FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

REvil-hit Medibank to pull plug on IT, shore up defenses

If safety regulations are written in blood, what are security policies written in? Sweat and cursing?

Australian health insurance company Medibank will take all of its IT systems offline and close its branches over the weekend as part of its ongoing efforts to improve security and recover from a massive data security breach in October.…

  • December 8th 2022 at 21:35

Five British companies fined for making half a million nuisance calls

Nice. They went after vulnerable people and folks over 60 who opted out of marketing calls

Britain's data watchdog has slapped financial penalties totaling Β£435,000 (c $529,000) on five companies it says collectively made almost half of million marketing calls to people registered with the Telephone Preference Service (TPS).…

  • December 8th 2022 at 11:41

Weep for the cybercriminals who fell for online scams and lost $2.5m last year

I'm the smartest guy in the room, I'm sure the message from IRS refunds is legit

Scammers have scammed their fellow cybercriminals out of more than $2.5 million on three dark web forums alone over the last 12 months, according to Sophos researchers.…

  • December 8th 2022 at 09:59

North Korea hits new low by using Seoul Halloween tragedy to exploit Internet Explorer zero-day

Evil, pure and simple

North Korea has hit a new low, using the death of over 150 people to exploit a zero-day flaw in Internet Explorer.…

  • December 8th 2022 at 07:02

States label TikTok 'a malicious and menacing threat'

Texas bucks app off government devices as Indiana takes social media biz to court

Two more US states have launched aggressive action against made-in-China social media app TikTok.…

  • December 8th 2022 at 04:30

Egad, did Apple do something right? End-to-end encryption for (most) iCloud services

And remember CSAM scanning plan? Forget that was ever a thing

Apple says it will provide end-to-end encryption for most iCloud services, having abandoned its previously announced – and then quietly shelved – plan to check the legality of on-device photos prior to cloud synchronization.…

  • December 8th 2022 at 01:44

San Francisco terminates explosive killer cop bots

I'll be back, or perhaps not

San Francisco legislators this week changed course on their killer robot policy, banning the police from using remote-control bots fitted with explosives. For now.…

  • December 7th 2022 at 20:00

Taiwan bans state-owned devices from running Chinese platform TikTok

US FCC Commissioner praises Taiwan’s security decision as US state governments follow suit

Public sector bans of Chinese platform TikTok on the grounds of national security have arisen in both Taiwan and additional US states following last week’s ban in South Dakota.…

  • December 7th 2022 at 10:48

Microsoft: (Cyber) winter is coming as DDoS attack disrupts Russian bank

Where's the Night's Watch when you need them?

Microsoft has warned Europe to be on alert for cyber attacks from Russia this winter, just as a series of attacks hit Russian organizations – including the country's second-largest bank.…

  • December 7th 2022 at 07:25

Amnesty International Canada claims attack by China-backed forces

Threat actors allegedly looking for contacts and monitoring org's future plans

The Canadian branch of Amnesty International was the target of an attack it has pinned on a Chinese state-sponsored actor.…

  • December 7th 2022 at 04:29

South Pacific vacations may be wrecked by ransomware

New Zealand government reels, Vanuatu’s spent weeks entirely offline

New Zealand's Privacy Commission has signalled it may open an investigation into local managed services provider Mercury IT, which serves many government agencies and businesses and has been hit by ransomware.…

  • December 7th 2022 at 02:58

Rackspace confirms ransomware attack behind days-long email meltdown

Hope the name Hackspace doesn't stick

Updated Rackspace has admitted a ransomware infection was to blame for the days-long email outage that disrupted services for customers. …

  • December 6th 2022 at 22:45

Want to detect Cobalt Strike on the network? Look to process memory

Security analysts have tools to spot hard-to-find threat, Unit 42 says

Enterprise security pros can detect malware samples in environments that incorporate the highly evasive Cobalt Strike attack code by analyzing artifacts in process memory, according to researchers with Palo Alto Networks' Unit 42 threat intelligence unit.…

