FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Police pounce on 'pompompurin' – alleged mastermind of BreachForums

Crypto laundering service gets cleaned up by police and SVB mess draws in more criminals

In Brief A man accused of being the head of one of the biggest criminal online souks, BreachForums, has been arrested in Peekskill, New York.…

  • March 20th 2023 at 06:02

TikTok cannot be considered a private company, says Australian report

ALSO: Japan ends chip supply crimp on South Korea, APAC infosec spending surges; Philippines SIM registration stalls

Asia In Brief ByteDance, the Chinese developer of TikTok, "can no longer be accurately described as a private enterprise" and is instead intertwined with China's government, according to a report [PDF] submitted to Australia's Select Committee on Foreign Interference through Social Media.…

  • March 19th 2023 at 23:30

BianLian ransomware crew goes 100% extortion after free decryptor lands

No good deed goes unpunished, or something like that

The BianLian gang is ditching the encrypting-files-and-demanding-ransom route and instead is going for full-on extortion.…

  • March 19th 2023 at 13:37

You've been pwned, how much will each stolen customer SSN cost you? How about $7.5k?

At the very least, with other costs on top

A Florida healthcare group has settled a class-action lawsuit after thieves stole more than 447,000 patients' names, Social Security numbers, and sensitive medical information, from its servers.…

  • March 18th 2023 at 14:02

Google: Turn off Wi-Fi calling, VoLTE to protect your Android from Samsung hijack bugs

Four flaws open mobiles, cars to remote-control at baseband level with just a phone number

Google security analysts have warned Android device users that several zero-day vulnerabilities in some Samsung chipsets could allow an attacker to completely hijack and remote-control their handsets knowing just the phone number.…

  • March 17th 2023 at 20:35

Eufy security cams 'ignore cloud opt-out, store unique IDs' of anyone who walks by

Gadget maker accused of 'corporate voyeurism' by gathering up footage against your wishes

A lawsuit filed against eufy security cam maker Anker Tech claims the biz assigns "unique identifiers" to the faces of any person who walks in front of its devices – and then stores that data in the cloud, "essentially logging the locations of unsuspecting individuals" when they stroll past.…

  • March 17th 2023 at 19:30

Feds arrest and charge exiled Chinese billionaire over massive crypto fraud

This one has it all: Donald Trump’s inner circle, a Beijing bot backlash, conspiracy theories, and more

Meet the newest member of the crypto rogues' gallery: Ho Wan Kwok, aka Guo Wengui, aka Miles Guo, whom the US Department of Justice on Wednesday arrested over what investigators have described as a "sprawling and complex scheme … to solicit investments in various entities and programs through false statements and representations to hundreds of thousands of Kwok's online followers."…

  • March 17th 2023 at 02:59

Here's how Chinese cyber spies exploited a critical Fortinet bug

Looks to be the same baddies attacking VMware hypervisors last year

Suspected Chinese spies have exploited a critical Fortinet bug, and used custom networking malware to steal credentials and maintain network access, according to Mandiant security researchers.…

  • March 17th 2023 at 01:00

FTX inner circle helped itself to $3.2B, liquidators say

SBF alone pocketed $2.2B, or so this bankruptcy paperwork goes

In fresh filings in the FTX bankruptcy case, the cryptocurrency-exchange-slash-hedge-fund's liquidators sayΒ they've uncovered $3.2 billion (Β£2.6b) in payments and loans made to disgraced FTX founder Sam Bankman-Fried and his inner circle. …

  • March 16th 2023 at 22:04

Got Conti? Here's the ransomware cure to avoid paying up

Kaspersky cracks the code, so get busy before the next update comes

Good news for ransomware victims: Kaspersky security researchers say they've cracked the Conti ransomware code and released a decryptor tool after uncovering leaked data belonging to the notorious Russian crime group.…

  • March 16th 2023 at 20:28

UK.gov bans TikTok from its devices as a 'precaution' over spying fears

Gov staff using it on personal mobes just fine... it's not like ministers use WhatsApp etc for business ... oh wait

The United Kingdom government has banned use of Chinese social media platform TikTok among ministers and officials on their work devices as a β€œprecautionary” measure over worries the app is used to snoop on Brits.…

  • March 16th 2023 at 14:34

Hands up who DIDN'T exploit this years-old flaw to ransack a US govt web server...

