FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Mon Dieu! Suspected French ShinyHunters gang member in the dock

Man seized in Morocco is now presumably sleepless in Seattle

A French citizen was scheduled to appear before a US court on Friday on a nine-count indictment related to his alleged involvement in the ShinyHunters cybercrime gang that trafficked in identity and corporate data theft and sometimes extortion.…

  • January 28th 2023 at 08:50

Microsoft to enterprises: Patch your Exchange servers

If you want to keep the miscreants out, put the updates in, Redmond says

Microsoft is urging organizations to protect their Exchange servers from cyberattacks by keeping them updated and hardened, since online criminals are still going after valuable data in the email system.…

  • January 28th 2023 at 01:03

Uncle Sam slaps $10m bounty on Hive while Russia ban-hammers FBI, CIA

New meaning to sweetening the pot

Uncle Sam has put up a $10 million reward for intel on Hive ransomware criminals' identities and whereabouts, while Russia has blocked the FBI and CIA websites, along with the Rewards for Justice site offering the bounty.…

  • January 27th 2023 at 23:59

Savvy cybersecurity pros benefit from host of free resources to step up fight against hackers and cyber threats

Sign up to SANS Institute to keep up to speed with all aspects of the fast-evolving infosec sector

Sponsored Post They say there's no such thing as a free lunch, but in fact there's a veritable feast of valuable resources online for infosec professionals which won't cost you anything.…

  • January 27th 2023 at 08:57

UK Cyber Security Centre's scary new story: One phish, two phish, Russia phish, Iran phish

Nice people on LinkedIn want to harvest logins from politicians, boffins, and defense types

The UK's National Cyber Security Centre (NCSC) has warned of two similar spear-phishing campaigns, one originating from Russia, the other from Iran.…

  • January 27th 2023 at 05:32

FBI smokes ransomware Hive after secretly buzzing around gang's network for months

Uncle Sam doles out decryption keys to 300+ victims amid sting op

The FBI said it has shut down the Hive's ransomware network, seizing control of the notorious gang's servers and websites, and thwarting the pesky criminals' ability to sting future victims.…

  • January 26th 2023 at 20:30

FBI catches up with infosec and crypto communities, blames Lazarus Group for $100 million heist

Well played, feds. What's next? Ransomware is rampant? Strong passwords are important?

The FBI has confirmed what cybersecurity researchers have been saying for months: the North Korean-sponsored Lazarus Group was behind the theft last year of $100 million in crypto assets from blockchain startup Harmony.…

  • January 25th 2023 at 01:45

Google slays thousands of fake news vids posted by pro-China group Dragonbridge

If you yell 'death to America' and no one watches the video, does it make a sound?

Google's Threat Analysis Group (TAG) has burned more than 50,000 spammy fake news stories and other content posted by the pro-China 'Dragonbridge' gang.…

  • January 27th 2023 at 02:58

Bloke allegedly stole, sold private info belonging to 'tens of millions' globally

If true, was it worth the $500k and prison jumpsuit?

A man suspected of stealing personal data belonging to tens of millions of people worldwide and selling that info on cybercrime forums has been arrested by Dutch police.…

  • January 26th 2023 at 07:34

Months after NSA disclosed Microsoft cert bug, datacenters remain unpatched

You know when we all said quit using MD5? We really meant it

Most Windows-powered datacenter systems and applications remain vulnerable to a spoofing bug in CryptoAPI that was disclosed by the NSA and the UK National Cyber Security Center (NCSC) and patched by Microsoft last year, according to Akamai's researchers.…

  • January 26th 2023 at 02:07

Microsoft closes another door to attackers by blocking Excel XLL files from the internet

More of them used by baddies since Redmond blocked VBA macros

Microsoft in March will start blocking Excel XLL add-ins from the internet to shut down an increasingly popular attack vector for miscreants.…

  • January 25th 2023 at 21:59

Strengthening the human element

How to locate cybersecurity risks in remote working

Webinar The implementation of lockdowns during the maelstrom of the Coronavirus pandemic led to fast track changes to traditional work practices. To meet the challenges of operating in a global emergency, businesses and organizations of every kind had to urgently find a way to keep operating.…

  • January 25th 2023 at 12:28

Cybersecurity professionals upskill in Brazil and Mexico

SANS Institute meets fast-growing demand for cyber security training in Latin America

Sponsored Post The scale of cybersecurity threats facing Latin America was brought into focus by recently when it published details of NICKEL, a "China-based threat actor". The malware was used to attack global organisations with "a large amount of activity" targeting Central and South America, including Mexico and Brazil.…

  • January 25th 2023 at 08:53

Go to security school, GoTo – theft of encryption keys shows you need it

Ongoing probe into cloud storage attack finds customer data exfiltrated

Remote access outfit GoTo has admitted that a threat actor exfiltrated an encryption key that allowed access to "a portion" of encrypted backup files.…

  • January 25th 2023 at 08:28

Logfile management is no fun. Now it's a nightmare thanks to critical-rated VMware flaws

You know the drill: patch before criminals use these bugs in vRealize to sniff your systems

VMware has issued fixes for four vulnerabilities, including two critical 9.8-rated remote code execution bugs, in its vRealize Log Insight software. …

  • January 25th 2023 at 02:45

Apple emits emergency patch for older iPhones after snoops pounce on WebKit hole

Also: Yay for Data Privacy Day!