  • December 6th 2022 at 15:30

KmsdBot botnet is down after operator sends typo in command

Cashdollar: 'It’s not often we get this kind of story in security'

Somewhere out there, a botnet operator is kicking themselves and probably hoping no one noticed the typo they transmitted in a command that crashed their whole operation. …

  • December 6th 2022 at 13:30

How to secure application identities at developmental speed

We discuss the top emerging DevSecOps trends with CyberArk

Webinar There you are, standing in front of two peaks, a security roadmap in your back pocket to guide you up the sheer track of the first mountain. In the other pocket, a DevOps plan that will have you leaping like a mountain goat from rock to rock up the next door peak. You wonder which mountain to scale first, but it is an impossible choice. The night is stealing all the light from the sky, and you must make up your mind.…

  • December 6th 2022 at 10:30

TSA to expand facial recognition across America

System is optional, for the moment

America's Transport Security Administration, better known as the TSA, has been testing facial recognition software to automatically screen passengers flying across the country in 16 airports. And now it's looking into rolling it out nationwide next year.…

  • December 6th 2022 at 02:30

Four suspects cuffed, face extradition over tax refund scam plot

RDP servers allegedly raided in hunt for personal info to exploit

Four men suspected of plotting to commit wire fraud and identity theft have been arrested and now face extradition to America.…

  • December 6th 2022 at 01:30

Gunfire at electrical grid kills power for 45,000 in North Carolina

You don't have to be a coder to cut off the juice when blunt tools are around

Officials in Moore County, North Carolina, declared a state of emergency on Sunday after gunfire damaged an electrical substation and left 45,000 homes and businesses without power in near freezing temperatures.…

  • December 5th 2022 at 23:30

Google warns stolen Android keys used to sign info-stealing malware

OEMs including Samsung, LG and Mediatek named and shamed

Compromised Android platform certificate keys from device makers including Samsung, LG and Mediatek are being used to sign malware and deploy spyware, among other software nasties.…

  • December 5th 2022 at 22:30

Securing Application Identities in 2023

The rise and rise of non-human identities

Webinar Just as Frank Sinatra sang in days gone by, 'love and marriage' goes together like a 'horse and carriage,' there should be no question about the true pairing of security and speed. Or as Sinatra went on to croon, 'try, try, try to separate them, it's an illusion.' Companies may feel they are forced to choose between securing all their application identities at the cost of speed of development, but this doesn't have to be the case.…

  • December 5th 2022 at 10:27

Remuneration coming for TrustCor customers impacted by CA revocation

Also, a Capone henchman lands behind bars, while nearly 9/10 DoD contract firms fail security standards

In brief Certificate Authority TrustCor responded to its ejection from Mozilla and Microsoft's browsers by offering refunds for some customers, while leaving other resellers to pick up the mess on their own.…

  • December 5th 2022 at 05:45

Rackspace customers rage as email outage continues and migrations create migraines

Hosting company has nothing to say on data loss, restore times, or root cause

Rackspace has not offered any explanation of the "security incident" that has taken out its hosted Exchange environment and led the company to predict multiple days of downtime before restoration.…

  • December 5th 2022 at 04:45

Rackspace rocked by β€˜security incident’ that has taken out hosted Exchange services

Warns recovery could take several days and pledges better support after customer complaints

Updated Some of Rackspace’s hosted Microsoft Exchange services have been taken down by what the company has described as a β€œsecurity incident”.…

  • December 3rd 2022 at 10:58

US Air Force reveals B-21 Raider stealth bomber that'll fly the unfriendly skies

'Digital bomber' will bring 'peace through deterrence'

In Palmdale, California on Friday, Northrop Grumman CEO Kathy Warden revealed a US Air Force warplane that had only been shown in artist renderings and is supposed to be seldom seen, the B-21 Raider.…

