FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Microsoft: For better security, scan more Exchange server objects

February 26th 2023 at 09:00

Software giant takes some files and processes off the exclusion list

Microsoft is recommending that Exchange server users scan certain objects for viruses and other threats that until now had been excluded.…

☐ β˜† βœ‡ The Register - Security

'Ethical hacker' among ransomware suspects cuffed by Dutch cops

February 25th 2023 at 09:04

Beware the Dark Side

Dutch police have arrested three men for their alleged involvement with a ransomware gang that stole sensitive data and extorted hundreds of thousands of euros from thousands of companies.…

☐ β˜† βœ‡ The Register - Security

Telus source code, staff info for sale on dark web forum

February 25th 2023 at 00:30

$50k buys you '1,000 unique repositories' that may or may not be legit

Canadian communications giant Telus is investigating whether crooks have stolen employee data and its source code, all of which is being offered for sale on a criminal forum.…

☐ β˜† βœ‡ The Register - Security

Bitcoin mining rig found stashed in school crawlspace

February 24th 2023 at 23:30

Don't blame the kids! Ex-city employee charged with $17k power theft

Pics A Massachusetts man accused of using his job as a city's assistant facilities director to hide a cryptocurrency mining operation in the crawlspace of a school has surrendered himself to authorities on Friday morning after skipping his Thursday arraignment. …

☐ β˜† βœ‡ The Register - Security

Google destroyed evidence for antitrust battle, Feds complain

February 24th 2023 at 22:30

rm -rf'ing staff chat logs can't go unpunished, says Uncle Sam

The US Department of Justice (DoJ) asked the judge hearing its antitrust case against Google to sanction the search advertising giant for destruction of evidence.…

☐ β˜† βœ‡ The Register - Security

European Commission bans TikTok from staff gadgets

February 24th 2023 at 07:27

Cyber Europe cyber worried about cyber threats, doesn't cyber use the other C word (China)

The European Commission on Thursday banned the use of the TikTok short video app on corporate devices and on the personal devices of employees enrolled in the commission's mobile device management service.…

☐ β˜† βœ‡ The Register - Security

Microsoft grows automated assault disruption to cover BEC, ransomware campaigns

February 24th 2023 at 06:30

There’s no HumOR in cyberattacks

At last year's Ignite show, Microsoft talked up a capability in its 365 Defender that automatically detects and disrupts a cyberattack while still in progress, hopefully stopping or reducing any resulting damage. Now it's extending that to include additional criminal areas.…

☐ β˜† βœ‡ The Register - Security

Ukraine invasion blew up Russian cybercrime alliances

February 24th 2023 at 05:00

Study: Old pacts ditched the moment Moscow moved in

The so-called "brotherhood" or Russian-speaking cybercriminals is yet another casualty of the war in Ukraine, albeit one that few outside of Moscow are mourning.…

☐ β˜† βœ‡ The Register - Security

Suspected Russian NLBrute malware boss extradited to US

February 23rd 2023 at 23:30

Dariy Pankov accused of infiltrating systems, selling tool and passwords to other miscreants

A Russian national accused of developing the NLBrute brute-force hacking tool has made his first court appearance this week in Florida over accusations he used the tool to spawn a criminal empire.…

☐ β˜† βœ‡ The Register - Security

Dole production plants crippled by ransomware, stores run short

February 23rd 2023 at 21:30

Yes, we have no bananas, and things aren't looking peachy on the salad front

Irish agricultural megacorp Dole has confirmed that it has fallen victim to a ransomware infection that reportedly shut down some of its North American production plants.…

☐ β˜† βœ‡ The Register - Security

FTX fiasco founder SBF faces further fraud charges

February 23rd 2023 at 20:30

Fake donors allegedly padded politicians' pockets, both Republican and Democrat

FTX founder Sam Bankman-Fried's eight-count indictment related to the collapse of his crypto empire has been superseded by a new 12-count indictment unsealed in New York which provide graphic details about the extent the defunct biz paid off politicians. …

☐ β˜† βœ‡ The Register - Security

Sensitive DoD emails exposed by unsecured Azure server

February 23rd 2023 at 19:30

AWS, Google and Oracle may benefit as Microsoft blames the Pentagon and the Pentagon blames Microsoft

A hole in a US military email server operated by Microsoft left more than a terabyte of sensitive data exposed to the internet less than a month after Office 365 was awarded a higher level of government security accreditation.…

☐ β˜† βœ‡ The Register - Security

Kremlin claims Ukraine hackers behind fake missile strike alerts

February 23rd 2023 at 06:30

Ten cities panic after emergency systems start Putin out warnings of an impending attack

