FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Twitter whistleblower Zatko disses bird site as dysfunctional data dump

September 14th 2022 at 00:11

Mudge tells senators his former bosses are 'terrified' of the French, US regulators are toothless

Twitter's former head of security Peiter "Mudge" Zatko on Tuesday told the US Senate Judiciary Committee that the social media company's lax data handling and inability to present problems to its board of directors threaten the privacy, security, and democracy for Americans.…

☐ β˜† βœ‡ The Register - Security

Microsoft fixes Windows security hole likely widely exploited by miscreants

September 13th 2022 at 22:50

Plus: Nasty no-auth RCE in TCP/IP stack, Adobe flaws, and many more updates

Patch Tuesday September's Patch Tuesday is here and it brings, among other things, fixes from Microsoft for one security bug that miscreants have used to fully take over Windows systems along with details of a second vulnerability that, while not yet under attack, has already been publicly disclosed.…

☐ β˜† βœ‡ The Register - Security

Patch your Mitel VoIP systems, Lorenz ransomware gang is back on the prowl

September 13th 2022 at 18:38

Criminals do love that unpatched VoIP and IoT kit

The Lorenz ransomware gang is exploiting a vulnerability in Mitel VoIP appliances to break corporate networks.…

☐ β˜† βœ‡ The Register - Security

How to get inside the mind of hackers

September 13th 2022 at 15:12

Spanish speaking SANS experts can help the LATAM cyber community detect and respond to attacks

Sponsored Post No matter how hard organizations in Latin America try to stop malicious attackers from infiltrating their IT systems, breaches are inevitable – as recent events demonstrate. …

☐ β˜† βœ‡ The Register - Security

Musk seeks yet another excuse to get out of Twitter buyout: This time it's Mudge's severance check

September 13th 2022 at 00:03

If at first you don't succeed...

Elon Musk has come up with a new reason to get out of his acquisition of Twitter - a severance payment.…

☐ β˜† βœ‡ The Register - Security

One month after Black Hat disclosure, HP's enterprise kit still unpatched

September 13th 2022 at 08:30

What could go wrong with leaving firmware open after world's biggest hacker convention talk?

Multiple high-severity firmware bugs in HP's business computers remain unpatched, some more than a year after Binarly security researchers disclosed the vulnerabilities to HP and then discussed them at the Black Hat security conference last month.…

☐ β˜† βœ‡ The Register - Security

Cisco: Yes, Yanluowang leaked our data. No, it's not serious

September 13th 2022 at 07:30

Everything's fine!

The Yanluowang ransomware group behind the May attack on Cisco Systems has publicly leaked the stolen files on the dark web over the weekend, but the networking giant says there's nothing to worry about.…

☐ β˜† βœ‡ The Register - Security

Chinese-linked cyber crims nab $529 million from Indian nationals

September 13th 2022 at 05:30

Authorities also bust a shell company scam operation with links to the Middle Kingdom

Chinese scammers have reportedly stolen a whopping $529 million dollars from Indian residents using instant lending apps, lures of part-time jobs, and bogus cryptocurrency trading schemes, according to the cyber crime unit in the state of Uttar Pradesh.…

☐ β˜† βœ‡ The Register - Security

Apple patches iPhone and macOS flaws under active attack

September 12th 2022 at 23:07

High-value targets tend to get hit

Apple has pushed out five security fixes including two vulnerabilities in its iPhones, iPads and Mac operating systems that are already being exploited.…

☐ β˜† βœ‡ The Register - Security

Google Cloud closes $5.4b Mandiant acquisition

September 12th 2022 at 18:15

Now it's really got all eyes on you

Google closed its $5.4 billion Mandiant acquisition today in a move that brings the threat intel and incident response giant under the Google Cloud umbrella. …

☐ β˜† βœ‡ The Register - Security

Security pros get ability to manually add incidents to Microsoft Sentinel

September 12th 2022 at 16:01

*Tappity tappity* Yes the NSA's on the phone. Well maybe the automated log check didn't pick it up yet, Chad!

