FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Mattress maker Tempur Sealy says it isolated tech system to contain cyber burglary

Sleeping giant says no sign yet personal info was stolen

Tempur Sealy, among the world's largest providers of bedding, has notified the Securities and Exchange Commission of a digital burglary by cyber crims that forced it to isolate parts of the tech infrastructure.…

  • August 1st 2023 at 14:31

US military battling cyber threats from within and without

As if attacks from China weren't enough, one of the Air Force's own has reportedly gone rogue

The US government is fighting a pair of cyber security incidents, one involving Chinese spies who potentially gained access to crucial American computer networks and the other related to an Air Force engineer allegedly compromised communications security by stealing sensitive equipment and taking it home.…

  • August 1st 2023 at 07:29

China bans export of drones some countries have already banned anyway

Some say retaliation for sanctions, but Beijing says it just wants world peace

China introduced restrictions on Monday that mean would-be exporters will require a license to ship certain drones and related equipment out of the Middle Kingdom.…

  • August 1st 2023 at 06:00

White House: Losing Section 702 spy powers would be among 'worst intelligence failures of our time'

As expert panel suggests some tweaks to boost public's confidence in FISA

The White House has weighed in on the Section 702 debate, urging lawmakers to reauthorize, "without new and operationally damaging restrictions," the controversial snooping powers before they expire at the end of the year.…

  • July 31st 2023 at 19:58

Hikvision, Nvidia named in contract for 'Uyghur detection'

GPU giant says you can't stop secondary sales, surveillance gear maker maintains innocence

Updated Video surveillance equipment maker Hikvision was paid $6 million by the Chinese government last year to provide technology that could identify members of the nation's Uyghur people, a Muslim ethnic majority, according to physical security monitoring org IPVM.…

  • July 31st 2023 at 12:25

What would sustainable security even look like?

Clue: Nothing like what’s on offer today

Opinion "There seems to be something wrong with our bloody ships today," fumed Admiral David Beatty during 1916's Battle of Jutland. Fair enough: three of the Royal Navy's finest vessels had just blown up and sank.…

  • July 31st 2023 at 08:30

US senator victim-blames Microsoft for Chinese hack

ALSO: China says US hacked it right back, BreachForums users have been pwned, and this week's critical vulns

Infosec in brief US senator Ron Wyden (D-OR) thinks it's Microsoft's fault that Chinese hackers broke into Exchange Online, and he wants three separate government agencies to launch investigations and hold the Windows giant "responsible for its negligent cyber security practices." …

  • July 31st 2023 at 00:59

Florida man accused of hoarding America's secrets faces fresh charges

Mar-a-Lago IT director told 'the boss wanted the server deleted'

Federal prosecutors have expanded their criminal case against a famous Floridian and his loyal minions for allegedly mishandling national security secrets and not being forthright about the storage and handling of hundreds of classified documents.…

  • July 29th 2023 at 00:59

Millions of people's data stolen because web devs forget to check access perms

IDORs of the storm

Personal, financial, and health information belonging to millions of folks has been stolen via a particular class of website vulnerability, say cybersecurity agencies in the US and Australia. They're urging developers to review their code and squish these bugs for good.…

  • July 29th 2023 at 00:09

FBI boss: Congress must renew Section 702 spy powers – that's how we get nearly all our cyber intel

Also: China's 'got a bigger hacking program than that of every major nation combined'

Nearly all of the FBI's technical intelligence on malicious "cyber actors" in the first half of this year was obtained via Section 702 searches, according to FBI Director Christopher Wray.…

  • July 28th 2023 at 19:52

Chinese companies evade sanctions, fuel Moscow’s war on Ukraine, says report

PRC semiconductor exports curiously rose 19% y-o-y for first 9 months of 2022

Chinese companies, including state-owned defense companies, are evading tech sanctions and fueling Moscow’s war in Ukraine, according to a US report released on Thursday.…

  • July 28th 2023 at 19:27

NATO probes hacktivist crew's boasts of stolen portal data

'Gay furry hackers' say it's in response to 'attacks on human rights' and noooothing to do with Russia-Ukraine

