FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Capita staffers told attackers stole data from its own pension fund

Three months after mega breach by Russian cybercrime group

Capita has informed some of its employees that its own pension fund was among the victims of a cybercrime attack on its system, resulting in the theft of their personal details, they say.…

  • July 7th 2023 at 12:11

Nickelodeon probes claims of massive data leak as SpongeBob fans rejoice

TV network's attorneys 'on a DMCA rampage' ... are you sure you're ready, kids?

Nickelodeon says it is probing claims that "decades old" material was stolen from it and leaked online. This follows reports on social media that someone had dumped 500GB of snatched animation files. Hilarity, and many SpongeBob SquarePants memes, ensued.…

  • July 6th 2023 at 22:45

Microsoft puts out Outlook fire, says everything's fine with Teams malware flaw

Redmond's not fixing the latter because it 'relies on social engineering'

Microsoft is having a rough week with troubles including an Outlook.com bug that prevented some email users from searching their messages for several hours on Thursday, and a Teams flaw that allows people to send phishing emails and malware to other Teams users.…

  • July 6th 2023 at 21:20

LockBit louts unload ransomware at Japan’s most prolific cargo port

Nagoya Harbor hit the rocks yesterday but looks to be afloat once more

The port of Nagoya – which shifted 2.68 million shipping containers and 164 million tons of cargo in 2022 – has moved precious few in the last 24 hours after finding itself the latest victim of Russia's notorious LockBit ransomware gang.…

  • July 6th 2023 at 03:13

North Korean satellite had no military utility for spying, says South Korea

Lends credence to theory that Pyongyang is testing ballistic missiles against international rules

A North Korean satellite allegedly designed for reconnaissance was not viable for its alleged intended purpose, according to South Korea's military on Wednesday.…

  • July 6th 2023 at 00:30

Ex-Amazon manager jailed for stealing $10M using fake vendor invoices

Prime doesn't pay – well, not that much, anyway

A now-former Amazon manager described by prosecutors as the "mastermind" behind a nearly $10 million scheme to steal money from the online megaretailer using fake invoices has been sentenced to 16 years behind bars in federal prison.…

  • July 6th 2023 at 00:28

RAM-ramming Rowhammer is back – to uniquely fingerprint devices

Just use it sparingly, as it may crash equipment or burn out memory

Boffins at the University of California, Davis have devised a purportedly practical way to apply a memory abuse technique called Rowhammer to build unique, stable device fingerprints.…

  • July 5th 2023 at 21:14

Suspected bank-infecting OPERA1ER crime boss cuffed

Cops reckon gang swiped as much as $30M from financial orgs

International cops have arrested a suspected "key figure" of a cybercrime group dubbed OPERA1ER that has stolen as much as $30 million from more than 30 banks and financial orgs across 15 countries.…

  • July 5th 2023 at 19:40

Singapore tells crypto operators: act like grown up financial institutions

Digital payment skeptics of the world, unite! You have nothing to lose but grifters and crims

Singapore has joined the ranks of nations requiring digital payment operators to follow the same sort of regulations and customer protection requirements that apply to conventional financial institutions.…

  • July 5th 2023 at 06:24

Undiplomatic Chinese threat actor attacks embassies and foreign affairs departments

Sneaky HTML smuggling signals MustangPanda shift towards Europe, Checkpoint charges

Infosec outfit Checkpoint says it's spotted a Chinese actor targeting diplomatic facilities around Europe.…

  • July 4th 2023 at 05:29

You've patched right? '340K+ Fortinet firewalls' wide open to critical security bug

That's a vulnerability that's under attack, fix available ... cancel those July 4th plans, perhaps?

