FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Google brings Street View back to India following 2016 ban

July 28th 2022 at 10:28

This time local companies provide the images and there's no mention of national security worries

Google has brought its Street View service – which offers photographs of most locations on Google Maps – back to India, six years after the nation rejected it as an invasion of privacy and a threat to national security.…

☐ β˜† βœ‡ The Register - Security

FileWave fixes bugs that left 1,000+ orgs open to ransomware, data theft

July 27th 2022 at 22:33

Internet-connected MDM instances, each with an 'unrestricted number' of managed devices, were vulnerable

FileWave has fixed a couple vulnerabilities in its endpoint management software that could allow a remote attacker to bypass authentication and take full control of the deployment and associated devices.…

☐ β˜† βœ‡ The Register - Security

We're likely only seeing 'the tip of the iceberg' of Pegasus spyware use against the US

July 27th 2022 at 21:58

House intel chair raises snoop tool concerns as Google and others call for greater crack down

Google and internet rights groups have called on Congress to weigh in on spyware, asking for sanctions and increased enforcement against so-called legit surveillanceware makers.…

☐ β˜† βœ‡ The Register - Security

US puts $10 million bounty on North Korean cyber-crews

July 27th 2022 at 19:30

Kim will be shaking in his shoes

The US is offering up to $10 million for information on members of state-sponsored North Korean threat groups, double the amount that the State Department announced in April.…

☐ β˜† βœ‡ The Register - Security

Apple network traffic takes mysterious detour through Russia

July 27th 2022 at 18:56

Land of Putin capable of attacking routes in cyberspace as well as real world

Apple's internet traffic took an unwelcome detour through Russian networking equipment for about twelve hours between July 26 and July 27.…

☐ β˜† βœ‡ The Register - Security

AWS ups security for Elastic Block Store, Kubernetes service

July 27th 2022 at 17:00

Stretching its security software a bit further

Amazon’s cloud platform is extending security capabilities for a couple of its widely used services; Amazon Elastic Block Store (EBS) and Amazon Elastic Kubernetes Service (EKS).…

☐ β˜† βœ‡ The Register - Security

Knotweed Euro cyber mercenaries attacking private sector, says Microsoft

July 27th 2022 at 16:45

Reports seeing 'offensive actor' flinging SubZero malware

Microsoft has published an analysis of a Europe-based "private-sector offensive actor" with a view to helping its customers spot signs of attacks by money-hungry gangsters.…

☐ β˜† βœ‡ The Register - Security

Time from vulnerability disclosures to exploits is shrinking

July 27th 2022 at 15:00

Palo Alto Networks Unit 42 incident response team warns of patch speedups

Palo Alto Networks' annual Unit 42 incident response report is out, warning of an ever-decreasing gap between vulnerability disclosures and an increase in cybercrime.…

☐ β˜† βœ‡ The Register - Security

Weak data protection helped China attack US Federal Reserve, report says

July 27th 2022 at 10:31

Details of adversarial tradecraft detailed, includes many email accounts

China's cyber espionage activities are extensive and sophisticated but when the Middle Kingdom tried to steal sensitive economic data from the US Fed, poor security meant its operatives didn't have to dip too far into their bags of tricks.…

☐ β˜† βœ‡ The Register - Security

IBM puts NIST’s quantum-resistant crypto to work in Z16 mainframe

July 27th 2022 at 06:30

Big Blue says it helped developed the algos, so knows what it's doing

IBM has started offering quantum-resistant crypto – using the quantum-resistant crypto recommended by the US National Institute of Standards and Technology (NIST).…

☐ β˜† βœ‡ The Register - Security

Vietnamese attacker circumvents Facebook security with β€˜DUCKTAIL’ malware

July 27th 2022 at 05:03

Session cookies and 2FA subversion allow takeover of biz and ad accounts, lead to unauthorized ad buys

Security vendor WithSecure, which was spun out in March 2022 as F-Secure’s enterprise security arm, claims it’s found malware that targets Facebook Business accounts.…

☐ β˜† βœ‡ The Register - Security

Charter told to pay $7.3b in damages after cable installer murders grandmother

July 27th 2022 at 00:54

Broadband giant says it will appeal jury verdict in negligence case

Charter Communications must pay out $7 billion in damages after one of its Spectrum cable technicians robbed and killed an elderly woman, a jury decided Tuesday.…

☐ β˜† βœ‡ The Register - Security

Crypto exchange Kraken reportedly hunted by the Feds for alleged sanctions busting

