FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Another zero-click Apple spyware maker just popped up on the radar again

Pegasus, pssh, you so 2000-and-late

Malware reportedly developed by a little-known Israeli commercial spyware maker has been found on devices of journalists, politicians, and an NGO worker in multiple countries, say researchers. …

  • April 12th 2023 at 00:42

April Patch Tuesday: Ransomware gangs already exploiting this Windows bug

Plus Google, SAP, Adobe and Cisco emit fixes

Microsoft patched 97 security flaws today for April's Patch Tuesday including one that has already been found and exploited by miscreants attempting to deploy Nokoyawa ransomware.…

  • April 11th 2023 at 23:04

Azure admins warned to disable shared key access as backdoor attack detailed

The default is that sharing is caring as Redmond admits: 'These permissions could be abused'

A design flaw in Microsoft Azure – that shared key authorization is enabled by default when creating storage accounts – could give attackers full access to your environment, according to Orca Security researchers.…

  • April 11th 2023 at 13:00

40% of IT security pros say they've been told not to report a data leak

Plus: KFC, Pizza Hut owner spills more beans on ransomware hit... latest critical flaws... and more

In Brief More than 40 percent of surveyed IT security professionals say they've been told to keep network breaches under wraps despite laws and common decency requiring disclosure.…

  • April 11th 2023 at 09:37

How much to infect Android phones via Google Play store? How about $20k

Or whatever you managed to haggle with these miscreants

If you want to sneak malware onto people's Android devices via the official Google Play store, it may cost you about $20,000 to do so, Kaspersky suggests.…

  • April 10th 2023 at 23:01

Inside FTX: Jokes about misplaced funds, diabolical IT, poor oversight, and worse

How's the saying go? $50m here, $50m there, pretty soon you're talking real money

The liquidators picking over the remains of FTX have released their first formal report into Sam Bankman-Fried's imploded empire – and it somehow appears things are worse than feared.…

  • April 10th 2023 at 21:43

Apple squashes iOS, macOS zero-day bugs already exploited by snoops

Keep calm and install patches before abuse becomes widespread

Apple rolled out patches on Good Friday to its iOS, iPadOS, and macOS operating systems and the Safari web browser to address vulnerabilities found by Google and Amnesty International that were exploited in the wild.…

  • April 10th 2023 at 21:01

Google to kill Dropcam, Nest Secure hardware next year

Great, more company for Stadia, Duo and pals in the graveyard

Owners of Dropcam security cameras and Nest Secure systems have been given an unwelcome deadline from Google: their smart home products will be shut off April 8 next year.…

  • April 10th 2023 at 18:58

Microsoft, Fortra are this fed up with cyber-gangs abusing Cobalt Strike

Oh, sure, let's play a game of legal and technical whack-a-mole

Microsoft and Fortra are taking legal and technical actions to thwart cyber-criminals from using the latter company's Cobalt Strike software to distribute malware.…

  • April 10th 2023 at 16:29

When it comes to technology, securing your future means securing your present

How to build cyber resiliency in the face of complexity

Sponsored Feature Most economies and business sectors are dealing with extreme volatility and economic uncertainty. Even as the dislocation caused by the pandemic three years ago looked to be settling down, business leaders have had to contend with geopolitical concerns, rising interest rates, and surging inflation.…

  • April 10th 2023 at 13:58

MSI hit in cyberattack, warns against installing knock-off firmware

1.5TB of databases, source code, BIOS tools said to be stolen

Owners of MSI-brand motherboards, GPUs, notebooks, PCs, and other equipment should exercise caution when updating their device's firmware or BIOS after the manufacturer revealed it has recently suffered a cyberattack.…

  • April 7th 2023 at 23:26

Welcome to open source, Elon. Your Twitter code just got a CVE for shadow ban bug

Plus: Substack shanked by bitter Twitter?

