FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Go programming language arrives at security warnings that are useful

September 6th 2022 at 22:40

Low-noise tool hopes to highlight vulnerabilities imported into projects

The open source Go programming language, developed by Google, has added support for vulnerability management in a way designed to preserve programmers' patience.…

☐ β˜† βœ‡ The Register - Security

Cyberattack brings down InterContinental Hotels' booking systems

September 6th 2022 at 20:42

Online booking systems and other services knocked offline amid network intrusion

The IT systems of InterContinental Hotels Group, the massive hospitality organization that operates 17 hotel brands around the world, have been compromised, causing ongoing disruption to the corporation's online booking systems and other services.…

☐ β˜† βœ‡ The Register - Security

Ransomware gang hits second-largest US school district

September 6th 2022 at 17:45

FBI and CISA on-site to assist with incident response over Labor Day weekend

Updated Cybercriminals hit the Los Angeles Unified School District (LAUSD) over the holiday weekend with a ransomware attack that temporarily shut down email, computer systems, and applications.…

☐ β˜† βœ‡ The Register - Security

Newly discovered cyberspy crew targets Asian governments and corporations

September 6th 2022 at 16:15

Worok uses mix of publicly available tools, custom malware to steal info, gang active since 2020

A cyberespionage group has targeted government agencies and big-name corporations throughout Asia since at least 2020, using the notorious ProxyShell vulnerabilities in Microsoft Exchange to gain initial access.…

☐ β˜† βœ‡ The Register - Security

Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay

September 6th 2022 at 13:30

Lloyd's defends stance as critics say policy tweaks make it less worthwhile to spend on premiums

Critics unhappy about insurers excluding certain nation-state attacks from cyber policies should consider the alternative: higher prices, according to Lloyd's of London.…

☐ β˜† βœ‡ The Register - Security

Nadine Dorries promotes 'Brexit rewards' of proposed UK data protection law

September 5th 2022 at 11:06

Culture secretary talks up pre-Commons reading as UK waits to hear who new leader will be

On the day the UK is set to appoint its new prime minister, digital and culture secretary Nadine Dorries is introducing legislation in Parliament she promises will β€œdrop unnecessary box-ticking and measures stifling British businesses.”…

☐ β˜† βœ‡ The Register - Security

Maximum protection against hostile incursions

September 5th 2022 at 13:57

Want to hear more about the critical role of identity in Zero Trust security? Join our webinar on 20th September

Webinar The cyber security of any organisation or enterprise relies on the integrity of its identity management structure. After all, there's no shortage of bad actors looking for a chink in the wall.…

☐ β˜† βœ‡ The Register - Security

NATO investigates after criminals claim to be selling its stolen missile plans

September 5th 2022 at 13:04

Also, Microsoft’s one-click TikTok trick, a 14-year old Aussie cracks ASD encryption in an hour, and more

In brief NATO officials are investigating after criminals put up some data for sale on dark forums that they claim is "classified" information stolen from European missile maker MBDA.…

☐ β˜† βœ‡ The Register - Security

Microsoft mistakenly rated Chromium, Electron as malware

September 5th 2022 at 06:57

Windows Defender update fixed the mess after a weekend of false positive weirdness

Microsoft appears to have fixed a problem that saw its Defender antivirus program identify apps based on the Chromium browser engine and/or Electron JavaScript framework as malware, and suggest users remove them.…

☐ β˜† βœ‡ The Register - Security

China orders tech companies to 'improve traceability' of users to control 'rumours and false information'

September 5th 2022 at 00:32

PLUS: Australia mints a physical crypto-coin; Alibaba Cloud claims world's biggest DC; India’s space airbags; and more

China will conduct a three month blitz to cleanse the local internet of "rumors and false information".…

☐ β˜† βœ‡ The Register - Security

Google, YouTube ban election trolls ahead of US midterms

September 2nd 2022 at 23:26

Plus: Truth Social barred from Play until it shows just one iota of decency

Google and its YouTube subsidiary have joined other social media networks pledging to keep the 2022 US midterm elections safe and free from Russian trolls β€” and anyone else spewing democracy-damaging disinformation – by taking down such content.…

☐ β˜† βœ‡ The Register - Security

Convicted felon busted for 3D printing gun parts

September 2nd 2022 at 20:24

Just days after US rules tackling homemade firearms take effect

A US man has admitted he broke the law when he used 3D printers to make components converting semi-automatic guns to full auto.…