July 26th 2022 at 22:36

Plus: Coinbase said to face SEC wrath, blockchain scam CEO admits using victims' millions to fund Hawaiian condo

The US government is reportedly investigating Kraken, a massive cryptocurrency exchange suspected of violating sanctions against Iran, and is expected to slap the crypto behemoth with a fine in the near future.…

☐ β˜† βœ‡ The Register - Security

Culture shock: Ransomware gang sacks arts orgs' email lists

July 26th 2022 at 21:04

Don't worry, the crooks totally deleted the data and promised not to use it for evil

A ransomware gang has not only taken down WordFly, a mailing list provider for top arts organizations among others, but also siphoned data belonging to the US-based Smithsonian, Canada's Toronto Symphony Orchestra, and the Courtauld Institute of Art in London.…

☐ β˜† βœ‡ The Register - Security

Luca Stealer malware spreads rapidly after code handily appears on GitHub

July 26th 2022 at 17:00

Cool, another Rust project ... Oh

A new info-stealer malware is spreading rapidly in the wild as the developer behind it continues to add capabilities and recently released the source code on GitHub.…

☐ β˜† βœ‡ The Register - Security

With ransomware, the road to recovery starts well before you’re attacked

July 26th 2022 at 16:55

Learn how to orchestrate your survival strategy here

Webinar Ensuring your data is protected is the first step in dealing with cyber-attacks and outages. But that's only half the job. …

☐ β˜† βœ‡ The Register - Security

Ransomware less popular this year, but malware up: SonicWall cyber threat report

July 26th 2022 at 14:26

Be ready for a rebound, and protect yourself with patching and segmentation

SonicWall has published its latest threat report, showing a drop in ransomware but an increase in malware attacks in the first half of 2022.…

☐ β˜† βœ‡ The Register - Security

Cyber security training to fit your summer plans

July 26th 2022 at 14:21

A flexible approach to cyber security training and certification from SANS & GIAC

Sponsored Post Keeping the world safe from cyber threats requires both passion and skills. And you can grow both with training that makes you battle-ready as soon as you leave the classroom.…

☐ β˜† βœ‡ The Register - Security

LockBit ransomware gang claims it ransacked Italy’s tax agency

July 26th 2022 at 07:30

Miscreants boast of 78GB haul, officials say everything's fine

The LockBit ransomware crew is claiming to have stolen 78GB of data from Italy's tax agency and is threatening to leak it if a ransom isn't paid by July 31.…

☐ β˜† βœ‡ The Register - Security

Node.js prototype pollution is bad for your app environment

July 25th 2022 at 21:46

Boffins find common code constructs that may be exploitable to achieve remote code execution

Back in March, security researchers reported a critical command injection vulnerability in Parse Server, an open-source backend for Node.js environments.…

☐ β˜† βœ‡ The Register - Security

T-Mobile US to cough up $550m after info stolen on 77m customers

July 25th 2022 at 20:58

Oops, did the Un-carrier under-count by 29m punters?

T-Mobile US has agreed to pay about $550 million to end legal action against it and improve its security after crooks infiltrated the self-described Un-carrier last summer and harvested personal data belonging to almost 77 million customers.…

☐ β˜† βœ‡ The Register - Security

Twitter launches probe after miscreants claim to have swiped 5.4m users' details

July 25th 2022 at 20:21

And yes, Musk is back in the headlines, denying another affair

Twitter is investigating claims that a near-seven-month-old vulnerability in its software has been exploited to obtain the phone numbers and email addresses of a reported 5.4 million users. …

☐ β˜† βœ‡ The Register - Security

Cyber-mercenaries for hire represent shifting criminal business model

July 25th 2022 at 17:00

Emerging threat group offers a broad range of attack services

An emerging and fast-growing threat group is using a unique business model to offer cybercriminals a broad range of services that span from leaked databases and distributed denial-of-service (DDoS) attacks to hacking scripts and, in the future, potentially ransomware.…

☐ β˜† βœ‡ The Register - Security

DoJ approves Google's acquisition of Mandiant

July 25th 2022 at 15:00

Plus: Ukrainian fake news and Uber admits covering up data breach

In Brief Google's legally fraught journey to buy cybersecurity business Mandiant is in its final stretch, with the US Department of Justice closing its investigation and giving the go-ahead for the sale to proceed.…

☐ β˜† βœ‡ The Register - Security

Infosec not your job but your responsibility? How to be smarter than the average bear

