FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

French-speaking voleurs stole $30m in 15-country bank, telecoms cyber-heist spree

November 4th 2022 at 06:22

Smooth 'OPERA1ER' hit orgs around the world over four or more years

A French-speaking criminal group codenamed OPERA1ER has pulled off more than 30 cyber-heists against telecom organizations and banks across Africa, Asia, and Latin America, stealing upwards of $30 million over four years, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Multi-factor auth fatigue is real – and it's why you may be in the headlines next

November 3rd 2022 at 20:45

Overwhelmed by waves of push notifications, worn-down users inadvertently let the bad guys in

Analysis The September cyberattack on ride-hailing service Uber began when a criminal bought the stolen credentials of a company contractor on the dark web.…

☐ β˜† βœ‡ The Register - Security

International summit agrees crack down on crypto to combat ransomware

November 3rd 2022 at 16:45

Commitments include international wallet info sharing, KYC requirements, and an AML crackdown

The White House's second International Counter Ransomware Initiative summit has concluded, and this year the 36-nation group has made clear it intends to crack down on how cryptocurrencies are used to finance ransomware operations.…

☐ β˜† βœ‡ The Register - Security

Royal Mail customer data leak shutters online Click and Drop

November 3rd 2022 at 08:29

Customers complain of exposed order info, multiple charges β€” but still no postage

A technical SNAFU shut down the UK's Royal Mail Click and Drop website on Tuesday after a security "issue" allowed some customers to see others' order information. …

☐ β˜† βœ‡ The Register - Security

US Treasury thwarts DDoS attack from Russian Killnet group

November 2nd 2022 at 20:45

Yet another pathetic 'stunt' from pro-Kremlin criminals

The US Treasury Department has thwarted a distributed denial of service (DDoS) attack that officials attributed to Russian hacktivist group Killnet.…

☐ β˜† βœ‡ The Register - Security

Ransomware cost US banks $1.2 billion last year

November 2nd 2022 at 16:30

Up 188% on 2020 but could be because financial institutions were encouraged to report incidents

Banks in the US paid out nearly $1.2 billion in 2021 as a result of ransomware attacks, a marked rise over the year before though it may simply be due to more financial institutions being asked to report incidents.…

☐ β˜† βœ‡ The Register - Security

Former Apple worker pleads guilty to $17m mail and wire fraud charges

November 2nd 2022 at 13:00

Nefarious schemes included harvesting motherboard components and selling them back to Apple

A one-time Apple employee working as a buyer within the iGiant's supply chain department has pleaded guilty to mail and wire fraud charges spanning multiple years, ultimately costing the company $17 million.…

☐ β˜† βœ‡ The Register - Security

Ritz cracker giant settles bust-up with insurer over $100m+ NotPetya cleanup

November 2nd 2022 at 07:29

Deal could 'upend the entire cyber-insurance ecosystem and make it almost impossible to get meaningful cyber coverage'

Mondelez International has settled its lawsuit against Zurich American Insurance Company, which it brought because the insurer refused to cover the snack giant's $100-million-plus cleanup bill following the 2017 NotPetya outbreak.…

☐ β˜† βœ‡ The Register - Security

Dropbox admits 130 of its private GitHub repos were copied after phishing attack

November 1st 2022 at 23:52

Personal info and data safe, stolen code not critical, apparently

Dropbox has said it was successfully phished, resulting in someone copying 130 of its private GitHub code repositories and swiping some of its secret API credentials.…

☐ β˜† βœ‡ The Register - Security

OpenSSL downgrades horror bug after week of panic, hype

November 1st 2022 at 21:39

Relax, there's more chance of Babbage coming back to life to hack your system than this flaw being exploited

OpenSSL today issued a fix for a critical-turned-high-severity vulnerability that project maintainers warned about last week. …

☐ β˜† βœ‡ The Register - Security

Government by Gmail catches up with UK minister... who is reappointed anyway

November 1st 2022 at 14:30

Home Secretary 'nominally in charge' of nation's security apologizes for breach of tech protocols

The UK's Home Secretary – the minister in charge of policing and internal security – has been forced to apologize for breaching IT security protocols in government.…

☐ β˜† βœ‡ The Register - Security

Kioxia warns of potential cost of US chip policy over China

November 1st 2022 at 10:30

Nice NAND industry you have there, would be a shame if something happened to it

Attempts to reorganize supply chains to cut out China and foil its attempts to build a high-tech chip industry will be costly and may simply cause the Middle Kingdom to redouble its efforts, says memory maker Kioxia.…

