FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Lawyer sees almost 1,000 complainants sign up to Capita breach class action

95% pertain to pension schemes administered by outsourcing giant, says Barings Law

The law firm that last month sent a Letter of Claim to Capita over a security breach in late March says it has signed up nearly 1,000 clients as it prepares a class action lawsuit aimed at the outsourcing giant.…

  • July 21st 2023 at 10:38

MOVEit body count closes in on 400 orgs, 20M+ individuals

'One of the most significant hacks of recent years,' we're told

The number of victims and costs tied to the MOVEit file transfer hack continues to climb as the fallout from the massive supply chain attack enters week seven.…

  • July 20th 2023 at 21:01

RIP Kevin Mitnick: Former most-wanted hacker dies at 59

Tributes paid to husband, father, son and rogue-turned-consultant

Obit Kevin Mitnick, probably the world's most-famous computer hacker – and subsequently writer, public speaker, and security consultant – has succumbed to pancreatic cancer. He was 59.…

  • July 20th 2023 at 18:01

Under CISA pressure collab, Microsoft makes cloud security logs available for free

In hindsight, it's probably good practice to give clients access to cloud logs

Microsoft announced on Wednesday it would provide all customers free access to cloud security logs – a service usually reserved for premium clients – within weeks of a reveal that government officials' cloud-based emails were targets of an alleged China-based hack.…

  • July 20th 2023 at 12:30

Ukraine busts bot farm spreading Russian infowar propaganda and fraud

Plus: Spanish cops arrest Ukrainian scareware dev after ten-year hunt

Ukrainian cops have disrupted a massive bot farm with more than 100 operators allegedly spreading fake news about the Russian invasion, leaking personal information belonging to Ukrainian citizens, and instigating fraud schemes.…

  • July 20th 2023 at 07:30

Tech support scammers go analog, ask victims to mail bundles of cash

The approach is the same, but never mind the crypto or gift cards

Cybercriminals are taking their business offline in a new approach to familiar technical support scams recently identified by the US Federal Bureau of Investigation.…

  • July 19th 2023 at 21:00

INTERSECT '23: Network Security Summit unveils cutting-edge strategies to safeguard digital assets

Palo Alto Networks addresses the mounting challenges posed by sophisticated cyberthreats

Sponsored Post Join Palo Alto Networks at the INTERSECT '23: Network Security Summit, on July 27, 2023 09:00 AM PDT in the Americas and on August 2, 2023, at 10:00 AM CEST in Europe.…

  • July 19th 2023 at 09:45

US adds Euro spyware makers to export naughty list

Predator dev joins Pegasus slinger

The US government on Tuesday added commercial spyware makers Intellexa and Cytrox to its Entity List, saying the duo are a possible threat to national security.…

  • July 18th 2023 at 23:42

Recycling giant TOMRA pulls systems offline following 'extensive cyberattack'

Says baddies launched attack at weekend, isolates parts of tech infrastructure to contain spread

Norwegian mining and recycling giant TOMRA says it has isolated tech systems as it deals with an "extensive cyberattack."…

  • July 18th 2023 at 12:59

Cybercrime – big in Asia Pacific

SANS first DFIR Summit in Asia gives organizations in Asia Pacific an opportunity to build their cyber security expertise

Sponsored Post Kroll's latest State of Incident Response: APAC report suggests that over half of all organizations in Asia Pacific (59 percent) have experienced a cyber incident, of which a third (32 percent) have suffered multiple incidents.…

  • July 18th 2023 at 02:43

Quick: Manually patch this Zimbra bug that's under attack

Smells like Russian cyber spies (again)

A vulnerability in Zimbra's software is being exploited right now by miscreants to compromise systems and attack selected government organizations, experts reckon.…

  • July 17th 2023 at 21:49

Beijing wants to make the Great Firewall of China even greater

Also more fiery, with vague but firm orders to create a 'security barrier'

Over the weekend Chinese president Xi Jinping gave a directive to officials to build a Beijing-supervised "security barrier" around its internet.…

  • July 17th 2023 at 18:28

Boris Johnson pleads ignorance, which just might work

Also: More high-profile MOVEit victims; CVSS 4.0 coming soon; and a long list of critical vulnerabilities

Infosec in brief Former UK prime minister Boris Johnson lobbed a wrench into the works of the country's COVID-19 inquiry by claiming he couldn't remember the passcode to unlock an old phone being sought by investigators.…

  • July 17th 2023 at 02:20

Infosec watchers: TeamTNT crew may blast holes in Azure, Google Cloud users

Why limit yourself to only stealing AWS credentials?