☐ β˜† βœ‡ The Register - Security

Revealed: US telcos admit to storing, handing over location data

September 2nd 2022 at 17:15

Letters to FCC confirm what many believed, don't address a bigger problem

US mobile carriers know a lot about where their customers every move, and according to letters sent to the Federal Communications Commission (FCC), they routinely store such location data for years, willingly hand it over to law enforcement if served a proper subpoena, and say users can't opt out.…

☐ β˜† βœ‡ The Register - Security

Indian court directs chat app Telegram to disclose details of copyright infringers

September 2nd 2022 at 14:15

Judge says that servers being located in Singapore is not a get-out clause

A ruling handed down from the Delhi High Court this week declared that Telegram must hand over information such as IP addresses, mobile numbers, and devices used by channels on the platform involved in copyright infringement.…

☐ β˜† βœ‡ The Register - Security

Ex-NSA trio who spied on Americans for UAE now banned from arms exports

September 2nd 2022 at 01:11

From hero to zero-day ... to plain zero

Three former US government cyber-spies who, among other things, illicitly compromised and snooped on Americans' devices for the United Arab Emirates government have been banned from participating in international arms exports under a deal reached with Uncle Sam.…

☐ β˜† βœ‡ The Register - Security

Here's how 5 mobile banking apps put 300,000 users' digital fingerprints at risk

September 1st 2022 at 10:04

Spoiler: They used hard-coded AWS credentials

Massive amounts of private data – including more than 300,000 biometric digital fingerprints used by five mobile banking apps – have been put at risk of theft due to hard-coded Amazon Web Services credentials, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Oh no, that James Webb Space Telescope snap might actually contain malware

September 1st 2022 at 07:04

Is nothing sacred?

Scumbags are using a photo from the James Webb Space Telescope to smuggle Windows malware onto victims' computers – albeit in a roundabout way.…

☐ β˜† βœ‡ The Register - Security

LabMD gets another shot at defamation claim against 'extortionate' infosec biz

September 1st 2022 at 03:49

But keep your attorney on a 'short leash' against Tiversa, court warns

LabMD, the embattled and now defunct cancer-testing company, will get another chance at suing security firm Tiversa for defamation following an appeals court ruling. …

☐ β˜† βœ‡ The Register - Security

FBI: Look out, crooks stole $1.3b in cryptocurrency in just three months this year

September 1st 2022 at 02:32

DeFi, as in, defying belief

The FBI has urged people to be cautious and heavily research a DeFi – decentralized finance – provider before putting your money into it, after more than a billion dollars was stolen from these providers in three months.…

☐ β˜† βœ‡ The Register - Security

Decisions on health data sharing should not be taken by politicians, citizen juries find

August 31st 2022 at 11:16

Britain's National Data Guardian report also warns NHS needs to earn people’s trust, support for controversial data platform

As the NHS in England is set to launch a competition for a far-reaching patient data platform, a public consultation has said decisions about health data sharing should not be taken by politicians.…

☐ β˜† βœ‡ The Register - Security

China-linked APT40 gang targets wind farms, Australian government

August 31st 2022 at 05:02

ScanBox installed after victims lured to fake Murdoch news sites with phishing emails

Researchers at security company Proofpoint and PricewaterhouseCoopers (PWC) said on Tuesday they had identified a cyber espionage campaign that delivers the ScanBox exploitation framework through a malicious fake Australian news site.…

☐ β˜† βœ‡ The Register - Security

Find a security hole in Google's open source and you could bag a $31,337 reward

August 30th 2022 at 22:58

Will it be enough to prevent the next software supply-chain attack?

Google has created a bug bounty program that will reward those who find and report vulnerabilities in its open-source projects, thereby hopefully strengthening software supply-chain security.…

☐ β˜† βœ‡ The Register - Security

That 'clean' Google Translate app is actually Windows crypto-mining malware

August 30th 2022 at 10:27

Ah, nothing like a classic Trojan horse

Watch out: someone is spreading cryptocurrency-mining malware disguised as legitimate-looking applications, such as Google Translate, on free software download sites and through Google searches.…

☐ β˜† βœ‡ The Register - Security

Google Play to ban Android VPN apps from interfering with ads

August 30th 2022 at 00:43

Developers say this is not the privacy protection it's made out to be

Google in November will prohibit Android VPN apps in its Play store from interfering with or blocking advertising, a change that may pose problems for some privacy applications.…