☐ β˜† βœ‡ The Register - Security

German cops arrest student suspected of running infamous dark-web souk

November 1st 2022 at 05:28

Deutschland im Deep Web destroyed

A 22-year-old student German federal police believe to be the administrator of one of the largest German-speaking, dark-web forums has been arrested. …

☐ β˜† βœ‡ The Register - Security

Unofficial fix emerges for Windows bug abused to infect home PCs with ransomware

November 1st 2022 at 03:48

Broken code signature? LGTM, says Microsoft OS

A cybersecurity firm has issued another unofficial patch to squash a bug in Windows that Microsoft has yet to fix, with this hole being actively exploited to spread ransomware.…

☐ β˜† βœ‡ The Register - Security

India's Home Ministry cracks down on predatory lending apps following suicides

November 1st 2022 at 03:15

Local media say they're China backed, Ministry only mentions organized crime

India's Home Ministry has asked state governments to crack down on illegal lending apps it says have led to "multiple suicides by citizens owing to harassment, blackmail, and harsh recovery methods."…

☐ β˜† βœ‡ The Register - Security

Education tech giant gets an F for security after sensitive info on 40 million users stolen

October 31st 2022 at 22:54

Chegg it out: Four blunders in four years

Sloppy data security at education tech giant Chegg exposed students and workers' personal information not once but four times in various ways over four years, according to the FTC. …

☐ β˜† βœ‡ The Register - Security

The White House's global ransomware summit couldn't come at a better time

October 31st 2022 at 17:30

As cyber threats ramp up, businesses and organizations will be hoping for more than platitudes

The White House has begun its second annual International Counter Ransomware Summit in which Biden administration officials will convene with representatives of three dozen nations, the EU, and private business to discuss the growing threat posed by data-destroying cyber attacks.…

☐ β˜† βœ‡ The Register - Security

Ordinary web access request or command to malware?

October 31st 2022 at 16:30

Cranefly group unleashes nasty little technique using Microsoft Internet Information Services (IIS) logs

A threat group that targets corporate emails is delivering dropper malware through a novel technique that uses Microsoft Internet Information Services (IIS) logs to send commands disguised as web access requests.…

☐ β˜† βœ‡ The Register - Security

Apple patches actively exploited iPhone, iPad kernel vulns

October 31st 2022 at 07:32

Plus: Misconfigured server leaks Thomson Reuters data; VMware patches critical flaw in retired software; MalwareBytes apologies for a hoodie

In brief Apple has patched an iOS and iPad OS vulnerability that's already been exploited.…

☐ β˜† βœ‡ The Register - Security

Singapore hosts ICS/OT cybersecurity training extravaganza

October 31st 2022 at 03:00

Two great SANS events for APAC cyber security professionals to boost their ICS knowledge and skills

Sponsored Post Cybercriminals generally respect no limits or boundaries, but there is evidence to suggest that they are singling out industrial control systems (ICS) and operational technology (OT) systems such as supervisory control and data acquisition (SCADA) platforms in the Asia Pacific region which may represent easier targets for their attention.…

☐ β˜† βœ‡ The Register - Security

Indian government creates body with power to order social media content takedowns

October 30th 2022 at 23:32

PLUS: China’s digital currency surges; Infosys tax portals wobble again; Singapore crypto protections; and more

Asia In Brief India's government has given itself the power to compel social networks to take down content.…

☐ β˜† βœ‡ The Register - Security

This Windows worm evolved into slinging ransomware. Here's how to detect it

October 28th 2022 at 22:11

Raspberry Robin hits 1,000 orgs in just one month

Raspberry Robin, a worm that spreads through Windows systems via USB drives, has rapidly evolved: now backdoor access is being sold or offered to infected machines so that ransomware, among other code, can be installed by cybercriminals.…

☐ β˜† βœ‡ The Register - Security

Federal bans aren't stopping US states from buying forbidden Chinese kit

October 28th 2022 at 17:32

Report claims thousands of orgs are still happily writing checks

Only a "handful" of US states have stopped buying Chinese technologies deemed by the government to pose security threats, according to a report from a Washington policy research group.…

☐ β˜† βœ‡ The Register - Security

The top cloud cyber security threats unpacked

October 28th 2022 at 13:12

Our webinar offers practical advice on how to ward off cloud-borne bugs of the digital variety

Webinar The cloud is constantly in flux, and with its continual growth comes an equally rapid acceleration of threats and vulnerabilities direct towards it. You could say the cloud environment resembles the wild west where even hired guns carefully guarding your wagon train are not always enough to prevent an ambush by a gang of determined outlaws.…