The chunk of internal source code Twitter released the other week contains a "shadow ban" vulnerability serious enough to earn its own CVE, as it can be exploited to bury someone's account of sight "without recourse."…

  • April 7th 2023 at 19:12

It's this easy to seize control of someone's Nexx 'smart' home plugs, garage doors

Netizens urged to disconnect kit after 40,000-plus devices found riddled with dumb bugs

A handful of bugs in Nexx's smart home devices can be exploited by crooks to, among other things, open doors, power off appliances, and disable alarms. More than 40,000 of these gadgets in residential and commercial properties are said to be vulnerable after the manufacturer failed to act.…

  • April 7th 2023 at 11:00

With ICMP magic, you can snoop on vulnerable HiSilicon, Qualcomm-powered Wi-Fi

WPA stands for will-provide-access, if you can successfully exploit a target's setup

A vulnerability identified in at least 55 Wi-Fi router models can be exploited by miscreants to spy on victims' data as it's sent over a wireless network.…

  • April 7th 2023 at 07:30

CAN do attitude: How thieves steal cars using network bus

It starts with a headlamp and fake smart speaker, and ends in an injection attack and a vanished motor

Automotive security experts say they have uncovered a method of car theft relying on direct access to the vehicle's system bus via a smart headlamp's wiring.…

  • April 6th 2023 at 10:34

Criminal records office yanks web portal offline amid 'cyber security incident'

ACRO says payment data safe, other info may have been snaffled

ACRO, the UK's criminal records office, is combing over a "cyber security incident" that forced it to pull its customer portal offline.…

  • April 6th 2023 at 08:30

Cops cuff teenage 'Robin Hood hacker' suspected of peddling stolen info

Luxury cars and designer duds don't seem very prince of thieves

Spanish cops have arrested a 19-year-old suspected of stealing records belonging to half a million taxpayers and developing a database to sell stolen information to other cyber criminals.…

  • April 6th 2023 at 07:33

Cops put the squeeze on Genesis crime souk denizens, not just the admins this time

Feds managed to image entire backend server with full details

The FBI today released additional information about its takedown of the Genesis Market, a major online shop for stolen account access credentials, revealing that they'd pwned the marketplace for at least two years.…

  • April 5th 2023 at 21:45

Microsoft tells admins to autoreview your Autopatch alerts or autolose the service

And you wouldn't want that ... would you?

Microsoft is updating a service introduced last year that shifts the responsibility of patching Windows devices from IT admins to the vendor itself.…

  • April 5th 2023 at 11:15

Notorious stolen credential warehouse Genesis Market seized by FBI

Operation Cookie Monster crumbles stolen data-as-a-service vendor

A notorious source of stolen credentials, genesis.market, has had its website seized by the FBI.…

  • April 5th 2023 at 06:30

Feds seize $112m in cryptocurrency linked to 'pig-butchering' finance scams

Thieves go nose-to-tail stripping cash from victims

The US Department of Justice has seized cryptocurrency worth about $112 million from accounts linked to so-called pig butchering investment scams.…

  • April 4th 2023 at 23:00

Can ChatGPT bash together some data-stealing code? With the right prompts, sure

But nothing a keen beginner couldn't do, anyway

A Forcepoint staffer has blogged about how he used ChatGPT to craft some code that exfiltrates data from an infected machine. At first, it sounds bad, but in reality, it's nothing an intermediate or keen beginner programmer couldn't whack together themselves anyway.…

  • April 4th 2023 at 22:00

UK data watchdog fines TikTok Β£12.7M for failing to protect kids

Some 1.4 million under-13s used the app in 2020 by the ICO's estimates

Fresh off the back of an embarrassing "grilling" by US Congress on national security grounds, TikTok has received a more concrete reprimand from the UK's Information Commissioner's Office (ICO) – a fine of Β£12.7 million ($15.8 million) for "misusing children's data."…

  • April 4th 2023 at 13:42

Bank rewrote ads for infosec jobs to stop scaring away women

Blokes happily bluffed; women played it by the book, leaving the bank struggling to hire

Australia's Westpac bank re-wrote its job ads for infosec roles after finding the language it used deterred female candidates.…

  • April 4th 2023 at 05:37

Hey Siri, use this ultrasound attack to disarm a smart-home system

We speak to the boffins behind latest trick to fool Google Assistant, Cortana, Alexa

Academics in the US have developed an attack dubbed NUIT, for Near-Ultrasound Inaudible Trojan, that exploits vulnerabilities in smart device microphones and voice assistants to silently and remotely access smart phones and home devices.…

  • April 4th 2023 at 00:59

Uber driver info stolen yet again: This time from law firm

Never mind software supply chain attacks, lawyers are the new soft target?

