FreshRSS

๐Ÿ”’
โŒ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Ever suspected bankers could just use WhatsApp comms? $1.8b says you're right

Thought shadow IT at your office was bad? Try enforcing workplace device policies on hedge fund traders

Updated Ever given a colleague a quick Signal call so you can sidestep a monitored workplace app? Well, we'd hope you're not in a highly regulated industry like staff at eleven of the world's most powerful financial firms, who yesterday were fined nearly $2 billion for off-channel comms.โ€ฆ

  • September 28th 2022 at 13:00

Here's how crooks will use deepfakes to scam your biz

Need some tools of deception? GitHub's got 'em

All of the materials and tools needed to make deepfake videos โ€“ from source code to publicly available images and account authentication bypass services โ€“ are readily available and up for sale on the public internet and underground forums.ย โ€ฆ

  • September 28th 2022 at 07:24

Australia asks FBI to help find attacker who stole data from millions of users

Apparent perp claims to have deleted swiped info as carrier Optus struggles to get its story straight

+Comment Australian authorities have asked the United States Federal Bureau of Investigation (FBI) to assist with investigations into the data breach at local telco Optus.โ€ฆ

  • September 28th 2022 at 03:35

A question of identity

How Incode creates trust by keeping data private and secure

Video There's no getting away from it, identity is key - the prima materia for creating security and trust in your multi-cloud universe.โ€ฆ

  • September 28th 2022 at 03:09

Sophos fixes critical firewall hole exploited by miscreants

Code-injection bug in your network security... mmm, yum yum

A critical code-injection vulnerability in Sophos Firewall has been fixed โ€”ย but not before miscreants found and exploited the bug.โ€ฆ

  • September 28th 2022 at 00:35

Samsung sued for gobbling up too much personal info that miscreants then stole

If you're gonna force everyone to register an account, at least protect that data, lawsuit argues

A lawsuit has accused Samsung of failing to address a cyber-intrusion in early 2022, leading to the theft of US customers' personally identifiable information (PII) in a second attack months later in July.โ€ฆ

  • September 27th 2022 at 18:15

Meta busts first Chinese campaign prodding US midterms

Russian cybercriminals were also caught targeting Europe with anti-Ukraine messages

Meta says it has disrupted a misinformation network targeting US political discourse ahead of the 2022 midterm elections โ€“ and one that sought to influence public opinion in Europe about the conflict in Ukraine.โ€ฆ

  • September 27th 2022 at 15:00

Microsoft says it's boosted phishing protection in Windows 11 22H2

Security tool warns admins, users when a password is used on an untrusted site or stored locally

In the latest version of Windows 11, namely 22H2, Microsoft has introduced a feature in its Defender SmartScreen tool designed to, hopefully, keep passwords safer.โ€ฆ

  • September 27th 2022 at 14:00

What's Microsoft been up to? A quick tour of Windows 11 22H2's security features

And some requirements to be aware of

In brief As it rolled out a laundry list of features in the latest version of Windows 11, namely version 22H2, this month, Microsoft has also detailed some of the added security mechanisms.โ€ฆ

  • September 27th 2022 at 11:32

China's infosec researchers obeyed Beijing and stopped reporting vulns ... or did they?

Report finds increase in anonymous vuln reports

The number of vulnerability reports provided by Chinese information security researchers has fallen sharply, according to research by think tank The Atlantic Council, which also found a strangely commensurate increase in bug reports from unknown sources.โ€ฆ

  • September 27th 2022 at 06:58

Ukraine fears 'massive' Russian cyberattacks on power, infrastructure

Will those be before or after the nuke strikes Putin keeps banging on about?

Russia plans to conduct "massive cyberattacks" on Ukraine and its allies' critical infrastructure and energy sector, according to Kyiv.โ€ฆ

  • September 27th 2022 at 00:03

SQL Server admins warned about Fargo ransomware

From a city in North Dakota with a crime problem to file-scrambling nasty

Organizations are being warned about a wave of attacks targeting Microsoft SQL Server with ransomware known as Fargo, which encrypts files and threatens victims that their data may be published online if they do not pay up.โ€ฆ

  • September 26th 2022 at 16:00

India seeks verified IDs to register email accounts

PLUS: Warnings on Chinese payment schemes; AWS brushes up its Cantonese; Hong Kong ponders digital dollar; and more!