Apple has issued an emergency patch for older kit to fix a WebKit security flaw that Cupertino warns is under active attack.…

  • January 24th 2023 at 20:45

Fujitsu: Quantum computers no threat to encryption just yet

Heavily hyped tech bound for some sort of milestone by decade end

Research conducted by Fujitsu suggests there is no need to panic about quantum computers being able to decode encrypted data – this is unlikely to happen in the near future, it claims.…

  • January 24th 2023 at 19:47

Microsoft took its macros and went home, so miscreants turned to Windows LNK files

Adapt or die

Microsoft's move last year to block macros by default in Office applications is forcing miscreants to find other tools with which to launch cyberattacks, including the software vendor's LNK files – the shortcuts Windows uses to point to other files.…

  • January 23rd 2023 at 13:34

Happy Lunar New Year: Beijing warns of enhanced surveillance during celebrations

Censors are on the lookout for showering under a waterfall of money, overeating, and more conventional sins

The Cyberspace Administration of China (CAC) has preempted celebrations for Lunar New Year – the Year of the Rabbit* commences on January 22 – by warning citizens to keep evidence of seasonal overindulgence off the internet.…

  • January 20th 2023 at 05:30

US authorities release asylum seekers after leaking their data online

Also: US terrorist no-fly list found left on unsecured server, Russian dark web drug markets go to war

In brief Nearly 3,000 immigrants seeking asylum in the United States have been released from custody after Immigration and Customs Enforcement (ICE) officials inadvertently published their personal information online.…

  • January 23rd 2023 at 05:01

India floats plan to make big tech pay for news, walks back government censorship

PLUS: Taiwan’s new supercomputer; China-linked cybercrims strike; Australian content clampdown; and more

Asia In Brief India's IT minister has signaled he is willing to revisit a proposal to use government fact checkers to decide what is fake news that should be removed from social media.…

  • January 23rd 2023 at 03:01

Ireland’s privacy watchdog fines WhatsApp €5.5 million

You’ve got 6 months to get into compliance, it tells yak-yak app

Ireland's data protection authority has fined WhatsApp Ireland €5.5 million for breaches of the GDPR relating to its service and told it comply with data processing laws within six months.…

  • January 20th 2023 at 17:15

Miscreants sure do love ransacking cloud networks, more so than before

Thanks for putting all your data in one basket

As enterprises around the world continue to move to the cloud, cybercriminals are following right behind them.…

  • January 20th 2023 at 06:27

Crims steal data on 40 million T-Mobile US customers

Sixth snafu in five years? Crooks have this useless carrier on speed dial

T-Mobile US today said someone abused an API to download the personal information of 37 million subscribers.…

  • January 20th 2023 at 01:33

PayPal says crooks poked around 35,000 accounts in credential stuffing attack

That passwordless option is looking really good right about now

The personal information of 35,000 PayPal users was exposed in December, according to a notification letter sent to the online payment company's customers this week.…

  • January 19th 2023 at 23:45

Finally, ransomware victims are refusing to pay up

Near 50% drop in extorted dosh ... or so it says here

The amount of money paid to ransomware attackers dropped significantly in 2022, and not because the number of attacks fell.…

  • January 19th 2023 at 22:30

University of Texas latest US school to ban TikTok

Great, now staff and students can stop scrolling and get back to work

Faculty and students at the University of Texas at Austin (UT) this week became the latest members of a public US university to lose access to Chinese video app TikTok via campus networks.…

  • January 19th 2023 at 16:15

Mailchimp 'fesses up to second digital burglary in five months

Social engineering helped intruders break into customers' inboxes again

Email marketing service Mailchimp has confirmed intruders have gained access to more than 100 customer accounts after successfully deploying a social engineering attack.…

  • January 19th 2023 at 14:16

Ransomware severs 1,000 ships from on-shore servers

Get your eyepatch out: Cyber attacks on the high seas are trending

A Norwegian maritime risk management business is getting a lesson in that very area, after a ransomware attack forced its ShipManager software offline and left 1,000 ships without a connection to on-shore servers. …

  • January 19th 2023 at 11:01

Thousands of Sophos firewalls still vulnerable out there to hijacking

As hundreds of staff axed this week

Updated More than 4,000 public-facing Sophos firewalls remain vulnerable to a critical remote code execution bug disclosed last year and patched months later, according to security researchers.…

