FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Coffee Meets Bagel outage caused by cybercriminals deleting data and files

Did you potentially miss the love match of your life in week-long blackout? Nope, nobody could access it

If you got snubbed by the object of your affections on dating app Coffee Meets Bagel (CMB) in late August, don't feel bad, the company says its systems were down due to cyber baddies.…

  • September 6th 2023 at 16:01

Meatbag mishaps more menacing than malware? CISOs think so

Company boards, on the other hand, aren't letting cybersecurity disturb their sleep as much

Chief information security officers (or CISOs) see human error as the most significant risk to data protection compared to other UK board directors.…

  • September 6th 2023 at 13:20

You patched yet? Years-old Microsoft security holes still hot targets for cyber-crooks

We're number one! We're number one! We're...

It's generally accepted that security flaws in Microsoft's products are a top magnet for crooks and fraudsters: its sprawling empire of hardware and software is a target-rich ecosystem in that there is a wide range of bugs to exploit, and a huge number of vulnerable organizations and users.…

  • September 5th 2023 at 21:37

Big Tech has failed to police Russian disinformation, EC study concludes

In Putin's Russia, the planet hacks you

The power of the EU's Digital Services Act (DSA) to actually police the world's very large online platforms (VLOPs) has been tested in a new study focused on Russian social media disinformation.…

  • September 5th 2023 at 17:45

Freecycle gives users the gift of a security breach notice

Change your passwords. And maybe give the recycling a miss this time

Updated Freecycle, the charity aimed at recycling detritus that would otherwise be headed for landfill, has become the latest organization to suffer at the hands of cyber attackers and admit to a breach.…

  • September 5th 2023 at 14:24

Northern Ireland's top cop quits after security breach, disciplinary controversy

Simon Byrne faced backlash over FoI blunder, plus claims officers were 'punished' to appease Sinn FΓ©in

Northern Ireland's police chief, Simon Byrne, resigned last night after an emergency meeting of the Policing Board amid discontent in the rank and file over a data breach that exposed serving officers' info, as well as news he was considering appealing a court ruling linked to the Troubles.…

  • September 5th 2023 at 11:45

Attackers accessed UK military data through high-security fencing firm's Windows 7 rig

Irony, not barbed wire, cuts the deepest

The risk of running obsolete code and hardware was highlighted after attackers exfiltrated data from a UK supplier of high-security fencing for military bases. The initial entry point? A Windows 7 PC.…

  • September 4th 2023 at 15:25

Microsoft calls time on ancient TLS in Windows, breaking own stuff in the process

Hold onto your SQL Server, enterprise admins

Microsoft has reminded users that TLS 1.0 and 1.1 will soon be disabled by default in Windows.…

  • September 4th 2023 at 14:15

Tsunami watch

Mitigating the threat of bot-driven DDoS attacks

Webinar It's sometimes easy to be lulled into a sense of false security and imagine that your organization or business will not become a target of highly professional cybercriminals, hacktivists and even nation-state actors. But the threat posed by DDoS attacks is very much on the rise.…

  • September 4th 2023 at 14:08

Northern Irish cops release 2 men after Terrorism Act arrests linked to data breach

Came in wake of the force publishing their own people's data in botched FoI

Nearly four weeks after the Police Service of Northern Ireland (PSNI) published data on 10,000 employees in a botched response to a Freedom of Information request, another two men, aged 21 and 22, have been released on bail after being arrested under the Terrorism Act.…

  • September 4th 2023 at 12:33

Apple opens annual applications for free hackable iPhones

ALSO: Brazilian stalkerware database ripped by the short hairs, a fast fashion breach, and this week's critical vulns

Infosec in brief The latest round of Apple's Security Research Device (SRD) program is open, giving security researchers a chance to get their hands on an unlocked device – and Apple's blessing to attack it and test its security capabilities.…

  • September 4th 2023 at 02:58

Cops drill into chat apps, sink plot to smuggle tonnes of coke into Europe

Big blow to blighters' blow-by-the-boatload blueprint

Video Efforts by cops to seize and shut down encrypted messaging apps favored by criminals, and then mine their conversations for evidence, appear to have led to more arrests β€” plus the seizure of about 2.7 tonnes of cocaine.…

