FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ The Register - Security

Russia, Iran discuss tech manufacturing, infosec and e-governance collaboration

July 22nd 2022 at 03:01

Proposed working group would see Moscow's miltech conglomerate Rostec operate in Tehran

Iran's Communications Ministry joined in a pledge with Russian state-owned defence and technology conglomerate Rostec to explore future collaboration in e-government, information security, and other areas.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Ex-Coinbase manager charged in first-ever crypto insider trading case

July 21st 2022 at 22:20

Exec, his brother, and a pal raked in $1.5m in illicit gains, Feds claim

A now-former Coinbase manager, his brother, and a friend were today charged with wire fraud conspiracy and wire fraud in connection with the first-ever cryptocurrency insider trading scheme in the US.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

US Cyber Command spots another 20 malware strains targeting Ukraine

July 21st 2022 at 20:29

Plus Mandiant, Cisco Talos uncover digital espionage

US Cyber Command has disclosed 20 new strains of malware among the numerous software nasties and cyberattacks being used against Ukrainian targets over the last few months.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Simplifying backup and recovery management

July 21st 2022 at 13:49

Removing the risks of fragmented data protection

Webinar Nothing ever stays the same for long in IT. New ways to meet the changing requirements of businesses are constantly needed alongside in-house structural and policy reforms, plus the added complication of complying with new and updated regulations.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

DataDome looks to CAPTCHA the moment with test of humanity that doesn't hurt

July 21st 2022 at 12:15

As the verification technology weathers ongoing criticism from users, one anti-bot security vendor rolls out its own tool

Apple last month gave hope to a large segment of the mobile device-using population when it announced that the upcoming iOS 16 operating system will eliminate the requirement to use CAPTCHAs to verify their humanity before accessing a website.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Outlook email users alerted to suspicious activity from Microsoft-owned IP address

July 21st 2022 at 10:27

Netizens turn amateur sleuths to discover Windows giant is the source of weird login attempts

Updated Strange things are afoot in the world of Microsoft email with multiple users reporting unusual sign-in notifications for their Outlook accounts.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

What does software supply chain pain really feel like? Find out right here

July 21st 2022 at 10:19

This Immersive Labs webinar will make it feel mighty real

Webinar The explosion of open-source projects in recent years has allowed organizations to build ever more complex architectures using their pick of components developed by specialists or "the community".โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Atlassian reveals critical flaws in almost everything it makes and touches

July 21st 2022 at 01:54

Fixes issued, warns it 'has not exhaustively enumerated all potential consequences'

Atlassian has warned users of its Bamboo, Bitbucket, Confluence, Fisheye, Crucible, and Jira products that a pair of critical-rated flaws threaten their security.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Suspected Gozi malware gang 'CIO' extradited to US on fraud, hacking charges

July 20th 2022 at 23:56

Euro man allegedly known as 'Virus' faces years behind bars if convicted

A man suspected of providing the IT infrastructure behind the Gozi banking trojan has been extradited to the US to face a string of computer fraud charges.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Google: Kremlin-backed goons spread Android malware disguised as pro-Ukraine app

July 20th 2022 at 20:36

Don't. Download. Unknown. Apps.

Kremlin-backed criminals are trying to trick people into downloading Android malware by spoofing a Ukrainian military group, according to Google security researchers.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Boffins release tool to decrypt Intel microcode. Have at it, x86 giant says

July 20th 2022 at 19:59

Peek behind the curtain to see SGX implemented, Spectre mitigated, and more

Infosec boffins have released a tool to decrypt and unpack the microcode for a class of low-power Intel CPUs, opening up a way to look at how the chipmaker has implemented various security fixes and features as well as things like virtualization.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

DoJ, FBI recover $500,000 in ransomware payments to Maui gang

July 20th 2022 at 15:45

Money paid by healthcare facilities to North Korean group traced through blockchain and Chinese launderers

Federal law enforcement officials this week said they seized about $500,000 that healthcare facilities in the United States paid to the Maui ransomware group.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Singapore distances itself from local crypto companies

July 20th 2022 at 10:45

Consumer protection regulation coming soon as anti-crypto rhetoric ratchets

The Monetary Authority of Singapore (MAS) said on Tuesday that its cryptocurrency regulations will add measures to protect consumers, in addition to ongoing work to contain money laundering and terrorist funding.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Amazon sues 10,000 Facebook Group admins for offering fake reviews

July 20th 2022 at 06:33

Good luck deciding which toxic monopolist deserves your sympathy in this fight

Amazon is suing over 10,000 administrators of Facebook groups that offer to post fake reviews on the online souk's website in exchange for products and money.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Belgium says Chinese cyber gangs attacked its government and military