Asia In Brief India's government last week released a draft telco law that defines all over-the-top services as telecoms providers and therefore makes them subject to the same regulations imposed on carriers.โ€ฆ

  • September 26th 2022 at 01:20

How do you run rings around ransomware?

Build data resilience in the cloud first

Webinar It's critical to protect data from infection or exposure to ransomware. The risks are all too clear and the consequences of inattention, weak foundations, and lack of strategic preparation can be catastrophic.โ€ฆ

  • September 26th 2022 at 13:29

An expert guide to securing APIs

How Web Application and API Protection (WAAP) can help you sleep at night

Webinar The application programming interface (API) has been around pretty much as long as computing itself, but it's perhaps only since the early years of the millennium that its use exploded with a mass shift to web applications.โ€ฆ

  • September 26th 2022 at 09:50

Noberus ransomware gets info-stealing upgrades, targets Veeam backup software

'One of the most dangerous and active malware developers operating at the moment'

Crooks spreading the Noberus ransomware are adding weapons to their malware to steal data and credentials from compromised networks.โ€ฆ

  • September 25th 2022 at 08:50

Open up, it's the IRS. We're here about the crypto tax you dodged

'At least ten' people didn't declare coin income. Wow, what a bust

The IRS has been granted a court order to collect records from a bank the agency said will help it identify US taxpayers who failed to report taxable income from crypto trades.ย โ€ฆ

  • September 23rd 2022 at 19:25

Significant customer data exposed in attack on Australian telco

Subscribers have questions โ€“ like 'When were you going to tell us?'

Updated Australian telecommunications company Optus has fallen victim to a significant cyberattack and data breach.โ€ฆ

  • September 23rd 2022 at 17:29

Iran blocks Whatsapp, Instagram as citizens protest death of Mahsa Amini

Also: New 'magnet of threats' attackers and FBI has details on Iran's online incursion into Albania

Iran is experiencing a near-total internet service disruption in the west and intermittent interruptions nationwide, with access to Instagram, Whatsapp and some mobile networks being blocked, says Netblocks.โ€ฆ

  • September 23rd 2022 at 15:24

Keeping secrets safe off prem

Harness the power of hardware with Confidential Computing in the cloud

Webinar Keeping data confidential in a cloud environment requires the highest possible privacy levels. It's only then that your most sensitive workloads can survive the burgeoning risks to data security that every organisation faces.โ€ฆ

  • September 23rd 2022 at 09:08

Privacy watchdog steps up fight against Europol's hoarding of personal data

If you could stop storing records on people unconnected to any crimes, that would be great

An EU watchdog says rules that allow Europol cops to retain personal data on individuals with no links to criminal activity go against Europe's own data privacy protections, not to mention undermining the regulator's powers and role.โ€ฆ

  • September 23rd 2022 at 06:27

Check out this Android spyware, says Microsoft, the home of a gazillion Windows flaws

While issuing an emergency patch for Endpoint Configuration Manager

Data-stealing spyware disguised as a banking rewards app is targeting Android users, Microsoft's security team has warned.โ€ฆ

  • September 22nd 2022 at 20:15

Cambodian authorities crack down on cyber slavery amid international pressure

Lured by fake jobs, victims are isolated abroad and forced to carry out crypto and romance scams, and more

Authorities in Sihanoukville, Cambodia announced on Sunday that a raid last week uncovered evidence of forced labor cybercrime syndicates that participated in human trafficking and torture.โ€ฆ

  • September 22nd 2022 at 15:15

Fake sites fool Zoom users into downloading deadly code

Ah, the human touch

Beware the Zoom site you don't recognize, as a criminal gang is creating multiple fake versions aimed at luring users to download malware that can steal banking data, IP addresses, and other information.โ€ฆ

  • September 22nd 2022 at 13:45

Alert: 15-year-old Python tarfile flaw lurks in 'over 350,000' code projects

Oh cool, a 5,500-day security hole

At least 350,000 open source projects are believed to be potentially vulnerable to exploitation via a Python module flaw that has remained unfixed for 15 years.โ€ฆ