A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.…

  • July 15th 2023 at 08:28

Celsius feels the heat: Ex-CEO arrested, watchdogs line up to sue bankrupt crypto biz

Exec faces fraud charges, one regulator wants $5 billion fine

Alex Mashinsky, the now-former CEO of collapsed cryptocurrency concern Celsius, today faces charges of fraud as prosecutors and watchdogs pile in.…

  • July 13th 2023 at 20:48

Microsoft whips up unrest after revealing Azure AD name change

Ditching it after a decade? Devs warn of the hours to correct documentation and chaos it'll cause

Microsoft is causing a stir among some tech pros after confirming it plans to rename Azure AD to Entra.…

  • July 12th 2023 at 17:02

Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws

Plus: Apple bungles another rapid security response; important ICS updates land; and more

Patch Tuesday Microsoft today addressed 130 CVE-listed vulnerabilities in its products – and five of those bugs have already been exploited in the wild.…

  • July 11th 2023 at 23:26

Barts NHS hack leaves folks on tenterhooks over extortion

BlackCat pounces on 7TB of data and theatens to release it

Staff at one of the UK's largest hospital groups have spent a nervous week wondering if private data, stolen from their employer's IT systems by a ransomware gang, is going to be splurged online after a deadline to prevent publication passed.…

  • July 11th 2023 at 07:32

LibertΓ©, Γ‰galitΓ©, Spyware: France okays cops snooping on phones

ALSO: Shell fails to learn from past leaks; hundreds of solar plants found open to Mirai; and this week's crit vulns

Infosec in brief With riots rocking the country, French parliamentarians have passed a bill granting law enforcement the right to snoop on suspects via "the remote activation of an electronic device without the knowledge or consent of its owner." …

  • July 10th 2023 at 05:33

Capita staffers told attackers stole data from its own pension fund

Three months after mega breach by Russian cybercrime group

Capita has informed some of its employees that its own pension fund was among the victims of a cybercrime attack on its system, resulting in the theft of their personal details, they say.…

  • July 7th 2023 at 12:11

Nickelodeon probes claims of massive data leak as SpongeBob fans rejoice

TV network's attorneys 'on a DMCA rampage' ... are you sure you're ready, kids?

Nickelodeon says it is probing claims that "decades old" material was stolen from it and leaked online. This follows reports on social media that someone had dumped 500GB of snatched animation files. Hilarity, and many SpongeBob SquarePants memes, ensued.…

  • July 6th 2023 at 22:45

Microsoft puts out Outlook fire, says everything's fine with Teams malware flaw

Redmond's not fixing the latter because it 'relies on social engineering'

Microsoft is having a rough week with troubles including an Outlook.com bug that prevented some email users from searching their messages for several hours on Thursday, and a Teams flaw that allows people to send phishing emails and malware to other Teams users.…

  • July 6th 2023 at 21:20

LockBit louts unload ransomware at Japan’s most prolific cargo port

Nagoya Harbor hit the rocks yesterday but looks to be afloat once more

The port of Nagoya – which shifted 2.68 million shipping containers and 164 million tons of cargo in 2022 – has moved precious few in the last 24 hours after finding itself the latest victim of Russia's notorious LockBit ransomware gang.…

  • July 6th 2023 at 03:13

North Korean satellite had no military utility for spying, says South Korea

Lends credence to theory that Pyongyang is testing ballistic missiles against international rules

A North Korean satellite allegedly designed for reconnaissance was not viable for its alleged intended purpose, according to South Korea's military on Wednesday.…