Why patching matters: Everyone seemingly had a crack at security bug

Multiple criminals, including at least potentially one nation-state group, broke into a US federal government agency's Microsoft Internet Information Services web server by exploiting a critical three-year-old Telerik bug to achieve remote code execution.…

  • March 15th 2023 at 23:00

Cancer patient sues hospital after ransomware gang leaks her nude medical photos

Victim offered two years of credit monitoring after highly sensitive records dumped online

A cancer patient whose nude medical photos and records were posted online after they were stolen by a ransomware gang, has sued her healthcare provider for allowing the "preventable" and "seriously damaging" leak.…

  • March 15th 2023 at 20:05

SVB collapse's mix of money, urgency and uncertainty makes it irresistible to scammers

Phishing, dodgy domain names, and sophisticated attacks already deployed

The collapse of Silicon Valley Bank (SVB) late last week sent tremors through the global financial system, creating opportunities for short-sellers – and numerous species of scammer.…

  • March 15th 2023 at 05:46

China sought control of submarine cables to spy, says Micronesia

Outgoing president alleges Beijing is systematically bullying strategically located island paradise

The outgoing president of the Federated States of Micronesia (FSM), David Panuelo, penned a lengthy letter last week accusing Beijing of rampant bribery, spying and other tactics – including an attempt to take control of the nation's submarine cables and telecoms infrastructure.…

  • March 15th 2023 at 03:29

Microsoft: Patch this severe Outlook bug that Russian miscreants exploited

Plus: Fixes for SAP, Adobe. Android, Chrome

Patch Tuesday Microsoft's March Patch Tuesday includes new fixes for 74 bugs, two of which are already being actively exploited, and nine that are rated critical. Let's start with the two that miscreants found before Redmond issued a fix.…

  • March 14th 2023 at 23:59

Microsoft squashes Windows bug exploited to inflict ransomware misery

Not-so-smart SmartScreen flagged up by Googlers

Criminals are exploiting a Microsoft SmartScreen bug to deliver Magniber ransomware, potentially infecting hundreds of thousands of devices, without raising any security red flags, according to Google's Threat Analysis Group (TAG).…

  • March 14th 2023 at 19:01

India floats idea of dedicated tribunal to handle online offences

Consultation for the long-awaited Digital India Act is finally under way although the draft law's still not been revealed

India's government has started to consult some proposed details of its long-awaited Digital India Act, including a declaration that the bill needed a dedicated adjudicatory tool for offenses committed online.…

  • March 13th 2023 at 07:58

UK refreshes national security plan to stop more of China's secret-stealing cyber-tricks

A threat that needs two orgs to tackle it: the 'Integrated Security Fund' and the 'National Protective Security Authority'

Britain's domestic intelligence service MI5 will oversee a new agency tasked with helping organizations combat Chinese cyber-spies and other threats.…

  • March 14th 2023 at 07:40

LockBit brags: We'll leak thousands of SpaceX blueprints stolen from supplier

And also, Ring hit with ransomware, too? No, says Amazon

Ransomware gang Lockbit has boasted it broke into Maximum Industries, which makes parts for SpaceX, and stole 3,000 proprietary schematics developed by Elon Musk's rocketeers.…

  • March 13th 2023 at 23:40

Zoll Medical says intruders had 1M+ patient, staff records at their fingertips

Names, addresses, SSNs all up for grabs

Medical device and software maker Zoll Medical says the personal and health information of more than a million people, including patients and employees, may have been stolen by crooks in January.…

  • March 13th 2023 at 21:30

CISA joins forces with Women in CyberSecurity to break up the boy's club

Also, the FBI just admitted to bypassing warrants by buying cellphone location data, and this week's actionable items

in brief Cybersecurity and Infrastructure Security Agency's director Jen Easterly has been outspoken in her drive to bring more women into the security industry, and this year for International Women's Day her agency formalized that pledge by announcing a partnership with nonprofit Women in CyberSecurity (WiCyS).…