☐ β˜† βœ‡ The Register - Security

Biden now wants to toughen up chemical sector's cybersecurity

October 27th 2022 at 22:36

Control panels facing the internet? Data stolen? You gotta keep an ion this stuff

The White House is adding the chemical sector to a program launched last year to improve cybersecurity capabilities within America's critical infrastructure industries.…

☐ β˜† βœ‡ The Register - Security

The point solution IAM evolution under reform

October 27th 2022 at 13:01

A consolidation of IAM tools, suppliers and managed services providers is changing the default approach

Sponsored Feature The inexorable pace of technological innovation in response to the unrelenting growth of cyber attacks has led to fragmentation within cyber security provision. Things generally follow a common pattern, starting with a new security requirement being identified, whether a response to a novel threat, or a compliance or regulation challenge. This leads buyers to specialized tools, usually from smaller vendors that do one thing well. But inevitably over time, buyers end up using a mishmash of systems and tools, each with its own job and management processes.…

☐ β˜† βœ‡ The Register - Security

Purpleurchin cryptocurrency miners spotted scouring free GitHub, Heroku accounts

October 27th 2022 at 07:27

This is why we can't have nice things

A stealthy cryptocurrency mining operation has been spotted using thousands of free accounts on GitHub, Heroku and other DevOps outfits to craft digital tokens. GitHub, for one, forbids the mining of coins using its cloud resources.…

☐ β˜† βœ‡ The Register - Security

Japan to citizens: Get a digital ID or health insurance gets harder

October 27th 2022 at 03:57

Risk of death is certainly one way to get the populace on board

Japan's plan to phase out public health insurance cards in favor of linking the services to a digital ID card could compel those who oppose the digitization to sign up.…

☐ β˜† βœ‡ The Register - Security

Pro-China crew ramps up disinfo ahead of US midterms. Not that anyone's falling for it

October 27th 2022 at 00:31

Hey, Xi, ζ»šεΌ€

The prolific pro-Beijing Dragonbridge crew has apparently stepped up its activity ahead of the US 2022 midterms by trying to discourage Americans from voting as well as pinning the Nord Stream pipeline explosion on Uncle Sam.…

☐ β˜† βœ‡ The Register - Security

Feds accuse Ukrainian of renting out PC-raiding Raccoon malware to fiends

October 26th 2022 at 23:06

Separately, charges slapped on alleged operator of dark market, The Real Deal

Mark Sokolovsky, 26, a Ukrainian national, is being held in the Netherlands while he awaits extradition to America on cybercrime charges, the US Justice Department said on Tuesday.…

☐ β˜† βœ‡ The Register - Security

Cisco AnyConnect Windows client under active attack

October 26th 2022 at 20:31

Make sure you're patched – and update VMware Cloud Foundation, too, by the way

Cisco says miscreants are exploiting two vulnerabilities in its AnyConnect Secure Mobility Client for Windows, which is supposed to ensure safe VPN access for remote workers.…

☐ β˜† βœ‡ The Register - Security

Microsoft realizes it hasn't updated list of banned dodgy Windows 10 drivers in years

October 26th 2022 at 18:45

Hope no one was relying on that to block threats, er, yeah?

Microsoft appears to have woken up and realized it may have left certain Windows Server and Windows 10 systems exposed to exploitable drivers for years.…

☐ β˜† βœ‡ The Register - Security

New Year, new cyber security career

October 26th 2022 at 09:00

Say hello to SANS 2023 training events and the new job that will inevitably follow

Sponsored Post The turn of the year is always a good time to take stock and think about where you are heading. Many hard working cybersecurity professionals will be keeping as close an eye on the calendar as they are on cyber criminals.…

☐ β˜† βœ‡ The Register - Security

Ransomware down this year – but there's a catch

October 26th 2022 at 05:28

2021 was such a banner year for extortionists, 2022 is gonna look rosy in comparison

The number of ransomware attacks worldwide dropped 31 percent year-over-year during the first nine of months 2022, at least as far as SonicWall has observed. But don't get too excited.…

☐ β˜† βœ‡ The Register - Security

If someone tries ransacking your Windows network, it's a bit easier now to grok in Microsoft 365 Defender

October 26th 2022 at 04:27

Blinking, beeping, and flashing lights, blinking and beeping and flashing...