Millions of Russians in almost a dozen cities throughout the country were greeted Wednesday morning by radio alerts, text messages, and sirens warning of an air raid or missile strikes that never occurred. The warnings were later blamed on hackers.…

☐ β˜† βœ‡ The Register - Security

Datacenters in China, Singapore cracked by crims who then targeted tenants

February 23rd 2023 at 05:45

Infiltrators tried to create fake remote hands tasks, alter visitor lists

Criminals have targeted datacenter operators in Singapore and China, tapping into their CCTV cameras, accessing their tenant lists and then attacking those customers.…

☐ β˜† βœ‡ The Register - Security

Lawyers join forces to fight common enemy: The SEC and its probes into cyber-victims

February 23rd 2023 at 02:00

Did the financial watchdog just do the impossible and herd cats?

More than 80 law firms say they are "deeply troubled" by the US Securities and Exchange Commission's demand that Covington & Burling hand over names of its clients whose information was stolen by Chinese state-sponsored hackers.…

☐ β˜† βœ‡ The Register - Security

Open source software has its perks, but supply chain risks can't be ignored

February 22nd 2023 at 12:46

While app development is faster and easier, security is still a concern

Analysis Open source components play an increasingly central role in the software development scene, proving to be a boon in a time of continuous integration and deployment, DevOps, and daily software updates.…

☐ β˜† βœ‡ The Register - Security

Global threats fuel cyber defence training

February 22nd 2023 at 09:13

SANS Institute ramps up delivery of new security training courses to help keep info sec pros ahead of cyber criminals

Sponsored Post The global impact of cyber threats on businesses, governments, organisations and individuals around the world is ramping up exponentially, with experts warning that danger is set to dramatically worsen in coming months and years.…

☐ β˜† βœ‡ The Register - Security

Accidental WhatsApp account takeovers? It's a thing

February 21st 2023 at 11:00

Blame it on phone number recycling (yes, that's a thing, too)

A stranger may be receiving your private WhatsApp messages, and also be able to send messages to all of your contacts – if you have changed your phone number and didn't delete the WhatsApp account linked to it.…

☐ β˜† βœ‡ The Register - Security

Locking down the remote printer

February 21st 2023 at 07:21

No longer a blind spot, printer security is now a grown up conversation says Brother

Sponsored Feature As businesses journey deeper into an era of restless digital change, it's surprising how inventions from past decades still define the office environment.…

☐ β˜† βœ‡ The Register - Security

DNA testing biz vows to improve infosec after criminals break into database it forgot it had

February 20th 2023 at 20:30

Settles lawsuit with two states after wider leak that affected millions

A DNA diagnostics company will pay $400,000 and tighten its security in the wake of a 2021 attack where criminals broke into its network and swiped personal data on over two million people from a nine-year-old "legacy" database the company forgot it had.…

☐ β˜† βœ‡ The Register - Security

What Mary, Queen of Scots, can teach today’s cybersec royalty

February 20th 2023 at 09:30

Tech has changed in 400 years. The rules haven’t

Opinion Mary, Queen of Scots, was a hapless CEO, even by the standards of 1600s Europe. Mother of the first Stuart King of England, James I (and VI of Scotland; let's not go into that), she was herself the first Stuart monarch to lose both throne and head. She wasn't the last. The family had issues.…

☐ β˜† βœ‡ The Register - Security

GoDaddy joins the dots and realizes it's been under attack for three years

February 20th 2023 at 02:27

Also: Russia may legalize hacking; Oakland declares ransomware emergency; the CVEs you should know about this week

In brief Web hosting and domain name concern GoDaddy has disclosed a fresh attack on its infrastructure, and concluded that it is one of a series of linked incidents dating back to 2020.…

☐ β˜† βœ‡ The Register - Security

If you're struggling to secure email forwarding, it's not you, it's ... the protocols

February 19th 2023 at 09:00

Eggheads prove they can mimic messages and bag bug bounty bucks

Analysis Over the past two decades, efforts have been made to make email more secure. Alas, defensive protocols implemented during this period, such as SPF, DKIM, and DMARC, remain unable to deal with the complexity of email forwarding and differing standards, a study has concluded.…

☐ β˜† βœ‡ The Register - Security

Intruder alert: FBI tackles 'isolated' IT security breach

February 17th 2023 at 22:30

Move along, totally nothing to see here

The FBI claims it has dealt with a cybersecurity "incident" that reportedly involved computer systems being used to investigate child sexual exploitation.…