  • March 13th 2023 at 12:32

The UK's bad encryption law can't withstand global contempt

Any sufficiently stupid technology is indistinguishable from magical thinking

Opinion Around the world, a vital technology is failing. Just as massive solar flares fry satellites and climate-change superstorms overwhelm flood defences, so a new surge of ridiculous IT-related events is burning out irony meters across the globe.…

  • March 13th 2023 at 10:32

Cutting complexity

Ensuring cybersecurity defences do more with less

Webinar It's like living in a fever dream out there in the world of cybersecurity. More and more sophisticated attacks, a tsunami of solutions offering a gilt-edged escape from the need to constantly reconfigure your defences, and relentless pressure to always stay one step ahead of the hackers.…

  • March 13th 2023 at 08:52

Google euthanizes Chrome Cleanup Tool because it no longer has a purpose

Times have changed and unwanted software on Windows is a rarity (unless you count Windows itself)

Google is bidding adieu to an application that enabled Chrome users on Windows systems to get rid of unwanted software.…

  • March 11th 2023 at 00:28

What happens if you 'cover up' a ransomware infection? For Blackbaud, a $3m charge

File under cost of doing business

Blackbaud has agreed to pay $3 million to settle charges that it made misleading disclosures about a 2020 ransomware infection in which crooks stole more than a million files on around 13,000 of the cloud software slinger's customers.…

  • March 10th 2023 at 22:05

Electronics market shows US-China decoupling will hike inflation and slow growth

Singapore's central bank has a gloomy vision of the future

According to the Monetary Authority of Singapore (MAS), trade barriers between US and China have resulted in geoeconomic fragmentation and will likely result in slower global growth and higher inflation.…

  • March 10th 2023 at 18:00

Acronis downplays intrusion after 12GB trove leaks online

Cyber-thief said goal was to 'humiliate' data-protection biz

The CISO of Acronis has downplayed what appeared to be an intrusion into its systems, insisting only one customer was affected, using stolen credentials, and that all other data remains safe.…

  • March 10th 2023 at 03:45

Catholic clergy surveillance org 'outs gay priests'

Religious non-profit allegedly hoovered up location data from dating apps to ID clerics

A Catholic clergy conformance organization has reportedly been buying up tracking data from mobile apps to identify gay priests, and providing that information to bishops around America.…

  • March 10th 2023 at 02:30

FBI and international cops catch a NetWire RAT

Malware-seekers were diverted to the Feds, severing a Croatian connection

International law enforcement agencies have claimed another victory over cyber criminals, after seizing the website, and taking down the infrastructure operated by crims linked to the NetWire remote access trojan (RAT).…

  • March 10th 2023 at 01:33

AT&T blames marketing bods for exposing 9M accounts

Says it was old and boring data, so that's OK, then ...

AT&T has confirmed that miscreants had access to nine million of its wireless customers' account details after a vendor's network was broken into in January.…

  • March 9th 2023 at 22:30

US House reps, staff health data swiped in cyber-heist

Data for sale via dark web, Senate in line of fire, too

Health data and other personal information of members of Congress and staff were stolen during a breach of servers run by DC Health Care Link and are now up for sale on the dark web.…

  • March 9th 2023 at 21:27

Refreshed from its holiday, Emotet has gone phishing

Notorious botnet starts spamming again after a three-month pause

Emotet is back. After another months-long lull since a spate of attacks in November 2022, the notorious malware operation that has already survived a law enforcement takedown and various periods of inactivity began sending out malicious emails on Tuesday morning.…

  • March 9th 2023 at 18:27

Suspected Chinese cyber spies target unpatched SonicWall devices

They've been lurking in networks since at least 2021

Suspected Chinese cyber criminals have zeroed in on unpatched SonicWall gateways and are infecting the devices with credential-stealing malware that persists through firmware upgrades, according to Mandiant.…

  • March 9th 2023 at 02:26

Dems, Repubs eye up ban on chat apps they don't like

Clock is ticking for TikTok and other foreign natter-ware

On Tuesday a bipartisan group of a dozen US senators introduced a bill to authorize the Commerce Department to ban information and communications technology products and services deemed threats to national security.…

