Skip to content

PossibleThreat Articles

Articles for the experts…

  • Security
    • Sophos
    • MalwareBytes
    • TrendMicro
    • Microsoft
    • Fortinet
  • Sciences
  • Independent
    • Krebs
    • Wired
    • Securiteam
    • ComputerWorld

Cryptography

Security Sophos 

Popular JWT cloud security library patches “remote” code execution hole

January 10, 2023 0 Comments Cryptography, json, jsonwebtoken, jwt, rce, vulnerability

Credit to Author: Paul Ducklin| Date: Tue, 10 Jan 2023 17:59:26 +0000

It’s remotely triggerable, but attackers would already have pretty deep network access if they could “prime” your server for compromise.

Read more
Security Sophos 

RSA crypto cracked? Or perhaps not!

January 6, 2023 0 Comments Crypto, Cryptography

Credit to Author: Paul Ducklin| Date: Fri, 06 Jan 2023 17:59:18 +0000

Stand down from blue alert, it seems… but why not plan your cryptographic agility anyway?

Read more
Security Sophos 

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]

January 5, 2023 0 Comments Cryptography, lastpass, Naked Security Podcast, Podcast, pytorch

Credit to Author: Paul Ducklin| Date: Thu, 05 Jan 2023 17:52:39 +0000

Lots of big issues this week: breaches, encryption, supply chains and patching problems. Listen now! (Full transcript inside.)

Read more
Security Sophos 

Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

January 5, 2023 0 Comments Cryptography, Cybercrime, data loss, Linux, Machine Learning, malware, Podcast, security leadership, vulnerability

Credit to Author: Paul Ducklin| Date: Wed, 04 Jan 2023 19:50:54 +0000

Lessons for us all: improve cryptography, fight cybercrime, own your supply chain… and don’t steal my data and then pretend you’re sorry.

Read more
Security Sophos 

Serious Security: Vital cybersecurity lessons from the holiday season

January 4, 2023 0 Comments Cryptography, Cybercrime, data loss, Linux, Machine Learning, malware, Podcast, security leadership, vulnerability

Credit to Author: Paul Ducklin| Date: Wed, 04 Jan 2023 17:50:54 +0000

Lessons for us all: improve cryptography, fight cybercrime, own your supply chain… and don’t steal my data and then pretend you’re sorry.

Read more
Security Sophos 

US passes the Quantum Computing Cybersecurity Preparedness Act – and why not?

December 29, 2022 0 Comments congress, Cryptography, grover, pqc, quantum, Quantum Computing, shor

Credit to Author: Paul Ducklin| Date: Thu, 29 Dec 2022 13:45:11 +0000

Cryptographic agility: the ability and the willingness to change quickly when needed.

Read more
Security Sophos 

Serious Security: MD5 considered harmful – to the tune of $600,000

November 30, 2022 0 Comments cnil, Cryptography, edf, hashing, Law & order, MD5, pbkdf2

Credit to Author: Paul Ducklin| Date: Wed, 30 Nov 2022 17:58:49 +0000

It’s not just the hashing, by the way. It’s the salting and the stretching, too!

Read more
Security Sophos 

The OpenSSL security update story – how can you tell what needs fixing?

November 2, 2022 0 Comments Cryptography, cve-2022-3602, cve-2022-378, OpenSSL, vulnerability

Credit to Author: Paul Ducklin| Date: Thu, 03 Nov 2022 00:44:19 +0000

How to Hack! Finding OpenSSL library files and accurately identifying their version numbers…

Read more
Security Sophos 

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!

November 1, 2022 0 Comments Cryptography, cve-2022-3602, cve-2022-3786, OpenSSL, vulnerability, vulneravility

Credit to Author: Paul Ducklin| Date: Tue, 01 Nov 2022 17:24:07 +0000

That bated-breath OpenSSL update is out! It’s no longer rated CRITICAL, but we advise you to patch ASAP anyway. Here’s why…

Read more
Security Sophos 

SHA-3 code execution bug patched in PHP – check your version!

November 1, 2022 0 Comments cryptograhpy, Cryptography, cve-2022-37454, php, sha-3, vulnerability

Credit to Author: Paul Ducklin| Date: Tue, 01 Nov 2022 14:09:10 +0000

As everyone waits for news of a bug in OpenSSL, here’s a reminder that other cryptographic code in your life may also need patching!

Read more
  • ← Previous
  • Next →

Recent Posts

  • RFK Jr. Orders HHS to Give Undocumented Migrants’ Medicaid Data to DHS
  • ‘No Kings’ Protests, Citizen-Run ICE Trackers Trigger Intelligence Warnings
  • CBP’s Predator Drone Flights Over LA Are a Dangerous Escalation
  • Here’s What Marines and the National Guard Can (and Can’t) Do at LA Protests
  • How to Protest Safely in the Age of Surveillance

Recent Comments

    Archives

    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • March 2020
    • February 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019

    Categories

    • BitCoin
    • Blokt
    • ComputerWorld
    • Currency
    • Digital
    • Fortinet
    • Independent
    • Krebs
    • MalwareBytes
    • Microsoft
    • News
    • QuickHeal
    • Science
    • Securiteam
    • Security
    • Sophos
    • Technology
    • TrendMicro
    • Wired
    Copyright © 2025 PossibleThreat Articles. All rights reserved.
    Theme: ColorMag by ThemeGrill. Powered by WordPress.