DogWalk zero-day Windows bug receives patch – but not from Microsoft

A Windows zero-day vulnerability dubbed “DogWalk” has not received an official patch yet from Microsoft, but that hasn’t stopped others from offering free fixes to protect users.

Read more in my article on the Hot for Security blog. Continue reading DogWalk zero-day Windows bug receives patch – but not from Microsoft

Smashing Security podcast #278: Tim Hortons, avoiding sanctions, and good faith security research

Trouble brews with the Tim Hortons app, Mandiant gets in a tussle with a Russian ransomware gang, and should good faith security researchers be at risk of prosecution?

All this and much more is discussed in the latest edition of the award-winning “S… Continue reading Smashing Security podcast #278: Tim Hortons, avoiding sanctions, and good faith security research

Apple protected App Store users from $1.5 billion fraud last year

Apple says that it protected many millions of users from being defrauded to the tune of nearly $1.5 billion dollars in the last year, by policing its official App Store.

According to a newly published report by Apple, over 1.6 million risky and untr… Continue reading Apple protected App Store users from $1.5 billion fraud last year

Smashing Security podcast #277: Bad bots, cheeky ransoms, and good deepfakes

Ransom acts of kindness are top of our mind, as we also explore how bad bots are hogging more and more of the internet’s activity, and look at how deepfakes could be a good thing after all.

All this and much more is discussed in the latest edition o… Continue reading Smashing Security podcast #277: Bad bots, cheeky ransoms, and good deepfakes

Hacker steals Verizon employee database after tricking worker into granting remote access

A database of contact information for hundreds of Verizon employees is in the hands of cybercriminals, after a member of staff was duped into granting a hacker access to their work PC.

Read more in my article on the Hot for Security blog. Continue reading Hacker steals Verizon employee database after tricking worker into granting remote access

Follina. Unpatched Microsoft Office zero-day vulnerability exploited in the wild

The world is waiting for a patch from Microsoft, after a zero-day vulnerability in Microsoft Office was found to be being exploited in boobytrapped Word documents to remotely execute code on victims’ PCs. Continue reading Follina. Unpatched Microsoft Office zero-day vulnerability exploited in the wild

Using 2FA phone numbers for targeted advertising. One of the dumbest ways ever for a company to abuse its users’ trust. Take a bow, Twitter. And have a $150 million fine too.

Twitter has been fined $150 million for using phone numbers submitted by users to boost their security… for targeted advertising. Continue reading Using 2FA phone numbers for targeted advertising. One of the dumbest ways ever for a company to abuse its users’ trust. Take a bow, Twitter. And have a $150 million fine too.