Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Google backpedals on new Android developer registration rules — www.bleepingcomputer.com/… (Android is not becoming quite as Apple-like after all — better for Linux geeks, worse for regular folks) Deep Dive — that Cloudflare Outage […]
Continue readingCategory: Security Bits
Security Bits — 9 November 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. More evidence of the dangers of Agentic Browsers: ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands — thehackernews.com/… Related Article: Be Cautious with Agentic Web Browsers — tidbits.com/… (by […]
Continue readingSecurity Bits — 26 October 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. 🇺🇸 US Court Blocks Spyware Vendor NSO Group from Targeting WhatsApp Users — cyberinsider.com/… (Maybe their recent change to US ownership will give this injunction more teeth!) Update on the Tea app which suffered […]
Continue readingSecurity Bits — 12 October 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Another interesting twist in the NSO Group Saga: Spyware maker NSO Group confirms acquisition by US investors — techcrunch.com/… (via Allison) ❗ Action Alerts Calls to action, if any stories in this section are […]
Continue readingSecurity Bits — 28 September 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. The industry is fighting back against the recent spike in supply-chain attacks targeting shared library platforms like NPM, PyPi, etc.: GitHub tightens npm security with mandatory 2FA, access tokens — www.bleepingcomputer.com/… 🇺🇸 Details are […]
Continue readingSecurity Bits — 14 September 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Some clarity has emerged on the spate of Salesforce-related data breaches mentioned in the previous instalment — krebsonsecurity.com/… & www.bleepingcomputer.com/… The issue was with how the third-party AI chatbot from Salesloft integrated with Salesforce, […]
Continue readingSecurity Bits — 31 August 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. 🇺🇸 The leaked data from the Allianz Life breach discussed last time has been added to Have-I-Been-Pwned, so you can now check if you are affected — www.bleepingcomputer.com/… There have been confusing developments in […]
Continue readingSecurity Bits — 17 August 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. 🎧 More details on the Tea leak discussed last time, with reporting of how many women are continuing to use the app, and including new sigunups 🤯: kill switch: why are women still signing […]
Continue readingSecurity Bits — 1 August 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. 🇬🇧 It looks like the UK is trying to find a face-saving way to back down from it’s secretive attempt to back-door Apple’s iCloud Advanced Data Protection feature — appleinsider.com/… (Nothing official because everything […]
Continue readingSecurity Bits — 20 July 2025
❗ Action Alerts Calls to action, if any stories in this section are relevant to you, there is some action you should take. Microsoft July 2025 Patch Tuesday fixes one zero-day, 137 flaws — www.bleepingcomputer.com/…, krebsonsecurity.com/… & isc.sans.edu/… Most important patches for typical NosillaCastaways are Office zero-click exploits (triggered by previewing a document) Most important […]
Continue reading