Purple teaming - learning to think like your adversaries Episode Details
Special minisode! Michelle Farenci knows her stuff, because she's a cybersecurity practitioner inside a cybersecurity company. Learn why thinking like an attacker makes you a better defender. Full transcript: https://nakedsecurity.sophos.com/listen-up-4-cybersecurity-first-purple-teaming
S3 Ep55.6: Cyberinsurance - help or hindrance?

Published: 10/25/2021 11:24:49
S3 Ep55.6: Cyberinsurance - help or hindrance? Episode Details
Special minisode! Dr Jason Nurse, Associate Professor in Cybersecurity at the University of Kent, takes on the controversial topic of cyberinsurance. Full transcript: https://nakedsecurity.sophos.com/becybersmart-2021-cyberinsurance