July 25th 2022 at 11:27

Many of last week's security stories tell the same tale

Opinion The calls are coming from inside the house! Lately, Outlook users have been getting their own version of this classic urban horror myth. The email system is alerting them to suspicious activity on their accounts, and helpfully providing the IP addresses responsible.…

☐ β˜† βœ‡ The Register - Security

Realizing your software has a vulnerability is bad. Realizing you’ve shipped it to thousands of customers…

July 25th 2022 at 10:54

How bad can it be? Find out with this webinar

Webinar If you realized software you'd developed contained a vulnerability that left you – and your customers - open to cyber-attack what should your first priority be?…

☐ β˜† βœ‡ The Register - Security

My Big Coin founder is – you guessed it – a $6m crypto-fraudster

July 22nd 2022 at 23:08

Con man blew victims' cash on antiques, artwork, other riches

A crook who created a business called My Big Coin to cheat victims out of more than $6 million has been found guilty by a jury.…

☐ β˜† βœ‡ The Register - Security

Microsoft closes off two avenues of attack: Office macros, RDP brute-forcing

July 22nd 2022 at 21:44

Blockade against VBA scripts in downloaded files is back on by default

Microsoft is trying to shut the door on a couple of routes cybercriminals have used to attack users and networks.…

☐ β˜† βœ‡ The Register - Security

Don't dive head first into that crypto pool, FBI warns

July 22nd 2022 at 21:00

Liquidity scams cost victims more than $70m, agents say

The FBI has warned cryptocurrency owners and would-be owners about a scam involving phony liquidity mining that the bureau says has cost victims more than $70 million in combined losses since 2019.…

☐ β˜† βœ‡ The Register - Security

At the edge, nobody can hear your IoT devices scream …

July 22nd 2022 at 09:43

Red Hat’s approach to locking down remote industrial networks and data processing facilities

Sponsored Feature If you've ever wondered what edge computing looks like in action, you could do worse than study the orbiting multi-dimensional challenge that is the multi-agency International Space Station (ISS).…

☐ β˜† βœ‡ The Register - Security

British intelligence recycles old argument for thwarting strong encryption: Think of the children!

July 22nd 2022 at 07:30

Levy and Robinson are at it again

Comment Two notorious characters from the British security services have published a paper that once again suggests breaking strong end-to-end encryption would be a good thing for society. …

☐ β˜† βœ‡ The Register - Security

Russia, Iran discuss tech manufacturing, infosec and e-governance collaboration

July 22nd 2022 at 03:01

Proposed working group would see Moscow's miltech conglomerate Rostec operate in Tehran

Iran's Communications Ministry joined in a pledge with Russian state-owned defence and technology conglomerate Rostec to explore future collaboration in e-government, information security, and other areas.…

☐ β˜† βœ‡ The Register - Security

Ex-Coinbase manager charged in first-ever crypto insider trading case

July 21st 2022 at 22:20

Exec, his brother, and a pal raked in $1.5m in illicit gains, Feds claim

A now-former Coinbase manager, his brother, and a friend were today charged with wire fraud conspiracy and wire fraud in connection with the first-ever cryptocurrency insider trading scheme in the US.…

☐ β˜† βœ‡ The Register - Security

US Cyber Command spots another 20 malware strains targeting Ukraine

July 21st 2022 at 20:29

Plus Mandiant, Cisco Talos uncover digital espionage

US Cyber Command has disclosed 20 new strains of malware among the numerous software nasties and cyberattacks being used against Ukrainian targets over the last few months.…

☐ β˜† βœ‡ The Register - Security

Simplifying backup and recovery management

July 21st 2022 at 13:49

Removing the risks of fragmented data protection

Webinar Nothing ever stays the same for long in IT. New ways to meet the changing requirements of businesses are constantly needed alongside in-house structural and policy reforms, plus the added complication of complying with new and updated regulations.…

☐ β˜† βœ‡ The Register - Security

DataDome looks to CAPTCHA the moment with test of humanity that doesn't hurt

July 21st 2022 at 12:15

As the verification technology weathers ongoing criticism from users, one anti-bot security vendor rolls out its own tool

Apple last month gave hope to a large segment of the mobile device-using population when it announced that the upcoming iOS 16 operating system will eliminate the requirement to use CAPTCHAs to verify their humanity before accessing a website.…

