FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

'I Don't Care About Cookies' extension sold to Avast

Users of cookie-warning-buster add-on already forking off due to privacy concerns

The lone developer of anti-cookie-warning browser add-on "I Don't Care About Cookies" has sold it to Avast, resulting in both concern – and new forks.…

  • September 21st 2022 at 14:15

WAAP it out for application security

APIs are everywhere, and WAAP can help you protect them

Webinar The latest Data Breach Investigations Report (DBIR) states that applications are the 'main attack vector,' responsible for over 80 percent of breaches. Hardly welcome news since APIs are in use everywhere and have direct access to data in a way which web applications do not.…

  • September 21st 2022 at 10:11

ChromeLoader, what took you so long? Malvertising irritant now slings ransomware

Doesn't make cents, makes bigger bucks instead ... probably

ChromeLoader – the malware that exploded onto the scene this year by hijacking browsers to redirect users to pages of ads – is apparently evolving into a more significant threat by deploying malicious payloads that go beyond malvertising.…

  • September 21st 2022 at 09:26

Look who's fallen foul of Europe's data retention rules. France and Germany

'Indiscriminate' preemptive harvesting of personal info a big no-no. What a novel concept

On Tuesday, the European Court of Justice (ECJ) issued rulings that limit indiscriminate data retention in France and Germany.…

  • September 21st 2022 at 06:32

USA adds two more Chinese carriers to 'probably a national security threat' list

Pacific Network Corp and China Unicom join the likes of Huawei, Hytera, Hikvision on list of dangerous suppliers

The US Federal Communications Commission (FCC) has added two Chinese companies to its list of communications equipment suppliers rated a threat to national security: Pacific Network Corp, its wholly owned subsidiary ComNet (USA) LLC, and China Unicom (Americas).…

  • September 21st 2022 at 04:58

Crypto biz Wintermute loses $160m in cyber-heist, tells us not to stress out

The other Tessier-Ashpool AIs are surely disappointed

Cryptocurrency market maker Wintermute says $160 million in digital assets have been stolen from it in a cyber-heist, though it assures customers that everything's fine.…

  • September 20th 2022 at 21:35

Meta, Twitter, Apple, Google urged to up encryption game in post-Roe America

Tech giants 'throwing their users to the wolves'

Facebook, Twitter, Google, Apple, and others today faced renewed pressure to protect the privacy of messaging app users seeking healthcare treatment.…

  • September 20th 2022 at 19:19

Uber explains how it was pwned this month, points finger at Lapsus$ gang

From annoying MFA alerts to 'several internal systems' infiltrated

Uber, four days after suffering a substantial cybersecurity breach, has admitted its attacker accessed "several internal systems" including the corporation's G Suite account, and downloaded internal Slack messages and a tool used by its finance department to manage "some" invoices.…

  • September 19th 2022 at 22:54

Been hit by LockerGoga ransomware? A free fix is now out

Software nasty used to cause hundreds of millions of dollars in damages, cops say

If you've been hit by the LockerGoga ransomware, an international law enforcement effort has publicly released a tool to fix the problem.…

  • September 19th 2022 at 20:07

Grand Theft Auto 6 maker confirms source code, vids stolen in cyber-heist

So is that three or four stars?

Take-Two Interactive confirmed on Monday that its Rockstar Games subsidiary has been compromised and confidential data for Grand Theft Auto 6 has been stolen.…

  • September 19th 2022 at 17:12

GPT-3 'prompt injection' attack causes bad bot manners

Also, EA goes kernel-deep to stop cheaters, PuTTY gets hijacked by North Korea, and more.