  • December 3rd 2022 at 02:58

Medibank prognosis gets worse after more stolen data leaked

Plus Australia launches an investigation into insurer's data privacy practices

Australian health insurer Medibank's prognosis following an October data breach keeps getting worse as criminals dumped another batch of stolen customer data on the dark web. …

  • December 2nd 2022 at 23:10

FBI warns about Cuba, no, not that one β€” the ransomware gang

Critical infrastructure attacks ramping up

The US government has issued an alert about Cuba; not the state but a ransomware gang that's taking millions in purloined profits.…

  • December 2nd 2022 at 20:30

Domain aging gang CashRewindo picks vintage sites to push malvertising

Like fine wine, the longer it sits, the better it is

A sophisticated and very patient threat group behind a global malvertising scheme is using so-called aged domains to skirt past cybersecurity tools and catch victims in investment scams.…

  • December 2nd 2022 at 10:59

Mozilla, Microsoft drop TrustCor as root certificate authority

'There is no evidence to suggest that TrustCor violated conduct, policy, or procedure' says biz

Updated Mozilla and Microsoft have taken action against a certificate authority accused of having close ties to a US military contractor that allegedly paid software developers to embed data-harvesting malware in mobile apps.…

  • December 2nd 2022 at 09:30

Two signs in the comms cabinet said 'Do not unplug'. Guess what happened

No amount of resilience planning can defeat determined idiots whose devices are low on battery

On Call Welcome once more to On-Call, The Register's weekly reader-contributed column that tells tales of IT pros being asked to fix things that should never have broken.…

  • December 2nd 2022 at 07:00

Nvidia patches 29 GPU driver bugs that could lead to code execution, device takeover

Take a break from the gaming and fix these now

Nvidia fixed more than two dozen security flaws in its GPU display driver, the most severe of which could allow an unprivileged user to modify files, and then escalate privileges, execute code, tamper with or steal data, or even take over your device.…

  • December 1st 2022 at 23:30

Google warns of commercial Heliconia spyware hitting Chrome, Firefox, Microsoft Defender

Meanwhile NSO faces new lawsuit over Pegasus flying onto journalists' phones

Google's Threat Analysis Group (TAG) said on Wednesday that its researchers discovered commercial spyware called Heliconia that's designed to exploit vulnerabilities in Chrome and Firefox browsers as well as Microsoft Defender security software.…

  • December 1st 2022 at 20:30

Intruders gain access to user data in LastPass incident

Password manager says credentials safely encrypted, confirms link to August attack

Intruders broke into a third-party cloud storage service LastPass shares with affiliate company GoTo and gained access to "certain elements" of customers' information, the pair have confirmed.…

  • December 1st 2022 at 13:30

Twenty years on, command-line virus scanner ClamAV puts out version 1

Used by millions – and the first official finished edition is here

The ClamAV command-line virus scanner used on many Linux boxes has attained an important-looking milestone release: version 1.0.0.…

  • December 1st 2022 at 10:51

Keeping customers happy means the big IAM just got bigger

You need to open up core systems to consumers and partners. Here's how to do it securely

Sponsored Feature It's easy to forget the human factor when it comes to cybersecurity. Completely locking down your network will certainly make you secure, just as completely locking down your building will do the same. The problem is you'll struggle to get much work done, because people need access to assets, physical or virtual, to do their jobs.…

  • December 1st 2022 at 09:02

Almost 300 predatory loan apps found in Google and Apple stores

Note to self: Lenders don’t need the contact list on your mobile device

Almost 300 apps, downloaded by around 15 million users, have been pulled from the Google Play and Apple App stores over claims they promised quick loans at reasonable rates but then used extortion and other predatory schemes against borrowers.…

  • December 1st 2022 at 07:30

Sirius XM flaw unlocks so-called smart cars thanks to code flaw

Telematics program doesn't just give you music, but a big security flaw

Sirius XM's Connected Vehicle Services has fixed an authorization flaw that would have allowed an attacker to remotely unlock doors and start engines on connected cars knowing only the vehicle identification number (VIN).…