In an IT world that is increasingly automated, there are still occasions when manual operations are necessary. According to Microsoft, one of these times is when security events are reported to enterprise security operation centers (SOCs).…

☐ β˜† βœ‡ The Register - Security

Reducing the risk of ransomware

September 12th 2022 at 15:34

How to protect data assets with a comprehensive security strategy

Webinar Keeping data secure from ransomware attacks requires dedicated attention to constantly evolving risks. Zero Trust security is one of the many rungs on the IT team's Jacob's Ladder to data asset security heaven. But there are other steps you can take, not least making assured data recovery integral to an organization's cyber security.…

☐ β˜† βœ‡ The Register - Security

Boffins build microphone safety kit to detect eavesdroppers

September 12th 2022 at 07:30

TickTock mic lock won't work on Apple

Scientists from the National University of Singapore and Yonsei University in the Republic of Korea have developed a device for verifying whether your laptop microphone is secretly recording your conversations.…

☐ β˜† βœ‡ The Register - Security

Retbleed slugs VM performance by up to 70 percent in kernel 5.19

September 12th 2022 at 01:29

VMware ran tests and saw some nasty numbers. Performance of next kernel otherwise uncontroversial

VMware engineers have tested the Linux kernel's fix for the Retbleed speculative execution bug, and report it can impact compute performance by a whopping 70 percent.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam sanctions Iran's intel agency over Albanian cyberattack

September 10th 2022 at 13:00

Iranians won't be terrified, but US vendors need to check their customers

The US Treasury Department has issued sanctions against Iran's intelligence agency in response to that country's cyberattack against Albania and other "cyber-enabled activities against the United States and its allies."…

☐ β˜† βœ‡ The Register - Security

Shape-shifting cryptominer savages Linux endpoints and IoT

September 10th 2022 at 11:00

Also, Authorities seize WT1SHOP selling 5.8m sets of PII, The North Face users face tough security hike

In brief AT&T cybersecurity researchers have discovered a sneaky piece of malware targeting Linux endpoints and IoT devices in the hopes of gaining persistent access and turning victims into crypto-mining drones.…

☐ β˜† βœ‡ The Register - Security

Data tracking poses a 'national security risk' FTC told

September 9th 2022 at 23:19

'We're making China's job easier'

The massive amounts of digital data being bought and sold β€” or sometimes freely shared β€” poses a grave national security risk, according to a former US policymaker and diplomat.…

☐ β˜† βœ‡ The Register - Security

Feds freeze $30m in cryptocurrency stolen from Axie Infinity

September 9th 2022 at 22:08

But the North Korean criminals are still over half a billion digicash dollars up

Federal investigators and private companies seized $30 million in cryptocurrency stolen in March by North Korean-linked APT gang Lazarus Group from a video game developer, the latest example of the growing skills of government and cybersecurity experts to track and recover such ill-gotten gains.…

☐ β˜† βœ‡ The Register - Security

Meta disbands Responsible Innovation team, spreads it out over Facebook and co

September 9th 2022 at 17:28

Still unclear: Were members just screaming into a void for the past few years?

Facebook parent Meta has disbanded its Responsible Innovation Team (RIT) that it claimed last year was a central part of efforts to "proactively surface and address potential harms to society in all that we build." …

☐ β˜† βœ‡ The Register - Security

US seeks standards dominance, lets Huawei access previously forbidden crypto tech

September 9th 2022 at 03:58

Beijing thinks standards should include central network controls. Washington does not

The US Commerce Department's Bureau of Industry and Security (BIS) has relaxed restrictions that barred export of some encryption technologies to Huawei, in the name of ensuring the United States is in a better position to negotiate global standards.…

☐ β˜† βœ‡ The Register - Security

Dump these small-biz routers, says Cisco, because we won't patch their flawed VPN

September 8th 2022 at 23:26

Nothing like an authentication bypass for your private IPSec network

Cisco patched three security vulnerabilities in its products this week, and said it will leave unpatched a VPN-hijacking flaw that affects four small business routers.…

☐ β˜† βœ‡ The Register - Security

Mandiant β€˜highly confident’ foreign cyberspies will target US midterm elections

September 8th 2022 at 22:18

It is with a heavy heart that we must announce that the hackers are at it again

Mandiant is "highly confident" that foreign cyberspies will target US election infrastructure, organizations, and individuals in the run-up to the November midterm elections.…

☐ β˜† βœ‡ The Register - Security

Google urges open source community to fuzz test code

September 8th 2022 at 21:00

We'll even get our checkbook out, web giant says

Google's open source security team says OSS-Fuzz, its community fuzzing service, has helped fix more than 8,000 security vulnerabilities and 26,000 other bugs in open source projects since its 2016 debut.…

☐ β˜† βœ‡ The Register - Security

Private equity suits at Thoma Bravo pull out of Darktrace acquisition

September 8th 2022 at 13:00

'Enterprise immune system' sees share price slump

US private equity investor Thoma Bravo has pulled out of its planned takeover of Darktrace, causing shares in the UK cybersecurity company to plummet.…

☐ β˜† βœ‡ The Register - Security

Lazarus Group unleashed a MagicRAT to spy on energy providers

September 8th 2022 at 12:00

Cisco finds custom malware in North Korea's latest cyberespionage effort

The North Korean state-sponsored crime ring Lazarus Group is behind a new cyberespionage campaign with the goal to steal data and trade secrets from energy providers across the US, Canada and Japan, according to Cisco Talos.…

☐ β˜† βœ‡ The Register - Security

What’s the secret behind a secure password?