☐ β˜† βœ‡ The Register - Security

Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers

August 29th 2022 at 18:08

Grab and deploy this backend update if you offer even repo read access

A critical command-injection vulnerability in multiple API endpoints of Atlassian Bitbucket Server and Data Center could allow an unauthorized attacker to remotely execute malware, and view, change, and even delete data stored in repositories.…

☐ β˜† βœ‡ The Register - Security

77% of security leaders fear we’re in perpetual cyberwar from now on

August 27th 2022 at 07:49

Also, Charming Kittens from Iran scrape email inboxes, France could fine Google again, and more

In brief A survey of cybersecurity decision makers found 77 percent think the world is now in a perpetual state of cyberwarfare.…

☐ β˜† βœ‡ The Register - Security

PyPI warns of first-ever phishing campaign against its users

August 26th 2022 at 19:21

On the bright side, top devs are getting hardware security keys

The Python Package Index, better known among developers as PyPI, has issued a warning about a phishing attack targeting developers who use the service.…

☐ β˜† βœ‡ The Register - Security

Now Oktapus gets access to some DoorDash customer info via phishing attack

August 26th 2022 at 16:33

Double check who exactly you're sending your username and password to, eh?

DoorDash has confirmed that "a small percentage" of its customers and delivery drivers' information, including names, email and delivery addresses, phone numbers, and order and partial credit card details, were exposed as part of a broad phishing campaign dubbed Oktapus.…

☐ β˜† βœ‡ The Register - Security

Twilio, Cloudflare just two of 135 orgs targeted by Oktapus phishing campaign

August 25th 2022 at 22:57

This, this is more like what we mean by a sophisticated cyberattack

Updated Criminals behind the cyberattack attempts on Twilio and Cloudflare earlier this month had cast a much wider net in their phishing expedition, targeting as many as 135 organizations β€” primarily IT, software development and cloud services providers based in the US.…

☐ β˜† βœ‡ The Register - Security

LastPass source code, blueprints stolen by intruder

August 25th 2022 at 21:02

Your passwords are still safe, biz says

Internal source code and documents have been stolen from LastPass by a cyber-thief.…

☐ β˜† βœ‡ The Register - Security

Crooks target top execs on Office 365 with MFA-bypass scheme

August 25th 2022 at 18:01

'Widespread' campaign hunts for multimillion-dollar transactions

A business email compromise scheme targeting CEOs and CFOs using Microsoft Office 365 combines phishing with a man-in-the-middle attack to defeat multi-factor authentication.…

☐ β˜† βœ‡ The Register - Security

Twitter, Meta kill hundreds of pro-Western troll accounts

August 25th 2022 at 15:00

It turns out online chicanery aiming to destabilize foreign nations is a two-way street

Well known for an abundance of anti-western troll accounts and propaganda, Twitter and Meta are reporting that they've taken down nearly 200 accounts that, for the past five years, have been amplifying pro-Western messages in the Middle East and Central Asia.…

☐ β˜† βœ‡ The Register - Security

Ever present danger

August 25th 2022 at 13:41

Recognizing the signs of an impending ransomware attack with Red Canary

Webinar It's no surprise that there has been an explosion in ransomware following the evolution of cryptocurrencies. The emergence of Bitcoin in 2010 suddenly provided an easy and untraceable way to force victims to pay.…

☐ β˜† βœ‡ The Register - Security

Shout-out to whoever went to Black Hat and had North Korean malware on their PC

August 25th 2022 at 09:24

I am the one who NOCs

The folks tasked with defending the Black Hat conference network see a lot of weird, sometimes hostile activity, and this year it included malware linked to Kim Jong-un's agents.…

☐ β˜† βœ‡ The Register - Security

Block sued after ex-staffer siphons customer data

August 24th 2022 at 23:09

'Don't be such a Square' hits different these days

Block – the digital payments giant formerly known as Square – faces allegations it failed to take adequate measures to protect customers' personal information.…

☐ β˜† βœ‡ The Register - Security

80,000 internet-connected cameras still vulnerable after critical patch offered

August 24th 2022 at 20:46

Just more IoT conscripts for the botnet armies

Tens of thousands of internet-facing IP cameras made by China-based Hikvision remain unpatched and exploitable despite a fix being issued for a critical security bug nearly a year ago.…