  • January 18th 2023 at 23:30

Period-tracking apps, search engines on notice by draft law

And no more geofencing around health clinics either

A bill proposed by Washingston state lawmakers would make it illegal for period-tracking apps, Google or any other website to sell consumers' health data while also making it harder for them to collect and share this personal information.…

  • January 18th 2023 at 18:31

Been hit by BianLian ransomware? Here's your get-out-of-jail-free card

Avast issues a free decryptor so victims can get their data back

Cybersecurity firm Avast has released a free decryptor for victims of BianLian – an emerging ransomware threat that came into the public eye in last year.…

  • January 18th 2023 at 03:01

Russian criminals can't wait to hop over OpenAI's fence, use ChatGPT for evil

Scriptkiddies rush to machine intelligence to make up for lack in skills

Cybercriminals are famously fast adopters of new tools for nefarious purposes, and ChatGPT is no different in that regard. …

  • January 18th 2023 at 00:01

Nearly 300 MSI motherboards will run any old code in Secure Boot, no questions asked

'I believe they made this change deliberately' claims researcher

Updated The Secure Boot process on almost 300 different PC motherboard models manufactured by Micro-Star International (MSI) isn't secure, which is particularly problematic when "Secure" is part of the process description.…

  • January 17th 2023 at 20:01

Microsoft locks door to default guest authentication in Windows Pro

Bringing OS version into sync with Enterprise and Education editions

Microsoft wants to bulk up the security in Windows Pro editions by ensuring the SMB insecure guest authentication fallbacks are no longer the default setting in the operating system.…

  • January 17th 2023 at 17:01

Crypto exchanges freeze accounts tied to North Korea’s notorious Lazarus Group

Well whaddya know, the crypto ecosystem did the right thing by stiffing the WannaCry bandits

Two cryptocurrency exchanges have frozen accounts identified as having been used by North Korea’s notorious Lazarus Group.…

  • January 17th 2023 at 06:29

Tencent fired 100 people for corruption during 2022

A couple have already been jailed, others shown the door for embezzling or arranging sham contracts

Chinese web and gaming giant Tencent has admitted it fired more than 100 people in 2022 for various forms of corruption – some so serious it reported them to local police.…

  • January 17th 2023 at 05:29

For password protection, dump LastPass for open source Bitwarden

After the security breach last summer, staying put is playing with fire

Opinion For better or worse, we still need passwords, and to protect and organize them, I recommend the open source Bitwarden password manager.…

  • January 16th 2023 at 11:30

China aims to grow local infosec industry by 30 percent a year, to $22 billion by 2025

Optimistically suggests international collaboration – including on standards – will help it get there

China's government has declared the nation's information security industry needs to grow – fast.…

  • January 16th 2023 at 01:59

NSA asks Congress to let it get on with that warrantless data harvesting, again

Also: That Pokemon is actually a RAT, Uncle Sam fails a password audit

In brief A US intelligence boss has asked Congress to reauthorize a controversial set of powers that give snoops warrantless authorization to surveil electronic communications in the name of fighting terrorism and so forth.…

  • January 14th 2023 at 20:57

Russians say they can grab software from Intel again

And Windows updates from Microsoft, too

People in Russia can reportedly once again download drivers and some other software from Intel and Microsoft, which both withdrew from the nation after its invasion of Ukraine.…

  • January 14th 2023 at 08:07

Canadian owes bosses for 'time theft' after work-tracking app sinks tribunal bid

She hoped to score thousands but laptop app had other ideas

A woman in Canada failed in her claim for wrongful dismissal due to evidence from software designed to track her work time activity.…

  • January 13th 2023 at 18:43

Microsoft Defender ASR rules strip icons, app shortcuts from Taskbar, Start Menu

Happy Friday 13th sysadmins! Techies find workarounds but Redmond still 'investigating'

Techies are reporting that Microsoft Defender for Endpoint attack surface reduction (ASR) rules have gone haywire and are removing icons and applications shortcuts from the Taskbar and Start Menu.…

  • January 13th 2023 at 13:30

Long data privacy notices aren't foolproof, Euro watchdog tells Meta

As Meta reels from €390 million EU fine, the 'personalized ads' case might not be over, Max Schrem’s legal group says

Lengthy privacy notices included in a social media platform's terms of service can do little to help it comply with transparency requirements under European law, according to recently revealed documents from a case in which Meta was fined €390 million ($414 million).…

  • January 13th 2023 at 11:30

This can’t be a real bomb threat: You've called a modem, not a phone

Security was nonetheless very, very, interested in hearing this comms engineer tell his tale

On-Call Welcome once again to On-Call, The Register's weekly compendium of tales from readers who were asked to deal with IT oddities and mostly emerged unscathed.…

