FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

In the face of data disaster

How to recover from cyber attacks on Microsoft 365

Webinar Every organization needs a full set of data recovery tools. The sort that will get you back up and running quickly after a ransomware attack, outage, or accidental data deletion. And it's best to be prepared in advance rather than deal with the data disaster face to face when it happens.…

  • May 2nd 2023 at 14:14

Data loss costs are going up – and not just for those who choose to pay thieves

Ransoms, investigations, and breach-related lawsuits are hitting companies in the wallet, law firm says

Data loss – particularly from ransomware attacks – has always been a costly proposition for enterprises. However, the price organizations have to pay is going up, not only in terms of the ransom demanded but also for the cost of investigating attacks and the lawsuits that increasingly follow in the wake of such breaches.…

  • May 2nd 2023 at 10:41

Russia's APT28 targets Ukraine government with bogus Windows updates

Nasty emails designed to infect systems with info-stealing malware

The Kremlin-backed threat group APT28 is flooding Ukrainian government agencies with email messages about bogus Windows updates in the hope of dropping malware that will exfiltrate system data.…

  • May 2nd 2023 at 06:37

Feds rethink warrantless search stats and – oh look, a huge drop in numbers

119,000 instances of homeland snooping as the power to do so comes under review

Warrantless searches of US residents' communications by the FBI dropped sharply last year – from about 3.4 million in 2021 to 119,383 in 2022, according to Uncle Sam.…

  • May 2nd 2023 at 01:56

IT giant Bitmarck shuts down customer, internal systems after cyberattack

Patient data 'was and is never endangered', says medical tech slinger

German IT services provider Bitmarck has shut down all of its customer and internal systems, including entire datacenters in some cases, following a cyberattack. …

  • May 1st 2023 at 18:55

Centralized secrets management picks up pace

How cloud migration and machine identities are fueling enterprise demand for secrets management systems

Sponsored Feature There's no question that fast-feedback software delivery offers multiple advantages by streamlining processes for developers. But in software development, as in life, there is no such thing as a free lunch.…

  • May 1st 2023 at 14:08

Google adds account sync for Authenticator, without E2EE

Also: Your Salesforce Community site might be leaking; a new CPU side-channel; and this week's critical vunls

in brief You may have heard news this week that Google is finally updating its authenticator app to add Google account synchronization. Before you rush to ensure your two-factor secrets are safe in the event you lose your device, take heed: The sync process isn't end-to-end encrypted.…

  • May 1st 2023 at 11:04

Your security failure was so bad we have to close the company … NOT!

There are pranks, and savage pranks, and this prank when the CTO and HR ganged up on a very stressed techie

Who, Me? Welcome once again, gentle reader, to the safe space we call Who, Me? in which Reg readers can confess to the naughty or not-quite-competent things they did at work, knowing they will not be judged.…

  • May 1st 2023 at 07:31

China has 50 hackers for every FBI cyber agent, says Bureau boss

Combatting it is going to take more money. Lots of more money.

China has 50 hackers for every one of the FBI's cyber-centric agents, the Bureau's director told a congressional committee last week.…

  • May 1st 2023 at 02:32

Online Safety Bill age checks? We won't do 'em, says Wikipedia

World's encyclopedia warns draft law could boot it offline in UK

Wikipedia won't be age-gating its services no matter what final form the UK's Online Safety Bill takes, two senior folks from nonprofit steward the Wikimedia Foundation said this morning.…

  • April 28th 2023 at 14:30

Google sues CryptBot slingers, gets court order to shut down malware domains

Hands off those Chrome users, they're ours!

