FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

'Russian hacktivists' brag of flooding German airport sites

In other words, script kiddies up to shenanigans again

A series of distributed denial-of-service (DDoS) attacks shut down seven German airports' websites on Thursday, a day after a major IT glitch at Lufthansa grounded flights.…

  • February 17th 2023 at 18:30

Cry Havoc and let slip dogs of war ... there's an upgraded malware server in town

ThreatLabz finds free alternative to Cobalt Strike and other tools used in the wild

There's a fresh open-source command-and-control (C2) framework on the loose, dubbed Havoc, as an alternative to the popular Cobalt Strike, and other mostly legitimate tools, that have been abused to spread malware.…

  • February 17th 2023 at 10:30

EU lawmakers argue against signing US data-transfer pact

Committee: Something about complaints process being dealt with in total secrecy doesn't sit right

Lawmakers in the European Parliament have urged the European Commission not to issue the "adequacy decision" needed for the EU-US Data Privacy Framework (DPF) to officially become the pipeline for data to freely flow from the EU to the States.…

  • February 17th 2023 at 09:30

Antivirus apps are there to protect you – Cisco's ClamAV has a heckuva flaw

Switchzilla hardware and software need attention, unless you fancy arbitrary remote code execution

Antivirus software is supposed to be an important part of an organization's defense against the endless tide of malware.…

  • February 17th 2023 at 06:02

Norway finds a way to recover crypto North Korea pinched in Axie heist

Meanwhile South Korea's Do Kwon is sought for fraud by US authorities

Norwegian authorities announced on Thursday that they had recovered $5.9 million of cryptocurrency stolen in the Axie Infinity hack – an incident widely held to have been perpetrated by the Lazarus Group, which has links to North Korea.…

  • February 17th 2023 at 05:15

Google's big security cert log overhaul broke Android apps. Now it's hit undo

Devs missed warnings plus tons of code relies again on lone open source maintainer

Google this week reversed an overhaul of one of its security-related file formats after the transition broke Android apps.…

  • February 16th 2023 at 22:26

VMware, Windows 11 shafted by Windows Server 2022

OS won't start on some systems with ESXi VMs, while Win11 updates may not make it to devices

Updated Microsoft is sorting through two issues with Windows Server 2022 that affect VMware virtual machines and updates not getting passed on to Windows 11 devices.…

  • February 16th 2023 at 20:30

More victims of fake crypto investor scam speak to The Register

UK-based Coin Publishers were conned out of $206,000 after meeting in a Barcelona hotel

Exclusive When Ahad Shams detailed on Twitter how his company was scammed out of $4 million in cryptocurrency after a face-to-face meeting, Chris Hunter immediately recognized what was going on.…

  • February 16th 2023 at 18:30

ESXiArgs ransomware fights off Team America's data recovery script

Want a clue to what you’re dealing with? Check the ransom note

That didn't take long.…

  • February 16th 2023 at 01:30

Intel patches up SGX best it can after another load of security holes found

Plus bugs squashed in Server Platform Services and more

Intel's Software Guard Extensions (SGX) are under the spotlight again after the chipmaker disclosed several newly discovered vulnerabilities affecting the tech, and recommended users update their firmware.…

  • February 15th 2023 at 20:40

Storage security toughen-up for compliance and cyberwar in 2023

Giving storage platforms enhanced built-in security features will be a significant step toward counteracting the impacts of cybercrime in 2023, Dell experts predict

Sponsored Feature Cybercriminals tend not to discriminate when it comes to the type of data they steal. Structured or unstructured, both formats contain valuable information that will bring them a profit. From a cybersecurity practitioner's perspective, however, structural state presents specific challenges when it comes to storing and moving sensitive data assets around.…

  • February 15th 2023 at 12:23

Hyundai and Kia issue software upgrades to thwart killer TikTok car theft hack

Gone in 60 seconds using a USB-A plug and brute force instead of a key

Korean car-makers Hyundai and Kia will issue software updates to some of their models after a method of stealing them circulated on TikTok, leading to many thefts and even some deaths.…

