FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Husband and wife nuclear warship 'spy' team get 20 years each

The Toebbes tried selling US Navy secrets, but handed them right to the FBI

A woman and her husband, who both copped to trying to sell nuclear warship secrets to a foreign government, have been sentenced to prison, with each set to spend around two decades behind bars.…

  • November 10th 2022 at 17:14

Twitter CISO flies the coop

As social media giant grapples with Musk takeover, a safe pair of hands reaches for the door

Troubled social media giant Twitter has lost the services of its chief information security officer to cap off another chaotic week following its acquisition by Elon Musk.…

  • November 10th 2022 at 16:34

A roadmap to better cyber security training

SANS courses show you what’s useful and NICE

Sponsored Post It's a common problem when it comes to finding a new job or landing that all important promotion. You need to upgrade your CV to show some knowledge and experience of systems, tools and frameworks that your current role doesn't require but the next step up the ladder does. But how do you learn what you need if you're current role focuses on a different set of priorities, or even know what areas of speciality different organisations prize most highly in the first place?…

  • November 10th 2022 at 09:00

Windows breaks under upgraded IceXLoader malware

We're the malware of Nim!

A malware loader deemed in June to be a "work in progress" is now fully functional and infecting thousands of Windows corporate and home PCs.…

  • November 10th 2022 at 04:46

Wells Fargo, Zelle slammed by Liz Warren over rampant online banking fraud

Customers 'more than twice' as likely to be hit by scams, says Dem Senator

Wells Fargo customers who use Zelle to send and request payments suffer more than twice the rate of fraud and other online scams as people using other big banks, according to US Senator Elizabeth Warren (D-MA).…

  • November 9th 2022 at 21:15

VMware warns of three critical holes in remote-control tool

Anyone can pretend to be your Windows IT support and take command of staff devices

VMware has revealed a terrible trio of critical-rated flaws in Workspace ONE Assist for Windows – a product used by IT and help desk staff to remotely take over and manage employees' devices.…

  • November 9th 2022 at 01:16

Microsoft squashes six security bugs already exploited in the wild

Plus: Fixes from Intel, AMD, Citrix and more

Patch Tuesday November's Patch Tuesday also falls on election day in the US, so let's hope that democracy fares better than Microsoft, which reported six of today's bugs are already being exploited in the wild by miscreants.…

  • November 9th 2022 at 00:18

Swiss Re wants government bail out as cybercrime insurance costs spike

Giant forecasts premiums rising to $23b by 2025

As insurance companies struggle to stay afloat amid rising cyber claims, Swiss Re has recommended a public-private partnership insurance scheme with one option being a government-backed fund to help fill the coverage gap.…

  • November 8th 2022 at 20:30

Robin Banks crooks back at the table with fresh phish from Russia

Phishing-as-a-service group's toolset now includes ways to get around MFA

Robin Banks, the phishing-as-a-service (PHaaS) platform that was kicked off Cloudflare for malicious activity, is back in action with a Russian service provider and new tools to make it easier to bypass security measures.…

  • November 8th 2022 at 17:45

Experian, T-Mobile US settle data spills for mere $16m

Two breaches: one in 2012, another in 2015 – saw 18m folks' records stolen

Experian and T-Mobile US have reached separate settlements with 40 states in America following a pair of data security breaches in 2012 and 2015. The settlement will net authorities $16 million, along with assurances it won't happen again.…

  • November 8th 2022 at 17:00

FBI: Russian hacktivists achieve only 'limited' DDoS success

OK, so you've got a botnet. That don't impress me much

Pro-Russia hacktivists' recent spate of network-flooding bot traffic aimed at US critical infrastructure targets, while annoying, have had "limited success," according to the FBI.…

  • November 8th 2022 at 02:31

Feds find Silk Road thief's $1b+ Bitcoin stash in popcorn tin, hidden safe

Uncle Sam follows the money ... all the way to a single-board computer

A crook who stole more than 50,000 Bitcoins from the dark web souk Silk Road in 2012 has pleaded guilty and lost the lot, with a stretch behind bars likely ahead of him. …