NATO is investigating claims by miscreants that they broke into the military alliance's unclassified information-sharing and collaboration IT environment, stole information belonging to 31 nations, and leaked 845 MB of compressed data.…

  • July 27th 2023 at 22:33

Medical files of 8M-plus people fall into hands of Clop via MOVEit mega-bug

Maximus plus Deloitte and Chuck E. Cheese join 500+ victim orgs

Accounting giant Deloitte, pizza and birthday party chain Chuck E. Cheese, government contractor Maximus, and the Hallmark Channel are among the latest victims that the Russian ransomware crew Clop claims to have compromised via the MOVEit vulnerability.…

  • July 27th 2023 at 20:01

Think tank calls for monitoring of Chinese AI-enabled products

Will make regulating China’s 5G telecom equipment look like a cinch

Chinese made AI-enabled products should spark similar concerns to Middle Kingdom sourced 5G equipment and therefore be regulated, said think tank Australian Strategic Policy Institute (ASPI) on Thursday.…

  • July 27th 2023 at 18:54

Crooks pwned your servers? You've got four days to tell us, SEC tells public companies

Cripes, they actually sound serious

Public companies that suffer a computer crime likely to cause a "material" hit to an investor will soon face a four-day time limit to disclose the incident, according to rules approved today by the US Securities and Exchange Commission.…

  • July 26th 2023 at 23:48

Russia throws founder of infosec biz Group-IB in the clink for treason

Sachkov faces 14-year stretch after 'unreasonably rushed trial'

A Russian court has sentenced Ilya Sachkov, the founder of security research house Group-IB, to 14 years in a maximum-security prison after finding the executive guilty of high treason.…

  • July 26th 2023 at 20:31

Ambulance patient records system hauled offline for cyber-attack probe

UK trusts serving 12 million people affected as vendor awaits results of forensic investigation

Several UK NHS ambulance organizations have been struggling to record patient data and pass it to other providers following a cyber-attack aimed at health software company Ortivus.…

  • July 26th 2023 at 09:01

Sneaky Python package security fixes help no one – except miscreants

Good thing these eggheads have created a database of patches

Python security fixes often happen through "silent" code commits, without an associated Common Vulnerabilities and Exposures (CVE) identifier, according to a group of computer security researchers.…

  • July 26th 2023 at 07:28

Ivanti plugs critical bug – but not before it was used against Norwegian government

Uncle Sam warns sysadmins to get patching as soon as possible

A critical security flaw in Ivanti's mobile endpoint management code was exploited and used to compromise 12 Norwegian government agenciesΒ before the vendor plugged the hole.…

  • July 26th 2023 at 06:27

Apple patches exploited bugs in iPhones plus other holes

One spotted by Amnesty International - wonder what that was used for?

Apple has released fixes for several security flaws that affect its iPhones, iPads, macOS computers, and Apple TV and watches, and warned that some of these bugs have already been exploited.…

  • July 25th 2023 at 21:29

TETRA radio comms used by emergency heroes easily cracked, say experts

If it looks like a backdoor, walks like a backdoor, maybe it's ... export control

Updated Midnight Blue, a security firm based in the Netherlands, has found five vulnerabilities that affect Terrestrial Trunked Radio (TETRA), used in Europe, the United Kingdom, and many other countries by government agencies, law enforcement, and emergency services organizations.…

  • July 24th 2023 at 23:20

AMD Zenbleed chip bug leaks secrets fast and easy

Zen 2 flaw more simple than Spectre, exploit code already out there – get patching when you can

AMD has started issuing some patches for its processors affected by a serious silicon-level bug dubbed Zenbleed that can be exploited by rogue users and malware to steal passwords, cryptographic keys, and other secrets from software running on a vulnerable system.…

  • July 24th 2023 at 20:41

Google Cloud shores up log permissions for builder bot

ALSO: Amazon's child-sized COPPA fine, smart tech security labels coming to the US, and this week's critical vulns

Infosec in brief Google Cloud has fixed an issue in which it gave away a little too much info in its audit logs to a service account.…

  • July 24th 2023 at 04:08

Stolen Microsoft key may have opened up a lot more than US govt email inboxes

How does the Azure giant come back from this?