  • September 2nd 2023 at 07:55

More Okta customers trapped in Scattered Spider's web

Oktapus phishing campaign criminals are back in action

Customers of cloudy identification vendor Okta are reporting social engineering attacks targeting their IT service desks in attempts to compromise user accounts with administrator permissions.…

  • September 1st 2023 at 19:15

Massive attack

Defeating a DDoS swarm

Webinar Any organization can lose service, revenue, and reputation as a result. If you are particularly unlucky, a DDoS attack can defenestrate your network defences. You may find yourself facing an cyber criminal who wants to take your business for everything it's got - not an attractive prospect in anybody's book.…

  • September 1st 2023 at 13:34

Good news for Key Group ransomware victims: Free decryptor out now

That's what we call a static shock

Even ransomware operators make mistakes, and in the case of ransomware gang the Key Group, a cryptographic error allowed a team of security researchers to develop and release a decryption tool to restore scrambled files.…

  • August 31st 2023 at 22:47

Kremlin-backed Sandworm strikes Android devices with data-stealing Infamous Chisel

Five Eyes nations warn of hit against Ukrainian military systems

Russia's Sandworm crew is using an Android malware strain dubbed Infamous Chisel to remotely access Ukrainian soldiers' devices, monitor network traffic, access files, and steal sensitive information, according to a Five Eyes report published Thursday.…

  • August 31st 2023 at 19:13

Barracuda gateway attacks: How Chinese snoops keep a grip on victims' networks

Backdoors detailed, plus CISA releases more IOCs for IT depts to check

Nearly a third of organizations compromised by Chinese cyberspies via a critical bug in some Barracuda Email Security Gateways were government units, according to Mandiant.…

  • August 30th 2023 at 23:00

Microsoft ain't happy with Russia-led UN cybercrime treaty

Could be used to put ethical hackers, and citizens, behind bars

A controversial United Nations proposal has a new foe, Microsoft, which has joined the growing number of organizations warning delegates that the draft version of the UN cybercrime treaty only succeeds in justifying state surveillance β€” not stopping criminals, as originally intended.…

  • August 30th 2023 at 18:23

Toyota Japan back on the road after probably-not-cyber attack halted production

Malfunction took 14 plants offline for 36 hours. Oh, what a … nah, too obvious

Toyota Japan has recovered from what it's described as a "malfunction in the production order system" that halted production on 28 lines across 14 plants starting on Monday evening.…

  • August 30th 2023 at 03:58

Meta reckons China's troll farms could learn proper OpSec from Russia's fake news crews

Claims to have taken down two colossal networks, with 'Secondary Infektion' schooling 'Spamouflage'

Russia appears to be "better" at running online trolling campaigns aimed at pushing its political narratives than China, according to Meta's latest Adversarial Threat Report.…

  • August 30th 2023 at 00:58

University cuts itself off from internet after mystery security snafu

Halls of learning are stuck offline, but go Wolverines!

Updated The University of Michigan has isolated itself from the internet but, hey, everything's fine!…

  • August 29th 2023 at 21:37

Apple security boss faces iPads-for-gun-permits bribery charge... again

'We will continue fighting this case' global chief's lawyer tells us

An appeals court has reversed a 2021 decision to drop a bribery charge against Apple's head of global security, who is accused of donating iPads worth up to $80,000 to a sheriff's office in exchange for giving his Cupertino agents concealed carry weapon licenses.…

  • August 29th 2023 at 20:32

FBI-led Operation Duck Hunt shoots down Qakbot

Totally plucked: Agents remotely roast Windows botnet malware on victims' machines

Uncle Sam today said an international law enforcement effort dismantled Qakbot, aka QBot, a notorious botnet and malware loader responsible for losses totaling hundreds of millions of dollars worldwide, and seized more than $8.6 million in illicit cryptocurrency.…

  • August 29th 2023 at 20:03

More UK cops' names and photos exposed in supplier breach

All 47,000 Met Police officers and staff reportedly accessed in break-in

London's Metropolitan Police has said a third-party data breach exposed staff and officers' names, ranks, photos, vetting levels, and salary information.…

