I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck.
I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.)
I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits.
I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars.
Readers and audiences love my material and enjoy coming back for more,
If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Posts
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
New podcast: AI - ENTERPRISE BEST PRACTICES
Duck (🦆 yes, that is I!) and @d@merveilles.town (David Emerson) of ☀️SolCyber give you a well-informed guide to using AI safely, all in plain English.
Straight talk, good humour, no FUD, and zero hype - this is a short, digestible, and very instructive episode.
Listen now 🔈, or read 📖 a cleanly-edited transcript (curated by me - free of AI guesswork and speculation 😬):
https://solcyber.com/tales-from-the-soc-ai-enterprise-best-practices-s1-ep026/
(More links in the comments for a variety of podcast feeds.)
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Patch Tuesday Mystery! A BitLocker bypass dubbed CVE-2026-50661 was patched in the July 2026 Windows update…
So far, media coverage is just repeating Microsoft’s basic report, which admits this was a zero-day (known and disclosed already) but not exactly which already-disclosed bug it relates to.
CrowdStrike, amongst others, has reasonably wondered whether, although “not confirmed at this time, this CVE may be the patch for [Nightmare Eclipse’s] GreatXML.”
I wrote up this exploit in detail (including how well it worked for him in real-world testing) when it was first disclosed last month.
https://solcyber.com/bitlocker-defender-zero-days-and-bragging-rights-more-ms-nightmares/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
European supermarket chain Lidl is in the news for a data breach.
Reports suggest that that the company has published a breach warning online in NL, BE, and DE - but good luck spotting it if you're just a regular user. (As a challenge, see if you can spot the link to the notification on the main DE site, shown below. Hint: that's not where they published it :-)
Early reports suggest that the breach affects online shoppers (so if you went into a shop and bought items directly off the shelves, whether you paid by cash or card, it sounds as though you're OK), and happened at a third-party service provider with whom a selection of Lidl's data was shared.
According Lidl's official report, the stolen data definitely includes at least name, email address, phone number, birthdate, and customer number.
Lidl's own notification says words to the effect that "at this point," the company is ruling out that passwords, physical addresses, bank details and other payment information were stolen. (For example, in Dutch, the phrase used is "op dit moment"; in French, it is "pour le moment.")
But, as Bleeping Computer suggested earlier today, further investigation might rule it back in, because this is not quite the same as saying "we are already permanently certain that this did not happen."
Watch this space, and if you're a Lidl online customer with a Lidl account, be doubly careful of emails, DMs or other messages that offer to "help" you to secure yourself in the aftermath of this breach.
In particular, don't take any action based on phone numbers, links, download suggestions, or other "advice articles" sent to you, because they could have come from anywhere. Use official links or contact details you obtained well before the breach - from existing invoices, for example, or from printed correspondence.
Remember, too, that search engines and AI agents can be tricked by sponsorship or lured by fake content into recommending bogus links.
Even if those links weren't deliberately crafted by scammers in advance, criminals regularly look out for "hallucinated" links that they can register in the hope of catching out well-meaning internet users, in a type of online treachery known in the jargon by the memorable name of *slopsquatting*.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Bug had 98% CVSS score, but was 100% exploited against Nissan and perhaps 100s more companies…
Explainer and actionable advice by me on the ☀️SolCyber blog:
https://solcyber.com/nissan-staff-hacked-via-oracle-zero-day-bug/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Apple updates arrive, including for phone users (iOS 26.5.2). Apparently no 0-days…
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
TALES FROM THE SOC: Exploits versus Entropy - are the shiniest new threats worse than the disruptive disorder of history? Join me and David Emerson (@d@merveilles.town) for another thoughtfully outspoken but infectiously good-humored episode 😬
Find this awesome ☀️SolCyber podcast on your favorite podcast feed, or listen directly here:
https://tales-from-the-soc.podbean.com/e/exploits-versus-entropy-s1-ep-025/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Join me and co-host David Emerson (@d@merveilles.town) - some strong words in this episode, but it's entertaining, educational, and good-humoured nevertheless!