☐ β˜† βœ‡ The Register - Security

'Russian hacktivists' brag of flooding German airport sites

February 17th 2023 at 18:30

In other words, script kiddies up to shenanigans again

A series of distributed denial-of-service (DDoS) attacks shut down seven German airports' websites on Thursday, a day after a major IT glitch at Lufthansa grounded flights.…

☐ β˜† βœ‡ The Register - Security

Cry Havoc and let slip dogs of war ... there's an upgraded malware server in town

February 17th 2023 at 10:30

ThreatLabz finds free alternative to Cobalt Strike and other tools used in the wild

There's a fresh open-source command-and-control (C2) framework on the loose, dubbed Havoc, as an alternative to the popular Cobalt Strike, and other mostly legitimate tools, that have been abused to spread malware.…

☐ β˜† βœ‡ The Register - Security

EU lawmakers argue against signing US data-transfer pact

February 17th 2023 at 09:30

Committee: Something about complaints process being dealt with in total secrecy doesn't sit right

Lawmakers in the European Parliament have urged the European Commission not to issue the "adequacy decision" needed for the EU-US Data Privacy Framework (DPF) to officially become the pipeline for data to freely flow from the EU to the States.…

☐ β˜† βœ‡ The Register - Security

Antivirus apps are there to protect you – Cisco's ClamAV has a heckuva flaw

February 17th 2023 at 06:02

Switchzilla hardware and software need attention, unless you fancy arbitrary remote code execution

Antivirus software is supposed to be an important part of an organization's defense against the endless tide of malware.…

☐ β˜† βœ‡ The Register - Security

Norway finds a way to recover crypto North Korea pinched in Axie heist

February 17th 2023 at 05:15

Meanwhile South Korea's Do Kwon is sought for fraud by US authorities

Norwegian authorities announced on Thursday that they had recovered $5.9 million of cryptocurrency stolen in the Axie Infinity hack – an incident widely held to have been perpetrated by the Lazarus Group, which has links to North Korea.…

☐ β˜† βœ‡ The Register - Security

Google's big security cert log overhaul broke Android apps. Now it's hit undo

February 16th 2023 at 22:26

Devs missed warnings plus tons of code relies again on lone open source maintainer

Google this week reversed an overhaul of one of its security-related file formats after the transition broke Android apps.…

☐ β˜† βœ‡ The Register - Security

VMware, Windows 11 shafted by Windows Server 2022

February 16th 2023 at 20:30

OS won't start on some systems with ESXi VMs, while Win11 updates may not make it to devices

Updated Microsoft is sorting through two issues with Windows Server 2022 that affect VMware virtual machines and updates not getting passed on to Windows 11 devices.…

☐ β˜† βœ‡ The Register - Security

More victims of fake crypto investor scam speak to The Register

February 16th 2023 at 18:30

UK-based Coin Publishers were conned out of $206,000 after meeting in a Barcelona hotel

Exclusive When Ahad Shams detailed on Twitter how his company was scammed out of $4 million in cryptocurrency after a face-to-face meeting, Chris Hunter immediately recognized what was going on.…

☐ β˜† βœ‡ The Register - Security

ESXiArgs ransomware fights off Team America's data recovery script

February 16th 2023 at 01:30

Want a clue to what you’re dealing with? Check the ransom note

That didn't take long.…

☐ β˜† βœ‡ The Register - Security

Intel patches up SGX best it can after another load of security holes found

February 15th 2023 at 20:40

Plus bugs squashed in Server Platform Services and more

Intel's Software Guard Extensions (SGX) are under the spotlight again after the chipmaker disclosed several newly discovered vulnerabilities affecting the tech, and recommended users update their firmware.…

☐ β˜† βœ‡ The Register - Security

Storage security toughen-up for compliance and cyberwar in 2023

February 15th 2023 at 12:23

Giving storage platforms enhanced built-in security features will be a significant step toward counteracting the impacts of cybercrime in 2023, Dell experts predict

Sponsored Feature Cybercriminals tend not to discriminate when it comes to the type of data they steal. Structured or unstructured, both formats contain valuable information that will bring them a profit. From a cybersecurity practitioner's perspective, however, structural state presents specific challenges when it comes to storing and moving sensitive data assets around.…

☐ β˜† βœ‡ The Register - Security

Hyundai and Kia issue software upgrades to thwart killer TikTok car theft hack

February 15th 2023 at 07:29

Gone in 60 seconds using a USB-A plug and brute force instead of a key

Korean car-makers Hyundai and Kia will issue software updates to some of their models after a method of stealing them circulated on TikTok, leading to many thefts and even some deaths.…

