Patch Tuesday wrap-up, August 2014: RCE + ASLR bypass + EoP == patch early, patch all!

Patch Tuesday is here again. Paul Ducklin explains how this month’s vulnerabilities can work together for harm, and why *all* the updates matter, not just the ones that ended up with a “critical” or “severe” tag…

SSCC 155 – cybercrime bust, cloud laws, phishing and malware back from extinction [PODCAST]

In this episode, Sophos experts John Shier and Paul Ducklin tackle the week’s interesting security stories. John and Duck get stuck into: a high-profile cybercrime arrest; how mainstream brands help phishers; and why macro malware is making a comeback.

Patch Tuesday wrap-up, July 2014 – Adobe fixes “Rosetta”, plus a new risky file type on Windows…

Patch Tuesday for July 2014 is just behind us in the case of Microsoft and Adobe, and just ahead of us in the case of Oracle. Paul Ducklin tells you what you need to know…

59 vulns in IE, teenager versus Turing, and Twitter gets wormed – 60 Sec Security [VIDEO]

Is 59 vulns in IE some kind of record? Did a computer really pass the Turing Test? Can a network worm ever be a joke? Find out in one minute!

SSCC 151 – Measuring vulns, Apple and Wi-Fi privacy, Android ransomware and more [PODCAST]

It’s our weekly security pocast! Chester Wisniewski and Paul Ducklin dig into the latest security news for lessons we can all learn…

Patch Tuesday wrap-up, May 2014 – Adobe and Microsoft both patch multiple remotable holes

Patch Tuesday updates from both Microsoft and Adobe are out. There aren’t any huge surprises this month, but both companies have critical patches for remote code execution holes…

Monday review – the hot 17 stories of the week

Catch up with everything we’ve written in the last seven days – it’s weekly roundup time.

Microsoft and Adobe have 0-days, AOL breached, and we win an award! 60 Sec Security [VIDEO]

Are two zero-days better than one? What happened to AOL’s user database? And is that another award that Naked Security just won? Find out in 60 Sec Security for 03 May 2014…

That was quick! Microsoft patches the “1776” hole in Internet Explorer

The Internet Explorer zero-day bug that made the headlines a few days ago went by the nerdy name of CVE-2014-1776. The good news? No need to wait until next Patch Tuesday for a fix – Microsoft has issued one already.

SSCC 145 – Zero-days x2, fixing Heartbleed x2, and security-by-design [PODCAST]

An 0-day in IE and an 0-day in Flash; two approaches to fixing OpenSSL after Heartbleed; how to get a free pass to Infosec Europe 2014; and why security happens by design and not by accident! Join Chet and Duck for another podcast in the weekly Chet Chat series…