  • March 9th 2023 at 01:28

Securing ways to share workplace passwords

Keeper protects your team’s credentials without slowing down business

Sponsored Feature When the first computer system passwords were set in 1961, few people needed to carry personal credentials to get through daily life. Nowadays, login credentials are ubiquitous across nearly every application, software and web service.…

  • March 8th 2023 at 09:30

Boeing signs off design of anti-jamming tech that keeps satellites online

China and Russia won't be jammin' US sats no more

Boeing said on Tuesday its anti-jam ground-based satellite communications system had passed the necessary tests to validate its design for use in the U.S. Space Force’s Pathfinder program.…

  • March 8th 2023 at 06:27

Aussie tech worker payroll scheme operators found guilty of tax fraud

Contractors left hanging while principals splurged on luxury goods

Three of the principals of an Australian scheme that offered free payroll services to tech contractors have been found guilty of conspiring to defraud the Commonwealth and conspiring to deal with the proceeds of crime.…

  • March 8th 2023 at 04:04

Acer confirms server intrusion after miscreant offers 160GB cache of stolen files

Customer info safe, or so we're told

Acer has confirmed someone broke into one of its servers after a miscreant put up for sale a 160GB database of what's claimed to be the Taiwanese PC maker's confidential information.…

  • March 8th 2023 at 01:12

Alert: Crims hijack these DrayTek routers to attack biz

Workaround: Throw away kit? Hope there's a patch?

If you're still using post-support DrayTek Vigor routers it may be time to junk them, see if they can be patched, or come up with some other workaround, as a malware variant is setting up shop in the kit.…

  • March 8th 2023 at 00:01

Pro-Putin scammers trick politicians and celebrities into low-tech hoax video calls

Who needs deepfakes when you've got makeup and 'element of surprise'?

Pro-Russian scammers using social engineering and impersonation to trick prominent western commentators into conducting recorded video calls have kicked these campaigns "into high gear" over the past 12 months, according to security researchers.…

  • March 7th 2023 at 10:01

EPA orders US states to check cyber security of public water supplies

Don’t let miscreants poison the wells

The US government is requiring states to assess the cyber security capabilities of their drinking water systems, part of the White House's broader efforts to protect the nation's critical infrastructure from attacks by nation-states and other cyber threats.…

  • March 6th 2023 at 22:45

DoppelPaymer ransomware suspects cuffed, alleged ringleaders escape

Millions extorted from victims, one attack left hospital patient dead

German and Ukrainian cops have arrested suspected members of the DoppelPaymer ransomware crew and issued warrants for three other "masterminds" behind the global operation that extorted tens of millions of dollars and may have led to the death of a hospital patient.…

  • March 6th 2023 at 21:45

Where are the women in cyber security? On the dark side, study suggests

Also, Royal ransomware metastasizes to other critical sectors, and this week's critical vulnerabilities

In Brief If you can't join them, then you may as well try to beat them – at least if you're a talented security engineer looking for a job and you happen to be a woman. …

  • March 6th 2023 at 03:01

Secret Service, ICE break the law over and over with fake cell tower spying

Investigations 'at risk' from sloppy surveillance uncovered by audit probe

The US Secret Service and Immigration and Customs Enforcement (ICE) agencies have failed to follow the law and official policy regarding the use of cell-site simulators, according to a government audit.…

  • March 4th 2023 at 01:00

Snap CISO: I rate software supply chain risk 9.9 out of 10

'Understanding your inventory is absolutely No. 1' he tells The Reg

SCSW On a scale of 1 to 10, 10 being the highest risk, Snap Chief Information Security Officer Jim Higgins rates software supply chain risk "about 9.9."…

  • March 4th 2023 at 00:01

FTC: BetterHelp pushed users to share mental health info then gave it to Facebook

Feds propose $7.8M payment and ban on revealing 'sensitive' data to settle complaint

Even if you don't know anyone who has used BetterHelp's services, podcast fans will recognize it from its annoying adverts for its online therapists. American regulators, however, allege the company's relationship with the advertising industry is more perverse than a mere irritating jingle, claiming it betrayed loyalties that should lie with customers by passing on their mental health info to Facebook, Snapchat and others.…

  • March 3rd 2023 at 21:30

Frankenstein malware stitched together from code of others disguised as PyPI package

