FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Australia building 'top secret' cloud to catch up and link with US, UK intel orgs

Plans to share 'vast amounts of data' – very carefully

Australia is building a top-secret cloud to host intelligence data and share it with the US and UK, which have their own clouds built for the same purpose.…

  • December 7th 2023 at 04:33

Apple and some Linux distros are open to Bluetooth attack

Issue has been around since at least 2012

A years-old Bluetooth authentication bypass vulnerability allows miscreants to connect to Apple, Android and Linux devices and inject keystrokes to run arbitrary commands, according to a software engineer at drone technology firm SkySafe.…

  • December 6th 2023 at 20:47

Locking down the edge

Watch this webinar to find out how Zero Trust fits into the edge security ecosystem

Sponsored Post Edge security is a growing headache. The attack surface is expanding as more operational functions migrate out of centralized locations and into distributed sites and devices.…

  • December 6th 2023 at 16:09

A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list

Apparently no one thought to check if this D-Link router 'issue' was actually exploitable

A security vulnerability previously added to CISA's Known Exploited Vulnerability catalog (KEV), which was recognized by CVE Numbering Authorities (CNA), and included in reputable threat reports is now being formally rejected by infosec organizations.…

  • December 6th 2023 at 14:45

Shielding the data that drives AI

Why we need the confidence to deploy secure, compliant AI-powered applications and workloads

Sponsored Feature Every organisation must prioritise the protection of mission critical data, applications and workloads or risk disaster in the face of an ever-widening threat landscape.…

  • December 6th 2023 at 10:23

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

Bitbucket, Confluence and Jira all in danger, again. Sigh

Atlassian has emailed its customers to warn of four critical vulnerabilities, but the message had flaws of its own – the links it contained weren't live for all readers at the time of despatch.…

  • December 6th 2023 at 06:57

Microsoft issues deadline for end of Windows 10 support – it's pay to play for security

Limited options will be available into 2028, for an undisclosed price

Microsoft on Tuesday warned that full security support for Windows 10 will end on October 14, 2025, but offered a lifeline for customers unable or unwilling to upgrade two years hence.…

  • December 6th 2023 at 06:31

Cisco intros AI to find firewall flaws, warns this sort of thing can't be free

Predicts cyber crims will find binary brainboxes harder to battle

Cisco's executive veep for security Jeetu Patel has predicted that AI will change the infosec landscape, but that end users will eventually pay for the privilege of having a binary brainbox by their side when they go into battle.…

  • December 6th 2023 at 04:29

Fancy Bear goes phishing in US, European high-value networks

GRU-linked crew going after our code warns Microsoft - Outlook not good

Fancy Bear, the Kremlin's cyber-spy crew, has been exploiting two previously patched bugs for large-scale phishing campaigns against high-value targets – like government, defense, and aerospace agencies in the US and Europe – since March, according to Microsoft. …

  • December 6th 2023 at 00:15

CISA details twin attacks on federal servers via unpatched ColdFusion flaw

Tardy IT admins likely to get a chilly reception over the lack of updates

CISA has released details about a federal agency that recently had at least two public-facing servers compromised by attackers exploiting a critical Adobe ColdFusion vulnerability.…

  • December 5th 2023 at 17:40

DSPM deep dive: debunking data security myths

To maintain a strong data security posture, you must protect the data where it lives

Partner Content There are plenty of technology acronyms in the alphabet soup of the cybersecurity industry, but DSPM is the latest one leading the charge; its recent buzz has brought scrutiny to various security concepts that have cluttered the meaning behind data security posture management.…

  • December 5th 2023 at 16:21

BlackCat ransomware crims threaten to directly extort victim's customers

Accounting software firm Tipalti says it’s investigating alleged break-in of its systems

The AlphV/BlackCat ransomware group said it plans to "go direct" to the clients of a firm it allegedly attacked to extort them, claiming to have infiltrated the systems of accounting software vendor Tipalti.…

  • December 5th 2023 at 12:30

It's ba-ack... UK watchdog publishes age verification proposals

Won't somebody think of the children?

The UK's communications regulator has laid out guidance on how online services might perform age checks as part of the Online Safety Act.…

  • December 5th 2023 at 10:22

UK government denies China/Russia nuke plant hack claim

Report suggests Sellafield compromised since 2015, response seems worryingly ignorant of Stuxnet

The government of the United Kingdom has issued a strongly worded denial of a report that the Sellafield nuclear complex has been compromised by malware for years.…

  • December 5th 2023 at 06:30

US warns Iranian terrorist crew broke into 'multiple' US water facilities

There's a war on and critical infrastructure operators are still using default passwords

Iran-linked cyber thugs have exploited Israeli-made programmable logic controllers (PLCs) used in "multiple" water systems and other operational technology environments at facilities across the US, according to multiple law enforcement agencies .…