Microsoft is bringing Azure Active Directory Identity Protection alerts to Microsoft 365 Defender to seemingly help IT folks thwart criminals infiltrating corporate networks via compromised users.…

☐ β˜† βœ‡ The Register - Security

Health insurer Medibank's data breach diagnosis keeps getting worse

October 26th 2022 at 03:45

All four million customers at risk of having records of medical treatments exposed

Australian health insurer Medibank's data breach was today revealed to be even worse than first thought, with a regulatory filing stating that info describing all four million customers has been accessed.…

☐ β˜† βœ‡ The Register - Security

FTC slaps down Drizly CEO after 2.4m user records stolen from 'careless' booze app biz

October 26th 2022 at 00:07

At least this'll give some ammo to CISOs dying for stronger IT defenses

Analysis Drizly CEO James Cory Rellas is in the firing line after his company exposed about 2.5 million customers' personal information in a computer security blunder. …

☐ β˜† βœ‡ The Register - Security

PayPal ditches passwords, at least on Apple devices

October 25th 2022 at 19:30

No more reusing, recycling passwords

PayPal has added passkeys for passwordless login to accounts across Apple devices.…

☐ β˜† βœ‡ The Register - Security

The safety of numbers

October 25th 2022 at 12:32

The future of effective crowdsourced cybersecurity according to Bugcrowd

Webinar It was the English philosopher Sir Francis Bacon who first wrote 'knowledge is power,' a phrase which is probably equally applicable in fighting cybercrime today as it was in 1597 when he first committed it to paper. Because failing to keep up with the latest intel on malware and hacking methods can leave your organization open to a lot of potential risks.…

☐ β˜† βœ‡ The Register - Security

Gone phishing: UK data watchdog fines construction biz Β£4.4m for poor infosec hygiene

October 25th 2022 at 08:30

Staff member bit on lure, ultimately exposed up to 113,000 colleagues' personal information

Britain's data watchdog has slapped construction business Interserve Group with a potential Β£4.4 million ($4.98M) fine after a successful phishing attack by criminals exposed the personal data of up to 113,000 employees.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam says Chinese agents tried to interfere with Huawei criminal case in US

October 24th 2022 at 23:40

Beijing also sought to recruit academics and officials in America, and more claimed

American prosecutors on Monday accused 13 people of committing espionage-linked crimes in the US on behalf of the Chinese government.…

☐ β˜† βœ‡ The Register - Security

Payment terminal malware steals $3.3m worth of credit card numbers – so far

October 24th 2022 at 22:11

With shops leaving VNC and RDP open, quelle surprise

Cybercriminals have used two strains of point-of-sale (POS) malware to steal the details of more than 167,000 credit cards from payment terminals. If sold on underground forums, the haul could net the thieves upwards of $3.3 million.…

☐ β˜† βœ‡ The Register - Security

DHL named most-spoofed brand in phishing

October 24th 2022 at 18:42

With Microsoft and LinkedIn close on shipping giant's heels

DHL is the most spoofed brand when it comes to phishing emails, according to Check Point.…

☐ β˜† βœ‡ The Register - Security

Alert: This ransomware preys on healthcare orgs via weak-ass VPN servers

October 24th 2022 at 17:00

FBI, CISA warn of Daixin gang after OakBend Medical Center hit

Federal agencies are warning of a threat group called Daixin Team that is using ransomware and data extortion tactics to target US healthcare organizations.…

☐ β˜† βœ‡ The Register - Security

Google says slap some GUAC on your software supply chain

October 24th 2022 at 12:30

Also: Iranian election hackers are back, the TSA gets regulatory on train cybersecurity, and more

In brief Google has released a new open source software tool to help businesses better understand the risks to their software supply chains by aggregating security metadata into a queryable, standardized database.…

☐ β˜† βœ‡ The Register - Security

A year of SANS security summits

October 24th 2022 at 09:11

A mixture of free online events and in-person conferences that put you at the heart of the cyber security industry

Sponsored Post Where do the world's cyber security professionals get an opportunity to mingle and swap tips with their global peers while engaging in interactive, hands-on learning exercises that will help them stop cyber criminals in their tracks?…

☐ β˜† βœ‡ The Register - Security

Linux: Here, there and everywhere

October 24th 2022 at 08:40

How Red Hat turns an open source entity into overt enterprise security

Webinar Linux has come a long way from the early days of 1991 when the Linux kernel grew out of a student project.…

☐ β˜† βœ‡ The Register - Security

Could you not? BlackByte ransomware slinger twists the knife with data stealer

October 24th 2022 at 07:40

Your IT storage may go from terabytes to Exbytes

At least one affiliate of the high-profile ransomware-as-a-service (RaaS) group BlackByte is using a custom tool to exfiltrate files from a victim's network, a key step in the fast-growing business of double-extortion.…

☐ β˜† βœ‡ The Register - Security

Hacktivists say they stole 100,000 emails from Iran's nuclear energy agency

October 24th 2022 at 02:30

Tehran laughs it off as foreign psyop or media stunt. Just don't remind them about Stuxnet, OK?