  • February 15th 2023 at 07:29

Apple splats zero-day bug, other gremlins in macOS, iOS

WebKit flaw 'may have been exploited' – just like Tim Cook 'may have' made a million bucks this week

Apple this week released bug-splatting updates to its operating systems and Safari browser, to fix a zero-day vulnerability in its WebKit browser engine that's reported to have been actively exploited.…

  • February 15th 2023 at 05:27

Russian crook made $90M exploiting stolen info on Tesla, Roku, Avnet, Snap, more

Undisclosed earnings reports swiped, exploited

A Russian national with ties to the Kremlin exploited stolen upcoming financial filings belonging to hundreds of companies to help him and his associates net more than $90 million.…

  • February 15th 2023 at 00:58

Microsoft delivers 75-count box of patches for Valentine's Day

Adobe, SAP, Intel, AMD, Android also show up with bouquet of fixes

Patch Tuesday Happy Patch Tuesday for February, 2023, which falls on Valentine's Day.…

  • February 14th 2023 at 22:25

Record-breaking number of record-breaking DDoS attacks confirmed

And growing abuse of cloud – because using hijacked Brazilian cable modems to down sites is so 2013

Dozens of companies over the weekend were hit by distributed denial-of-service (DDoS) attacks, including the largest one yet recorded, or so Cloudflare says.…

  • February 14th 2023 at 20:15

Google lets a few Android devices into its Privacy Sandbox

Chocolate Factory's ad tech renovation is moving ahead, like it or not

Google on Tuesday began rolling out a beta test of its Privacy Sandbox software for a small portion of Android 13 devices to learn how its purportedly privacy-protecting ad tech actually performs.…

  • February 14th 2023 at 17:00

Romance scam targets security researcher, hilarity ensues

Happy Valentine's Day! Now don't get fooled

It sounds like the plot of a somewhat far-fetched romcom-slash-thriller Netflix series, maybe billed as You meets Your Place or Mine, dropping just in time for Valentine's Day.…

  • February 14th 2023 at 02:30

Pepsi Bottling Ventures says info-stealing malware swiped sensitive data

That's not what I like

Crooks have breached Pepsi Bottling Ventures' network and, after deploying info-stealing malware, made off with sensitive personal and financial information according to a notification sent to consumers.…

  • February 14th 2023 at 00:30

Namecheap admits 'unauthorized emails' pwning its customers

Blames 'third-party provider' as phishers drain Ethereum wallets

Domain registrar Namecheap blamed a "third-party provider" that sends its newsletters after customers complained of receiving phishing emails from Namecheap's system.…

  • February 13th 2023 at 16:13

LockBit's Royal Mail ransom deadline flies by. No data released

Also: Russian wiper malware authors turn to data theft, plus this week's critical vulns

in brief The notorious LockBit ransomware gang has taken credit for an attack on the Royal Mail – but a deadline it gave for payment has come and gone with nothing exposed to the web except the group's claims.…

  • February 13th 2023 at 12:38

Learn the art of malicious compliance: doing exactly what you were asked, even when it's wrong

Smart-alec worker found a way to avoid nasty, boring jobs – by doing what he was told

Who, Me? Ah, gentle reader, welcome back once again to the comfortable backwater of The Register we call Who, Me? in which readers' tales of not-quite-rightness are immortalized for the ages.…

  • February 13th 2023 at 08:28

China's spy balloon barrage earns six of its companies a spot on US entity list

US Commerce Department can't just let red balloons go by

The US Department of Commerce added six more entities to its blacklist on Friday on grounds of national security after an errant Chinese surveillance balloon was shot down over the US last week.…

  • February 13th 2023 at 06:28

Ransomware crooks steal 3m+ patients' medical records, personal info

All that data coming soon to a darkweb crime forum near you?