  • August 29th 2023 at 11:35

Health, payment info for 1.2M people feared stolen from Purfoods in IT attack

Meal delivery biz leaves bitter taste

Purfoods has notified more than 1.2 million people that their personal and medical data β€”Β including payment card and bank account numbers, security codes, and some protected health information β€” may have been stolen from its servers during what sounds like a ransomware infection earlier this year.…

  • August 28th 2023 at 21:45

Malware loader lowdown: The big 3 responsible for 80% of attacks so far this year

Top of the list to trip sensors

Three malware loaders β€” QBot, SocGholish, and Raspberry Robin β€” are responsible for 80 percent of observed attacks on computers and networks so far this year.…

  • August 28th 2023 at 16:30

Whiffy malware stinks after tracking location via Wi-FI

ALSO: Euro chip maker breached, crims plan to undermine cyber insurance, and this week's critical vulnerabilities

Infosec in Brief No one likes malware, but malicious code that tracks your location is particularly unlovable.…

  • August 28th 2023 at 05:15

Taiwanese infosec researchers challenge Microsoft's China espionage finding

PLUS: India calls for global action on AI and crypto; Vietnam seeks cybersecurity independence; China bans AI prescribing drugs

Asia In Brief Taiwan-based infosec consultancy Team T5 has disputed Microsoft's alleged timeline of just when a Beijing-linked attack group named Flax Typhoon commenced its campaigns.…

  • August 28th 2023 at 02:58

Tor turns to proof-of-work puzzles to defend onion network from DDoS attacks

No miners were involved in this story

Tor, which stands for The Onion Router, weathered a massive distributed denial-of-service (DDoS) storm from June last year through to May.…

  • August 26th 2023 at 08:31

FBI: Who was going around hijacking Barracuda email boxes? China, probably

Joins in the chorus of advice to bin the gear instead of trying for a fix

The FBI has warned owners of Barracuda Email Security Gateway (ESG) appliances the devices are likely undergoing attack by snoops linked to China, and removing the machines from service remains the safest course of action.…

  • August 25th 2023 at 00:17

Pulling the strings

The critical rise of generative AI use in ransomware attacks on applications

Webinar It's a fact of life that ransomware is a constant threat, like a dark cloud on every horizon. Recent research suggests that the volume of attacks has doubled in the last year.…

  • August 24th 2023 at 12:49

Two teens were among those behind the Lapsus$ cyber-crime spree, jury finds

From BT and Nvidia to Grand Theft Auto 6, pair went on a total tear

Two teenage members of the chaotic Lapsus$ cyber-crime gang helped compromise computer systems of Uber and Nvidia, and also blackmailed Grand Theft Auto maker Rockstar Games among other high-profile victims, a jury has decided.…

  • August 24th 2023 at 07:33

Tornado Cash 'laundered over $1B' in criminal crypto-coins

Founder Roman Storm cuffed on conspiracy, sanctions busting charges

Two founders of Tornado Cash were formally accused by US prosecutors today of laundering more than $1 billion in criminal proceeds through their cryptocurrency mixer.…

  • August 23rd 2023 at 22:45

North Korea may be itching to sell $40m of purloined Bitcoin

Those weapons programs aren't going to fund themselves

Lazarus Group, the infamous cryptocurrency thieves backed by North Korea, may try to liquidate a stash of stolen Bitcoin worth more than $40 million, according to the FBI.…

  • August 23rd 2023 at 18:45

Criminals go full Viking on CloudNordic, wipe all servers and customer data

IT outfit says it can't β€” and won't β€” pay the ransom demand

CloudNordic has told customers to consider all of their data lost following a ransomware infection that encrypted the large Danish cloud provider's servers and "paralyzed CloudNordic completely," according to the IT outfit's online confession.…

  • August 23rd 2023 at 07:26

'Millions' of spammy emails with no opt-out? That'll cost you $650K, Experian

Credit-reporting giant disagrees with FTC, will hand over the pocket change to make Feds go away

Experian has agreed to cough up $650,000 after being accused of spamming people with no opt-out button.…