Crime-as-a-service vendors mix and match components as needed by client

A malicious package discovered in the Python Package Index (PyPI) is the latest example of what threat hunters from Kroll called the continued "democratization of cybercrime," with the bad guys creating malware variants from the code of others.…

  • March 3rd 2023 at 18:30

Warning on SolarWinds-like supply-chain attacks: 'They're just getting bigger'

Industry hasn't 'improved much at all' Mandiant's Eric Scales tells us

SCSW Back in 2020, Eric Scales led the incident response team investigating a state-backed software supply-chain attack that compromised application build servers and led to infections at government agencies and tech giants including Microsoft and Intel.…

  • March 3rd 2023 at 11:33

German Digital Affairs Committee hearing heaps scorn on Chat Control

Proposal to break encryption to scan messages for abuse material challenged as illegal and unworkable

Europe's proposed "Chat Control" legislation to automatically scan chat, email, and instant message communications for child sexual exploitation material (CSEM) ran up against broad resistance at a meeting of the German Parliament's (Bundestag) Digital Affairs Committee on Wednesday.…

  • March 3rd 2023 at 10:34

Smart security

Outlawing cybersecurity hype

Webinar Trying to keep on top of all the hype and complexity in cybersecurity can be more than an just an uphill struggle and more like a veritable mountain to climb every morning.…

  • March 3rd 2023 at 10:15

Pushers of insecure software in Biden's crosshairs

Just-revealed US cybersecurity strategy 'has fangs' for catching crafty criminals and crummy coders

Analysis Technology providers can expect more regulations, while cyber criminals can look for US law enforcement to step up their efforts to disrupt ransomware gangs and other illicit activities, under the Biden administration's computer security plan announced on Thursday.…

  • March 3rd 2023 at 00:15

CI/CD: Necessary for modern software development, yet it carries a lot of risk

With great speed comes great insecurity

SCSW CI/CD over the past decade has become the cornerstone of modern software development.…

  • March 2nd 2023 at 23:10

Intruder alert: WH Smith hit by another cyber attack

Less than a year after Funky Pigeon leaked data of greetings cards biz

Less than a year after its online greetings card subsidiary Funky Pigeon was attacked, WH Smith has admitted someone broke into its systems.…

  • March 2nd 2023 at 13:27

Forget ChatGPT, the most overhyped security tool is technology itself, Wiz warns

Infosec also needs to widen its talent pool or miss out

Interview It's a tough economy to ask for a bigger security team or larger budget to buy technology to protect against cyberattacks. …

  • March 2nd 2023 at 08:30

It's official: BlackLotus malware can bypass Secure Boot on Windows machines

The myth 'is now a reality'

BlackLotus, a UEFI bootkit that's sold on hacking forums for about $5,000, can now bypass Secure Boot, making it the first known malware to run on Windows systems even with the firmware security feature enabled.…

  • March 1st 2023 at 21:30

PlugX RAT masquerades as legit Windows debugger to slip past security

DLL side-loading does the trick, again

Cybercriminals are disguising the PlugX remote access trojan as a legitimate open-source Windows debugging tool to evade detection and compromise systems.…

  • March 1st 2023 at 07:30

Google: You get crypto, you get crypto, almost everyone gets email crypto!

Personal Gmail users still out of luck

Google continued its client-side encryption rollout, the feature generally available to some Gmail and Calendar users who can now send and receive encrypted messages and meeting invites.…

  • March 1st 2023 at 01:38

US government sets a 30-day deadline for wiping TikTok from feds' phones

Last chance to film yourself doing a ByteDance, in the US and abroad

The White House has ordered all federal government employees to delete TikTok from work devices, over fears the video-sharing app could be used to spy on Americans. …

  • March 1st 2023 at 00:30

US cybersecurity chief: Software makers shouldn't lawyer their way out of security responsibilities

Who apart from Microsoft is happy with the ship now, oh just fix it later approach?

SCSW What's more dangerous than Chinese spy balloons? Unsafe software and other technology products, according to America's Cybersecurity and Infrastructure Agency (CISA) Director Jen Easterly.…

  • February 28th 2023 at 22:32
❌