July 20th 2022 at 03:15

China, as usual, says it just wants a peaceful and prosperous internet

The government of Belgium has claimed it detected three Chinese Advanced Persistent Threat actors attacking its public service and defence forces.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Security flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns

July 19th 2022 at 23:15

About '1.5 million' folks and organizations use these gadgets

A handful of vulnerabilities, some critical, in MiCODUS GPS tracker devices could allow criminals to disrupt fleet operations and spy on routes, or even remotely control or cut off fuel to vehicles, according to CISA. And there's no fixes for these security flaws.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Google pulls malware-infected apps in its Store, over 3 million users at risk

July 19th 2022 at 20:00

Some people call me the code cowboy, some call me the gangster of root, 'cause I'm a Joker

Google pulled 60 malware-infected apps from its Play Store, installed by more than 3.3 million punters, that can be used for all kinds of criminal activities including credential theft, spying and even stealing money from victims.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Walmart-controlled flight booking service suffers substantial data leak

July 19th 2022 at 11:15

India's Cleartrip is being very opaque about what happened

An Indian flight booking website majority-owned by US retail colossus Walmart has experienced a data breach, but is saying very little about what happened or the risks to customers.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Jailed crooks told to cough up $600k for COVID fraud

July 19th 2022 at 01:59

Poetic justice? The virus does love it in some federal prisons

Two Florida residents will spend years behind bars and pay more than half a million dollars for wire fraud and identity theft, among other illicit deeds, for running COVID-19 scams.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Bogus cryptocurrency apps steal millions in mere months

July 18th 2022 at 21:46

As if the crypto world needs any help in making money vanish

Cybercriminals posing as legitimate investment firms and cryptocurrency exchanges have stolen tens of millions of dollars from more than 200 people by convincing them to download mobile apps and deposit cryptocurrency into wallets owned by the perpetrators.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Botnet malware disguises itself as password cracker for industrial controllers

July 18th 2022 at 19:12

Can't get into that machine? No problem, just trust this completely sketchy looking tool

Industrial engineers and operators are being lured into running backdoor malware disguised as tools for recovering access to work systems.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Albanian government websites go dark after cyberattack

July 18th 2022 at 15:00

Citizen services only moved online in May. What could possibly go wrong?

Updated Albania's online public services and websites have gone dark following what appears to be a cyberattack.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Microsoft's latest security patch troubles Windows 11 users

July 18th 2022 at 14:00

The curse of Patch Tuesday strikes again as error codes wreak minor havoc

Updated Complaints over Microsoft's latest patch Tuesday have intensified after some Windows 11 users found their systems worse for wear following installation.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Bill for US telcos to bin Chinese kit blows out by $3 billion

July 18th 2022 at 04:59

Carriers likely to get cents on the dollar for ditched Huawei and ZTE kit unless more funds are found

The US Federal Communications Commission (FCC) notified Congress on Friday that the cost to rip and replace equipment kit from Huawei and ZTE installed at US telcos is more than $3 billion higher than funding allocated for the program.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

TikTok's chief security officer steps aside, thanks to Oracle move

July 18th 2022 at 03:58

Takes up advisory role that might leave time to play with parent company's homebrew cloudy SmartNICs

TikTok's Global Chief Security Officer Roland Cloutier has "transitioned" from his job into "a strategic advisory role focusing on the business impact of security and trust programs."โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Alibaba execs hauled in to discuss Shanghai Police data leak

July 18th 2022 at 01:15

Plus: Weibo cracks down on political puns; Singaporean crypto biz Vauld restructures; Philippines fights Facebook rumors

Asia In Brief Senior execs from Alibaba Cloud were summoned to discuss the data leak that saw information pertaining to a billion Chinese citizens sold on the dark web, according to Nikkei and The Wall Street Journal.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

North Koreans spotted harassing SMBs with malware

July 16th 2022 at 14:34

Also: Lawyers told to dissuade clients from paying off ransomware crooks, and more

In brief SMBs, beware: Microsoft said this week it has discovered a North Korean crew targeting small businesses with ransomware since September of last year.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

CISA pulls the fire alarm on Juniper Networks bugs

July 15th 2022 at 20:57

Hate to ruin your Friday

Juniper Networks has patched critical-rated bugs across its Junos Space, Contrail Networking and NorthStar Controller products that are serious enough to prompt CISA to weigh in and advise admins to update the software as soon as possible.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Thousands of websites run buggy WordPress plugin that allows complete takeover

July 15th 2022 at 19:15

All versions are susceptible, there's no patch, so now's a good time to remove this add-on

Miscreants have reportedly scanned almost 1.6 million websites in attempts to exploit an arbitrary file upload vulnerability in a previously disclosed buggy WordPress plugin.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Windows Network File System flaw results in arbitrary code execution as SYSTEM

July 15th 2022 at 14:15

Follina was all very exciting, but did you patch CVE-2022-30136?