  • August 22nd 2023 at 21:58

SEC fines fintech crypto fund that promised 2,700% returns

Titan Global Capital Management to pay $1m to those it advised without admitting fault

A New York fintech biz is set to pay $1 million in fines under a US Securities and Exchange Commission order that claims it advertised "annualized" returns on Titan Crypto of up to 2,700 percent, a number based on a "purely hypothetical account."…

  • August 22nd 2023 at 15:34

The devil in the detail

How AI is powering ransomware attacks on applications

Webinar You could be forgiven for wondering if anything can ever again be completely straightforward or demonstrably authentic in a world where generative AI can masquerade convincingly as your mother, or express itself in the exact language your best friend might use.…

  • August 22nd 2023 at 12:46

Apple's defense against apps vandalizing other apps still broken, developer claims

Cupertino appears to be blasΓ© about long-standing macOS bug, so coder has blabbed

Updated Apple last year introduced a security feature called App Management that's designed to prevent one application from modifying another without authorization under macOS Ventura – but a developer claims it’s not very good at its job under some circumstances.…

  • August 22nd 2023 at 08:27

Ivanti Sentry exploited in the wild, patches emitted

Good thing you're not exposing admin port 8443 to the world, right? Uh, right?

A critical authentication bypass bug in MobileIron Sentry has been exploited in the wild, its maker Ivanti said in an advisory on Monday.…

  • August 22nd 2023 at 00:30

Uncle Sam: Rest of the world would love to steal our space blueprints – don't let 'em

If spies aren't swiping designs via joint ventures, they're breaking into IT networks and mulling sat hijackings

With America outspending the rest of the world on space technologies, those systems and their blueprints are a highly alluring and lucrative target for sticky-fingered spies, Uncle Sam has reminded industry.…

  • August 21st 2023 at 21:54

Leak of 75k employee records was insiders' fault, claims Tesla

Identity Access Management? What's that?

Insiders are to blame for a May data breach at Tesla, the company claimed in filings after news of the incident was reported months ago by German media.…

  • August 21st 2023 at 17:35

High severity vuln in WinRAR could allow code to run when files are opened

Update now: Millions of users potentially impacted, plus uncounted warez folks

Users of the popular WinRAR compression and archiving tool should update now to avoid a vulnerability that allows code to be run when a user opens a RAR file.…

  • August 21st 2023 at 13:35

Last rites for the UK's Online Safety Bill, an idea too stupid to notice it's dead

Snoopers Charter: Dead cows don't snitch

Opinion Information wants to be free. This usefully ambiguous battle cry has been the mischievous slogan of hackers since early networking thinker Stuart Brand coined it in the early 1980s. Intended as part of a discussion about the inherent contradictions of intellectual property, it has bestowed irony in many other places since.…

  • August 21st 2023 at 08:31

Microsoft DNS boo-boo breaks Hotmail for users around the globe

ALSO: NYC says kthxbye to TikTok, slain Microsoft exec's wife indicted, and some ASAP patch warnings

Infosec in brief Someone at Microsoft has some explaining to do after a messed-up DNS record caused emails sent from accounts using Microsoft's Outlook Hotmail service to be rejected and directed to spam folders starting on Thursday.…

  • August 21st 2023 at 03:34

Interpol arrests 14 who allegedly scammed $40m from victims in 'cyber surge'

Cops credit security shops with an assist, tho it's a drop in the ocean

An Interpol-led operation arrested 14 suspects and identified 20,674 "suspicious" networks spanning 25 African countries that international cops have linked to more than $40 million in cybercrime losses.…

  • August 20th 2023 at 07:18

FYI: There's another BlackCat ransomware variant on the prowl

Bad kitty, no catnip for you

Here's a heads up. Another version of BlackCat ransomware has been spotted extorting victims. This variant embeds two tools, we're told: the network toolkit Impacket for lateral movement within compromised environments, and Remcom for remote code execution.…

  • August 18th 2023 at 21:33

Add 'writing malware' to the list of things generative AI is not very good at doing

But it may help with fuzzing

Analysis Despite the hype around criminals using ChatGPT and various other large language models to ease the chore of writing malware, it seems this generative AI technology isn't terribly good at helping with that kind of work.…