More than 338,000 FortiGate firewalls are still unpatched and vulnerable to CVE-2023-27997, a critical bug Fortinet fixed last month that's being exploited in the wild.…

  • July 3rd 2023 at 23:17

TSA wants to expand facial recognition to hundreds of airports within next decade

Digital rights folks, as you can imagine, want the tech grounded

America's Transportation Security Agency (TSA) intends to expand its facial-recognition program used to screen US air travel passengers to 430 domestic airports in under a decade.…

  • July 3rd 2023 at 22:12

Dublin Airport staff pay data 'compromised' by criminals

Attackers accessed it via third-party services provider, says management group

It's an awkward Monday for Dublin Airport after pay and benefits details for some 2,000 staff were apparently "compromised" following a recent attack on professional service provider Aon.…

  • July 3rd 2023 at 15:14

US authorities warn on China's new counter-espionage law

Almost anything you download from China could be considered spying, but at least one analyst isn't worried

The United States' National Counterintelligence and Security Center (NCSC) has warned that China's updated Counter-Espionage law – which came into effect on July 1 – is dangerously ambiguous and could pose a risk to global business.…

  • July 3rd 2023 at 06:28

Japan rebukes Fujitsu for cloud security fails

PLUS: Philippines cyber-slave raid; South Korea’s crypto crackdown; AWS boosts Chinese exports; and more

Asia In Brief Japan's government last Friday rebuked Fujitsu for shabby cloud security.…

  • July 3rd 2023 at 01:35

Us, hacked by LockBit? No, says TSMC, that would be our IT supplier

So, uh, who's gonna pay that $70M ransom?

Following claims by ransomware gang LockBit that it has stolen data belonging to TSMC, the chip-making giant has said it was in fact one of its equipment suppliers, Kinmax, that was compromised by the crew, and not TSMC itself.…

  • June 30th 2023 at 23:17

Cops told: Er, no, you need a wiretap order if you want real-time Facebook snooping

Privacy: It's a Jersey Thing

New Jersey cops must apply for a wiretap order β€” not just a warrant β€” for near-continual snooping on suspects' Facebook accounts, according to a unanimous ruling by that US state's Supreme Court. …

  • June 30th 2023 at 19:40

Life long cyber security learning

SANS training courses are scheduled for multiple locations across the EMEA region this Autumn

Sponsored Post Nobody here at is likely to argue with Albert Einstein's idea that "intellectual growth should commence at birth and cease only at death".…

  • June 30th 2023 at 09:01

Quirky QWERTY killed a password in Paris

Quelle tragΓ©die – techie had to visit the city of lights twice to sort this one out

On Call Hard-coded into The Register's week is that each Friday morning you’ll find a new instalment of On Call, our reader contributed tales of tech support troubles.…

  • June 30th 2023 at 07:27

Fujitsu admits it fluffed the fix for Japan’s flaky ID card scheme

Yet another snafu for digital services push

Fujitsu Japan is in the spotlight again for all the wrong reasons, after fumbling its attempt to fix the nation's troubled ID card scheme.…

  • June 30th 2023 at 01:47

Crook who stole $23m+ in YouTube song royalties gets five years behind bars

Claims he wants to stay in the music biz after time in a Sing Sing

One of the two men who admitted stealing more than $23 million in royalty payments for songs played on YouTube has been sentenced to nearly six years behind bars for his role in what prosecutors called "one of the largest music-royalty frauds ever."…

  • June 29th 2023 at 23:38

It's 2023 and memory overwrite bugs are not just a thing, they're still number one

Cough, cough, use Rust. Plus: Eight more exploited bugs added to CISA's must-patch list

The most dangerous type of software bug is the out-of-bounds write, according to MITRE this week. This type of flaw is responsible for 70 CVE-tagged holes in the US government's list of known vulnerabilities that are under active attack and need to be patched, we note.…

  • June 29th 2023 at 20:24

Chinese balloon that US shot down was 'crammed' with American hardware

Blasted from the sky in February, device never transmitted photos, videos, or radar data it collected, officials say

It's been months since "spy balloon" fever gripped the United States, but the headline-grabbing flying object – alleged to have been deployed by China – is back in the news. Preliminary findings from the US inspection of its wreckage show a whole bunch of commercially available hardware made in the States.…

  • June 29th 2023 at 17:03

Now Apple takes a bite out of encryption-bypassing 'spy clause' in UK internet law

Not the iPhone maker's first think-of-the-children rodeo

Apple has joined the rapidly growing chorus of tech organizations calling on British lawmakers to revise the nation's Online Safety Bill – which for now is in the hands of the House of Lords – so that it safeguards strong end-to-end encryption.…