  • November 7th 2022 at 22:28

All the US midterm-related lies to expect when you're electing

Don't like the results? The election must have been rigged

Misinformation related to tomorrow's US midterm elections hasn't slowed, according to security researchers. …

  • November 7th 2022 at 21:30

Microsoft hits the switch on password-free smartphone authentication

No more MF phish on this MFA cellphone as Azure AD CBA + YubiKey hits preview

Microsoft is rolling out another way for smartphone and tablet users to protect themselves from phishing attacks as post-pandemic hybrid work pulls more and more workers under bring-your-own-device (BYOD) policies.…

  • November 7th 2022 at 17:30

Oh, look: More malware in the Google Play store

Also, US media hit with JavaScript supply chain attack, while half of govt employees use out-of-date mobile OSes

in brief A quartet of malware-laden Android apps from a single developer have been caught with malicious code more than once, yet the infected apps remain on Google Play and have collectively been downloaded more than one million times. …

  • November 7th 2022 at 15:30

Can confidential computing stop the next crypto heist?

Tech giants and startups hype next big thing in security

Amid the theft of billions of dollars in cryptocurrency over recent months, confidential computing may have a role in protecting people's money in future.…

  • November 7th 2022 at 13:30

Japan officially joins NATO's cyber defense center

Already red-teaming and blue teaming in the international Locked Shields contest every year

Japan’s Ministry of Defence (JMOD) announced on Friday that it has formally joined NATO’s Cooperative Cyber Defense Centre of Excellence (CCDCOE).…

  • November 7th 2022 at 11:32

China is likely stockpiling and deploying vulnerabilities, says Microsoft

Increase in espionage and cyberattacks since law requiring vulnerabilities first be reported to Beijing

Microsoft has asserted that China's offensive cyber capabilities have improved, thanks to a law that has allowed Beijing to create an arsenal of unreported software vulnerabilities.…

  • November 7th 2022 at 07:56

Red Cross seeks digital equivalent of its emblems to mark some tech as off-limits in war

Suggests tweaks to IP semantics as one way to identify protected tech and traffic

The International Committee of the Red Cross (ICRC) wants to devise a digital equivalent of its emblems (the red cross and red crescent), to signify that certain digital resources are protected and must not be targeted during cyberwarfare.…

  • November 7th 2022 at 06:01

Breached health insurer won't pay ransom to protect customers, warns of more attacks

Australia's Medibank uses a government-approved Band-Aid to cover a gaping 10-milion-record wound

Australian health insurer Medibank – which spent October discovering a security incident was worse than it first thought – has announced it will not pay a ransom to attackers that made off with personal info describing nearly ten million customers.…

  • November 7th 2022 at 01:45

SolarWinds reaches $26m settlement with shareholders, expects SEC action

One 8-K filing, two bombshells

SolarWinds has agreed to pay $26 million to settle a shareholder lawsuit, and it's also expecting to be slapped with an enforcement action by Uncle Sam – both related to its infamous 2020 supply chain security fiasco, according to the software maker's most recent US regulatory filing.…

  • November 4th 2022 at 21:59

Double-check demand payment emails from law firms: Convincing fakes surface

Crimson Kingsnake impersonates legit attorneys, fakes email threads from your colleagues in far-reaching BEC campaign

A new threat group called Crimson Kingsnake is impersonating real law companies and debt recovery services to intimidate businessess into paying bogus overdue invoices.…

  • November 4th 2022 at 18:30

French-speaking voleurs stole $30m in 15-country bank, telecoms cyber-heist spree

Smooth 'OPERA1ER' hit orgs around the world over four or more years

A French-speaking criminal group codenamed OPERA1ER has pulled off more than 30 cyber-heists against telecom organizations and banks across Africa, Asia, and Latin America, stealing upwards of $30 million over four years, according to security researchers.…

  • November 4th 2022 at 06:22

Multi-factor auth fatigue is real – and it's why you may be in the headlines next

Overwhelmed by waves of push notifications, worn-down users inadvertently let the bad guys in

Analysis The September cyberattack on ride-hailing service Uber began when a criminal bought the stolen credentials of a company contractor on the dark web.…