Trend Micro Research has published an anatomy of a Windows remote code execution vulnerability lurking in the Network File System.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Digital burglary at recruitment agency Morgan Hunt confirmed

July 15th 2022 at 07:30

Third-party software developer blamed for 'improperly storing credentials to our database'

The bad news keeps on rolling for British recruitment agency Morgan Hunt amid confirmation it suffered a digital burglary, with intruders making off with the personal data for some of the freelancers on its books.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Meet Mantis โ€“ the tiny shrimp that launched 3,000 DDoS attacks

July 15th 2022 at 02:28

Watch out for deadly pinchers after that record-breaking attack

The botnet behind the largest-ever HTTPS-based distributed-denial-of-service (DDoS) attack has been named after a tiny shrimp.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Homeland Security warns: Expect Log4j risks for 'a decade or longer'

July 14th 2022 at 22:59

Great, another thing that's gone endemic

Organizations can expect risks associated with Log4j vulnerabilities for "a decade or longer," according to the US Department of Homeland Security.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Lenovo issues firmware updates after UEFI vulnerabilities disclosed

July 14th 2022 at 16:15

Dรฉjร  vu all over again for laptop maker as researchers poke holes in its code

Security researchers have spotted fresh flaws in Lenovo laptops just months after the vendor patched a bunch of its products.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Cloud security needs assistants

July 14th 2022 at 15:45

Join the Register and Palo Alto Networks to hear the merits of the agents vs agentless approach

Webinar Cloud security is a challenge likely to keep a lot of IT professionals awake at night. So there might be some relief in knowing what types of tool offer the best protection โ€“ agent-based or agentless โ€“ and if organizations really have to rely on just one or the other.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Amazon gave Ring video to cops without consent or warrant 11 times so far in 2022

July 14th 2022 at 13:45

Got no time for that red tape in an emergency, says exec

Updated Amazon's home security wing Ring turned over footage to US law enforcement without permission from the devices' owners and seemingly without a warrant 11 times so far in 2022.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Why less can be more in backup and recovery management

July 14th 2022 at 08:40

The simplified approach to data protection in hybrid clouds

Webinar Most IT infrastructures evolve over time as the needs of the business and its users change to meet fresh demands and comply with updated organizational policies and regulatory requirements.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

1.9m patient records exposed in healthcare debt collector ransomware attack

July 13th 2022 at 21:06

The P in PFC now stands for Pwned

Professional Finance Company, a Colorado-based debt collector whose customers include hundreds of US hospitals, medical clinics, and dental groups, recently disclosed that private data โ€“ including names, addresses, social security numbers, and health records โ€“ for more than 1.9 million people was exposed during a ransomware infection.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

This big phish can swim around MFA, says Microsoft Security

July 13th 2022 at 19:04

Slippery AiTM attacks targeted more than 10,000 orgs over the past nine months

A widespread phishing campaign that has hit more than 10,000 organizations since September 2021 uses adversary-in-the-middle (AiTM) proxy sites to get around multifactor authentication (MFA) features and steal credentials that are then used to compromise business email accounts.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

SCOTUS judges 'doxxed' after overturning Roe v Wade

July 13th 2022 at 18:28

Physical and IP addresses as well as credit card info revealed in privacy breach

The US Supreme Court justices who overturned Roe v. Wade last month may have been doxxed โ€“ had their personal information including physical and IP addresses, and credit card info revealed โ€“ according to threat intel firm Cybersixgill.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Mergers and acquisitions put zero trust to the ultimate test

July 13th 2022 at 17:00

Bypasses an arduous integration process with right security footing from the start

When Jay Chaudhry launched Zscaler in 2007, he envisioned a number of use cases for the zero-trust platform, from security for a growing distributed, virtualized IT environment a nascent cloud computing environment to improved network visibility and identity governance.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

X.org servers update closes 2 security holes, adds neat component tweaks

July 13th 2022 at 16:00

Arbitrary code execution flaws in the X Keyboard Extension were bad news

X.org has released a bunch of updates, which includes closing two security holes and, yes, this affects Wayland users too.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Microsoft's July Patch Tuesday fixes actively exploited bug

July 12th 2022 at 22:11

No, Windows Autopatch didn't kill the monthly patchapalooza

Patch Tuesday Despite worries that Patch Tuesday may not be as exciting now that Microsoft's Windows Autopatch is live โ€” with a slew of caveats โ€” the second Tuesday of this month arrived with 84 security fixes, including 4 critical bugs and one that's under active exploit.ย โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Amazon squashes years-old authentication bugs in AWS Kubernetes service