  • September 22nd 2022 at 01:16

San Francisco cops can use private cameras to live-monitor 'significant events'

All eyes on you, and you, and you

San Francisco police are now set to use non-city-owned video cameras for real-time surveillance under a rule approved by the Board of Supervisors.โ€ฆ

  • September 21st 2022 at 23:52

Malwarebytes blocks Google, YouTube as malware

Sounds like fair comment

Updated Google and its Youtube domains are being flagged as malicious by Malwarebytes as of Wednesday morning, blocking users from accessing a whole range of websites.โ€ฆ

  • September 21st 2022 at 15:56

'I Don't Care About Cookies' extension sold to Avast

Users of cookie-warning-buster add-on already forking off due to privacy concerns

The lone developer of anti-cookie-warning browser add-on "I Don't Care About Cookies" has sold it to Avast, resulting in both concern โ€“ and new forks.โ€ฆ

  • September 21st 2022 at 14:15

WAAP it out for application security

APIs are everywhere, and WAAP can help you protect them

Webinar The latest Data Breach Investigations Report (DBIR) states that applications are the 'main attack vector,' responsible for over 80 percent of breaches. Hardly welcome news since APIs are in use everywhere and have direct access to data in a way which web applications do not.โ€ฆ

  • September 21st 2022 at 10:11

ChromeLoader, what took you so long? Malvertising irritant now slings ransomware

Doesn't make cents, makes bigger bucks instead ... probably

ChromeLoader โ€“ the malware that exploded onto the scene this year by hijacking browsers to redirect users to pages of ads โ€“ is apparently evolving into a more significant threat by deploying malicious payloads that go beyond malvertising.โ€ฆ

  • September 21st 2022 at 09:26

Look who's fallen foul of Europe's data retention rules. France and Germany

'Indiscriminate' preemptive harvesting of personal info a big no-no. What a novel concept

On Tuesday, the European Court of Justice (ECJ) issued rulings that limit indiscriminate data retention in France and Germany.โ€ฆ

  • September 21st 2022 at 06:32

USA adds two more Chinese carriers to 'probably a national security threat' list

Pacific Network Corp and China Unicom join the likes of Huawei, Hytera, Hikvision on list of dangerous suppliers

The US Federal Communications Commission (FCC) has added two Chinese companies to its list of communications equipment suppliers rated a threat to national security: Pacific Network Corp, its wholly owned subsidiary ComNet (USA) LLC, and China Unicom (Americas).โ€ฆ

  • September 21st 2022 at 04:58

Crypto biz Wintermute loses $160m in cyber-heist, tells us not to stress out

The other Tessier-Ashpool AIs are surely disappointed

Cryptocurrency market maker Wintermute says $160 million in digital assets have been stolen from it in a cyber-heist, though it assures customers that everything's fine.โ€ฆ

  • September 20th 2022 at 21:35

Meta, Twitter, Apple, Google urged to up encryption game in post-Roe America

Tech giants 'throwing their users to the wolves'

Facebook, Twitter, Google, Apple, and others today faced renewed pressure to protect the privacy of messaging app users seeking healthcare treatment.โ€ฆ

  • September 20th 2022 at 19:19

Uber explains how it was pwned this month, points finger at Lapsus$ gang

From annoying MFA alerts to 'several internal systems' infiltrated

Uber, four days after suffering a substantial cybersecurity breach, has admitted its attacker accessed "several internal systems" including the corporation's G Suite account, and downloaded internal Slack messages and a tool used by its finance department to manage "some" invoices.โ€ฆ

  • September 19th 2022 at 22:54

Been hit by LockerGoga ransomware? A free fix is now out

Software nasty used to cause hundreds of millions of dollars in damages, cops say

If you've been hit by the LockerGoga ransomware, an international law enforcement effort has publicly released a tool to fix the problem.โ€ฆ

  • September 19th 2022 at 20:07

Grand Theft Auto 6 maker confirms source code, vids stolen in cyber-heist

So is that three or four stars?

