FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

US treasury whips up sanctions for crypto mixer Tornado Cash

August 8th 2022 at 23:00

Being the money launderer for North Korea’s Lazarus Group comes at a price

The US Treasury Department is levying sanctions against Tornado Cash, a notorious cryptocurrency mixer that it says has been used by threat groups like ransomware gang Lazarus to launder stolen digital assets.…

☐ β˜† βœ‡ The Register - Security

Twilio customer data exposed after its staffers got phished

August 8th 2022 at 17:45

Comms giant says several other firms targeted in 'sophisticated attack'

Twilio confirmed a breach of the communication giant's network and accessed "a limited number" of customer accounts after tricking some employees into falling for a phishing attack.…

☐ β˜† βœ‡ The Register - Security

Microsoft tightens Edge security for less visited websites

August 8th 2022 at 17:15

We're pretty sure that doesn't mean it's safe to click on sketchy popups

Microsoft wants to make it safer for Edge users to browse and visit unfamiliar websites by automatically applying stronger security settings.…

☐ β˜† βœ‡ The Register - Security

Slack leaked hashed passwords from its servers for years

August 8th 2022 at 11:45

Users who created shared invitation links for their workspace had login details slip out among encrypted traffic

Did Slack send you a password reset link last week? The company has admitted to accidentally exposing the hashed passwords of workspace users.…

☐ β˜† βœ‡ The Register - Security

Dark Utilities C2 service draws thousands of cyber criminals

August 8th 2022 at 06:31

Nascent platform provides miscreants an easier and cheaper way to launch remote access, DDoS, and other attacks

A platform that makes it easier for cyber criminals to establish command-and-control (C2) servers has already attracted 3,000 users since launching earlier this year, and will likely expand its client list in the coming months.…

☐ β˜† βœ‡ The Register - Security

DuckDuckGo says Hell, Hell, No to those Microsoft trackers after web revolt

August 6th 2022 at 19:41

Plus: That Twitter privacy leak, scammers send Ubers for victims, critical flaw in Cisco gear, and more

In brief DuckDuckGo has finally mostly cracked down on the third-party Microsoft tracking scripts that got the alternative search engine into hot water earlier this year.…

☐ β˜† βœ‡ The Register - Security

Hi, I'll be your ransomware negotiator today – but don't tell the crooks that

August 6th 2022 at 08:19

What it's like bargaining with criminals ... and advising clients suffering their worst day yet

Interview The first rule of being a ransomware negotiator is that you don't admit you're a ransomware negotiator β€” at least not to LockBit or another cybercrime gang. …

☐ β˜† βœ‡ The Register - Security

Nomad to crypto thieves: Please give us back 90%, keep 10% as a reward. Deal?

August 5th 2022 at 19:43

The Feds may see things differently

Cryptocurrency bridge Nomad sent a message to the looters who drained nearly $200 million in tokens from its coffers earlier this week: return at least 90 percent of the ill-gotten gains, keep 10 percent as a bounty for discovering the security flaw, and Nomad will consider this a "white-hat" hack, as opposed to plain old theft, and not take legal action.…

☐ β˜† βœ‡ The Register - Security

Warning! Critical flaws found in US Emergency Alert System

August 5th 2022 at 18:05

DEF CON may be about to blow lid off security hole

The US government is warning of critical vulnerabilities in its Emergency Alert System (EAS) systems that, if exploited, could enable intruders to send fake alerts out over television, radio, and cable networks.…

☐ β˜† βœ‡ The Register - Security

Critical flaws found in four Cisco SMB router ranges – for the second time this year

August 5th 2022 at 06:57

At least Switchzilla thinks they're salvageable, unlike the boxes it ordered binned back in June

Cisco has revealed four of its small business router ranges have critical flaws – for the second time in 2022 alone.…

☐ β˜† βœ‡ The Register - Security

Bloke robbed of $800,000 in cryptocurrency by fake wallet app wants payback from Google

August 4th 2022 at 23:45

I got played via the Play store

Last October, California resident Jacob Pearlman downloaded an Android version of a cryptocurrency wallet app called Phantom from the Google Play app store.…

☐ β˜† βœ‡ The Register - Security

Taiwanese military reports DDoS in wake of Pelosi visit

August 4th 2022 at 12:23

Controversial visit to Taiwan continues to reverberate through cyberspace, the real world, and the semiconductor industry

Taiwan's Ministry of National Defense confirmed it was hit by a DDoS attack on Wednesday in what has been an eventful week for the island nation, US-Sino relations, and semiconductors.…