  • January 13th 2023 at 07:29

Euro-cops shut down crypto scam that bilked millions from unwitting punters

If the investment opportunity sounds too good to be true …

European cops arrested 15 suspected scammers and shut down a multi-country network of call centers selling fake cryptocurrency that law enforcement said stole upwards of hundreds of million euros from victims.…

  • January 13th 2023 at 06:30

Microsoft fumbles zero trust upgrade for some Asian customers

Enhanced access privileges for partners choke on double-byte characters, contribute to global delays

Microsoft has messed up a zero trust upgrade its service provider partners have been asked to implement for customers.…

  • January 13th 2023 at 05:58

Lawyers slam SEC for 'blatant fishing expedition' after Exchange mega-attack

Not a 'whiff of wrongdoing' here, says attorney now fighting off Uncle Sam

The US Securities and Exchange Commission (SEC) has sued international law firm Covington & Burling for details about 298 of the biz's clients whose information was accessed by a Chinese state-sponsored hacking group in November 2020.…

  • January 12th 2023 at 20:06

VALL-E AI can mimic a person’s voice from a three-second snippet

Are you really saying what I’m hearing?

Microsoft researchers are working on a text-to-speech (TTS) model that can mimic a person's voice – complete with emotion and intonation – after a mere three seconds of training.…

  • January 12th 2023 at 08:30

US think tank says China would probably lose if it tries to invade Taiwan

But even a short conflict would wreck the economy, which would be bad news for semiconductor supplies

Three years from now, hypothetically, China launches an amphibious invasion of Taiwan. It does not go well, according to a top Washington think tank report.…

  • January 12th 2023 at 03:15

Royal Mail, cops probe 'cyber incident' that's knackered international mail

Don't go postal and call it a cyberattack because nobody knows (yet) what knocked out key system

Final update Royal Mail confirmed a "cyber incident" has disrupted its ability to send letters and packages abroad, and also caused some delays on post coming into the UK.…

  • January 11th 2023 at 22:57

AI-generated phishing emails just got much more convincing

Did a criminally minded robot write this? In part, yes.

GPT-3 language models are being abused to do much more than write college essays, according to WithSecure researchers.…

  • January 11th 2023 at 20:13

Microsoft fixes Windows database connections it broke in November

January Patch Tuesday update resolves issue caused by Patch Tuesday update late in '22

Included in the usual tsunami of fixes Microsoft issued this week as part of Patch Tuesday was one that took care of a connectivity problem for applications using the Open Database Connectivity (ODBC) interface.…

  • January 11th 2023 at 17:00

German cartel watchdog objects to the way Google processes user data

Not transparent, not specific, and too easy to say yes to

Google users don't have enough choice over whether – and to what extent – they agree to "far-reaching processing of their data across services," Germany's competition regulator says, adding that the tech giant should change its "data processing" terms and practices.…

  • January 11th 2023 at 16:15

Swiss Army's Threema messaging app was full of holes – at least seven

At least the penknives are still secure

A supposedly secure messaging app preferred by the Swiss government and army was infested with bugs – possibly for a long time – before an audit by ETH Zurich researchers.…

  • January 11th 2023 at 08:01

Health insurer Aflac blames US partner for leak of Japanese cancer policy info

Zurich’s Japanese outpost also leaks a couple of million records

Global insurer Aflac's Japanese branch has revealed that personal data describing more than three million customers of its cancer insurance product has been leaked online.…

  • January 11th 2023 at 03:29

Privacy on the line: Boffins break VoLTE phone security

Call metadata can be ferreted out

Boffins based in China and the UK have devised a telecom network attack that can expose call metadata during VoLTE/VoNR conversations.…

  • January 11th 2023 at 01:58

First Patch Tuesday of the year explodes with in-the-wild exploit fix

Plus: Intel, Adobe, SAP and Android bugs

Patch Tuesday Microsoft fixed 98 security flaws in its first Patch Tuesday of 2023 including one that's already been exploited and another listed as publicly known. Of the new January vulnerabilities, 11 are rated critical because they lead to remote code execution.…

  • January 11th 2023 at 00:00

Russian meddling in 2016 US presidential election was weak sauce

Boffins find Twitter foreign influence campaign didn't have much pull

Russian disinformation didn't materially affect the way people voted in the 2016 US presidential election, according to a research study published on Monday, though that doesn't make the effect totally inconsequential.…

  • January 10th 2023 at 22:00

How to track equipped cars via exploitable e-ink platemaker

Miscreants could have tracked, modified, deleted digital plates

California's street-legal ink license plates only received a nod from the US government in October, but reverse engineers have already discovered vulnerabilities in the system allowing them to track each plate, reprogram them or even delete them at a whim.…

  • January 10th 2023 at 16:18
❌