In Brief OpenAI's popular natural language model GPT-3 has a problem: It can be tricked into behaving badly by doing little more than telling it to ignore its previous orders.…

  • September 19th 2022 at 13:37

Indonesia accuses Google of abusing monopoly

PLUS: Qualys CEO says APAC has infosec advantages; Singapore's Sea ebbs in Americas; Toshiba's tepid takeover update; and more

Asia In Brief Indonesia's competition regulator, the Komisi Pengawas Persaingan Usaha (KPPU) has alleged that Google has violated local anti-monopoly laws by abusing its dominant position for the distribution of apps and its requirement that developers must use its payment systems.…

  • September 19th 2022 at 00:58

Can reflections in eyeglasses actually leak info from Zoom calls? Here's a study into it

About time someone shone some light onto this

Boffins at the University of Michigan in the US and Zhejiang University in China want to highlight how bespectacled video conferencing participants are inadvertently revealing sensitive on-screen information via reflections in their eyeglasses.…

  • September 17th 2022 at 07:32

School chat app Seesaw abused to send 'inappropriate image' to parents, teachers

This is why we don't reuse passwords, kids

Parents and teachers received a link to an "inappropriate image" this week via Seesaw after miscreants hijacked accounts in a credential stuffing attack against the popular school messaging app.…

  • September 16th 2022 at 21:45

Turbo boost your career in cyber security

Access free SANS course demos to find out just how much you can learn

Sponsored Post Few segments of the IT industry change as quickly, or as often, as cyber security. But the perpetual, fast evolving battle to outwit the hackers presents a real challenge for security professionals tasked with protecting mission critical data, applications and services from disruption and theft.…

  • September 16th 2022 at 09:30

Eastern European org hit by second record-smashing DDoS attack

Cough, cough, U, cough, kraine

Akamai says it has absorbed the largest-ever publicly known distributed denial of service (DDoS) attack – an assault against an unfortunate Eastern European organization that went beyond 700 million packets per second.…

  • September 16th 2022 at 06:04

China can destroy US space assets, Space Force ops nominee warns

Wants swarms of small satellites that are harder to destroy – and outsourcing to improve cybersecurity

The Biden-nominated chief of space operations for the USA's Space Force (USSF) rates China his greatest challenge, as the Middle Kingdom has developed technologies to destroy space assets.…

  • September 16th 2022 at 03:59

Uber reels from 'security incident' in which cloud systems seemingly hijacked

AWS and G Suite admin accounts likely popped, HackerOne bug bounty page hit, and more

Updated Uber is tonight reeling from what looks like a substantial cybersecurity breach.…

  • September 16th 2022 at 03:13

Ex-Broadcom engineer asks for house arrest over IP theft

Admits guilt, but claims he took files to jog his memory, afraid he'd not keep up with 'younger engineers'

Updated A former Broadcom engineer who pleaded guilty to stealing his ex-employer's trade secrets has asked the court not to give him prison time, saying he stole the files for reference, fearing he would "be unable to keep up" with "more technical and younger engineers" at a new startup.…

  • September 15th 2022 at 15:15

Building the barricades against identity-based attacks

Join our webinar to hear more about the value of Zero Trust unified identity protection platforms

Webinar The first six months of this year have been characterized by relentless cyber security attacks whether state-induced (Russia's attacks on Ukraine), or incidents of criminal extortion and data theft. In such a threatening environment it is vital that organizations and enterprises defend themselves from internet and identity-based attacks.…

  • September 15th 2022 at 13:42

Iran steps up its cybercrime game and Uncle Sam punches back

Criminal charges, more sanctions, and a $10m bounty, oh my

The US has issued indictments against three Iranians linked to the country's Islamic Revolutionary Guard Corps (IRGC) for their alleged roles in plotting ransomware attacks against American critical infrastructure, and also sanctioned multiple individuals and two entities.…

  • September 15th 2022 at 12:30

WordPress-powered sites backdoored after FishPig suffers supply chain attack

And two other security snafus in this web publishing world

It's only been a week or so, and obviously there are at least three critical holes in WordPress plugins and tools that are being exploited in the wild right now to compromise loads of websites.…

  • September 15th 2022 at 02:12

White House to tech world: Promise you'll write secure code – or Feds won't use it

Developers, why not simply build flawless software, thus solving all our vulnerability worries

The White House has published software security rules for federal agencies as part of a larger push to shore up America's IT supply chains.…

  • September 14th 2022 at 21:24

Nearly one in two industry pros scaled back open source use over security fears

Log4j being the main driver, this data science poll claims

About 40 percent of industry professionals say their organizations have reduced their usage of open source software due to concerns about security, according to a survey conducted by data science firm Anaconda.…