A stolen Microsoft security key may have allowed Beijing-backed spies to break into a lot more than just Outlook and Exchange Online email accounts.…

  • July 21st 2023 at 22:58

VirusTotal: We're sorry someone fat-fingered and exposed 5,600 users

File under PEBCAK

VirusTotal today issued a mea culpa, saying a blunder earlier this week by one of its staff exposed information belonging to 5,600 customers, including the email addresses of US Cyber Command, FBI, and NSA employees.…

  • July 21st 2023 at 20:58

Lawyer sees almost 1,000 complainants sign up to Capita breach class action

95% pertain to pension schemes administered by outsourcing giant, says Barings Law

The law firm that last month sent a Letter of Claim to Capita over a security breach in late March says it has signed up nearly 1,000 clients as it prepares a class action lawsuit aimed at the outsourcing giant.…

  • July 21st 2023 at 10:38

MOVEit body count closes in on 400 orgs, 20M+ individuals

'One of the most significant hacks of recent years,' we're told

The number of victims and costs tied to the MOVEit file transfer hack continues to climb as the fallout from the massive supply chain attack enters week seven.…

  • July 20th 2023 at 21:01

RIP Kevin Mitnick: Former most-wanted hacker dies at 59

Tributes paid to husband, father, son and rogue-turned-consultant

Obit Kevin Mitnick, probably the world's most-famous computer hacker – and subsequently writer, public speaker, and security consultant – has succumbed to pancreatic cancer. He was 59.…

  • July 20th 2023 at 18:01

Under CISA pressure collab, Microsoft makes cloud security logs available for free

In hindsight, it's probably good practice to give clients access to cloud logs

Microsoft announced on Wednesday it would provide all customers free access to cloud security logs – a service usually reserved for premium clients – within weeks of a reveal that government officials' cloud-based emails were targets of an alleged China-based hack.…

  • July 20th 2023 at 12:30

Ukraine busts bot farm spreading Russian infowar propaganda and fraud

Plus: Spanish cops arrest Ukrainian scareware dev after ten-year hunt

Ukrainian cops have disrupted a massive bot farm with more than 100 operators allegedly spreading fake news about the Russian invasion, leaking personal information belonging to Ukrainian citizens, and instigating fraud schemes.…

  • July 20th 2023 at 07:30

Tech support scammers go analog, ask victims to mail bundles of cash

The approach is the same, but never mind the crypto or gift cards

Cybercriminals are taking their business offline in a new approach to familiar technical support scams recently identified by the US Federal Bureau of Investigation.…

  • July 19th 2023 at 21:00

INTERSECT '23: Network Security Summit unveils cutting-edge strategies to safeguard digital assets

Palo Alto Networks addresses the mounting challenges posed by sophisticated cyberthreats

Sponsored Post Join Palo Alto Networks at the INTERSECT '23: Network Security Summit, on July 27, 2023 09:00 AM PDT in the Americas and on August 2, 2023, at 10:00 AM CEST in Europe.…

  • July 19th 2023 at 09:45

US adds Euro spyware makers to export naughty list

Predator dev joins Pegasus slinger

The US government on Tuesday added commercial spyware makers Intellexa and Cytrox to its Entity List, saying the duo are a possible threat to national security.…

  • July 18th 2023 at 23:42

Recycling giant TOMRA pulls systems offline following 'extensive cyberattack'

Says baddies launched attack at weekend, isolates parts of tech infrastructure to contain spread

Norwegian mining and recycling giant TOMRA says it has isolated tech systems as it deals with an "extensive cyberattack."…

  • July 18th 2023 at 12:59

Cybercrime – big in Asia Pacific

SANS first DFIR Summit in Asia gives organizations in Asia Pacific an opportunity to build their cyber security expertise

Sponsored Post Kroll's latest State of Incident Response: APAC report suggests that over half of all organizations in Asia Pacific (59 percent) have experienced a cyber incident, of which a third (32 percent) have suffered multiple incidents.…

  • July 18th 2023 at 02:43

Quick: Manually patch this Zimbra bug that's under attack

Smells like Russian cyber spies (again)

