FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

An important system on project [REDACTED] was all [REDACTED] up

Luckily, [REDACTED] was there to save the day

Who Me? Welcome once again to the horrors of Monday, dear reader. But fear not – The Register is here to cushion the blow of the working week's resumption with a instalment of Who, Me?, our reader-contributed stories of tech gone awry.…

  • May 15th 2023 at 07:30

Ransomware corrupts data, so backups can be faster and cheaper than paying up

Smash and grab raids don’t leave time for careful encryption

Ransomware actors aim to spend the shortest amount of time possible inside your systems, and that means the encryption they employ is shoddy and often corrupts your data. That in turn means restoration after paying ransoms is often a more expensive chore than just deciding not to pay and working from our own backups.…

  • May 15th 2023 at 06:32

Arm acknowledges side-channel attack but denies Cortex-M is crocked

Spectre-esque exploit figures out when interesting info might be in memory

Black Hat Asia Arm issued a statement last Friday declaring that a successful side attack on its TrustZone-enabled Cortex-M based systems was "not a failure of the protection offered by the architecture."…

  • May 15th 2023 at 05:36

Toyota's bungling of customer privacy is becoming a pattern

Also: 3D printing gun mods = jail time; France fines Clearview AI for ignoring fine; this week's critical vulns, and more

in brief Japanese automaker Toyota has admitted yet again to mishandling customer data – this time saying it exposed information on more than two million Japanese customers for the past decade, thanks to a misconfigured cloud environment. …

  • May 15th 2023 at 02:26

'Top three Balkans drug kingpins' arrested after cops crack their Sky ECC chats

Maybe try carrier pigeons instead

European police arrested three people in Belgrade described as "the biggest" drug lords in the Balkans in what cops are chalking up to another win in dismantling Sky ECC's encrypted messaging app last year.…

  • May 13th 2023 at 07:14

Why Microsoft just patched a patch that squashed an under-attack Outlook bug

Let's take a quick dive into Windows API

Microsoft in March fixed an interesting security hole in Outlook that was exploited by miscreants to leak victims' Windows credentials. This week the IT giant fixed that fix as part of its monthly Patch Tuesday update.…

  • May 12th 2023 at 23:17

Ex-Ubiquiti dev jailed for 6 years after stealing internal corp data, extorting bosses

Momentary lapse in VPN led to stretch in the cooler, $1.6m bill

Nickolas Sharp has been sentenced to six years in prison and ordered to pay almost $1.6 million to his now-former employer Ubiquiti – after stealing gigabytes of corporate data from the biz and then trying to extort almost $2 million from his bosses while posing as an anonymous hacker.…

  • May 12th 2023 at 20:28

Britain's largest private pension scheme reveals scale of Capita break-in

USS says burgled biz reckons data on 470,000 'active, deferred and retired' members may have been accessed

Universities Superannuation Scheme, the UK’s largest private pension provider, says Capita has warned that details of almost half a million members were held on servers accessed during the recent breach.…

  • May 12th 2023 at 16:59

Activists gatecrash Capita's AGM to protest GPS tracking contract

Outsourcer asked to take 'principled stance'

We hear Privacy International and a few other campaign groups set up camp outside Capita's AGM in London yesterday protesting Capita's involvement as an outsourcer in a UK government GPS tracking contract.…

  • May 12th 2023 at 10:36

UK cops score legal win in EncroChat snooping op

But tribunal punts on whether data was intercepted in transit

The UK's National Crime Agency has partially won an important legal battle in a case that challenged the warrants used to obtain messages from cyber crook hangout EncroChat.…

  • May 12th 2023 at 06:08

India to send official whassup to WhatsApp after massive spamstorm

In a weird way, we can blame this on AI being a better bet than blockchain

India's IT minister Rajeev Chandrasekhar will ask WhatsApp to explain what's up, after the Meta-owned messaging service experienced a dramatic increase in spam calls.…

  • May 12th 2023 at 01:57

Let white-hat hackers stick a probe in those voting machines, say senators

HAVA go at breaking electronic ballot box security

US voting machines would undergo deeper examination for computer security holes under proposed bipartisan legislation.…

  • May 11th 2023 at 21:35

Millions of mobile phones come pre-infected with malware, say researchers

The threat is coming from inside the supply chain

Black Hat Asia Miscreants have infected millions of Androids worldwide with malicious firmware before the devices even shipped from their factories, according to Trend Micro researchers at Black Hat Asia.…

  • May 11th 2023 at 17:58

ENISA leans into EU-based clouds with draft cybersecurity label

Time for AWS and pals to start thinking about JVs?