Google said it obtained a court order to shut down domains used to distribute CryptBot after suing the distributors of the info-stealing malware.…

  • April 27th 2023 at 23:04

Microsoft is busy rewriting core Windows code in memory-safe Rust

Now that's a C change we can back

Microsoft is rewriting core Windows libraries in the Rust programming language, and the more memory-safe code is already reaching developers.…

  • April 27th 2023 at 20:45

Microsoft probes complaints of Edge leaking URLs to Bing

Remember next time Redmond begs you not to install another browser

You might want to think twice before typing anything into Microsoft's Edge browser, as an apparent bug in a recent release of Redmond's Chromium clone appears to be funneling URLs you visit back to the Bing API.…

  • April 26th 2023 at 21:08

DoJ, Treasury accuses 3 men of laundering crypto for North Korea

If the DPRK is named, you know it somehow involves Lazarus Group

The US government is aggressively pursuing three men accused of wide-ranging and complex conspiracies of laundering stolen and illicit cryptocurrency that the North Korean regime used to finance its massive weapons programs.…

  • April 26th 2023 at 18:44

The good, the bad and the generative AI

ChatGPT is just the beginning: CISOs need to prepare for the next wave of AI-powered attacks

Sponsored Feature Change in the tech industry is usually evolutionary, but perhaps more interesting are the exceptions to this rule – the microprocessor in 1968, the IBM PC in 1981, the web in 1989, the smartphone in 2007. These are the technologies whose appearance began new eras that completely reshaped the industry around them.…

  • April 26th 2023 at 08:32

Apache Superset: A story of insecure default keys, thousands of vulnerable systems, few paying attention

Two out of three public-facing app instances open to hijacking

Apache Superset until earlier this year shipped with an insecure default configuration that miscreants could exploit to login and take over the data visualization application, steal data, and execute malicious code.…

  • April 25th 2023 at 22:35

Menaced by miscreants, critical infrastructure needs a good ETHOS. Ah, here's one

OT firms construct handy early-warning info-sharing system

RSA Conference A group of some of the largest operational technology companies are using this year's RSA Conference as an opportunity to launch an open source early-threat-warning system designed for OT and industrial control systems (ICS) environments. …

  • April 25th 2023 at 20:10

How fiends abuse an out-of-date Microsoft Windows driver to infect victims

It's like those TV movies where a spy cuts a wire and the whole building's security goes out

Ransomware spreaders have built a handy tool that abuses an out-of-date Microsoft Windows driver to disable security defenses before dropping malware into the targeted systems.…

  • April 24th 2023 at 11:30

That 3CX supply chain attack keeps getting worse: Other vendors hit

Also, Finland sentences CEO of breach company to prison (kind of), and this week's laundry list of critical vulns

In Brief We thought it was probably the case when the news came out, but now it's been confirmed: The X_Trader supply chain attack behind the 3CX compromise last month wasn't confined to the telco developer.…

  • April 24th 2023 at 03:27

Chinese scientists calculate the Milky Way's mass as 805 billion times that of our Sun

ALSO: Australia says offensive hacking is working; DJI hit with $279m patent suit; Philippines Police leak data; and more

Asia In Brief Chinese scientists have estimated the mass of the Milky Way.…

  • April 24th 2023 at 00:29

European air traffic control confirms website 'under attack' by pro-Russia hackers

Another cyber nuisance in support of Putin's war, nothing too serious

Europe's air-traffic agency appears to be the latest target in pro-Russian miscreants' attempts to disrupt air travel.…

  • April 22nd 2023 at 07:09

Microsoft pushes for more women in cybersecurity

Redmond tops industry average, still got a way to go

Microsoft has partnered with organizations around the globe to bring more women into infosec roles, though the devil is in the details.…

  • April 21st 2023 at 22:03

International cops urge Meta not to implement secure encryption for all

Why? Well, think of the children, of course

An international group of law enforcement agencies are urging Meta not to standardize end-to-end encryption on Facebook Messenger and Instagram, which they say will harm their ability to fight child sexual abuse material (CSAM) online.…

  • April 21st 2023 at 10:28

Healthcare organisations urged to improve system security

Patient data covering sensitive areas has long been a high-value target for cybercriminals

Sponsored Post Digital patient medical records now cover a whole gamut of sensitive details such as clinical diagnoses/treatments, prescriptions, personal finances and insurance policies. Which makes keeping them safe more important than ever.…

  • April 21st 2023 at 08:35

Thanks for fixing the computer lab. Now tell us why we shouldn’t expel you?