Uber has had more of its internal data stolen from a third party that suffered a security breach. This time, the personal info of the app's drivers was swiped by miscreants from the IT systems of law firm Genova Burns.…

  • April 3rd 2023 at 20:27

April brings tulips, taxes ... and phisherfolk scammers

Tactical#Octopus: Don't let users click on that zip file

The last few days of America's tax season are stressful enough, dealing with deadlines and, increasingly, online scams. Now comes another one, a sophisticated and ongoing phishing campaign by a threat group dubbed "Tactical#Octopus" that is using tax-related lures to spread malware.…

  • April 3rd 2023 at 18:39

Capita: Cyber-attack broke some of our IT systems

Staff regain access to Microsoft apps, tech outsourcer still working to restore services for some

Capita – everyone's favorite outsourcing badass – is still working to restore services for some customers after admitting the IT outage of certain services on Friday was caused by a cyber attack and efforts to contain the infiltration.…

  • April 3rd 2023 at 15:33

Keeping secrets safe

How to implement robust secret and identity management

Webinar Keeping digital authentication credentials safe is a highly sensitive task in an ever-evolving IT landscape, made more difficult when you consider the ongoing shift from static to dynamic applications aligned with increasingly distributed teams of workers.…

  • April 3rd 2023 at 13:22

Western Digital confirms digital burglary, calls the cops

Thinks info from internal systems 'obtained' by miscreant, unsure of nature or scope data

Western Digital is today dealing with a "network security incident" after detecting a break-in into its internal systems by an unauthorized third party.…

  • April 3rd 2023 at 11:58

3CX thought supply chain attack was a false positive

'It's not unusual for VoIP apps' says CEO

Updated The CEO of VoIP software provider 3CX said his team tested its products in response to alerts of suspicious activity that was later found to be a supply chain attack, and assessed reports of issues with the software as a false positive.…

  • April 3rd 2023 at 07:32

Vietnam threatens to cut off two million mobile subscribers

To scupper scams, account-holders must hand over personal info or else

Almost two million mobile phone subscribers in Vietnam are at risk of having their services severed, thanks to a new government policy that seeks to curb spam.…

  • April 3rd 2023 at 04:33

School principal resigns after writing $100,000 check to Elon Musk impersonator

ALSO: DJI forgets the 'B' in 'BCC,' and this week's critical known exploits

In Brief The principal of a Florida science and technology charter school has resigned after allegedly writing a $100,000 check to an Elon Musk impersonator using school funds.…

  • April 3rd 2023 at 01:58

Ukrainian cops nab suspects accused of stealing $4.3m from victims across Europe

If the price looks too good to be true, it probably is

Ukrainian cops have arrested two suspects and detained 10 others for their alleged roles in a cybercrime gang that used phishing scams and phony online marketplaces to steal more than $4.3 million from over 1,000 victims across Europe.…

  • April 1st 2023 at 07:25

NYPD blues: Cops ignored 93 percent of surveillance law rules

Who watches the watchmen? The Office of the Inspector General

Back in July 2020, then New York City Mayor Bill de Blasio signed the Public Oversight of Surveillance Technology (POST) Act into law, which required the New York Police Department to reveal how it uses surveillance technology and to formulate surveillance policies.…

  • March 31st 2023 at 20:06

Psst! Infosec bigwigs: Wanna be head of security at HM Treasury for Β£50k?