☐ β˜† βœ‡ The Register - Security

India scraps data protection law in favor of better law coming … sometime

August 4th 2022 at 06:58

Tech giants and digital rights groups didn't like it, but at least it was a law

The government of India has scrapped the Personal Data Protection Bill it's worked on for three years, and announced it will – eventually – unveil a superior bill.…

☐ β˜† βœ‡ The Register - Security

Student crashes Cloudflare beta party, redirects email, bags a bug bounty

August 4th 2022 at 06:31

Simple to exploit, enough to pocket $3,000

A Danish ethical hacker was able to work his way uninvited into a closed Cloudflare beta and found a vulnerability that could have been exploited by a cybercriminal to hijack and steal someone else's email.…

☐ β˜† βœ‡ The Register - Security

UK Parliament bins its TikTok account over China surveillance fears

August 4th 2022 at 05:58

Plan to educate the children turned out to be a 'won't someone think of the children?' moment

The UK's Parliament has ended its presence on TikTok after MPs pointed out the made-in-China social media service probably sends data about its users back to Beijing.…

☐ β˜† βœ‡ The Register - Security

Solana, Phantom blame Slope after millions in crypto-coins stolen from 8,000 wallets

August 4th 2022 at 03:26

SOL holders literally S.O.L.

Millions of dollars worth of Solana cryptocurrency and other tokens were stolen from seemingly thousands of netizens this week by thieves exploiting some kind of security weakness or blunder.…

☐ β˜† βœ‡ The Register - Security

Microsoft widens enterprise access to its threat intelligence pool

August 3rd 2022 at 21:31

Organizations can be more proactive in tracking threats, finding holes in their protection

Microsoft says it will give enterprise security operation centers (SOCs) broader access to the massive amount of threat intelligence it collects every day.…

☐ β˜† βœ‡ The Register - Security

Ex-T-Mobile US store owner phished staff, raked in $25m from unlocking phones

August 3rd 2022 at 20:17

That's just the tip of the iceberg – and now he faces potentially years in the clink

A now-former T-Mobile US store stole at least 50 employees' work credentials to run a phone unlocking and unblocking service that prosecutors said netted $25 million.…

☐ β˜† βœ‡ The Register - Security

Sonatype shines light on typosquatting ransomware threat in PyPI

August 3rd 2022 at 17:15

It's all fun and games until somebody gets their files encrypted

Miscreants making use of typosquatting are being spotted by researchers at Sonatype, emphasizing the need to check that the package is really the one you meant to download.…

☐ β˜† βœ‡ The Register - Security

You can’t choose when you’ll be hit by ransomware, but you can choose how you prepare

August 3rd 2022 at 15:46

Without a road to recovery, you’re just going to be roadkill

Sponsored Feature What sort of disaster would you rather prepare for? Hurricanes are destructive, but you know when one's coming, giving you time to take defensive action. Earthquakes vary in their destructive power, but you never know when they're going to hit, meaning your ability to recover after the impact is critical.…

☐ β˜† βœ‡ The Register - Security

NortonLifeLock and Avast $8.6b deal gets provisional yes from UK regulator

August 3rd 2022 at 11:30

Plus: Even market authorities can't seem to keep up with Microsoft's Defender branding

The UK's Competition and Markets Authority has given a provisional nod to the proposed merger of British cybersecurity company Avast and US rival NortonLifeLock.…

☐ β˜† βœ‡ The Register - Security

Post-quantum crypto cracked in an hour with one core of an ancient Xeon

August 3rd 2022 at 06:59

NIST's nifty new algorithm looks like it's in trouble

One of the four encryption algorithms America's National Institute of Standards and Technology (NIST) considered as likely to resist decryption by quantum computers has had holes kicked in it by researchers using a single core of a regular Intel Xeon CPU, released in 2013.…

☐ β˜† βœ‡ The Register - Security

Nancy Pelosi ties Chinese cyber-attacks to need for Taiwan visit

August 3rd 2022 at 02:58

And as if to confirm the link, a DDoS takes out Taiwan's presidential website ahead of senior politico's arrival

Speaker of the US House of Representatives Nancy Pelosi has tied her controversial visit to Taiwan to an alleged barrage of China-directed cyber-attacks against the territory.…

☐ β˜† βœ‡ The Register - Security

VMware patches critical 'make me admin' auth bypass bug, plus nine other flaws

August 3rd 2022 at 00:26

Meanwhile, a security update for rsync

VMware has fixed a critical authentication bypass vulnerability that hits 9.8 out of 10 on the CVSS severity scale and is present in multiple products.…