  • July 6th 2023 at 00:30

Ex-Amazon manager jailed for stealing $10M using fake vendor invoices

Prime doesn't pay – well, not that much, anyway

A now-former Amazon manager described by prosecutors as the "mastermind" behind a nearly $10 million scheme to steal money from the online megaretailer using fake invoices has been sentenced to 16 years behind bars in federal prison.…

  • July 6th 2023 at 00:28

RAM-ramming Rowhammer is back – to uniquely fingerprint devices

Just use it sparingly, as it may crash equipment or burn out memory

Boffins at the University of California, Davis have devised a purportedly practical way to apply a memory abuse technique called Rowhammer to build unique, stable device fingerprints.…

  • July 5th 2023 at 21:14

Suspected bank-infecting OPERA1ER crime boss cuffed

Cops reckon gang swiped as much as $30M from financial orgs

International cops have arrested a suspected "key figure" of a cybercrime group dubbed OPERA1ER that has stolen as much as $30 million from more than 30 banks and financial orgs across 15 countries.…

  • July 5th 2023 at 19:40

Singapore tells crypto operators: act like grown up financial institutions

Digital payment skeptics of the world, unite! You have nothing to lose but grifters and crims

Singapore has joined the ranks of nations requiring digital payment operators to follow the same sort of regulations and customer protection requirements that apply to conventional financial institutions.…

  • July 5th 2023 at 06:24

Undiplomatic Chinese threat actor attacks embassies and foreign affairs departments

Sneaky HTML smuggling signals MustangPanda shift towards Europe, Checkpoint charges

Infosec outfit Checkpoint says it's spotted a Chinese actor targeting diplomatic facilities around Europe.…

  • July 4th 2023 at 05:29

You've patched right? '340K+ Fortinet firewalls' wide open to critical security bug

That's a vulnerability that's under attack, fix available ... cancel those July 4th plans, perhaps?

More than 338,000 FortiGate firewalls are still unpatched and vulnerable to CVE-2023-27997, a critical bug Fortinet fixed last month that's being exploited in the wild.…

  • July 3rd 2023 at 23:17

TSA wants to expand facial recognition to hundreds of airports within next decade

Digital rights folks, as you can imagine, want the tech grounded

America's Transportation Security Agency (TSA) intends to expand its facial-recognition program used to screen US air travel passengers to 430 domestic airports in under a decade.…

  • July 3rd 2023 at 22:12

Dublin Airport staff pay data 'compromised' by criminals

Attackers accessed it via third-party services provider, says management group

It's an awkward Monday for Dublin Airport after pay and benefits details for some 2,000 staff were apparently "compromised" following a recent attack on professional service provider Aon.…

  • July 3rd 2023 at 15:14

US authorities warn on China's new counter-espionage law

Almost anything you download from China could be considered spying, but at least one analyst isn't worried

The United States' National Counterintelligence and Security Center (NCSC) has warned that China's updated Counter-Espionage law – which came into effect on July 1 – is dangerously ambiguous and could pose a risk to global business.…

  • July 3rd 2023 at 06:28

Japan rebukes Fujitsu for cloud security fails

PLUS: Philippines cyber-slave raid; South Korea’s crypto crackdown; AWS boosts Chinese exports; and more

Asia In Brief Japan's government last Friday rebuked Fujitsu for shabby cloud security.…

  • July 3rd 2023 at 01:35

Us, hacked by LockBit? No, says TSMC, that would be our IT supplier

So, uh, who's gonna pay that $70M ransom?

Following claims by ransomware gang LockBit that it has stolen data belonging to TSMC, the chip-making giant has said it was in fact one of its equipment suppliers, Kinmax, that was compromised by the crew, and not TSMC itself.…

  • June 30th 2023 at 23:17

Cops told: Er, no, you need a wiretap order if you want real-time Facebook snooping

Privacy: It's a Jersey Thing

New Jersey cops must apply for a wiretap order β€” not just a warrant β€” for near-continual snooping on suspects' Facebook accounts, according to a unanimous ruling by that US state's Supreme Court. …

  • June 30th 2023 at 19:40

Life long cyber security learning

SANS training courses are scheduled for multiple locations across the EMEA region this Autumn