  • August 18th 2023 at 00:39

Don't just patch your Citrix gear, check for intrusion: Two bugs exploited in wild

About 2,000 NetScaler installations feared compromised as CISA raises alarm over ShareFile

Updated Miscreants are actively exploiting critical bugs in two of Citrix's products, both of which the business IT player fixed earlier this summer.…

  • August 17th 2023 at 21:55

Man arrested in Northern Ireland police data leak as more incidents come to light

Plus laptop and radio with yet more officers details reportedly nicked from car

A man was arrested in Northern Ireland for suspected Collection of Terrorist Information following an incident where police mistakenly leaked details that identified 10,000 serving officers, but he has now been released on bail.…

  • August 17th 2023 at 12:03

Japan's digital minister surrenders salary to say sorry for data leaks

The My Number card mess remains unsolved as trust in e-government remains muted

Japan’s digital minister has doubled down on a June promise to penalize himself for the poor rollout of the country’s digital ID, My Number Card, by offering up three months salary on Tuesday.…

  • August 17th 2023 at 04:58

Vietnam admits it has just ten percent of the infosec pros it needs

Which is a problem, because local orgs are leaking data and shadowy traders are cashing in

Vietnam’s Ministry of Information and Communications has admitted the nation has a vast shortfall of infosec pros.…

  • August 17th 2023 at 02:59

Discord.io pulls the cord after crooks steal 760K users' info

Cleanup will involve 'complete rewrite of our website's code'

Discord.io has shut down "for the foreseeable future," after crooks stole, and then put up for sale, data belonging to all 760,000 of the service's users.…

  • August 16th 2023 at 22:58

Clorox cleans up IT security breach that soaked its biz ops

Plus: Medical records for 4M people within reach of Clop gang after IBM MOVEit deployment hit

The Clorox Company has some cleaning up to do as some of its IT systems remain offline and operations "temporarily impaired" following a security breach.…

  • August 15th 2023 at 22:22

Ensure data security at the edge

Why a fully mobile, hybrid and edge workforce needs a more flexible security solution

Sponsored Feature Securing the corporate network has never been a simple process, but years ago it was at least a bit more straightforward. Back then, the network perimeter was clear and well defined, and everything inside itΒ was considered trusted and safe. The security team defended against everything outside, established security protocols and deployed security tools, monitored the network gateways, and kept sensitive data as safe as possible.…

  • August 15th 2023 at 12:16

You're not seeing double – yet another UK copshop is confessing to a data leak

Norfolk and Suffolk constabularies admit to accidentally including raw crime data in FoI responses

Norfolk and Suffolk police have stepped forward to admit that a β€œtechnical issue” resulted in raw data pertaining to crime reports accidentally being included in Freedom of Information responses.…

  • August 15th 2023 at 11:28

Tech CEO admits role in tricking Qualcomm into $150M takeover

Abreezio? Maybe not, but it was a plea deal

The former chief executive of a company that was sold to Qualcomm for more than $150 million has pleaded guilty to one count of money laundering relating to a $1.5 million transaction involving proceeds from the deal.…

  • August 15th 2023 at 10:27

Florida Man and associates indicted for conspiracy to steal data, software

Voting machines and their info allegedly accessed without authorization by keen golfer's gofers

Authorities in the US state of Georgia have indicted a famous Floridian and his loyal associates on counts including theft of data, software, and personal information.…

  • August 15th 2023 at 06:58

Chinese media teases imminent exposΓ© of seismic US spying scheme

Again labels America a hacker empire over alleged backdoors found in earthquake monitoring kit

China's Global Times, a state-controlled media outlet, has teased an imminent exposΓ© of alleged US attacks on seismic data measurement stations.…

  • August 15th 2023 at 01:57

Sextortion suspects on trial after teen victim dies from a self-inflicted gunshot wound

Trio alleged to have blackmailed over 100 targets after threats of intimate image release

Two Nigerian men have been extradited to the US and were scheduled to appear in deferral court on Monday, charged with sextortion and causing the death of one of their victims: a teen who was found dead from a self-inflicted gunshot wound.…

  • August 14th 2023 at 23:28
❌