Cloud services providers that aren't based in Europe β€”Β like the Big Three β€” may have to team up with a cloud that is operated and maintained from the EU if they want ENISA's stamp of approval for handling sensitive data.…

  • May 11th 2023 at 12:44

Sonatype axes 14 percent of staff, reminds them not to talk to the press

Workers slam 'horrendous' handling of layoffs that left even 'engineering managers in the dark'

Exclusive Software supply chain management biz Sonatype has laid off 14 percent of its global workforce, according to internal documents seen by The Register.…

  • May 10th 2023 at 20:38

Twitter adds new DM features, and Musk claims encryption is here, starting today

We'll believe our DMs are secure when someone provides proof, thanks

Updated Twitter has rolled out some quality of life updates for direct messages on the platform, and CEO Elon Musk reckons the site is to start encrypting DMs, beginning today, without providing proof that's the case.…

  • May 10th 2023 at 16:55

What should protection for your 365 data really look like?

Don't let the cyber-criminals spread through your enterprise

Sponsored Microsoft 365 has worked its way into so many facets of our organizations that it can be hard to imagine what life would be like without it.…

  • May 10th 2023 at 14:12

23-year-old Brit linked to 2020 Twitter attack and SIM-swap scheme pleads guilty

Admits to cyberstalking, wire fraud charges as Feds take $700k off him

A 23-year-old British citizen has confessed to "multiple schemes" involving computer crimes, including playing a part in the July 2020 Twitter attack that saw the accounts of Amazon CEO Jeff Bezos, Kanye West, and former President Barack Obama hijacked by an unidentified crew.…

  • May 10th 2023 at 12:32

Capita looking at a bill of Β£20M over breach clean-up costs

Analyst says expense 'no small drop in ocean' but reputational damage could be 'far greater'

Britain's leaky outsourcing behemoth Capita is warning investors that the clean-up bill for its recent digital break-in will cost up to Β£20 million ($25.24 million).…

  • May 10th 2023 at 11:00

Japan's ubiquitous convenience stores now serving up privacy breaches

Fujitsu in the frame for foul up with government document dispersal app

Japan's minister for digital transformation and digital reform, Taro Kono, has apologized after a government app breached citizens' privacy.…

  • May 10th 2023 at 03:31

Two Microsoft Windows bugs under attack, one in Secure Boot with a manual fix

On the plus side, this month's update batch is a bit smaller than usual

Patch Tuesday May's Patch Tuesday brings some good and some bad news, and if you're a glass-half-full type, you'd lead off with Microsoft's relatively low number of security fixes: a mere 38.…

  • May 9th 2023 at 23:15

FBI-led Op Medusa slays NATO-bothering Russian military malware network

Perseus to the rescue as Snake eats itself

The FBI has cut off a network of Kremlin-controlled computers used to spread the Snake malware which, according to the Feds, has been used by Russia's FSB to steal sensitive documents from NATO members for almost two decades.…

  • May 9th 2023 at 20:28

Microsoft disarms push notification bombers with number matching in Authenticator

Mandatory measure against attackers who spam MFA folks into submission

Microsoft is hoping to curb a growing threat to multi-factor authentication (MFA) by enforcing a number-matching step for those using Microsoft Authenticator push notifications when signing into services.…

  • May 9th 2023 at 19:45

EU proposes spyware Tech Lab to keep Big Brother governments in check

Potential roles for IT pros and lawyers, European city location included

Tired of working for an egomaniacal startup boss or dull enterprise biz? A new org has been proposed called the Tech Lab, where you'd investigate the worst kinds of surveillance by governments on their citizens. In which despotic state, you ask? Surprise! You could base yourself in any European city.…

  • May 9th 2023 at 16:40

Beijing raids consultancy, State-sponsored media warns more to come

Retaliation or national security?