  • November 3rd 2022 at 20:45

International summit agrees crack down on crypto to combat ransomware

Commitments include international wallet info sharing, KYC requirements, and an AML crackdown

The White House's second International Counter Ransomware Initiative summit has concluded, and this year the 36-nation group has made clear it intends to crack down on how cryptocurrencies are used to finance ransomware operations.…

  • November 3rd 2022 at 16:45

Royal Mail customer data leak shutters online Click and Drop

Customers complain of exposed order info, multiple charges β€” but still no postage

A technical SNAFU shut down the UK's Royal Mail Click and Drop website on Tuesday after a security "issue" allowed some customers to see others' order information. …

  • November 3rd 2022 at 08:29

US Treasury thwarts DDoS attack from Russian Killnet group

Yet another pathetic 'stunt' from pro-Kremlin criminals

The US Treasury Department has thwarted a distributed denial of service (DDoS) attack that officials attributed to Russian hacktivist group Killnet.…

  • November 2nd 2022 at 20:45

Ransomware cost US banks $1.2 billion last year

Up 188% on 2020 but could be because financial institutions were encouraged to report incidents

Banks in the US paid out nearly $1.2 billion in 2021 as a result of ransomware attacks, a marked rise over the year before though it may simply be due to more financial institutions being asked to report incidents.…

  • November 2nd 2022 at 16:30

Former Apple worker pleads guilty to $17m mail and wire fraud charges

Nefarious schemes included harvesting motherboard components and selling them back to Apple

A one-time Apple employee working as a buyer within the iGiant's supply chain department has pleaded guilty to mail and wire fraud charges spanning multiple years, ultimately costing the company $17 million.…

  • November 2nd 2022 at 13:00

Ritz cracker giant settles bust-up with insurer over $100m+ NotPetya cleanup

Deal could 'upend the entire cyber-insurance ecosystem and make it almost impossible to get meaningful cyber coverage'

Mondelez International has settled its lawsuit against Zurich American Insurance Company, which it brought because the insurer refused to cover the snack giant's $100-million-plus cleanup bill following the 2017 NotPetya outbreak.…

  • November 2nd 2022 at 07:29

Dropbox admits 130 of its private GitHub repos were copied after phishing attack

Personal info and data safe, stolen code not critical, apparently

Dropbox has said it was successfully phished, resulting in someone copying 130 of its private GitHub code repositories and swiping some of its secret API credentials.…

  • November 1st 2022 at 23:52

OpenSSL downgrades horror bug after week of panic, hype

Relax, there's more chance of Babbage coming back to life to hack your system than this flaw being exploited

OpenSSL today issued a fix for a critical-turned-high-severity vulnerability that project maintainers warned about last week. …

  • November 1st 2022 at 21:39

Government by Gmail catches up with UK minister... who is reappointed anyway

Home Secretary 'nominally in charge' of nation's security apologizes for breach of tech protocols

The UK's Home Secretary – the minister in charge of policing and internal security – has been forced to apologize for breaching IT security protocols in government.…

  • November 1st 2022 at 14:30

Kioxia warns of potential cost of US chip policy over China

Nice NAND industry you have there, would be a shame if something happened to it

Attempts to reorganize supply chains to cut out China and foil its attempts to build a high-tech chip industry will be costly and may simply cause the Middle Kingdom to redouble its efforts, says memory maker Kioxia.…

  • November 1st 2022 at 10:30

German cops arrest student suspected of running infamous dark-web souk

Deutschland im Deep Web destroyed

A 22-year-old student German federal police believe to be the administrator of one of the largest German-speaking, dark-web forums has been arrested. …

  • November 1st 2022 at 05:28

Unofficial fix emerges for Windows bug abused to infect home PCs with ransomware

Broken code signature? LGTM, says Microsoft OS

A cybersecurity firm has issued another unofficial patch to squash a bug in Windows that Microsoft has yet to fix, with this hole being actively exploited to spread ransomware.…