Guessing the admin password is cool. Using it, even for good, is dangerous

On Call It’s always twelve o’clock somewhere, the saying goes, but Friday comes around but once a week and only this day does The Register offer a fresh instalment of On Call, our reader-contributed tales of tech support torture and turmoil.…

  • April 21st 2023 at 06:32

Capita has 'evidence' customer data was stolen in digital burglary

Admits criminals accessed 4% of servers from March 22 until it spotted them at month-end

Business process outsourcing and tech services player Capita says there is proof that some customer data was scooped up by cyber baddies that broke into its systems late last month.…

  • April 20th 2023 at 13:29

An earlier supply chain attack led to the 3CX supply chain attack, Mandiant says

Threat hunters traced it back to malware-laced Trading Technologies' software

The supply-chain attack against 3CX last month was caused by an earlier supply-chain compromise of a different software firm β€” Trading Technologies β€” according to Mandiant, whose consulting crew was hired by 3CX to help the VoIP biz investigate the intrusion.…

  • April 20th 2023 at 12:00

AI defenders ready to foil AI-armed attackers

Operational AI cybersecurity systems have been gaining valuable experience that will enable them to defend against AI-armed opponents.

Sponsored Feature For some time now, alerts concerning the utilisation of AI by cybercriminals have been sounded in specialist and mainstream media alike – with the set-to between AI-armed attackers and AI-protected defenders envisaged in vivid gladiatorial terms.…

  • April 20th 2023 at 08:34

Protect the Industrial Control Systems (ICS)

ICS security is fast becoming a frontline defense against hackers intent on causing mayhem

Sponsored Post Some of the most famous cyber attacks in history have been directed against Industrial Control Systems (ICS).…

  • April 20th 2023 at 08:08

Medusa ransomware crew brags about spreading Bing, Cortana source code

'Does have a somewhat Lapsus$ish feel' we're told

The Medusa ransomware gang has put online what it claims is a massive leak of internal Microsoft materials, including Bing and Cortana source code.…

  • April 19th 2023 at 23:12

Appeals court spares Google from $20m patent payout over Chrome

Chocolate Factory can afford some staples now, or?

Six years after a jury decided otherwise, Google has convinced an appeals court to reverse a $20 million patent judgment against the web giant.…

  • April 19th 2023 at 22:28

Spyware slinger QuaDream’s reported demise may be the canary in the coal mine

NSO and others are still out there, but pariahs find it hard to do business

Analysis Israeli spyware shop QuaDream is reportedly shutting down due to financial troubles.…

  • April 19th 2023 at 20:20

GitHub debuts pedigree check for npm packages via Actions

Publishing provenance possibly prevents problems

Developers who use GitHub Actions to build software packages for the npm registry can now add a command flag that will publish details about the code's origin.…

  • April 19th 2023 at 16:00

Prioritize what matters most

How to manage your cloud and container vulnerabilities at scale

Webinar There's nothing complicated about the statistics released in Sysdig's latest report. They're alarming and should keep many an IT team up at night.…

  • April 19th 2023 at 09:34

US citizens charged with pushing pro-Kremlin disinfo, election interference

Also a bunch of Russians plus someone giving free trips to the Motherland

Four US citizens have been accused of working on behalf of the Russian government to push pro-Kremlin propaganda and unduly influence elections in Florida.…

  • April 18th 2023 at 23:35

Russian snoops just love invading unpatched Cisco gear, America and UK warn

Spying on foreign targets? That's our job!