Several California medical groups have sent security breach notification letters to more than three million patients alerting them that crooks may have stolen a ton of their sensitive health and personal information during a ransomware infection in December.…

  • February 11th 2023 at 02:16

US, UK slap sanctions on Russians linked to Conti, Ryuk, Trickbot malware

Any act that sends so much as a ruble to seven named netizens now forbidden

The US and UK have sanctioned seven Russians for their alleged roles in disseminating Conti and Ryuk ransomware and the Trickbot banking trojan.…

  • February 10th 2023 at 07:24

US teases more China tech sanctions, this time to deflate balloon-makers

State Dept already has one target, FBI is identifying sources of floating surveillance platform's components

The Chinese surveillance balloon that drifted across the US last week looks set to spark a new round of sanctions against Middle Kingdom tech firms.…

  • February 10th 2023 at 06:31

Australia gives made-in-China CCTV cams the boot

The usual suspects - Hikvision and Dahua - named as a risk to national security, prompting the usual denials

Australia's Defence Department removed all Chinese manufactured surveillance cameras after an audit detailed the number of Hikvision and Dahua devices installed in various government facilities.…

  • February 10th 2023 at 04:28

Romance scammers' favorite lies cost victims $1.3B last year

Don't trust your super-hot military boyfriend you've never met. He doesn't exist

As Valentine's Day approaches, if your offshore oil rig worker "boyfriend" – who looks like Bradley Cooper in his online pics and has hinted at proposing to you for months, but you've never met in real life – suddenly needs money for "hospital bills" … Just. Don't. Do. It.…

  • February 10th 2023 at 03:28

Reddit reveals security incident that looks more SNAFU than TIFU

Phishing hooked internal documents, code, and some non-critical systems, but users' personal info safe

Colorful web forum Reddit has revealed it has suffered a security breach.…

  • February 10th 2023 at 01:29

Codebreakers decipher Mary, Queen of Scots' secret letters 436 years after her execution

Digital sleuths chop through crypto challenge in 'surreal' search

A team of codebreakers discovered – and then cracked – more than 50 secret letters written by Mary Stuart, Queen of Scots while she was imprisoned in England by her cousin, Queen Elizabeth I. …

  • February 9th 2023 at 08:30

Uncle Sam wants to strip the IoS out of IoT with light crypto

NIST weighs up algorithms for small devices – and an architecture for massive systems

The US National Institute of Standards and Technology wants to protect all devices great and small, and is getting closer to settling on next-gen cryptographic algorithms suitable for systems at both ends of that spectrum – the very great and the very small.…

  • February 9th 2023 at 00:30

Among the thousands of ESXiArgs ransomware victims? FBI and CISA to the rescue

Evil code hits more than 3,800 servers globally, according to the Feds

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a recovery script to help companies whose servers were scrambled in the recent ESXiArgs ransomware outbreak.…

  • February 8th 2023 at 21:30

Scammers steal $4 million in crypto during face-to-face meeting

Demand to display wallet full of coin facilitated mystery heist

Ahad Shams, the co-founder of Web3 metaverse gaming engine startup Webaverse, discovered in late November 2022 that someone had stolen $4 million of his cryptocurrency – during a real world interaction.…

  • February 8th 2023 at 13:30

Suspect in Finnish psychotherapy center blackmail hack arrested

Suomi sentence expected for shrink records theft

French police have arrested a 25-year-old Finnish man accused of hacking a psychotherapy clinic, stealing more than 22,000 patients' therapy notes, demanding ransom payments from them and also leaking this very private info on a Tor website.…

  • February 8th 2023 at 06:30

Eurocops shut down Exclu encrypted messaging app, arrest dozens

German and Dutch authorities say the app was a favorite of organized criminals and drug smugglers

An encrypted messaging service that has been on law enforcement's radar since a 2019 raid on an old NATO bunker has been shut down after a sweeping series of raids across Europe last week. …

  • February 7th 2023 at 07:30

Embarrassment as US cyber ambassador's Twitter account is hacked

'Perils of the job' we're told

A top US cyber diplomat said his Twitter account was compromised over the weekend.…

  • February 6th 2023 at 23:59

Here's a list of proxy IPs to help block KillNet's DDoS bots

Put pro-Putin bots on the do not call list

A free tool aims is helping organizations defend against KillNet distributed-denial-of-service (DDoS) bots and comes as the US government issued a warning that the Russian cybercrime gang is stepping up its network flooding attacks against hospitals and health clinics.…

  • February 6th 2023 at 21:00

Trust, not tech, is holding back a safer internet

Excuse me, citizen, did you packet this data yourself?