Please give us a listen, like, boost, comment, subscribe, etc. (And message us if you have any funky topics you think we should cover in future!)
Search TALES FROM THE SOC in your favourite podcast feed, or find a human-curated, readable transcript plus tightly-edited audio on the ☀️SolCyber blog here:
https://solcyber.com/tales-from-the-soc-back-to-basics-s1-ep022/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Online accommodation giant booking dot com has been breached, but seems to be rather coy about it so far.
The business is owned by a multibillion-dollar US company that owns numerous other online accommodation services, but so far only booking dot com seems to have been infiltrated in this attack.
As often happens, the biz has been quick to emphasise what was *not* stolen (financial data, apparently), but doesn’t yet seem to know, or to have said, exactly how many of its many millions of users were affected, or exactly what data *was* stolen.
The BBC reports that the breach “could include” victims’ booking details, names, addresses, emails, phone numbers, plus “anything you may have shared with the accommodation,” which one imagines might cover all sorts of information about children travelling with you, your vehicle, related travel plans and expected arrival times, and more.
Historical data - in other words, bookings already done and dusted - are apparently affected, not merely currently active bookings, but there’s no indication of how far back the breach goes.
Advice on “what to do” is hard to give in cases like this, where the business that has let you down still doesn’t know just how badly or how extensively.
Whatever you do, be careful of crooks who know or guess that you’re a booking dot com customer (and who may sound surprisingly believable through data acquired via this very breach) trying to conduct a follow-up scam, especially if they’re offering to “help” you recover in some way.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
A ‘Janus’ attack! Funky bug-o’-the day is CVE-2026-5704 in the venerable GNU ‘tar’ utility.
Tar is short for “tape archive,” and it’s one of the oldest and most widely-used package download formats around. (When you see files called *.tgz, or *.tbz, or *.txz, those are just tar archives that have subsequently been compressed.)
Each entry in the archive has a name, a list of access permissions and other attributes, a size, and (size) bytes’ worth of data. Some filenames, such as Unix or Windows symbolic links, refer to other files and don’t have any data of their own, so they are supposed to be stored with a size of zero, and zero bytes of data.
Except that GNU tar doesn’t check that archive items that shouldn’t have any data don’t have any data.
And it handles “no-data” objects differently depending on whether you *list* the archive (to see if it has any unwanted stuff in it) or you *extract* it.
When you list the contents, the program just skips over any data attached to any “no-data” files, without warning you about the presence of data that shouldn’t really be there.
But when you extract the archive, the program *doesn’t* skip over the unwanted data - it starts looking for the next archive item right away. So, if the “injected data that shouldn’t be there” has the same format as a regular entry in the archive… the program extracts it!
Those “injected data” files will therefore be hidden from view when you list the archive, yet will automatically be extracted when you unpack the very same archive :-)
If you’re a programmer, make sure you don’t let multiple, inconsistently coded error-checking routines creep into different parts of your project. (Be extra careful if you let some kind of vibe coding tool loose on different parts of a problem at different times!)
PS. The name ‘Janus attack’ comes from the Ancient Roman deity Janus, who was literally two-faced, one on each side of his head.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
A great read for the weekend about navigating the perils of cryptographic complexity!
A low-severity bug just patched in OpenSSL reminds us to be not only mindful of history, but also willing to move with the times.
Entertaining, educational, and in plain English… ahem, by me on the ☀️SolCyber blog:
https://solcyber.com/openssl-bugfix-highlights-post-quantum-crypto-dilemma/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
The latest iPhone bugfixes just arrived (version 26.4.1).
The Apple Security Portal was unmodified when I did the update - which was useless to me, considering the page from which I triggered the update explicitly advised me to look there for the full story :-)
But the portal page had been updated, by the time I had patched and rebooted, to say, “26.4.1 has no CVEs.”
(A CVE is a standardised, unique bug identification number widely used to denote a software flaw that constitutes at least some sort of cybersecurity risk).