Sponsored Post Nobody here at is likely to argue with Albert Einstein's idea that "intellectual growth should commence at birth and cease only at death".…

  • June 30th 2023 at 09:01

Quirky QWERTY killed a password in Paris

Quelle tragΓ©die – techie had to visit the city of lights twice to sort this one out

On Call Hard-coded into The Register's week is that each Friday morning you’ll find a new instalment of On Call, our reader contributed tales of tech support troubles.…

  • June 30th 2023 at 07:27

Fujitsu admits it fluffed the fix for Japan’s flaky ID card scheme

Yet another snafu for digital services push

Fujitsu Japan is in the spotlight again for all the wrong reasons, after fumbling its attempt to fix the nation's troubled ID card scheme.…

  • June 30th 2023 at 01:47

Crook who stole $23m+ in YouTube song royalties gets five years behind bars

Claims he wants to stay in the music biz after time in a Sing Sing

One of the two men who admitted stealing more than $23 million in royalty payments for songs played on YouTube has been sentenced to nearly six years behind bars for his role in what prosecutors called "one of the largest music-royalty frauds ever."…

  • June 29th 2023 at 23:38

It's 2023 and memory overwrite bugs are not just a thing, they're still number one

Cough, cough, use Rust. Plus: Eight more exploited bugs added to CISA's must-patch list

The most dangerous type of software bug is the out-of-bounds write, according to MITRE this week. This type of flaw is responsible for 70 CVE-tagged holes in the US government's list of known vulnerabilities that are under active attack and need to be patched, we note.…

  • June 29th 2023 at 20:24

Chinese balloon that US shot down was 'crammed' with American hardware

Blasted from the sky in February, device never transmitted photos, videos, or radar data it collected, officials say

It's been months since "spy balloon" fever gripped the United States, but the headline-grabbing flying object – alleged to have been deployed by China – is back in the news. Preliminary findings from the US inspection of its wreckage show a whole bunch of commercially available hardware made in the States.…

  • June 29th 2023 at 17:03

Now Apple takes a bite out of encryption-bypassing 'spy clause' in UK internet law

Not the iPhone maker's first think-of-the-children rodeo

Apple has joined the rapidly growing chorus of tech organizations calling on British lawmakers to revise the nation's Online Safety Bill – which for now is in the hands of the House of Lords – so that it safeguards strong end-to-end encryption.…

  • June 29th 2023 at 06:40

Network security guy in extradition tug of war between US and Russia

Group-IB spinout confirms Kislitsin is wanted by both Washington and Moscow

A Russian network security specialist and former editor of Hacker magazine who is wanted by the US and Russia on cybercrime charges has been detained in Kazakhstan as the two governments seek his extradition.…

  • June 29th 2023 at 00:58

Miscreants leak texts and info siphoned by Android stalkerware app LetMeSpy

Just as America's Supremes set a high bar for cyberstalking

It's bad enough there's some Android stalkerware out there with the not-at-all-creepy moniker LetMeSpy. Now someone's got hold of the information the app collects – such as victims' text messages and call logs – as well as the email addresses of those who sought out the software, and leaked it all.…

  • June 27th 2023 at 22:22

Cops' total pwnage of 'secure' EncroChat nets 6,500+ arrests, €740m in funds – so far

Or so the Europlod says

Police breaking into and snooping on the EncroChat encrypted messaging network has led to 6,558 arrests worldwide and nearly €740 million seized in criminal funds, according to cops in France and the Netherlands.…

  • June 27th 2023 at 21:23

Warning: JavaScript registry npm vulnerable to 'manifest confusion' abuse

Failure to match metadata with packaged files is perfect for supply chain attacks

The npm Public Registry, a database of JavaScript packages, fails to compare npm package manifest data with the archive of files that data describes, creating an opportunity for the installation and execution of malicious files.…

  • June 27th 2023 at 20:40

Tackling the cyber skills gap with AI

Why the future of cyber security could be fully autonomous where the AI works independently

Sponsored Feature The cybersecurity sector, it is now routinely attested, is in the midst of a long-term skills crisis.…