  • June 29th 2023 at 06:40

Network security guy in extradition tug of war between US and Russia

Group-IB spinout confirms Kislitsin is wanted by both Washington and Moscow

A Russian network security specialist and former editor of Hacker magazine who is wanted by the US and Russia on cybercrime charges has been detained in Kazakhstan as the two governments seek his extradition.…

  • June 29th 2023 at 00:58

Miscreants leak texts and info siphoned by Android stalkerware app LetMeSpy

Just as America's Supremes set a high bar for cyberstalking

It's bad enough there's some Android stalkerware out there with the not-at-all-creepy moniker LetMeSpy. Now someone's got hold of the information the app collects – such as victims' text messages and call logs – as well as the email addresses of those who sought out the software, and leaked it all.…

  • June 27th 2023 at 22:22

Cops' total pwnage of 'secure' EncroChat nets 6,500+ arrests, €740m in funds – so far

Or so the Europlod says

Police breaking into and snooping on the EncroChat encrypted messaging network has led to 6,558 arrests worldwide and nearly €740 million seized in criminal funds, according to cops in France and the Netherlands.…

  • June 27th 2023 at 21:23

Warning: JavaScript registry npm vulnerable to 'manifest confusion' abuse

Failure to match metadata with packaged files is perfect for supply chain attacks

The npm Public Registry, a database of JavaScript packages, fails to compare npm package manifest data with the archive of files that data describes, creating an opportunity for the installation and execution of malicious files.…

  • June 27th 2023 at 20:40

Tackling the cyber skills gap with AI

Why the future of cyber security could be fully autonomous where the AI works independently

Sponsored Feature The cybersecurity sector, it is now routinely attested, is in the midst of a long-term skills crisis.…

  • June 27th 2023 at 08:34

Cloud security advice and expertise at your fingertips

Join AWS, Google Cloud, Microsoft Azure, and SANS Institute for the Cloud Security Exchange 2023

Sponsored Post Imagine if you could get instant advice on how to protect your cloud infrastructure against cyber threats from some of the world's best cloud security experts without leaving the comfort of your chair.…

  • June 27th 2023 at 02:46

American and Southwest Airlines pilot candidate data exposed

Time to start practising identity protection

A vendor that operates a pilot recruitment platform used by major airlines exposed the personal files of more than 8,000 pilot and cadet applicants at American Airlines and Southwest Airlines.…

  • June 26th 2023 at 15:29

Ex-FBI employee jailed for taking classified material home

Also: a PII harvest at Dole's server farm, military members mailed mystery smartwatches, and this week's critical vulns

Infosec in brief In a case startlingly similar to charges recently unsealed against one-term US president Donald Trump, a former FBI analyst has been jailed for taking sensitive classified material home with her.…

  • June 26th 2023 at 12:04

JP Morgan accidentally deletes evidence in multi-million record retention screwup

Fined $4m for Who-Me-esque mess, for which it blames unnamed archiving vendor's retention settings

JP Morgan has been fined $4 million by America's securities watchdog, the SEC, for deleting millions of email records dating from 2018 relating to its Chase Bank subsidiary.…

  • June 26th 2023 at 09:30

The unlimited value of a strong defence

How protective AI is a powerful weapon in the fight against cyber attackers using AI for malicious acts.

Webinar In the new age of generative AI, it would be foolhardy to imagine that bad actors won't already be exploiting every opportunity to launch an attack with their own malicious AI generated war machines.…

  • June 26th 2023 at 02:16

Google bug bounties inch closer to Microsoft's payouts

Chocolate Factory paid a record $12m in 2022

Bug hunters who found security holes in Google β€” and also responsibly disclosed details of those flaws to the Chocolate Factory β€” earned more than $12 million in bounty rewards in 2022, marking a record year for the corporation's Vulnerability Reward Programs (VRPs) in terms of payouts and number of vulnerabilities found and fixed.…

  • June 24th 2023 at 14:19

UK cyberspies warn ransomware crews targeting law firms

Nation states will use you to get to your friends, says NCSC

British law practices of "all sizes and types" have been warned by GCHQ's cyberspy arm that their "widespread adoption of hybrid working" combined with the large sums of money they handle is making them a target.…

  • June 23rd 2023 at 12:09

Keep it schtum!