A vulnerability in Zimbra's software is being exploited right now by miscreants to compromise systems and attack selected government organizations, experts reckon.…

  • July 17th 2023 at 21:49

Beijing wants to make the Great Firewall of China even greater

Also more fiery, with vague but firm orders to create a 'security barrier'

Over the weekend Chinese president Xi Jinping gave a directive to officials to build a Beijing-supervised "security barrier" around its internet.…

  • July 17th 2023 at 18:28

Boris Johnson pleads ignorance, which just might work

Also: More high-profile MOVEit victims; CVSS 4.0 coming soon; and a long list of critical vulnerabilities

Infosec in brief Former UK prime minister Boris Johnson lobbed a wrench into the works of the country's COVID-19 inquiry by claiming he couldn't remember the passcode to unlock an old phone being sought by investigators.…

  • July 17th 2023 at 02:20

Infosec watchers: TeamTNT crew may blast holes in Azure, Google Cloud users

Why limit yourself to only stealing AWS credentials?

A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.…

  • July 15th 2023 at 08:28

Celsius feels the heat: Ex-CEO arrested, watchdogs line up to sue bankrupt crypto biz

Exec faces fraud charges, one regulator wants $5 billion fine

Alex Mashinsky, the now-former CEO of collapsed cryptocurrency concern Celsius, today faces charges of fraud as prosecutors and watchdogs pile in.…

  • July 13th 2023 at 20:48

Microsoft whips up unrest after revealing Azure AD name change

Ditching it after a decade? Devs warn of the hours to correct documentation and chaos it'll cause

Microsoft is causing a stir among some tech pros after confirming it plans to rename Azure AD to Entra.…

  • July 12th 2023 at 17:02

Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws

Plus: Apple bungles another rapid security response; important ICS updates land; and more

Patch Tuesday Microsoft today addressed 130 CVE-listed vulnerabilities in its products – and five of those bugs have already been exploited in the wild.…

  • July 11th 2023 at 23:26

Barts NHS hack leaves folks on tenterhooks over extortion

BlackCat pounces on 7TB of data and theatens to release it

Staff at one of the UK's largest hospital groups have spent a nervous week wondering if private data, stolen from their employer's IT systems by a ransomware gang, is going to be splurged online after a deadline to prevent publication passed.…

  • July 11th 2023 at 07:32

LibertΓ©, Γ‰galitΓ©, Spyware: France okays cops snooping on phones

ALSO: Shell fails to learn from past leaks; hundreds of solar plants found open to Mirai; and this week's crit vulns

Infosec in brief With riots rocking the country, French parliamentarians have passed a bill granting law enforcement the right to snoop on suspects via "the remote activation of an electronic device without the knowledge or consent of its owner." …

  • July 10th 2023 at 05:33

Capita staffers told attackers stole data from its own pension fund

Three months after mega breach by Russian cybercrime group

Capita has informed some of its employees that its own pension fund was among the victims of a cybercrime attack on its system, resulting in the theft of their personal details, they say.…

  • July 7th 2023 at 12:11

Nickelodeon probes claims of massive data leak as SpongeBob fans rejoice

TV network's attorneys 'on a DMCA rampage' ... are you sure you're ready, kids?

Nickelodeon says it is probing claims that "decades old" material was stolen from it and leaked online. This follows reports on social media that someone had dumped 500GB of snatched animation files. Hilarity, and many SpongeBob SquarePants memes, ensued.…

  • July 6th 2023 at 22:45

Microsoft puts out Outlook fire, says everything's fine with Teams malware flaw

Redmond's not fixing the latter because it 'relies on social engineering'

Microsoft is having a rough week with troubles including an Outlook.com bug that prevented some email users from searching their messages for several hours on Thursday, and a Teams flaw that allows people to send phishing emails and malware to other Teams users.…

  • July 6th 2023 at 21:20

LockBit louts unload ransomware at Japan’s most prolific cargo port

Nagoya Harbor hit the rocks yesterday but looks to be afloat once more

The port of Nagoya – which shifted 2.68 million shipping containers and 164 million tons of cargo in 2022 – has moved precious few in the last 24 hours after finding itself the latest victim of Russia's notorious LockBit ransomware gang.…

