FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

FTC goes undercover to probe suspected antivirus scam, scores $26M settlement

Imagine trying to trick folks into buying $500 of unnecessary repairs – and they turn out to be federal agents

A pair of tech support businesses accused of swindling marks out of their hard-earned cash have agreed to cough up a $26 million settlement following an undercover probe by the FTC.…

  • March 14th 2024 at 20:24

LockBit ransomware kingpin gets 4 years behind bars

Canadian-Russian said to have turned to a life of cybercrime during pandemic, now must pay the price – literally

A LockBit ransomware kingpin has been sentenced to almost four years behind bars and ordered to pay more than CA$860,000 ($635,000, Β£500,000) in restitution to some of his victims by a Canadian court as he awaits extradition to the US.…

  • March 14th 2024 at 18:26

Google gooses Safe Browsing with real-time protection that doesn't leak to ad giant

Rare occasion when you do want Big Tech to make a hash of it

Google has enhanced its Safe Browsing service to enable real-time protection in Chrome for desktop, iOS, and soon Android against risky websites, without sending browsing history data to the ad biz.…

  • March 14th 2024 at 17:58

Record breach of French government exposes up to 43 million people's data

Zut alors! Department for registering and helping unemployed people broken into

A French government department - responsible for registering and assisting unemployed people - is the latest victim of a mega data breach that compromised the information of up to 43 million citizens.…

  • March 14th 2024 at 16:06

International effort to disrupt cybercrime moves into operational phase

Will the WEF experiment work?

The Cybercrime Atlas, a massive undertaking that aims to disrupt cybercriminals across the globe, enters its operational phase in 2024, two years after organizers laid the groundwork at the RSA Conference.…

  • March 14th 2024 at 15:00

US to probe Change Healthcare's data protection standards as lawsuits mount

Services slowly coming back online but providers still struggling

Change Healthcare is being investigated over the alleged 6 TB data theft by the ALPHV ransomware group as it continues recovery efforts.…

  • March 14th 2024 at 14:03

US Congress goes bang, bang, on TikTok sale-or-ban plan

Bill proposes to do to China what China already does to the US – make life hard for foreign social networks

The United States House of Representatives on Wednesday passed the Protecting Americans from Foreign Adversary Controlled Applications Act – a law aimed at forcing TikTok's Chinese parent ByteDance to sell the app's US operations or face the prospect of a ban.…

  • March 14th 2024 at 01:46

Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack

Akira ransomware crooks brag of swiping thousands of ID documents during break-in

Over the next few weeks, Nissan Oceania will make contact with around 100,000 people in Australia and New Zealand whose data was pilfered in a December 2023 attack on its systems – perhaps by the Akira ransomware gang.…

  • March 14th 2024 at 00:32

Poking holes in Google tech bagged bug hunters $10M

A $2M drop from previous year. So … things are more secure?

Google awarded $10 million to 632 bug hunters last year through its vulnerability reward programs.…

  • March 13th 2024 at 18:00

Cryptocurrency laundryman gets hung out to dry

Bitcoin Fog washed hundreds of millions for criminals

The operator of the world's longest-running Bitcoin money laundering service faces a 50-year prison sentence after being found guilty in a US court.…

  • March 13th 2024 at 16:45

Microsoft Copilot for Security prepares for April liftoff

Automated AI helper intended to make security more manageable

Microsoft Copilot for Security, a subscription AI security service, will be generally available on April 1, 2024, the company announced on Wednesday.…

  • March 13th 2024 at 16:00

Stanford University failed to detect ransomware intruders for 4 months

27,000 individuals had data stolen, which for some included names and social security numbers

Stanford University says the cybersecurity incident it dealt with last year was indeed ransomware, which it failed to spot for more than four months.…

  • March 13th 2024 at 12:05

Reducing the cloud security overhead

Why creating a layered defensive strategy that includes security by design can help address cloud challenges