☐ β˜† βœ‡ The Register - Security

Outlook email users alerted to suspicious activity from Microsoft-owned IP address

July 21st 2022 at 10:27

Netizens turn amateur sleuths to discover Windows giant is the source of weird login attempts

Updated Strange things are afoot in the world of Microsoft email with multiple users reporting unusual sign-in notifications for their Outlook accounts.…

☐ β˜† βœ‡ The Register - Security

What does software supply chain pain really feel like? Find out right here

July 21st 2022 at 10:19

This Immersive Labs webinar will make it feel mighty real

Webinar The explosion of open-source projects in recent years has allowed organizations to build ever more complex architectures using their pick of components developed by specialists or "the community".…

☐ β˜† βœ‡ The Register - Security

Atlassian reveals critical flaws in almost everything it makes and touches

July 21st 2022 at 01:54

Fixes issued, warns it 'has not exhaustively enumerated all potential consequences'

Atlassian has warned users of its Bamboo, Bitbucket, Confluence, Fisheye, Crucible, and Jira products that a pair of critical-rated flaws threaten their security.…

☐ β˜† βœ‡ The Register - Security

Suspected Gozi malware gang 'CIO' extradited to US on fraud, hacking charges

July 20th 2022 at 23:56

Euro man allegedly known as 'Virus' faces years behind bars if convicted

A man suspected of providing the IT infrastructure behind the Gozi banking trojan has been extradited to the US to face a string of computer fraud charges.…

☐ β˜† βœ‡ The Register - Security

Google: Kremlin-backed goons spread Android malware disguised as pro-Ukraine app

July 20th 2022 at 20:36

Don't. Download. Unknown. Apps.

Kremlin-backed criminals are trying to trick people into downloading Android malware by spoofing a Ukrainian military group, according to Google security researchers.…

☐ β˜† βœ‡ The Register - Security

Boffins release tool to decrypt Intel microcode. Have at it, x86 giant says

July 20th 2022 at 19:59

Peek behind the curtain to see SGX implemented, Spectre mitigated, and more

Infosec boffins have released a tool to decrypt and unpack the microcode for a class of low-power Intel CPUs, opening up a way to look at how the chipmaker has implemented various security fixes and features as well as things like virtualization.…

☐ β˜† βœ‡ The Register - Security

DoJ, FBI recover $500,000 in ransomware payments to Maui gang

July 20th 2022 at 15:45

Money paid by healthcare facilities to North Korean group traced through blockchain and Chinese launderers

Federal law enforcement officials this week said they seized about $500,000 that healthcare facilities in the United States paid to the Maui ransomware group.…

☐ β˜† βœ‡ The Register - Security

Singapore distances itself from local crypto companies

July 20th 2022 at 10:45

Consumer protection regulation coming soon as anti-crypto rhetoric ratchets

The Monetary Authority of Singapore (MAS) said on Tuesday that its cryptocurrency regulations will add measures to protect consumers, in addition to ongoing work to contain money laundering and terrorist funding.…

☐ β˜† βœ‡ The Register - Security

Amazon sues 10,000 Facebook Group admins for offering fake reviews

July 20th 2022 at 06:33

Good luck deciding which toxic monopolist deserves your sympathy in this fight

Amazon is suing over 10,000 administrators of Facebook groups that offer to post fake reviews on the online souk's website in exchange for products and money.…

☐ β˜† βœ‡ The Register - Security

Belgium says Chinese cyber gangs attacked its government and military

July 20th 2022 at 03:15

China, as usual, says it just wants a peaceful and prosperous internet

The government of Belgium has claimed it detected three Chinese Advanced Persistent Threat actors attacking its public service and defence forces.…

☐ β˜† βœ‡ The Register - Security

Security flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns

July 19th 2022 at 23:15

About '1.5 million' folks and organizations use these gadgets

A handful of vulnerabilities, some critical, in MiCODUS GPS tracker devices could allow criminals to disrupt fleet operations and spy on routes, or even remotely control or cut off fuel to vehicles, according to CISA. And there's no fixes for these security flaws.…

☐ β˜† βœ‡ The Register - Security

Google pulls malware-infected apps in its Store, over 3 million users at risk

July 19th 2022 at 20:00

Some people call me the code cowboy, some call me the gangster of root, 'cause I'm a Joker

Google pulled 60 malware-infected apps from its Play Store, installed by more than 3.3 million punters, that can be used for all kinds of criminal activities including credential theft, spying and even stealing money from victims.…