  • July 6th 2023 at 03:13

North Korean satellite had no military utility for spying, says South Korea

Lends credence to theory that Pyongyang is testing ballistic missiles against international rules

A North Korean satellite allegedly designed for reconnaissance was not viable for its alleged intended purpose, according to South Korea's military on Wednesday.…

  • July 6th 2023 at 00:30

Ex-Amazon manager jailed for stealing $10M using fake vendor invoices

Prime doesn't pay – well, not that much, anyway

A now-former Amazon manager described by prosecutors as the "mastermind" behind a nearly $10 million scheme to steal money from the online megaretailer using fake invoices has been sentenced to 16 years behind bars in federal prison.…

  • July 6th 2023 at 00:28

RAM-ramming Rowhammer is back – to uniquely fingerprint devices

Just use it sparingly, as it may crash equipment or burn out memory

Boffins at the University of California, Davis have devised a purportedly practical way to apply a memory abuse technique called Rowhammer to build unique, stable device fingerprints.…

  • July 5th 2023 at 21:14

Suspected bank-infecting OPERA1ER crime boss cuffed

Cops reckon gang swiped as much as $30M from financial orgs

International cops have arrested a suspected "key figure" of a cybercrime group dubbed OPERA1ER that has stolen as much as $30 million from more than 30 banks and financial orgs across 15 countries.…

  • July 5th 2023 at 19:40

Singapore tells crypto operators: act like grown up financial institutions

Digital payment skeptics of the world, unite! You have nothing to lose but grifters and crims

Singapore has joined the ranks of nations requiring digital payment operators to follow the same sort of regulations and customer protection requirements that apply to conventional financial institutions.…

  • July 5th 2023 at 06:24

Undiplomatic Chinese threat actor attacks embassies and foreign affairs departments

Sneaky HTML smuggling signals MustangPanda shift towards Europe, Checkpoint charges

Infosec outfit Checkpoint says it's spotted a Chinese actor targeting diplomatic facilities around Europe.…

  • July 4th 2023 at 05:29

You've patched right? '340K+ Fortinet firewalls' wide open to critical security bug

That's a vulnerability that's under attack, fix available ... cancel those July 4th plans, perhaps?

More than 338,000 FortiGate firewalls are still unpatched and vulnerable to CVE-2023-27997, a critical bug Fortinet fixed last month that's being exploited in the wild.…

  • July 3rd 2023 at 23:17

TSA wants to expand facial recognition to hundreds of airports within next decade

Digital rights folks, as you can imagine, want the tech grounded

America's Transportation Security Agency (TSA) intends to expand its facial-recognition program used to screen US air travel passengers to 430 domestic airports in under a decade.…

  • July 3rd 2023 at 22:12

Dublin Airport staff pay data 'compromised' by criminals

Attackers accessed it via third-party services provider, says management group

It's an awkward Monday for Dublin Airport after pay and benefits details for some 2,000 staff were apparently "compromised" following a recent attack on professional service provider Aon.…

  • July 3rd 2023 at 15:14

US authorities warn on China's new counter-espionage law

Almost anything you download from China could be considered spying, but at least one analyst isn't worried

The United States' National Counterintelligence and Security Center (NCSC) has warned that China's updated Counter-Espionage law – which came into effect on July 1 – is dangerously ambiguous and could pose a risk to global business.…

  • July 3rd 2023 at 06:28

Japan rebukes Fujitsu for cloud security fails

PLUS: Philippines cyber-slave raid; South Korea’s crypto crackdown; AWS boosts Chinese exports; and more

Asia In Brief Japan's government last Friday rebuked Fujitsu for shabby cloud security.…

  • July 3rd 2023 at 01:35

Us, hacked by LockBit? No, says TSMC, that would be our IT supplier

So, uh, who's gonna pay that $70M ransom?

Following claims by ransomware gang LockBit that it has stolen data belonging to TSMC, the chip-making giant has said it was in fact one of its equipment suppliers, Kinmax, that was compromised by the crew, and not TSMC itself.…

  • June 30th 2023 at 23:17
❌