Sponsored Feature The world is filled with choices. Whether it's the 20 different types of shampoo on offer at the grocery store, or the dozens of Linux distros you can try for free, you can have it all.…

  • March 13th 2024 at 08:51

Whizkids jimmy OpenAI, Google's closed models

Infosec folk aren’t thrilled that if you poke APIs enough, you learn AI's secrets

Boffins have managed to pry open closed AI services from OpenAI and Google with an attack that recovers an otherwise hidden portion of transformer models.…

  • March 13th 2024 at 08:34

March Patch Tuesday sees Hyper-V join the guest-host escape club

Critical bugs galore among 61 Microsoft fixes, 56 from Adobe, a dozen from SAP, and a fistful from Fortinet

Patch Tuesday Microsoft's monthly patch drop has arrived, delivering a mere 61 CVE-tagged vulnerabilities – none listed as under active attack or already known to the public.…

  • March 13th 2024 at 00:16

Meta sues ex infra VP for allegedly stealing top-secret datacenter blueprints

Exec accused of using own work PC to swipe confidential AI and staffing docs for stealth cloud startup

An ex-Meta veep has been sued by his former bosses for "brazenly disloyal and dishonest conduct" – and by that, they mean he allegedly stole confidential documents to help him build and recruit colleagues for an AI cloud startup. …

  • March 12th 2024 at 22:39

Biden's budget proposal boosts CISA funding to $3B

Plus almost $1.5b for health-care cybersecurity

US President Joe Biden has asked Congress to approve an extra $103 million in funding for the Cybersecurity and Infrastructure Security Agency, bringing CISA's total budget to $3 billion.…

  • March 12th 2024 at 18:30

JetBrains is still mad at Rapid7 for the ransomware attacks on its customers

War of words wages on between vendors divided

Last week, we wrote about how security outfit Rapid7 threw JetBrains, the company behind the popular CI/CD platform TeamCity, under the bus over allegations of silent patching. Now, JetBrains has gone on the offensive.…

  • March 12th 2024 at 16:30

UK council yanks IT systems and phone lines offline following cyber ambush

Targeting recovery this week, officials still trying to 'dentify the nature of the incident'

Leicester City Council says IT systems and a number of its critical service phone lines will remain down until later this week at the earliest following a "cyber incident".…

  • March 12th 2024 at 11:45

French government sites disrupted by très grande DDoS

Russia and Sudan top the list of suspects

Several French government websites have been disrupted by a severe distributed denial of service attack.…

  • March 12th 2024 at 06:26

White House and lawmakers increase pressure on UnitedHealth to ease providers' pain

US senator calls cyber attack 'inexcusable,' calls for mandatory security rules

The Biden administration and US lawmakers are turning up the pressure on UnitedHealth group to ease medical providers' pain after the ransomware attack on Change Healthcare, by expediting payments to hospitals, physicians and pharmacists – among other tactics.…

  • March 12th 2024 at 00:02

Kremlin accuses America of plotting cyberattack on Russian voting systems

Don't worry, we have a strong suspicion Putin's still gonna win

The Kremlin has accused the United States of meddling in Russia's upcoming presidential election, and even accused Uncle Sam of planning a cyberattack on the country's online voting system.…

  • March 11th 2024 at 21:58

British Library pushes the cloud button, says legacy IT estate cause of hefty rebuild

Five months in and the mammoth post-ransomware recovery has barely begun

The British Library says legacy IT is the overwhelming factor delaying efforts to recover from the Rhysida ransomware attack in late 2023.…

  • March 11th 2024 at 13:30

How do you lot feel about Pay or say OK to ads model, asks ICO

And does it count as consent?