September 8th 2022 at 09:30

Intelligent, uncompromising software according to Specops

Webinar Passwords are the first line of defense against bad actors gaining illegal access to data, a protective rampart that too often falls to common mistakes and increasingly sophisticated cyberattacks.…

☐ β˜† βœ‡ The Register - Security

Halfords slapped on wrist for breaching email marketing laws

September 8th 2022 at 09:27

Bike and car accessory slinger fined Β£30,000 for hitting send on more than 499k unsolicited emails

Bike and car accessory retailer Halfords has found itself in the wrong lane with Britain’s data watchdog for sending hundreds of thousands of unsolicited marketing emails to members of the public.…

☐ β˜† βœ‡ The Register - Security

DoJ charges pair over China-linked attempt to build semi-autonomous crypto haven on nuked Pacific atoll

September 8th 2022 at 05:30

Yes, that’s a lot to digest: Marshall Islands legislators allegedly bribed to make it possible

About halfway between The Philippines and Hawaii is a place called Rongelap Atoll that’s infamous for having been unintentionally irradiated by nuclear weapons tests conducted by America at nearby Bikini Atoll in 1954.…

☐ β˜† βœ‡ The Register - Security

Ransomware protection from the top drawer

September 7th 2022 at 18:28

Why Zero Trust security needs secure infrastructure, systems, networks, users, and applications

Webinar Statistics suggest that there was a ransomware attack on a company or organization every 11 seconds in 2021, but only 57 percent of the victims successfully retrieved their kidnapped data by using back up. And the 32 percent that paid a ransom only recovered 65 percent of their lost data.…

☐ β˜† βœ‡ The Register - Security

US school year opens with reading, writing, and ransomware

September 7th 2022 at 18:00

FBI warns that Vice Society threat group is ramping up attacks on the education sector

The Vice Society threat group is ramping up ransomware attacks on US school districts just as students around the country return to the classroom, the FBI and other federal agencies are warning.…

☐ β˜† βœ‡ The Register - Security

Mandiant links APT42 to Iranian 'terrorist org'

September 7th 2022 at 14:00

'It's hard to imagine a more dangerous scenario,' Mandiant Intel VP told The Reg

Mandiant has named a new threat group, APT42, that it says functions as the cyberspy arm of Iran's Islamic Revolutionary Guard Corps (IRGC), which has plotted to murder US citizens including former National Security Advisor John Bolton.…

☐ β˜† βœ‡ The Register - Security

Cybercriminals target games popular with kids to distribute malware

September 7th 2022 at 12:34

Kaspersky research finds Minecraft and Roblox have the most malicious files associated with them

With 3 billion players globally, the $200 billion gaming market is an increasingly ripe target for cybercriminals – with the perennially popular Minecraft one of the most targeted lures.…

☐ β˜† βœ‡ The Register - Security

As Cybersecurity Week begins, Beijing claims US attacked Uni doing military research

September 7th 2022 at 05:15

National Security Agency apparently has tools that crack Solaris boxes

China has accused the United States of a savage cyber attack on a university famed for conducting aerospace research and linked to China's military.…

☐ β˜† βœ‡ The Register - Security

Pakistan politicians label government cybersecurity team 'incompetent'

September 7th 2022 at 02:15

MP alleges taxpayer database – which holds personal info on millions – has come under attack

A Pakistani parliamentary committee has labelled its own cybersecurity agency "incompetent".…

☐ β˜† βœ‡ The Register - Security

Go programming language arrives at security warnings that are useful

September 6th 2022 at 22:40

Low-noise tool hopes to highlight vulnerabilities imported into projects

The open source Go programming language, developed by Google, has added support for vulnerability management in a way designed to preserve programmers' patience.…

☐ β˜† βœ‡ The Register - Security

Cyberattack brings down InterContinental Hotels' booking systems

September 6th 2022 at 20:42

Online booking systems and other services knocked offline amid network intrusion

The IT systems of InterContinental Hotels Group, the massive hospitality organization that operates 17 hotel brands around the world, have been compromised, causing ongoing disruption to the corporation's online booking systems and other services.…