You’d think it would be easy enough for Apple to update its portal page *before* updating its update servers (if you get my drift), rather than *after*, but there you go…
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Funky audio science (or great marketing - time will tell :-) as automotive biz Škoda announces a new bicycle bell…
Old becomes new again with a product called “duobell” that aims to defeat the hazard of digital noise-cancelling headphones, using a 100% analogue, battery-free, finger-operated bell much like the one (or your parents, or grandparents) had back in 1979.
Anyone who rides a bicycle as their primary urban transport will know just how futile most bike bells are against distracted pedestrians glued to their phones and cocooned via headphones or earbuds. Shouting LOOK OUT very loudly will pierce most headphone audio-blankets, and the sound envelope of the words seems to transcend any language barrier, but it’s not exactly a friendly or socially respectable approach and can lead to pedestrians freezing rather than moving to safety.
Škoda claims to have perfected a resonator that can produce frequencies low enough to evade digital cancellation (about 750Hz, apparently) without needing something the size and mass of Big Ben, as well as a mechanical system for clanging forth a sort-of random mess of higher frequencies in short bursts that the cancellation algorithms simply can’t keep up with.
The theory is that pedestrians will hear what sounds like a bicycle bell even if they have taken active measures to shut such sounds out.
All in something that’s not much bigger than a traditional bicycle bell. (Think of a traditional circular dome-shaped bell but extruded into a slightly squashed sphere.)
Seems you can’t actually buy one yet, so there’s no chance to do the ultimate peer review of trying it for yourself, but if it works it will be a cool example of an “analogue computer,” albeit one that would probably have been impossible to design and build without advanced digital computers and manufacturing processes :-)
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
RE: @zackwhittaker@mastodon.social
Anyone who has space to say things like "PEBKAC" or "trust in tech because humans are the weakest link" is either a misanthrope or a paid-on-commission cybersecurity salesperson :-)
For example, we still hear advice such as "don't open emails (or view attachments, or click links) from unknown sources" spouted as if it were usable, let alone useful, advice.
Yet many employees are assigned to tasks in which opening attachments from new senders is a vital part of their job - try working in HR and refusing to open resumes sent in apparently good faith. Try working in accounts payable or legal and refusing to look at what might be a formal legal challenge such as a financial lawsuit threat or a DMCA takedown request that requires a response.
Same with advice such as "never read out a 2FA code to anyone over the phone," when some orgs explicitly ask you to do just that to "prove" you have the claimed phone number under your control right now. (I've had SMS codes sent to identify myself *by voice over the phone* from both a bank and a telco. The requests were real, even though the bank's own online ADVICE IN BIG LETTERS was never, ever, to tell SMS codes to anyone.)
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
𝔸𝕞𝕠𝕤 𝕥𝕙𝕖 𝔸𝕣𝕞𝕒𝕕𝕚𝕝𝕝𝕠'𝕤 𝔸𝕝𝕞𝕒𝕟𝕒𝕔: Like many of us, Amos is following NASA's Artemis II mission...
For awesome, community-centered cybersecurity content all year round, join us on the ☀️SolCyber blog:
https://solcyber.com/blog
#AmosArmadillo
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Hasbro, the games company, today made a non-April-Fool’s admission to the SEC that it was breached.
Sites are “undergoing maintenance,” and the biz says that disruption “may continue for several weeks.”
Often, that level of disruption turns out to mean “company-wide ransomware crisis,” but at this point, Hasbro probably only knows what it doesn’t yet know, if you know what I mean.
The company says it spotted the intrusion on 2026-03-28, but that’s not necessarily when the crooks first got in.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
𝔸𝕞𝕠𝕤 𝕥𝕙𝕖 𝔸𝕣𝕞𝕒𝕕𝕚𝕝𝕝𝕠'𝕤 𝔸𝕝𝕞𝕒𝕟𝕒𝕔: Microsoft Excel once had a flight simulator hidden in it! (Until understandable security concerns said, "Probably better not to do that.")
For awesome, community-centred cybersecurity content all year round, join me, Amos, and the team on the ☀️SolCyber blog:
https://solcyber.com/blog
#AmosArmadillo
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Location tracking? Sometimes we can’t opt out, even if we want to; at other times we can’t opt in, even when it might be really useful…
I report on a tragic story that reminds us of the important nuances in managing hazard and risk in privacy and cybersecurity.
