Stop calling it ‘the cloud’, start selling t-shirts…

A couple of years ago, I said something to the press that became a minor meme.
My suggestion was that people should “stop calling it ‘the cloud'” and start referring to it as “somebody else’s computer” instead.
After all, as soon as you start using lan… Continue reading Stop calling it ‘the cloud’, start selling t-shirts…→

Riseup, providing encrypted comms for over 15 years, could run out of money next month

Riseup.net, the non-profit collective which has been providing dissidents a way to encrypt their communications since 1999, without revealing your location or logging your IP address, is running out of money:
The news is not good
We hate to be bad news… Continue reading Riseup, providing encrypted comms for over 15 years, could run out of money next month→

Podcast with Ahmed Mansoor, the world’s most spied-on man

If you’re a user of Apple products you should know that critical updates have been pushed out for iOS and OS X in the last couple of weeks, addressing vulnerabilities that state-sponsored hackers have been using to spy upon people of interest.
Malware … Continue reading Podcast with Ahmed Mansoor, the world’s most spied-on man→

Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily

Get trending info on hackers, exploits, and vulnerabilities every day for FREE with the Recorded Future Cyber Daily [Sponsor]

Graham Cluley Security News is sponsored this week by the folks at Recorded Future. Thanks to the great team there for their support!

Recorded Future provides deep, detailed insight into emerging threats by automatically collecting, analyzing, and organizing billions of data points from the Web.

And now, with its FREE Cyber Daily email all IT security professionals can access information about the top trending threat indicators – helping you use threat intelligence to help make better decisions quickly and easily.

Which means that you will be able to benefit from a daily update of the following:

  • Information Security Headlines: Top trending news stories.
  • Top Targeted Industries: Companies targeted by cyber attacks, grouped by their industries.
  • Top Hackers: Organizations and people recognized as hackers by Recorded Future.
  • Top Exploited Vulnerabilities: Identified vulnerabilities with language indicating malcode activity. These language indicators range from security research (“reverse engineering,” “proof of concept”) to malicious exploitation (“exploited in the wild,” “weaponized”).
  • Top Vulnerabilities: Identified vulnerabilities that generated significant amounts of event reporting, useful for general vulnerability management.

Infosec professionals agree that the Cyber Daily is an essential tool:

“I look forward to the Cyber Daily update email every morning to start my day. It’s timely and exact, with a quick overview of emerging threats and vulnerabilities. For organizations looking to strengthen their security program with threat intelligence, Recorded Future’s Cyber Daily is the perfect first step that helps to prioritize security actions.” – Tom Doyle, CIO at EBI Consulting.

So, what are you waiting for?

Sign up for the Cyber Daily today, and starting tomorrow you’ll receive the top trending threat indicators.


If you’re interested in sponsoring my site for a week, and reaching an IT-savvy audience that cares about computer security, you can find more information here.

Continue reading Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily→

Mac users vulnerable to state-sponsored Trident attack, fixed in iOS last week. Patch now

Remember the critical security holes that Apple patched in iOS last week after a human rights activist had his iPhone targeted in a seemingly state-sponsored attack?

Ahmed Mansoor received two suspicious SMS messages on his iPhone, directing him to websites containing a zero-day iOS exploit. Researchers connected the attack to Israeli-based firm NSO Group, and dubbed the vulnerabilities “Trident”.

Well, Apple has now quietly rolled-out a further security update revealing that the zero-day flaws are also present in Apple’s OS X desktop operating system, as well as the desktop version of their OS X Safari browser.

My advice to Apple users? Make sure that your Macs, MacBooks, iPhones and iPads are up-to-date.

On OS X the easiest way to update your computer is to open the App Store app on your Mac, then click Updates in the toolbar. If updates are available, click the Update buttons to download and install them.

On iOS go to Settings > General > Software Update.

You may not be a human rights activist, but the fact that it took Apple *days* to issue a fix for OS X users after patching the same vulnerabilities in iOS has opened an opportunity for others to potentially exploit them against desktop users.

In an ideal world, Apple would have patched its mobile and desktop operating systems at the same time.

What we don’t know is whether Apple didn’t know the vulnerability was also present in OS X when it issued the iOS fixes, or whether it made the difficult decision to urgently update iOS even though its equivalent OS X fixes weren’t yet ready.

Continue reading Mac users vulnerable to state-sponsored Trident attack, fixed in iOS last week. Patch now→

‘Identity and access management solution without compromise’ is compromised

OneLogin describes itself as the “identity and access management (IAM) solution without compromise.”
Which means it must be OneLogin’s very worst nightmare to discover that it has itself been compromised.
It appears that a hacker was able to view “Secu… Continue reading ‘Identity and access management solution without compromise’ is compromised→