Beijing sent a message to foreign businesses this week when it launched an investigation into Shanghai-based Capvision Partners on the grounds of national security, accusing the consultancy firm of failure to prevent espionage.…

  • May 9th 2023 at 07:40

FYI: Intel BootGuard OEM private keys leak from MSI cyber heist

Plus: Court-ordered domain seizures of DDoS-for-hire sites

Updated Intel is investigating reports that BootGuard private keys, used to protect PCs from hidden malware, were leaked when data belonging to Micro-Star International (MSI) was stolen and dumped online. …

  • May 9th 2023 at 02:27

Western Digital: Customer info stolen in that IT attack

Hard times for buyers of these hard drives

Customer information was stolen from the IT systems of Western Digital in the March security breach we've previously reported, forcing the storage manufacturer to shut down its online store until at least next week.…

  • May 8th 2023 at 23:01

WordPress plugin hole puts '2 million websites' at risk

XSS marks the spot

WordPress users with the Advanced Custom Fields plugin on their website should upgrade after the discovery of a vulnerability in the code that could open up sites and their visitors to cross-site scripting (XSS) attacks.…

  • May 8th 2023 at 22:22

Twitter admits 'security incident' made private Circles not so much

Perhaps one of the thousands of people laid off from the biz could have fixed it, just a thought

Twitter has finally admitted a "security incident" caused some users' semi-private Twitter Circle tweets to show up on others' timelines.…

  • May 8th 2023 at 21:18

Modern Auth comes to on-prem Exchange Server gear

Guess this'll have to do while we wait for *checks notes* ES 2025

Microsoft last year said that it was putting off the next version of Exchange Server until the second half of 2025 so engineers could continue bulking up the security of a product that has become a popular target of cybercriminals.…

  • May 8th 2023 at 16:15

T-Mobile US suffers second data theft within months

Also, Capita's buckets are leaking, ransomware attackers deliver demands via emergency alert, and this week's critical vulns

in brief We'd say you'll never guess which telco admitted to a security breakdown last week, but you totally will: T-Mobile US, and for the second time (so far) this year.…

  • May 8th 2023 at 04:31

DEF CON to set thousands of hackers loose on LLMs

Can't wait to see how these AI models hold up against a weekend of red-teaming by infosec's village people

This year's DEF CON AI Village has invited hackers to show up, dive in, and find bugs and biases in large language models (LLMs) built by OpenAI, Google, Anthropic, and others.…

  • May 6th 2023 at 17:20

Dump these insecure phone adapters because we're not fixing them, says Cisco

Security hole ranks 9.8 out of 10 in severity, 0 out of 10 in patch availability

There is a critical security flaw in a Cisco phone adapter, and the business technology giant says the only step to take is dumping the hardware and migrating to new kit.…

  • May 5th 2023 at 21:04

A right Royal pain in the Dallas: City IT systems crippled by ransomware

Texas officials preach limited government ... but not this limited

The city of Dallas, Texas, is working to restore city services following a ransomware attack that crippled its IT systems.…

  • May 5th 2023 at 19:19

Capita admits some pension data 'likely' to have been accessed in March breach

Weeks after outsourcer admits 'cyber incident' more warnings issued

Capita is telling pension customers that some data contained within its systems was potentially accessed when criminals broke into the outsourcing giant's tech infrastructure earlier this year.…

  • May 5th 2023 at 11:57

Users complain over UK state-owned bank's services as Atos eyes the exit

National Savings & Investment contracting for massive tech deals as customers complain of 2FA failure

Updated The UK National Savings and Investment bank is being bombarded with complaints over failing online security and authentication features which customers say have locked them out of their accounts.…