On the ☀️SolCyber blog:
https://solcyber.com/location-tracking-there-when-you-dont-want-it-not-there-when-you-need-it/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
FreeBSD Forums and Linux.org (plus others) were hit by a cross-site scripting (XSS) attack, but seem to have caught and patched it before any real harm was done.
Apparently, an outdated “XenForo” installation allowed an attacker to [1] create a new account, [2] submit a first post requiring approval, [3] steal the authentication token of the admin that looked at the new post to review it, [4] sneak in using that stolen token to deface the site.
Both sites have easy-to-find writeups on their home pages, which are worth reading, and say that they quickly took their servers offline, found when the attack started, reverted everything back to that point (a matter of hours), patched, decided that the attack had gone no further than defacement, and brought their forums back up.
New accounts created and genuine posts made during the danger period will presumably be lost, which is annoying but not dramatic.
Seems that no end-user accounts were harmed during the period that the exploit was in play.
So much for passwords, 2FA, MFA, TOTP, passkeys, hardware security authenticators, etc., eh? Bypass the lot by grabbing a “proof of coolness” badge from someone who already went through the whole login process so you don’t have to…
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
The 'TeamPCP' cybergang is all over the media - here's why, and what to do.
I take a look at TeamPCP’s latest string of attacks, how to spot if you’ve been a victim, and how to protect against this sort of software supply-chain criminality in the future. (All written in jargonbusting plain English :-)
By me on the ☀️SolCyber blog:
https://solcyber.com/return-of-the-worm-teampcp-versus-the-supply-chain/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
𝔸𝕞𝕠𝕤 𝕥𝕙𝕖 𝔸𝕣𝕞𝕒𝕕𝕚𝕝𝕝𝕠'𝕤 𝔸𝕝𝕞𝕒𝕟𝕒𝕔: Ever mistyped or misread an obvious word? It's easily done...
Follow me, and Amos's cool Almanac, and lots more community-centered cybersecurity content, on the not-a-sales-schpiel cybersecurity site I write for called the ☀️SolCyber blog:
https://solcyber.com/blog
#AmosArmadillo
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Here’s how the news of a hyperactive cyber gang going by “TeamPCP” broke recently…
This is the Aqua Security/Trivy attack that kicked off global concern about this attack group - a great plain-English writeup that explains just how much data, with immediate real-world value, can be grabbed in a single compromise.
(And watch this space - 🦆 I shall be back over the coming weekend with a follow-up story covering *at least three more attacks by the same group* in recent days, and what you can do to protect yourself.)
Learn why blindly automating everything in your supply chain is a Bad Idea!
On the ☀️SolCyber (@solcybermss@bird.makeup) blog:
https://solcyber.com/what-if-a-cybersecurity-tool-turns-against-you/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Catch me and co-host David Emerson (@d@merveilles.town) of human-friendly cybersecurity outfit ☀️SolCyber (@solcybermss@bird.makeup) in the latest episode of the funky no-sales-schpiel podcast TALES FROM THE SOC…
We have some strong words to say about “Back to Basics,” but we retain our intellectual objectivity and our good humour throughout. And you can trust me on that 😬
Please give us a listen, like, boost, comment, subscribe, etc. (And message us if you have any funky topics you think we should cover in future!)
Human-curated, readable transcript plus tightly-edited audio available here:
https://solcyber.com/tales-from-the-soc-back-to-basics-s1-ep022/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Latest ☀️TALES FROM THE SOC podcast just dropped - join me and co-host David Emerson of SolCyber for S1 Ep022…
Strong opinions and sound advice, all given in plain English with good humor!
Listen in your browser or just search “Tales From The SOC” in your favorite podcast feed:
https://tales-from-the-soc.podbean.com/e/back-to-basics-s1-ep022/
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Here comes another raft of security updates for iPhone users - iOS 26.4 is out (and it’s a chunky 5GB download).
Various new features but lots of security fixes - to WebKit and Safari, in the kernel, in the Wi-Fi stack, in Apple’s own KeyChain subsystem for storing secrets such as passwords…
…and there’s a lock screen bug, too, where locking your phone might not be enough to keep other people out, for example if your phone is briefly unattended but locked.
