Paul Ducklin (@duckblog) 's Twitter Profile
Paul Ducklin

@duckblog

Duck is a passionate security proselytiser. (That's like an evangelist, but more so!)

ID: 132778684

calendar_today14-04-2010 04:37:34

6,6K Tweet

10,10K Followers

34 Following

Paul Ducklin (@duckblog) 's Twitter Profile Photo

Latest โ˜€๏ธSolCyber Managed Security podcast episode is out: LISTEN ๐Ÿ”ˆ or READ ๐Ÿ“– (full, carefully-edited transcript provided) ๐—ฆ๐Ÿญ ๐—˜๐—ฝ ๐Ÿฌ๐Ÿญ๐Ÿฐ: ๐—ฆ๐—ข๐—– ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ - ๐—›๐—ผ๐˜„ ๐—บ๐˜‚๐—ฐ๐—ต โ€œ๐—ผ๐˜‚๐˜โ€ ๐—ถ๐—ป ๐—ผ๐˜‚๐˜๐˜€๐—ผ๐˜‚๐—ฟ๐—ฐ๐—ฒ? solcyber.com/tales-from-theโ€ฆ

Latest โ˜€๏ธ<a href="/SolCyberMSS/">SolCyber Managed Security</a> podcast episode is out: LISTEN ๐Ÿ”ˆ or READ ๐Ÿ“– (full, carefully-edited transcript provided) ๐—ฆ๐Ÿญ ๐—˜๐—ฝ ๐Ÿฌ๐Ÿญ๐Ÿฐ: ๐—ฆ๐—ข๐—–  ๐—ฅ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ - ๐—›๐—ผ๐˜„ ๐—บ๐˜‚๐—ฐ๐—ต โ€œ๐—ผ๐˜‚๐˜โ€ ๐—ถ๐—ป ๐—ผ๐˜‚๐˜๐˜€๐—ผ๐˜‚๐—ฟ๐—ฐ๐—ฒ?

solcyber.com/tales-from-theโ€ฆ
Paul Ducklin (@duckblog) 's Twitter Profile Photo

Thinking of using a VPN because of new age verification rules? Well, VPNs can be double-edged swords โš”๏ธ. Hereโ€™s a must-read explainer in plain English, and advice on what to do about it. Please like and share: solcyber.com/when-vpns-go-rโ€ฆ

Thinking of using a VPN because of new age verification rules?

Well, VPNs can be double-edged swords โš”๏ธ. 

Hereโ€™s a must-read explainer in plain English, and advice on what to do about it. Please like and share:

solcyber.com/when-vpns-go-rโ€ฆ
Paul Ducklin (@duckblog) 's Twitter Profile Photo

Use an iPhone? Appleโ€™s latest security fixes are out in version 18.6. Possible remote code execution, security bypasses, data leakage - all the usuals. The recent zero-day in Chrome (CVE-2025-6558, a bug in the ANGLE library) turns out to affect Apple too.

Use an iPhone? Appleโ€™s latest security fixes are out in version 18.6. Possible remote code execution, security bypasses, data leakage - all the usuals.

The recent zero-day in Chrome (CVE-2025-6558, a bug in the ANGLE library) turns out to affect Apple too.
Paul Ducklin (@duckblog) 's Twitter Profile Photo

Please read this article before your sense of humour lures you into using this website for real ๐Ÿ˜€๐Ÿค” Look if you must, laugh if you like, but donโ€™t do anything stupid with the IDs it makes! (Would you want to get sued by an MP?) solcyber.com/fake-id-generaโ€ฆ

Paul Ducklin (@duckblog) 's Twitter Profile Photo

LISTEN NOW ๐Ÿ”ˆ(or ๐Ÿ“– the transcript): experts Gabriel Gonzalez of IOActive, Inc and Joe Saunders of RunSafe Security confront automotive hacking, now and in the futureโ€ฆ (Also, an awesome and well-informed host. If I do say so myself ๐Ÿ˜ฌ) runsafesecurity.com/podcast/securiโ€ฆ

Paul Ducklin (@duckblog) 's Twitter Profile Photo

๐Ÿฒ๐Ÿฌ ๐—ฆ๐—ฒ๐—ฐ๐—ผ๐—ป๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†: Rootkit treachery on Linux, LOLBIN style! Learn both attack and defense in just 60 seconds. Hire me to work for you: pducklin.com/about Visit the โ˜€๏ธSolCyber Managed Security blog: solcyber.com/blog

Paul Ducklin (@duckblog) 's Twitter Profile Photo

Chrome 139 has landed with 12 security fixes, including two use-after-frees. Use-after-free bugs are common vehicles for remote code execution, because one part of the program trusts data it shouldnโ€™t. Look for 139.0.7258.66 (or .67 on Win and macOS).