The UK's Information Commissioner's Office (ICO) has opened a consultation on "consent or pay" business models. We're sure readers of The Register will have a fair few things to say.…

  • March 11th 2024 at 11:16

Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability

PLUS: NSA shares cloud security tips; Infosec training for Jordanian women; Critical vulnerabilities

Infosec in brief Cybersecurity researchers informed Microsoft that Notorious North Korean hackers Lazarus Group discovered the "holy grail" of rootkit vulnerabilities in Windows last year, but Redmond still took six months to patch the problem.…

  • March 11th 2024 at 04:28

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

Plus: CISA pulls plug on couple of systems feared compromised

There's yet another group of miscreants out there hijacking insecure Ivanti devices: A new, financially motivated gang dubbed Magnet Goblin has emerged from the shadowy digital depths with a knack for rapidly exploiting newly disclosed vulnerabilities before vendors have issued a fix.…

  • March 8th 2024 at 22:55

Microsoft confirms Russian spies stole source code, accessed internal systems

Still 'no evidence' of any compromised customer-facing systems, we're told

Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant also characterized the intrusion as "ongoing."…

  • March 8th 2024 at 16:56

Change Healthcare registers pulse after crippling ransomware attack

Remaining services are expected to return in the coming weeks after $22M ALPHV ransom

Change Healthcare has taken the first steps toward a full recovery from the ransomware attack in February by bringing its electronic prescription services back online.…

  • March 8th 2024 at 14:33

Chrome users – get an alert when extensions are in danger of falling into wrong hands

Under New Management is an early-warning system for potential poisoning of add-ons with malware

Millions of Chrome users now have a way to guard against the threat of extension subversion, that is, if they don't mind installing yet another browser extension.…

  • March 7th 2024 at 19:45

Swiss cheese security? Play ransomware gang milks government of 65,000 files

Classified docs, readable passwords, and thousands of personal information nabbed in Xplain breach

The Swiss government had around 65,000 files related to it stolen by the Play ransomware gang during an attack on an IT supplier, its National Cyber Security Center (NCSC) says.…

  • March 8th 2024 at 12:35

Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva

Who knew that unzipping a font archive could unleash a malicious file

Online graphic design platform Canva went looking for security problems in fonts, and found three – in "strange places."…

  • March 8th 2024 at 03:57

Securing open source software: Whose job is it, anyway?

CISA announces more help, and calls on app makers to step up

The US government and some of the largest open source foundations and package repositories have announced a series of initiatives intended to improve software supply-chain security, while also repeating calls for developers to increase support for such efforts.…

  • March 8th 2024 at 01:02

We're not Meta support: State AGs tell Zuck to fix rampant account takeover problem

'We refuse to operate as customer service representatives'

A group of 41 US state attorneys general, tired of serving as a customer complaint clearinghouse for Facebook and Instagram users, have sent a letter to Meta asking it to figure out how to reduce a "dramatic and persistent spike" in account takeovers.…

  • March 7th 2024 at 21:45

Possible China link to Change Healthcare ransomware attack

Alleged crim bought SmartScreen Killer, Cobalt Strike on dark-web markets

A criminal claiming to be an ALPHV/BlackCat affiliate β€” the gang responsible for the widely disruptive Change Healthcare ransomware infection last month β€”Β  may have ties to Chinese government-backed cybercrime syndicates.…

  • March 7th 2024 at 18:30

JetBrains TeamCity under attack by ransomware thugs after disclosure mess

More than 1,000 servers remain unpatched and vulnerable

Security researchers are increasingly seeing active exploit attempts using the latest vulnerabilities in JetBrains' TeamCity that in some cases are leading to ransomware deployment.…

  • March 7th 2024 at 16:34

Belgian ale legend Duvel's brewery borked as ransomware halts production

Biz reassures quaffers it has enough beer, expects quick recovery before weekend

Belgian beer brewer Duvel says a ransomware attack has brought its facility to a standstill while its IT team works to remediate the damage.…

  • March 7th 2024 at 12:45

VMware urges emergency action to blunt hypervisor flaws

Critical vulns in USB under ESXi and desktop hypervisors found by Chinese researchers at cracking contest