Siri is, as often happens, the culprit. Please, folks, turn off *everything you can* at the lock screen - notifications, Siri, the works. The more “special case” app features you allow at the lock screen, the less of a “lock” it really is!
No zero-days this time (at least, nothing declared as a known 0-day), but get it while it’s hot. And review those lock screen and notification settings!
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Techies love to invent their own vocabulary, because it sounds distinctive and special. We all get that.
Sometimes, this takes the form of jargon, or acronyms, or initialisms, that just happen to be short and therefore convenient, and everyone is happy. After all, it's much easier to say PIN than "personal identification number," or ECDHM instead of "Diffie Hellman Merkle Key Exchange, but using Elliptic Curve scalar multiplication, also known as point addition, in place of traditional modular exponentiation."
But sometimes these techie-terms are semantically confusing, because techies are often capable of choosing exactly the wrong words, and then resisting all suggestions to change them, arguing that "their meaning is perfectly clear once you learn it," even if the proposed replacement is quite clearly superior in every possible way.
Obvious examples are continuing to use the words "blacklist" and "whitelist," even though the words "blocklist" and "allowlist" are undeniably better. Not only are they usefully self-descriptive (and free of any potentially insulting historical or moral baggage), but also the same length, so that on-screen menus, picklists, and documentation can be updated in moments without affecting the layout.
Another example is the concept of "rotating credentials" after a breach. Where did that nonsense come from? What this means is INVALIDATING existing credentials, and CHANGING THEM to completely new ones that have never been used before.
You might choose to "rotate tyres" on a car or bicycle in order to even out the wear between left and right, or front and rear, and 24/7 businesses may work on a system of "rotating shifts," so that everyone does the same share of day/evening/night hours.
But credentials should never, ever be knowingly "rotated," which unavoidably implies looping in a well-defined order through a fixed list of pre-determined values.
"Rotating credentials" is a ridiculous term, not least because it really means "changing credentials," a phrase that removes the potential for confusion among non-techie readers. It's also the same lexical length, at least in English, so you can't even argue that it might depend on the art department to do a redesign :-)
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
Happy Fourth Tuesday - Firefox 𝟭𝟰𝟵.𝟬 is out, with an all-new, built-in VPN to keep you "anonymous," except that you need to sign into a Mozilla account before you can turn it on 🤷🏽
Lots of security fixes, as you might expect, but nothing Critical, and no zero-days. (An 0-day is a security hole that the crooks found first.)
There's a mix of bug types patched, including: flaws in the just-in-time (JIT) compiler that magically converts some JavaScript source into raw machine code to speed things up; memory mismanagement errors that can probably be triggered by rogue images or media files embedded in innocent-looking pages; and sandbox escapes, which is where JavaScript code that's supposed to have carefully restricted powers is able to access data or perform functions that your current security settings say shouldn't be possible.
Click the 𝘛𝘩𝘳𝘦𝘦 𝘓𝘪𝘯𝘦𝘴 icon at top right (the "hamburger menu button") > 𝘏𝘦𝘭𝘱 > 𝘈𝘣𝘰𝘶𝘵 𝘍𝘪𝘳𝘦𝘧𝘰𝘹 to check your current version and to jump the queue to fetch the new one if you haven't received it yet.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.
I’m Paul Ducklin, but everyone calls me Duck. I’ve been in cybersecurity since the early days of computer viruses, right at the pointy end - reversing, coding, analysing, responding, and supporting the community. (You may know me as one of the names behind the legendary EICAR test file.) I’m an accomplished, award-winning technical writer well-known for explaining even super-complex technical stuff in plain English, from esoteric cryptographic bugs to wacky security exploits. I’m an experienced and entertaining speaker who consistently gets glowing feedback for the quality and impact of my talks, live malware demos, and webinars. Readers and audiences love my material and enjoy coming back for more, If you have any writing, speaking or presenting you’d like me to do for you, or if you’re a journalist looking for informed and eminently quotable content, please get in touch via my ABOUT ME link.