The UK and US governments have sounded the alarm on Russian intelligence targeting unpatched Cisco routers to deploy malware and carry out surveillance.…

  • April 18th 2023 at 20:45

Microsoft opens up Defender threat intel library with file hash, URL search

Surprised there's no ChatGPT angle and that it's not called MalwareTotal

Security researchers and analysts can now search Microsoft's Threat Intelligence Defender database using file hashes and URLs when pulling together information for network intrusion investigations and whatnot.…

  • April 18th 2023 at 19:30

Payments firm accused of aiding 'contact Microsoft about a virus' scammers must cough $650k

'My computer locked up and a siren went off,' one mark tells Better Business Bureau

Updated Two execs and a multinational payment processing company must pay $650k to the US government, says the FTC, which accuses them of knowingly processing credit card payments for Microsoft-themed support scammers.…

  • April 18th 2023 at 18:34

Brit cops rapped over app that recorded 200k phone calls

Officers didn't know software was saving personal data and neither did people on other end

Several police forces in Britain are being put on the naughty step by the UK's data watchdog for using a calling app that recorded hundreds of thousands of phone conversations and illegally retained that data.…

  • April 18th 2023 at 13:38

Wrong time to weaken encryption, UK IT chartered institute tells government

Plus: Signal, WhatsApp, and Viber also write online protest over Online Safety Bill back door

The UK’s chartered institute for IT has slammed proposed legislation that could see the government open a β€œback door” to encrypted messaging.…

  • April 18th 2023 at 11:27

Capita IT breach gets worse as Black Basta claims it's now selling off stolen data

No worries, outsourcer only handles government tech contracts worth billions

Black Basta, the extortionists who claimed they were the ones who lately broke into Capita, have reportedly put up for sale sensitive details, including bank account information, addresses, and passport photos, stolen from the IT outsourcing giant.…

  • April 18th 2023 at 07:25

US alleges China created troll army that tried to have dissidents booted from Zoom

Charges laid against 44, including officers of China’s Cyberspace Administration

The United States Department of Justice has charged 44 people over schemes prosecutors allege were run by China’s National Police to silence opponents of the Communist Party of China.…

  • April 18th 2023 at 04:37

Military helicopter crash blamed on failure to apply software patch

A rather nice beach in Australia now briefly hosted an unusual feature

An Australian military helicopter crash was reportedly caused by failure to apply a software patch, with a hefty side serving of pilot error.…

  • April 18th 2023 at 03:30

LockBit crew cooks up half-baked Mac ransomware

Please, no need to fix these problems

LockBit has developed ransomware that can encrypt files on Arm-powered Macs, said to be a first for the prolific cybercrime crew. …

  • April 17th 2023 at 21:30

Marketing biz sent 107 million spam emails... to just 437k people

Recruitment company fined Β£130,000 by data regulator for breaking PECR

A recruitment business that sent out an eye watering 107 million spam emails is now nursing a Β£130,000 ($161,000) fine from Britain’s data watchdog.…

  • April 17th 2023 at 12:45

Firmware is on shaky ground – let's see what it's made of

Old architectures just don't stack up

Opinion Most data theft does clear harm to the victim, and often to its customers. But while embarrassing, the cyberattack against MSI in which source code was said to be stolen is harder to diagnose. It looks like a valuable company asset that's cost a lot to develop. That its theft may be no loss is a weird idea. But then, firmware is weirder than we give it credit for. It's even hard to say exactly what it is.…

  • April 17th 2023 at 09:41

Student requested access to research data. And waited. And waited. And then hacked to get root

The punishment – Windows 98 administration chores – was far worse than the crime

Who, Me? Welcome once more to Who Me? The Register’s confessional column in which readers admit to being the source of SNAFUs.…

  • April 17th 2023 at 07:29

Update now: Google emits emergency fix for zero-day Chrome vulnerability

Also: Tech players spin up white hat protection, this week's critical bugs, and more

In brief Google on Friday released an emergency update for Chrome to address a zero-day security flaw.…

