FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdaySecurity

Industrial Cellular Routers at Risk: 11 New Vulnerabilities Expose OT Networks

By Ravie Lakshmanan
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose operational technology (OT) networks to external attacks. The findings were presented by Israeli industrial cybersecurity firm OTORIO at the Black Hat Asia 2023 conference last week. "Industrial cellular routers and gateways are essential

New Ransomware Gang RA Group Hits U.S. and South Korean Organizations

By Ravie Lakshmanan
A new ransomware group known asΒ RA GroupΒ has become the latest threat actor to leverage the leaked Babuk ransomware source code to spawn its own locker variant. The cybercriminal gang, which is said to have been operating since at least April 22, 2023, is rapidly expanding its operations, according to cybersecurity firm Cisco Talos. "To date, the group has compromised three organizations in the
  • May 15th 2023 at 11:59

Why High Tech Companies Struggle with SaaS Security

By The Hacker News
It's easy to think high-tech companies have a security advantage over other older, more mature industries. Most are unburdened by 40 years of legacy systems and software. They draw some of the world’s youngest, brightest digital natives to their ranks, all of whom consider cybersecurity issues their entire lives. Perhaps it is due to their familiarity with technology that causes them to overlook
  • May 15th 2023 at 11:25

Researchers Uncover Powerful Backdoor and Custom Implant in Year-Long Cyber Campaign

By Ravie Lakshmanan
Government, aviation, education, and telecom sectors located in South and Southeast Asia have come under the radar of a new hacking group as part of a highly-targeted campaign that commenced in mid-2022 and continued into the first quarter of 2023. Symantec, by Broadcom Software, is tracking the activity under its insect-themed monikerΒ Lancefly, with the attacks making use of a "powerful"
  • May 15th 2023 at 10:17

New 'MichaelKors' Ransomware-as-a-Service Targeting Linux and VMware ESXi Systems

By Ravie Lakshmanan
A new ransomware-as-service (RaaS) operation called MichaelKors has become the latest file-encrypting malware to target Linux andΒ VMware ESXi systemsΒ as of April 2023. The development points to cybercriminal actors increasingly setting their eyes on the ESXi, cybersecurity firm CrowdStrike said in a report shared with The Hacker News. "This trend is especially noteworthy given the fact that ESXi

AI Hacking Games (Jailbreak CTFs)

By /u/phoenixzeu

I just wrote an article on Prompt Injection CTF challenges and open-source LLMs that ca be installed on your personal PC (in case you want a free alternative to OpenAI).

CTFs can be a great way to better understand the limitations of these new AI models that are becoming accessible to anyone and are integrated into more and more apps.

submitted by /u/phoenixzeu
[link] [comments]

An important system on project [REDACTED] was all [REDACTED] up

Luckily, [REDACTED] was there to save the day

Who Me? Welcome once again to the horrors of Monday, dear reader. But fear not – The Register is here to cushion the blow of the working week's resumption with a instalment of Who, Me?, our reader-contributed stories of tech gone awry.…

  • May 15th 2023 at 07:30

CLR SqlShell Malware Targets MS SQL Servers for Crypto Mining and Ransomware

By Ravie Lakshmanan
Poorly managed Microsoft SQL (MS SQL) servers are the target of a new campaign that's designed to propagate a category of malware calledΒ CLR SqlShellΒ that ultimately facilitates the deployment of cryptocurrency miners and ransomware. "Similar to web shell, which can be installed on web servers, SqlShell is a malware strain that supports various features after being installed on an MS SQL server,

Former Ubiquiti Employee Gets 6 Years in Jail for $2 Million Crypto Extortion Case

By Ravie Lakshmanan
A former employee of Ubiquiti has beenΒ sentencedΒ to six years in jail after he pleaded guilty to posing as an anonymous hacker and a whistleblower in an attempt to extort almost $2 million worth of cryptocurrency while working at the company. Nickolas Sharp, 37, was arrested in December 2021 for using his insider access as a senior developer to steal confidential data and sending an anonymous

Ransomware corrupts data, so backups can be faster and cheaper than paying up

Smash and grab raids don’t leave time for careful encryption

Ransomware actors aim to spend the shortest amount of time possible inside your systems, and that means the encryption they employ is shoddy and often corrupts your data. That in turn means restoration after paying ransoms is often a more expensive chore than just deciding not to pay and working from our own backups.…

  • May 15th 2023 at 06:32

The UK’s Secretive Web Surveillance Program Is Ramping Up

By Matt Burgess
A government effort to collect people’s internet records is moving beyond its test phase, but many details remain hidden from public view.