Opinion The tech sector is failing at cybersecurity. Global spending on the stuff is at $190 billion a year, a quarter of the US defense budget. That hasn't stemmed an estimated $7 trillion in annual cybercriminal damages. People are fond of saying that the Wild West days of the internet are over, but on those numbers an 1875 Dodge City bank vault looks like Fort Knox.…

  • February 6th 2023 at 09:30

School laptop auction devolves into extortion allegation

Also: Atlassian says Jira has a 9.4 severity bug and the TSA issues milquetoast no-fly list security advisory

When a Texas school district sold some old laptops at auction last year, it probably didn't expect to end up in a public legal fight with a local computer repair shop – but a debate over what to do with district data found on the liquidated machines has led to precisely that.…

  • February 6th 2023 at 07:32

Ransomware scum launch wave of attacks on critical, but old, VMWare ESXi vuln

You’ve had almost two years to patch and some of the software is EOL, now attackers dΓ©ployer un ranΓ§ongiciel

France's Computer Emergency Response Team has issued a Bulletin D'Alerte regarding a campaign to infect VMware’s ESXI hypervisor with ransomware.…

  • February 6th 2023 at 06:30

Have we learnt nothing from SolarWinds supply chain attacks? Not yet it appears

From frameworks to new federal offices it's time to get busy

The hack of SolarWinds' software more than two years ago pushed the threat of software supply chain attacks to the front of security conversations, but is anything being done?.…

  • February 5th 2023 at 12:00

Iran crew stole Charlie Hebdo database, says Microsoft

Same gang pestered US voters during 2020 presidential election

Microsoft believes the gang who boasted it had stolen and leaked more than 200,000 Charlie Hebdo subscribers' personal information is none other than a Tehran-backed criminal group.…

  • February 4th 2023 at 08:45

HeadCrab bots pinch 1,000+ Redis servers to mine coins

We devoting full time to floating under /etc

A sneaky botnet dubbed HeadCrab that uses bespoke malware to mine for Monero has infected at least 1,200 Redis servers in the last 18 months.…

  • February 4th 2023 at 00:27

Fast-evolving Prilex POS malware can block contactless payments

... forcing users to insert their cards into less-secure PIN systems

The reasons businesses and consumers like contactless payment transactions – high security and speed – are what make those systems bad for cybercriminals.…

  • February 3rd 2023 at 20:25

Guy accused of wrecking crypto exchange now hauled into court

Mango Markets still offline for now ... but v4 comeback release looms

The man accused of bringing down decentralized crypto exchange Mango Markets through market manipulation has made his first appearance in court in connection with the theft of millions in cryptocurrency.…

  • February 3rd 2023 at 19:30

Another RAC staffer nabbed for storing, sharing car crash data

Once is an accident. Twice is coincidence. Surely there won't be a third for roadside assistance biz

A former employee of RAC, one of Britain's major roadside recovery service operators, has pleaded guilty to data theft after he stored traffic accident information on his personal device that was passed onto claims companies.…

  • February 3rd 2023 at 11:30

Chinese surveillance balloon over US causes fearful gasbagging

Floats over missile silos, shooting it down ruled more dangerous than whatever it's up to

Updated A Chinese high-altitude spy balloon, spotted drifting over America, has caused concern about national security – though the US Department of Defense says it will not be shot down by F22s at this time.…