  • April 17th 2023 at 01:15

Russia-pushed UN Cybercrime Treaty may rewrite global law. It's ... not great

Let's go through all the proposed problematic powers, starting with surveillance and censorship

Special report United Nations negotiators convened this week in Vienna, Austria, to formulate a draft cybercrime treaty, and civil society groups are worried.…

  • April 14th 2023 at 23:46

US extradites Nigerian charged over $6m email fraud scam

Maybe our prince has come at last

A suspected Nigerian fraudster is scheduled to appear in court Friday for his alleged role in a $6 million plot to scam businesses via email.…

  • April 14th 2023 at 21:20

Compatibility mess breaks not one but two Windows password tools

Windows LAPS and legacy LAPS don't play nicely under certain conditions, Microsoft says

Integrating the Local Administrator Password Solution (LAPS) into Windows and Windows Server that came with updates earlier this week is causing interoperability problems with what's called legacy LAPS, Microsoft says.…

  • April 14th 2023 at 17:50

While Twitter wants to sell its verification, Microsoft will do it for free on LinkedIn

Redmond expands a digital ID process for its platform as Musk seeks cash for blue check marks

As Elon Musk tears at Twitter's credibility by demanding businesses and individuals pay for their blue verification checks, Microsoft is pushing its own free digital ID tech to companies and their employees on LinkedIn.…

  • April 14th 2023 at 10:14

Linux kernel logic allowed Spectre attack on 'major cloud provider'

Kernel 6.2 ditched a useful defense against ghostly chip design flaw

The Spectre vulnerability that has haunted hardware and software makers since 2018 continues to defy efforts to bury it.…

  • April 14th 2023 at 06:27

To improve security, consider how the aviation world stopped blaming pilots

When admitting to an error isn't seen as a failure, improvement easy to achieve, says pilot-turned-CISO

To improve security, the cybersecurity industry needs to follow the aviation industry's shift from a blame culture to a "just" culture, according to ISACA director Serge Christiaans.…

  • April 14th 2023 at 04:29

Pentagon super-leak suspect cuffed: 21-year-old Air National Guardsman

When bragging about your job on Discord gets just a little out of hand?

The FBI has detained a 21-year-old Air National Guardsman suspected of leaking a trove of classified Pentagon documents on Discord.…

  • April 13th 2023 at 19:52

How insecure is America's FirstNet emergency response system? Seriously, anyone know?

Senator Wyden warns full probe needed into vital comms network

AT&T is "concealing vital cybersecurity reporting" about its FirstNet phone network for first responders and the US military, according to US Senator Ron Wyden (D-OR), who said the network had been dubbed unsafe by CISA.…

  • April 12th 2023 at 23:58

FBI: How fake Xi cops prey on Chinese nationals in the US

δ½ ε₯½ [insert name], ζˆ‘εœ¨ Ministry of Public Security ε·₯作 [insert shakedown]

Criminals posing as law enforcement agents of the Chinese government are shaking down Chinese nationals living the United States by accusing them of financial crimes and threatening to arrest or hurt them if they don't pay, according to the FBI.…

  • April 12th 2023 at 23:26

Mission possible

Tamping down risk in cloud management

Webinar There's nothing like reading a report based on real world data to give IT teams an fresh sense of priority.…

  • April 12th 2023 at 09:21

3CX teases security-focused client update, plus password hashing

As Mandiant finds more evidence it was North Korea wot done it

The CEO of VoIP software provider 3CX has teased the imminent release of a security-focused upgrade to the company’s progressive web application client.…

  • April 12th 2023 at 04:35

US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster

It's not all doom and gloom because ML also amplifies defensive efforts, probably

Bots like ChatGPT may not be able to pull off the next big Microsoft server worm or Colonial Pipeline ransomware super-infection but they may help criminal gangs and nation-state hackers develop some attacks against IT, according to Rob Joyce, director of the NSA's Cybersecurity Directorate.…

  • April 12th 2023 at 01:50
❌