  • September 14th 2022 at 19:29

Google and Meta fined over $70m for privacy violations in Korea

Both search giant and Facebook parent claim they play by the rules, will challenge decision

South Korea's Personal Information Protection Commission (PIPC) has issued two large fines for privacy violations: a $50 million penalty for Google and $22 million for Meta.…

  • September 14th 2022 at 10:25

Ransomware gang threatens 1m-plus medical record leak

Criminals continue to target some of the most vulnerable

Two recent ransomware attacks against healthcare systems indicate cybercriminals continue to put medical clinics and hospitals firmly in their crosshairs.…

  • September 14th 2022 at 00:57

Twitter whistleblower Zatko disses bird site as dysfunctional data dump

Mudge tells senators his former bosses are 'terrified' of the French, US regulators are toothless

Twitter's former head of security Peiter "Mudge" Zatko on Tuesday told the US Senate Judiciary Committee that the social media company's lax data handling and inability to present problems to its board of directors threaten the privacy, security, and democracy for Americans.…

  • September 14th 2022 at 00:11

Microsoft fixes Windows security hole likely widely exploited by miscreants

Plus: Nasty no-auth RCE in TCP/IP stack, Adobe flaws, and many more updates

Patch Tuesday September's Patch Tuesday is here and it brings, among other things, fixes from Microsoft for one security bug that miscreants have used to fully take over Windows systems along with details of a second vulnerability that, while not yet under attack, has already been publicly disclosed.…

  • September 13th 2022 at 22:50

Patch your Mitel VoIP systems, Lorenz ransomware gang is back on the prowl

Criminals do love that unpatched VoIP and IoT kit

The Lorenz ransomware gang is exploiting a vulnerability in Mitel VoIP appliances to break corporate networks.…

  • September 13th 2022 at 18:38

How to get inside the mind of hackers

Spanish speaking SANS experts can help the LATAM cyber community detect and respond to attacks

Sponsored Post No matter how hard organizations in Latin America try to stop malicious attackers from infiltrating their IT systems, breaches are inevitable – as recent events demonstrate. …

  • September 13th 2022 at 15:12

Musk seeks yet another excuse to get out of Twitter buyout: This time it's Mudge's severance check

If at first you don't succeed...

Elon Musk has come up with a new reason to get out of his acquisition of Twitter - a severance payment.…

  • September 13th 2022 at 00:03

One month after Black Hat disclosure, HP's enterprise kit still unpatched

What could go wrong with leaving firmware open after world's biggest hacker convention talk?

Multiple high-severity firmware bugs in HP's business computers remain unpatched, some more than a year after Binarly security researchers disclosed the vulnerabilities to HP and then discussed them at the Black Hat security conference last month.…

  • September 13th 2022 at 08:30

Cisco: Yes, Yanluowang leaked our data. No, it's not serious

Everything's fine!

The Yanluowang ransomware group behind the May attack on Cisco Systems has publicly leaked the stolen files on the dark web over the weekend, but the networking giant says there's nothing to worry about.…

  • September 13th 2022 at 07:30

Chinese-linked cyber crims nab $529 million from Indian nationals

Authorities also bust a shell company scam operation with links to the Middle Kingdom

Chinese scammers have reportedly stolen a whopping $529 million dollars from Indian residents using instant lending apps, lures of part-time jobs, and bogus cryptocurrency trading schemes, according to the cyber crime unit in the state of Uttar Pradesh.…

  • September 13th 2022 at 05:30

Apple patches iPhone and macOS flaws under active attack

High-value targets tend to get hit

Apple has pushed out five security fixes including two vulnerabilities in its iPhones, iPads and Mac operating systems that are already being exploited.…

  • September 12th 2022 at 23:07

Google Cloud closes $5.4b Mandiant acquisition

Now it's really got all eyes on you

Google closed its $5.4 billion Mandiant acquisition today in a move that brings the threat intel and incident response giant under the Google Cloud umbrella. …

  • September 12th 2022 at 18:15

Security pros get ability to manually add incidents to Microsoft Sentinel

*Tappity tappity* Yes the NSA's on the phone. Well maybe the automated log check didn't pick it up yet, Chad!