☐ β˜† βœ‡ The Register - Security

How a crypto bridge bug led to a $200m 'decentralized crowd looting'

August 2nd 2022 at 23:34

Flash mob exploits Nomad's validation code blunder

Cryptocurrency bridge service Nomad, which describes itself as "an optimistic interoperability protocol that enables secure cross-chain communication," has been drained of tokens notionally worth $190.7 million if exchanged for US dollars.…

☐ β˜† βœ‡ The Register - Security

Robinhood's crypto unit hit with $30m fine over security, anti-crime misses

August 2nd 2022 at 19:42

And just lays off about a quarter of staff

Updated Robinhood's cryptocurrency operations has been formally fined $30 million for violating New York's anti-money-laundering and cybersecurity regulations.…

☐ β˜† βœ‡ The Register - Security

How cybercrims embrace messaging apps to spread malware, communicate

August 2nd 2022 at 17:45

Underground forums are so last year. Telegram, Discord offer better privacy, functionality to criminals, says Intel 471

Cybercriminals are turning to messaging apps like Telegram and Discord as alternatives to popular underground forums: not only for the private communications and security features but also as avenues for spreading malware.…

☐ β˜† βœ‡ The Register - Security

Bot army risk as 3,000+ apps found spilling Twitter API keys

August 2nd 2022 at 14:45

Please stop leaving credentials where miscreants can find them

Want to build your own army? Engineers at CloudSEK have published a report on how to do just that in terms of bots and Twitter, thanks to API keys leaking from applications.…

☐ β˜† βœ‡ The Register - Security

Miscreants aim to cause Discord discord with malicious npm packages

August 2nd 2022 at 09:31

LofyLife campaign comes amid GitHub security lockdown

Cybercriminals continue to use npm packages to drop malicious packages on unsuspecting victims, most recently to steal Discord login tokens, bank card data, and other user information from infected systems.…

☐ β˜† βœ‡ The Register - Security

Charges filed over $300m 'textbook pyramid and Ponzi scheme' crypto startup

August 2nd 2022 at 01:09

Financial watchdog accuses 11 of playing role in alleged scam

Forsage, an alleged crypto Ponzi scheme purporting to be a decentralized smart contract platform, bilked millions of investors worldwide out of more than $300 million, according to America's securities watchdog.…

☐ β˜† βœ‡ The Register - Security

Defence against the dark arts of ransomware

August 1st 2022 at 16:30

Locking in safeguards against incursion with Rubrik Zero Trust Security

Webinar It's just any old Monday, already you are mentally ticking off the to do list, and then, as you reach for your morning coffee and switch on your screen. Devastation. You've been hacked.…

☐ β˜† βœ‡ The Register - Security

Akamai: We stopped record DDoS attack in Europe

August 1st 2022 at 07:27

A 'sophisticated, global botnet' held an Eastern European biz under siege over 30 days

Akamai Technologies squelched the largest-ever distributed denial-of-service (DDoS) attack in Europe earlier this month against a company that was being consistently hammered over a 30-day period.…

☐ β˜† βœ‡ The Register - Security

Spyware developer charged by Australian Police after 14,500 sales

August 1st 2022 at 00:30

PLUS: India open to space tourism; China/Indonesia infosec pact; Paytm denies breach; Infosys dodges government again; and more

Asia In Brief Australia's federal police (AFP) on Friday charged a man with creating and profiting from spyware that allowed total remote control of victims' computers.…

☐ β˜† βœ‡ The Register - Security

Tim Hortons offers free coffee and donut to settle data privacy invasion claims

July 30th 2022 at 13:25

Also, malicious VBA macros are out and container files are in, Robin Banks helps criminals rob banks, and more

In brief Canadian fast food chain Tim Hortons is settling multiple data privacy class-action lawsuits against it by offering something it knows it's good for: a donut and coffee.…

☐ β˜† βœ‡ The Register - Security

This is what to expect when a managed service provider gets popped

July 30th 2022 at 00:30

MSP should just stand for My Server's Pwned!