  • November 1st 2022 at 03:48

India's Home Ministry cracks down on predatory lending apps following suicides

Local media say they're China backed, Ministry only mentions organized crime

India's Home Ministry has asked state governments to crack down on illegal lending apps it says have led to "multiple suicides by citizens owing to harassment, blackmail, and harsh recovery methods."…

  • November 1st 2022 at 03:15

Education tech giant gets an F for security after sensitive info on 40 million users stolen

Chegg it out: Four blunders in four years

Sloppy data security at education tech giant Chegg exposed students and workers' personal information not once but four times in various ways over four years, according to the FTC. …

  • October 31st 2022 at 22:54

The White House's global ransomware summit couldn't come at a better time

As cyber threats ramp up, businesses and organizations will be hoping for more than platitudes

The White House has begun its second annual International Counter Ransomware Summit in which Biden administration officials will convene with representatives of three dozen nations, the EU, and private business to discuss the growing threat posed by data-destroying cyber attacks.…

  • October 31st 2022 at 17:30

Ordinary web access request or command to malware?

Cranefly group unleashes nasty little technique using Microsoft Internet Information Services (IIS) logs

A threat group that targets corporate emails is delivering dropper malware through a novel technique that uses Microsoft Internet Information Services (IIS) logs to send commands disguised as web access requests.…

  • October 31st 2022 at 16:30

Apple patches actively exploited iPhone, iPad kernel vulns

Plus: Misconfigured server leaks Thomson Reuters data; VMware patches critical flaw in retired software; MalwareBytes apologies for a hoodie

In brief Apple has patched an iOS and iPad OS vulnerability that's already been exploited.…

  • October 31st 2022 at 07:32

Singapore hosts ICS/OT cybersecurity training extravaganza

Two great SANS events for APAC cyber security professionals to boost their ICS knowledge and skills

Sponsored Post Cybercriminals generally respect no limits or boundaries, but there is evidence to suggest that they are singling out industrial control systems (ICS) and operational technology (OT) systems such as supervisory control and data acquisition (SCADA) platforms in the Asia Pacific region which may represent easier targets for their attention.…

  • October 31st 2022 at 03:00

Indian government creates body with power to order social media content takedowns

PLUS: China’s digital currency surges; Infosys tax portals wobble again; Singapore crypto protections; and more

Asia In Brief India's government has given itself the power to compel social networks to take down content.…

  • October 30th 2022 at 23:32

This Windows worm evolved into slinging ransomware. Here's how to detect it

Raspberry Robin hits 1,000 orgs in just one month

Raspberry Robin, a worm that spreads through Windows systems via USB drives, has rapidly evolved: now backdoor access is being sold or offered to infected machines so that ransomware, among other code, can be installed by cybercriminals.…

  • October 28th 2022 at 22:11

Federal bans aren't stopping US states from buying forbidden Chinese kit

Report claims thousands of orgs are still happily writing checks

Only a "handful" of US states have stopped buying Chinese technologies deemed by the government to pose security threats, according to a report from a Washington policy research group.…

  • October 28th 2022 at 17:32

The top cloud cyber security threats unpacked

Our webinar offers practical advice on how to ward off cloud-borne bugs of the digital variety

Webinar The cloud is constantly in flux, and with its continual growth comes an equally rapid acceleration of threats and vulnerabilities direct towards it. You could say the cloud environment resembles the wild west where even hired guns carefully guarding your wagon train are not always enough to prevent an ambush by a gang of determined outlaws.…

  • October 28th 2022 at 13:12

Biden now wants to toughen up chemical sector's cybersecurity

Control panels facing the internet? Data stolen? You gotta keep an ion this stuff

The White House is adding the chemical sector to a program launched last year to improve cybersecurity capabilities within America's critical infrastructure industries.…

  • October 27th 2022 at 22:36

The point solution IAM evolution under reform

A consolidation of IAM tools, suppliers and managed services providers is changing the default approach

Sponsored Feature The inexorable pace of technological innovation in response to the unrelenting growth of cyber attacks has led to fragmentation within cyber security provision. Things generally follow a common pattern, starting with a new security requirement being identified, whether a response to a novel threat, or a compliance or regulation challenge. This leads buyers to specialized tools, usually from smaller vendors that do one thing well. But inevitably over time, buyers end up using a mishmash of systems and tools, each with its own job and management processes.…

