Subj : Sophos Virus News To : All From : Daryl Stout Date : Thu May 19 2022 14:47:09 Here is the latest information from the Naked Security Blog from Sophos. You can go to nakedsecurity.sophos.com to read these. You can also sign up to have these delivered to your email during the week. Be sure that you PRACTICE SAFE HEX -- and that you keep your anti-virus, anti-malware, anti-spyware, and anti-ransomware software up to date. Do NOT open any email attachments, even if they appear to be from someone you know!! Even if you were notified in advance that the file was coming before it arrived, use EXTREME CAUTION when opening attachments, or even clicking on links. If it appears your email has been spoofed, change your access password immediately!! It's best to use 2 unrelated words (the longer, the better), separated by a non-alphabetic character...such as BOAT+TOUCH (please do NOT use this example). While you can't use high ascii characters online, you can use numbers, letters (upper and lower case), and symbols. The use of a Password Manager, such as Dashlane, is STRONGLY RECOMMENDED. That way, you can create a different password for each site you visit, and you don't have to remember them...plus, you can make it a complex password, that's difficult for someone to guess. If they do, they can steal your identity, and make you liable for things like credit card debt, etc. Lastly, if your browser seemingly locks up, telling you to call Microsoft at a certain number, do NOT call the number!! Instead, close your web browser, clear the cache and cookies, do a full virus scan, then restart the browser. You may also want to reboot the computer afterwards. *** S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns [podcast] Latest episode - listen now! *** Pwn2Own hacking schedule released - Windows and Linux are top targets What's better? Disclose early, patch fast? Or dig deep, disclose in full, patch more slowly? *** Apple patches zero-day kernel hole and much more - update now! You'll find fixes for numerous kernel-level code execution holes, including a 0-day vulnerability in many (though not all) versions *** Firefox out-of-band update to 100.0.1 -- just in time for Pwn2Own? A new point-release of Firefox. Not unusual, but the timing of this one is interesting, with Pwn2Own coming up in a few days. *** He cracked passwords for a living -- now he's serving 4 years in prison Crooks don't need a password for every user on your network to break in and wreak havoc. One could be enough. *** --- SBBSecho 3.15-Win32 * Origin: The Thunderbolt BBS - Little Rock, Arkansas (454:1/33) .