Ensuring communications stay secure

Webinar The explosion in remote working since the pandemic means the number of people doing their job from home has more than doubled in the UK.…

  • June 23rd 2023 at 08:53

Chinese malware intended to infect USB drives accidentally infects networked storage too

Hides itself from popular Asian AV, also uses games to do its dirty work

Malware intended to spread on USB drives is unintentionally infecting networked storage devices, according to infosec vendor Checkpoint.…

  • June 23rd 2023 at 05:31

US cyber ambassador says China knows how to steal its way to dominance of cloud and AI

Calls on governments to combat 'playbook' that propelled Huawei to prominence

China has a playbook to use IP theft to seize leadership in cloud computing, and other nations should band together to stop that happening, according to Nathaniel C. Fick, the US ambassador-at-large for cyberspace and digital policy.…

  • June 23rd 2023 at 03:31

To kill BlackLotus malware, patching is a good start, but...

...that alone 'could provide a false sense of security,' NSA warns in this handy free guide for orgs

BlackLotus, the malware capable of bypassing Secure Boot protections and compromising Windows computers, has caught the ire of the NSA, which today published a guide to help organizations detect and prevent infections of the UEFI bootkit.…

  • June 22nd 2023 at 21:48

Now BlackCat extortionists threaten to leak stolen plastic surgery pics

Sharing a cancer patient's nude snaps earlier wasn't enough for these scumbags

Ransomware gang BlackCat claims it infected a plastic surgery center, stole "lots" of highly sensitive medical records, and has vowed to leak patients' photos if the clinic doesn't pay up.…

  • June 22nd 2023 at 17:57

The Log4j vulnerability – how can we all do better next time?

Accept there are some risks you don’t control but which nonetheless you can’t ignore

Sponsored Feature Friday the 10 of December 2021 is etched in the memory of many IT professionals, but not for reasons they will look back on with fondness. That was the day, just as most American workers were logging off for a long weekend, when a critical vulnerability in an obscure but essential piece of software code first came to widespread attention.…

  • June 22nd 2023 at 08:53

Japan's digital ID card gets emergency review amid data leaks

PM wants response as urgent as that mustered for COVID-19

Japanese prime minister Fumio Kishida has ordered an emergency review of the nation's ID Cards, amid revelations of glitches and data leaks that threaten the government's digital services push.…

  • June 22nd 2023 at 04:45

A clash of titans

Shielding with protective AI from bad actors using AI for cyberattacks

Webinar The one thing a cyber security team can rarely afford to do is relax its vigilance. But count the collective manhours spent on the frontline and the figure starts to look unsustainable, leaving many organizations with little choice but to engage with technology to help defend against malign intent.…

  • June 22nd 2023 at 03:12

A (cautionary) tale of two patched bugs, both exploited in the wild

One affects VMware's monitoring tool and the other TP-Link routers

Miscreants are right now exploiting two security bugs for which patches exist, one in a VMware network and applications monitoring tool and the other in some TP-Link routers.…

  • June 21st 2023 at 23:14

Apple squashes kernel bug used by TriangleDB spyware

Snoops may be targeting macOS in addition to iPhones, Kaspersky says

Whoever is infecting people's iPhones with the TriangleDB spyware may be targeting macOS computers with similar malware, according to Kaspersky researchers.…

  • June 21st 2023 at 20:26

FTC accuses DNA testing company of lying about dumping samples

1Health must strengthen protections for genetic information as part of settlement

The Federal Trade Commission has alleged that genetic testing firm 1Health.io, also known as Vitagene, deceived people when it said it would dispose of their physical DNA sample as well as their collected health data.…

  • June 21st 2023 at 19:30

Training in Spanish for cyber security pros

Sponsored Post Cybercrime is a global phenomenon, but the effectiveness of measures put in place to fight it varies considerably from one region to another.…

