Exploit

(get it in RSS or Atom)

SSCC 198 - "Fusking"? Did I hear that correctly? [PODCAST]

A week of many patches, Lenovo in the news again, an anti-forensic tool with a misleading name, and the rudely-named "sport" of Fusking.

Listen to our latest straight-talking security podcast...

The VENOM "virtual machine escape" bug - what you need to know

snake-1200

Here's what you need to know about VENOM, the latest security vulnerability to be given a marketing-friendly name.

If you're using any virtual machines, read this to set your mind at rest...

Apple updates Safari on OS X, fixes critical flaws

No sooner had we reported that Microsoft will adopt a "rolling update" model for Windows 10...

...than we received notice of Apple's latest "rolling update" for its Safari browser.

Microsoft Word Intruder - the malware that writes new malware for you

Malware construction kits started in the 1990s as a way of expanding the virus-writing counterculture, but now they are all about money. SophosLabs looks at MWI, the Microsoft Word Intruder...

Bugs in the hospital: how to pwn your own pethidine machine

Feeling short-changed by the nurse in charge of your painkiller quota? Telnet into the drug dispenser!

Paul Ducklin looks at how to avoid this sort of security hole...

SSCC 196 - From Wi-Fi bugs to carder busts [PODCAST]

From bugs to busts, here's the latest episode of our weekly security news podcast - for your listening pleasure.

That's SHUTTING down your PC, not SHOOTING it down! 60 Sec Security [VIDEO]

Ever felt like shooting your PC? This guy did it! (And more news in our weekly one-minute security video.)

Wi-Fi security software chokes on network names, opens potential hole for hackers

wifi-250

The Wi-Fi security software "wpa_supplicant," found in Android amongst many other places, has a potentially hackable security hole...

D-Link router user? Keep your ears and eyes open for the next firmware fixes!

A critical bug that leaves various D-Link routers wide open has apparently been patched...

...except that the patches need patches.

Watch out!

If the "Deep Web" becomes searchable, is it still deep? 60 Sec Security [VIDEO]

Watch the latest episode of our only-takes-a-minute security roundup video!

This week: From old crypto bugs to the latest Windows security holes...

Get into RSA 2015 for free, hear eye-opening talks!

The annual RSA Conference in San Francisco is next week, starting on Monday 20 April 2015.

Get a free expo pass on us...

Update Tuesday, April 2015 - Urgent action needed over Microsoft HTTP bug

We don't usually focus on one vulnerability and say, "Do that first." But this month, we're willing to make an exception.

The Microsoft HTTP stack has a bug that could let attackers straight in with a simple HTTP request...

What a lot of patches! 60 Sec Security [VIDEO]

Watch the latest episode of our weekly fun-but-serious security news video.

It only takes a minute!

Apple fixes loads of security holes in OS X, iOS, Apple TV, Safari

OS X gets a brand new photo application called, er, Photos, but the security fixes are the real reason you want these updates.

Has Uber scored an executive touchdown? 60 Sec Security [VIDEO]

Watch the latest episode of our weekly "news in one minute" security video...

"Probably tired and shagged out after a long squawk" - 60 Sec Security [VIDEO]

Our weekly witty-but-serious video - news you can use, and it only takes a minute.

Enjoy...

SSCC 191 - Live in Ljubljana [PODCAST]

Chester is on the road again, this time to present at a conference in Slovenia.

So this episode of the Chet Chat comes to you from an al fresco café in downtown Ljubljana...

What's that screenshot doing on Facebook? 60 Sec Security [VIDEO]

Facebook, ransomware and updates to updates - all in 60 seconds!

Our weekly video for 21 March 2015...

SSCC 190 - The CeBIT 2015 edition [PODCAST]

sscc-5-years-250

Recorded right on the Sophos booth at the CeBIT show in Hannover, Germany.

Here's the Fifth Anniversary edition of our weekly podcast...enjoy!

Update Tuesday wrap-up, March 2015 - FREAK fixed fast, and lots more from Microsoft

Adobe published no bulletins for March 2015, so this one is all about Microsoft...