Chrome 139 has landed with 12 security fixes, including two use-after-frees.

Use-after-free bugs are common vehicles for remote code execution, because one part of the program trusts data it shouldnโ€™t.

Look for 139.0.7258.66 (or .67 on Win and macOS).
Paul Ducklin (@duckblog) 's Twitter Profile Photo

๐—”๐—บ๐—ผ๐˜€'๐˜€ ๐—”๐—น๐—บ๐—ฎ๐—ป๐—ฎ๐—ฐ: Rootkits - When cybercriminals come up with tricks to hide their tricks. Find lots more human-friendly, plain-English advice from Amos and the team on the โ˜€SolCyber Managed Security blog: solcyber.com/blog #AtAA #AmosAlmanac

๐—”๐—บ๐—ผ๐˜€'๐˜€ ๐—”๐—น๐—บ๐—ฎ๐—ป๐—ฎ๐—ฐ: Rootkits - When cybercriminals come up with tricks to hide their tricks.

Find lots more human-friendly, plain-English advice from Amos and the team on the โ˜€<a href="/SolCyberMSS/">SolCyber Managed Security</a> blog:
solcyber.com/blog

#AtAA #AmosAlmanac
Paul Ducklin (@duckblog) 's Twitter Profile Photo

OpenSSLโ€™s latest update is out: 3.5.2. None of the bug fixes are tagged as โ€œsecurity fixes,โ€ so no CVEs this time. There is a runtime change if you use โ€œFIPS mode,โ€ so that asymmetric crypto keys are explicitly tested when imported.

OpenSSLโ€™s latest update is out: 3.5.2. None of the bug fixes are tagged as โ€œsecurity fixes,โ€ so no CVEs this time.

There is a runtime change if you use โ€œFIPS mode,โ€ so that asymmetric crypto keys are explicitly tested when imported.
Paul Ducklin (@duckblog) 's Twitter Profile Photo

Firefox just pushed out 141.0.3 to fix a weird bug! โ€œStrict modeโ€ was supposed to block cryptominers but didnโ€™t. Browser-based cryptomining isnโ€™t much of a thing these days, which is probably why the bug went unnoticed. But itโ€™s been fixed now anyway.

Firefox just pushed out 141.0.3 to fix a weird bug! โ€œStrict modeโ€ was supposed to block cryptominers but didnโ€™t. 

Browser-based cryptomining isnโ€™t much of a thing these days, which is probably why the bug went unnoticed. But itโ€™s been fixed now anyway.
Paul Ducklin (@duckblog) 's Twitter Profile Photo

๐—”๐—บ๐—ผ๐˜€'๐˜€ ๐—”๐—น๐—บ๐—ฎ๐—ป๐—ฎ๐—ฐ: Remote Code Execution - the cyber-attacker's favored partner-in-crime. Lots of plain-English advice from Amos and the team on the โ˜€๏ธSolCyber Managed Security blog: solcyber.com/blog #AtAA #AmosAlmanac

๐—”๐—บ๐—ผ๐˜€'๐˜€ ๐—”๐—น๐—บ๐—ฎ๐—ป๐—ฎ๐—ฐ: Remote Code Execution - the cyber-attacker's favored partner-in-crime.

Lots of plain-English advice from Amos and the team on the โ˜€๏ธ<a href="/SolCyberMSS/">SolCyber Managed Security</a> blog:
solcyber.com/blog

#AtAA #AmosAlmanac
Paul Ducklin (@duckblog) 's Twitter Profile Photo

Appleโ€™s latest iOS update just arrived. The security notes say only that 18.6.1 โ€œhas no published CVE entries.โ€ There is โ€œa new Blood Oxygen experience for users in the United States,โ€ whatever *that* meansโ€ฆ Auto-FTP boost? Dial-your-own VO2 Max?

Appleโ€™s latest iOS update just arrived. The security notes say only that 18.6.1 โ€œhas no published CVE entries.โ€

There is โ€œa new Blood Oxygen experience for users in the United States,โ€ whatever *that* meansโ€ฆ Auto-FTP boost? Dial-your-own VO2 Max?