A Russian-language miscreant claims to have hacked their way into a managed service provider, and has asked for help monetizing what's said to be access to the networks and computers of that MSP's 50-plus US customers.…

☐ β˜† βœ‡ The Register - Security

Feds put $10m bounty on Putin pal accused of bankrolling US election troll farm

July 29th 2022 at 19:39

Just in time for the midterms

The Feds have put up a $10 million reward for information about foreign interference in US elections in general, and more specifically a Russian oligarch and close friend of President Vladimir Putin accused of funding an organization that meddled in the 2016 presidential elections.…

☐ β˜† βœ‡ The Register - Security

Decentralized IPFS networks forming the 'hotbed of phishing'

July 29th 2022 at 18:00

P2P file system makes it more difficult to detect and take down malicious content

Threat groups are increasingly turning to InterPlanetary File System (IPFS) peer-to-peer data sites to host their phishing attacks because the decentralized nature of the sharing system means malicious content is more effective and easier to hide.…

☐ β˜† βœ‡ The Register - Security

BreachForums booms on the back of billion-record Chinese data leak

July 29th 2022 at 07:05

Plenty of recent users appear to be from China, and hoping for more leaks of local data

The popularity of stolen data bazaar BreachForums surged after it was used to sell a giant database of stolen information describing Chinese citizens, threat intelligence firm Cybersixgill said on Thursday.…

☐ β˜† βœ‡ The Register - Security

Businesses confess: We pass cyberattack costs onto customers

July 29th 2022 at 06:30

Cover an average of $4.4 million per raid ourselves? No chance, mate

The costs incurred by organizations suffering data losses continue to go up, and 60 percent of companies surveyed by IBM said they were passing them onto customers.…

☐ β˜† βœ‡ The Register - Security

US court system suffered 'incredibly significant attack' – sealed files at risk

July 29th 2022 at 04:29

Effects still being felt today across US government

The United States' federal court system "faced an incredibly significant and sophisticated cyber security breach, one which has since had lingering impacts on the department and other agencies."…

☐ β˜† βœ‡ The Register - Security

JPMorgan, UBS among trio accused of shoddy ID theft protection

July 28th 2022 at 21:59

SEC extracts pocket change from bankers, wags finger, sends them on their way

JPMorgan Securities, UBS Financial Services, and TradeStation Securities aren't doing enough to thwart crooks who want to steal customers' identity, says America's financial watchdog.…

☐ β˜† βœ‡ The Register - Security

Suspected radiation alert saboteurs cuffed by cops after sensors disabled

July 28th 2022 at 19:19

You might say the police were in their element

Spain's national police say they have arrested two former government workers suspected of breaking into the computer network of the country's radioactivity alert system (RAR) and disabling more than a third of its sensors.…

☐ β˜† βœ‡ The Register - Security

Google brings Street View back to India following 2016 ban

July 28th 2022 at 10:28

This time local companies provide the images and there's no mention of national security worries

Google has brought its Street View service – which offers photographs of most locations on Google Maps – back to India, six years after the nation rejected it as an invasion of privacy and a threat to national security.…

☐ β˜† βœ‡ The Register - Security

FileWave fixes bugs that left 1,000+ orgs open to ransomware, data theft

July 27th 2022 at 22:33

Internet-connected MDM instances, each with an 'unrestricted number' of managed devices, were vulnerable

FileWave has fixed a couple vulnerabilities in its endpoint management software that could allow a remote attacker to bypass authentication and take full control of the deployment and associated devices.…

☐ β˜† βœ‡ The Register - Security

We're likely only seeing 'the tip of the iceberg' of Pegasus spyware use against the US

July 27th 2022 at 21:58

House intel chair raises snoop tool concerns as Google and others call for greater crack down

Google and internet rights groups have called on Congress to weigh in on spyware, asking for sanctions and increased enforcement against so-called legit surveillanceware makers.…

☐ β˜† βœ‡ The Register - Security

US puts $10 million bounty on North Korean cyber-crews

July 27th 2022 at 19:30

Kim will be shaking in his shoes

The US is offering up to $10 million for information on members of state-sponsored North Korean threat groups, double the amount that the State Department announced in April.…

☐ β˜† βœ‡ The Register - Security

Apple network traffic takes mysterious detour through Russia

July 27th 2022 at 18:56

Land of Putin capable of attacking routes in cyberspace as well as real world

Apple's internet traffic took an unwelcome detour through Russian networking equipment for about twelve hours between July 26 and July 27.…

☐ β˜† βœ‡ The Register - Security

AWS ups security for Elastic Block Store, Kubernetes service

July 27th 2022 at 17:00

Stretching its security software a bit further

Amazon’s cloud platform is extending security capabilities for a couple of its widely used services; Amazon Elastic Block Store (EBS) and Amazon Elastic Kubernetes Service (EKS).…