☐ β˜† βœ‡ The Register - Security

Walmart-controlled flight booking service suffers substantial data leak

July 19th 2022 at 11:15

India's Cleartrip is being very opaque about what happened

An Indian flight booking website majority-owned by US retail colossus Walmart has experienced a data breach, but is saying very little about what happened or the risks to customers.…

☐ β˜† βœ‡ The Register - Security

Jailed crooks told to cough up $600k for COVID fraud

July 19th 2022 at 01:59

Poetic justice? The virus does love it in some federal prisons

Two Florida residents will spend years behind bars and pay more than half a million dollars for wire fraud and identity theft, among other illicit deeds, for running COVID-19 scams.…

☐ β˜† βœ‡ The Register - Security

Bogus cryptocurrency apps steal millions in mere months

July 18th 2022 at 21:46

As if the crypto world needs any help in making money vanish

Cybercriminals posing as legitimate investment firms and cryptocurrency exchanges have stolen tens of millions of dollars from more than 200 people by convincing them to download mobile apps and deposit cryptocurrency into wallets owned by the perpetrators.…

☐ β˜† βœ‡ The Register - Security

Botnet malware disguises itself as password cracker for industrial controllers

July 18th 2022 at 19:12

Can't get into that machine? No problem, just trust this completely sketchy looking tool

Industrial engineers and operators are being lured into running backdoor malware disguised as tools for recovering access to work systems.…

☐ β˜† βœ‡ The Register - Security

Albanian government websites go dark after cyberattack

July 18th 2022 at 15:00

Citizen services only moved online in May. What could possibly go wrong?

Updated Albania's online public services and websites have gone dark following what appears to be a cyberattack.…

☐ β˜† βœ‡ The Register - Security

Microsoft's latest security patch troubles Windows 11 users

July 18th 2022 at 14:00

The curse of Patch Tuesday strikes again as error codes wreak minor havoc

Updated Complaints over Microsoft's latest patch Tuesday have intensified after some Windows 11 users found their systems worse for wear following installation.…

☐ β˜† βœ‡ The Register - Security

Bill for US telcos to bin Chinese kit blows out by $3 billion

July 18th 2022 at 04:59

Carriers likely to get cents on the dollar for ditched Huawei and ZTE kit unless more funds are found

The US Federal Communications Commission (FCC) notified Congress on Friday that the cost to rip and replace equipment kit from Huawei and ZTE installed at US telcos is more than $3 billion higher than funding allocated for the program.…

☐ β˜† βœ‡ The Register - Security

TikTok's chief security officer steps aside, thanks to Oracle move

July 18th 2022 at 03:58

Takes up advisory role that might leave time to play with parent company's homebrew cloudy SmartNICs

TikTok's Global Chief Security Officer Roland Cloutier has "transitioned" from his job into "a strategic advisory role focusing on the business impact of security and trust programs."…

☐ β˜† βœ‡ The Register - Security

Alibaba execs hauled in to discuss Shanghai Police data leak

July 18th 2022 at 01:15

Plus: Weibo cracks down on political puns; Singaporean crypto biz Vauld restructures; Philippines fights Facebook rumors

Asia In Brief Senior execs from Alibaba Cloud were summoned to discuss the data leak that saw information pertaining to a billion Chinese citizens sold on the dark web, according to Nikkei and The Wall Street Journal.…

☐ β˜† βœ‡ The Register - Security

North Koreans spotted harassing SMBs with malware

July 16th 2022 at 14:34

Also: Lawyers told to dissuade clients from paying off ransomware crooks, and more

In brief SMBs, beware: Microsoft said this week it has discovered a North Korean crew targeting small businesses with ransomware since September of last year.…

☐ β˜† βœ‡ The Register - Security

CISA pulls the fire alarm on Juniper Networks bugs

July 15th 2022 at 20:57

Hate to ruin your Friday

Juniper Networks has patched critical-rated bugs across its Junos Space, Contrail Networking and NorthStar Controller products that are serious enough to prompt CISA to weigh in and advise admins to update the software as soon as possible.…

☐ β˜† βœ‡ The Register - Security

Thousands of websites run buggy WordPress plugin that allows complete takeover

July 15th 2022 at 19:15

All versions are susceptible, there's no patch, so now's a good time to remove this add-on

Miscreants have reportedly scanned almost 1.6 million websites in attempts to exploit an arbitrary file upload vulnerability in a previously disclosed buggy WordPress plugin.…

❌