  • May 5th 2023 at 08:30

China labels USA 'Empire of hacking' based on old Wikileaks dumps

Pot, meet kettle, both containing weak sauce

The National Computer Virus Emergency Response Center of China and local infosec outfit 360 Total Security have conducted an investigation called "The Matrix" that found the CIA conducts offensive cyber ops, and labelled the United States an "Empire of Hacking".…

  • May 5th 2023 at 02:32

Ex-Uber CSO gets probation for covering up theft of data on millions of people

Exec begged judge for leniency – and it worked

Joe Sullivan won't serve any serious time behind bars for his role in covering up Uber's 2016 computer security breach and trying to pass off a ransom payment as a bug bounty.…

  • May 4th 2023 at 23:20

Strike three: FTC says Meta still failing to protect user privacy

Deals between Zuckercorp + FTC in 2012 and 2020 are being ignored, so time to get stricter, says commish

The US Federal Trade Commission is preparing to take action against Facebook parent company Meta for a third time over claims it failed to protect user privacy, as required under a 2020 agreement Meta made with the regulator.…

  • May 4th 2023 at 16:08

Go ahead, forget that password. Use a passkey instead, says Google

'But they're gonna take my thumbs' hits different in 2023

Google wants to take us further into a passwordless future by allowing personal account holders to login using passkeys rather than using passphrases and multifactor authentication (MFA).…

  • May 4th 2023 at 00:32

Meta does the 'We found baddies and crushed them' thing again – this time for AI

Who would have thought crims would try using Facebook to fool people?

Meta says it has shut down over 1,000 links related to ChatGPT that lead its users to malware, as criminals seek to profit from the current craze for generative AI.…

  • May 3rd 2023 at 23:59

Insurers can't use 'act of war' excuse to avoid Merck's $1.4B NotPetya payout

'The get-out-of-jail-free card option has been removed' as one expert put it

Merck's insurers can't use an "act of war" clause to deny the pharmaceutical giant an enormous payout to clean up its NotPetya infection, a court has ruled.…

  • May 3rd 2023 at 21:22

Chrome's HTTPS padlock heads to Google Graveyard

As blue check marks start showing up in Gmail

Logowatch Google plans to retire the padlock icon that appears in the Chrome status bar during a secure HTTPS web browsing session because the interface graphic has outlived its usefulness.…

  • May 3rd 2023 at 20:03

The importance of being certified

New GIAC Security Professional and revamped GIAC Security Expert qualifications offer increased choice and flexibility for cybersecurity pros

Sponsored Post The importance of certifications such as the GIAC (Global Information Assurance Certification) has never been greater for infosec professionals. Because adding them to the CV will not only improve individual skill levels, but also differentiate candidates in an increasingly competitive cyber security industry.…

  • May 3rd 2023 at 03:20

Apple pushes first-ever 'rapid' patch – and rapidly screws up

Maybe you're just installing it wrong?

Apple on Monday pushed to some iPhones and Macs its first-ever rapid security fix.…

  • May 2nd 2023 at 23:30

Mirai botnet loves exploiting your unpatched TP-Link routers, CISA warns

Oracle and Apache holes also on Uncle Sam's list of big bad abused bugs

The US government's Cybersecurity and Infrastructure Security Agency (CISA) is adding three more flaws to its list of known-exploited vulnerabilities, including one involving TP-Link routers that is being targeted by the operators of the notorious Mirai botnet.…

  • May 2nd 2023 at 22:45

Apple, Google propose anti-stalking spec for Bluetooth tracker tags

We moved fast and broke things, people got harassed and murdered, so let's revisit privacy

Apple and Google have come together to develop an industry specification to prevent "unwanted tracking," otherwise known as stalking, via Bluetooth location tracking tags.…

  • May 2nd 2023 at 21:00

288 arrested in multinational Monopoly Market takedown

US tells criminals it 'will find you' and has a particular set of skills

In an international operation 288 people have been arrested across the US, Europe and South America after allegedly selling opioids on the now-shuttered Monopoly Market dark web drug trafficking marketplace, according to US and European law enforcement.…