☐ β˜† βœ‡ The Register - Security

Knotweed Euro cyber mercenaries attacking private sector, says Microsoft

July 27th 2022 at 16:45

Reports seeing 'offensive actor' flinging SubZero malware

Microsoft has published an analysis of a Europe-based "private-sector offensive actor" with a view to helping its customers spot signs of attacks by money-hungry gangsters.…

☐ β˜† βœ‡ The Register - Security

Time from vulnerability disclosures to exploits is shrinking

July 27th 2022 at 15:00

Palo Alto Networks Unit 42 incident response team warns of patch speedups

Palo Alto Networks' annual Unit 42 incident response report is out, warning of an ever-decreasing gap between vulnerability disclosures and an increase in cybercrime.…

☐ β˜† βœ‡ The Register - Security

Weak data protection helped China attack US Federal Reserve, report says

July 27th 2022 at 10:31

Details of adversarial tradecraft detailed, includes many email accounts

China's cyber espionage activities are extensive and sophisticated but when the Middle Kingdom tried to steal sensitive economic data from the US Fed, poor security meant its operatives didn't have to dip too far into their bags of tricks.…

☐ β˜† βœ‡ The Register - Security

IBM puts NIST’s quantum-resistant crypto to work in Z16 mainframe

July 27th 2022 at 06:30

Big Blue says it helped developed the algos, so knows what it's doing

IBM has started offering quantum-resistant crypto – using the quantum-resistant crypto recommended by the US National Institute of Standards and Technology (NIST).…

☐ β˜† βœ‡ The Register - Security

Vietnamese attacker circumvents Facebook security with β€˜DUCKTAIL’ malware

July 27th 2022 at 05:03

Session cookies and 2FA subversion allow takeover of biz and ad accounts, lead to unauthorized ad buys

Security vendor WithSecure, which was spun out in March 2022 as F-Secure’s enterprise security arm, claims it’s found malware that targets Facebook Business accounts.…

☐ β˜† βœ‡ The Register - Security

Charter told to pay $7.3b in damages after cable installer murders grandmother

July 27th 2022 at 00:54

Broadband giant says it will appeal jury verdict in negligence case

Charter Communications must pay out $7 billion in damages after one of its Spectrum cable technicians robbed and killed an elderly woman, a jury decided Tuesday.…

☐ β˜† βœ‡ The Register - Security

Crypto exchange Kraken reportedly hunted by the Feds for alleged sanctions busting

July 26th 2022 at 22:36

Plus: Coinbase said to face SEC wrath, blockchain scam CEO admits using victims' millions to fund Hawaiian condo

The US government is reportedly investigating Kraken, a massive cryptocurrency exchange suspected of violating sanctions against Iran, and is expected to slap the crypto behemoth with a fine in the near future.…

☐ β˜† βœ‡ The Register - Security

Culture shock: Ransomware gang sacks arts orgs' email lists

July 26th 2022 at 21:04

Don't worry, the crooks totally deleted the data and promised not to use it for evil

A ransomware gang has not only taken down WordFly, a mailing list provider for top arts organizations among others, but also siphoned data belonging to the US-based Smithsonian, Canada's Toronto Symphony Orchestra, and the Courtauld Institute of Art in London.…

☐ β˜† βœ‡ The Register - Security

Luca Stealer malware spreads rapidly after code handily appears on GitHub

July 26th 2022 at 17:00

Cool, another Rust project ... Oh

A new info-stealer malware is spreading rapidly in the wild as the developer behind it continues to add capabilities and recently released the source code on GitHub.…

☐ β˜† βœ‡ The Register - Security

With ransomware, the road to recovery starts well before you’re attacked

July 26th 2022 at 16:55

Learn how to orchestrate your survival strategy here

Webinar Ensuring your data is protected is the first step in dealing with cyber-attacks and outages. But that's only half the job. …

☐ β˜† βœ‡ The Register - Security

Ransomware less popular this year, but malware up: SonicWall cyber threat report

July 26th 2022 at 14:26

Be ready for a rebound, and protect yourself with patching and segmentation

SonicWall has published its latest threat report, showing a drop in ransomware but an increase in malware attacks in the first half of 2022.…

☐ β˜† βœ‡ The Register - Security

Cyber security training to fit your summer plans

July 26th 2022 at 14:21

A flexible approach to cyber security training and certification from SANS & GIAC

Sponsored Post Keeping the world safe from cyber threats requires both passion and skills. And you can grow both with training that makes you battle-ready as soon as you leave the classroom.…

❌