  • November 30th 2022 at 23:30

San Francisco lawmakers approve lethal robots – but they can't carry guns

Update: Plan pulled after public outcry

Updated San Francisco police can deploy so-called "killer robots" following a Board of Supervisors' vote on Tuesday, clearing the cops to use robots equipped with explosives in extreme situations.…

  • November 30th 2022 at 21:30

TikTok NSFW if you work for the South Dakota government

Governor bans platform and website from all state-owned devices that can connect to the internet

The governor of South Dakota issued an executive order on Tuesday banning the use of Chinese social media platform TikTok for state government agencies, employees and contractors on state devices.…

  • November 30th 2022 at 11:31

Cloudflare finds a way through China's network defences

Teams with locals to allow consistent security policy to make it through the Great Firewall

Cloudflare has found a way to extend some of its services across the Great Firewall and into mainland China.…

  • November 30th 2022 at 04:58

Criminals use trending TikTok challenge to make data-stealing malware invisible

PSA: Don't download unknown apps even if they promise naked people

Malware-slinging miscreants are taking advantage of a trending TikTok challenge β€” and viewers' dirty minds β€” to spread data-stealing malware via a phony app that's had more than one million views so far.…

  • November 29th 2022 at 20:00

Lockheed Martin's Army cyber training platform goes civilian

Army civilian employees, that is, but aerospace biz says it could be used in the private sector, too

Locheed Martin has bagged a government contract to train 17,000 remote US Army civilian employees on security readiness, and wants to also extend the offer to private entities.…

  • November 29th 2022 at 17:45

The five cyber attack techniques of the apocalypse

Watch SANS experts discuss some of the most devious and dangerous methods employed by hackers in 2022

Webinar This year's RSA Conference saw SANS security experts gather to identify and discuss five of the most dangerous cyber attack techniques identified in the first half of the year. If you missed the original debate, don't worry, you have another chance to learn what you should be looking out for.…

  • November 29th 2022 at 13:00

Sandworm gang launches Monster ransomware attacks on Ukraine

The RansomBoggs campaign is the Russia-linked group’s latest assault on the smaller country

The Russian criminal crew Sandworm is launching another attack against organizations in Ukraine, using a ransomware that analysts at Slovakian software company ESET are calling RansomBoggs.…

  • November 29th 2022 at 08:30

International cops arrest hundreds of fraudsters, money launderers and cocaine kingpins

$155,000-a-month lifestyle ends in cuffs for suspected crim

Europol has arrested hundreds of fraudsters, money launderers and cocaine kingpins, and shut down thousands of websites selling pirated and counterfeit products in a series of raids over the past month.…

  • November 29th 2022 at 06:01

Blockchain couldn't stop TXT spam in India, regulator now trying AI

Maybe – just maybe – messages and calls from +91 might become more trustworthy

India's Telecom Regulatory Authority (TRAI) has announced a fresh crackdown on TXT spam – this time using artificial intelligence, after a previous blockchain-powered effort delivered mixed results.…

  • November 29th 2022 at 02:29

Windows Server domain controllers may stop, restart after recent updates

Microsoft outlines a workaround while pulling together a fix to LSASS memory leak

Updates to Windows Server released as part of this month's Patch Tuesday onslaught might cause some domain controllers to stop working or automatically restart, according to Microsoft.…

  • November 28th 2022 at 15:46

Want to boost your cyber security skills by playing games this Christmas?