☐ β˜† βœ‡ The Register - Security

Apple splats zero-day bug, other gremlins in macOS, iOS

February 15th 2023 at 05:27

WebKit flaw 'may have been exploited' – just like Tim Cook 'may have' made a million bucks this week

Apple this week released bug-splatting updates to its operating systems and Safari browser, to fix a zero-day vulnerability in its WebKit browser engine that's reported to have been actively exploited.…

☐ β˜† βœ‡ The Register - Security

Russian crook made $90M exploiting stolen info on Tesla, Roku, Avnet, Snap, more

February 15th 2023 at 00:58

Undisclosed earnings reports swiped, exploited

A Russian national with ties to the Kremlin exploited stolen upcoming financial filings belonging to hundreds of companies to help him and his associates net more than $90 million.…

☐ β˜† βœ‡ The Register - Security

Microsoft delivers 75-count box of patches for Valentine's Day

February 14th 2023 at 22:25

Adobe, SAP, Intel, AMD, Android also show up with bouquet of fixes

Patch Tuesday Happy Patch Tuesday for February, 2023, which falls on Valentine's Day.…

☐ β˜† βœ‡ The Register - Security

Record-breaking number of record-breaking DDoS attacks confirmed

February 14th 2023 at 20:15

And growing abuse of cloud – because using hijacked Brazilian cable modems to down sites is so 2013

Dozens of companies over the weekend were hit by distributed denial-of-service (DDoS) attacks, including the largest one yet recorded, or so Cloudflare says.…

☐ β˜† βœ‡ The Register - Security

Google lets a few Android devices into its Privacy Sandbox

February 14th 2023 at 17:00

Chocolate Factory's ad tech renovation is moving ahead, like it or not

Google on Tuesday began rolling out a beta test of its Privacy Sandbox software for a small portion of Android 13 devices to learn how its purportedly privacy-protecting ad tech actually performs.…

☐ β˜† βœ‡ The Register - Security

Romance scam targets security researcher, hilarity ensues

February 14th 2023 at 02:30

Happy Valentine's Day! Now don't get fooled

It sounds like the plot of a somewhat far-fetched romcom-slash-thriller Netflix series, maybe billed as You meets Your Place or Mine, dropping just in time for Valentine's Day.…

☐ β˜† βœ‡ The Register - Security

Pepsi Bottling Ventures says info-stealing malware swiped sensitive data

February 14th 2023 at 00:30

That's not what I like

Crooks have breached Pepsi Bottling Ventures' network and, after deploying info-stealing malware, made off with sensitive personal and financial information according to a notification sent to consumers.…

☐ β˜† βœ‡ The Register - Security

Namecheap admits 'unauthorized emails' pwning its customers

February 13th 2023 at 16:13

Blames 'third-party provider' as phishers drain Ethereum wallets

Domain registrar Namecheap blamed a "third-party provider" that sends its newsletters after customers complained of receiving phishing emails from Namecheap's system.…

☐ β˜† βœ‡ The Register - Security

LockBit's Royal Mail ransom deadline flies by. No data released

February 13th 2023 at 12:38

Also: Russian wiper malware authors turn to data theft, plus this week's critical vulns

in brief The notorious LockBit ransomware gang has taken credit for an attack on the Royal Mail – but a deadline it gave for payment has come and gone with nothing exposed to the web except the group's claims.…

☐ β˜† βœ‡ The Register - Security

Learn the art of malicious compliance: doing exactly what you were asked, even when it's wrong

February 13th 2023 at 08:28

Smart-alec worker found a way to avoid nasty, boring jobs – by doing what he was told

Who, Me? Ah, gentle reader, welcome back once again to the comfortable backwater of The Register we call Who, Me? in which readers' tales of not-quite-rightness are immortalized for the ages.…

☐ β˜† βœ‡ The Register - Security

China's spy balloon barrage earns six of its companies a spot on US entity list

February 13th 2023 at 06:28

US Commerce Department can't just let red balloons go by

The US Department of Commerce added six more entities to its blacklist on Friday on grounds of national security after an errant Chinese surveillance balloon was shot down over the US last week.…

☐ β˜† βœ‡ The Register - Security

Ransomware crooks steal 3m+ patients' medical records, personal info

February 11th 2023 at 02:16

All that data coming soon to a darkweb crime forum near you?