☐ β˜† βœ‡ The Register - Security

VMware confirms Carbon Black causes BSODs, boot loops on Windows

August 24th 2022 at 16:08

Well, you can't be attacked if your PC won't start

VMware has admitted an update on some versions of its Carbon Black endpoint solution is responsible for BSODs and boot loops on Windows machines after multiple organizations were affected by the problem.…

☐ β˜† βœ‡ The Register - Security

Attacker snags account details from streaming service Plex

August 24th 2022 at 14:00

'Limited subset' of users have emails, usernames, and hashed passwords stolen from the platform

Users of popular streaming and media organizing service Plex are waking up to an unpleasant email this morning saying, in the words of a Reg reader, "Plex have been hacked and their main site is down as we all rush to change passwords."…

☐ β˜† βœ‡ The Register - Security

Lloyd's to exclude certain nation-state attacks from cyber insurance policies

August 24th 2022 at 06:28

Kim Jong-un has entered the chat

Updated Lloyd's of London insurance policies will stop covering losses from certain nation-state cyber attacks and those that happen during wars, beginning in seven months' time.…

☐ β˜† βœ‡ The Register - Security

Twitter savaged by former security boss Mudge in whistleblower complaint

August 23rd 2022 at 22:00

Loose access to production systems, out of date software, and more claimed

Twitter's former security chief Peiter "Mudge" Zatko accused the company and its board of directors of violating financial rules, of fraud, and of grossly neglecting its security obligations in a complaint to the US Securities & Exchange Commission, the Federal Trade Commission, and the US Justice Department last month.…

☐ β˜† βœ‡ The Register - Security

Smartphone gyroscopes threaten air-gapped systems, researcher finds

August 23rd 2022 at 18:00

Network interface card LEDs are a risk too by blinking in Morse code

An Israeli security researcher known for foiling air gap security measures has published a reminder of just how vulnerable the approaches are to both visual and ultrasonic threats. …

☐ β˜† βœ‡ The Register - Security

Microsoft finds critical hole in operating system that for once isn't Windows

August 23rd 2022 at 00:58

Oh wow, get a load of Google using strcpy() all wrong – strcpy! Haha, you'll never ever catch us doing that

Microsoft has described a severe ChromeOS security vulnerability that one of its researchers reported to Google in late April.…

☐ β˜† βœ‡ The Register - Security

If you haven't patched Zimbra holes by now, assume you're toast

August 23rd 2022 at 00:32

Here's how to detect an intrusion via vulnerable email systems

Organizations that didn't immediately patch their Zimbra email systems should assume miscreants have already found and exploited the bugs, and should start hunting for malicious activity across IT networks, according to Uncle Sam.…

☐ β˜† βœ‡ The Register - Security

Novant Health admits leak of 1.3m patients' info to Facebook

August 22nd 2022 at 22:00

But don't worry, Zuck would never misuse this type of sensitive data

Novant Health confirmed that it may have disclosed 1.3 million patients' sensitive data, including email addresses, phone numbers, financial information - even doctor's appointment details - to Meta.…

☐ β˜† βœ‡ The Register - Security

Hiding a phishing attack behind the AWS cloud

August 22nd 2022 at 21:00

Scammers are using cloud services to create and host web pages that can be used to lure victims into handing over their credentials

Criminals are slipping phishing emails past automated security scanners inside Amazon Web Services (AWS) to establish a launching pad for attacks.…

☐ β˜† βœ‡ The Register - Security

Warning over Java libraries and deserialization security weaknesses

August 22nd 2022 at 20:00

There is a madness to the methods

Boffins at universities in France, Germany, Luxembourg, and Sweden took a deep dive into known Java deserialization vulnerabilities, and have now resurfaced with their findings. In short, they've drawn attention to the ways in which libraries can accidentally introduce serious security flaws.…

☐ β˜† βœ‡ The Register - Security

LockBit gang hit by DDoS attack after threatening to leak Entrust ransomware data

August 22nd 2022 at 16:08

Prolific group pummeled days after claiming to be file thief behind attack on cybersecurity vendor

The LockBit ransomware group last week claimed responsibility for an attack on cybersecurity vendor in June. The high-profile gang is now apparently under a distributed denial-of-service (DDoS) because of it.…

☐ β˜† βœ‡ The Register - Security

Zoom patches make-me-root security flaw, patches patch

August 22nd 2022 at 06:20

Plus: See if in-app browsers are monitoring you, a novel industrial network attack technique, and more

In brief Zoom fixed a pair of privilege escalation vulnerabilities, which were detailed at the Black Hat conference this month, but that patch was bypassed, necessitating yet another fix.…