  • October 27th 2022 at 13:01

Purpleurchin cryptocurrency miners spotted scouring free GitHub, Heroku accounts

This is why we can't have nice things

A stealthy cryptocurrency mining operation has been spotted using thousands of free accounts on GitHub, Heroku and other DevOps outfits to craft digital tokens. GitHub, for one, forbids the mining of coins using its cloud resources.…

  • October 27th 2022 at 07:27

Japan to citizens: Get a digital ID or health insurance gets harder

Risk of death is certainly one way to get the populace on board

Japan's plan to phase out public health insurance cards in favor of linking the services to a digital ID card could compel those who oppose the digitization to sign up.…

  • October 27th 2022 at 03:57

Pro-China crew ramps up disinfo ahead of US midterms. Not that anyone's falling for it

Hey, Xi, ζ»šεΌ€

The prolific pro-Beijing Dragonbridge crew has apparently stepped up its activity ahead of the US 2022 midterms by trying to discourage Americans from voting as well as pinning the Nord Stream pipeline explosion on Uncle Sam.…

  • October 27th 2022 at 00:31

Feds accuse Ukrainian of renting out PC-raiding Raccoon malware to fiends

Separately, charges slapped on alleged operator of dark market, The Real Deal

Mark Sokolovsky, 26, a Ukrainian national, is being held in the Netherlands while he awaits extradition to America on cybercrime charges, the US Justice Department said on Tuesday.…

  • October 26th 2022 at 23:06

Cisco AnyConnect Windows client under active attack

Make sure you're patched – and update VMware Cloud Foundation, too, by the way

Cisco says miscreants are exploiting two vulnerabilities in its AnyConnect Secure Mobility Client for Windows, which is supposed to ensure safe VPN access for remote workers.…

  • October 26th 2022 at 20:31

Microsoft realizes it hasn't updated list of banned dodgy Windows 10 drivers in years

Hope no one was relying on that to block threats, er, yeah?

Microsoft appears to have woken up and realized it may have left certain Windows Server and Windows 10 systems exposed to exploitable drivers for years.…

  • October 26th 2022 at 18:45

New Year, new cyber security career

Say hello to SANS 2023 training events and the new job that will inevitably follow

Sponsored Post The turn of the year is always a good time to take stock and think about where you are heading. Many hard working cybersecurity professionals will be keeping as close an eye on the calendar as they are on cyber criminals.…

  • October 26th 2022 at 09:00

Ransomware down this year – but there's a catch

2021 was such a banner year for extortionists, 2022 is gonna look rosy in comparison

The number of ransomware attacks worldwide dropped 31 percent year-over-year during the first nine of months 2022, at least as far as SonicWall has observed. But don't get too excited.…

  • October 26th 2022 at 05:28

If someone tries ransacking your Windows network, it's a bit easier now to grok in Microsoft 365 Defender

Blinking, beeping, and flashing lights, blinking and beeping and flashing...

Microsoft is bringing Azure Active Directory Identity Protection alerts to Microsoft 365 Defender to seemingly help IT folks thwart criminals infiltrating corporate networks via compromised users.…

  • October 26th 2022 at 04:27

Health insurer Medibank's data breach diagnosis keeps getting worse

All four million customers at risk of having records of medical treatments exposed

Australian health insurer Medibank's data breach was today revealed to be even worse than first thought, with a regulatory filing stating that info describing all four million customers has been accessed.…

  • October 26th 2022 at 03:45

FTC slaps down Drizly CEO after 2.4m user records stolen from 'careless' booze app biz

At least this'll give some ammo to CISOs dying for stronger IT defenses

Analysis Drizly CEO James Cory Rellas is in the firing line after his company exposed about 2.5 million customers' personal information in a computer security blunder. …

  • October 26th 2022 at 00:07

PayPal ditches passwords, at least on Apple devices

No more reusing, recycling passwords

PayPal has added passkeys for passwordless login to accounts across Apple devices.…

  • October 25th 2022 at 19:30
❌