  • February 3rd 2023 at 05:32

LockBit brags it pumped ION full of ransomware

Crims put a February 4 deadline for software slinger to pay up

UK regulators are investigating a cyberattack against financial technology firm ION, while the LockBit ransomware gang has threatened to publish the stolen data on February 4 if the software provider doesn't pay up.…

  • February 3rd 2023 at 07:30

Former Ubiquiti dev pleads guilty in data theft and extortion case

Nickolas Sharp now faces up to 35 years in prison

A former Ubiquiti Networks employee accused of hatching an elaborate plot to first steal nearly $2 million from his employer, extort more, then later orchestrating a smear campaign against the company pleaded guilty to multiple felony charges Thursday.…

  • February 3rd 2023 at 01:30

Malvertising attacks are distributing .NET malware loaders

The campaign illustrates another option for miscreants who had relied on Microsoft macros

Malvertising attacks are being used to distribute virtualized .NET loaders that are highly obfuscated and dropping info-stealer malware.…

  • February 2nd 2023 at 19:27

Super Bock says 'cyber' nasty 'disrupting computer services'

Portugal's biggest exporter of beer warns of restrictions to supply chain

Super Bock Group, Portugal's largest beverage biz, is warning of potential interruption to supplies as it manages the fallout from cybercrooks attacking its tech infrastructure.…

  • February 2nd 2023 at 11:15

Google boosts bounties for open source flaws found via fuzzing

Max reward per project integration is now $30k

Google sweetened the potential pot to $30,000 for bug hunters in its open source OSS-Fuzz code testing project.…

  • February 1st 2023 at 23:01

Microsoft sweeps up after breaking .NET with December security updates

XPS doc display issues fixed – until the next patch, at least

Microsoft this week rolled out fixes to issues caused by security updates released in December 2022 that botched how XPS documents are displayed in various versions of .NET and .NET Framework.…

  • February 1st 2023 at 18:59

Attackers abuse Microsoft’s 'verified publisher' status to steal data

Malicious OAuth apps were the tickets into victims' systems

Miscreants using malicious OAuth applications abused Microsoft's "verified publisher" status to gain access to organizations' cloud environments, then steal data and pry into to users' mailboxes, calendars, and meetings.…

  • February 1st 2023 at 06:30

Microsoft upgrades Defender to lock down Linux gear for its own good

Ballmer thought this kernel was cancer, Nadella may disagree

Organizations using Microsoft's Defender for Endpoint will now be able to isolate Linux devices from their networks to contain intrusions and whatnot.…

  • January 31st 2023 at 20:45

New year, new storage challenge

How to keep unstructured data secure

Webinar If your IT team is making new year resolutions, one of them might be to ramp up safeguarding measures for the increasing amount of unstructured data being captured by businesses and organizations.…

  • January 31st 2023 at 13:01

Amid FTX's burning wreckage, Japan outpost promises asset withdrawals in February

Well what do you know – plenty of hard-nosed regulation by central authorities actually protected investors

Collapsed crypto exchange FTX's Japanese outpost has told customers it will permit them to withdraw assets in February.…

  • January 31st 2023 at 05:29

South Korea makes crypto crackdown a national justice priority

It's listed alongside issues like tackling gang violence, drugs, and sex crimes

South Korea's Ministry of Justice will create a "Virtual Currency Tracking System" to crack down on money laundering facilitated by cryptocurrencies, and rated the establishment of the facility among its priorities for the year.…

  • January 31st 2023 at 04:28

Chromebook SH1MMER exploit promises admin jailbreak

Schools' laptops are out if this one gets around, tho beware bricking

Users of enterprise-managed Chromebooks now, for better or worse, have a way to break the shackles of administrative control through an exploit called SHI1MMER.…

  • January 30th 2023 at 22:45

The wages of sin aren't that great if you're a developer choosing the dark side

Salary report shows OKish pay, plus the possibility of getting ripped off and the whole prison thing

Malware developers and penetration testers are in high demand across dark web job posting sites, with a few astonishing - but mostly average - wages.…

  • January 30th 2023 at 21:45
❌