  • May 2nd 2023 at 19:55

In the face of data disaster

How to recover from cyber attacks on Microsoft 365

Webinar Every organization needs a full set of data recovery tools. The sort that will get you back up and running quickly after a ransomware attack, outage, or accidental data deletion. And it's best to be prepared in advance rather than deal with the data disaster face to face when it happens.…

  • May 2nd 2023 at 14:14

Data loss costs are going up – and not just for those who choose to pay thieves

Ransoms, investigations, and breach-related lawsuits are hitting companies in the wallet, law firm says

Data loss – particularly from ransomware attacks – has always been a costly proposition for enterprises. However, the price organizations have to pay is going up, not only in terms of the ransom demanded but also for the cost of investigating attacks and the lawsuits that increasingly follow in the wake of such breaches.…

  • May 2nd 2023 at 10:41

Russia's APT28 targets Ukraine government with bogus Windows updates

Nasty emails designed to infect systems with info-stealing malware

The Kremlin-backed threat group APT28 is flooding Ukrainian government agencies with email messages about bogus Windows updates in the hope of dropping malware that will exfiltrate system data.…

  • May 2nd 2023 at 06:37

Feds rethink warrantless search stats and – oh look, a huge drop in numbers

119,000 instances of homeland snooping as the power to do so comes under review

Warrantless searches of US residents' communications by the FBI dropped sharply last year – from about 3.4 million in 2021 to 119,383 in 2022, according to Uncle Sam.…

  • May 2nd 2023 at 01:56

IT giant Bitmarck shuts down customer, internal systems after cyberattack

Patient data 'was and is never endangered', says medical tech slinger

German IT services provider Bitmarck has shut down all of its customer and internal systems, including entire datacenters in some cases, following a cyberattack. …

  • May 1st 2023 at 18:55

Centralized secrets management picks up pace

How cloud migration and machine identities are fueling enterprise demand for secrets management systems

Sponsored Feature There's no question that fast-feedback software delivery offers multiple advantages by streamlining processes for developers. But in software development, as in life, there is no such thing as a free lunch.…

  • May 1st 2023 at 14:08

Google adds account sync for Authenticator, without E2EE

Also: Your Salesforce Community site might be leaking; a new CPU side-channel; and this week's critical vunls

in brief You may have heard news this week that Google is finally updating its authenticator app to add Google account synchronization. Before you rush to ensure your two-factor secrets are safe in the event you lose your device, take heed: The sync process isn't end-to-end encrypted.…

  • May 1st 2023 at 11:04

Your security failure was so bad we have to close the company … NOT!

There are pranks, and savage pranks, and this prank when the CTO and HR ganged up on a very stressed techie

Who, Me? Welcome once again, gentle reader, to the safe space we call Who, Me? in which Reg readers can confess to the naughty or not-quite-competent things they did at work, knowing they will not be judged.…

  • May 1st 2023 at 07:31

China has 50 hackers for every FBI cyber agent, says Bureau boss

Combatting it is going to take more money. Lots of more money.

China has 50 hackers for every one of the FBI's cyber-centric agents, the Bureau's director told a congressional committee last week.…

  • May 1st 2023 at 02:32

Online Safety Bill age checks? We won't do 'em, says Wikipedia

World's encyclopedia warns draft law could boot it offline in UK

Wikipedia won't be age-gating its services no matter what final form the UK's Online Safety Bill takes, two senior folks from nonprofit steward the Wikimedia Foundation said this morning.…

  • April 28th 2023 at 14:30

Google sues CryptBot slingers, gets court order to shut down malware domains

Hands off those Chrome users, they're ours!

Google said it obtained a court order to shut down domains used to distribute CryptBot after suing the distributors of the info-stealing malware.…

  • April 27th 2023 at 23:04

Microsoft is busy rewriting core Windows code in memory-safe Rust

Now that's a C change we can back

Microsoft is rewriting core Windows libraries in the Rust programming language, and the more memory-safe code is already reaching developers.…

  • April 27th 2023 at 20:45
❌