  • December 4th 2023 at 23:30

Hershey phishes! Crooks snarf chocolate lovers' creds

Stealing Kit Kat maker's data?! Give me a break

There's no sugarcoating this news: The Hershey Company has disclosed cyber crooks gobbled up 2,214 people's financial information following a phishing campaign that netted the chocolate maker's data.…

  • December 4th 2023 at 19:15

Two new versions of OpenZFS fix long-hidden corruption bug

Version 2.2.2 and also 2.1.14, showing that this wasn't a new issue in the latest release

The bug that was very occasionally corrupting data on file copies in OpenZFS 2.2.0 has been identified and fixed, and there's a fix for the previous OpenZFS release too.…

  • December 4th 2023 at 16:15

Exposed Hugging Face API tokens offered full access to Meta's Llama 2

With more than 1,500 tokens exposed, research highlights importance of securing supply chains in AI and ML

Updated The API tokens of tech giants Meta, Microsoft, Google, VMware, and more have been found exposed on Hugging Face, opening them up to potential supply chain attacks. …

  • December 4th 2023 at 14:00

EU lawmakers finalize cyber security rules that panicked open source devs

PLUS: Montana TikTok ban ruled unconstitutional; Dollar Tree employee data stolen; critical vulnerabilities

Infosec in brief The European Union’s Parliament and Council have reached an agreement on the Cyber Resilience Act (CRA), setting the long-awaited security regulation on a path to final approval and adoption, along with new rules exempting open source software.…

  • December 4th 2023 at 06:01

New Relic's cyber-something revealed as attack on staging systems, some users

Ongoing investigation found evidence of stolen employee creds and social engineering

Nine days after issuing a vaguely worded warning about a possible cyber security incident, web tracking and analytics outfit New Relic has revealed a two-front attack.…

  • December 4th 2023 at 04:27

Scores of US credit unions offline after ransomware infects backend cloud outfit

Supply chain attacks: The gift that keeps on giving

A ransomware infection at a cloud IT provider has disrupted services for 60 or so credit unions across the US, all of which were relying on the attacked vendor. …

  • December 2nd 2023 at 00:01

Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks

Two CVEs can be abused to steal sensitive info or execute code

Apple has issued emergency fixes to plug security flaws in iPhones, iPads, and Macs that may already be under attack.…

  • December 1st 2023 at 21:31

UEFI flaws allow bootkits to pwn potentially hundreds of devices using images

Exploits bypass most secure boot solutions from the biggest chip vendors

Hundreds of consumer and enterprise devices are potentially vulnerable to bootkit exploits through unsecured BIOS image parsers.…

  • December 1st 2023 at 20:12

US readies prison cell for another Russian Trickbot developer

Hunt continues for the other elusive high-ranking members

Another member of the Trickbot malware crew now faces a lengthy prison sentence amid US law enforcement's ongoing search for its leading members.…

  • December 1st 2023 at 15:08

Regulator says stranger entered hospital, treated a patient, took a document ... then vanished

Scottish health group to tweak security checks, access authorization to avoid a repeat

NHS Fife is on the wrong end of a stern ticking off by Britain's data regulator after it made a howling privacy error that aided an as yet unknown person who had entered a hospital ward only to walk off with data on 14 patients.…

  • December 1st 2023 at 10:15

Interpol makes first border arrest using Biometric Hub to ID suspect

Global database of faces and fingerprints proves its worth

European police have for the first time made an arrest after remotely checking Interpol's trove of biometric data to identify a suspected smuggler.…

  • December 1st 2023 at 07:25

Today's 'China is misbehaving online' allegations come from Google, Meta

Zuck boots propagandists, Big G finds surge of action directed at Taiwan

Meta and Google have disclosed what they allege are offensive cyber ops conducted by China.…

  • December 1st 2023 at 02:59

Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes

Plus: 3 critical CVEs in Zyxel NAS devices

Google has rolled out six Chrome security fixes including one emergency patch for a bug for which exploit code is already out there. You're encouraged to thus grab the latest updates for the browser.…

  • November 30th 2023 at 20:45

Admin of $19M marketplace that sold social security numbers gets 8 years in jail

24 million Americans thought to have had their personal data stolen and sold for pennies

A Ukrainian national is facing an eight year prison sentence for running an online marketplace that sold the personal data of approximately 24 million US citizens.…

  • November 30th 2023 at 18:30

Black Basta ransomware operation nets over $100M from victims in less than two years

Assumed Conti offshoot averages 7 figures for each successful attack but may have issues with, er, 'closing deals'

The Black Basta ransomware group has reportedly generated upwards of $100 million in revenue since it started operations in April 2022.…