  • June 21st 2023 at 13:25

Oreo cookie maker says crooks gobbled up staff info

50K-plus employees' personal info swiped after law firm rolled

Mondelez International has warned 51,000 of its past and present employees that their personal information has been stolen from a law firm hired by the Oreo and Ritz cracker giant.…

  • June 20th 2023 at 21:01

Reddit confirms BlackCat gang pinched some data

Crooks demand $4.5m to keep '80GB' of corp info private – and no API price hikes

Reddit this week confirmed ransomware gang BlackCat, aka AlphaV, broke into its corporate systems in February.…

  • June 20th 2023 at 18:34

Over 100,000 compromised ChatGPT accounts found for sale on dark web

Cybercrooks hoping users have whispered employer secrets to chatbot

UPDATED Singapore-based threat intelligence outfit Group-IB has found ChatGPT credentials in more than 100,000 stealer logs traded on the dark web in the past year.…

  • June 20th 2023 at 10:08

Data leak at major law firm sets Australia's government and elites scrambling

BlackCat attack sparks injunction preventing coverage of purloined docs

An infosec incident at a major Australian law firm has sparked fear among the nation's governments, banks and businesses – and a free speech debate.…

  • June 20th 2023 at 05:04

Guess what happened to this US agency using outdated software?

Also: Hackers target security researchers, MaaS model flourishing, and this week's vulnerabilities

Infosec in brief Remember earlier this year, when we found out that a bunch of baddies including at least one nation-state group broke into a US federal government agency's Microsoft Internet Information Services (IIS) web server by exploiting a critical three-year-old Telerik bug to achieve remote code execution?…

  • June 19th 2023 at 14:32

Outsource to infill on cyber security

Automating, simplifying, and calling in external help can increase the chances of blocking and mitigating attacks

Sponsored Feature Life is tougher than ever for security pros facing a rising tide of cyberattacks. And adversaries are becoming more adept than ever at using diverse methods and technologies to scale up assaults on their selected targets.…

  • June 19th 2023 at 08:35

With dead-time dump, Microsoft revealed DDoS as cause of recent cloud outages

Previous claims its own software updates were the issue remain almost, kinda, plausible

In the murky world of political and corporate spin, announcing bad news on Friday afternoon – a time when few media outlets are watching, and audiences are at a low ebb – is called "taking out the trash." And that’s what Microsoft appears to have done last Friday.…

  • June 19th 2023 at 00:32

Third MOVEit bug fixed a day after PoC exploit made public

Millions of people's personal info swiped, Clop leaks begin with 'Shell's stolen data'

Progress Software on Friday issued a fix for a third critical bug in its MOVEit file transfer suite, a vulnerability that had just been disclosed the day earlier.…

  • June 16th 2023 at 23:05

LockBit suspect's arrest sheds more light on 'trustworthy' gang

Plus: Accused is innocent until proven guilty, but is known to be an Apple fan

FBI agents have arrested a Russian man suspected of being part of the Lockbit ransomware gang. An unsealed complaint alleges the 20-year-old was an Apple fanboy, an online gambler, and scored 80 percent of at least one ransom payment given to the criminals.…

  • June 16th 2023 at 19:01

Capita faces first legal Letter of Claim over mega breach

Barings Law claims 250 people that 'suspect' data theft signed up to class action

Capita is facing its first legal claim over the high profile digital burglary in late March that exposed some customer data to intruders and will cost the outsourcing biz around Β£20 million ($26 million) to clean up.…

  • June 16th 2023 at 13:04

Microsoft: Russia sent its B team to wipe Ukrainian hard drives

WhisperGate-spreading Cadet Blizzard painted as haphazard but dangerous crew

Here's a curious tale about a highly destructive yet flaky Kremlin-backed crew that was active during the early days of Russia's invasion of Ukraine, then went relatively quiet – until this year.…

  • June 16th 2023 at 06:31

EU boss Breton: There's no Huawei that Chinese comms kit is safe to use in Europe

European Commission's own networks to toss Middle Kingdom boxes amid calls for total replacement

European commissioner Thierry Breton wants Huawei and ZTE barred throughout the EU, and revealed plans to remove kit made by the Chinese telecom vendors from the Commission's internal networks.…

  • June 16th 2023 at 00:31
❌