Hypervisors are supposed to provide an inviolable isolation layer between virtual machines and hardware. But hypervisor heavyweight VMware by Broadcom yesterday revealed its hypervisors are not quite so inviolable as it might like.…

  • March 7th 2024 at 07:30

Reminder: Infostealer malware is coming for your ChatGPT credentials

Singaporean researchers note rising presence of OpenAI logins in infostealer malware logs

Stolen ChatGPT credentials are a hot commodity on the dark web, according to Singapore-based threat intelligence firm Group-IB, which claims to have found some 225,000 log files containing login details for the service last year.…

  • March 7th 2024 at 06:27

US politicians want ByteDance to sell off TikTok or face ban

The American mind must not be at the mercy of Chinese algorithms

A group of US lawmakers introduced legislation on Tuesday that, if passed, would force Chinese internet concern ByteDance to divest TikTok – its most valuable property – or see it banned in the US.…

  • March 7th 2024 at 06:05

Lawsuit claims gift card fraud is the gift that keeps on giving, to Google

Play Store commissions are a nice little earner, wherever they come from

Google has been accused of profiting from gift card scams.…

  • March 7th 2024 at 01:15

Chinese chap charged with stealing Google’s AI datacenter secrets

Moonlighted for PRC companies after side-stepping Big G's security, allegedly

A now-former Google employee has been charged with stealing the ad giant’s AI trade secrets while quietly working for two Chinese companies – after easily defeating whatever security controls Big G had in place.…

  • March 7th 2024 at 00:37

FBI: Critical infrastructure suffers spike in ransomware attacks

Jump in overall cybercrime reports, $60M-plus reportedly lost to extortionists alone, Feds reckon

Digital crimes potentially cost victims more than $12.5 billion last year, according to the FBI's latest Internet Crime Complaint Center (IC3) annual report. …

  • March 6th 2024 at 20:49

Apple's trademark tight lips extend to new iPhone, iPad zero-days

Two flaws fixed, one knee bent to the EU, and a budding cybersecurity star feature in iOS 17.4

Apple's latest security patches address four vulnerabilities affecting iOS and iPadOS, including two zero-days that intel suggests attackers have already exploited.…

  • March 6th 2024 at 17:01

Capita says 2023 cyberattack costs a factor as it reports staggering Β£100M+ loss

Additional cuts announced, sparking fears of further layoffs

Outsourcing giant Capita today reported a net loss of Β£106.6 million ($135.6 million) for calendar 2023, with the costly cyberattack by criminals making a hefty dent in its annual financials.…

  • March 6th 2024 at 12:31

Chip lobby group SEMI to EU: Export restrictions should only be used in self-defense

Please don't scare away foreign investors - who do you think pays for this stuff?

SEMI, an industry association representing 3,000 chip vendors, would really appreciate it if the European Union would back off plans to impose export controls on China, arguing that they should only be used as a "last resort" to protect national security.…

  • March 6th 2024 at 08:23

Japan orders local giants LINE and NAVER to disentangle their tech stacks

Government mighty displeased about a shared Active Directory that led to a big data leak

Japan's government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users' data exposed.…

  • March 6th 2024 at 03:29

Uncle Sam intervenes as Change Healthcare ransomware fiasco creates mayhem

As the crooks behind the attack - probably ALPHV/BlackCat - fake their own demise

The US government has stepped in to help hospitals and other healthcare providers affected by the Change Healthcare ransomware infection, offering more relaxed Medicare rules and urging advanced funding to providers.…

  • March 6th 2024 at 00:30

Fidelity customers' financial info feared stolen in suspected ransomware attack

Insurance giant blames Infosys, LockBit claims credit

Criminals have probably stolen nearly 30,000 Fidelity Investments Life Insurance customers' personal and financial information β€” including bank account and routing numbers, credit card numbers and security or access codes β€” after breaking into Infosys' IT systems in the fall.…

  • March 5th 2024 at 19:28

US accuses Army vet cyber-Casanova of sharing Russia-Ukraine war secrets

Where better to expose confidential data than on a dating app?