July 12th 2022 at 18:45

Three vulnerabilities in one line of code

AWS fixed three authentication bugs present in one line of code in its IAM Authenticator for Kubernetes, used by the cloud giant's popular managed Kubernetes service Amazon EKS, that could allow an attacker to escalate privileges within a Kubernetes cluster.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Older AMD, Intel chips vulnerable to data-leaking 'Retbleed' Spectre variant

July 12th 2022 at 16:00

Speculative execution side-channels continue to haunt silicon world

Older AMD and Intel chips are vulnerable to yet another Spectre-based speculative-execution attack that exposes secrets within kernel memory despite defenses already in place. Mitigating this side channel is expected to take a toll on performance.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Microsoft 365 patches for Windows 7 to end in 2023

July 12th 2022 at 12:15

By then you won't be able to install the suite on Windows 8.1

Microsoft has warned users clinging to Windows 7 and Windows 8.1 that the end really is nigh.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

UK Info Commissioner slams use of WhatsApp by health officials during pandemic

July 12th 2022 at 06:55

Sure, stuff got done fast โ€“ but personal information was put at risk

The UK Information Commissioner's Office (ICO) on Monday issued a reprimand and called for a review of how and whether messaging services should be used for government business practices, after finding widespread and potentially dangerous use of private email, WhatsApp and other messaging tools by officials at the Department of Health and Social Care (DHSC).โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Take the day off: Windows Autopatch is live and can even fix cloudy PCs

July 12th 2022 at 06:03

But first, there's a whole lot of AD and Intune prep to be done

Microsoft's promised service to enable automatic, continuous patching of Windows has gone live.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

San Francisco cops want real-time access to private security cameras for surveillance

July 11th 2022 at 23:24

ACLU hits back at 'unprecedented power grab'

San Francisco lawmakers are mulling a proposed law that would allow police to use private security cameras โ€“ think: those in residential doorbells, medical clinics, and retail shops โ€“ in real time for surveillance purposes.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Security vendor splits โ€“ not quits โ€“ to address Russia's invasion of Ukraine

July 7th 2022 at 10:44

Singapore's Group-IB was once a Moscow startup and will now conduct 'regional diversification'

Singapore-based security vendor and services provider Group-IB has commenced a "regional diversification" program that will see it not just continue to operate in Russia (unlike a great many other companies), but do so with a dedicated entity.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

Defense contractor pays $9m to settle whistleblower's cybersecurity allegations

July 11th 2022 at 18:18

Former Aerojet Rocketdyne employee cites failure to meet minimums for NASA, Pentagon

Aerojet Rocketdyne, which makes propulsion and power systems for launch vehicles, missiles and satellites for NASA and the US military, has agreed to pay $9 million to settle charges it misrepresented its products' compliance with cybersecurity requirements in federal government contracts.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

HavanaCrypt ransomware sails in as a fake Google update

July 11th 2022 at 16:00

Difficult to detect, hiding its window by using the ShowWindow function in Windows

A new ransomware family is being delivered as a bogus Google Software Update, using Microsoft functionality as part of its attack.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

US military contractor moves to buy Israeli spy-tech company NSO Group

July 11th 2022 at 13:00

Biden blacklist a stumbling block for any possible deal

US security technology provider L3Harris has courted controversial Israeli spyware firm NSO with an aim to buy it, according to reports.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

UK response to China's tech ambitions labelled 'incoherent and muted'

July 11th 2022 at 04:59

Working outside power blocs, without policy, leaves Blighty a likely rule-taker says Foreign Affairs Committee

The UK's response to China's well-publicized efforts to use technology standards to shape the world in its image has been "incoherent and muted" according to report by the House of Commons Foreign Affairs Committee.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

How data on a billion people may have leaked from a Chinese police dashboard

July 10th 2022 at 16:48

Record-breaking dump thanks to password-less Kibana endpoint?

Details have emerged on how more than a billion personal records were stolen in China and put up for sale on the dark web, and it all boils down to a unprotected online dashboard that left the data open to anyone who could find it.โ€ฆ

โ˜ โ˜† โœ‡ The Register - Security

How to survive a SYN flood attack

July 8th 2022 at 14:02

G-Core Labs' XDP-based DDoS protection platform filters bad traffic across a network of high capacity CDNs

Sponsored Post If you do any sort of business via the web, the damage caused by a distributed denial of service (DDoS) attack could be catastrophic for your bottom line.โ€ฆ

โŒ