  • November 30th 2023 at 13:15

Locking down Industrial Control Systems

SANS unveils online hub with valuable tools and information for cybersecurity professionals defending ICS

Sponsored Post Industrial Control Systems (ICS) which can automate processes, increase productivity and reduce labour costs, are rapidly gaining worldwide enterprise traction.…

  • November 30th 2023 at 08:47

Weak session keys let snoops take a byte out of your Bluetooth traffic

BLUFFS spying flaw present in iPhones, ThinkPad, plenty of chipsets

Multiple Bluetooth chips from major vendors such as Qualcomm, Broadcom, Intel, and Apple are vulnerable to a pair of security flaws that allow a nearby miscreant to impersonate other devices and intercept data.…

  • November 30th 2023 at 07:32

US lawmakers have Chinese LiDAR on their threat-detection radar

Amid fears Beijing could harvest spatial data, letter suggests Huawei-style bans may be needed

A US congressional committee has questioned whether Chinese-made Light Detection and Ranging (LiDAR) devices might have a negative impact on national security, and suggested they may therefore be worthy of the same bans that prevent stateside adoption of other tech.…

  • November 30th 2023 at 02:29

Rogue ex-Motorola techie admits cyberattack on former employer, passport fraud

Pro tip: Don't use your new work email to phish your old firm

An ex-Motorola Solutions technician in the US has admitted he tried to fraudulently obtain a passport while awaiting trial for a cyberattack on his former employer.…

  • November 30th 2023 at 01:15

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew

CISA calls for stronger IT defenses as Texas district also hit by ransomware crew

CISA is investigating a cyberattack against a Pennsylvania water authority by suspected Iranian miscreants. The intrusion forced operators to switch a pumping station to manual control.…

  • November 29th 2023 at 21:16

Okta data breach dilemma dwarfs earlier estimates

All customer support users told their info was accessed after analysis oversight

Okta has admitted that the number of customers affected by its October customer support system data breach is far greater than previously thought.…

  • November 29th 2023 at 17:01

British Library begins contacting customers as Rhysida leaks data dump

CRM databases were accessed and library users are advised to change passwords

The Rhysida ransomware group has published most of the data it claimed to have stolen from the British Library a month after the attack was disclosed.…

  • November 29th 2023 at 12:30

UK government rings the death knell for SIM farms

Acts under the guise of protecting the public from fraud, yet history suggests Home Office has other motives

The UK government plans to introduce new legislation to ban SIM farms, which it views as a widely abused means for carrying out cyber fraud.…

  • November 29th 2023 at 11:01

Brit borough council apologizes for telling website users to disable HTTPS

Planning portal back online with a more secure connection

Reading Borough Council has securely restored its planning portal after facing criticism for recommending questionable tech security practices to users.…

  • November 29th 2023 at 09:30

Japan's space agency suffers cyber attack, points finger at Active Directory

JAXA is having a tough time in cyberspace and outer space, the latter thanks to an electrical glitch

Japan's Space Exploration Agency (JAXA) has reported a cyber incident.…

  • November 29th 2023 at 06:57

Plex gives fans a privacy complex after sharing viewing habits with friends by default

Grandma is watching what?!

Updated A new Plex "feature" has infuriated some users after sharing with others what they are watching on the streaming service. This functionality is on by default.…

  • November 28th 2023 at 20:30

Helping companies defend what attackers want most - their data

Varonis introduces Athena AI to transform data security and incident response

Partner Content Athena AI, the new generative AI layer that spans across the entire Varonis Data Security Platform, redefines how security teams protect data - from visibility to action.…

  • November 28th 2023 at 14:18

Europol shutters ransomware operation with kingpin arrests

A few low-level stragglers remain on the loose, but biggest fish have been hooked

International law enforcement investigators have made a number of high-profile arrests after tracking a major cybercrime group for more than four years.…

  • November 28th 2023 at 13:45

A bird’s eye view of your global attack surface

Get to know your external attack surface before the cyber criminals map it first

Sponsored Post Building an effective cyber security defense involves protecting the assets you know you have as well as the ones you don't.…

  • November 28th 2023 at 08:52

India's CERT given exemption from Right To Information requests

Activists worry investigations may stay secret, and then there's those odd incident reporting requirements

India's government has granted its Computer Emergency Response Team, CERT-In, immunity from Right To Information (RTI) requests – the nation's equivalent of the freedom of information queries in the US, UK, or Australia.…

  • November 28th 2023 at 06:31

'Serial cybercriminal and scammer' jailed for 8 years, told to pay back $1.2M

Crook did everything from SIM swaps to fake verified badge scams

A Los Angeles man has been jailed after pulling off SIM-swap attacks on victims, hijacking social media accounts, committing fraud with Zelle payments, and impersonating Apple support.…