Yet another US military man is facing a potentially significant stretch in prison after allegedly sending secret national defense information (NDI) overseas.…

  • March 5th 2024 at 17:06

IP address X-posure now a feature on Musk's social media thing

Just a little FYI

Video and audio calling features for X Premium users added last year to Elon Musk's version of Twitter have been expanded to everyone on the platform, and FYI: It may reveal your IP address to those you're nattering away to.…

  • March 5th 2024 at 16:18

Rapid7 throws JetBrains under the bus for 'uncoordinated vulnerability disclosure'

Exploits began within hours of the original disclosure, so patch now

Updated Security shop Rapid7 is criticizing JetBrains for flouting its policy against silent patching regarding fixes for two fresh vulnerabilities in the TeamCity CI/CD server.…

  • March 5th 2024 at 13:15

Spam crusade lands charity in hot water with data watchdog

Penny Appeal sent more than 460,000 texts asking for money to help war-torn countries, no opt out

Typically it is energy improvement peddlers or debt help specialists that are disgraced by Britain's data watchdog for spamming unsuspecting households, but the latest entrant in the hall of shame is a charity.…

  • March 5th 2024 at 09:30

Cloudflare wants to put a firewall in front of your LLM

Claims to protect against DDoS, sensitive data leakage

Cloudflare has tweaked its web application firewall (WAF) to add protections for applications using large language models.…

  • March 5th 2024 at 01:32

American Express admits card data exposed and blames third party

Don't leave home without … IT security

A security failure at a third-party vendor exposed an untold number of American Express card numbers, expiry dates, and other data to persons unknown.…

  • March 4th 2024 at 23:04

Change Healthcare attack latest: ALPHV bags $22M in Bitcoin amid affiliate drama

No honor among thieves?

ALPHV/BlackCat, the gang behind the Change Healthcare cyberattack, has received more than $22 million in Bitcoin in what might be a ransomware payment.…

  • March 4th 2024 at 21:01

Seoul accuses North Korea of stealing southern chipmakers' designs

Kim Jong Un's all in for home-built silicon says warning

North Korean government spies have broken into the servers of at least two chipmakers and stolen product designs as part of attempts to spur Kim Jong Un's plans for a domestic semiconductor industry, according to Seoul's security agency.…

  • March 4th 2024 at 20:00

German defense chat overheard by Russian eavesdroppers on Cisco's WebEx

Officials can't tell whether the tape was edited, but fear Kremlin has more juicy bits to release in the future

The German Ministry of Defense (Bundeswehr) has confirmed that a recording of a call between high-ranking officials discussing war efforts in Ukraine, leaked by Russian media, is legitimate.…

  • March 4th 2024 at 17:45

Ransomware ban backers insist thugs must be cut off from payday

Increasingly clear number of permanent solutions is narrowing

Global law enforcement authorities' attempts to shutter the LockBit ransomware crew have sparked a fresh call for a ban on ransomware payments to perpetrators.…

  • March 4th 2024 at 14:30

The federal bureau of trolling hits LockBit, but the joke's on us

When you can't lock 'em up, lock 'em out

Opinion The best cop shows excel at mind games: who's tricking whom, who really wins, and what price they pay. A twist of humor adds to the drama and keeps us hooked. It's rare enough in real life, far less so in the grim meat grinder of cybersecurity, yet sometimes it happens. It's happening right now.…

  • March 4th 2024 at 09:30

LockBit's contested claim of fresh ransom payment suggests it's been well hobbled

ALSO: CISA warns Ivanti vuln mitigations might not work, SAML hijack doesn't need ADFS, and crit vulns

Infosec in brief The infamous LockBit ransomware gang has been busy in the ten days since an international law enforcement operation took down many of its systems. But despite its posturing, the gang might have suffered more than it's letting on.…

  • March 4th 2024 at 03:15
❌