Juicy private sector job vs … money off a season travel ticket

Given the importance of the Treasury department's function to Britain, Reg readers might expect the Head of Cyber Security vacancy currently being advertised would come with a salary that reflects its criticality.…

  • March 31st 2023 at 11:40

NHS Highland 'reprimanded' by data watchdog for BCC blunder with HIV patients

'Serious breach of trust' says ICO, 'stakes too high' for mistakes in cases like this

In a classic email snafu NHS Highland sent messages to 37 patients infected with HIV and inadvertently used carbon copy (CC) instead of Blind Carbon Copy meaning the recipients could see each other’s email addresses.…

  • March 31st 2023 at 09:35

Pro-Russia cyber gang Winter Vivern puts US, Euro lawmakers in line of fire

Winter is coming for NATO countries

A cyber spy gang supporting Russia is targeting US elected officials and their staffers, in addition to European lawmakers, using unpatched Zimbra Collaboration software in two campaigns spotted by Proofpoint.…

  • March 31st 2023 at 07:30

Leaked IT contractor files detail Kremlin's stockpile of cyber-weapons

Snowden-esque 'Vulkan' dossier links Moscow firm to FSB, GRU, SRV

An unidentified whistleblower has provided several media organizations with access to leaked documents from NTC Vulkan – a Moscow IT consultancy – that allegedly show how the firm supports Russia's military and intelligence agencies with cyber warfare tools.…

  • March 31st 2023 at 01:24

Azure blunder left Bing results editable, MS 365 accounts potentially exposed

'BingBang' boo-boo affected other internal Microsoft apps, too

An Azure Active Directory (AAD) misconfiguration by Microsoft in one of its own cloud-hosted applications could have allowed miscreants to subvert the IT giant's Bing search engine – even changing search results.…

  • March 30th 2023 at 23:30

AlienFox malware caught in the cloud hen house

Malicious toolkit targets misconfigured hosts in AWS and Office 365

A fast-evolving toolkit that can be used to compromise email and web hosting services represents a disturbing evolution of attacks in the cloud, which for the most part have previously been confined to mining cryptocurrencies.…

  • March 30th 2023 at 21:30

Do you use comms software from 3CX? What to do next after biz hit in supply chain attack

Miscreants hit downstream customers with infostealers

Two security firms have found what they believe to be a supply chain attack on communications software maker 3CX – and the vendor's boss is advising users to switch to the progressive web app until the 3CX desktop client is updated.…

  • March 30th 2023 at 16:25

Microsoft uses carrot and stick with Exchange Online admins

If you need extra time to dump RPS, OK, but email from unsupported Exchange servers is blocked till they’re up to date

Some Exchange Online users who have the RPS feature turned off by Microsoft can now have it re-enabled – at least until September when the tool is retired.…

  • March 30th 2023 at 14:27

The most important email conversation you will ever have

Securing your business against BEC

Webinar Business email compromise (BEC) is possibly the worst of cybercrimes because it abuses trust. It feeds on relationships carefully nurtured over decades and erodes a confidence which is foundational to cooperation, and progress.…

  • March 30th 2023 at 09:14

Warning: Your wireless networks may leak data thanks to Wi-Fi spec ambiguity

How someone can nab buffered info, by hook or by kr00k

Ambiguity in the Wi-Fi specification has left the wireless networking stacks in various operating systems vulnerable to several attacks that have the potential to expose network traffic.…

  • March 30th 2023 at 06:29

Another year, another North Korean malware-spreading, crypto-stealing gang named

Mandiant identifies 'moderately sophisticated' but 'prolific' APT43 as global menace

Google Cloud's recently acquired security outfit Mandiant has named a new nasty from North Korea: a cyber crime gang it calls APT43 and accuses of a five-year rampage.…

  • March 30th 2023 at 04:40

Smugglers busted sneaking tech into China

'Intel inside' a suspiciously baggy t-shirt gave the game away – as did a truckload of parts

International Talk Like a Pirate Day is still months away – circle September 19 on your calendar, me hearties! – but The Register has found news of technology smuggling in China that suggests a buccaneering approach to imports.…

  • March 30th 2023 at 03:02

Malware disguised as Tor browser steals $400k in cryptocash

Beware of third party downloads

Clipboard-injector malware disguised as Tor browser installers has been used to steal about $400,000 in cryptocurrency from nearly 16,000 users worldwide so far in 2023, according to Kaspersky researchers.…