Arm acknowledges side-channel attack but denies Cortex-M is crocked

Spectre-esque exploit figures out when interesting info might be in memory

Black Hat Asia Arm issued a statement last Friday declaring that a successful side attack on its TrustZone-enabled Cortex-M based systems was "not a failure of the protection offered by the architecture."…

  • May 15th 2023 at 05:36

Toyota's bungling of customer privacy is becoming a pattern

Also: 3D printing gun mods = jail time; France fines Clearview AI for ignoring fine; this week's critical vulns, and more

in brief Japanese automaker Toyota has admitted yet again to mishandling customer data – this time saying it exposed information on more than two million Japanese customers for the past decade, thanks to a misconfigured cloud environment. …

  • May 15th 2023 at 02:26

How to Use Google Authenticator

By Reece Rogers
The two-factor authentication tool got some serious upgrades that can help you bolster security for your online accounts.

Weekly Update 347

By Troy Hunt
Weekly Update 347

A late one this week as I cover from the non-stop conferencing that was the Azure user group in Perth, followed by the Cyber West keynote, then the social drinks that night, the flight back home straight into the AusCERT gala dinner, the panel on data governance that morning then wrapping up with the speed debate Friday arvo. I think that's all... Anyway, better later than never and nothing too serious in this week's update. Personally, I'm finding the house works the most fun to talk about so I'm going to hit the publish button on this post now then go back to drafting the blog series on everything we've done 😊

Weekly Update 347
Weekly Update 347
Weekly Update 347
Weekly Update 347

References

  1. The RentoMojo data breach entered circulation and ended up in HIBP (another couple of million accounts right there)
  2. I started a thread with before and after shots of the house works (writing up a much more comprehensive blog series right now...)
  3. This is the story I mentioned about the bloke in Melbourne copping it from the public for craning his McLaren into his apartment (its' "guitar lessons" all over again!)
  4. To the audience question about door locks, I did go back and look again and there's a Yale Assure Lock 2 that supersedes the SL I had an order (still no Apple HomeKey support though πŸ˜”)
  5. Sponsored by: Kolide ensures only secure devices can access your cloud apps. It's Zero Trust tailor-made for Okta. Book a demo today.

Toyota Leaked Vehicle Data of 2 Million Customers

By Dhruv Mehrotra, Andrew Couts
The FBI disables notorious Russia-linked malware, the EU edges toward a facial recognition ban, and security firm Dragos has an intrusion of its own.

New Phishing-as-a-Service Platform Lets Cybercriminals Generate Convincing Phishing Pages

By Ravie Lakshmanan
A new phishing-as-a-service (PhaaS or PaaS) platform namedΒ GreatnessΒ has been leveraged by cybercriminals to target business users of the Microsoft 365 cloud service since at least mid-2022, effectively lowering the bar to entry for phishing attacks. "Greatness, for now, is only focused on Microsoft 365 phishing pages, providing its affiliates with an attachment and link builder that creates

'Top three Balkans drug kingpins' arrested after cops crack their Sky ECC chats

Maybe try carrier pigeons instead

European police arrested three people in Belgrade described as "the biggest" drug lords in the Balkans in what cops are chalking up to another win in dismantling Sky ECC's encrypted messaging app last year.…

  • May 13th 2023 at 07:14

Why Microsoft just patched a patch that squashed an under-attack Outlook bug

Let's take a quick dive into Windows API

Microsoft in March fixed an interesting security hole in Outlook that was exploited by miscreants to leak victims' Windows credentials. This week the IT giant fixed that fix as part of its monthly Patch Tuesday update.…

  • May 12th 2023 at 23:17

XWorm Malware Exploits Follina Vulnerability in New Wave of Attacks

By Ravie Lakshmanan
Cybersecurity researchers have discovered an ongoing phishing campaign that makes use of a unique attack chain to deliver theΒ XWorm malwareΒ on targeted systems. Securonix, which is tracking the activity cluster under the nameΒ MEME#4CHAN, said some of the attacks have primarily targeted manufacturing firms and healthcare clinics located in Germany. "The attack campaign has been leveraging rather

Ex-Ubiquiti dev jailed for 6 years after stealing internal corp data, extorting bosses

Momentary lapse in VPN led to stretch in the cooler, $1.6m bill

Nickolas Sharp has been sentenced to six years in prison and ordered to pay almost $1.6 million to his now-former employer Ubiquiti – after stealing gigabytes of corporate data from the biz and then trying to extort almost $2 million from his bosses while posing as an anonymous hacker.…

  • May 12th 2023 at 20:28

Britain's largest private pension scheme reveals scale of Capita break-in

USS says burgled biz reckons data on 470,000 'active, deferred and retired' members may have been accessed

Universities Superannuation Scheme, the UK’s largest private pension provider, says Capita has warned that details of almost half a million members were held on servers accessed during the recent breach.…

  • May 12th 2023 at 16:59

Key findings from ESET’s new APT Activity Report – Week in security with Tony Anscombe

By Editor

What have some of the world's most infamous advanced threat actors been up to and what might be the implications of their activities for your business?