☐ β˜† βœ‡ The Register - Security

Ransomware gang hits second-largest US school district

September 6th 2022 at 17:45

FBI and CISA on-site to assist with incident response over Labor Day weekend

Updated Cybercriminals hit the Los Angeles Unified School District (LAUSD) over the holiday weekend with a ransomware attack that temporarily shut down email, computer systems, and applications.…

☐ β˜† βœ‡ The Register - Security

Newly discovered cyberspy crew targets Asian governments and corporations

September 6th 2022 at 16:15

Worok uses mix of publicly available tools, custom malware to steal info, gang active since 2020

A cyberespionage group has targeted government agencies and big-name corporations throughout Asia since at least 2020, using the notorious ProxyShell vulnerabilities in Microsoft Exchange to gain initial access.…

☐ β˜† βœ‡ The Register - Security

Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay

September 6th 2022 at 13:30

Lloyd's defends stance as critics say policy tweaks make it less worthwhile to spend on premiums

Critics unhappy about insurers excluding certain nation-state attacks from cyber policies should consider the alternative: higher prices, according to Lloyd's of London.…

☐ β˜† βœ‡ The Register - Security

Nadine Dorries promotes 'Brexit rewards' of proposed UK data protection law

September 5th 2022 at 11:06

Culture secretary talks up pre-Commons reading as UK waits to hear who new leader will be

On the day the UK is set to appoint its new prime minister, digital and culture secretary Nadine Dorries is introducing legislation in Parliament she promises will β€œdrop unnecessary box-ticking and measures stifling British businesses.”…

☐ β˜† βœ‡ The Register - Security

Maximum protection against hostile incursions

September 5th 2022 at 13:57

Want to hear more about the critical role of identity in Zero Trust security? Join our webinar on 20th September

Webinar The cyber security of any organisation or enterprise relies on the integrity of its identity management structure. After all, there's no shortage of bad actors looking for a chink in the wall.…

☐ β˜† βœ‡ The Register - Security

NATO investigates after criminals claim to be selling its stolen missile plans

September 5th 2022 at 13:04

Also, Microsoft’s one-click TikTok trick, a 14-year old Aussie cracks ASD encryption in an hour, and more

In brief NATO officials are investigating after criminals put up some data for sale on dark forums that they claim is "classified" information stolen from European missile maker MBDA.…

☐ β˜† βœ‡ The Register - Security

Microsoft mistakenly rated Chromium, Electron as malware

September 5th 2022 at 06:57

Windows Defender update fixed the mess after a weekend of false positive weirdness

Microsoft appears to have fixed a problem that saw its Defender antivirus program identify apps based on the Chromium browser engine and/or Electron JavaScript framework as malware, and suggest users remove them.…

☐ β˜† βœ‡ The Register - Security

China orders tech companies to 'improve traceability' of users to control 'rumours and false information'

September 5th 2022 at 00:32

PLUS: Australia mints a physical crypto-coin; Alibaba Cloud claims world's biggest DC; India’s space airbags; and more

China will conduct a three month blitz to cleanse the local internet of "rumors and false information".…

☐ β˜† βœ‡ The Register - Security

Google, YouTube ban election trolls ahead of US midterms

September 2nd 2022 at 23:26

Plus: Truth Social barred from Play until it shows just one iota of decency

Google and its YouTube subsidiary have joined other social media networks pledging to keep the 2022 US midterm elections safe and free from Russian trolls β€” and anyone else spewing democracy-damaging disinformation – by taking down such content.…

☐ β˜† βœ‡ The Register - Security

Convicted felon busted for 3D printing gun parts

September 2nd 2022 at 20:24

Just days after US rules tackling homemade firearms take effect

A US man has admitted he broke the law when he used 3D printers to make components converting semi-automatic guns to full auto.…

☐ β˜† βœ‡ The Register - Security

Revealed: US telcos admit to storing, handing over location data

September 2nd 2022 at 17:15

Letters to FCC confirm what many believed, don't address a bigger problem

US mobile carriers know a lot about where their customers every move, and according to letters sent to the Federal Communications Commission (FCC), they routinely store such location data for years, willingly hand it over to law enforcement if served a proper subpoena, and say users can't opt out.…

☐ β˜† βœ‡ The Register - Security

Indian court directs chat app Telegram to disclose details of copyright infringers