In an IT world that is increasingly automated, there are still occasions when manual operations are necessary. According to Microsoft, one of these times is when security events are reported to enterprise security operation centers (SOCs).…

  • September 12th 2022 at 16:01

Reducing the risk of ransomware

How to protect data assets with a comprehensive security strategy

Webinar Keeping data secure from ransomware attacks requires dedicated attention to constantly evolving risks. Zero Trust security is one of the many rungs on the IT team's Jacob's Ladder to data asset security heaven. But there are other steps you can take, not least making assured data recovery integral to an organization's cyber security.…

  • September 12th 2022 at 15:34

Boffins build microphone safety kit to detect eavesdroppers

TickTock mic lock won't work on Apple

Scientists from the National University of Singapore and Yonsei University in the Republic of Korea have developed a device for verifying whether your laptop microphone is secretly recording your conversations.…

  • September 12th 2022 at 07:30

Retbleed slugs VM performance by up to 70 percent in kernel 5.19

VMware ran tests and saw some nasty numbers. Performance of next kernel otherwise uncontroversial

VMware engineers have tested the Linux kernel's fix for the Retbleed speculative execution bug, and report it can impact compute performance by a whopping 70 percent.…

  • September 12th 2022 at 01:29

Uncle Sam sanctions Iran's intel agency over Albanian cyberattack

Iranians won't be terrified, but US vendors need to check their customers

The US Treasury Department has issued sanctions against Iran's intelligence agency in response to that country's cyberattack against Albania and other "cyber-enabled activities against the United States and its allies."…

  • September 10th 2022 at 13:00

Shape-shifting cryptominer savages Linux endpoints and IoT

Also, Authorities seize WT1SHOP selling 5.8m sets of PII, The North Face users face tough security hike

In brief AT&T cybersecurity researchers have discovered a sneaky piece of malware targeting Linux endpoints and IoT devices in the hopes of gaining persistent access and turning victims into crypto-mining drones.…

  • September 10th 2022 at 11:00

Data tracking poses a 'national security risk' FTC told

'We're making China's job easier'

The massive amounts of digital data being bought and sold β€” or sometimes freely shared β€” poses a grave national security risk, according to a former US policymaker and diplomat.…

  • September 9th 2022 at 23:19

Feds freeze $30m in cryptocurrency stolen from Axie Infinity

But the North Korean criminals are still over half a billion digicash dollars up

Federal investigators and private companies seized $30 million in cryptocurrency stolen in March by North Korean-linked APT gang Lazarus Group from a video game developer, the latest example of the growing skills of government and cybersecurity experts to track and recover such ill-gotten gains.…

  • September 9th 2022 at 22:08

Meta disbands Responsible Innovation team, spreads it out over Facebook and co

Still unclear: Were members just screaming into a void for the past few years?

Facebook parent Meta has disbanded its Responsible Innovation Team (RIT) that it claimed last year was a central part of efforts to "proactively surface and address potential harms to society in all that we build." …

  • September 9th 2022 at 17:28

US seeks standards dominance, lets Huawei access previously forbidden crypto tech

Beijing thinks standards should include central network controls. Washington does not

The US Commerce Department's Bureau of Industry and Security (BIS) has relaxed restrictions that barred export of some encryption technologies to Huawei, in the name of ensuring the United States is in a better position to negotiate global standards.…

  • September 9th 2022 at 03:58

Dump these small-biz routers, says Cisco, because we won't patch their flawed VPN

Nothing like an authentication bypass for your private IPSec network

Cisco patched three security vulnerabilities in its products this week, and said it will leave unpatched a VPN-hijacking flaw that affects four small business routers.…

  • September 8th 2022 at 23:26

Mandiant β€˜highly confident’ foreign cyberspies will target US midterm elections

It is with a heavy heart that we must announce that the hackers are at it again

Mandiant is "highly confident" that foreign cyberspies will target US election infrastructure, organizations, and individuals in the run-up to the November midterm elections.…