The post Key findings from ESET’s new APT Activity Report – Week in security with Tony Anscombe appeared first on WeLiveSecurity

  • May 12th 2023 at 15:15

Why you need parental control software – and 5 features to look for

By Phil Muncaster

Strike a balance between making the internet a safer place for your children and giving them the freedom to explore, learn and socialize

The post Why you need parental control software – and 5 features to look for appeared first on WeLiveSecurity

Netgear Routers' Flaws Expose Users to Malware, Remote Attacks, and Surveillance

By Ravie Lakshmanan
As many as five security flaws have been disclosed in Netgear RAX30 routers that could be chained to bypass authentication and achieve remote code execution. "Successful exploits could allow attackers to monitor users' internet activity, hijack internet connections, and redirect traffic to malicious websites or inject malware into network traffic," Claroty security researcher Uri KatzΒ saidΒ in a

New Stealthy Variant of Linux Backdoor BPFDoor Emerges from the Shadows

By Ravie Lakshmanan
A previously undocumented and mostly undetected variant of a Linux backdoor calledΒ BPFDoorΒ has been spotted in the wild, cybersecurity firm Deep Instinct said in a technical report published this week. "BPFDoorΒ retains its reputation as an extremely stealthy and difficult-to-detect malware with this latest iteration," security researchers Shaul Vilkomir-Preisman and Eliran Nissan said. BPFDoor (

Solving Your Teams Secure Collaboration Challenges

By The Hacker News
In today's interconnected world, where organisations regularly exchange sensitive information with customers, partners and employees, secure collaboration has become increasingly vital. However, collaboration can pose a security risk if not managed properly. To ensure that collaboration remains secure, organisations need to take steps to protect their data. Since collaborating is essential for

Activists gatecrash Capita's AGM to protest GPS tracking contract

Outsourcer asked to take 'principled stance'

We hear Privacy International and a few other campaign groups set up camp outside Capita's AGM in London yesterday protesting Capita's involvement as an outsourcer in a UK government GPS tracking contract.…

  • May 12th 2023 at 10:36

Bl00dy Ransomware Gang Strikes Education Sector with Critical PaperCut Vulnerability

By Ravie Lakshmanan
U.S. cybersecurity and intelligence agencies have warned of attacks carried out by a threat actor known as theΒ Bl00dy Ransomware GangΒ that attempt to exploit vulnerable PaperCut servers against the education facilities sector in the country. The attacks took place in early May 2023, the Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) said in a

UK cops score legal win in EncroChat snooping op

But tribunal punts on whether data was intercepted in transit

The UK's National Crime Agency has partially won an important legal battle in a case that challenged the warrants used to obtain messages from cyber crook hangout EncroChat.…

  • May 12th 2023 at 06:08

New Flaw in WordPress Plugin Used by Over a Million Sites Under Active Exploitation

By Ravie Lakshmanan
A security vulnerability has been disclosed in the popular WordPress pluginΒ Essential Addons for ElementorΒ that could be potentially exploited to achieve elevated privileges on affected sites. The issue, tracked as CVE-2023-32243, has been addressed by the plugin maintainers in version 5.7.2 that was shipped on May 11, 2023. Essential Addons for Elementor has over one million active

India to send official whassup to WhatsApp after massive spamstorm

In a weird way, we can blame this on AI being a better bet than blockchain

India's IT minister Rajeev Chandrasekhar will ask WhatsApp to explain what's up, after the Meta-owned messaging service experienced a dramatic increase in spam calls.…

  • May 12th 2023 at 01:57

Let white-hat hackers stick a probe in those voting machines, say senators

HAVA go at breaking electronic ballot box security

US voting machines would undergo deeper examination for computer security holes under proposed bipartisan legislation.…

  • May 11th 2023 at 21:35

Millions of mobile phones come pre-infected with malware, say researchers

The threat is coming from inside the supply chain

Black Hat Asia Miscreants have infected millions of Androids worldwide with malicious firmware before the devices even shipped from their factories, according to Trend Micro researchers at Black Hat Asia.…

  • May 11th 2023 at 17:58

ENISA leans into EU-based clouds with draft cybersecurity label

Time for AWS and pals to start thinking about JVs?

Cloud services providers that aren't based in Europe β€”Β like the Big Three β€” may have to team up with a cloud that is operated and maintained from the EU if they want ENISA's stamp of approval for handling sensitive data.…

  • May 11th 2023 at 12:44

A Republican-Led Lawsuit Threatens Critical US Cyber Protections

By Eric Geller
Three states are suing to block security rules for water facilities. If they win, it may open the floodgates for challenges to other cyber rules.
❌