September 2nd 2022 at 14:15

Judge says that servers being located in Singapore is not a get-out clause

A ruling handed down from the Delhi High Court this week declared that Telegram must hand over information such as IP addresses, mobile numbers, and devices used by channels on the platform involved in copyright infringement.…

☐ β˜† βœ‡ The Register - Security

Ex-NSA trio who spied on Americans for UAE now banned from arms exports

September 2nd 2022 at 01:11

From hero to zero-day ... to plain zero

Three former US government cyber-spies who, among other things, illicitly compromised and snooped on Americans' devices for the United Arab Emirates government have been banned from participating in international arms exports under a deal reached with Uncle Sam.…

☐ β˜† βœ‡ The Register - Security

Here's how 5 mobile banking apps put 300,000 users' digital fingerprints at risk

September 1st 2022 at 10:04

Spoiler: They used hard-coded AWS credentials

Massive amounts of private data – including more than 300,000 biometric digital fingerprints used by five mobile banking apps – have been put at risk of theft due to hard-coded Amazon Web Services credentials, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Oh no, that James Webb Space Telescope snap might actually contain malware

September 1st 2022 at 07:04

Is nothing sacred?

Scumbags are using a photo from the James Webb Space Telescope to smuggle Windows malware onto victims' computers – albeit in a roundabout way.…

☐ β˜† βœ‡ The Register - Security

LabMD gets another shot at defamation claim against 'extortionate' infosec biz

September 1st 2022 at 03:49

But keep your attorney on a 'short leash' against Tiversa, court warns

LabMD, the embattled and now defunct cancer-testing company, will get another chance at suing security firm Tiversa for defamation following an appeals court ruling. …

☐ β˜† βœ‡ The Register - Security

FBI: Look out, crooks stole $1.3b in cryptocurrency in just three months this year

September 1st 2022 at 02:32

DeFi, as in, defying belief

The FBI has urged people to be cautious and heavily research a DeFi – decentralized finance – provider before putting your money into it, after more than a billion dollars was stolen from these providers in three months.…

☐ β˜† βœ‡ The Register - Security

Decisions on health data sharing should not be taken by politicians, citizen juries find

August 31st 2022 at 11:16

Britain's National Data Guardian report also warns NHS needs to earn people’s trust, support for controversial data platform

As the NHS in England is set to launch a competition for a far-reaching patient data platform, a public consultation has said decisions about health data sharing should not be taken by politicians.…

☐ β˜† βœ‡ The Register - Security

China-linked APT40 gang targets wind farms, Australian government

August 31st 2022 at 05:02

ScanBox installed after victims lured to fake Murdoch news sites with phishing emails

Researchers at security company Proofpoint and PricewaterhouseCoopers (PWC) said on Tuesday they had identified a cyber espionage campaign that delivers the ScanBox exploitation framework through a malicious fake Australian news site.…

☐ β˜† βœ‡ The Register - Security

Find a security hole in Google's open source and you could bag a $31,337 reward

August 30th 2022 at 22:58

Will it be enough to prevent the next software supply-chain attack?

Google has created a bug bounty program that will reward those who find and report vulnerabilities in its open-source projects, thereby hopefully strengthening software supply-chain security.…

☐ β˜† βœ‡ The Register - Security

That 'clean' Google Translate app is actually Windows crypto-mining malware

August 30th 2022 at 10:27

Ah, nothing like a classic Trojan horse

Watch out: someone is spreading cryptocurrency-mining malware disguised as legitimate-looking applications, such as Google Translate, on free software download sites and through Google searches.…

☐ β˜† βœ‡ The Register - Security

Google Play to ban Android VPN apps from interfering with ads

August 30th 2022 at 00:43

Developers say this is not the privacy protection it's made out to be

Google in November will prohibit Android VPN apps in its Play store from interfering with or blocking advertising, a change that may pose problems for some privacy applications.…

☐ β˜† βœ‡ The Register - Security

Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers

August 29th 2022 at 18:08

Grab and deploy this backend update if you offer even repo read access

A critical command-injection vulnerability in multiple API endpoints of Atlassian Bitbucket Server and Data Center could allow an unauthorized attacker to remotely execute malware, and view, change, and even delete data stored in repositories.…

☐ β˜† βœ‡ The Register - Security

77% of security leaders fear we’re in perpetual cyberwar from now on

August 27th 2022 at 07:49

Also, Charming Kittens from Iran scrape email inboxes, France could fine Google again, and more

In brief A survey of cybersecurity decision makers found 77 percent think the world is now in a perpetual state of cyberwarfare.…

❌