Take-Two Interactive confirmed on Monday that its Rockstar Games subsidiary has been compromised and confidential data for Grand Theft Auto 6 has been stolen.โ€ฆ

  • September 19th 2022 at 17:12

GPT-3 'prompt injection' attack causes bad bot manners

Also, EA goes kernel-deep to stop cheaters, PuTTY gets hijacked by North Korea, and more.

In Brief OpenAI's popular natural language model GPT-3 has a problem: It can be tricked into behaving badly by doing little more than telling it to ignore its previous orders.โ€ฆ

  • September 19th 2022 at 13:37

Indonesia accuses Google of abusing monopoly

PLUS: Qualys CEO says APAC has infosec advantages; Singapore's Sea ebbs in Americas; Toshiba's tepid takeover update; and more

Asia In Brief Indonesia's competition regulator, the Komisi Pengawas Persaingan Usaha (KPPU) has alleged that Google has violated local anti-monopoly laws by abusing its dominant position for the distribution of apps and its requirement that developers must use its payment systems.โ€ฆ

  • September 19th 2022 at 00:58

Can reflections in eyeglasses actually leak info from Zoom calls? Here's a study into it

About time someone shone some light onto this

Boffins at the University of Michigan in the US and Zhejiang University in China want to highlight how bespectacled video conferencing participants are inadvertently revealing sensitive on-screen information via reflections in their eyeglasses.โ€ฆ

  • September 17th 2022 at 07:32

School chat app Seesaw abused to send 'inappropriate image' to parents, teachers

This is why we don't reuse passwords, kids

Parents and teachers received a link to an "inappropriate image" this week via Seesaw after miscreants hijacked accounts in a credential stuffing attack against the popular school messaging app.โ€ฆ

  • September 16th 2022 at 21:45

Turbo boost your career in cyber security

Access free SANS course demos to find out just how much you can learn

Sponsored Post Few segments of the IT industry change as quickly, or as often, as cyber security. But the perpetual, fast evolving battle to outwit the hackers presents a real challenge for security professionals tasked with protecting mission critical data, applications and services from disruption and theft.โ€ฆ

  • September 16th 2022 at 09:30

Eastern European org hit by second record-smashing DDoS attack

Cough, cough, U, cough, kraine

Akamai says it has absorbed the largest-ever publicly known distributed denial of service (DDoS) attack โ€“ an assault against an unfortunate Eastern European organization that went beyond 700 million packets per second.โ€ฆ

  • September 16th 2022 at 06:04

China can destroy US space assets, Space Force ops nominee warns

Wants swarms of small satellites that are harder to destroy โ€“ and outsourcing to improve cybersecurity

The Biden-nominated chief of space operations for the USA's Space Force (USSF) rates China his greatest challenge, as the Middle Kingdom has developed technologies to destroy space assets.โ€ฆ

  • September 16th 2022 at 03:59

Uber reels from 'security incident' in which cloud systems seemingly hijacked

AWS and G Suite admin accounts likely popped, HackerOne bug bounty page hit, and more

Updated Uber is tonight reeling from what looks like a substantial cybersecurity breach.โ€ฆ

  • September 16th 2022 at 03:13

Ex-Broadcom engineer asks for house arrest over IP theft

Admits guilt, but claims he took files to jog his memory, afraid he'd not keep up with 'younger engineers'

Updated A former Broadcom engineer who pleaded guilty to stealing his ex-employer's trade secrets has asked the court not to give him prison time, saying he stole the files for reference, fearing he would "be unable to keep up" with "more technical and younger engineers" at a new startup.โ€ฆ

  • September 15th 2022 at 15:15

Building the barricades against identity-based attacks

Join our webinar to hear more about the value of Zero Trust unified identity protection platforms

Webinar The first six months of this year have been characterized by relentless cyber security attacks whether state-induced (Russia's attacks on Ukraine), or incidents of criminal extortion and data theft. In such a threatening environment it is vital that organizations and enterprises defend themselves from internet and identity-based attacks.โ€ฆ

  • September 15th 2022 at 13:42

Iran steps up its cybercrime game and Uncle Sam punches back

Criminal charges, more sanctions, and a $10m bounty, oh my

The US has issued indictments against three Iranians linked to the country's Islamic Revolutionary Guard Corps (IRGC) for their alleged roles in plotting ransomware attacks against American critical infrastructure, and also sanctioned multiple individuals and two entities.โ€ฆ

