S3 Ep31: Apple zero-days, Flubot scammers and PHP supply chain bug

Published: May 5, 2021, 10:48 p.m.

We look into Apple's recent emergency updates that closed off four in-the-wild browser bugs. We explain how the infamous "Flubot" home delivery scam works and how to stop it. We investigate a recent security bug that threatened the PHP ecosystem.\n\nhttps://nakedsecurity.sophos.com/apple-products-hit-by-fourfecta-of-zero-day-exploits\nhttps://nakedsecurity.sophos.com/naked-security-live-beware-flubot-the-home-delivery-scam\nhttps://nakedsecurity.sophos.com/php-community-sidesteps-its-third-supply-chain-attack\n \nWith Kimberly Truong, Doug Aamoth and Paul Ducklin.\n\nOriginal music by Edith Mudge (https://www.edithmudge.com)\n\nGot questions/suggestions/stories to share?\nEmail: tips@sophos.com\nTwitter: NakedSecurity (https://twitter.com/nakedsecurity)\nInstagram: NakedSecurity (https://instagram.com/nakedsecurity)