  • November 28th 2023 at 01:06

Trio of major holes in ownCloud expose admin passwords, allow unauthenticated file mods

Mitigations require mix of updating libraries and manual customer action

ownCloud has disclosed three critical vulnerabilities, the most serious of which leads to sensitive data exposure and carries a maximum severity score.…

  • November 27th 2023 at 18:28

Leader of pro-Russia DDoS crew Killnet 'unmasked' by Russian state media

Also: NXP China attack, Australia can't deliver on ransom payment ban (yet), and Justin Sun's very bad month

Infosec in Brief Cybercriminals working out of Russia go to great lengths to conceal their real identities, and you won't ever find the state trying to unmask them either – as long as they keep supplying the attacks on Axis nations. It's the reason why we found it so amusing that of all the ways the identity of an organized cybercrime gang leader could be revealed, it was Russian state media that may have recently outed someone of note.…

  • November 27th 2023 at 11:02

Education is the foundation of modern cyber defence

How to enhance employee career development and retain skilled staff with SANS cyber training

Sponsored Post Every organisation needs to make cyber security training a high priority. Effective education is an essential part of improving security practices and fostering a sound security posture.…

  • November 27th 2023 at 09:57

Ransomware-hit British Library: Too open for business, or not open enough?

Unique institutions need unique security. Instead, they're fobbed off with the same old, same old

Opinion The British Library’s showpiece site, in a listed red brick building in St Pancras, is presided over by a large bronze sculpture depicting Isaac Newton poring over a document he’s working with, measuring it with dividers.…

  • November 27th 2023 at 09:30

Crypto crasher Do Kwon's extradition approved, but destination is unclear

Hey Google, are the jails nicer in South Korea or the US?

Terraform Labs founder Do Kwon – a wanted man in both South Korea and the United States – will soon face extradition from Montenegro after a court gave approval for his removal.…

  • November 27th 2023 at 05:33

Beijing fosters foreign influencers to spread its propaganda

They get access to both China's internet and global platforms, and cash in on both

China is offering foreign influencers access to its vast market in return for content that sings its praises and helps to spreads Beijing's desired narratives more widely around the world, according to think tank the Australian Strategic Policy Institute (ASPI).…

  • November 27th 2023 at 03:31

OpenCart owner turns air blue after researcher discloses serious vuln

Web storefront maker fixed the flaw, but not before blasting infoseccer

The owner of the e-commerce store management system OpenCart has responded with hostility to a security researcher disclosing a vulnerability in the product.…

  • November 24th 2023 at 15:32

BlackCat claims it is behind Fidelity National Financial ransomware shakedown

One of US's largest underwriters forced to shut down a number of key systems

Fortune 500 insurance biz Fidelity National Financial (FNF) has confirmed that it has fallen victim to a "cybersecurity incident."…

  • November 23rd 2023 at 18:01

Industry piles in on North Korea for sustained rampage on software supply chains

Kim’s cyber cronies becoming more active, sophisticated in attempts to pwn global orgs

The national cybersecurity organizations of the UK and the Republic of Korea (ROK) have issued a joint advisory warning of an increased volume and sophistication of North Korean software supply chain attacks. …

  • November 23rd 2023 at 13:38

Attack on direct debit provider London & Zurich leaves customers with 6-figure backlogs

Customers complain of poor comms during huge outage that’s sparked payroll fears

A ransomware attack and resulting outages at direct debit collection company London & Zurich has forced at least one customer to take out a short-term loan as six-figure backlogs continue to cause cash flow mayhem.…

  • November 23rd 2023 at 11:47

Stop social engineering at the IT help desk

How Secure Service Desk thwarts social engineering attacks and secures user verification

Sponsored Post Ransomware can hit any organization at any time, and hackers are proving adept at social engineering techniques to gain access to sensitive data in any way they can.…

  • November 23rd 2023 at 09:09

Mirai malware infects routers and cameras for new botnet

Akamai sounds the alarm – won't name the manufacturers yet

Akamai has uncovered two zero-day bugs capable of remote code execution, both being exploited to distribute the Mirai malware and built a botnet army for distributed denial of service (DDoS) attacks.…

  • November 23rd 2023 at 08:25

New Relic warns customers it's experienced a cyber … something

Users told to hold tight and await instructions as investigation continues

Web tracking and analytics outfit New Relic has issued a scanty security advisory warning customers it has experienced a scary cyber something.…

  • November 23rd 2023 at 04:58

North Korea makes finding a gig even harder by attacking candidates and employers

That GitHub repo an interviewer wants you to work on could be malware

Palo Alto Networks' Unit 42 has detailed a pair of job market hacking schemes linked to state-sponsored actors in North Korea: one in which the threat actors pose as job seekers, the other as would-be employers.…

  • November 23rd 2023 at 01:33
❌