Register for this free SANS Holiday Hack Challenge to find out how

Sponsored Post Christmas is a time for gift giving and spending time with your friends and family – but that doesn't have to be all. What if you could add to the fun by taking part in an entertaining free holiday-themed cyber security event that both builds your skills and gives you the chance of adding a stellar prize to the pile of gifts under your tree?…

  • November 28th 2022 at 13:06

US bans Chinese telecoms imports – won't even consider authorizing them

Part bureaucratic box ticking, part crackdown that makes even Wi-Fi routers and smartphones off limits

The United States' Federal Communications Commission (FCC) has barred itself from authorizing the import or sale of Chinese telecoms and video surveillance products from Huawei, ZTE, Hytera Communications, Hikvision, and Dahua, on national security grounds.…

  • November 27th 2022 at 22:32

How advances in email encryption bring all-out security success

Listen in to our webinar on 30th November to find out

Webinar Email provides us with an infinite number of possible exchanges. We send approximately 332 billion messages a day but having so much convenience and flexibility at our fingertips also brings security risks.…

  • November 25th 2022 at 12:50

Guess the most common password. Hint: We just told you

Also, Another red team tool at risk of turning to the darkside, and Meta catches the US military behaving badly

In brief NordPass has released its list of the most common passwords of 2022, and frankly we're disappointed in all of you.…

  • November 25th 2022 at 09:38

Elon Musk to abused Twitter users: Your tormentors are coming back

Promises restoration of suspended accounts, despite previous pledge to do no such thing

Twitter CEO Elon Musk has decided to allow suspended accounts back onto the micro-blogging service.…

  • November 25th 2022 at 05:16

UK bans Chinese CCTV cameras on 'sensitive' government sites

Agencies told to rip 'em off core networks and replace 'em whenever and wherever possible

Updated The United Kingdom has decided Chinese video cameras have no place in government facilities.…

  • November 25th 2022 at 00:30

Meta links US military to fake social media influence campaigns

Didn't say they were good, though – covert ops apparently got 'little to no engagement' from targets

In its latest quarterly threat report, Meta said it had detected and disrupted influence operations originating in the US, and it calls out those it believes are responsible: the American military.…

  • November 24th 2022 at 12:15

European Parliament Putin things back together after cyber attack

DDoS started not long after Russia was declared a state sponsor of terrorism

The European Parliament has experienced a cyber attack that started not long after it declared Russia to be a state sponsor of terrorism.…

  • November 24th 2022 at 06:03

Still using a discontinued Boa web server? Microsoft warns of supply chain attacks

Flaws in the open-source tool exploited – and India's power grid was a target

Microsoft is warning that systems using the long-discontinued Boa web server could be at risk of attacks after a series of intrusion attempts of power grid operations in India likely included exploiting security flaws in the technology.…

  • November 23rd 2022 at 19:00

'Pig butchering' romance scam domains seized and slaughtered by the Feds

'We allege these fraudsters bled dry each of their victims' of $10m

The US government seized seven domain names used in so-called "pig butchering" scams that netted criminals more than $10 million.…

  • November 23rd 2022 at 00:30

DraftKings gamblers lose $300,000 to credential stuffing attack

Users of the sports betting site rolled the dice on reusing passwords and lost

A credential stuffing attack over the weekend that affected sports betting biz DraftKings resulted in as much as $300,000 being stolen from customer accounts.…

  • November 22nd 2022 at 23:30

AWS fixes 'confused deputy' vulnerability in AppSync

Datadog security researchers found the flaw before miscreants did

Amazon Web Services (AWS) fixed a cross-tenant flaw in AWS AppSync that could allow miscreants to abuse that cloud service to assume identity and access management roles in other AWS accounts, and then gain access to and control over those resources. …

  • November 22nd 2022 at 22:01

Microsoft's attempts to harden Kerberos authentication broke it on Windows Servers

Emergency out-of-band updates to the rescue

Microsoft is rolling out fixes for problems with the Kerberos network authentication protocol on Windows Server after it was broken by November Patch Tuesday updates.…

  • November 21st 2022 at 23:00

World Cup phishing emails spike in Middle Eastern countries

That's where the money is

Phishing attempts targeting victims in the Middle East increased 100 percent last month in the lead up to the World Cup in Qatar, according to security shop Trellix.…

  • November 21st 2022 at 20:49
❌