  • June 27th 2023 at 08:34

Cloud security advice and expertise at your fingertips

Join AWS, Google Cloud, Microsoft Azure, and SANS Institute for the Cloud Security Exchange 2023

Sponsored Post Imagine if you could get instant advice on how to protect your cloud infrastructure against cyber threats from some of the world's best cloud security experts without leaving the comfort of your chair.…

  • June 27th 2023 at 02:46

American and Southwest Airlines pilot candidate data exposed

Time to start practising identity protection

A vendor that operates a pilot recruitment platform used by major airlines exposed the personal files of more than 8,000 pilot and cadet applicants at American Airlines and Southwest Airlines.…

  • June 26th 2023 at 15:29

Ex-FBI employee jailed for taking classified material home

Also: a PII harvest at Dole's server farm, military members mailed mystery smartwatches, and this week's critical vulns

Infosec in brief In a case startlingly similar to charges recently unsealed against one-term US president Donald Trump, a former FBI analyst has been jailed for taking sensitive classified material home with her.…

  • June 26th 2023 at 12:04

JP Morgan accidentally deletes evidence in multi-million record retention screwup

Fined $4m for Who-Me-esque mess, for which it blames unnamed archiving vendor's retention settings

JP Morgan has been fined $4 million by America's securities watchdog, the SEC, for deleting millions of email records dating from 2018 relating to its Chase Bank subsidiary.…

  • June 26th 2023 at 09:30

The unlimited value of a strong defence

How protective AI is a powerful weapon in the fight against cyber attackers using AI for malicious acts.

Webinar In the new age of generative AI, it would be foolhardy to imagine that bad actors won't already be exploiting every opportunity to launch an attack with their own malicious AI generated war machines.…

  • June 26th 2023 at 02:16

Google bug bounties inch closer to Microsoft's payouts

Chocolate Factory paid a record $12m in 2022

Bug hunters who found security holes in Google β€” and also responsibly disclosed details of those flaws to the Chocolate Factory β€” earned more than $12 million in bounty rewards in 2022, marking a record year for the corporation's Vulnerability Reward Programs (VRPs) in terms of payouts and number of vulnerabilities found and fixed.…

  • June 24th 2023 at 14:19

UK cyberspies warn ransomware crews targeting law firms

Nation states will use you to get to your friends, says NCSC

British law practices of "all sizes and types" have been warned by GCHQ's cyberspy arm that their "widespread adoption of hybrid working" combined with the large sums of money they handle is making them a target.…

  • June 23rd 2023 at 12:09

Keep it schtum!

Ensuring communications stay secure

Webinar The explosion in remote working since the pandemic means the number of people doing their job from home has more than doubled in the UK.…

  • June 23rd 2023 at 08:53

Chinese malware intended to infect USB drives accidentally infects networked storage too

Hides itself from popular Asian AV, also uses games to do its dirty work

Malware intended to spread on USB drives is unintentionally infecting networked storage devices, according to infosec vendor Checkpoint.…

  • June 23rd 2023 at 05:31

US cyber ambassador says China knows how to steal its way to dominance of cloud and AI

Calls on governments to combat 'playbook' that propelled Huawei to prominence

China has a playbook to use IP theft to seize leadership in cloud computing, and other nations should band together to stop that happening, according to Nathaniel C. Fick, the US ambassador-at-large for cyberspace and digital policy.…

  • June 23rd 2023 at 03:31

To kill BlackLotus malware, patching is a good start, but...

...that alone 'could provide a false sense of security,' NSA warns in this handy free guide for orgs

BlackLotus, the malware capable of bypassing Secure Boot protections and compromising Windows computers, has caught the ire of the NSA, which today published a guide to help organizations detect and prevent infections of the UEFI bootkit.…

  • June 22nd 2023 at 21:48

Now BlackCat extortionists threaten to leak stolen plastic surgery pics

Sharing a cancer patient's nude snaps earlier wasn't enough for these scumbags

Ransomware gang BlackCat claims it infected a plastic surgery center, stole "lots" of highly sensitive medical records, and has vowed to leak patients' photos if the clinic doesn't pay up.…

  • June 22nd 2023 at 17:57
❌