☐ β˜† βœ‡ The Register - Security

NSO Group CEO steps down, 100 employees let go too

August 22nd 2022 at 05:01

Controversial Pegasus spyware maker to focus on NATO sales while battling various court cases

Pegasus spyware slinger NSO Group announced on Sunday it will reorganize, replacing its CEO and letting go of around 100 workers.…

☐ β˜† βœ‡ The Register - Security

Ex-HP finance manager jailed after going on $5m spending spree using company plastic

August 19th 2022 at 19:27

Tesla sedan, 46 Chanel bags, 16 Rolexes, and more equals three years behind bars

Now-former HP finance manager Shelbee Szeto has been sentenced to three years in prison and ordered to forfeit more than 250 luxury items after she blew $5m on herself using company credit cards.…

☐ β˜† βœ‡ The Register - Security

Two years on, Apple iOS VPNs still leak IP addresses

August 19th 2022 at 07:37

Privacy, it's a useful marketing term. *Offer does not apply in China

Apple has left a VPN bypass vulnerability in iOS unfixed for at least two years, leaving identifying IP traffic data exposed, and there's no sign of a fix.…

☐ β˜† βœ‡ The Register - Security

The truth about that draft law banning Uncle Sam buying insecure software

August 19th 2022 at 02:22

There's always a get-out clause

An attempt by lawmakers to improve parts of the US government's cybersecurity defenses has raised questions – and hackles – among infosec professionals.…

☐ β˜† βœ‡ The Register - Security

Keeping the keys to the kingdom secure

August 18th 2022 at 16:30

Learn how you can improve your password security and keep your organization's data safe

Webinar Believe it or not the word 'password' is still being used as the most common password across all industries, including retail and ecommerce.…

☐ β˜† βœ‡ The Register - Security

Google blocks third record-breaking DDoS attack in as many months

August 18th 2022 at 16:00

46 million requests per second network flood comes as attacks increase by more than 200% compared to last year

Google says it has blocked the largest ever HTTPS-based distributed-denial-of-service (DDoS) attack in June, which peaked at 46 million requests per second.…

☐ β˜† βœ‡ The Register - Security

Ransomware attack on UK water company clouded by confusion

August 18th 2022 at 06:28

Clop gang thought it hit Thames Water – but real victim was elsewhere

A water company in the drought-hit UK was recently compromised by a ransomware gang, though initially it was unclear exactly which water company was the victim.…

☐ β˜† βœ‡ The Register - Security

Deluge of of entries to Spamhaus blocklists includes 'various household names'

August 18th 2022 at 05:59

Nastymail tracking service blames sloppy sending practices for swelling lists of dangerous mailers

Spam-tracking service Spamhaus reported Tuesday that some of the world's biggest brands are getting loose with their email practices, causing its spam blocklists (SBL) to swell significantly.…

☐ β˜† βœ‡ The Register - Security

Janet Jackson music video declared a cybersecurity exploit

August 18th 2022 at 05:30

Another reason not to play 1989's Rhythm Nation – it may mess with some hard disk drives

The music video for Janet Jackson's 1989 pop hit Rhythm Nation has been recognized as an exploit for a cybersecurity vulnerability after Microsoft reported it can crash old laptop computers.…

☐ β˜† βœ‡ The Register - Security

Google, Apple squash exploitable browser bugs

August 17th 2022 at 22:47

Chrome flaw has public exploit, WebKit hole actively abused along with kernel escalation

Google has issued 11 security fixes for desktop Chrome, including one bug that has an exploit for it out in the wild.…

☐ β˜† βœ‡ The Register - Security

Software developer cracks Hyundai car security with Google search

August 17th 2022 at 20:19

Top tip: Your RSA private key should not be copied from a public code tutorial

A developer says it was possible to run their own software on the car infotainment hardware after discovering the vehicle's manufacturer had secured its system using keys that were not only publicly known but had been lifted from programming examples.…

☐ β˜† βœ‡ The Register - Security

After 7 years, long-term threat DarkTortilla crypter is still evolving

August 17th 2022 at 18:41

.NET-based malware can push wide range of malicious payloads, and evades detection, Secureworks says

A highly pervasive .NET-based crypter that has flown under the radar since about 2015 and can deliver a wide range of malicious payloads continues to evolve rapidly, with almost 10,000 code samples being uploaded to VirusTotal over a 16-month period.…

❌