  • September 8th 2022 at 22:18

Google urges open source community to fuzz test code

We'll even get our checkbook out, web giant says

Google's open source security team says OSS-Fuzz, its community fuzzing service, has helped fix more than 8,000 security vulnerabilities and 26,000 other bugs in open source projects since its 2016 debut.…

  • September 8th 2022 at 21:00

Private equity suits at Thoma Bravo pull out of Darktrace acquisition

'Enterprise immune system' sees share price slump

US private equity investor Thoma Bravo has pulled out of its planned takeover of Darktrace, causing shares in the UK cybersecurity company to plummet.…

  • September 8th 2022 at 13:00

Lazarus Group unleashed a MagicRAT to spy on energy providers

Cisco finds custom malware in North Korea's latest cyberespionage effort

The North Korean state-sponsored crime ring Lazarus Group is behind a new cyberespionage campaign with the goal to steal data and trade secrets from energy providers across the US, Canada and Japan, according to Cisco Talos.…

  • September 8th 2022 at 12:00

What’s the secret behind a secure password?

Intelligent, uncompromising software according to Specops

Webinar Passwords are the first line of defense against bad actors gaining illegal access to data, a protective rampart that too often falls to common mistakes and increasingly sophisticated cyberattacks.…

  • September 8th 2022 at 09:30

Halfords slapped on wrist for breaching email marketing laws

Bike and car accessory slinger fined Β£30,000 for hitting send on more than 499k unsolicited emails

Bike and car accessory retailer Halfords has found itself in the wrong lane with Britain’s data watchdog for sending hundreds of thousands of unsolicited marketing emails to members of the public.…

  • September 8th 2022 at 09:27

DoJ charges pair over China-linked attempt to build semi-autonomous crypto haven on nuked Pacific atoll

Yes, that’s a lot to digest: Marshall Islands legislators allegedly bribed to make it possible

About halfway between The Philippines and Hawaii is a place called Rongelap Atoll that’s infamous for having been unintentionally irradiated by nuclear weapons tests conducted by America at nearby Bikini Atoll in 1954.…

  • September 8th 2022 at 05:30

Ransomware protection from the top drawer

Why Zero Trust security needs secure infrastructure, systems, networks, users, and applications

Webinar Statistics suggest that there was a ransomware attack on a company or organization every 11 seconds in 2021, but only 57 percent of the victims successfully retrieved their kidnapped data by using back up. And the 32 percent that paid a ransom only recovered 65 percent of their lost data.…

  • September 7th 2022 at 18:28

US school year opens with reading, writing, and ransomware

FBI warns that Vice Society threat group is ramping up attacks on the education sector

The Vice Society threat group is ramping up ransomware attacks on US school districts just as students around the country return to the classroom, the FBI and other federal agencies are warning.…

  • September 7th 2022 at 18:00

Mandiant links APT42 to Iranian 'terrorist org'

'It's hard to imagine a more dangerous scenario,' Mandiant Intel VP told The Reg

Mandiant has named a new threat group, APT42, that it says functions as the cyberspy arm of Iran's Islamic Revolutionary Guard Corps (IRGC), which has plotted to murder US citizens including former National Security Advisor John Bolton.…

  • September 7th 2022 at 14:00

Cybercriminals target games popular with kids to distribute malware

Kaspersky research finds Minecraft and Roblox have the most malicious files associated with them

With 3 billion players globally, the $200 billion gaming market is an increasingly ripe target for cybercriminals – with the perennially popular Minecraft one of the most targeted lures.…

  • September 7th 2022 at 12:34

As Cybersecurity Week begins, Beijing claims US attacked Uni doing military research

National Security Agency apparently has tools that crack Solaris boxes

China has accused the United States of a savage cyber attack on a university famed for conducting aerospace research and linked to China's military.…

  • September 7th 2022 at 05:15

Pakistan politicians label government cybersecurity team 'incompetent'

MP alleges taxpayer database – which holds personal info on millions – has come under attack

A Pakistani parliamentary committee has labelled its own cybersecurity agency "incompetent".…

  • September 7th 2022 at 02:15
❌