  • September 15th 2022 at 12:30

WordPress-powered sites backdoored after FishPig suffers supply chain attack

And two other security snafus in this web publishing world

It's only been a week or so, and obviously there are at least three critical holes in WordPress plugins and tools that are being exploited in the wild right now to compromise loads of websites.โ€ฆ

  • September 15th 2022 at 02:12

White House to tech world: Promise you'll write secure code โ€“ or Feds won't use it

Developers, why not simply build flawless software, thus solving all our vulnerability worries

The White House has published software security rules for federal agencies as part of a larger push to shore up America's IT supply chains.โ€ฆ

  • September 14th 2022 at 21:24

Nearly one in two industry pros scaled back open source use over security fears

Log4j being the main driver, this data science poll claims

About 40 percent of industry professionals say their organizations have reduced their usage of open source software due to concerns about security, according to a survey conducted by data science firm Anaconda.โ€ฆ

  • September 14th 2022 at 19:29

Google and Meta fined over $70m for privacy violations in Korea

Both search giant and Facebook parent claim they play by the rules, will challenge decision

South Korea's Personal Information Protection Commission (PIPC) has issued two large fines for privacy violations: a $50 million penalty for Google and $22 million for Meta.โ€ฆ

  • September 14th 2022 at 10:25

Ransomware gang threatens 1m-plus medical record leak

Criminals continue to target some of the most vulnerable

Two recent ransomware attacks against healthcare systems indicate cybercriminals continue to put medical clinics and hospitals firmly in their crosshairs.โ€ฆ

  • September 14th 2022 at 00:57

Twitter whistleblower Zatko disses bird site as dysfunctional data dump

Mudge tells senators his former bosses are 'terrified' of the French, US regulators are toothless

Twitter's former head of security Peiter "Mudge" Zatko on Tuesday told the US Senate Judiciary Committee that the social media company's lax data handling and inability to present problems to its board of directors threaten the privacy, security, and democracy for Americans.โ€ฆ

  • September 14th 2022 at 00:11

Microsoft fixes Windows security hole likely widely exploited by miscreants

Plus: Nasty no-auth RCE in TCP/IP stack, Adobe flaws, and many more updates

Patch Tuesday September's Patch Tuesday is here and it brings, among other things, fixes from Microsoft for one security bug that miscreants have used to fully take over Windows systems along with details of a second vulnerability that, while not yet under attack, has already been publicly disclosed.โ€ฆ

  • September 13th 2022 at 22:50

Patch your Mitel VoIP systems, Lorenz ransomware gang is back on the prowl

Criminals do love that unpatched VoIP and IoT kit

The Lorenz ransomware gang is exploiting a vulnerability in Mitel VoIP appliances to break corporate networks.โ€ฆ

  • September 13th 2022 at 18:38

How to get inside the mind of hackers

Spanish speaking SANS experts can help the LATAM cyber community detect and respond to attacks

Sponsored Post No matter how hard organizations in Latin America try to stop malicious attackers from infiltrating their IT systems, breaches are inevitable โ€“ as recent events demonstrate.ย โ€ฆ

  • September 13th 2022 at 15:12

Musk seeks yet another excuse to get out of Twitter buyout: This time it's Mudge's severance check

If at first you don't succeed...

Elon Musk has come up with a new reason to get out of his acquisition of Twitter - a severance payment.โ€ฆ

  • September 13th 2022 at 00:03

One month after Black Hat disclosure, HP's enterprise kit still unpatched

What could go wrong with leaving firmware open after world's biggest hacker convention talk?

Multiple high-severity firmware bugs in HP's business computers remain unpatched, some more than a year after Binarly security researchers disclosed the vulnerabilities to HP and then discussed them at the Black Hat security conference last month.โ€ฆ

  • September 13th 2022 at 08:30

Cisco: Yes, Yanluowang leaked our data. No, it's not serious

Everything's fine!

The Yanluowang ransomware group behind the May attack on Cisco Systems has publicly leaked the stolen files on the dark web over the weekend, but the networking giant says there's nothing to worry about.โ€ฆ

  • September 13th 2022 at 07:30
โŒ