Iran's Atomic Energy Organization has laughed off claims that the email systems of a subsidiary were compromised, revealing important operational data about a nuclear power plant.…

☐ β˜† βœ‡ The Register - Security

As Russia wages disinfo war, Ukraine's cyber chief calls for global anti-fake news fight

October 22nd 2022 at 22:53

'Completely new approaches should be developed to prevent the influence of this propaganda'

As a hybrid offline and online war wages on in Ukraine, Viktor Zhora, who leads the country's cybersecurity agency, has had a front-row seat of it all.…

☐ β˜† βœ‡ The Register - Security

Good news, URSNIF no longer a banking trojan. Bad news, it's now a backdoor

October 21st 2022 at 10:28

And one designed to slip ransomware and data-stealing code onto infected machines

URSNIF, the malware also known as Gozi that attempts to steal online banking credentials from victims' Windows PCs, is evolving to support extortionware.…

☐ β˜† βœ‡ The Register - Security

Oops, web trackers may have leaked 3 million patients' info

October 20th 2022 at 23:42

Scream with us: Aaaaaa-AAH

A hospital network in Wisconsin and Illinois fears visitor tracking code on its websites may have transmitted personal information on as many as 3 million patients to Meta, Google, and other third parties.…

☐ β˜† βœ‡ The Register - Security

Cloud migration and the cyber skills shortage

October 20th 2022 at 17:51

Protecting applications off prem demands a fresh wave of security talent

Sponsored Post Shifting workloads and applications to the cloud is on every forward-thinking CIO's wish list. It is also their worst nightmare. If they get it right, they've helped to transform and modernize their organization's operations and everyone's happy. If they get it wrong, it's a different story, made much worse if a seriously expensive data breach is involved.…

☐ β˜† βœ‡ The Register - Security

BlueBleed: Microsoft customer data leak claimed to be 'one of the largest' in years

October 20th 2022 at 15:00

SOCRadar says sensitive info from 150,000 orgs was exposed, Redmond disputes findings

Microsoft has confirmed one of its own misconfigured cloud systems led to customer information being exposed to the internet, though it disputes the extent of the leak.…

☐ β˜† βœ‡ The Register - Security

President Biden still wants his cybersecurity labels on those smart devices

October 20th 2022 at 09:30

May follow Finland and Germany in adopting Singapore's standard

The Biden administration is pushing ahead with its drive to add cyber security labeling to consumer Internet of Things (IoT) devices, and may join other nations in adopting the scheme pioneered by Singapore.…

☐ β˜† βœ‡ The Register - Security

Confidentiality in the cloud: the delicate bargain of trust

October 20th 2022 at 06:32

How hardware-assisted data security can boost the integrity of sensitive data sets stored in cloud environments

Sponsored Feature The concept behind Confidential Computing isn't new – organisations have been using hardware-assisted technology to encrypt and decrypt data for a while now. But fresh impetus from the Confidential Computing Consortium , new technology, and greater reliance on off prem public clouds to host and process sensitive information is prompting a more widespread re-evaluation of its benefits.…

☐ β˜† βœ‡ The Register - Security

Health insurer's infosec incident diagnosis goes from 'take a chill pill' to emergency ward

October 20th 2022 at 01:34

Australia's Medibank says it's been shown stolen data that includes details of treatments administered to customers

Updated Australian health insurer Medibank has revealed it's been contacted by a group that claims to have its customers' data and is threatening to distribute it.…

☐ β˜† βœ‡ The Register - Security

CISA warns of security holes in industrial Advantech, Hitachi kit

October 20th 2022 at 00:35

When we concede that everything has bugs, we wish it wasn't quite everything

This week, the US government's Cybersecurity and Infrastructure Security Agency (CISA) expanded its ever-growing list of vulnerability in industrial control systems (ICS) and critical infrastructure technology.…

☐ β˜† βœ‡ The Register - Security

Cost of a health insurance security breach? NY watchdogs say it's $4.5m

October 19th 2022 at 23:54

Hundreds of thousands of people's sensitive info poorly protected

New York regulators continue turning the screws on organizations with slapdash computer security.…

☐ β˜† βœ‡ The Register - Security

Verizon prepaid accounts hijacked by SIM swap crooks

October 19th 2022 at 22:04

Nightmare for those with one-time security codes texted to their phones

Verizon has notified some prepaid customers that their accounts were compromised and their phone numbers potentially hijacked by crooks via SIM swaps.…

❌