  • March 30th 2023 at 01:30

Microsoft Defender shoots down legit URLs as malicious

Those hoping to use nefarious websites like, er, Zoom are overrun by alerts. Redmond 'investigating'

Updated Microsoft's at-times-glitchy Defender service is again causing headaches for IT admins by flagging legitimate URLs as malicious.…

  • March 29th 2023 at 18:31

EU mandated messaging platform love-in is easier said than done: Cambridge boffins

Digital Market Act interoperability requirement a social challenge as well as a technical one

By March 2024, instant messaging and real-time media apps operated by large tech platforms in Europe will be required to communicate with other services, per the EU's Digital Markets Act (DMA).…

  • March 29th 2023 at 14:28

FTX cryptovillain Sam Bankman-Fried charged with bribing Chinese officials

Court gives him new rules: Use one laptop, while living with the 'rents.

US authorities have charged FTX co-founder Sam Bankman-Fried (aka SBF) with attempting to bribe Chinese officials with $40 million worth of cryptocurrency in exchange for unfreezing trading accounts.…

  • March 29th 2023 at 10:24

DDoS DNS attacks are old-school, unsophisticated … and they’re back

So why would you handle them on your own?

Sponsored Feature Ransomware may currently be the biggest bogeyman for cybersecurity pros, law enforcement, and governments, but it shouldn't divert us from more traditional, but still very disruptive threats.…

  • March 29th 2023 at 08:34

China urges Apple to improve security and privacy

It's a juicy market that welcomes foreign investment, National development boss reminds Tim Cook

Senior Chinese government officials have urged Apple CEO Tim Cook to improve the security and privacy features of his company's products.…

  • March 29th 2023 at 01:27

Apple patches all the iThings, including iOS 15 hole under attack right now

Issue identified in February but owners of older kit weren't warned

Happy belated Patch Tuesday from Cupertino: Apple has issued security updates for almost every piece of code it slings - including a fix for a vulnerability in older iOS devices the iGiant believes is under attack right now.…

  • March 28th 2023 at 22:16

Google again accused of willfully destroying evidence in Android antitrust battle

Starting to see a pattern here? Judge seems to think so

Updated Google Chat histories handed over by the web giant in ongoing Android antitrust litigation reveal the biz has been systematically destroying evidence, according to those suing the big G.…

  • March 28th 2023 at 20:09

President Biden kind of mostly bans commercial spyware from US govt

Executive order has loopholes for Uncle Sam's snoop tools and American-made code

US president Joe Biden on Monday issued an executive order on the "prohibition on use by the United States government of commercial spyware that poses risks to national security" – a title that is not quite as simple it seems.…

  • March 28th 2023 at 02:45

Lawyers cough up $200k after health data stolen in Microsoft Exchange pillaging

In addition to $100k given to LockBit

New York law firm Heidell, Pittoni, Murphy and Bach (HPMB) has agreed to pay $200,000 to settle a data-breach lawsuit related to the now-notorious Hafnium Microsoft Exchange attacks that siphoned sensitive data from victims around the world. …

  • March 27th 2023 at 22:45

Gone in 120 seconds: Tesla Model 3 child's play for hackers

Plus OIG finds Uncle Sam fibbed over Login.gov

In brief A team of hackers from French security shop Synacktiv have won $100,000 and a Tesla Model 3 after subverting the Muskmobile's entertainment system, and from there opening up the car's core management systems.…

  • March 27th 2023 at 11:32

China crisis is a TikToking time bomb

ByteDance with the devil if you dare

Opinion As country after country bans TikTok from official systems, it’s fair to ask what’s so dodgy about a social network filled with dance crazes, makeup advice and cats.…

  • March 27th 2023 at 09:30

CISA unleashes Untitled Goose Tool to honk at danger in Microsoft's cloud

Not a headline we expected to write today

American cybersecurity officials have released an early-warning system to protect Microsoft cloud users.…

  • March 24th 2023 at 19:16
❌