Several California medical groups have sent security breach notification letters to more than three million patients alerting them that crooks may have stolen a ton of their sensitive health and personal information during a ransomware infection in December.…

☐ β˜† βœ‡ The Register - Security

US, UK slap sanctions on Russians linked to Conti, Ryuk, Trickbot malware

February 10th 2023 at 07:24

Any act that sends so much as a ruble to seven named netizens now forbidden

The US and UK have sanctioned seven Russians for their alleged roles in disseminating Conti and Ryuk ransomware and the Trickbot banking trojan.…

☐ β˜† βœ‡ The Register - Security

US teases more China tech sanctions, this time to deflate balloon-makers

February 10th 2023 at 06:31

State Dept already has one target, FBI is identifying sources of floating surveillance platform's components

The Chinese surveillance balloon that drifted across the US last week looks set to spark a new round of sanctions against Middle Kingdom tech firms.…

☐ β˜† βœ‡ The Register - Security

Australia gives made-in-China CCTV cams the boot

February 10th 2023 at 04:28

The usual suspects - Hikvision and Dahua - named as a risk to national security, prompting the usual denials

Australia's Defence Department removed all Chinese manufactured surveillance cameras after an audit detailed the number of Hikvision and Dahua devices installed in various government facilities.…

☐ β˜† βœ‡ The Register - Security

Romance scammers' favorite lies cost victims $1.3B last year

February 10th 2023 at 03:28

Don't trust your super-hot military boyfriend you've never met. He doesn't exist

As Valentine's Day approaches, if your offshore oil rig worker "boyfriend" – who looks like Bradley Cooper in his online pics and has hinted at proposing to you for months, but you've never met in real life – suddenly needs money for "hospital bills" … Just. Don't. Do. It.…

☐ β˜† βœ‡ The Register - Security

Reddit reveals security incident that looks more SNAFU than TIFU

February 10th 2023 at 01:29

Phishing hooked internal documents, code, and some non-critical systems, but users' personal info safe

Colorful web forum Reddit has revealed it has suffered a security breach.…

☐ β˜† βœ‡ The Register - Security

Codebreakers decipher Mary, Queen of Scots' secret letters 436 years after her execution

February 9th 2023 at 08:30

Digital sleuths chop through crypto challenge in 'surreal' search

A team of codebreakers discovered – and then cracked – more than 50 secret letters written by Mary Stuart, Queen of Scots while she was imprisoned in England by her cousin, Queen Elizabeth I. …

☐ β˜† βœ‡ The Register - Security

Uncle Sam wants to strip the IoS out of IoT with light crypto

February 9th 2023 at 00:30

NIST weighs up algorithms for small devices – and an architecture for massive systems

The US National Institute of Standards and Technology wants to protect all devices great and small, and is getting closer to settling on next-gen cryptographic algorithms suitable for systems at both ends of that spectrum – the very great and the very small.…

☐ β˜† βœ‡ The Register - Security

Among the thousands of ESXiArgs ransomware victims? FBI and CISA to the rescue

February 8th 2023 at 21:30

Evil code hits more than 3,800 servers globally, according to the Feds

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a recovery script to help companies whose servers were scrambled in the recent ESXiArgs ransomware outbreak.…

☐ β˜† βœ‡ The Register - Security

Scammers steal $4 million in crypto during face-to-face meeting

February 8th 2023 at 13:30

Demand to display wallet full of coin facilitated mystery heist

Ahad Shams, the co-founder of Web3 metaverse gaming engine startup Webaverse, discovered in late November 2022 that someone had stolen $4 million of his cryptocurrency – during a real world interaction.…

☐ β˜† βœ‡ The Register - Security

Suspect in Finnish psychotherapy center blackmail hack arrested

February 8th 2023 at 06:30

Suomi sentence expected for shrink records theft

French police have arrested a 25-year-old Finnish man accused of hacking a psychotherapy clinic, stealing more than 22,000 patients' therapy notes, demanding ransom payments from them and also leaking this very private info on a Tor website.…

☐ β˜† βœ‡ The Register - Security

Eurocops shut down Exclu encrypted messaging app, arrest dozens

February 7th 2023 at 07:30

German and Dutch authorities say the app was a favorite of organized criminals and drug smugglers

An encrypted messaging service that has been on law enforcement's radar since a 2019 raid on an old NATO bunker has been shut down after a sweeping series of raids across Europe last week. …

☐ β˜† βœ‡ The Register - Security

Embarrassment as US cyber ambassador's Twitter account is hacked

February 6th 2023 at 23:59

'Perils of the job' we're told

A top US cyber diplomat said his Twitter account was compromised over the weekend.…

❌